<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Hosts News : SetupAHost</title><link>http://msmvps.com/blogs/hostsnews/archive/tags/SetupAHost/default.aspx</link><description>Tags: SetupAHost</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Attack of the WinFixer Clones</title><link>http://msmvps.com/blogs/hostsnews/archive/2007/10/06/1234124.aspx</link><pubDate>Sat, 06 Oct 2007 08:34:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1234124</guid><dc:creator>winhelp2002</dc:creator><slash:comments>2</slash:comments><comments>http://msmvps.com/blogs/hostsnews/archive/2007/10/06/1234124.aspx#comments</comments><description>&lt;p&gt;Lately there has been a huge increase in the WinFixer affiliates/clones ... although these clones go to great lengths to hide their true idenity, you can sniff them out if you know where to look ... WinFixer is run by &amp;quot;Innovative Marketing&amp;quot; and their main distrubtion host is SetupAHost based in Canada, although WinFixer also has&amp;nbsp;setup servers&amp;nbsp;in several other countries.&lt;/p&gt;
&lt;p&gt;Acting on a email tip from Sebastiaan S I browsed over to &amp;quot;&lt;em&gt;performanceoptimizer(dot)com&lt;/em&gt;&amp;quot;. Clicking the Download button redirects to a (https) payment site. Both of these sites are related and using the same IP address (190.15.73.254) However as you can see below there is already a&amp;nbsp;problem ...&lt;/p&gt;
&lt;p&gt;&lt;img src="http://mvps.org/winhelp2002/blog/performanceoptimizer1.gif" border="1" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;To show you the SetupAHost connection you have to look at the (https) traffic and the details which is displayed below and clearly shows (highlighted in red) SetupAHost.&lt;/p&gt;
&lt;p&gt;&lt;img style="WIDTH:484px;HEIGHT:531px;" height="531" src="http://mvps.org/winhelp2002/blog/performanceoptimizer.gif" width="484" border="1" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;Now if you browse over to &amp;quot;freerepair(dot)org&amp;quot; on the same IP address ... oh my even my AV (NOD32) knows it&amp;#39;s WinFixer!&lt;/p&gt;
&lt;p&gt;&lt;img src="http://mvps.org/winhelp2002/blog/freerepair.gif" border="1" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;Another clone of the same IP Address is&amp;nbsp;CryptDrive which &lt;a class="" href="http://www.symantec.com/en/hk/smb/security_response/writeup.jsp?docid=2007-091020-4537-99" target="_blank"&gt;Symantec describes&lt;/a&gt; as:&lt;br /&gt;&lt;em&gt;&amp;quot;CryptDrive is a misleading application that may give exaggerated reports about potential risks on the computer.&amp;quot;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Sadly I though we had convinced ValueClick to &lt;a class="" href="http://msmvps.com/blogs/hostsnews/archive/2007/05/25/valueclick-cuts-ties-with-the-winfixer-group.aspx" target="_blank"&gt;break their ties&lt;/a&gt; with WinFixer ... but it looks like that is not the case.&lt;br /&gt;Yes &amp;quot;ad2cash&amp;quot; is on the same IP as the above and there are quite a few other examples of the below ...&lt;/p&gt;
&lt;p&gt;&lt;img style="WIDTH:500px;HEIGHT:261px;" height="261" src="http://mvps.org/winhelp2002/blog/ad2cash.gif" width="500" border="1" alt="" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1234124" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/hostsnews/archive/tags/SetupAHost/default.aspx">SetupAHost</category></item></channel></rss>