<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security and Privacy &#187; Rogue Software</title>
	<atom:link href="http://hijack-this.co.uk/category/rogue-software/feed/" rel="self" type="application/rss+xml" />
	<link>http://hijack-this.co.uk</link>
	<description>My ramblings on how to protect yourself online</description>
	<lastBuildDate>Thu, 05 Apr 2012 14:34:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>new Fake AV techniques</title>
		<link>http://hijack-this.co.uk/2011/07/new-fake-av-techniques/</link>
		<comments>http://hijack-this.co.uk/2011/07/new-fake-av-techniques/#comments</comments>
		<pubDate>Fri, 29 Jul 2011 17:21:26 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[Security advice]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=558</guid>
		<description><![CDATA[http://xylibox.blogspot.com/2011/07/trojanfakeavlvt.html once you get past the colourful language from the analyst, it is a very good read &#38; shows what we are up against. Please forgive any errors in language as he doesn&#8217;t have English as a first language This particular one has the ability to replace your existing antivirus with itself &#38; make you [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://xylibox.blogspot.com/2011/07/trojanfakeavlvt.html">http://xylibox.blogspot.com/2011/07/trojanfakeavlvt.html</a></p>
<p>once you get past the colourful language from the analyst, it is a very good read &amp; shows what we are up against. Please forgive any errors in language as he doesn&rsquo;t have English as a first language</p>
<p>This particular one has the ability to replace your existing antivirus with itself &amp; make you think that you are still protected when you aren&rsquo;t and it installs Zero access rootkit</p>
<p>This is definitely something to watch out for</p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F07%2Fnew-fake-av-techniques%2F&amp;title=new%20Fake%20AV%20techniques" id="wpa2a_2"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/07/new-fake-av-techniques/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cybercriminals Hoping You’ll Bite iPhone 5 Bait</title>
		<link>http://hijack-this.co.uk/2011/05/cybercriminals-hoping-you%e2%80%99ll-bite-iphone-5-bait/</link>
		<comments>http://hijack-this.co.uk/2011/05/cybercriminals-hoping-you%e2%80%99ll-bite-iphone-5-bait/#comments</comments>
		<pubDate>Wed, 25 May 2011 07:20:24 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Iphone]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[fake adverts]]></category>
		<category><![CDATA[fake software]]></category>
		<category><![CDATA[keylogger]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=480</guid>
		<description><![CDATA[Online criminals know there are enough gadget hounds out there to make a scam surrounding any shiny new Apple device a surefire moneymaker. To that end, they’ve already begun sending out phishing emails for the iPhone 5. The phishing emails appear to be official emails from Apple.com, with the title “Finally. The amazing iPhone 5. [...]]]></description>
			<content:encoded><![CDATA[<p>Online criminals know there are enough gadget hounds out there to make a scam surrounding any shiny new Apple device a surefire moneymaker. To that end, they’ve already begun sending out phishing emails for the iPhone 5.</p>
<p>The phishing emails appear to be official emails from Apple.com, with the title “Finally. The amazing iPhone 5. Now available in black edition.” The body of the message shows a hand holding a transparent iPhone, followed by an enticing offer to “check it out,” according to <a title="MacRumors" href="http://www.macrumors.com/2011/05/22/phishing-and-malware-emails-posing-as-apple-and-the-iphone-5-launch/" target="_blank">MacRumors</a>.</p>
<p>Although there’s been much speculation about the next generation iPhone, Apple has not set a release date for it. In fact, Apple hasn’t even announced it yet, but that isn’t stopping this cleverly crafted Mac-themed scam from spreading.</p>
<p>So what are you checking out when you click the link to see the new iPhone 5?</p>
<p>You won’t receive any info about the smartphone, but you will enable a rigged Windows file to run malicious code on your computer. And you’ll also be taken to a phony Apple Web page that asks for your Apple ID and other sensitive information.</p>
<p>Apple announces new products, especially ones of this magnitude, in highly publicized press conferences. So if you receive an unsolicited email purporting to have information about the new iPhone 5, ignore it, DELETE IT WITHOUT EVEN READING IT.</p>
<p>story from: <a href="http://www.securitynewsdaily.com/cybercriminals-hoping-youll-bite-iphone-5-bait-0813/">http://www.securitynewsdaily.com/cybercriminals-hoping-youll-bite-iphone-5-bait-0813/</a></p>
<p>This malware is quite well detected by many antivirus companies, but not all. It is a fairly standard Zapchast IRC trojan that will attempt to download lots of other crap &amp; malware to your computer.</p>
<p>It also appears to try to  perform a DDOS flood attack against several other competing Mirc users and channels to block their channels, so no doubt will turn out to be connected to the typical fake AV scams and stealing your money</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F05%2Fcybercriminals-hoping-you%25e2%2580%2599ll-bite-iphone-5-bait%2F&amp;title=Cybercriminals%20Hoping%20You%E2%80%99ll%20Bite%20iPhone%205%20Bait" id="wpa2a_4"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/05/cybercriminals-hoping-you%e2%80%99ll-bite-iphone-5-bait/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>new malware spam- order.zip</title>
		<link>http://hijack-this.co.uk/2011/05/new-malware-spam-order-zip/</link>
		<comments>http://hijack-this.co.uk/2011/05/new-malware-spam-order-zip/#comments</comments>
		<pubDate>Tue, 10 May 2011 11:07:51 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=462</guid>
		<description><![CDATA[There is a new spam bot out there sending a malware link. see  screenshot all emails so far appear to originate from a Ukrainian server noc.maximuma.net  91.196.148.8  which may or may not have been hacked, but web searches suggest that lots of spam &#38; malware is being distributed via that server hosting company So far I [...]]]></description>
			<content:encoded><![CDATA[<div>There is a new spam bot out there sending a malware link. see  screenshot</div>
<div>
<div id="attachment_463" class="wp-caption aligncenter" style="width: 310px"><a class="thickbox" rel="462" href="http://hijack-this.co.uk/wp-content/uploads/2011/05/order.jpg" ><img class="size-medium wp-image-463" title="order" src="http://hijack-this.co.uk/wp-content/uploads/2011/05/order-300x148.jpg" alt="screen shot of spam email" width="300" height="148" /></a><p class="wp-caption-text">screenshot of typical spam email </p></div>
</div>
<div>all emails so far appear to originate from a Ukrainian server noc.maximuma.net  91.196.148.8  which may or may not have been hacked, but web searches suggest that lots of spam &amp; malware is being distributed via that server hosting company</div>
<div>So far I have seen several different sites hosting the malware and the senders &amp; recipient email addresses are all random or spoofed</div>
<div>At present antivirus detection is very sporadic but samples have been sent to all known AV companies  so I do expect a better detection rate very shortly</div>
<div>The current payload is always order.zip, which when extracted pretends to be order.doc  but has a lot of spaces then .exe so simply clicking on it will infect you</div>
<div>It appears to be a downloader or installer for one of the fake Antivirus programs, that currently plague us.</div>
<div>You can see a quick automatic  analysis on the <a title="Anubis website" href="http://anubis.iseclab.org/?action=result&amp;task_id=176c30921b571e7c405639cb597aeeefa&amp;format=html" target="_blank"><span style="color: #0000ff;">Anubis website</span></a> From previous experience of this sort of malware and the locations it installs itself to , I would not be at all surprised if the malware shown in the Anubis report also installs the TDL4 bootkit</div>
<div>Update: they have changed the email slightly to something that resembles a previous attack attempt and included a &#8220;your  credit card will be charged with xxxxx $</div>
<div>That always gets the unwary to follow the link, to check if it is their card that has been falsely charged</div>
<div>
<div id="attachment_469" class="wp-caption aligncenter" style="width: 310px"><a class="thickbox" rel="462" href="http://hijack-this.co.uk/wp-content/uploads/2011/05/order2.jpg" ><img class="size-medium wp-image-469" title="order2" src="http://hijack-this.co.uk/wp-content/uploads/2011/05/order2-300x216.jpg" alt="" width="300" height="216" /></a><p class="wp-caption-text">Revised updated email, showing alleged credit card charge</p></div>
<p>Results are coming in from many antivirus companies now, saying that it is a version of the spyeyes crimeware toolkit. Spyeyes is well described  in this <a title="Symantec Blog" href="http://www.symantec.com/connect/blogs/spyeye-bot-versus-zeus-bot" target="_blank"><span style="color: #0000ff;">Symantec blog</span></a></p>
<p>&nbsp;</p>
</div>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F05%2Fnew-malware-spam-order-zip%2F&amp;title=new%20malware%20spam-%20order.zip" id="wpa2a_6"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/05/new-malware-spam-order-zip/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Microsoft is aware of nine fraudulent digital certificates issued by Comodo</title>
		<link>http://hijack-this.co.uk/2011/03/microsoft-is-aware-of-nine-fraudulent-digital-certificates-issued-by-comodo/</link>
		<comments>http://hijack-this.co.uk/2011/03/microsoft-is-aware-of-nine-fraudulent-digital-certificates-issued-by-comodo/#comments</comments>
		<pubDate>Wed, 23 Mar 2011 17:50:02 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[Skype]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=456</guid>
		<description><![CDATA[The full advisory can be found on the Web at: http://www.microsoft.com/technet/security/advisory/2524375.mspx. =========================== SUMMARY =========================== Microsoft is aware of nine fraudulent digital certificates issued by Comodo, a certification authority present in the Trusted Root Certification Authorities Store on all supported versions of Microsoft Windows. Comodo advised Microsoft on March 16, 2011 that nine certificates had been [...]]]></description>
			<content:encoded><![CDATA[<p>The full advisory can be found on the Web at: <a href="http://www.microsoft.com/technet/security/advisory/2524375.mspx">http://www.microsoft.com/technet/security/advisory/2524375.mspx</a>.</p>
<p>===========================<br />
SUMMARY<br />
===========================<br />
Microsoft is aware of nine fraudulent digital certificates issued by Comodo, a certification authority present in the Trusted Root Certification Authorities Store on all supported versions of Microsoft Windows. Comodo advised Microsoft on March 16, 2011 that nine certificates had been signed on behalf of a third party without sufficiently validating its identity. These certificates may be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against all Web browser users including users of Internet Explorer.</p>
<p>Certificates for the following Web properties are affected:</p>
<p>• login.live.com<br />
• mail.google.com<br />
•www.google.com<br />
• login.yahoo.com (3 certificates)<br />
• login.skype.com<br />
• addons.mozilla.org<br />
• &#8220;Global Trustee&#8221;</p>
<p>Comodo has revoked these certificates, and they are listed in Comodo’s current Certificate Revocation List (CRL). In addition, browsers which have enabled the Online Certificate Status Protocol (OCSP) will interactively validate these certificates and block them from being used.</p>
<p>An update is available for all supported versions of Windows to help address this issue. For more information about this update, see Microsoft Knowledge Base Article 2524375 (<a href="http://support.microsoft.com/kb/2524375">http://support.microsoft.com/kb/2524375</a>).</p>
<p>Typically, no action is required of customers to install this update, because the majority of customers have automatic updating enabled and this update will be downloaded and installed automatically. For more information, including how to manually install this update, see the Suggested Actions section of this advisory.</p>
<p>===========================<br />
RECOMMENDATIONS<br />
===========================<br />
Review Microsoft Security Advisory 2524375 for an overview of the issue, details on affected components, suggested actions, frequently asked questions (FAQ), and links to additional resources. MSRA Security Partners who are experiencing issues believed to be related to the issues described in this advisory should contact us via e-mail or by calling 888-HELPSEC with your custom Access ID.</p>
<p>===========================<br />
ADDITIONAL RESOURCES<br />
===========================<br />
• Microsoft Security Advisory 2524375 – Fraudulent Digital Certificates Could Allow Spoofing –<a href="http://www.microsoft.com/technet/security/advisory/2524375.mspx">http://www.microsoft.com/technet/security/advisory/2524375.mspx</a></p>
<p>• Microsoft Security Response Center (MSRC) Blog: <a href="http://blogs.technet.com/msrc">http://blogs.technet.com/msrc</a></p>
<p>More details on <a href="http://blogs.comodo.com/it-security/data-security/the-recent-ca-compromise/" target="_blank">Comodo blog</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F03%2Fmicrosoft-is-aware-of-nine-fraudulent-digital-certificates-issued-by-comodo%2F&amp;title=Microsoft%20is%20aware%20of%20nine%20fraudulent%20digital%20certificates%20issued%20by%20Comodo" id="wpa2a_8"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/03/microsoft-is-aware-of-nine-fraudulent-digital-certificates-issued-by-comodo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beware of New year e-cards</title>
		<link>http://hijack-this.co.uk/2011/01/beware-of-new-year-e-cards/</link>
		<comments>http://hijack-this.co.uk/2011/01/beware-of-new-year-e-cards/#comments</comments>
		<pubDate>Sat, 01 Jan 2011 17:18:00 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[fake adverts]]></category>
		<category><![CDATA[fake software]]></category>
		<category><![CDATA[keylogger]]></category>
		<category><![CDATA[protection]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=412</guid>
		<description><![CDATA[Please avoid all untrusted Happy New Year e-card links. The Shadowserver Foundation is warning of a new malicious and advanced botnet that has just been discovered and ressembles the Storm Worm designs. New Fast Flux Botnet for the Holidays: Could it be Storm Worm 3.0/Waledac 2.0? http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20101230 Those of us here at Shadowserver hope you&#8217;re [...]]]></description>
			<content:encoded><![CDATA[<p>Please avoid all untrusted Happy New Year e-card links.  The Shadowserver Foundation is warning of a new malicious and advanced botnet that has just been discovered and ressembles the Storm Worm designs.</p>
<p>New Fast Flux Botnet for the Holidays: Could it be Storm Worm 3.0/Waledac 2.0?<br />
<a href="http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20101230">http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20101230</a><br />
Those of us here at Shadowserver hope you&#8217;re having a wonderful holiday season and are ready to bring in the new year. We were trying to relax and enjoy relatively quiet times until we noticed a new spam campaign that recently started. At first it looked like your regular old holiday e-card scams that have been around for years. </p>
<p>However, upon closer inspection it looks like we could be dealing with the next generation of Storm Worm or Waledac. If you consider Waledac to be Storm Worm 2.0, this looks like it could be version 3.0 or at least Waledac 2.0. There are no real version numbers of course, but we don&#8217;t have anything else to call it yet. What&#8217;s it involve you ask? </p>
<p> CHARACTERISTICS OF NEW BOTNET </p>
<p>Well here&#8217;s the list of what we&#8217;ve seen so far: </p>
<p>* Large scale Spam campaigns sending out e-mails with links<br />
* New malicious domains that are fast flux! (TTL of 0 and name servers that frequently update IPs)<br />
* Links are to several hacked websites hosting HTML pages that refresh to new malicious domains<br />
* Links are also directly to new malicious domains<br />
* Malicious domains hosting links to fake flash player and refreshes to exploit pages<br />
* Malware installs that begin beaching to several hosts over HTTP (what we dubbed HTTP2p with Waledac)<br />
* Malware that&#8217;s been updated to look a bit more like legitimate than past variants<br />
* A very buggy network that is not often available (upstream devices not available)<br />
* Changing/Updated binaries</p>
<p>  AVOID THESE E-CARD MESSAGES: </p>
<p>Let&#8217;s start with the Spam Campaign. We&#8217;ve seen a multitude of subject lines and bodies. Below you&#8217;ll find a list of subjects we&#8217;ve seen and an example e-mail message. These are coming from all over the Internet with spoofed sender addresses. </p>
<p> Greeting for you!<br />
 Greeting you with heartiest New Year wishes<br />
 Greetings to You<br />
 Happy New Year greetings e-card is waiting for you<br />
 Happy New Year greetings for you<br />
 Happy New Year greetings from your friend<br />
 Have a happy and colorful New Year!<br />
 l want to share Greeting with you<br />
 New Year 2011 greetings for you<br />
 You have a greeting card<br />
 You have a New Year Greeting!<br />
 You have received a greetings card<br />
 You&#8217;ve got a Happy New Year Greeting Card!</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F01%2Fbeware-of-new-year-e-cards%2F&amp;title=Beware%20of%20New%20year%20e-cards" id="wpa2a_10"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/01/beware-of-new-year-e-cards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Another Microsoft Security Essentials scam</title>
		<link>http://hijack-this.co.uk/2010/11/another-microsoft-security-essentials-scam/</link>
		<comments>http://hijack-this.co.uk/2010/11/another-microsoft-security-essentials-scam/#comments</comments>
		<pubDate>Fri, 05 Nov 2010 08:30:46 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[fake adverts]]></category>
		<category><![CDATA[fake software]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=395</guid>
		<description><![CDATA[Once again we need to warn you about a scam involving Microsoft Security Essentials Security Essentials is a free Antivirus program from Microsoft available to any windows user with a validated copy of a supported desktop version of windows ( XP SP3, Vista SP2 Windows 7 ) You should only download it from the Microsoft [...]]]></description>
			<content:encoded><![CDATA[<p><!--OffDef--></p>
<p>Once again we need to warn you about a scam involving Microsoft Security Essentials<br />
Security Essentials is a free Antivirus program from <a href="http://www.microsoft.com/security_essentials/">Microsoft </a>available to any windows user with a validated copy of a supported desktop version of windows ( XP SP3, Vista SP2 Windows 7 ) You should only download it from the <a href="http://www.microsoft.com/security_essentials/">Microsoft Security Essentials website </a><br />
The scammers have created a look a like site with links to download Security Essentials BUT following the links you have to create a membership with them &amp; pay for the privilege of downloading free software. It is the same scam that I told you about in <a href="http://hijack-this.co.uk/2010/09/adobe-reader-update-scam/">this post about Adobe Reader</a><br />
This one appears to be a different bunch of scammers but with the same result. They will clear your credit card &amp; sell all your details to anyone they can.<br />
One malware researcher used their links to download Security Essentials &amp; got a nasty trojan instead of the genuine program</p>
<div id="attachment_396" class="wp-caption aligncenter" style="width: 310px"><a class="thickbox" rel="395" href="http://hijack-this.co.uk/wp-content/uploads/2010/11/mse1.jpg" ><img class="size-medium wp-image-396" title="mse1" src="http://hijack-this.co.uk/wp-content/uploads/2010/11/mse1-300x226.jpg" alt="" width="300" height="226" /></a><p class="wp-caption-text">Fake Microsoft Security Essentials site</p></div>
<p><a class="thickbox" rel="395" href="http://hijack-this.co.uk/wp-content/uploads/2010/11/mse2.jpg" ><img class="size-medium wp-image-397 alignnone" title="mse2" src="http://hijack-this.co.uk/wp-content/uploads/2010/11/mse2-300x200.jpg" alt="" width="300" height="200" /></a></p>
<p>If you read carefully, you see they do say in the tiny small print that MSE is a free program and you are paying for the benefit and convenience of downloading it from them instead of the approved free Microsoft site<br />
<a class="thickbox" rel="395" href="http://hijack-this.co.uk/wp-content/uploads/2010/11/mse3.jpg" ><img class="size-medium wp-image-398 alignnone" title="mse3" src="http://hijack-this.co.uk/wp-content/uploads/2010/11/mse3-300x56.jpg" alt="" width="300" height="56" /></a></p>
<p>We stress again that <strong>http://securityessentials-2011.com</strong> is a scam site that is trying to steal your money and is not to be trusted . Only download Microsoft Security Essentials direct from <a href="http://www.microsoft.com/security_essentials/" >Microsoft </a></p>

<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2010%2F11%2Fanother-microsoft-security-essentials-scam%2F&amp;title=Another%20Microsoft%20Security%20Essentials%20scam" id="wpa2a_12"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2010/11/another-microsoft-security-essentials-scam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Skype Update scam</title>
		<link>http://hijack-this.co.uk/2010/09/skype-update-scam/</link>
		<comments>http://hijack-this.co.uk/2010/09/skype-update-scam/#comments</comments>
		<pubDate>Thu, 30 Sep 2010 09:59:06 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[Skype]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[fake adverts]]></category>
		<category><![CDATA[fake software]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=389</guid>
		<description><![CDATA[Following on from my previous post, the scammers are also using Skype The fake website looks like this and the membership page is exactly the same as shown previously Once again Don&#8217;t fall for it only only use the genuine Skype site to download skype &#038; update it]]></description>
			<content:encoded><![CDATA[<p><!--OffDef--><br />
Following on from my previous post, the scammers are also using Skype<br />
<div id="attachment_391" class="wp-caption aligncenter" style="width: 310px"><a class="thickbox" rel="389" href="http://hijack-this.co.uk/wp-content/uploads/2010/09/skypescam1.jpg" ><img src="http://hijack-this.co.uk/wp-content/uploads/2010/09/skypescam1-300x175.jpg" alt="" title="skypescam1" width="300" height="175" class="size-medium wp-image-391" /></a><p class="wp-caption-text">Fake Skype website </p></div><br />
The fake website looks like this and the membership page is exactly the same as shown previously<br />
<div id="attachment_390" class="wp-caption aligncenter" style="width: 310px"><a class="thickbox" rel="389" href="http://hijack-this.co.uk/wp-content/uploads/2010/09/Skypescam_email.jpg" ><img src="http://hijack-this.co.uk/wp-content/uploads/2010/09/Skypescam_email-300x153.jpg" alt="" title="Skypescam_email" width="300" height="153" class="size-medium wp-image-390" /></a><p class="wp-caption-text">Skype email scam</p></div></p>
<p>Once again Don&#8217;t fall for it only only use <a href="http://www.skype.com" target="_blank">the genuine Skype site</a> to download skype &#038; update it </p>

<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2010%2F09%2Fskype-update-scam%2F&amp;title=Skype%20Update%20scam" id="wpa2a_14"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2010/09/skype-update-scam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Reader Update Scam</title>
		<link>http://hijack-this.co.uk/2010/09/adobe-reader-update-scam/</link>
		<comments>http://hijack-this.co.uk/2010/09/adobe-reader-update-scam/#comments</comments>
		<pubDate>Thu, 30 Sep 2010 09:13:30 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[adobe]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[fake adverts]]></category>
		<category><![CDATA[fake software]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=375</guid>
		<description><![CDATA[There are about to be updates issued for Adobe reader to plug security holes and vulnerabilities. The scammers have jumped in on the act and are sending emails pretending to be from an Adobe update service. If you are foolish enough to follow the links then you end up on a scam site trying to [...]]]></description>
			<content:encoded><![CDATA[<p><!--OffDef--><br />
There are about to be updates issued for Adobe reader to plug security holes and vulnerabilities. The scammers have jumped in on the act and are sending emails pretending to be from an Adobe  update service.<br />
<div id="attachment_376" class="wp-caption aligncenter" style="width: 310px"><a class="thickbox" rel="375" href="http://hijack-this.co.uk/wp-content/uploads/2010/09/pdfscam_email.jpg" ><img src="http://hijack-this.co.uk/wp-content/uploads/2010/09/pdfscam_email-300x142.jpg" alt="" title="pdfscam_email" width="300" height="142" class="size-medium wp-image-376" /></a><p class="wp-caption-text">Adobe PDF scam email </p></div></p>
<p>If you are foolish enough to follow the links then you end up on a scam site trying to sell you an unknown PDF reader, BUT the sting is that you don&#8217;t just download &#038; try it or even buy it outright. Oh no ! you have to create a  membership and give all your details before you even find out how much is being taken from your bank or credit card.  </p>
<p><a class="thickbox" rel="375" href="http://hijack-this.co.uk/wp-content/uploads/2010/09/pdf_scam.jpg" ><img src="http://hijack-this.co.uk/wp-content/uploads/2010/09/pdf_scam-298x300.jpg" alt="" title="pdf_scam" width="298" height="300" class="alignleft size-medium wp-image-379" /></a><a class="thickbox" rel="375" href="http://hijack-this.co.uk/wp-content/uploads/2010/09/pdfscam2.jpg" ><img src="http://hijack-this.co.uk/wp-content/uploads/2010/09/pdfscam2-300x218.jpg" alt="" title="pdfscam2" width="300" height="218" class="alignright size-medium wp-image-380" /></a><br />
Don&#8217;t fall for it and only update Adobe reader from the<a href="http://www.adobe.com/" target="_blank"> official Adobe site</a>, when the actual Update is released ( It is expected in Early October 2010)<br />
Or of course use an alternative PDF reader of your choice, Just be aware that PDF vulnerabilities do affect all PDF readers and some might not get updated as quickly as others. Just because you use an alternative doesn&#8217;t mean that you are immune or safe from vulnerabilities in Adobe products </p>

<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2010%2F09%2Fadobe-reader-update-scam%2F&amp;title=Adobe%20Reader%20Update%20Scam" id="wpa2a_16"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2010/09/adobe-reader-update-scam/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Fake Microsoft Malicious Software Removal tool</title>
		<link>http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/</link>
		<comments>http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/#comments</comments>
		<pubDate>Wed, 11 Aug 2010 16:57:37 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=311</guid>
		<description><![CDATA[It was brought to my attention by sUBs, a malware researcher who developed Combofix ( a tool to help remove persistant malware threats &#38; rogue scamware from infected computers) that a fake Microsoft malicious software removal tool is spreading This total piece of scamware is designed to imitate the genuine MMSRT &#38; has the usual [...]]]></description>
			<content:encoded><![CDATA[<p>It was brought to my attention by sUBs, a malware researcher who developed Combofix ( a tool to help remove persistant malware threats &amp; rogue scamware from infected computers) that a fake Microsoft malicious software removal tool is spreading<br />
This total piece of scamware is designed to imitate the genuine MMSRT &amp; has the usual fake detections &amp; then entices you buy the latest rogue scamware Shield EC Antivirus which our good friends <a href="http://sunbeltblog.blogspot.com/2010/07/shield-ec-rogue-security-product-that.html" target="_blank">Sunbelt Software have blogged about.</a><br />
The last screen clearly shows that they want you to buy this useless scamware</p>

<a href='http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/rogue_1/' title='Rogue_1'><img width="150" height="106" src="http://hijack-this.co.uk/wp-content/uploads/2010/08/Rogue_1-150x106.png" class="attachment-thumbnail" alt="Rogue_1" title="Rogue_1" /></a>
<a href='http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/rogue_1a/' title='Rogue_1A'><img width="150" height="137" src="http://hijack-this.co.uk/wp-content/uploads/2010/08/Rogue_1A-150x137.png" class="attachment-thumbnail" alt="Rogue_1A" title="Rogue_1A" /></a>
<a href='http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/rogue_1b/' title='Rogue_1B'><img width="150" height="137" src="http://hijack-this.co.uk/wp-content/uploads/2010/08/Rogue_1B-150x137.png" class="attachment-thumbnail" alt="Rogue_1B" title="Rogue_1B" /></a>
<a href='http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/rogue_1c/' title='Rogue_1C'><img width="150" height="137" src="http://hijack-this.co.uk/wp-content/uploads/2010/08/Rogue_1C-150x137.png" class="attachment-thumbnail" alt="Rogue_1C" title="Rogue_1C" /></a>

<p>The installer for this piece of malware is detected by several Antiviruses currently as shown on this <a href="http://www.virustotal.com/file-scan/report.html?id=73b0e3dc9a74f97892194efe47886957232a2e72374a0a57bccb64b81bff29e6-1281535897" target="_blank">Virus Total </a>report page</p>
<p>If you are unfortunate to be infected by this piece of scamware, it can be difficult to remove. Don&#8217;t fall for all the other scams on the net saying you need to buy other software to remove it. Ask for help on our malware cleaning forum <a href="http://thespykiller.co.uk" target="_blank">http://thespykiller.co.uk</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2010%2F08%2Ffake-microsoft-malicious-software-removal-tool%2F&amp;title=Fake%20Microsoft%20Malicious%20Software%20Removal%20tool" id="wpa2a_18"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>WOW  wowmatrix keylogger</title>
		<link>http://hijack-this.co.uk/2009/11/wow-keylogger/</link>
		<comments>http://hijack-this.co.uk/2009/11/wow-keylogger/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 11:00:42 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[games]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[fake adverts]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[keylogger]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[world of warcraft]]></category>
		<category><![CDATA[wowmatrix]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=227</guid>
		<description><![CDATA[I was notified of a google advert for a fake wowmatrix site. The original genuine wowmatrix is seen by many games players as not completely within the rules of the games Wowmatrix is an addon that makes it easier to update and install other tweaks and addons to your game. Obviously using a fake version [...]]]></description>
			<content:encoded><![CDATA[<p><br />
I was notified of a google advert for a fake wowmatrix site. The original genuine wowmatrix is seen by many games players as not completely within the rules of the games<br />
Wowmatrix is an addon that makes it easier to update and install other tweaks and addons to your game. Obviously using a fake version that downloads false addons &#038; tweaks and installs them leaves you open to a lot of problems. </p>
<p>The advert on google looks like a search listing and it is only apparant that it is a sponsored listing or advert on close inspection</p>
<p><a class="thickbox" rel="227" href="http://hijack-this.co.uk/wp-content/uploads/2009/11/wowmatrix.PNG" ><img class="size-medium wp-image-228 aligncenter" title="wowmatrix" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/wowmatrix-300x148.PNG" alt="wowmatrix" width="300" height="148" /></a><span id="more-227"></span></p>
<p>if you look at the screenshots of the 2 sites, you will see that there is very little difference between them and an unwary visitor can soon get infected</p>
<p>Don&#8217;t get caught out by it and get your passwords stolen. The downloads on the fake site are recognized by several antiviruses as a password stealer and downloads lots of other trojans and malware</p>
<p>the genuine site is on the left, the fake site on the right</p>
<table border="0">
<tbody>
<tr>
<td><a class="thickbox" rel="227" href="http://hijack-this.co.uk/wp-content/uploads/2009/11/genuine_wowmatrix.PNG" ><img title="genuine_wowmatrix" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/genuine_wowmatrix-300x297.PNG" alt="genuine_wowmatrix" width="300" height="297" /></a></td>
<td><a class="thickbox" rel="227" href="http://hijack-this.co.uk/wp-content/uploads/2009/11/fake_wowmatrix1.PNG" ><img title="fake_wowmatrix" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/fake_wowmatrix1-300x291.PNG" alt="fake_wowmatrix" width="300" height="291" /></a></td>
</tr>
</tbody>
</table>
<p style="text-align: left;"><strong>I strongly recommend using <a href="http://www.roboform.com/php/land.php?affid=dvk01&amp;frm=frame17" target="_blank">ROBOFORM </a>which keeps all passwords in a secure encrypted database that only you (not a keylogger or malware) can access and use it to create safe secure passwords</strong></p>
<p><a href="http://www.roboform.com/php/land.php?affid=dvk01&amp;frm=frame17" target="_blank"><img src="http://www.roboform.com/affiliates/banners/728x90-warning3-free.gif" border="0" alt="RoboForm: Learn more..." width="728" height="90" /></a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2009%2F11%2Fwow-keylogger%2F&amp;title=WOW%20%20wowmatrix%20keylogger" id="wpa2a_20"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/wow-keylogger/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

