<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Spyware Sucks</title><link>http://msmvps.com/blogs/spywaresucks/default.aspx</link><description>But here is the dirty little secret of browser security: Even if every Internet browser made today were completely bug-free, it wouldn&amp;#39;t stop malicious hackers and malware. Why? Because the vast majority of successful malicious exploits today don&amp;#39;t exploit buggy browsers, but rather unwitting end-users. That is, Web-based malware is successful because end-users are intentionally installing it! Most exploit code doesn&amp;#39;t search for an unpatched vulnerability, but simply asks the user to install. - Roger Grimes, Infoworld</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/SpywareSucks" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item><title>FTC versus Innovative Marketing et al – Sam Jain  and Kirsty Ross respond (and other developments)</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/Y9QFQyIPSjY/1697445.aspx</link><pubDate>Wed, 01 Jul 2009 09:08:15 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1697445</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1697445</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/07/01/1697445.aspx#comments</comments><description>&lt;p&gt;&lt;strong&gt;Sam Jain&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;I would have loved to shine a light on some nice juicy arguments but, alas, it wasn’t to be.&amp;#160; The entirety of Jain’s answer compromised just a few types of response, as follows:&lt;/p&gt;  &lt;p&gt;Paragraph text version 1)&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“Paragraph X of the Complaint contains legal conclusions to which no response is required”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Paragraph text version 2)&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“Paragraph X of the Complaint contains legal conclusions to which no response is required.&amp;#160; To the extent Paragraph X of the Complaint contains factual allegations to which a response is required, Mr Jain lacks sufficient information to admit or deny the allegations and therefore denies those allegations”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Paragraph text version 3)&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“The subject matter of the Complaint in this case is the basis for an ongoing investigation conducted by the U.S. Attorney for the Northern District of Illinois.&amp;#160; Exercising his rights under the Fifth Amendment of the Constitution of the United States, Mr Jain respectfully declines to answer the allegations contained in paragraph X on the ground that his answer might tend to incriminate him.&amp;#160; Mr Jain further respectfully requests that such declination have the same procedural effect under Fed. R. Civ. P. 8(d), as if he specifically denied the allegations.”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Paragraph text version 4)&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“Exercising his rights under the Fifth Amendment of the Constitution of the United States, Mr Jain respectfully declines to answer the allegations contained in Paragraph X on the ground that his answer might tend to incriminate him.&amp;#160; Mr Jain further respectfully requests that such declination have the same procedural effect under Fed. R. Civ. P. 8(d), as if he specifically denied the allegations.”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;And so it goes on, with variations to the same theme such as “Mr Jain lacks sufficient information to admit or deny the allegations... and therefore denies those allegations”.&lt;/p&gt;  &lt;p&gt;Finally, Mr Jain puts forth three Affirmative Defenses: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;Plaintiff has failed to state a claim upon which relief can be granted&amp;quot;, and &lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;Any injury allegedly incurred was not caused by Mr Jain, and any injury resulted from superseding or intervening events outside the knowledge or control of Mr Jain&amp;quot;, and &lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;Mr Jain expressly reserves the right to assert any and all other defenses to the Amended Complaint as they become known&amp;quot;.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;In short, it is 17 pages saying pretty much nothing at all…&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Kristy Ross&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Kristy Ross has also filed her Answer (31 pages long).&amp;#160; It, too, contains various denials and coy Fifth Amendments incrimination demurs, but she does admit (aka agree) that the FTC is an independent agency of the US Government created by statute, that it enforces Section 5(a) of the FTC Act and is authorized to initiate federal district court proceeding. &lt;/p&gt;  &lt;p&gt;Her defenses are: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“The statement of any defense does not assume the burden of proof for any issue as to which applicable law places the burden upon plaintiff. Defendant expressly reserves the right to amend and/or supplement her defenses or assert any matters in avoidance of plaintiff&amp;#39;s claim which may become appropriate as discovery proceeds in this case”; and &lt;/p&gt;    &lt;p&gt;“Plaintiff has failed to state a claim upon which relief can be granted”; and &lt;/p&gt;    &lt;p&gt;“Any injury allegedly incurred was not caused by Defendant Ross and any injury resulted from superseding or intervening events outside the knowledge or control of Defendant Ross”.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Innovative Marketing, Inc and Daniel Sundin &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The FTC has lodged a Motion for Entry of Default for want of answer or other defense, with responses due by 13 July 2009.&amp;#160; Bearing in mind both parties have ignored the proceedings so far, and are unrepresented, I doubt that IM or Sundin are going to acknowledge the FTC&amp;#39;s lawsuit now. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Marc D&amp;#39;Souza &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Arguments via Motion and Reply continue as D&amp;#39;Souza attempts to have the complaint against him dismissed.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;James Reno and ByteHosting&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The Judge has signed the Reno Orders, so that is all over and done with. &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1697445" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=Y9QFQyIPSjY:9jKt6UQWYvM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=Y9QFQyIPSjY:9jKt6UQWYvM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=Y9QFQyIPSjY:9jKt6UQWYvM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/Y9QFQyIPSjY" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/07/01/1697445.aspx</feedburner:origLink></item><item><title>FTC v Innovative Marketing – the agreement with James Reno and Byte Hosting</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/IaqVwwdHZj4/1695625.aspx</link><pubDate>Tue, 16 Jun 2009 15:23:48 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1695625</guid><dc:creator>sandi</dc:creator><slash:comments>3</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1695625</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/06/17/1695625.aspx#comments</comments><description>&lt;p&gt;&lt;img style="margin:10px 20px 20px 0px;display:inline;" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_0D59123F.png" alt="" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Back on the 11th I reminded everybody that I expected the proposed stipulated final order between the FTC, Reno and ByteHosting to be filed within days.&amp;#160; As luck would have it, a Final Order For Permanent Injunction and Monetary Judgment as to James M. Reno and ByteHosting Internet Services, LLC was filed with the Court the very next day.&lt;/p&gt;  &lt;p&gt;Below are the proposed terms of the Permanent Injunction and Monetary Judgment.&amp;#160; &lt;/p&gt;  &lt;p&gt;Bear in mind, when you read about the monetary judgment, that earlier court documents have disclosed that “&lt;em&gt;after weeks of searching, the FTC has located only $174,000 of the defendants&amp;#39; assets. ... The bulk of these funds belong to James Reno.&lt;/em&gt;”&lt;/p&gt;  &lt;p&gt;Also bear in mind, the Permanent Injunction and Monetary Judgment has not yet been signed by the Judge Hon. Richard D. Bennett.&lt;/p&gt;  &lt;p&gt;The Order is described as &amp;quot;&lt;em&gt;remedial in nature, and no portion of any payments paid herein shall be deemed or construed as payment of a fine, damages, penalty or punitive assessment&lt;/em&gt;&amp;quot;. &lt;/p&gt;  &lt;p&gt;Take a deep breath ladies and gentlemen, there is a lot of information here… “Defendants” refers to Reno and ByteHosting Internet Services.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;CONDUCT PROHIBITIONS&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;Reno and ByteHosting Internet Services, as well as their officers, agents, servants, employees and those persons in active concert or participation with them who receive actual notice of the order by personal service or otherwise, are PERMANENTLY RESTRAINED AND ENJOINED from: &lt;/p&gt;  &lt;p&gt;A. directly or indirectly misrepresenting, expressly or by implication, that: &lt;/p&gt;  &lt;p&gt;(1) a computer can or any other type of remote or local computer analysis has been performed; or    &lt;br /&gt;(2) security or privacy problems have been detected on a computer, &lt;/p&gt;  &lt;p&gt;B. publishing, disseminating, distributing, installing, downloading or providing customer support for any software that interferes with a consumer&amp;#39;s computer use, including but not limited to software that: &lt;/p&gt;  &lt;p&gt;(a) changes consumers&amp;#39; preferred Internet homepage settings;    &lt;br /&gt;(b) inserts a new advertising toolbar onto consumers&amp;#39; Internet browsers;     &lt;br /&gt;(c) generates numerous &amp;quot;pop up&amp;quot; advertisements on consumers&amp;#39; computer screens when consumers&amp;#39; Internet browsers are closed;     &lt;br /&gt;(d) adds advertising icons to the computer&amp;#39;s desktop;     &lt;br /&gt;(e) tampers with, disables, or otherwise alters the performance of other programs, including anti-spyware and anti-virus programs;     &lt;br /&gt;(f) alters Internet browser security settings, including the list of safe or trusted websites;     &lt;br /&gt;(g) installs other advertising Software on consumers&amp;#39; computers;     &lt;br /&gt;(h) conducts, or purports to conduct, a computer scan that purports to detect security or privacy threats that do not exist on the scanned computer; or     &lt;br /&gt;(i) creates security or privacy threats on a computer for the purpose of selling Software to eliminate those problems. &lt;/p&gt;  &lt;p&gt;C. concealing or attempting to conceal their identities by, among other things: &lt;/p&gt;  &lt;p&gt;(a) using any domain names that have been registered using false or incomplete information;    &lt;br /&gt;(b) claiming that they place advertisements on behalf of, or otherwise represent, individuals or entities, unless they possess written authorization to represent such individuals or entities. &lt;/p&gt;  &lt;p&gt;D. engaging in commercial activity of any kind - whether as a partner, employee, employer, officer, director, control person, independent contractor, consultant, service provider, or otherwise - with Innovative Marketing, Inc., Sam Jain, Daniel Sundin, Marc D&amp;#39;Souza, Maurice D&amp;#39;Souza, or Kristy Ross, or any entity controlled by Innovative Marketing, Inc., Sam Jain, Daniel Sundin, Marc D&amp;#39;Souza, Maurice D&amp;#39;Souza, or Kristy Ross. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;In connection with the marketing, distributing, or sale of, or the provision of customer support for, any goods or services, Defendants and their officers, agents, servants, employees and attorneys, and persons in active concert or participation with them who receive actual notice of the order by personal service or otherwise, are PERMANENTLY RESTRAINED AND ENJOINED from: &lt;/p&gt;  &lt;p&gt;(a) misrepresenting, directly or by implication, to any potential purchaser of any goods or services, any material fact, including but not limited to: &lt;/p&gt;  &lt;p&gt;(1) the total cost to purchase, receive, or use, or the quality of, any good or services that are subject to the sales offer;    &lt;br /&gt;(2) any material restrictions, limitations, or conditions to purchase, receive or use the goods or services; or     &lt;br /&gt;(3) any material aspect of the nature or terms of a refund, cancellation, exchange, or repurchase policy for the goods or services; or &lt;/p&gt;  &lt;p&gt;(b) providing substantial assistance to any third party to make any material misrepresentation including but not limited to those misrepresentations prohibited by paragraph (a) above. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;MONETARY JUDGMENT&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;(a) Judgment in the amount of &lt;strong&gt;$1,859,954.93&lt;/strong&gt; jointly and severally against the defendants.     &lt;br /&gt;(b) The monetary judgment be suspended upon defendants compliance with certain conditions, including that within 15 days after the date of entry of the Order, the defendants pay:&lt;/p&gt;  &lt;p&gt;(1) $17,827 from bank accounts listed in an attachment to the order to the IRS and State of Ohio;    &lt;br /&gt;(2) the remaining balance of all bank accounts listed in the attachment (approximately $98,870) to the Commission (with the defendants allowed to withdraw and retain just $7,500.00).&amp;#160; Monies paid to the FTC or its agent are to be used for &amp;quot;&lt;em&gt;equitable relief, including but not limited to consumer redress, and any attendant expenses for the administration of such equitable relief&lt;/em&gt;&amp;quot;. &lt;/p&gt;  &lt;p&gt;If the defendants have failed to disclose any material asset or materially misstated the value of any asset in certain financial statements or related documents, or have made any other material misstatement or omission in the financial statements or related documents, then the Order shall be reopened and suspension of the judgment shall be lifted for the purpose of requiring payment of the full judgment (less anything already paid).&amp;#160; If such a reinstatement occurs, the Court shall make an express determination that the monetary judgment shall be immediately due and payable (with interest). &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;COMPLIANCE MONITORING&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;So that the Commission can monitor and investigate compliance with any provision of this order and investigate the accuracy of any defendants&amp;#39; financial statements: &lt;/p&gt;  &lt;p&gt;(a) The defendants shall submit within 10 days of receipt of written notice from a representative of the Commission, additional written reports which are true and accurate and sworn to oath under penalty of perjury; produce documents for inspection and copying; appear for deposition; and provide entry during normal business hours to any business location in each Defendants&amp;#39; possession or direct or indirect control to inspect the business operation.&lt;/p&gt;  &lt;p&gt;The Commission is authorized to use all other lawful means, including but not limited to: &lt;/p&gt;  &lt;p&gt;(1) obtaining discovery from any person, without further leave of the court, using certain prescribed Federal procedures;    &lt;br /&gt;(2) posing as consumers and suppliers to the Defendants, their employees, or any other entity managed or controlled in whole or in part by any defendant, without the necessity of identification or prior notice; and &lt;/p&gt;  &lt;p&gt;(c) Defendants shall permit representatives of the Commission to interview any employer, consultant, independent contractor, representative, agent, or employee who has agreed to such an interview, relating in any way to any conduct subject to this order (the person interviewed may have counsel present). &lt;/p&gt;  &lt;p&gt;The Defendants must, for a period of 5 years from the date of entry of the order, notify the Commission of: &lt;/p&gt;  &lt;p&gt;(a) any changes in the defendant&amp;#39;s residence, mailing address and telephone number within 10 days of the date of such change;    &lt;br /&gt;(b) any changes in the defendant&amp;#39;s employment status (including self-employment) and any change in such defendant&amp;#39;s ownership in any business entity, within 10 days of such change.&amp;#160; Such notice will include the name and address of each business that such defendant is affiliated with, employed by, creates or forms, or performs services for; a detailed description of the nature of the business; and a detailed description of such defendant&amp;#39;s duties and responsibilities in connection with the business or employment; and     &lt;br /&gt;(c) any changes in the defendant&amp;#39;s name or use of any aliases or fictitious names.     &lt;br /&gt;(d) any changes in structure of the corporate defendant or any business entity that any defendant directly or indirectly controls, or has an ownership interest in, that may affect compliance obligations arising under the order.     &lt;br /&gt;(e) 180 days after the date of entry of the order, and annually thereafter for a period of 5 years, defendants shall each provide a written report to the FTC, which is true and accurate and sworn to under penalty of perjury, setting forth in detail the manner and form in which they are complied with the order.     &lt;br /&gt;(f) Each defendant shall notify the Commission of the filing of a bankruptcy petition by such defendant within 15 days of filing. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;RECORD KEEPING PROVISIONS&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;For a period of 8 years from the date of entry of the order, defendants, for any business that such defendant directly or indirectly controls, or in which such defendant has a majority ownership interest, and their agents, employees, officers, corporations and those persons in active concern or participation with them who receive actual notice of this Order by personal service or otherwise, are HEREBY RESTRAINED AND ENJOINED from failing to create and retain as set out in the order: &lt;/p&gt;  &lt;p&gt;(a) accounting records    &lt;br /&gt;(b) personnel records     &lt;br /&gt;(c) customer files     &lt;br /&gt;(d) complaints and refund requests     &lt;br /&gt;(e) records reflecting contact information and detailed payment history for all persons or entities engaged in the marketing, sale, distributing or installing of software at the direction of, or for the benefit of, the defendants     &lt;br /&gt;(f) copies of all scripts and training materials used in connection with the training of staff in customer support     &lt;br /&gt;(g) all records and documents necessary to demonstrate full compliance with each provision of the order &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;DISTRIBUTION OF ORDER&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;Every 5 years from the date of entry of the order, defendants shall deliver copies of the order to: &lt;/p&gt;  &lt;p&gt;(a) Corporate Defendant: all principals, officers, directors and managers; and all employees, agents and representatives who engage in conduct related to the subject matter of the order; and any business entity resulting from any change in structure set forth in the Order    &lt;br /&gt;(b) Individual defendant as control person: for any business that the individual defendant controls, directly or indirectly, or in which such defendant has a majority ownership interest - all principals, officers, directors and managers; and all employees, agents and representatives who engage in conduct related to the subject matter of the order; and any business entity resulting from any change in structure set forth in the Order.     &lt;br /&gt;(c) Individual defendant as employee or non-control person (aka Reno himself): for any business where the individual defendant is not a controlling person of a business but otherwise engages in conduct in connection with the selling, distributing, marketing or provision of customer support for computer security software, such defendant must deliver a copy of the order to all principals and managers of such business before engaging in the conduct.     &lt;br /&gt;(d) Defendants must secure a signed and dated statement acknowledging receipt of the Order from all persons receiving a copy of the order. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;COOPERATION WITH THE FTC&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;Defendants shall, in connection with this action or any subsequent investigations related to or associated with the transactions or the occurrences that are the subject of the FTC&amp;#39;s complaint, cooperate in good faith with the FTC and appear at such places and times as the FTC shall reasonably request, after written notice, for interviews, conferences, pretrial discovery, review of documents and for such other matters as may be reasonably requested by the FTC.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;One last thing…..&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;I noticed tonight that visitors to bytehosting.com (and several other Reno owned domains) are being redirected to google.com.&amp;#160; That is a trick that I have seen being used quite a few times to divert visitors away from malvertizing domains.&lt;/p&gt;  &lt;p&gt;&lt;img style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/7851.image_5F00_0E6C2236.png" width="909" height="648" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1695625" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=IaqVwwdHZj4:Niab6cM4lCg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=IaqVwwdHZj4:Niab6cM4lCg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=IaqVwwdHZj4:Niab6cM4lCg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/IaqVwwdHZj4" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/06/17/1695625.aspx</feedburner:origLink></item><item><title>The number one rule of technical support, which Symantec seems to have forgotten, is ***PAY ATTENTION***</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/7LJGlhWAzO4/1695601.aspx</link><pubDate>Tue, 16 Jun 2009 10:31:44 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1695601</guid><dc:creator>sandi</dc:creator><slash:comments>10</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1695601</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/06/16/1695601.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-right-width:0px;margin:10px 15px 15px 0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/7848.image_5F00_062D6E81.png" width="482" height="302" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;I sent a request for technical support to Symantec today – I thought, foolishly it seemed, that it was clear, succinct, and to the point.&amp;#160; My message was:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;&lt;em&gt;Unable to download hotfix &lt;/em&gt;&lt;/strong&gt;&lt;a target="_blank"&gt;ftp://ftp.symantec.com/public/english_us_canada/hotfix/defutil/KB20080828105226EN.exe&lt;/a&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&lt;strong&gt;&lt;em&gt; &lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;Error when attempting download:&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;220 spftp/1.0.0000 Server [68.177.231.161]          &lt;br /&gt;501 Syntax incorrect           &lt;br /&gt;421 Service not available, closing control connection&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;I have been trying to download the hotfix for 48 hours.&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;Norton error requiring hotfix: - &amp;quot;The virus definitions required by Norton Internet Security are not valid. You cannot run a scan until this problem is resolved.&amp;quot;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;The Norton systray icon is RED.&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Symantec technical support sent me the following response:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;&lt;em&gt;“I understand from your message that you have installed Norton Internet Security (NIS) 2009 and you are encountering an error message Error: &amp;quot;(3038,100)&amp;quot; when you run a Full System Scan with your Norton 2009 product. &lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;This issue may occur if the virus definitions are not up to date, In order to resolve this issue we need to update the virus definitions using Intelligent Updater and run Full System Scan. For step by step instructions, please click on&amp;#160; the link provided below: &lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;Title: &amp;#39;Error: &amp;quot;(3038,100)&amp;quot; when you run a Full System Scan with your Norton 2009 product&amp;#39;          &lt;br /&gt;Document ID: 20081007220233EN           &lt;br /&gt;Web URL:           &lt;br /&gt;&lt;/em&gt;&lt;/strong&gt;&lt;a href="http://www.symantec.com/norton/support/kb/web_view.jsp?wv_type=public_web&amp;amp;ssfromlink=true&amp;amp;sprt_cid=8eafb964-d4eb-407c-a3ff-d8b5b42a18c0&amp;amp;seg=hho&amp;amp;ct=us&amp;amp;lg=en&amp;amp;docurl=20081007220233EN&amp;rdquo;" target="_blank"&gt;http://www.symantec.com/norton/support/kb/web_view.jsp?wv_type=public_web&amp;amp;ssfromlink=true&amp;amp;sprt_cid=8eafb964-d4eb-407c-a3ff-d8b5b42a18c0&amp;amp;seg=hho&amp;amp;ct=us&amp;amp;lg=en&amp;amp;docurl=20081007220233EN”&lt;/a&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;The KB article I was referred to advises me to, and I quote…&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;&lt;em&gt;“Download the fix tool. &lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;Save the file to the Windows desktop. &lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;a target="_blank"&gt;ftp://ftp.symantec.com/public/english_us_canada/hotfix/defutil/KB20080828105226EN.exe&lt;/a&gt;&lt;/em&gt;&lt;/strong&gt;&lt;strong&gt;&lt;em&gt;”&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;strong&gt;For pity’s sake, which of the very first 4 words in my technical support request, being “Unable to download hotfix”, is so difficult to understand???&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;BTW, you will see that I did not actually tell Symantec that the error on the system in question was 3038,100 – that little gem of information was taken from a slew of system data that was added to the bottom of my request by support by the NIS support interface itself, unbeknownst to me (damned if I can understand why they need to know if I have an optical drive installed, or what the local time is where I am).&amp;#160; The error being reported the affected system was actually 3035,2 (but it seems that that error requires the same fix as 3038,100, so we’ll let them off for that one).&lt;/p&gt;  &lt;p&gt;To save myself the grief that comes from beating my head against the brick wall that is Symantec technical support I sourced the hotfix via alternate means, ran the hotfix, rebooted TWICE and ran a Live Update.&amp;#160; Guess what… it actually WORKED.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;UPDATE&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;I had replied to Symantec, before I was able to source the hotfix by other means, and asked that they send the hotfix direct to me via email.&amp;#160; I was less than polite, I am afraid.&amp;#160; This is what I wrote:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;&lt;em&gt;The VERY FIRST SENTENCE IN MY TECHNICAL SUPPORT REQUEST IS: &amp;quot; Unable to download hotfix &lt;/em&gt;&lt;/strong&gt;&lt;a target="_blank"&gt;ftp://ftp.symantec.com/public/english_us_canada/hotfix/defutil/KB20080828105226EN.exe&lt;/a&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&lt;strong&gt;&lt;em&gt;.&amp;#160; Let me repeat the error message in hopes that somebody will actually READ it this time. &lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;Error when attempting download:         &lt;br /&gt;220 spftp/1.0.0000 Server [68.177.231.161]          &lt;br /&gt;501 Syntax incorrect          &lt;br /&gt;421 Service not available, closing control connection &lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;With that in mind, WHY ON EARTH WOULD YOU SEND ME TO A TECHNICAL SUPPORT DOCUMENT that tells me to download a hotfix when I have already told you that it won&amp;#39;t download???&amp;#160; Please send the fixes to me by email.         &lt;br /&gt;Also, PLEASE NOTE that the Norton Support Window refers me to the 3038,100 fix tool, BUT the NORTON PROGRAM ITSELF reports that the problem is 3035,2.&amp;#160; &amp;lt;--- PLEASE READ THAT VERY CAREFULLY - NORTON 360 IS ALSO REPORTING THE ERROR 3035,2.&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;I have another email here.&amp;#160; This time Symantec Technical support wrote:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;em&gt;“I understand that you are getting an error message with error code &amp;quot;(3038,100)&amp;quot; when you run a Full System Scan with your Norton 2009 product and &lt;strong&gt;&lt;u&gt;you tried to download the fix tool and it failed with error code “220 spftp/1.0.0000 Server [68.177.231.161]”, “501 Syntax incorrect” and “421 Service not available, closing control connection&lt;/u&gt;&lt;/strong&gt;” (My emphasis)&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;I would like to inform you that this issue might occur might due to lack of latest virus definition updates or if the virus definitions are corrupted.&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;In order to resolve it, we need to update the virus definitions of Norton by running the fix tool and then restart the PC. After restarting the computer, a Help &amp;amp; Support window may open and you may still see the error. Please exit the Help &amp;amp; Support window, and then restart the computer again. It must resolve the issue.&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;For further assistance with the steps that need to be followed, please go through the following link.&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;Web URL:&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;&lt;a href="http://www.symantec.com/norton/support/kb/web_view.jsp?wv_type=public_web&amp;amp;ssfromlink=true&amp;amp;sprt_cid=8eafb964-d4eb-407c-a3ff-d8b5b42a18c0&amp;amp;seg=hho&amp;amp;ct=us&amp;amp;lg=en&amp;amp;docurl=20081007220233EN" target="_blank"&gt;http://www.symantec.com/norton/support/kb/web_view.jsp?wv_type=public_web&amp;amp;ssfromlink=true&amp;amp;sprt_cid=8eafb964-d4eb-407c-a3ff-d8b5b42a18c0&amp;amp;seg=hho&amp;amp;ct=us&amp;amp;lg=en&amp;amp;docurl=20081007220233EN&lt;/a&gt;&lt;/em&gt;&lt;em&gt;”&lt;/em&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;The technician then continued on, telling me that if the hotfix did not work I would need to download the Norton Removal Tool.&lt;/p&gt;  &lt;p&gt;Yeah, I didn’t believe it either.&amp;#160; I was referred back to exactly the same URL even after they acknowledged that I was not able to download hotfixes.&amp;#160; My response began with:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;&lt;em&gt;“Forget it.&amp;#160; Please close this Technical Support Incident as &amp;quot;customer gave up&amp;quot;.”&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1695601" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=7LJGlhWAzO4:ktqZLTucBpU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=7LJGlhWAzO4:ktqZLTucBpU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=7LJGlhWAzO4:ktqZLTucBpU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/7LJGlhWAzO4" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/06/16/1695601.aspx</feedburner:origLink></item><item><title>FTC versus Innovative Marketing et al – developments</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/vuBJOgD_1qA/1694940.aspx</link><pubDate>Thu, 11 Jun 2009 01:40:17 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1694940</guid><dc:creator>sandi</dc:creator><slash:comments>1</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1694940</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/06/11/1694940.aspx#comments</comments><description>&lt;p&gt;So sayeth the Court.... &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“&lt;em&gt;This Court conducted a hearing yesterday on almost all outstanding motions in this case and rendered the following rulings for the reasons stated on the record: &lt;/em&gt;&lt;/p&gt;    &lt;ul&gt;     &lt;li&gt;&lt;em&gt;Sam Jain&amp;#39;s Motion to Stay (Paper No. 45) is DENIED;&lt;/em&gt;&lt;/li&gt;      &lt;li&gt;&lt;em&gt;Kristy Ross&amp;#39;s Motion to Temporary Stay (Paper No. 48) is DENIED;&lt;/em&gt;&lt;/li&gt;      &lt;li&gt;&lt;em&gt;FTC&amp;#39;s Motion for Order Holding Sam Jain and Kristy Ross in Contempt of Court and Requiring the Repatriation of their Assets (Paper No. 49) is DENIED;&lt;/em&gt;&lt;/li&gt;      &lt;li&gt;&lt;em&gt;Kristy Ross&amp;#39;s Motion to Strike or in the Alternative Motion for an Extension of Time (Paper No. 51) is MOOT;&lt;/em&gt;&lt;/li&gt;      &lt;li&gt;&lt;em&gt;Sam Jain&amp;#39;s Motion to Strike or in the Alternative Motion for an Extension of Time (Paper No. 52) is MOOT;&lt;/em&gt;&lt;/li&gt;      &lt;li&gt;&lt;em&gt;Sam Jain&amp;#39;s Motion to Modify Preliminary Injunction (Paper No. 58) is DENIED IN PART, with the Court withholding a ruling on the requested modification of the asset freeze;&lt;/em&gt;&lt;/li&gt;      &lt;li&gt;&lt;em&gt;Sam Jain&amp;#39;s Motion to Dismiss under Rule 12(b)(7) and 19 (Paper No. 60) is DENIED;&lt;/em&gt;&lt;/li&gt;      &lt;li&gt;&lt;em&gt;Kristy Ross&amp;#39;s Motion to Dismiss under Rule 12(b)(7) and 19 (Paper No. 61) is DENIED;&lt;/em&gt;&lt;/li&gt;      &lt;li&gt;&lt;em&gt;Marc D&amp;#39;Souza&amp;#39;s Motion to Dismiss under Rule 12(b)(7) and 19 (Paper No. 70) is DENIED; and&lt;/em&gt;&lt;/li&gt;      &lt;li&gt;&lt;em&gt;Marc D&amp;#39;Souza&amp;#39;s Motion for Temporary Stay and Modification of Preliminary Injunction (Paper No. 71) is DENIED IN PART, with the Court withholding a ruling on the requested modification of the asset freeze. &lt;/em&gt;&lt;/li&gt;   &lt;/ul&gt;    &lt;p&gt;&lt;em&gt;Sam Jain&amp;#39;s Motion to Modify Preliminary Injunction (Paper No. 58), Marc D&amp;#39;Souza&amp;#39;s Motion for Temporary Stay and Modification of Preliminary Injunction (Paper No. 71) and Kristy Ross&amp;#39;s oral motion to modify the preliminary injunction all require further briefing and argument on the issue of whether the asset freeze in Section IV of the Preliminary Injunction should be modified.&amp;#160; Moreover, this Court withheld ruling on Maurice D&amp;#39;Souza&amp;#39;s Motion to Dismiss for Lack of Jurisdiction under Rule 12(b)(2) (Paper No. 90) so that limited jurisdictional discovery can occur and further briefing and argument. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;On these outstanding issues, a hearing will be held on Wednesday, July 8, 2009 at 10:00 a.m.&amp;#160; Counsel for Sam Jain, Marc D&amp;#39;Souza, Kristy Ross and the FTC will each be permitted to smit an additional brief on whether the asset freeze should be modified by Tuesday, June 23, 2009.&amp;#160; Counsel for Maurice D&amp;#39;Souza and the FTC will also each be permitted to submit an additional brief on whether this Court has personal jurisdiction over Maurice D&amp;#39;Souza by the same date.&amp;#160; The briefs should be limited to ten (10) pages, excluding attachments and exhibits.&lt;/em&gt;”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;The Court will issue a scheduling order at the hearing on July 8, 2009.&lt;/p&gt;  &lt;p&gt;As a brief recap, the arguments put forward by Sam Jain, Kristy Ross and Marc D’Souza in their Motions to Dismiss the FTC complaint under Rule 12(b)(7) and 19 (which were dismissed) were:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;that the FTC had failed to join Innovative Marketing, a &amp;quot;necessary and indispensible party&amp;quot;, claiming that the FTC had never served IMI (the FTC served IMI *twice*). &lt;/li&gt;    &lt;li&gt;that Jack Palladino did not represent IMI and was not authorised to accept service, claiming that Palladino had not made the statements attributed to him&lt;/li&gt;    &lt;li&gt;that the service of IMI in Belize was invalid under the local laws. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Previous relevant commentary: &lt;/p&gt;  &lt;p&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2008/12/17/1656984.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2008/12/17/1656984.aspx&lt;/a&gt;    &lt;br /&gt;&lt;a title="http://msmvps.com/blogs/spywaresucks/archive/2009/02/10/1671117.aspx" href="http://msmvps.com/blogs/spywaresucks/archive/2009/02/10/1671117.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/02/10/1671117.aspx&lt;/a&gt;&amp;#160; &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/03/09/1676922.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/03/09/1676922.aspx&lt;/a&gt;    &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/02/27/1674119.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/02/27/1674119.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;I didn&amp;#39;t blog about the defendants’ claim that the service on IMI in Belize was invalid.&amp;#160; The gist of the argument was that the defendants were claiming IMI had not been properly served by the FTC when the FTC personally served IMI&amp;#39;s registered agent in that country because the defendants had found a single State Department web page that advised that &amp;quot;&lt;em&gt;Belize and the United States are parties to an agreement that requires all service of process in Belize to be sent exclusively to Belize&amp;#39;s central authority&lt;/em&gt;&amp;quot;.&amp;#160; Unfortunately for the defendants, it turned out that the web page on which the defendants were relying was &amp;quot;defunct&amp;quot;.&amp;#160; A link to the cited web page on the United States Department of State&amp;#39;s Bureau of Consular Affairs&amp;#39; main judicial assistance portal had been deactivated some years earlier due to inaccuracies that had developed over time, although some links to the web page remained on the CA web which were accessible to the public.&amp;#160; The cited web page itself was disabled on March 6, 2009 after it was discovered that it was still being linked to.&amp;#160; The FTC pointed out in its response to the defendants’ claim that if the defendants had checked with the State Department they would have been told that the information was wrong.&lt;/p&gt;  &lt;p&gt;Sam Jain’s Motion to Stay (Paper No. 45) (which was denied) was his request that the FTC proceedings be stayed “&lt;em&gt;until the ongoing parallel federal criminal case against him is resolved”&lt;/em&gt; because “&lt;em&gt;to defend both cases simultaneously will effectively prevent him from defending either adequately and will force him to choose between sacrificing his Fifth Amendment privilege against self incrimination or his right to defend the civil claims&lt;/em&gt;”.&amp;#160; Kristy Ross’s Motion to Temporary Stay (Paper No. 48) basically made the same arguments.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;James Reno and Bytehosting Internet Services&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Back on 18 March 2009 I reported that the FTC, James Reno and Bytehosting Internet Services had requested the Court stay further proceedings as to James Reno and Bytehosting for a period of 90 days. &lt;/p&gt;  &lt;p&gt;The stay was requested so that the Commission&amp;#39;s attorneys could seek approval of a &amp;quot;&lt;em&gt;Stipulated Final Order for Permanent Injunction and Monetary Judgment As To Defendants James M. Reno and Bytehosting Internet Services, LLC&lt;/em&gt;&amp;quot;.&amp;#160; Reno and Bytehosting executed a proposed stipulated final order on 11 March 2009, but this proposed stipulated final order must firstly be approved by the Director of the Bureau of Consumer Protection and then considered, voted on and approved by the full Commission; a procedure that can take up to 90 days. &lt;/p&gt;  &lt;p&gt;The stay was granted on 18 March 2009, therefore I expect that the proposed stipulated final order will be lodged with the court any day now (assuming it is approved by the Director of the Bureau of Consumer Protection and then the full Commission).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1694940" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=vuBJOgD_1qA:ZdlKVvag0r4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=vuBJOgD_1qA:ZdlKVvag0r4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=vuBJOgD_1qA:ZdlKVvag0r4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/vuBJOgD_1qA" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/06/11/1694940.aspx</feedburner:origLink></item><item><title>FTC versus Innovative Marketing… developments</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/XFWLEkuizZg/1694898.aspx</link><pubDate>Wed, 10 Jun 2009 13:22:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1694898</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1694898</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/06/10/1694898.aspx#comments</comments><description>&lt;p&gt;Today was a big day…&lt;/p&gt;  &lt;p&gt;“Motion Hearing held on Tuesday 9 June, 2009 re:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;(51) MOTION to Strike (49) MOTION for Other Relief &lt;i&gt;Order Holding Sam Jain and Kristy Ross In Contempt Of Court And Requiring The Repatriation Of Their Assets&lt;/i&gt; &lt;i&gt;OR IN THE ALTERNATIVE&lt;/i&gt; MOTION to Strike (49) MOTION for Other Relief &lt;i&gt;Order Holding Sam Jain and Kristy Ross In Contempt Of Court And Requiring The Repatriation Of Their Assets&lt;/i&gt; &lt;i&gt;OR IN THE ALTERNATIVE&lt;/i&gt; MOTION for Extension of Time filed by Kristy Ross,&lt;/li&gt;    &lt;li&gt;(45) MOTION to Stay filed by Sam Jain, &lt;/li&gt;    &lt;li&gt;(106) MOTION to Dismiss &lt;i&gt;the Complaint Pursuant to Rule 12(b)(6)&lt;/i&gt; filed by Marc D&amp;#39;Souza, &lt;/li&gt;    &lt;li&gt;(90) MOTION to Dismiss for Lack of Jurisdiction filed by Maurice D&amp;#39;Souza, &lt;/li&gt;    &lt;li&gt;(60) MOTION to Dismiss &lt;i&gt;Complaint&lt;/i&gt; filed by Sam Jain, &lt;/li&gt;    &lt;li&gt;(52) MOTION to Strike (49) MOTION for Other Relief &lt;i&gt;Order Holding Sam Jain and Kristy Ross In Contempt Of Court And Requiring The Repatriation Of Their Assets&lt;/i&gt; &lt;i&gt;or, in the Alternative, for Extension of Time to Respond&lt;/i&gt; MOTION to Strike (49) MOTION for Other Relief &lt;i&gt;Order Holding Sam Jain and Kristy Ross In Contempt Of Court And Requiring The Repatriation Of Their Assets&lt;/i&gt; &lt;i&gt;or, in the Alternative, for Extension of Time to Respond&lt;/i&gt; filed by Sam Jain, &lt;/li&gt;    &lt;li&gt;(61) MOTION to Dismiss &lt;i&gt;COMPLAINT&lt;/i&gt; filed by Kristy Ross, &lt;/li&gt;    &lt;li&gt;(48) MOTION to Stay &lt;i&gt;(Temporary)&lt;/i&gt; filed by Kristy Ross, &lt;/li&gt;    &lt;li&gt;(71) MOTION to Stay &lt;i&gt;Temporary&lt;/i&gt; filed by Marc D&amp;#39;Souza, &lt;/li&gt;    &lt;li&gt;(70) MOTION to Dismiss &lt;i&gt;Complaint&lt;/i&gt; filed by Marc D&amp;#39;Souza &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;The hearing was held before Judge Richard D Bennett and &lt;strong&gt;not concluded.&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;By the way, Innovative Marketing is still unrepresented and, as far as I know, have not paid a cent of the $8,000 per day fine levied by the Court (I may be wrong, I hope I’m wrong, but suspect that I am not).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1694898" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=XFWLEkuizZg:1X5B7-rasWQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=XFWLEkuizZg:1X5B7-rasWQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=XFWLEkuizZg:1X5B7-rasWQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/XFWLEkuizZg" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/06/10/1694898.aspx</feedburner:origLink></item><item><title>3 malvertizements</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/3AJA1IoWJpg/1692845.aspx</link><pubDate>Thu, 21 May 2009 04:43:20 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1692845</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1692845</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/05/21/1692845.aspx#comments</comments><description>&lt;p&gt;All created using, we think, Fuse – all use the encrypted-code-as-dynamic-text trick.&lt;/p&gt;  &lt;p&gt;Malvertizement 1 (reported by &lt;a href="http://securityblahblah.blogspot.com/" target="_blank"&gt;Greg Feezel&lt;/a&gt;) and seen on &lt;a href="http://malwaredatabase.net/blog/index.php/2009/05/20/fox-serving-up-malvertisement-leading-to-scareware-products/" target="_blank"&gt;Fox Audience Network&lt;/a&gt;:&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_22E787EC.png" width="786" height="146" /&gt;&amp;#160; &lt;/p&gt;  &lt;p&gt;Hits &lt;strong&gt;bigstat.net&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: REGTIME LTD    &lt;br /&gt;Created 18 February 2009    &lt;br /&gt;NS1.NAMESELF.COM    &lt;br /&gt;NS2.NAMESELF.COM &lt;/p&gt;  &lt;p&gt;IP: 212.95.32.166 - Berlin, Netdirekt &lt;/p&gt;  &lt;p&gt;Shares IP with greatstat.com &lt;/p&gt;  &lt;p&gt;Registrant - bigstat.net and greatstat.com   &lt;br /&gt;Anemari Rotko (ranemari@yahoo.com)    &lt;br /&gt;Tulskaya, 247/14    &lt;br /&gt;Moscow, 109029, Russia    &lt;br /&gt;+7 495 364 9627 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;Malvertizement 2: &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_2BFBC580.png" width="755" height="116" /&gt;&amp;#160; &lt;/p&gt;  &lt;p&gt;Hits &lt;strong&gt;clickmatter.net&lt;/strong&gt;, a domain already featured on this blog several times. &lt;/p&gt;  &lt;p&gt;ICANN Registrar: REGTIME LTD   &lt;br /&gt;Created 11 July 2008    &lt;br /&gt;NS08.DOMAINCONTROL.COM    &lt;br /&gt;NS09.DOMAINCONTROL.COM &lt;/p&gt;  &lt;p&gt;IP: Currently no web site.&amp;#160; Last held IP was 216.195.59.78 &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Mark Haagland (markhaagland@gmail.com)    &lt;br /&gt;Ehijajate tee 150    &lt;br /&gt;Tallin, Harjumaa, 13522, EE    &lt;br /&gt;+37 262 01114 &lt;/p&gt;  &lt;p&gt;The email address has been seen in association with domains previously registered to jackyouthere@gmail.com and other malvertizing incidents: &lt;/p&gt;  &lt;p&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/01/15/1661878.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/01/15/1661878.aspx&lt;/a&gt;    &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/02/18/1672789.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/02/18/1672789.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;Malvertizement 3: &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_7CCEFB4A.png" width="646" height="181" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_43DCC99D.png" width="653" height="181" /&gt;&amp;#160; &lt;/p&gt;  &lt;p&gt;Hits &lt;strong&gt;adoptserver.info&lt;/strong&gt;, another domain featured on this blog several times. &lt;/p&gt;  &lt;p&gt;ICANN Registrar: REGTIME LTD   &lt;br /&gt;Created 24 Jun 2007    &lt;br /&gt;NS.ADOPTSERVER.INFO    &lt;br /&gt;NS2.ADOPTSERVER.INFO &lt;/p&gt;  &lt;p&gt;IP: Offline and currently not resolving. Last held IP was 64.28.187.77 &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Javier Vega (softjoda@yahoo.com)    &lt;br /&gt;Tegelbacken 7, Box 193    &lt;br /&gt;Stockholm, 10123    &lt;br /&gt;+46 841 23433 &lt;/p&gt;  &lt;p&gt;softjoda@yahoo.com is associated with 12 domains, including servedad.net which has been implicated in malvertizing incidents in the past: &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2008/12/13/1656668.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2008/12/13/1656668.aspx&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1692845" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=3AJA1IoWJpg:iQVB25Yc9aM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=3AJA1IoWJpg:iQVB25Yc9aM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=3AJA1IoWJpg:iQVB25Yc9aM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/3AJA1IoWJpg" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/05/21/1692845.aspx</feedburner:origLink></item><item><title>ALERT: Please treat advertising from Gilmours Media (gilmoursmedia.com) with extreme caution</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/YBy8Gr6jPig/1692842.aspx</link><pubDate>Wed, 20 May 2009 13:04:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1692842</guid><dc:creator>sandi</dc:creator><slash:comments>1</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1692842</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/05/20/1692842.aspx#comments</comments><description>&lt;p&gt;&lt;img height="490" width="576" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_7EC50FAB.png" align="left" alt="image" border="0" title="image" style="border-right-width:0px;margin:10px 20px 20px 0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" /&gt; &lt;br /&gt;They have been caught distributing malvertizing. &lt;/p&gt;
&lt;p&gt;Current registration details are: &lt;/p&gt;
&lt;p&gt;ICANN Registrar: REGTIME LTD &lt;br /&gt;Created 24 March 2008 &lt;br /&gt;NS1.NAMESELF.COM &lt;br /&gt;NS2.NAMESELF.COM &lt;/p&gt;
&lt;p&gt;IP: 64.28.187.33 - New York, Internet Path Inc &lt;/p&gt;
&lt;p&gt;Registrant: &lt;/p&gt;
&lt;p&gt;Jacob Tua (saidfahtih@gmail.com) &lt;br /&gt;Maltiskam 12-67 &lt;br /&gt;Belgrade 11008 &lt;br /&gt;Russia &lt;br /&gt;+381 113 114 094&lt;/p&gt;
&lt;p&gt;It should be noted that gilmoursmedia.com was originally registered via the infamous ESTDOMAINS, to a &amp;quot;&lt;strong&gt;Jacob Tua&lt;/strong&gt;&amp;quot; of &lt;strong&gt;Maltiskam 12-67, Belgrade, 11008, telephone +381.113114094&lt;/strong&gt;. &lt;/p&gt;
&lt;p&gt;More importantly, the email address for &amp;quot;Jacob Tua&amp;quot; was &amp;quot;&lt;strong&gt;jackyouthere@gmail.com&lt;/strong&gt;&amp;quot;.&amp;nbsp; See this Apple discussion forum conversation about a the clipboard hijacking problem &amp;ndash; the same clipboard hijacking problem that led to Adobe changing the way Flash behaves: &lt;br /&gt;&lt;a target="_blank" href="http://discussions.apple.com/thread.jspa?messageID=7768848"&gt;http://discussions.apple.com/thread.jspa?messageID=7768848&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The domain being copied to clipboard via the Flash exploit was &amp;quot;&lt;strong&gt;windowsxp-privacy.net&lt;/strong&gt;&amp;quot;, which just so happened to be registered to, you guessed it, &lt;strong&gt;jackyouthere@gmail.com&lt;/strong&gt;!! This information was posted to the discussion thread on 20 August 2008. &lt;/p&gt;
&lt;p&gt;&amp;quot;Jacob Tua&amp;quot; was also listed as owning &lt;strong&gt;adclickmate.net&lt;/strong&gt;, another domain associated with malvertizing: &lt;br /&gt;&lt;a target="_blank" href="http://msmvps.com/blogs/spywaresucks/archive/2009/02/18/1672789.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/02/18/1672789.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The contact phone number for Gilmours Media is/was the same as that for &amp;quot;Trackstar Media&amp;quot;, being tel 401.237.4731.&lt;/p&gt;
&lt;p&gt;But the address is different, being 17 Vernon Street, Warren: &lt;br /&gt;&lt;a target="_blank" href="http://www.merchantcircle.com/business/Trackstarmedia.401-237-4731"&gt;http://www.merchantcircle.com/business/Trackstarmedia.401-237-4731&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;img height="146" width="315" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image5_5F00_64AAE66E.png" align="left" alt="image" border="0" title="image" style="border-bottom:0px;border-left:0px;margin:10px 20px 20px 0px;display:inline;border-top:0px;border-right:0px;" /&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;trackstarmedia.com was suspended due to inaccurate WHOIS information.&amp;nbsp; That domain has also been featured on this blog before: &lt;br /&gt;&lt;a target="_blank" href="http://msmvps.com/blogs/spywaresucks/archive/2008/08/13/1644602.aspx" title="http://msmvps.com/blogs/spywaresucks/archive/2008/08/13/1644602.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2008/08/13/1644602.aspx&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;img height="122" width="569" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_2EFCCBF8.png" alt="image" border="0" title="image" style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" /&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;img height="357" width="424" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_791A678E.png" alt="image" border="0" title="image" style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" /&gt;&amp;nbsp; &lt;img height="353" width="420" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_1B99390E.png" alt="image" border="0" title="image" style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" /&gt; &lt;/p&gt;
&lt;p&gt;&lt;img height="360" width="418" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_6B96999F.png" alt="image" border="0" title="image" style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1692842" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=YBy8Gr6jPig:aJQbesU3JgY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=YBy8Gr6jPig:aJQbesU3JgY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=YBy8Gr6jPig:aJQbesU3JgY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/YBy8Gr6jPig" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/05/20/1692842.aspx</feedburner:origLink></item><item><title>ALERT: More malvertizements featuring classmates.com are being displayed at mediatakeout.com</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/mvs59XDr4hc/1691872.aspx</link><pubDate>Tue, 05 May 2009 06:16:29 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1691872</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1691872</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/05/05/1691872.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_64A6ADF1.png" width="861" height="131" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 20px 20px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_52829284.png" width="306" height="258" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;The malvertizements are at a web site called mediatakeout.com.&amp;#160; There are two of them:&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;mediatakeout.com/adserver/classmates300x250.swf&lt;/strong&gt;    &lt;br /&gt;Adopstools results - &lt;a title="http://www.adopstools.com/index.asp?section=quicklink&amp;amp;id=qjQ0XEgKuMwGOH2m" href="http://www.adopstools.com/index.asp?section=quicklink&amp;amp;id=qjQ0XEgKuMwGOH2m" target="_blank"&gt;http://www.adopstools.com/index.asp?section=quicklink&amp;amp;id=qjQ0XEgKuMwGOH2m&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;mediatakeout.com/adserver/classmates728x90.swf&lt;/strong&gt;    &lt;br /&gt;Adopstools results - &lt;a title="http://www.adopstools.com/index.asp?section=quicklink&amp;amp;id=5xX9tYDn83p75I5q" href="http://www.adopstools.com/index.asp?section=quicklink&amp;amp;id=5xX9tYDn83p75I5q" target="_blank"&gt;http://www.adopstools.com/index.asp?section=quicklink&amp;amp;id=5xX9tYDn83p75I5q&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;It looks like they have been in circulation for less than a day.&lt;/p&gt;  &lt;p&gt;The malvertizements have been reported to the web site owners.&lt;/p&gt;  &lt;p&gt;These malvertizements are interesting, because they hit an additional domain, being &lt;strong&gt;bannerfarm.ace.advertising.com&lt;/strong&gt;, which is an AOL asset.&amp;#160; AOL have been notified as well.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1691872" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=mvs59XDr4hc:7sttVMfyhhs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=mvs59XDr4hc:7sttVMfyhhs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=mvs59XDr4hc:7sttVMfyhhs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/mvs59XDr4hc" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/05/05/1691872.aspx</feedburner:origLink></item><item><title>ALERT: malvertizing impersonating well known classmates.com advertisements.</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/8jXo2sXkKQk/1691824.aspx</link><pubDate>Mon, 04 May 2009 14:17:49 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1691824</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1691824</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/05/04/1691824.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_0ACEFFDC.png" width="861" height="131" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 20px 20px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_3F94076C.png" width="306" height="258" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Reported by Kimberley:   &lt;br /&gt;&lt;a href="http://www.bluetack.co.uk/forums/index.php?s=&amp;amp;showtopic=18064&amp;amp;view=findpost&amp;amp;p=91839" target="_blank"&gt;www.bluetack.co.uk/forums/index.php?s=&amp;amp;showtopic=18064&amp;amp;view=findpost&amp;amp;p=91839&lt;/a&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;The malvertizements are very familiar, yes?&lt;/p&gt;  &lt;p&gt;Now, &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/04/23/1690197.aspx" target="_blank"&gt;we already know that a known bad actor, yourdirectmedia, has supplied &amp;quot;Classmatesmedia, Rick Harris, 619 949 8952&amp;quot; as a referee&lt;/a&gt;.&amp;#160; We also suspect (I have not had this independently confirmed) that classmatesmedia does not directly sells advertising - rather, I believe that United Online Advertising Solutions is responsible for that chore (uolmediagroup.com).&lt;/p&gt;  &lt;p&gt;How much do you want to bet that somebody impersonating classmates.com, or falsely claiming to represent them, is responsible for these malvertizements.&lt;/p&gt;  &lt;p&gt;On display at ifood.tv, bhg.com, fitnessmagazine.com.&amp;#160; Hosted by Doubleclick :(&lt;/p&gt;  &lt;p&gt;m1.2mdn.net/2282252/classmates300x250.swf   &lt;br /&gt;m1.2mdn.net/2282252/classmates728x90.swf&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1691824" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=8jXo2sXkKQk:dCXiuTrupsE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=8jXo2sXkKQk:dCXiuTrupsE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=8jXo2sXkKQk:dCXiuTrupsE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/8jXo2sXkKQk" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/05/04/1691824.aspx</feedburner:origLink></item><item><title>ALERT: Malvertizement featuring Crawler</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/bihyxLEwDxg/1691621.aspx</link><pubDate>Thu, 30 Apr 2009 14:08:55 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1691621</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1691621</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/04/30/1691621.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 20px 20px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_12757A7D.png" width="330" height="279" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Same old same old.&amp;#160; The malvertizement hits the domains &lt;strong&gt;statcluster.com&lt;/strong&gt; and &lt;strong&gt;enjoyspringtime.com&lt;/strong&gt; (both domains have been mentioned on this blog several times). &lt;/p&gt;  &lt;p&gt;The Adopstools results make it obvious that there is something suspicious:   &lt;br /&gt;&lt;a href="http://www.adopstools.net/index.asp?section=quicklink&amp;amp;id=R59g0m36S016WwBW" target="_blank"&gt;http://www.adopstools.net/index.asp?section=quicklink&amp;amp;id=R59g0m36S016WwBW&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;From &lt;strong&gt;statcluster.com&lt;/strong&gt; and &lt;strong&gt;enjoyspringtime.com&lt;/strong&gt; we end up at crustat.com then on to either &lt;strong&gt;free-webscaners&lt;/strong&gt;.com or &lt;strong&gt;truconv.com&lt;/strong&gt; or &lt;strong&gt;olinredr2.com&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;From &lt;strong&gt;olinredr2.com&lt;/strong&gt; to &lt;strong&gt;pyani.com&lt;/strong&gt; to &lt;strong&gt;offer-provider.com&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;From &lt;strong&gt;trueconv.com&lt;/strong&gt; to &lt;strong&gt;total-virusprotection.com&lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1691621" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=bihyxLEwDxg:c79DbBZT7aA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=bihyxLEwDxg:c79DbBZT7aA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=bihyxLEwDxg:c79DbBZT7aA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/bihyxLEwDxg" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/04/30/1691621.aspx</feedburner:origLink></item><item><title>A frightening tale of computer infection and its consequences</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/i7XHkoSPJig/1691530.aspx</link><pubDate>Wed, 29 Apr 2009 13:22:44 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1691530</guid><dc:creator>sandi</dc:creator><slash:comments>6</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1691530</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/04/29/1691530.aspx#comments</comments><description>&lt;p&gt;“&lt;em&gt;It all started when I wanted to get more performance out of my video card. I download the latest drivers and included this virus.&lt;/em&gt;”&lt;/p&gt;  &lt;p&gt;Yep, that one simple act turned into an infection nightmare lasting three weeks.&amp;#160; I’m hoping Micky will work out exactly where he got the drivers from, and let us know (as well as warning whoever it is that is distributing the infected drivers.&lt;/p&gt;  &lt;p&gt;The entire sorry tale is at &lt;strong&gt;www mickyj com / blog htm&lt;/strong&gt; (link deliberately broken because I&amp;#39;m not sure that I want anybody going there yet). &lt;/p&gt;  &lt;p&gt;To save you from the need to visit, I&amp;#39;ll copy Micky&amp;#39;s tale of woe verbatim.&amp;#160; Micky’s message to everybody is &lt;em&gt;“Make sure to point out that no matter how cluey you are with IT (I have 20 years experience) these things are getting nasty.”&lt;/em&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;em&gt;&lt;strong&gt;Reproduced with permission.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;“Where have I been for almost 3 weeks? - 26 April 2009 - mickeyj.com &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;&lt;strong&gt;Virux/Virut&lt;/strong&gt;         &lt;br /&gt;Keywords: PE_VIRUX.E-2, PE_VIRUX.C-2, Win32/Virut, Cryp_Virux, W32.Virut, PE_VIRUX.G-1, PE_VIRUX.F &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;... Offline. I am lucky enough to be one of the two people in Australia/New Zealand to have been infected with a rare strain of the Virux/Virut virus on my home PC. This is according to Trend Micro&amp;#39;s Statistics. If you get this virus, be very afraid. It infected every EXE, SCR, DLL, HTM, HTML, ASPX file (And more). It copied itself to every USB device including my Camera flash cards and USB keys. It infected my Outlook email signatures (So I need to contact people I have emailed), Outlook stationary and more. I started seeing a pattern where infected executable files were about 20 kb larger than the originals and my internet would slow down (Due to incoming IRC connections). It was almost impossible to beat. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;If I am like you, I have a whole heap of downloads on my PC that contains all my setup files. That included service packs, video drivers, scanner and printer drivers. All were infected. As I tried to reinstall my hardware I got reinfected. If I plugged in a memory card, I got reinfected. I even found the virus on my media centre and Xbox shared folders. It got everywhere. (Even played with my firmware on my router). &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;It all started when I wanted to get more performance out of my video card. I download the latest drivers and included this virus. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;I reinstalled Windows XP Pro and all my additions at least 20 times between 26/3/09 - 16/4/09 before I finally got online again. I know this as I can no longer activate my Microsoft software. I have exceeded the install number allowed for a retail version of the product. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;I got to the point of throwing out USB keys and starting to install everything fresh, from fresh downloads. Finally, I have myself back up and running (Minus all my data). Both AVG and Trend Micro could not protect me from reinfection. The virus is encrypted. It hides in space within exe files and nothing can detect is due to the encryption. Trend Micro etc can only detect it once the &amp;quot;exe&amp;quot; has started modifying other files. It happens so fast and Trend Micro and others can&amp;#39;t clean it. I think I had 50 infections per second once the virus broke free. The virus targets all files in C:\Windows and C:\Windows\System32 first so basically, Windows becomes one big virus. It becomes especially hard to handle when AVG and Trend Micro start quarantining the virus, removing essential Windows files out of your system so ... Your system can&amp;#39;t reboot. I also had the virus in system restore so the OS was completely tainted. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;I got to the point where as soon as Trend or AVG triggered, I pressed the workstations reset button, shoved in my XP disk and started reformatting. I think my earlier mistake was trying to clean the virus. The more I tried, the more I got infected. I tried the Symantec removal tools and many others. They all did not deal with this particular strain of the virus. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;If you see this virus, run away. Be very, very afraid. Format your PC. Get your files back from backups. Don&amp;#39;t trust any files off your old system as the virus is encrypted and could be in any file. Certainly antivirus can detect this virus when it starts running, but by then, it is too late. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;The virus detected was:        &lt;br /&gt;PE_VIRUX.E-2         &lt;br /&gt;PE_VIRUX.C-2         &lt;br /&gt;Win32/Virut         &lt;br /&gt;Cryp_Virux         &lt;br /&gt;W32.Virut         &lt;br /&gt;PE_VIRUX.G-1         &lt;br /&gt;PE_VIRUX.F &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;The virus downloaded and installed the following strains:        &lt;br /&gt;Virus.Virut.r         &lt;br /&gt;W32.Virut.CF         &lt;br /&gt;W32/Virut.n         &lt;br /&gt;PE_VIRUT.BO.         &lt;br /&gt;TROJ_VIRUX.A. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;It also downloaded:        &lt;br /&gt;TROJ_AGENT.CHB         &lt;br /&gt;TROJ_MAILBOT.CN         &lt;br /&gt;TROJ_SMALL.NAX         &lt;br /&gt;TROJ_AGENT.ZNH &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;&lt;strong&gt;Google blocked my website&lt;/strong&gt;         &lt;br /&gt;Keywords: Google, Website, Harm, iFrame &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;.. And rightly so. I have been hacked. It has been a shocking month for me thus far. My home PC covered in Viruses for the first half of the month, 1 week to breath and then my website hacked in the second half of the month. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;When you Google mickyj.com you get a result that lists &amp;quot;This site may harm your computer&amp;quot; under my website. When you click the link for my website, you get a google page warning viewers not to go to my website. Obviously I wanted to find out more so I downloaded the code for my website and found 4 iFrame infections had been injected into the code. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;I contacted Google Support through their help system, after fixing my website. It took a little bit to explain to them what I found, how I had cleaned it all and how the infection had likely occurred, then they &amp;quot;verified&amp;quot; and &amp;quot;reviewed&amp;quot; my website and it is up again in all it&amp;#39;s glory. Thanks Google Guys. You were awesome. I was unable to request verification of my website through the web interface as my Domain name holder has some restrictions in place that I could not get around. The Google guys understood this and did an awesome job helping me through their help system. I can&amp;#39;t stress enough how fantastic these guys were. Especially Johnathon at Google. you guys rock. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;Website up and running, safe again on the 25th April. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;&lt;strong&gt;New Wrinkle&lt;/strong&gt;         &lt;br /&gt;Keywords: Twitter, Suspended &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;Twitter have blocked me for suspicious activity. 26th April Twitter suspended my account. What ?? I hope that this is related to the virus I had earlier and can be easily explained and then unblocked. This has not been a good month. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;Maybe things will be better tomorrow as it is my Birthday !”&lt;/em&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;For what its worth Micky, Happy Birthday!&lt;/p&gt;  &lt;p&gt;And… change all your passwords!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1691530" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=i7XHkoSPJig:6pJTdZ0WONo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=i7XHkoSPJig:6pJTdZ0WONo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=i7XHkoSPJig:6pJTdZ0WONo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/i7XHkoSPJig" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/04/29/1691530.aspx</feedburner:origLink></item><item><title>More information about the malvertizements that appeared on guardian.co.uk and electronicsnews.com.au</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/BaIR01z-zCs/1691412.aspx</link><pubDate>Mon, 27 Apr 2009 23:05:03 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1691412</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1691412</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/04/28/1691412.aspx#comments</comments><description>&lt;p&gt;There are two malvertizements that I highlighted, being: &lt;/p&gt;  &lt;p&gt;m1.au.2mdn.net/1949664/hp_300x250.swf   &lt;br /&gt;m1.emea.2mdn.net/989589/hp_728x90.swf &lt;/p&gt;  &lt;p&gt;The 300x250 malvert touches hit-detect.com and measurehits.com.   &lt;br /&gt;The 728x90 malvert touches ydmstats.com and measurehits.com.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Redirects: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;We go from measurehits.com to crustat.com. &lt;/p&gt;  &lt;p&gt;From there we go to one of several different domains: &lt;/p&gt;  &lt;p&gt;olinredr2.com/&amp;lt;&amp;lt;redacted&amp;gt;&amp;gt;   &lt;br /&gt;truconv.com/&amp;lt;&amp;lt;redacted&amp;gt;&amp;gt;    &lt;br /&gt;free-webscaners.com/&amp;lt;&amp;lt;redacted&amp;gt;&amp;gt; &amp;lt;--- fraudware domain &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;If a victim is redirected to olinredr2.com then they end up at pyani.com,then offer-provider.com.&amp;#160; offer-provider.com is a fraudware domain touting fake security software under various names such as &amp;quot;SpywareRemover&amp;quot; and &amp;quot;VirusRemover2009&amp;quot; and &amp;quot;AntiSpywareSolution 2009&amp;quot;. &lt;/p&gt;  &lt;p&gt;If a victim is redirected to truconv.com then they end up at total-virusprotection.com, another fraudware domain.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1691412" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=BaIR01z-zCs:rIBt1L9KrSE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=BaIR01z-zCs:rIBt1L9KrSE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=BaIR01z-zCs:rIBt1L9KrSE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/BaIR01z-zCs" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/04/28/1691412.aspx</feedburner:origLink></item><item><title>Further information regarding the malvertizements touting ebay discovered at perezhilton.com</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/d9C7-ADI6mk/1691411.aspx</link><pubDate>Mon, 27 Apr 2009 22:45:16 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1691411</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1691411</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/04/28/1691411.aspx#comments</comments><description>&lt;p&gt;The malvertizement redirects victims to various fraudware/scareware products via several redirects (some of the URLs change at random – victims don’t hit all of the domains listed below).&lt;/p&gt;  &lt;p&gt;These are the URLs that are hit by the malvertizement – we have seen all of them before:&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;statcluster.com/crossdomain.xml     &lt;br /&gt;statcluster.com/c/index.php?id&amp;lt;&amp;lt;redacted&amp;gt;&amp;gt;      &lt;br /&gt;crustat.com/ts/in.cgi?&amp;lt;&amp;lt;redacted&amp;gt;&amp;gt;      &lt;br /&gt;olinredr2.com/?accs=&amp;lt;&amp;lt;redacted&amp;gt;&amp;gt;      &lt;br /&gt;pyani.com/in.cgi?&amp;lt;&amp;lt;redacted&amp;gt;&amp;gt;       &lt;br /&gt;offer-provider.com/&amp;lt;&amp;lt;redacted&amp;gt;&amp;gt;      &lt;br /&gt;truconv.com/&amp;lt;&amp;lt;redacted&amp;gt;&amp;gt;      &lt;br /&gt;justwebsecurity.com/&amp;lt;&amp;lt;redacted&amp;gt;&amp;gt;&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Final destinations: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;offer-provider.com is a fraudware domain touting fake security software under various names such as &amp;quot;SpywareRemover&amp;quot; and &amp;quot;VirusRemover2009&amp;quot; and &amp;quot;AntiSpywareSolution 2009&amp;quot;. &lt;/p&gt;  &lt;p&gt;trueconv leads to the fraudware total-virusprotection.com. &lt;/p&gt;  &lt;p&gt;justwebsecurity.com leads to a fake &amp;quot;System Security&amp;quot; scanning page.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1691411" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=d9C7-ADI6mk:lyrWLjK2knY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=d9C7-ADI6mk:lyrWLjK2knY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=d9C7-ADI6mk:lyrWLjK2knY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/d9C7-ADI6mk" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/04/28/1691411.aspx</feedburner:origLink></item><item><title>ALERT: Malvertizing at perezhilton.com</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/0ZRbf1j_JHU/1691394.aspx</link><pubDate>Mon, 27 Apr 2009 14:37:10 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1691394</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1691394</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/04/27/1691394.aspx#comments</comments><description>&lt;p&gt;perezhilton.com is an extremely popular site, and the potential audience for the malvertizers is *huge*.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.bluetack.co.uk/forums/index.php" target="_blank"&gt;Kimberley&lt;/a&gt; and I make a great team.&amp;#160; I knew that there was a malvertizement being displayed on perezhilton.com, but I hadn’t been able to get definitive proof – Kimberley got it.&lt;/p&gt;  &lt;p&gt;Check out the screenshot below – note that the referrer is &lt;strong&gt;perezhilton.com/page/2&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Also, note that the screenshot is evidence of a GET request for &lt;strong&gt;f.blogads.com/www/delivery/ai.php?filename=ebay_300x250.swf&amp;amp;contentype=swf&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;img style="display:inline;" title="image" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_2CDFB8FA.png" width="602" height="347" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Now, let’s look at the rest of the capture:&lt;/p&gt;  &lt;p&gt;&lt;img style="display:inline;" title="image" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_426219B7.png" width="697" height="214" /&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;statcluster.com&lt;/strong&gt; is a known bad domain – so is &lt;strong&gt;enjoyspringtime.com&lt;/strong&gt;, &lt;strong&gt;crustat.com&lt;/strong&gt;, &lt;strong&gt;olinred2.com&lt;/strong&gt;, &lt;strong&gt;pyani.com&lt;/strong&gt; and &lt;strong&gt;offer-provider.com&lt;/strong&gt;.&lt;/p&gt;  &lt;p&gt;The malvertizements have been reported to blogads.com and I have every confidence that they will be removed very quickly.&lt;/p&gt;  &lt;p&gt;This is what the malvertizement looks like:&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 20px 20px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_13354F82.png" width="326" height="278" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1691394" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=0ZRbf1j_JHU:6vvxNu2pj6g:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=0ZRbf1j_JHU:6vvxNu2pj6g:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=0ZRbf1j_JHU:6vvxNu2pj6g:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/0ZRbf1j_JHU" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/04/27/1691394.aspx</feedburner:origLink></item><item><title>ALERT: Malvertizing at electronicsnews.com.au</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/2BVopiDtsH4/1691388.aspx</link><pubDate>Mon, 27 Apr 2009 12:31:02 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1691388</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1691388</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/04/27/1691388.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_52AD167B.png" width="967" height="470" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Edited to fix subjectline&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;It is a malvertizement featuring HP (visually identical to the HP malvertizement described in my earlier article):    &lt;br /&gt;&lt;a title="http://msmvps.com/blogs/spywaresucks/archive/2009/02/28/1674634.aspx" href="http://msmvps.com/blogs/spywaresucks/archive/2009/02/28/1674634.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/02/28/1674634.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The malvertizement itself is at this URL:    &lt;br /&gt;&lt;strong&gt;m1.au.2mdn.net/1949664/hp_300x250.swf&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;Adopstools test results here:    &lt;br /&gt;&lt;a title="http://www.adopstools.com/index.asp?section=quicklink&amp;amp;id=ZdWLlE0YcK7rkK5C" href="http://www.adopstools.com/index.asp?section=quicklink&amp;amp;id=ZdWLlE0YcK7rkK5C" target="_blank"&gt;http://www.adopstools.com/index.asp?section=quicklink&amp;amp;id=ZdWLlE0YcK7rkK5C&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Yes, it is the same advert that we found on guardian.co.uk    &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/04/27/1691363.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/04/27/1691363.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The malvertizement has been reported to the appropriate parties.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1691388" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=2BVopiDtsH4:8wfhIQKkXuw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=2BVopiDtsH4:8wfhIQKkXuw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=2BVopiDtsH4:8wfhIQKkXuw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/2BVopiDtsH4" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/04/27/1691388.aspx</feedburner:origLink></item><item><title>ALERT: Malvertizing at guardian.co.uk</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/bR-cVm_PJCQ/1691363.aspx</link><pubDate>Mon, 27 Apr 2009 04:59:23 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1691363</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1691363</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/04/27/1691363.aspx#comments</comments><description>&lt;p&gt;There are two of them, both featuring HP (the ads have been documented on this blog in the past).&lt;/p&gt;  &lt;p&gt;Both advertisements are being served via 2mdn.net and have been reported to the appropriate parties.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;m1.emea.2mdn.net/989589/hp_728x90.swf&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_50D6F3A5.png" width="973" height="262" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;m1.au.2mdn.net/1949664/hp_300x250.swf&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_68B7F7C2.png" width="922" height="405" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1691363" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=bR-cVm_PJCQ:zlZ8VWcSGFM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=bR-cVm_PJCQ:zlZ8VWcSGFM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=bR-cVm_PJCQ:zlZ8VWcSGFM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/bR-cVm_PJCQ" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/04/27/1691363.aspx</feedburner:origLink></item><item><title>ALERT: blogads.com is serving malvertizements</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/1BTFDyCR67o/1691362.aspx</link><pubDate>Mon, 27 Apr 2009 04:42:08 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1691362</guid><dc:creator>sandi</dc:creator><slash:comments>1</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1691362</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/04/27/1691362.aspx#comments</comments><description>&lt;p&gt;The malvertizements have been reported to blogads.com.&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_039AE947.png" width="753" height="111" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;z.blogads.com/www/delivery/afr.php?n+a91736e9&amp;amp;zoneid=86&amp;amp;cb=INSERT_RANDOM_NUMBER_HERE&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_5492CA66.png" width="325" height="274" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;z.blogads.com/www/delivery/afr.php?n+aa00ce7a&amp;amp;zoneid=87&amp;amp;cb=INSERT_RANDOM_NUMBER_HERE&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;The adverts hit statcluster.com, enjoyspringtime.com and crustat.com (all known bad domains).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1691362" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=1BTFDyCR67o:MywKoBlDZJ0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=1BTFDyCR67o:MywKoBlDZJ0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=1BTFDyCR67o:MywKoBlDZJ0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/1BTFDyCR67o" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/04/27/1691362.aspx</feedburner:origLink></item><item><title>Another fake Phoenix University malvertizement</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/FHJaMZ2MDkI/1690418.aspx</link><pubDate>Fri, 24 Apr 2009 05:44:56 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1690418</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1690418</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/04/24/1690418.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 20px 20px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_5CFB80C5.png" width="329" height="278" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;This one is using the same domains as the previous version (although it should be noted that, although visually identical, this one had a different Hash to the one I looked at yesterday).&lt;/p&gt;  &lt;p&gt;Victims end up at one of two fraudware sites, scanspywareonline.com or justwebsecurity.com.&lt;/p&gt;  &lt;p&gt;I have written about justwebsecurity.com already, so let’s take a look at &lt;strong&gt;scanspywareonline.com&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;scanspywareonline.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS PVT. LTD. D/B/A PUBLICDOMAINREGISTRY.COM    &lt;br /&gt;Created 4 March 2009    &lt;br /&gt;NS1H1.DNS-MANAGE.COM    &lt;br /&gt;NS2H1.DNS-MANAGE.COM    &lt;br /&gt;NS3H1.DNS-MANAGE.COM    &lt;br /&gt;DN4H1.DNS-MANAGE.COM &lt;/p&gt;  &lt;p&gt;IP: 205.252.24.226 - Virginia, Herndon ,Beyond The Network America Inc &lt;/p&gt;  &lt;p&gt;Registrant details hidden behind privacyprotect.org &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;IP address shared with 21 other sites (take a deep breath – all except for one list DIRECTI as the ICANN Registrar – seriously, you’d think that DIRECTI would have learned what to watch out for by now.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;advancesoftpc.com     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: ENOM INC    &lt;br /&gt;Registrant: Internet Marketing Ltd    &lt;br /&gt;Volodymyr Kushnir    &lt;br /&gt;Patrisa Lumumby str. 7, flat 30, Kiev    &lt;br /&gt;Registration service: namecheap.com &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;antispywarepro.net&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: DIRECT INTERNET SOLUTIONS    &lt;br /&gt;Created 16 September 2008    &lt;br /&gt;Registrant details hidden behind privacyprotect.org    &lt;br /&gt;Registration service: DNS-MANAGE.COM &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;kweekz.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS    &lt;br /&gt;Created 27 November 2006    &lt;br /&gt;Registrant: &amp;quot;admin&amp;quot;, unused@fabrica.net.ua, Lomonosova 59, Kiev    &lt;br /&gt;Registration service: DNS-MANAGE.COM &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;netspywarescan.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS    &lt;br /&gt;Created 19 December 2008    &lt;br /&gt;Registrant hidden behind privacyprotect.org    &lt;br /&gt;Registration service: DNS-MANAGE.COM&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;online-spyware-scan.net&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS    &lt;br /&gt;Created 4 March 2009    &lt;br /&gt;Registrant hidden behind privacyprotect.org    &lt;br /&gt;Registration service: DNS-MANAGE.COM &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;onlinespyscan.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS    &lt;br /&gt;Created 7 April 2009    &lt;br /&gt;Registrant hidden behind privacyprotect.org    &lt;br /&gt;Registration service: DNS-MANAGE.COM&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;onlinespyscan.net&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS    &lt;br /&gt;Created 7 April 2009    &lt;br /&gt;Registrant hidden behind privacyprotect.org    &lt;br /&gt;Registration service: DNS-MANAGE.COM&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;onlinespyscanner.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS    &lt;br /&gt;Created 7 April 2009    &lt;br /&gt;Registrant hidden behind privacyprotect.org    &lt;br /&gt;Registration service: DNS-MANAGE.COM &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;onlinespyscanner.net     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS    &lt;br /&gt;Created 7 April 2009    &lt;br /&gt;Registrant hidden behind privacyprotect.org    &lt;br /&gt;Registration service: DNS-MANAGE.COM&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;onlinespywarescanner.net&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS    &lt;br /&gt;Created 4 March 2009    &lt;br /&gt;Registrant hidden behind privacyprotect.org    &lt;br /&gt;Registration service: DNS-MANAGE.COM&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;onlinespywaresscanner.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS    &lt;br /&gt;Created 7 April 2009    &lt;br /&gt;Registrant hidden behind privacyprotect.org    &lt;br /&gt;Registration service: DNS-MANAGE.COM &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;onlinespywaresscanner.net     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS    &lt;br /&gt;Created 7 April 2009    &lt;br /&gt;Registrant hidden behind privacyprotect.org    &lt;br /&gt;Registration service: DNS-MANAGE.COM.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;pcspeed-up.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS    &lt;br /&gt;Created 8 May 2008    &lt;br /&gt;Registrant hidden behind privacyprotect.org    &lt;br /&gt;Registration service: DNS-MANAGE.COM&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;scanforspywares.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS    &lt;br /&gt;Created 7 April 2009    &lt;br /&gt;Registrant hidden behind privacyprotect.org    &lt;br /&gt;Registration service: DNS-MANAGE.COM&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;scanforspywares.net&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS    &lt;br /&gt;Created 7 April 2009    &lt;br /&gt;Registrant hidden behind privacyprotect.org    &lt;br /&gt;Registration service: DNS-MANAGE.COM&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;scanspywareonline.net&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS    &lt;br /&gt;Created 4 March 2009    &lt;br /&gt;Registrant hidden behind privacyprotect.org    &lt;br /&gt;Registration service: DNS-MANAGE.COM&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;smartpcsoft.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS    &lt;br /&gt;Created 9 April 2009    &lt;br /&gt;Registrant hidden behind privacyprotect.org    &lt;br /&gt;Registration service: DNS-MANAGE.COM&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;spywareonlinescan.net&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS    &lt;br /&gt;Created 7 April 2009    &lt;br /&gt;Registrant hidden behind privacyprotect.org    &lt;br /&gt;Registration service: DNS-MANAGE.COM&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;spywareonlinescanner.net&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS    &lt;br /&gt;Created 7 April 2009    &lt;br /&gt;Registrant hidden behind privacyprotect.org    &lt;br /&gt;Registration service: DNS-MANAGE.COM&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;spywarescanonline.net&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS    &lt;br /&gt;Created 4 March 2009    &lt;br /&gt;Registrant hidden behind privacyprotect.org    &lt;br /&gt;Registration service: DNS-MANAGE.COM &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;winflashmedia.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS    &lt;br /&gt;Created 16 January 2008    &lt;br /&gt;Registrant: Bogdan Pankiv (software@fabrica.net.ua - note, see kweekz.com above), Gorkogo 122, apt.19, Kiev    &lt;br /&gt;Registration service: DNS-MANAGE.COM &lt;/p&gt;  &lt;p&gt;Registration service used: &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;DNS-MANAGE.COM&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI INTERNET SOLUTIONS    &lt;br /&gt;Created 1 March 2009    &lt;br /&gt;Registrant hidden behind privacyprotect.org&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1690418" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=FHJaMZ2MDkI:j0UzmHLm6qc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=FHJaMZ2MDkI:j0UzmHLm6qc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=FHJaMZ2MDkI:j0UzmHLm6qc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/FHJaMZ2MDkI" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/04/24/1690418.aspx</feedburner:origLink></item><item><title>ALERT:  Malvertizement featuring Phoenix University</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/AF0OItUj5qU/1690203.aspx</link><pubDate>Thu, 23 Apr 2009 14:49:51 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1690203</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1690203</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/04/23/1690203.aspx#comments</comments><description>&lt;p&gt;&lt;strong&gt;PLEASE TREAT ALL CONTENT FROM PERFECT-BANNER.COM WITH EXTREME CAUTION&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 25px 25px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_5C47B9D9.png" width="329" height="278" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Adopstools scan results:   &lt;br /&gt;&lt;a href="http://www.adopstools.net/index.asp?section=quicklink&amp;amp;id=36xxrvvFRC85pkp7" target="_blank"&gt;http://www.adopstools.net/index.asp?section=quicklink&amp;amp;id=36xxrvvFRC85pkp7&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Malvertizement host:   &lt;br /&gt;&lt;strong&gt;perfect-banner.com&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Hits the domains &lt;strong&gt;statcluster.com&lt;/strong&gt; and &lt;strong&gt;enjoyspringtime.com&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;From there to &lt;strong&gt;crustat.com, pnfzetnax.net&lt;/strong&gt; (or &lt;strong&gt;justwebsecurity.com&lt;/strong&gt;), then to 78.47.132.220. &lt;/p&gt;  &lt;p&gt;-----&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;perfectbanner.com     &lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;ICANN Registrar: ENOM, INC.   &lt;br /&gt;Created 10 March 2009    &lt;br /&gt;NS1.PERFECT-BANNER.COM    &lt;br /&gt;NS2.PERFECT-BANNER.COM    &lt;br /&gt;NS3.PERFECT-BANNER.COM    &lt;br /&gt;NS4.PERFECT-BANNER.COM &lt;/p&gt;  &lt;p&gt;IP: 89.149.244.137 - Hessen, Frankfurt Am Main, Netdirekt E.k &lt;/p&gt;  &lt;p&gt;Shares IP with one other site, being &lt;strong&gt;4netbanners.com&lt;/strong&gt; - please treat the domain 4netbanners.com with extreme caution &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Nexton Limited    &lt;br /&gt;Whois Agent    &lt;br /&gt;Irpinskaya 69    &lt;br /&gt;Kiev, 03142    &lt;br /&gt;UA &lt;/p&gt;  &lt;p&gt;Registration service provided by:   &lt;br /&gt;Contact: director@climbing-games.com    &lt;br /&gt;ruler-domains.com    &lt;br /&gt;director@climbing-games.com has been mentioned on this blog before, in association with the fraudware domain ie-security.com:    &lt;br /&gt;&lt;a title="http://msmvps.com/blogs/spywaresucks/archive/2009/02/02/1668084.aspx" href="http://msmvps.com/blogs/spywaresucks/archive/2009/02/02/1668084.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/02/02/1668084.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Also associated with the malware domain xp-police-av.com:   &lt;br /&gt;&lt;a title="http://www.precisesecurity.com/blogs/2009/02/17/xp-police-av/" href="http://www.precisesecurity.com/blogs/2009/02/17/xp-police-av/" target="_blank"&gt;http://www.precisesecurity.com/blogs/2009/02/17/xp-police-av/&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;----- &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;4netbanners.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: KEY-SYSTEMS GMBH    &lt;br /&gt;Created 9 April 2009    &lt;br /&gt;NS1.MYDOMAIN-IN.NET    &lt;br /&gt;MS2.MYDOMAIN-IN.NET &lt;/p&gt;  &lt;p&gt;IP: 89.149.244.137 - Hessen, Frankfurt Am Main, Netdirekt E.k &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Primak Vornen (primakvornen@myself.com    &lt;br /&gt;Punane 34    &lt;br /&gt;Tallin 13619    &lt;br /&gt;EE    &lt;br /&gt;37 263 176 2334 &lt;/p&gt;  &lt;p&gt;----- &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;ruler-domains.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: ENOM INC    &lt;br /&gt;Created 17 November 2008    &lt;br /&gt;NS5.NAMESERVER01.COM    &lt;br /&gt;NS6.NAMESERVER01.COM &lt;/p&gt;  &lt;p&gt;IP: 78.46.88.142 - Bayern, Gunzenhausen, Hetzner &lt;/p&gt;  &lt;p&gt;Shares IP with 12 other sites being av-cash.com, billingpayment.net, gilded-youth.com, iloveyourbrain.com, loyalbox.biz, richisoftware2.com, ruler-cash.com, ruler-dating.com, ruler-domains.com, ruler-search.com, vashkont.com, vashkontakt.com, vkontaktev.com - all domains should be treated with extreme caution. &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Sergey Ryabov (director@climbing-games.com)    &lt;br /&gt;7 921 927 0961    &lt;br /&gt;Fax: 7 921 927 0961    &lt;br /&gt;Scherbakova st., 6-38    &lt;br /&gt;Saint-Petersburg, 197375    &lt;br /&gt;RU &lt;/p&gt;  &lt;p&gt;-----&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;statcluster.com     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: YESNIC CO. LTD    &lt;br /&gt;Created: 3 April 2009    &lt;br /&gt;NS1.STATCLUSTER.COM    &lt;br /&gt;NS2.STATCLUSTER.COM &lt;/p&gt;  &lt;p&gt;IP: 174.37.196.175 - Texas, Dallas, Softlayer Technologies Inc &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Burt N Charlesworth (burtn@mail.com)    &lt;br /&gt;971 Hidden Valley Road    &lt;br /&gt;170742    &lt;br /&gt;US    &lt;br /&gt;2129887344 (this number traces to New York, and is not owned by Burt N Charlesworth, or anybody with the same or similar surname) &lt;/p&gt;  &lt;p&gt;----- &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;enjoyspringtime.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: COMMUNIGAL COMMUNICATIONS LTD    &lt;br /&gt;Created 20 March 2009    &lt;br /&gt;DNS1.COMMUNIGAL.NET    &lt;br /&gt;DNS2.COMMUNIGAL.NET &lt;/p&gt;  &lt;p&gt;IP: 38.99.168.101 - Ontario, Toronto, Psinet Inc &lt;/p&gt;  &lt;p&gt;Registrar:   &lt;br /&gt;Robert Robinson (robertrobinson@mail.com)    &lt;br /&gt;4452 Dogwood Lane, Phoenix, 85012    &lt;br /&gt;602 520 553 9781 &lt;/p&gt;  &lt;p&gt;We&amp;#39;ve come across Robert Robinson before, that is the ID used to register the domain welovesandi.com (&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/04/01/1683651.aspx)" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/04/01/1683651.aspx)&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;----- &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;crustat.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: COMMUNIGAL COMMUNICATIONS LTD    &lt;br /&gt;Created: 5 March 2009    &lt;br /&gt;DNS1.COMMUNIGAL.NET    &lt;br /&gt;DNS2.COMMUNIGAL.NET &lt;/p&gt;  &lt;p&gt;IP: 94.76.213.234 - UK, Hp3-right &lt;/p&gt;  &lt;p&gt;Shares IP with one other domain, being tldst.com &lt;/p&gt;  &lt;p&gt;Registrant details hidden behind WHOIS privacy service &lt;/p&gt;  &lt;p&gt;----- &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;pnfzetnax.net&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: INTERNET INVEST, LTD. DBA IMENA.UA    &lt;br /&gt;Created: 20 March 2009    &lt;br /&gt;NS1.IMENA.COM.UA    &lt;br /&gt;NS2.IMENA.COM.UA &lt;/p&gt;  &lt;p&gt;IP: 85.10.243.126 - Hetzner, Germany &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;David Armstrong (avidarms@mail.com)    &lt;br /&gt;1785 Haul Road    &lt;br /&gt;Golden Valley    &lt;br /&gt;55427    &lt;br /&gt;1 6512387511 (traces to Minneapolis, MN) &lt;/p&gt;  &lt;p&gt;----- &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;justwebsecurity.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: REGTIME LTD    &lt;br /&gt;Created 20 April 2009    &lt;br /&gt;NS1.JUSTWEBSECURITY.COM    &lt;br /&gt;NS2.JUSTWEBSECURITY.COM &lt;/p&gt;  &lt;p&gt;IP: 91.212.65.55 - Ukraine, Eurohost Llc &lt;/p&gt;  &lt;p&gt;Shares IP with three other domains, being globalsecurityscan.com, onlinebrandsecurity.com and scanprotectiononline.com (all domains should be treated with extreme caution). &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Rene Clay (renepclay@text2re.com)    &lt;br /&gt;1555 Lake Floyd Circle    &lt;br /&gt;Chevy Chase    &lt;br /&gt;MD 20815    &lt;br /&gt;US    &lt;br /&gt;1 301 941 5618&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1690203" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=AF0OItUj5qU:LU3n2FtmrM8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=AF0OItUj5qU:LU3n2FtmrM8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=AF0OItUj5qU:LU3n2FtmrM8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/AF0OItUj5qU" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/04/23/1690203.aspx</feedburner:origLink></item><item><title>Another lesson in assessing the reliability of credit references</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/loI4knk_PyI/1690197.aspx</link><pubDate>Thu, 23 Apr 2009 13:57:37 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1690197</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1690197</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/04/23/1690197.aspx#comments</comments><description>&lt;p&gt;ALERT:&amp;#160; Please treat any content from these domains with suspicion, and be very careful about any credit reference you receive that refers to:&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;yourdirectmedia.com, atlantmedia, traffichunters, olympicmedia.net ads2revenue, adsrepublic, truemedian.com, readadsolutions.com, adsmanagement.com&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;ALERT: Watch out for the impersonation of legitimate businesses in credit reference checks.&amp;#160; Details below.&lt;/p&gt;  &lt;p&gt;-----&lt;/p&gt;  &lt;p&gt;It is fascinating to watch the way that the people behind malvertizing do business.&amp;#160; It wasn&amp;#39;t that long ago that they were inherently lazy, using the same Registrars over and over, hosting myriad malicious web sites at the same IP address, using the same name servers for multiple domains, using different combinations of the same names and email addresses over and over for WHOIS purposes, using the same templates for their fake &amp;#39;advertising network&amp;#39; websites... redundancy was a foreign concept to them. &lt;/p&gt;  &lt;p&gt;Even the credit references that they supplied were easy to spot as dodgy if you knew what to look for.&amp;#160; There was often an obvious association between different domains used by referees if we bothered to take even a cursory look at the Registrant and hosting details. &lt;/p&gt;  &lt;p&gt;That being said, the bad guys have been changing their modus operandi with regards to trade references and it is getting harder to spot problems.&amp;#160; Let&amp;#39;s have a look at some recent examples that have crossed my desk. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;YOURDIRECTMEDIA.COM SHENANIGANS:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Yourdirectmedia.com&lt;/strong&gt; have been caught supplying &lt;strong&gt;AtlantMedia&lt;/strong&gt; as a credit referee – a referee that is easy to discredit - atlantmedia is a known bad actor. &lt;/p&gt;  &lt;p&gt;Cite: &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2008/12/10/1656329.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2008/12/10/1656329.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;atlantmedia.net&lt;/strong&gt; used to have IP address 89.149.235.24 - Lithuania Kaunas Netdirect-uab-retrogarsas (web site currently not resolving). &lt;/p&gt;  &lt;p&gt;A connection has been discovered between &lt;strong&gt;atlantmedia.net&lt;/strong&gt; and &lt;strong&gt;olympicmedia.net&lt;/strong&gt; (also offline) – its last IP was 212.95.53.164 and it used to be at IP 216.195.54.212 (&lt;strong&gt;atlantmedia.net&lt;/strong&gt; used to have the IP 216.195.57.40) &lt;/p&gt;  &lt;p&gt;Let&amp;#39;s not forget that a connection has been drawn between &lt;strong&gt;traffichunters, olympicmedia&lt;/strong&gt; and the now infamous &lt;strong&gt;Innovative Marketing&lt;/strong&gt;, thanks to an email slip-up. &lt;/p&gt;  &lt;p&gt;Cite: &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/03/27/1682054.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/03/27/1682054.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;&lt;img style="border-right-width:0px;margin:10px 25px 25px 0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_4E20AE71.png" width="679" height="636" /&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;IMPERSONATION OF LEGITIMATE COMPANIES&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;When I first saw the name Tribalfusion listed as a referee for &lt;strong&gt;yourdirectmedia&lt;/strong&gt;, my immediate reaction was &amp;quot;&lt;em&gt;what the hell is tribalfusion doing being a referee for these guys?&lt;/em&gt;&amp;quot;&amp;#160; A bit of digging revealed the truth. &lt;/p&gt;  &lt;p&gt;The referee given was &amp;quot;&lt;strong&gt;Tribalfusion, Mike Carter, 215 789 9793&lt;/strong&gt;&amp;quot;.&amp;#160; But, it just so happens that that phone number belongs to &amp;quot;&lt;strong&gt;ads2revenue&lt;/strong&gt;&amp;quot;, not &amp;quot;tribalfusion&amp;quot; - we know this because the number used to be on the &lt;strong&gt;ads2revenue&lt;/strong&gt; web site (although the phone number has since been removed from the &lt;strong&gt;ads2revenue&lt;/strong&gt; site). &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;ads2revenue&lt;/strong&gt;     &lt;br /&gt;ICANN REGISTRAR: ENOM, INC     &lt;br /&gt;Date created: 12 November 2008 &lt;/p&gt;  &lt;p&gt;NS1.ADS2REVENUE.COM - 93.190.141.36    &lt;br /&gt;NS2.ADS2REVENUE.COM - 93.190.141.37     &lt;br /&gt;NS3.ADS2REVENUE.COM - 212.95.32.48     &lt;br /&gt;MAIL.ADS2REVENUE.COM - 212.95.32.48 &lt;/p&gt;  &lt;p&gt;IP: 212.95.32.48 - Hessen, Frankfurt Am Main - Netdirekt E.k &lt;/p&gt;  &lt;p&gt;Dedicated Hosting &lt;/p&gt;  &lt;p&gt;Registrant: Hidden behind WHOISGUARD &lt;/p&gt;  &lt;p&gt;Already mentioned on spywaresucks once before - cite: &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/02/28/1674707.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/02/28/1674707.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Another referee supplied by &lt;strong&gt;yourdirectmedia.com&lt;/strong&gt; was &amp;quot;Classmatesmedia, Rick Harris, 619 949 8952&amp;quot;.&amp;#160; In this case there was nothing definitive to be discovered about the phone number, but we still have cause for concern.&amp;#160; As far as I know, classmatesmedia does not directly sells advertising - rather, United Online Advertising Solutions does that (uolmediagroup.com) &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;THE USE OF EXECUTIVE (AKA MANAGED, AKA SERVICED) OFFICES&lt;/u&gt;&lt;/strong&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Many of us are careful to check things like phone numbers and addresses when researching potential advertisers and credit references, and that good habit is becoming more common.&amp;#160; Because of this it has become harder for the bad guys to use fake phone numbers and addresses. &lt;/p&gt;  &lt;p&gt;To get around this, the bad guys are sometimes using executive offices as the contact address and phone number for credit references (and their own web sites). &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;ADSREPUBLIC SHENANIGANS&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;adsrepublic&lt;/strong&gt; has been trying to sell advertising under pretty typical “red flag” circumstances (lots of urgency, please run ads as soon as possible etc).&amp;#160; &lt;/p&gt;  &lt;p&gt;Their email message headers revealed that the email was coming from Latvia (despite the advertiser claiming to be based in Atlanta, Georgia - specifically Suite 1500, 3500 Lenox Road).&amp;#160; That address in Atlanta is a &amp;quot;virtual office&amp;quot;: &lt;/p&gt;  &lt;p&gt;Cite: &lt;a href="http://www.interactiveoffices.com/search.php?id_country=1&amp;amp;id_state=2&amp;amp;id_city=3" target="_blank"&gt;http://www.&lt;strong&gt;interactiveoffices.com&lt;/strong&gt;/search.php?id_country=1&amp;amp;id_state=2&amp;amp;id_city=3&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;The referees supplied by adsrepublic were:&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;truemedian.com&lt;/strong&gt;, &lt;strong&gt;realadsolutions.com&lt;/strong&gt; and &lt;strong&gt;adsmanagement.com&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Let&amp;#39;s look at the referee addresses – all are Executive/Virtual Offices: &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;truemedian.com&lt;/strong&gt; - suite 300, 1800 John F Kennedy Boulevard     &lt;br /&gt;cite: &lt;a href="http://jfk.yourofficeusa.com/"&gt;http://jfk.&lt;strong&gt;yourofficeusa&lt;/strong&gt;.com/&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;realadsolutions.com&lt;/strong&gt; - Suite 700 210 Interstate North Pkwy     &lt;br /&gt;cite: &lt;a href="http://www.interactiveoffices.com/officescanada.php?id_state=2&amp;amp;id=37"&gt;http://www.&lt;strong&gt;interactiveoffices.com&lt;/strong&gt;/officescanada.php?id_state=2&amp;amp;id=37&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;adsmanagement.com&lt;/strong&gt; - Suite 1500, 121 south orange avenue     &lt;br /&gt;cite: &lt;a href="http://orlando.youroffice.com/"&gt;http://orlando.&lt;strong&gt;youroffice.com&lt;/strong&gt;/&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;truemedian.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: 1 &amp;amp; 1 INTERNET AG    &lt;br /&gt;Created 30 January 2009    &lt;br /&gt;NS1.PANELBOXMANAGER.COM    &lt;br /&gt;NS2.PANELBOXMANAGER.COM &lt;/p&gt;  &lt;p&gt;IP: 72.55.186.42 - Quebec, Montreal, Panelbox &lt;/p&gt;  &lt;p&gt;IP shared with 506 other sites &lt;/p&gt;  &lt;p&gt;Registrant details hidden behind 1&amp;amp;1 Private Registration &lt;/p&gt;  &lt;p&gt;----- &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;realadsolutions.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: 1 &amp;amp; 1 INTERNET AG    &lt;br /&gt;Created 30 January 2009    &lt;br /&gt;NS1.PANELBOXMANAGER.COM    &lt;br /&gt;NS2.PANELBOXMANAGER.COM &lt;/p&gt;  &lt;p&gt;IP: 72.55.186.42 - Quebec, Montreal, Panelbox &lt;/p&gt;  &lt;p&gt;IP shared with 506 other sites &lt;/p&gt;  &lt;p&gt;Registrant details hidden behind 1&amp;amp;1 Private Registration &lt;/p&gt;  &lt;p&gt;----- &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;adsmanagement.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: NAMEVIEW, INC    &lt;br /&gt;Created 29 September 2003 &amp;lt;!&amp;gt;    &lt;br /&gt;NS1.HITFARM.COM    &lt;br /&gt;NS2.HITFARM.COM &lt;/p&gt;  &lt;p&gt;IP: 208.87.33.150 - New Providence, Nassau, Secure Hosting Ltd &lt;/p&gt;  &lt;p&gt;IP shared with 488,707 other sites &lt;/p&gt;  &lt;p&gt;Registrant details currently hidden behind Whois Identity Shield &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Now let’s look at the advertisement itself.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;adsrepublic.com&lt;/strong&gt; was offering advertising using the domain &lt;strong&gt;lorentrio.com&lt;/strong&gt; - a domain that is interesting in and of itself. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;lorentrio.com&lt;/strong&gt; was registered via Directi on the 29th of March.&amp;#160; With WHOIS details hidden behind privacyprotect, the domain is immediately suspicious. At time of writing, the IP address for &lt;strong&gt;lorentrio.com&lt;/strong&gt; is 94.75.216.152 (Amsterdam, Leaseweb).&amp;#160; It shares IP with the following domains: &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;alitasis.com, idatrinity.com, junstring.com, kernerlane.com, lacoste-ads.com, mosdao.com, namlean.com, nokia-corp.com, tornadomb.com &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;lacoste-ads.com&lt;/strong&gt; and &lt;strong&gt;nokia-corp.com&lt;/strong&gt; are immediate causes for concern, and make me wonder if there are (or will be) malvertizing campaigns circulated that pretend to represent Lacoste or Nokia.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;nokia-corp.com&lt;/strong&gt; was created on 14 April 2009, registered via Directi and with Registrant information again hidden behind privacyprotect. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;lacoste-ads.com&lt;/strong&gt; was created on 2 March 2009, registered via Directi and with Registrant information again hidden behind a privacy service. &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1690197" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=loI4knk_PyI:yVTXo2H61JM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=loI4knk_PyI:yVTXo2H61JM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=loI4knk_PyI:yVTXo2H61JM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/loI4knk_PyI" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/04/23/1690197.aspx</feedburner:origLink></item></channel></rss>
