Jump to content


Photo

Adware.Rogue.Windefender.C


  • This topic is locked This topic is locked
98 replies to this topic

#1 B-boy/StyLe/

B-boy/StyLe/

    FFreestyleRR

  • Experts
  • PipPipPipPipPip
  • 824 posts
  • Gender:Male
  • Location:Bulgaria

Posted 09 May 2009 - 05:23 PM

hXXp://rapidshare.com/files/231138341/_68E9.rar.html

VirusTotal (6/40)

Not hit by MBAM:

Quote

Database version: 2102
Windows 6.1.7100

10.5.2009 г. 01:06:20
mbam-log-2009-05-10 (01-06-20).txt

Scan type: Quick Scan
Objects scanned: 60379
Time elapsed: 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

*Came with Loaris Trojan Remover installation...

One FP with loaris and not hit by VirusTotal.

Posted Image
Posted Image
My help is always free of charge. If you appreciate my work, you can buy me a beer or two by clicking here - Posted Image

#2 Lusitano

Lusitano

    Regular Member

  • Malware Hunters
  • PipPip
  • 75 posts
  • Gender:Male

Posted 09 May 2009 - 06:10 PM

RAR corrupted

#3 B-boy/StyLe/

B-boy/StyLe/

    FFreestyleRR

  • Experts
  • PipPipPipPipPip
  • 824 posts
  • Gender:Male
  • Location:Bulgaria

Posted 09 May 2009 - 06:33 PM

View PostLusitano, on May 10 2009, 12:10 AM, said:

RAR corrupted

Lol. You're right ! Sorry :(

hXXp://rapidshare.com/files/231159439/_660.rar.html

Posted Image
My help is always free of charge. If you appreciate my work, you can buy me a beer or two by clicking here - Posted Image

#4 MysteryFCM

MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 5,018 posts
  • Gender:Male
  • Location:Tyneside, UK

Posted 09 May 2009 - 07:34 PM

Was this actually installed by loaris?

/edit

The rar just seems to contain another rar with a database and version info file? Do you have the original executable that this belongs to?
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#5 MysteryFCM

MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 5,018 posts
  • Gender:Male
  • Location:Tyneside, UK

Posted 09 May 2009 - 07:50 PM

Okie, downloaded the file from loaris.com and;

hjt1.com > UPX packed > http://virusscan.jotti.org/en/scanresult/c...044888c03236e77

Unpacked:
http://virusscan.jotti.org/en/scanresult/b...a24e3ee95dc412e

Looking at hjt1 in a hex editor, shows it's a renamed copy of Trend Micro HJT (naughty naughty).

Can't see the files you rar'd though?
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#6 B-boy/StyLe/

B-boy/StyLe/

    FFreestyleRR

  • Experts
  • PipPipPipPipPip
  • 824 posts
  • Gender:Male
  • Location:Bulgaria

Posted 09 May 2009 - 08:03 PM

Maybe some kind of definition file ? I don't know.

Posted Image

After installation process:

Posted Image
Posted Image
My help is always free of charge. If you appreciate my work, you can buy me a beer or two by clicking here - Posted Image

#7 MysteryFCM

MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 5,018 posts
  • Gender:Male
  • Location:Tyneside, UK

Posted 09 May 2009 - 08:07 PM

Oks, cheers :( (don't have access to a test machine atm, so couldn't actually run it)

/edit

Jottie results for the DB file (3 detections)

http://virusscan.jotti.org/en/scanresult/0...7520333f32c74a3
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#8 B-boy/StyLe/

B-boy/StyLe/

    FFreestyleRR

  • Experts
  • PipPipPipPipPip
  • 824 posts
  • Gender:Male
  • Location:Bulgaria

Posted 09 May 2009 - 08:12 PM

Maybe FP, but keep an eye on it :(

All the best,

B-boy :)
Posted Image
My help is always free of charge. If you appreciate my work, you can buy me a beer or two by clicking here - Posted Image

#9 Loaris

Loaris

    New Member

  • Members
  • Pip
  • 37 posts
  • Gender:Male

Posted 05 June 2009 - 11:00 AM

View PostB-boy/StyLe/, on May 10 2009, 01:12 AM, said:

Maybe FP, but keep an eye on it :huh:

All the best,

B-boy ;)

Yes, you can keep an eye on us. But, why you can't contact us DIRECTLY and get answers on ALL your questions??
If you have any doubts -- we can solve them! What is your suspicion, and claims?

#10 Loaris

Loaris

    New Member

  • Members
  • Pip
  • 37 posts
  • Gender:Male

Posted 05 June 2009 - 11:34 AM

>>Looking at hjt1 in a hex editor, shows it's a renamed copy of Trend Micro HJT (naughty naughty).

Naughty?! Probably only for you. Many trojans blocked antispyware and tools by exe name. As result some of our customers can't run Trend Micro HJ. I renamed this tool - obviously, is not it? :huh:

>>http://virusscan.jotti.org/en/scanresult/05073d87f4f95074ef482d69b7520333f32c74a3

I don't know what is it. But can assume that it is part of signature from temp folders for detection malware. Any one can send me this file for analyse?

--
any other claim?

#11 MysteryFCM

MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 5,018 posts
  • Gender:Male
  • Location:Tyneside, UK

Posted 05 June 2009 - 11:41 AM

View PostLoaris, on Jun 5 2009, 05:34 PM, said:

>>Looking at hjt1 in a hex editor, shows it's a renamed copy of Trend Micro HJT (naughty naughty).

Naughty?! Probably only for you. Many trojans blocked antispyware and tools by exe name. As result some of our customers can't run Trend Micro HJ. I renamed this tool - obviously, is not it? :huh:

You've missed the point - renaming and including someone elses tool without disclosure or permission (something I doubt you obtained), is bad ethics.
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#12 Loaris

Loaris

    New Member

  • Members
  • Pip
  • 37 posts
  • Gender:Male

Posted 05 June 2009 - 12:00 PM

View PostMysteryFCM, on Jun 5 2009, 04:41 PM, said:

You've missed the point - renaming and including someone elses tool without disclosure or permission (something I doubt you obtained), is bad ethics.

You are right - if it doing for hide real author and/or for deception users.

But in this case -- normal tactic. I didn't remove compyright or EULA! It's accesible in unregistered version without any restrictions.
and more: on many security forums was recomendded the same tactic - renaming.

#13 Loaris

Loaris

    New Member

  • Members
  • Pip
  • 37 posts
  • Gender:Male

Posted 05 June 2009 - 12:32 PM

Instead of that would combine in the fight against malware, you start a game competitor.
not nice! :huh:

#14 TeMerc

TeMerc

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 1,990 posts
  • Gender:Male
  • Location:Phx. AZ. USA
  • Interests:Formula 1 Auto Racing, Computer Security, Entertainment, Sci-Fi, SuperHeroes

Posted 05 June 2009 - 12:37 PM

View PostLoaris, on Jun 5 2009, 10:00 AM, said:

You are right - if it doing for hide real author and/or for deception users.

But in this case -- normal tactic. I didn't remove compyright or EULA! It's accesible in unregistered version without any restrictions.
and more: on many security forums was recomendded the same tactic - renaming.
I think Mystery was referring to the bundling of HiajckThis! into your software. I'd be surprised if Trend Micro approved this.

And yes, renaming is a very popular 'trick', and it is also used in the security forums you mentioned and they are all providing 'free' support, your product costs money to use, does it not?
Tom Mercado
Consumer Support Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#15 B-boy/StyLe/

B-boy/StyLe/

    FFreestyleRR

  • Experts
  • PipPipPipPipPip
  • 824 posts
  • Gender:Male
  • Location:Bulgaria

Posted 05 June 2009 - 12:44 PM

I apologise for the initiated inconvenience. I talk about only for that I saw during use of your product. Nothing more.

I'll send this file to Avira support team for double check as well.

Here is the file:

hXXp://www.mediafire.com/download.php?gq2mjmyc2d3

VirusTotal (5/40)
Posted Image
My help is always free of charge. If you appreciate my work, you can buy me a beer or two by clicking here - Posted Image

#16 Loaris

Loaris

    New Member

  • Members
  • Pip
  • 37 posts
  • Gender:Male

Posted 05 June 2009 - 12:52 PM

View PostTeMerc, on Jun 5 2009, 06:37 PM, said:

I think Mystery was referring to the bundling of HiajckThis! into your software. I'd be surprised if Trend Micro approved this.

And yes, renaming is a very popular 'trick', and it is also used in the security forums you mentioned and they are all providing 'free' support, your product costs money to use, does it not?


If will be any abuse from TrendMicro - I'll remove this tool. You are from TrendMicro? not? So write them about Loaris... I tried several times - unsuccess. I don't see any problem with it!

Did you see http://support.loaris.com ? We provide free support for ALL users. Try to find whom we are not responded. We provide free trial key if users ask (and some times it is good tactic - several of this users buy license later ).

#17 Loaris

Loaris

    New Member

  • Members
  • Pip
  • 37 posts
  • Gender:Male

Posted 05 June 2009 - 12:59 PM

View PostB-boy/StyLe/, on Jun 5 2009, 06:44 PM, said:

I apologise for the initiated inconvenience. I talk about only for that I saw during use of your product. Nothing more.

I'll send this file to Avira support team for double check as well.

Here is the file:

hXXp://www.mediafire.com/download.php?gq2mjmyc2d3

VirusTotal (5/40)

Hello,

thank you! but I can't access to mediafire (may be my ISP blocked this site) please could you to pack this file with password and send it to me via evloaris@gmail.com

#18 Loaris

Loaris

    New Member

  • Members
  • Pip
  • 37 posts
  • Gender:Male

Posted 05 June 2009 - 01:05 PM

View PostLoaris, on Jun 5 2009, 06:52 PM, said:

If will be any abuse from TrendMicro - I'll remove this tool. You are from TrendMicro? not? So write them about Loaris... I tried several times - unsuccess. I don't see any problem with it!

I want to clarify - why it is not a problem for us. In this case, I'm just going to recommend to download HJ from TrendMicro site.
Somewhat difficult for the end users - but nothing more

#19 TeMerc

TeMerc

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 1,990 posts
  • Gender:Male
  • Location:Phx. AZ. USA
  • Interests:Formula 1 Auto Racing, Computer Security, Entertainment, Sci-Fi, SuperHeroes

Posted 05 June 2009 - 01:08 PM

View PostLoaris, on Jun 5 2009, 10:52 AM, said:

If will be any abuse from TrendMicro - I'll remove this tool. You are from TrendMicro? not? So write them about Loaris... I tried several times - unsuccess. I don't see any problem with it!

Did you see http://support.loaris.com ? We provide free support for ALL users. Try to find whom we are not responded. We provide free trial key if users ask (and some times it is good tactic - several of this users buy license later ).
I've sent a message to them via a private forum linking to this public forum.

Again, you miss my point about the bundling of HJT with your product. I never mentioned your support.
Tom Mercado
Consumer Support Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#20 Loaris

Loaris

    New Member

  • Members
  • Pip
  • 37 posts
  • Gender:Male

Posted 05 June 2009 - 01:14 PM

View PostTeMerc, on Jun 5 2009, 07:08 PM, said:

I've sent a message to them via a private forum linking to this public forum.

thanks.

But I am outraged that our soft classified as a rogue by your team!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users