CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 949
Comments: 28
block bottom
spacer spacer

iedefender
Goto page 1, 2, 3, 4, 5 ... 16, 17, 18  Next
 
Post new topic   Reply to topic       All -> FavForums -> Unknown Files [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
securitynut

Sergeant
Sergeant


Joined: Jul 11, 2007
Posts: 95
Location: USA

PostPosted: Tue Oct 30, 2007 2:48 pm    Post subject: iedefender
Reply with quote

Attached below is a copy of IEdefender (hxxp://www.iedefender.com/) a new rogue software. I tried running it sandboxed but was unable to get it to run fully. I emailed it to kaspersky and they said it was clean... however I also sent it to Avira (antivir) and they concluded malware.

There is one topic currently in the Hijack this forum where this person is getting constant security popups saying he is infected and to download iedefender:
CastleCops Link/t206255-HijackThis_log.html

a quick search on castlecops indicated that iedefender has just been added to the definitions for Ad-Aware SE and Trojan Hunter. virustotal results are clean except for VBA which is flagging it as:
suspected of Backdoor.Delf.180 (paranoid heuristics)

below find the results of Avira's investigation:


Dear Sir or Madam,

Thank you for your email to Avira's virus lab.
Tracking number: INC000934XX.

A listing of files alongside their results can be found below:
File ID Filename Size (Byte) Result
2229432 ieDefender-setup.exe 2.46 MB CLEAN
2230594 iedefender.exe 1.31 MB MALWARE


Please find a detailed report concerning each individual sample below:
Filename Result
ieDefender-setup.exe CLEAN

The file 'ieDefender-setup.exe' has been determined to be 'CLEAN'. Our analysts did not discovered any malicious content.

Filename Result
iedefender.exe MALWARE

The file 'iedefender.exe' has been determined to be 'MALWARE'. Our analysts named the threat SPR/Fake.IEDefender. The term "SPR/" ("Security or Privacy Risk") denotes a program that might possibly be able to affect the security of your system, might trigger activities you might not want or might violate your privacy.Detection will be added to our virus definition file (VDF) with one of the next updates.



So with all of this I would conclude that is it malware. Please add it to the listserv.

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5800

MIRT Premium

PostPosted: Wed Oct 31, 2007 12:42 am    Post subject:
Reply with quote

Kaspersky have confirmed that this is malware, I've added the file to the malware listserv.

CastleCops Link/p1015767-MD5_7a974fed8ffba2b4c36291a75f5f00c0_ieDefender_exe.html


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
iedefender

Trooper
Trooper


Joined: Nov 02, 2007
Posts: 17
Location: USA

PostPosted: Fri Nov 02, 2007 12:21 pm    Post subject:
Reply with quote

wrote:
Kaspersky have confirmed that this is malware, I've added the file to the malware listserv.

CastleCops Link/p1015767-MD5_7a974fed8ffba2b4c36291a75f5f00c0_ieDefender_exe.html
Hello, we're developers of IEDefender, our software is clean and is real antispyware. As we can see, people from your site send our exe to different antivirus and antispyware companies, trying to black PR our company. They've got answers, that our soft is clean, because IT IS CLEAN! We contacted Kaspersky, they also confirmed, there are no problems with our software, you can check our .exe with any popular antiviruses, there no problems! Stop sending your detractive mails and messages, in other case we would be forced to send all information to our lawyers and meet your representative in the court, where it would be very hard for you to prove, that our software is not real, because IT'S REAL ANTISPYWARE!

Back to top
View users profile Send private message
TonyKlein

Site Moderator
Microsoft MVP

Joined: Oct 15, 2002
Posts: 13114
Location: Netherlands
MIRT Moderators MVP Premium Security Experts

PostPosted: Fri Nov 02, 2007 5:03 pm    Post subject:
Reply with quote

iedefender wrote:
We contacted Kaspersky, they also confirmed, there are no problems with our software!


Erm:

Quote:
File ieDefender.exe received on 11.02.2007 17:57:17 (CET)
Current status: scanning finished

Kaspersky 7.0.0.125 2007.11.02 not-a-virus:FraudTool.Win32.IeDefender.a


_________________
Tony image CLSID List


Last edited by TonyKlein on Fri Nov 02, 2007 5:18 pm, edited 3 times in total
Back to top
View users profile Send private message
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6299
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Fri Nov 02, 2007 5:05 pm    Post subject:
Reply with quote

@ iedefender

Answer this directly .

If you are legit then why does malware advertise your software ?

Back to top
View users profile Send private message Send email
MysteryFCM

Sergeant
Sergeant


Joined: Feb 07, 2007
Posts: 125
Location: Tyneside, UK

PostPosted: Fri Nov 02, 2007 5:18 pm    Post subject:
Reply with quote

iedefender wrote:
They've got answers, that our soft is clean, because IT IS CLEAN!


Your "soft" may be clean, but your "antispyware" software is a rogue ..... and take me to court if you like.


_________________
Regards

Steven Burn
Ur I.T. Mate Group / hpHosts
it-mate.co.uk / hosts-file.net
Back to top
View users profile Send private message Visit posters website
iedefender

Trooper
Trooper


Joined: Nov 02, 2007
Posts: 17
Location: USA

PostPosted: Sat Nov 03, 2007 1:52 am    Post subject:
Reply with quote

nosirrah wrote:
@ iedefender

Answer this directly .

If you are legit then why does malware advertise your software ?


Yes, we know about this problem, we have a partnership for our distributors to advertise our program, we pay them a percent of registration fee. Some of them use illegal methods, that we not accept, our customers send us abuses about it and we closed some of our affiliates accounts without paying them. We are watching on it but there are problems with them sometimes. We're working on this problem and it's very sad for us. But just think if somebody would advertise any famous antiviruses this way would you add them to malware too?

Back to top
View users profile Send private message
iedefender

Trooper
Trooper


Joined: Nov 02, 2007
Posts: 17
Location: USA

PostPosted: Sat Nov 03, 2007 1:55 am    Post subject:
Reply with quote

MysteryFCM wrote:
iedefender wrote:
They've got answers, that our soft is clean, because IT IS CLEAN!


Your "soft" may be clean, but your "antispyware" software is a rogue ..... and take me to court if you like.


Oh, I see, you've tried our .exe file? May be you can describe us here, what our "antispyware" did at your computer? May be you can answer it here with all details? The only thing that it's doing is scanning computer and deleting spyware and malware from it. NOTHING else. We also make usual updates. Do you have another information? We would be very glad to hear it. And if you don't know anything about it and just want to criticise something here, than stop stop this EDIT.

PROFANITY REMOVED

Back to top
View users profile Send private message
MysteryFCM

Sergeant
Sergeant


Joined: Feb 07, 2007
Posts: 125
Location: Tyneside, UK

PostPosted: Sat Nov 03, 2007 1:57 am    Post subject:
Reply with quote

iedefender wrote:
nosirrah wrote:
@ iedefender

Answer this directly .

If you are legit then why does malware advertise your software ?


Yes, we know about this problem, we have a partnership for our distributors to advertise our program, we pay them a percent of registration fee. Some of them use illegal methods, that we not accept, our customers send us abuses about it and we closed some of our affiliates accounts without paying them. We are watching on it but there are problems with them sometimes. We're working on this problem and it's very sad for us. But just think if somebody would advertise any famous antiviruses this way would you add them to malware too?


MANY well known companies have been ripped to shreds for the same thing ....... but in your case, not only are you spamvertized via malware, a part of your own software is also detected as malware


_________________
Regards

Steven Burn
Ur I.T. Mate Group / hpHosts
it-mate.co.uk / hosts-file.net
Back to top
View users profile Send private message Visit posters website
MysteryFCM

Sergeant
Sergeant


Joined: Feb 07, 2007
Posts: 125
Location: Tyneside, UK

PostPosted: Sat Nov 03, 2007 2:10 am    Post subject:
Reply with quote

iedefender wrote:
Do you have another information? We would be very glad to hear it. And if you don't know anything about it and just want to criticise something here, than stop stop this bullshit.


How to win friends and influence people eh? ...... very well, fancy screenie's?

http://hosts-file.net/docs/imgIED_Ohdear.gif

http://hosts-file.net/docs/imgIED_Payupdammit.gif

Hows that ......? .... both of the file's you've detected as malicious are LEGIT! ... want proof of that?, ask Microsoft (after all, both file's were created by them!)


_________________
Regards

Steven Burn
Ur I.T. Mate Group / hpHosts
it-mate.co.uk / hosts-file.net
Back to top
View users profile Send private message Visit posters website
iedefender

Trooper
Trooper


Joined: Nov 02, 2007
Posts: 17
Location: USA

PostPosted: Sat Nov 03, 2007 2:29 am    Post subject:
Reply with quote

MysteryFCM wrote:
iedefender wrote:
nosirrah wrote:
@ iedefender

Answer this directly .

If you are legit then why does malware advertise your software ?


Yes, we know about this problem, we have a partnership for our distributors to advertise our program, we pay them a percent of registration fee. Some of them use illegal methods, that we not accept, our customers send us abuses about it and we closed some of our affiliates accounts without paying them. We are watching on it but there are problems with them sometimes. We're working on this problem and it's very sad for us. But just think if somebody would advertise any famous antiviruses this way would you add them to malware too?


MANY well known companies have been ripped to shreds for the same thing ....... but in your case, not only are you spamvertized via malware, a part of your own software is also detected as malware


Oh, really? Who detects it? You? Any proves? Tell us, what part of our software is malware? I see only bullshit from you, no proves and nothing else. All new messages without proves from you would be ignored, I want to talk with smart people not ones, who just want to spit here.

Back to top
View users profile Send private message
iedefender

Trooper
Trooper


Joined: Nov 02, 2007
Posts: 17
Location: USA

PostPosted: Sat Nov 03, 2007 2:32 am    Post subject:
Reply with quote

MysteryFCM wrote:
iedefender wrote:
Do you have another information? We would be very glad to hear it. And if you don't know anything about it and just want to criticise something here, than stop stop this bullshit.


How to win friends and influence people eh? ...... very well, fancy screenie's?

http://hosts-file.net/docs/imgIED_Ohdear.gif

http://hosts-file.net/docs/imgIED_Payupdammit.gif

Hows that ......? .... both of the file's you've detected as malicious are LEGIT! ... want proof of that?, ask Microsoft (after all, both file's were created by them!)


lol! our software also scan startups,if you would look at castlecops database you would find both entries, here they are:
CastleCops Link/atxlist-1569.html
CastleCops Link/s8025-msmsgs_exe.html
If you would have a license copy of our program you would know, that we didn't delete suspicious files and some malware, but only warn users about it with description of these files, so that they can choose if they want to delete it manually themselves. Any other questions? I still don't see any proves, that our software is malware or makes something bad.

Back to top
View users profile Send private message
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6299
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Sat Nov 03, 2007 2:38 am    Post subject:
Reply with quote

And what of this site : http://85.255.121.126/scan/ .

Why do several other rogue scam scan sites look and function exactly like this ? Malware alarm and spy shredder have the exact same animated gif fake scans .

You are a liar and I can prove it . One of the sites on your server is exactly where the fake codec is that installs the trojan that advertises your scam software . Here are the three sites on your server :

Iedefender.com <- rogue software
Youlikehere.com <- installs the trojan that advertises your rogue
Ixworldpay.com <- likely your next scam

It is to damn bad that we have made it harder to scam people . Create legit software and this won't happen .

Back to top
View users profile Send private message Send email
MysteryFCM

Sergeant
Sergeant


Joined: Feb 07, 2007
Posts: 125
Location: Tyneside, UK

PostPosted: Sat Nov 03, 2007 2:42 am    Post subject:
Reply with quote

I never said your program was malware, I said it was a rogue and that part of it was detected as malware ..... lemme give you a helping hand as you obviously missed it;

CastleCops Link/p1016957-iedefender.html#1016957

Additionally, PrevX detects your program as;

Heuristic: Suspicious File With Covert Attributes

.. and we already know about Kaspersky detecting it .... but VBA32 detects it as;

suspected of Backdoor.Delf.180 (paranoid heuristics)

.. and WebWasher detects it as;

Riskware.Fake.IEDefender

Might wanna do a little research before you claim otherwise Wink

.... and the screenshots shows your program detecting two legit file's as malware (on a clean machine by the way). The malicious versions of those file's aren't on the machine, nor have they ever been Wink

But worse still .... failing to detect ANY of the malware I've got in a dedicated research folder.

As for it's deleting anything, not gonna happen if you gotta pay for that now is it?


_________________
Regards

Steven Burn
Ur I.T. Mate Group / hpHosts
it-mate.co.uk / hosts-file.net
Back to top
View users profile Send private message Visit posters website
iedefender

Trooper
Trooper


Joined: Nov 02, 2007
Posts: 17
Location: USA

PostPosted: Sat Nov 03, 2007 2:47 am    Post subject:
Reply with quote

nosirrah wrote:
And what of this site : http://85.255.121.126/scan/ .

Why do several other rogue scam scan sites look and function exactly like this ? Malware alarm and spy shredder have the exact same animated gif fake scans .

You are a liar and I can prove it . One of the sites on your server is exactly where the fake codec is that installs the trojan that advertises your scam software . Here are the three sites on your server :

Iedefender.com <- rogue software
Youlikehere.com <- installs the trojan that advertises your rogue
Ixworldpay.com <- likely your next scam

It is to damn bad that we have made it harder to scam people . Create legit software and this won't happen .


we have virtual hosting and some of our affiliates can use it too. may be you'll find some more scam there, do you want us to change hosting? are you trying to prove, that we use illegal advertising methods? I've already answered this question. We have affiliate program we don't allow affiliates to advertise our software this way, but there are some cheaters and we always delete their accounts as soon as we find them.
but why you are talking about malware? where did you find malware there?

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Unknown Files All times are GMT
Goto page 1, 2, 3, 4, 5 ... 16, 17, 18  Next
Page 1 of 18

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer