<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6603303756960994854</id><updated>2024-10-09T13:35:59.362+11:00</updated><category term="rogue av"/><category term="fake av"/><category term="scareware"/><category term="security"/><category term="rogue app"/><category term="fake alert"/><category term="Rogue Apps"/><category term="rogue"/><category term="Malicious Intent"/><category term="Rogue Anti Spyware"/><category term="seo"/><category term="fake codec"/><category term="malware"/><category term="seo poisoning"/><category term="System Security"/><category term="Winifighter"/><category term="fake video codec"/><category term="koobface"/><category term="Antivirus Plus"/><category term="Facebook"/><category term="Security Antivirus"/><category term="Security Tool"/><category term="Tools"/><category term="android"/><category term="fake"/><category term="fake app"/><category term="porn"/><category term="social engineering"/><category term="winter games"/><category term="winter olympics"/><category term="06d.ru"/><category term="15scanner.com"/><category term="192.220.110.22"/><category term="213.163.89.60"/><category term="89.248.174.61"/><category term="89.47.237.55"/><category term="Acai Berry"/><category term="Atlanta flood pictures"/><category term="Disk2vhd"/><category term="Farm Town"/><category term="Hyper-V"/><category term="IE"/><category term="IRS"/><category term="KROTEG"/><category term="Live PC Care"/><category term="MS08-078"/><category term="MaCatte"/><category term="Malformed"/><category term="McAfee"/><category term="Mediacodec"/><category term="Microsoft HTML Application host"/><category term="SE2010.exe"/><category term="Safety Center"/><category term="SecurityTool"/><category term="Sysguard"/><category term="System Cleaner"/><category term="The Best Nude Celebrity Movie Site"/><category term="TotalSecurity"/><category term="TrustCop"/><category term="TrustFighter"/><category term="TrustNinja"/><category term="Video ActiveX Object"/><category term="Video ActiveX Object Error"/><category term="Virtual Hard Disk"/><category term="Virtual PC"/><category term="Virus"/><category term="Virut"/><category term="Vulnerabilities"/><category term="Windows File Protection"/><category term="Windows System Suite"/><category term="WiniShield"/><category term="XML"/><category term="Zbot"/><category term="acaipowermax.com"/><category term="adultsvideo.cn"/><category term="alyssafan.net"/><category term="androidonlinefix.info"/><category term="antivirussecurescannerv3.com"/><category term="bestmalwaredetect.com"/><category term="blacklist"/><category term="bypass"/><category term="clone"/><category term="comres.dll"/><category term="darkerprojects.com"/><category term="dougalek"/><category term="downloader"/><category term="exploit"/><category term="fake VAC"/><category term="fake microsoft update"/><category term="fakealert"/><category term="file infector"/><category term="freakyloveresults.com"/><category term="freeanalsextubemovies.com"/><category term="freebigutilites.com"/><category term="gaoanalitics.info"/><category term="google"/><category term="guardinfo.net"/><category term="hockey game schedule"/><category term="homeamateurclips.com"/><category term="idrb.com"/><category term="inter olympics"/><category term="internet explorer"/><category term="kukuruku-290709.com"/><category term="linewebsearch.com"/><category term="lowsec"/><category term="macatte.com"/><category term="macrovirus"/><category term="mail1.e-corecorporation.com"/><category term="malicious"/><category term="malicious domain"/><category term="microsoftupdate.html"/><category term="mshta.exe"/><category term="notcompatible"/><category term="obfuscated script"/><category term="p2v"/><category term="packupdate_build"/><category term="pcprotectzone.com"/><category term="porntube2000"/><category term="proscan5.info"/><category term="qlft9c"/><category term="ransomware"/><category term="read-cnn2.com"/><category term="rogue domain"/><category term="roguerogue av"/><category term="scam"/><category term="sdra64.exe"/><category term="searchscanner.net"/><category term="security essentials 2010 removal"/><category term="securityadjust.com"/><category term="securityannounce.com"/><category term="sfc.exe"/><category term="shellcode"/><category term="sinel.com"/><category term="starbasi"/><category term="summit102.summitdesign.net"/><category term="system file checker"/><category term="terminateprocess"/><category term="theatypxdd.net"/><category term="tinyurl"/><category term="tmp.exe"/><category term="trojan"/><category term="trustfighter.com"/><category term="ue4x08f5myqdl.cn"/><category term="update09.exe"/><category term="video"/><category term="vulnerability"/><category term="whitelist"/><category term="windowsprotectionsuite.com"/><category term="windowssecuritysuite.com"/><category term="winfixscanner7.com"/><category term="yahoo im spam"/><title type='text'>Malware Research Experts</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default?redirect=false'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default?start-index=26&amp;max-results=25&amp;redirect=false'/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>36</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-7430318314100418196</id><published>2012-05-03T12:02:00.001+10:00</published><updated>2012-05-03T12:02:24.870+10:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="android"/><category scheme="http://www.blogger.com/atom/ns#" term="androidonlinefix.info"/><category scheme="http://www.blogger.com/atom/ns#" term="gaoanalitics.info"/><category scheme="http://www.blogger.com/atom/ns#" term="notcompatible"/><title type='text'>NotCompatible Android Malware: First-known Android Drive-By Download Attack</title><summary type="text">On May 2nd 2012, Lookout reported the first known incident where compromised websites are being used to serve malicious apps to Android users.



&quot;NotCompatible is a new Android trojan that appears to serve as a simple TCP relay / proxy while posing as a system update. This threat does not currently appear to cause any direct harm to a target device, but could potentially be used to gain illicit </summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/7430318314100418196/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2012/05/notcompatible-android-malware-first.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/7430318314100418196'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/7430318314100418196'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2012/05/notcompatible-android-malware-first.html' title='NotCompatible Android Malware: First-known Android Drive-By Download Attack'/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3Y0cOdKUw2Q9AeFEZ-0Ke4A2M_gGhcFyed811kGtnjoYHssoqwS-XO7moiqspVtwgfDjl6fMYje-jydvFK7Ko2ENCA8SCUGz-lKGamW5CJOlANADLHmYQy1HGR2WfPHzpvpjuBNy6voc/s72-c/iframe.png" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-2017603005287592654</id><published>2012-04-17T17:18:00.000+10:00</published><updated>2012-04-17T17:18:12.872+10:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="android"/><category scheme="http://www.blogger.com/atom/ns#" term="dougalek"/><title type='text'>Android Malware Dougalek Steals Contact Information</title><summary type="text">Dougalek is a mobile malware that runs on Android devices.&amp;nbsp;It downloads and plays movie clips from a predetermined remote website while stealing information in the background.

The mobile malware requests the following permissions:

INTERNET - Allows applications to open network sockets.
READ_CONTACTS - Allows an application to read the user&#39;s contacts data.
READ_PHONE_STATE - Allows read </summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/2017603005287592654/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2012/04/android-malware-dougalek-steals-contact.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/2017603005287592654'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/2017603005287592654'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2012/04/android-malware-dougalek-steals-contact.html' title='Android Malware Dougalek Steals Contact Information'/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6mpBff6foRCbfCNK_MsXpQFsWiZAQ-JDRdYPMiInijP-HrmBVtXMvFS_Sivih03kb3U472bKWeXlPLYoyKMgVLhTn9ADRBem7vuO7g3bWOQ3pPXLZXSfsZ5i-rQPGOifMPx_iQMoqHTg/s72-c/dougalek_permissions.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-4424561577804281629</id><published>2012-04-06T09:05:00.000+10:00</published><updated>2012-04-06T09:05:50.648+10:00</updated><title type='text'>Google&#39;s Project Glass</title><summary type="text">image courtesy of wired.com
Google has recently unveiled Project Glass.

The idea is that it&#39;s going to be a kind of an augmented-reality device that provides google services via a sort of slim eyewear.
It sounds kind of cool to be able to take photos of what you are exactly looking at, and immediately share it to your friends, access maps, and all that kind of stuff.&amp;nbsp;
But knowing that </summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/4424561577804281629/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2012/04/googles-project-glass.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/4424561577804281629'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/4424561577804281629'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2012/04/googles-project-glass.html' title='Google&#39;s Project Glass'/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-2249099777772758711</id><published>2012-03-27T15:44:00.001+11:00</published><updated>2012-03-27T15:51:29.622+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="IRS"/><category scheme="http://www.blogger.com/atom/ns#" term="scam"/><category scheme="http://www.blogger.com/atom/ns#" term="social engineering"/><title type='text'>Fake IRS Income Tax Appeal Rejection Notice</title><summary type="text">Fake IRS Income Tax Appeal Rejection Notice
Your income tax appeal has been declined!
Unsuspecting users who receive this fake notification via email telling them that their income tax appeal has been rejected are being lured into opening and executing malicious email attachments.
The cyber criminals are using scare tactics together with legitimate-looking rejection email notifications:
Sample </summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/2249099777772758711/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2012/03/fake-irs-income-tax-appeal-rejection.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/2249099777772758711'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/2249099777772758711'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2012/03/fake-irs-income-tax-appeal-rejection.html' title='Fake IRS Income Tax Appeal Rejection Notice'/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgmOhrY_ximDl7ar0jCM2gqCgCYdCPjSn1NMad5EXCCj4kpEy9XLyio6ClxJbaoc9T335Cm-qObTwvXY4bEreeToZMlZYyk591d0-6SOtXPnMoYQX4TcMVcOV1XZJMGToLXYdlZbC8s-QY/s72-c/2012327-104643.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-8743703747024874624</id><published>2010-03-05T16:10:00.000+11:00</published><updated>2012-03-27T11:37:35.913+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="google"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue"/><category scheme="http://www.blogger.com/atom/ns#" term="Rogue Anti Spyware"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue av"/><category scheme="http://www.blogger.com/atom/ns#" term="seo"/><category scheme="http://www.blogger.com/atom/ns#" term="seo poisoning"/><title type='text'>Exploiting Google</title><summary type="text">SEO : Search Engine Optimization. No, it&#39;s not another buzz word.  It&#39;s a technique used by malware authors to propagate their malware.  They use one of the most respected search engines today (Google) to make their way into the user&#39;s machine.  Piggybacking on a prestigious, and highly trusted search engine is an efficient and effective way to reach out to billions of users worldwide.Rogue AVs </summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/8743703747024874624/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2010/03/exploiting-google.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/8743703747024874624'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/8743703747024874624'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2010/03/exploiting-google.html' title='Exploiting Google'/><author><name>Di</name><uri>http://www.blogger.com/profile/01162451377862044081</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-2858110783425593133</id><published>2010-03-05T15:34:00.000+11:00</published><updated>2012-03-27T11:37:35.895+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="file infector"/><category scheme="http://www.blogger.com/atom/ns#" term="Virus"/><category scheme="http://www.blogger.com/atom/ns#" term="Virut"/><title type='text'>Virus.Virut takes the spotlight</title><summary type="text">In this era of spywares, file infectors have little exposure left.  But nevertheless, they are still a challenge to antimalware engineers.  Years ago, the names Nimda and CIH were famous in both the malware and antimalware industry.  These past few years, the spotlight is on Virut.Last year we saw an influx of Virus.Virut infected samples.  Virus.Virut is, in my opinion, one of the best viruses </summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/2858110783425593133/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2010/03/virusvirut-takes-spotlight.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/2858110783425593133'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/2858110783425593133'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2010/03/virusvirut-takes-spotlight.html' title='Virus.Virut takes the spotlight'/><author><name>Di</name><uri>http://www.blogger.com/profile/01162451377862044081</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-4813668445506079616</id><published>2010-03-05T15:06:00.001+11:00</published><updated>2012-03-27T14:09:10.284+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="rogue"/><category scheme="http://www.blogger.com/atom/ns#" term="Rogue Anti Spyware"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue av"/><category scheme="http://www.blogger.com/atom/ns#" term="scareware"/><category scheme="http://www.blogger.com/atom/ns#" term="seo"/><category scheme="http://www.blogger.com/atom/ns#" term="seo poisoning"/><title type='text'>Disasterware strikes again, as they call it!</title><summary type="text">The magnitude 6.4 earthquake does not only rattle Taiwan but even the internet users as well. It is another opportunity for Malware writers to poison returned results from searches about this disaster. It now became a constant attack every time there is major news, earthquake, tsunami or any other event that would call the attention of the people. It seems now it guarantees every news has </summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/4813668445506079616/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2010/03/disasterware-strikes-again-as-they-call.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/4813668445506079616'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/4813668445506079616'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2010/03/disasterware-strikes-again-as-they-call.html' title='Disasterware strikes again, as they call it!'/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEju05m7jgregwZnk1UjmlQyytwTF4yuLK2CfCy8HT6pAuhFBFwrkmP8udvY3q9019UD4MO03aj182i_kBzG36aL0GFffxgEPETLHuo4UVoaGSLRLjWB_IOUzrpRGRp02-ldNTahH5QXdsEP/s72-c/te.JPG" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-1373630826035155451</id><published>2010-03-01T10:48:00.000+11:00</published><updated>2012-03-27T13:25:27.813+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="rogue"/><category scheme="http://www.blogger.com/atom/ns#" term="Rogue Anti Spyware"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue av"/><category scheme="http://www.blogger.com/atom/ns#" term="scareware"/><category scheme="http://www.blogger.com/atom/ns#" term="seo"/><category scheme="http://www.blogger.com/atom/ns#" term="seo poisoning"/><title type='text'>Chilling rogues on Chile</title><summary type="text">Shortly after the Haiti earthquake incident, the world is rocked again with the news of the Chile earthquake. And with the wave of searches on google about the Chile earthquake, malware authors have once again taken this opportunity to proliferate rogue antipsyware.

Searches returned from google are generally not suspect, especially if they bear URLs that seem normal. But one particular site (</summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/1373630826035155451/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2010/03/chilling-rogues-on-chile.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/1373630826035155451'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/1373630826035155451'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2010/03/chilling-rogues-on-chile.html' title='Chilling rogues on Chile'/><author><name>Di</name><uri>http://www.blogger.com/profile/01162451377862044081</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgsiAAkdKdfmqyVfOix3QRFzCORmgOwIpIZZR_h1ADBXVarhVEuAKVGveQ43VXNqR4WV9tzcbHzLBygZpHdp7Reysi0qsUl_pkwh0ka6IfIW2bEWJT5lJ_isxk8NZ3hm9FrZhhmibkJVA4/s72-c/pic1.JPG" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-3774927061905468349</id><published>2010-02-24T11:11:00.001+11:00</published><updated>2012-03-27T11:20:30.677+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="SE2010.exe"/><category scheme="http://www.blogger.com/atom/ns#" term="security essentials 2010 removal"/><title type='text'>How To Remove: Security Essentials 2010</title><summary type="text">
Security Essentials 2010 (SE2010.exe) is a new rogue application which is usually arrives as a file dropped by a Trojan or downloaded from the internet. It employs the same techniques as of Internet Security 2010…then again, said techniques have proven effective before, so why fix what is not broken?

Without being asked, SE2010 scans the infected computer and displays the list of threats&amp;nbsp;</summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/3774927061905468349/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2010/02/how-to-remove-security-essentials-2010.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/3774927061905468349'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/3774927061905468349'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2010/02/how-to-remove-security-essentials-2010.html' title='How To Remove: Security Essentials 2010'/><author><name>Mylene Enriquez Villacorte</name><uri>http://www.blogger.com/profile/06591360260354017972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPzBSBrGNwPAWod1O-cJ_a96jOFV37dp9l_MeJHZfUmmW2TvZf78I_roX4eBJ8og15yfWmXNBSKpGM84isrtcPACrOCTXuCSNGFVQpwBCjxWCMfGEi0OzRh9a-RCcT2HILThoxLXXq638/s72-c/esse2010.bmp" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-7894413693316798746</id><published>2010-02-23T22:35:00.002+11:00</published><updated>2012-03-27T13:34:18.318+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="darkerprojects.com"/><category scheme="http://www.blogger.com/atom/ns#" term="fake av"/><category scheme="http://www.blogger.com/atom/ns#" term="hockey game schedule"/><category scheme="http://www.blogger.com/atom/ns#" term="packupdate_build"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue"/><category scheme="http://www.blogger.com/atom/ns#" term="Rogue Anti Spyware"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue av"/><category scheme="http://www.blogger.com/atom/ns#" term="Security Antivirus"/><category scheme="http://www.blogger.com/atom/ns#" term="seo"/><category scheme="http://www.blogger.com/atom/ns#" term="seo poisoning"/><category scheme="http://www.blogger.com/atom/ns#" term="winter games"/><category scheme="http://www.blogger.com/atom/ns#" term="winter olympics"/><title type='text'>SEO Poisoning scores a goal at the 2010 Winter Olympics</title><summary type="text">
The Hockey games on the 2010 Winter Olympics are well under way and SEO poisoning attacks abound! Hockey enthusiasts turning to the Internet in search of game schedules are in for quite a surprise as cyber-criminals are quick to ensure that their malicious websites appear in the top Google search results.








Redirection

Unsuspecting users who click on the malicious search results are </summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/7894413693316798746/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2010/02/seo-poisoning-scores-goal-at-2010.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/7894413693316798746'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/7894413693316798746'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2010/02/seo-poisoning-scores-goal-at-2010.html' title='SEO Poisoning scores a goal at the 2010 Winter Olympics'/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjO5WKuJ2Ttj9R_HxK9e0HLbd0VECcvXL9ITyIf5S6jRwMZB_yB5BhWFHenEAXbXmcUrwXeCNsmQ0mulKpQvO-1poOcYyt1OnEqNnJaR2OlD5xlfOKMQTK-EHHpQM9V6sGzS-Wacuvd9RI/s72-c/2010223-16535.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-2668088893974877876</id><published>2010-02-22T14:21:00.053+11:00</published><updated>2010-02-22T18:42:21.321+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="fake av"/><category scheme="http://www.blogger.com/atom/ns#" term="fake codec"/><category scheme="http://www.blogger.com/atom/ns#" term="fake video codec"/><category scheme="http://www.blogger.com/atom/ns#" term="inter olympics"/><category scheme="http://www.blogger.com/atom/ns#" term="Live PC Care"/><category scheme="http://www.blogger.com/atom/ns#" term="Rogue Anti Spyware"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue av"/><category scheme="http://www.blogger.com/atom/ns#" term="Security Antivirus"/><category scheme="http://www.blogger.com/atom/ns#" term="Security Tool"/><category scheme="http://www.blogger.com/atom/ns#" term="Windows System Suite"/><category scheme="http://www.blogger.com/atom/ns#" term="winter games"/><category scheme="http://www.blogger.com/atom/ns#" term="winter olympics"/><title type='text'>Rogues on Winter Olympics&#39; Playing Field</title><summary type="text">	Another hot topic circulating around the internet is the Winter Olympics and the hits around the search engines come soaring when the news of the death of a 21 year old luger Nodar Kumaritashvili breaks out. Malware writers are quick on taking advantage of this news to infect computer users browsing every website wanting to be updated. They also use as well as the current medal count at the said</summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/2668088893974877876/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2010/02/rogue-avs-on-winter-olympics-playing.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/2668088893974877876'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/2668088893974877876'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2010/02/rogue-avs-on-winter-olympics-playing.html' title='Rogues on Winter Olympics&#39; Playing Field'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgaatpO9RGhnkAkjZmsAzmmpDSp8qBwK6PgJsvaiDiNHakpJGFuSSdXS3MudEw7ohVrWz7fwzNzghKVcryMqoLP9aodIEONMg98V5m170FZu2MXZnXEzR3_NmVDzOBMwEKcAZnzRYVy1oo/s72-c/GoogleResult_IS.JPG" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-9094134902099729508</id><published>2010-02-19T15:51:00.014+11:00</published><updated>2010-02-19T16:29:11.165+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="fake av"/><category scheme="http://www.blogger.com/atom/ns#" term="fake codec"/><category scheme="http://www.blogger.com/atom/ns#" term="fake video codec"/><category scheme="http://www.blogger.com/atom/ns#" term="porntube2000"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue av"/><category scheme="http://www.blogger.com/atom/ns#" term="scareware"/><category scheme="http://www.blogger.com/atom/ns#" term="Security Tool"/><category scheme="http://www.blogger.com/atom/ns#" term="Video ActiveX Object"/><category scheme="http://www.blogger.com/atom/ns#" term="Video ActiveX Object Error"/><title type='text'>Porntube Anyone? Bonus Scareware!</title><summary type="text">Porn clips are everywhere! But then again, rogue antivirus software are everywhere too.The fake video codec tactic targets unsuspecting users wanting to view the adult videos purportedly being hosted in the malicious website:hxxp://porntube2000.comClicking on one of the thumbnails presents a video player window with the error message &quot;Video ActiveX Object Error&quot;. The message asks the user install</summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/9094134902099729508/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2010/02/porntube-anyone-bonus-scareware.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/9094134902099729508'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/9094134902099729508'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2010/02/porntube-anyone-bonus-scareware.html' title='Porntube Anyone? Bonus Scareware!'/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVvy_JLpWoXKYvMTNlJoqH9Xwt7vv-3erMFzmE-SMaT8CqtyftACeWkO1YwcDZQ2KkWsnAT7jbesOJ1rwxK5KIgOuo28xD9YnoP6leMLBzEmV7BxGqmVZ8Y1HI-CJAKbqU_jAFjmtLweg/s72-c/RogueAntiSpyware.SecurityTool_2010218-153048_censored.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-2680195565876006640</id><published>2010-01-22T12:03:00.000+11:00</published><updated>2012-03-27T13:23:07.767+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Acai Berry"/><category scheme="http://www.blogger.com/atom/ns#" term="acaipowermax.com"/><category scheme="http://www.blogger.com/atom/ns#" term="freakyloveresults.com"/><category scheme="http://www.blogger.com/atom/ns#" term="social engineering"/><category scheme="http://www.blogger.com/atom/ns#" term="yahoo im spam"/><title type='text'>Social Engineering Tactics Promote &amp;quot;Miracle&amp;quot; Berries</title><summary type="text">I received an unlikely Yahoo! IM from a long time friend with whom I have not been in contact with for quite a long time.

Af first I thought, wow this would be a good time to catch up.

She buzzed me and asked me if I was busy, then gave me a URL to try out very quickly and tell her what the results tell me.

Well, here&#39;s the screenshot:


The link was: hxxp://freakyloverresults.com

At this </summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/2680195565876006640/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2010/01/social-engineering-tactics-promote.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/2680195565876006640'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/2680195565876006640'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2010/01/social-engineering-tactics-promote.html' title='Social Engineering Tactics Promote &amp;quot;Miracle&amp;quot; Berries'/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-110204503188381751</id><published>2009-12-07T17:52:00.002+11:00</published><updated>2012-03-27T14:05:54.482+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="adultsvideo.cn"/><category scheme="http://www.blogger.com/atom/ns#" term="fake"/><category scheme="http://www.blogger.com/atom/ns#" term="fake codec"/><category scheme="http://www.blogger.com/atom/ns#" term="fake VAC"/><category scheme="http://www.blogger.com/atom/ns#" term="fakealert"/><category scheme="http://www.blogger.com/atom/ns#" term="freeanalsextubemovies.com"/><category scheme="http://www.blogger.com/atom/ns#" term="freebigutilites.com"/><category scheme="http://www.blogger.com/atom/ns#" term="homeamateurclips.com"/><category scheme="http://www.blogger.com/atom/ns#" term="Malicious Intent"/><category scheme="http://www.blogger.com/atom/ns#" term="porn"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue"/><category scheme="http://www.blogger.com/atom/ns#" term="SecurityTool"/><title type='text'>Fake codec used by porn site</title><summary type="text">Here&#39;s another porn site distributing malware under the guise of video codecs:

hxxp://adultsvideo.cn/

Unsuspecting users wanting to view the adult videos are tricked into downloading and installing the fake codec.

The fake codec can be downloaded from this url:

hxxp://freebigutilites.com/ActiveX-Video-Codec.45092.exe

The server spits out files that have different MD5s each time.

</summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/110204503188381751/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2009/12/fake-codec-used-by-porn-site.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/110204503188381751'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/110204503188381751'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2009/12/fake-codec-used-by-porn-site.html' title='Fake codec used by porn site'/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-1121239611001828555</id><published>2009-11-03T18:14:00.002+11:00</published><updated>2012-03-27T13:58:09.485+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="fake app"/><category scheme="http://www.blogger.com/atom/ns#" term="fake av"/><category scheme="http://www.blogger.com/atom/ns#" term="MaCatte"/><category scheme="http://www.blogger.com/atom/ns#" term="macatte.com"/><category scheme="http://www.blogger.com/atom/ns#" term="McAfee"/><category scheme="http://www.blogger.com/atom/ns#" term="proscan5.info"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue app"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue av"/><category scheme="http://www.blogger.com/atom/ns#" term="scareware"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><title type='text'>MaCatte scareware fools users by masquerading as McAfee</title><summary type="text">

MaCatte Antivirus is a rogue av that attempts to impersonate McAfee scanners in order to scam users.

This scareware has been seen to be using a bogus My Computer online scan similar to ones we&#39;ve seen here, here and here.



The online scan can be seen on this url:

hxxp://proscan5.info/25/26-088wLzQzL1EzL==

The downloader being served from this url is time-sensitive and will not work after a</summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/1121239611001828555/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2009/11/macatte-scareware-fools-users-by.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/1121239611001828555'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/1121239611001828555'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2009/11/macatte-scareware-fools-users-by.html' title='MaCatte scareware fools users by masquerading as McAfee'/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-4397491505754653189</id><published>2009-10-21T09:02:00.000+11:00</published><updated>2012-03-27T13:23:07.790+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Disk2vhd"/><category scheme="http://www.blogger.com/atom/ns#" term="Hyper-V"/><category scheme="http://www.blogger.com/atom/ns#" term="p2v"/><category scheme="http://www.blogger.com/atom/ns#" term="Tools"/><category scheme="http://www.blogger.com/atom/ns#" term="Virtual Hard Disk"/><category scheme="http://www.blogger.com/atom/ns#" term="Virtual PC"/><title type='text'>Sysinternals Releases Disk2vhd v1.0</title><summary type="text">Sysinternals has recently released Disk2vhd that &quot;simplifies the migration of physical systems into virtual machines (p2v).&quot;


Disk2vhd is a utility that creates VHD (Virtual Hard Disk - Microsoft’s Virtual Machine disk format) versions of physical disks for use in Microsoft Virtual PC or Microsoft Hyper-V virtual machines (VMs)


More here.</summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/4397491505754653189/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2009/10/sysinternals-releases-disk2vhd-v10.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/4397491505754653189'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/4397491505754653189'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2009/10/sysinternals-releases-disk2vhd-v10.html' title='Sysinternals Releases Disk2vhd v1.0'/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-8359127873910716058</id><published>2009-10-15T13:21:00.000+11:00</published><updated>2012-03-27T13:23:07.862+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="rogue app"/><category scheme="http://www.blogger.com/atom/ns#" term="Rogue Apps"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue av"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><category scheme="http://www.blogger.com/atom/ns#" term="Sysguard"/><category scheme="http://www.blogger.com/atom/ns#" term="TrustCop"/><category scheme="http://www.blogger.com/atom/ns#" term="TrustNinja"/><category scheme="http://www.blogger.com/atom/ns#" term="Winifighter"/><category scheme="http://www.blogger.com/atom/ns#" term="WiniShield"/><title type='text'>Sysguard / Winifighter Clones</title><summary type="text">Here are some screenshots of the members of this scareware family:



Beware of these rouge apps.</summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/8359127873910716058/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2009/10/sysguard-winifighter-clones.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/8359127873910716058'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/8359127873910716058'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2009/10/sysguard-winifighter-clones.html' title='Sysguard / Winifighter Clones'/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-8121198510273340056</id><published>2009-10-13T14:48:00.002+11:00</published><updated>2012-03-27T14:00:46.830+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="bestmalwaredetect.com"/><category scheme="http://www.blogger.com/atom/ns#" term="pcprotectzone.com"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue app"/><category scheme="http://www.blogger.com/atom/ns#" term="Rogue Apps"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue av"/><category scheme="http://www.blogger.com/atom/ns#" term="scareware"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><category scheme="http://www.blogger.com/atom/ns#" term="securityadjust.com"/><category scheme="http://www.blogger.com/atom/ns#" term="securityannounce.com"/><category scheme="http://www.blogger.com/atom/ns#" term="theatypxdd.net"/><category scheme="http://www.blogger.com/atom/ns#" term="TrustFighter"/><category scheme="http://www.blogger.com/atom/ns#" term="trustfighter.com"/><category scheme="http://www.blogger.com/atom/ns#" term="Winifighter"/><title type='text'>Winifighter Clone: TrustFighter</title><summary type="text">

Another scareware has been spotted in the wild and it calls itself TrustFighter. This is a recent addition to the Winifighter family of scareware.

Same as other members of this family of scareware, as in a previous post, TrustFighter creates heaps of junk binary files in the %systemroot% and %system% directories.

Sample junk files are the following:

%systemroot%\51c0vzr24975.dll
%systemroot%</summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/8121198510273340056/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2009/10/winifighter-clone-trustfighter.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/8121198510273340056'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/8121198510273340056'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2009/10/winifighter-clone-trustfighter.html' title='Winifighter Clone: TrustFighter'/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-2092597175979321171</id><published>2009-09-25T14:10:00.000+10:00</published><updated>2012-03-27T13:23:07.755+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="192.220.110.22"/><category scheme="http://www.blogger.com/atom/ns#" term="fake microsoft update"/><category scheme="http://www.blogger.com/atom/ns#" term="lowsec"/><category scheme="http://www.blogger.com/atom/ns#" term="mail1.e-corecorporation.com"/><category scheme="http://www.blogger.com/atom/ns#" term="microsoftupdate.html"/><category scheme="http://www.blogger.com/atom/ns#" term="sdra64.exe"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><category scheme="http://www.blogger.com/atom/ns#" term="sinel.com"/><category scheme="http://www.blogger.com/atom/ns#" term="summit102.summitdesign.net"/><category scheme="http://www.blogger.com/atom/ns#" term="tmp.exe"/><category scheme="http://www.blogger.com/atom/ns#" term="update09.exe"/><category scheme="http://www.blogger.com/atom/ns#" term="Zbot"/><title type='text'>Bogus MS Update</title><summary type="text">We have been receiving bogus emails claiming to be coming from Microsoft:


...public distribution of this Update through the official website »www.microsoft.com would have result in efficient creation of a malicious software, we made a decision to issue an experimental private version of an update for all users Microsoft Windows OS.
as the computer set to receive notifications when new updates </summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/2092597175979321171/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2009/09/bogus-ms-update.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/2092597175979321171'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/2092597175979321171'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2009/09/bogus-ms-update.html' title='Bogus MS Update'/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-5156128671050962708</id><published>2009-09-22T15:03:00.000+10:00</published><updated>2012-03-27T13:27:17.534+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="06d.ru"/><category scheme="http://www.blogger.com/atom/ns#" term="15scanner.com"/><category scheme="http://www.blogger.com/atom/ns#" term="213.163.89.60"/><category scheme="http://www.blogger.com/atom/ns#" term="89.248.174.61"/><category scheme="http://www.blogger.com/atom/ns#" term="89.47.237.55"/><category scheme="http://www.blogger.com/atom/ns#" term="Atlanta flood pictures"/><category scheme="http://www.blogger.com/atom/ns#" term="fake alert"/><category scheme="http://www.blogger.com/atom/ns#" term="fake av"/><category scheme="http://www.blogger.com/atom/ns#" term="idrb.com"/><category scheme="http://www.blogger.com/atom/ns#" term="read-cnn2.com"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue"/><category scheme="http://www.blogger.com/atom/ns#" term="roguerogue av"/><category scheme="http://www.blogger.com/atom/ns#" term="scareware"/><category scheme="http://www.blogger.com/atom/ns#" term="seo"/><category scheme="http://www.blogger.com/atom/ns#" term="TotalSecurity"/><category scheme="http://www.blogger.com/atom/ns#" term="winfixscanner7.com"/><title type='text'>Another Shameless SEO based on Atlanta Flooding</title><summary type="text">Users Googling &quot;Atlanta flood pictures&quot; receive a yet another SEO attack, using a possibly compromised legitimate Australian website hosting restaurants in the famous Bondi area.

Here&#39;s a screenshot of a google search result:


A Fiddler capture shows us the redirections:


So we go from
hxxp://idrb.com/pdf_files/atlanta-flood-pictures.html&amp;gt;hxxp://06d.ru/t.php&amp;gt;&amp;gt;hxxp://read-cnn2.com/?pid</summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/5156128671050962708/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2009/09/another-shameless-seo-based-on-atlanta.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/5156128671050962708'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/5156128671050962708'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2009/09/another-shameless-seo-based-on-atlanta.html' title='Another Shameless SEO based on Atlanta Flooding'/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-6028339232818734005</id><published>2009-09-18T21:14:00.003+10:00</published><updated>2012-03-27T13:55:19.028+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="koobface"/><title type='text'>Koobface on the Move, Serving Scareware !!</title><summary type="text">We have been seeing a lot of new movement on the koobface front Lately.



As koobface-serving domains are being taken down as early as the good guys discover them, the bad guys are at it and they respond by registering new ones. At the moment, their, C&amp;amp;C server is hosted in China with IP Address 61.235.117.83.

The bad guys are still using a fake facebook website, as well as posing as a fake</summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/6028339232818734005/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2009/09/koobface-on-move-serving-scareware.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/6028339232818734005'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/6028339232818734005'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2009/09/koobface-on-move-serving-scareware.html' title='Koobface on the Move, Serving Scareware !!'/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-7147598506315870075</id><published>2009-08-27T18:52:00.000+10:00</published><updated>2012-03-27T13:23:07.825+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="alyssafan.net"/><category scheme="http://www.blogger.com/atom/ns#" term="fake alert"/><category scheme="http://www.blogger.com/atom/ns#" term="fake app"/><category scheme="http://www.blogger.com/atom/ns#" term="fake av"/><category scheme="http://www.blogger.com/atom/ns#" term="fake codec"/><category scheme="http://www.blogger.com/atom/ns#" term="fake video codec"/><category scheme="http://www.blogger.com/atom/ns#" term="Mediacodec"/><category scheme="http://www.blogger.com/atom/ns#" term="porn"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue app"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue av"/><category scheme="http://www.blogger.com/atom/ns#" term="Safety Center"/><category scheme="http://www.blogger.com/atom/ns#" term="scareware"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><category scheme="http://www.blogger.com/atom/ns#" term="The Best Nude Celebrity Movie Site"/><category scheme="http://www.blogger.com/atom/ns#" term="ue4x08f5myqdl.cn"/><category scheme="http://www.blogger.com/atom/ns#" term="video"/><title type='text'>Porn site distributes scareware</title><summary type="text">Another website has recently been spotted to be serving up malware in the guise of fake video codecs.

This one praises itself as &quot;The Best Nude Celebrity Movie Site&quot;
hxxp://alyssafan.net/1.html



But in order to watch the any video, we would need to download and install their &quot;Certified ActiveX video codec (VAC codec) use to protect content Copyrights&quot;

The fake fake codec can be downloaded </summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/7147598506315870075/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2009/08/porn-site-distributes-scareware.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/7147598506315870075'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/7147598506315870075'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2009/08/porn-site-distributes-scareware.html' title='Porn site distributes scareware'/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-8617714107682697927</id><published>2009-08-21T18:56:00.000+10:00</published><updated>2012-03-27T13:29:01.226+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="blacklist"/><category scheme="http://www.blogger.com/atom/ns#" term="Facebook"/><category scheme="http://www.blogger.com/atom/ns#" term="fake"/><category scheme="http://www.blogger.com/atom/ns#" term="fake alert"/><category scheme="http://www.blogger.com/atom/ns#" term="fake av"/><category scheme="http://www.blogger.com/atom/ns#" term="koobface"/><category scheme="http://www.blogger.com/atom/ns#" term="Malicious Intent"/><category scheme="http://www.blogger.com/atom/ns#" term="ransomware"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue av"/><category scheme="http://www.blogger.com/atom/ns#" term="scareware"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><category scheme="http://www.blogger.com/atom/ns#" term="System Security"/><category scheme="http://www.blogger.com/atom/ns#" term="terminateprocess"/><category scheme="http://www.blogger.com/atom/ns#" term="whitelist"/><title type='text'>Scareware asking for ransom: System Security</title><summary type="text">

Scareware is BIG business. They use heaps of scare tactics in order to convince unsuspecting users into buying rogue applications. But here&#39;s one that does a bit more than just scaring.

System Security terminates almost all running processes. This basically prevents us from using our computers. More importantly, this hinders execution of tools necessary to investigate the infection and aid in </summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/8617714107682697927/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2009/08/scareware-asking-for-ransome.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/8617714107682697927'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/8617714107682697927'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2009/08/scareware-asking-for-ransome.html' title='Scareware asking for ransom: System Security'/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-740869398642720971</id><published>2009-08-20T18:37:00.000+10:00</published><updated>2012-03-27T13:23:07.832+11:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="clone"/><category scheme="http://www.blogger.com/atom/ns#" term="fake alert"/><category scheme="http://www.blogger.com/atom/ns#" term="fake av"/><category scheme="http://www.blogger.com/atom/ns#" term="guardinfo.net"/><category scheme="http://www.blogger.com/atom/ns#" term="linewebsearch.com"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue app"/><category scheme="http://www.blogger.com/atom/ns#" term="rogue av"/><category scheme="http://www.blogger.com/atom/ns#" term="scareware"/><category scheme="http://www.blogger.com/atom/ns#" term="searchscanner.net"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><category scheme="http://www.blogger.com/atom/ns#" term="windowsprotectionsuite.com"/><category scheme="http://www.blogger.com/atom/ns#" term="windowssecuritysuite.com"/><title type='text'>Rogue AV Clone: Windows Protection Suite</title><summary type="text">

Another scareware has been spotted and it calls itself Windows Protection Suite.

You can get Windows Protection Suite from one of these urls:
hxxp://searchscanner.net/?p=WKmimHVlbXCHjsbIo22EfYCIt1POo22YXZmK0qR0qay9sYmbm5h2lpd9fXCHodjSbpRelWZsmGGZYWPMU9jSzKKsl3OWh9esb2VraWhpbWyWX5aMlJNqhxxp://linewebsearch.com/?p=</summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/740869398642720971/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2009/08/rogue-av-clone-windows-protection-suite.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/740869398642720971'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/740869398642720971'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2009/08/rogue-av-clone-windows-protection-suite.html' title='Rogue AV Clone: Windows Protection Suite'/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6603303756960994854.post-4448198461650871963</id><published>2009-08-19T18:07:00.001+10:00</published><updated>2012-03-27T13:27:03.924+11:00</updated><title type='text'></title><summary type="text">

A recently leaked threesome sex tape, involving Grey&#39;s Anatomy&#39;s &quot;McSteamy&quot; Eric Dane and wife Rebecca Gayheart, has been circulating around the internet. And we all know that controversial stuff like these are often taken advantage of and used to distribute malware using techniques such as social engineering and SEO (search-engine optimization). Users of one particular website have been </summary><link rel='replies' type='application/atom+xml' href='http://malware-research-experts.blogspot.com/feeds/4448198461650871963/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malware-research-experts.blogspot.com/2009/08/recently-leaked-threesome-sex-tape.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/4448198461650871963'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6603303756960994854/posts/default/4448198461650871963'/><link rel='alternate' type='text/html' href='http://malware-research-experts.blogspot.com/2009/08/recently-leaked-threesome-sex-tape.html' title=''/><author><name>Steve Espino</name><uri>http://www.blogger.com/profile/11714946188727181972</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYYO8smrHIuPrFl-J9_dM76Pb1UsneF88fI8KWtsz0RH5sEPGJfC4l_0N7tNdZS7DIsEzlOQAnY1AAHovlXNuzFYwhkQPkg5qKjuqg248EO8R19CvH_vOkQT33sXRGA/s220/steve-espino.jpg'/></author><thr:total>0</thr:total></entry></feed>