<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Hosts News : ipsCA</title><link>http://msmvps.com/blogs/hostsnews/archive/tags/ipsCA/default.aspx</link><description>Tags: ipsCA</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Another Rogue product from LocusSoftware</title><link>http://msmvps.com/blogs/hostsnews/archive/2008/04/11/1582513.aspx</link><pubDate>Fri, 11 Apr 2008 09:58:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1582513</guid><dc:creator>winhelp2002</dc:creator><slash:comments>1</slash:comments><comments>http://msmvps.com/blogs/hostsnews/archive/2008/04/11/1582513.aspx#comments</comments><description>&lt;p&gt;Following up on a &lt;a class="" href="http://msmvps.com/blogs/spywaresucks/archive/2008/04/10/1580976.aspx" target="_blank"&gt;post from Sandi&lt;/a&gt; who is reporting yet another malicious advertisement (.swf) that redirects several times until you land on one of many rogue Antispyware products from &lt;a class="" title="Whois Info" href="http://whois.domaintools.com/antispywaremaster.com" target="_blank"&gt;LocusSoftware&lt;/a&gt; ...&lt;/p&gt;
&lt;p&gt;&lt;img height="379" alt="" src="http://mvps.org/winhelp2002/blog/antispywaremaster3.gif" width="515" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;When you click the Download button you are routed to a &amp;quot;secure&amp;quot; page where you are prompted to purchase their (bogus) product ... as I &lt;a class="" href="http://msmvps.com/blogs/hostsnews/archive/2008/03/19/1547210.aspx"&gt;predicted&lt;/a&gt; before once Comodo revoked their certificated from the WinFixer/SetUpAHost (LocusSoftware) group ...&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&amp;quot;Good news gang ... I was informed by Comodo that they have revoked all certificates issues to the WinFixer/SetUpAHost ... I know it&amp;#39;s only a small victory but it causes them to look elsewhere, and I&amp;#39;m sure it won&amp;#39;t take them long to establish another bogus setup ...&amp;quot;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Looks like they switched to &amp;quot;&lt;a class="" href="http://certs.ipsca.com/" target="_blank"&gt;ipsCA&lt;/a&gt;&amp;quot; for their certificates ... (highlighted in blue)&lt;/p&gt;
&lt;p&gt;&lt;img height="320" alt="" src="http://mvps.org/winhelp2002/blog/antispywaremaster.gif" width="433" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;What&amp;#39;s scary about this connection is ipsCA is a certificate issuer via Microsoft ... from the info on their site ...&lt;/p&gt;
&lt;p&gt;&lt;img height="201" alt="" src="http://mvps.org/winhelp2002/blog/antispywaremaster2.gif" width="354" border="1" /&gt;&amp;nbsp;Image edited for display purposes.&lt;/p&gt;
&lt;p&gt;I&amp;#39;ll be contacting the involved parties to see if they will revoke these certificates as well ...&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1582513" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/hostsnews/archive/tags/ipsCA/default.aspx">ipsCA</category></item></channel></rss>