Nueva variante de FAKE ANTIVIRUS SYSTEM 2011, con los tres EXEs que lo integran

La heuristica del ELISTARA nos reporta estos tres ficheros que una vez preanalizados vemos que Son FAKE AV SYSTEM 2011
Pasamos a controlar los tres ficheros a partir del ELISTARA 22.41 de hoy
File name: SECURITYMANAGER.EXE.Muestra EliStartPage v22.39
Submission date: 2011-01-18 11:36:18 (UTC)
Current status: queued queued analysing finished
Result: 15/ 43 (34.9%)
VT Community

not reviewed
Safety score: –
Compact Print results Antivirus Version Last Update Result
AhnLab-V3 2011.01.18.00 2011.01.17 Trojan/Win32.FakeAV
AntiVir 7.11.1.169 2011.01.18 –
Antiy-AVL 2.0.3.7 2011.01.18 –
Avast 4.8.1351.0 2011.01.18 Win32:FakeAV-BCT
Avast5 5.0.677.0 2011.01.18 Win32:FakeAV-BCT
AVG 10.0.0.1190 2011.01.18 –
BitDefender 7.2 2011.01.18 Gen:Variant.Kazy.8506
CAT-QuickHeal 11.00 2011.01.18 (Suspicious) – DNAScan
ClamAV 0.96.4.0 2011.01.18 –
Commtouch 5.2.11.5 2011.01.18 –
Comodo 7429 2011.01.18 –
DrWeb 5.0.2.03300 2011.01.18 Trojan.Packed.666
Emsisoft 5.1.0.1 2011.01.18 –
eSafe 7.0.17.0 2011.01.17 –
eTrust-Vet 36.1.8105 2011.01.17 –
F-Prot 4.6.2.117 2011.01.17 –
F-Secure 9.0.16160.0 2011.01.18 Gen:Variant.Kazy.8506
Fortinet 4.2.254.0 2011.01.16 –
GData 21 2011.01.18 Gen:Variant.Kazy.8506
Ikarus T3.1.1.97.0 2011.01.18 –
Jiangmin 13.0.900 2011.01.18 –
K7AntiVirus 9.77.3570 2011.01.18 –
Kaspersky 7.0.0.125 2011.01.18 –
McAfee 5.400.0.1158 2011.01.18 –
McAfee-GW-Edition 2010.1C 2011.01.18 –
Microsoft 1.6402 2011.01.18 –
NOD32 5796 2011.01.18 a variant of Win32/Kryptik.JSC
Norman 6.06.12 2011.01.18 –
nProtect 2011-01-18.01 2011.01.18 Gen:Variant.Kazy.8506
Panda 10.0.2.7 2011.01.17 Suspicious file
PCTools 7.0.3.5 2011.01.18 –
Prevx 3.0 2011.01.18 Medium Risk Malware
Rising 22.83.01.03 2011.01.18 –
Sophos 4.61.0 2011.01.18 Troj/FakeAV-CLV
SUPERAntiSpyware 4.40.0.1006 2011.01.18 Trojan.Agent/Gen-FakeScan
Symantec 20101.3.0.103 2011.01.18 –
TheHacker 6.7.0.1.115 2011.01.14 –
TrendMicro 9.120.0.1004 2011.01.18 –
TrendMicro-HouseCall 9.120.0.1004 2011.01.18 –
VBA32 3.12.14.2 2011.01.17 –
VIPRE 8109 2011.01.18 Trojan.Win32.Generic.pak!cobra
ViRobot 2011.1.18.4261 2011.01.18 –
VirusBuster 13.6.151.0 2011.01.17 –
Additional informationShow all
MD5   : 72544bd4a1dd4e30bc6ad4b557c4c8bf
SHA1  : 2e415ebea7d3dcd23378b2a8638a35f3f4ced437

File size : 70656 bytes

publisher….: It Systems
copyright….: (c) It Systems Corp. All rights reserved.
product……: SoftWare processes (c)
description..: Software processes
original name: scanner.exe
internal name: scanner

__________________

File name: SECURITYHELPER.EXE.Muestra EliStartPage v22.39
Submission date: 2011-01-18 11:39:27 (UTC)
Current status: queued queued analysing finished
Result: 14/ 43 (32.6%)
VT Community

not reviewed
Safety score: –
Compact Print results Antivirus Version Last Update Result
AhnLab-V3 2011.01.18.00 2011.01.17 Trojan/Win32.FakeAV
AntiVir 7.11.1.169 2011.01.18 –
Antiy-AVL 2.0.3.7 2011.01.18 –
Avast 4.8.1351.0 2011.01.18 Win32:FakeAV-BCT
Avast5 5.0.677.0 2011.01.18 Win32:FakeAV-BCT
AVG 10.0.0.1190 2011.01.18 FakeAV.IED
BitDefender 7.2 2011.01.18 –
CAT-QuickHeal 11.00 2011.01.18 –
ClamAV 0.96.4.0 2011.01.18 –
Commtouch 5.2.11.5 2011.01.18 –
Comodo 7429 2011.01.18 Heur.Suspicious
DrWeb 5.0.2.03300 2011.01.18 Trojan.Packed.666
Emsisoft 5.1.0.1 2011.01.18 –
eSafe 7.0.17.0 2011.01.17 –
eTrust-Vet 36.1.8105 2011.01.17 –
F-Prot 4.6.2.117 2011.01.17 –
F-Secure 9.0.16160.0 2011.01.18 –
Fortinet 4.2.254.0 2011.01.16 –
GData 21 2011.01.18 Win32:FakeAV-BCT
Ikarus T3.1.1.97.0 2011.01.18 –
Jiangmin 13.0.900 2011.01.18 –
K7AntiVirus 9.77.3570 2011.01.18 –
Kaspersky 7.0.0.125 2011.01.18 –
McAfee 5.400.0.1158 2011.01.18 Artemis!640BF9C62CAF
McAfee-GW-Edition 2010.1C 2011.01.18 Artemis!640BF9C62CAF
Microsoft 1.6402 2011.01.18 –
NOD32 5796 2011.01.18 a variant of Win32/Kryptik.JSC
Norman 6.06.12 2011.01.18 –
nProtect 2011-01-18.01 2011.01.18 –
Panda 10.0.2.7 2011.01.17 Suspicious file
PCTools 7.0.3.5 2011.01.18 –
Prevx 3.0 2011.01.18 Medium Risk Malware
Rising 22.83.01.03 2011.01.18 –
Sophos 4.61.0 2011.01.18 Troj/FakeAV-CLV
SUPERAntiSpyware 4.40.0.1006 2011.01.18 –
Symantec 20101.3.0.103 2011.01.18 –
TheHacker 6.7.0.1.115 2011.01.14 –
TrendMicro 9.120.0.1004 2011.01.18 –
TrendMicro-HouseCall 9.120.0.1004 2011.01.18 –
VBA32 3.12.14.2 2011.01.17 –
VIPRE 8109 2011.01.18 Trojan.Win32.Generic.pak!cobra
ViRobot 2011.1.18.4261 2011.01.18 –
VirusBuster 13.6.151.0 2011.01.17 –
Additional informationShow all
MD5   : 640bf9c62cafaf4e7de3cdae8a5e79bf
SHA1  : 0e9bead16e01428f22d2b8e2ef0f4d1d557eefe3
File size : 3847680 bytes
publisher….: It Systems
copyright….: (c) It Systems Corp. All rights reserved.
product……: SoftWare processes (c)
description..: Software processes
original name: scanner.exe
internal name: scanner

____________

File name: ANTIVIRUS_SYSTEM_2011.EXE.Muestra EliStartPage v22.39
Submission date: 2011-01-18 11:43:36 (UTC)
Current status: queued (#8) queued (#5) analysing finished
Result: 16/ 43 (37.2%)
VT Community

not reviewed
Safety score: –
Compact Print results Antivirus Version Last Update Result
AhnLab-V3 2011.01.18.00 2011.01.17 Trojan/Win32.FakeAV
AntiVir 7.11.1.169 2011.01.18 TR/Crypt.CFI.Gen
Antiy-AVL 2.0.3.7 2011.01.18 –
Avast 4.8.1351.0 2011.01.18 Win32:FakeAV-BCL
Avast5 5.0.677.0 2011.01.18 Win32:FakeAV-BCL
AVG 10.0.0.1190 2011.01.18 –
BitDefender 7.2 2011.01.18 Gen:Variant.Kazy.8284
CAT-QuickHeal 11.00 2011.01.18 –
ClamAV 0.96.4.0 2011.01.18 –
Commtouch 5.2.11.5 2011.01.18 –
Comodo 7429 2011.01.18 –
DrWeb 5.0.2.03300 2011.01.18 Trojan.Packed.666
Emsisoft 5.1.0.1 2011.01.18 Gen.Variant.Kazy!IK
eSafe 7.0.17.0 2011.01.17 –
eTrust-Vet 36.1.8105 2011.01.17 –
F-Prot 4.6.2.117 2011.01.17 –
F-Secure 9.0.16160.0 2011.01.18 Gen:Variant.Kazy.8284
Fortinet 4.2.254.0 2011.01.16 –
GData 21 2011.01.18 Gen:Variant.Kazy.8284
Ikarus T3.1.1.97.0 2011.01.18 Gen.Variant.Kazy
Jiangmin 13.0.900 2011.01.18 –
K7AntiVirus 9.77.3570 2011.01.18 –
Kaspersky 7.0.0.125 2011.01.18 –
McAfee 5.400.0.1158 2011.01.18 –
McAfee-GW-Edition 2010.1C 2011.01.18 –
Microsoft 1.6402 2011.01.18 –
NOD32 5796 2011.01.18 a variant of Win32/Kryptik.JSC
Norman 6.06.12 2011.01.18 –
nProtect 2011-01-18.01 2011.01.18 Gen:Variant.Kazy.8284
Panda 10.0.2.7 2011.01.17 Trj/CI.A
PCTools 7.0.3.5 2011.01.18 –
Prevx 3.0 2011.01.18 Medium Risk Malware
Rising 22.83.01.03 2011.01.18 –
Sophos 4.61.0 2011.01.18 Troj/FakeAV-CLV
SUPERAntiSpyware 4.40.0.1006 2011.01.18 –
Symantec 20101.3.0.103 2011.01.18 –
TheHacker 6.7.0.1.115 2011.01.14 –
TrendMicro 9.120.0.1004 2011.01.18 –
TrendMicro-HouseCall 9.120.0.1004 2011.01.18 –
VBA32 3.12.14.2 2011.01.17 –
VIPRE 8109 2011.01.18 Trojan.Win32.Generic.pak!cobra
ViRobot 2011.1.18.4261 2011.01.18 –
VirusBuster 13.6.151.0 2011.01.17 –
Additional informationShow all
MD5   : 1b1fb8c67da3f34036c26ffed2e631c8
SHA1  : 29c0b1c4b35be350389fc12b57740286db0ca98f

File size : 2412544 bytes
publisher….: It Systems
copyright….: (c) It Systems Corp. All rights reserved.
product……: SoftWare processes (c)
description..: Software processes
original name: scanner.exe
internal name: scanner

____________

A partir de las 19 horas de hoy, el ELISTARA 22.41 que los controla estará disponible en nuestra web.

saludos

ms, 18-1-2011

__________

NOTA: Los interesados en información sobre contrato de soporte Asistencia Tecnica de SATINFO y/o licencia de uso/actualizaciones de sus utilidades, contacten con info@satinfo.es
__________

Este blog no se hace responsable de las opiniones y comentarios de los textos en los que se cita la Fuente, ofreciendo su contenido solo para facilitar el acceso a la información del mismo.

Puedes seguir cualquier respuesta a esta entrada mediante el canal RSS 2.0. Los comentarios y los pings están cerrados.

Los comentarios están cerrados.

 

Uso de cookies

Este sitio web utiliza cookies para que usted tenga la mejor experiencia de usuario. Si continúa navegando está dando su consentimiento para la aceptación de las mencionadas cookies y la aceptación de nuestra política de cookies, pinche el enlace para mayor información.

ACEPTAR
Aviso de cookies