Author Topic: Rogue AntiVirus Attempt (Please Read)  (Read 4916 times)

Ok while browsing on Google I stumbled opon a page with a Disquised website adress. And you may have already guess it and you're mabey right, I CLICKED IT.
It brought me a so called "Security brown townysis". This makes the user think that the system is infected with Malware. Ontop it says "To fix these programs download our Antivirus to fix you're computer." (something like that.).
Here is the picture of the attempt. (Please read all labels to understand the compramized enviroment.)

Thay do try to make the user think that the computer is infected by using the most common Windows border. Thus making the user think that there computer's security has found some viruses.

When you think you are smart enough to navigate out of the page....You're still not smart at all. Either way you are getting a virus if you press ANY button (This includes the 'X' on the top right of the window). (Please read all labels to understand the compramized enviroment.)

Basicly the webpage wont take a "No" for an answer. The only way from getting away from this page is to open up you're task manager (CTRL + ALT + DELETE). Then press "Start Task Manager" then click what looks like the Rogue Antivirus Page then press "End Task". I suggest closing all iexplorer windows due to it may have sent you more pages than 1.

Over all I got 4 "Packed.win32.krap.an" (Trojan Virus) from studying the page. I had to blank the URL Adress to prevent dumbasses from copying the link into there URL and getting a Virus and getting me in trouble. I also censored some blanks because its personal info.

Here is a picture made by Symantech of the Program:


Rogue Name: SecurityToolFraud -Symantech
Made in: China
« Last Edit: June 11, 2010, 03:02:53 PM by Tyler66 »

Internet Explorer.
Your problem.

Internet Explorer.
Your problem.
You get these anyhow. This is no pop-up.

You get these anyhow. This is no pop-up.
Firefox is more secure and less likey for this to come up.
DL malwarebytes', rename the exacutable and run it.

Firefox is more secure and less likey for this to come up.
DL malwarebytes', rename the exacutable and run it.
I already downloaded MalwareBytes on my computer. Its broken and I do not know why.

I already downloaded MalwareBytes on my computer. Its broken and I do not know why.
The virus probably screwed it up.

Boot into safe mode with networking, then reinstall it.

The virus probably screwed it up.

Boot into safe mode with networking, then reinstall it.
The program was screwed up before the Rogue Attempt, Way back. I have not reinstalled it yet due to the lack of intrest.

Also, I found the Rogue AntiVirus name. It is shown in OP.


you went extremely batstuff crazy with all the tools in MSPaint

also you spelled "compromised" wrong lol

OH GOD THE TOOLBARS
That's why I use chrome. C:

Ontopic: I'm sure a total starfish made that page. I don't even know why people make viruses, all that proves is that they're a complete douchebag.

tl;dr: only dush pussie lickers mak viruses

Download spybot search and destroy.
Immunize
No longer get these.

Updated with picture.
Also, you people stop telling me what kind of Antivirus to Download, Im happy with what I have.

URL = research.
Toolbar = research editing.
Favorites = research websites.

Spybot is not a anti virus program.

It's immunize adds ip/url's to places like this into your hosts file and redirects them to your ip
« Last Edit: June 11, 2010, 03:08:31 PM by tails »

URL = research.
Toolbar = research editing.
Favorites = research websites.
SDAF

Spybot is not a anti virus program.
That makes me less interested to even download it.