|
Donation/Premium |
|
 |
|
|
|
|
|
|
|
Survey |
|
 |
|
|
|
|
|
|
|
 |
 |
| View previous topic :: View next topic |
| Author |
Message |
securitynut
Sergeant

 Joined: Jul 11, 2007 Posts: 95 Location: USA
|
Posted: Tue Oct 30, 2007 2:48 pm Post subject: iedefender |
|
|
Attached below is a copy of IEdefender (hxxp://www.iedefender.com/) a new rogue software. I tried running it sandboxed but was unable to get it to run fully. I emailed it to kaspersky and they said it was clean... however I also sent it to Avira (antivir) and they concluded malware.
There is one topic currently in the Hijack this forum where this person is getting constant security popups saying he is infected and to download iedefender:
/t206255-HijackThis_log.html
a quick search on castlecops indicated that iedefender has just been added to the definitions for Ad-Aware SE and Trojan Hunter. virustotal results are clean except for VBA which is flagging it as:
suspected of Backdoor.Delf.180 (paranoid heuristics)
below find the results of Avira's investigation:
Dear Sir or Madam,
Thank you for your email to Avira's virus lab.
Tracking number: INC000934XX.
A listing of files alongside their results can be found below:
File ID Filename Size (Byte) Result
2229432 ieDefender-setup.exe 2.46 MB CLEAN
2230594 iedefender.exe 1.31 MB MALWARE
Please find a detailed report concerning each individual sample below:
Filename Result
ieDefender-setup.exe CLEAN
The file 'ieDefender-setup.exe' has been determined to be 'CLEAN'. Our analysts did not discovered any malicious content.
Filename Result
iedefender.exe MALWARE
The file 'iedefender.exe' has been determined to be 'MALWARE'. Our analysts named the threat SPR/Fake.IEDefender. The term "SPR/" ("Security or Privacy Risk") denotes a program that might possibly be able to affect the security of your system, might trigger activities you might not want or might violate your privacy.Detection will be added to our virus definition file (VDF) with one of the next updates.
So with all of this I would conclude that is it malware. Please add it to the listserv.
|
|
| Back to top |
|
 |
tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5800
|
|
| Back to top |
|
 |
iedefender
Trooper

 Joined: Nov 02, 2007 Posts: 17 Location: USA
|
Posted: Fri Nov 02, 2007 12:21 pm Post subject: |
|
|
Hello, we're developers of IEDefender, our software is clean and is real antispyware. As we can see, people from your site send our exe to different antivirus and antispyware companies, trying to black PR our company. They've got answers, that our soft is clean, because IT IS CLEAN! We contacted Kaspersky, they also confirmed, there are no problems with our software, you can check our .exe with any popular antiviruses, there no problems! Stop sending your detractive mails and messages, in other case we would be forced to send all information to our lawyers and meet your representative in the court, where it would be very hard for you to prove, that our software is not real, because IT'S REAL ANTISPYWARE!
|
|
| Back to top |
|
 |
TonyKlein
Site Moderator Microsoft MVP
 Joined: Oct 15, 2002 Posts: 13114 Location: Netherlands
|
Posted: Fri Nov 02, 2007 5:03 pm Post subject: |
|
|
| iedefender wrote: | | We contacted Kaspersky, they also confirmed, there are no problems with our software! |
Erm:
| Quote: | File ieDefender.exe received on 11.02.2007 17:57:17 (CET)
Current status: scanning finished
Kaspersky 7.0.0.125 2007.11.02 not-a-virus:FraudTool.Win32.IeDefender.a |
_________________ Tony CLSID List
Last edited by TonyKlein on Fri Nov 02, 2007 5:18 pm, edited 3 times in total |
|
| Back to top |
|
 |
nosirrah
Security Expert Special Response Team
 Joined: Apr 19, 2006 Posts: 6299 Location: USA
|
Posted: Fri Nov 02, 2007 5:05 pm Post subject: |
|
|
@ iedefender
Answer this directly .
If you are legit then why does malware advertise your software ?
|
|
| Back to top |
|
 |
MysteryFCM
Sergeant

 Joined: Feb 07, 2007 Posts: 125 Location: Tyneside, UK
|
Posted: Fri Nov 02, 2007 5:18 pm Post subject: |
|
|
| iedefender wrote: | | They've got answers, that our soft is clean, because IT IS CLEAN! |
Your "soft" may be clean, but your "antispyware" software is a rogue ..... and take me to court if you like. _________________ Regards
Steven Burn
Ur I.T. Mate Group / hpHosts
it-mate.co.uk / hosts-file.net
|
|
| Back to top |
|
 |
iedefender
Trooper

 Joined: Nov 02, 2007 Posts: 17 Location: USA
|
Posted: Sat Nov 03, 2007 1:52 am Post subject: |
|
|
| nosirrah wrote: | @ iedefender
Answer this directly .
If you are legit then why does malware advertise your software ? |
Yes, we know about this problem, we have a partnership for our distributors to advertise our program, we pay them a percent of registration fee. Some of them use illegal methods, that we not accept, our customers send us abuses about it and we closed some of our affiliates accounts without paying them. We are watching on it but there are problems with them sometimes. We're working on this problem and it's very sad for us. But just think if somebody would advertise any famous antiviruses this way would you add them to malware too?
|
|
| Back to top |
|
 |
iedefender
Trooper

 Joined: Nov 02, 2007 Posts: 17 Location: USA
|
Posted: Sat Nov 03, 2007 1:55 am Post subject: |
|
|
| MysteryFCM wrote: | | iedefender wrote: | | They've got answers, that our soft is clean, because IT IS CLEAN! |
Your "soft" may be clean, but your "antispyware" software is a rogue ..... and take me to court if you like. |
Oh, I see, you've tried our .exe file? May be you can describe us here, what our "antispyware" did at your computer? May be you can answer it here with all details? The only thing that it's doing is scanning computer and deleting spyware and malware from it. NOTHING else. We also make usual updates. Do you have another information? We would be very glad to hear it. And if you don't know anything about it and just want to criticise something here, than stop stop this EDIT.
PROFANITY REMOVED
|
|
| Back to top |
|
 |
MysteryFCM
Sergeant

 Joined: Feb 07, 2007 Posts: 125 Location: Tyneside, UK
|
Posted: Sat Nov 03, 2007 1:57 am Post subject: |
|
|
| iedefender wrote: | | nosirrah wrote: | @ iedefender
Answer this directly .
If you are legit then why does malware advertise your software ? |
Yes, we know about this problem, we have a partnership for our distributors to advertise our program, we pay them a percent of registration fee. Some of them use illegal methods, that we not accept, our customers send us abuses about it and we closed some of our affiliates accounts without paying them. We are watching on it but there are problems with them sometimes. We're working on this problem and it's very sad for us. But just think if somebody would advertise any famous antiviruses this way would you add them to malware too? |
MANY well known companies have been ripped to shreds for the same thing ....... but in your case, not only are you spamvertized via malware, a part of your own software is also detected as malware _________________ Regards
Steven Burn
Ur I.T. Mate Group / hpHosts
it-mate.co.uk / hosts-file.net
|
|
| Back to top |
|
 |
MysteryFCM
Sergeant

 Joined: Feb 07, 2007 Posts: 125 Location: Tyneside, UK
|
Posted: Sat Nov 03, 2007 2:10 am Post subject: |
|
|
| iedefender wrote: | | Do you have another information? We would be very glad to hear it. And if you don't know anything about it and just want to criticise something here, than stop stop this bullshit. |
How to win friends and influence people eh? ...... very well, fancy screenie's?
http://hosts-file.net/docs/imgIED_Ohdear.gif
http://hosts-file.net/docs/imgIED_Payupdammit.gif
Hows that ......? .... both of the file's you've detected as malicious are LEGIT! ... want proof of that?, ask Microsoft (after all, both file's were created by them!) _________________ Regards
Steven Burn
Ur I.T. Mate Group / hpHosts
it-mate.co.uk / hosts-file.net
|
|
| Back to top |
|
 |
iedefender
Trooper

 Joined: Nov 02, 2007 Posts: 17 Location: USA
|
Posted: Sat Nov 03, 2007 2:29 am Post subject: |
|
|
| MysteryFCM wrote: | | iedefender wrote: | | nosirrah wrote: | @ iedefender
Answer this directly .
If you are legit then why does malware advertise your software ? |
Yes, we know about this problem, we have a partnership for our distributors to advertise our program, we pay them a percent of registration fee. Some of them use illegal methods, that we not accept, our customers send us abuses about it and we closed some of our affiliates accounts without paying them. We are watching on it but there are problems with them sometimes. We're working on this problem and it's very sad for us. But just think if somebody would advertise any famous antiviruses this way would you add them to malware too? |
MANY well known companies have been ripped to shreds for the same thing ....... but in your case, not only are you spamvertized via malware, a part of your own software is also detected as malware |
Oh, really? Who detects it? You? Any proves? Tell us, what part of our software is malware? I see only bullshit from you, no proves and nothing else. All new messages without proves from you would be ignored, I want to talk with smart people not ones, who just want to spit here.
|
|
| Back to top |
|
 |
iedefender
Trooper

 Joined: Nov 02, 2007 Posts: 17 Location: USA
|
Posted: Sat Nov 03, 2007 2:32 am Post subject: |
|
|
| MysteryFCM wrote: | | iedefender wrote: | | Do you have another information? We would be very glad to hear it. And if you don't know anything about it and just want to criticise something here, than stop stop this bullshit. |
How to win friends and influence people eh? ...... very well, fancy screenie's?
http://hosts-file.net/docs/imgIED_Ohdear.gif
http://hosts-file.net/docs/imgIED_Payupdammit.gif
Hows that ......? .... both of the file's you've detected as malicious are LEGIT! ... want proof of that?, ask Microsoft (after all, both file's were created by them!) |
lol! our software also scan startups,if you would look at castlecops database you would find both entries, here they are:
/atxlist-1569.html
/s8025-msmsgs_exe.html
If you would have a license copy of our program you would know, that we didn't delete suspicious files and some malware, but only warn users about it with description of these files, so that they can choose if they want to delete it manually themselves. Any other questions? I still don't see any proves, that our software is malware or makes something bad.
|
|
| Back to top |
|
 |
nosirrah
Security Expert Special Response Team
 Joined: Apr 19, 2006 Posts: 6299 Location: USA
|
Posted: Sat Nov 03, 2007 2:38 am Post subject: |
|
|
And what of this site : http://85.255.121.126/scan/ .
Why do several other rogue scam scan sites look and function exactly like this ? Malware alarm and spy shredder have the exact same animated gif fake scans .
You are a liar and I can prove it . One of the sites on your server is exactly where the fake codec is that installs the trojan that advertises your scam software . Here are the three sites on your server :
Iedefender.com <- rogue software
Youlikehere.com <- installs the trojan that advertises your rogue
Ixworldpay.com <- likely your next scam
It is to damn bad that we have made it harder to scam people . Create legit software and this won't happen .
|
|
| Back to top |
|
 |
MysteryFCM
Sergeant

 Joined: Feb 07, 2007 Posts: 125 Location: Tyneside, UK
|
|
| Back to top |
|
 |
iedefender
Trooper

 Joined: Nov 02, 2007 Posts: 17 Location: USA
|
Posted: Sat Nov 03, 2007 2:47 am Post subject: |
|
|
| nosirrah wrote: | And what of this site : http://85.255.121.126/scan/ .
Why do several other rogue scam scan sites look and function exactly like this ? Malware alarm and spy shredder have the exact same animated gif fake scans .
You are a liar and I can prove it . One of the sites on your server is exactly where the fake codec is that installs the trojan that advertises your scam software . Here are the three sites on your server :
Iedefender.com <- rogue software
Youlikehere.com <- installs the trojan that advertises your rogue
Ixworldpay.com <- likely your next scam
It is to damn bad that we have made it harder to scam people . Create legit software and this won't happen . |
we have virtual hosting and some of our affiliates can use it too. may be you'll find some more scam there, do you want us to change hosting? are you trying to prove, that we use illegal advertising methods? I've already answered this question. We have affiliate program we don't allow affiliates to advertise our software this way, but there are some cheaters and we always delete their accounts as soon as we find them.
but why you are talking about malware? where did you find malware there?
|
|
| Back to top |
|
 |
|
|
|
You can post new topics in this forum You can reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You can attach files in this forum You cannot download files in this forum
|
Powered by phpBB © 2001 phpBB Group
|