Friday, April 24, 2009

ErrorEasy

ErrorEasy is a rogue that belongs to the same family as ErrorFix, RegTool, RegfixPro.
These fake tools are not detecting infected files or malwares but fake registry problems.



Another rogue (ErrorRepairTool) shows a relationship between, PC Utility Inc. (the editor of these tools) and 2Squared.com (a known rogue editor). But PC Utility Inc. claims that their products are legit and there is no relationship with 2Squared.com.

IP of ErrorRepairTool websites and the name of the company in the privacy page:
updatesprofessional.com (174.36.234.248) 2Squared Inc.
updates-micro.com (174.36.234.248) 2Squared Inc.
fixupdates.com (174.36.234.248) 2Squared Inc.
fix-xp.com (174.36.234.248) 2Squared Inc.
registry-updates.com (174.36.234.248) 2Squared Inc.

errorrepairtool.com (75.125.61.163) PC Utility Inc.
errorstool.com (75.125.61.163) PC Utility Inc.
errorsrepair.com(75.125.61.163) PC Utility Inc.

All pages where PC Utility Inc. was quoted have been removed (they were online yesterday). Google keeps some traces about it:


It was exactly the same page, but 2Squared Inc. was replaced by PC Utility Inc.


Back to ErrorEasy. To update itself, ErrorEasy contacts
ErrorEasy.com/databases/getinfo.php
database.registrysmart.com/updates/definitions.db
database.privacycontrol.com/updates/privacy.db

Looks like déja-vu, see RegistryFox Rogue (from another known rogue company: AntiSpyware LLC.).

database.registrysmart.com (75.125.200.226)
adwarealert.com (75.125.200.226)
evidenceeraser.com (75.125.200.226)
registrysmart.com (75.125.200.226)
restore-pc.com (75.125.200.226)

privacycontrol.com (75.125.61.162)
errorsweeper.com (75.125.61.162)
antispywarebot.com (75.125.61.162)
regclean.com (75.125.61.162)
2squared.com (75.125.61.162)

In the code of ErrorEasy, there is a hardcoded URL to 2Squared.com:



The Database is the same as AntiSpyware LLC. rogue.
There is a hardcoded string of 2Squared.com in the PC Utility Inc. tool.
And no relationship ?