<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: SpyAxe -&#x3E; SpywareStrike in Security</title>
<link>http://www.dslreports.com/forum/r15201676</link>
<description></description>
<language>en</language>
<pubDate>Sun, 29 Nov 2009 03:59:58 EDT</pubDate>
<lastBuildDate>Sun, 29 Nov 2009 03:59:58 EDT</lastBuildDate>

<item>
<title>Re: SpyAxe -&#x3E; SpywareStrike</title>
<link>http://www.dslreports.com/forum/remark,15273885</link>
<description><![CDATA[<A HREF="/useremail/u/1162456"><b>fatdcuk</b></A> : <div class="bquote"><SMALL>said by  TeMerc <A HREF="/useremail/u/937383"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>But is the SpySherriff\SpyTrooper\SpyDemolisher\Spyware-Stop gang also related to the SpyAxe\SpywareStrike bunch?<br><br>And if so what links connect them?<br> </DIV>"bottom feeder's" is a definite common denominator present]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15273885</guid>
<pubDate>Wed, 18 Jan 2006 15:53:38 EDT</pubDate>
</item>

<item>
<title>Re: SpyAxe -&#x3E; SpywareStrike</title>
<link>http://www.dslreports.com/forum/remark,15270206</link>
<description><![CDATA[<A HREF="/useremail/u/618942"><b>bobince</b></A> :  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>But is the SpySheriff\SpyTrooper\SpyDemolisher\Spyware-Stop gang also related to the SpyAxe\SpywareStrike bunch?<HR></BLOCKQUOTE><br><br>Apart from having the same business model, affiliating with the same Russian adult webmasters, and using the same old dodgy hosting companies as the rest of CWSdom - no, not as far as I can tell. Here's a whois dump of servers associated with them:<br><br><PRE>SpyAxe rogue antispyware and scare ads<br>same interface as antivirusgold, adwaredelete (Impro group)<br>  @cogent<br>    ns4.aboutjohnniewalker.biz    66.250.170.82       David Taylor SunShine Alant<br>    ns4.almanah.biz               66.250.170.82       Joshua Veronimo Olongapo<br>  @pilosoft<br>    ns2.aboutjohnniewalker.biz    69.31.93.162        David Taylor SunShine Alant<br>    ns2.almanah.biz               69.31.93.162        Joshua Veronimo Olongapo<br>    spyaxesupport.com             69.31.131.82        David Taylor SunShine Alant<br>  @esthost<br>    malwarewipe.com               85.255.114.202      Michael Rodriges Olongapo<br>    ns5.almanah.biz               85.255.114.202      Joshua Veronimo Olongapo<br>    download6.spyaxe.net          85.255.114.203      David Taylor SunShine Alant<br>    antiwatch.com                 85.255.114.203      David Taylor SunShine Alant<br>    malwarewipesupport.com        85.255.114.206      David Taylor SunShine Alant<br>    malwarewipeupdate.com         85.255.114.206      David Taylor SunShine Alant<br>  @netcat<br>    spyaxe.com                    195.225.176.68      David Taylor SunShine Alant<br>    spyaxe.biz                    195.225.176.68      David Taylor SpyAxe Alant<br>    spyaxe.net                    195.225.176.68      David Taylor SpyAxe Alant<br>    ns1.aboutjohnniewalker.biz    195.225.176.68      David Taylor SunShine Alant<br>    ns1.almanah.biz               195.225.176.68      Joshua Veronimo Olongapo<br>    almanah.biz                   195.225.176.68      Joshua Veronimo Olongapo<br>    nospywaresoft.com             195.225.176.68      David Taylor Keramitsu<br>    spywarestrike.com             195.225.176.68      David Taylor Keramitsu<br>    ns3.aboutjohnniewalker.biz    195.225.176.76      David Taylor SunShine Alant<br>    ns3.almanah.biz               195.225.176.76      Joshua Veronimo Olongapo<br>  @atrivo<br>    ns6.almanah.biz               216.255.183.2       Joshua Veronimo Olongapo</PRE><br><br>Whereas here's the SpySheriff et al gang (who are indeed also responsible for the new PestTrap).<br><br><PRE>SpywareNo gang, italian-bilanguage exploit hub redir from new megatds.<br>expdialer used as target in server hackings. user nullday on umaxforum.<br>ICQ 3317159. linked to sgrunt, WB.<br>  @aps<br>    mongoliadc.org                64.124.84.147       Alexandre Krouglov Peter teensgate<br>    buscando.org                  64.124.84.147       Alexandre Krouglov Peter teensgate<br>    jlojc.org                     64.124.84.147       Alexandre Krouglov Peter teensgate<br>    buy-cheap-vioxx.com           64.124.84.148       Alexandre Krouglov Peter teensgate<br>  @pilosoft<br>    goldgaypost.com               69.31.128.141       Albert Hendrik Euro Tech nullday<br>  @atrivo<br>    smart-security.info           69.50.166.194       Aleksandr Romantsev Overijse<br>    bridgeuk.org                  69.50.166.194       Alexandre Krouglov Peter teensgate<br>    spywareno.com                 69.50.166.196       Alexandre Petrov Moscow<br>    spyware-cash.com              69.50.166.196       Alexandre Ivanov Ecuador<br>    spyware-stop.com              69.50.166.196       ExpDialer markus nullday<br>    pesttrap.com                  69.50.167.173       Alison Popandopulos crystaljones<br>    ns1.pesttrap.com              69.50.168.101       Alison Popandopulos crystaljones<br>    spytrooper.com                69.50.170.82        Alison Popandopulos crystaljones<br>    spysheriff.com                69.50.170.83        Alexandre Ivanov Ecuador<br>    spy-trooper.com               69.50.170.83        Alexandre Ivanov Ecuador<br>    spydemolisher.com             69.50.170.84        Alexandre Ivanov Ecuador<br>    pillsbook.com                 69.50.170.86        Alex Circle Moscow teensgate<br>  @theplanet<br>    karamoke.com                  70.84.54.50         Alexandre Mikoni Peter tamej<br>    tamej.com                     70.84.54.51         Egor Abramov Peter<br>  @uaonline<br>    guysgalleries.com             80.77.88.27         Albert Hendrik Euro Tech nullday<br>    gaylovetwinks.com             80.77.88.27         Albert Hendrik Euro Tech nullday<br>    picboys.net                   80.77.88.27         Albert Hendrik Euro Tech nullday<br>  @livas.lv<br>  * expdialer.com                 84.245.216.10       ExpDialer markus nullday<br>  @esthost<br>    1listing.org                  85.255.115.138      Alexandre Krouglov Peter teensgate<br>    tlc-pregled.com               85.255.115.138      Alexandre Zixer Peter teensgate<br>  @aps - expired domain name trade<br>    beactiveamerica.org           208.184.65.253      Alexandre Krouglov Peter teensgate<br>    714ministries.org             208.184.65.253      Alexandre Krouglov Peter teensgate<br>    adwareno.com                  208.184.65.253      Alexandre Krouglov Peter teensgate<br>    baccarat-winning.com          208.184.65.253      Alexandre Krouglov Peter teensgate<br>    cozin.org                     208.184.65.253      Alexandre Krouglov Peter teensgate<br>    paperrepublic.com             208.184.65.253      Alexandre Krouglov Peter teensgate<br>    touringlondon.org             208.184.65.253      Alexandre Krouglov Peter teensgate<br>    commodity-trading-online.com  208.184.65.254      Alexandre Krouglov Peter teensgate<br>    ninetozero.org                208.184.65.254      Alexandre Krouglov Peter teensgate<br>    unspyware.com                 208.184.65.254      Alexandre Krouglov Peter mongoliadc<br>    wolfgang-lehner.net           208.184.65.254      Alexandre Krouglov Peter teensgate<br>    ghostinc.org                  209.66.115.248      Alexandre Krouglov Peter teensgate<br>    simple-mortgage-calculator.com209.66.115.248      Alexandre Krouglov Peter teensgate<br>    telipay.com                   209.66.115.248      Alexandre Krouglov Peter teensgate<br>    autodialblocker.com           209.66.115.249      Alexandre Petrov Peter teensgate<br>    celleros.com                  209.66.115.249      Alexandre SearchMeta beactiveamerica<br>    lyricsongmusic.com            209.66.115.249      Alexandre Krouglov Peter teensgate<br>    skiins.com                    209.66.115.249      Alexandre Krouglov Peter teensgate<br>  @enom parking<br>    teensgate.com                 63.251.83.53        Alexandre Krouglov Peter mediaheap<br>  dns broken?<br>  * traffcash.com                                     ExpDialer markus nullday</PRE><br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15270206</guid>
<pubDate>Wed, 18 Jan 2006 05:07:11 EDT</pubDate>
</item>

<item>
<title>Re: SpyAxe -&#x3E; SpywareStrike</title>
<link>http://www.dslreports.com/forum/remark,15270009</link>
<description><![CDATA[<A HREF="/useremail/u/378696"><b>eburger68</b></A> : Andrew:<br><br>Good catch! Here's yet another SpySheriff clone that popped up:<br><br>PestTrap (pesttrap.com)<br>Info: &raquo;<A HREF="http://spywarewarrior.com/viewtopic.php?t=19219" >spywarewarrior.com/viewtopic.php?t=19219</A><br><br>Best,<br><br>Eric L. Howes<br><SMALL>--<br>Microsoft MVP<BR>Sunbelt Software<BR>Spyware Warrior</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15270009</guid>
<pubDate>Wed, 18 Jan 2006 02:59:04 EDT</pubDate>
</item>

<item>
<title>Re: SpyAxe -&#x3E; SpywareStrike</title>
<link>http://www.dslreports.com/forum/remark,15267812</link>
<description><![CDATA[<A HREF="/useremail/u/937383"><b>TeMerc</b></A> : But is the SpySherriff\SpyTrooper\SpyDemolisher\Spyware-Stop gang also related to the SpyAxe\SpywareStrike bunch?<br><br>And if so what links connect them?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15267812</guid>
<pubDate>Tue, 17 Jan 2006 19:19:40 EDT</pubDate>
</item>

<item>
<title>Re: SpyAxe -&#x3E; SpywareStrike</title>
<link>http://www.dslreports.com/forum/remark,15267209</link>
<description><![CDATA[<A HREF="/useremail/u/618942"><b>bobince</b></A> : Hi Eric!<br><br>Whooboy. Have you looked at the whois info for spyware-stop.com? It's good old markus-nullday-ExpDialer.<br><br>Which finally confirms the long-suspected link between the SpywareNo/SpySheriff/SpyTropper/SpyDemolisher gang and CWS exploits. (Other than that CWS exploits so often install them.)<br><br>expdialer.com/traffcash.com is/was itself a significant CWS affiliate hub from which the exploits were served. So looks like the SpywareNo gang are themselves criminal exploit-installers.<br><br>Which isn't like any great surprise or anything of course.<br><br>Edit: www.master-x.com/forum/postings/464302 - if the fish's translation is accurate, here's "markus" asking for affiliates to promote Spyware-Stop by all means including unsolicited downloads.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15267209</guid>
<pubDate>Tue, 17 Jan 2006 17:56:17 EDT</pubDate>
</item>

<item>
<title>Re: SpyAxe -&#x3E; SpywareStrike</title>
<link>http://www.dslreports.com/forum/remark,15261974</link>
<description><![CDATA[<A HREF="/useremail/u/1193253"><b>SpannerITWks</b></A> : They must have been in such a rush to bang it out, and with All those different versions too, they musta got confused which product they are trying to foist on people this time.<br><br>It's got SpywareNo! plastered all over the panels etc lol.<br><br>&raquo;<A HREF="http://www.spyware-stop.com/help.php#r9" >www.spyware-stop.com/help.php#r9</A><br><br>Don't you just weep for them hey !<br><br>Spanner<br><SMALL>--<br>I Only Know What I Know, But I'm Learning all The Time - Stay Safe - Spanner intheWorks/SpannerITWks</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15261974</guid>
<pubDate>Mon, 16 Jan 2006 23:43:45 EDT</pubDate>
</item>

<item>
<title>Re: SpyAxe -&#x3E; SpywareStrike</title>
<link>http://www.dslreports.com/forum/remark,15261890</link>
<description><![CDATA[<A HREF="/useremail/u/378696"><b>eburger68</b></A> : Hi All:<br><br>More "wonderful" news from the rogue anti-spyware front: the universally loved SpySheriff has also spawned yet another clone: Spyware-Stop (spyware-stop.com). Screenshots here:<br><br>&raquo;<A HREF="http://www.spywarewarrior.com/family_resemblances.htm#15" >www.spywarewarrior.com/family_re&middot;&middot;&middot;s.htm#15</A><br><br>That's rogue family # 15 above. Families #17, #18, #19, #20, #21, and #22 (visible lower on the same page) contain most of the rest of the CWS-related rogue anti-spyware apps<br><br>Best,<br><br>Eric L. Howes<br><SMALL>--<br>Microsoft MVP<BR>Sunbelt Software Consultant<BR>Spyware Warrior</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15261890</guid>
<pubDate>Mon, 16 Jan 2006 23:29:49 EDT</pubDate>
</item>

<item>
<title>Re: SpyAxe -&#x3E; SpywareStrike</title>
<link>http://www.dslreports.com/forum/remark,15201676</link>
<description><![CDATA[<A HREF="/useremail/u/937383"><b>TeMerc</b></A> : There may also be an association with the following apps:<br>Program Files\Crystalys Media and \\Program Files\Video iCodec<br><br>Seems noahadfear is looking for info on them, but not what is linked to below.<br><br>Additional info provided by a user at TC:<br>&raquo;<A HREF="http://forums.tomcoyote.org/index.php?showtopic=55547" >forums.tomcoyote.org/index.php?s&middot;&middot;&middot;ic=55547</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15201676</guid>
<pubDate>Sun, 08 Jan 2006 21:04:11 EDT</pubDate>
</item>

<item>
<title>Re: SpyAxe -&#x3E; SpywareStrike</title>
<link>http://www.dslreports.com/forum/remark,15201058</link>
<description><![CDATA[<A HREF="/useremail/u/1065964"><b>Corrine</b></A> : <div class="bquote"><SMALL>said by  Profixer <A HREF="/useremail/u/1227122"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>...I just popped into work to put up a desk...<br> </DIV>That is no way to spend a Sunday.  There's no limit to the talents of LS Research!  <br><SMALL>--<br>Microsoft MVP, Windows - Security; Administrator Freedomlist & LandzDown; Charter Member ASAP</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15201058</guid>
<pubDate>Sun, 08 Jan 2006 19:31:27 EDT</pubDate>
</item>

<item>
<title>Re: SpyAxe -&#x3E; SpywareStrike</title>
<link>http://www.dslreports.com/forum/remark,15200876</link>
<description><![CDATA[<A HREF="/useremail/u/856028"><b>winchester73</b></A> : We would be up a creek without a paddle if noahdfear wasn't updating his tool so frequently.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15200876</guid>
<pubDate>Sun, 08 Jan 2006 19:05:11 EDT</pubDate>
</item>

<item>
<title>Re: SpyAxe -&#x3E; SpywareStrike</title>
<link>http://www.dslreports.com/forum/remark,15198025</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : We started seeing this on Jan 5th.  In fact,  suzi <A HREF="/useremail/u/999833"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> wrote up a nice blog on the new SpyAxe twin, SpywareStrike.<br>&raquo;<A HREF="http://blogs.zdnet.com/Spyware/index.php?p=742" >blogs.zdnet.com/Spyware/index.php?p=742</A><br><br>Unfortunately, I'm sure we'll see more of these smitfraud variants, using many different exploits.  I'm glad Lavasoft is working hard to keep up with these :)<br><br><I>Edit:  typo</I><br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR><br>Microsoft MVP/Windows Security 2003-2006<br><br><BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15198025</guid>
<pubDate>Sun, 08 Jan 2006 11:10:49 EDT</pubDate>
</item>

<item>
<title>Re: SpyAxe -&#x3E; SpywareStrike</title>
<link>http://www.dslreports.com/forum/remark,15198009</link>
<description><![CDATA[<A HREF="/useremail/u/1162456"><b>fatdcuk</b></A> : Thats great news LS Steve<br><br>SmitRem C/O NoAdFear has already updated his tool to take care of this new variant.<br>&raquo;<A HREF="http://www3.dslreports.com/faq/13542" >www3.dslreports.com/faq/13542</A><br><br>Also MIcrosoft released a patch for the WMF exploit on 5/1/06<br>&raquo;<A HREF="http://www3.dslreports.com/forum/remark,15177537~start=0" >www3.dslreports.com/forum/remark&middot;&middot;&middot;~start=0</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15198009</guid>
<pubDate>Sun, 08 Jan 2006 11:07:08 EDT</pubDate>
</item>

<item>
<title>Re: SpyAxe -&#x3E; SpywareStrike</title>
<link>http://www.dslreports.com/forum/remark,15197988</link>
<description><![CDATA[<A HREF="/useremail/u/917630"><b>Cudni</b></A> : It never ends. Thanks for heads up<br><br>Cudni]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15197988</guid>
<pubDate>Sun, 08 Jan 2006 11:02:07 EDT</pubDate>
</item>

<item>
<title>SpyAxe -&#x3E; SpywareStrike</title>
<link>http://www.dslreports.com/forum/remark,15197950</link>
<description><![CDATA[<A HREF="/useremail/u/1227122"><b>Profixer</b></A> : Hey All... just a heads up to let you know that SpyAxe has had a baby...Spyware Strike. The website is on the same IP for spyaxe (spywarestrike.com). We have been receiving reports of this one installed using WMF exploits and will be adding it to detection ASAP... (yes yes I know its sunday... I just popped into work to put up a desk) I hope MS fix the WMF problem on tuesday.. its gettin outa' hand....]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15197950</guid>
<pubDate>Sun, 08 Jan 2006 10:54:31 EDT</pubDate>
</item>

</channel>
</rss>
