Archive for December, 2006

Updated the HOSTS file

The MVPS HOSTS file was recently updatedhttp://www.mvps.org/winhelp2002/hosts.htm Download: hosts.zip (125 kb)http://www.mvps.org/winhelp2002/hosts.zip How To: Download and Extract the HOSTS filehttp://www.mvps.org/winhelp2002/hosts2.htm HOSTS File – Frequently Asked Questionshttp://www.mvps.org/winhelp2002/hostsfaq.htm Note: the “text” version makes a great resource for determining possible culprits … (515 kb)http://www.mvps.org/winhelp2002/hosts.txt Sign up for HOSTS file update noticeshttp://www.mvps.org/winhelp2002/hosts.htm#contribute

Another VideoCash site to avoid

Just as soon as VideoCash dropped “5starvideos.com” (now Parked) most it was likely too well detected … however you can see the kind of traffic they were generating … Unfortunately they have registered a new domain Dec 25th to take up the slack … keypromanager(dot)com VirusTotal results: AntiVir 7.3.0.21 12.27.2006 DR/Zlob.Gen Authentium 4.93.8 12.22.2006  no […]

Another nasty Codec

Yet another fake codec site … but this one whacks you just by visiting the site or one of the more than 50 affiliates that automatically redirect you to this site. Notice than there is no Cancel button, only an Ok … the bad part is even if you click the RedX button it whacks […]

Scumbag vs. Scumbag

In a recent developement after MessengerPlus! was chastized for the advertising content that was displayed to the user when the “Sponsored Program” (Circle Distribution aka: C2Media/LOP) is installed … so what’s the big deal? The text in their EULA allows for them to replace the users HOSTS file … so their work-around was to rip-off […]

Fake codec with a twist

These codec sites have a new twist … they are now displaying the typical fake codec message from Windows Media Player.   However this new version automaticall redirects the viewer and the Trojan.Zlog file is automatically loaded … This new (fake) codec site was only registered Dec. 11 and I’ve found about 60 (adult) sites […]

HOSTS File Updated

The MVPS HOSTS file was recently updated [12-15-06]http://www.mvps.org/winhelp2002/hosts.htm Download: hosts.zip (123 kb)http://www.mvps.org/winhelp2002/hosts.zip How To: Download and Extract the HOSTS filehttp://www.mvps.org/winhelp2002/hosts2.htm HOSTS File – Frequently Asked Questionshttp://www.mvps.org/winhelp2002/hostsfaq.htm Note: the “text” version makes a great resourcefor determining possible culprits … (503 kb)http://www.mvps.org/winhelp2002/hosts.txt Sign up for HOSTS file update noticeshttp://www.mvps.org/winhelp2002/hosts.htm#contribute

Another fake Video ActiveX Object

Looks like VideoCash has changed vendors already … seems like they do every few days … Clicking the link leads to activexmediaobject(dot)com which is registered where else? ESTDOMAINSThere website layout is exactly the same as the one I reported previously … it looks like VideoCash is switching from the fake “codec” sites to “activex” (VAX) […]

Another fake codec to avoid

I found this fake codec site using a new social engineering trick … they play the (adult) movie in Windows Media Player from a small pop-up but as you can see it’s blank. While the movie plays the sound is audible but no video … this is to trick the viewer into clicking the link […]

Zango offers Teen Porn

While researching several suspect sites today I ran across a disturbing find … Zango offering Teen Porn! I had to cover up the images with the View Source as they are too graphic and disgusting. As you can see above in the link description “Free exclusive teen pictures and movie galleries” there is no doubt […]

Another IFrame VML exploit

Following up on a SunBelt blog post … I noticed the site mentioned wasn’t really the problem but the IFrame exploit contained on the page, which produces a Information Bar pop-up in IE7 In researching this culprit I found that the same exploit is being served up on several other sites. 2 of which were […]