Jump to content

Malwarebytes

Fake Windows Security


3 replies to this topic

#1
josee

    New Member

  • Members
  • Pip
  • 24 posts
This File comes with LinkSafeness Fake ntivirus (Rogue)





Posted Image

#2
josee

    New Member

  • Members
  • Pip
  • 24 posts
Ups , i think i make a mistake when uploading file on my first post :)

Attached Files



#3
alexeck

    Regular Member

  • Experts
  • PipPip
  • 57 posts
FakeSmoke: starts with the WiniGuard back around Oct 2008 and whose family of all rogues so far as seen below

The installation is in 3 parts.
The primary installer (Setup.exe) which is a progress bar which drops two secondary installers.

The first to be ran is what creates over 700 Fake files in both %WINDWS% and %SYSTEM% and the second is the rogues install wizard.

The file that opens the Windows Security Center is also found in the %LOCAL_SETTINGS%\Temp with the two secondary installers.

BlockKeeper
BlockProtector
BlockScanner
BlockWatcher
LinkSafeness
OmegaAntivir
SafeFighter
SafetyKeeper
SaveArmor
SaveDefender
SecureKeeper
SecureVeteran
SecureWarrior
SecurityFighter
SecuritySoldier
ShieldSafeness
SiteVillain
SoftBarrier
SoftCop
SoftSafeness
SoftStrongHold
SoftVeteran
SystemFighter
SystemVeteran
SystemWarrior
TREAntivirus
TrustCop
TrustFighter
TrustSoldier
TrustWarrior
WinBlueSoft
winiblusoft
WiniFighter
WiniGuard
WiniShield

#4
Fatdcuk

    Malware BBQ'er

  • Moderators
  • PipPipPipPipPipPip
  • 16,155 posts
  • Gender:Male
  • Location:127.0.0.1
Hi josee,

The file was already known to the MBAM database as Rogue.Multiple as we have a good string lock on it currently.
.
Ade Gill
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us