<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Spyware Sucks</title><link>http://msmvps.com/blogs/spywaresucks/default.aspx</link><description>Teaching all Internet users about the latest risks to their online safety and how to stay safe when surfing the Web (and she knows a lot about Internet Explorer too) ;o)</description><dc:language>en</dc:language><generator>CommunityServer 2008 SP1 (Build: 30619.63)</generator><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/SpywareSucks" type="application/rss+xml" /><item><title>OFF-TOPIC: Spam King kills family members, then himself...</title><link>http://feeds.feedburner.com/~r/SpywareSucks/~3/345172174/1642081.aspx</link><pubDate>Fri, 25 Jul 2008 01:09:19 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1642081</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/07/25/1642081.aspx#comments</comments><description>&lt;p&gt;What a shocking turn of events&lt;/p&gt; &lt;p&gt;&lt;a title="http://www.denverpost.com/breakingnews/ci_9985333" href="http://www.denverpost.com/breakingnews/ci_9985333" target="_blank"&gt;http://www.denverpost.com/breakingnews/ci_9985333&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;The dead child was only 3 years old :o(&amp;nbsp; &lt;/p&gt; &lt;p&gt;I have always considered spammers to be the scum of the earth, but this - what sort of person must he have been to be capable of such an act ... I can only hope that there is a Hell, and that he is in it.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1642081" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=lc8GxJ"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=lc8GxJ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=2slTBj"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=2slTBj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/345172174" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Off+topic/default.aspx">Off topic</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2008/07/25/1642081.aspx</feedburner:origLink></item><item><title>Google introduces HTTPS for GMAIL</title><link>http://feeds.feedburner.com/~r/SpywareSucks/~3/345151499/1642080.aspx</link><pubDate>Fri, 25 Jul 2008 00:32:46 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1642080</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/07/25/1642080.aspx#comments</comments><description>&lt;p&gt;And, it&amp;#39;s about time too!!&lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_d478e616_2D00_1970_2D00_410b_2D00_a64f_2D00_52c48302a4dd.png" width="380" height="82" /&gt; &lt;/p&gt; &lt;p&gt;Full details are available via the Google Team announcement:&lt;/p&gt; &lt;p&gt;&lt;a title="http://feeds.feedburner.com/~r/OfficialGmailBlog/~3/344985025/making-security-easier.html" href="http://feeds.feedburner.com/~r/OfficialGmailBlog/~3/344985025/making-security-easier.html" target="_blank"&gt;http://feeds.feedburner.com/~r/OfficialGmailBlog/~3/344985025/making-security-easier.html&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1642080" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=AeDXrJ"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=AeDXrJ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=A91h7j"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=A91h7j" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/345151499" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2008/07/25/1642080.aspx</feedburner:origLink></item><item><title>UPS spam</title><link>http://feeds.feedburner.com/~r/SpywareSucks/~3/344471210/1641982.aspx</link><pubDate>Thu, 24 Jul 2008 10:40:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641982</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/07/24/1641982.aspx#comments</comments><description>&lt;p&gt;There is a lot of it out there .. here is a screenshot of just one that I received:&lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_f5893761_2D00_3074_2D00_4e24_2D00_9e36_2D00_04ec94c90902.png" width="664" height="438" /&gt; &lt;/p&gt; &lt;p&gt;First of all, I didn&amp;#39;t send a postal package.&amp;nbsp; Secondly, UPS isn&amp;#39;t going to us that qq.com address.&amp;nbsp; Thirdly, UPS offers online parcel tracking - why on earth would they send you a document to open?&amp;nbsp; Finally, as far as I know, sending such emails is not standard operating procedure for UPS.&lt;/p&gt; &lt;p&gt;UPS did issue a warning about the virus, but the URL no longer works:&lt;br /&gt;&lt;a title="warning" href="http://www.ups.com/content/us/en/about/news/service_updates/virus_us.html" target="_blank"&gt;UPS Virus warning&lt;/a&gt;&lt;/p&gt; &lt;p&gt;According to &lt;a href="http://urbanlegends.about.com/b/2008/07/15/ups-virus-warning.htm" target="_blank"&gt;urbanlegend.about.com&lt;/a&gt;, the text of the warning was:&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;&lt;em&gt;Attention Virus Warning &lt;br /&gt;&lt;/em&gt;&lt;/p&gt; &lt;p&gt;&lt;em&gt;We have become aware there is a fraudulent email being sent that says it is coming from UPS and leads the reader to believe that a UPS shipment could not be delivered. The reader is advised to open an attachment reportedly containing a waybill for the shipment to be picked up. &lt;br /&gt;&lt;/em&gt;&lt;/p&gt; &lt;p&gt;&lt;em&gt;This e-mail attachment contains a virus. We recommend that you do not open the attachment, but delete the email immediately. &lt;br /&gt;&lt;/em&gt;&lt;/p&gt; &lt;p&gt;&lt;em&gt;UPS may send official notification messages on occasion, but they rarely include attachments. If you receive a notification message that includes an attachment and are in doubt about its authenticity, please contact &lt;/em&gt;&lt;em&gt;&lt;a href="mailto:customerservice@ups.com" target="_blank"&gt;customerservice@ups.com&lt;/a&gt;&lt;/em&gt;&lt;em&gt;. &lt;br /&gt;&lt;/em&gt;&lt;/p&gt; &lt;p&gt;&lt;em&gt;Please note that UPS takes its customer relationships very seriously, but cannot take responsibility for the unauthorized actions of third parties. &lt;br /&gt;&lt;/em&gt;&lt;/p&gt; &lt;p&gt;&lt;em&gt;Thank you for your attention.&lt;/em&gt; &lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;Further information about the UPS spam (the purpose of which, btw, is to fool you running the exe in the zip file, thereby infecting your system with fraudware) can be found here:&lt;/p&gt; &lt;p&gt;&lt;a href="http://msmvps.com/blogs/donna/archive/2008/07/14/ups-packet-service-malware-spam.aspx" target="_blank"&gt;http://msmvps.com/blogs/donna/archive/2008/07/14/ups-packet-service-malware-spam.aspx&lt;/a&gt; &lt;p&gt;&lt;a title="http://www.pandasecurity.com/enterprise/media/press-releases/viewnews?noticia=9301" href="http://www.pandasecurity.com/enterprise/media/press-releases/viewnews?noticia=9301" target="_blank"&gt;http://www.pandasecurity.com/enterprise/media/press-releases/viewnews?noticia=9301&lt;/a&gt;&amp;nbsp; &lt;p&gt;&lt;a href="http://www.dslreports.com/forum/r20789896-UPS-packet-upsinvoicezip-WORM" target="_blank"&gt;http://www.dslreports.com/forum/r20789896-UPS-packet-upsinvoicezip-WORM&lt;/a&gt; &lt;p&gt;&lt;a href="http://www.trendmicro.com/vinfo/grayware/ve_graywareDetails.asp?GNAME=TSPY%5FZBOT%2EPF" target="_blank"&gt;http://www.trendmicro.com/vinfo/grayware/ve_graywareDetails.asp?GNAME=TSPY%5FZBOT%2EPF&lt;/a&gt; &lt;p&gt;&lt;a href="http://feeds.trendmicro.com/~r/Anti-MalwareBlog/~3/342457447/" target="_blank"&gt;http://feeds.trendmicro.com/~r/Anti-MalwareBlog/~3/342457447/&lt;/a&gt; &lt;p&gt;&lt;a href="http://feeds.trendmicro.com/~r/Anti-MalwareBlog/~3/337327468/" target="_blank"&gt;http://feeds.trendmicro.com/~r/Anti-MalwareBlog/~3/337327468/&lt;/a&gt; &lt;p&gt;&lt;a href="http://us.mcafee.com/virusInfo/default.asp?id=description&amp;amp;virus_k=132901" target="_blank"&gt;http://us.mcafee.com/virusInfo/default.asp?id=description&amp;amp;virus_k=132901&lt;/a&gt; &lt;p&gt;&lt;a href="http://my.opera.com/harrywaldron/blog/2008/07/16/united-parcel-service-fake-email-for-package-non-delivery" target="_blank"&gt;http://my.opera.com/harrywaldron/blog/2008/07/16/united-parcel-service-fake-email-for-package-non-delivery&lt;/a&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641982" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=V92dMJ"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=V92dMJ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=TyMMAj"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=TyMMAj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/344471210" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2008/07/24/1641982.aspx</feedburner:origLink></item><item><title>Fraudware via Blogspot - no advertising required...</title><link>http://feeds.feedburner.com/~r/SpywareSucks/~3/343552961/1641878.aspx</link><pubDate>Wed, 23 Jul 2008 13:17:37 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641878</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/07/23/1641878.aspx#comments</comments><description>&lt;p&gt;Actually, it could be fraudware or it could be a p0rn site trying to tempt you into installing a fake media codec depending on the luck of the draw...&lt;/p&gt; &lt;p&gt;Anyway, part of my &amp;#39;day job&amp;#39; nowadays is keeping an eye on the programs that have been whitelisted by TRUSTe&amp;#39;s Trusted Download Program (hence my official title of &amp;quot;Online Compliance Researcher&amp;quot;).&amp;nbsp; There I was, trawling the net, searching for signs of trouble when my PC was broadsided by an unexpected browser hijack...&lt;/p&gt; &lt;h1&gt;*** !!!WARNING WARNING WARNING!!! - DO NOT VISIT ANY OF THE FOLLOWING URLS WITHOUT THE PROTECTION OF REALLY GOOD ANTIVIRUS AND ANTISPYWARE SOFTWARE, AND A WILLINGNESS TO REFORMAT YOUR COMPUTER TO GET RID OF THE CRUD IF YOUR REALLY GOOD ANTIVIRUS AND ANTISPYWARE SOFTWARE HAPPENS TO FAIL - !!!WARNING WARNING WARNING!!***&lt;/h1&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;Ok, hopefully that warning is big enough and flashy enough and scary enough that *all* of my readers will PAY ATTENTION to the warning.&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;By a combination of circumstances I ended up at a malicious blog being:&lt;br /&gt;&lt;strong&gt;spyware-doctor-2008.blogspot.com/2008/06/desktop-spyware-block-spyware-reduce.html.&amp;nbsp; &lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;(BTW, I should make it clear that the blog in question has *NOTHING* to do with any whitelisted application. The blog page simply happens to mention the name of an application that I was checking on and I stumbled across it thanks to the wonders of modern search engines.&amp;nbsp; There is no association between any TRUSTe whitelisted application and the blog in question.&amp;nbsp; There.. we&amp;#39;re clear on that? Good!)&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;That fun little page has a piece of javascript in the source code that redirects visitors to &lt;strong&gt;c1_spyware-doctor-2008_2336_bs.oughtworld.com/images/header.php&lt;/strong&gt;.&lt;/p&gt; &lt;p&gt;The &lt;strong&gt;bs.oughtworld.com&lt;/strong&gt; site, in turn, pushes us to &lt;strong&gt;spyware-doctor-2008_2336_bs.oughtworld.com/index.html&lt;/strong&gt;, and from there things get a bit random.&lt;/p&gt; &lt;p&gt;Every time I re-tested the &lt;strong&gt;oughtworld.com/index.html&lt;/strong&gt; page, I was redirected to a different site, being one of the following:&lt;/p&gt; &lt;p&gt;&lt;strong&gt;grander5.com/soft.php?aid=0253&amp;amp;d=2&amp;amp;product=XPA&lt;/strong&gt; which redirected to&lt;br /&gt;&lt;strong&gt;freewebscanner.com/2009/1/freescan.php?aid=880253&lt;/strong&gt;  &lt;p&gt;-or- &lt;p&gt;&lt;strong&gt;grander5.com/soft.php?aid=0253&amp;amp;d=2&amp;amp;product=XPC&lt;/strong&gt;&amp;nbsp; which redirected to &lt;strong&gt;online-xpcleaner.com/2/freescan.php?aid=880253&lt;/strong&gt;  &lt;p&gt;-or- &lt;p&gt;&lt;strong&gt;onlinestreamvide.com/freemovie/541/1/&lt;/strong&gt; (which tries to trick visitor into installing a fake video codec)  &lt;p&gt;-or- &lt;p&gt;&lt;strong&gt;avwav.com/2099.htm&lt;/strong&gt; (this site has some encrypted javascript that I haven&amp;#39;t bothered to decode) &lt;p&gt;-or- &lt;p&gt;&lt;strong&gt;windows-scannernv.com/2008/3/_freescan.php?aid=880218&lt;/strong&gt; (a fraudware (fake security software) page) &lt;p&gt;-or- &lt;p&gt;&lt;strong&gt;getmyvideonow.com/exclusive5/id/3913044/5/black/white/0/Video/&lt;/strong&gt; (another site that tries to trick visitors into installing a fake video codec) - WARNING: graphic content via pop-up window &lt;p&gt;&amp;nbsp; &lt;p&gt;After a certain number of visits to the &lt;strong&gt;bs.oughtworld.com/index.html&lt;/strong&gt; page, we start hitting an Error 404 - there is some IP tracking going on, and once you&amp;#39;ve had what the bad guys consider to be your fair share of web content, well, they lock you out. &lt;p&gt;Incidents such as this one make it too easy to draw a connection between various fraud activities, in this case fraudware and online porn and fake video codecs.&amp;nbsp; Yay them. &lt;p&gt;&amp;nbsp; &lt;p&gt;&lt;strong&gt;&lt;u&gt;DOMAIN INFORMATION&lt;/u&gt;&lt;/strong&gt; &lt;p&gt;&lt;strong&gt;oughtworld.com&lt;/strong&gt; - created 3 June 2008, Registrar DIRECTI INTERNET SOLUTIONS PVT LTD.&amp;nbsp; Its Name Server (itsfreedns.com) Registrar is none other than the infamous ESTDOMAINS.  &lt;p&gt;&lt;strong&gt;grander5.com&lt;/strong&gt; - created 7 July 2008, Regisrar DIRECTI INTERNET SOLUTIONS PVT LTD. WHOIS hidden behind privacyprotect.org.&amp;nbsp; I note that &amp;quot;australianembassy.ru&amp;quot; shares IP address with mynick.name - somebody has a sense of humour.  &lt;p&gt;&lt;strong&gt;onlinestreamvide.com&lt;/strong&gt; - created 17 May 2008, Registrar ESTDOMAINS (why are we not surprised?)  &lt;p&gt;&lt;strong&gt;avwav.com&lt;/strong&gt; - created 5 April 2008, Registrar ESTDOMAINS.  &lt;p&gt;&lt;strong&gt;windows-scannernv.com&lt;/strong&gt; - created 22 July 2008, Registrar DIRECTI INTERNET SOLUTIONS, name servers supplied by MYNICK.NAME.&amp;nbsp; WHOIS hidden behind privacyprotect.  &lt;p&gt;&lt;strong&gt;getmyvideonow.com&lt;/strong&gt; - created 7 July 2008, Registrar ESTDOMAINS.&amp;nbsp; Contact email &amp;quot;&lt;strong&gt;iedefender@gmail.com&lt;/strong&gt;&amp;quot; - those with long memories will remember a fraudware called IEDEFENDER.&amp;nbsp; Coincidentally (yes, I am being facetious) the Registrar for iedefender.com is, can you guess?&amp;nbsp;&amp;nbsp; Yep, ESTDOMAINS.  &lt;p&gt;&lt;strong&gt;&lt;u&gt;&lt;/u&gt;&lt;/strong&gt;&amp;nbsp; &lt;p&gt;&lt;strong&gt;&lt;u&gt;While we are on the topic of iedefender@gmail.com&lt;/u&gt;&lt;/strong&gt; &lt;p&gt;Other sites/fraudware associated with &lt;a href="mailto:iedefender@gmail.com"&gt;iedefender@gmail.com&lt;/a&gt;, discovered after just a few minutes digging include: &lt;p&gt;&lt;strong&gt;free-viruscan.com&lt;br /&gt;getvideoc.com&lt;br /&gt;downloaditrightnow.com&lt;br /&gt;files-secure.com&lt;br /&gt;fast-viruscanner.com&lt;/strong&gt;  &lt;p&gt;My gentle readers may take some amusement from this URL - &amp;quot;IE Defender Folks Playing Games&amp;quot;&lt;br /&gt;&lt;a href="http://blog.malwareteks.com/ie-defender-folks-playing-games/"&gt;http://blog.malwareteks.com/ie-defender-folks-playing-games/&lt;/a&gt; &lt;p&gt;&amp;nbsp; &lt;p&gt;The following is very interesting - the language is, apparently, Ukranian.&amp;nbsp; Promonaut is talking about malwarebytes.&amp;nbsp; Anybody want to translate? I have an archive of the whole page, just in case it disappears ;o) &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_d82987fb_2D00_8cea_2D00_448a_2D00_bc5e_2D00_c05ce29ffc5b.png" width="538" height="95" /&gt;  &lt;p&gt;URL: &lt;a title="http://promonaut.livejournal.com/223473.html" href="http://promonaut.livejournal.com/223473.html" target="_blank"&gt;http://promonaut.livejournal.com/223473.html&lt;/a&gt;&amp;nbsp; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_da00a9d3_2D00_d27a_2D00_48b5_2D00_acac_2D00_7b6877908e09.png" width="918" height="586" /&gt;  &lt;p&gt;&amp;nbsp; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_07e8a2ae_2D00_54a4_2D00_4939_2D00_a889_2D00_8f0c69127f4f.png" width="718" height="767" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641878" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=aXfLlJ"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=aXfLlJ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=vqZ1Yj"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=vqZ1Yj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/343552961" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2008/07/23/1641878.aspx</feedburner:origLink></item><item><title>CNET hit by malvertizements</title><link>http://feeds.feedburner.com/~r/SpywareSucks/~3/338746007/1641310.aspx</link><pubDate>Fri, 18 Jul 2008 06:32:48 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641310</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/07/18/1641310.aspx#comments</comments><description>&lt;p&gt;Why is it that after I pontificate that &amp;quot;&lt;em&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2008/07/15/1640737.aspx" target="_blank"&gt;pushers of malvertizing are finding it harder and harder to get their wares on to high profile, high traffic sites&lt;/a&gt;&lt;/em&gt;&amp;quot; we receive word that &lt;a href="http://forums.cnet.com/5208-7598_102-0.html?forumID=51&amp;amp;threadID=300898&amp;amp;start=0" target="_blank"&gt;CNET was hit&lt;/a&gt;?&amp;nbsp; That&amp;#39;ll teach me to keep my mouth shut won&amp;#39;t it :o)&lt;/p&gt; &lt;p&gt;Ok, this is a new dialogue box - it appeared when I tried to close the fraudware site window ... yes, clicking on OK does seem to open the Add Favorites window, but who knows what else it may be doing in the background&amp;nbsp; - I still recommend that you use the Red X to close the dialogue box.&lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_af0e7ba5_2D00_cd77_2D00_41d4_2D00_b8c6_2D00_6ac78c5fbeab.png" width="679" height="405" /&gt; &lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;Thanks to Donna for the heads up:&lt;br /&gt;&lt;a title="http://www.dozleng.com/updates/index.php?showtopic=16111" href="http://www.dozleng.com/updates/index.php?showtopic=16111" target="_blank"&gt;http://www.dozleng.com/updates/index.php?showtopic=16111&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641310" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=jgyScJ"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=jgyScJ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=A3bCpj"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=A3bCpj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/338746007" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2008/07/18/1641310.aspx</feedburner:origLink></item><item><title>Spyware Sucks rated 8.3 (Great) on Blogged.com</title><link>http://feeds.feedburner.com/~r/SpywareSucks/~3/338587393/1641295.aspx</link><pubDate>Fri, 18 Jul 2008 02:04:41 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641295</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/07/18/1641295.aspx#comments</comments><description>&lt;p&gt;How cool is this?&amp;nbsp; I just spotted this email in my overloaded inbox.&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;&amp;quot;&lt;em&gt;Dear Spyware Sucks author, &lt;/em&gt;&lt;/p&gt; &lt;p&gt;&lt;em&gt;Our editors recently reviewed your blog and have given it an 8.3 score out of (10) in the Technology/Internet category of Blogged.com.&amp;nbsp; This is quite an achievement! &lt;/em&gt; &lt;p&gt;&lt;em&gt;&lt;a href="http://www.blogged.com/directory/technology/internet" target="_blank"&gt;http://www.blogged.com/directory/technology/internet&lt;/a&gt;&lt;/em&gt; &lt;p&gt;&lt;em&gt;We evaluated your blog based on the following criteria: Frequency of Updates, Relevance of Content, Site Design, and Writing Style. &lt;br /&gt;After carefully reviewing each of these criteria, your site was given its 8.3 score [out of a possible score of 10].&lt;/em&gt;&amp;quot;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;Nice :o) &lt;p&gt;Spyware Sucks resides in the sub-category of &lt;a href="http://www.blogged.com/directory/technology/internet/internet-security" target="_blank"&gt;Internet Security&lt;/a&gt;. &lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641295" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=5LonbJ"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=5LonbJ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=eF4qOj"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=eF4qOj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/338587393" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Admin+announcements/default.aspx">Admin announcements</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2008/07/18/1641295.aspx</feedburner:origLink></item><item><title>Press Release: New Internet Safety Web content provides valuable information for teens, parents, educators and seniors</title><link>http://feeds.feedburner.com/~r/SpywareSucks/~3/338587394/1641292.aspx</link><pubDate>Fri, 18 Jul 2008 01:50:23 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641292</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/07/18/1641292.aspx#comments</comments><description>&lt;p&gt;Building on the work of his &lt;a href="http://www.atg.wa.gov/page.aspx?id=18884" target="_blank"&gt;Youth Internet Safety Task Force&lt;/a&gt; and the &lt;a href="http://www.atg.wa.gov/page.aspx?id=1792" target="_blank"&gt;high-tech unit&lt;/a&gt; in his &lt;a href="http://www.atg.wa.gov/page.aspx?id=1792" target="_blank"&gt;Consumer Protection Division&lt;/a&gt;, Attorney General Rob McKenna today announced a number of updates to his office’s &lt;a href="http://www.atg.wa.gov/InternetSafety.aspx" target="_blank"&gt;Internet Safety&lt;/a&gt; Web pages.  &lt;p&gt;In partnership with national Internet safety expert, Linda Criddle, author of the Internet safety manual &lt;a href="http://www.look-both-ways.com/" target="_blank"&gt;Look Both Ways,&lt;/a&gt; McKenna’s office has added fresh information to its Web site for &lt;a href="http://atg.wa.gov/InternetSafety/Teens.aspx" target="_blank"&gt;youth&lt;/a&gt;, &lt;a href="http://atg.wa.gov/InternetSafety/Adults.aspx" target="_blank"&gt;adults&lt;/a&gt;, &lt;a href="http://atg.wa.gov/InternetSafety/Seniors.aspx" target="_blank"&gt;seniors&lt;/a&gt; and &lt;a href="http://atg.wa.gov/InternetSafety/FamiliesAndEducators.aspx" target="_blank"&gt;educators.&lt;/a&gt;  &lt;p&gt;“&lt;em&gt;The Internet has made life easier for all of us in so many ways, but it’s also made it easier for criminals, scammers and bullies&lt;/em&gt;,” McKenna said.&amp;nbsp; “&lt;em&gt;This new information will help people update their Internet safety regimen and learn ways they may be exposing themselves to ID theft, stalking, scams and other Internet threats.&lt;/em&gt;”  &lt;p&gt;Top tips for &lt;a href="http://www.atg.wa.gov/InternetSafety/Teens.aspx" target="_blank"&gt;youth&lt;/a&gt; include:  &lt;ul&gt; &lt;ul&gt; &lt;li&gt;Your personal information is a commodity: Every piece of information you post, and every action you take online has commercial value to someone. The site shows kids how they put can put personal information at risk just by &lt;a href="http://www.atg.wa.gov/InternetSafety/SocializingOnline.aspx" target="_blank"&gt;taking surveys&lt;/a&gt;, participating in &lt;a href="http://www.atg.wa.gov/InternetSafety/SocializingOnline.aspx" target="_blank"&gt;chat, discussion boards, and forums&lt;/a&gt;, &lt;a href="http://www.atg.wa.gov/InternetSafety/SocializingOnline.aspx" target="_blank"&gt;online dating&lt;/a&gt;, &lt;a href="http://www.atg.wa.gov/InternetSafety/CommunicatingOnline.aspx" target="_blank"&gt;creating personal e-mail aliases&lt;/a&gt;, &lt;a href="http://www.atg.wa.gov/InternetSafety/SharingOnline.aspx" target="_blank"&gt;sharing images and video&lt;/a&gt;, and &lt;a href="http://www.atg.wa.gov/InternetSafety/GamingOnline.aspx" target="_blank"&gt;gaming online&lt;/a&gt;. Then it shows them how to protect themselves.  &lt;li&gt;You can be an &lt;a href="http://www.atg.wa.gov/InternetSafety/IDTheft.aspx" target="_blank"&gt;identity theft victim&lt;/a&gt; without even knowing it. Because youth do not check their credit reports, they are prime targets for thieves who open credit in their names and rack up bills the youth may never learn about until it’s too late. Learn how to protect yourself and ways to repair your credit if it is too late.  &lt;li&gt;Even if you and your friends are careful to protect your identities on-line, you may be &lt;a href="http://www.atg.wa.gov/InternetSafety/Teens.aspx" target="_blank"&gt;exposing yourselves&lt;/a&gt; to predators through chats on your social media pages. The site demonstrates how easy it is for on-line predators to gather information when people are not careful.  &lt;li&gt;&lt;a href="http://www.atg.wa.gov/InternetSafety/Teens.aspx" target="_blank"&gt;Everything you post is permanent.&lt;/a&gt; Once information is posted on the Internet, it can be downloaded and stored indefinitely—even if you take it down—and you have no idea who has viewed it—potential employers, stalkers, classmates, parents.&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt; &lt;p&gt;Information for &lt;a href="http://www.atg.wa.gov/InternetSafety/Adults.aspx" target="_blank"&gt;adults&lt;/a&gt; includes:  &lt;ul&gt; &lt;ul&gt; &lt;li&gt;Ways to be smarter about &lt;a href="http://www.atg.wa.gov/InternetSafety/SpendingSavingOnline.aspx" target="_blank"&gt;spending and saving on-line&lt;/a&gt; like creating strong passwords, identifying secure sites and safely participating in on-line auctions and classifieds;  &lt;li&gt;Tips for &lt;a href="http://www.atg.wa.gov/InternetSafety/DefensiveComputing.aspx" target="_blank"&gt;defensive computing&lt;/a&gt; including things to keep in mind as you browse, download or share information via the Web; and  &lt;li&gt;Things to keep in mind while &lt;a href="http://www.atg.wa.gov/InternetSafety/ComputingOnTheGo.aspx" target="_blank"&gt;mobile computing&lt;/a&gt;, including using public computers and mobile phones.&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt; &lt;p&gt;&lt;a href="http://www.atg.wa.gov/InternetSafety/FamiliesAndEducators.aspx" target="_blank"&gt;Parents and educators&lt;/a&gt; can learn how to protect children with information like:  &lt;ul&gt; &lt;ul&gt; &lt;li&gt;A &lt;a href="http://www.atg.wa.gov/InternetSafety/FamiliesAndEducators.aspx" target="_blank"&gt;checklist for family internet safety&lt;/a&gt;, including a family Internet safety contract;  &lt;li&gt;How to protect kids from &lt;a href="http://www.atg.wa.gov/InternetSafety/FamiliesAndEducators.aspx" target="_blank"&gt;on-line bullies&lt;/a&gt;; and  &lt;li&gt;Unintentional consequences of sharing &lt;a href="http://www.atg.wa.gov/InternetSafety/FamiliesAndEducators.aspx" target="_blank"&gt;student information on-line&lt;/a&gt;, including photos, school sports schedules and other information that could expose students to predators.&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt; &lt;p&gt;The site also includes &lt;a href="http://www.atg.wa.gov/InternetSafety/Seniors.aspx" target="_blank"&gt;tips for seniors&lt;/a&gt; like:  &lt;ul&gt; &lt;ul&gt; &lt;li&gt;How to safely &lt;a href="http://www.atg.wa.gov/InternetSafety/Seniors.aspx" target="_blank"&gt;socialize on-line&lt;/a&gt; and avoid on-line dating scams;  &lt;li&gt;How to avoid scams that prey on &lt;a href="http://www.atg.wa.gov/InternetSafety/FraudOnline.aspx" target="_blank"&gt;emotions&lt;/a&gt; when you are posting information about weddings or deaths; and  &lt;li&gt;Other &lt;a href="http://www.atg.wa.gov/InternetSafety/Seniors.aspx" target="_blank"&gt;specialized advice&lt;/a&gt; for those with limited experience on the Internet.&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641292" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=NAaAdJ"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=NAaAdJ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=ySBsOj"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=ySBsOj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/338587394" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2008/07/18/1641292.aspx</feedburner:origLink></item><item><title>TRUSTe changes from not-for-profit to for-profit</title><link>http://feeds.feedburner.com/~r/SpywareSucks/~3/337485871/1641102.aspx</link><pubDate>Tue, 15 Jul 2008 09:05:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641102</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/07/15/1641102.aspx#comments</comments><description>&lt;p&gt;&lt;strong&gt;Edited to fix typographical errors&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;img height="152" width="150" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/truste_2D00_logo_2D00_square_5F00_9df7f469_2D00_7d21_2D00_42d3_2D00_a904_2D00_fe5c942baf4b.jpg" align="left" alt="truste-logo-square" /&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The news is out - TRUSTe is now a for-profit, instead of a not-for profit.&lt;/p&gt;
&lt;p&gt;As I am sure all of you have noticed, I have been silent about TRUSTe since I started working with them on 16 July 2008.&amp;nbsp; But now, I think, the time has come to speak.&lt;/p&gt;
&lt;p&gt;The number one question being asked of me in my tiny corner of the world, now that the world at large knows that TRUSTe is no longer a not-for-profit,&amp;nbsp; is &amp;quot;&lt;em&gt;Sandi, did you know this was going to happen?&amp;quot;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The answer to the question is yes, I did know that this change was coming.&amp;nbsp; TRUSTe have been completely open and honest with me about their plans.&amp;nbsp; They understood that by associating my name with theirs I was also associating my hard-won good reputation with their reputation, and they wanted to be sure I walked in with my eyes open.&lt;/p&gt;
&lt;p&gt;The next question that is asked of me is &amp;quot;&lt;em&gt;Why did you agree to work with TRUSTe?&lt;/em&gt;&amp;quot;.&amp;nbsp; In personal emails one of my correspondents even described TRUSTe as a scam, and I have been told, more than once, that my own reputation would be harmed by being associated with TRUSTe, and I can understand why they felt such concern.&amp;nbsp; For example, people such as Ben Edelman and Eric Howes have been, and continue to be, very critical of TRUSTe (&lt;a target="_blank" href="http://www.haloscan.com/comments/alexeck/1759652510912038825/#413054"&gt;Eric&amp;#39;s comment&lt;/a&gt; to &lt;a target="_blank" href="http://sunbeltblog.blogspot.com/2008/07/truste-is-now-for-profit.html"&gt;Alex Eckelberry&amp;#39;s blog entry at Sunbelt&lt;/a&gt; about the change from not-for-profit is an excellent example of some of the more negative opinions that are held).&lt;/p&gt;
&lt;p&gt;Anyway, the short answer is that I agreed to work with TRUSTe because TRUSTe and I have some of the same goals, and because TRUSTe (and I) saw within TRUSTe a real need that I can fill.&amp;nbsp; Let me try to explain.&lt;/p&gt;
&lt;p&gt;I have been doing this (&amp;quot;this&amp;quot; being fighting malware and associated misbehaviors on the Internet in its many forms) for many years - since early 2000.&amp;nbsp; In fact, this October I am up for my 10th Microsoft MVP Award in a row.&amp;nbsp;&amp;nbsp; My world - my sphere of concern, of interest, and of influence - encompasses not only the end user but also the anti-virus and anti-spyware community, and businesses and persons who earn a living from &amp;quot;the Internet&amp;quot;.&amp;nbsp; I have had to face up to, and settle within myself to the best of my ability, the inevitable conflicts of interest that arise when I consider the wants and needs of all of those different parties and I cannot pretend that it has not been a challenge.&lt;/p&gt;
&lt;p&gt;Just one facet of my struggle has been reconciling the needs and wants of the end user with the needs and wants of the businesses that service them.&amp;nbsp; Over the years, and especially during recent times, I have corresponded with, and spoken in person to, several &amp;quot;bad actors&amp;quot; (aka adware purveyors) who have been working to improve their software&amp;#39;s behavior, and one message has come through loud and clear, which is that they often encounter, and are discouraged by, what they perceive as a lack of forgiveness on the part of some members of the security/antispyware community.&amp;nbsp; The strongest impression that I am left with is that the attitude they face is one of &amp;quot;once a sinner, always a sinner&amp;quot; - calls are not returned, emails are not acknowledged, attempts at explanation are rejected, and attempts to get improvements acknowledged and, when justified, changes made to antivirus/antispyware software to stop it from flagging and removing the software that has changed its behavior have been discouragingly difficult to achieve.&lt;/p&gt;
&lt;p&gt;My personal opinion is that the &amp;quot;once a sinner, always a sinner&amp;quot; attitude is wrong.&amp;nbsp; To treat &amp;quot;bad actors&amp;quot; as evil personified or not worthy of forgiveness or redemption when they are trying to change their ways, is discouraging at best, and at worst may lead them to throw up their hands and say &amp;quot;&lt;em&gt;why bother trying to change if I&amp;#39;m going to be stuck on the blacklist forever anyway&amp;quot;&lt;/em&gt;.&amp;nbsp; If that happens, what good have we, the champions for the end user, really done?&lt;/p&gt;
&lt;p&gt;Another thing that has been communicated to me over the years is that, sometimes, the demands of the security community may directly harm a business&amp;#39;s right to protect itself from piracy or misuse/abuse of its software.&lt;/p&gt;
&lt;p&gt;For example, let&amp;#39;s look at trial software.&amp;nbsp;&amp;nbsp; If such software leaves behind a registry key, or a hidden file, that is used to prevent the reinstallation of time-limited software, and that key or file has a deliberately obscure name, is that necessarily wrong?&amp;nbsp; Should the fact that a registry key or file being left behind on uninstall be disclosed to the user, even if it means that such disclosure will make it easier for the user to bypass anti-piracy protection?&amp;nbsp; This is just one of the problems I have been confronted by, and have had to devote a lot of time and thought to.&amp;nbsp; What do I put first? The right of the end user to be able to easily find everything related to a particular piece of software (and potentially use that knowledge to &amp;#39;play the system&amp;#39;) or do I give priority to a business&amp;#39;s right to avoid piracy of their software?&lt;/p&gt;
&lt;p&gt;Some demand that every file, every folder, every registry key, be removed when software is uninstalled and will accept no reasoning nor excuse for its remaining, even if this means that any protection against misuse of trial software is lost.&amp;nbsp; Is this right?&amp;nbsp; In short, no.&amp;nbsp; We have to find a balance - a sustainable balance between the needs of the end user, and the needs of the business that services them.&lt;/p&gt;
&lt;p&gt;Then there is the question of advertising and adware.&amp;nbsp; To some, all adware is bad.&amp;nbsp; To others, adware is acceptable with full disclosure, but at the same time long spiels of disclosure text are not acceptable.&amp;nbsp; So, how much disclosure is enough, and how should it be communicated?&amp;nbsp; The greater the disclosure, the more the user has to read and acknowledge, and the greater the risk of confusion.&amp;nbsp; For what its worth, my personal opinion is that the traditional requirement that an EULA be displayed and acknowledged should be discarded.&amp;nbsp; Instead, a succinct list of important points should be displayed, with further detail (aka the full EULA) to be made available on clicking a link.&amp;nbsp; Or, the most important words in an EULA should be highlighted in bold font to draw the eye.&lt;/p&gt;
&lt;p&gt;How does all of the above tie in with why I decided to work with TRUSTe?&amp;nbsp; I&amp;#39;m getting to that :)&lt;/p&gt;
&lt;p&gt;After many years of watching and talking - of thinking and listening - of agonizing and beating of my breast (ok, I admit it, that last one was deliberately over the top) here are the beliefs on which I stand.&amp;nbsp; I admit that over the years my stance has changed - in the past I have held extremist (and dare I say unrealistic) views about software and software behavior, but so be it.&amp;nbsp; As far as I am concerned, the ability to stand up and say &amp;quot;yeah, I was wrong&amp;quot; is just as important as being right:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Adware is not all bad&lt;/strong&gt;.&amp;nbsp; I have said several times over the years that I believe that every (wo)man deserves their wage, and I do not have a problem with software authors earning an income from adware.&amp;nbsp;&amp;nbsp; That being said, I also believe that users of software are entitled to know exactly what the adware is, what it will do, and what effect it will have on their computers and their privacy and they *must* be given a clear opportunity to decline the adware if they so desire.&amp;nbsp; I also believe that those who offer software for download have the right to refuse to supply us with their wares, or limit its functionality, if we are not willing to accept adware or pay for the software.&amp;nbsp; I do NOT believe that anybody has the right to try and get around such requirements.&amp;nbsp; We do not have a God-given right get stuff for free, or to play the system, just because we found it on the Internet (yeah yeah, just so you know I don&amp;#39;t download movies off the Internet, or burn copies of CDs or DVDs or use pirated software - sucks to be me, but I put my money where my mouth is - do as I do, not just as I say).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Advertising is not all bad.&amp;nbsp; &lt;/strong&gt;Once again, I believe that every (wo)man deserves their wage.&amp;nbsp; Reality is that it costs money to build and maintain a web site, and make it available to the masses.&amp;nbsp; The alternative to advertising is for web sites to move to a user pays, access by registration only, model, and that is something I do NOT want to see.&amp;nbsp; I do not use ad blockers and only recommend that web page advertising be blocked when the web site in question is displaying malvertizing, and that web site has refused to address the problem&amp;nbsp; after being warned - safety must come first).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&amp;quot;The Internet&amp;quot;, as the average user understands it, can not survive on philanthropy&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Good Internet behavior should be acknowledged and encouraged&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Work to rehabilitate and then forgive.&amp;nbsp; &lt;/strong&gt;Without a chance at redemption we eventually succumb to exhaustion and the temptation to continue down the path we have been treading.&amp;nbsp; It is wrong to be so unwaveringly hard on somebody that they despair of forgiveness.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;After many emails and phone calls I can say that I honestly believe that my beliefs and stance, and the beliefs and stance of those who work under the TRUSTe banner, can walk in tandem.&amp;nbsp; And I do not easily lay my reputation on the line.&amp;nbsp; It was hard fought for, and hard won.&amp;nbsp; I am very aware that my readers&amp;#39; trust has been hard gained and can be easily lost but I truly believe that TRUSTe are not the &amp;quot;public relations front for privacy abusive online companies&amp;quot; that some believe them to be.&amp;nbsp; TRUSTe have lofty goals, and the best of intentions, and deserve my support.&lt;/p&gt;
&lt;p&gt;My personal opinion is that an important piece of the TRUSTe message and mission is missing from the public perception.&amp;nbsp; A lot of people have focused on who TRUSTe has certified (and that certified party&amp;#39;s pre-existing reputation), and TRUSTe&amp;#39;s failures and missteps over the years, but how many have sat down and deeply considered the question of, or had a substantial one-on-one heart-to-heart with somebody at TRUSTe about, *WHY* TRUSTe does what it does and what its end goal is?&amp;nbsp; Well, I did just that, and after all the talking and all the listening I believe that a primary goal of TRUSTe, in my own words, is to &lt;strong&gt;acknowledge and encourage good behavior; to rehabilitate, support and guide companies in the transition from bad netizen to good netizen, and to offer a chance at redemption and forgiveness, while at the same time maintaining a framework to discipline offenders.&amp;nbsp; &lt;/strong&gt;TRUSTe aims to encourage best practice, to encourage businesses to continue working toward a lofty standard, and they offer bad actors the chance of redemption.&amp;nbsp; That is why I agreed to work with them, even though that means putting my own reputation on the line.&amp;nbsp; Of course, by doing all of this TRUSTe put their own (and my) reputation on the line every time that they certify (even provisionally) an ex-bad actor, but that is the risk that they (and I) must take.&lt;/p&gt;
&lt;p&gt;I don&amp;#39;t want to be the unforgiving disciplinarian who is always wielding the big stick, and always hitting my correspondent over the head with the fact that they did bad things in the past, and I don&amp;#39;t want TRUSTe to be that either.&amp;nbsp; I see no long term benefit.&lt;/p&gt;
&lt;p&gt;I will end with a commentary about the change from not-for-profit to for-profit.&amp;nbsp; I recently spent a week at TRUSTe&amp;#39;s office in San Francisco, working with the team behind the Trusted Download Program, and I was there when the change from not-to-profit to for-profit was in its final stages - I was in the room when the announcement was made to all staff and I have spoken in person with Fran Maier as well as TRUSTe management and employees about their dreams and goals and plans for TRUSTe and the effect that the change will have on day to day operations.&amp;nbsp; It saddens me to see anybody allege that now that TRUSTe is a &amp;#39;for-profit&amp;#39; that TRUSTe (and by association the people behind it) are only in it for the money, because I have seen no sign that such an allegation is true.&lt;/p&gt;
&lt;p&gt;I have had far more time to consider this change, to talk to TRUSTe, to ask the hard questions and consider the responses I have received - by phone, by email and in one-on-one conversations where I can look them in the eye and watch them as they respond - than have most, if not all, commentators on this change.&amp;nbsp; I see an opportunity for TRUSTe to improve and grow, not only to offer more services to clients but also, most importantly from my perspective, improve compliance monitoring.&amp;nbsp; After all, that is why they brought me on board.&amp;nbsp; And I can tell you this - every time I have brought an issue to TRUSTe&amp;#39;s attention they have acted on the information I have supplied, and I have been happy with the steps that they have taken.&amp;nbsp; Every...single...time.&amp;nbsp;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&amp;quot;What issues?&amp;quot; I hear you say.&amp;nbsp;&amp;nbsp; Sadly, I am not in a position to share specifics - you will have to take my word on trust (no pun intended).&amp;nbsp;&amp;nbsp; I can only hope that I have, over the years, proven myself to be trustworthy in your eyes, and that you will give me, and TRUSTe, the benefit of the doubt.&lt;/p&gt;
&lt;p&gt;For now, I need some rest.&lt;/p&gt;
&lt;p&gt;Sandi.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641102" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=OoFb6J"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=OoFb6J" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=sta6Vj"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=sta6Vj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/337485871" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/General+stuff/default.aspx">General stuff</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2008/07/15/1641102.aspx</feedburner:origLink></item><item><title>A malvertizement featuring XE Radio rears its head again</title><link>http://feeds.feedburner.com/~r/SpywareSucks/~3/335712397/1640838.aspx</link><pubDate>Tue, 15 Jul 2008 03:43:02 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1640838</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/07/15/1640838.aspx#comments</comments><description>&lt;p&gt;Interestingly, the malvertizement features the same campaign as the &lt;a href="http://www.bluetack.co.uk/forums/index.php?s=622a909e954e0ecf3bafa8fde857c3cf&amp;amp;showtopic=18064&amp;amp;st=90&amp;amp;p=88026&amp;amp;#entry88026" target="_blank"&gt;MediaMan malvertizement&lt;/a&gt; that Kimberley found on isuisse, iquebec, ibelgique and ifrance back on 10 July.&lt;/p&gt; &lt;p&gt;Screenshots of the XM Radio malvertizement:&lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_ef17b8d6_2D00_ede3_2D00_4191_2D00_9eaf_2D00_2d57f75642b9.png" width="734" height="96" /&gt; &lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_a65b03c8_2D00_4978_2D00_4497_2D00_aaad_2D00_a90b69a0f176.png" width="738" height="95" /&gt; &lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_43f7d4f2_2D00_bc47_2D00_4e50_2D00_96c3_2D00_3846cbbe42f2.png" width="735" height="95" /&gt; &lt;/p&gt; &lt;p&gt;We see various domains when hit by a malicious redirect, including:&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;stathisranch.net/crossdomain.xml &lt;/strong&gt; &lt;p&gt;&lt;strong&gt;stathisranch.net/c/index.php?&amp;lt;&amp;lt;removed&amp;gt;&amp;gt;&lt;/strong&gt;  &lt;p&gt;&lt;strong&gt;profitabill.com/?cmpid=asbarrator&lt;/strong&gt; (this is the same as the MediaMan malvertizement mentioned above) &lt;p&gt;&lt;strong&gt;adnetserver.com/?&amp;lt;&amp;lt;removed&amp;gt;&amp;gt; &lt;/strong&gt; &lt;p&gt;&lt;strong&gt;adverdaemon.com/?&amp;lt;&amp;lt;removed&amp;gt;&amp;gt; &lt;/strong&gt; &lt;p&gt;&lt;strong&gt;antispywaremaster.com/data/&amp;lt;&amp;lt;removed&amp;gt;&amp;gt; &lt;/strong&gt; &lt;p&gt;&lt;strong&gt;sicherheitstool.com/kontroller/?&amp;lt;&amp;lt;removed&amp;gt;&amp;gt;&lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1640838" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=pzqLOJ"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=pzqLOJ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=kd7EFj"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=kd7EFj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/335712397" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2008/07/15/1640838.aspx</feedburner:origLink></item><item><title>New malvertizement featuring Levis, myownpursuit.com (Lexus) and the re-emergence of Lady Speedstick</title><link>http://feeds.feedburner.com/~r/SpywareSucks/~3/335651685/1640832.aspx</link><pubDate>Tue, 15 Jul 2008 02:11:25 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1640832</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/07/15/1640832.aspx#comments</comments><description>&lt;p&gt;There have been several malvertizements in circulation, being: &lt;p&gt;&amp;nbsp; &lt;p&gt;&lt;strong&gt;unicastads.com/&amp;lt;removed&amp;gt;/728x90.swf &lt;/strong&gt;(the original malicious ad has already replaced with a &amp;#39;clean&amp;#39; one)&lt;br /&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_eac28f1c_2D00_e7ea_2D00_4373_2D00_86ad_2D00_3553610295f4.png" width="738" height="97" /&gt; &lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_a76f1005_2D00_48c2_2D00_4110_2D00_a1c7_2D00_750fb3c392f9.png" width="733" height="98" /&gt; &lt;/p&gt; &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;unicastads.com/&amp;lt;removed&amp;gt;/300x250.swf&lt;/strong&gt; (the original malicious ad has already replaced with a &amp;#39;clean&amp;#39; one)&lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_2f6c6189_2D00_7561_2D00_4c4f_2D00_ab92_2D00_5906daad27c1.png" width="352" height="293" /&gt;&amp;nbsp;&amp;nbsp; &lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_f7ed3ce5_2D00_f4f3_2D00_4038_2D00_9a67_2D00_b4b1b55b9538.png" width="353" height="294" /&gt; &lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;trueffect-cdn.com/&amp;lt;removed&amp;gt;/300x250.swf&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_005b80fc_2D00_b333_2D00_4501_2D00_890d_2D00_6cfd44f056d6.png" width="418" height="300" /&gt;&amp;nbsp; &lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_06167bd3_2D00_bf97_2D00_4b2c_2D00_90d0_2D00_7fa14c416586.png" width="418" height="299" /&gt; &lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;trueffect-cdn.com/&amp;lt;removed&amp;gt;/728x90.swf&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_8ffed748_2D00_fdad_2D00_4838_2D00_873f_2D00_76aa7bebac8c.png" width="743" height="124" /&gt;&amp;nbsp;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;pointroll-ads.com/&amp;lt;removed&amp;gt;/300x250.swf?&lt;/strong&gt; &lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_611d9a79_2D00_165e_2D00_4e7f_2D00_bc59_2D00_852e2dc52a8b.png" width="302" height="250" /&gt; &lt;/p&gt; &lt;p&gt;&amp;nbsp; &lt;p&gt;&lt;strong&gt;unicastads.com&lt;/strong&gt; is registered via Estdomains, as is &lt;strong&gt;trueffect-cdn.com&lt;/strong&gt; and &lt;strong&gt;pointroll-ads.com&lt;/strong&gt;.  &lt;p&gt;&amp;nbsp; &lt;p&gt;At time of writing, the Levis malvertizement is leading users to fraudware sites, including &amp;quot;&lt;strong&gt;Vista Antivirus 2008&lt;/strong&gt;&amp;quot;.&amp;nbsp; The pointroll-ads.com SWF also leads victims to fraudware sites, including &lt;strong&gt;tds.internetsecuritydeluxe.com&lt;/strong&gt;/&amp;lt;removed&amp;gt;.&amp;nbsp; I fully expect these two advertisements, now they have been &amp;#39;outed&amp;#39; to also be &amp;#39;cleaned&amp;#39;. &lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1640832" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=meMcOJ"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=meMcOJ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=4PGeWj"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=4PGeWj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/335651685" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2008/07/15/1640832.aspx</feedburner:origLink></item><item><title>Watch out for these malvertizements...</title><link>http://feeds.feedburner.com/~r/SpywareSucks/~3/335175909/1640742.aspx</link><pubDate>Mon, 14 Jul 2008 15:12:39 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1640742</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/07/15/1640742.aspx#comments</comments><description>&lt;p&gt;&lt;strong&gt;I have not seen a malvertizement featuring this site before - muchmusic.com&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_673f9641_2D00_3400_2D00_4ac8_2D00_9897_2D00_3df99ad8ba99.png" width="450" height="52" /&gt; &lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_8cde5b70_2D00_6ae0_2D00_430b_2D00_ab02_2D00_49d7d76340ae.png" width="450" height="50" /&gt; &lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;dreammates.com - this one dumped me at virusremover2008.com (domain created on 20 May 2008)&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_51841baa_2D00_3f41_2D00_41c0_2D00_97e7_2D00_5b4054c19a93.png" width="798" height="430" /&gt; &lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_2b8f9225_2D00_de03_2D00_45c3_2D00_9db7_2D00_f0d6e1a77aec.png" width="803" height="429" /&gt; &lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_697510e4_2D00_dd4b_2D00_4ccb_2D00_a5b1_2D00_138d4dec4691.png" width="801" height="429" /&gt; &lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_d85c43a1_2D00_cf0a_2D00_4312_2D00_9692_2D00_3a486a96e039.png" width="799" height="428" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1640742" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=hiIq7J"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=hiIq7J" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=m26jKj"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=m26jKj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/335175909" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2008/07/15/1640742.aspx</feedburner:origLink></item><item><title>Developments in the malvertizing world - a new distribution conduit involving MySpace</title><link>http://feeds.feedburner.com/~r/SpywareSucks/~3/335155627/1640737.aspx</link><pubDate>Mon, 14 Jul 2008 14:42:43 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1640737</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/07/15/1640737.aspx#comments</comments><description>&lt;p&gt;Kimberley writes about a new distribution conduit that she has found - in this example it is an old malvertizement with a currently inactive campaign.&lt;/p&gt; &lt;p&gt;Details here:&amp;nbsp; &lt;a title="index.php-s=&amp;amp;showtopic=18064&amp;amp;view=findpost&amp;amp;p=88161" href="http://www.bluetack.co.uk/forums/index.php?s=&amp;amp;showtopic=18064&amp;amp;view=findpost&amp;amp;p=88161" target="_blank"&gt;Bluetack Forum&lt;/a&gt;&lt;/p&gt; &lt;p&gt;In short, funmunch.com is offering a &amp;quot;MySpace Banner&amp;quot; for download that is, in fact, a malvertizement (an old one, but still a malvertizement). &lt;/p&gt; &lt;p&gt;Here&amp;#39;s the question - why would funmunch.com make the banner available for download in the first place, presumably without being paid for it, and why would they have left it there after the inevitable complaints were received (of course, we&amp;#39;re assuming that MySpace users actually downloaded and used the SWF file, and that victims (sorry, visitors) to the MySpace pages were savy enough to work out how they being hijacked).&lt;/p&gt; &lt;p&gt;Coincidentally, a &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2008/05/09/1617880.aspx#1640679" target="_blank"&gt;Jane McIntyre posted a comment to my blog&lt;/a&gt;, advising that she had been hijacked while surfing MySpace, and dumped at maxconvert.com (hosted in the Ukraine).&amp;nbsp; I have highlighted maxconvert.com before, and it was discovered that maxconvert.com&amp;nbsp; shares A records with promoplexer.com (a domain associated with fraudware) - a peak at that domain revealed associations with macsweeper and cleantor (both fraudware).&lt;/p&gt; &lt;p&gt;I&amp;#39;m not surprised that the criminals behind malvertizements are using whatever conduit they can to distribute their wares.&amp;nbsp; As advertising networks have gotten better at spotting dodgy advertisements and as the networks pressure their clients (even &amp;#39;self managing&amp;#39; clients) to check advertising when it is accepted, and as the major web sites have also become more cautious when accepting advertising, and as the names/domains behind malvertizements become more well known, I get the feeling that the pushers of malvertizing are finding it harder and harder to get their wares on to high profile, high traffic sites, with the result being that they are having to pimp their ads to lower traffic, less well known sites where, thankfully, the impact of malvertizing is proportionally lower.&lt;/p&gt; &lt;p&gt;Now, if only we could get MySpace to clean up their act...&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1640737" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=0ly5ZJ"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=0ly5ZJ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=xUucPj"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=xUucPj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/335155627" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2008/07/15/1640737.aspx</feedburner:origLink></item><item><title>Off topic: World's oldest blogger dies...</title><link>http://feeds.feedburner.com/~r/SpywareSucks/~3/334733065/1640681.aspx</link><pubDate>Mon, 14 Jul 2008 03:05:39 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1640681</guid><dc:creator>sandi</dc:creator><slash:comments>1</slash:comments><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/07/14/1640681.aspx#comments</comments><description>&lt;p&gt;How sad, even though it is an event that comes to us all.&lt;/p&gt; &lt;p&gt;An Australian lady credited as being the oldest blogger in the world, Olive Riley, died on Saturday - her blog was a lovely thing to read.&lt;/p&gt; &lt;p&gt;Although her blog, &lt;a title="www.allaboutolive.com.au" href="http://www.allaboutolive.com.au"&gt;www.allaboutolive.com.au&lt;/a&gt;, seems to no longer exist (there is no A Record and according to domain tools, no web site), but you can can get a taste of what she wrote about at a temporary blog set up by a friend called &amp;quot;&lt;a href="http://worldsoldestblogger.blogspot.com/" target="_blank"&gt;World&amp;#39;s Oldest Blogger&lt;/a&gt;&amp;quot;.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1640681" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=9Z8e0J"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=9Z8e0J" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=n4ETAj"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=n4ETAj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/334733065" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Off+topic/default.aspx">Off topic</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2008/07/14/1640681.aspx</feedburner:origLink></item><item><title>The Sun Java installer still sucks....</title><link>http://feeds.feedburner.com/~r/SpywareSucks/~3/330748863/1639966.aspx</link><pubDate>Wed, 09 Jul 2008 12:34:10 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1639966</guid><dc:creator>sandi</dc:creator><slash:comments>9</slash:comments><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/07/09/1639966.aspx#comments</comments><description>&lt;p&gt;I was prompted to install the latest update to Sun Java a short while ago, and the installer still sucks.&lt;/p&gt; &lt;ol&gt; &lt;li&gt;The installer still triggers a UAC prompt.&lt;/li&gt; &lt;li&gt;The installer still does NOT remove old versions of Java - old versions that take 136 megabytes per version.&lt;br /&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_1f1fcaa7_2D00_cb0f_2D00_4747_2D00_bc93_2D00_c2855882b62b.png" width="670" height="39" /&gt; &lt;/li&gt; &lt;li&gt;&lt;strong&gt;The option to install Open Office is still enabled by default&lt;/strong&gt;, and the English language skills of whoever it was that coded the text on the installer screen need attention.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;I swear, if I see a press releases trumpeting an increase in &amp;quot;users&amp;quot; of OpenOffice... &lt;br /&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_78d98395_2D00_8e47_2D00_470c_2D00_ac2c_2D00_e61d88763854.png" width="651" height="496" /&gt; &lt;/li&gt; &lt;li&gt;There is still no cancel button, and the openoffice.org graphic sucks ... look how pixelated the text and graphics are.&lt;br /&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_19138326_2D00_f7c9_2D00_4661_2D00_80cb_2D00_cf9fb23bf6dc.png" width="663" height="512" /&gt; &lt;/li&gt;&lt;/ol&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639966" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=mdOesJ"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=mdOesJ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=npl9pj"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=npl9pj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/330748863" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2008/07/09/1639966.aspx</feedburner:origLink></item><item><title>ALERT: new malvertizement protocols, courtesy of Kimberley</title><link>http://feeds.feedburner.com/~r/SpywareSucks/~3/330521391/1639920.aspx</link><pubDate>Wed, 09 Jul 2008 06:30:42 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1639920</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/07/09/1639920.aspx#comments</comments><description>&lt;p&gt;As always, Kimberley&amp;#39;s report makes for fascinating reading:&lt;/p&gt; &lt;p&gt;&lt;a href="http://www.bluetack.co.uk/forums/index.php?s=&amp;amp;showtopic=18064&amp;amp;view=findpost&amp;amp;p=88026" target="_blank"&gt;http://www.bluetack.co.uk/forums/index.php?s=&amp;amp;showtopic=18064&amp;amp;view=findpost&amp;amp;p=88026&lt;/a&gt;&lt;/p&gt; &lt;p&gt;What is especially interesting is that the advertisement in question that started the whole thing was NOT a SWF - it was a GIF - hosted by 247mediadirect.com.&amp;nbsp; The end target, a malicious SWF, is hosted at the same IP.&lt;/p&gt; &lt;p&gt;Hosted (again) in Malaysia, a Robtex search reveals many connections between 247mediadirect.com and known malvertizement domains:&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Hostnames sharing IP with A-Records&lt;/strong&gt;&lt;br /&gt;ns1.aboutstat.com | ns1.adlbrite.com | ns1.akamahi.net | ns1.entrerrenglonadura.com | ns1.googiesindication.com | ns1.newstat.net | ns1.officialstat.com | ns1.quinquecahue.com | ns1.stat-diagnostic-imaging.net | ns1.statetstr.com | ns1.stathisranch.net | ns1.stathome.net | ns1.staticglobalsources.com | ns1.staticglobalsources.net | ns1.station-appraisals.com | ns1.station-appraisals.net | ns1.statnation.net | ns1.statsla.net | ns1.statworld.net | ns1.thetechnorati.com | ns1.vozemiliogaranon.com&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Domains using this as nameserver&lt;br /&gt;&lt;/strong&gt;aboutstat.com | adlbrite.com | akamahi.net | entrerrenglonadura.com | googiesindication.com | newstat.net | officialstat.com | quinquecahue.com | stat-diagnostic-imaging.net | statetstr.com | stathisranch.net | stathome.net | staticglobalsources.com | staticglobalsources.net | station-appraisals.com | station-appraisals.net | statnation.net | statsla.net | statworld.net | thetechnorati.com | vozemiliogaranon.com &lt;p&gt;&lt;strong&gt;WHOIS:&lt;/strong&gt; &lt;p&gt;Registrant: Media Hosting Ltd. 32 Jacka Blvd St Kilda VIC, Melbourne 3182 AU +61-03-9534-52830  &lt;p&gt;Domain Name: 247MEDIADIRECT.COM  &lt;p&gt;Administrative Contact: Pearson, Ross rpearson79@yahoo.com 32 Jacka Blvd St Kilda VIC, Melbourne 3182 AU +61-03-9534-52830  &lt;p&gt;Technical Contact: Pearson, Ross rpearson79@yahoo.com 32 Jacka Blvd St Kilda VIC, Melbourne 3182 AU +61-03-9534-52830 &lt;p&gt;247mediadirect.com was created on 18 May 2008. &lt;p&gt;The WHOIS information looks legitimate, BUT, the phone number has one too many digits for Melbourne (or the whole of Australia for that matter), and as far as I can tell there is no such company as Media Hosting Ltd - and the address is a parking area close to the ocean. &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_4945c472_2D00_94de_2D00_4978_2D00_b4de_2D00_88cbbd3269b2.png" width="357" height="290" /&gt;  &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_64c19740_2D00_3704_2D00_4569_2D00_b307_2D00_40e25fb89a50.png" width="492" height="339" /&gt;  &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_ce93984d_2D00_019e_2D00_420d_2D00_a2a5_2D00_cf46a6390298.png" width="688" height="472" /&gt;  &lt;p&gt;The building that you see in the picture is &amp;quot;Donovans&amp;quot;, a restaurant: &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_8add74ae_2D00_64c2_2D00_4283_2D00_8345_2D00_4732e670e44e.png" width="405" height="418" /&gt;  &lt;p&gt;BTW, we have seen 247mediadirect.com before (back in January):&lt;br /&gt;&lt;a title="http://www.bluetack.co.uk/forums/lofiversion/index.php/t18306.html" href="http://www.bluetack.co.uk/forums/lofiversion/index.php/t18306.html" target="_blank"&gt;http://www.bluetack.co.uk/forums/lofiversion/index.php/t18306.html&lt;/a&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639920" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=Y1kZJJ"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=Y1kZJJ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=OGgsVj"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=OGgsVj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/330521391" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2008/07/09/1639920.aspx</feedburner:origLink></item><item><title>ALERT: malvertizement featuring classmates.com</title><link>http://feeds.feedburner.com/~r/SpywareSucks/~3/330301084/1639882.aspx</link><pubDate>Wed, 09 Jul 2008 00:32:28 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1639882</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/07/09/1639882.aspx#comments</comments><description>&lt;p&gt;Campaign URLS (you will note that the campaign is identical to the one for the Skype malvertizement): &lt;p&gt;&lt;strong&gt;waytotheprofit.com/?cmpid=contangogo&lt;br /&gt;station-appraisals.com/c/index.php?id=&amp;lt;&amp;lt;removed&amp;gt;&amp;gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_09f761ed_2D00_5d0c_2D00_4d59_2D00_9878_2D00_0deb07b1891d.png" width="734" height="95" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639882" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=YgLAGJ"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=YgLAGJ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=rojgmj"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=rojgmj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/330301084" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2008/07/09/1639882.aspx</feedburner:origLink></item><item><title>ALERT: Malvertizement featuring Skype</title><link>http://feeds.feedburner.com/~r/SpywareSucks/~3/330293492/1639879.aspx</link><pubDate>Wed, 09 Jul 2008 00:17:23 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1639879</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/07/09/1639879.aspx#comments</comments><description>&lt;p&gt;No company is safe from impersonation....&lt;/p&gt; &lt;p&gt;Campaign URLS:&lt;/p&gt; &lt;p&gt;&lt;strong&gt;waytotheprofit.com/?cmpid=contangogo&lt;br /&gt;station-appraisals.com/c/index.php?id=&amp;lt;&amp;lt;removed&amp;gt;&amp;gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_fa109a8c_2D00_0d63_2D00_47c5_2D00_8764_2D00_5120fc875635.png" width="729" height="92" /&gt; &lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_0236e39c_2D00_8431_2D00_4b25_2D00_884c_2D00_e84641c05548.png" width="732" height="91" /&gt; &lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_3e87efad_2D00_5dc7_2D00_47a3_2D00_97ac_2D00_19e5be00ac93.png" width="752" height="94" /&gt; &lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;The &lt;strong&gt;waytotheprofit&lt;/strong&gt; URL leads us to an &lt;strong&gt;adverdaemon.com&lt;/strong&gt; URL, and from there to the fraudware site - I ended up at a German site, being &lt;strong&gt;sicherheitstool.com.&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Robtex reports that &amp;quot;&lt;em&gt;sicherheitstool.com is a domain controlled by two nameservers at sicherheitstool.com themselves. They are on the same IP network. Incoming mail for sicherheitstool.com is handled by one mailserver which are also at sicherheitstool.com. sicherheitstool.com has one IP record . virusvakt.com, winanonymous.com, avsystemcare.com and at least seven other hosts point to the same IP.&lt;/em&gt;&amp;quot;&lt;/p&gt; &lt;p&gt;sicherheitstool.com is hosted by &lt;strong&gt;Webair Internet Development Inc (&lt;/strong&gt;&lt;a title="http://www.webair.com/" href="http://www.webair.com/" target="_blank"&gt;&lt;strong&gt;http://www.webair.com/&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;).&amp;nbsp; &lt;/strong&gt;Feel free to complain to them ;o)&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Hostnames sharing IP with A-Records&lt;/strong&gt;&lt;br /&gt;anchisupaisutsu.com | .anchiwamu2008.com | .antiespiadorado.com | .antispionagepro.com | .antispywaresuite.com | .antivirusforalle.com | .antiviruspcsuite.com | .antiworm2008.com | .avsystemshield.com | .bugdokter.com | .debellaworm2008.com | .defensaantimalware.com | .discosemerros.com | .diskfejlfri.com | .diskrensare.com | .driveproteccion.com | .errorsoshi.com | .fjernervirus.com | .ingavirus.com | .ingenmulighetforvirus.com | .keineviren.com | .kyouikyuuen.com | .maximumantivirus.com | .meinbesterschutz.com | .menacerescue.com | .mistikotitatuipologisti.com | .nettordinateur.com | .onlinepcguard.com | .orantiespion.com | .pcprivacytool.com | .pcrengoringsmaskine.com | .pcsikker.com | .pcveiligheidstool.com | .pcvirusless.com | .plattefehlerfrei.com | .pp-total.com | .privacidadeprotegida.com | .protecaoconfiavel.com | .proteccionconfiable.com | .puliscitutto.com | .rescatedeamenazas.com | .riscattodaminacce.com | .safepctool.com | .shinraihogo.com | .sikkerpcredskap.com | .sistemaimune.com | .skyddsverktyg.com | .smittfri.com | .solutionreg.com | .suiteantispyware.com | .supashuri.com | .suspenzorpc.com | .trojansfiltre.com | .trustedprotection.com | .turvapc.com | .utiledereparation.com | .utilisateursur.com | .virtualpcguard.com | .virusdeteccion.com | .virusfrittsystem.com | .virusstopper.net | .virusuwadame.com | .virusvakt.com | .winanonymous.com | .winsecureav.com | .winspycontrol.com | adioserrores.com | alltiettantivirus.com | anchisupaisutsu.com | anchiwamu2008.com | antiespiadorado.com | antiespionspack.com | antigusanos2008.com | antispionage.com | antispionagepro.com | antispypremium.com | antispywarecontrol.com | antispywareseigyo.com | antispywaresuite.com | antiver2008.com | antivirusaskeladd.com | antivirusgenial.com | antivirusordi.com | antiviruspcpakke.com | antiviruspcsuite.com | antiviruspertutti.com | antivirusscherm.com | antivirussolusjon.com | antiworm2008.com | antiwurm2008.com | aucunsvirus.com | avsystemcare.com | avsystemshield.com | bedreigingsmonitoor.com | bedsteantivirus.com | bereiniger.com | beschermingstool.com | besutohogo.com | bogyotsuru.com | bortmedvirus.com | bugdokter.com | bugsdestroyer.com | debellaworm2008.com | defectshuri.com | diannaoqingjieji.com | discerrorfree.com | discosemerros.com | discosenzaerrori.com | discosinerrores.com | diskfejlfri.com | diskrensare.com | disqudurprotection.com | dokterfix.com | doraibuhogo.com | drivedefender.com | driveproteccion.com | echterschutz.com | effaceurvirus.com | einaprivadesapc.com | elmejorantivirus.com | errclean.com | errorfri.com | errorout.com | errorskydd.com | errorsoshi.com | fehlerbeseitiger.com | fejlrenser.com | fejlreparering.com | felfixare.com | festplattenreiniger.com | fiksfeil.com | filtrodetrojan.com | filtrotroiani.com | fixmenaces.com | fullsystemprotection.com | goldenantispy.com | gorudenanchisupai.com | harddiskvakt.com | harddrevvagt.com | herramientadereparacion.com | hukommelsesbeskytter.com | keinegefahr.com | keinestoerungen.com | konsekieraser.com | kontentsueraser.com | kyoishusei.com | kyouikyuuen.com | liberapc.com | lifelongpc.com | lungavitapc.com | maskinpcpro.com | maximumantivirus.com | megaviruskit.com | megliopc.com | meinbesterschutz.com | melhorpc.com | memoiredefenseur.com | menacerescue.com | menacesecure.com | mendingtool.com | miavcompleto.com | mijnantivirus.com | minnesverktyg.com | mistikotitatuipologisti.com | moncontenuassistant.com | munazifalhasob.com | nettordinateur.com | nientevirus.com | nochanceforvirus.com | nocompromaat.com | noespias.com | norwayvirus.com | nowayvirus.com | nulinfektioner.com | oczyszczaczkomputerza.com | onlinepcguard.com | pasokoneiju.com | pc-prot.com | pcbeskyttelse.com | pcohneviren.com | pcopschoner.com | pcopschoningsstel.com | pcprivacytool.com | pcrengoringsmaskine.com | pcsegura.com | pcsikker.com | pcsikkerhed.com | pcsod.com | pcsuanbukkon.com | pcvirusless.com | pembersihkomputer.com | plattefehlerfrei.com | pp-total.com | privacidadeprotegida.com | privacidadplus.com | proteccionconfiable.com | protectingtool.com | protectioncomplete.com | protejaseudrive.com | protejasudrive.com | protezionesoft.com | puliscitutto.com | puliturasystem.com | regbotemedel.com | regrensere.com | rejishufuku.com | rensningverktyg.com | reparameacas.com | reparamenazas.com | repareja.com | reparetudo.com | rescatedeamenazas.com | riscattodaminacce.com | sanitardiska.com | schijfhersteller.com | schutztool.com | semerros.com | senzaerrori.com | shinraihogo.com | shufukutsuru.com | sikkerpcvaerktoj.com | sininfecciones.com | sistemaimune.com | skyddsverktyg.com | sletingenvirus.com | solutionreg.com | stoltbeskyttelse.com | suiteantispyware.com | supashuri.com | suspenzorpc.com | sysdepannage.com | syskontroller.com | systemesansvirus.com | systemordnare.com | tabortvirus.com | toroianfiruta.com | trojanerfilter.com | trojansfilter.com | trojansfiltre.com | tryggdator.com | turvapc.com | utiledeprotection.com | vacinatotal.com | varrevirus.com | vigilamenazas.com | virenfrierpc.com | virenloescher.com | virenstopper.com | virtual-leatherman.com | virtualpcguard.com | virusdeteccion.com | virusdifesa.com | viruseffaceur.com | virusfjernere.com | virusforsvar.com | virusfrittsystem.com | virusgarde.com | virusschlacht.com | virusseigyo.jp | virusstopper.net | virusudryddet.com | virusuwadame.com | virusvakt.com | virusvanguard.com | wegvonviren.com | winadsiz.com | winanonyme.com | winanonymitet.com | winanonymous.com | winanzen.com | winbescherming.com | windefensa.com | winhogo.com | winpcalmeglio.com | winpcdocteur.com | winpcdoctor.com | winpcdoktor.com | winpckontroll.com | winpcrensare.com | winpcrensere.com | winriservatezza.com | winsecureav.com | winsikkerantivirus.com | winsikretav.com | winspycontrol.com | winsurffilter.com | wintemizleyicisi.com | wintrygghet.com | wirusumuryokuka.com | www.antiwurm2008.com | www.avsystemcare.com | www.besutohogo.com | www.ingavirus.com | zebraantivirus.com&lt;/p&gt; &lt;p&gt;&lt;strong&gt;D&lt;/strong&gt;&lt;strong&gt;omains sharing mailservers&lt;/strong&gt;&lt;br /&gt;acchiappavirus.com | adiosvirus.com | allertaminacce.com | antiamenazas.com | antievidence.com | antivirusfiable.com | antivirusforalle.com | antivirusmagique.com | anzentsuru.com | apagahistorico.com | apolloantivirus.com | archivoprotector.com | archivosenestado.com | atemaiserro.com | atrapavirus.com | aucunchoixpourvirus.com | aucunefaute.com | aucuninfection.com | aucunmenace.com | avseguro.com | bandoaivirus.com | bandoalleinfezioni.com | bastioneantivirus.com | beskyttelseonline.com | beskyttendevaerktoj.com | blanchdisc.com | borresuspasos.com | bossedeserreurs.com | brossedesfautes.com | bugseraser.com | caiforavirus.com | chasseurdeserreures.com | cleanpctool.com | confidentsurf.com | confidentuser.com | contenteraser.com | curerrores.com | dataconfidentiality.com | defensecelebre.com | defensededriver.com | defensedinformation.com | defensedudisque.com | defensenetsurfage.com | defensivesystem.com | dejitarufukugen.com | dejitarukyoikira.com | dejitaruwakuchin.com | detapurotekuta.com | detaripea.com | detectaerrores.com | diskassistent.com | disksizesaver.com | disksparare.com | disukushuri.com | driversecurise.com | einwandfreierpc.com | eliminadordeamenazas.com | elmejorantivirus.com | emperahogo.com | enmiendaerrores.com | eracheisa.com | erasutoppu.com | erreurchasseur.com | errorfighter.com | essentialeraser.com | extremuclean.com | fairukyua.com | feilvakt.com | fejlreparering.com | felfixare.com | ferramentasegura.com | festplattentool.com | fiksdinpc.com | filtredetraces.com | fixthemnow.com | fjernervirus.com | foutenwacht.com | geheugenredder.com | guardiandelaprivacidad.com | gubbishremover.com | hackerstaisaku.com | herramientasegura.com | historialout.com | ingavirus.com | ingenmulighetforvirus.com | inmunepc.com | kakujitsutsuru.com | keinespurenlassen.com | keineviren.com | knowhowprotection.com | konsekiauto.com | kontentsufiruta.com | kurinkonseki.com | kyoiireza.com | largavidapc.com | limpietodo.com | lomejorenantivirus.com | longlifepc.com | lungavitapc.com | manutencaopc.com | menacefighter.com | menacemonitor.com | menacescrubber.com | monitordeamenazas.com | mycontentassistant.com | nettoyeurdeserreures.com | nettoyeurdevirus.com | ohnespurensurfen.com | omelhorantivirus.com | onlineverktyg.com | onrainpurotekuta.com | oruripea.com | pasderreurs.com | pasdesfautes.com | pasendommagement.com | pasplusdespertes.com | pasplusdevirus.com | pcantiviruspro.com | pcassertor.com | pcboosterpro.com | pcbunan.com | pceternel.com | pcforfender.com | pchealthkeeper.com | pchjaelper.com | pckairyo.com | pclibredevirus.com | pcpropre.com | pcredskab.com | pcsansbug.com | pcsecuresystem.com | pcsecurise.com | pctoolpro.com | pcultralimpia.com | pcveiligheidstool.com | perfektantivirus.com | preservingtool.com | privacidadyseguridad.com | privacywarrior.com | protecaoconfiavel.com | proteccioncompleta.com | proteccionimperial.com | protecteurdinfo.com | protectionassuree.com | protectionconue.com | protectiondedriver.com | protectiondenetsurfage.com | proteggidati.com | puraibashihosho.com | puraibashitoshinrai.com | rendimientototal.com | rensanu.com | reparaerrores.com | reparemenaces.com | repareya.com | rimuoviciarpame.com | riparaminacce.com | riparasubito.com | safeharddrive.com | safepctool.com | safudaijoubu.com | salvaspaziosudisco.com | sansendommagement.com | sansinfections.com | sayonarabaggu.com | schijfruimteredder.com | schutzderdaten.com | schutzfuerpc.com | secretosasalvo.com | secretoseguro.com | sefunahimitsu.com | sekretessforsvarare.com | senzadoppioni.com | shingaidome.com | shinraihogo.com | shinraipafomansu.com | shisutemudifensu.com | sichererschutz.com | sikkerbrukere.com | sikkerpcredskap.com | sikkersystem.com | sinataques.com | sinrrastros.com | sinsenales.com | sistemaprotegido.com | sistemupyua.com | sisutemuantei.com | sisutemuorugurin.com | skyddsprogram.com | smittfri.com | speichertool.com | stopbedreiging.com | stopminacce.com | storageprotector.com | succesantivirus.com | surfforsure.com | syssauvegarde.com | systemesansfaute.com | systemhoover.com | systemschild.com | tackanejvirus.com | tilforlatelig.com | trasheraser.com | trojansdestroyer.com | trustedantivirus.com | trustedprotection.com | trygpcbruger.com | turnkeyantivirus.com | uk.prevedhosting.net | unidadessanas.com | usuarioprotegido.com | utiledereparation.com | utilisateursur.com | vaktmotvirus.com | virenvernichter.com | virusbekaemper.com | viruskrakker.com | virussperr.com | virusurimuva.com | virusvanger.com | virusvijand.com | volumformatredskap.com | wirusufinisshu.com | wirusukyua.com | wirusushattodaun.com | yourprivacyguard.com | zentaiwakuchin.com&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Domains sharing nameservers&lt;/strong&gt;&lt;br /&gt;acchiappavirus.com | adiosvirus.com | antiamenazas.com | antievidence.com | antivirusfiable.com | antivirusforalle.com | antivirusmagique.com | anzentsuru.com | apagahistorico.com | apolloantivirus.com | archivosenestado.com | atemaiserro.com | atrapavirus.com | aucunchoixpourvirus.com | aucunefaute.com | aucuninfection.com | aucunmenace.com | avseguro.com | bandoalleinfezioni.com | bastioneantivirus.com | beskyttelseonline.com | beskyttendevaerktoj.com | blanchdisc.com | borresuspasos.com | bossedeserreurs.com | brossedesfautes.com | bugseraser.com | chasseurdeserreures.com | cleanpctool.com | cleanuptool.com | confidentsurf.com | confidentuser.com | contenidoseguros.com | contenteraser.com | curerrores.com | dataconfidentiality.com | defensecelebre.com | defensededriver.com | defensedinformation.com | defensedudisque.com | defensivesystem.com | dejitarufukugen.com | dejitarukyoikira.com | dejitaruwakuchin.com | detapurotekuta.com | detaripea.com | detectaerrores.com | diskassistent.com | disksizesaver.com | disksparare.com | disukushuri.com | doubledefender.com | driversecurise.com | einwandfreierpc.com | eliminadordeamenazas.com | emperahogo.com | enmiendaerrores.com | erasutoppu.com | errorfighter.com | essentialeraser.com | extremuclean.com | fairukyua.com | feilvakt.com | fejlfripc.com | fejlreparering.com | felfixare.com | ferramentasegura.com | festplattentool.com | filtredetraces.com | fixthemnow.com | fjernervirus.com | foutenwacht.com | geheugenredder.com | guardiandelaprivacidad.com | gubbishremover.com | hackerstaisaku.com | herramientasegura.com | historialout.com | ingavirus.com | ingenmulighetforvirus.com | inmunepc.com | keinespurenlassen.com | keineviren.com | knowhowprotection.com | konsekiauto.com | kontentsufiruta.com | kurinkonseki.com | kyoiireza.com | largavidapc.com | limpietodo.com | lomejorenantivirus.com | longlifepc.com | lungavitapc.com | manutencaopc.com | menacefighter.com | menacemonitor.com | menacescrubber.com | monitordeamenazas.com | mycontentassistant.com | netsurfageassure.com | nettoyeurdeserreures.com | nettoyeurdevirus.com | ohnespurensurfen.com | omelhorantivirus.com | onlineverktyg.com | onrainpurotekuta.com | oruripea.com | pasderreurs.com | pasdesfautes.com | pasdesmenaces.com | pasendommagement.com | pasplusdespertes.com | pasplusdevirus.com | pcantiviruspro.com | pcassertor.com | pcboosterpro.com | pcbunan.com | pceternel.com | pcforfender.com | pchealthkeeper.com | pchjaelper.com | pcinforedder.com | pclibredevirus.com | pcredskab.com | pcsansbug.com | pcsecurise.com | pctoolpro.com | pcultralimpia.com | pcveiligheidstool.com | poseidonantivirus.com | preservingtool.com | privacidadgarantizada.com | privacidadyseguridad.com | privacywarrior.com | protecaoconfiavel.com | proteccionasegurada.com | proteccioncompleta.com | proteccionimperial.com | protecteurdinfo.com | protectiondedriver.com | protectiondenetsurfage.com | proteggidati.com | puraibashihosho.com | puraibashitoshinrai.com | rendimientototal.com | rensanu.com | reparaerrores.com | repareja.com | reparemenaces.com | repareya.com | rimuoviciarpame.com | riparaminacce.com | riparasubito.com | safeharddrive.com | safepctool.com | safudaijoubu.com | salvaspaziosudisco.com | sansendommagement.com | sansinfections.com | sayonarabaggu.com | schijfruimteredder.com | schutzderdaten.com | schutzfuerpc.com | secretosasalvo.com | secretoseguro.com | sefunahimitsu.com | sekretessforsvarare.com | senzadoppioni.com | shingaidome.com | shinraihogo.com | shinraipafomansu.com | shisutemudifensu.com | sikkerbrukere.com | sikkerpcredskap.com | sikkersystem.com | sinataques.com | sinrrastros.com | sinsenales.com | sistemaprotegido.com | sistemupyua.com | sisutemuantei.com | sisutemuorugurin.com | skyddsprogram.com | smittfri.com | speichertool.com | stopbedreiging.com | stopminacce.com | succesantivirus.com | surfforsure.com | syssauvegarde.com | systemesansfaute.com | systemhoover.com | systemschild.com | tackanejvirus.com | tilforlatelig.com | trustedantivirus.com | trustedprotection.com | trygpcbruger.com | turnkeyantivirus.com | uk.prevedhosting.net | unidadessanas.com | usuarioprotegido.com | utiledereparation.com | utilisateursur.com | vaktmotvirus.com | virenvernichter.com | virusbekaemper.com | virussperr.com | virusurimuva.com | virusvanger.com | virusvijand.com | volumformatredskap.com | winchesterprotector.com | wirusufinisshu.com | wirusukyua.com | wirusushattodaun.com | zentaiwakuchin.com&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639879" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=Z5zJZJ"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=Z5zJZJ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=ACTNEj"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=ACTNEj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/330293492" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2008/07/09/1639879.aspx</feedburner:origLink></item><item><title>An interesting browser hijacking that I have not seen before... watch out for the "free" Geobytes Geoflag</title><link>http://feeds.feedburner.com/~r/SpywareSucks/~3/329789812/1639767.aspx</link><pubDate>Tue, 08 Jul 2008 12:49:50 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1639767</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/07/08/1639767.aspx#comments</comments><description>&lt;p&gt;&lt;strong&gt;&lt;em&gt;Edit: the Geobytes flag has been removed from the blog being discussed below - YAY!!!&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;I was pinged by another MVP tonight, who was very concerned because he had visited a blog on msmvps.com, only to have his web browser immediately hijacked - redirected away from the blog he wanted to read to &lt;strong&gt;ozdirect.com.au&lt;/strong&gt;.&amp;nbsp; So, I went to take a look.&lt;/p&gt; &lt;p&gt;I, also, was immediately redirected away from the blog to &lt;strong&gt;ozdirect.com.au&lt;/strong&gt;.&lt;/p&gt; &lt;p&gt;Thankfully I had made sure that Fiddler was running in the background, just in case, because the hijack occurred once, and I can confirm that the free Geobytes Geoflag on the blog is what is hijacking visitors to the blog in question.&lt;/p&gt; &lt;p&gt;This is what happens.&lt;/p&gt; &lt;p&gt;When the blog loads, I see the following request and response:&lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_8e824223_2D00_b034_2D00_4132_2D00_a4ea_2D00_cbea7bf58b69.png" width="947" height="537" /&gt; &lt;/p&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;Note the window.open and reference to ozdirect.com.au&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Now, look what happens if I refresh the blog:&lt;/p&gt; &lt;p&gt;Request and &lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_67858660_2D00_37de_2D00_492c_2D00_a44a_2D00_92861d5efc57.png" width="945" height="529" /&gt; &lt;/p&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;No more window.open or ozdirect.com.au.&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;Now, it just so happens that Geobytes states on their web page that, if you add the free Geoflag to your site, the following will occur:&lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_bd679b63_2D00_93e9_2D00_4fee_2D00_b69b_2D00_47905d82af41.png" width="721" height="83" /&gt; &lt;br /&gt;Source: &lt;a title="http://www.geobytes.com/GeoPhrase.htm" href="http://www.geobytes.com/GeoPhrase.htm" target="_blank"&gt;http://www.geobytes.com/GeoPhrase.htm&lt;/a&gt;&lt;/p&gt; &lt;p&gt;The site then goes on to say:&lt;/p&gt; &lt;p&gt;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_0653b5b1_2D00_97fe_2D00_49a7_2D00_a626_2D00_e2e19c731cf3.png" width="712" height="174" /&gt; &lt;/p&gt; &lt;p&gt;The problem is, the &amp;quot;new window [with] the original intended content&amp;quot; did not open - not for me, and not for my MVP correspondent.&lt;/p&gt; &lt;p&gt;I mean, seriously, what website owner in his or her right mind would agree to allowing his or her visitors to be hijacked - dragged away from their site and dumped somewhere else under such circumstances in a world where pop-up blockers are the rule, rather than the exception.&amp;nbsp; &lt;strong&gt;&lt;em&gt;Oh, and by the way, I have long since disabled the pop-up blocker in IE8 on my system - I need to see pop-ups as part of my role as an Online Compliance Researcher, so we can&amp;#39;t even blame a pop-up blocker for Geobytes&amp;#39; failure to open the promised new window on this system.&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;We will report the problem to the blog&amp;#39;s owner, so hopefully the nasty little flag will be gone soon...&amp;nbsp; What nasty flag?&amp;nbsp; This nasty flag - the Australian flag that you can see in the screenshot below:&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;img alt="map" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/map_5F00_b9b532c2_2D00_eabb_2D00_4621_2D00_b722_2D00_cde87a2eab48.png" width="469" height="501" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639767" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=VpW40J"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=VpW40J" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=bKaCVj"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=bKaCVj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/329789812" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2008/07/08/1639767.aspx</feedburner:origLink></item><item><title>New malvertizement featuring Forex AutoPilot</title><link>http://feeds.feedburner.com/~r/SpywareSucks/~3/327886672/1639541.aspx</link><pubDate>Sun, 06 Jul 2008 06:45:47 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1639541</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/07/06/1639541.aspx#comments</comments><description>&lt;p&gt;Kimberly, who is monitoring the ongoing malvertizement problems at isuisse.com, ibelgique.com and iquebec.com, has discovered a new malvertizement featuring Forex Autopilot.&lt;/p&gt; &lt;p&gt;&amp;quot;&lt;em&gt;A yet unseen, new malvertizement is present on the homepage of isuisse.com, ibelgique.com &amp;amp; iquebec.com. The banner advertises Forex AutoPilot and the creative is belonging to the new generation created with Fuse Kit 2.1.4. This is now the FOURTH malicious banner discovered since June the 12th on websites belonging to the group iEUROP. Just on a site note, the XM Radio malvertizement is also being displayed at isuisse on the portal page. This brings the count up to THREE active malvertizements being served to the visitors!!! Imagine the number of users being redirected to fake online scanners ... Enough is enough, this has to stop.&lt;/em&gt;&amp;quot;&lt;/p&gt; &lt;p&gt;Malicious domains:&lt;/p&gt; &lt;p&gt;&lt;strong&gt;adoptserver.info&lt;/strong&gt;/_statis.gif?url=[removed]&lt;br /&gt;&lt;strong&gt;windowsxp-privacy.net&lt;/strong&gt;/?id=198760063&lt;br /&gt;&lt;strong&gt;xponlinescanner.com&lt;/strong&gt;/soft.php?aid=024202&amp;amp;d=3&amp;amp;product=XPA&lt;br /&gt;&lt;strong&gt;xponlinescanner9.com&lt;/strong&gt;/2009/1/freescan.php?aid=77024202 (registered 1 July 2008) &lt;p&gt;Fraudware sites: &lt;p&gt;antivirus-2009.com&lt;br /&gt;antivirus-database.com&lt;br /&gt;antivirus2009professional.com&lt;br /&gt;xpantivirusonline.com&lt;br /&gt;xponlinescanner.com&lt;br /&gt;xponlinescanner9.com &lt;p&gt;&lt;img alt="swf181" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/swf181_5F00_610ceb1b_2D00_dfe6_2D00_4a1b_2D00_aa0f_2D00_942dfc116e07.jpg" width="728" height="90" /&gt; &lt;/p&gt; &lt;p&gt;&lt;img alt="swf182" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/swf182_5F00_c5628a08_2D00_46ea_2D00_4bdf_2D00_a8fb_2D00_4bd914fb8b30.jpg" width="728" height="90" /&gt; &lt;/p&gt; &lt;p&gt;&lt;img alt="swf183" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/swf183_5F00_e156bbc7_2D00_9b7f_2D00_4d34_2D00_a2ce_2D00_bd309c3d22e4.jpg" width="728" height="90" /&gt; &lt;/p&gt; &lt;p&gt;&lt;img alt="swf184" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/swf184_5F00_15f55244_2D00_d217_2D00_4b15_2D00_a40b_2D00_85a9777e16c9.jpg" width="728" height="90" /&gt; &lt;/p&gt; &lt;p&gt;&lt;img alt="swf185" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/swf185_5F00_b5122513_2D00_8310_2D00_4253_2D00_92a3_2D00_e3aaf46d77d7.jpg" width="728" height="90" /&gt; &lt;/p&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;Images courtesy of Kimberley&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Source: &lt;a title="http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;amp;pid=87978&amp;amp;mode=threaded&amp;amp;show=&amp;amp;st=90&amp;amp;#entry87978" href="http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;amp;pid=87978&amp;amp;mode=threaded&amp;amp;show=&amp;amp;st=90&amp;amp;#entry87978" target="_blank"&gt;http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;amp;pid=87978&amp;amp;mode=threaded&amp;amp;show=&amp;amp;st=90&amp;amp;#entry87978&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639541" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=ICXT7J"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=ICXT7J" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=nddLBj"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=nddLBj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/327886672" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2008/07/06/1639541.aspx</feedburner:origLink></item><item><title>Oh goody. Another SWF display conduit to keep an eye on :o(</title><link>http://feeds.feedburner.com/~r/SpywareSucks/~3/325500682/1639206.aspx</link><pubDate>Thu, 03 Jul 2008 05:28:18 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1639206</guid><dc:creator>sandi</dc:creator><slash:comments>1</slash:comments><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/07/03/1639206.aspx#comments</comments><description>&lt;p&gt;Adobe Reader 9 has been released, and guess what, it can display SWF and FLA files... I wonder what implication this has with regards to the security landscape surrounding malicious SWF.&amp;nbsp;&amp;nbsp; Are we going to have to watch out for PDFs which contain malicious SWF?&amp;nbsp; &lt;/p&gt; &lt;p&gt;I simply do not have enough information to judge the safety implications (or otherwise) of this new Adobe Reader feature...&amp;nbsp; I quote from the announcement on the Adobe reader blog:&lt;/p&gt; &lt;p&gt;&lt;em&gt;&amp;quot;Adobe Reader 9 can natively display rich media content, which you&amp;#39;ll notice immediately with Portfolios. Interested in viewing SWF and FLV files? Adobe Reader 9 is the answer.&amp;quot;&lt;/em&gt;&lt;/p&gt; &lt;p&gt;The first thing that occurs to me that is our number one complaint about malicious SWF is that there is no way for the end user to stop the initial hijack that exposes them to malicious domains.&amp;nbsp; If Adobe Reader 9 prompts for user permission before opening a web browser, then in that way Adobe Reader is a safer way to view SWF.&amp;nbsp; If, on the other hand, the Reader allows an SWF to open a web browser without user interaction, then we are facing yet another conduit to danger.&lt;/p&gt; &lt;p&gt;Source:&amp;nbsp; &lt;a title="http://blogs.adobe.com/adobereader/2008/06/adobe_reader_9_is_here_1.html" href="http://blogs.adobe.com/adobereader/2008/06/adobe_reader_9_is_here_1.html" target="_blank"&gt;http://blogs.adobe.com/adobereader/2008/06/adobe_reader_9_is_here_1.html&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Oh, and while I think of it - the ActiveX changes in Internet Explorer 8 have the potential to make things safer for users when it comes to malicious SWF (and other ActiveX controls).&amp;nbsp; This is because IE8 will allow the user to choose to install ActiveX for all users, or just one user on the computer, AND it also will also introduce &amp;quot;per site&amp;quot; ActiveX.&amp;nbsp; That is, when you are prompted to allow an ActiveX control to run, you will be able to choose to allow the control to run at that one web site, or all web sites.&amp;nbsp; So, if you need Flash for one particular site, but don&amp;#39;t want Flash to be available to other sites, then you will be able to approve Flash for just that one site - cool, yes?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639206" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=c8cMSJ"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=c8cMSJ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpywareSucks?a=un1BSj"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpywareSucks?i=un1BSj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/325500682" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2008/07/03/1639206.aspx</feedburner:origLink></item></channel></rss>
