Author Topic: [SOLVED] Fake AV/Rogue (avastfrance.com)  (Read 6179 times)

0 Members and 1 Guest are viewing this topic.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
[SOLVED] Fake AV/Rogue (avastfrance.com)
« on: March 16, 2011, 01:59:03 PM »
Reported by an user in the German section. (hxxp://wxw.avastfrance.com/)
The site distributes a fake AV (Rogue), using avast's name...!!!

Report    2011-03-16 13:15:53 (GMT 1)
Website    avastfrance.com
Domain Hash    4d6e81c523fad80972e4e15ff80ec385
IP Address    174.123.72.226 [SCAN]
IP Hostname    e2.48.7bae.static.theplanet.com
IP Country    US (United States)
AS Number    21844
AS Name    THEPLANET-AS - ThePlanet.com Internet Service...
Detections    7 / 18 (39 %)
Status    DANGEROUS
« Last Edit: March 18, 2011, 07:25:55 AM by Asyn »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Fake AV/Rogue (avastfrance.com)
« Reply #1 on: March 16, 2011, 02:07:06 PM »
Avast already detect the executuble but not the site,i reported this site in one of my posts but no1 seemed to see it,anyway.
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

YoKenny

  • Guest
Re: Fake AV/Rogue (avastfrance.com)
« Reply #2 on: March 16, 2011, 02:09:34 PM »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Fake AV/Rogue (avastfrance.com)
« Reply #4 on: March 16, 2011, 02:10:47 PM »
Avast already detect the executuble but not the site,i reported this site in one of my posts but no1 seemed to see it,anyway.

Well, the site should be blocked, asap...!!!
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Fake AV/Rogue (avastfrance.com)
« Reply #5 on: March 16, 2011, 02:12:24 PM »
Avast already detect the executuble but not the site,i reported this site in one of my posts but no1 seemed to see it,anyway.

Well, the site should be blocked, asap...!!!
asyn


Of course!!
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

YoKenny

  • Guest
Re: Fake AV/Rogue (avastfrance.com)
« Reply #6 on: March 16, 2011, 02:17:57 PM »

Well, the site should be blocked, asap...!!!
It is by MBAM as well:
IP-BLOCK 174.123.72.226 (Type: outgoing, Port: 52612, Process: avastsvc.exe)

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Fake AV/Rogue (avastfrance.com)
« Reply #7 on: March 16, 2011, 02:22:28 PM »

Well, the site should be blocked, asap...!!!
It is by MBAM as well:
IP-BLOCK 174.123.72.226 (Type: outgoing, Port: 52612, Process: avastsvc.exe)

Thanks for the info about hpHosts and Mbam, Kenny..!
Still, we want avast to block it, too. ;)
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Fake AV/Rogue (avastfrance.com)
« Reply #8 on: March 16, 2011, 03:19:38 PM »
Hi Asyn,

Send a mail to avast that the following links should be detected:
So called Bad Anchor link here: hxtp://www.avastfrance.com/
See: http://www.virustotal.com/file-scan/report.html?id=9b8fbd43137dd84905e1b8b37e05de58b00484470c429127ba86fbd2c4d9221f-1300284565
0/ 43 (0.0%)
and PremiumSMSScan, here: htxp://www.avastfrance.com/dl/Avast-antivirus-francais.exe ,detected as NSIS:FakeInst-L by avast
See: http://xylibox.blogspot.com/2011/03/hoaxsms-fake-installer-avast-avast.html
Site should be flagged: http://deletemalware.blogspot.com/2011/03/fake-avast-antivirus-avast-antivirus.html
It is also in here: http://malc0de.com/database/
Reported on March 13th:
011/03/13_19:26   www. avastfrance.com/dl/Avast-antivirus-francais.exe   174. 123. 72. 226   e2. 48. 7bae.static.theplanet.com.   fake av   Whois Privacy Protection Service, Inc. / xfwryksrx AT whoisprivacyprotect.com   21844   
I do not know whether it is still alive? These issues are sometimes rather short-lived as soon as they are being found up,

polonus

« Last Edit: March 16, 2011, 04:02:19 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Fake AV/Rogue (avastfrance.com)
« Reply #9 on: March 16, 2011, 03:27:12 PM »
Thanks, pol..!! :)
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Fake AV/Rogue (avastfrance.com)
« Reply #10 on: March 17, 2011, 03:38:17 PM »
Still undetected? ???huh
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

doktornotor

  • Guest
Re: Fake AV/Rogue (avastfrance.com)
« Reply #11 on: March 17, 2011, 04:16:26 PM »
Still undetected? ???huh

Contact avast! however there's no option to report false negatives  :(

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89053
  • No support PMs thanks
Re: Fake AV/Rogue (avastfrance.com)
« Reply #12 on: March 17, 2011, 04:43:46 PM »
Yes and that is something which needs to be included in the list.

Though you could try and misuse the report false alert on a website, by reporting in the text input 'Your Message' window that it is a malicious site which isn't detected by either the network or web shields.

I tend to send an email to the usual virus (at) avast (dot) com address, with 'Undetected Malware - Network Shield' in the subject and details in the email body, no need for a sample.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Fake AV/Rogue (avastfrance.com)
« Reply #13 on: March 18, 2011, 07:25:28 AM »
Site gets blocked now, so I put this to solved.
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0