SpywareIsolator
Sites used by this rogue:
Site Name: SpywareIsolator.com
IP Address: 72.233.50.150
Site Name: SpywareIso.com
IP Address: 72.233.63.89
Site Name: SpywareIsolator2008.com
IP Address: 72.233.63.94
Site Name: si-download.net
IP Address: 72.233.63.95
Sample: si-download(dot)net/ landing / distrib / installer_abr.exe
Sites used by this rogue:
Site Name: VirusIsolator.com
Site Name: Virus-Isolator.org
Site Name: Virus-Isolator.us
Site Name: VirusIsolator.us
IP Address: 217.170.77.150
Site Name: SecurityScannerSite.com
IP Address: 217.170.77.150
Site Name: Xpprotectionsoftware.com
IP Address: 72.233.81.234
Site Name: XPdownloadcenter.com
IP Address: 72.233.81.234
Sample: XPdownloadcenter(dot)com/download/xpa_eng.exe
Fileshreddersoftware.com also shares the IP 72.233.81.234 which is again a crapware they are exploiting Lavasoft’s application name “File Shredder”.
AntiVirus 2008
Site Name: AntiVirus-Scanner.com
IP Address: 190.15.73.254
Site Name: AntiVirus2008x.com
IP Address: 64.28.177.250
AntiSpywareDeluxe
Site Name: AntiSpywareDeluxe.com
IP Address: 67.205.75.9
This is a clone of AntiSpywareDeluxe rogue application.
Site Name: SpywareDestructor.com
IP Address: 67.205.75.9
This is clone of Cleanator Rogue security application. The home page of this rogue currently comes up blank.
Site Name: PcSweeperPro.com
IP Address: 72.55.156.207
Imunizator
Site Name: Imunizator.com
IP Address: 67.205.75.10
Imunizator is a clone of MacSweeper Rogue security application, All Mac user be aware of this rogue.
All the above mentioned sites are active and distributing rogues, Stay away from all of these sites.
Bharath M N