Unlike the previous "As Seen on TV" computer product I tested, this appears to be a fairly decent tool for removing malware.
rogueamp
Example commercial: youtube.com/watch?v=5BwRKKAnD_Y
Unlike the previous "As Seen on TV" computer product I tested, this appears to be a fairly decent tool for removing malware.
Unlike the previous "As Seen on TV" computer product I tested, this appears to be a fairly decent tool for removing malware.
updated 11 years ago
Unlike the previous "As Seen on TV" computer product I tested, this appears to be a fairly decent tool for removing malware.
O fuck you guys rogueamp is back on the viruses for you today I got a sample of the big ransom ware thing that attacked all the chinese people and the brit bong hospials. This video will show you how to remove the malware maybe save your company????
Greets to MalwareHunterTeam and all the homies on malwaretips.com who made this video possible.
Also quick announcement malwareup.org is now back up so everybody go check it out at http://malwareup.org
This video is being managed exclusively by Newsflare. To use this video for broadcast or in a commercial player go to: newsflare.com/video/139949/other/april-2016-update-and-sick-dashcam-footy-of-me-flipping-my-car-while-drifitng or email: contact@newsflare.com or call: +44 (0) 20 3937 6280
Great analysis of the trojan here: http://researchcenter.paloaltonetworks.com/2016/03/new-os-x-ransomware-keranger-infected-transmission-bittorrent-client-installer
Business Insider article about this video: http://www.businessinsider.com/what-its-like-to-be-infected-with-keranger-ransomware-for-os-xmacs-2016-3
Cause somebody is gonna ask: http://j-walkispissed.bandcamp.com/album/assqu-ke
KeRanger is a file encrypting ransomware trojan hidden inside of a compromised copy of Transmission that runs on Mac OS X. As of the Sixth Day of March in the Year of our Lord two thousand and Sixteen there is not a free decryption tool for KeRanger encrypted files.
A somewhat annoying toolbar with a password generator and bookmarks.
For a more in depth analysis: http://www.bleepingcomputer.com/news/security/the-locky-ransomware-encrypts-local-files-and-unmapped-network-shares
As of the Twentieth Day of February in the Year of our Lord two thousand and Sixteen there is no known way to decrypt files affected by Locky. When this changes, I will update the description accordingly.
Much like the video from a couple weeks ago, this trojan is bundled with some type of freeware and pretends to be a core Windows function. The infected user is instructed to call a phone number that pretends to be Microsoft support, where they will be charged a fee to fix their computer. Its an interesting branch away from highly sophisticated malware that can steal information and remain undetected.
Jukin Media Verified (Original)
* For licensing / permission to use: Contact - licensing(at)jukinmediadotcom
http://www.bitdefender.com/solutions/total-security.html
There's not too much I can say in the description that isn't in the video, so if you have 40 minutes to kill feel free to watch. I have sort of mixed feelings about this software suite. While this does make sense for certain people (at the right price), I just don't think its the best solution for everyone.
This video shows a very simple trojan designed to scare the user into calling a scam service pretending to be a support hotline for Microsoft. Like many trojans of this type, the software itself is very crude; however, if it causes a victim to pay the scammers to "activate" Windows the scheme is an overall success.
A week or so ago someone asked me if I could show how to avoid infecting yourself when testing malware in a virtual machine, so instead of answering that question I decided to make a long ass video. The information is buried in there somewhere, don't worry.
Links:
VMWare Workstation (latest version): http://www.softpedia.com/get/System/OS-Enhancements/VMware-Workstation.shtml
VMWare Workstation 11: http://en.softonic.com/s/vmware-workstation-11
see title
stream channel: http://www.hitbox.tv/ampdan2
time zone stuff: http://www.timeanddate.com/worldclock/fixedtime.html?msg=Ampdan1+24+Hour+Livestream+Extravaganze&iso=20150522T15&p1=875&ah=23&am=55
countdown: http://www.timeanddate.com/countdown/generic?p0=875&iso=20150522T15&msg=Ampdan1%2024%20Hour%20Livestream%20Extravaganze
This is a clone of an older series of rogues that appears to have interesting effects in the 10026 build of Windows 10 Technical Preview. Removal was fairly easy once I figured out what I was doing.
1. Boot into Safe Mode with Networking (http://www.computerhope.com/issues/chsafe.htm)
2. Download MBAM Free (malwarebytes.org/mwb-download)
3. Install MBAM
4. Run a Threat Scan
5. Apply Actions
6. Reboot
New rogue, same old grammatical errors. Not terribly difficult to remove either. Skip to 5:44 for removal instructions.
1. Boot into Safe Mode with Networking (http://www.computerhope.com/issues/chsafe.htm)
2. Download MBAM Free (malwarebytes.org/mwb-download)
3. Install MBAM
4. Run a Threat Scan
5. Apply Actions
6. Reboot
Download the legitimate version of AdwCleaner from http://www.bleepingcomputer.com/download/adwcleaner
This is a very interesting fake antimalware program that attempts to leverage the popularity of AdwCleaner. Unlike most fake antivirus scams, this one is made in Visual Studio and uses Paypal to process payments.
PClock Removal Tool: http://emsi.at/DecryptPClock
More name hijacking from the Braviax family. This is a direct copy of Sirius/Zorton except with a name change. Removal instructions are still the same:
1. Boot into Safe Mode with Networking (http://www.computerhope.com/issues/chsafe.htm)
2. Download MBAM Free (malwarebytes.org/mwb-download)
3. Install MBAM
4. Run a Threat Scan
5. Apply Actions
6. Reboot
Back again with Braviax. This is a direct copy of Sirius/Zorton except with a name change. Removal instructions are still the same:
1. Boot into Safe Mode with Networking (http://www.computerhope.com/issues/chsafe.htm)
2. Download MBAM Free (malwarebytes.org/mwb-download)
3. Install MBAM
4. Run a Threat Scan
5. Apply Actions
6. Reboot
Possible names include:
AVbytes XP Antivirus 2015
AVbytes Vista Antivirus 2015
AVbytes Win 7 Antivirus 2015
AVbytes Win 8 Antivirus 2015
AVbytes XP Protection 2015
AVbytes Vista Protection 2015
AVbytes Win 7 Protection 2015
AVbytes Win 8 Protection 2015
Another week, another clone. This is a direct copy of Rango/Sirius except with a name change. Removal instructions are still the same:
1. Boot into Safe Mode with Networking (http://www.computerhope.com/issues/chsafe.htm)
2. Download MBAM Free (malwarebytes.org/mwb-download)
3. Install MBAM
4. Run a Threat Scan
5. Apply Actions
6. Reboot
More clones from the Braviax family again. This is a direct copy of Sirius except with a name change. Removal instructions are still the same:
1. Boot into Safe Mode with Networking (http://www.computerhope.com/issues/chsafe.htm)
2. Download MBAM Free (malwarebytes.org/mwb-download)
3. Install MBAM
4. Run a Threat Scan
5. Apply Actions
6. Reboot
Possible names include
Zorton XP Antivirus 2014
Zorton Vista Antivirus 2014
Zorton Win 7 Antivirus 2014
Zorton Win 8 Antivirus 2014
Zorton XP Protection 2014
Zorton Vista Protection 2014
Zorton Win 7 Protection 2014
Zorton Win 8 Protection 2014
Since this rogue is a direct clone of Windows AntiVirus Adviser, I am only making a quick removal guide.
1. Boot into Safe Mode with Networking (http://www.computerhope.com/issues/chsafe.htm)
2. Download MBAM Free (malwarebytes.org/mwb-download)
3. Install MBAM
4. Run a Threat Scan
5. Apply Actions
6. Reboot
Since this rogue is a direct clone of Rango 2014, I am only making a quick removal guide.
Possible names for this rogue include:
Sirius XP Antivirus 2014
Sirius Vista Antivirus 2014
Sirius Win 7 Antivirus 2014
Sirius Win 8 Antivirus 2014
Sirius XP Protection 2014
Sirius Vista Protection 2014
Sirius Win 7 Protection 2014
Sirius Win 8 Protection 2014
1. Boot into Safe Mode with Networking (http://www.computerhope.com/issues/chsafe.htm)
2. Download MBAM Free (malwarebytes.org/mwb-download)
3. Install MBAM
4. Run a Threat Scan
5. Apply Actions
6. Reboot
*Sorry for the reupload, the other one managed to get corrupted.
Back again with another new fake antivirus: Windows AntiVirus Adviser. By forcing the fake antivirus window on top, Adviser is a bit more aggressive than most fake antivirus programs today. Thankfully removal is still fairly simple:
1. Boot into Safe Mode with Networking (http://www.computerhope.com/issues/chsafe.htm)
2. Download MBAM Free (malwarebytes.org/mwb-download)
3. Install MBAM
4. Run a Threat Scan
5. Apply Actions
6. Reboot
*Sorry about the frame rate suckage, still trying to get this capture card to work properly
Stealing its name from an Ocsar-winning movie, Rango XP/Vista/Win 7/Win 8 Protection/Antivirus/Antispyware 2014 is a direct copy of a previous rogue with a similar naming scheme. Rango blocks Task Manager usage and web browsing, among other annoyances. Thankfully, removal of this fake antivirus program is trivial:
1. Boot into Safe Mode with Networking (http://www.computerhope.com/issues/chsafe.htm)
2. Download MBAM Free (malwarebytes.org/mwb-download)
3. Install MBAM
4. Run a Threat Scan
5. Apply Actions
6. Reboot
In today's video I take a look at a fake antimalware application for Android, which turns out to be a ransomware program called ScarePackage. The app is fairly broken, so removal is trivial.
Added blur filter per Malwarebytes' request.
The original video about the copyright strike is unlisted: http://youtu.be/pNJsXLwU_Wo
New video (Model M Buyer's Guide): http://youtu.be/ae-8GdSJTX8
For the first time in a few months I take a look at a new fake antivirus program which mimics a 2013 rogue's naming scheme. This one, dubbed Multirogue 2014 by SiR!, changing its name based on what operating system it is installed on (mine decided to be named Win 8 Antispyware 2014).
The possible names are:
XP Antivirus 2014
XP Antispyware 2014
XP Protection 2014
Vista Antivirus 2014
Vista Antispyware 2014
Vista Protection 2014
Win 7 Antivirus 2014
Win 7 Antispyware 2014
Win 7 Protection 2014
Win 8 Antivirus 2014
Win 8 Antispyware 2014
Win 8 Protection 2014
Removal of this rogue is fairly easy, and the instruction are as follows:
1. Boot into Safe Mode with Networking (http://www.computerhope.com/issues/chsafe.htm)
2. Download Malwarebytes' Anti-Malware from here: malwarebytes.org/mwb-download
3. Install MBAM
4. Run a Threat Scan
5. Reboot
new actual video coming whenever i get this microphone problem figured out
something to kick back and smoke a joint to
Apologies for the slightly off sounding audio, I had to use noise removal due to some weird clicking sound that got picked up by the microphone.
Today I take a look at a laundry list of registry cleaners, antispyware programs, video converters, and other software that can be classified as Potentially Unwanted Programs, or just crapware. Thanks to Porshepaj for the suggestion! Below is the set list:
McAfee Security Scan Plus
WinZip Malware Protector
RegCurePro
PC HealthBoost
ArcadeGiant
VideoPerformer
SearchProtect
PC Performer
PassShow
MyCleanPC
SpyZooka
PC Cleaner (sponsored by BleepingComputer.com)
SpyHunter
Cloud System Booster
Data File Host downloader
Optimizer Pro
LiveSupport
Trovi Search
Wise Care 365
DLL-files Fixer
PC Power Speed Optimizer
SparkTrust PC Cleaner Plus (sponsored by BleepingComputer.com)
Grand Finale
http://threatpost.com/rig-exploit-kit-pushing-cryptowall-ransomware/106540
After a several week hiatus, I take a brief look at the Cryptolocker-inspired file encrypting ransomware Cryptowall. The concept is pretty much the same, other than having the user pay through a Tor website and only in Bitcoin. Although previous versions of CryptoDefense mistakenly left the encryption keys on the host computer, this version does not have that convenience, and decryption as of now is not possible. However, Cryptowall does not affect System Restores, so restoring a previous version of a file is possible.
In today's video I take a look at a new ransomware trojan for Android called Koler. Koler very closely resembles the Reveton/Moneypak desktop locking ransomware found on Windows. When closed, Koler will open its block page every few seconds, making device use nearly impossible. While not always feasible, it is possible to open some type of task manager and kill the "BaDoink" process.
I apologize for the lack of videos lately, I've been pretty busy with classes and the semester ending so I haven't had much time to make these videos.
S!Ri's blog: http://siri-urz.blogspot.com
My DOGE wallet address: DGxtCo29jrpDM3wPtctZc4emNtcCpofzFa
Original video (ask questions here): youtube.com/watch?v=sQBArZCS40E
I'm back again, no guessing or checking with 30 more of your questions and 30 answers to those questions.
By viewer request I take a very brief look at some browser based ransomware. Similar to other "FBI Ransomwares", the Browlock trojan claims to be from the FBI (or another law enforcement agency depending on location), falsely alerts the victim that they are going to be arrested soon, and demands payment via MoneyPak to make the charges go away. Removal of this trojan is trivial: closing and holding down the Enter button in Internet Explorer closes the web page. Chrome and Firefox are able to close the site with only one dialog box.
For the first time in almost four months I take a look at a new fake antivirus called Futurro. Although it has an interesting name and a primitive interface, it does pretty well at blocking most programs.
Removal is pretty easy, but as always here are the instructions:
1. Restart your computer and boot into Safe Mode with Networking
2. Navigate to http://downloads.malwarebytes.org/mbam-download.php to download MBAM
3. Install Malwarebytes' Anti-Malware. You do not need to enable the free trial.
4. Update MBAM
5. Run a Quick Scan
6. Remove Selected
7. Reboot.


