Monday, December 15, 2008
New rogue Security Applications
Posted by Bharath M Narayan at 11:48 AM View Comments
Wednesday, December 3, 2008
Wednesday, November 12, 2008
Friday, October 31, 2008
Win Defender 2009
Posted by Bharath M Narayan at 12:52 AM View Comments
Thursday, October 23, 2008
AntiSpyware XP 2009
Posted by Bharath M Narayan at 7:50 PM View Comments
Wednesday, October 22, 2008
Pro Antispyware 2009
Pro Antispyware 2009 is a new member of WinSpywareProtect family of rogue security applications.
More info here
Bharath M N
Posted by Bharath M Narayan at 8:21 PM View Comments
Monday, October 20, 2008
New Rogues from Innovagest 2000 group
Posted by Bharath M Narayan at 8:17 PM View Comments
Sunday, October 19, 2008
PC Defender 2008
PC Defender 2008 is a new rogue clone from Winifixer family.
More info here.
Bharath M N
Posted by Bharath M Narayan at 3:01 AM View Comments
Friday, October 10, 2008
Rogue Security application update
Posted by Bharath M Narayan at 9:33 PM View Comments
Monday, September 15, 2008
AntiVirus Lab 2009
More info here
Bharath M N
Posted by Bharath M Narayan at 10:06 PM View Comments
Friday, September 12, 2008
New Rogue Security applications
A list of the recent rogue security applications can be found here, here and here
Bharath M N
Posted by Bharath M Narayan at 4:38 AM View Comments
Zlob Site Updates
A update on recent Zlob trojan Distributing sites and its component sites can be found here, here and here
Bharath M N
Posted by Bharath M Narayan at 4:34 AM View Comments
Friday, September 5, 2008
Smart Antivirus 2009
Smart Antivirus 2009 is a new rogue security Application.
More info here
Bharath M N
Posted by Bharath M Narayan at 3:15 AM View Comments
Friday, August 29, 2008
Tuesday, August 26, 2008
SpywarePreventer
Site Name: SpywarePreventer.com
IP Address: 216.255.186.253
Bharath M N
Posted by Bharath M Narayan at 3:43 AM View Comments
Friday, August 22, 2008
Power Antivirus
Site Name: Pwrantivirus.com
IP Address: 91.208.0.231
IP address: 91.208.0.246
Bharath M N
Posted by Bharath M Narayan at 5:22 PM View Comments
XPert Antivirus Enterprise
Site Name: Xpertantivirus.com
IP Address: 91.208.0.230
IP address: 91.208.0.246
Stay away from these sites.
Bharath M N
Posted by Bharath M Narayan at 4:56 PM View Comments
Thursday, August 21, 2008
MS Antivirus
Site Name: Msantivirusxp.com
IP Address: 91.208.0.229
IP address: 91.208.0.228
Bharath M N
Posted by Bharath M Narayan at 8:06 PM View Comments
Sunday, August 17, 2008
XP-Guard
This group calls themselves as "Pandora Software" any Security related application from this group should be avoided.
Site Name: XP-Guard.com
IP Address: 92.62.101.35
Bharath M N
Posted by Bharath M Narayan at 8:13 PM View Comments
Antivir64
Site Name: Antivir64.com
IP Address: 78.157.142.7
Following sites belongs to the same group
Xpertantivirus.com
Pwrantivirus.com
Powerantivirus2009.com
Powerantivirus-2009.com
Defender-scan.com
Watcher-scan.com
Stay away from these sites.
Bharath M N
Posted by Bharath M Narayan at 3:35 PM View Comments
Saturday, August 16, 2008
Zlob sites update
Site Name: Mpegdirection.com
IP Address: 85.255.113.235
Site Name: Flwprocedure.com
IP Address: 77.91.231.201
Scam Internet Security Page:
Site Name: Homepagefile.com
IP Address: 85.255.116.212
404Errorpage Scam:
Site Name: Dnserrorgoal.com
IP Address: 85.255.118.244
Security Guide Scam Page:
Site Name: Shortcutclicks.com
IP Address: 85.255.118.210
Ad-Server-Gate Pages:
Site Name: Opqgrin.com
IP Address: 85.255.118.211
Site Name: Trefuel.com
IP Address: 85.255.118.214
The Ad-Server-Gate pages redirects to fake Security center site Secureonlinetags.com which promotes Rogue security applications.
Site Name: Secureonlinetags.com
IP Address: 85.255.118.211
Other component sites:
Site used in the Internet Explorer tools menu to redirect to fake/scare scanner pages
Site Name: Iexplorerfiles.com
IP Address: 216.255.179.244
The following site is used in Zlob toolbar to redirect users to malicious domains distributing rogue security applications.
Site Name: Clickstoolbar.com
IP Address: 85.255.118.214
All the above mentioned sites advertise/push well documented Rogue security applications. Stay away from these sites.
Bharath M N
Posted by Bharath M Narayan at 3:00 PM View Comments
Friday, August 15, 2008
Monday, August 11, 2008
Internet Antivirus
Site Name: Internet-Antivirus.com
IP Address: 216.32.69.165
IP Address: 216.32.69.162
Following sites also belongs to the same family
Site Name: IA-Payment.com
Site Name: IA-License.com
Site Name: IA-Support.com
IP Address: 216.32.69.165
The rogue is pretty new detections of this rogue is really poor. Stay away from all these sites.
Bharath M N
Posted by Bharath M Narayan at 6:49 PM View Comments
Saturday, August 9, 2008
Antispyware 2008 XP
Site Name: Antispyware2008scanner.com
IP Address: 85.255.119.149
Site Name: AS2008dl.com
IP Address: 85.255.118.69
Reference links: dwl.as2008dl. com/load/setup_100542_4_.exe
Which furthers downloads the application from the following site
Site Name: Getas2008xp.com
IP Address: 85.255.119.132
Reference links: dl.getas2008xp. com/get/?type=scanner&pin=100542&lnd=4
Further there are many other sites that is used by this family of rogue security application. Below is a list of sites that belongs to this family.
Stay away from all these sites.
IP Address Site Name
85.255.118.226 Wspldrept.com
85.255.118.226 Wspexrept.com
85.255.119.154 Wspreprt.com
85.255.119.26 Winspywareprotection.com
64.28.185.138 Winspywareprotect2008.com
85.255.119.30 Av2008sales.com
85.255.119.158 Avcntxp.com
85.255.119.158 Avcntxp.com
85.255.119.150 Av2008check.com
85.255.119.156 As2008rep.com
85.255.119.29 Antispywaresales.com
85.255.118.228 Woeiruweoriu.com
85.255.118.227 Idreptavxp.com
Bharath M N
Posted by Bharath M Narayan at 8:51 PM View Comments
Wednesday, August 6, 2008
Malware distributing sites
Site Name: Flwinstrument.com
IP Address: 77.91.231.183
Site Name: Mpegutility.com
IP Address: 85.255.113.236
Trojan-Downloader Distributing sites
Site Name: Pressdownloadtostart.com
IP Address: 91.203.92.53
The Trojan installs the following Malicious BHO
O2 - BHO: Gold Manager - {D26AAB3B-B0DD-456C-A7E5-4DA9565FD6EE} - C:\WINDOWS\system32\goldman.dll
Site Name: Clickruntostartshow.com
IP Address: 91.203.92.53
The Trojan installs the following Malicious BHO
O2 - BHO: IE Optimizer - {BACA5B3B-DD57-4E62-B986-9A5677FBF001} - C:\WINDOWS\system32\iea32.dll
This site belongs to IE-defender family and the BHO is used to push IE-Antivirus which is a well documented rogue security application.
MediaTubeCodec Trojan Distributing site:
Site Name: Megabestsoftnah08.com
IP Address: 78.157.143.250
DNS Changer Trojan Distributing site:
Site Name: Ticketmoon.net
Site Name: Ticketlight.com
Site Name: Red-codec.net
Site Name: Nitrocodec.net
Stay away from all these sites.
Bharath M N
Posted by Bharath M Narayan at 11:00 PM View Comments
Sunday, August 3, 2008
More Rogue Security applications
PyroAntiSpy is new rogue security application from SpyLocked family of Rogue security applications.
Thanks to Donna for the information
Site Name: Pyroantispy.com
IP Address: 207.226.174.20
IP Address: 207.226.174.20
Antivirus 2008 XP is a rogue security application. Antivirus 2008 XP is a clone of WinSpywareProtect rogue security application
Site Name: Antivirus2008xp.com
IP Address: 216.195.50.93
IP Address: 85.255.119.150
Site Name: Av2008dl.com
IP Address: 85.255.118.70
Reference links: dwl.av2008dl. com/load/setup_1_2_.exe
Which furthers downloads the application from the following site
Site Name: Av2008store.com
IP Address: 85.255.119.134
Reference links: dl.av2008store. com/get/?type=scanner&pin=1&lnd=2
Stay away from all these sites.
Bharath M N
Posted by Bharath M Narayan at 5:18 PM View Comments
Friday, August 1, 2008
Zlob sites update
Site Name: Mpegversion.com
IP Address: 85.255.113.237
Scam Internet Security Page:
Site Name: Dryhomepage.com
IP Address: 85.255.116.214
404Errorpage Scam:
Site Name: Dnswebpage.com
IP Address: 85.255.118.246
Security Guide Scam Page:
Site Name: Topsafetysoft.com
IP Address: 85.255.118.214
Ad-Server-Gate Pages:
Site Name: Abcways.com
IP Address: 85.255.118.35
Site Name: Xyztogo.com
IP Address: 85.255.118.34
The Ad-Server-Gate pages redirects to fake Security center site Webbestlink.com which promotes Rogue security applications.
Site Name: Webbestlink.com
IP Address: 85.255.118.214
Other component sites:
The following site is used in Internet Explorer tools menu to redirect users to fake/scare scanner pages
Site Name: Iexplorerclue.com
IP Address: 216.255.179.244
The following site is used in Zlob toolbar to redirect users to malicious domains distributing rogue security applications.
Site Name: Websecurebar.com
IP Address: 85.255.118.213
All the above mentioned sites advertise/push well documented Rogue security applications. Stay away from these sites.
Bharath M N
Posted by Bharath M Narayan at 2:42 AM View Comments
Thursday, July 31, 2008
Power Antivirus 2009
Heads up to Jason for the information.
Site Name: Power-antivirus-2009.com
IP Address: 91.208.0.233
Bharath M N
Posted by Bharath M Narayan at 2:56 AM View Comments
Wednesday, July 30, 2008
A list of Malicious sites
Site Name: Releasedvideo.com
IP Address: 77.91.231.201
Site Name: Videoexternal.com
IP Address: 85.255.120.110
Zlob Component sites:
Site Name: Ihatemondayand.com
IP Address: 85.255.117.204
www.Ihatemondayand. com/get.php?partner= -> downloads Antispycheck Rogue security application
Scare/Fake scanner page:
Site Name: Scan.Wsp2008scanner.com
IP Address: 85.255.119.146
The installer is downloaded from the following site:
Site Name: Dwl.getwsp.com
IP Address: 85.255.118.66
SpyShedder rogue distributing site
Site Name: Shredder-scan.com
IP Address: 91.208.0.243
WinXDefender rogue distributing site
Site Name: Win-x-defenders.com
IP Address: 91.208.0.243
The site Win-x-defender.com also shares the same IP Address.
Win Antivir 2008 is the latest rogue security application from SpywareNo/SpySheriff family. Its a near clone of WinXSecurityCenter rogue security application.
Site Name: Win-antivir-2008.com
IP Address: 91.208.0.234
Win Antivirus 2008 is a near clone of Win Antivir 2008 rogue security application.
Site Name: Win-antivirus-2008.com
IP Address: 91.208.0.253
WinDefender 2008 is a rogue security application.
Site Name: Win-defender.com
IP Address: 207.226.179.162
Site Name: Trafficrotator.net
IP Address: 207.226.179.165
Reference: Trafficrotator. net/MTAwNg== which further redirects to one of the following Scare/Fake scanner sites
Site Name: Internetscannerlive.com
Site Name: Netscannerlive.com
Site Name: Webscanneronline.com
IP Address: 207.226.179.163
The following sites are also involved in distributing WinDefender 2008 rogue security application
Site Name: Dns-problem.com
IP Address: 207.226.179.147
Dns-problem. com site is a fake DNS error page which redirects to WinDefender 2008 registration page. Heads up to Malekal for posting it
Site Name:Registerwindefender.com
IP Address: 207.226.179.148
Stay away from all these sites.
Bharath M N
Posted by Bharath M Narayan at 3:01 AM View Comments
Sunday, July 27, 2008
TheSpyBot Promo site
Site Name: TheSpyBotpromo.com
IP Address: 207.176.7.6
Registrar: ESTDOMAINS, INC.
Bharath M N
Posted by Bharath M Narayan at 10:43 PM View Comments
Wednesday, July 23, 2008
Malware distributing sites
Site Name: Iwillseethatvideo.com
IP Address: 91.203.92.53
The Trojan installs the following Malicious BHO
O2 - BHO: BHO.ext2 - {401F4B6B-3C36-4E8D-BC07-F46FC6D67D9A} - C:\WINDOWS\system32\ieflt.dll
Site Name: Comeforvidsoft.com
IP Address: 91.203.92.53
The Trojan installs the following Malicious BHO
O2 - BHO: search toolbar - {7D76D0EB-AE56-4DF4-AFFC-20AFF4344AC6} - C:\WINDOWS\system32\tbsrch.dll
These sites belongs to IE-defender family and the BHO is used to push IE-Antivirus which is a well documented rogue security application.
MediaTubeCodec Trojan Distributing site:
Site Name: Best-soft-maxi.com
Site Name: Best-freeware2008.com
Site Name: Soft2008freeware.com
IP Address: 91.203.70.18
Stay away from these sites.
Bharath M N
Posted by Bharath M Narayan at 4:09 AM View Comments
Zlob sites update
Site Name: Formatmpeg.com
IP Address: 77.91.231.183
Site Name: Mpegstandard.com
IP Address: 85.255.120.108
Scam Internet Security Page:
Site Name: Otherhomepage.com
IP Address: 85.255.116.212
404Errorpage Scam:
Site Name: Adnsline.com
IP Address: 85.255.118.242
Security Guide Scam Page:
Site Name: Secureshortcuts.com
IP Address: 85.255.118.37
Which uses the following Scare/Fake scanner pages to promote rogue security application
Windows-virus-scanner.com -> A fake scanner promoting Antivirus 2009 rogue security application
Online-xpcleaner.com ->A fake scanner promoting XP cleaner a bogus/rogue cleaner software
Site Name: Asgates.com
IP Address: 85.255.118.214
Site Name: Qwgates.com
IP Address: 85.255.118.212
The Ad-Server-Gate pages redirects to fake Security center site Allsecurenews.com which promotes Rogue security applications.
Site Name: Allsecurenews.com
IP Address: 85.255.118.213
Other component sites
Site Name: Browseroption.com
IP Address: 216.255.179.244
http://www.Browseroption(dot)com/redirect.php -> redirects to scan.wspscanner.com, which is a fake/scare scan page used to push WinSpywareProtect rogue security application.
All the above mentioned sites advertise/push well documented Rogue security applications. Stay away from these sites.
Bharath M N
Posted by Bharath M Narayan at 2:33 AM View Comments
Antivirus Master
Site Name: Anvimaster.com
IP address: 91.208.0.240
Site Name: Anvi-scanner.com
IP address: 91.208.0.252
Here is the list of such sites:
Site Name: Vav-scan.com
Site Name: Vav-scanner.com
Site Name: Vavscan.com
Site Name: Vav-xscanner.com
Site Name: Vav-x-scanner.com
Vitae Antivirus 2008 is also clone of the above said rogue
Site Name: Vit-scanner.com
Site Name: Vit-xscanner.com
Site Name: Vit-x-scanner.com
Bharath M N
Posted by Bharath M Narayan at 1:52 AM View Comments