<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Spyware Sucks : Fraudware</title><link>http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx</link><description>Tags: Fraudware</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Fraudware that looks like Windows 7…</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/12/08/1744189.aspx</link><pubDate>Tue, 08 Dec 2009 07:12:02 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1744189</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1744189</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/12/08/1744189.aspx#comments</comments><description>&lt;p&gt;I saw this screenshot at the &lt;a href="http://pandalabs.pandasecurity.com/archive/Rogue-Antivirus-Optimized-for-Windows-7.aspx" target="_blank"&gt;Panda Software blog&lt;/a&gt;.&amp;#160; &lt;/p&gt;  &lt;p&gt;The author of the blog post wrote that the replica of the Windows 7 explorer shell displayed by the fraudware site was “devilishly deceiving and might even fool an expertly trained eye”.&lt;/p&gt;  &lt;p&gt;I would hope that an “expertly trained eye” would spot the fact that the word “Searches” has been mis-typed as “Seraches”&amp;#160; ;o)&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;img style="display:inline;" title="w7" alt="w7" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/7140.w7_5F00_4BCE935D.png" width="812" height="570" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1744189" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>FTC versus Innovative Marketing et al - developments</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/11/18/1740364.aspx</link><pubDate>Tue, 17 Nov 2009 23:58:50 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740364</guid><dc:creator>sandi</dc:creator><slash:comments>3</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1740364</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/11/18/1740364.aspx#comments</comments><description>&lt;p&gt;As we know, Jain&amp;#39;s legal counsel have applied for leave to withdraw as his attorneys of record.&amp;#160; They have not been given permission to withdraw yet, and the deadline for Jain to respond to the FTC&amp;#39;s renewed motion for sanctions was nigh, therefore Jain&amp;#39;s counsel has filed a document in opposition to the renewed motion. &lt;/p&gt;  &lt;p&gt;Jain&amp;#39;s counsel claims that: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Mr. Jain is not acting in bad faith, but on a well-justified fear that the FTC will attempt to circumvent and undermine his valid Fifth Amendment privilege against self-incrimination&lt;/em&gt;&amp;quot;. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;and &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Regarding deterrence, Mr. Jain is not guilty of a pattern of contumacious behavior; indeed, through counsel, he otherwise has actively participated in this case for almost one year&lt;/em&gt;.&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;and &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Finally, the FTC does not even address the possibility of lesser sanctions against Mr. Jain.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;My immediate reaction, on reading the motion, was “&lt;em&gt;come on, who are they trying to fool?&lt;/em&gt;”. Let&amp;#39;s not forget, when reading the above, that Jain&amp;#39;s legal counsel claim in their motion for leave to withdraw that they have NEVER had direct contact with Jain, and that they have had no indirect contact with him for more than 10 months, and that they have no idea where he is.&amp;#160; Such silence does not equate to &amp;#39;active&amp;#39; participation in my world. &lt;/p&gt;  &lt;p&gt;Not surprisingly, the FTC&amp;#39;s response has been swift and states, in part: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Counsel’s description of Jain’s conduct bears no resemblance to the facts of this case. Jain – a fugitive for nearly a year now – has been toying with this Court and the FTC from the outset of this case. Jain has ignored the Temporary Restraining Order and Preliminary Injunction entered by this Court, and completely disregarded this Court’s most recent command that he appear for deposition.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;and &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Jain has also wasted this Court’s time with a barrage of frivolous motions, which were designed solely to bog down this litigation and delay the FTC’s efforts to obtain redress on behalf of the millions of consumers Jain and his co-defendants have defrauded. Having succeeded in delaying this case for as long as possible, Jain has now disappeared, and left his lawyers behind to craft excuses for his egregious conduct.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;It makes you wonder whether Jain&amp;#39;s lawyers have received, or are going to receive, payment for their hard work over the past year, doesn&amp;#39;t it.&amp;#160; Here&amp;#39;s hoping they received plenty of $$ in advance.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740364" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>FTC versus Innovative Marketing et al - Sam Jain's legal counsel request leave to withdraw as attorneys of record</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/11/16/1739915.aspx</link><pubDate>Mon, 16 Nov 2009 01:49:05 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1739915</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1739915</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/11/16/1739915.aspx#comments</comments><description>&lt;p&gt;In a not unsurprising development, legal counsel for Sam Jain have petitioned the Court for permission to withdraw as attorneys for Sam Jain.&amp;#160; The FTC does not oppose the request, but does object to any further extension of Mr Jain&amp;#39;s time to respond to the FTC&amp;#39;s pending Renewed Motion for Rule 37 Sanctions. &lt;/p&gt;  &lt;p&gt;The reasons Jain&amp;#39;s attorneys ask for permission to withdraw are: &lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;They have NEVER communicated directly with Jain.&lt;/li&gt;    &lt;li&gt;Their last indirect communication with Jain was received on January 14, 2009.&lt;/li&gt;    &lt;li&gt;They have not communicated with Jain in more than 10 months, since before the bench warrant was issued for Jain&amp;#39;s arrest by the US District Court for the Northern District of California in an unrelated.&lt;/li&gt;    &lt;li&gt;They claim to have no knowledge of Jain&amp;#39;s whereabouts, and to have no ability to contact him directly. &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;Jain&amp;#39;s legal counsel state that &amp;quot;considering the bench warrant in the Northern District of California and the ongoing criminal investigation in the Northern District of Illinois, there is no indication Mr Jain will participate meaningfully in discovery, with or without counsel.&amp;quot;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1739915" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>FTC versus Innovative Marketing et al - developments</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/11/11/1738897.aspx</link><pubDate>Wed, 11 Nov 2009 03:33:51 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1738897</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1738897</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/11/11/1738897.aspx#comments</comments><description>&lt;p&gt;Innovative Marketing and Daniel Sundin are still unrepresented.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;09/16/2009      &lt;br /&gt;ORDER denying Motion of Marc D&amp;#39;Souza to Dismiss the Complaint. DIRECTING D&amp;#39;Souza to answer the complaint within 20 days. Signed by Judge Richard D Bennett on 9/16/09. &lt;/strong&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Viewing the totality of the allegations through the lens of judicial experience and common sense, this Court finds that the FTC has clearly “plea{d} factual content that allows the court to draw the reasonable inference that the defendant is liable for the misconduct alleged.” Iqbal, 129 S. Ct. at 1949 (citing Twombly, 550 U.S. at 50). Through its extensive factual pleadings, the FTC has positioned its claims against Marc D’Souza safely within the realm of plausibility.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;10/02/2009      &lt;br /&gt;MEMORANDUM ORDER granting Motion for Sanctions against Sam Jain insofar as certain conditions are imposed.&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;“The FTC’s Motion for Rule 37 Sanctions against Defendant Sam Jain (Paper No. 131) is GRANTED insofar as the following conditions are hereby imposed: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;em&gt;“1. the FTC is instructed to re-notice Jain’s deposition for an agreed upon time within the next thirty days of the date hereof;        &lt;br /&gt;2. Jain shall again be offered the opportunity to be deposed by video-conference from a location of his choosing;         &lt;br /&gt;3. Jain is hereby warned that if he fails to attend this upcoming deposition, this Court will consider imposing a default judgment against him pursuant to Federal Rule of Civil Procedure 37(d).”&lt;/em&gt; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;10/06/2009      &lt;br /&gt;ANSWER to FTC Complaint (document 1), by Marc D&amp;#39;Souza&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;A few minor admissions, lots of denials, a claim that &amp;quot;the FTC has authority to seek restitution, consumer redress or disgorgement with respect to conduct that took place outside the United States and that does not affect domestic commerce&amp;quot;, lot of declining to answer under the Fifth Amendment (while at the same time requesting that said refusal be treated as a denial).&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;10/22/2009      &lt;br /&gt;Second MOTION for Sanctions Pursuant to Rule 37 Against Sam Jain by Federal Trade Commission. Responses due by 11/9/2009&lt;/strong&gt; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Sam Jain has made a mockery of this proceeding and has demonstrated nothing but contempt for this Court and the American judicial system as a whole. Together with his codefendants, Jain perpetrated one of the largest online frauds ever prosecuted by the FTC, with a total consumer injury figure that – as the Court will soon hear – exceeds $150 million. After being caught red-handed by the FTC, Jain promptly fled the United States, leaving his lawyers behind to delay the FTC’s efforts to redress the massive consumer injury Jain helped inflict. After nearly a year of delay, Jain has reached the end of the road. Unwilling to comply with this Court’s command that he participate in discovery, Jain has no further ability to stall this litigation. As a result, Jain has washed his hands of this matter, and simply disappeared. Given these facts, it is difficult to imagine a case that better supports the imposition of terminating sanctions, or an individual more deserving of such an outcome than Jain.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;11/02/2009      &lt;br /&gt;MOTION for Extension of Time to File Response/Reply as to Second MOTION for Sanctions Pursuant to Rule 37 Against Sam Jain by Sam Jain. Responses due by 11/19/2009 (unopposed)&lt;/strong&gt; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Mr. Jain respectfully submits that good cause for granting this Motion exists: (1) Mr. Jain has not requested or received from the Court an extension on any other response or reply filed in this case; (2) Logistical obstacles and the important factual and legal issues raised by the FTC’s Renewed Motion necessitate a brief extension of time to respond.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;11/03/2009      &lt;br /&gt;Paperless ORDER granting Defendant Jain&amp;#39;s unopposed Motion for Extension of Time. Response to Second Motion for Sanctions due 11/16/2009 &lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1738897" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>Ponderings about the New York Times malvertizing incident</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/09/15/1723398.aspx</link><pubDate>Tue, 15 Sep 2009 05:08:33 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1723398</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1723398</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/15/1723398.aspx#comments</comments><description>&lt;p&gt;It has been all over the popular press – the New York Times web site had been tricked into accepting a malvertizement that was hijacking some visitors to that site and dumping them at a web site touting fake security software.&amp;#160; And, in a move that is kind of unusual, the New York Times web site displayed a warning about the malvertizement.&lt;/p&gt;  &lt;p&gt;It just so happens that over on &lt;a href="http://troy.yort.com/anatomy-of-a-malware-ad-on-nytimes-com" target="_blank"&gt;yort.com&lt;/a&gt; (author: Troy Davis) there is a screenshot demonstrating how the hijack was triggered:&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;table border="5" cellspacing="2" cellpadding="5" width="924"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="433"&gt;         &lt;p align="center"&gt;&lt;strong&gt;New York Times incident as &lt;/strong&gt;&lt;strong&gt;reported on yort.com&lt;/strong&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="475"&gt;         &lt;p align="center"&gt;&lt;strong&gt;Similar incident as reported on Spyware Sucks&lt;/strong&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="433"&gt;&lt;img style="border-right-width:0px;display:block;float:none;border-top-width:0px;border-bottom-width:0px;margin-left:auto;border-left-width:0px;margin-right:auto;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/6763.image_5F00_76465918.png" width="447" height="460" /&gt; &lt;/td&gt;        &lt;td valign="top" width="475"&gt;&amp;#160;&lt;img style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/4705.image_5F00_27FB9365.png" width="626" height="335" /&gt; &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;As you can see from the screenshots above, the two incidents are very similar, and the important stuff – the stuff that caused the hijack – is the code starting at “var a1” in both screenshots.&amp;#160; Depending on various conditions and controls (geolocation, IP address, time of day etc) some visitors would have received JUST the advertisement – others would have seen **the same advertisement** but would have also received the extra code (as pointed out above, starting at var a1).&lt;/p&gt;  &lt;p&gt;The IP address of the hijacking domain, tradenton.com, is:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;at a known bad IP (as reported on this blog on the 10th of September) &lt;/li&gt;    &lt;li&gt;other bad domains were discovered in the same IP range as far back as 4 September &lt;/li&gt;    &lt;li&gt;was very new (registered just this month) &lt;/li&gt;    &lt;li&gt;was registered using a known problematic Registrar &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;I have said many times on this blog and elsewhere that reputational checks are of CRITICAL IMPORTANCE when accepting advertisements.&amp;#160; Information was available to warn those alert to potential danger that caution was needed as far back as the 4th of September (cite: &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/04/1720609.aspx" target="_blank"&gt;my alert about vonage-inc.com on 4 September 2009&lt;/a&gt;).&lt;/p&gt;  &lt;p&gt;Please… take advantage of services such as &lt;a title="http://www.anti-malvertising.com/" href="http://www.anti-malvertising.com/" target="_blank"&gt;http://www.anti-malvertising.com/&lt;/a&gt; and start conducting indepth research when somebody tries to sell you advertising.&amp;#160; One day, your web site may not be hit by an advertisement that simply redirects your visitors to a fake security website.&amp;#160; Instead, your visitors may be redirected to:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;a p0rn0graphic web site, complete with streaming video and sound on the opening page:      &lt;br /&gt;&lt;a title="http://msmvps.com/blogs/spywaresucks/archive/2007/12/31/1428144.aspx" href="http://msmvps.com/blogs/spywaresucks/archive/2007/12/31/1428144.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2007/12/31/1428144.aspx&lt;/a&gt;       &lt;br /&gt;&lt;/li&gt;    &lt;li&gt;a web site that tries to infect your visitor’s computers using various security exploits:      &lt;br /&gt;      &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx&lt;/a&gt;       &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/07/22/1704910.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/07/22/1704910.aspx&lt;/a&gt; &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;img style="border-right-width:0px;margin:10px 0px 0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/7345.image_5F00_7C96B0C3.png" width="532" height="140" /&gt;     &lt;br /&gt;&lt;strong&gt;The New York Times hijack in progress, as captured and reported by yort.com…&lt;/strong&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;I have been reading the report at &lt;a href="http://www.wired.com/threatlevel/2009/09/nyt-revamps-online-ad-sales-after-malware-scam/" target="_blank"&gt;wired.com&lt;/a&gt; about this incident, and think it is worthwhile pondering some of the points made in the article.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;wired.com: “The move comes after a security loophole allowed scammers over the weekend to swap an innocuous advertisement for one serving a fake virus-warning, and hawking a deceptive scareware product intended to sell bogus security software.”&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;wired.com: ““Over the weekend, the ad being served up was switched so that an intrusive message, claiming to be a virus warning from the reader’s computer, appeared.”&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;wired.com are correct when they say that the incident occurred because of a “security loophole” (that is, the New York Times allowed content to be displayed on its web site that was hosted remotely by a domain outside of their direct command and control – an extremely common behavior and certainly not unusual to the New York Times).&amp;#160; &lt;/p&gt;  &lt;p&gt;That being said, I find it interesting that an “innocuous advertisement” would be “swapped out” or “switched”.&amp;#160; Standard modus operandi for incidents such as the one caught by yort.com has always been to simply add additional malicious code when certain conditions were met – the advertisement itself has not changed in previous incidents (except for when there is an industry-standard rotation of advertisements, which is not the same as a deliberate swapping out).&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;wired.com: “Readers &lt;u&gt;who clicked on the ad&lt;/u&gt; found their browsers hijacked while a fake virus-scan was displayed. If they allowed the malicous (sic) website to serve its executable payload, they’d be stuck with a fake scareware program that badgers them into buying supposed anti-virus software.”&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Wrong.&amp;#160; No user interaction is required for the hijack to occur.&amp;#160; Nobody needed to click on anything.&lt;/p&gt;  &lt;p&gt;Also, as evidenced by the yort.com report, if a person was not hijacked (and therefore had the opportunity to click on the advertisement), then they were redirected to a legitimate website (in the yort.com example, the BVLGARI advertisement was linked to the URL &lt;a title="http://www.bulgari.com/main.php?lang=6/ref=680" href="http://www.bulgari.com/main.php?lang=6/ref=680" target="_blank"&gt;http://www.bulgari.com/main.php?lang=6/ref=680&lt;/a&gt;).&lt;/p&gt;  &lt;p&gt;bulgari.com    &lt;br /&gt;ICANN Registrar: GROUP NBT PLC AKA NETNAMES     &lt;br /&gt;Created 17 February 1998     &lt;br /&gt;AUTH200.NS.UU.NET     &lt;br /&gt;AUTH210.NS.UU.NET     &lt;br /&gt;NS.BULGARI.COM &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Bulgari SpA     &lt;br /&gt;Lungotevere Marzio 11     &lt;br /&gt;Roma     &lt;br /&gt;00186     &lt;br /&gt;IT&lt;/p&gt;  &lt;p&gt;&lt;img style="border-right-width:0px;margin:10px 20px 20px 0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/7444.image_5F00_0926EE91.png" width="326" height="276" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;wired.com: “The Times declined to identify the “national advertiser” the scammers originally impersonated.”&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Again, let’s refer to yort.com.&amp;#160; From that article I can retrieve the URL of the advertisement used – you can see it to left of screen (I should warn you that there *may* have been more than one advertisement being supplied by the miscreants – we should not assume that this was the only advertisement that a victim may have seen).&lt;/p&gt;  &lt;p&gt;The author also writes:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“A comment gave the campaign ID as Vonage01_1163613_nyt12, though it was obviously unrelated to Vonage.”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;I wonder if the domain &lt;strong&gt;vonage-inc.com&lt;/strong&gt; was used by whoever it was that sold the malvertizing to the New York Times.&amp;#160; vonage-inc.com used to have the IP address 212.117.166.71, and known to be used by cybercriminals to impersonate the real Vonage.&amp;#160; Thankfully, vonage-inc.com seem to have been handed over to the *real* Vonage on or about 5 September.&lt;/p&gt;  &lt;p&gt;I wrote about vonage-inc.com back on &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/04/1720609.aspx" target="_blank"&gt;4 September 2009&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Edit: I see that the &lt;a href="http://www.nytimes.com/2009/09/15/technology/internet/15adco.html?_r=1" target="_blank"&gt;New York Times has admitted that Vonage was impersonated&lt;/a&gt;:&lt;/p&gt;  &lt;p&gt;&lt;em&gt;“The creator of the malicious ads posed as Vonage, the Internet telephone company, and persuaded NYTimes.com to run ads that initially appeared as real ads for Vonage. At some point, possibly late Friday, the campaign switched to displaying the virus warnings. &lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Because The Times thought the campaign came straight from Vonage, which has advertised on the site before, it allowed the advertiser to use an outside vendor that it had not vetted to actually deliver the ads, Ms. McNulty said. That allowed the switch to take place. “In the future, we will not allow any advertiser to use unfamiliar third-party vendors,” she said.”&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;Just to repeat what I said above, information was available on the net, warning that Vonage was being impersonated, as far back as &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/04/1720609.aspx" target="_blank"&gt;4 September&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;So, what do we know about the domains implicated in this latest incident? &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;tradenton.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC     &lt;br /&gt;Created 2 September 2009     &lt;br /&gt;NS1.EVERYDNS.NET     &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.69 - Luxembourg, Root Esolutions (a known bad IP address – also, note how close the IP address is to what used to be the IP address for vonage-inc.com)&lt;/p&gt;  &lt;p&gt;Currently shares IP with harlingens.com, kennedales.com, newadsresults.com, relunas.com and waveadvert.com &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Tradenton     &lt;br /&gt;Shawn Brownell (shawn@tradenton.com)     &lt;br /&gt;978-214-3972 fax: 978-214-3972     &lt;br /&gt;3051 Pearlman Avenue     &lt;br /&gt;Wilmington MA 01887     &lt;br /&gt;US &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;harlingens.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC     &lt;br /&gt;Created 2 September 2009     &lt;br /&gt;NS1.EVERYDNS.NET     &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;harlingens.com     &lt;br /&gt;Richard Andrew (admin@harlingens.com)     &lt;br /&gt;956-893-2463 fax: 956-893-2463     &lt;br /&gt;4859 Carolina Avenue     &lt;br /&gt;Harlingen TEX 78550 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;sex-and-the-city.cn&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: Chinese     &lt;br /&gt;Created 3 September 2009     &lt;br /&gt;NS1.EVERYDNS.NET     &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 94.102.48.209 - Noord-holland, Amsterdam, As29073 Ecatel Ltd &lt;/p&gt;  &lt;p&gt;Registrant: oregon.artscomm@state.or.us &lt;/p&gt;  &lt;p&gt;*****&lt;/p&gt;  &lt;p&gt;Finally, yort.com mentions adxbigad - I have found several references to adxbigad in scripts designed to remove advertising from the New York Times web site (cite: &lt;a href="http://userscripts.org/scripts/review/56684)" target="_blank"&gt;http://userscripts.org/scripts/review/56684)&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1723398" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>FTC versus Innovative Marketing et al – developments: Innovative Marketing and Daniel Sundin</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/08/12/1714996.aspx</link><pubDate>Wed, 12 Aug 2009 03:37:43 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1714996</guid><dc:creator>sandi</dc:creator><slash:comments>1</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1714996</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/08/12/1714996.aspx#comments</comments><description>&lt;p&gt;An Order of Default was entered against Innovative Marketing and Daniel Sundin on 6 August 2009 “&lt;em&gt;&lt;strong&gt;for want of answer or other defense&lt;/strong&gt;”&lt;/em&gt;.&lt;/p&gt;  &lt;p&gt;Regular readers will know that Innovative Marketing and Daniel Sundin have ignored the FTC action right from the start, and are unrepresented.&amp;#160; Innovative Marketing is meant to be paying a fine to the Court of $8,000 per day.&amp;#160; I have found nothing to indicate that they have paid anything at all.&lt;/p&gt;  &lt;p&gt;Maurice D’Souza has finally entered a defense (which follows pretty much the same theme as those lodged by other defendants).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1714996" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>ALERT: Malvertizing on Facebook and gaiaonline.com</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/08/03/1712174.aspx</link><pubDate>Sun, 02 Aug 2009 15:28:18 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1712174</guid><dc:creator>sandi</dc:creator><slash:comments>4</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1712174</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/08/03/1712174.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/4657.image_5F00_5C6A4AB1.png" width="721" height="128" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/3681.image_5F00_6EDA4D79.png" width="721" height="128" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/6712.image_5F00_1468EC3D.png" width="721" height="128" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/0447.image_5F00_60596E4B.png" width="721" height="128" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;This investigation started after I read a report by a fellow member of the security community that his mother had called him downstairs &amp;quot;&lt;em&gt;because her screen had been filled with warnings and download boxes whilst she was on Facebook&amp;#39;s &amp;#39;Owned&amp;quot; site&amp;#39;&lt;/em&gt;&amp;quot;, and he asked for help to find the malvert.&amp;#160; I also saw on the GAIA site that lots of people were having problems with browser hijackings on that site, and that a poster&amp;#39;s &amp;quot;&lt;em&gt;mother just got the exact same redirection from Facebook&lt;/em&gt;&amp;quot;: &lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.gaiaonline.com/forum/bug-reports-technical-support/help-redirected-slightly-different-than-the-scan-problem/t.52761261_31/" target="_blank"&gt;http://www.gaiaonline.com/forum/bug-reports-technical-support/help-redirected-slightly-different-than-the-scan-problem/t.52761261_31/&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Facebook incident: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The malvertizement that I caught on Facebook was displayed with a Facebook application - apps.new.facebook.com/humangifts/.&lt;/p&gt;  &lt;p&gt;The domains involved in the hijack were &lt;strong&gt;apps3.coolapps.com, social.bidsystem.com, icon.cubics.com, ads.cubics.com, zamnadserver.com, internetnetworkads.com&lt;/strong&gt; and &lt;strong&gt;jessicasimpsonblog.cn&lt;/strong&gt; before the victim finally ends up at a fraudware site (screenshot of network sessions below). &lt;/p&gt;  &lt;p&gt;Facebook said on their blog on &lt;a href="http://blog.facebook.com/blog.php?post=110636457130" target="_blank"&gt;25 July 2009&lt;/a&gt; that advertising displayed by Facebook applications is &amp;quot;&lt;em&gt;not from Facebook but placed within applications by third parties&lt;/em&gt;&amp;quot;.&amp;#160; I suspect that Facebook will face an ongoing problem if they are going to allow “third parties” to independently source and manage advertising to display in conjunction with Facebook Applications. &lt;/p&gt;  &lt;p&gt;Malvertizement - ads.cubics.com/CubicsGraphicAd.axd?adid=101153&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;gaiaonline.com incident: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The malvertizement that I saw on gaiaonline.com is visually identical, but some domains are different.&amp;#160; You will see that the bad SWF is coming from openx.org instead of cubics.com (screenshot of network sessions below). &lt;/p&gt;  &lt;p&gt;Malvertizement URL: c3.openx.org/416f7968fd52ccbf9686b55a6a85915c.swf&lt;/p&gt;  &lt;p&gt;Both malvertizements have been reported to the appropriate parties.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;icons.cubics.com     &lt;br /&gt;ads.cubics.com      &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: Network Solutions, LLC    &lt;br /&gt;Created 28 August 2004    &lt;br /&gt;NS: UDNS1.ULTRADNS.NET    &lt;br /&gt;NS: NDNS2.ULTRADNS.NET &lt;/p&gt;  &lt;p&gt;IP: 204.137.31.12 - Missouri, Kansas City, Adknowledge Inc &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Adknowledge    &lt;br /&gt;4600 Madison    &lt;br /&gt;Suite 1000    &lt;br /&gt;Kansas City, MO 64112    &lt;br /&gt;US &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;zamnadserver.com     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: HOOYOO (US) INC.    &lt;br /&gt;Created 6 May 2009    &lt;br /&gt;NS1.EVERYDNS.NET    &lt;br /&gt;NS2.EVERYDNS.NET    &lt;br /&gt;NS3.EVERYDNS.NET    &lt;br /&gt;NS4.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 94.76.213.227 - United Kingdom, Canonical Range for Hp3-right (Blueconnex Ltd) &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Giovanni Cattini (cattini@freebbmail.com    &lt;br /&gt;543 Ty Mair    &lt;br /&gt;Pembrokeshire Caldey Island SA70 7UJ    &lt;br /&gt;GB    &lt;br /&gt;44 183 484 4453 &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;internetnetworkads.com     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: DIRECTI    &lt;br /&gt;Created: 16 April 2009    &lt;br /&gt;NS1.REG.RU    &lt;br /&gt;NS2.REG.RU &lt;/p&gt;  &lt;p&gt;IP: 94.76.213.227 - United Kingdom, Canonical Range for Hp3-right (Blueconnex Ltd) &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Olivier Le Pord (shreeadarsha@gmail.com)    &lt;br /&gt;Unit No 6B, 6th Floor of M-6    &lt;br /&gt;New Delhi 11001    &lt;br /&gt;India    &lt;br /&gt;91 223 0611 555 &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;jessicasimpsonblog.cn     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: 广东时代互联科技有限公司    &lt;br /&gt;Created: 14 July 2009 &lt;/p&gt;  &lt;p&gt;IP: 78.47.91.155 - Berlin, Siarhei Shandrokha &lt;/p&gt;  &lt;p&gt;Sharing IP with bbcnewstyleguide.com, securingyourwebbrowser.com, brooklyn-bounty.com &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;antispywareliveproscannerv4.com     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: TODAYNIC.COM, INC    &lt;br /&gt;Created: 28 July 2009    &lt;br /&gt;NS1.EVERYDNS.NET    &lt;br /&gt;NS2.EVERYDNS.NET    &lt;br /&gt;NS3.EVERYDNS.NET    &lt;br /&gt;NS4.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: No IP &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Wright S Diana (diana1982@yahoo.com)    &lt;br /&gt;2433 Lacy Lane    &lt;br /&gt;Carrollton    &lt;br /&gt;Texas, US, 75006&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;onlineproscanner.com     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: BIZCN.COM, INC    &lt;br /&gt;Created: 3 January 2009    &lt;br /&gt;NS1.EVERYDNS.NET    &lt;br /&gt;NS2.EVERYDNS.NET    &lt;br /&gt;NS3.EVERYDNS.NET    &lt;br /&gt;NS4.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 209.44.126.52 - Quebec, Laval, Netelligent Hosting Services Inc &lt;/p&gt;  &lt;p&gt;Shares IP address with mx052.belmony.com&lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Igor Voloshin (addworld@freebbmail.com    &lt;br /&gt;ul. Vilkova 31-54    &lt;br /&gt;Moskva Moskovskay oblast 126108    &lt;br /&gt;+74952783443&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/0066.image_5F00_2E1A4621.png" width="775" height="470" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160; &lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/8473.image_5F00_171607A9.png" width="777" height="673" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1712174" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>FTC versus Innovative Marketing et al - developments re Sam Jain</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/07/30/1710850.aspx</link><pubDate>Thu, 30 Jul 2009 06:11:05 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1710850</guid><dc:creator>sandi</dc:creator><slash:comments>3</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1710850</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/07/30/1710850.aspx#comments</comments><description>&lt;p&gt;Regular readers of this blog will know that Sam Jain filed a motion for protective order requiring deposition to proceed by written questions, a motion which was DENIED on 22 July 2009. &lt;/p&gt;  &lt;p&gt;Sam Jain has now refused to be deposed, even refusing an offer from the FTC to be deposed by video-conference from a location of his choosing (an offer that was made by the FTC to allay any fears held by Jain that a deposition would lead to his arrest). &lt;/p&gt;  &lt;p&gt;Jain has a history in the courts that is less than complimentary.&amp;#160; As has been mentioned on this blog (and elsewhere) before, Jain was sued by Symantec in 2004 for pirating Symantec’s computer security software. He evaded service during those proceedings, and basically ignored the whole thing until judgment was entered in default. Then he tried to have the default judgment overturned. As noted by the FTC in its latest motion, the Court at that time described Jain&amp;#39;s action as a “&lt;em&gt;cynical and intentional manipulation of the[] proceedings&lt;/em&gt;”, and rejected the application.&amp;#160; I have tried to find out if Jain ever paid the default judgment in the Symantec case but have been unable to find out for sure, one way or the other. &lt;/p&gt;  &lt;p&gt;Also, let&amp;#39;s not forget that Jain is a fugitive.&amp;#160; He had a bench warrant issued against him in the United States District Court for the Central District of California early this year - a warrant that remains in effect. &lt;/p&gt;  &lt;p&gt;The FTC now seeks sanctions against Jain (that sanction being default judgment), and has filed a MOTION for Sanctions Pursuant to Rule 37(d).&amp;#160; Any responses must be filed by 17 August 2009.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1710850" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>FTC versus Innovative Marketing et al - developments</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/07/28/1710428.aspx</link><pubDate>Tue, 28 Jul 2009 03:17:49 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1710428</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1710428</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/07/28/1710428.aspx#comments</comments><description>&lt;p&gt;&lt;strong&gt;A win for Marc D&amp;#39;Souza. &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The preliminary injunction is to be modified as followed (the FTC indicated that it had no objections to the language of the amendments): &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;F. The Assets affected by this Paragraph shall include existing Assets of any Corporate Defendant, Individual Defendant (with the exception of Assets referenced in paragraph G), or Relief Defendant and Assets acquired after the effective date of this Order that are derived from conduct prohibited in Paragraphs I and II. &lt;/p&gt;    &lt;p&gt;G. With respect to Defendant Marc D’Souza, the Assets affected by this Paragraph do not include Assets acquired after December 31, 2006 that were generated independently of the IMI Defendants (other than Marc D’Souza) and are not derived from any conduct prohibited in Paragraphs I and II.&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Kristy Ross may move for a similar amendment. &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1710428" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>FTC versus Innovative Marketing et al - developments</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/07/24/1708097.aspx</link><pubDate>Fri, 24 Jul 2009 06:44:08 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1708097</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1708097</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/07/24/1708097.aspx#comments</comments><description>&lt;p&gt;Innovative Marketing and Daniel Sundin continue to ignore proceedings and are unrepresented.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Maurice D’Souza&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Maurice D&amp;#39;Souza&amp;#39;s motion to dismiss for lack of jurisdiction (paper number 90) has been DENIED WITHOUT PREJUDICE.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;img style="margin:10px 20px 20px 0px;display:inline;" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_71E0F16A.png" alt="" /&gt;&amp;#160;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Sam Jain&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Sam has been busy, filing a motion for protective order requiring deposition to proceed by written questions (paper number 121).&amp;#160; It was claimed in the Motion that &amp;quot;&lt;em&gt;Given the significant Fifth Amendment privilege objections Mr. Jain is compelled to raise, or risk waiving, in response to Plaintiff’s substantive questions, proceeding initially with the deposition by written questions will present the cleanest possible record and will permit full briefing and argument on the complex factual and legal bases underlying his privilege claims&lt;/em&gt;&amp;quot;.&amp;#160; The Motion also claimed &amp;quot;&lt;em&gt;significant criminal jeopardy&lt;/em&gt;&amp;quot; because of the ongoing investigation by the US Attorney&amp;#39;s Office (Northern District of Illinois) for alleged wire fraud and computer fraud and, amazingly, because he is is a fugitive (he has had a bench warrant issued against him in &amp;quot;&lt;em&gt;unrelated proceedings&lt;/em&gt;&amp;quot; in the US District Court (Northern District of California)). &lt;/p&gt;  &lt;p&gt;The motion has been DENIED.&amp;#160; Now we wait to see if Jain actually turns up for an oral deposition.&amp;#160; The notice of deposition attached to Jain&amp;#39;s motion recorded that the deposition was due to commence on 20 July 2009 at 10 a.m. Eastern Time.&amp;#160; Obviously that needs to be rescheduled.&lt;/p&gt;  &lt;p&gt;The motion to modify the preliminary injunction filed by Sam Jain (paper number 58) was also DENIED.&lt;/p&gt;  &lt;p&gt;As a reminder, Jain and his cohorts had a &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/06/11/1694940.aspx" target="_blank"&gt;bad day&lt;/a&gt; back on 9 June 2009 when:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;em&gt;Sam Jain&amp;#39;s Motion to Stay (Paper No. 45) was DENIED;&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Kristy Ross&amp;#39;s Motion to Temporary Stay (Paper No. 48) was DENIED;&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;FTC&amp;#39;s Motion for Order Holding Sam Jain and Kristy Ross in Contempt of Court and Requiring the Repatriation of their Assets (Paper No. 49) was DENIED;&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Kristy Ross&amp;#39;s Motion to Strike or in the Alternative Motion for an Extension of Time (Paper No. 51) was declared MOOT;&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Sam Jain&amp;#39;s Motion to Strike or in the Alternative Motion for an Extension of Time (Paper No. 52) was declared MOOT;&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Sam Jain&amp;#39;s Motion to Modify Preliminary Injunction (Paper No. 58) was DENIED IN PART, with the Court withholding a ruling on the requested modification of the asset freeze;&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Sam Jain&amp;#39;s Motion to Dismiss under Rule 12(b)(7) and 19 (Paper No. 60) was DENIED;&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Kristy Ross&amp;#39;s Motion to Dismiss under Rule 12(b)(7) and 19 (Paper No. 61) was DENIED;&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Marc D&amp;#39;Souza&amp;#39;s Motion to Dismiss under Rule 12(b)(7) and 19 (Paper No. 70) was DENIED; and&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Marc D&amp;#39;Souza&amp;#39;s Motion for Temporary Stay and Modification of Preliminary Injunction (Paper No. 71) was DENIED IN PART, with the Court withholding a ruling on the requested modification of the asset freeze. &lt;/em&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Ok, onward and upward.&amp;#160; Hopefully the deposition of Sam Jain will be scheduled to take place as soon as possible.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1708097" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>ALERT: malvertizement featuring “Blue Nile”</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/07/14/1700470.aspx</link><pubDate>Mon, 13 Jul 2009 23:59:53 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1700470</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1700470</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/07/14/1700470.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/4721.image_5F00_412F69F1.png" width="757" height="119" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;The SWF advertisement pictured above retrieves content from the domain &lt;strong&gt;adburau.net.&amp;#160; &lt;/strong&gt;That content is yet another SWF.&amp;#160; At time of writing, the SWF downloaded from the domain adburau.net was a single frame SWF with no images, or shapes, or fonts, or texts, no sounds, or videos, or buttons, or sprites, or scripts.&lt;/p&gt;  &lt;p&gt;The “Blue Nile” SWF contains the easily recognizable encrypted dynamic text:&lt;/p&gt;  &lt;p&gt;&lt;img style="display:inline;" title="image" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/5807.image_5F00_7253C5F3.png" width="346" height="335" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Let’s take a close look at adburau.net – we dig up some interesting information.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;adburau.net&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI    &lt;br /&gt;Created: 21 September 2008    &lt;br /&gt;NS1.ADBURAU.NET    &lt;br /&gt;NS2.ADBURAU.NET &lt;/p&gt;  &lt;p&gt;IP: 212.95.37.133 - Netdirekt, E.k &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Al Jabber    &lt;br /&gt;Said Fahtihma (saidfahtih@gmail.com)    &lt;br /&gt;A. Kodiri, 65    &lt;br /&gt;Tashkent    &lt;br /&gt;Kishlak, 100060    &lt;br /&gt;UZ    &lt;br /&gt;Tel: 998.348.754.198 &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Hostnames sharing IP with a-records: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;212-95-37-133.internetserviceteam.com   &lt;br /&gt;&lt;strong&gt;adclickmate.net     &lt;br /&gt;&lt;/strong&gt;ns1.adclickmate.net    &lt;br /&gt;ns2.adclickmate.net &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Historical information about adclickmate.net &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;A known &amp;quot;bad actor&amp;quot; reported on here: &lt;/p&gt;  &lt;p&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/02/18/1672789.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/02/18/1672789.aspx&lt;/a&gt;    &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/01/15/1661878.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/01/15/1661878.aspx&lt;/a&gt;    &lt;br /&gt;&lt;a href="http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;amp;st=180" target="_blank"&gt;http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;amp;st=180&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;adclickmate.net is currently &amp;quot;suspended&amp;quot; by Directi.&amp;#160; The Registrant is noted as: &lt;/p&gt;  &lt;p&gt;Mark Haagland (markhaagland@gmail.com)   &lt;br /&gt;Harjumaa str. 546-5    &lt;br /&gt;Tallin    &lt;br /&gt;Harjumaa,13514    &lt;br /&gt;EE    &lt;br /&gt;Tel: 37.262.01114 &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Previous Registrant details – adclickmate.net: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Hidden by privacyprotect for a while, but before that was registered to: &lt;/p&gt;  &lt;p&gt;Jacob Tua (jackyouthere@gmail.com) (a well known malvertizing associated name/email address)   &lt;br /&gt;Maltiskam 12-67    &lt;br /&gt;Belgrade    &lt;br /&gt;Belgrade,11008    &lt;br /&gt;RS    &lt;br /&gt;Tel: 381.113114094 &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;I find it concerning that DIRECTI allowed a “bad actor” domain (adburau.net) to replace one that they had suspended (adclickmate.net).&amp;#160; I also find it concerning that adburau.net replaced adclickmate.net so rapidly. See screenshots below.&amp;#160; According to domaintools.com, adclickmate.net was suspended from IP address 212.95.37.133 on or about &lt;strong&gt;19 February 2008&lt;/strong&gt;.&amp;#160; adburau.net appeared at the same IP address on or about &lt;strong&gt;23 February 2009&lt;/strong&gt;.&lt;/p&gt;  &lt;p&gt;Call me a cynic, but it seems that the bad guys are finding it too easy to use/abuse Directi.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;img style="display:inline;" title="image" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/8030.image_5F00_6890EF2C.png" width="958" height="459" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;img style="display:inline;" title="image" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/0842.image_5F00_5EF03309.png" width="958" height="532" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1700470" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>ALERT:  Please treat content from antventure.com, yellowlinebanner.com, redhousebanner.com, t.banner0709.com and knocklis.com with extreme caution</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/07/14/1700082.aspx</link><pubDate>Mon, 13 Jul 2009 15:22:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1700082</guid><dc:creator>sandi</dc:creator><slash:comments>5</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1700082</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/07/14/1700082.aspx#comments</comments><description>&lt;p&gt;&lt;img height="322" width="377" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/2063.image_5F00_34E5A339.png" align="left" alt="image" border="0" title="image" style="border-bottom:0px;border-left:0px;margin:10px 25px 25px 0px;display:inline;border-top:0px;border-right:0px;" /&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Normally when I write about malvertizing on this blog, the &amp;ldquo;goal&amp;rdquo; of the malvertizement has been to expose victims to fake security software (aka fraudware).&amp;nbsp; In one case, the &amp;ldquo;goal&amp;rdquo; was to expose the victim to a pornographic web site (complete with streaming video and sound on the opening page &amp;ndash; mlb.com was hit by that one).&lt;/p&gt;
&lt;p&gt;Today I saw a malvertizement that did not expose victims to fake security software, or unwanted pornography.&amp;nbsp; Instead, it exposed victims to a web site that tried, via various security exploits, to infect computers.&lt;/p&gt;
&lt;p&gt;If a victim is exposed to the dangerous content via the malvertizing discovered today, a malicious PDF is downloaded, which takes advantage of two exploits affecting Adobe Acrobat and Adobe Reader (CVE-2008-2992 and CVE-2009-0927).&amp;nbsp; These vulnerabilities are used to try to download even more malicious software via a web page.&lt;/p&gt;
&lt;p&gt;Anyway, here is how it happened.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;ad.yieldmanager.com&lt;/strong&gt; loaded content in an iframe from &lt;strong&gt;served.antventure.com&lt;/strong&gt;.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;served.antventure.com in turn pulled content, again in an iframe, from &lt;strong&gt;ad.antventure.com&lt;/strong&gt;.&amp;nbsp; The ad.antventure.com content was a slew of script that brought us back to &lt;strong&gt;ad.yieldmanager.com&lt;/strong&gt;. &lt;/p&gt;
&lt;p&gt;Then there was some back and forth between ad.yieldmanager.com and ad.adventure.com in iframes until, eventually, ad.antventure.com content loaded, you guessed it, ad.yieldmanager.com content. &lt;/p&gt;
&lt;p&gt;From here on in it gets really interesting.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;ad.yieldmanager.com loaded content from &lt;strong&gt;banner.yellowlinebanner.com&lt;/strong&gt;.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;The banner.yellowlinebanner.com content is a 728x90 banner advertisement featuring expedia.com.au. The HREF for the banner advertisement is an expedia.com.au URL but the graphic for the advertisement (a GIF) is pulled from &lt;strong&gt;creatives.redhousebanner.com&lt;/strong&gt;.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;The URL hosting the gif from creatives.redhousebanner.com contains an iframe that loads content from &lt;strong&gt;t.banner0709.com&lt;/strong&gt;. &lt;/p&gt;
&lt;p&gt;t.banner0709.com is where things get real nasty.&amp;nbsp; The t.banner0709.com URL is redirected to &lt;strong&gt;knocklis.com&lt;/strong&gt; (HTTP response code 302 - &amp;ldquo;temporary&amp;rdquo; move), and it is the knocklis.com web page that exposes the victim to the malicious PDF via an iframe in a PHP page.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;The knocklis.com page also tries (and fails) to load a graphic (test.gif) and (unsuccessfully) to load other content from the knocklis.com domain, as well as content from &lt;strong&gt;xn--18ba.example.com&lt;/strong&gt; (this, too, fails).&lt;/p&gt;
&lt;p&gt;You will have to forgive my obscuring the URLs &amp;ndash; the content is simply too dangerous for curiosity.&amp;nbsp; The exploits being utilized by the malicious PDF is known as &amp;ldquo;win32/pdfjsc.av&amp;rdquo;: &lt;br /&gt;&lt;a target="_blank" href="http://www.securityhome.eu/malware/malware.php?mal_id=5738206704a311ed2d81c38.88824099"&gt;http://www.securityhome.eu/malware/malware.php?mal_id=5738206704a311ed2d81c38.88824099&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;As a final note, if we visit the creatives.redhouse.com URL directly, the iframe does not appear.&amp;nbsp; Also, antventure.com has been problematic in the past:&lt;/p&gt;
&lt;p&gt;&lt;a target="_blank" href="http://www.bluetack.co.uk/forums/lofiversion/index.php/t19489.html" title="http://www.bluetack.co.uk/forums/lofiversion/index.php/t19489.html"&gt;http://www.bluetack.co.uk/forums/lofiversion/index.php/t19489.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a target="_blank" href="http://gigablast.com/get?c=main&amp;amp;d=109162469411&amp;amp;q=antventure.com&amp;amp;" title="http://gigablast.com/get?c=main&amp;amp;d=109162469411&amp;amp;q=antventure.com&amp;amp;"&gt;http://gigablast.com/get?c=main&amp;amp;d=109162469411&amp;amp;q=antventure.com&amp;amp;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The redhousebanner.com GIF&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;img height="115" width="757" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/2063.image_5F00_410C3EC2.png" alt="image" border="0" title="image" style="border-bottom:0px;border-left:0px;margin:10px 0px 20px;display:inline;border-top:0px;border-right:0px;" /&gt; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The banner.yellowlinebanner.com content with the iframe content:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;img height="694" width="901" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/8446.image_5F00_01D0A5D6.png" alt="image" border="0" title="image" style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" /&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;img height="176" width="875" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/5807.image_5F00_59CA0884.png" alt="image" border="0" title="image" style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1700082" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>FTC versus Innovative Marketing et al – Sam Jain  and Kirsty Ross respond (and other developments)</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/07/01/1697445.aspx</link><pubDate>Wed, 01 Jul 2009 09:08:15 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1697445</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1697445</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/07/01/1697445.aspx#comments</comments><description>&lt;p&gt;&lt;strong&gt;Sam Jain&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;I would have loved to shine a light on some nice juicy arguments but, alas, it wasn’t to be.&amp;#160; The entirety of Jain’s answer compromised just a few types of response, as follows:&lt;/p&gt;  &lt;p&gt;Paragraph text version 1)&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“Paragraph X of the Complaint contains legal conclusions to which no response is required”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Paragraph text version 2)&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“Paragraph X of the Complaint contains legal conclusions to which no response is required.&amp;#160; To the extent Paragraph X of the Complaint contains factual allegations to which a response is required, Mr Jain lacks sufficient information to admit or deny the allegations and therefore denies those allegations”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Paragraph text version 3)&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“The subject matter of the Complaint in this case is the basis for an ongoing investigation conducted by the U.S. Attorney for the Northern District of Illinois.&amp;#160; Exercising his rights under the Fifth Amendment of the Constitution of the United States, Mr Jain respectfully declines to answer the allegations contained in paragraph X on the ground that his answer might tend to incriminate him.&amp;#160; Mr Jain further respectfully requests that such declination have the same procedural effect under Fed. R. Civ. P. 8(d), as if he specifically denied the allegations.”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Paragraph text version 4)&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“Exercising his rights under the Fifth Amendment of the Constitution of the United States, Mr Jain respectfully declines to answer the allegations contained in Paragraph X on the ground that his answer might tend to incriminate him.&amp;#160; Mr Jain further respectfully requests that such declination have the same procedural effect under Fed. R. Civ. P. 8(d), as if he specifically denied the allegations.”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;And so it goes on, with variations to the same theme such as “Mr Jain lacks sufficient information to admit or deny the allegations... and therefore denies those allegations”.&lt;/p&gt;  &lt;p&gt;Finally, Mr Jain puts forth three Affirmative Defenses: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;Plaintiff has failed to state a claim upon which relief can be granted&amp;quot;, and &lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;Any injury allegedly incurred was not caused by Mr Jain, and any injury resulted from superseding or intervening events outside the knowledge or control of Mr Jain&amp;quot;, and &lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;Mr Jain expressly reserves the right to assert any and all other defenses to the Amended Complaint as they become known&amp;quot;.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;In short, it is 17 pages saying pretty much nothing at all…&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Kristy Ross&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Kristy Ross has also filed her Answer (31 pages long).&amp;#160; It, too, contains various denials and coy Fifth Amendments incrimination demurs, but she does admit (aka agree) that the FTC is an independent agency of the US Government created by statute, that it enforces Section 5(a) of the FTC Act and is authorized to initiate federal district court proceeding. &lt;/p&gt;  &lt;p&gt;Her defenses are: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“The statement of any defense does not assume the burden of proof for any issue as to which applicable law places the burden upon plaintiff. Defendant expressly reserves the right to amend and/or supplement her defenses or assert any matters in avoidance of plaintiff&amp;#39;s claim which may become appropriate as discovery proceeds in this case”; and &lt;/p&gt;    &lt;p&gt;“Plaintiff has failed to state a claim upon which relief can be granted”; and &lt;/p&gt;    &lt;p&gt;“Any injury allegedly incurred was not caused by Defendant Ross and any injury resulted from superseding or intervening events outside the knowledge or control of Defendant Ross”.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Innovative Marketing, Inc and Daniel Sundin &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The FTC has lodged a Motion for Entry of Default for want of answer or other defense, with responses due by 13 July 2009.&amp;#160; Bearing in mind both parties have ignored the proceedings so far, and are unrepresented, I doubt that IM or Sundin are going to acknowledge the FTC&amp;#39;s lawsuit now. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Marc D&amp;#39;Souza &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Arguments via Motion and Reply continue as D&amp;#39;Souza attempts to have the complaint against him dismissed.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;James Reno and ByteHosting&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The Judge has signed the Reno Orders, so that is all over and done with. &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1697445" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>FTC v Innovative Marketing – the agreement with James Reno and Byte Hosting</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/06/17/1695625.aspx</link><pubDate>Tue, 16 Jun 2009 15:23:48 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1695625</guid><dc:creator>sandi</dc:creator><slash:comments>4</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1695625</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/06/17/1695625.aspx#comments</comments><description>&lt;p&gt;&lt;img style="margin:10px 20px 20px 0px;display:inline;" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_0D59123F.png" alt="" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Back on the 11th I reminded everybody that I expected the proposed stipulated final order between the FTC, Reno and ByteHosting to be filed within days.&amp;#160; As luck would have it, a Final Order For Permanent Injunction and Monetary Judgment as to James M. Reno and ByteHosting Internet Services, LLC was filed with the Court the very next day.&lt;/p&gt;  &lt;p&gt;Below are the proposed terms of the Permanent Injunction and Monetary Judgment.&amp;#160; &lt;/p&gt;  &lt;p&gt;Bear in mind, when you read about the monetary judgment, that earlier court documents have disclosed that “&lt;em&gt;after weeks of searching, the FTC has located only $174,000 of the defendants&amp;#39; assets. ... The bulk of these funds belong to James Reno.&lt;/em&gt;”&lt;/p&gt;  &lt;p&gt;Also bear in mind, the Permanent Injunction and Monetary Judgment has not yet been signed by the Judge Hon. Richard D. Bennett.&lt;/p&gt;  &lt;p&gt;The Order is described as &amp;quot;&lt;em&gt;remedial in nature, and no portion of any payments paid herein shall be deemed or construed as payment of a fine, damages, penalty or punitive assessment&lt;/em&gt;&amp;quot;. &lt;/p&gt;  &lt;p&gt;Take a deep breath ladies and gentlemen, there is a lot of information here… “Defendants” refers to Reno and ByteHosting Internet Services.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;CONDUCT PROHIBITIONS&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;Reno and ByteHosting Internet Services, as well as their officers, agents, servants, employees and those persons in active concert or participation with them who receive actual notice of the order by personal service or otherwise, are PERMANENTLY RESTRAINED AND ENJOINED from: &lt;/p&gt;  &lt;p&gt;A. directly or indirectly misrepresenting, expressly or by implication, that: &lt;/p&gt;  &lt;p&gt;(1) a computer can or any other type of remote or local computer analysis has been performed; or    &lt;br /&gt;(2) security or privacy problems have been detected on a computer, &lt;/p&gt;  &lt;p&gt;B. publishing, disseminating, distributing, installing, downloading or providing customer support for any software that interferes with a consumer&amp;#39;s computer use, including but not limited to software that: &lt;/p&gt;  &lt;p&gt;(a) changes consumers&amp;#39; preferred Internet homepage settings;    &lt;br /&gt;(b) inserts a new advertising toolbar onto consumers&amp;#39; Internet browsers;     &lt;br /&gt;(c) generates numerous &amp;quot;pop up&amp;quot; advertisements on consumers&amp;#39; computer screens when consumers&amp;#39; Internet browsers are closed;     &lt;br /&gt;(d) adds advertising icons to the computer&amp;#39;s desktop;     &lt;br /&gt;(e) tampers with, disables, or otherwise alters the performance of other programs, including anti-spyware and anti-virus programs;     &lt;br /&gt;(f) alters Internet browser security settings, including the list of safe or trusted websites;     &lt;br /&gt;(g) installs other advertising Software on consumers&amp;#39; computers;     &lt;br /&gt;(h) conducts, or purports to conduct, a computer scan that purports to detect security or privacy threats that do not exist on the scanned computer; or     &lt;br /&gt;(i) creates security or privacy threats on a computer for the purpose of selling Software to eliminate those problems. &lt;/p&gt;  &lt;p&gt;C. concealing or attempting to conceal their identities by, among other things: &lt;/p&gt;  &lt;p&gt;(a) using any domain names that have been registered using false or incomplete information;    &lt;br /&gt;(b) claiming that they place advertisements on behalf of, or otherwise represent, individuals or entities, unless they possess written authorization to represent such individuals or entities. &lt;/p&gt;  &lt;p&gt;D. engaging in commercial activity of any kind - whether as a partner, employee, employer, officer, director, control person, independent contractor, consultant, service provider, or otherwise - with Innovative Marketing, Inc., Sam Jain, Daniel Sundin, Marc D&amp;#39;Souza, Maurice D&amp;#39;Souza, or Kristy Ross, or any entity controlled by Innovative Marketing, Inc., Sam Jain, Daniel Sundin, Marc D&amp;#39;Souza, Maurice D&amp;#39;Souza, or Kristy Ross. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;In connection with the marketing, distributing, or sale of, or the provision of customer support for, any goods or services, Defendants and their officers, agents, servants, employees and attorneys, and persons in active concert or participation with them who receive actual notice of the order by personal service or otherwise, are PERMANENTLY RESTRAINED AND ENJOINED from: &lt;/p&gt;  &lt;p&gt;(a) misrepresenting, directly or by implication, to any potential purchaser of any goods or services, any material fact, including but not limited to: &lt;/p&gt;  &lt;p&gt;(1) the total cost to purchase, receive, or use, or the quality of, any good or services that are subject to the sales offer;    &lt;br /&gt;(2) any material restrictions, limitations, or conditions to purchase, receive or use the goods or services; or     &lt;br /&gt;(3) any material aspect of the nature or terms of a refund, cancellation, exchange, or repurchase policy for the goods or services; or &lt;/p&gt;  &lt;p&gt;(b) providing substantial assistance to any third party to make any material misrepresentation including but not limited to those misrepresentations prohibited by paragraph (a) above. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;MONETARY JUDGMENT&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;(a) Judgment in the amount of &lt;strong&gt;$1,859,954.93&lt;/strong&gt; jointly and severally against the defendants.     &lt;br /&gt;(b) The monetary judgment be suspended upon defendants compliance with certain conditions, including that within 15 days after the date of entry of the Order, the defendants pay:&lt;/p&gt;  &lt;p&gt;(1) $17,827 from bank accounts listed in an attachment to the order to the IRS and State of Ohio;    &lt;br /&gt;(2) the remaining balance of all bank accounts listed in the attachment (approximately $98,870) to the Commission (with the defendants allowed to withdraw and retain just $7,500.00).&amp;#160; Monies paid to the FTC or its agent are to be used for &amp;quot;&lt;em&gt;equitable relief, including but not limited to consumer redress, and any attendant expenses for the administration of such equitable relief&lt;/em&gt;&amp;quot;. &lt;/p&gt;  &lt;p&gt;If the defendants have failed to disclose any material asset or materially misstated the value of any asset in certain financial statements or related documents, or have made any other material misstatement or omission in the financial statements or related documents, then the Order shall be reopened and suspension of the judgment shall be lifted for the purpose of requiring payment of the full judgment (less anything already paid).&amp;#160; If such a reinstatement occurs, the Court shall make an express determination that the monetary judgment shall be immediately due and payable (with interest). &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;COMPLIANCE MONITORING&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;So that the Commission can monitor and investigate compliance with any provision of this order and investigate the accuracy of any defendants&amp;#39; financial statements: &lt;/p&gt;  &lt;p&gt;(a) The defendants shall submit within 10 days of receipt of written notice from a representative of the Commission, additional written reports which are true and accurate and sworn to oath under penalty of perjury; produce documents for inspection and copying; appear for deposition; and provide entry during normal business hours to any business location in each Defendants&amp;#39; possession or direct or indirect control to inspect the business operation.&lt;/p&gt;  &lt;p&gt;The Commission is authorized to use all other lawful means, including but not limited to: &lt;/p&gt;  &lt;p&gt;(1) obtaining discovery from any person, without further leave of the court, using certain prescribed Federal procedures;    &lt;br /&gt;(2) posing as consumers and suppliers to the Defendants, their employees, or any other entity managed or controlled in whole or in part by any defendant, without the necessity of identification or prior notice; and &lt;/p&gt;  &lt;p&gt;(c) Defendants shall permit representatives of the Commission to interview any employer, consultant, independent contractor, representative, agent, or employee who has agreed to such an interview, relating in any way to any conduct subject to this order (the person interviewed may have counsel present). &lt;/p&gt;  &lt;p&gt;The Defendants must, for a period of 5 years from the date of entry of the order, notify the Commission of: &lt;/p&gt;  &lt;p&gt;(a) any changes in the defendant&amp;#39;s residence, mailing address and telephone number within 10 days of the date of such change;    &lt;br /&gt;(b) any changes in the defendant&amp;#39;s employment status (including self-employment) and any change in such defendant&amp;#39;s ownership in any business entity, within 10 days of such change.&amp;#160; Such notice will include the name and address of each business that such defendant is affiliated with, employed by, creates or forms, or performs services for; a detailed description of the nature of the business; and a detailed description of such defendant&amp;#39;s duties and responsibilities in connection with the business or employment; and     &lt;br /&gt;(c) any changes in the defendant&amp;#39;s name or use of any aliases or fictitious names.     &lt;br /&gt;(d) any changes in structure of the corporate defendant or any business entity that any defendant directly or indirectly controls, or has an ownership interest in, that may affect compliance obligations arising under the order.     &lt;br /&gt;(e) 180 days after the date of entry of the order, and annually thereafter for a period of 5 years, defendants shall each provide a written report to the FTC, which is true and accurate and sworn to under penalty of perjury, setting forth in detail the manner and form in which they are complied with the order.     &lt;br /&gt;(f) Each defendant shall notify the Commission of the filing of a bankruptcy petition by such defendant within 15 days of filing. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;RECORD KEEPING PROVISIONS&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;For a period of 8 years from the date of entry of the order, defendants, for any business that such defendant directly or indirectly controls, or in which such defendant has a majority ownership interest, and their agents, employees, officers, corporations and those persons in active concern or participation with them who receive actual notice of this Order by personal service or otherwise, are HEREBY RESTRAINED AND ENJOINED from failing to create and retain as set out in the order: &lt;/p&gt;  &lt;p&gt;(a) accounting records    &lt;br /&gt;(b) personnel records     &lt;br /&gt;(c) customer files     &lt;br /&gt;(d) complaints and refund requests     &lt;br /&gt;(e) records reflecting contact information and detailed payment history for all persons or entities engaged in the marketing, sale, distributing or installing of software at the direction of, or for the benefit of, the defendants     &lt;br /&gt;(f) copies of all scripts and training materials used in connection with the training of staff in customer support     &lt;br /&gt;(g) all records and documents necessary to demonstrate full compliance with each provision of the order &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;DISTRIBUTION OF ORDER&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;Every 5 years from the date of entry of the order, defendants shall deliver copies of the order to: &lt;/p&gt;  &lt;p&gt;(a) Corporate Defendant: all principals, officers, directors and managers; and all employees, agents and representatives who engage in conduct related to the subject matter of the order; and any business entity resulting from any change in structure set forth in the Order    &lt;br /&gt;(b) Individual defendant as control person: for any business that the individual defendant controls, directly or indirectly, or in which such defendant has a majority ownership interest - all principals, officers, directors and managers; and all employees, agents and representatives who engage in conduct related to the subject matter of the order; and any business entity resulting from any change in structure set forth in the Order.     &lt;br /&gt;(c) Individual defendant as employee or non-control person (aka Reno himself): for any business where the individual defendant is not a controlling person of a business but otherwise engages in conduct in connection with the selling, distributing, marketing or provision of customer support for computer security software, such defendant must deliver a copy of the order to all principals and managers of such business before engaging in the conduct.     &lt;br /&gt;(d) Defendants must secure a signed and dated statement acknowledging receipt of the Order from all persons receiving a copy of the order. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;COOPERATION WITH THE FTC&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;Defendants shall, in connection with this action or any subsequent investigations related to or associated with the transactions or the occurrences that are the subject of the FTC&amp;#39;s complaint, cooperate in good faith with the FTC and appear at such places and times as the FTC shall reasonably request, after written notice, for interviews, conferences, pretrial discovery, review of documents and for such other matters as may be reasonably requested by the FTC.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;One last thing…..&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;I noticed tonight that visitors to bytehosting.com (and several other Reno owned domains) are being redirected to google.com.&amp;#160; That is a trick that I have seen being used quite a few times to divert visitors away from malvertizing domains.&lt;/p&gt;  &lt;p&gt;&lt;img style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/7851.image_5F00_0E6C2236.png" width="909" height="648" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1695625" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>FTC versus Innovative Marketing et al – developments</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/06/11/1694940.aspx</link><pubDate>Thu, 11 Jun 2009 01:40:17 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1694940</guid><dc:creator>sandi</dc:creator><slash:comments>1</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1694940</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/06/11/1694940.aspx#comments</comments><description>&lt;p&gt;So sayeth the Court.... &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“&lt;em&gt;This Court conducted a hearing yesterday on almost all outstanding motions in this case and rendered the following rulings for the reasons stated on the record: &lt;/em&gt;&lt;/p&gt;    &lt;ul&gt;     &lt;li&gt;&lt;em&gt;Sam Jain&amp;#39;s Motion to Stay (Paper No. 45) is DENIED;&lt;/em&gt;&lt;/li&gt;      &lt;li&gt;&lt;em&gt;Kristy Ross&amp;#39;s Motion to Temporary Stay (Paper No. 48) is DENIED;&lt;/em&gt;&lt;/li&gt;      &lt;li&gt;&lt;em&gt;FTC&amp;#39;s Motion for Order Holding Sam Jain and Kristy Ross in Contempt of Court and Requiring the Repatriation of their Assets (Paper No. 49) is DENIED;&lt;/em&gt;&lt;/li&gt;      &lt;li&gt;&lt;em&gt;Kristy Ross&amp;#39;s Motion to Strike or in the Alternative Motion for an Extension of Time (Paper No. 51) is MOOT;&lt;/em&gt;&lt;/li&gt;      &lt;li&gt;&lt;em&gt;Sam Jain&amp;#39;s Motion to Strike or in the Alternative Motion for an Extension of Time (Paper No. 52) is MOOT;&lt;/em&gt;&lt;/li&gt;      &lt;li&gt;&lt;em&gt;Sam Jain&amp;#39;s Motion to Modify Preliminary Injunction (Paper No. 58) is DENIED IN PART, with the Court withholding a ruling on the requested modification of the asset freeze;&lt;/em&gt;&lt;/li&gt;      &lt;li&gt;&lt;em&gt;Sam Jain&amp;#39;s Motion to Dismiss under Rule 12(b)(7) and 19 (Paper No. 60) is DENIED;&lt;/em&gt;&lt;/li&gt;      &lt;li&gt;&lt;em&gt;Kristy Ross&amp;#39;s Motion to Dismiss under Rule 12(b)(7) and 19 (Paper No. 61) is DENIED;&lt;/em&gt;&lt;/li&gt;      &lt;li&gt;&lt;em&gt;Marc D&amp;#39;Souza&amp;#39;s Motion to Dismiss under Rule 12(b)(7) and 19 (Paper No. 70) is DENIED; and&lt;/em&gt;&lt;/li&gt;      &lt;li&gt;&lt;em&gt;Marc D&amp;#39;Souza&amp;#39;s Motion for Temporary Stay and Modification of Preliminary Injunction (Paper No. 71) is DENIED IN PART, with the Court withholding a ruling on the requested modification of the asset freeze. &lt;/em&gt;&lt;/li&gt;   &lt;/ul&gt;    &lt;p&gt;&lt;em&gt;Sam Jain&amp;#39;s Motion to Modify Preliminary Injunction (Paper No. 58), Marc D&amp;#39;Souza&amp;#39;s Motion for Temporary Stay and Modification of Preliminary Injunction (Paper No. 71) and Kristy Ross&amp;#39;s oral motion to modify the preliminary injunction all require further briefing and argument on the issue of whether the asset freeze in Section IV of the Preliminary Injunction should be modified.&amp;#160; Moreover, this Court withheld ruling on Maurice D&amp;#39;Souza&amp;#39;s Motion to Dismiss for Lack of Jurisdiction under Rule 12(b)(2) (Paper No. 90) so that limited jurisdictional discovery can occur and further briefing and argument. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;On these outstanding issues, a hearing will be held on Wednesday, July 8, 2009 at 10:00 a.m.&amp;#160; Counsel for Sam Jain, Marc D&amp;#39;Souza, Kristy Ross and the FTC will each be permitted to smit an additional brief on whether the asset freeze should be modified by Tuesday, June 23, 2009.&amp;#160; Counsel for Maurice D&amp;#39;Souza and the FTC will also each be permitted to submit an additional brief on whether this Court has personal jurisdiction over Maurice D&amp;#39;Souza by the same date.&amp;#160; The briefs should be limited to ten (10) pages, excluding attachments and exhibits.&lt;/em&gt;”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;The Court will issue a scheduling order at the hearing on July 8, 2009.&lt;/p&gt;  &lt;p&gt;As a brief recap, the arguments put forward by Sam Jain, Kristy Ross and Marc D’Souza in their Motions to Dismiss the FTC complaint under Rule 12(b)(7) and 19 (which were dismissed) were:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;that the FTC had failed to join Innovative Marketing, a &amp;quot;necessary and indispensible party&amp;quot;, claiming that the FTC had never served IMI (the FTC served IMI *twice*). &lt;/li&gt;    &lt;li&gt;that Jack Palladino did not represent IMI and was not authorised to accept service, claiming that Palladino had not made the statements attributed to him&lt;/li&gt;    &lt;li&gt;that the service of IMI in Belize was invalid under the local laws. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Previous relevant commentary: &lt;/p&gt;  &lt;p&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2008/12/17/1656984.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2008/12/17/1656984.aspx&lt;/a&gt;    &lt;br /&gt;&lt;a title="http://msmvps.com/blogs/spywaresucks/archive/2009/02/10/1671117.aspx" href="http://msmvps.com/blogs/spywaresucks/archive/2009/02/10/1671117.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/02/10/1671117.aspx&lt;/a&gt;&amp;#160; &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/03/09/1676922.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/03/09/1676922.aspx&lt;/a&gt;    &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/02/27/1674119.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/02/27/1674119.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;I didn&amp;#39;t blog about the defendants’ claim that the service on IMI in Belize was invalid.&amp;#160; The gist of the argument was that the defendants were claiming IMI had not been properly served by the FTC when the FTC personally served IMI&amp;#39;s registered agent in that country because the defendants had found a single State Department web page that advised that &amp;quot;&lt;em&gt;Belize and the United States are parties to an agreement that requires all service of process in Belize to be sent exclusively to Belize&amp;#39;s central authority&lt;/em&gt;&amp;quot;.&amp;#160; Unfortunately for the defendants, it turned out that the web page on which the defendants were relying was &amp;quot;defunct&amp;quot;.&amp;#160; A link to the cited web page on the United States Department of State&amp;#39;s Bureau of Consular Affairs&amp;#39; main judicial assistance portal had been deactivated some years earlier due to inaccuracies that had developed over time, although some links to the web page remained on the CA web which were accessible to the public.&amp;#160; The cited web page itself was disabled on March 6, 2009 after it was discovered that it was still being linked to.&amp;#160; The FTC pointed out in its response to the defendants’ claim that if the defendants had checked with the State Department they would have been told that the information was wrong.&lt;/p&gt;  &lt;p&gt;Sam Jain’s Motion to Stay (Paper No. 45) (which was denied) was his request that the FTC proceedings be stayed “&lt;em&gt;until the ongoing parallel federal criminal case against him is resolved”&lt;/em&gt; because “&lt;em&gt;to defend both cases simultaneously will effectively prevent him from defending either adequately and will force him to choose between sacrificing his Fifth Amendment privilege against self incrimination or his right to defend the civil claims&lt;/em&gt;”.&amp;#160; Kristy Ross’s Motion to Temporary Stay (Paper No. 48) basically made the same arguments.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;James Reno and Bytehosting Internet Services&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Back on 18 March 2009 I reported that the FTC, James Reno and Bytehosting Internet Services had requested the Court stay further proceedings as to James Reno and Bytehosting for a period of 90 days. &lt;/p&gt;  &lt;p&gt;The stay was requested so that the Commission&amp;#39;s attorneys could seek approval of a &amp;quot;&lt;em&gt;Stipulated Final Order for Permanent Injunction and Monetary Judgment As To Defendants James M. Reno and Bytehosting Internet Services, LLC&lt;/em&gt;&amp;quot;.&amp;#160; Reno and Bytehosting executed a proposed stipulated final order on 11 March 2009, but this proposed stipulated final order must firstly be approved by the Director of the Bureau of Consumer Protection and then considered, voted on and approved by the full Commission; a procedure that can take up to 90 days. &lt;/p&gt;  &lt;p&gt;The stay was granted on 18 March 2009, therefore I expect that the proposed stipulated final order will be lodged with the court any day now (assuming it is approved by the Director of the Bureau of Consumer Protection and then the full Commission).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1694940" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>FTC versus Innovative Marketing… developments</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/06/10/1694898.aspx</link><pubDate>Wed, 10 Jun 2009 13:22:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1694898</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1694898</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/06/10/1694898.aspx#comments</comments><description>&lt;p&gt;Today was a big day…&lt;/p&gt;  &lt;p&gt;“Motion Hearing held on Tuesday 9 June, 2009 re:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;(51) MOTION to Strike (49) MOTION for Other Relief &lt;i&gt;Order Holding Sam Jain and Kristy Ross In Contempt Of Court And Requiring The Repatriation Of Their Assets&lt;/i&gt; &lt;i&gt;OR IN THE ALTERNATIVE&lt;/i&gt; MOTION to Strike (49) MOTION for Other Relief &lt;i&gt;Order Holding Sam Jain and Kristy Ross In Contempt Of Court And Requiring The Repatriation Of Their Assets&lt;/i&gt; &lt;i&gt;OR IN THE ALTERNATIVE&lt;/i&gt; MOTION for Extension of Time filed by Kristy Ross,&lt;/li&gt;    &lt;li&gt;(45) MOTION to Stay filed by Sam Jain, &lt;/li&gt;    &lt;li&gt;(106) MOTION to Dismiss &lt;i&gt;the Complaint Pursuant to Rule 12(b)(6)&lt;/i&gt; filed by Marc D&amp;#39;Souza, &lt;/li&gt;    &lt;li&gt;(90) MOTION to Dismiss for Lack of Jurisdiction filed by Maurice D&amp;#39;Souza, &lt;/li&gt;    &lt;li&gt;(60) MOTION to Dismiss &lt;i&gt;Complaint&lt;/i&gt; filed by Sam Jain, &lt;/li&gt;    &lt;li&gt;(52) MOTION to Strike (49) MOTION for Other Relief &lt;i&gt;Order Holding Sam Jain and Kristy Ross In Contempt Of Court And Requiring The Repatriation Of Their Assets&lt;/i&gt; &lt;i&gt;or, in the Alternative, for Extension of Time to Respond&lt;/i&gt; MOTION to Strike (49) MOTION for Other Relief &lt;i&gt;Order Holding Sam Jain and Kristy Ross In Contempt Of Court And Requiring The Repatriation Of Their Assets&lt;/i&gt; &lt;i&gt;or, in the Alternative, for Extension of Time to Respond&lt;/i&gt; filed by Sam Jain, &lt;/li&gt;    &lt;li&gt;(61) MOTION to Dismiss &lt;i&gt;COMPLAINT&lt;/i&gt; filed by Kristy Ross, &lt;/li&gt;    &lt;li&gt;(48) MOTION to Stay &lt;i&gt;(Temporary)&lt;/i&gt; filed by Kristy Ross, &lt;/li&gt;    &lt;li&gt;(71) MOTION to Stay &lt;i&gt;Temporary&lt;/i&gt; filed by Marc D&amp;#39;Souza, &lt;/li&gt;    &lt;li&gt;(70) MOTION to Dismiss &lt;i&gt;Complaint&lt;/i&gt; filed by Marc D&amp;#39;Souza &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;The hearing was held before Judge Richard D Bennett and &lt;strong&gt;not concluded.&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;By the way, Innovative Marketing is still unrepresented and, as far as I know, have not paid a cent of the $8,000 per day fine levied by the Court (I may be wrong, I hope I’m wrong, but suspect that I am not).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1694898" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>3 malvertizements</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/05/21/1692845.aspx</link><pubDate>Thu, 21 May 2009 04:43:20 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1692845</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1692845</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/05/21/1692845.aspx#comments</comments><description>&lt;p&gt;All created using, we think, Fuse – all use the encrypted-code-as-dynamic-text trick.&lt;/p&gt;  &lt;p&gt;Malvertizement 1 (reported by &lt;a href="http://securityblahblah.blogspot.com/" target="_blank"&gt;Greg Feezel&lt;/a&gt;) and seen on &lt;a href="http://malwaredatabase.net/blog/index.php/2009/05/20/fox-serving-up-malvertisement-leading-to-scareware-products/" target="_blank"&gt;Fox Audience Network&lt;/a&gt;:&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_22E787EC.png" width="786" height="146" /&gt;&amp;#160; &lt;/p&gt;  &lt;p&gt;Hits &lt;strong&gt;bigstat.net&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: REGTIME LTD    &lt;br /&gt;Created 18 February 2009    &lt;br /&gt;NS1.NAMESELF.COM    &lt;br /&gt;NS2.NAMESELF.COM &lt;/p&gt;  &lt;p&gt;IP: 212.95.32.166 - Berlin, Netdirekt &lt;/p&gt;  &lt;p&gt;Shares IP with greatstat.com &lt;/p&gt;  &lt;p&gt;Registrant - bigstat.net and greatstat.com   &lt;br /&gt;Anemari Rotko (ranemari@yahoo.com)    &lt;br /&gt;Tulskaya, 247/14    &lt;br /&gt;Moscow, 109029, Russia    &lt;br /&gt;+7 495 364 9627 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;Malvertizement 2: &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_2BFBC580.png" width="755" height="116" /&gt;&amp;#160; &lt;/p&gt;  &lt;p&gt;Hits &lt;strong&gt;clickmatter.net&lt;/strong&gt;, a domain already featured on this blog several times. &lt;/p&gt;  &lt;p&gt;ICANN Registrar: REGTIME LTD   &lt;br /&gt;Created 11 July 2008    &lt;br /&gt;NS08.DOMAINCONTROL.COM    &lt;br /&gt;NS09.DOMAINCONTROL.COM &lt;/p&gt;  &lt;p&gt;IP: Currently no web site.&amp;#160; Last held IP was 216.195.59.78 &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Mark Haagland (markhaagland@gmail.com)    &lt;br /&gt;Ehijajate tee 150    &lt;br /&gt;Tallin, Harjumaa, 13522, EE    &lt;br /&gt;+37 262 01114 &lt;/p&gt;  &lt;p&gt;The email address has been seen in association with domains previously registered to jackyouthere@gmail.com and other malvertizing incidents: &lt;/p&gt;  &lt;p&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/01/15/1661878.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/01/15/1661878.aspx&lt;/a&gt;    &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/02/18/1672789.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/02/18/1672789.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;Malvertizement 3: &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_7CCEFB4A.png" width="646" height="181" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_43DCC99D.png" width="653" height="181" /&gt;&amp;#160; &lt;/p&gt;  &lt;p&gt;Hits &lt;strong&gt;adoptserver.info&lt;/strong&gt;, another domain featured on this blog several times. &lt;/p&gt;  &lt;p&gt;ICANN Registrar: REGTIME LTD   &lt;br /&gt;Created 24 Jun 2007    &lt;br /&gt;NS.ADOPTSERVER.INFO    &lt;br /&gt;NS2.ADOPTSERVER.INFO &lt;/p&gt;  &lt;p&gt;IP: Offline and currently not resolving. Last held IP was 64.28.187.77 &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Javier Vega (softjoda@yahoo.com)    &lt;br /&gt;Tegelbacken 7, Box 193    &lt;br /&gt;Stockholm, 10123    &lt;br /&gt;+46 841 23433 &lt;/p&gt;  &lt;p&gt;softjoda@yahoo.com is associated with 12 domains, including servedad.net which has been implicated in malvertizing incidents in the past: &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2008/12/13/1656668.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2008/12/13/1656668.aspx&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1692845" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>ALERT: Please treat advertising from Gilmours Media (gilmoursmedia.com) with extreme caution</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/05/20/1692842.aspx</link><pubDate>Wed, 20 May 2009 13:04:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1692842</guid><dc:creator>sandi</dc:creator><slash:comments>1</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1692842</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/05/20/1692842.aspx#comments</comments><description>&lt;p&gt;&lt;img height="490" width="576" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_7EC50FAB.png" align="left" alt="image" border="0" title="image" style="border-right-width:0px;margin:10px 20px 20px 0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" /&gt; &lt;br /&gt;They have been caught distributing malvertizing. &lt;/p&gt;
&lt;p&gt;Current registration details are: &lt;/p&gt;
&lt;p&gt;ICANN Registrar: REGTIME LTD &lt;br /&gt;Created 24 March 2008 &lt;br /&gt;NS1.NAMESELF.COM &lt;br /&gt;NS2.NAMESELF.COM &lt;/p&gt;
&lt;p&gt;IP: 64.28.187.33 - New York, Internet Path Inc &lt;/p&gt;
&lt;p&gt;Registrant: &lt;/p&gt;
&lt;p&gt;Jacob Tua (saidfahtih@gmail.com) &lt;br /&gt;Maltiskam 12-67 &lt;br /&gt;Belgrade 11008 &lt;br /&gt;Russia &lt;br /&gt;+381 113 114 094&lt;/p&gt;
&lt;p&gt;It should be noted that gilmoursmedia.com was originally registered via the infamous ESTDOMAINS, to a &amp;quot;&lt;strong&gt;Jacob Tua&lt;/strong&gt;&amp;quot; of &lt;strong&gt;Maltiskam 12-67, Belgrade, 11008, telephone +381.113114094&lt;/strong&gt;. &lt;/p&gt;
&lt;p&gt;More importantly, the email address for &amp;quot;Jacob Tua&amp;quot; was &amp;quot;&lt;strong&gt;jackyouthere@gmail.com&lt;/strong&gt;&amp;quot;.&amp;nbsp; See this Apple discussion forum conversation about a the clipboard hijacking problem &amp;ndash; the same clipboard hijacking problem that led to Adobe changing the way Flash behaves: &lt;br /&gt;&lt;a target="_blank" href="http://discussions.apple.com/thread.jspa?messageID=7768848"&gt;http://discussions.apple.com/thread.jspa?messageID=7768848&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The domain being copied to clipboard via the Flash exploit was &amp;quot;&lt;strong&gt;windowsxp-privacy.net&lt;/strong&gt;&amp;quot;, which just so happened to be registered to, you guessed it, &lt;strong&gt;jackyouthere@gmail.com&lt;/strong&gt;!! This information was posted to the discussion thread on 20 August 2008. &lt;/p&gt;
&lt;p&gt;&amp;quot;Jacob Tua&amp;quot; was also listed as owning &lt;strong&gt;adclickmate.net&lt;/strong&gt;, another domain associated with malvertizing: &lt;br /&gt;&lt;a target="_blank" href="http://msmvps.com/blogs/spywaresucks/archive/2009/02/18/1672789.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/02/18/1672789.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The contact phone number for Gilmours Media is/was the same as that for &amp;quot;Trackstar Media&amp;quot;, being tel 401.237.4731.&lt;/p&gt;
&lt;p&gt;But the address is different, being 17 Vernon Street, Warren: &lt;br /&gt;&lt;a target="_blank" href="http://www.merchantcircle.com/business/Trackstarmedia.401-237-4731"&gt;http://www.merchantcircle.com/business/Trackstarmedia.401-237-4731&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;img height="146" width="315" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image5_5F00_64AAE66E.png" align="left" alt="image" border="0" title="image" style="border-bottom:0px;border-left:0px;margin:10px 20px 20px 0px;display:inline;border-top:0px;border-right:0px;" /&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;trackstarmedia.com was suspended due to inaccurate WHOIS information.&amp;nbsp; That domain has also been featured on this blog before: &lt;br /&gt;&lt;a target="_blank" href="http://msmvps.com/blogs/spywaresucks/archive/2008/08/13/1644602.aspx" title="http://msmvps.com/blogs/spywaresucks/archive/2008/08/13/1644602.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2008/08/13/1644602.aspx&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;img height="122" width="569" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_2EFCCBF8.png" alt="image" border="0" title="image" style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" /&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;img height="357" width="424" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_791A678E.png" alt="image" border="0" title="image" style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" /&gt;&amp;nbsp; &lt;img height="353" width="420" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_1B99390E.png" alt="image" border="0" title="image" style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" /&gt; &lt;/p&gt;
&lt;p&gt;&lt;img height="360" width="418" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_6B96999F.png" alt="image" border="0" title="image" style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1692842" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>ALERT: More malvertizements featuring classmates.com are being displayed at mediatakeout.com</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/05/05/1691872.aspx</link><pubDate>Tue, 05 May 2009 06:16:29 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1691872</guid><dc:creator>sandi</dc:creator><slash:comments>3</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1691872</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/05/05/1691872.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_64A6ADF1.png" width="861" height="131" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 20px 20px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_52829284.png" width="306" height="258" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;The malvertizements are at a web site called mediatakeout.com.&amp;#160; There are two of them:&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;mediatakeout.com/adserver/classmates300x250.swf&lt;/strong&gt;    &lt;br /&gt;Adopstools results - &lt;a title="http://www.adopstools.com/index.asp?section=quicklink&amp;amp;id=qjQ0XEgKuMwGOH2m" href="http://www.adopstools.com/index.asp?section=quicklink&amp;amp;id=qjQ0XEgKuMwGOH2m" target="_blank"&gt;http://www.adopstools.com/index.asp?section=quicklink&amp;amp;id=qjQ0XEgKuMwGOH2m&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;mediatakeout.com/adserver/classmates728x90.swf&lt;/strong&gt;    &lt;br /&gt;Adopstools results - &lt;a title="http://www.adopstools.com/index.asp?section=quicklink&amp;amp;id=5xX9tYDn83p75I5q" href="http://www.adopstools.com/index.asp?section=quicklink&amp;amp;id=5xX9tYDn83p75I5q" target="_blank"&gt;http://www.adopstools.com/index.asp?section=quicklink&amp;amp;id=5xX9tYDn83p75I5q&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;It looks like they have been in circulation for less than a day.&lt;/p&gt;  &lt;p&gt;The malvertizements have been reported to the web site owners.&lt;/p&gt;  &lt;p&gt;These malvertizements are interesting, because they hit an additional domain, being &lt;strong&gt;bannerfarm.ace.advertising.com&lt;/strong&gt;, which is an AOL asset.&amp;#160; AOL have been notified as well.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1691872" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>ALERT: malvertizing impersonating well known classmates.com advertisements.</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/05/04/1691824.aspx</link><pubDate>Mon, 04 May 2009 14:17:49 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1691824</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1691824</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/05/04/1691824.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_0ACEFFDC.png" width="861" height="131" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 20px 20px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_3F94076C.png" width="306" height="258" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Reported by Kimberley:   &lt;br /&gt;&lt;a href="http://www.bluetack.co.uk/forums/index.php?s=&amp;amp;showtopic=18064&amp;amp;view=findpost&amp;amp;p=91839" target="_blank"&gt;www.bluetack.co.uk/forums/index.php?s=&amp;amp;showtopic=18064&amp;amp;view=findpost&amp;amp;p=91839&lt;/a&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;The malvertizements are very familiar, yes?&lt;/p&gt;  &lt;p&gt;Now, &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/04/23/1690197.aspx" target="_blank"&gt;we already know that a known bad actor, yourdirectmedia, has supplied &amp;quot;Classmatesmedia, Rick Harris, 619 949 8952&amp;quot; as a referee&lt;/a&gt;.&amp;#160; We also suspect (I have not had this independently confirmed) that classmatesmedia does not directly sells advertising - rather, I believe that United Online Advertising Solutions is responsible for that chore (uolmediagroup.com).&lt;/p&gt;  &lt;p&gt;How much do you want to bet that somebody impersonating classmates.com, or falsely claiming to represent them, is responsible for these malvertizements.&lt;/p&gt;  &lt;p&gt;On display at ifood.tv, bhg.com, fitnessmagazine.com.&amp;#160; Hosted by Doubleclick :(&lt;/p&gt;  &lt;p&gt;m1.2mdn.net/2282252/classmates300x250.swf   &lt;br /&gt;m1.2mdn.net/2282252/classmates728x90.swf&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1691824" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item></channel></rss>