Infected website, download fake AV for testing. Safe?

Neverhavemoney

Registered Nurse
Pro User
VIP
Local time
2:54 PM
Messages
214
Location
Rhode Island
Hey guys,
I finally got a pop-up ive been wanting for a few months now. It is one of those fake virus scanning websites trying to run a fake scan (just a .gif picture) and it tells me to download their AV.
Ya let me get right to that! REALLY!
I want to download, not install to my main computer, but just download the installation files to transfer to my old sandbox comptuer. This will be my first attemt at this, and i just wanted peoples input on what you think of this?

Am i alright to download this? A second opinion never hurts. Cant know everything. Damn :( hard pill to swollow haha!:roflmao:

Thanks everyone,
Ben
 

My Computer My Computer

At a glance

Windows 7 Ultimate Professional x64Intel Core i7-740QM @ 1.73GHz 4Core2 X 4GB DDR3-SDRAM 667MHzATI Mobility Radeon HD 5870 1GB SDRAM
Computer type
Laptop
Computer Manufacturer/Model Number
Clevo W870CU
OS
Windows 7 Ultimate Professional x64
CPU
Intel Core i7-740QM @ 1.73GHz 4Core
Motherboard
Intel PM55
Memory
2 X 4GB DDR3-SDRAM 667MHz
Graphics Card(s)
ATI Mobility Radeon HD 5870 1GB SDRAM
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
AUO149D 17.1" HD+/FHD @600Hz
Screen Resolution
1920X1080
Hard Drives
Seagate A0D-10F4 - 500 GB @7200RPM
PSU
43290mWh Intel Lithium-Ion Battery
Case
Cleveo W870CU
Cooling
2 Fans
Keyboard
Microsoft eHome MCIR 109
Mouse
Finger Sensing HID-Compliant Mouse Pad
Internet Speed
100 MB/s
Antivirus
avast! Antivirus
Browser
Google Chrome
Other Info
Biometric Enabled
2.0MP Cam
Well, if you're going to let it run its course to see what it does, make sure that the computer is completely isolated with ZERO and I mean ZERO information on it.

Also, keep in mind that not only can this sort of thing mess with your software, but in rare cases it can kill hardware if it's really horrid.
 

My Computer My Computer

At a glance

W7 Ult. x64 | OS XIntel Mobile Core 2 Duo 2.93Ghz [T9800 Penryn]4096MB Samsung DDR3 Dual Channel [PC3-8500F 1...NVIDIA GeForce 9600M GT 512MB [G96M Rev. C1]
Computer Manufacturer/Model Number
Apple Macbook Pro (April 2009)
OS
W7 Ult. x64 | OS X
CPU
Intel Mobile Core 2 Duo 2.93Ghz [T9800 Penryn]
Motherboard
NVIDIA nForce 730i Rev. B1 [Mac-F2268EC8 (U2E1)]
Memory
4096MB Samsung DDR3 Dual Channel [PC3-8500F 1066Mhz]
Graphics Card(s)
NVIDIA GeForce 9600M GT 512MB [G96M Rev. C1]
Sound Card
SB X-Fi Surround 5.1 USB | Onboard Realtek (Disabled)
Monitor(s) Displays
Acer x223wbd 22" | Apple Anti-Glare 17" (Disabled)
Screen Resolution
{Current} 1440x900 {Acer} 1680x1050 {Apple} 1920x1200
Hard Drives
{Internal}
Seagate Momentus 320GB 2.5" 7200RPM [ST9320421AS]

{Externals}
LaCie 320GB USB 2.0 HDD [301284UR]
LaCie 750GB USB 2.0 FW400 eSATA HDD [301314U]
LaCie 1TB USB 2.0 HDD [301304UR]
PSU
Magsafe
Case
Aluminum/Unibody (MBP52)
Cooling
2 x 6000 RPM Fans
Keyboard
Logitech G-15v2 [PN 920-000379]
Mouse
Logitech G-9 [PN 910-000338]
Internet Speed
12Mbps/2.5Mbps w/ 24Mbps Speed Boost [Comcast]
Other Info
Logitech X-540 Speakers [PN 970223-0122]
Sennheiser PC-151 Headset
Just had to post here.. really want to watch the out come of this one... Too many dirty AV companies out there trying to take advantage of the little folk... GL :)
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64-bitPentium(R) Dual-Core T4300 @ 2.10GHz3 GB DDR2 PC2-6400 (400 MHz) Samsung M4 70T28...Mobile Intel GMA4500M 32bit OS (64bit OS) dyn...
Computer Manufacturer/Model Number
Toshiba Satellite
OS
Windows 7 Home Premium 64-bit
CPU
Pentium(R) Dual-Core T4300 @ 2.10GHz
Motherboard
Toshiba Model KSWAA - Chipset Intel GL40 Rev 07
Memory
3 GB DDR2 PC2-6400 (400 MHz) Samsung M4 70T2864Q23-CF7
Graphics Card(s)
Mobile Intel GMA4500M 32bit OS (64bit OS) dynamically
Sound Card
Realtek ALC272-GR Software Sound
Monitor(s) Displays
16.0" HD TFT with TrueBrite Matrix colour LCD display
Screen Resolution
1366 x 768
Hard Drives
FUJITSU MJA2320BH G2-(S2) 320GB (5400RPM) Serial-ATA
Keyboard
Canadian Bilingual Keyboard 105 keys with 13 Function keys
Mouse
Touchpad Point device & Lexma USB Mouse
Internet Speed
Walking is Faster
Other Info
Wireless LAN Realtek RTL89191SE 802.11n PCI-E NIC + a
LAN Realek PCIe FE Family Controller and
TOSHIBA Software Modem
I know polar, this is why i want to download it. I want to write up a full detailed article on what happens when you get infected like this, and also create a package to get rid of this nasty, information stealing hoax. I hate these things, and they keep coming out with new ones every year. It sucks.

O well. Thanks,
Ben

Just had to post here.. really want to watch the out come of this one... Too many dirty AV companies out there trying to take advantage of the little folk... GL :)
 

My Computer My Computer

At a glance

Windows 7 Ultimate Professional x64Intel Core i7-740QM @ 1.73GHz 4Core2 X 4GB DDR3-SDRAM 667MHzATI Mobility Radeon HD 5870 1GB SDRAM
Computer type
Laptop
Computer Manufacturer/Model Number
Clevo W870CU
OS
Windows 7 Ultimate Professional x64
CPU
Intel Core i7-740QM @ 1.73GHz 4Core
Motherboard
Intel PM55
Memory
2 X 4GB DDR3-SDRAM 667MHz
Graphics Card(s)
ATI Mobility Radeon HD 5870 1GB SDRAM
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
AUO149D 17.1" HD+/FHD @600Hz
Screen Resolution
1920X1080
Hard Drives
Seagate A0D-10F4 - 500 GB @7200RPM
PSU
43290mWh Intel Lithium-Ion Battery
Case
Cleveo W870CU
Cooling
2 Fans
Keyboard
Microsoft eHome MCIR 109
Mouse
Finger Sensing HID-Compliant Mouse Pad
Internet Speed
100 MB/s
Antivirus
avast! Antivirus
Browser
Google Chrome
Other Info
Biometric Enabled
2.0MP Cam
Well, each Fake AV is different and sometimes require different removal tools.

You could however start the thread with that one AV and then each time you find a new one, dl it and solve the process needed to remove it and post on how you solved it.

It would be good to have a general tutorial though on what to do if you get infected by fake AV. As far as first steps or tips and tricks to get the best results.
 

My Computer My Computer

At a glance

Win7 Home Premium 64xIntel Core 2 Duo P7450 / 2.13 GHz (2.29 with ...4 GB PC-6400 Hyundai (2X2) at 800MhzNVIDIA GeForce GTX 260M 1GB DDR3 VRAM
Computer type
Laptop
Computer Manufacturer/Model Number
ASUS G60-RBBX05
OS
Win7 Home Premium 64x
CPU
Intel Core 2 Duo P7450 / 2.13 GHz (2.29 with Extreme Turbo)
Memory
4 GB PC-6400 Hyundai (2X2) at 800Mhz
Graphics Card(s)
NVIDIA GeForce GTX 260M 1GB DDR3 VRAM
Monitor(s) Displays
16" LED Backlit
Screen Resolution
1366 x 768 on laptop 1600x1050 max res on 22" external mon
Hard Drives
OCZ Agility 3 60GB SSD / 320 GB - Serial ATA-150 - 7200 rpm
PSU
6-cell Lithium ion { lasts 1.5 hours }
Case
ASUS G60 Laptop
Keyboard
Chicklet type back-lit (white light) keyboard
Mouse
Logitech G9 Laser Mouse 3200dpi and 1000 reports per minute
Internet Speed
Comcast 8.60mb/s up - 3.11mb/s down
Antivirus
MSE
Browser
Firefox
Other Info
General mid-budget gaming Comp. Low batterylife - High FrameRates - currently overheating problems :(

2nd Rig: Case: Rosewill BLACKHAWK Gaming ATX Mid Tower Computer Case

Mobo: GIGABYTE GA-990FXA-UD3
CPU: AMD FX-6200 Zambezi 3.8GHz (4.1GHz Turbo)
Heatsink: COOLER MASTER V8 CPU Cooler
RAM: Patriot Viper 3 8GB (2 x 4GB) 240-Pin DDR3 SDRAM 1866 (PC3 15000)
GPU: SAPPHIRE Radeon HD 6850 1GB 2
I want to download, not install to my main computer, but just download the installation files to transfer to my old sandbox comptuer. This will be my first attemt at this, and i just wanted peoples input on what you think of this?

Ben

Hi, Ben.

Since you need to ask, I think you know my answer. No, I do not recommend it. Merely clicking the link will start the installation. That said, if this is something you are going to do anyway, I strongly advise that you have a really good backup of all your files and if you have a home network, disconnect other computers from the network. Although not 100% safe, you need to download with VM.

As to illustrating what happens, I believe SunbeltBLOG has posted videos of what happens and I'm sure others have as well.

You could however start the thread with that one AV and then each time you find a new one, dl it and solve the process needed to remove it and post on how you solved it.

No need to re-invent the wheel. Bleeping Computer does an excellent job of providing instructions: Virus, Spyware, & Malware Removal Guides
 

My Computer My Computer

At a glance

Windows 7 & Windows Vista Ultimate
OS
Windows 7 & Windows Vista Ultimate
Merely clicking the link starts the download of the setup.exe which then needs to be executed in order to start the installation.

If you want to go anywhere on the net and deliberately download malware then may I suggest you run your browser through Sandboxie and execute any downloads through Sandboxie as well.

Take a bit of time to learn Sandboxie's capabilities and I doubt you would ever surf without it again.

I also virtualize my system with Returnil (prefer older version) and also use virtual machines but I still have images as backups.
 

My Computer My Computer

At a glance

7
OS
7
I would recommend doing this (if you insist on doing it) in an isolated virtual environment with integration tools disabled. Make sure you install av/malware programs in that vm.
 

My Computer My Computer

At a glance

Windows 7 Professional 64-bitIntel E8400 3GHzKingston PC3-10700H 4GbXFX Radeon HD 5850 BlackEd.
Computer Manufacturer/Model Number
self built
OS
Windows 7 Professional 64-bit
CPU
Intel E8400 3GHz
Motherboard
Intel DX48BT2
Memory
Kingston PC3-10700H 4Gb
Graphics Card(s)
XFX Radeon HD 5850 BlackEd.
Sound Card
Asus Xonar DG
Monitor(s) Displays
2x Samsung SM-T220HD 22"
Screen Resolution
1680x1050 on two monitors
Hard Drives
OCZ Vertex 2 120gb 3.5" (OS)
Seagate Momentus XT 500gb
Samsung F3 1Tb (games)
2x Samsung F1 1Tb
PSU
Thermaltake ToughPower 850w
Case
Thermaltake Armor
Cooling
Scythe Mugen II
Keyboard
Microsoft Comfort Curve USB
Mouse
Razer Diamondback 3G
Internet Speed
8128/443
Jax,
I dont understand virtual computing. Care to go more into it? Im looking to do testing with this, because i understand that you can't become infected but i have no idea how. Can you explain what it does?

Thanks,
Ben

Merely clicking the link starts the download of the setup.exe which then needs to be executed in order to start the installation.

If you want to go anywhere on the net and deliberately download malware then may I suggest you run your browser through Sandboxie and execute any downloads through Sandboxie as well.

Take a bit of time to learn Sandboxie's capabilities and I doubt you would ever surf without it again.

I also virtualize my system with Returnil (prefer older version) and also use virtual machines but I still have images as backups.
 

My Computer My Computer

At a glance

Windows 7 Ultimate Professional x64Intel Core i7-740QM @ 1.73GHz 4Core2 X 4GB DDR3-SDRAM 667MHzATI Mobility Radeon HD 5870 1GB SDRAM
Computer type
Laptop
Computer Manufacturer/Model Number
Clevo W870CU
OS
Windows 7 Ultimate Professional x64
CPU
Intel Core i7-740QM @ 1.73GHz 4Core
Motherboard
Intel PM55
Memory
2 X 4GB DDR3-SDRAM 667MHz
Graphics Card(s)
ATI Mobility Radeon HD 5870 1GB SDRAM
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
AUO149D 17.1" HD+/FHD @600Hz
Screen Resolution
1920X1080
Hard Drives
Seagate A0D-10F4 - 500 GB @7200RPM
PSU
43290mWh Intel Lithium-Ion Battery
Case
Cleveo W870CU
Cooling
2 Fans
Keyboard
Microsoft eHome MCIR 109
Mouse
Finger Sensing HID-Compliant Mouse Pad
Internet Speed
100 MB/s
Antivirus
avast! Antivirus
Browser
Google Chrome
Other Info
Biometric Enabled
2.0MP Cam
Ben, I've had to cleanup several computers with these infections. My advice is don't play with them.

Ken
 

My Computer My Computer

At a glance

Win7 x64 Ultimate SP1Intel i7-26008 GigGeforce gt 520
Computer Manufacturer/Model Number
Dell Optiplex 980
OS
Win7 x64 Ultimate SP1
CPU
Intel i7-2600
Memory
8 Gig
Graphics Card(s)
Geforce gt 520
Monitor(s) Displays
LG & Acer
Screen Resolution
1920x1080
Internet Speed
Fios 45/35
Other Info
Windows Home Server
Jax,
I dont understand virtual computing. Care to go more into it? Im looking to do testing with this, because i understand that you can't become infected but i have no idea how. Can you explain what it does?
You certainly can get get infected using a virtual system but on reboot the system returns to exactly how it was before entering virtual mode.

There a few different aspects such as sandboxie which creates a confined secure workspace within the real system.

Returnil, Shadow Defender and Wondershare Time Freeze sort of create a copy of the entire system that all the work is done in and is gone at reboot.

And then you have snapshot apps which I haven't really used but I have heard good and bad things about them, mostly good though.

May be best if you tread lightly and have a read through a few topics on the subject over at Wilders.

Light virtualization: Returnil/PowerShadow/ShadowDefender/ShadowUser Pro - Wilders Security Forums

sandboxing & virtualization - Wilders Security Forums
 

My Computer My Computer

At a glance

7
OS
7
Im very knowledgeable with infections, and things like this. I was head of the Vistax64 Infection Resolving Team. It was a great group of people we had.

Ben, I've had to cleanup several computers with these infections. My advice is don't play with them.

Ken
 

My Computer My Computer

At a glance

Windows 7 Ultimate Professional x64Intel Core i7-740QM @ 1.73GHz 4Core2 X 4GB DDR3-SDRAM 667MHzATI Mobility Radeon HD 5870 1GB SDRAM
Computer type
Laptop
Computer Manufacturer/Model Number
Clevo W870CU
OS
Windows 7 Ultimate Professional x64
CPU
Intel Core i7-740QM @ 1.73GHz 4Core
Motherboard
Intel PM55
Memory
2 X 4GB DDR3-SDRAM 667MHz
Graphics Card(s)
ATI Mobility Radeon HD 5870 1GB SDRAM
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
AUO149D 17.1" HD+/FHD @600Hz
Screen Resolution
1920X1080
Hard Drives
Seagate A0D-10F4 - 500 GB @7200RPM
PSU
43290mWh Intel Lithium-Ion Battery
Case
Cleveo W870CU
Cooling
2 Fans
Keyboard
Microsoft eHome MCIR 109
Mouse
Finger Sensing HID-Compliant Mouse Pad
Internet Speed
100 MB/s
Antivirus
avast! Antivirus
Browser
Google Chrome
Other Info
Biometric Enabled
2.0MP Cam
The very fact that you had to ask this in a public forum makes me wonder about your "knowledge with infections" Like Corrine said, there are plent of "articles" and videos around on this. It's not as if you would your "report" would be a world first. My opinion: waste of time.
 

My Computer My Computer

At a glance

Windows 7 Ultimate (x64) SP1Intel 3770k 4.6GHz8GB (2x 4GB) Crucial BallistixSapphire 7950 (1060/1600)
Computer Manufacturer/Model Number
tw33k
OS
Windows 7 Ultimate (x64) SP1
CPU
Intel 3770k 4.6GHz
Motherboard
ASUS Maximus V Formula
Memory
8GB (2x 4GB) Crucial Ballistix
Graphics Card(s)
Sapphire 7950 (1060/1600)
Sound Card
On Board Realtek HD Audio
Monitor(s) Displays
27" Acer B273HU (via HDMI)
Screen Resolution
2048 x 1152
Hard Drives
Crucial M4 128GB
2TB WD Black
1TB Samsung F3 SATA
1TB WD Elite External
2TB WD USB 3.0
PSU
Corsair AX750 Gold
Case
Corsair Obsidian 800DW
Cooling
Corsair H100 (2x AP-121/2x UK-3000 push/pull)
Keyboard
Microsoft Wireless 5000
Mouse
Microsoft Wireless 5000
Internet Speed
5mb/s
Other Info
Logitech z-2300 2.1 speakers
Lamptron FC-5 v2
It's not as if you would your "report" would be a world first. My opinion: waste of time.

Thats what they said to me when I climbed Everest.
 

My Computers My Computers

  • At a glance

    7 X64i5 84002x8gb 3200mhz
    Computer type
    PC/Desktop
    OS
    7 X64
    CPU
    i5 8400
    Motherboard
    gigabyte b365m ds3h
    Memory
    2x8gb 3200mhz
    Hard Drives
    various
    PSU
    pure power 11 400w cm
    Case
    Coolermaster
    Cooling
    cryorig m9i
  • At a glance

    7x64g54008gb ddr4 2400
    Computer type
    PC/Desktop
    OS
    7x64
    CPU
    g5400
    Motherboard
    ga b365m ds3h
    Memory
    8gb ddr4 2400
    PSU
    xfx pro 450w
Forums are about asking for advice regardless on your expertise.

I've done heaps of things on my machine such as running an nLited XP VM in a 2 gig ramdrive. What's it good for, probably nothing else than a learning curve in knowing that I can do it.

And yep I work voluntarily with an antimalware team of great fellas that are so far ahead of me in pc knowledge it's embarrassing.
 

My Computer My Computer

At a glance

7
OS
7
I posted this on here because I wanted people, honest people who work with the stuff to let me know certain things about doing this.

Settle mate :)


If you don't wish to run a VM - do you have enough room on your HDD for a 'throw away' installation? or even a seperate HDD?

You could could always dual boot with another installation, infect it - Do your best to fix it and if worse comes to worse, scrap the installation.

The only potential problem would be running the risk of a particularly nasty bugger getting into your MBR/boot data and infect all installed machines.


As for Virtual Machines, Virtual Box would be the quickest and easiest way to get a VM up and running.

Just don't allow it to share any of the Hosts folders.
 

My Computer My Computer

At a glance

8 Pro x64i7 3770K 4.6GHz16GB G.Skill Trident X 2666mhzx2 EVGA 780 Ti Superclocked SLI
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Systems by SmartEyeball
OS
8 Pro x64
CPU
i7 3770K 4.6GHz
Motherboard
ASUS P8Z77 WS
Memory
16GB G.Skill Trident X 2666mhz
Graphics Card(s)
x2 EVGA 780 Ti Superclocked SLI
Sound Card
SB X-FI Surround 5.1 PRO USB / ATH-AD900 Headphones
Monitor(s) Displays
x3 Dell U2410 / 58" Samsung
Screen Resolution
5760*1200/ 1920*1200
Hard Drives
2x Intel 520 240GB (RAID 0) * 2x WD Caviar Blacks 2TB (RAID 0) * 2TB WD Caviar Black * Sony Optirac DVD
PSU
Silverstone Strider Evolution 1200W
Case
Thermaltake Level 10 GT Snow Edition
Cooling
Noctua NH-D14
Keyboard
Topre Realforce // Ducky Shine MX Black // Filco Ninja TKL
Mouse
Thermaltake Theron (Highly Recommended) + Razer Imperator
Antivirus
MSE
Browser
IE, FF, WaterFox
Other Info
GT Extreme V2 Sim Racing Cockpit + 40" LCD and K/B Mouse stand ▼
Fanatec CSR Elite Wheel + Clubsport V1 Pedals + CSR shifter/7G-H ▼Saitek X52 Pro ▼ TrackIR 5 Pro
Buttkicker v2 Seat Rumbler with Dedicated 5.1 and Sub Woofer attached to frame ▼
=
Bloody Big Grin
I am not going to be installing this software to my main computer. I have an old computer. I am going to be transfering it to my old computer via flash drive.

Thanks,
Ben
 

My Computer My Computer

At a glance

Windows 7 Ultimate Professional x64Intel Core i7-740QM @ 1.73GHz 4Core2 X 4GB DDR3-SDRAM 667MHzATI Mobility Radeon HD 5870 1GB SDRAM
Computer type
Laptop
Computer Manufacturer/Model Number
Clevo W870CU
OS
Windows 7 Ultimate Professional x64
CPU
Intel Core i7-740QM @ 1.73GHz 4Core
Motherboard
Intel PM55
Memory
2 X 4GB DDR3-SDRAM 667MHz
Graphics Card(s)
ATI Mobility Radeon HD 5870 1GB SDRAM
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
AUO149D 17.1" HD+/FHD @600Hz
Screen Resolution
1920X1080
Hard Drives
Seagate A0D-10F4 - 500 GB @7200RPM
PSU
43290mWh Intel Lithium-Ion Battery
Case
Cleveo W870CU
Cooling
2 Fans
Keyboard
Microsoft eHome MCIR 109
Mouse
Finger Sensing HID-Compliant Mouse Pad
Internet Speed
100 MB/s
Antivirus
avast! Antivirus
Browser
Google Chrome
Other Info
Biometric Enabled
2.0MP Cam
My old computer isn't connected to the internet so I can't download it right from there. I refuse to incase an infection travels across my network.

Thanks,
Ben
 

My Computer My Computer

At a glance

Windows 7 Ultimate Professional x64Intel Core i7-740QM @ 1.73GHz 4Core2 X 4GB DDR3-SDRAM 667MHzATI Mobility Radeon HD 5870 1GB SDRAM
Computer type
Laptop
Computer Manufacturer/Model Number
Clevo W870CU
OS
Windows 7 Ultimate Professional x64
CPU
Intel Core i7-740QM @ 1.73GHz 4Core
Motherboard
Intel PM55
Memory
2 X 4GB DDR3-SDRAM 667MHz
Graphics Card(s)
ATI Mobility Radeon HD 5870 1GB SDRAM
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
AUO149D 17.1" HD+/FHD @600Hz
Screen Resolution
1920X1080
Hard Drives
Seagate A0D-10F4 - 500 GB @7200RPM
PSU
43290mWh Intel Lithium-Ion Battery
Case
Cleveo W870CU
Cooling
2 Fans
Keyboard
Microsoft eHome MCIR 109
Mouse
Finger Sensing HID-Compliant Mouse Pad
Internet Speed
100 MB/s
Antivirus
avast! Antivirus
Browser
Google Chrome
Other Info
Biometric Enabled
2.0MP Cam
Back
Top