I want to be infected

Smitty74

New Member
Reaction score
0
Everybody,

I am trying to evaluate different malware removal tools on system that I dont mind getting infected, Maybe get a few screen captures while I am at it. The problem is finding the malware to install. Its amazing to me that I cant find a single reliable place to get my test computer infected.

Does anybody know of a website that hosts these programs for testing purposes? In particular I am looking for a copy of SpywareGuard 2008, but any others would be appreciated.


Before you say it, I realize this post sounds a little sado-masochistic, but my intentions are good. hehe
 
Yea getting infected isn't as easy as one might think..It took me about a week to get my virtual machine infected. I finally ended up installing a Trojan dropper that I downloaded from a crack site, shortly afterwords I had AV 2009, 2008, XP, Spyware Guard, Vundo, Vundo.H, TDSS, and about 20 others.

The file I downloaded was named "spyware_guard_2008_key.exe" I'm sure with a little luck you can locate it.
 
I seem to have to same problem I can't ever seem to get infected if I want too either. Your best bet is to try downloading torrents from piratebay or mininova that other uses say is a virus.
 
Does anybody know of a website that hosts these programs for testing purposes? In particular I am looking for a copy of SpywareGuard 2008, but any others would be appreciated.

Shoot, had I seen this yesterday I could have sent it to you. I removed it without taking any of the files with me... Sorry.

Try here... See if these guys will help you. http://www.offensivecomputing.net/?q=node/1011

Also check this... Just for fun! http://www.youtube.com/watch?v=NPSJTVB3UAA
 
i hope this helps milw0rm.com please use at your on risk you can download millions of viruse trojans and spyware.
you can also get them here leetupload.com/members/Virii/
 
Last edited:
What's happening to alot of people is that they are infecting themselves with trojans like fake flash plugins or players.

For example, if you go to this site: WARNING THE FOLLOWING SITE IS A HARDCORE PORN WEBSITE THAT WILL TRY TO GET YOU TO DOWNLOAD A TROJAN/VIRUS TO INFECT YOUR COMPUTER:

http://www . megatubexxx . net/tube/todo/3176/bigtits/2

(note you will have to remove the spaces above to make the link work. I didnt want to put up an functional link that could be clicked.

You will see this:

1) Appears to be a "PornTube" website with hardcore videos. You will see that alot of the nav links at the top do not work and things like comments are non-functional.
2) When you click on any of the videos it will appear to be trying to play but it will ALWAYS tell you that you need a flash upgrade. A video (usually not the one you clicked) appears to be trying to play but there is "noise" moving back and forth which makes it appear as if you are having trouble with your flash player.
3) If you click on the flash upgrade you will actually download one of the latest variants of the virus/spyware/trojans that are going around now. I have seen some where it will just download on others it will actually install as soon as you click. DO NOT CLICK ON THAT FLASH UPGRADE LINK, YOU WILL LIKELY BECOME INFECTED IMMEDIATLY. Sometimes these sites will even try to warn you that you are infected if you do NOT click on the link and then will try to get you to download a fake antivirus instead. SO CHECK THIS SITE OUT AT YOUR OWN RISK.

The fact that so many machines are coming into our shop with the same infections tells me that most are coming from this type of infection process.
We have infected a few machines here to see what happens and it almost always is the same.

Domains like megatubexxx are usually only days or weeks old, so if you do a "whois" you will see they are very recent registrations.

We have cleaned up computers infected in this manner only to have the same machines come back weeks later, re-infected with the same viruses. Often we can find the offending porn website name in the browser history.
 
Last edited:
Try this...
www dot xewibudar dot com/michael-newdow.html

Definitely a rogue of some sort... Can't guarantee what you'll get though.
 
spyware site

Hi,
ran across this site yesterday, if your interested.
hxxp://antispyscanner13.com
site hosts System Guard 2009. wonder how may people click OK and let it install?
 
i tried using the link but avg blocks it.
picture.php
 
Hi,
ran across this site yesterday, if your interested.
hxxp://antispyscanner13.com
site hosts System Guard 2009. wonder how may people click OK and let it install?

hello, i have the same antispyscanner13.com on my computer as a pop up. the full URL is hxxp:// antispyscanner13.com/ sysgd09_2/3/10176 I have ran several malware removers and virus scans but cannot get rid of it. my computer knowledge does not expand beyond getting anti viruses etc so I am getting rather frazzled. Does anyone know what this pop up is attributed to or what i can do to prevent it? PLEASE HELP!!:confused:
 
hxxp://antispyware dot com/index.php?hop=wrldslrgst

Came across the above link when searching about removing viruses. If you click to download you will get antispyware 2009. You can save the file first, but run it, and all hell will break loose.
 
hi all' I had some fun today with the antispyware 2009 guys this was my email to them.


please I need help removing "antivirus 2009" from my computer will your product do that for me.

Abe

I will write a review about your product on my blog.

this is my first email from them I think I'm gonna have some more fun with them later today,


Re: Unregistered Inquiry
From: Antispyware - Support
To: *********@yahoo.com
Date: Fri Feb 06 09:47:30 2009
Hi,
Have you purchased Antispyware?May I have your bank number please?
--
For any further questions please reply to this email address and include
all previous messages in the email.

Regards,
Charles
The Antispyware Support Team
----------------------------
How am I doing? Email my supervisor David Page at: feedback.vmg@gmail.com
with any feedback. Please use this address only for feedback as it is not
monitored 24/7 and all support requests sent to the address will be moved.


I will then link them to this page and to my "blog" and show them what I think of them.

Abe
 
I dunno if sending them the link to this site is such a good idea. We're technically always playing catch-up to the Malware writers and by sending them a link to this thread (and this site), you'd basically be handing them every virus removal process used by techs on here over to the bad guys, and I'd really prefer them NOT to know what methods I use to clean their crap up. (I'm sure they'll find out sooner or later how some of us try to avoid the nuke and pave method, but I'd much rather it be later than sooner, if possible.)

Just my $.02
 
true, didn't think of that so I will not send it,
but I think they are smarter then that, I'm sure they know the removal procedures we use. they don't care if you can remove it what they want is to get the clients, (our customers) ,to pay for it before we get there and tell them its rouge.

Abe
 
Smarter than that?? Have you re-read their e-mail response again lately?

Re: Unregistered Inquiry
From: Antispyware - Support
To: *********@yahoo.com
Date: Fri Feb 06 09:47:30 2009
Hi,
Have you purchased Antispyware?May I have your bank number please?

I feel bad for us when someone that is well spoken and highly educated actually decides to do this kind of crap... well maybe not feel bad for us, since we'll make a lot of money cleaning it up.

LoL, that's like tire repair shops in small towns throwing nails in the middle of the road a mile outside of town. Maybe the makers of these Rogue's are really the guys behind GeekSquad and Firedog, just creating themselves extra business.
 
Back
Top