Nice Online Fake AV

hXXp://freeavscanonline.com/scan1/83 (I hope it is correct)
I was redirected from Google picture searching.

Target malware served to the user by this fake site is already detected as Win32:Malware-gen :slight_smile:

Sorry.
My avast! didn’t block the site. (- Web Shield on, PUP on, Heuristics - High and so on.)
That’s why I crated this thread.

playing with fire, here’s what I got in IE9 sandboxed, first theweb site message, and then when closing the dialog box (… yeah in such cases mostly ok and cancel are the same ), I got the IE smartscreen alert.

In Chrome I got nothing as JS was blocked in the first place.

At the end of all of the “scanning”, it offers a scanner to download and fix everything - thats the download that RejZoR was referring to.

The site could be added to the network shield block list though, have you submitted it yet?

The site could be added to the network shield block list though, have you submitted it yet?
These scan URLs are usually dead after a day or two, then they move to a new place..

avast! Web Shield doesn’t detect the exe file before it tries to enter the PC after the scan.
Why Web Shield doesn’t block the site itself.
Why?

Why Web Shield doesn't block the site itself.
see my post above...

the web shield doesn’t block sites, but drive by downloads of malware while browsing (so links to such data when connection is attempted and malware content is detected). The web shield analyses data, not URLs. Network shield does block sites, and this address could or should have been added to the blacklist, but as Pondus said, these URL don’t exist very long.

The fake antivirus itself is harmless. It’s just a webpage. The stuff that gets downloaded later is what’s really malicious. It will probably get blacklisted prettty soon in Network Shield.