A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #3186  by EP_X0FF
 Fri Oct 22, 2010 12:58 pm
This is fake alert (MSE UI fake) - ThinkPoint.

Install it and try to start iexplore for example. It will block your Windows at restart.

Runs through HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell as "hotfix"

However Windows can be simple unblocked with Task Manager.

Image
Image
 #6481  by thekillergreece
 Sun May 22, 2011 5:03 pm
EP_X0FF wrote:Copy-paste GUI clone of Microsoft Security Essential. This is not simple alike clone (like Security Essentials) - this is full UI copy of MSE.
Written on Delphi (cryptor + UPX inside).

VirusTotal
http://www.virustotal.com/analisis/1840 ... 1273465045

GUI / Detections / Give me money dialog

Dropped with legit MSE components to %Documents and Settings%\UserName\Application Data\Microsoft Security Essentials,
autorun through HKCU\Software\Microsoft\Windows\CurrentVersion\Run

That's how all this looking after unpacking :D
hey what is that?at your unpacking image...do you remember what is it?it is an antivirus creator?
 #6482  by EP_X0FF
 Sun May 22, 2011 5:05 pm
thekillergreece wrote:hey what is that?at your unpacking image...do you remember what is it?it is an antivirus creator?
It's CodeGear RAD Studio. Next time, please, do not quote big images, ok? :)
 #6483  by thekillergreece
 Sun May 22, 2011 5:10 pm
EP_X0FF wrote:
thekillergreece wrote:hey what is that?at your unpacking image...do you remember what is it?it is an antivirus creator?
It's CodeGear RAD Studio. Next time, please, do not quote big images, ok? :)


oh sorry :( im new member here -_-