<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Another WinFixer infiltration...this time on www.wfaa.com in Security</title>
<link>http://www.dslreports.com/forum/r18551684</link>
<description></description>
<language>en</language>
<pubDate>Fri, 27 Nov 2009 05:02:25 EDT</pubDate>
<lastBuildDate>Fri, 27 Nov 2009 05:02:25 EDT</lastBuildDate>

<item>
<title>Dallas routing:</title>
<link>http://www.dslreports.com/forum/remark,18578382</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : Related info:  &raquo;<A HREF="/forum/remark,18578373">Re: Is msmvps.com down?</A><br><br>:)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18578382</guid>
<pubDate>Wed, 27 Jun 2007 21:53:38 EDT</pubDate>
</item>

<item>
<title>Re: Contact with wfaa -</title>
<link>http://www.dslreports.com/forum/remark,18578362</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : <div class="bquote"><SMALL>said by  Just Bob <A HREF="/useremail/u/185348"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Gee, ya don't think they did a take down on msmvps.com, do ya?<br><br>EDIT: I should have added a smiley...or maybe not.<br>There are reports in the Dallas are of up to 18" of rain, record flooding, tens of thousands without power, and at least one fatality.<br> </DIV>3rd wettest June on record, and there is more rain yet to<br>come. Forecasters are saying it could continue through the<br>middle of next week.<br><br>Back on topic, a traceroute to msmvps.com seems to crap out<br>at COLO4-DALLA.car2.Dallas1.Level3.net. Considering how<br>much trouble there has been with their routers, it could<br>be related (the more conspiracy minded would think it was<br>a DDoS courtesy of the Winfixer gang, angry at being outed<br>by Sandi yet again.) <br><SMALL>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br>We are the Hacker Collective: Resistance Is Futile - All Your AACS Keys Will Be Assimilated.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18578362</guid>
<pubDate>Wed, 27 Jun 2007 21:49:39 EDT</pubDate>
</item>

<item>
<title>This problem has been escalated  ----</title>
<link>http://www.dslreports.com/forum/remark,18578327</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : Original Message:<br>-----------------<br>From: xxxxxxxxxxxxxxxxxxxxxx<br>Date: Tue, 26 Jun 2007 11:38:45 -0500 (CDT)<br>To: amysheehan    dslr.net<br>Subject:<B> CASE-1136394c277.93.88.fa.72.2-CASE - www.wfaa.com</B><br><br>Dear Amy,<br><br>Thank you so much for taking the time to write us.  <br><br>Your question has been forwarded to the appropriate department at WFAA.com.<br><br>We appreciate your feedback. <br><br>Thank you for your continued support.<br><br>Best Regards,<br>Mike<br><SMALL>--<br><A HREF="http://www.dslreports.com/phishtrack">DSLR Phishtracker</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18578327</guid>
<pubDate>Wed, 27 Jun 2007 21:40:38 EDT</pubDate>
</item>

<item>
<title>Re: Contact with wfaa -</title>
<link>http://www.dslreports.com/forum/remark,18578072</link>
<description><![CDATA[<A HREF="/useremail/u/185348"><b>Just Bob</b></A> : Gee, ya don't think they did a take down on msmvps.com, do ya?<br><br>EDIT: I should have added a smiley...or maybe not.<br>There are reports in the Dallas area of up to 18" of rain, record flooding, tens of thousands without power, and at least one fatality.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18578072</guid>
<pubDate>Wed, 27 Jun 2007 20:55:03 EDT</pubDate>
</item>

<item>
<title>Contact with wfaa -</title>
<link>http://www.dslreports.com/forum/remark,18577900</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : <BLOCKQUOTE><br><br>Original Message:<br>-----------------<br>From: xxxxxxxx.belointeractive@abc.com<br>Date: Mon, 25 Jun 2007 10:51:37 -0500 (CDT)<br>To: amysheehan================dslr.net<br>Subject: Customer Service Inquiry - www.wfaa.com<br><br>Dear Amy-<br><br>We have received your comment and will get back with you shortly.<br><br>***************** Your feedback *****************<br>Please have a look at this topic posted at dslreports re your website and<br>winfixer ads being served on Sunday<br>&raquo;<A HREF="/forum/r18551684-Another-WinFixer-infiltrationthis-">Another WinFixer infiltration...this time on www.wfaa.com</A><br>time-on-wwwwfaacom<br><br>I can't replicate the problem today but I think you need to have a look at<br>recent advertising changes that may have caused this problem.<br><br>I am registered as amysheehan @ dslreports and I am an executive online news producer<br>in Los Angeles for a network O/O station at xxxxx<br>My work email address isxxxxxxx@#####.com and you may reach me directly @ 818mmmmmmmm.<br>I have shared this info with our IT director for website operations who asked that I relay his offer of assistance for your online service issues.<br><br>Sincerely<br>Amy Sheehan<br>Huntington Beach, CA<br><br>Please feel free to contact me at my work email address or phone number if you would like specifics or background<br>info re this problem.<br>-amy-<br><br></BLOCKQUOTE><br><SMALL>--<br><A HREF="http://www.dslreports.com/phishtrack">DSLR Phishtracker</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18577900</guid>
<pubDate>Wed, 27 Jun 2007 20:18:21 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18571499</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : I'm beginning to wonder if Belo doesn't care that their<br>websites are serving up malware, and that the only way<br>to get them to take notice is to tell their competition<br>about it (here in DFW that would be myfoxdfw.com, nbc5i.com,<br>and cbs11tv.com).<br><br>A few years ago, wfaa.com was asking rather intrusive<br>personal questions you had to answer in order to visit<br>much of their site; so much so that whenever I wanted to<br>visit a local network's website, it was never theirs. <br><br>My mom's PC now has the MVPS hosts file on it, and I was<br>able to get it to install on one machine at work that is<br>not part of the network controlled by the company's IT<br>department - it is part of our lab LAN, and we can install<br>pretty much anything, short of copying files to or modifying<br>files on the network drives. I also put Firefox on it, <br>which is less susceptible to this kind of hostile<br>redirect.<br><SMALL>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br>We are the Hacker Collective: Resistance Is Futile - All Your AACS Keys Will Be Assimilated.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18571499</guid>
<pubDate>Tue, 26 Jun 2007 18:17:32 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18571430</link>
<description><![CDATA[<A HREF="/useremail/u/996768"><b>jbob</b></A> : Looks like a canned response.  I bet if you sent a message to the competing stations in the area this issue would be fixed much faster. Can you imagine the other stations reporting this about WFAA?   :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18571430</guid>
<pubDate>Tue, 26 Jun 2007 18:06:29 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18571391</link>
<description><![CDATA[<A HREF="/useremail/u/185348"><b>Just Bob</b></A> : I'm not very encouraged.<br><br>Perhaps if a large number of people were to file a complainant...<br><br>Dear Bob,<br><br>Thank you for your e-mail. <br><br>Everyone here at WFAA.com strives everyday to provide the most personally relevant news and information for our customers. And, it is through customer feedback that we are best able to meet customer needs, preferences and wishes. <br>We appreciate your feedback.<br><br>Thank you again for your e-mail. We encourage you to e-mail us again with any other comments, questions, concerns or complaints you may have.<br><br>Best Regards,<br><br>LaTonya S.<br><br>--------Original Message-------------<br>From: Bob <br>To: null<br>Date: 26-JUN-2007 11:21AM<br><br>It seems your site is serving ads for malware via Real Media and Valueclick:<br>&raquo;<A HREF="http://msmvps.com/blogs/spywaresucks/default.aspx" >msmvps.com/blogs/spywaresucks/default.aspx</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18571391</guid>
<pubDate>Tue, 26 Jun 2007 17:58:29 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18569688</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : This is likely happening on all Belo owned websites,<br>considering that the vector for the malicious redirects<br>is their own ad company, belointeractive (via RealMedia).<br><br>Which means that the website for the Dallas Morning News,<br>dallasnews.com, may also have the same problem. Though here<br> it could hit them in the bottom line as they will likely <br>lose quite a few subscriptions from people who have gone to <br>the site and gotten infected. <br><SMALL>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br>We are the Hacker Collective: Resistance Is Futile - All Your AACS Keys Will Be Assimilated.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18569688</guid>
<pubDate>Tue, 26 Jun 2007 12:46:16 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18568754</link>
<description><![CDATA[<A HREF="/useremail/u/185348"><b>Just Bob</b></A> : <div class="bquote"><SMALL>said by  Just Bob <A HREF="/useremail/u/185348"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>BTW, Sandi has seen this thread. Keep an eye on her blog.<br>&raquo;<A HREF="http://msmvps.com/blogs/spywaresucks/default.aspx" >msmvps.com/blogs/spywaresucks/default.aspx</A><br> </DIV>Sandi has blogged. She found that ultimately these infected ads come from Real Media and Valueclick.<br><br>&raquo;<A HREF="http://msmvps.com/blogs/spywaresucks/default.aspx" >msmvps.com/blogs/spywaresucks/default.aspx</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18568754</guid>
<pubDate>Tue, 26 Jun 2007 09:50:58 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18566427</link>
<description><![CDATA[<A HREF="/useremail/u/185348"><b>Just Bob</b></A> : Wow!<br><br>BTW, Sandi has seen this thread. Keep an eye on her blog.<br>&raquo;<A HREF="http://msmvps.com/blogs/spywaresucks/default.aspx" >msmvps.com/blogs/spywaresucks/default.aspx</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18566427</guid>
<pubDate>Mon, 25 Jun 2007 20:42:33 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18566407</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : Winfixer hosts entries (from the June 14th MVPS hosts file):<br><br># [Innovative Marketing Group][NSCACHE.NET][SetupAHost]<br>127.0.0.1  adnetserver.com<br>127.0.0.1  www.adnetserver.com<br>127.0.0.1  adserver.affiliatemg.com<br>127.0.0.1  amaena.com<br>127.0.0.1  www.amaena.com #[IE-SpyAd][Trojan.TrustedZone]<br>127.0.0.1  www.amxtravel.com<br>127.0.0.1  www.antivirus-comparison.com<br>127.0.0.1  www.antivirusproshop.com<br>127.0.0.1  ads2desk.com<br>127.0.0.1  www.bestofonlinesearch.com<br>127.0.0.1  www.bestsearchnet.com<br>127.0.0.1  betbonus.com<br>127.0.0.1  www.betbonus.com<br>127.0.0.1  www.billingcomplete.com<br>127.0.0.1  billingnow.com #[Trojan.TrustedZone]<br>127.0.0.1  secure.billingnow.com<br>127.0.0.1  www.billingnow.com<br>127.0.0.1  stats.bookmyfares.com<br>127.0.0.1  www.bookmyfares.com<br>127.0.0.1  www.cannis.org<br>127.0.0.1  www.casinoaceking.com<br>127.0.0.1  www.clickwwwsearch.com<br>127.0.0.1  www.completebilling.com<br>127.0.0.1  www.computershield.com<br>127.0.0.1  locator.contentsvc.com<br>127.0.0.1  www.creditsecretguide.com<br>127.0.0.1  cdn.downloadcontrol.com #[setuphost.vo.llnwd.net][Win32/Adware.WinFixer]<br>127.0.0.1  drivecleaner.com #[McAfee.FakeAlert-I]<br>127.0.0.1  cdn.drivecleaner.com<br>127.0.0.1  dynamique.drivecleaner.com<br>127.0.0.1  freeware.updates.drivecleaner.com<br>127.0.0.1  go.drivecleaner.com #[eTrust.Win32/Beenut]<br>127.0.0.1  jsp.drivecleaner.com<br>127.0.0.1  secure.drivecleaner.com<br>127.0.0.1  stats.drivecleaner.com<br>127.0.0.1  www.drivecleaner.com #[Symantec.DriveCleaner]<br>127.0.0.1  www.driveprotector.com<br>127.0.0.1  www.enhanceyourbust.com<br>127.0.0.1  www.epinioncash.com<br>127.0.0.1  errorprotector.com #[SunBelt.ErrorProtector][secure.winsoftware.com]<br>127.0.0.1  bin.errorprotector.com #[Downloader.Win32.WinFixer.l]<br>127.0.0.1  go.errorprotector.com #[Google Warning]<br>127.0.0.1  report.errorprotector.com<br>127.0.0.1  www.errorprotector.com #[HJTH.Downloader.Agent]<br>127.0.0.1  errorsafe.com #[Downloader.Win32.Agent.d]<br>127.0.0.1  br.errorsafe.com<br>127.0.0.1  de.errorsafe.com<br>127.0.0.1  download.errorsafe.com #[Prevx.Rogue.ErrorSafe]<br>127.0.0.1  go.errorsafe.com<br>127.0.0.1  kb.errorsafe.com<br>127.0.0.1  nl.errorsafe.com<br>127.0.0.1  se.errorsafe.com #[SiteAdvisor.errorsafe.com]<br>127.0.0.1  secure.errorsafe.com<br>127.0.0.1  utils.errorsafe.com #[winfixer.com]<br>127.0.0.1  www.errorsafe.com #[Symantec.ErrorSafe]<br>127.0.0.1  www.ezmp3downloads.com<br>127.0.0.1  www.fileprotector.com<br>127.0.0.1  genericscanner.com #[Rogue/Suspect]<br>127.0.0.1  www.genericscanner.com<br>127.0.0.1  getfreecar.com<br>127.0.0.1  www.getfreecar.com<br>127.0.0.1  gomyron.com #[Malicious Links]<br>127.0.0.1  jsp.gomyron.com<br>127.0.0.1  members.us.homecs.com<br>127.0.0.1  www.homecs.com #[ripoffreport.com]<br>127.0.0.1  locator.imagesrvr.com<br>127.0.0.1  locator1.cdn.imagesrvr.com #[setuphost.vo.llnwd.net]<br>127.0.0.1  www.incrediseek.com<br>127.0.0.1  innovativemarketing.com #[Trojan.Vundo.B][TROJ_CRYPT.N]<br>127.0.0.1  www.innovativemarketing.com<br>127.0.0.1  internetantispy.com #[Rogue/Suspect]<br>127.0.0.1  www.internetantispy.com<br>127.0.0.1  www.jobdrill.com<br>127.0.0.1  www.kpremium.com<br>127.0.0.1  www.matchservice.com<br>127.0.0.1  www.maxkb.com<br>127.0.0.1  www.mcafeereview.com #[locator.imagesrvr.com]<br>127.0.0.1  mp3u.com<br>127.0.0.1  download.mp3u.com<br>127.0.0.1  www.mp3u.com<br>127.0.0.1  www.mp3asap.com<br>127.0.0.1  www.mp3asap.net<br>127.0.0.1  www.multimediafixer.com<br>127.0.0.1  www.mysurvey4u.com<br>127.0.0.1  www.nortoncomparison.com<br>127.0.0.1  content.onerateld.com #[setuphost.vo.llnwd.net]<br>127.0.0.1  www.onestoponlineshop.net<br>127.0.0.1  www.pcsupercharger.com<br>127.0.0.1  pcturbopro.com<br>127.0.0.1  www.pcturbopro.com<br>127.0.0.1  popupavenger.com<br>127.0.0.1  www.popupavenger.com<br>127.0.0.1  images.popupguard.com<br>127.0.0.1  www.popupguard.com<br>127.0.0.1  stats1.reliablestats.com #[TR/Dldr.FakeAv.C]<br>127.0.0.1  stats2.reliablestats.com<br>127.0.0.1  www.review-software.com<br>127.0.0.1  www.ringtonegold.com #[LURHQ.IFrame.Exploit]<br>127.0.0.1  search42.com<br>127.0.0.1  www.search42.com<br>127.0.0.1  www.searchfindsearch.com<br>127.0.0.1  setupahost.net<br>127.0.0.1  noc.setupahost.net<br>127.0.0.1  www.setupahost.net<br>127.0.0.1  www.sexbuddies.com<br>127.0.0.1  sexprofit.com<br>127.0.0.1  go.sexprofit.com<br>127.0.0.1  jsp.sexprofit.com<br>127.0.0.1  sxp.sexprofit.com<br>127.0.0.1  www.sexprofit.com<br>127.0.0.1  www.smax.us #[Innovative Marketing Ukraine]<br>127.0.0.1  smileydistrict.com<br>127.0.0.1  softwareprofit.com<br>127.0.0.1  go.softwareprofit.com<br>127.0.0.1  www.softwareprofit.com<br>127.0.0.1  www.symantecreview.com<br>127.0.0.1  sysprotect.com<br>127.0.0.1  download.sysprotect.com<br>127.0.0.1  scanner.sysprotect.com<br>127.0.0.1  utils.sysprotect.com<br>127.0.0.1  www.sysprotect.com #[McAfee.SysProtect]<br>127.0.0.1  systemdoctor.com #[HJTH.Downloader.Agent]<br>127.0.0.1  de.systemdoctor.com<br>127.0.0.1  download.systemdoctor.com #[Win32/Adware.WinFixer]<br>127.0.0.1  es.systemdoctor.com<br>127.0.0.1  fr.systemdoctor.com<br>127.0.0.1  go.systemdoctor.com #[Symantec.SystemDoctor]<br>127.0.0.1  instlog.systemdoctor.com<br>127.0.0.1  px.systemdoctor.com<br>127.0.0.1  www.systemdoctor.com #[Downloader.Win32.WinFixer.l]<br>127.0.0.1  www.tattoobitches.com<br>127.0.0.1  www.theringtonesource.com<br>127.0.0.1  vantagesoftware.com #[Rogue/Suspect]<br>127.0.0.1  billing.vantagesoftware.com<br>127.0.0.1  www.vantagesoftware.com #[SiteAdvisor.vantagesoftware.com]<br>127.0.0.1  www.viptravelagent.com<br>127.0.0.1  www.virusguard.com<br>127.0.0.1  virussoftwarereview.com<br>127.0.0.1  purchase.virussoftwarereview.com<br>127.0.0.1  www.virussoftwarereview.com<br>127.0.0.1  www.virussw.com<br>127.0.0.1  http.edge.vru4.com #[McAfee.Adware-Apropos]<br>127.0.0.1  www.wantprofit.com<br>127.0.0.1  www.webinvestigator.com<br>127.0.0.1  go.winadblocker.com<br>127.0.0.1  secure.winadblocker.com<br>127.0.0.1  www.winadblocker.com<br>127.0.0.1  secure.winantispam.com<br>127.0.0.1  www.winantispam.com<br>127.0.0.1  secure.winantispy.com<br>127.0.0.1  www.winantispy.com<br>127.0.0.1  winantivirus.com #[Google Warning]<br>127.0.0.1  br.winantivirus.com<br>127.0.0.1  de.winantivirus.com<br>127.0.0.1  es.winantivirus.com<br>127.0.0.1  fr.winantivirus.com<br>127.0.0.1  go.winantivirus.com<br>127.0.0.1  kb.winantivirus.com<br>127.0.0.1  hk.winantivirus.com<br>127.0.0.1  instlog.winantivirus.com<br>127.0.0.1  purchase.winantivirus.com<br>127.0.0.1  secure.winantivirus.com #[SiteAdvisor.winantivirus.com]<br>127.0.0.1  support.winantivirus.com<br>127.0.0.1  ulog.winantivirus.com<br>127.0.0.1  utils.winantivirus.com<br>127.0.0.1  www.winantivirus.com #[Rogue/Suspect][TR/Dldr.FakeAV.A.6]<br>127.0.0.1  winantivirus.co.uk<br>127.0.0.1  www.winantivirus.co.uk<br>127.0.0.1  www.win-anti-virus-pro.com<br>127.0.0.1  www.win-virus-pro.com<br>127.0.0.1  winantispyware.com #[Symantec.WinAntiSpyware]<br>127.0.0.1  download.winantispyware.com<br>127.0.0.1  go.winantispyware.com #[SiteAdvisor.winantispyware.com]<br>127.0.0.1  www.winantispyware.com #[Rogue/Suspect]<br>127.0.0.1  kb.winantiviruspro.com<br>127.0.0.1  www.winantiviruspro.com #[SpySweeper.Spy.Cookie]<br>127.0.0.1  wincontentfilter.com<br>127.0.0.1  download.wincontentfilter.com<br>127.0.0.1  secure.wincontentfilter.com<br>127.0.0.1  download.windrivecleaner.com<br>127.0.0.1  www.windrivecleaner.com<br>127.0.0.1  www.windrivesafe.com<br>127.0.0.1  winfirewall.com<br>127.0.0.1  www.winfirewall.com<br>127.0.0.1  winfixer.co.uk<br>127.0.0.1  br.winfixer.com #[SiteAdvisor.winfixer.com]<br>127.0.0.1  download.winfixer.com #[Symantec.WinFixer]<br>127.0.0.1  fr.winfixer.com<br>127.0.0.1  winnanny.com #[Trojan.TrustedZone]<br>127.0.0.1  www.winnanny.com<br>127.0.0.1  www.winpluspak.com<br>127.0.0.1  ls.winpopupguard.com<br>127.0.0.1  www.winpopupguard.com<br>127.0.0.1  winprivacyguard.com<br>127.0.0.1  www.winprivacyguard.com<br>127.0.0.1  www.winproductions.com<br>127.0.0.1  activate.winsoftware.com<br>127.0.0.1  download.cdn.winsoftware.com #[setuphost.vo.llnwd.net][Win32/Adware.WinFixer]<br>127.0.0.1  updates.winsoftware.com<br>127.0.0.1  secure.winsoftware.com<br>127.0.0.1  trial.updates.winsoftware.com<br>127.0.0.1  www.winsoftware.com<br>127.0.0.1  uk.workhomecenter.com<br>127.0.0.1  www.workhomecenter.com<br><br>Not every one of these will be encountered. <br><SMALL>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br>We are the Hacker Collective: Resistance Is Futile - All Your AACS Keys Will Be Assimilated.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18566407</guid>
<pubDate>Mon, 25 Jun 2007 20:39:27 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18565792</link>
<description><![CDATA[<A HREF="/useremail/u/996768"><b>jbob</b></A> : Looks like the current MVPS Hosts file!   ;)<br><br>Edit:  Well looks like you posted as I was.  My reply was to your earlier post with the MVPS entries.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18565792</guid>
<pubDate>Mon, 25 Jun 2007 18:51:40 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18565764</link>
<description><![CDATA[<A HREF="/useremail/u/185348"><b>Just Bob</b></A> : I highly recommend the use of a hosts file. Personally I use the MVSP file:<br>&raquo;<A HREF="http://www.mvps.org/winhelp2002/hosts.htm" >www.mvps.org/winhelp2002/hosts.htm</A><br><br>Remember the good old days when the justification for the hosts file was a privacy issue rather than a security issue?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18565764</guid>
<pubDate>Mon, 25 Jun 2007 18:47:35 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18565681</link>
<description><![CDATA[<A HREF="/useremail/u/436079"><b>DrStrange</b></A> : Thanks for the hosts file entries.  I've seen zedo hits elsewhere on the 'net, and I'll bet this will propagate to other sites before it's stopped.  I generally block advertisers as a rule.  This case is an operational definition of my reasoning for doing so.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18565681</guid>
<pubDate>Mon, 25 Jun 2007 18:34:45 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18565487</link>
<description><![CDATA[<A HREF="/useremail/u/874811"><b>sivran</b></A> : Thanks for the list. The wfaa block is a stop-gap measure until I get proper filters in place. Heck, my dad surfs porn when I'm not around, and yet it was wfaa that got him.  What is the world coming to? :huh:<br><SMALL>--<br>Think outside the fox...<A HREF="http://www.mozilla.org/projects/seamonkey/">Seamonkey</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18565487</guid>
<pubDate>Mon, 25 Jun 2007 17:58:01 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18564609</link>
<description><![CDATA[<A HREF="/useremail/u/185348"><b>Just Bob</b></A> : <div class="bquote"><SMALL>said by  sivran <A HREF="/useremail/u/874811"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>WFAA's site serving up malware ads AGAIN? Excuse me while I go block their site entirely. The one single infection my network's experienced was through a bad ad on that site several months ago. <br> </DIV>I suppose I should mention again that it was Google ads served by Zedo that caused the problems on the travelpod website.But since there's no way to predict the source of the ads, you would have wider protection if you were to block Zedo, rather than WFAA.<br><br>Here's all the sites I could glean from my hosts file:<br>127.0.0.1  undertonenetworks.com #[zedo.com][IE-SpyAd]<br>127.0.0.1  www.undertonenetworks.com<br>127.0.0.1  zedo.com #[SecuritySpace.WebBug]<br>127.0.0.1  ads.zedo.com #[McAfee.Cookie-Zedo]<br>127.0.0.1  c1.zedo.com #[a1979.g.akamai.net]<br>127.0.0.1  c2.zedo.com #[SpySweeper.Spy.Cookie]<br>127.0.0.1  c3.zedo.com<br>127.0.0.1  c4.zedo.com #[zedo.vo.llnwd.net]<br>127.0.0.1  c5.zedo.com<br>127.0.0.1  c6.zedo.com<br>127.0.0.1  c7.zedo.com<br>127.0.0.1  c8.zedo.com #[zedo.vo.llnwd.net]<br>127.0.0.1  freeze.zedo.com<br>127.0.0.1  g.zedo.com #[zedo.live365.com]<br>127.0.0.1  gw.zedo.com<br>127.0.0.1  l1.zedo.com #[a1101.g.akamai.net]<br>127.0.0.1  l2.zedo.com<br>127.0.0.1  l3.zedo.com<br>127.0.0.1  l4.zedo.com #[Panda.Spyware:Cookie/Zedo]<br>127.0.0.1  l5.zedo.com<br>127.0.0.1  l6.zedo.com #[a515.g.akamai.net][Tenebril.Tracking Cookie]<br>127.0.0.1  l7.zedo.com<br>127.0.0.1  l8.zedo.com<br>127.0.0.1  simg.zedo.com #[zedo.vo.llnwd.net][a556.g.akamai.net]<br>127.0.0.1  ss1.zedo.com<br>127.0.0.1  ss2.zedo.com<br>127.0.0.1  xads.zedo.com<br>127.0.0.1  www.zedo.com #[Adware.RaxSearch]]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18564609</guid>
<pubDate>Mon, 25 Jun 2007 15:10:31 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18564216</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : <div class="bquote"><SMALL>said by  mysec <A HREF="/useremail/u/1295721"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A><br><br>They affect the previous version of the OS. I wonder how quickly <br>MAC people patch|upgrade! [/BQUOTE :</SMALL><BR><BR>MACs are inherently secure, and don't need to be patched or updated because they are impervious to exploits/viruses/hacking, aren't they? :D<br><br>LOL]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18564216</guid>
<pubDate>Mon, 25 Jun 2007 13:48:17 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18564149</link>
<description><![CDATA[<A HREF="/useremail/u/874811"><b>sivran</b></A> : WFAA's site serving up malware ads AGAIN? Excuse me while I go block their site entirely. The one single infection my network's experienced was through a bad ad on that site several months ago. <br><SMALL>--<br>Think outside the fox...<A HREF="http://www.mozilla.org/projects/seamonkey/">Seamonkey</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18564149</guid>
<pubDate>Mon, 25 Jun 2007 13:31:58 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18563051</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : It happened again just now, but this time on <br>intellicast.com. I had loaded the 1km radar page <br>for DFW to see where the storms we're supposed to be<br>getting today were at when I got redirected to errorsafe.<br><br>Since I had put all the Winfixer domains in the restricted<br>sites, it couldn't do anything - and the page was blank.<br>(This was on my work machine, BTW.)<br><br>A previous visit to the same radar page had a flash ad<br>served by Zedo. I think you're on to something here with<br>the Winfixer-Zedo connection  Just Bob <A HREF="/useremail/u/185348"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>.<br><br>Edit: it is a Zedo ad on WFAA that is likely doing this -<br>I have them in the restricted sites zone as well - this<br>seemed to have prevented a redirect to any Winfixer sites.<br><SMALL>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br>We are the Hacker Collective: Resistance Is Futile - All Your AACS Keys Will Be Assimilated.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18563051</guid>
<pubDate>Mon, 25 Jun 2007 10:03:34 EDT</pubDate>
</item>

<item>
<title>Re: Another ABC local to try</title>
<link>http://www.dslreports.com/forum/remark,18560701</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : Nothing that looks like it would be suspicious in my ad<br>filter's HTTP logs - only the normal tracking services.<br><br>The ones that I noticed were hitbox, adsonar, serving-sys,<br>tacoda and imrworldwide. All of which are in the hosts file. <br>The serving-sys one looked like it would generate the kind of<br>transparent popup ad superimposed over the main page that <br>I've seen sometimes on weather.com. -edit - those are called<br>eyeblaster ads.<br><SMALL>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br>We are the Hacker Collective: Resistance Is Futile - All Your AACS Keys Will Be Assimilated.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18560701</guid>
<pubDate>Sun, 24 Jun 2007 19:22:06 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18559889</link>
<description><![CDATA[<A HREF="/useremail/u/185348"><b>Just Bob</b></A> : I took a look at the source and found zedo. That seemed to ring a bell, as they haven't always had a sterling reputation.<br><br>The old zedo:<br>&raquo;<A HREF="http://209.85.165.104/search?q=cache:u-V3VxUCL0oJ:en.wikipedia.org/wiki/ZEDO+zedo&hl=en&ct=clnk&cd=3&gl=us" >209.85.165.104/search?q=cache:u-&middot;&middot;&middot;=3&gl=us</A><br><br>The new zedo:<br>&raquo;<A HREF="http://en.wikipedia.org/wiki/ZEDO" >en.wikipedia.org/wiki/ZEDO</A><br><br>It seems they have grown up a bit and are now the third largest company in their market. As the first and second companies have been acquired, I would think they are trying very hard to clean up their image and would be very sensitive to any suggestion of impropriety.<br><br>Nonetheless, I was able to find what sounds like a similar problem on the travelpod web site. It's a long thread, but very informative. It seems zedo serves ads in rotation and when they have exhausted their supply, they serve google ads through the zedo servers. In this case it seems to have been a google ad that was hijacked.<br>&raquo;<A HREF="http://www.travelpod.com/forums/lofiversion/index.php/t2403.html" >www.travelpod.com/forums/lofiver&middot;&middot;&middot;403.html</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18559889</guid>
<pubDate>Sun, 24 Jun 2007 15:53:42 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18557304</link>
<description><![CDATA[<A HREF="/useremail/u/1159554"><b>norwegian</b></A> : Not sure what is happening there, on the News 8 page, but it is shutting down the server of Hostsman.<br><br>Seems the ads are the same as the home page, and no issues with the server running for that.<br><SMALL>--<br>The only thing necessary for the triumph of evil is for good men to do nothing - Edmund Burke</SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18557304?c=1179177&ret=L2ZvcnVtL3IxODU1MTY4NC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="6996 bytes" WIDTH=600 HEIGHT=49 SRC="/r0/download/1179177.thumb600~fbb7ade262878fa18e80327227897d3c/ScreenShot048.gif/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18557304</guid>
<pubDate>Sat, 23 Jun 2007 23:00:15 EDT</pubDate>
</item>

<item>
<title>Another ABC local to try</title>
<link>http://www.dslreports.com/forum/remark,18557163</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : Does this ABC o/o station's article about the caller ID spoofing cause you any problems???<br>&raquo;<A HREF="http://abclocal.go.com/ktrk/story?section=sci_tech&id=3953183" >abclocal.go.com/ktrk/story?secti&middot;&middot;&middot;=3953183</A><br><br>Please let me know.<br><br><B>NOTE:</B> The AP article published on KTRK in Houston is dated <B>3/1/06 </B>  and is not readily available on many ABC o/o websites.<br>-amy-<br>:)<br><SMALL>--<br><A HREF="http://www.dslreports.com/phishtrack">DSLR Phishtracker</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18557163</guid>
<pubDate>Sat, 23 Jun 2007 22:17:00 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18557125</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : An update: I tried going to the Local News section tonight<br>with my hosts file temporarily disabled and my ad filter<br>turned off. (Risky, I know, but I knew what to do should a<br>redirect occur.)<br><br>I reloaded the Local News page about 4-5 times (just short<br>of the point at which the site prompts for membership), but<br>couldn't get even one redirect. If their IT was on the ball<br>about it, they would have taken action on the complaint I<br>sent them through their email system. Hopefully they have.<br><br>WinFixer is a variant of one of the most common trojan<br>infections, Vundo. According to Sandi Hardmeier, who first<br>found they had infiltrated AOL's and MSN Messenger's ad<br>networks, the company responsible is Valueclick. They<br>claimed to have dropped Winfixer as a client, yet Sandi<br>has found that flash ads from a Valueclick domain, <br>adfarm.mediaplex.com, are still redirecting web surfers<br>to Winfixer domains:<br><br>&raquo;<A HREF="http://msmvps.com/blogs/spywaresucks/archive/2007/05.aspx" >msmvps.com/blogs/spywaresucks/ar&middot;&middot;&middot;/05.aspx</A><br><SMALL>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br>We are the Hacker Collective: Resistance Is Futile - All Your AACS Keys Will Be Assimilated.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18557125</guid>
<pubDate>Sat, 23 Jun 2007 22:07:54 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18552619</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : On the machines where I work at, IT hasn't gotten around to<br>upgrading to IE7 on.<br><br>As for the attempt, the furthest it got was a redirect from<br>the WFAA site to pcturbopro.com. I think it happened when<br>I clicked the back button from More News 8 Investigates page.<br><br>When I saw it pop up, I figured the easiest way to get rid<br>of it was to kill IE with the task manager.<br><br>I just tried it on another machine, one that doesn't have<br>a hosts file on it. It came up on the Local News page after<br>I reloaded it a couple of times. It was on Firefox on it, and<br>I got rid of the redirect by killing FF in the task manager.<br>Only this time it was Errorsafe. Not sure which ad is<br>triggering it, though.<br><br>Edit: I sent them an email through their online comment system<br>with links to SiteAdvisor pages on the WinFixer domains<br>that I encountered. Hopefully that will prevent a less<br>savvy user of the site who doesn't know what WinFixer is<br>or the domains associated with them avoid getting infected.<br><SMALL>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br>We are the Hacker Collective: Resistance Is Futile - All Your AACS Keys Will Be Assimilated.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18552619</guid>
<pubDate>Fri, 22 Jun 2007 21:39:08 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18552441</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : <div class="bquote"><SMALL>said by  jansson_mark <A HREF="/useremail/u/444625"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</SMALL><BR><BR>How can you - or anyone else - get infected by simply visiting a website? You must be using unpatched old browsers. </DIV><BR>Only days after Apple released Mac OS X 10.4.10, it has also released Security Update 2007-006.<br><br>&raquo;<A HREF="http://news.com.com/8301-10784_3-9733849-7.html?part=rss&subj=news&tag=2547-1_3-0-20" >news.com.com/8301-10784_3-973384&middot;&middot;&middot;1_3-0-20</A><br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Both vulnerabilities involve surfing the Internet.<HR></BLOCKQUOTE><br><br>They affect the previous version of the OS. I wonder how quickly <br>MAC people patch|upgrade! <br><BR>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18552441</guid>
<pubDate>Fri, 22 Jun 2007 20:57:01 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18551871</link>
<description><![CDATA[<A HREF="/useremail/u/1103148"><b>sectionsix</b></A> : I looked around at hxxp://www.wfaa.com/localnews/investigates/ for a bit and didn't see anything, I used IE7 BTW. For security I'm running WinXP SP2 (all patches), NOD security suite beta, SandBoxIE, and IE-SPYAD. The only ugly thing I found at that site was the redirect "become a member" page.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18551871</guid>
<pubDate>Fri, 22 Jun 2007 18:59:04 EDT</pubDate>
</item>

<item>
<title>Re: Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18551814</link>
<description><![CDATA[<A HREF="/useremail/u/444625"><b>jansson_mark</b></A> : How can you - or anyone else - get infected by simply visiting a website? You must be using unpatched old browsers. I tryed to infect my system with Winfixer...just for fun...but I failed. I would have had to download and run .exe file to get infected.<br><SMALL>--<br>My computer security & privacy related homepage &raquo;<A HREF="http://www.markusjansson.net" >www.markusjansson.net</A> <br>Use HushTools or GnuPG/PGP to encrypt any email before sending it to me to protect our privacy.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18551814</guid>
<pubDate>Fri, 22 Jun 2007 18:47:09 EDT</pubDate>
</item>

<item>
<title>Another WinFixer infiltration...this time on www.wfaa.com</title>
<link>http://www.dslreports.com/forum/remark,18551684</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : About an hour and a half ago I was on WFAA's (a local ABC<br>affiliate) website, www.wfaa.com, looking for a story on<br>the noon news about caller ID spoofing being used for<br>phishing (vishing in this case) purposes. I was in the News 8<br>Investigates section of the site when my IE window got <br>resized to the bottom right very small, and a prompt asking<br>if I wanted to install and run something called PcTurboPro<br>popped up.<br><br>Since this had all the hallmarks of a drive-by download<br>attempt at getting spyware on my workstation, and it had<br>only TrendMicro OfficeScan and no hosts file, I killed IE6<br>with the task manager. I then went to SiteAdvisor where I<br>found out I had prevented a WinFixer infection on it.<br><br>Something on a third party ad network wfaa.com was using,<br>or their own ad network, BeloInteractive, appears to have<br>been infiltrated by WinFixer. I'm not sure what it was, <br>and didn't see anything in my ad filter's logs here on<br>this machine that looked suspicious, but it's there all<br>right - it left behind a tracking cookie on my workstation.<br><SMALL>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br>We are the Hacker Collective: Resistance Is Futile - All Your AACS Keys Will Be Assimilated.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18551684</guid>
<pubDate>Fri, 22 Jun 2007 18:16:09 EDT</pubDate>
</item>

</channel>
</rss>
