<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PC Cybertek &#187; adware</title>
	<atom:link href="http://www.pccybertek.com/tag/adware/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pccybertek.com</link>
	<description>The Cyberspace Information &#38; Security Outpost</description>
	<lastBuildDate>Fri, 03 Feb 2012 11:23:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Fake Xvid Update Serving Up Malware</title>
		<link>http://www.pccybertek.com/2011/04/fake-xvid-update-serving-up-malware/</link>
		<comments>http://www.pccybertek.com/2011/04/fake-xvid-update-serving-up-malware/#comments</comments>
		<pubDate>Mon, 11 Apr 2011 05:52:10 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[adware]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[video]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[divx]]></category>
		<category><![CDATA[xvid]]></category>

		<guid isPermaLink="false">http://www.pccybertek.com/?p=434</guid>
		<description><![CDATA[I&#8217;m going to make this short and sweet to get the word out there. I will delve further into what actual malware is being served and what the effects are at a further date. The following image was taken from a screen shot I made. It shows the fake video player that shows a rotating [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://pccybertek.moesarts.com/wp-content/uploads/2011/04/fake-xvid-player1.jpg"><img src="http://pccybertek.moesarts.com/wp-content/uploads/2011/04/fake-xvid-player1-150x150.jpg" alt="" title="fake xvid player" width="150" height="150" class="alignleft size-thumbnail wp-image-437" /></a>  </p>
<p>I&#8217;m going to make this short and sweet to get the word out there. I will  delve further into what actual malware is being served and what the effects are at a further date.</p>
<p>The following image was taken from a screen shot I made. It shows the fake video player that shows a rotating &#8220;waiting&#8221; graphic and pretends that it can&#8217;t load the video because it needs to be updated.<br />
<a href="http://pccybertek.moesarts.com/wp-content/uploads/2011/04/fake-xvid-player1.jpg"><img src="http://pccybertek.moesarts.com/wp-content/uploads/2011/04/fake-xvid-player1.jpg" alt="" title="fake xvid player" width="376" height="279" class="aligncenter size-full wp-image-437" /></a></p>
<p>I knew this was a threat because I&#8217;m also a video editor and I keep all my codecs up to date. However, I thought I would pursue this further so I could see what file was going to be installed. Then I could run analysis on it and report my findings here. But I was running ESET NOD32 and it recognized this page was a threat and also blocked whatever this page tried top send me. You can see the results below.</p>
<p><a href="http://pccybertek.moesarts.com/wp-content/uploads/2011/04/eset-block.jpg"><img src="http://pccybertek.moesarts.com/wp-content/uploads/2011/04/eset-block.jpg" alt="Fake xvid page block" title="ESET NOD32 page blocked" width="848" height="669" class="aligncenter size-full wp-image-438" /></a></p>
<p>So just don&#8217;t update your video player through any website that claims your video player needs to be update to view an online video. I would imagine there will be variations of this soon. Like fake Quicktime Player or Windows Media Player updates. I will grab a copy of the file this site is trying to distribute, for further analysis, later and post my findings here. That&#8217;s going to take some time and I have seen this fake xvid update a couple times now and decided I should spread the word sooner rather than later.  </p>
]]></content:encoded>
			<wfw:commentRss>http://www.pccybertek.com/2011/04/fake-xvid-update-serving-up-malware/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Malware Removal Sites, Software and Thoughts</title>
		<link>http://www.pccybertek.com/2010/02/malware-removal-sites-software-and-thoughts/</link>
		<comments>http://www.pccybertek.com/2010/02/malware-removal-sites-software-and-thoughts/#comments</comments>
		<pubDate>Sun, 07 Feb 2010 08:50:25 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[adware]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[free software]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[hijacked]]></category>

		<guid isPermaLink="false">http://www.pccybertek.com/?p=380</guid>
		<description><![CDATA[Last night I saw a banner ad for a &#8220;new&#8221; version of Risk. I use to play Risk, the board game, many years ago and thought this looks like fun. So I downloaded and installed it. With in a couple of minutes, ESET NOD32 was blocking downloads from a site I wasn&#8217;t at. Next time [...]]]></description>
			<content:encoded><![CDATA[<p>Last night I saw a banner ad for a &#8220;new&#8221; version of Risk. I use to play Risk, the board game, many years ago and thought this looks like fun. So I downloaded and installed it. With in a couple of minutes, ESET NOD32 was blocking downloads from a site I wasn&#8217;t at. Next time I went to use google to search for something, my search results were being redirected. Looks like it installed some malware on my computer. Most likely it&#8217;s some sort of XSS cross scripting exploit.<br />
<span id="more-380"></span><br />
So first I downloaded Spybot Search n Destroy. Back in the day, it was one of my must have malware removal tools. First let me say I&#8217;m not knocking the people over at http://www.safer-networking.org they do great work and they make Spybot S&#038;D free. I also highly recommend their <a href="http://www.safer-networking.org/en/regalyzer/index.html">RegAlyzer</a> which you can even find here in my download section. But Spybot only found 4 &#8220;threats&#8221; which were all cookies. In this day and age, lets face it, cookies aren&#8217;t really a &#8220;threat&#8221; but the anti-malware software makers, especially the demos, in an effort to pump up the number of &#8220;found threats&#8221; and scare you into buying their product are call cookies &#8220;threats.&#8221; </p>
<p>My next download was AdAware. Also one of my old standbys. After a couple of hours of scanning, it didn&#8217;t find anything. Even though it wasn&#8217;t finished I had hoped that after a couple hours it would have found something, anything. Then I thought there must be some other tools out there these days. There was one more on my old reliable but I&#8217;ll skip that for now since I didn&#8217;t get it. I figured I should find some malware related forums and update my knowledge on what&#8217;s out there these days. I don&#8217;t mind getting my hands dirty and digging through registry keys and directories. Which, I didn&#8217;t mention, but had already gone through the auto start and run registry keys and files that were created around the time my hijacking took place. In my search I came across the <a href="http://forums.malwarebytes.org/">Malwarebytes users support forum</a>. After reading a couple of posts I realized this was a good place for finding out about new malware and removal techniques as well as the program Malwarebytes. Since I haven&#8217;t tried it before and the forum, which is a forum that was created by users/fans of Malwarebytes, spoke so highly of it, I downloaded and installed it and started a complete scan. In a couple of minutes it had found 2 infections. I let it scan my system, which scanned 653800 objects and took 6 hours 28 minutes for the full scan. The scan just completed and found 35 infected objects. A quick view of the results shows me several registry files and the rest are files, non of which are cookies. Since I ran Spybot S&#038;D earlier and deleted the cookies it found, I can&#8217;t say if cookies would have been part of the results. With the exception of a couple of false positives, some of my security tools, the results are looking very promising. One item I see right of the back is svchost.exe which is in my /Local Settings/Temp/ which is defiantly bad. This is something pretending to be a legit windows service but it doesn&#8217;t belong here. There are also a couple of registry keys listed as Trojan.BHO which, even though I forgot to mention I did run earlier, Hijackthis didn&#8217;t identify. Now I unchecked the couple of false positives, and told Malwarebytes to delete the rest and save a log file. After this I&#8217;m told it needs to reboot. No problem, I expected that. Windows is rebooting and I&#8217;m anxiously waiting to see if this fixed my problem. I haven&#8217;t played World of Warcraft or logged into any of my sites in case there was also a password stealer installed. In fact I&#8217;m writing this from my wife&#8217;s laptop which is on my network but doesn&#8217;t have any write permissions from network users. </p>
<p>Reboot has completed and now comes time to test this. I sure hope it works because I&#8217;m posting the results regardless of the outcome. First I will launch Firefox. This isn&#8217;t my main browser but I have a script blocking extension in it which has alerted me to some of the redirects and blocked them. My first search &#8220;malware forums&#8221; brings up plenty of results and the first result I click on, Majorgeeks.com, goes where it should. But this was what happened before. The first result I clicked on would work but all the results I clicked on after would be hijcked&#8230; Awww a new window just opened to www.searchfindsite.com which doesn&#8217;t look good. !@#$@#$ I just tried another result from google and was redirected to findservicesonline.com and I see that malwarebytes.com didn&#8217;t clean it this one up. It did find and remove some items that spybot s&#038;d didn&#8217;t but I still have the hijacked search results. And my quest continues. When I do find a way to remove this, I will post about it. </p>
<p>If you know of some good malware removal tools, please leave me a comment. I&#8217;m going to try a couple of others I have and let you know what I find.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pccybertek.com/2010/02/malware-removal-sites-software-and-thoughts/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

