<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Hosts News</title><link>http://msmvps.com/blogs/hostsnews/default.aspx</link><description>&amp;quot;There&amp;#39;s no place like 127.0.0.1&amp;quot; ... Blocking Ads, Parasites, and Hijackers with a Hosts File</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 (Build: 21119.1142)</generator><item><title>Another round of Chinese hackers</title><link>http://msmvps.com/blogs/hostsnews/archive/2008/05/11/1619832.aspx</link><pubDate>Sun, 11 May 2008 19:01:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1619832</guid><dc:creator>winhelp2002</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/hostsnews/rsscomments.aspx?PostID=1619832</wfw:commentRss><comments>http://msmvps.com/blogs/hostsnews/archive/2008/05/11/1619832.aspx#comments</comments><description>&lt;p&gt;Seems like every day now there is another report of sites being hacked by various methods ... many are Chinese related.&lt;br /&gt;Much to my surprise when I ran a scan at LinkScanner&amp;quot; ...&amp;nbsp;it produced the following prompt ...&lt;/p&gt;
&lt;p&gt;&lt;img height="404" alt="" src="http://mvps.org/winhelp2002/blog/explabs2.gif" width="579" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;As I&amp;#39;ve mentioned many times before any time you see that prompt &lt;strong&gt;it always relates to Exploits&lt;/strong&gt; ...&lt;/p&gt;
&lt;p&gt;&lt;img height="285" alt="" src="http://mvps.org/winhelp2002/blog/explabs.gif" width="526" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;As you can see there are several sites involved and several exploits including &amp;quot;ri.exe&amp;quot; from another related site. All these sites are on the same IP ... VirusTotal &lt;a class="" href="http://www.virustotal.com/analisis/e3a608803bf8a3df6e9d415c1bbbe080" target="_blank"&gt;results here&lt;/a&gt; ...&lt;/p&gt;
&lt;p&gt;There are several other notable sites that were injected with these sites ... which Google has flagged as harmful ... ouch!&lt;/p&gt;
&lt;p&gt;&lt;img height="187" alt="" src="http://mvps.org/winhelp2002/blog/explabs3.gif" width="550" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;Appears no site is really safe from these culprits ... be careful out there folks ...&lt;/p&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1619832" width="1" height="1"&gt;</description></item><item><title>Texas Charges Nexusmedia Deceived Web Users</title><link>http://msmvps.com/blogs/hostsnews/archive/2008/05/10/1618819.aspx</link><pubDate>Sat, 10 May 2008 11:36:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1618819</guid><dc:creator>winhelp2002</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/hostsnews/rsscomments.aspx?PostID=1618819</wfw:commentRss><comments>http://msmvps.com/blogs/hostsnews/archive/2008/05/10/1618819.aspx#comments</comments><description>&lt;p&gt;&lt;strong&gt;Nexusmedia charged with failing to inform consumers about spyware downloads&lt;br /&gt;&lt;/strong&gt;&amp;quot;&lt;em&gt;Texas Attorney General Greg Abbott charged a Colorado software business with selling screensavers that were bundled with adware or spyware. Further, although the defendants promised child-safe screensavers, their products commonly included images of unclothed women&lt;/em&gt;&amp;quot; ... [full &lt;a class="" href="http://www.oag.state.tx.us/oagNews/release.php?id=2444" target="_blank"&gt;story here&lt;/a&gt;]&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;em&gt;However, Friday’s enforcement action charges McLaughlin with bundling his screensavers with independent, unrelated software called the My Search Toolbar. Customers who purchased the screensavers were not given the opportunity to opt out of the toolbar&lt;/em&gt;.&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;img height="138" alt="" src="http://mvps.org/winhelp2002/blog/nexusmedia.gif" width="612" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;Imagine that! ... &amp;quot;not available to Texas residents&amp;quot; ... I wonder why? Were only Texas residents were decieved?&lt;br /&gt;Also&amp;nbsp;interesting it appears Nexusmedia has revised their &lt;a class="" href="http://www.nexusmedia.net/license.htm"&gt;website&lt;/a&gt; to include the following:&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;em&gt;We have made an effort to allow you to opt out of installing the NexusBar however there may be some screensavers that will silently install this so with that said, by installing this software you also agree to install the toolbar&lt;/em&gt;.&amp;quot;&lt;/p&gt;
&lt;p&gt;They have also removed any mention to &amp;quot;No Adware/Spyware&amp;quot; ... seems like some sites are already aware of the issue ...&lt;/p&gt;
&lt;p&gt;&lt;img height="170" alt="" src="http://mvps.org/winhelp2002/blog/nexusmedia2.gif" width="513" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;It&amp;#39;s bad enough when adware is bundled with free downloads ... but now to purchase a screensaver and still get whacked with no consent adware is really underhanded ... although sleezy underhanded tactics are nothing new for MySearch.&lt;/p&gt;
&lt;p&gt;I bet it won&amp;#39;t be long before &amp;quot;IAC Search Media&amp;quot; (formally AskJeeves) starts to spin this issue ...&lt;/p&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1618819" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/hostsnews/archive/tags/Nexusmedia/default.aspx">Nexusmedia</category></item><item><title>Get your Trojan.Codec in FullHD 1080</title><link>http://msmvps.com/blogs/hostsnews/archive/2008/05/02/1611657.aspx</link><pubDate>Fri, 02 May 2008 14:58:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1611657</guid><dc:creator>winhelp2002</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/hostsnews/rsscomments.aspx?PostID=1611657</wfw:commentRss><comments>http://msmvps.com/blogs/hostsnews/archive/2008/05/02/1611657.aspx#comments</comments><description>&lt;p&gt;Well I must say they sure are creative ... now you can get your Trojan.Codec in FullHD 1080 ... imagine that!&lt;/p&gt;
&lt;p&gt;&lt;img height="386" alt="" src="http://mvps.org/winhelp2002/blog/hrenota.gif" width="468" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;Or maybe you would prefer a Trojan (Trojan-Downloader.Win32.Peregar.cf) in Dolby 5.1 surround sound? ... yeah right! ...&lt;/p&gt;
&lt;p&gt;&lt;img height="460" alt="" src="http://mvps.org/winhelp2002/blog/hrenota2.gif" width="610" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;The download for this is pretty well detected (Result: 23/31 (74.2%) VirusTotal results &lt;a class="" href="http://www.virustotal.com/analisis/0cb1455e6b095110c5800dff02b27de3" target="_blank"&gt;here&lt;/a&gt; ...&lt;/p&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1611657" width="1" height="1"&gt;</description></item><item><title>Yet another LocusSoftware connection with ipsCA</title><link>http://msmvps.com/blogs/hostsnews/archive/2008/04/30/1609723.aspx</link><pubDate>Wed, 30 Apr 2008 09:32:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1609723</guid><dc:creator>winhelp2002</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/hostsnews/rsscomments.aspx?PostID=1609723</wfw:commentRss><comments>http://msmvps.com/blogs/hostsnews/archive/2008/04/30/1609723.aspx#comments</comments><description>&lt;p&gt;Here is yet another &lt;a class="" title="Another Rogue product from LocusSoftware" href="http://msmvps.com/blogs/hostsnews/archive/2008/04/11/1582513.aspx" target="_blank"&gt;example&lt;/a&gt; of LocusSoftware foisting their bogus products upon the public with the help of &amp;quot;ipsCA&amp;quot; ...&lt;/p&gt;
&lt;p&gt;&lt;img height="416" alt="" src="http://mvps.org/winhelp2002/blog/antimalwareguard2.gif" width="590" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;If you click the &amp;quot;Try free&amp;quot; button ... my AV (NOD32 v3) jumps up with the following: (and kills the connection)&lt;/p&gt;
&lt;p&gt;&lt;img height="553" alt="" src="http://mvps.org/winhelp2002/blog/antimalwareguard4.gif" width="450" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;However I am still able via Microsoft Fiddler to capture the traffic connections, including when you attempt to purchase via the &amp;quot;Buy now&amp;quot; button above ... you can see the redirection to their &amp;quot;payment&amp;quot; site and the certificate issued by &amp;quot;ipsCA&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;img height="575" alt="" src="http://mvps.org/winhelp2002/blog/antimalwareguard.gif" width="521" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;Just so there is no confusion of the connection between LocusSoftware and the payment site ... all you have to do is Google and there it is ...&lt;/p&gt;
&lt;p&gt;&lt;img height="408" alt="" src="http://mvps.org/winhelp2002/blog/antimalwareguard3.gif" width="557" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;Another interesting connection is &amp;quot;antimalwareguard&amp;quot; is &lt;a class="" title="Whois Info" href="http://whois.domaintools.com/antimalwareguard.com" target="_blank"&gt;registered to&lt;/a&gt; &amp;quot;Serg Moon&amp;quot; who &lt;a class="" href="http://msmvps.com/blogs/spywaresucks/archive/2008/04/22/1599434.aspx" target="_blank"&gt;Sandi Hardmeier&lt;/a&gt; has identified several times as being behind the rash of malicious advertisements on legit websites ... it really makes you wonder if these &amp;quot;Certificate Issuers&amp;quot; even bother to investigate who they are dealing with ... apparently ipsCA doesn&amp;#39;t!&lt;/p&gt;
&lt;p&gt;I also found the same payment site being used by &amp;quot;&lt;a class="" href="http://bharath-m-narayan.blogspot.com/2008/04/saga-of-ie-defender-family.html" target="_blank"&gt;IEAntiVirus&lt;/a&gt;&amp;quot; and several others ...&lt;/p&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1609723" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/hostsnews/archive/tags/Serg+Moon/default.aspx">Serg Moon</category></item><item><title>Another bogus Windows Media Player prompt</title><link>http://msmvps.com/blogs/hostsnews/archive/2008/04/23/1602114.aspx</link><pubDate>Thu, 24 Apr 2008 04:19:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1602114</guid><dc:creator>winhelp2002</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/hostsnews/rsscomments.aspx?PostID=1602114</wfw:commentRss><comments>http://msmvps.com/blogs/hostsnews/archive/2008/04/23/1602114.aspx#comments</comments><description>&lt;p&gt;Landing on the following site the visitor is prompted with a bogus Media Player prompt ...&lt;/p&gt;
&lt;p&gt;&lt;img height="484" alt="" src="http://mvps.org/winhelp2002/blog/getadultaccess.gif" width="505" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;The image is designed to look like a real Windows Media Player ... and as you can see IE7 blocked the automatic download of the file ... then you see the fake prompt &amp;quot;&lt;em&gt;You need to download new version Video ActiveX object&lt;/em&gt;&amp;quot; ... now as I&amp;#39;ve mentioned many times before there is no such thing ...&lt;/p&gt;
&lt;p&gt;The download (XXXmediaCodec.exe) was scanned at VirusTotal (Result: 18/32 (&lt;strong&gt;56.25%&lt;/strong&gt;) full results &lt;a class="" href="http://www.virustotal.com/analisis/f23fd9463208fdb192d4a6d3ed467107" target="_blank"&gt;here&lt;/a&gt;&lt;br /&gt;&amp;quot;&lt;em&gt;getadultaccess&lt;/em&gt;&amp;quot; is hosted at Ukrtelegroup Ltd (85.255.112.0 - 85.255.127.255)&lt;/p&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1602114" width="1" height="1"&gt;</description></item><item><title>MVPS HOSTS File Update April-22-2008</title><link>http://msmvps.com/blogs/hostsnews/archive/2008/04/22/1600497.aspx</link><pubDate>Wed, 23 Apr 2008 03:25:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1600497</guid><dc:creator>winhelp2002</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/hostsnews/rsscomments.aspx?PostID=1600497</wfw:commentRss><comments>http://msmvps.com/blogs/hostsnews/archive/2008/04/22/1600497.aspx#comments</comments><description>&lt;p&gt;&lt;img height="48" alt="" src="http://www.mvps.org/winhelp2002/noplace.gif" width="256" border="0" /&gt;&lt;br /&gt;The MVPS HOSTS file was recently updated [April-22-2008]&lt;br /&gt;&lt;a href="http://www.mvps.org/winhelp2002/hosts.htm"&gt;http://www.mvps.org/winhelp2002/hosts.htm&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Download&lt;/strong&gt;: hosts.zip (154 kb)&lt;br /&gt;&lt;a href="http://www.mvps.org/winhelp2002/hosts.zip"&gt;http://www.mvps.org/winhelp2002/hosts.zip&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;How To: Download and Extract the HOSTS file&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.mvps.org/winhelp2002/hosts2.htm"&gt;http://www.mvps.org/winhelp2002/hosts2.htm&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;HOSTS File - Frequently Asked Questions&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.mvps.org/winhelp2002/hostsfaq.htm"&gt;http://www.mvps.org/winhelp2002/hostsfaq.htm&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Note: the &amp;quot;text&amp;quot; version makes a great resource for determining possible culprits ... (668 kb)&lt;br /&gt;&lt;a href="http://www.mvps.org/winhelp2002/hosts.txt"&gt;http://www.mvps.org/winhelp2002/hosts.txt&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sign up for HOSTS file update notices&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.mvps.org/winhelp2002/updates.htm"&gt;http://www.mvps.org/winhelp2002/updates.htm&lt;/a&gt;&lt;/p&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1600497" width="1" height="1"&gt;</description></item><item><title>Another Rogue Antispyware product from the Pandora Software group</title><link>http://msmvps.com/blogs/hostsnews/archive/2008/04/16/1591440.aspx</link><pubDate>Thu, 17 Apr 2008 01:02:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1591440</guid><dc:creator>winhelp2002</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/hostsnews/rsscomments.aspx?PostID=1591440</wfw:commentRss><comments>http://msmvps.com/blogs/hostsnews/archive/2008/04/16/1591440.aspx#comments</comments><description>&lt;p&gt;Following up on a article from our friends at BleepingComputer &amp;quot;&lt;a class="" href="http://www.bleepingcomputer.com/malware-removal/malware-bell" target="_blank"&gt;How to remove Malware Bell&lt;/a&gt;&amp;quot; we find:&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;em&gt;Malware Bell is a rogue anti-spyware from the same developers as IE Defender and Files Secure. Malware Bell is installed and advertised through the use of Trojans that are installed as Internet Explorer Browser Helper Objects&lt;/em&gt;.&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;img height="436" alt="" src="http://mvps.org/winhelp2002/blog/malwarebell3.gif" width="599" border="0" /&gt;&lt;/p&gt;
&lt;p&gt;These people are so lame they can&amp;#39;t even write their own detections ... (highlighted in red) it&amp;#39;s actually from McAfee ... &lt;/p&gt;
&lt;p&gt;&lt;img height="454" alt="" src="http://mvps.org/winhelp2002/blog/malwarebell2.gif" width="516" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;As you can see there are several redirects when you [choke] attempt to purchase their bogus product ... the sad part is here is &lt;a class="" href="http://msmvps.com/blogs/hostsnews/archive/2008/04/11/1582513.aspx"&gt;another example&lt;/a&gt; of &amp;quot;ipsCA&amp;quot; issuing certificates to known bogus products ...&lt;/p&gt;
&lt;p&gt;&lt;img height="332" alt="" src="http://mvps.org/winhelp2002/blog/malwarebell.gif" width="432" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;I found the exact same thing with &amp;quot;VirusIsolator&amp;quot; which Symantec &lt;a class="" href="http://www.symantec.com/security_response/writeup.jsp?docid=2008-041610-1005-99" target="_blank"&gt;detects and describes&lt;/a&gt; as:&lt;br /&gt;&amp;quot;&lt;em&gt;The program reports false or exaggerated system security threats on the computer.&amp;quot;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;So I have to ask ... &lt;strong&gt;ipsCA what are you thinking!&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&amp;quot;installed and advertised through the use of Trojans&amp;quot; ... &amp;quot;reports false or exaggerated system security threats&amp;quot;&lt;/p&gt;
&lt;p&gt;Yes I did contact ipsCA previously and all I got back was an automated reply with a &amp;quot;&lt;em&gt;Support:276800&lt;/em&gt;&amp;quot; ...&lt;/p&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1591440" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/hostsnews/archive/tags/Pandora+Software/default.aspx">Pandora Software</category></item><item><title>Another malicious Movie site</title><link>http://msmvps.com/blogs/hostsnews/archive/2008/04/14/1586548.aspx</link><pubDate>Mon, 14 Apr 2008 15:36:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1586548</guid><dc:creator>winhelp2002</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/hostsnews/rsscomments.aspx?PostID=1586548</wfw:commentRss><comments>http://msmvps.com/blogs/hostsnews/archive/2008/04/14/1586548.aspx#comments</comments><description>&lt;p&gt;Landing on the following site ... the typical layout of clickable images is displayed with the following message&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;em&gt;&lt;strong&gt;Video is protected by unique technology PriveContent&lt;/strong&gt;&lt;/em&gt;&amp;quot; ... well that&amp;#39;s something new ...&lt;/p&gt;
&lt;p&gt;&lt;img height="424" alt="" src="http://mvps.org/winhelp2002/blog/niche-planet.gif" width="462" border="1" /&gt;&amp;nbsp;&lt;em&gt;Image edited for display purposes&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;If you click the &amp;quot;&lt;em&gt;Enable video now&lt;/em&gt;&amp;quot; you are redirected to a download that is detected as &amp;quot;&lt;em&gt;&lt;strong&gt;Trojan.Fake.GoogleBar&lt;/strong&gt;&lt;/em&gt;&amp;quot;&lt;br /&gt;or directly accessing the site of the download you see a similar message ...&lt;/p&gt;
&lt;p&gt;&lt;img height="312" alt="" src="http://mvps.org/winhelp2002/blog/niche-planet2.gif" width="420" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;If you read the text in the above prompt it&amp;#39;s laughable ... &amp;quot;&lt;strong&gt;you will receive 98 dollars&lt;/strong&gt;&amp;quot; ... yeah right! all you get is an infected computer. VirusTotal results &lt;a class="" href="http://www.virustotal.com/analisis/5cf196cceac700d1da95458b88c03072" target="_blank"&gt;here&lt;/a&gt; ... SunBelt technical results &lt;a class="" href="http://research.sunbelt-software.com/ViewMalware.aspx?id=3883833" target="_blank"&gt;here&lt;/a&gt; ...&lt;/p&gt;
&lt;p&gt;From their EULA: &amp;quot;&lt;em&gt;You grant PC permission to add/remove features and/or functions to the existing software and/or service, or to install new applications from PC, third parties or any other application, at any time, in our sole discretion, with or without your knowledge and/or interaction.&amp;quot;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Now if the above statement doesn&amp;#39;t alert you that you will be infected I don&amp;#39;t know what does ...&lt;/p&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1586548" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/hostsnews/archive/tags/Trojan.Fake.GoogleBar/default.aspx">Trojan.Fake.GoogleBar</category></item><item><title>Another Rogue product from LocusSoftware</title><link>http://msmvps.com/blogs/hostsnews/archive/2008/04/11/1582513.aspx</link><pubDate>Fri, 11 Apr 2008 09:58:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1582513</guid><dc:creator>winhelp2002</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/hostsnews/rsscomments.aspx?PostID=1582513</wfw:commentRss><comments>http://msmvps.com/blogs/hostsnews/archive/2008/04/11/1582513.aspx#comments</comments><description>&lt;p&gt;Following up on a &lt;a class="" href="http://msmvps.com/blogs/spywaresucks/archive/2008/04/10/1580976.aspx" target="_blank"&gt;post from Sandi&lt;/a&gt; who is reporting yet another malicious advertisement (.swf) that redirects several times until you land on one of many rogue Antispyware products from &lt;a class="" title="Whois Info" href="http://whois.domaintools.com/antispywaremaster.com" target="_blank"&gt;LocusSoftware&lt;/a&gt; ...&lt;/p&gt;
&lt;p&gt;&lt;img height="379" alt="" src="http://mvps.org/winhelp2002/blog/antispywaremaster3.gif" width="515" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;When you click the Download button you are routed to a &amp;quot;secure&amp;quot; page where you are prompted to purchase their (bogus) product ... as I &lt;a class="" href="http://msmvps.com/blogs/hostsnews/archive/2008/03/19/1547210.aspx"&gt;predicted&lt;/a&gt; before once Comodo revoked their certificated from the WinFixer/SetUpAHost (LocusSoftware) group ...&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&amp;quot;Good news gang ... I was informed by Comodo that they have revoked all certificates issues to the WinFixer/SetUpAHost ... I know it&amp;#39;s only a small victory but it causes them to look elsewhere, and I&amp;#39;m sure it won&amp;#39;t take them long to establish another bogus setup ...&amp;quot;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Looks like they switched to &amp;quot;&lt;a class="" href="http://certs.ipsca.com/" target="_blank"&gt;ipsCA&lt;/a&gt;&amp;quot; for their certificates ... (highlighted in blue)&lt;/p&gt;
&lt;p&gt;&lt;img height="320" alt="" src="http://mvps.org/winhelp2002/blog/antispywaremaster.gif" width="433" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;What&amp;#39;s scary about this connection is ipsCA is a certificate issuer via Microsoft ... from the info on their site ...&lt;/p&gt;
&lt;p&gt;&lt;img height="201" alt="" src="http://mvps.org/winhelp2002/blog/antispywaremaster2.gif" width="354" border="1" /&gt;&amp;nbsp;Image edited for display purposes.&lt;/p&gt;
&lt;p&gt;I&amp;#39;ll be contacting the involved parties to see if they will revoke these certificates as well ...&lt;/p&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1582513" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/hostsnews/archive/tags/ipsCA/default.aspx">ipsCA</category></item><item><title>Is PCSecurityShield still a Rogue Antispyware company?</title><link>http://msmvps.com/blogs/hostsnews/archive/2008/04/08/1577992.aspx</link><pubDate>Tue, 08 Apr 2008 06:57:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1577992</guid><dc:creator>winhelp2002</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/hostsnews/rsscomments.aspx?PostID=1577992</wfw:commentRss><comments>http://msmvps.com/blogs/hostsnews/archive/2008/04/08/1577992.aspx#comments</comments><description>&lt;p&gt;&lt;a class="" href="http://msmvps.com/blogs/donna/archive/2008/04/07/comodo-licensed-their-firewall-to-rogue-company.aspx" target="_blank"&gt;Donna&amp;#39;s SecurityFlash&lt;/a&gt; pointed out that there is quite a storm over the discovery that Comodo has licensed their firewall engine to PCSecurityShield ... once considered&amp;nbsp;promoting Rogue/Suspect Antispyware products ...&lt;/p&gt;
&lt;p&gt;Seems PCSecurityShield has turned around their business model and are now rebranding several Security related products. This&amp;nbsp;excerpt from Download.com (&lt;a class="" href="http://www.download.com/PCSecurityShield/3260-20_4-6292274.html" target="_blank"&gt;Company Profile&lt;/a&gt;) ...&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;em&gt;PCSecurityShield is a 3 year old internet security company that licenses various technologies and provides consumers will products to insure safe web activities. PCSecurityShield partners with many top worldwide technology companies to bring internet protection to the average consumer while providing superior, free customer service.&amp;quot;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Some of the products they now rebrand:&lt;/p&gt;
&lt;p&gt;The Shield Firewall - engine licensed from Comodo&lt;br /&gt;Spyware 24x7 - engine licensed from Lavasoft&lt;br /&gt;The Shield Deluxe 2008 6.0.2.621 - engine licensed from Kaspersky&lt;br /&gt;Security Shield 2008 - engine licensed from&amp;nbsp; F-Secure&lt;/p&gt;
&lt;p&gt;While I would not recommend any of these products, they certainly can no longer be considered Rogue products ... with that in mind I have decided to remove the related entries from the &lt;a class="" href="http://www.mvps.org/winhelp2002/hosts.htm" target="_blank"&gt;HOSTS file&lt;/a&gt; and this will reflect in the next update.&lt;/p&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1577992" width="1" height="1"&gt;</description></item><item><title>Zango Alleges Kaspersky Is Badware Itself</title><link>http://msmvps.com/blogs/hostsnews/archive/2008/04/05/1574360.aspx</link><pubDate>Sun, 06 Apr 2008 04:37:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1574360</guid><dc:creator>winhelp2002</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/hostsnews/rsscomments.aspx?PostID=1574360</wfw:commentRss><comments>http://msmvps.com/blogs/hostsnews/archive/2008/04/05/1574360.aspx#comments</comments><description>&lt;p&gt;Well ... here we go again ... MediaPost is &lt;a class="" href="http://publications.mediapost.com/index.cfm?fuseaction=Articles.showArticleHomePage&amp;amp;art_aid=79635" target="_blank"&gt;reporting&lt;/a&gt; that Zango is again going after Kaspersky. Zango lost round 1 in court and they are not happy with the decision. In their latest filing (link to .pdf &lt;a class="" href="http://blog.ericgoldman.org/" target="_blank"&gt;here&lt;/a&gt;) they state the Court was wrong and that Kaspersky is actually Badware (as defined in &lt;a class="" href="http://www.stopbadware.org/" target="_blank"&gt;StopBadware.org&lt;/a&gt;) ... now that&amp;#39;s a real stretch!&lt;/p&gt;
&lt;p&gt;Then Zango goes on to describe Kaspersky as &amp;quot;&lt;a class="" title="Wikipedia Description" href="http://en.wikipedia.org/wiki/Scareware" target="_blank"&gt;Scareware&lt;/a&gt;&amp;quot; ... imagine that! this should get real interesting when Kaspersky responds ... &amp;quot;&lt;em&gt;&lt;a class="" href="http://www.microsoft.com/security/portal/" target="_blank"&gt;Microsoft Malware Protection Center&lt;/a&gt;&lt;/em&gt;&amp;quot; reports Zango/Hotbar ranks 3 of of the Top 10 ...&lt;/p&gt;
&lt;p&gt;&lt;img height="262" alt="" src="http://mvps.org/winhelp2002/blog/zangotop10.gif" width="277" border="0" /&gt;&lt;/p&gt;
&lt;p&gt;I guess we can tell who is the real &amp;quot;Badware&amp;quot; here ... sounds like it&amp;#39;s time for another Benjamin Edelman &lt;a class="" href="http://www.benedelman.org/news/073107-1.html" target="_blank"&gt;report&lt;/a&gt; ... which found that Zango was in violation of the FTC agreement ...&lt;/p&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1574360" width="1" height="1"&gt;</description></item><item><title>Vomba Acquires Adware Company WhenU</title><link>http://msmvps.com/blogs/hostsnews/archive/2008/04/04/1571935.aspx</link><pubDate>Fri, 04 Apr 2008 16:25:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1571935</guid><dc:creator>winhelp2002</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/hostsnews/rsscomments.aspx?PostID=1571935</wfw:commentRss><comments>http://msmvps.com/blogs/hostsnews/archive/2008/04/04/1571935.aspx#comments</comments><description>&lt;p&gt;MediaPost is &lt;a class="" href="http://publications.mediapost.com/index.cfm?fuseaction=Articles.showArticleHomePage&amp;amp;art_aid=79634" target="_blank"&gt;reporting&lt;/a&gt; that Vomba has acquired Whenu ... Who is Vomba? they are a division of &amp;quot;Gamma Entertainment&amp;quot;&lt;/p&gt;
&lt;p&gt;Just so there is no confusion of &amp;quot;who-is-who&amp;quot; ... and where they are located:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Vomba Network&lt;br /&gt;&amp;nbsp;3300 Cote-Vertu, Suite 406&lt;br /&gt;&amp;nbsp;Montreal, QC H4R 2B7&lt;/p&gt;
&lt;p&gt;&amp;nbsp;WHENU.COM&lt;br /&gt;&amp;nbsp;3300 Cote-Vertu, Suite 406&lt;br /&gt;&amp;nbsp;Montreal, QC H4R 2B7&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Surfing accuracy&lt;br /&gt;&amp;nbsp;3300 Cote-Vertu Suite 406&lt;br /&gt;&amp;nbsp;Montreal, Quebec H4R 2B7&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Media Traffic Agency Inc&lt;br /&gt;&amp;nbsp;3300 Cote-Vertu Suite 406&lt;br /&gt;&amp;nbsp;Montreal, Quebec H4R 2B7&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Integrated Search Technologies&lt;br /&gt;&amp;nbsp;3300 Cote-Vertu Suite 410&lt;br /&gt;&amp;nbsp;Montreal, Quebec H4R 2B7&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Gamma Entertainment Inc&lt;br /&gt;&amp;nbsp;3300 Cote-Vertu Suite 406&lt;br /&gt;&amp;nbsp;Montreal, Quebec H4R 2B7&lt;/p&gt;
&lt;p&gt;[Gamma Entertainment][66.152.92.0 - 66.152.92.255]&lt;/p&gt;
&lt;p&gt;[Gamma Networking via Integrated Search Technologies][66.152.93.0 - 66.152.93.127]&lt;/p&gt;
&lt;p&gt;[Gamma Networking via Marketing Engines][66.152.85.0 - 66.152.85.255]&lt;/p&gt;
&lt;p&gt;[Gamma Networking via Surfaccuracy][66.152.93.128 - 66.152.93.255]&lt;/p&gt;
&lt;p&gt;The &amp;quot;adware&amp;quot; community has been relatively quite lately, however I suspect we are about to see a new rash of adware applications involving all of the above ...&lt;/p&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1571935" width="1" height="1"&gt;</description></item></channel></rss>