Thursday, December 6, 2007

AntiSpy Pro 2.4






AntiSpy Pro 2.4 -Another rogue application from ESTDOMAINS, This application is a clone of IEDefender.

I have added screenshots for both the applications, so that you can compare them.

Make sure you do not install this useless application.


AntiSpy-Pro.com


AntiSpy Pro 2.4

IEDefender.com

IE Defender 2.4.3

Additional information:

Domain Name: antispy-pro.com
Status: clientTransferProhibited
Registrar: ESTDOMAINS, INC.
Whois Server: whois.estdomains.com
Referral URL: http://www.estdomains.com

Expiration Date: 2008-11-15
Creation Date: 2007-11-15
Last Update Date: 2007-11-15

Name Servers:
ns1.antispy-pro.com
ns2.antispy-pro.com

IP Address: 85.255.121.149
Website Status: active
Server Type: Apache/2.2.3 (Debian) PHP/4.4.4-8+etch4
Cache Date: 2007-12-06 04:27:55 MST

Virustotal results: 4/32 (12.5%)

ClamAV-----> Adware.Fakealert-21
Kaspersky----->not-a-virus:FraudTool.Win32.IeDefender.j
VBA32----->suspected of Backdoor.Delf.180 (paranoid heuristics)
Symantec----->AntiSpyPro


File size: 2836949 bytes
MD5: 3e66a8d4eed567b696fd23de45f1b1ee
SHA1: 86dbd9677bfcf0bc96528bbad18b6e5e1c12e4f8
PEiD: -
packers: ASPack

Virustotal result is quiet bad, so stay away from this site.

2 comments:

Anonymous said...

Cool story you got here. I'd like to read something more about that topic. The only thing that blog needs is a few pics of such gizmos as gps jammer.

Anonymous said...

Interesting article as for me. I'd like to read more concerning that topic. The only thing this blog misses is a few pics of some devices.
Alex Trider
Cell jammer