Scam/Malware Warning
#26
Since no one else did it yet, I booted up the ol' Windows VM to see what it does on a practical basis.

It starts out appearing as a normal AC installer, ending with the expected opening of the AC website:

1. https://uloadr.com/u/l5p.png
2. https://uloadr.com/u/onc.png
3. https://uloadr.com/u/8lg.png
4. https://uloadr.com/u/6t3.png
5. https://uloadr.com/u/cny.png
6. https://uloadr.com/u/958.png
7. https://uloadr.com/u/jrt.png
8. https://uloadr.com/u/3p4.png
9. https://uloadr.com/u/t4m.png
10. https://uloadr.com/u/3ng.png
11. https://uloadr.com/u/87d.png

During and after this installation, Process Explorer shows no malicious processes:

12. https://uloadr.com/u/654.png
13. https://uloadr.com/u/tuy.png

The AC which was just installed launches OK:

14. https://uloadr.com/u/u6n.png

After launching AC and after closing it, there are still no malicious processes:

15. https://uloadr.com/u/81p.png
16. https://uloadr.com/u/5q2.png
17. https://uloadr.com/u/3yb.png

At this point I rebooted just in case any malware needed a chance to get going.

Updated MBAM and ran a quick scan (full scan is not necessary):

18. https://uloadr.com/u/49j.png

While that was running, I ran a checksum on the "fake" AC installer and the "real" one hosted on the genuine site. They match (fake first, real second):

19. https://uloadr.com/u/am0.png
20. https://uloadr.com/u/0ok.png

The MBAM scan completed clean:

21. https://uloadr.com/u/i05.png

As a final check, GMER (rootkit detector) was also clean. (No screenshot included as there is absolutely nothing to see.)

Conclusion: No malware or anything otherwise malicious -- the installer wasn't even tampered with -- except misdirecting users, possibly in an attempt to get advertisement hits or to establish the false site as genuine for future attacks.

Also, browser search settings were not tampered with, nor were any toolbars or other unwanted packages installed.
Thanks given by:


Messages In This Thread
Scam/Malware Warning - by makkE - 18 Oct 10, 10:50PM
RE: Scam/Malware Warning - by Gibstick - 18 Oct 10, 10:55PM
RE: Scam/Malware Warning - by Habluka - 18 Oct 10, 11:26PM
RE: Scam/Malware Warning - by Alien - 18 Oct 10, 11:42PM
RE: Scam/Malware Warning - by Ronald_Reagan - 18 Oct 10, 11:59PM
RE: Scam/Malware Warning - by mikebefore - 19 Oct 10, 02:23AM
RE: Scam/Malware Warning - by Vermi - 19 Oct 10, 06:29AM
RE: Scam/Malware Warning - by Huntsman - 19 Oct 10, 06:36AM
RE: Scam/Malware Warning - by RandumKiwi - 19 Oct 10, 06:58AM
RE: Scam/Malware Warning - by RandumKiwi - 19 Oct 10, 07:25AM
RE: Scam/Malware Warning - by Shorty - 19 Oct 10, 08:43AM
RE: Scam/Malware Warning - by tempest - 19 Oct 10, 08:06PM
RE: Scam/Malware Warning - by Ghost - 19 Oct 10, 08:21PM
RE: Scam/Malware Warning - by Bullpup - 19 Oct 10, 09:05PM
RE: Scam/Malware Warning - by JGAN - 19 Oct 10, 09:38PM
RE: Scam/Malware Warning - by tempest - 19 Oct 10, 10:00PM
RE: Scam/Malware Warning - by ärkefiende - 19 Oct 10, 10:07PM
RE: Scam/Malware Warning - by tempest - 19 Oct 10, 10:07PM
RE: Scam/Malware Warning - by eynstyne - 20 Oct 10, 12:03AM
RE: Scam/Malware Warning - by Gibstick - 20 Oct 10, 12:19AM
RE: Scam/Malware Warning - by eynstyne - 20 Oct 10, 01:10AM
RE: Scam/Malware Warning - by Brahma - 20 Oct 10, 02:28AM
RE: Scam/Malware Warning - by Ghost - 20 Oct 10, 02:36AM
RE: Scam/Malware Warning - by eynstyne - 20 Oct 10, 02:46AM
RE: Scam/Malware Warning - by JGAN - 20 Oct 10, 03:18AM
RE: Scam/Malware Warning - by vonunov - 20 Oct 10, 03:45AM
RE: Scam/Malware Warning - by RandumKiwi - 20 Oct 10, 07:22AM
RE: Scam/Malware Warning - by OpenSource - 20 Oct 10, 05:11PM
RE: Scam/Malware Warning - by V-Man - 20 Oct 10, 07:28AM
RE: Scam/Malware Warning - by Lightning - 20 Oct 10, 11:46AM
RE: Scam/Malware Warning - by eynstyne - 20 Oct 10, 04:41PM
RE: Scam/Malware Warning - by JGAN - 20 Oct 10, 07:55PM
RE: Scam/Malware Warning - by eynstyne - 20 Oct 10, 08:12PM
RE: Scam/Malware Warning - by Private_Ale - 21 Oct 10, 08:44AM
RE: Scam/Malware Warning - by Brahma - 21 Oct 10, 05:15PM
RE: Scam/Malware Warning - by Zarjio - 22 Oct 10, 06:50PM
RE: Scam/Malware Warning - by JGAN - 22 Oct 10, 07:50PM
RE: Scam/Malware Warning - by V-Man - 23 Oct 10, 06:42AM
RE: Scam/Malware Warning - by XFA - 23 Oct 10, 04:09AM
RE: Scam/Malware Warning - by Jason - 26 Oct 10, 12:25AM