Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 29th, 2011, 12:53 PM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,517
Default Rogue AV "AVG Antivirus 2011"

avg.exe - 5/43 - MD5 : e17a9937cb0314c22aeba5804727151f

Bleeping Removal Guide

Name:  One.JPG
Views: 1269
Size:  25.0 KB

Name:  Two.JPG
Views: 1270
Size:  67.6 KB

Name:  Three.JPG
Views: 1268
Size:  59.6 KB

Name:  Four.JPG
Views: 1266
Size:  18.2 KB
  #2  
Old January 29th, 2011, 02:27 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,846
Default Re: Rogue AV "AVG Antivirus 2011"

Interesting how the've gone to the trouble of using AVG icons, but then funny how they list it as Dr.Web

It would still fool at lot of people though, and i guess it already has
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #3  
Old January 29th, 2011, 02:31 PM
Ibrad's Avatar
Ibrad Ibrad is offline
Very Frequent Poster
 
Join Date: Dec 2009
Posts: 1,887
Default Re: Rogue AV "AVG Antivirus 2011"

They can't seem to make up their mind, do they want to copy AVG or Dr. Web
__________________
Panda Security TRUSTED MOD


Panda Cloud Antivirus + Rising PC Doctor + Common Sense

My Security Blog: http://igl-security.blogspot.com/
  #4  
Old January 29th, 2011, 07:18 PM
Noob's Avatar
Noob Noob is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 5,229
Default Re: Rogue AV "AVG Antivirus 2011"

Hahaha, next generation Fake AV's now completely emulating real AV GUI!!
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736
SRP - UAC - EMET

Browser: Google Chrome v25.xx

Windows 7 Ultimate x64
  #5  
Old January 30th, 2011, 12:57 AM
Phant0m's Avatar
Phant0m Phant0m is offline
Massive Poster
 
Join Date: Jun 2003
Location: Canada
Posts: 3,326
Default Re: Rogue AV "AVG Antivirus 2011"

This must be circulating quickly, I had to already deal with this AVG rogue yesterday on one of my clients computer.

To me, for visual wise, it looks completely different than the real thing.

However, to my client, it was very, very convincing. When he called up about this problem with AVG, he basically said that this AVG is overrunning his computer, it loaded up on his computer automatically and it rendered useless the McAfee. He went onto saying “AVG shouldn’t be allowed to do this, should be criminal!”, and I said, from the sounds of things, I believe you have a AVG rogue infection, the real AVG wouldn’t display such malicious behavior.

Went out, I removed it, and addressed McAfee problems, checked for recent updates, received the recent updates and then his ISP decided to suspend his Internet account just at the moment I was getting ready to leave for home. Contacted his ISP, gave client information, mention ISP modem loss of Internet connectivity, and I was informed that the clients account was suspended due to a payment being missed recently.
__________________
"Success is almost totally dependent upon drive and persistence. The extra energy required to make another effort or try another approach is the secret of winning.” --Dennis Waitley
  #6  
Old January 30th, 2011, 03:23 AM
Noob's Avatar
Noob Noob is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 5,229
Default Re: Rogue AV "AVG Antivirus 2011"

LOL what a pain, now you will have to go back

Hahaha IMO that GUI is more than enough to disguise most people!
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736
SRP - UAC - EMET

Browser: Google Chrome v25.xx

Windows 7 Ultimate x64
  #7  
Old January 30th, 2011, 07:34 AM
carat
 
Posts: n/a
Default Re: Rogue AV "AVG Antivirus 2011"

Better GUI than the original
  #8  
Old January 31st, 2011, 04:12 PM
safeguy's Avatar
safeguy safeguy is offline
Frequent Poster
 
Join Date: Jun 2010
Location: Singapore
Posts: 872
Default Re: Rogue AV "AVG Antivirus 2011"

It looks ugly. I'm wondering if the original AVG itself has added this to their database/signatures...
__________________
Uncertainty is the only certainty there is, and knowing how to live with insecurity is the only security...
  #9  
Old January 31st, 2011, 10:15 PM
MrBrian MrBrian is offline
Very Frequent Poster
 
Join Date: Feb 2008
Posts: 2,925
Default Re: Rogue AV "AVG Antivirus 2011"

FakeXPA raises a few brows
  #10  
Old February 2nd, 2011, 07:38 AM
Daveski17's Avatar
Daveski17 Daveski17 is offline
Massive Poster
 
Join Date: Nov 2008
Location: Lloegyr
Posts: 5,309
Default Re: Rogue AV "AVG Antivirus 2011"

F-Secure's take on the rogue AVG.
__________________
Quis custodiet ipsos custodes?
  #11  
Old February 2nd, 2011, 08:50 PM
safeguy's Avatar
safeguy safeguy is offline
Frequent Poster
 
Join Date: Jun 2010
Location: Singapore
Posts: 872
Default Re: Rogue AV "AVG Antivirus 2011"

Quote:
Aside from AVG's logo, the rogue's interface bears no resemblance to that of the legit AVG Anti-Virus Free Edition 2011.

Imagine how many more people will be duped if it resembles the real thing...
__________________
Uncertainty is the only certainty there is, and knowing how to live with insecurity is the only security...
  #12  
Old February 3rd, 2011, 03:13 PM
EliteKiller's Avatar
EliteKiller EliteKiller is offline
Very Frequent Poster
 
Join Date: Jan 2007
Location: TX
Posts: 1,123
Default Re: Rogue AV "AVG Antivirus 2011"

I've removed the fake AVG 2011 from one XP Pro SP3 pc and one Vista HP SP2 pc. After the removal flash player is not listed as an add-on in IE8. However it continues to work in Firefox 3.6.13. I've tried the following:

1) Ran the flash uninstaller
2) Ran CCleaner
3) Downloaded and installed the full flash activex installer

This did not resolve the issue. Add-on is not listed and flash will not play on any website.

4) Ran the subinacl fix - no change
5) Uninstall IE8 and revert to IE6 - no change
6) Reinstall IE8 - no change
7) Tried to uninstall/reinstall flash again - no change
Ran the XP fixpolicies fix - no change

I have not tried a repair install, but at this point I am stumped.
  #13  
Old February 15th, 2011, 08:09 PM
egomoo's Avatar
egomoo egomoo is offline
Regular Poster
 
Join Date: Aug 2007
Posts: 115
Default Re: Rogue AV "AVG Antivirus 2011"

I have tried to remove fake AVG Antivirus 2011 using Safe Returner

It will fix the hijack of broswer

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\chrome.exe
Attached Images
 
__________________
SafeReturner Developer
  #14  
Old February 16th, 2011, 08:19 PM
4everybody 4everybody is offline
Infrequent Poster
 
Join Date: Nov 2010
Posts: 2
Default Re: Rogue AV "AVG Antivirus 2011"

Did anyone find out whats causing This ?? I believe that the Rogue AVG does some changes in Registry or any, WHich Apparantly making IE not to play Any videos. Other browsers plays the video without any issues & IE alone Alerts like, Cannot Find flash player.

If Any got a fix for this, please do let everyone know the same.

Regards,
4Everybody

Quote:
Originally Posted by EliteKiller
I've removed the fake AVG 2011 from one XP Pro SP3 pc and one Vista HP SP2 pc. After the removal flash player is not listed as an add-on in IE8. However it continues to work in Firefox 3.6.13. I've tried the following:

1) Ran the flash uninstaller
2) Ran CCleaner
3) Downloaded and installed the full flash activex installer

This did not resolve the issue. Add-on is not listed and flash will not play on any website.

4) Ran the subinacl fix - no change
5) Uninstall IE8 and revert to IE6 - no change
6) Reinstall IE8 - no change
7) Tried to uninstall/reinstall flash again - no change
Ran the XP fixpolicies fix - no change

I have not tried a repair install, but at this point I am stumped.
  #15  
Old February 16th, 2011, 10:19 PM
egomoo's Avatar
egomoo egomoo is offline
Regular Poster
 
Join Date: Aug 2007
Posts: 115
Default Re: Rogue AV "AVG Antivirus 2011"

Do Please check the value about

{D2F97240-C9F4-11CF-BFC4-00A0C90C2BDB} is the CLSID of shockwave flash object

the path in the registry

Quote:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{D2F97240-C9F4-11CF-BFC4-00A0C90C2BDB}]


Or you could use my fix code (just copy it and save to a notepad as fix.reg)

Quote:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{D2F97240-C9F4-11CF-BFC4-00A0C90C2BDB}]
"Compatibility Flags"=dword:00000010

__________________
SafeReturner Developer
  #16  
Old February 16th, 2011, 10:52 PM
EliteKiller's Avatar
EliteKiller EliteKiller is offline
Very Frequent Poster
 
Join Date: Jan 2007
Location: TX
Posts: 1,123
Default Re: Rogue AV "AVG Antivirus 2011"

@egomoo

Unfortunately your suggestion did not resolve the issue. The dword and value you listed was already intact on the pc that had the rogue AVG removed. Removing the key and adding the reg file had no change. Using IE8 and visiting Hulu still displays "Hulu requires Flash Player 10.0.32 or higher. Please download and install the latest version of Flash Player before continuing."
  #17  
Old February 17th, 2011, 02:12 AM
egomoo's Avatar
egomoo egomoo is offline
Regular Poster
 
Join Date: Aug 2007
Posts: 115
Default Re: Rogue AV "AVG Antivirus 2011"

o,I'm sorry

In my test,I use a Windows XP sp2 machine

maybe the CLSID is different about Flash Player 10

But the key is below

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\
__________________
SafeReturner Developer
  #18  
Old February 17th, 2011, 02:31 AM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,846
Lightbulb Re: Rogue AV "AVG Antivirus 2011"

@ EliteKiller

Hi, i've had similar problems in the past. Sometimes it "might" be due to not allowing some scripting, or all, and/or iframes, and/or refferer/s. Also now it seems we have to allow PlugInContainer as well As you said FF is ok, i'm only posting that info in case others would like to know, if they don't already

As for IE, have you looked in Options at the settings ? The following is on IE6.

Name:  v.gif
Views: 650
Size:  10.8 KB

Name:  ie.gif
Views: 645
Size:  7.6 KB

Also something such as MruBlaster etc could be blocking it ?
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #19  
Old February 17th, 2011, 12:55 PM
4everybody 4everybody is offline
Infrequent Poster
 
Join Date: Nov 2010
Posts: 2
Default Re: Rogue AV "AVG Antivirus 2011"

All the Above Steps, failed to Fix it. Anything else to Try ??
  #20  
Old February 17th, 2011, 04:01 PM
mjlk's Avatar
mjlk mjlk is offline
Infrequent Poster
 
Join Date: Jul 2009
Posts: 7
Default Re: Rogue AV "AVG Antivirus 2011"

Quote:
Originally Posted by 4everybody
All the Above Steps, failed to Fix it. Anything else to Try ??

Adobe Forums :
-http://forums.adobe.com/message/3454998#3454998-
  #21  
Old February 17th, 2011, 08:37 PM
EliteKiller's Avatar
EliteKiller EliteKiller is offline
Very Frequent Poster
 
Join Date: Jan 2007
Location: TX
Posts: 1,123
Default Re: Rogue AV "AVG Antivirus 2011"

Quote:
Originally Posted by mjlk
Adobe Forums :
-http://forums.adobe.com/message/3454998#3454998-

Thanks for sharing that link.

- Uninstalling using the flash removal tool ~ reboot
- reinstall flash 9 ~ reboot
- uninstall flash again using the removal tool ~ reboot
- install flash 10 ~ reboot

The trick was definitely uninstalling flash and installing the old version 9 first. All of the reboots may not be necessary, but I did them anyhow and flash now works on the pc that was infected with the fake AVG 2011.
  #22  
Old February 19th, 2011, 07:19 PM
Ibrad's Avatar
Ibrad Ibrad is offline
Very Frequent Poster
 
Join Date: Dec 2009
Posts: 1,887
Default Re: Rogue AV "AVG Antivirus 2011"

Just saw on the Panda Cloud forum that a user reported that got a sample just like this except AVG Antivirus is was Dr. Web Antivirus for Windows 2011.
__________________
Panda Security TRUSTED MOD


Panda Cloud Antivirus + Rising PC Doctor + Common Sense

My Security Blog: http://igl-security.blogspot.com/
  #23  
Old February 19th, 2011, 07:51 PM
John Bull's Avatar
John Bull John Bull is offline
Banned
 
Join Date: Nov 2009
Location: London UK
Posts: 904
Default Re: Rogue AV "AVG Antivirus 2011"

I suppose I`ll get a few kicks, but here goes.

These AVG look-a-likes not only look like fakes, but smell like them. Yes they will fool a lot of people if they are silly enough to click anything, but to the more experienced user, their behaviour is a joke.

OK, a false threat panel can pop up and cause concern with perhaps ONE infection message, but 22 !! I cannot stop laughing. After months of web activity and no daily/weekly scans, it just MAY be possible, but even that is stretching it a little.

Use Sandboxie all the time and these cowboy`s can paint AVG or Dr.Web Picasso`s all over the screen. Just completely ignore them, delete the sandbox contents and away they go down the plug hole - Glug Glug. No infection in sight. Next one please.

John

I have added this footnote to provide some fact in case my main comments are taken as one of JB`s joy-rides.

Over the past few months, I have had TWO fake AVG alerts pop up inside SBxie. Of course I knew they were the work of some freak. All I did was delete the contents of the sandbox, shut down SBie and FF, then checked my REAL AVG. NOTHING there of course and a quick scan with HMP and MBAM was clear.

So all I can say is "Roll up, roll up you hackers, you `aint going nowhere". Just use SBxie then you can forget all these pretty pictures from the rogues gallery.

Last edited by John Bull : February 20th, 2011 at 04:18 AM.
  #24  
Old February 19th, 2011, 09:39 PM
zfactor's Avatar
zfactor zfactor is offline
Massive Poster
 
Join Date: Mar 2005
Location: on my zx10-r
Posts: 4,273
Default Re: Rogue AV "AVG Antivirus 2011"

my mother AND my mother in law both got hit with this today my mom is running nis2011 and my mother in law is running avast and they both let it right through. arghhhh now i have work tomm to remove this garbage. they BOTH got it while on their facebook page
__________________
Meatwad you're up next, with your knock-knock.
Meatwad make the money see. Meatwad get the honeys G. Drivin in my car, living like a star ice on my fingers and my toes, and im a taurus

"Some days your the windshield. Some days your the bug"
Eset ESS V6 / Webroot WSA / Avast! IS V8
  #25  
Old February 20th, 2011, 08:34 PM
zfactor's Avatar
zfactor zfactor is offline
Massive Poster
 
Join Date: Mar 2005
Location: on my zx10-r
Posts: 4,273
Default Re: Rogue AV "AVG Antivirus 2011"

VERY NICE well i was going to have to fix this on my mother in law's computer but this morning she turned it on and said it took a while to come on and then when it did avast popped up and said it found and fixed a threat and suggested a reboot. she did and the avg antivirus was no longer there. i did double check to make sure it was gone and it was except 2 leftover reg entries i deleted otherwise it cleaned it all up. very nice and thank you avast
__________________
Meatwad you're up next, with your knock-knock.
Meatwad make the money see. Meatwad get the honeys G. Drivin in my car, living like a star ice on my fingers and my toes, and im a taurus

"Some days your the windshield. Some days your the bug"
Eset ESS V6 / Webroot WSA / Avast! IS V8
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:21 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums