R3v3rs3e's Blog

Posts Tagged ‘Safety Center’

Scareware uses Fake Windows 7 Action Center

Posted by Steve Espino on December 8, 2009

Privacy Center, Privacy Components and Safety Center are some of the aliases used by this family of scareware that hide under the guise of a fake Windows 7 Action Center.

The scareware installer uses the filename win_protection_update.exe and once installed, this scareware displays fake scan results in an attempt to convince unsuspecting users into buying the fake software.

A lifetime license for this fake app amounts to a hefty $79.95 plus $19.95 for “Premium Support”.

Here are some domains related to distributing this attack:

software-scaner-online.com
scaner-online-malware.biz

PC Tools Spyware Doctor with Antivirus detects this scareware as RogueAntiSpyware.PrivacyCenter.AJ.

Posted in Rogue Apps | Tagged: , , , , , , , , , , , , , , , , , , , , , , | Leave a Comment »

Porn site distributes scareware

Posted by Steve Espino on August 27, 2009

Another website has recently been spotted to be serving up malware in the guise of fake video codecs.

This one praises itself as “The Best Nude Celebrity Movie Site”
hxxp://alyssafan.net/1.html

face_codec

But in order to watch the any video, we would need to download and install their “Certified ActiveX video codec (VAC codec) use to protect content Copyrights”

The fake fake codec can be downloaded here:
hxxp://alyssafan.net/Mediacodec_v4.8.exe

One of the components used in this attack is an onfuscated javascript file that can be found in the %temp% folder.

obfuscated

This script translates to:

deobfuscated

This script downloads:
hxxp://ue4x08f5myqdl.cn/u3.exe

Which then gives us scareware Safety Center:

safetycenter

Beware of fake video codecs!

Posted in Uncategorized | Tagged: , , , , , , , , , , , , , , , | 2 Comments »

 
Follow

Get every new post delivered to your Inbox.