Se afișează postările cu eticheta trojan. Afișați toate postările
Se afișează postările cu eticheta trojan. Afișați toate postările

miercuri, 21 decembrie 2022

Windows Security & Control

 Windows Security & Control is yet another rogue security application , it is also a clone from the following rogues : Windows System Optimizator , Windows Optimization Center and Windows Optimization & Security

As we look at those clones , they are much intended to infect like other clones it blocks applications , invade safemode disable system restore and disable legitimate microsoft security essentials including real time protection 


The program nothing founds only an imaginary system error and viruses by also implant itself at startup to stop the errors is to purchase key or patch the program to stop errors.

The virus use the fake microsoft security essentials alert and install but at next restart the virus replace the shell with himself.

Even if you dont know the virus hide itself in %appdata% with a random of characters it can be :

tvvdeo.exe

dxkovi.exe

frdkiu.exe

xhbvkt.exe

dnvavl.exe

jhtmch.exe

ixrojp.exe

lsjqxr.exe

udsydv.exe

lcvecw.exe

bcgtmj.exe

dvedrq.exe

yhgkbq.exe

lfkrwf.exe

ghqnrt.exe

Even if you dont heart they are the same application but randomized letters 

The virus is called SecurityScanner.exe and had an md5 hash : 7dde6427dcf06d0c861693b96ad053a0

Once registered it stop blocking applications and let use legitimate antivirus to remove it

Thanks to Ender's show (File captured on 2017)

joi, 15 decembrie 2022

Windows Optimization & Security

Windows Optimization & Security is another Bogus antivirus program clone of Windows System Optimizator and Windows Optimization Center

He may look like this : (Source Forum malwarebytes)


Is another rogue faking microsoft security essentials alert pushing into installing the windows optimization and security by fake setup installers.

He may release his own icon in taskbar and desktop when registered.He use a brute way to hide itself from delete file he create a copy of itself in %appdata% but for now he didnt use protect.exe filename also it use random names and hide itself.

He may hijack the winlogon shell in resulting almost difficulty to remove in safe mode by this rogue when closed explorer but his alerts and blocking apps still remain :





Example of random file .exe it may look like : C:\Documents and Settings\{username}\Application Data\payjxv.exe

It also disable System restore and blocking windows defender and kill the windows defender process with its own commands.

It also disable UAC user account control and spread the commands to kill microsoft security essentials :

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR="1"

You can reset the value of DISABLESR to 0 re enabling the system restore ability

WINLogon shell hijacked

[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]

"Shell"="'C:\Documents and Settings\{username}\Application Data\payjxv.exe'"

When you get this you can change back to explorer.exe and delete the file in cause

MD5 of the virus for curious : 03f4360a1503e369199dbaee4afa5f28

ESET-NOD32 A Variant Of Win32/Adware.PrivacyGuard2010.AD

Microsoft : Rogue:WIN32/Fakepav

In this evolution of fakepav it increase its ability per every cloned family. Test the virus at the risk

Thanks to Virusshare.

For removal press here https://forums.malwarebytes.com/topic/72980-removal-instructions-for-windows-optimization-security/

sâmbătă, 22 octombrie 2022

Windows Antivirus Pro fakescanti

 Windows Antivirus pro is a Phony security software in the fakescanti family.

His interface is starting like this : 









When executed and running it start installing and decompress some trojans svchast.exe a fake svchost process while holding it start to block executables not also to make them like corrupted modifying the registry.

The error will result in this :




Not also it install an addon for IE internet Explorer while access some sites even google or yahoo the pop up is :











While Running it start to display on taskbar and windows certain errors :


























When running it extract on tmp an exe called dbinstinit and wipex.html this one it extract its file and make to display a fake security center.Any click will result in activation of this rogue









After 15 minutes of running is copying 2 htmls onhelp and sonhelp.html one of them contain your personal wallpaper and one the spyware warning when perfomed the desktop background will be :



When hijacked also display fake errors that svchost has stopped : 

Those tactics to lure the user that the pc infected by spyware and viruses and to remove the viruses and hijacked wallpaper and run properly the executables it need to be registred.

Test this threat on a vmware or virtual box.
Thanks to OpenMalware.
Filename is Windows Antivirus Pro.exe and md5 is : 3fec8b41a9564c1aa1c3dea03a2e4c97


luni, 23 decembrie 2019

Wista Antivirus - A variant of SpywareIsolator / SpyEraser

Wista Antivirus is an rogue antivirus which is name is really wista antivirus without any mistake or mispell this rogue is specified a clone of spywareisolator.
When starting the splash screen is loading.
After loading a scan with few non existent things has been loaded.
Interface Look Like This.

Upon this rogue has finished the scan is pop up an warning with an sound incoming look like a siren.

One or more threats are indecent somehow so i check back to settings to check out what he have.
 It said to turn on everything to pay up to 90 USD TO this rogue however i load ollydbg to check out to retrieve an activation key
 And this does every time click it have an sound effect so no pop up payload taskbar.Sounds idle
 And all stuff to turn on it require register of license :
 And if we see the infections of the spyware scan it look like this.
 How i do know the variant of SpywareIsolator and innovagest2000 / Bakasoftware?Mostly it have wav file and dll folder nothing at all include an rogue with large installer MB
The installer of the wista antivirus was identified.
wistaantivirus_setup.exe
MD5 bc73a7bf5758a10e53b6a5928b983c9e 
Adware.SpywareIsolator
Wistaantivirus.s
And now we are making the activation process.The fever of rogues on full version incoming.
 And finally we know what to do the code is 3927306263 with my caps off name as seen it check clipboard this rogue but it require to press the button.
 And finally success.Nice one full version and if we click on any attempt to remove the threats.
 So to have an high protection and threat remove it says to reboot the PC Process so it have glitch if on registred app said invalid key it corrects back to the previous valid.
 Well after restart registred and perfect :) no more false positive and disable the register button
 No found viruses.
 Turned on everything hmm.
 Then this one is falling on my attempt of full version.
 His name is funny but great thanks to Fedor22.For sharing this sample.
Video Review :
Stay away.This rogue sample was tested in 2018 - 2019 

duminică, 10 noiembrie 2019

System Adware Scanner 2010 - Rogue WinWebSec

System Adware scanner 2010 is a phony rogue which his site template is steal AVG And is installed without a pop up warning.Is a clone from the rogues : Security Tool , Smart Security (Fake) , Windows Smart Security . 2009 , system security 2009 etc.
Is being installer if the user click on a warning pop up :
If we try task manager it saying the following warning :
Affected and blocked exe are taskmgr.exe and the mbam.exe
 Once we click on this warning it installs automatically the system adware scanner 2010 and spawns fake alert about spyware , infected computer etc
The interface of system adware scanner 2010 look like :
Also this pop up will recreate the payload and making them fast itself the malware.
The system adware scanner have a checking and files left from scanning the fake threats once files left 0 all files are scanned and the scan is finished
Unlike this rogueware he have also a CPU Load by his process and GUI.
CPU load from this fake antivirus.
And now after finish all infections are fake but i am still wait for new payloads 
This fake antivirus once running cannot be killed process is behave like a system idle process or access denied to kill the fake antivirus using process explorer
But one more thing is to catch all payloads and other interesting and curious.
Let's try to turn on something
But we cannot enable anything when is activated

Nothing cannot be activated but is still keep to say to activate the aliases : sysadscanner SAS

 
 Continue Unprotected so when i still try to bypass fakealerts but they are more fast right now we cannot also change settings or disable

What about crack or get a license :
 Not too far but we remember attempts and we show more payloads on a infected pc
Lame license check
More payloads i have identifies but more problems and another fake alert 
More payloads i identified but their gui are not applied as system tool and other winwebsec family of rogues
But is blocking only taskmgr.exe nothing interesting from dumb rogueware Few leaks from his html code 
 Pop up ballon messages from taskbar




 Warnings differently any click rediect to payment page.
 SAS?Update maybe is checking around this rogueware

If we try help support there is :
 Saving the report file not too far
We are gonna now to register the software no matter 6 license one year month so here is a serial list dump :

SASNL-LUMUT-AXZCU-JUA55-MANDA
SASNL-LUMUT-AXZUY-JUA51-NBAHD
SASNL-LUMUT-AXUCY-JUA44-90DSA
SASNL-LUMUT-AUZCY-JUA41-20DSA
SASNL-LUMUT-UXZCY-JUA33-YSH2A
SASNL-LUMUT-AXZCU-UHA31-8JSA3
SASNL-LUMUT-AXZUY-UHA22-7HWBA
SASNL-LUMUT-AXUCY-UHA21-1IQBW
SASNL-LUMUT-AUZCY-UHA11-5BDFW
SASNL-LUMUT-UXZCY-UHA01-4JHSQ
SASYL-L2M2T-AXZC2-2HA55-3MDWI
SASYL-L2M2T-AXZ2Y-2HA51-2NJSW
SASYL-L2M2T-AX2CY-2HA44-4NDUW
SASYL-L2M2T-A2ZCY-2HA41-6SBNO
SASYL-L2M2T-2XZCY-2HA33-92NN2
SASYL-L2M2T-AXZC2-2HA31-N27SB
SASYL-L2M2T-AXZ2Y-2HA22-9DIQ9
SASYL-L2M2T-AX2CY-2HA21-72NSB
SASYL-L2M2T-A2ZCY-2HA11-10S9Z
SASYL-L2M2T-2XZCY-2HA01-82NIS
SASYL-L1M1T-AXZC1-JHA55-01KMQ
SASYL-L1M1T-AXZ1Y-JHA51-9W9IX
SASYL-L1M1T-AX1CY-JHA44-NB92M
SASYL-L1M1T-A1ZCY-JHA41-17JS9
SASYL-L1M1T-1XZCY-JHA33-0W9JZ
SASYL-L1M1T-AXZC1-JHA31-MN38D
SASYL-L1M1T-AXZ1Y-JHA22-6DJ93
SASYL-L1M1T-AX1CY-JHA12-P92OC
SASYL-L1M1T-A1ZCY-JHA11-JD72B
SASYL-L1M1T-1XZCY-JHA01-Z1X67
Clipboard check :
 Ok Nice registration but another trick is to create a file with extension .r

 c:\Documents and Settings\All Users\Application Datak4w4x7f7\k4w4x7f7.r
This is an example of trick registration with empty file also serial keys
c:\Documents and Settings\All Users\Application Data\k4w4x7f7
c:\Documents and Settings\All Users\Application Data\k4w4x7f7\k4w4x7f7
c:\Documents and Settings\All Users\Application Data\k4w4x7f7\k4w4x7f7.exe
c:\Documents and Settings\All Users\Application Data\k4w4x7f7\k4w4x7f7.i
c:\WINDOWS\system32\drivers\k4w4x7f7.sys
This is a random character executable you have to use license key but i research this type
of rogue virus antimalware 
 Is said to reboot the pc and the process will be normal after restart
A fake clean up so nothing real i guess.
 Once registred we can enable everything full version


 License type and rogueware warranty
 Enable everything :
 Update registred?Server error maybe online server but last update still change the version
System adware scanner 2010 1.01

Attempts to crack activate rogue and more ways to be smart than rogueav .Video About System Adware Scanner 2010 Here :
                                  

DO NOT TRUST SYSTEM ADWARE SCANNER 2010 ROGUE VIRUS SO A LOT OF WAYS AND ATTEMPTS TO DEFEAT THE FAKE ANTIVIRUS.
                               Thanks to : EnigmaSoft , Emisisoft and Andrew Mickleson
                        All helps to reverse and test the sample of fakeav




1.You can remove the bogus rogue with mbam This rogue will not block the legitimate cleaner
2.The command for uninstaller is buggy
3.Remove any registry entry which is negative and caused by this program

Curious to take the sample? Here is the md5 of the file d9f4025d3ea3cb0a26dabcf6176c45c8