May 2008 - Posts

Want a Trojan.Zlob with your fake scan results?

It's amazing the lengths these culprits will go to ... landing on the following site not only do you get a fake spyware scan, you can also get a version of Trojan.Zlob at the same time ...

The fake scanner redirects to "antivirus-scanonline" from my last post, and the bogus "video decoder" is a variant of Trojan.Zlob ... (install_player_3913241.exe) VirusTotal results here ...

Posted by winhelp2002 with 2 comment(s)

Another fake scanner site

Landing on the following site the visitor is presented with a fake scan which displays that you are infected ...

As you can see the "Information Bar" has blocked the automatic download ... and prompted the user ...

The highlighted (in red) was the auto download ... if you proceed they also try to get you to "Run" the "AtnvrsInstall.exe"
which sadly is not very well detected (2/32) Kespersky detects as: Downloader.Win32.FraudLoad.bw

Posted by winhelp2002 with 1 comment(s)

MVPS HOSTS File Update May-18-2008


The MVPS HOSTS file was recently updated [April-22-2008]
http://www.mvps.org/winhelp2002/hosts.htm

Download: hosts.zip (157 kb)
http://www.mvps.org/winhelp2002/hosts.zip

How To: Download and Extract the HOSTS file
http://www.mvps.org/winhelp2002/hosts2.htm

HOSTS File - Frequently Asked Questions
http://www.mvps.org/winhelp2002/hostsfaq.htm

Note: the "text" version makes a great resource for determining possible culprits ... (684 kb)
http://www.mvps.org/winhelp2002/hosts.txt

Sign up for HOSTS file update notices
http://www.mvps.org/winhelp2002/updates.htm

Posted by winhelp2002 with no comments

Another round of Chinese hackers

Seems like every day now there is another report of sites being hacked by various methods ... many are Chinese related.
Much to my surprise when I ran a scan at LinkScanner" ... it produced the following prompt ...

As I've mentioned many times before any time you see that prompt it always relates to Exploits ...

As you can see there are several sites involved and several exploits including "ri.exe" from another related site. All these sites are on the same IP ... VirusTotal results here ...

There are several other notable sites that were injected with these sites ... which Google has flagged as harmful ... ouch!

Appears no site is really safe from these culprits ... be careful out there folks ...

Posted by winhelp2002 with no comments

Texas Charges Nexusmedia Deceived Web Users

Nexusmedia charged with failing to inform consumers about spyware downloads
"Texas Attorney General Greg Abbott charged a Colorado software business with selling screensavers that were bundled with adware or spyware. Further, although the defendants promised child-safe screensavers, their products commonly included images of unclothed women" ... [full story here]

"However, Friday’s enforcement action charges McLaughlin with bundling his screensavers with independent, unrelated software called the My Search Toolbar. Customers who purchased the screensavers were not given the opportunity to opt out of the toolbar."

Imagine that! ... "not available to Texas residents" ... I wonder why? Were only Texas residents were decieved?
Also interesting it appears Nexusmedia has revised their website to include the following:

"We have made an effort to allow you to opt out of installing the NexusBar however there may be some screensavers that will silently install this so with that said, by installing this software you also agree to install the toolbar."

They have also removed any mention to "No Adware/Spyware" ... seems like some sites are already aware of the issue ...

It's bad enough when adware is bundled with free downloads ... but now to purchase a screensaver and still get whacked with no consent adware is really underhanded ... although sleezy underhanded tactics are nothing new for MySearch.

I bet it won't be long before "IAC Search Media" (formally AskJeeves) starts to spin this issue ...

Posted by winhelp2002 with no comments
Filed under:

Get your Trojan.Codec in FullHD 1080

Well I must say they sure are creative ... now you can get your Trojan.Codec in FullHD 1080 ... imagine that!

Or maybe you would prefer a Trojan (Trojan-Downloader.Win32.Peregar.cf) in Dolby 5.1 surround sound? ... yeah right! ...

The download for this is pretty well detected (Result: 23/31 (74.2%) VirusTotal results here ...

Posted by winhelp2002 with no comments