A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #7422  by Xylitol
 Tue Jul 19, 2011 6:44 pm
Anyone heard of the new FakeAv 'BlueFlare Antivirus' ?
http://www.2-viruses.com/remove-blueflare-antivirus

Seem only PC Tools affiliates talk about this infection
They have released a screenshot here:
Image

That make me perplex, even Malwarebytes' guys have not see the color of this one.
And i'm sure you have noticed on the screenshot the window title 'Windows Steady Work'
A lame hex edit from malware author (I've never see that on Tritax FakeAV family) or a fake infection for says 'only us detect this one' ?
Also in computer helping forums/communities, seem no one got infected or talk about BlueFlare.

Affil site who released a screenshot:
Image

Site design remind me this campaign on twitter with random detection name submitted each ~30secs:
Image
Advertising ParetoLogic product and some others.

Image

And here:
http://deletemalware.blogspot.com/2011/ ... virus.html
This blog who relayed info (shit got virals in other helping sites)
Entry was posted 16 Jul, we are now the 19 and no one have a MD5.
 #7440  by bitx
 Wed Jul 20, 2011 10:52 am
The funny thing is that deletemalware blog only raised public awareness of possible new rogue AV, they never said that this rogue actually exists.
We've have been receiving complaints about a program called BlueFlare Antivirus for a couple of days. From what we've heard about this application, it could be rogue anti-virus software.
They do not have the binary, only complaints and log files from visitors. They made a decision to inform people about possible new threat and told them scan the computer with free anti-malware if anything similar pop ups on users computer screens.
Unfortunately, we couldn't find anything related to BlueFlare Antivirus and it certainly raises our suspicion of fraud. We are currently investigating this threat and will provide more information as it becomes available.
It's a warning not an analysis of malware. However, other websites probably assumed that it's a real rogue and some of them even made screenshots that are clearly fake. Well, raising public awareness is one thing, but giving a full analysis of rogue that may not even exist and suggesting commercial removal tool "desinged to remove BlueFlare Antivirus" is another story.
 #7444  by Xylitol
 Wed Jul 20, 2011 12:21 pm
Seem there is also some fake screenshot with the FakeAV 'Zentom System Guard'

Image

the interface i know is
Image

edit:
SiR! did something like that a while back for warn:
http://siri-urz.blogspot.com/2009/10/se ... rogue.html
Last edited by Xylitol on Wed Jul 20, 2011 12:28 pm, edited 2 times in total.
 #7446  by EP_X0FF
 Wed Jul 20, 2011 12:27 pm
I think they are all Photoshop/Paint work, 80 level.