<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Scam] Bogus anti-spyware site in Spam, Scam and Phishbusters</title>
<link>http://www.dslreports.com/forum/r20765013</link>
<description></description>
<language>en</language>
<pubDate>Wed, 03 Dec 2008 03:02:51 EDT</pubDate>
<lastBuildDate>Wed, 03 Dec 2008 03:02:51 EDT</lastBuildDate>

<item>
<title>Re: [Scam] Bogus anti-spyware site</title>
<link>http://www.dslreports.com/forum/remark,20770825</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : It should go without saying for most people here, but <br>you should disable that link so that no one landing on<br>this page accidentally follows it and gets infected.<br><br>Just change the http portion of the URL to hxxp.<br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20770825</guid>
<pubDate>Thu, 10 Jul 2008 15:49:45 EDT</pubDate>
</item>

<item>
<title>Re: [Scam] Bogus anti-spyware site</title>
<link>http://www.dslreports.com/forum/remark,20766028</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : Another fresh batch of the RBN Zlob variants, No wonder you hit on it with that search criteria. That page has the following keyword tags embedded:<br><br><div class="bquote"> TITLE Cell Phone Numbers Going Public TITLE<br><br>META NAME="keywords" CONTENT="samsung cell phone, nokia cell phone accessories, british columbia phone book, reverse phone search free, reverse cell phone directory free, conference phone, activate new phone sprint, history of cell phone, sprint international phone cards, dayton ohio phone book, bellsouth residential phone numbers, water proof cell phone pouch, cell phone number reversal for canada, phone number for equifax credit, when was the cell phone invented, locating phone numbers, barb klapp cell mobile phone, fake phone service, mature phone sex, casio cell phone, video phone, business phone listing, lg chocolate phone, best cell phone companies, camera-less phone, cell phone pics, time warner cable phone internet, mini phone, comic animations on phone, free wireless phone internet speed evdo, reverse phone look, free trial phone chat, movie phone, cordless phone consumer report, reverse phone, cell phone backgrounds, cricket cell phone plan, united kingdom phone directory, motorola cordless phone, cellular phone locator, prepaid cell phone<br></div>While the page you hit on >http://www.geocities.com/bkuaytccdo/cell-phone-numbers-going-public.html pulls >http://antispyware2008a.com<br><br><div class="borderless siteshot"><small>Snapped 2008-07-09 18:00:04 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br><A TITLE="Zoom" HREF="http://i.dslr.net/urls/40/76640.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/40/76640.gif"></A><br>&raquo;<A HREF="http://antispyware2008a.com" >antispyware2008a.com</A></small></div><br><br>the previous directory >http://www.geocities.com/bkuaytccdo/ will send you to a Russian pharmacy drug peddler masquerading as a Canadian entity. Currently using the domain soonmaster.com <br><br><div class="borderless siteshot"><small>Snapped 2008-07-09 17:59:45 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br><A TITLE="Zoom" HREF="http://i.dslr.net/urls/41/76641.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/41/76641.gif"></A><br>&raquo;<A HREF="http://soonmaster.com/" >soonmaster.com/</A></small></div><br><br>Though <b>antispyware2008a.com</b> appears to be partnered with <b>antispyware-2008-download.org</b> and both hosted on IP <b>78.157.143.251</b> by VdHost Ltd./ UltraNet, vdhost.biz in Latvia:<br><br><pre><br>inetnum: 78.157.143.128 - 78.157.143.255<br>netname: VDHOST<br>descr: VdHost Ltd.<br>descr: abuse@vdhost.biz<br>country: LV<br>admin-c: AV2990-RIPE<br>tech-c: UNHM-RIPE<br>status: ASSIGNED PA<br>mnt-by: UN-MNT<br>source: RIPE # Filtered<br>.<br>role: UltraNet Hostmaster<br>address: UltraNet SIA<br>Aizkraukles 23<br>Riga, LV-1006<br>Latvia<br>phone: +371 67543003<br>fax-no: +371 67594435<br>e-mail: hostmaster@ultranet.lv<br>admin-c: AS28817-RIPE<br>admin-c: MS16883-RIPE<br>tech-c: AS28817-RIPE<br>nic-hdl: UNHM-RIPE<br>mnt-by: UN-MNT<br>source: RIPE # Filtered<br>.<br>person: Arturs Vavilovs<br>address: Riga<br>phone: +371 29653077<br>e-mail: admin@vdhost.biz<br>nic-hdl: AV2990-RIPE<br>mnt-by: UN-MNT<br>source: RIPE # Filtered<br>.<br>% Information related to '78.157.128.0/19AS35057'<br>.<br>route: 78.157.128.0/19<br>descr: SIA ULTRANET<br>origin: AS35057<br>mnt-by: UN-MNT<br>source: RIPE # Filtered<br></pre><br>.<br>The real nuts and bolts of the operation are hosted right nextdoor on IP <b>78.157.143.250</b>: &raquo;<A HREF="http://www.google.com/search?hl=en&q=78.157.143.250&btnG=Google+Search" >www.google.com/search?hl=en&q=78&middot;&middot;&middot;e+Search</A><br><br><pre><br>78.157.128.0-78.157.159.255 LV-ULTRANET-20070830 SIA ULTRANET<br>. <br> <br>78.157.147.149 4637834.com<br>78.157.128.0/19 SIA ULTRANET<br>AS35057 UltraNet Ltd. <br>78.157.128.0-78.157.159.255 LV-ULTRANET-20070830 SIA ULTRANET<br>.  <br>78.157.143.250 <br>.<br>*.anti-spy-ware-2008.com    <br>*.antispyware-2008-download.com    <br>*.antispyware-2008.info     <br>*.antispyware2008-download.com     <br>*.antispyware2008.name     <br>*.antispyware2008y.com     <br>*.ns1.antispyware2008y.com     <br>anti-spy-ware-2008.com    <br>antispyware-2008-download.com    <br>antispyware-2008.info    <br>antispyware2008-download.com    <br>antispyware2008.name     <br>antispyware2008y.com     <br>mail.anti-spy-ware-2008.com     <br>mail.antispyware-2008-download.com     <br>mail.antispyware-2008.info     <br>mail.antispyware2008-download.com    <br>mail.antispyware2008y.com    <br>mail.ns1.antispyware2008y.com    <br>ns1.anti-spy-ware-2008.com    <br>ns1.antispyware-2008-download.com   <br>ns1.antispyware-2008.info    <br>ns1.antispyware2008-download.com   <br>ns1.antispyware2008.name   <br>ns1.antispyware2008y.com   <br>ns2.anti-spy-ware-2008.com  <br>ns2.antispyware-2008-download.com    <br>ns2.antispyware-2008.info    <br>ns2.antispyware2008-download.com   <br>ns2.antispyware2008.name    <br>ns2.antispyware2008y.com    <br>www.anti-spy-ware-2008.com  <br>www.antispyware-2008-download.com   <br>www.antispyware-2008.info<br>www.antispyware2008-download.com  <br>www.antispyware2008y.com <br></pre><br><br>Not suprising that the antispyware2008a.com domain was registered with the notorious cyber criminal support services of EST Domains:<br><br><pre><br>Results returned from whois.estdomains.com:<br>.<br>Registration Service Provided By: ESTDOMAINS INC<br>Contact: +1.3027224217<br>Website: >http://www.estdomains.com<br> <br>Domain Name: ANTISPYWARE2008A.COM <br>.<br>Registrant:<br>    OAO Dormash<br>    Nikolai Ilenko        (nikolai.dormash@google.com)<br>    Moscow city<br>    Moscow<br>    Moskovskaya oblast,163622<br>    RU<br>    Tel. +7.4952001288<br>    Fax. +7.4952001290<br>.<br>Creation Date: 05-Jul-2008  <br>Expiration Date: 05-Jul-2009<br>.<br>Domain servers in listed order:<br>    ns2.antispyware2008a.com<br>    ns1.antispyware2008a.com<br> <br>.<br>Administrative Contact:<br>    OAO Dormash<br>    Nikolai Ilenko        (nikolai.dormash@google.com)<br>    Moscow city<br>    Moscow<br>    Moskovskaya oblast,163622<br>    RU<br>    Tel. +7.4952001288<br>    Fax. +7.4952001290<br>.<br>Technical Contact:<br>    OAO Dormash<br>    Nikolai Ilenko        (nikolai.dormash@google.com)<br>    Moscow city<br>    Moscow<br>    Moskovskaya oblast,163622<br>    RU<br>    Tel. +7.4952001288<br>    Fax. +7.4952001290<br>.<br>Billing Contact:<br>    OAO Dormash<br>    Nikolai Ilenko        (nikolai.dormash@google.com)<br>    Moscow city<br>    Moscow<br>    Moskovskaya oblast,163622<br>    RU<br>    Tel. +7.4952001288<br>    Fax. +7.4952001290<br>.<br>Status:ACTIVE<br></pre><br><br>A bogus domain registration containing information copied from an Ukrainian company Dormash OAO, dormash.com: &raquo;<A HREF="http://translate.google.com/translate?u=http%3A%2F%2Fwww.dormash.com&hl=en&ie=UTF8&sl=ru&tl=en" >translate.google.com/translate?u&middot;&middot;&middot;ru&tl=en</A><br><br>The file download "setup.exe"<br><br>[att=1]<br><br>when submitted to VirusTotal shows:<br><br>[att=2][att=3]<br><br>These are all part of the large group of hijack installs that try and force the victim to submit card data and pay to clean up a non existant infection, at least prior tot he download Other members of the group are "AntiSpyCheck", etc.<br><br>MGD<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20766028?c=1326187&ret=L2ZvcnVtL3IyMDc2NTAxMy54bWw%3D"><IMG class="apic" BORDER=0 TITLE="25831 bytes" WIDTH=600 HEIGHT=435 SRC="/r0/download/1326187.thumb600~2c44f047156a527ac54bda2791cc59df/Antispyware.png/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20766028?c=1326188&ret=L2ZvcnVtL3IyMDc2NTAxMy54bWw%3D"><IMG TITLE="13231 bytes" BORDER=0 WIDTH=550 HEIGHT=624 SRC="/r0/download/1326188~ca0d7b3b94f59665ecd21b24b4bfab48/Antivirus_zlob1.png"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20766028?c=1326189&ret=L2ZvcnVtL3IyMDc2NTAxMy54bWw%3D"><IMG TITLE="11088 bytes" BORDER=0 WIDTH=551 HEIGHT=553 SRC="/r0/download/1326189~0c6629987a6b379b5d417f5c38a200c2/Antivirus_zlob2.png"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20766028</guid>
<pubDate>Wed, 09 Jul 2008 18:05:48 EDT</pubDate>
</item>

<item>
<title>Re: [Scam] Bogus anti-spyware site</title>
<link>http://www.dslreports.com/forum/remark,20765143</link>
<description><![CDATA[<A HREF="/useremail/u/910278"><b>Oleg</b></A> : Dam fake scan looks real  :p]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20765143</guid>
<pubDate>Wed, 09 Jul 2008 15:32:37 EDT</pubDate>
</item>

<item>
<title>[Scam] Bogus anti-spyware site</title>
<link>http://www.dslreports.com/forum/remark,20765013</link>
<description><![CDATA[<A HREF="/useremail/u/749583"><b>justbits</b></A> : hxxp://antispyware2008a.com/scanner.php?p=1&c=1&e=1&aff=1151&sc=0<br><br>I'm not sure this is the right place to report this, but I found it interesting. The page was linked to by Google for the search term: "all cell phone numbers are being released to telemarketing companies" by the original referring web site: hxxp://www.geocities.com/bkuaytccdo/ cell-phone-numbers-going-public.html<br><br>The web page opens a bogus javascript anti spyware scanner simulation.<br>It tries to trick you into keeping the page open as if it's actually scanning your machine. (It even reports a successful scan under Safari on Mac OS X.)<br>It tries to trick you into downloading and running a Setup.exe that automatically downloads when you click on anywhere on a subsequent "analysis" page.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20765013</guid>
<pubDate>Wed, 09 Jul 2008 15:10:18 EDT</pubDate>
</item>

</channel>
</rss>
