Jump to content

Malwarebytes

Malwareremovalbot


3 replies to this topic

#1
Fatdcuk

    Malware BBQ'er

  • Moderators
  • PipPipPipPipPipPip
  • 16,150 posts
  • Gender:Male
  • Location:127.0.0.1
Well these *** clowns are ripping on your popularity ;)

h_t_t_p://malware.bytescan.org/

The software seems to photo shy at the mo,it hides everytime i goto use my image capture software but they seem to have a f/p problem.

Upload of installer to VT yields 2/39 hits
http://www.virustotal.com/analisis/bdf0fa7...70494c862edc3be

Not 100% it is rogue but goddam sleazy at best.
Ade Gill
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#2
Jaxryley

    Forum Deity

  • Malware Hunters
  • PipPipPipPipPipPip
  • 6,718 posts
  • Gender:Male
  • Location:West Aussie
  • Interests:Gardening and computers.
I see what you mean where you can't grab a screenie of the gui.

I fired up an XP vm where it installed no probs and tried to grab a screenie and it's gui disappeared.

So I thought ahh, Vista's snipping tool within the real system will be able to grab a screenie.

Even though the rogue's gui didn't disappear Vista's snipping tool just wouldn't work properly!

Go figure? ;)

#3
sho-dan

    कैंसर योद्धा

  • Honorary Members
  • PipPipPipPipPipPip
  • 3,023 posts
  • Gender:Not Telling
  • Location:Jah Jersey Shore
This one be around for a while, looks like a rogue, acts like a rouge but is it a rogue in the true sense.
MBAM and SAS doesnt pick it up
It does'nt control the computer with constent popups when closing, no force reboots, F/Ps are created and removal is done manually via Add/Remove, C:Programs, registry removal also removes the setupxv icon from the Control panel

HKEY_CURRENT_USER\Software\MalwareRemovalBot

This can be found in the Google ads on jotti, its only in a regional zone as jotti explain in email

Something odd about the name below ;) I did email Igor about the name abuse, we shall see if I get an answer

setupxv Properties info: Version
  • Company:Igor Pavlov

  • File Version:4.42

  • Internal Name:7zS.sfx

  • Original File Name7zS.sfx.exe

  • Product Name:7-Zip

  • Product Name:4.42

"Don't worry about a thing,
'Cause every little thing gonna be all right!"

#4
GT500

    Mostly Cantankerous

  • Trusted Advisors
  • PipPipPipPipPipPip
  • 5,527 posts
  • Gender:Male
  • Location:Fortville, IN
* No option to save a log.

* You must purchase to remove detected items.

* At least one customer of theirs thinks she purchased MBAM.

Quote

For we wrestle not against flesh and blood, but against principalities, against powers, and against the worldly governors, the princes of the darkness of this world...





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us