
BHO Details:
Filename: wbspark.dll
Hijack this entry: O2-BHO: wbspark - (BC42164F-2C53-1B42-1563-1A7624A24C11) - C: \WINDOWS\system32\wbspark.dll
SunBelt SandBox Result



Posted by Bharath M Narayan at 7:10 PM View Comments
Stopingspy.com

Posted by Bharath M Narayan at 9:00 PM View Comments
This is a new rogue security application which is successor of IE Defender Rogue security application. The AntiSpy-Pro is an exact clone of IE Defender rogue security application.
Posted by Bharath M Narayan at 4:34 PM View Comments
Posted by Bharath M Narayan at 6:50 PM View Comments
Guard-center.com
Application Screen Shot of Guard-center
Liveantispy.com
Application Screen Shot of Liveantispy

Posted by Bharath M Narayan at 5:59 PM View Comments

Posted by Bharath M Narayan at 12:38 AM View Comments
Posted by Bharath M Narayan at 11:48 PM View Comments

Usually the porn sites use the following fake alert to goad the user into downloading the fake video decoder.

ElseIf.biz uses the IP Address: 85.255.121.148; Detection of the download from this site is really poor. Stay away from malicious porn sites.
Avoid the site and all its downloads…
The website's name reminds me of the collage days where in we coded in C-language :-)
Code:
if(You are sensible not to download and install codec promoted by porn site)
{
Your system is safe and you need not worry about the Zlob Trojan infection
Exit from the porn trap;
}
else if(you install the codec)
{
Welcome to the world of Zlob infected PC's;
The Trojan will make sure to make you have a terrible experience;
Use tool to remove the infection;
Make a promise never to install a codec pushed from a porn site;
Finally exit from the porn trap;
}
else
{
Wait until the bad guys comes up with a new trick to trap you;
goto CODE
}
Isn’t it a funny code :-)
Bharath MN
Posted by Bharath M Narayan at 1:51 AM View Comments

Yet another Rogue Security application from SpyLocked group of Rogue security application.
VirProtect is the latest entry to the list; This Rogue is currently advertised by the latest Zlob Trojan. The site uses the IP 85.255.119.126 which is also used by virusray.com (Previous rogue security application released from this group)
Screenshot of the application.

Detection of the rogue is poor.
VirusTotal Scan Result: 7/31 (22.59%)
Avast 4.7.1074.0 2007.11.13 Win32:Spycrush-B
BitDefender 7.2 2007.11.13 Adware.SpyLocked.C
Ikarus T3.1.1.12 2007.11.13 Virus.Win32.Spycrush.B
Kaspersky 7.0.0.125 2007.11.13 not-a-virus:FraudTool.Win32.VirusProtectPro.h
Microsoft 1.3007 2007.11.12 Program:Win32/VirusLocker
Rising 20.18.11.00 2007.11.13 Hack.Win32.VirusProtectPro.a
VBA32 3.12.2.4 2007.11.11 Application.Win32.Adware.VirusProtectPro
Avoid it at all cost…
Bharath M N
Posted by Bharath M Narayan at 12:06 AM View Comments


Posted by Bharath M Narayan at 2:54 AM View Comments