Showing posts with label MS Removal Tool. Show all posts
Showing posts with label MS Removal Tool. Show all posts

Sunday, 19 June 2011

Tracking Cyber Crime: Gagarincash AV Affiliate

Another Fake AV affiliate infiltrated: Gagarincash AV
My friend ScriptKiddieSec gived me a ICQ number for contact these guys, and get access


Gagarincash AV site (nb: The man on background is Yuri Gagarin):


Contrary to the BestAV network who was very professional and closed, Gagarincash have a very simple interface and new account can be created if you have an invitation, and for get invitation, you need to pose as bad guys :þ



When connected, all is grouped on the same page:

Statistics, FakeAV download and three invitation keys, if you want invite someone.
The text before statistics is interesting: Обновляйте exe раз в 5-10 минут. Теперь будет чище гораздо.
It's mean the FakeAV Exe is repacked every 5-10 minutes. (Like BestAV and many others)

According to VirusTotal, repacked FakeAV are detected by 11 Antivirus


Finally it's time to test their FakeAV, and it's: Security Shield 2011, named 'pack.exe' on their download page.


 i'm sure you know it too ;)


 Fake gate:

You can edit your details on Gagarincash, and something i've noticed directly: your current password appear in plaintext on the input password. (i guess account infos are not encrypted on the database)


Contrary to common beliefs, peoples who make FakeAV are not some alone guys who do that for them.
Generaly behind a fakeAV there is a affiliate network who product a huge trafic, don't take them slightly.

The unpack of their FakeAV is boring like this:



Have a nice day.
PS: For those who menace me on irc, who you will call, hitman ?
haha, fags.

Gagarincash related ~
Tracking Cyber Crime: Inside the FakeAV Business (14 Jun 2k11)
Security Shield 2011 (11 Jun 2k11)
Essential Cleaner (18 May 2k11)
MS Removal Tool (29 Mar 2k11)
Security Shield (9 Dec 2k10)
System Tool (12 Dec 2k10)
Security Tool (10 Aug 2k10)

Tuesday, 14 June 2011

Tracking Cyber Crime: Inside the FakeAV Business

Few days ago, a friend mention me about his new article.


For those who don't have access you can see the article here:


I've already see alots of FakeAV samples who got a filename like 'BestAV.exe'
Man, you have definitely intrigued me with your post :)
And like that, i've started to hunt these 'BestAV' guys.

After alot of coffee, i finally come inside the network.
You will see, it's nicely organized, they are responsible for the MS Removal Tool plague.

The main site is named BestAV2, you'll see only this:


WHOIS:
nicline.com's WHOIS database is only for information purposes,
this information consists on domain name registration records.
nicline.com does not guarantee the accuracy of the information
contained in the WHOIS. nicline.com allows the use of the
information only for lawful purposes, under no circumstances this data
will be use for: (a) allow, enable, or otherwise support the transmission
by e-mail, telephone, or facsimile of mass unsolicited, commercial
advertising or solicitations to entities other than the data recipient's
own existing customers; or (b) enable high volume, automated,
electronic processes that send queries or data to the systems of
Registry Operator or any ICANN-Accredited Registrar, except as
reasonably necessary to register domain names or modify existing
registrations.



Service provided by First Ukrainian Internet-Registrar LLC
Hosting solutions and domain registration service.

Domain name: bestavsoft2.com

Registrant:
Ivan Shlesko (SROW-1714932)

audiodius@hotmail.com
ordinskaya 23
Kiev none
827123 UA
+3 80993362121

Administrative contact:
Ivan Shlesko (SRCO-2727745)
Ivan Shlesko
audiodius@hotmail.com
ordinskaya 23
Kiev none
827123 UA
+3 80993362121

Technical contact:
Vyacheslav Cherkashyn (SRCO-101023)
First Ukrainian Internet-Registrar LLC
info@forward.com.ua
134-4-100 Nab Pobeda
Dnepropetrovsk Dnepropetrovsk
49106 UA
+38 0563705242 fax:+38 0563705242

Domain servers in listed order:
ns3.prohosting.com.ua 213.186.192.137
netname.com.ua 91.207.44.31

Created: 02 Dec 2010 00:53:48:930 UTC
Expires: 01 Dec 2011 00:00:00:000 UTC
Last updated: 02 Dec 2010 00:53:48:930 UTC

Like the ripped announce on the ScriptKiddieSec blog says: it's a FakeAV Service, that explain why we see a big amounts of samples like MS Removal Tool, Security Tool, etc.. every day.
Anyone who have money can buy his own MS Removal Tool copy and make money by infecting peoples
The benefit system work like that: 50% for the customer and 50% for the site owner (BestAV team).


Statistic of the customer FakeAV:

I've hidden the stats here, but if you want an example:
(Yeah, easy money.)

FakeAV download:

Testing the downloaded FakeAV:

I guess you know it:

The famous fake payement gate:

BestAv sample found in the wild:

And that even include a system for know wich AntiVirus detect actualy the malware:

Like he says: These guys has a very good cryptor support:

Public download link:

 The customer can manual encrypt the malware:

Can use also a public API

Domains:

Redirector:

News pages, about campaigns, downtime etc...

Condition of use (what a joke):

Escrow support:

What's your mind now about FakeAV ?

BestAV related ~
Security Shield 2011 (11 Jun 2k11)
Essential Cleaner (18 May 2k11)
MS Removal Tool (29 Mar 2k11)
Security Shield (9 Dec 2k10)
System Tool (12 Dec 2k10)
Security Tool (10 Aug 2k10)

Wednesday, 18 May 2011

Essential Cleaner

According to S!Ri:
Essential Cleaner is a new version of MS Removal Tool, System Tool, Security Tool, Total security 2009, System Security rogue.
This fake anti-spyware tool displays fake alert messages, prevent execution of legit programs, detects inexistent infections and Hijacks desktop background to scare users.


To register (and help removal), copy paste one of these codes:
EEDA-S0DF5-GS5E0-FG14S-2DF8G
EEDA-JUYH3-24GHJ-HGKSH-FKLSD
EEDA-89OF7-7324R-5SAD4-TG68U
EEDA-HFVDR-9844O-U54DA-5TBSC
EEDA-G8FB6-1V87S-DRT1S-63SRG
EEDA-4BGY2-JY4KO-IT98Y-7HJ43
EEDA-5D1V2-XB0D5-JT1TY-97DS3
EEDA-F40SA-1ER5H-4FG5D-F8412
EEDA-SERFH-2642S-F04SD-64FG1
EEDA-S0DF5-GS5E0-FG14S-2DF8G
EEDA-452S3-ER00F-TSE35-S8FSD
EEDA-FGS5D-649RG-4S53D-412SF
EEDA-4TS8R-D6F5D-4JH8T-U4JK5
EEDA-2AE32-1VFC2-B6894-G67YU
EEDA-P9685-4H41A-DSW3A-2R64T
EEDA-5SRTS-AEHUF-YA54S-D6F35
EEDA-A1SDF-RY4E8-7U98D-F1GB2
EEDA-A1SDF-6AS4D-RF5RE-79G84
EEDA-TTUYJ-7UO54-G561H-J1D6F
EEDA-G84H6-S854F-79ZA8-W4ERS
EEDA-6W954-FX65B-41VDF-8G4JI
EEDA-U94KO-LF4G4-1V8S1-2CRFE
EEDA-TGN15-RFF29-AASDJ-ASD65
8812702347
7713712456
6614722565
EEDB-ADEEF-FEADD-2FEAA-3EFA7
EEDB-ADEEE-3ADEF-4A78C-32768
4432125899
5532225898
6632325897


Note for reverse engineers ~

Anti VMware:

 Double check: (TextBox/Clipboard)

Tuesday, 29 March 2011

MS Removal Tool


According to S!Ri,
MS Removal Tool is a new version of System Tool, Security Tool, Total security 2009, System Security rogue. This fake anti-spyware tool displays fake alert messages, prevent execution of legit programs, detects inexistent infections and Hijacks desktop background to scare users.


To register (and help removal), copy paste one of these codes:
WNDS-5D1V2-XB0D5-JT1TY-97DS3
WNDS-JUYH3-24GHJ-HGKSH-FKLSD
WNDS-89OF7-7324R-5SAD4-TG68U
WNDS-HFVDR-9844O-U54DA-5TBSC
WNDS-G8FB6-1V87S-DRT1S-63SRG
WNDS-4BGY2-JY4KO-IT98Y-7HJ43
WNDS-F40SA-1ER5H-4FG5D-F8412
WNDS-SERFH-2642S-F04SD-64FG1
WNDS-S0DF5-GS5E0-FG14S-2DF8G
WNDS-452S3-ER00F-TSE35-S8FSD
WNDS-FGS5D-649RG-4S53D-412SF
WNDS-4TS8R-D6F5D-4JH8T-U4JK5
WNDS-2AE32-1VFC2-B6894-G67YU
WNDS-P9685-4H41A-DSW3A-2R64T
WNDS-5SRTS-AEHUF-YA54S-D6F35
WNDS-A1SDF-RY4E8-7U98D-F1GB2
WNDS-A1SDF-6AS4D-RF5RE-79G84
WNDS-TTUYJ-7UO54-G561H-J1D6F
WNDS-G84H6-S854F-79ZA8-W4ERS
WNDS-6W954-FX65B-41VDF-8G4JI
WNDS-U94KO-LF4G4-1V8S1-2CRFE
WNDS-TGN15-RFF29-AASDJ-ASD65
AAAA-BBBBB-CCCCC-DDDDD-EEEEE

Notes for reverse engineers ~

Anti VMware:


And some others tricks who make it difficult to run it with VMware.. but finaly with patience...
Auto copy:


Serial check:


Like previous versions, this rogue continue to use Clipboard API for see if the serial is not inside.