New variants of VirusBurst have yet again reared an ugly head. The two latest files:
C:\Windows\System32\httge.dll
C:\Windows\System32\ggagksr.dll
Read More Here
Malware Advisor is going to post information specifically related to adware, spyware and malware. Most links will point to my forum, where all are invited to take part in discussion, seek assistance with malware removal and find out about the latest malware threats.
New variants of VirusBurst have yet again reared an ugly head. The two latest files:
C:\Windows\System32\httge.dll
C:\Windows\System32\ggagksr.dll
Read More Here
I found the latest from the gang at SurfSideKick while VML trolling. The relationship is noticeable in more than one way. Bleeping Computing have a nice write up here and compares file names and paths.
You can read about what my experience with was here in our forums
UPDATE 2: Forums will have sporadic access until posted here as of 1030AM MST
UPDATED: Forum is now up as of 9:45AM MST
The forums are down due to some hosting maintenance. In the mean time, why don't you check out whats on the the main site. Seems like a perfect opportunity, doesn't it?
From there you can check out a bunch of my favorite blogs or some of the newsletters I link to.
MS releases out of cycle patch for most recent VML IE exploit. Read More Here
IE exploit begins to stretch its legs as more reports come in about entire servers being hacked and more users getting infected. MS responds that they may just even patch out of cycle and then there is a third party patch out too. Read More Here
Another variant was found this week to be added into the removal tools for those infected with SmithFraud\Zlob infections. These guys try hard, but the anti-malware gang stays pretty much on top of these, not likely users will get so heavily infected with this one. Read More Here
Seems some spammers are finally doing what I thought was a regular thing, collecting email addresses via chain letters or jokes. One of my pet peeves is the ridiculous amount of email sent with 150 email addresses in the header. And it usually seems to be that AOL dipshits are the worst offenders. Read More Here
The people behind StopBadware.org seem to have a connection to FunWeb Products. I happened across this while reading the latest from BillP, Bits From Bill whom for those not in the know, is the developer behind WinPatrol.
While investigating the description of an application in the WinPatrol PLUS database he found that one of the board members of the company behind FunWeb, IAC Interactive is also behind the Berkeley
Center For Internet & Society at Harvard Law School. And they just happen to be the primary backers of StopBadware.org.
Interesting to say the least. FunWeb's rep is less than stellar, tho not nearly as bad as other adware bundled types of apps.
Read More Here
The other day I mentioned that a lawsuit against Zango had been dismissed. Sad news all around, except for the asshats at Zango. They proclaimed:
"We have maintained from its inception that this case had no merit. The dismissal vindicates that position," said Ken McGraw, Zango's general counsel in the statement. "[This] serves to confirm that Zango's desktop advertising software is not spyware in any shape or form and that our business model is entirely legitimate," he added.
But the truth of the matter was, the lawyers for the plaintiffs requested the suit be dropped!! Yeah thats right. The merits of the case itself were not in question, but rather the case could not stand up to the qualifications to become a class-action lawsuit. The lawyers at The Collins Law Firm are anxious to talk to any other litigants to move forward and begin action again.
This person has for the last year or so has been laying claim to several pieces of software which are used to fight malware. To just name a few:
SmithRem-Used against many of the SmithFraud\Zlob infections.
NailFix- Used against Aurora\Nail infections.
RogueFix- Used against some variants of SmithFraud
There are others as well. Some of these people he has allegedly ripped off are Microsoft MVPs.
When confronted he slanders his accusers, calls them vile names and is overall not someone who you would trust. He changes his Whois info and tries to hide his identity. He even began to offer help to users via email to avoid any detection by the security community.
Some of the originators of these scripts are contemplating legal action. But we all know how well that works on the Net.
The only other recourse is to try and shame him into doing the right thing. But based on comments found via a Google search for pcbutts it's an unlikely thing he will because it appears the right thing just isn't in his genetic make up.
But you can do the right thing, by spreading the word about this person. You can also do your part by complaining to the ISP hosting his site at:
BillP lets all users of WinPatrol access PLUS Info for September.
The group over at Prevx have made a stand alone removal tool for this nasty bit of work. You can find it at here at Prevx
The latest rogue makes no obvious effort to appear to be much different than many of the other rogues. We need to be thankful these guys have a limited resource in their imaginations. Read More Here
It would seem that McAfee SiteAdvisor has developed a bit of a hiccup with it's ratings system, or, perhaps their crawler has a bug in it.
Many of the well known anti-malware forums have been red-flagged in the last few days. Sites like Tom Coyote, CEXX and Ad-Aware Support forum.
These are obvious mistakes in the system somewhere. The SiteAdvisor group has been made aware of these mistakes and are taking action to correct them. It just won't be as fast as we would like.
I am rated as an 'Experienced Reviewer' and as such, my comments carry a little bit of weight in the ratings of sites. If you're aware of a site which needs some corrective commentary, be they good sites flagged as bad or visa versa, let me know and I'll work my mojo magic on them.
UPDATE: SiteAdvisor is attempting to whitelist these types of security forums and correct the problem.
Malware writers have out done themselves with this one. Variable DLs, dependant on browser. Hourly changes of said files from DL sites.
Rootkit detection tools don't detect in many cases. Fried test machines when researchers attempt analysis.
Oh and did I say there isn't really any fix for it yet? Well there is one, but it's not for the faint of heart or the technically challenged either.
Read More Here
The scumbags at Direct Revenue get off lightly as a suit brought by the state of California gives very little if any real punishment.
That's truly a major disappointment. These lowlifes needed to be crushed. Read More Here
Yet another SmithFraud\Zlob variant has hit the streets.
They call this one VirusRescue. But rest assured the only thing that will be needing rescuing will be your sanity as you come to find, after being duped into purchasing this POS that your system is running ragged and you have al sorts of pop ups.
And the scumbags who created this thing then tried to post into a fellow security advisor's forum and defend the app.
Mistake. BIG mistake. HUGE even.
Then people like PG and Moore from Bluetack get their engines revved up and carnage ensues. Not to mention the kick ass reply from Security Cadets. But it's the good kind of carnage, the kind where the bad guys get their asses whooped.
Well it's been a few weeks and I have neglected this blog, sorry about that, here are some quick links to get you caught up.
New Zlob\SmithFraud Variant: VirusRescue
August Patch Causing IE Crashes
Webroot State Of Spyware Report
Another Zango-Porn Connection?
CDT Report On Affiliate Adware Game
Well it seems an article posted on digg incorrectly stated some facts in the relationship with Zango and porn. As it turns out (if you followed this, you're aware), Zango was not distributing porn but their association with YapBrowser certainly didn't help matters. Paperghost gives the lowdown on the facts.
Well hot on the heels of Zango being exposed for advising affiliates on how to insert their software onto MySpace, comes great news!!
Warner Bros. is dumping Zango as an adware vendor!!
Got a few things happening last day or so:
Bots Invade MySpace
F-Secure Finds Exploits At Social Engineering Sites
Zango once again gets capped in another drive-by 'zealot' attack. At least they would lead you to believe it's some sort of vendetta.
Anyone with half a brain could see right through all their excuses and double speak. Read More Here
BillP continues to improve upon Scotty's abilities to ensure users are safe, offering another version with some bug fixes and a requested feature. Read More Here
Well it seems that once again, Zango, our favorite provider of adware found in some amazingly perverse content, has been exposed by Paperghost.
They really should just add him to the payroll, he does more to regulate their affiliates that the guy who is supposed to be doing it for them. Read More Here
Looks like this app is one in the same as the others in the SmithFraud family. Panda claims to have found it. Read More Here
Still yet another case of an adware company using MySpace to spread its bundles of 'joy'. This is the second company in two weeks caught doing this. Lets hope MySpace gets on the ball and tries to do something about it. Until then, MySpace users beware.
Well after getting some negative press back in May, the newly formed but still-doing-business-as-usual 180Solutions-cum Zango is once again duping users on MySpace.
See, you really can't change the spots on a leopard. Or is that the stripes on a zebra? Regardless, read more here
This rogue is very new and so far no users have claimed to be infected by it, but give it time, they will begin to popup by weekends end I'm sure. I even took the time to add a comment as a reviewer of the app for SiteAdvisor. Read More Here
Several specialty tools were updated today with new
variants and better scanning and fixing:
I am returning to a forum where I originally began my interest in helping others remove malware. They had been over run with spammers and all but abandoned. CEXX forums is now undergoing a revival. Read More Here
Malware writers craft fake files imitating MS WGA to trick users and load a bundle of junk wares. MS MVPs are franticly gathering info to spread the word and submitting files to malware vendors to be added to databases. Read More Here
WinPatrol keeps on improving and delivering one of the best system monitoring applications on the Net. PLUS users get even greater control over any system changes and can find out when files were created, monitor hidden files and more!! Read More Here
Latest rogue shows not much in way of creativity, just claims that it destroys spyware but with it's affiliation with known bundlers of malware, it's highly unlike to do much of anything useful.
Read More Here
The latest variant sometimes carries a rootkit in it, but the tool seems to catch the ones that do not. This new variant also hides when using HijackThis, so users need to rename the tool to trick the malware. Read More Here
Lots of talk about the latest from MS, their Windows Genuine Advantage and its notification tool. Most of the talk is about how to disable the notification tool.
We have a couple of threads in the forum, one here that talks about the many ways to do just that. And another one here which has links relating to the implementation of the tool over all. Don't forget to take the poll in the second link.
Related links:
How Windows Product Activation Works
I have a new thread in the forums dedicated to specific infections and fixes for those infections. Users should use caution when applying these fixes and take note that machines may still have other infections after the specific fix is used. Read More Here
Webhelper's site has been under attack since the 16 of June by DollarRevenue. It seems that after being blogged about here and here they got a little pissed off and decided to attack him!! Read More Here
Three new variants of SpywareQuake were found the last 24-36 hours. And both SmithFraudFix and SmithRem have been updated and deal with all three, including BHOs and CLSIDs. Way to go guys!!
New files:
oybgrql.dll
yvvdj.dll
xuefh.dll
SmithFraud Updates in forum.
Two SmithFraud variants found recently, fix tools updated and working so well that this infection has come down to running two steps to remove it.
Kudos to the experts who craft these tools to fight off the scumbags who create them. New variants have been found almost on a weekly basis and the tools are updated within 24 hours in most cases. Read more about SmithFraud Infection Family Here
A new rogue has been uncovered in the last 24 hours or so: Titan Shield. It is part of the SmithFraud rogue family and many of it's files have already been added for removal by the SmithFraudFix tool by Siri
New version sneak peek of WinPatrol for PLUS users only, some neat new features, a must have for all. Read More Here
Noahadfear, noted MS MVP has returned to the malware fight and updated his SmithRem tool. Read More Here
Well it seems my hosting company is having some troubles with our IP blocks 'not being announced to our upstream providers'. Read More Here
Sorry for any inconveniences, hopefully we will be back
up soon.
Still yet another new SmithFraud variant found: C:\WINDOWS\system32\higjxe.dll"<<<<---new
file
C:\WINDOWS\system32\hvnwm.dll"<<<<---new
file
Another variant found, Siri SmithFraudFix updated:
Search SharedTaskScheduler's .dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{f5947202-e9cb-4a72-88e7-22f2cbd2b124}"="chenopodiaceae"
[HKEY_CLASSES_ROOT\CLSID\{f5947202-e9cb-4a72-88e7-22f2cbd2b124}\InProcServer32]
@="C:\WINDOWS\System32\bolnyz.dll" <<<<---new file
[HKEY_CURRENT_USER\Software\Classes\CLSID\{f5947202-e9cb-4a72-88e7-22f2cbd2b124}\InProcServer32]
@="C:\WINDOWS\System32\bolnyz.dll"
PG finds yet another instance of a rogue 180Delusions affiliates. But this time they are distributing the software via a botnet!! When will the madness end? Read More Here
IM malware installs its own browser without consent. Crazy style of infection plays music too! Read More Here
Well it seems that the scum over at 180Solutions have figured a way to nestle their crapware into MySpace.
It's amazing that the most notoriously infamous adware pushing company can get their stuff added to so many huge sites.
How is it that the people who approve these deals don't know about them? Maybe there is a stronger element behind it? Maybe the VC groups that back these scumbags at 180 have connections far beyond the basic hallways and inner circles of affiliate worlds.
How else could you explain it? Read More Here
Browser dependant malware payloads give users tailored infections. Read More Here
Warner Bros today announced a partnership with 180Solutions. Yes, that's right, the people who have brought you all sorts of wonderful entertainment have joined forces with the people who have brought you all sorts of......adware, popups, unethical installs, excuses and in another case, even child porn, via the wonderful world of their affiliates. Read some about it here in the forums.
Before you send Mom that e-card, you better read about what else she may get along with the pleasant sentiments....some not to pleasant malware. Read More Here
FTC has fined one anti-spyware rogue $4Million dollars and barred another from collecting users info. Read More Here
My good friend Wayne Porter of SpywareGuide, FaceTime and ReveNews has a new product he is touting, an EULA Analyzer. While this is not necessarily a new idea, I'm certain it will be tic above any other analyzers currently available. Read more about it here in our forum.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{CA14EE13-ED15-C4A2-17FF-DA4D15C1BC5E}"="Twain"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"
[HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CA14EE13-ED15-C4A2-17FF-DA4D15C1BC5E}\InProcServer32]
@="C:\WINDOWS\system32\twain32.dll"
UPDATE MAR 25-1:25MST:
There has been a fix created over at Bleeping Computing. Spyware Quake Fix
********************************
OK, it appears the culprit dll in this variant is: stickrep.dll
It will be located in the system32 folder. Deleting that along with the Spyware Quake related folder and SpywareQuake.exe may remove the infection entirely. Still waiting for more reports, first one in seems to have worked. Unsure if running the SmithRem fix is absolutely needed at this time, seeing as it can't be included in the database as yet. See here
******************
There are 4-6 of these in a few forums. And all are exhibiting the same types of symptoms as SpyFalcon\SpywareStrike\AlphaCleaner and all the other variants. More to come soon.
Gotta love this. As its clients discover the oh-so-shady business practices of 180, they drop 'em like hot potatoes. Read More Here
Great write-up by Brian Krebs of Security Fix on how volunteers keep track of botnets. Read More Here
CDT & StopBadware.org to release adware reports this week. They will name names and give details on how and why adware proliferates. Following closely behind that Ben Edelman provides major vendors supporting 180Solutions.
In this article, Brian Krebs of Security Fix talks about the inherent flaws in which anti-spyware apps use to detect keyloggers and has some good info from a couple of researchers. Read More Here
In this part, PG interviews the guy who gave him the inside info about these botnets. Very cool reading for sure. Read More Here
Paperghost and SpywareGuide once again have sunken deep undercover into the Dark Side of the Net and uncover a botnet comprised of nearly 150,000 boxes!! And just how did many of these machines get taken over? You guessed it, via IM.
Unsuspecting users who click on links sent by other compromised machines can have files installed which search their machines to get critical information to access all sorts of sensitive data. The botmasters even install special script to look for exploits in many of the e-cart applications such as CCBill, Comersus Cart and CactuShop.
If these couple of articles and their follow ups don't prevent you from clicking links all the time, I don't know what will. Read More Here
Direct Revenue make unprecedented concessions, yet still are not required to keep an eye on the ever present, all powerful, excuse invoking affiliates. Read More Here
Paperghost on why it's important to consider nearly every angle of an infection. From what it is, to what it does to who made it and why they made it. Not to mention what they have done in the past. As
Webhelper says: "One must know the past in order to understand the future, if one is to change the future" Read More Here
CatleCops has another article recapping the Aluria\WhenU 'whitewash' and subsequent missteps taken by one of Aluria's outgoing executives. Seems in this Spyware Warrior thread he was caught giving false reviews (called astro turfing) to the Aluria product at download.com. There is also more info in the CastleCops Forum Newsletter
Blogger documents a BraveSentry unauthorized install. Nicely done with screenshots and everything. Found via Sunbelt Blog. NetSato Blog
Some white hat researchers have found a vulnerability in the popular system suite. Zone Labs was informed in December and has yet to reply to the info provided. More Here
Another day another rogue. This time it's a SpySherriff clone: PestWiper. Hosted on the same servers as other rogues and blacklisted by everyone. Read More Here
Viewpoint media player called spyware by one journalist, he tells users how to prevent its installation. Viewpoint didn't like it. Read More
New rogue found, pushing two anti-spyware apps on users. Found by Sunbelt Software researchers. Read More
New variant of Vundo found, tool created by Atribune updated and working.
A new file has been found in the SpyFalcon infection:
ginuerep.dll
Located in the C\WINNT\system32 folder.
The fix at Bleeping Computing has been updated to include its removal.
Aluria software vendor is trying to remove traces of its scandal from back in October 2004 which involved their reclassification of WhenU software.
It appears all references of press releases are disappearing from their website at an alarming rate. And it seems there is a new classification in the anti-spyware business: 'consumer ware' which is what they now call WhenU. Oh, and what else is listed as this new found section of consumer ware? 180Solutions. More to read here