Jump to content

Malwarebytes

Last rogues


10 replies to this topic

#1
Jammie

    New Member

  • Members
  • Pip
  • 16 posts
  • Gender:Male
  • Location:UK-UA
Guys check this:
hxxp://winspycontrol.com/ - 100% rogue :P
hxxp://www.smartfixer.com/ - need test :)
Thank's

#2
nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,158 posts
  • Location:Northampton, MA USA
I will fire them up tonight .

Reverse IP in a sec .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,158 posts
  • Location:Northampton, MA USA
Winspycontrol.com is on a AVSystemcare clone server . 112 total sites , most not in english . MBAM can remove the ones installed by or advertised through trojans .

The www.smartfixer.com server is mostly pr0n and pharna sites , 257 total . I will look into some of them tonight to see if any infect .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#4
Sparsha

    True Member

  • Experts
  • PipPipPipPip
  • 264 posts
  • Gender:Male
More information on smartfixer:
http://sunbeltblog.blogspot.com/2007/06/sm...ed-through.html
Cheers,
Sparsha

#5
Sparsha

    True Member

  • Experts
  • PipPipPipPip
  • 264 posts
  • Gender:Male
might be a few more junk scanners on this site

antivirusnew.blogspot.com
Cheers,
Sparsha

#6
nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,158 posts
  • Location:Northampton, MA USA
Smartfixer produced 84 ridiculous FPs for the sole purpose of scaring the user into purchasing their scam product .

The FPs were all temp internet files and random image files . These were all listed as critical threats .

The update option is also a scam . It declares that a new version can be downloaded but this new version has the same MD5 as the old .

Will be added to MBAM tonight .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#7
nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,158 posts
  • Location:Northampton, MA USA
Attempting to locate the installer for winspycontrol or the suffix that allows download .

It also seems that their server is under very high stress , pages open slowly and don't always generate complete graphics .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#8
nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,158 posts
  • Location:Northampton, MA USA
Old suffixes don't work , time to grab some new ones .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#9
nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,158 posts
  • Location:Northampton, MA USA
Current working suffix : data/index.php?06550859571002075652024367404b6e075a6b570757501356550a5e0c060b0b475307020d04173b
b045a020c070f004453090550

Now you are mine .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#10
Jammie

    New Member

  • Members
  • Pip
  • 16 posts
  • Gender:Male
  • Location:UK-UA
thank's nosirrah, good work :P

#11
SwampDiner

    True Member

  • Experts
  • PipPipPipPip
  • 419 posts
  • Location:The Internets
Added 155





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us