Hi everyone,
I just stumbled upon an article and thought to warn you guys.
Total Defender is the latest rouge anti-virus program appeared on the Internet that pretends to be real security software for Microsoft Windows Vista and XP. Be careful about such rogue antivirus software. Such fake security programs (for example Antivirus 2009, Spyware Guard 2009) are circulating over the internet these days.
The Total Defender site looks like this:
More Info:
Code:This is just for your information. Domain: Total-Defender. com IP: 94.247.2.41 Country: Latvia Host: DATORU EXPRESS SERVISS Ltd. Organization: ZlKon File: total-defender-setup.exe Connects to: 0 200 HTTP 94.247.2.41 /ck.php 21 1 200 HTTP 94.247.2.41 /tdd.php?i=1 2 200 HTTP 94.247.2.41 /ck.php 3 301 HTTP 94.247.2.41 /tdp.php?ak=24DIGITHASH 4 200 HTTP CONNECT pp-pay.net:443 5 200 HTTP CONNECT pp-pay.net:443 6 200 HTTP CONNECT pp-pay.net:443 7 200 HTTP CONNECT bill-support.com:443
Screenshots:
If you already got infected, then free trial of VIPRE will remove it.
Sources:
Jkwebtalks
Sunbelt Blog
Pandalabs Blog
Last edited by ahashmi06; 01-27-2009 at 06:10 PM.
ahashmi06 i think you should add it to the current list of rogue security program list
merge it there , to make it easy for user to read bout it
knackbag.com
Total Defender is quite stealthy?
VirusTotal
----------
analisis/f787c1378f97716f41594ddad09d1f13
File total-defender-setup.exe received on 01.27.2009 12:51:40 (CET)
Current status: finished
Result: 7/39 (17.95%)
JOTTI
--------
A-Squared Found nothing
AntiVir Found TR/Drop.Fake.TDAV.4, SPR/Fake.TDAV.22
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found Trojan.Fakealert.3913
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found Rogue:W32/TotalDefender.A
G DATA Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Sophos Antivirus Found Troj/FakeAV-JI
VirusBuster Found nothing
VBA32 Found nothing
------
Move ur post to rogue security program lists
Last edited by Ceyfer √; 01-27-2009 at 07:04 PM.
"Semper Fidelis."
Added in rogue security program list. Thank you ismailtahir for your advice.
this one is a bit scary for its stealthy![]()