<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Hosts News : Pandora Software</title><link>http://msmvps.com/blogs/hostsnews/archive/tags/Pandora+Software/default.aspx</link><description>Tags: Pandora Software</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Can Sponsored Results be trusted?</title><link>http://msmvps.com/blogs/hostsnews/archive/2008/08/26/1645917.aspx</link><pubDate>Wed, 27 Aug 2008 04:09:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1645917</guid><dc:creator>winhelp2002</dc:creator><slash:comments>4</slash:comments><comments>http://msmvps.com/blogs/hostsnews/archive/2008/08/26/1645917.aspx#comments</comments><description>&lt;p&gt;I&amp;#39;ve commented about this subject before ... and I have still not changed my mind ... NO No No ...&lt;/p&gt;
&lt;p&gt;Recently the &lt;a target="_blank" href="http://sunbeltblog.blogspot.com/2008/08/continuing-problem-of-malware-being.html"&gt;SunBelt blog&lt;/a&gt; touched on this, and I thought I&amp;#39;d provide a good example ...&lt;/p&gt;
&lt;p&gt;&lt;img width="503" src="http://mvps.org/winhelp2002/blog/avxp-2008.gif" height="501" style="border:1px solid black;" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;em&gt;Tested by g0Ogle&lt;/em&gt;&amp;quot; ... I think not! ... if a user happens to click that &amp;quot;Sponsored Link&amp;quot; ... they end up here ...&lt;/p&gt;
&lt;p&gt;&lt;img width="565" src="http://mvps.org/winhelp2002/blog/avxp-20082.gif" height="553" style="border:1px solid black;" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;So not only do these culprits want to whack you with a infectious ActiveX (&lt;em&gt;virusremover.dll&lt;/em&gt;) they also want you to click the &amp;quot;Remove All&amp;quot; button to install their fake antispyware program and all the other nasties that come with it ... my AV NOD32 v3 however doesn&amp;#39;t think that would be a good idea ...&lt;/p&gt;
&lt;p&gt;&lt;img width="300" src="http://mvps.org/winhelp2002/blog/avxp-20083.gif" height="144" style="border:1px solid black;" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;Submitting &amp;quot;&lt;em&gt;virusremover.dll&lt;/em&gt;&amp;quot; to &lt;a target="_blank" href="http://www.virustotal.com/analisis/8758b1d10f81d5bfe002b2919ce94fb5"&gt;VirusTotal&lt;/a&gt; gives the following &lt;strong&gt;Result: 23/36 (63.89%)&lt;/strong&gt; &lt;/p&gt;
&lt;p&gt;&lt;img width="527" src="http://mvps.org/winhelp2002/blog/avxp-20084.gif" height="235" style="border:1px solid black;" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;Notice that &lt;strong&gt;Ask&lt;/strong&gt; routes their Sponsored Result thru Google then redirects to the (un)desired site ...&lt;br /&gt;&amp;quot;avxp-2008(dot)net&amp;quot; is yet another site maintained by the &amp;quot;Pandora Software Group&amp;quot;&lt;/p&gt;
&lt;p&gt;I could provide many more examples ... but you get the idea ... even these &amp;quot;&lt;a target="_blank" href="http://en.wikipedia.org/wiki/Domain_parking" title="Wikipedia description of Parked Sites"&gt;Parking Services&lt;/a&gt;&amp;quot; use these type of practices in their fake Sponsored Results on &amp;quot;Parked&amp;quot; sites ... and that why I include many of their sites as entries in the &lt;a target="_blank" href="http://www.mvps.org/winhelp2002/hosts.htm"&gt;HOSTS file&lt;/a&gt; ... everyone is glad to take the &lt;strong&gt;$$$&lt;/strong&gt; provided by these clients, but very few services are willing to investigate these clients prior to hosting their content ...&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1645917" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/hostsnews/archive/tags/Pandora+Software/default.aspx">Pandora Software</category></item><item><title>Another Rogue Antispyware product from the Pandora Software group</title><link>http://msmvps.com/blogs/hostsnews/archive/2008/04/16/1591440.aspx</link><pubDate>Thu, 17 Apr 2008 01:02:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1591440</guid><dc:creator>winhelp2002</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/hostsnews/archive/2008/04/16/1591440.aspx#comments</comments><description>&lt;p&gt;Following up on a article from our friends at BleepingComputer &amp;quot;&lt;a class="" href="http://www.bleepingcomputer.com/malware-removal/malware-bell" target="_blank"&gt;How to remove Malware Bell&lt;/a&gt;&amp;quot; we find:&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;em&gt;Malware Bell is a rogue anti-spyware from the same developers as IE Defender and Files Secure. Malware Bell is installed and advertised through the use of Trojans that are installed as Internet Explorer Browser Helper Objects&lt;/em&gt;.&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;img height="436" alt="" src="http://mvps.org/winhelp2002/blog/malwarebell3.gif" width="599" border="0" /&gt;&lt;/p&gt;
&lt;p&gt;These people are so lame they can&amp;#39;t even write their own detections ... (highlighted in red) it&amp;#39;s actually from McAfee ... &lt;/p&gt;
&lt;p&gt;&lt;img height="454" alt="" src="http://mvps.org/winhelp2002/blog/malwarebell2.gif" width="516" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;As you can see there are several redirects when you [choke] attempt to purchase their bogus product ... the sad part is here is &lt;a class="" href="http://msmvps.com/blogs/hostsnews/archive/2008/04/11/1582513.aspx"&gt;another example&lt;/a&gt; of &amp;quot;ipsCA&amp;quot; issuing certificates to known bogus products ...&lt;/p&gt;
&lt;p&gt;&lt;img height="332" alt="" src="http://mvps.org/winhelp2002/blog/malwarebell.gif" width="432" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;I found the exact same thing with &amp;quot;VirusIsolator&amp;quot; which Symantec &lt;a class="" href="http://www.symantec.com/security_response/writeup.jsp?docid=2008-041610-1005-99" target="_blank"&gt;detects and describes&lt;/a&gt; as:&lt;br /&gt;&amp;quot;&lt;em&gt;The program reports false or exaggerated system security threats on the computer.&amp;quot;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;So I have to ask ... &lt;strong&gt;ipsCA what are you thinking!&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&amp;quot;installed and advertised through the use of Trojans&amp;quot; ... &amp;quot;reports false or exaggerated system security threats&amp;quot;&lt;/p&gt;
&lt;p&gt;Yes I did contact ipsCA previously and all I got back was an automated reply with a &amp;quot;&lt;em&gt;Support:276800&lt;/em&gt;&amp;quot; ...&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1591440" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/hostsnews/archive/tags/Pandora+Software/default.aspx">Pandora Software</category></item></channel></rss>