please follow me on: http://malware-research-experts.blogspot.com
Archive for the ‘Uncategorized’ Category
Malware Research Experts
Posted by Steve Espino on March 27, 2012
Posted in Uncategorized | Leave a Comment »
Spyware Doctor with AntiVirus 2010 gets 4.5 out of 5 stars from How-to Geek
Posted by Steve Espino on November 6, 2009
PC Tools’ award winning Spyware Doctor with AntiVirus 2010 has done it again, earning a rating of 4.5 out of 5 stars as reviewed by How-to Geek.
Spyware Doctor with Antivirus is a top-rated malware, spyware & virus removal utility that detects, removes and protects your PC from thousands of potential spyware, adware, trojans, viruses, keyloggers, spybots and tracking threats. Spyware Doctor’s advanced Intelliguard technology only alerts users on a true spyware and virus detection. Spyware Doctor with Antivirus has the most advanced update feature that continually improves its spyware and virus fighting capabilities on a daily basis. As spyware gets more complex in order to avoid detection, Spyware Doctor responds with new technology to stay one step ahead.
More details here.
Posted in Uncategorized | Tagged: How-to Geek, PC Tools, SDAV, Spyware Doctor, Spyware Doctor with AntiVirus 2010 | Leave a Comment »
MaCatte scareware fools users by masquerading as McAfee
Posted by Steve Espino on November 3, 2009

MaCatte Antivirus is a rogue av that attempts to impersonate McAfee scanners in order to scam users, which PC Tools Spyware Doctor with Antivirus aptly detects as RogueAntiSpyware.MaCatte
This scareware has been seen to be using a bogus My Computer online scan similar to ones we’ve seen here, here and here.

The online scan can be seen on this url:
hxxp://proscan5.info/25/26-088wLzQzL1EzL==
The downloader being served from this url is time-sensitive and will not work after a period of time. A session ID of some sort is embedded on the binary executable itself. After such time has elapsed, the downloader tells the user to contact MaCatte Antivirus support people. This prevents reverse-engineers from replicating the infection and gathering samples for analysis.
Presence of these files / folders would signal infection from this scareware:
C:\Documents and Settings\All Users\Application Data\msca
C:\Documents and Settings\All Users\Application Data\msca\MaCatte.ico
C:\Documents and Settings\All Users\Application Data\msca\mcull.exe
C:\Documents and Settings\All Users\Application Data\msca\msc.exe
C:\Documents and Settings\All Users\Application Data\msca\Viruses.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Media\WPtect.dll
C:\Documents and Settings\All Users\Desktop\MaCatte.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\MaCatte
C:\Documents and Settings\All Users\Start Menu\Programs\MaCatte\MaCatte.lnk
Unsuspecting users are set back from their hard-earned money by a hefty $99.
Stay away from these rogue apps.
Posted in Uncategorized | Tagged: fake app, fake av, MaCatte, MaCatte Antivirus, macatte.com, McAfee, PC Tools, proscan5.info, rogue app, rogue av, RogueAntiSpyware.MaCatte, scareware, security, Spyware Doctor, Spyware Doctor with AntiVirus | 2 Comments »
Spyware Doctor with AntiVirus 2010 wins PC Mag Editor’s Choice
Posted by Steve Espino on October 16, 2009
This just in: on 15th October 2009, Spyware Doctor with AntiVirus 2010 wins PC Mag Editor’s Choice award!
The latest Spyware Doctor proved effective in every area of malware removal and blocking. It’s a great product.
The award-winning Spyware Doctor with AntiVirus 2010 can be downloaded here.
Posted in Uncategorized | Tagged: PC Mag Editor's Choice, pctools, Spyware Doctor, Spyware Doctor with AntiVirus 2010 | Leave a Comment »
Another Shameless SEO based on Atlanta Flooding
Posted by Steve Espino on September 22, 2009
Users Googling “Atlanta flood pictures” receive a yet another SEO attack, using a possibly compromised legitimate Australian website hosting restaurants in the famous Bondi area.
Here’s a screenshot of a google search result:

A Fiddler capture shows us the redirections:

So we go from
hxxp://idrb.com/pdf_files/atlanta-flood-pictures.html
>hxxp://06d.ru/t.php
>>hxxp://read-cnn2.com/?pid=207&sid=de9f8f
>>>hxxp://winfixscanner7.com/scan1/?pid=207&engine=pHTyzjTyMzEyOS44Mi4xOTAmdGltZT0xMjUuNgAMPAVN
An installer named Soft_207.exe will be presented for download, which PC Tools Spyware Doctor with Antivirus aptly detects as RogueAntiSpyware.TotalSecurity.
At the moment, the PC Tools Malware Research Centre has observed the following domains being used for the distribution:
winfixscanner7(dot)com
15scanner(dot)com
These domains resolve to the following IP addresses:
89.47.237.55
89.248.174.61
213.163.89.60
But knowing the trend in scareware, there could be heaps more domains being created as we speak.
PC Tools Spyware Doctor with Antivirus protects its users from RogueAntiSpyware.TotalSecurity.
Posted in Uncategorized | Tagged: 06d.ru, 15scanner.com, 213.163.89.60, 89.248.174.61, 89.47.237.55, Atlanta flood pictures, fake alert, fake av, idrb.com, PC Tools, read-cnn2.com, rogue, rogue app, rogue av, RogueAntiSpyware.TotalSecurity, scareware, SEO, Spyware Doctor, Total Security, winfixscanner7.com | Leave a Comment »
Porn site distributes scareware
Posted by Steve Espino on August 27, 2009
Another website has recently been spotted to be serving up malware in the guise of fake video codecs.
This one praises itself as “The Best Nude Celebrity Movie Site”
hxxp://alyssafan.net/1.html

But in order to watch the any video, we would need to download and install their “Certified ActiveX video codec (VAC codec) use to protect content Copyrights”
The fake fake codec can be downloaded here:
hxxp://alyssafan.net/Mediacodec_v4.8.exe
One of the components used in this attack is an onfuscated javascript file that can be found in the %temp% folder.

This script translates to:

This script downloads:
hxxp://ue4x08f5myqdl.cn/u3.exe
Which then gives us scareware Safety Center:

Beware of fake video codecs!
Posted in Uncategorized | Tagged: alyssafan.net, fake alert, fake app, fake av, fake codec, fake video codec, Mediacodec, porn, rogue app, rogue av, Safety Center, scareware, security, The Best Nude Celebrity Movie Site, ue4x08f5myqdl.cn, video | 2 Comments »












