Saturday, December 8, 2007

freemoviepro.com

Freemoviepro.com
A malicious domain that spams, the download available on the site installs a malicious BHO.
The image displayed on the site:

BHO Details:

Filename: wbspark.dll
Hijack this entry: O2-BHO: wbspark - (BC42164F-2C53-1B42-1563-1A7624A24C11) - C: \WINDOWS\system32\wbspark.dll

SunBelt SandBox Result


Virustotal Scan Result: 18/32 (56.25%)


Stay away from this site.
Bharath M N

Thursday, December 6, 2007

Three More Malicious Domains

More Malicious Domains


Three More Malicious Domains on 58.65.238.130

Killspy.org
Liveprotection.net

Stopingspy.com


A few days back I had written about the four malicious sites on the server 58.65.238.130. Link

Now the server is hosting seven malicious sites distributing Rogue Security applications. The entire list:

1. Dr-protection.com
2. Guard-center.com
3. Killspy.org
4. Liveantispy.com
5. Liveprotection.net
6. Online-guard.net
7. Stopingspy.com

The download from three new sites was submitted to visrutotal.com and here are the results:

Virustotal Scan Result: 5/32 (15.63%)

AhnLab-V3 2007.12.6.2 2007.12.06 Win-Trojan/Spyshield.51200
Kaspersky 7.0.0.125 2007.12.06 not-a-virus:FraudTool.Win32.SpySheriff.f
Microsoft 1.3007 2007.12.06 Program:Win32/SpySheriff
Sophos 4.24.0 2007.12.06 Troj/DrProt-Gen
VirusBuster 4.3.26:9 2007.12.06 Adware.SpySherif.Gen.2

As you can see the detections are poor stay away from all these sites.

Bharath MN

AntiSpy-Pro.com

AntiSpy-Pro.com


This is a new rogue security application which is successor of IE Defender Rogue security application. The AntiSpy-Pro is an exact clone of IE Defender rogue security application.



IE Defender has a history of stealthily installing on the user system when they install Zlob codec. So AntiSpy-Pro will be the next Rogue security application that will be advertised through Zlob Trojans.




Snapshot of AntiSpy-Pro Application


The site details:
IP Address: 85.255.121.149
created on 2007-11-15
Name Servers: ns1.antispy-pro.com
ns2.antispy-pro.com

Warning message from the app:

If AntiSpy-Pro stealthily installs on your system then it’s sure that your system is infected by Zlob Trojan.

VirusTotal Scan Result: 3/32 (9.38%)

ClamAV - - Adware.Fakealert-21
Kaspersky - - not-a-virus:FraudTool.Win32.IeDefender.j
VBA32 - - suspected of Backdoor.Delf.180 (paranoid heuristics)

Stay away from this Rogue security application.

Bharath M N

Saturday, December 1, 2007

List of Malicious Domains

List of Malicious Domains
ghktoolkit.com - > Zlob trojan distributing site
zxcsolution.com -> Zlob trojan distributing site
codectime.com -> DNS Changer distributing site
codecvids.com -> Zlob trojan distributing site
217.20.122.32 -> a bunch of malicious files hosted on the site
Detection of the malicious files distributed by these sites are really poor.
Stay away from these sites...
Bharath M N

Tuesday, November 27, 2007

Yet another bunch of Rogue Security applications

Yet another bunch of Rogue Security applications


Currently there are four websites distributing clone of SpySheriff Rogue Security application. All the domains share the same IP address 58.65.238.130

Dr-protection.com



Application Screen Shot of Dr-protection


Guard-center.com

Application Screen Shot of Guard-center


Liveantispy.com



Application Screen Shot of Liveantispy



Online-guard.net

Application Screen Shot of Online-guard



Virus total Scan Results:

AhnLab-V3 2007.11.27.1 2007.11.27 Win-Trojan/Spyshield.51200
Kaspersky 7.0.0.125 2007.11.27 not-a-virus:FraudTool.Win32.SpySheriff.f
VirusBuster 4.3.26:9 2007.11.26 Adware.SpySherif.Gen.2

Detection of these Rogue security applications are poor, Stay away from these sites.

Bharath M N

Tuesday, November 20, 2007

Deuscleaneronline.com

Deuscleaneronline.com


Another Rogue Security application which looks similar to Drive Cleaner Application; The site uses the scare scan tactics to scare the user into purchasing the rogue application. The site registrar is ESTDOMAINS and it uses the IP 24.244.171.69 which is used by other malicious sites.

Detection of the Rogue is really poor. Avoid it at all cost...

Bharath M N

Monday, November 19, 2007

Another List of Zlob distributing Sites

Another List of Zlob Trojan distributing Sites
Stvfirm.com (85.255.118.179)
Ictmanufacture.com (85.255.113.234)
Ocnservice.com (85.255.115.178)
Xvsenterprise.com (85.255.115.179)
Bsplaycodec.com (64.28.184.180)
Detection of the installer from these sites is poor. Stay away from these sites.

Bharath M N

Saturday, November 17, 2007

ElseIf.biz

ElseIf.biz



Yet another site that is used to distribute Zlob Trojan; The site main page states that the domain is suspended; but surely is working as an active repository of Trojan files.


Usually the porn sites use the following fake alert to goad the user into downloading the fake video decoder.

Screenshot of the fake Error Message Box

ElseIf.biz uses the IP Address: 85.255.121.148; Detection of the download from this site is really poor. Stay away from malicious porn sites.


Avoid the site and all its downloads…

The website's name reminds me of the collage days where in we coded in C-language :-)

Code:
if(You are sensible not to download and install codec promoted by porn site)
{
Your system is safe and you need not worry about the Zlob Trojan infection
Exit from the porn trap;
}

else if(you install the codec)
{
Welcome to the world of Zlob infected PC's;
The Trojan will make sure to make you have a terrible experience;
Use tool to remove the infection;
Make a promise never to install a codec pushed from a porn site;
Finally exit from the porn trap;
}

else
{
Wait until the bad guys comes up with a new trick to trap you;
goto CODE
}

Isn’t it a funny code :-)


Bharath MN

Wednesday, November 14, 2007

VirProtect.com

VirProtect.com






Yet another Rogue Security application from SpyLocked group of Rogue security application.

VirProtect is the latest entry to the list; This Rogue is currently advertised by the latest Zlob Trojan. The site uses the IP 85.255.119.126 which is also used by virusray.com (Previous rogue security application released from this group)



Screenshot of the application.


Detection of the rogue is poor.


VirusTotal Scan Result: 7/31 (22.59%)

Avast 4.7.1074.0 2007.11.13 Win32:Spycrush-B
BitDefender 7.2 2007.11.13 Adware.SpyLocked.C
Ikarus T3.1.1.12 2007.11.13 Virus.Win32.Spycrush.B
Kaspersky 7.0.0.125 2007.11.13 not-a-virus:FraudTool.Win32.VirusProtectPro.h
Microsoft 1.3007 2007.11.12 Program:Win32/VirusLocker
Rising 20.18.11.00 2007.11.13 Hack.Win32.VirusProtectPro.a
VBA32 3.12.2.4 2007.11.11 Application.Win32.Adware.VirusProtectPro

Avoid it at all cost…

Bharath M N

Sunday, November 11, 2007

ErrorInspector.com

ErrorInspector.com


A hoax site distributing Rogue Security Application; webpage doesn’t provide any link to download the Application. This rogue Security application is also advertised through the Mediaplex(owned by ValueClick).

Screenshot of ads displayed for ErrorInspector by Mediaplex.


This site also uses the IP 84.243.253.220 which is used by many other Sellmosoft Inc Rogue Security Application.Some of the other Rogue security applications that used/uses this IP are:


1. Performanceoptimizer.com
2. Antivirussecuritypro.com
3. Cryptdrive.com
4. Windefender.com
5. ErrorDigger.Com


and many more. Detection on Virustotal is really poor. The application is related to winantivirus(dot)com family of Rogue Security Applications.

Sunbelt CWSandbox Analysis


Avoid it at all cost...


Bharath M N