Archive for August 20th, 2008

AdWare Alert fake antispyware application

Wednesday, August 20th, 2008

AdWare Alert is a fake antispyware application. DO NOT download any software from domain(s) of AdWare Alert.

AdWare Alert

File setupxv.exe received on 08.20.2008 15:39:33 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.8.19.0 2008.08.20 -
AntiVir 7.8.1.23 2008.08.20 -
Authentium 5.1.0.4 2008.08.20 -
Avast 4.8.1195.0 2008.08.19 -
AVG 8.0.0.161 2008.08.20 -
BitDefender 7.2 2008.08.20 -
CAT-QuickHeal 9.50 2008.08.20 -
ClamAV 0.93.1 2008.08.19 -
DrWeb 4.44.0.09170 2008.08.20 -
eSafe 7.0.17.0 2008.08.20 Suspicious File
eTrust-Vet 31.6.6037 2008.08.20 -
Ewido 4.0 2008.08.20 -
F-Prot 4.4.4.56 2008.08.19 -
Fortinet 3.14.0.0 2008.08.20 -
GData 2.0.7306.1023 2008.08.20 -
Ikarus T3.1.1.34.0 2008.08.20 not-a-virus:FraudTool.Win32.SpywareBot.o
K7AntiVirus 7.10.421 2008.08.19 not-a-virus:AdWare.Win32.f.DE
Kaspersky 7.0.0.125 2008.08.20 not-a-virus:FraudTool.Win32.AntiSpyware.dd
McAfee 5364 2008.08.19 potentially unwanted program ErrorKiller
Microsoft 1.3807 2008.08.20 -
NOD32v2 3370 2008.08.20 -
Norman 5.80.02 2008.08.20 W32/SpySheriff.DE
Panda 9.0.0.4 2008.08.19 -
PCTools 4.4.2.0 2008.08.20 -
Prevx1 V2 2008.08.20 -
Rising 20.58.22.00 2008.08.20 -
Sophos 4.32.0 2008.08.20 -
Sunbelt 3.1.1564.1 2008.08.20 -
Symantec 10 2008.08.20 -
TheHacker 6.3.0.5.054 2008.08.19 -
TrendMicro 8.700.0.1004 2008.08.20 -
VBA32 3.12.8.3 2008.08.20 -
ViRobot 2008.8.20.1342 2008.08.20 -
VirusBuster 4.5.11.0 2008.08.20 -
Webwasher-Gateway 6.6.2 2008.08.20 -
 
Additional information
File size: 4712925 bytes
MD5…: fe65d6c018140ad5dc5e4371070bcccc
SHA1..: be6338b9c61015478563d2a37e335927f8fd2cc7
SHA256: 8ca0da2a2185976bd747f98ac6072836c932a481773403c2b66e75bf133f5665
SHA512: 1b4d7ea834dde2383d1002557ab5f5e3dbfbae409337c083bee419a57f486395
f71c2b82edd8561f5627dc997bfd14ec1602ed4e78ca70d9b740d11a26cbd7da
PEiD..: UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0×43b3a0
timedatestamp…..: 0×4466b13c (Sun May 14 04:25:32 2006)
machinetype…….: 0×14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0×1000 0×2d000 0×0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0×2e000 0xe000 0xd600 7.90 9be8e90910e79b930f5c7b8b9dcc46d4
.rsrc 0×3c000 0×18000 0×17a00 7.51 21286ec5b702dd809c400b8559c8a78a

( 5 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, ExitProcess
> COMCTL32.dll: -
> OLEAUT32.dll: -
> SHELL32.dll: ShellExecuteExA
> USER32.dll: SetTimer

( 0 exports )

packers (Kaspersky): PE_Patch.UPX, UPX
packers (F-Prot): UPX

AdWare Alert

Host: adware-download.com
IP: 70.86.182.194

Whois:

OrgName:    ThePlanet.com Internet Services, Inc.
OrgID:      TPCM
Address:    315 Capitol
Address:    Suite 205
City:       Houston
StateProv:  TX
PostalCode: 77002
Country:    US
RTechHandle: PP46-ARIN
RTechName:   Pathos, Peter
RTechPhone:  +1-214-782-7800
RTechEmail:   abuse@theplanet.com

Host: adwarealert.com
IP: 72.32.29.230

Whois of IP 72.32.29.230 distributing fake antispyware application AdWare Alert:

OrgName:    Rackspace.com, Ltd.
OrgID:      RSPC
Address:    9725 Datapoint Drive
Address:    Suite 100
City:       San Antonio
StateProv:  TX
PostalCode: 78229
Country:    US
OrgAbuseHandle: ABUSE45-ARIN
OrgAbuseName:   Abuse Desk
OrgAbusePhone:  +1-210-892-4000
OrgAbuseEmail:  abuse@rackspace.com

Other sites on  IP 72.32.29.230 distributing fake antispyware application AdWare Alert:

1.  Adwarealert.com 
2.  Evidenceeraser.com 
3.  Movieadvanced.com 
4.  Registrysmart.com 
5.  Restore-pc.com 

Host: setup.adwarealert.com
IP: 72.32.29.234

Whois:

OrgName:    Rackspace.com, Ltd.
OrgID:      RSPC
Address:    9725 Datapoint Drive
Address:    Suite 100
City:       San Antonio
StateProv:  TX
PostalCode: 78229
Country:    US
OrgAbuseHandle: ABUSE45-ARIN
OrgAbuseName:   Abuse Desk
OrgAbusePhone:  +1-210-892-4000
OrgAbuseEmail:  abuse@rackspace.com

AdWare Alert

AdWare Alert

Host: ssl.clickbank.net
IP: 64.128.87.138 and 64.128.87.139

Whois of  IP 64.128.87.138 distributing fake antispyware application AdWare Alert:

OrgName:    tw telecom holdings, inc.
OrgID:      TWTC
Address:    10475 Park Meadows Drive
City:       Littleton
StateProv:  CO
PostalCode: 80124
Country:    US

OrgAbuseHandle: TWTAD-ARIN
OrgAbuseName:   tw telecom Abuse Desk
OrgAbusePhone:  +1-800-898-6473
OrgAbuseEmail:  abuse@twtelecom.net

AdWare Alert

Antivirus XP 2008 rogue antivirus application

Wednesday, August 20th, 2008

Antivirus XP 2008 is a rogue antivirus application. DO NOT download any software from domain(s) of Antivirus XP 2008.

Antivirus XP 2008

 

File codecpack.v.1.0.86.exe received on 08.20.2008 12:45:54 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.8.19.0 2008.08.20 -
AntiVir 7.8.1.23 2008.08.20 -
Authentium 5.1.0.4 2008.08.20 -
Avast 4.8.1195.0 2008.08.19 -
AVG 8.0.0.161 2008.08.20 -
BitDefender 7.2 2008.08.20 -
CAT-QuickHeal 9.50 2008.08.19 -
ClamAV 0.93.1 2008.08.19 -
DrWeb 4.44.0.09170 2008.08.20 -
eSafe 7.0.17.0 2008.08.19 -
eTrust-Vet 31.6.6036 2008.08.19 -
Ewido 4.0 2008.08.19 -
F-Prot 4.4.4.56 2008.08.19 -
F-Secure 7.60.13501.0 2008.08.20 -
Fortinet 3.14.0.0 2008.08.20 PossibleThreat
GData 2.0.7306.1023 2008.08.20 -
Ikarus T3.1.1.34.0 2008.08.20 -
K7AntiVirus 7.10.421 2008.08.19 -
Kaspersky 7.0.0.125 2008.08.20 -
McAfee 5364 2008.08.19 -
Microsoft 1.3807 2008.08.20 -
NOD32v2 3370 2008.08.20 -
Norman 5.80.02 2008.08.20 -
Panda 9.0.0.4 2008.08.19 Suspicious file
PCTools 4.4.2.0 2008.08.19 -
Prevx1 V2 2008.08.20 Malicious Software
Rising 20.58.22.00 2008.08.20 -
Sophos 4.32.0 2008.08.20 -
Sunbelt 3.1.1546.1 2008.08.15 -
TheHacker 6.3.0.5.054 2008.08.19 -
TrendMicro 8.700.0.1004 2008.08.20 Possible_DLDER
VBA32 3.12.8.3 2008.08.19 -
ViRobot 2008.8.20.1342 2008.08.20 -
VirusBuster 4.5.11.0 2008.08.19 -
Webwasher-Gateway 6.6.2 2008.08.20 -
 
Additional information
File size: 79360 bytes
MD5…: d1f9c74c23a1790e13608beacdebd4ba
SHA1..: 042213713d0c025fd23b2a00b500d4594558580c
SHA256: 5c304d86d4c9a6a2473acaab032247275d9cd639e98db0e153683eb44ff7f693
SHA512: 49d29178c42f6fff0eca719351d3e051c2f361f4ccfdf23ccc41827d8127fc86
f8f14830ac678b25fa46fb96f1c17f51afc0aa97c16386f128d45304f1512c46
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0×4123f0
timedatestamp…..: 0×48aacec8 (Tue Aug 19 13:46:48 2008)
machinetype…….: 0×14c (I386)

( 2 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0×1000 0×1333c 0×12800 7.96 dc3e23112b39a0132e2ad7ff7ea2ee75
.rdata 0×15000 0×818 0xa00 4.68 d9b27a4fa7b22f0173d4dc53c3347d0a

( 7 imports )
> KERNEL32.dll: CloseHandle, DeviceIoControl, CreateFileA, GetVolumeInformationA, ExitProcess, TerminateProcess, SetProcessPriorityBoost, SetThreadPriority, GetCurrentThread, SetPriorityClass, GetCurrentProcess, GetEnvironmentVariableA, GetShortPathNameA, GetModuleFileNameA, IsBadWritePtr, GetComputerNameA, WriteFile, lstrlenA, lstrcatA, GetTempPathA, GetTickCount, Sleep, lstrcpyA, CreateProcessA
> USER32.dll: wsprintfA
> SHELL32.dll: ShellExecuteExA, SHChangeNotify, SHGetSpecialFolderPathA
> MSVCRT.dll: atol, _except_handler3, sprintf, rand, __3@YAXPAX@Z, __2@YAPAXI@Z, strstr, __CxxFrameHandler, strncat, strncpy, _strdup, atoi
> MSVCP60.dll: __Tidy@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@AAEX_N@Z, __Grow@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@AAE_NI_N@Z, _npos@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@2IB, __Xlen@std@@YAXXZ, __C@_1___Nullstr@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@CAPBDXZ@4DB, __1_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAE@XZ, __Eos@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@AAEXI@Z
> SHLWAPI.dll: PathGetDriveNumberA
> WININET.dll: InternetCloseHandle, InternetReadFile, HttpQueryInfoA, InternetOpenUrlA, InternetOpenA

( 0 exports )

Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=F3B8AD7200D4B54536ED016CEE442D00AB916133

 

Antivirus XP 2008

Antivirus XP 2008

Host: 1st-tube.com
IP: 74.50.117.84

Whois of IP 74.50.117.84 distributing rogue antivirus application Antivirus XP 2008

OrgName:    NOC4Hosts Inc.
OrgID:      NOC4H
Address:    400 N Tampa St
Address:    #1025
City:       Tampa
StateProv:  FL
PostalCode: 33602
Country:    US
RAbuseHandle: NAA7-ARIN
RAbuseName:   Noc4Hosts Abuse Admin
RAbusePhone:  +1-877-801-1443
RAbuseEmail:   abuse@noc4hosts.com

Other sites on IP 74.50.117.84 distributing rogue antivirus application Antivirus XP 2008:

1.  Best-cracks.com 
2.  Celebs-on-video.com 
3.  Codechost.com 
4.  Codecupgrade.com 
5.  Crack-all.com 
6.  Crack-expert.com 
7.  Crack-land.com 
8.  Freemoviesdb.net 
9.  Just-tube.com 
10.  Karachun.net 
11.  Megasoftportal.net 
12.  Muzdownload.com 
13.  Porntubev20.com 
14.  Pro-scanner.com 
15.  Scanner-pro.com 
16.  Scanner-tool.com 
17.  Showconz.com 
18.  Softupdat.com 
19.  Surf-scanner.com 
20.  Unlimdownloads.com 
21.  Updatehost.com 
22.  Winantivirus2008.org 
23.  Crackundeground.com 
24.  Online-av-scan.com 
25.  Porn-tube-2008.com 

Host: img-library.com
IP: 85.255.117.252

Whois:

netname:        UkrTeleGroup
descr:          UkrTeleGroup Ltd.
admin-c:        UA481-RIPE
tech-c:         UA481-RIPE
country:        UA
org-name:       UkrTeleGroup Ltd.
org-type:       LIR
address:        UkrTeleGroup Ltd.
                Mechnikova 58/5
                65029 Odessa
                Ukraine
phone:          +380487311011
fax-no:         +380487502499
mnt-ref:        UKRTELE-MNT
mnt-ref:        RIPE-NCC-HM-MNT
mnt-by:         RIPE-NCC-HM-MNT
source:         RIPE # Filtered

person:         Andrew Sotov
address:        Mechnikova 58/5 65029 Odessa
abuse-mailbox:  abuse@urktelegroup.com.ua

Other sites:

1.  Document-checking.com 
2.  Helpsupportcenter.com 
3.  Img-library.com 
4.  Protection-wizard.com 

Host: any-pictures.com
IP: 85.255.117.251

Whois:

netname:        UkrTeleGroup
descr:          UkrTeleGroup Ltd.
admin-c:        UA481-RIPE
tech-c:         UA481-RIPE
country:        UA
org-name:       UkrTeleGroup Ltd.
org-type:       LIR
address:        UkrTeleGroup Ltd.
                Mechnikova 58/5
                65029 Odessa
                Ukraine
phone:          +380487311011
fax-no:         +380487502499
mnt-ref:        UKRTELE-MNT
mnt-ref:        RIPE-NCC-HM-MNT
mnt-by:         RIPE-NCC-HM-MNT
source:         RIPE # Filtered

person:         Andrew Sotov
address:        Mechnikova 58/5 65029 Odessa
abuse-mailbox:  abuse@urktelegroup.com.ua

Other sites:

1.  Any-pictures.com 
2.  Bigimagecatalogue.com 
3.  Imagesishere.com 

Host: antivirus-xp-08.net
IP: 77.244.220.134

Whois:

netname:        PRIMENET1
descr:          Allocation for our customer PrimeNet
country:        RU
admin-c:        RZT1-RIPE
tech-c:         RZT1-RIPE
status:         ASSIGNED PA
mnt-by:         RZT-MNT
mnt-lower:      RZT-MNT
mnt-routes:     RZT-MNT
source:         RIPE # Filtered

person:         Network Admins  RZT-SERVICE
address:        191011 Saint-Petersburg, Russia
address:        Lomonosova sq. 1
phone:          +78123142643
e-mail:         rztncc@sysadmins.spb.ru

Other sites:

1.  Antivirusxp08.net 
2.  Antivirxp08.com 
3.  Av-xp-08.com 
4.  Avxp-08.com 
5.  Avxp-2008.com 
6.  Avxp08.com 
7.  Avxp2008.com 
8.  Youpornztube.net 
9.  Youpornztube.org 

Host: www.antivirus-xp-08.net
IP: 85.17.45.51

Whois:

netname:        LEASEWEB
descr:          LeaseWeb
descr:          P.O. Box 93054
descr:          1090BB AMSTERDAM
descr:          Netherlands
descr:          www.leaseweb.com
remarks:        Please send email to “abuse@leaseweb.com” for complaints
remarks:        regarding portscans, DoS attacks and spam.
remarks:        INFRA-AW
country:        NL
admin-c:        LSW1-RIPE
tech-c:         LSW1-RIPE
status:         ASSIGNED PA
mnt-by:         OCOM-MNT
source:         RIPE # Filtered

person:         RIP Mean
address:        P.O. Box 93054
address:        1090BB AMSTERDAM
address:        Netherlands
phone:          +31 20 3162880
fax-no:         +31 20 3162890
abuse-mailbox:  abuse@leaseweb.com

Antivirus XP 2008

Host: secure.eglobalbilling.com
IP: 216.195.56.148

Whois of IP 216.195.56.148 selling rogue antivirus application Antivirus XP 2008:

OrgName:    APS Telecom
OrgID:      APSTE
Address:    8130 SW BEAVERTON-HILLSDALE HWY
City:       PORTLAND
StateProv:  OR
PostalCode: 97225
Country:    US

NetRange:   216.195.32.0 - 216.195.63.255
CIDR:       216.195.32.0/19
NetName:    APS-EPSI
NetHandle:  NET-216-195-32-0-1
Parent:     NET-216-0-0-0-0
NetType:    Direct Allocation
NameServer: NS1.3FN.NET
NameServer: NS2.3FN.NET
Comment:    send abuse issues to , send network abuse@3fn.net

Other sites of IP 216.195.56.148 selling rogue antivirus application Antivirus XP 2008:

1.  Adult-billing.com 
2.  Billhlp.com 
3.  Billingcenteronline.com 
4.  Billinghost.net 
5.  Billingintegrator.com 
6.  Billingmill.com 
7.  Billingserviceonline.com 
8.  Billingsquad.net 
9.  Billingsvc.com 
10.  Billinternet.com 
11.  Billsvc.com 
12.  Customerhlp.com 
13.  Ebillingcenter.com 
14.  Eglobalbilling.com 
15.  Extrabilling.com 
16.  Fantazybill.com 
17.  Legalbillingsystems.com 
18.  Mainbillingcenter.com 
19.  Orderhlp.com 
20.  Paymentbit.com 
21.  Paymentbit.net 
22.  Paymentforge.com 
23.  Quickdownloadpro.com 
24.  Safepaymentsonline.com 
25.  Software-payment.com 
26.  Spankyhosting.com 
27.  Support-wizard.com 
28.  Supporthlp.com 
29.  Truebillingservices.com 
30.  Ultimatepayment.com 

Antivirus XP 2008

Page 1 of 11