Author Topic: System Defend Antivirus 2010 - new rogue AV ?!  (Read 16267 times)

0 Members and 1 Guest are viewing this topic.


Hermite15

  • Guest
Re: System Defend Antivirus 2010 - new rogue AV ?!
« Reply #1 on: May 14, 2010, 08:00:55 PM »
needs to be run in a VM to see what it does after a couple of hours or days. My guess is obviously yes, that's rogue. Again, remains to find out what it does. I wouldn't  risk an install ;D We need Polonus here ;) and also Pondus is after rogue AVs...they'll probably see that thread. Thanks for posting that's interesting.

that's all I got so far, not about the "AV", but about the main site offering the download
http://www.mywot.com/en/scorecard/www.brothersoft.com

I can't believe that CNet and softpedia are offering it too ::)

edit: publisher  >>>> hxxp://www.preedasoftware.com/ ( 61.19.247.206  based in Thailand)
hxxp://www.preedasoftware.com/index2.php
hxxp://www.systemdefendantivirus.com
nothing here: http://wepawet.iseclab.org/view.php?hash=7e47ba314c38630907a94fad07c54f03&t=1273860244&type=js
http://wepawet.iseclab.org/view.php?hash=ac1e2e1b636034021b3e5bfd8547c462&t=1273861319&type=js
« Last Edit: May 15, 2010, 11:12:32 AM by Logos »

doktornotor

  • Guest
Re: System Defend Antivirus 2010 - new rogue AV ?!
« Reply #2 on: May 14, 2010, 08:04:03 PM »
As you said, need some VM to install, don't have one handy ATM. Well, could try to install to a sandbox but don't feel like that  ;D

I can't believe that CNet and softpedia are offering it too ::)

Yeah, that's really a WTH...

Hermite15

  • Guest
Re: System Defend Antivirus 2010 - new rogue AV ?!
« Reply #3 on: May 14, 2010, 08:06:18 PM »
I've edited my first post in the mean time, trying to find out more about the publisher...

Hermite15

  • Guest
Re: System Defend Antivirus 2010 - new rogue AV ?!
« Reply #4 on: May 14, 2010, 08:18:16 PM »
http://www.wmtips.com/tools/info/?url=http://www.preedasoftware.com/
http://validator.w3.org/check?uri=http://www.preedasoftware.com/
again, Polonus could interpret that...may be there's nothing there either, I haven't got a clue. I'm not familiar at all with those web tools.
Quote
Errors found while checking this document as XHTML 1.0 Transitional!

other errors on the download page:
http://jigsaw.w3.org/css-validator/validator?uri=http://www.preedasoftware.com/index2.php
http://validator.w3.org/check?uri=http://www.preedasoftware.com/index2.php
« Last Edit: May 14, 2010, 08:27:11 PM by Logos »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33907
  • malware fighter
Re: System Defend Antivirus 2010 - new rogue AV ?!
« Reply #5 on: May 14, 2010, 08:52:46 PM »
Hi Logos,

You miss the malcode if you do not also check the links from that site
Suspicious at some time are/were:
http://www.google.com/safebrowsing/diagnostic?site=www.geardownload.com  
At the crux of this may be regnow*com, a site full of adware and trojans...

http://safeweb.norton.com/report/show?url=regnow.com&x=0&y=0 alerted by Community Rating:
website- unsafe risky downloads reported by some users, here's a few[ keylogger!!!
spy agent adware downloader-xz trojan lot of spyware and others??

well to sum it up: malicious software includes 74 trojans, 5 backdoors, 2 viruses.
Successful infection resulted in an average of 2 new processes on the target machine

Another link not completely beyond suspicion: http://www.google.com/safebrowsing/diagnostic?site=www.softwarelode.com

And finally then this link: http://www.google.com/safebrowsing/diagnostic?site=download.cnet.com
Malicious software includes 1 trojan.
Successful infection resulted in an average of 1 new process on the target machine,
last found to be there 2010-03-07,

polonus
« Last Edit: May 14, 2010, 08:57:51 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Hermite15

  • Guest
Re: System Defend Antivirus 2010 - new rogue AV ?!
« Reply #6 on: May 14, 2010, 09:11:34 PM »
Hi Logos,

You miss the malcode if you do not also check the links from that site


yeah... ;D >>> I checked only two pages, the main one with the ads about the sites providing the download, and the main download page. Okay this said all you found is that sites providing the download are infected (including CNet), but you didn't find anything related to this particular download, and its publisher >>> hxxp://www.preedasoftware.com and System Defend Antivirus 2010  ??? doesn't seem easy :D but I'm sure that's a rogue, no possible doubt (intuitively yes...).
« Last Edit: May 14, 2010, 09:42:48 PM by Logos »

doktornotor

  • Guest
Re: System Defend Antivirus 2010 - new rogue AV ?!
« Reply #7 on: May 15, 2010, 10:41:24 AM »
So this is what Softpedia calls ad-supported?! Shame on the guys.  ::) >:( :-X

With a behaviour like that, it's beyond doubt that it's not only useless, but definitely rogue as well. Those forced-to-be-clicked ads will point you to a malware-infested site sooner rather than later.

Offline sg09

  • Full Member
  • ***
  • Posts: 175
    • Current Technology Discounts
Re: System Defend Antivirus 2010 - new rogue AV ?!
« Reply #8 on: May 15, 2010, 11:20:54 AM »
So this is what Softpedia calls ad-supported?! Shame on the guys.  ::) >:( :-X

With a behaviour like that, it's beyond doubt that it's not only useless, but definitely rogue as well. Those forced-to-be-clicked ads will point you to a malware-infested site sooner rather than later.
It's a worthless crap and surely it may lead to drive-by-downloads for sure. I had collected few screenshot but all deleted because now I have deleted the VM. Testing this crap have spoiled my evening.  >:(
Anyone who knows how to loose can certainly learn how to win.

Hermite15

  • Guest
Re: System Defend Antivirus 2010 - new rogue AV ?!
« Reply #9 on: May 15, 2010, 11:24:38 AM »
why did you delete the screen shots, that's exactly what we need ??? you could have taken them from the host system ::) anyway, can you describe the behavior of that crap, assuming you tested it in a VM? some say it prompts for a first system check before installing...(mentioned either on wilders or another site...)
« Last Edit: May 15, 2010, 11:26:37 AM by Logos »

doktornotor

  • Guest
Re: System Defend Antivirus 2010 - new rogue AV ?!
« Reply #10 on: May 15, 2010, 11:28:00 AM »
why did you delete the screen shots, that's exactly what we need ??? you could have taken them from the host system ::)

FWIW, there are a couple of screenshots on Wilders thread. Basically, it's a Kaspersky GUI rip-off flooded with ads, even the logo is stolen from Kaspersky.  ::)

Hermite15

  • Guest
Re: System Defend Antivirus 2010 - new rogue AV ?!
« Reply #11 on: May 15, 2010, 11:31:55 AM »
why did you delete the screen shots, that's exactly what we need ??? you could have taken them from the host system ::)

FWIW, there are a couple of screenshots on Wilders thread. Basically, it's a Kaspersky GUI rip-off flooded with ads, even the logo is stolen from Kaspersky.  ::)

this I knew I saw them >>> what I meant is screen shots showing the "software" and system behavior, i.e. dialog boxes, prompts etc...anything suspicious or very obviously rogueware like.

Hermite15

  • Guest
Re: System Defend Antivirus 2010 - new rogue AV ?!
« Reply #12 on: May 15, 2010, 11:34:36 AM »
it's also on ZDnet France >>> hxxp://www.zdnet.fr/telecharger/logiciel/system-defend-antivirus-2010-39830683s.htm  ::)

Offline sg09

  • Full Member
  • ***
  • Posts: 175
    • Current Technology Discounts
Re: System Defend Antivirus 2010 - new rogue AV ?!
« Reply #13 on: May 15, 2010, 11:39:20 AM »
why did you delete the screen shots, that's exactly what we need ??? you could have taken them from the host system ::) anyway, can you describe the behavior of that crap, assuming you tested it in a VM? some say it prompts for a first system check before installing...(mentioned either on wilders or another site...)
Give me some time, I will post them. I am installing it again in VM.
Anyone who knows how to loose can certainly learn how to win.

Hermite15

  • Guest
Re: System Defend Antivirus 2010 - new rogue AV ?!
« Reply #14 on: May 15, 2010, 11:50:07 AM »
why did you delete the screen shots, that's exactly what we need ??? you could have taken them from the host system ::) anyway, can you describe the behavior of that crap, assuming you tested it in a VM? some say it prompts for a first system check before installing...(mentioned either on wilders or another site...)
Give me some time, I will post them. I am installing it again in VM.

okay ;) >>> please post screen shots not just of the interface of the program, but first of all of suspicious behavior if any, like prompts to remove malware, system behavior change etc...