Dangerous Fake Av,

Davo
edited October 2008 in Sample submission

that is why i love some other AV's, no need to be infected, they have all the variant samples added as Generic and they made a strong Generic for all those FAKE, and now those people that use that AV is protected against all these FAKE's AV.


AdSpy.Gen - VirusRemover2008_Setup_Free


Dropper.Gen - PCAntispy_Installer


here are the samples of FAKE AV,


make a strong generic for them.


/applications/core/interface/file/attachment.php?id=3503" data-fileid="3503" rel="">VirusRemover2008_Setup_Free_en.rar

/applications/core/interface/file/attachment.php?id=3504" data-fileid="3504" rel="">PCAntispy_Installer_eng.rar

Comments

  • I assure you that neither Avira or any other AV detects ALL variants of "FakeAV". For once the fake AVs are behind some custom packers and they renew the malware daily to avoid detection (and usually they succeed). That's why every AV has updates. Unfortunately a large amount of malware has the payload trough Scareware or fake antivirus products thus making detection harder.


    Meanwhile we are working on a generic detection for this kind of malware that you sent us.