<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7583799459434033687</id><updated>2012-03-15T22:04:25.152-06:00</updated><category term='smart protection 2012 fakeav fake rogue trojan virus analysis removal tdsskiller zeroaccess roguekiller mgtools thisisu majorgeeks major geeks'/><category term='windows 8 consumer preview smart partner fakeav fake rogue trojan virus analysis removal thisisu major geeks majorgeeks'/><category term='windows 7 internet 2012 security antispyware fakeav fake firewall broken will not start thisisu major geeks'/><category term='security shield 2011 fakeav fake rogue virus malware analysis removal thisisu majorgeeks major geeks'/><category term='zeroaccess 0access max++ sirefef rootkit iomega oak technologies inc trojan virus fake hitmanpro thisisu majorgeeks major geeks'/><category term='dorkbot zbot analysis removal worm virus thisisu'/><category term='windows telemetry center fakeav fake rogue trojan virus analysis removal thisisu majorgeeks major geeks'/><category term='tdl4     tdss     rootkit     alureon     tidserv     tdsserv thisisu'/><category term='Zentom System Guard fakeav rootkit runonce spawns thisisu'/><category term='vista security 2012 fakeav rogue analysis removal firewall thisisu majorgeeks major geeks'/><category term='zero access zeroaccess max++ sirefef rootkit analysis removal malware zaccess 0access trojan virus major geeks majorgeeks thisisu'/><category term='kaspersky rescue 10 disk disc tutorial guide thisisu major geeks majorgeeks'/><category term='ZeroAccess zero access 0access rootkit oak technology inc fake thisisu major geeks majorgeeks'/><category term='system fix fakeav fake rogue trojan virus malware removal analysis thisisu majorgeeks major geeks'/><category term='xp antispyware 2012 fake fakeav rogue trojan analysis removal rootkit zeroaccess max++ sirefef  pihar tdlfs majorgeeks major geeks thisisu'/><category term='panda security zero access zeroaccess 0access rootkit yorkyt netsvcs iomega oak technologies abnow redirect virus thisisu majorgeeks major geeks'/><category term='internet defender fakeav fake rogue trojan malware analysis removal thisisu major geeks majorgeeks'/><category term='zero access rootkit zaccess sirefef max++'/><category term='privacy protection fake av rogue fakeav analysis removal zeroaccess sirefef max++ rootkit thisisu'/><category term='tdl4 alureon tdss bootkit rootkit partition mbr thisisu major geeks majorgeeks'/><category term='system restore fakeav rogue analysis removal fakehdd virus rootkit thisisu'/><category term='security scanner 2012 fakeav fake rogue trojan virus analysis removal thisisu majorgeeks major geeks'/><category term='system restore fakeav rogue analysis removal fakehdd fake thisisu virus'/><category term='win7 antispyware 2012 fakeav rogue analysis removal firewall thisisu majorgeeks major geeks'/><category term='ecops ransom virus trojan thisisu majorgeeks major geeks'/><category term='protection center fakeav rogue tdss fake thisisu'/><category term='internet security fake rogue fakeav trojan virus isecurity thisisu majorgeeks major geeks'/><category term='zero access rootkit zaccess sirefef max++ thisisu'/><category term='security sphere 2012 remove fakeav fake virus rogue thisisu'/><category term='system security 2011 fakeav rogue fake virus rogue thisisu'/><category term='windows functionality checker fakeav rogue trojan virus zeroaccess 0access zaccess max++ sirefef rootkit thisisu major geeks majorgeeks'/><category term='smart fortress 2012 fakeav fake rogue trojan virus analysis removal malware thisisu majorgeeks major geeks'/><category term='thisisu security antivirus fakeav fake virus rogue buy'/><category term='security monitor 2012 fakeav fake rogue trojan virus malware analysis removal thisisu majorgeeks major geeks'/><category term='best virus protection fakeav fake rogue virus trojan fakevime rloader removal analysis thisisu major geeks majorgeeks'/><category term='system check rloader fake av fake rogue fakehdd trojan zbot parasite majorgeeks major geeks thisisu'/><title type='text'>Malware Analysis and Removal</title><subtitle type='html'>Blog by Thisisu @ MajorGeeks.com</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>37</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-5856185121620070452</id><published>2012-03-15T18:29:00.012-06:00</published><updated>2012-03-15T22:04:25.164-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='panda security zero access zeroaccess 0access rootkit yorkyt netsvcs iomega oak technologies abnow redirect virus thisisu majorgeeks major geeks'/><title type='text'>Panda Security Creates ZeroAccess Cleaning Tool (Yorkyt.exe) - Removes Abnow Redirect</title><summary type='text'>Panda Security has created an AntiZeroAccess tool that works very well compared to others I have tested in the past.

In fact, it practically removed every trace of ZeroAccess minus 2-3 dormant files. What really impressed me was that it was able to delete the heart of ZeroAccess, the $NtUninstallKBXXXXX$ folder.

I am posting my results from the scans and information I was able to gather.
I used</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/5856185121620070452/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/03/panda-security-creates-zeroaccess.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/5856185121620070452'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/5856185121620070452'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/03/panda-security-creates-zeroaccess.html' title='Panda Security Creates ZeroAccess Cleaning Tool (Yorkyt.exe) - Removes Abnow Redirect'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-tIifQjBkIJk/T2J3hcUHfiI/AAAAAAAAAR0/ABhb3ygt5MQ/s72-c/panda_yorkty_icon.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-5704330890318110666</id><published>2012-03-08T20:48:00.003-06:00</published><updated>2012-03-13T01:09:36.539-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='best virus protection fakeav fake rogue virus trojan fakevime rloader removal analysis thisisu major geeks majorgeeks'/><title type='text'>Best Virus Protection (FakeAV) bundled with RLoader (Rootkit) - 03.08.2012 - Analysis and Removal</title><summary type='text'>This was performed on a virtual machine.  __________________________________________________________________________________
Looks similar to Microsoft Security Essentials, a legitimate antivirus.

It is not very aggressive.

Here is one of the alerts to the right:

 __________________________________________________________________________________


RogueKiller





¤¤¤ Bad processes: 1 ¤¤¤
[</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/5704330890318110666/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/03/best-virus-protection-fakeav-bundled.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/5704330890318110666'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/5704330890318110666'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/03/best-virus-protection-fakeav-bundled.html' title='Best Virus Protection (FakeAV) bundled with RLoader (Rootkit) - 03.08.2012 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-mqRvIe084yU/T1loKW26h8I/AAAAAAAAAQ0/KBcICGiT3zY/s72-c/bvp-maingui.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-6691862363814974781</id><published>2012-03-06T03:45:00.004-06:00</published><updated>2012-03-06T22:51:42.762-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='zeroaccess 0access max++ sirefef rootkit iomega oak technologies inc trojan virus fake hitmanpro thisisu majorgeeks major geeks'/><title type='text'>ZeroAccess Authors Are Now Faking Company Name: Iomega</title><summary type='text'>





In a previous post I mentioned that ZeroAccess authors were faking the Company name: Oak Technologies Inc. Well, they have changed who they want to disguise their malicious .dll files to the company Iomega. Oak Technologies Inc. will still be used but be prepared to start looking out for files with the company name Iomega as well.
____________________________________________________________</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/6691862363814974781/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/03/zeroaccess-authors-are-now-faking.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/6691862363814974781'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/6691862363814974781'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/03/zeroaccess-authors-are-now-faking.html' title='ZeroAccess Authors Are Now Faking Company Name: Iomega'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-6Ma9IrlNPjs/T1XL4LH-C6I/AAAAAAAAAP8/K8hl_oM-7qA/s72-c/za7.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-6904704828749597233</id><published>2012-03-03T19:16:00.011-06:00</published><updated>2012-03-03T23:12:16.899-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='windows 8 consumer preview smart partner fakeav fake rogue trojan virus analysis removal thisisu major geeks majorgeeks'/><title type='text'>Windows 8 Consumer Preview - Windows Smart Partner (FakeAV) - 03.03.2012 - Analysis and Removal</title><summary type='text'>This is the new Metro UI in Windows 8
I figured I should start experimenting with Windows 8. What better way to learn Windows 8 than infecting the OS with a Fake Antivirus and then removing it? :-D
I did disable Windows Defender before I was able to get infected. Windows Defender was actually blocking my previous attempts to get infected :-) So far I am impressed with the new Windows Defender </summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/6904704828749597233/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/03/windows-8-consumer-preview-windows.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/6904704828749597233'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/6904704828749597233'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/03/windows-8-consumer-preview-windows.html' title='Windows 8 Consumer Preview - Windows Smart Partner (FakeAV) - 03.03.2012 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-M2YAyUa1EEI/T1K2e-sJvUI/AAAAAAAAAPg/MZAagRiVMHQ/s72-c/windows_smart_partner_metroui.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-3845025711067554073</id><published>2012-02-29T18:00:00.000-06:00</published><updated>2012-02-29T18:00:24.079-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smart fortress 2012 fakeav fake rogue trojan virus analysis removal malware thisisu majorgeeks major geeks'/><title type='text'>Smart Fortress 2012 (FakeAV) - 02.29.2012 - Analysis and Removal</title><summary type='text'>This was performed on a virtual machine __________________________________________________________________________________
 Smart Fortress 2012 is an improvement of Smart Protection 2012.

You may have a difficult time getting Windows Explorer (explorer.exe) to launch if you start out in Normal Mode after a reboot.

I started my removal from Safe Mode because of this.
 ___________________________</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/3845025711067554073/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/02/smart-fortress-2012-fakeav-02292012.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/3845025711067554073'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/3845025711067554073'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/02/smart-fortress-2012-fakeav-02292012.html' title='Smart Fortress 2012 (FakeAV) - 02.29.2012 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-jBPoZnOYYGw/T065EcWyvaI/AAAAAAAAAOg/QUqoJYBQp1o/s72-c/smart_fortress_2012_gui.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-21329502583019508</id><published>2012-02-26T03:56:00.004-06:00</published><updated>2012-02-26T18:21:20.062-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='windows telemetry center fakeav fake rogue trojan virus analysis removal thisisu majorgeeks major geeks'/><title type='text'>Windows Telemetry Center (FakeAV) - 02.26.2012 - Analysis and Removal</title><summary type='text'> This was performed on a virtual machine  __________________________________________________________________________________ 
Same family as Windows Functionality Checker and Security Antivirus.

It was basically exactly the same as Windows Functionality Checker. Even the number of bad registry entries at KEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\currentversion\image file execution options </summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/21329502583019508/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/02/windows-telemetry-center-fakeav.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/21329502583019508'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/21329502583019508'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/02/windows-telemetry-center-fakeav.html' title='Windows Telemetry Center (FakeAV) - 02.26.2012 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-hJTf4ACRi_M/T0n7DwZmp_I/AAAAAAAAAOI/wVCkWOF_DRg/s72-c/telemetry_center_gui.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-6744661072525805782</id><published>2012-02-25T01:53:00.001-06:00</published><updated>2012-02-26T04:05:13.208-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ecops ransom virus trojan thisisu majorgeeks major geeks'/><title type='text'>Ecops (Ransom Trojan) - 02.25.2012 - Analysis and Removal</title><summary type='text'>This was performed on a virtual machine

This is a trojan that infects the following files: C:\Windows\explorer.exe 
C:\Windows\system32\dllcache\explorer.exe

 
The Company Name of both explorer.exe files was: Belkin Corporation
The MD5 hash value of both explorer.exe files was: cc3031638f4aef9c8d4062bb3103140b  (VT)

This trojan prevents you from doing anything in both Safe Mode and Normal Mode</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/6744661072525805782/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/02/ecops-ransom-trojan-02252012-analysis.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/6744661072525805782'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/6744661072525805782'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/02/ecops-ransom-trojan-02252012-analysis.html' title='Ecops (Ransom Trojan) - 02.25.2012 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-d2tkom26nec/T0iIchGSJkI/AAAAAAAAANw/KEEE6LlYYbE/s72-c/ransom-ecops.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-224663931608714487</id><published>2012-02-23T16:19:00.012-06:00</published><updated>2012-02-26T18:21:54.091-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='windows functionality checker fakeav rogue trojan virus zeroaccess 0access zaccess max++ sirefef rootkit thisisu major geeks majorgeeks'/><title type='text'>Windows Functionality Checker (FakeAV) bundled with ZeroAccess (Rootkit) - 02.23.2012 - Analysis and Removal</title><summary type='text'> This was performed on a virtual machine __________________________________________________________________________________ 
Looks very similar to Security Antivirus. It definitely packs more of a punch though and I'm not just referring to the ZeroAccess rootkit that was bundled in the sample I ran.

Instead of modifying the hosts file, it creates hundreds (700+) of bad entries in this key: </summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/224663931608714487/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/02/windows-functionality-checker-fakeav.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/224663931608714487'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/224663931608714487'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/02/windows-functionality-checker-fakeav.html' title='Windows Functionality Checker (FakeAV) bundled with ZeroAccess (Rootkit) - 02.23.2012 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-xtP5x9GCZ3Q/T0atqaITiKI/AAAAAAAAANQ/Mbh89-N2GYY/s72-c/windows_functionality_checker_gui.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-6791463807896826711</id><published>2012-02-23T03:13:00.004-06:00</published><updated>2012-03-04T01:45:04.393-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security scanner 2012 fakeav fake rogue trojan virus analysis removal thisisu majorgeeks major geeks'/><title type='text'>Security Scanner 2012 (FakeAV) - 02.23.2012 - Analysis and Removal</title><summary type='text'>This was performed on a virtual machine__________________________________________________________________________________Much like Security Shield 2011, upon first injection, you will be notified that the "&lt;Name of Fake AV&gt; has been installed successfully!".
Does not matter if you press X or OK, you are already infected and the Fake AV will start automatically "scanning" your system._____________</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/6791463807896826711/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/02/security-scanner-2012-fakeav-02232012.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/6791463807896826711'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/6791463807896826711'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/02/security-scanner-2012-fakeav-02232012.html' title='Security Scanner 2012 (FakeAV) - 02.23.2012 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-nYQUyU8o35A/T0X-0I-YAzI/AAAAAAAAAMY/pbUoK1W7OUE/s72-c/security_scanner_gui.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-8941345405015912162</id><published>2012-02-23T02:28:00.005-06:00</published><updated>2012-02-26T03:59:50.554-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='internet security fake rogue fakeav trojan virus isecurity thisisu majorgeeks major geeks'/><title type='text'>Internet Security (FakeAV) - 02.23.2012 - Analysis and Removal</title><summary type='text'> This was performed on a virtual machine__________________________________________________________________________________
This one is very similar to Privacy Protection.
This entire infection, minus any potential bundled rootkits is all tied into a single bad .exe (isecurity.exe) in the %allusersprofile% directory.
_________________________________________________________________________________</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/8941345405015912162/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/02/internet-security-fakeav-02232012.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/8941345405015912162'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/8941345405015912162'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/02/internet-security-fakeav-02232012.html' title='Internet Security (FakeAV) - 02.23.2012 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-PB8CLfYxM08/T0XyTKB7pdI/AAAAAAAAAMA/2zUNMLnf8c0/s72-c/internet_security_gui.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-2436017741955978245</id><published>2012-02-18T15:52:00.007-06:00</published><updated>2012-02-19T14:39:41.772-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ZeroAccess zero access 0access rootkit oak technology inc fake thisisu major geeks majorgeeks'/><title type='text'>ZeroAccess Authors Are Now Faking Company Name: Oak Technology Inc.</title><summary type='text'>First, I should mention that, Oak Technology Inc is a legitimate company that designs, develops, and markets high-performance multimedia  semiconductors and related software to original equipment manufacturers  worldwide who serve the multimedia PC, digital video consumer  electronics, and digital office equipment markets. For more information, read here: Wiki

Similar to how many malware authors</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/2436017741955978245/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/02/zeroaccess-authors-are-now-faking.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/2436017741955978245'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/2436017741955978245'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/02/zeroaccess-authors-are-now-faking.html' title='ZeroAccess Authors Are Now Faking Company Name: Oak Technology Inc.'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-3253246090485464973</id><published>2012-02-11T14:10:00.001-06:00</published><updated>2012-02-11T15:36:03.259-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='zero access zeroaccess max++ sirefef rootkit analysis removal malware zaccess 0access trojan virus major geeks majorgeeks thisisu'/><title type='text'>Max++ / Sirefef / ZeroAccess Rootkit Analysis and Full Removal Procedure by Thisisu - Volume IV</title><summary type='text'>Hello,

Yesterday when I was only looking for FakeAVs to analyze, I ended up getting a surprise which was a ZeroAccess rootkit. After months of purposely trying to infect a virtual machine with this rootkit (so I didn't have to keep infecting my own live computer with it for analysis purposes), I had pretty much convinced myself that every ZeroAccess dropper had some sort of anti "VMdetect" code </summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/3253246090485464973/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/02/max-sirefef-zeroaccess-rootkit-analysis.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/3253246090485464973'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/3253246090485464973'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/02/max-sirefef-zeroaccess-rootkit-analysis.html' title='Max++ / Sirefef / ZeroAccess Rootkit Analysis and Full Removal Procedure by Thisisu - Volume IV'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-7531339794988420720</id><published>2012-02-09T02:08:00.003-06:00</published><updated>2012-02-26T04:00:07.177-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security monitor 2012 fakeav fake rogue trojan virus malware analysis removal thisisu majorgeeks major geeks'/><title type='text'>Security Monitor 2012 (FakeAV) - 02.09.2012 - Analysis and Removal</title><summary type='text'> This was performed on a virtual machine__________________________________________________________________________________ 

MBAM

Registry Keys Detected: 1HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Security Monitor 2012 (Trojan.FakeAlert) -&gt; Quarantined and deleted successfully.

Registry Values Detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|jo50nluvu7bb (</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/7531339794988420720/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/02/security-monitor-2012-fakeav-02092012.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/7531339794988420720'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/7531339794988420720'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/02/security-monitor-2012-fakeav-02092012.html' title='Security Monitor 2012 (FakeAV) - 02.09.2012 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-9bPMbMCEERY/TzN5PyWMSOI/AAAAAAAAALg/H5AtiOsCoIg/s72-c/sm2012_main.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-1701394192747483812</id><published>2012-02-08T13:03:00.008-06:00</published><updated>2012-02-26T04:00:22.289-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smart protection 2012 fakeav fake rogue trojan virus analysis removal tdsskiller zeroaccess roguekiller mgtools thisisu majorgeeks major geeks'/><title type='text'>Smart Protection 2012 (FakeAV) - 02.08.2012 - Analysis and Removal</title><summary type='text'>This was performed on a virtual machine

I found this one very similar to Security Sphere 2012. Full report with video here. Upon infection, the screen above appears and starts to "scan" your system automatically. Whenever the "scan" is finished, the screenshot to the right will appear. These are all fake notices that your PC is infected as Smart Protection 2012 is not legitimate to begin with.A </summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/1701394192747483812/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/02/smart-protection-2012-fakeav-02082012.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/1701394192747483812'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/1701394192747483812'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/02/smart-protection-2012-fakeav-02082012.html' title='Smart Protection 2012 (FakeAV) - 02.08.2012 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-NkRdTnyea4w/TzK9muP5blI/AAAAAAAAALA/am1P6_d1Y0A/s72-c/smartprotection2012.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-113407517541372421</id><published>2012-02-05T03:47:00.002-06:00</published><updated>2012-02-26T04:00:34.696-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='internet defender fakeav fake rogue trojan malware analysis removal thisisu major geeks majorgeeks'/><title type='text'>Internet Defender (FakeAV) - 02.05.2012 - Analysis and Removal</title><summary type='text'>This was performed on a virtual machine

Here is what you may receive before actually getting infected. A warning message similar to the following:
Pressing OK prompts you download and run a suspicious .exe file. In my case it was "SETUP_SECURITY_DEFENDER_704[1].EXE". This is your last chance to avoid getting infected.


 If you choose OK, Internet Defender starts scanning your PC and falsely </summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/113407517541372421/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/02/internet-defender-fakeav-02052012.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/113407517541372421'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/113407517541372421'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/02/internet-defender-fakeav-02052012.html' title='Internet Defender (FakeAV) - 02.05.2012 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-pqyypKPHHtQ/Ty5Iskw0x8I/AAAAAAAAAKw/et98dJZTNVs/s72-c/id-scanning.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-3129767854566710358</id><published>2012-01-20T20:38:00.001-06:00</published><updated>2012-02-26T04:00:55.184-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='xp antispyware 2012 fake fakeav rogue trojan analysis removal rootkit zeroaccess max++ sirefef  pihar tdlfs majorgeeks major geeks thisisu'/><title type='text'>XP Antispyware 2012 (FakeAV) - 01.20.2012 - Analysis and Removal</title><summary type='text'>This was performed on a live (not Virtual) machine.
Important to note that this particular machine came with two different FakeAVs: XP Antispyware 2012 and System Check which I've covered earlier here.__________________________________________________________________________________

RogueKiller






¤¤¤ Bad processes: 4 ¤¤¤
[WINDOW : System Check] aG6mmkUgRr179B.exe -- C:\Documents and Settings</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/3129767854566710358/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/01/xp-antispyware-2012-fakeav-01202012.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/3129767854566710358'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/3129767854566710358'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/01/xp-antispyware-2012-fakeav-01202012.html' title='XP Antispyware 2012 (FakeAV) - 01.20.2012 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-9H12hToAeC0/Txoe-ns53fI/AAAAAAAAAKE/gskl7_zd1mc/s72-c/exp.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-1452980206760186252</id><published>2012-01-17T21:09:00.006-06:00</published><updated>2012-02-26T04:01:18.476-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='system check rloader fake av fake rogue fakehdd trojan zbot parasite majorgeeks major geeks thisisu'/><title type='text'>System Check (FakeAV) - 01.17.2012 - Analysis and Removal</title><summary type='text'> This was performed on a live (not Virtual) machine.
It's important to note that this particular computer was not booting properly when I first received it. Most likely it was due to the rootkit present (Virus.Win32.Rloader.a) and not the FakeAV as has been the case with other PCs with this type of infection.
After booting off a Windows 7 RE disc and performing a sfc /scannow while offline (sfc /</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/1452980206760186252/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/01/system-check-fakeav-01172012-analysis.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/1452980206760186252'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/1452980206760186252'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/01/system-check-fakeav-01172012-analysis.html' title='System Check (FakeAV) - 01.17.2012 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-9R8I8Prledk/TxYl7zwB6DI/AAAAAAAAAIw/qUzCbHxepJg/s72-c/systemcheckgui.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-836920372585542345</id><published>2012-01-10T20:08:00.005-06:00</published><updated>2012-02-26T04:01:43.074-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vista security 2012 fakeav rogue analysis removal firewall thisisu majorgeeks major geeks'/><title type='text'>Vista Security 2012 (FakeAV) - 01.10.2012 - Analysis and Removal</title><summary type='text'>
This was performed on a live (not Virtual) machine.

Here is what was loaded when I first turned on the computer in Normal Mode.  
Lots of pop-ups as you see, this one was a bit more aggressive than some of the others I've seen.
On top of it all I would get constant application errors regarding Norton Antivirus. ZeroAccess rootkit had a snack ;-)


Here is the screen you will be brought to if </summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/836920372585542345/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/01/vista-security-2012-fakeav-01102012.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/836920372585542345'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/836920372585542345'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/01/vista-security-2012-fakeav-01102012.html' title='Vista Security 2012 (FakeAV) - 01.10.2012 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-9mV4RMJ1fMk/TwznGgpu1uI/AAAAAAAAAIk/Fw5XtUe4YPs/s72-c/vistasecurity2012.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-285945345372657621</id><published>2012-01-08T04:23:00.001-06:00</published><updated>2012-01-08T04:44:52.771-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='kaspersky rescue 10 disk disc tutorial guide thisisu major geeks majorgeeks'/><title type='text'>How To: Use Kaspersky Rescue Disk To Scan and Remove Malware</title><summary type='text'>Kaspersky Rescue Disk 10 can be downloaded hereOnly to be used in extreme cases where normal malware methods are not working

You have to press any key on the keyboard in order to continue using the Kaspersky Rescue Disk.






Choose your language. English is the default selected language. Press Enter to make your selection.






Press Enter for "Graphic Mode".







Please be patient, </summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/285945345372657621/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/01/how-to-use-kaspersky-rescue-disk-to.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/285945345372657621'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/285945345372657621'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/01/how-to-use-kaspersky-rescue-disk-to.html' title='How To: Use Kaspersky Rescue Disk To Scan and Remove Malware'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-tYid9j-06BU/TwlqSJTzmyI/AAAAAAAAAF8/lmPWXIb0550/s72-c/krd10pressanykey.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-2799869179316085181</id><published>2012-01-08T03:09:00.008-06:00</published><updated>2012-01-08T04:43:06.598-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tdl4 alureon tdss bootkit rootkit partition mbr thisisu major geeks majorgeeks'/><title type='text'>How To: Use GParted To Remove Hidden TDL4 Partition</title><summary type='text'>
These are based on the original instructions I created for a user on November 17th 2011, when we first started seeing this types of infections on the Malware Removal forums at MajorGeeks.

For those that do not know about the latest TDL4 infections, more can be read at: TDL4 Infection Update Win32/Olmasco MAXSS Pihar

I have updated the tutorial guide for the latest stable version of GParted </summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/2799869179316085181/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/01/how-to-use-gparted-to-remove-hidden.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/2799869179316085181'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/2799869179316085181'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/01/how-to-use-gparted-to-remove-hidden.html' title='How To: Use GParted To Remove Hidden TDL4 Partition'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-ht9zPeFv9q8/TwlXOfkGedI/AAAAAAAAADg/zf4ZNpop0Io/s72-c/gparted_splash_0-11-07.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-489171577818821018</id><published>2012-01-06T20:05:00.002-06:00</published><updated>2012-02-26T04:02:24.217-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='win7 antispyware 2012 fakeav rogue analysis removal firewall thisisu majorgeeks major geeks'/><title type='text'>Win 7 Antispyware 2012 (FakeAV) - 01.06.2012 - Analysis and Removal</title><summary type='text'>
This was performed on a live (not Virtual) machine.
I just happened to open the Action Center and noticed the below screenshot which I thought was interesting, but probably not anything new.  



RogueKiller






¤¤¤ Bad processes: 1 ¤¤¤
[SUSP PATH] Smad.exe -- C:\Users\Steve\AppData\Local\SanctionedMedia\Smad\Smad.exe -&gt; KILLED [TermProc]

¤¤¤ Registry Entries: 17 ¤¤¤
[SUSP PATH] HKCU\[...]\</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/489171577818821018/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2012/01/win-7-antispyware-2012-fakeav-01062012.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/489171577818821018'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/489171577818821018'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2012/01/win-7-antispyware-2012-fakeav-01062012.html' title='Win 7 Antispyware 2012 (FakeAV) - 01.06.2012 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/--HllRmknO18/Twef7JzaSMI/AAAAAAAAADI/91A1UveRBI4/s72-c/win7antispyware.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-397415987589553477</id><published>2011-12-19T20:10:00.001-06:00</published><updated>2012-02-26T04:02:50.210-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='system fix fakeav fake rogue trojan virus malware removal analysis thisisu majorgeeks major geeks'/><title type='text'>System Fix (FakeAV) - 12.19.2011 - Analysis and Removal</title><summary type='text'>This was performed on a live (not Virtual) machine.



RogueKiller






¤¤¤ Registry Entries: 7 ¤¤¤
[SUSP PATH] HKLM\[...]\Run : VuCWtdJYrTTuTWk.exe (C:\Documents and Settings\All Users.WINDOWS\Application Data\VuCWtdJYrTTuTWk.exe) -&gt; DELETED
[HJPOL] HKLM\[...]\System : DisableTaskMgr (1) -&gt; DELETED
[HJ] HKCU\[...]\Internet Settings : WarnOnHTTPSToHTTPRedirect (0) -&gt; REPLACED (1)
[WallPP] HKCU\[</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/397415987589553477/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2011/12/system-fix-fakeav-12192011-analysis-and.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/397415987589553477'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/397415987589553477'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2011/12/system-fix-fakeav-12192011-analysis-and.html' title='System Fix (FakeAV) - 12.19.2011 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-LGTh-z4-xFc/Tu_oAUcLVXI/AAAAAAAAACk/g5ObMAmth1Q/s72-c/systemfix.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-88580715892056880</id><published>2011-12-17T19:38:00.001-06:00</published><updated>2012-02-26T04:03:04.507-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security shield 2011 fakeav fake rogue virus malware analysis removal thisisu majorgeeks major geeks'/><title type='text'>Security Shield 2011 (FakeAV) - 12.17.2011 - Analysis and Removal</title><summary type='text'>
This was performed on a live (not Virtual) machine.



RogueKiller






¤¤¤ Bad processes: 1 ¤¤¤
[SUSP PATH] uijultenx.exe -- C:\DOCUME~1\BFF093~1.MAU\LOCALS~1\APPLIC~1\uijultenx.exe -&gt; KILLED [TermProc] 

¤¤¤ Registry Entries: 3 ¤¤¤
[SUSP PATH] HKCU\[...]\Run : cdloader ("C:\Documents and Settings\B.F. Maupin\Application Data\mjusbsp\cdloader2.exe" MAGICJACK) -&gt; FOUND
[SUSP PATH] HKUS\S-1-5-21</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/88580715892056880/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2011/12/security-shield-2011-fake-av-12172011.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/88580715892056880'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/88580715892056880'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2011/12/security-shield-2011-fake-av-12172011.html' title='Security Shield 2011 (FakeAV) - 12.17.2011 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-VbytLXkv2Rc/Tu_vzz4gK7I/AAAAAAAAAC0/nWteZ_s9Ni8/s72-c/sas.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-5637545055700043261</id><published>2011-12-15T03:16:00.000-06:00</published><updated>2011-12-17T03:53:13.090-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='windows 7 internet 2012 security antispyware fakeav fake firewall broken will not start thisisu major geeks'/><title type='text'>Windows 7 Internet Security 2012 (FakeAV)  -- The Aftermath...</title><summary type='text'>This article also applies to Windows 7 AntiSpyware 2012


These particular FakeAVs aim to break the Windows 7 Firewall as well as attempting to scam you for your financial information -- and they are very successful.
Earlier this week at work,  I had the pleasure of working on a PC with this infection. I had known before hand that the Firewall would have been compromised; and it was.

First I </summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/5637545055700043261/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2011/12/windows-7-internet-security-2012-fakeav.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/5637545055700043261'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/5637545055700043261'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2011/12/windows-7-internet-security-2012-fakeav.html' title='Windows 7 Internet Security 2012 (FakeAV)  -- The Aftermath...'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-1852615972509227841</id><published>2011-11-19T00:49:00.000-06:00</published><updated>2011-12-15T20:34:56.769-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='protection center fakeav rogue tdss fake thisisu'/><title type='text'>Protection Center (FakeAV) - 11.19.2011 - Analysis and Removal</title><summary type='text'>
====notes====
First it messes with the .exe file association so that you won't be able to run programs.

There's .inf and .reg patches to fix this.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Protection Center
HKEY_CURRENT_USER\SOFTWARE\24d1ca9a-a864-4f7b-86fe-495eb56529d8
HKEY_CURRENT_USER\SOFTWARE\7bde84a2-f58f-46ec-9eac-f1f90fead080

Folders Infected:
c:\program files\protection </summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/1852615972509227841/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2011/11/protection-center-fakeav-11192011.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/1852615972509227841'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/1852615972509227841'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2011/11/protection-center-fakeav-11192011.html' title='Protection Center (FakeAV) - 11.19.2011 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-8191917293124631294</id><published>2011-11-12T01:32:00.000-06:00</published><updated>2011-12-15T20:34:40.678-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='system restore fakeav rogue analysis removal fakehdd virus rootkit thisisu'/><title type='text'>System Restore v1.1 (FakeAV) - 11.12.2011 - Analysis and Removal</title><summary type='text'>
====notes====
JGFMXz1Ipf65 and JGFMXz1Ipf65.exe in %CommonAppData%

"System Restore" entry in the start menu and an icon on the desktop.

Mostly likely will need to make use of TDSSKiller as appears it installs a TDLFS and Rookit.Boot.SST.b which causes browser redirects. 

====music====
Funf D - Counted</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/8191917293124631294/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2011/11/system-restore-v2-11122011-analysis-and.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/8191917293124631294'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/8191917293124631294'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2011/11/system-restore-v2-11122011-analysis-and.html' title='System Restore v1.1 (FakeAV) - 11.12.2011 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-5348313217158153199</id><published>2011-11-10T01:32:00.000-06:00</published><updated>2011-12-15T20:34:22.154-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='dorkbot zbot analysis removal worm virus thisisu'/><title type='text'>Dorkbot (Worm) - 11.10.2011 - Analysis and Removal</title><summary type='text'>
====notes====
Creates a heh.cmd file with the following commands:
ping -n 15 127.0.0.1
taskkill /f /im gagajeje.exe
taskkill /f /im marcia.exe
taskkill /f /im hula.exe
taskkill /f /im official27.exe
taskkill /f /im ev0ga.exe
ping -n 15 127.0.0.1
ev0ga.exe
Creates the following files in user's %appdata%:
13.exe, 14.exe, 15.exe, 16.tmp, 17.exe, Ahiaia.exe.

Creates "kakao2" folder in user %appdata</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/5348313217158153199/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2011/11/dorkbot-11102011-analysis-and-removal.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/5348313217158153199'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/5348313217158153199'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2011/11/dorkbot-11102011-analysis-and-removal.html' title='Dorkbot (Worm) - 11.10.2011 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-7470430611048877761</id><published>2011-11-04T23:47:00.000-06:00</published><updated>2011-12-15T20:34:05.588-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='privacy protection fake av rogue fakeav analysis removal zeroaccess sirefef max++ rootkit thisisu'/><title type='text'>Privacy Protection (FakeAV) - 11.05.2011 - Analysis and Removal</title><summary type='text'>
"Privacy Protection" is a fake AV in the same category as "Cloud Protection".

Most likely will come bundled with a newer variant of the Max++/Sirefef/ZeroAccess rootkit

Audio: Those Two Guys - 33 Rev (Blake Jarrell and Starkid Mix)</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/7470430611048877761/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2011/11/privacy-protection-11052011-analysis.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/7470430611048877761'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/7470430611048877761'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2011/11/privacy-protection-11052011-analysis.html' title='Privacy Protection (FakeAV) - 11.05.2011 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-1971585213894346379</id><published>2011-11-01T19:09:00.000-06:00</published><updated>2011-12-15T20:33:52.333-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='system security 2011 fakeav rogue fake virus rogue thisisu'/><title type='text'>System Security 2011 (FakeAV) - 11.01.2011 - Analysis and Removal</title><summary type='text'>
Performed on a Virtual Machine.</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/1971585213894346379/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2011/11/system-security-2011-11012011-analysis.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/1971585213894346379'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/1971585213894346379'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2011/11/system-security-2011-11012011-analysis.html' title='System Security 2011 (FakeAV) - 11.01.2011 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-6893664191403353705</id><published>2011-10-29T16:15:00.000-05:00</published><updated>2011-12-15T20:33:21.311-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tdl4     tdss     rootkit     alureon     tidserv     tdsserv thisisu'/><title type='text'>TDL4 (Rootkit) - 10.29.2011 - Analysis and Removal</title><summary type='text'>
TDL4</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/6893664191403353705/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2011/10/tdl4.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/6893664191403353705'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/6893664191403353705'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2011/10/tdl4.html' title='TDL4 (Rootkit) - 10.29.2011 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-1587873924619294595</id><published>2011-10-26T16:27:00.000-05:00</published><updated>2011-12-15T20:33:00.493-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='system restore fakeav rogue analysis removal fakehdd fake thisisu virus'/><title type='text'>System Restore (FakeAV) - 10.26.2011 - Analysis and Removal</title><summary type='text'>This was performed on a Virtual Machine.
The infection places the hidden attribute on the entire OS drive.</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/1587873924619294595/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2011/10/system-restore-10262011-analysis-and.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/1587873924619294595'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/1587873924619294595'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2011/10/system-restore-10262011-analysis-and.html' title='System Restore (FakeAV) - 10.26.2011 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-3538620051198446471</id><published>2011-10-23T19:32:00.001-05:00</published><updated>2011-12-15T20:31:04.468-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='thisisu security antivirus fakeav fake virus rogue buy'/><title type='text'>Security AntiVirus (FakeAV) - 10.22.2011 - Analysis and Removal</title><summary type='text'>
This was performed on a Virtual Machine.

Modifies host file

Some obvious traces missed by MBAM shown.</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/3538620051198446471/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2011/10/security-antivirus-10222011-analysis.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/3538620051198446471'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/3538620051198446471'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2011/10/security-antivirus-10222011-analysis.html' title='Security AntiVirus (FakeAV) - 10.22.2011 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-1405725759361585929</id><published>2011-10-23T19:31:00.001-05:00</published><updated>2011-12-15T20:32:30.438-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security sphere 2012 remove fakeav fake virus rogue thisisu'/><title type='text'>Security Sphere 2012 (FakeAV) - 10.22.2011 - Analysis and Removal</title><summary type='text'>
This was performed on a Virtual Machine.</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/1405725759361585929/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2011/10/security-sphere-2012-10222011-analysis.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/1405725759361585929'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/1405725759361585929'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2011/10/security-sphere-2012-10222011-analysis.html' title='Security Sphere 2012 (FakeAV) - 10.22.2011 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-7607636154285745621</id><published>2011-10-23T19:30:00.000-05:00</published><updated>2011-12-15T20:32:13.412-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Zentom System Guard fakeav rootkit runonce spawns thisisu'/><title type='text'>Zentom System Guard (FakeAV) - 10.20.2011 - Analysis and Removal</title><summary type='text'>
This was done on a Virtual Machine on 10.20.2011

Possibly included a ZeroAccess driver if it were not for me being on a VM.

Did not find the random RunOnce registry .exe spawns like I wanted to analyze.</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/7607636154285745621/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2011/10/zentom-system-guard-10202011-analysis.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/7607636154285745621'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/7607636154285745621'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2011/10/zentom-system-guard-10202011-analysis.html' title='Zentom System Guard (FakeAV) - 10.20.2011 - Analysis and Removal'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-683777504390047732</id><published>2011-10-23T19:29:00.000-05:00</published><updated>2011-12-15T20:28:56.180-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='zero access rootkit zaccess sirefef max++'/><title type='text'>Max++/Sirefef/ZeroAccess Rootkit Analysis . Volume III</title><summary type='text'>
Testing ESET's removal tool for this infection. Results shown.</summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/683777504390047732/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2011/10/maxsirefefzeroaccess-rootkit-analysis_157.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/683777504390047732'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/683777504390047732'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2011/10/maxsirefefzeroaccess-rootkit-analysis_157.html' title='Max++/Sirefef/ZeroAccess Rootkit Analysis . Volume III'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-7325765622454115413</id><published>2011-10-23T19:27:00.000-05:00</published><updated>2011-12-15T20:31:49.954-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='zero access rootkit zaccess sirefef max++ thisisu'/><title type='text'>Max++/Sirefef/ZeroAccess Rootkit Analysis . Volume II</title><summary type='text'></summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/7325765622454115413/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2011/10/maxsirefefzeroaccess-rootkit-analysis_23.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/7325765622454115413'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/7325765622454115413'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2011/10/maxsirefefzeroaccess-rootkit-analysis_23.html' title='Max++/Sirefef/ZeroAccess Rootkit Analysis . Volume II'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7583799459434033687.post-2662069772863206969</id><published>2011-10-23T19:26:00.000-05:00</published><updated>2011-12-15T20:31:19.129-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='zero access rootkit zaccess sirefef max++ thisisu'/><title type='text'>Max++/Sirefef/ZeroAccess Rootkit Analysis</title><summary type='text'> 
September 2011 max++/sirefef/zaccess sample used.
ComboFix did  warn that TCP/IP was infected as well but I didn't capture that footage  unfortunately. The video program I was using must have closed. The same  happened when I was testing RKill and RogueKiller. Both were  unsuccessful.

Prior to removing any components of infection, here are the results of various tools:

webroot's antiza tool  </summary><link rel='replies' type='application/atom+xml' href='http://thisisudax.blogspot.com/feeds/2662069772863206969/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thisisudax.blogspot.com/2011/10/maxsirefefzeroaccess-rootkit-analysis.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/2662069772863206969'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7583799459434033687/posts/default/2662069772863206969'/><link rel='alternate' type='text/html' href='http://thisisudax.blogspot.com/2011/10/maxsirefefzeroaccess-rootkit-analysis.html' title='Max++/Sirefef/ZeroAccess Rootkit Analysis'/><author><name>thisisu</name><uri>http://www.blogger.com/profile/17580873341825818871</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://3.bp.blogspot.com/-ddln36CmN6k/Tu1X5594_0I/AAAAAAAAAB4/TVYPEPP_6F8/s220/ab.jpg'/></author><thr:total>0</thr:total></entry></feed>
