Windows Antivirus pro is a Phony security software in the fakescanti family.
His interface is starting like this :
When executed and running it start installing and decompress some trojans svchast.exe a fake svchost process while holding it start to block executables not also to make them like corrupted modifying the registry.
The error will result in this :
Not also it install an addon for IE internet Explorer while access some sites even google or yahoo the pop up is :
While Running it start to display on taskbar and windows certain errors :
When running it extract on tmp an exe called dbinstinit and wipex.html this one it extract its file and make to display a fake security center.Any click will result in activation of this rogue
After 15 minutes of running is copying 2 htmls onhelp and sonhelp.html one of them contain your personal wallpaper and one the spyware warning when perfomed the desktop background will be :
When hijacked also display fake errors that svchost has stopped :
Those tactics to lure the user that the pc infected by spyware and viruses and to remove the viruses and hijacked wallpaper and run properly the executables it need to be registred.
Advanced Security Tool 2010 is a rogue antivirus software once running it start implanting itself using a mof file and batch file to enter the rogue by itself in real legitimate windows security center
Interface GUI Is like this :
This is one not actually reskined by safety Antispyware and WinPC Defender however fakerean is tripled itself rogue family or other multiple times
How he implant itself to legitimate security center
He first open itself a batch file with command wscui.cpl and mofcomp it use the security center resources and command to make the rogue product visible to real security center
Look in trial version
So looking at other payloads and he also drop viruses junk files to be classifited as virus malware backdoor trojan and other it make invalid exe dll reg acebot and other it have random files name.
If we ignore or click close or later or something to continue unprotected look like that
So i decided to activate the rogue :
The version of activation is differently too far this rogue does not require email so pretty fragile for a little cracking for his code.
Once we ignore bypass activation or a payload alert we got this
And if we wanna to make change to turn off and on we got also this
I forgot once restart pc we get the payload un used by the rogue. replace explorer.
And support ?
Here is all ingredients from this fakerean they are so located in %appdata%
asectool.exe md5 : a2f34f8c19beaff52730fd438570e133
He drop most of the files
So the payload like firewall alert is sinister :
It use the username of the PC And the ComputerName
Also update black version
This version is not blocking little bit from executables
I am also asked are you sure?
Activation Code after i debug little bit here is code i found :
3547-74831239063-9802
After activation it show the code that is valid and store into registry Called Advanced Security
The dialog is a braviax looking window.
After i activated i need to cleanup and restart program.WHAT??
Threat removed.
Once activated i can also update but he refresh the inject of security center files because is turned on high protection
Full version still no threats :
Let's do an update
And the legitimate security center was disabled or notify that rogue up to date and scanning virus on
You have to erase him with MBAM
I also tested on windows 10 and higher os but most fully error and compatibility mode to XP
Video Review i release him video review in 2017 and i cracked in 2019:
Personal Protector is a fake security software from fakespyguard Family Clone : Advanced Defender Personal Guard 2009
The Interface from installer look like this :
His database is not actually empty so he after restart or in a strange moment he can overload and load the database worker to find threats and implating fake alert after disable real security center
Notifications are Showed Like That :
Let (FakeSpyGuard Name)
Was Similar to Smart Protector
The Installer is PersonalProtectorInstaller.exe
MD5 : 672d77d4bc81da0850cd970fa682fa47
This trojan after a boot or log off or time similar he scan for threats
He also drop dll installer bootkit and program files may look like this
c:\Documents and Settings\All Users\Microsoft PData\inetprovider.dll
%UserProfile%\Desktop\Personal Protector.lnk
%UserProfile%\Start Menu\Programs\Personal Protector
%UserProfile%\Start Menu\Programs\Personal Protector\Personal Protector.lnk
%UserProfile%\Start Menu\Programs\Personal Protector\Uninstall.lnk
The files was dropped by installer.
Also after reboot or long time logged on also Starting to create a fake security center and find threats.
And security so the register to activate there is no way to bypass if you close said invalid
The Input from database is : base.wdb and baseadd.wdb this is so differently
The database will look in plain notepad text no encryption :
base.wdb
asty1|Trojan-Downloader.Win32.Banload.dcd|This Trojan downloads other files via the Internet and launches them for execution on the victim machine without the user’s knowledge or consent|3|Trojan
asty2|Backdoor.Agobot.gen|This is a classical backdoor and allows a 'master' to control the victim machine remotely by sending commands via IRC channels|1|Spyware
asty3|Virus.JS.Fortnight|JS.Fortnight is an Internet worm that uses infected emails with hidden links to an Internet Web page from which it downloads its infected code.|1|JavaScript Virus
asty4|Email-Flooder.Win32.FriendGreetings|Advert.FriendGreetings is an electronic post card program that once installed, unlike other similar programs, sends out emails to all addresses found in a victim computer's Microsoft address book|1|Malware
asty5|Email-Worm.Win32.Eyeveg.g|This worm spreads via the Internet as an attachment to infected emails|3|Malware
asty6|Trojan-Clicker.BAT.Small.c|This Trojan opens web sites without the knowledge or consent of the user|3|Internet virus
asty7|Trojan-Downloader.HTML.Agent.aq|This Trojan downloads other malicious programs|2|Trojan downloader
asty8|Trojan-Spy.HTML.Citifraud.db|This Trojan uses spoofing technology, and is a fake HTML page|3|Spyware programm
asty9|Trojan-Spy.HTML.Combats.a|This Trojan is designed to steal confidential data|2|Spyware programm
astz1|Backdoor.Netbus|This is a hidden (hacker's) remote administration utility similar to the known Backdoor.BO (a.k.a. Back Orifice) Trojan|3|Backdors
Did you notice ? He mistaked the Personal Guard 2009 and Allow to exit ?
baseadd.wdb
C:\WINDOWS\inf\1394vdbg.inf|Trojan-Spy.HTML.Combats.a|This Trojan is designed to steal confidential data|2|Spyware program|0
c:\WINDOWS\inf\axant5.inf|Trojan-Clicker.BAT.Small.c|This Trojan opens web sites without the knowledge or consent of the user|2|Internet virus|0
C:\WINDOWS\inf\1394.inf|Email-Worm.Win32.Eyeveg.g|This worm spreads via the Internet as an attachment to infected emails|3|Malware|0
C:\WINDOWS\inf\1394vdbg.inf|Trojan-Spy.HTML.Combats.a|This Trojan is designed to steal confidential data|2|Spyware program|0
c:\WINDOWS\inf\axant5.inf|Trojan-Clicker.BAT.Small.c|This Trojan opens web sites without the knowledge or consent of the user|2|Internet virus|0
C:\WINDOWS\system\VER.DLL|Backdoor.Netbus|This is a hidden (hacker's) remote administration utility similar to the known Backdoor.BO (a.k.a. Back Orifice) Trojan|2|backdoor|0
C:\WINDOWS\inf\1394.inf|Email-Worm.Win32.Eyeveg.g|This worm spreads via the Internet as an attachment to infected emails|3|Malware|0
C:\WINDOWS\ehome\custsat.dll|Trojan-Spy.HTML.Combats.a|This Trojan is designed to steal confidential data|2|Spyware program|0
C:\WINDOWS\AppPatch\sysmain.sdb|Trojan-Clicker.BAT.Small.c|This Trojan opens web sites without the knowledge or consent of the user|2|Internet virus|0
C:\WINDOWS\Driver Cache\i386\portcls.sys|Backdoor.Netbus|This is a hidden (hacker's) remote administration utility similar to the known Backdoor.BO (a.k.a. Back Orifice) Trojan|2|backdoor|0
C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\updspapi.dll|Email-Worm.Win32.Eyeveg.g|This worm spreads via the Internet as an attachment to infected emails|3|Malware|0
C:\WINDOWS\twain_32\wiatwain.ds|Trojan-Spy.HTML.Combats.a|This Trojan is designed to steal confidential data|2|Spyware program|0
C:\WINDOWS\Microsoft.NET\Framework\sbs_iehost.dll|Trojan-Clicker.BAT.Small.c|This Trojan opens web sites without the knowledge or consent of the user|2|Internet virus|0
C:\WINDOWS\Microsoft.NET\Framework\SharedReg12.dll|Backdoor.Netbus|This is a hidden (hacker's) remote administration utility similar to the known Backdoor.BO (a.k.a. Back Orifice) Trojan|2|backdoor|0
C:\WINDOWS\srchasst\msgr3en.dll|Email-Worm.Win32.Eyeveg.g|This worm spreads via the Internet as an attachment to infected emails|3|Malware|0
C:\WINDOWS\explorer.exe|Backdoor.Netbus|This is a hidden (hacker's) remote administration utility similar to the known Backdoor.BO (a.k.a. Back Orifice) Trojan|2|backdoor|0
C:\WINDOWS\TASKMAN.exe|Trojan-Clicker.BAT.Small.c|This Trojan opens web sites without the knowledge or consent of the user|2|Internet virus|0
C:\WINDOWS\srchasst\srchctls.dll|Email-Worm.Win32.Eyeveg.g|This worm spreads via the Internet as an attachment to infected emails|3|Malware|0
C:\WINDOWS\PeerNet\sqlqp20.dll|Trojan-Spy.HTML.Combats.a|This Trojan is designed to steal confidential data|2|Spyware program|0
C:\WINDOWS\PeerNet\sqldb20.dll|Trojan-Spy.HTML.Combats.a|This Trojan is designed to steal confidential data|2|Spyware program|0
C:\WINDOWS\PeerNet\sqlse20.dll|Trojan-Spy.HTML.Combats.a|This Trojan is designed to steal confidential data|2|Spyware program|0
C:\WINDOWS\security\Database\secedit.dll|Backdoor.Netbus|This is a hidden (hacker's) remote administration utility similar to the known Backdoor.BO (a.k.a. Back Orifice) Trojan|2|backdoor|0
C:\WINDOWS\system32\chkntfs.exe|Trojan-Spy.HTML.Combats.a|This Trojan is designed to steal confidential data|2|Spyware program|0
C:\WINDOWS\system32\csrss.exe|Trojan-Clicker.BAT.Small.c|This Trojan opens web sites without the knowledge or consent of the user|2|Internet virus|0
C:\WINDOWS\system32\dxdiag.exe|Backdoor.Netbus|This is a hidden (hacker's) remote administration utility similar to the known Backdoor.BO (a.k.a. Back Orifice) Trojan|2|backdoor|0
C:\WINDOWS\system32\iernonce.dll|Email-Worm.Win32.Eyeveg.g|This worm spreads via the Internet as an attachment to infected emails|3|Malware|0
C:\WINDOWS\system32\jobexec.dll|Trojan-Spy.HTML.Combats.a|This Trojan is designed to steal confidential data|2|Spyware program|0
C:\WINDOWS\system32\mfc40.dll|Trojan-Clicker.BAT.Small.c|This Trojan opens web sites without the knowledge or consent of the user|2|Internet virus|0
C:\WINDOWS\system32\msdtc.exe|Backdoor.Netbus|This is a hidden (hacker's) remote administration utility similar to the known Backdoor.BO (a.k.a. Back Orifice) Trojan|2|backdoor|0
C:\WINDOWS\system32\ntmsevt.dll|Trojan-Spy.HTML.Combats.a|This Trojan is designed to steal confidential data|2|Spyware program|0
C:\WINDOWS\system32\runas.exe|Trojan-Clicker.BAT.Small.c|This Trojan opens web sites without the knowledge or consent of the user|2|Internet virus|0
C:\WINDOWS\system32\wpabaln.exe|Trojan-Spy.HTML.Combats.a|This Trojan is designed to steal confidential data|2|Spyware program|0
The registration is saving as a bookmark adress if is correct after i debug the private registration
Code is :
58086752C1D853DE3C770472E76898F2C0AC1AD3
Once Registred he disable the fake security center and remedy all negative changes and cleanup allowed and store in a salted code hashed private.
Also if you put digits or dashes under code may works
No Any of the files will be quaratine still empty the file 0 kb until modify
Now there is no continue unprotected or ALT + F4
The Update Also is fake
Update Antivirus Modules database module update program update completed i think is not remote a server or update error
The registry look like this location : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Personal Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Personal Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "personalprotector"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce "suicide"
Activated and Installed data
STAY AWAY If you don't know is a virus
Video Review and payload :