Log in

View Full Version : "HOT URL!" your PC infected, install AV2009


evaluator
January 31st, 2009, 03:45
hehe, good promo, m$ icons looks naturElly.. & downloaded exe.Icon also very good.. letz unpack!

http://computeronlineproscan.com/promo/1/freescan.php?nu=77008808

evaluator
January 31st, 2009, 04:52
damn, again faulty crypter, coded for particular Kernel32 code.. forced execution & inside was clean UPX..
pass: MALWARE

Kayaker
January 31st, 2009, 04:55
Pretty fascinating dissection by Joe Stewart on the AV2008 crapware, btw. Someone even hacked into their website and found out their earnings. Fricking amazing, we're talking about $5million US potential yearly earnings by these botnets.

Rogue Antivirus Dissected

http://www.secureworks.com/research/threats/rogue-antivirus-part-1/?threat=rogue-antivirus-part-1

http://www.secureworks.com/research/threats/rogue-antivirus-part-2/?threat=rogue-antivirus-part-2


The Federal Trade Commission is trying to take down similar malware scams:

http://www.secureworks.com/research/blog/2008/12/12/ftc-takes-on-antivirus-xp/