2012

Just a heads up ive seen four unique SHA256 for FakeAV 2012 in the last 60 minutes.

https://www.virustotal.com/file/cc59206fe2751c8357776fe74361c8eb68408f46f941f39fd3da44c511d86dd1/analysis/1326399074/

http://urlquery.net/queued.php?id=15932

your VT link is dead…use new.virustotal.com

Interesting, his link works here…!!! :wink:

i am getting not found in opera ???

strange…it works in IE ::slight_smile:

Well, it works with FF.

It also works with google chrome - did you use https?

polonus

Well, it works with FF.

Same here, Asyn ;D

Great. :wink:

Hi razoreqx,

Is this the video-converter malware? You should get a Connection refused>…
Because the avast network shield neatly blocks access to that address…

As you search for malware for ip 108.59.1.12 you can see site is up but the malware did no longer respond within an hour - 2011-12-24 14:00:41 2011-12-24 14:09:31 0.1 response dead
I wish we could have malware being taken down that quickly everywhere…
This one is a live one and up from that same IP: -http://www.premiumsave.info/installmate/addons/zugo/indy-indyesigns-dtx.exe detection (adware not malicious 2012-01-06 13:30:24 up and alive )see: https://www.virustotal.com/file/cb0b91204b71b7b5a2009707e9c2c9fa63af05080f94fcd1d3ae75318eb37d2d/analysis/

polonus

Hope we get the samples for vista antivirus 2012,win7 home security 2012 ans other latest versions…avast doesnt seem to detect them! :-[ :cry: >:( :-\

Also,forum friends keep your windows up to date with critical security patches through windows updates…u will cut out a lot of exploit type malware via it…

@true indian

if you check the VPS release history http://www.avast.com/en-eu/virus-update-history

you will see that in almost every updates there are Win32:FakeAlert / Win32:FakeSys / Win32:FakeAV

so they are updating, but new versions are released every day…they look the same, but are changed to avoid detection