Rogue ... antivirus 2009

Discussion in 'malware problems & news' started by Chuck57, Jul 31, 2008.

Thread Status:
Not open for further replies.
  1. emperordarius

    emperordarius Registered Member

    Joined:
    Apr 27, 2008
    Posts:
    1,218
    Location:
    Who cares
    Thanks aigle. Maybe it would have been a user friendly app if it wasn't a rogue:D
     
  2. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Hmmm... it,s stiull friendly. :rolleyes:
     
  3. HURST

    HURST Registered Member

    Joined:
    Jul 20, 2007
    Posts:
    1,419
    Thanks for testing aigle. I didn't expected GesWall to fail.
    Different GUI, different name, same old rogue....
     
  4. Dark Shadow

    Dark Shadow Registered Member

    Joined:
    Oct 11, 2007
    Posts:
    4,553
    Location:
    USA
    Now that you mentioned it yes confirmed.Same experience wth sandboxie.
     
  5. Dark Shadow

    Dark Shadow Registered Member

    Joined:
    Oct 11, 2007
    Posts:
    4,553
    Location:
    USA
    You very well may be correct. I get this with Java applet,when I close java sits in tray and when I move pointer over its gone.
     
  6. Dark Shadow

    Dark Shadow Registered Member

    Joined:
    Oct 11, 2007
    Posts:
    4,553
    Location:
    USA
    And On that note, I can see why people fall for it the pretty eye candy.:cool:
     
  7. midway40

    midway40 Registered Member

    Joined:
    Jul 24, 2006
    Posts:
    1,257
    Location:
    SW MS, USA
    This has been a nice discussion with everyone voicing their observations of this particular piece of malware. I have been pretty busy lately and had no time to play with it anymore myself. Thanks for all the input :)
     
  8. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Tried with HauteSecure. It blocks most of these link by its black list..... Strangely real time protection of HAuteSecure works even with Opera.
     

    Attached Files:

    • 1.jpg
      1.jpg
      File size:
      12.8 KB
      Views:
      553
    • 2.jpg
      2.jpg
      File size:
      12.4 KB
      Views:
      556
    • 3.jpg
      3.jpg
      File size:
      12.1 KB
      Views:
      562
    • 4.jpg
      4.jpg
      File size:
      84.6 KB
      Views:
      10
  9. Threedog

    Threedog Registered Member

    Joined:
    Mar 20, 2005
    Posts:
    1,125
    Location:
    Nova Scotia, Canada
    Superantispyware Pro real time blocks the executable now.
     
  10. Mapson

    Mapson Registered Member

    Joined:
    Dec 29, 2005
    Posts:
    54
    aigle, thanks again for all your tests, they really are appreciated. It might be worth you keeping an eye on the RSS feed that follows - http://www.hosts-file.net/rss.asp
     
  11. simmikie

    simmikie Registered Member

    Joined:
    Nov 11, 2006
    Posts:
    321
  12. Chuck57

    Chuck57 Registered Member

    Joined:
    Sep 2, 2002
    Posts:
    1,770
    Location:
    New Mexico, USA
    Jealous? LOL It just proves that DefenseWall is one of the best, if not the best, at protecting you. I bet Returnil works too. Lots of bad stuff out there, although this antivirus 2008 or 2009 is more of a nuisance. There's lots of good security out there too. geswall, Returnil, Sandboxie are a few of the good ones.
     
  13. CogitoErgoSum

    CogitoErgoSum Registered Member

    Joined:
    Aug 22, 2005
    Posts:
    641
    Location:
    Cerritos, California
    For those who are interested,

    To satisfy my curiosity, I personally tested this malware sample against DefenseWall(DW). Fortunately, whether I let the program run it's full course or terminate it's process earlier in the sequence, DW successfully blocks and contains it. Before rolling back and deleting the associated malicious files and registry entries, I created two logs for one to review as proof. Keep in mind that these logs were taken when I allowed the program to run it's full course.


    Peace & Gratitude,

    CogitoErgoSum
     

    Attached Files:

    Last edited: Aug 13, 2008
  14. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Thanks Mapson!
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.