There are questions about this program some people would like to know .. Including me.
http://www.spywarewarrior.com/viewtopic.php?t=22305
http://securityticker.blogspot.com/2006/08...new-trojan.html
http://www.securitycadets.com/2006/08/new-...ue-virusrescue/
http://www.securitycadets.com/2006/08/my-r...to-virusrescue/
Is this just another new rogue antispyware program posing as a legit Spyware remover that costs $49 before it will remove anything it finds.. [ and what actual threats will it find ? ]
Sure looks like it so far , despite their claims that :
QUOTE
VirusRescue really removes all the infections from your PC and has on of the best scanning & detection engines in industry
It really really removes all infections , or they just really want us all to believe that it really does .. ?
I'm not paying $50 dollars to find out
Virusrecue.com
IP Address: 85.255.118.146
QUOTE
Domain Name: VIRUSRESCUE.COM
Registrar: ESTDOMAINS, INC.
Whois Server: whois.estdomains.com
Referral URL: http:// www.estdomains.com
Name Server: MANAGEDNS1.ESTHOST.COM
Name Server: MANAGEDNS2.ESTHOST.COM
Status: ACTIVE
Updated Date: 16-mar-2006
Creation Date: 16-mar-2006
Expiration Date: 16-mar-2007
Registrar: ESTDOMAINS, INC.
Whois Server: whois.estdomains.com
Referral URL: http:// www.estdomains.com
Name Server: MANAGEDNS1.ESTHOST.COM
Name Server: MANAGEDNS2.ESTHOST.COM
Status: ACTIVE
Updated Date: 16-mar-2006
Creation Date: 16-mar-2006
Expiration Date: 16-mar-2007
The registrant details seem to be changing around a lot recently , trying to hide something guys ?
http://whois.domaintools.com/virusrescue.com
QUOTE
VirusRescue Inc
Jeffry Murphy
Sherwood Road, 8
Toowong
null,Qld 4006
AU
Tel. +617.387615500
Jeffry Murphy
Sherwood Road, 8
Toowong
null,Qld 4006
AU
Tel. +617.387615500
CODE
Registration Service Provided By: ESTDOMAINS INC
Contact: +1.3027224217
Website: http ://www.estdomains.com
Domain Name: VIRUSRESCUE.COM
Registrant:
VirusRescue Inc
Jeffry Murphy @gmail.com)
Sherwood Road, 8
Toowong
null,Qld 4006
AU
Tel. +617.387615500
Creation Date: 16-Mar-2006
Expiration Date: 16-Mar-2007
Domain servers in listed order:
managedns1.esthost.com
managedns2.esthost.com
Administrative Contact:
VirusRescue Inc
Jeffry Murphy @gmail.com)
Sherwood Road, 8
Toowong
null,Qld 4006
AU
Tel. +617.387615500
Technical Contact:
VirusRescue Inc
Jeffry Murphy @gmail.com)
Sherwood Road, 8
Toowong
null,Qld 4006
AU
Tel. +617.387615500
Billing Contact:
VirusRescue Inc
Jeffry Murphy @gmail.com)
Sherwood Road, 8
Toowong
null,Qld 4006
AU
Tel. +617.387615500
Status:ACTIVE
Contact: +1.3027224217
Website: http ://www.estdomains.com
Domain Name: VIRUSRESCUE.COM
Registrant:
VirusRescue Inc
Jeffry Murphy @gmail.com)
Sherwood Road, 8
Toowong
null,Qld 4006
AU
Tel. +617.387615500
Creation Date: 16-Mar-2006
Expiration Date: 16-Mar-2007
Domain servers in listed order:
managedns1.esthost.com
managedns2.esthost.com
Administrative Contact:
VirusRescue Inc
Jeffry Murphy @gmail.com)
Sherwood Road, 8
Toowong
null,Qld 4006
AU
Tel. +617.387615500
Technical Contact:
VirusRescue Inc
Jeffry Murphy @gmail.com)
Sherwood Road, 8
Toowong
null,Qld 4006
AU
Tel. +617.387615500
Billing Contact:
VirusRescue Inc
Jeffry Murphy @gmail.com)
Sherwood Road, 8
Toowong
null,Qld 4006
AU
Tel. +617.387615500
Status:ACTIVE
Now the DNS records show here another email address:
virusrescue.com IN SOA server: managedns1.estboxes.com
email: david.alant.gmail.com
serial: 2006070105
refresh: 7200
retry: 7200
expire: 2419200
minimum ttl: 38400
38400s (10:40:00)
Results from 13 days ago...
Now take a note of this guys name- David taylor
Registration Service Provided By: ESTDOMAINS
Contact: +1.3027224217
Website: http:// www.estdomains.com
Domain Name: VIRUSRESCUE.COM
Registrant:
SunShine Ltd
David Taylor @gmail.com)
U-12 Gamma Commercial Complex # 47
Rizal Highway cor. Manila Ave Subic Bay
Olongapo City
null,98101
PH
Tel. +206.9543154
Creation Date: 16-Mar-2006
Expiration Date: 16-Mar-2007
Domain servers in listed order:
managedns1.esthost.com
managedns2.esthost.com
Administrative Contact:
SunShine Ltd
David Taylor@gmail.com)
U-12 Gamma Commercial Complex # 47
Rizal Highway cor. Manila Ave Subic Bay
Olongapo City
null,98101
PH
Tel. +206.9543154
Status:ACTIVE
Retrieving DNS records for virusrescue.com...
DNS servers
managedns4.estboxes.com
managedns3.estboxes.com
managedns2.estboxes.com [69.50.183.26]
managedns1.estboxes.com [69.50.182.18]
Answer records
virusrescue.com 1 A 85.255.118.146 38400s
virusrescue.com 1 SOA server: managedns1.estboxes.com
email: david@alant.gmail.com
serial: 2006070104
refresh: 7200
retry: 7200
expire: 2419200
minimum ttl: 38400
38400s
virusrescue.com 1 NS managedns1.estboxes.com 172800s
virusrescue.com 1 NS managedns2.estboxes.com 172800s
virusrescue.com 1 NS managedns3.estboxes.com 172800s
virusrescue.com 1 NS managedns4.estboxes.com 172800s
--------------------------------------------------------------
David Taylor can also be found in the registrant details for Spyware Strike and Spyfalcon at the very least..
http://blogs.zdnet.com/Spyware/?p=770
QUOTE
The name SpyAxe, top rogue anti-spsyware app of 2005, brings up anger and frustration for its many victims but now SpyFalcon has burst on the scene looking like a replacement for SpyAxe. SpyFalcon, just like SpyAxe, is being installed along with trojans through exploits.
QUOTE
Registrant:
SunShine Ltd
David Taylor
U-12 Gamma Commercial Complex # 47
Rizal Highway cor. Manila Ave Subic Bay
Olongapo City
null,98101
PH
Tel. +206.9543154
Creation Date: 16-Jan-2006
Expiration Date: 16-Jan-2007
Domain servers in listed order:
ns1.antispydns.biz
ns2.antispydns.biz
ns3.antispydns.biz
And another :
Registration Service Provided By: ESTDOMAINS
Contact: +1.3027224217
Website: http:// www.estdomains.com
Domain Name: SPYWARESTRIKE.COM
Registrant:
Spywarestrike Inc
David Alan Taylor @spywarestrike.com)
Unit 110 Alpha Bldg. Subic International Hotel Rizal cor.
Sta. Rita Road, Subic Bay Freeport
Olongapo City
null,2200
SunShine Ltd
David Taylor
U-12 Gamma Commercial Complex # 47
Rizal Highway cor. Manila Ave Subic Bay
Olongapo City
null,98101
PH
Tel. +206.9543154
Creation Date: 16-Jan-2006
Expiration Date: 16-Jan-2007
Domain servers in listed order:
ns1.antispydns.biz
ns2.antispydns.biz
ns3.antispydns.biz
And another :
Registration Service Provided By: ESTDOMAINS
Contact: +1.3027224217
Website: http:// www.estdomains.com
Domain Name: SPYWARESTRIKE.COM
Registrant:
Spywarestrike Inc
David Alan Taylor @spywarestrike.com)
Unit 110 Alpha Bldg. Subic International Hotel Rizal cor.
Sta. Rita Road, Subic Bay Freeport
Olongapo City
null,2200
QUOTE
Domain Name: SPYFALCON.COM
Registrant:
SpyFalcon ltd.
David Taylor
Unit 110 Alpha Bldg. Subic International Hotel Rizal cor.
Sta. Rita Road, Subic Bay Freeport
Olongapo City
null,2200
PH
Tel. +206.9543154
Creation Date: 16-Jan-2006
Expiration Date: 16-Jan-2007
Domain servers in listed order:
ns1.antispydns.biz
ns2.antispydns.biz
ns3.antispydns.biz
Registrant:
SpyFalcon ltd.
David Taylor
Unit 110 Alpha Bldg. Subic International Hotel Rizal cor.
Sta. Rita Road, Subic Bay Freeport
Olongapo City
null,2200
PH
Tel. +206.9543154
Creation Date: 16-Jan-2006
Expiration Date: 16-Jan-2007
Domain servers in listed order:
ns1.antispydns.biz
ns2.antispydns.biz
ns3.antispydns.biz
How about this , updateyourwindows domain which shares the same IP as Spyfalcon.. ?
I can't think of any other purpose of this site , besides the intentional confusion it will cause to hijacked users who might think it is the real microsoft windows update site.
QUOTE
Registration Service Provided By: ESTDOMAINS INC
Contact: +1.3027224217
Website: http:// www.estdomains.com
Domain Name: UPDATEYOURWINDOWS.COM
Registrant:
SunShine Ltd
David Taylor
U-12 Gamma Commercial Complex # 47
Rizal Highway cor. Manila Ave Subic Bay
Olongapo City
null,98101
PH
Tel. +206.9543154
Creation Date: 05-Feb-2006
Expiration Date: 05-Feb-2007
Domain servers in listed order:
ns1.antispydns.biz
ns2.antispydns.biz
ns3.antispydns.biz
Contact: +1.3027224217
Website: http:// www.estdomains.com
Domain Name: UPDATEYOURWINDOWS.COM
Registrant:
SunShine Ltd
David Taylor
U-12 Gamma Commercial Complex # 47
Rizal Highway cor. Manila Ave Subic Bay
Olongapo City
null,98101
PH
Tel. +206.9543154
Creation Date: 05-Feb-2006
Expiration Date: 05-Feb-2007
Domain servers in listed order:
ns1.antispydns.biz
ns2.antispydns.biz
ns3.antispydns.biz
Popular guy. He sure likes his rogue spyware apps.. If it's even a real person.
Is there a connection between VirusRescue and these other rogue scam anti-spyware apps ? You tell me.
---------------------------------------------------------------------------------
And another interesting thing is their choice of webhost , who we have totally blocked in the B.I.S.S malware blocklist due to the shocking amount of malware coming from there.
QUOTE
inetnum: 85.255.112.0 - 85.255.127.255
netname: inhoster
descr: Inhoster hosting company
descr: OOO Inhoster, Poltavskij Shliax 24, Kharkiv, 61000, Ukraine
netname: inhoster
descr: Inhoster hosting company
descr: OOO Inhoster, Poltavskij Shliax 24, Kharkiv, 61000, Ukraine
Now if you were setting up a legit anti-spyware company would you choose to associate your business next door to the very same people you are targetting ? Obviously not something that was considered here if you are to believe for a moment that they are legit..
Inhoster are very well known as one of the preferred webhosts by malware pushers.. Netcat hosting in the ukraine, Intercage/Atrivotech/Atrivohell in San Francisco USA and various russian federation webhosts being some of the other high level ones.
Traceroute even shows the connection passes through nlayer and an atrivo named node , which belongs to the malware infested Atrivohell/Intercage network.
QUOTE
10 61 61 61 - 69.22.142.78 so-2-3-0.cr1.sfo1.us.nlayer.net
11 77 77 77 - 69.22.128.250 atrivo.ge1-4.hr1.sfo1.us.nlayer.net
12 78 77 78 - 85.255.118.146 virusrescue.com
11 77 77 77 - 69.22.128.250 atrivo.ge1-4.hr1.sfo1.us.nlayer.net
12 78 77 78 - 85.255.118.146 virusrescue.com
Seems that its anything goes on these networks , with the amount of malware being traced back as originating from there.
These malware pushers love to use it for hijacking unsuspecting users with the most dangerous spyware/trojan/rootkit hijackers they can.
The real kicker though , is that they also install their preferred anti-spyware removal program of the moment and force their victims to pay up to remove these very same hijacks..
--
Not surprisingly , Inhoster/estdomains is actually hosted by Intercage / AtrivoHell :
estdomains.com = 69.50.183.26
--
CODE
11 77 77 61 69.22.143.14 ge4-8.hr1.sfo1.us.nlayer.net
12 77 78 77 69.22.128.250 atrivo.ge1-4.hr1.sfo1.us.nlayer.net
13 78 78 77 69.50.183.26
12 77 78 77 69.22.128.250 atrivo.ge1-4.hr1.sfo1.us.nlayer.net
13 78 78 77 69.50.183.26
---
CIDR: 69.50.160.0/19
NetName: INTERCAGE-NETWORK-GROUP
NetHandle: NET-69-50-160-0-1
Parent: NET-69-0-0-0-0
NetType: Direct Allocation
NameServer: MAIL.ATRIVO.COM
NameServer: PAVEL.ATRIVO.COM
Domain Name: ESTDOMAINS.COM
Registrant:
Estdomains Inc
110 W. Ninth Street #688
Wilmington
Delaware,19801
US
Tel. +1.3027224217
Creation Date: 19-Aug-2004
Expiration Date: 19-Aug-2010
Domain servers in listed order:
ans2.esthost.com
ns6.esthost.com
ans1.esthost.com
ns5.esthost.com
As you can see here - http://ow.bbclone.de/2005/11/09/esthost-or...lc-equals-spam/ , Inhoster actually was Esthost at some point in the past , until they decided to try and cover their tracks :
Previous:
inetnum: 85.255.112.0 - 85.255.127.255
netname: EstHost
descr: Inhoster hosting company
descr: OOO Inhoster, ul.Antonova 5, Kiev, 03186, Ukraine
Now:
inetnum: 85.255.112.0 - 85.255.127.255
netname: inhoster
descr: Inhoster hosting company
descr: OOO Inhoster, Poltavskij Shliax 24, Kharkiv, 61000, Ukraine
---------------------------------------------------------------------------------
Even more details of the trail these gangsters leave behind :
Intercage with lots of wmf exploits
http://spamhuntress.com/2006/01/07/interca...f-wmf-exploits/
ISPs hosting spyware - who are they?
http://blogs.zdnet.com/Spyware/?p=763
SpywareQuake scum on the run?
http://netrn.net/spywareblog/archives/2006...cum-on-the-run/
The Webhelper has a growing collection of Intercage/AtrivoHell malware IP's:
http://www.webhelper4u.com/CWS/cwsal_atrivo_ips.html
=---------------------
An absolute must read topic , where even an Atrivo/Intercage employee admits things are beyond their control , and by cutting off the gangsters abusng their network would cause them to lose out on the profits they are making from the illegal activities running amok on their network:
http://lists.sosdg.org/pipermail/sosdg-nan...ber/009861.html
There is no "network of esthost". The network in which Esthost resides
is our network.
Esthost is one of our larger clients, They are very
successful in the industry of web hosting and domain registration. They
just recently became an ICANN Accredited Registrar. I won't comment on
"why" they're so successful... But for some, that may be obvious.
I believe an investigation by law enforcement is a very corrective
step... That would definately clean Esthost up .
I can honestly say, there are 2 of our major clients who are very
successful... and with both of those comes occasional abuse. On one,
it's the occasional spam via exploit. The other... Esthost... Well... A
lot worse abuse then just spam.
Re: Atrivo/InterCage Abuse
http://lists.sosdg.org/pipermail/sosdg-nan...hread.html#9857
Russ at Atrivo.com wrote in news:1125683278.320264.138150
@f14g2000cwb.googlegroups.com:
> If I had the ability... I would cut Esthost as a client... But, in
> doing so, it causes nearly a quarter if not half of the company's
> monthly revenue to be cut. That is not too good of a move nor
> reasonably possible
--------------------------------------------------------------------------------------------
A common hijack coming from the malware ridden 85.255* net range is this codec scam below.
I picked up xpassword manager off of a victims computer who was infected with SpywareQuake just recently - http://www.bluetack.co.uk/forums/index.php?showtopic=14961
85.255.118.10
getpornmag.com
intcodec.com
mdcodec.com
xpasswordmanager.com
zipcodec.com - 85.255.118.14
Intcodec/zipcodec , they are the scam codec people that hijack your computer after getting you to installing their movie codecs.. shortly after the popups saying you are infected via scam security programs follow.
CODE
Trojan.Emcodec.F is a Trojan horse that drops and executes a copy of Trojan.Zlob.
The Trojan masquerades as an installer for IntCodec 6.0.
The Trojan masquerades as an installer for IntCodec 6.0.
http://research.sunbelt-software.com/threa...;threatid=44478
http://www.symantec.com/security_response/...-99&tabid=2
http://forum.sysinternals.com/forum_posts....46&get=last
CODE
function codecDownload()
{
if (window.navigator.userAgent.indexOf("SV1") != -1) {
return;
}
else {
window.setTimeout("location.href='http://www.intcodec.com/int/intcodec-v6.286.exe'", 3000);
}
}
{
if (window.navigator.userAgent.indexOf("SV1") != -1) {
return;
}
else {
window.setTimeout("location.href='http://www.intcodec.com/int/intcodec-v6.286.exe'", 3000);
}
}
Somewhere in the fine print , for those that bother to look , you will find these details:
QUOTE
SOFTWARE INSTALLATION: Components bundled with our software may report to Licensor and/or its affiliates the installation status of certain marketing offers, such as toolbars, and also generalized installation information, such as language preference and operating system version, to assist Licensor in its product development.
No personal information will be communicated to INTCODEC or its affiliates during this process. Licensor may offer additional components through our version checking/update system.
These components include:
( a ) Security Toolbar: Internet Explorer application that protects your computer while you browse by setting high level of security for suspicious hosts.
( B ) Popups advertising module: Internet Explorer windows may pop up when you are connected to internet.
( c ) Commercial homepage manager: your Internet Explorer homepage will be changed.
( d ) Security software: antivirus application.
No personal information will be communicated to INTCODEC or its affiliates during this process. Licensor may offer additional components through our version checking/update system.
These components include:
( a ) Security Toolbar: Internet Explorer application that protects your computer while you browse by setting high level of security for suspicious hosts.
( B ) Popups advertising module: Internet Explorer windows may pop up when you are connected to internet.
( c ) Commercial homepage manager: your Internet Explorer homepage will be changed.
( d ) Security software: antivirus application.
================
More to follow yet I'm sure..
================
/edit:
http://www.vitalsecurity.org/2006/08/virus...-rescue-me.html
================