<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PC Cybertek &#187; fake adobe player</title>
	<atom:link href="http://www.pccybertek.com/tag/fake-adobe-player/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pccybertek.com</link>
	<description>The Cyberspace Information &#38; Security Outpost</description>
	<lastBuildDate>Fri, 03 Feb 2012 11:23:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Fake Adobe Flash Player</title>
		<link>http://www.pccybertek.com/2009/09/fake-adobe-flash-player/</link>
		<comments>http://www.pccybertek.com/2009/09/fake-adobe-flash-player/#comments</comments>
		<pubDate>Fri, 11 Sep 2009 10:27:22 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[0day]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[fix]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[fake adobe player]]></category>

		<guid isPermaLink="false">http://www.pccybertek.com/?p=258</guid>
		<description><![CDATA[There is a fake adobe flash player updater that monitors your google searches. It looks just like the adobe flash installer. I&#8217;m not sure where I picked it up, but luckily I found this fake adobe flash player on a computer running firefox. Good thing I run NOD 32. I have been getting a notice [...]]]></description>
			<content:encoded><![CDATA[<p>There is a fake adobe flash player updater that monitors your google searches. It looks just like the adobe flash installer. I&#8217;m not sure where I picked it up, but luckily I found this fake adobe flash player on a computer running firefox. Good thing I run NOD 32. I have been getting a notice that NOD 32 was blocking an outbound connection <img src="http://pccybertek.moesarts.com/wp-content/uploads/2009/09/fake_flash.jpg" alt="fake_flash" title="fake_flash" width="350" height="432" class="alignleft size-full wp-image-259" /></p>
<p>I found out that I was infected by this Fake <a href="http://blog.misec.net/2009/08/25/fake-adobe-flash-player-monitors-your-google-searches/">Adobe Flash Player</a></p>
<p>While that website does tell you how to figure out if you have it or not, it doesn&#8217;t really tell you how to remove it, unless you buy their program. So I&#8217;m currently in the process of removing it. If you do have it, you&#8217;ll want to stop it right now! I&#8217;ve found that by going into Firefox&#8217;s extensions (Tools -> Addons -> extensions) you can disable Adobe Player 0.2 and restart Firefox. After doing this, I no longer got the warning for NOD 32 that it&#8217;s blocking the connection that msjupdate site, which I don&#8217;t know why it hasn&#8217;t been shut down yet.<br />
I found socks.exe was running and when I looked for that file, I found it in my Windows/system folder with a creation date of 09-09-09, so I stopped socks.exe and renamed it socks.bak I would have deleted it but just in case it wasn&#8217;t installed by this Trojan, I figure it&#8217;s better to rename it. If some legit program I have starts complaining that socks.exe is missing, I can always rename it back to socks.exe</p>
<p>Once I&#8217;ve figured out how to completely remove it, I will update this post. In the meantime, disabling it will work. It&#8217;s after 3AM and I should have been in bed hours ago, but this was too important not to immediately warn you about it and give you at least a way of stopping it until I can post removal instructions. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.pccybertek.com/2009/09/fake-adobe-flash-player/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

