<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-36446935</id><updated>2011-11-30T00:55:14.742-08:00</updated><title type='text'>Spywarebox: A blog about online (in)security.</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default?start-index=101&amp;max-results=100'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>121</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-36446935.post-8884540042871782319</id><published>2008-05-30T13:31:00.000-07:00</published><updated>2008-05-30T13:33:29.307-07:00</updated><title type='text'>RED ALERT!!</title><content type='html'>&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/SEBkUPXzW-I/AAAAAAAAAyI/YT4pwz7AmJk/s1600-h/desk1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5206271468126821346" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/SEBkUPXzW-I/AAAAAAAAAyI/YT4pwz7AmJk/s400/desk1.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;Nice wallpaper pushing a rogue.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-8884540042871782319?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/8884540042871782319/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=8884540042871782319&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8884540042871782319'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8884540042871782319'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/05/red-alert.html' title='RED ALERT!!'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/SEBkUPXzW-I/AAAAAAAAAyI/YT4pwz7AmJk/s72-c/desk1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-5444798822565662942</id><published>2008-05-13T15:15:00.001-07:00</published><updated>2008-05-13T15:17:16.084-07:00</updated><title type='text'>AdultFriendFinder account suspended</title><content type='html'>&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/SCoTNjsnhRI/AAAAAAAAAyA/n3q8T_cRjvE/s1600-h/adultfriendriender.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5199989843394266386" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/SCoTNjsnhRI/AAAAAAAAAyA/n3q8T_cRjvE/s400/adultfriendriender.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Some spyware pushed AdultFriendFinder... but apparently they got blocked ;-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-5444798822565662942?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/5444798822565662942/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=5444798822565662942&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5444798822565662942'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5444798822565662942'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/05/adultfriendfinder-account-suspended.html' title='AdultFriendFinder account suspended'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/SCoTNjsnhRI/AAAAAAAAAyA/n3q8T_cRjvE/s72-c/adultfriendriender.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-2165613528563579729</id><published>2008-05-13T15:14:00.000-07:00</published><updated>2008-05-13T15:15:50.056-07:00</updated><title type='text'>Buffer overflow attempt?</title><content type='html'>&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/SCoTCjsnhQI/AAAAAAAAAx4/mzREHJh6p8Y/s1600-h/buffer.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5199989654415705346" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/SCoTCjsnhQI/AAAAAAAAAx4/mzREHJh6p8Y/s400/buffer.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-2165613528563579729?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/2165613528563579729/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=2165613528563579729&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2165613528563579729'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2165613528563579729'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/05/buffer-overflow-attempt.html' title='Buffer overflow attempt?'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/SCoTCjsnhQI/AAAAAAAAAx4/mzREHJh6p8Y/s72-c/buffer.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-7173997274390051730</id><published>2008-05-01T14:53:00.000-07:00</published><updated>2008-05-01T14:54:54.116-07:00</updated><title type='text'>BraveSentry joke</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_CRb3gYmxpzA/SBo7_lQHHjI/AAAAAAAAAxw/YI3LwsiXTQQ/s1600-h/Screcshot-1.png"&gt;&lt;img style="cursor: pointer;" src="http://bp1.blogger.com/_CRb3gYmxpzA/SBo7_lQHHjI/AAAAAAAAAxw/YI3LwsiXTQQ/s400/Screcshot-1.png" alt="" id="BLOGGER_PHOTO_ID_5195531083642773042" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;What? You must be kidding!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-7173997274390051730?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/7173997274390051730/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=7173997274390051730&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/7173997274390051730'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/7173997274390051730'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/05/bravesentry-joke.html' title='BraveSentry joke'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/SBo7_lQHHjI/AAAAAAAAAxw/YI3LwsiXTQQ/s72-c/Screcshot-1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-7224367086373424289</id><published>2008-04-07T19:35:00.001-07:00</published><updated>2008-04-07T19:37:54.402-07:00</updated><title type='text'>Spot the mistake courtesy of TrustedAntivirus</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_CRb3gYmxpzA/R_rZ_E5FkFI/AAAAAAAAAxo/sKraooP23cY/s1600-h/allert.png"&gt;&lt;img style="cursor: pointer;" src="http://bp1.blogger.com/_CRb3gYmxpzA/R_rZ_E5FkFI/AAAAAAAAAxo/sKraooP23cY/s400/allert.png" alt="" id="BLOGGER_PHOTO_ID_5186697598538715218" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Hint: achtung!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-7224367086373424289?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/7224367086373424289/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=7224367086373424289&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/7224367086373424289'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/7224367086373424289'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/04/spot-mistake-courtesy-of.html' title='Spot the mistake courtesy of TrustedAntivirus'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/R_rZ_E5FkFI/AAAAAAAAAxo/sKraooP23cY/s72-c/allert.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-2301316414085013205</id><published>2008-04-01T10:47:00.000-07:00</published><updated>2008-04-01T10:50:46.744-07:00</updated><title type='text'>Winsoftware localisations</title><content type='html'>Having fun with different versions of WinAntivirusPro... French, German, Italian.... you name it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/R_J1XE5FkDI/AAAAAAAAAxY/NTj99snNd38/s1600-h/winsoftwareall.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5184335160367484978" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/R_J1XE5FkDI/AAAAAAAAAxY/NTj99snNd38/s400/winsoftwareall.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R_J1y05FkEI/AAAAAAAAAxg/h0PiKjMVnj0/s1600-h/winantivirus_french.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5184335637108854850" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R_J1y05FkEI/AAAAAAAAAxg/h0PiKjMVnj0/s400/winantivirus_french.png" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-2301316414085013205?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/2301316414085013205/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=2301316414085013205&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2301316414085013205'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2301316414085013205'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/04/winsoftware-localisations.html' title='Winsoftware localisations'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/R_J1XE5FkDI/AAAAAAAAAxY/NTj99snNd38/s72-c/winsoftwareall.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-5161300948506260102</id><published>2008-03-31T15:06:00.000-07:00</published><updated>2008-03-31T15:07:33.162-07:00</updated><title type='text'>TrustedAntivirus Scam</title><content type='html'>&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R_FgcE5FkBI/AAAAAAAAAxI/-0ftTjJeM9M/s1600-h/securePCcleaner00.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5184030681545936914" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R_FgcE5FkBI/AAAAAAAAAxI/-0ftTjJeM9M/s400/securePCcleaner00.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R_FgdE5FkCI/AAAAAAAAAxQ/Wcb-Im5lypk/s1600-h/securePCcleaner.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5184030698725806114" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R_FgdE5FkCI/AAAAAAAAAxQ/Wcb-Im5lypk/s400/securePCcleaner.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Ah... it will never change...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-5161300948506260102?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/5161300948506260102/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=5161300948506260102&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5161300948506260102'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5161300948506260102'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/03/trustedantivirus-scam.html' title='TrustedAntivirus Scam'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/R_FgcE5FkBI/AAAAAAAAAxI/-0ftTjJeM9M/s72-c/securePCcleaner00.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-1714441778472181129</id><published>2008-03-31T13:26:00.000-07:00</published><updated>2008-03-31T13:27:54.281-07:00</updated><title type='text'>Scam again</title><content type='html'>&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/R_FJGk5Fj_I/AAAAAAAAAw4/LlbTChJp1eg/s1600-h/spyshredd01.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5184005023411310578" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/R_FJGk5Fj_I/AAAAAAAAAw4/LlbTChJp1eg/s400/spyshredd01.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/R_FJG05FkAI/AAAAAAAAAxA/-zTGNmn1JEA/s1600-h/spyshredd02.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5184005027706277890" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/R_FJG05FkAI/AAAAAAAAAxA/-zTGNmn1JEA/s400/spyshredd02.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Don't buy this rogue stuff. It's a S.C.A.M.!!!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-1714441778472181129?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/1714441778472181129/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=1714441778472181129&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/1714441778472181129'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/1714441778472181129'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/03/scam-again.html' title='Scam again'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_CRb3gYmxpzA/R_FJGk5Fj_I/AAAAAAAAAw4/LlbTChJp1eg/s72-c/spyshredd01.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-3629788943246785981</id><published>2008-03-19T09:09:00.000-07:00</published><updated>2008-03-19T09:12:39.372-07:00</updated><title type='text'>Malware tampers with verclsid</title><content type='html'>&lt;div&gt;Verclsid.exe is used to verify a COM object before it is instantiated by Windows Explorer.&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R-E6-XnwcJI/AAAAAAAAAvc/xK3IHcJYHu4/s1600-h/verclsid.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5179485889619849362" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R-E6-XnwcJI/AAAAAAAAAvc/xK3IHcJYHu4/s400/verclsid.png" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;This threat attempts to delete verclsid.exe. I guess the idea is to execute a non verified nasty COM object regardless ;-)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-3629788943246785981?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/3629788943246785981/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=3629788943246785981&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/3629788943246785981'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/3629788943246785981'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/03/malware-tampers-with-verclsid.html' title='Malware tampers with verclsid'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/R-E6-XnwcJI/AAAAAAAAAvc/xK3IHcJYHu4/s72-c/verclsid.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-6772480914531934489</id><published>2008-03-03T15:48:00.001-08:00</published><updated>2008-03-03T15:59:48.536-08:00</updated><title type='text'>AVSystemcare, 5 star rating?</title><content type='html'>My PC gets infected with a Trojan which pushes the famous AVSystemCare rogue:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R8yObgKwijI/AAAAAAAAAnY/w1TdUXfHLGE/s1600-h/spywarewarning.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5173666675084528178" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R8yObgKwijI/AAAAAAAAAnY/w1TdUXfHLGE/s400/spywarewarning.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Very nice install screen!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/R8yPKwKwilI/AAAAAAAAAno/qzlvsDm7d9Q/s1600-h/avsystemcareworld.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5173667486833347154" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/R8yPKwKwilI/AAAAAAAAAno/qzlvsDm7d9Q/s400/avsystemcareworld.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Lots of happy customers:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R8yPKgKwikI/AAAAAAAAAng/IZdNeE7dy7Q/s1600-h/avpeople.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5173667482538379842" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R8yPKgKwikI/AAAAAAAAAng/IZdNeE7dy7Q/s400/avpeople.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;It's MY DECISION!!!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R8yP1gKwimI/AAAAAAAAAnw/AA2OQiY9J9s/s1600-h/avyourdecision.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5173668221272754786" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R8yP1gKwimI/AAAAAAAAAnw/AA2OQiY9J9s/s400/avyourdecision.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Verdict:&lt;br /&gt;A very good looking product with very bad intentions (your money). &lt;div&gt; &lt;/div&gt;&lt;div&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/R8yQzAKwinI/AAAAAAAAAn4/sMNdxbRMk1k/s1600-h/avscam.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5173669277834709618" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/R8yQzAKwinI/AAAAAAAAAn4/sMNdxbRMk1k/s400/avscam.png" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-6772480914531934489?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/6772480914531934489/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=6772480914531934489&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/6772480914531934489'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/6772480914531934489'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/03/avsystemcare-5-star-rating.html' title='AVSystemcare, 5 star rating?'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/R8yObgKwijI/AAAAAAAAAnY/w1TdUXfHLGE/s72-c/spywarewarning.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-5571242033476548168</id><published>2008-02-28T15:58:00.000-08:00</published><updated>2008-02-28T16:03:04.006-08:00</updated><title type='text'>When a picture hides an executable</title><content type='html'>A GIF file is harmless, right?&lt;br /&gt;&lt;br /&gt;Wait, maybe not!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/R8dK0kGXslI/AAAAAAAAAnI/Fd6QYPQrNBk/s1600-h/picexe.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5172184963962352210" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/R8dK0kGXslI/AAAAAAAAAnI/Fd6QYPQrNBk/s400/picexe.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It turns out it's an EXE renamed just for the fun of it.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;VirusTotal sneak preview:&lt;/p&gt;&lt;p&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/R8dLSUGXsmI/AAAAAAAAAnQ/u9dPocv6l2k/s1600-h/gifvt.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5172185475063460450" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/R8dLSUGXsmI/AAAAAAAAAnQ/u9dPocv6l2k/s400/gifvt.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-5571242033476548168?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/5571242033476548168/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=5571242033476548168&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5571242033476548168'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5571242033476548168'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/02/when-picture-hides-executable.html' title='When a picture hides an executable'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_CRb3gYmxpzA/R8dK0kGXslI/AAAAAAAAAnI/Fd6QYPQrNBk/s72-c/picexe.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-2161228542933412646</id><published>2008-02-28T09:15:00.001-08:00</published><updated>2008-02-28T09:18:22.938-08:00</updated><title type='text'>Fake Zlob Trojan codec site down? or not....</title><content type='html'>&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R8bsVUGXsiI/AAAAAAAAAmw/qm-gftcgG04/s1600-h/estdomains.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5172081072998429218" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R8bsVUGXsiI/AAAAAAAAAmw/qm-gftcgG04/s400/estdomains.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Apparently a goner....&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/R8bsVkGXsjI/AAAAAAAAAm4/V0u461o1JJQ/s1600-h/rockingmovs.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5172081077293396530" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/R8bsVkGXsjI/AAAAAAAAAm4/V0u461o1JJQ/s400/rockingmovs.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Hmm.... maybe not:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/R8bsV0GXskI/AAAAAAAAAnA/8WedDkFrWZY/s1600-h/stillactive.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5172081081588363842" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/R8bsV0GXskI/AAAAAAAAAnA/8WedDkFrWZY/s400/stillactive.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-2161228542933412646?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/2161228542933412646/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=2161228542933412646&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2161228542933412646'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2161228542933412646'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/02/fake-codec-site-down-or-not.html' title='Fake Zlob Trojan codec site down? or not....'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/R8bsVUGXsiI/AAAAAAAAAmw/qm-gftcgG04/s72-c/estdomains.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-4056196135571477775</id><published>2008-02-27T15:53:00.000-08:00</published><updated>2008-03-05T15:21:24.378-08:00</updated><title type='text'>Trojans from China: exposed!</title><content type='html'>A nice collection of Trojans being pushed massively stored at:&lt;br /&gt;down[hidden].china-s0ft.cn/downlist.txt&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/R8X400GXsgI/AAAAAAAAAmg/FU45wBK8_nw/s1600-h/chinesetrojans.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5171813333327131138" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/R8X400GXsgI/AAAAAAAAAmg/FU45wBK8_nw/s400/chinesetrojans.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;and more from another domain:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/R8X5dUGXshI/AAAAAAAAAmo/crv65XMv2zs/s1600-h/malwaredomain.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5171814029111833106" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/R8X5dUGXshI/AAAAAAAAAmo/crv65XMv2zs/s400/malwaredomain.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-4056196135571477775?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/4056196135571477775/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=4056196135571477775&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4056196135571477775'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4056196135571477775'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/02/trojans-from-china-exposed.html' title='Trojans from China: exposed!'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/R8X400GXsgI/AAAAAAAAAmg/FU45wBK8_nw/s72-c/chinesetrojans.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-8688413997069204138</id><published>2008-02-25T12:44:00.000-08:00</published><updated>2008-02-25T12:58:00.262-08:00</updated><title type='text'>Zlob Trojan: fake error, real infection</title><content type='html'>I found a fake video codec while doing some Google searches. It is very well crafted, with a bit of social engineering. At first I thought this one was VMware aware because of the error message. However, some deeper analysis revealed it was not. Some interesting things came up. Below is a summary.&lt;br /&gt;&lt;br /&gt;Upon executing the sample, the following message shows up:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/R8MpY0GXsaI/AAAAAAAAAlw/RPw22a-XP1Q/s1600-h/webcodec.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5171022303430422946" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/R8MpY0GXsaI/AAAAAAAAAlw/RPw22a-XP1Q/s400/webcodec.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;However, in the background things are taking place:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/R8Mqf0GXscI/AAAAAAAAAmA/oaqPe4R__1U/s1600-h/webcodectfiddler.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5171023523201135042" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/R8Mqf0GXscI/AAAAAAAAAmA/oaqPe4R__1U/s400/webcodectfiddler.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;An Internet Explorer toolbar is created:&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R8MpZEGXsbI/AAAAAAAAAl4/pSUERR9fdT0/s1600-h/webcodectoolbar.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5171022307725390258" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R8MpZEGXsbI/AAAAAAAAAl4/pSUERR9fdT0/s400/webcodectoolbar.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Only the following security vendors are detecting this threat at the time of posting:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R8MqgEGXsdI/AAAAAAAAAmI/BLv8HV0S8oA/s1600-h/webcodecvt.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5171023527496102354" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R8MqgEGXsdI/AAAAAAAAAmI/BLv8HV0S8oA/s400/webcodecvt.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-8688413997069204138?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/8688413997069204138/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=8688413997069204138&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8688413997069204138'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8688413997069204138'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/02/zlob-trojan-fake-error-real-infection.html' title='Zlob Trojan: fake error, real infection'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/R8MpY0GXsaI/AAAAAAAAAlw/RPw22a-XP1Q/s72-c/webcodec.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-2305324327001133224</id><published>2008-02-21T13:21:00.000-08:00</published><updated>2008-02-21T13:33:03.054-08:00</updated><title type='text'>Porn YouTube impersonation leads to malware</title><content type='html'>&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/R73s2UGXsXI/AAAAAAAAAlY/ACG1zbhTD4s/s1600-h/logoporntube.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5169548365143716210" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/R73s2UGXsXI/AAAAAAAAAlY/ACG1zbhTD4s/s400/logoporntube.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;"Show Yourself"?&lt;br /&gt;&lt;br /&gt;Once you pick a video, you are prompted to download a codec.&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R73s2kGXsYI/AAAAAAAAAlg/jiwDKWD8Tt4/s1600-h/porntubecontent.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5169548369438683522" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R73s2kGXsYI/AAAAAAAAAlg/jiwDKWD8Tt4/s400/porntubecontent.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The site is totally bogus and the comments posted are fake (of course). Though kudos to whoever wrote them.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/R73s2EGXsWI/AAAAAAAAAlQ/WsSVi4vfuts/s1600-h/comments.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5169548360848748898" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/R73s2EGXsWI/AAAAAAAAAlQ/WsSVi4vfuts/s400/comments.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Installs a rogue app (VirusHeat) as well as a bunch of other bad stuff.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/R73s20GXsZI/AAAAAAAAAlo/IMe2mWtAFfI/s1600-h/virusheat.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5169548373733650834" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/R73s20GXsZI/AAAAAAAAAlo/IMe2mWtAFfI/s400/virusheat.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-2305324327001133224?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/2305324327001133224/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=2305324327001133224&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2305324327001133224'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2305324327001133224'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/02/porn-youtube-impersonation-leads-to.html' title='Porn YouTube impersonation leads to malware'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/R73s2UGXsXI/AAAAAAAAAlY/ACG1zbhTD4s/s72-c/logoporntube.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-8546265738965459852</id><published>2008-02-20T14:38:00.000-08:00</published><updated>2008-02-20T14:42:26.357-08:00</updated><title type='text'>RogueFest</title><content type='html'>Stay away from those scams!&lt;br /&gt;&lt;br /&gt;Malware Crush:&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R7ysY0GXsTI/AAAAAAAAAk4/R21MTUC10f8/s1600-h/malwarecrush1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5169196014616686898" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R7ysY0GXsTI/AAAAAAAAAk4/R21MTUC10f8/s400/malwarecrush1.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Filter Program:&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/R7ysZEGXsUI/AAAAAAAAAlA/CyGjMvMYJSQ/s1600-h/filterprogram.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5169196018911654210" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/R7ysZEGXsUI/AAAAAAAAAlA/CyGjMvMYJSQ/s400/filterprogram.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Advanced Cleaner&lt;br /&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/R7ysZUGXsVI/AAAAAAAAAlI/SGqr-AqpqhM/s1600-h/advancedcleaner.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5169196023206621522" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/R7ysZUGXsVI/AAAAAAAAAlI/SGqr-AqpqhM/s400/advancedcleaner.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-8546265738965459852?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/8546265738965459852/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=8546265738965459852&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8546265738965459852'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8546265738965459852'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/02/roguefest.html' title='RogueFest'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/R7ysY0GXsTI/AAAAAAAAAk4/R21MTUC10f8/s72-c/malwarecrush1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-4480117126293357480</id><published>2008-02-18T12:41:00.000-08:00</published><updated>2008-02-18T12:44:07.318-08:00</updated><title type='text'>Search2Find installs rogue SystemDefender</title><content type='html'>&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R7ntxkGXsQI/AAAAAAAAAkg/eIKZ1FHdbTM/s1600-h/search2find1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5168423483144122626" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R7ntxkGXsQI/AAAAAAAAAkg/eIKZ1FHdbTM/s400/search2find1.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/R7ntx0GXsRI/AAAAAAAAAko/3bx6uOU6lqo/s1600-h/search2find2.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5168423487439089938" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/R7ntx0GXsRI/AAAAAAAAAko/3bx6uOU6lqo/s400/search2find2.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/R7ntyEGXsSI/AAAAAAAAAkw/2PkFIK5Hbg4/s1600-h/search2find3.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5168423491734057250" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/R7ntyEGXsSI/AAAAAAAAAkw/2PkFIK5Hbg4/s400/search2find3.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-4480117126293357480?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/4480117126293357480/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=4480117126293357480&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4480117126293357480'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4480117126293357480'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/02/search2find-installs-rogue.html' title='Search2Find installs rogue SystemDefender'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/R7ntxkGXsQI/AAAAAAAAAkg/eIKZ1FHdbTM/s72-c/search2find1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-6876219930690994081</id><published>2008-02-18T11:19:00.000-08:00</published><updated>2008-02-18T11:24:43.722-08:00</updated><title type='text'>Rogue infestation</title><content type='html'>A VM image infected with several rogue anti spyware apps. Note the antivirus.exe process (in Process Explorer). Although you see the process, the file is invisible to the system. Rootkit technique....&lt;br /&gt;Also, one of the rogue is VM aware....&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/R7na0UGXsLI/AAAAAAAAAj4/EVgBXzbYLN4/s1600-h/rogueprocessexplorer.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5168402639667835058" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/R7na0UGXsLI/AAAAAAAAAj4/EVgBXzbYLN4/s400/rogueprocessexplorer.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R7nbPkGXsPI/AAAAAAAAAkY/Y5H6iY4JVzE/s1600-h/roguevm.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5168403107819270386" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R7nbPkGXsPI/AAAAAAAAAkY/Y5H6iY4JVzE/s400/roguevm.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R7na0kGXsMI/AAAAAAAAAkA/ZoCDjV0H_D8/s1600-h/roguesyscleaner.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5168402643962802370" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R7na0kGXsMI/AAAAAAAAAkA/ZoCDjV0H_D8/s400/roguesyscleaner.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/R7na00GXsNI/AAAAAAAAAkI/H6t-j09kpC0/s1600-h/roguewallpaper.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5168402648257769682" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/R7na00GXsNI/AAAAAAAAAkI/H6t-j09kpC0/s400/roguewallpaper.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/R7na00GXsOI/AAAAAAAAAkQ/giy7Kc3rhL0/s1600-h/roguewarning.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5168402648257769698" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/R7na00GXsOI/AAAAAAAAAkQ/giy7Kc3rhL0/s400/roguewarning.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-6876219930690994081?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/6876219930690994081/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=6876219930690994081&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/6876219930690994081'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/6876219930690994081'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/02/rogue-infestation.html' title='Rogue infestation'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/R7na0UGXsLI/AAAAAAAAAj4/EVgBXzbYLN4/s72-c/rogueprocessexplorer.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-6008096410498193781</id><published>2008-02-15T12:27:00.000-08:00</published><updated>2008-02-15T13:20:14.136-08:00</updated><title type='text'>Rootkit + Rbot Worm</title><content type='html'>I found something interesting while analyzing a malware sample.&lt;br /&gt;A process called "taskmaneger.exe" was running (I can see it in Process Explorer). However it was not visible on the hard disk under its location System32.&lt;br /&gt;I therefore rebooted under Linux (dual boot drive) and mounted the XP disk. I browsed it from Linux and this time I found the cuplrit classified as the Rbot Worm.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/R7X2v0GXsKI/AAAAAAAAAjw/CVCv1zN_pQM/s1600-h/root.PNG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5167307448777158818" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/R7X2v0GXsKI/AAAAAAAAAjw/CVCv1zN_pQM/s400/root.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;It is using Rootkit techniques to hide itself from Explorer, however, the process is still visible....&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-6008096410498193781?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/6008096410498193781/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=6008096410498193781&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/6008096410498193781'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/6008096410498193781'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/02/rootkit-rbot-worm.html' title='Rootkit + Rbot Worm'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/R7X2v0GXsKI/AAAAAAAAAjw/CVCv1zN_pQM/s72-c/root.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-5499386668519652091</id><published>2008-02-05T14:25:00.000-08:00</published><updated>2008-02-05T14:26:02.436-08:00</updated><title type='text'>Most hacked AppInit_DLLs ever</title><content type='html'>&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/R6jiaJZ3_LI/AAAAAAAAAjg/wFk8T97CH2U/s1600-h/appinit1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5163625911609195698" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/R6jiaJZ3_LI/AAAAAAAAAjg/wFk8T97CH2U/s400/appinit1.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/R6jiaJZ3_MI/AAAAAAAAAjo/1JcGJAtBJ2c/s1600-h/appinit2.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5163625911609195714" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/R6jiaJZ3_MI/AAAAAAAAAjo/1JcGJAtBJ2c/s400/appinit2.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-5499386668519652091?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/5499386668519652091/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=5499386668519652091&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5499386668519652091'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5499386668519652091'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/02/most-hacked-appinitdlls-ever.html' title='Most hacked AppInit_DLLs ever'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/R6jiaJZ3_LI/AAAAAAAAAjg/wFk8T97CH2U/s72-c/appinit1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-6883064530740265676</id><published>2008-01-21T12:23:00.000-08:00</published><updated>2008-01-21T12:27:43.141-08:00</updated><title type='text'>Storm Worm: Love Edition</title><content type='html'>&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R5T_XWBl8hI/AAAAAAAAAi4/1Cdppt_CCS0/s1600-h/stormlove.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5158028249760395794" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R5T_XWBl8hI/AAAAAAAAAi4/1Cdppt_CCS0/s400/stormlove.png" border="0" /&gt;&lt;/a&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/R5T_XGBl8gI/AAAAAAAAAiw/b-UodtQ--FY/s1600-h/stormlove2.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5158028245465428482" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/R5T_XGBl8gI/AAAAAAAAAiw/b-UodtQ--FY/s400/stormlove2.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/R5UAE2Bl8iI/AAAAAAAAAjA/Yx1irImKfH0/s1600-h/stormlove3.png"&gt;&lt;/a&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/R5UALWBl8jI/AAAAAAAAAjI/DQZPpNYnD5s/s1600-h/stormlove3.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5158029143113593394" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/R5UALWBl8jI/AAAAAAAAAjI/DQZPpNYnD5s/s400/stormlove3.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-6883064530740265676?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/6883064530740265676/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=6883064530740265676&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/6883064530740265676'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/6883064530740265676'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/01/storm-worm-love-edition.html' title='Storm Worm: Love Edition'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/R5T_XWBl8hI/AAAAAAAAAi4/1Cdppt_CCS0/s72-c/stormlove.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-731096061709825315</id><published>2008-01-17T13:34:00.000-08:00</published><updated>2008-01-17T13:42:26.331-08:00</updated><title type='text'>Malware AutoIt error</title><content type='html'>AutoIt is a program to write Windows scripts. This malware author didn't smoke test it well enough... it crashed on my machine as it was trying to do its payload.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R4_LVmBl8fI/AAAAAAAAAio/dOTvaorhw2A/s1600-h/autoiterror.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5156563670207427058" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R4_LVmBl8fI/AAAAAAAAAio/dOTvaorhw2A/s400/autoiterror.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-731096061709825315?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/731096061709825315/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=731096061709825315&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/731096061709825315'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/731096061709825315'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/01/malware-autoit-error.html' title='Malware AutoIt error'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/R4_LVmBl8fI/AAAAAAAAAio/dOTvaorhw2A/s72-c/autoiterror.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-3080686442059082075</id><published>2008-01-10T15:54:00.000-08:00</published><updated>2008-01-10T16:11:04.346-08:00</updated><title type='text'>MSN Worm</title><content type='html'>The worm propagates from System to System by downloading an infected Zip file and sending it to all your contacts in MSN.&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/R4awVWBl8dI/AAAAAAAAAiY/e05ytsXp6ms/s1600-h/msnworm.png"&gt;&lt;/a&gt;&lt;/div&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R4awo2Bl8eI/AAAAAAAAAig/aQr6Dw2F2IY/s1600-h/msnworm.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5154001039315562978" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R4awo2Bl8eI/AAAAAAAAAig/aQr6Dw2F2IY/s400/msnworm.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;Stay away from pictures sent to you in a zip file!&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-3080686442059082075?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/3080686442059082075/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=3080686442059082075&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/3080686442059082075'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/3080686442059082075'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/01/msn-worm.html' title='MSN Worm'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/R4awo2Bl8eI/AAAAAAAAAig/aQr6Dw2F2IY/s72-c/msnworm.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-4459497369108971276</id><published>2008-01-04T13:52:00.000-08:00</published><updated>2008-01-04T13:53:49.239-08:00</updated><title type='text'>A Happy New Year from Storm Worm</title><content type='html'>Email from Storm Botnet:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/R36qpmBl8aI/AAAAAAAAAiA/_dO8gsdjUMI/s1600-h/stormemail1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5151742655317012898" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/R36qpmBl8aI/AAAAAAAAAiA/_dO8gsdjUMI/s400/stormemail1.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Infected page with obfuscated JavaScript:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R36qp2Bl8bI/AAAAAAAAAiI/n0Sa3E38u30/s1600-h/stormemail2.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5151742659611980210" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R36qp2Bl8bI/AAAAAAAAAiI/n0Sa3E38u30/s400/stormemail2.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Installs a rootkit on the PC&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R36qp2Bl8cI/AAAAAAAAAiQ/feDX2Lcsx-g/s1600-h/stormemail3.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5151742659611980226" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R36qp2Bl8cI/AAAAAAAAAiQ/feDX2Lcsx-g/s400/stormemail3.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-4459497369108971276?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/4459497369108971276/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=4459497369108971276&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4459497369108971276'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4459497369108971276'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/01/happy-new-year-from-storm-worm.html' title='A Happy New Year from Storm Worm'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/R36qpmBl8aI/AAAAAAAAAiA/_dO8gsdjUMI/s72-c/stormemail1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-8357506707166649437</id><published>2008-01-04T09:39:00.000-08:00</published><updated>2008-01-04T09:45:51.331-08:00</updated><title type='text'>Facebook Phishing Scam</title><content type='html'>This domain is hosted in China and pretends to be the Facebook login page.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/R35wRGBl8ZI/AAAAAAAAAh4/AYXkBe814TU/s1600-h/phish.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5151678462735806866" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/R35wRGBl8ZI/AAAAAAAAAh4/AYXkBe814TU/s400/phish.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Fiddler transcript below. It captures your email address and password and sends it over. After that, it redirects you to the legit Facebook page where you are prompted again to enter your credentials.&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R35wQ2Bl8YI/AAAAAAAAAhw/488rhXadnt4/s1600-h/2phish.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5151678458440839554" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R35wQ2Bl8YI/AAAAAAAAAhw/488rhXadnt4/s400/2phish.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-8357506707166649437?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/8357506707166649437/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=8357506707166649437&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8357506707166649437'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8357506707166649437'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2008/01/facebook-phishing-scam.html' title='Facebook Phishing Scam'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/R35wRGBl8ZI/AAAAAAAAAh4/AYXkBe814TU/s72-c/phish.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-4066116263650462107</id><published>2007-12-11T13:05:00.001-08:00</published><updated>2007-12-11T13:06:18.276-08:00</updated><title type='text'>DioCleaner Rogue</title><content type='html'>&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/R177urjHLGI/AAAAAAAAAho/yLHvh3275v4/s1600-h/ip.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5142824603886234722" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/R177urjHLGI/AAAAAAAAAho/yLHvh3275v4/s400/ip.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/R177rbjHLFI/AAAAAAAAAhg/REnz1ioX1C8/s1600-h/dio1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5142824548051659858" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/R177rbjHLFI/AAAAAAAAAhg/REnz1ioX1C8/s400/dio1.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/R177oLjHLEI/AAAAAAAAAhY/hL0CHcSPEJc/s1600-h/dio2.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5142824492217084994" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/R177oLjHLEI/AAAAAAAAAhY/hL0CHcSPEJc/s400/dio2.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Typical Rogue infection.&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-4066116263650462107?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/4066116263650462107/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=4066116263650462107&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4066116263650462107'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4066116263650462107'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/12/diocleaner-rogue.html' title='DioCleaner Rogue'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/R177urjHLGI/AAAAAAAAAho/yLHvh3275v4/s72-c/ip.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-6509073653508377922</id><published>2007-11-28T16:36:00.000-08:00</published><updated>2007-11-28T16:37:36.554-08:00</updated><title type='text'>IE Defender infection + hijacked search results</title><content type='html'>&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/R04JxLWP3BI/AAAAAAAAAhQ/w_zf5A2LYd0/s1600-h/hijackedresults.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5138054965340658706" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/R04JxLWP3BI/AAAAAAAAAhQ/w_zf5A2LYd0/s400/hijackedresults.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-6509073653508377922?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/6509073653508377922/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=6509073653508377922&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/6509073653508377922'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/6509073653508377922'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/11/ie-defender-infection-hijacked-search.html' title='IE Defender infection + hijacked search results'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/R04JxLWP3BI/AAAAAAAAAhQ/w_zf5A2LYd0/s72-c/hijackedresults.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-952573517299911686</id><published>2007-11-09T09:25:00.000-08:00</published><updated>2007-11-09T09:27:07.175-08:00</updated><title type='text'>Broken exploit</title><content type='html'>&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RzSYPZYAqyI/AAAAAAAAAgw/M1KnI34fZSg/s1600-h/brokenexploit.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5130893265758890786" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RzSYPZYAqyI/AAAAAAAAAgw/M1KnI34fZSg/s400/brokenexploit.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;Nice little function... but it is broken now. Too bad.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-952573517299911686?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/952573517299911686/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=952573517299911686&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/952573517299911686'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/952573517299911686'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/11/broken-exploit.html' title='Broken exploit'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/RzSYPZYAqyI/AAAAAAAAAgw/M1KnI34fZSg/s72-c/brokenexploit.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-4785473956368008833</id><published>2007-11-05T12:59:00.000-08:00</published><updated>2007-11-05T13:01:01.058-08:00</updated><title type='text'>Rogue uses System Shutdown ploy</title><content type='html'>&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/Ry-ETKcWwrI/AAAAAAAAAgo/4EEHn9HTJEA/s1600-h/shutdown.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5129463965353951922" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/Ry-ETKcWwrI/AAAAAAAAAgo/4EEHn9HTJEA/s400/shutdown.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If you let the timer go all the way, nothing happens.. of course...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-4785473956368008833?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/4785473956368008833/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=4785473956368008833&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4785473956368008833'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4785473956368008833'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/11/rogue-uses-system-shutdown-ploy.html' title='Rogue uses System Shutdown ploy'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/Ry-ETKcWwrI/AAAAAAAAAgo/4EEHn9HTJEA/s72-c/shutdown.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-701294644460806670</id><published>2007-11-02T10:12:00.001-07:00</published><updated>2007-11-02T10:13:43.308-07:00</updated><title type='text'>Fake 404 contains an iframe</title><content type='html'>&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RytahacWwpI/AAAAAAAAAgY/aVRcjyL_oVg/s1600-h/iframe.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5128292130771878546" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RytahacWwpI/AAAAAAAAAgY/aVRcjyL_oVg/s400/iframe.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;YES!!!!!!!&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RytaqacWwqI/AAAAAAAAAgg/FU_-bPlfw80/s1600-h/iframe2.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5128292285390701218" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RytaqacWwqI/AAAAAAAAAgg/FU_-bPlfw80/s400/iframe2.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-701294644460806670?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/701294644460806670/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=701294644460806670&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/701294644460806670'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/701294644460806670'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/11/fake-404-contains-iframe.html' title='Fake 404 contains an iframe'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/RytahacWwpI/AAAAAAAAAgY/aVRcjyL_oVg/s72-c/iframe.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-4500303529549342685</id><published>2007-10-29T15:34:00.001-07:00</published><updated>2007-10-29T15:35:21.758-07:00</updated><title type='text'>My Google homepage hacked</title><content type='html'>&lt;div&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RyZgDacWwnI/AAAAAAAAAgI/9NiHwlBjkR4/s1600-h/googlehack1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5126890837562016370" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RyZgDacWwnI/AAAAAAAAAgI/9NiHwlBjkR4/s400/googlehack1.png" border="0" /&gt;&lt;/a&gt; &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RyZgF6cWwoI/AAAAAAAAAgQ/eKdlpz0_sDk/s1600-h/googlehack2.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5126890880511689346" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RyZgF6cWwoI/AAAAAAAAAgQ/eKdlpz0_sDk/s400/googlehack2.png" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-4500303529549342685?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/4500303529549342685/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=4500303529549342685&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4500303529549342685'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4500303529549342685'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/10/my-google-homepage-hacked.html' title='My Google homepage hacked'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/RyZgDacWwnI/AAAAAAAAAgI/9NiHwlBjkR4/s72-c/googlehack1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-809096771465676934</id><published>2007-10-29T15:33:00.001-07:00</published><updated>2007-10-29T15:34:13.472-07:00</updated><title type='text'>Weird Error Message</title><content type='html'>&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RyZf3acWwmI/AAAAAAAAAgA/XYstUNZlxY0/s1600-h/weirderror.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5126890631403586146" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RyZf3acWwmI/AAAAAAAAAgA/XYstUNZlxY0/s400/weirderror.png" border="0" /&gt;&lt;/a&gt;  &lt;div&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-809096771465676934?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/809096771465676934/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=809096771465676934&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/809096771465676934'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/809096771465676934'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/10/weird-error-message.html' title='Weird Error Message'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/RyZf3acWwmI/AAAAAAAAAgA/XYstUNZlxY0/s72-c/weirderror.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-451861958311479122</id><published>2007-10-26T11:35:00.001-07:00</published><updated>2007-10-26T11:36:15.344-07:00</updated><title type='text'>Rogue with Knowledge base: are you serious?</title><content type='html'>&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RyIzlqcWwlI/AAAAAAAAAf4/Zdjf7lRMG7k/s1600-h/errorsafeknowledgebase.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5125716048042443346" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RyIzlqcWwlI/AAAAAAAAAf4/Zdjf7lRMG7k/s400/errorsafeknowledgebase.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-451861958311479122?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/451861958311479122/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=451861958311479122&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/451861958311479122'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/451861958311479122'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/10/rogue-with-knowledge-base-are-you.html' title='Rogue with Knowledge base: are you serious?'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/RyIzlqcWwlI/AAAAAAAAAf4/Zdjf7lRMG7k/s72-c/errorsafeknowledgebase.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-3751790581424484588</id><published>2007-10-18T15:29:00.000-07:00</published><updated>2007-10-18T15:30:40.860-07:00</updated><title type='text'>Oh, a security toolbar?</title><content type='html'>&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RxfecT3hMZI/AAAAAAAAAfw/7nyefeE6op0/s1600-h/avsystemcaretoolbar.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5122807679108067730" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RxfecT3hMZI/AAAAAAAAAfw/7nyefeE6op0/s400/avsystemcaretoolbar.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;Welcome back to AVSystemCare's deceptive security toolbar.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-3751790581424484588?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/3751790581424484588/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=3751790581424484588&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/3751790581424484588'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/3751790581424484588'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/10/oh-security-toolbar.html' title='Oh, a security toolbar?'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/RxfecT3hMZI/AAAAAAAAAfw/7nyefeE6op0/s72-c/avsystemcaretoolbar.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-8649591113789848139</id><published>2007-10-18T15:26:00.000-07:00</published><updated>2007-10-18T15:29:08.570-07:00</updated><title type='text'>PrivacyProtector's provocative ad</title><content type='html'>How far are rogue programs going to go to convince you?&lt;br /&gt;&lt;br /&gt;This is shocking, showing you real porn pictures that you may have on your computer.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/Rxfd4D3hMYI/AAAAAAAAAfo/7HlPUn69JXE/s1600-h/privacyprotectorad.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5122807056337809794" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/Rxfd4D3hMYI/AAAAAAAAAfo/7HlPUn69JXE/s400/privacyprotectorad.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-8649591113789848139?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/8649591113789848139/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=8649591113789848139&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8649591113789848139'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8649591113789848139'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/10/privacyprotectors-provocative-ad.html' title='PrivacyProtector&apos;s provocative ad'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_CRb3gYmxpzA/Rxfd4D3hMYI/AAAAAAAAAfo/7HlPUn69JXE/s72-c/privacyprotectorad.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-4620565034070075169</id><published>2007-10-15T13:09:00.000-07:00</published><updated>2007-10-15T13:10:53.863-07:00</updated><title type='text'>PestTrap goes X</title><content type='html'>Their new domain: xpesttrap.com&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RxPJKD3hMWI/AAAAAAAAAfY/UCfPUzaXb7Q/s1600-h/pesttrap.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5121658375924429154" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RxPJKD3hMWI/AAAAAAAAAfY/UCfPUzaXb7Q/s400/pesttrap.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-4620565034070075169?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/4620565034070075169/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=4620565034070075169&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4620565034070075169'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4620565034070075169'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/10/pesttrap-goes-x.html' title='PestTrap goes X'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_CRb3gYmxpzA/RxPJKD3hMWI/AAAAAAAAAfY/UCfPUzaXb7Q/s72-c/pesttrap.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-1021359471860383028</id><published>2007-10-15T12:26:00.000-07:00</published><updated>2007-10-15T13:36:31.361-07:00</updated><title type='text'>AVSystemCare: from fake alert to rogue</title><content type='html'>Fake alert #1:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RxO-_j3hMSI/AAAAAAAAAe4/H5nX5IxQDG0/s1600-h/avsystemcare1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5121647200419524898" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RxO-_j3hMSI/AAAAAAAAAe4/H5nX5IxQDG0/s400/avsystemcare1.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Fake alert#2:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RxO_Gj3hMTI/AAAAAAAAAfA/c47KG9Vmdko/s1600-h/avsystemcare2.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5121647320678609202" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RxO_Gj3hMTI/AAAAAAAAAfA/c47KG9Vmdko/s400/avsystemcare2.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Webpage:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RxO_Gj3hMUI/AAAAAAAAAfI/0M5gtfa6MZs/s1600-h/avsystemcare3.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5121647320678609218" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RxO_Gj3hMUI/AAAAAAAAAfI/0M5gtfa6MZs/s400/avsystemcare3.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Rogue:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RxPPNz3hMXI/AAAAAAAAAfg/uQOAnqJKJtU/s1600-h/avsystemcare4.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5121665037418705266" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RxPPNz3hMXI/AAAAAAAAAfg/uQOAnqJKJtU/s400/avsystemcare4.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-1021359471860383028?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/1021359471860383028/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=1021359471860383028&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/1021359471860383028'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/1021359471860383028'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/10/avsystemcare-from-fake-alert-to-rogue.html' title='AVSystemCare: from fake alert to rogue'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/RxO-_j3hMSI/AAAAAAAAAe4/H5nX5IxQDG0/s72-c/avsystemcare1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-2220601024034635367</id><published>2007-10-12T11:48:00.001-07:00</published><updated>2007-10-12T11:51:07.443-07:00</updated><title type='text'>Storm Worm rootkit</title><content type='html'>&lt;div&gt;I know this is kind of old news but here is a little sample of what it does.&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;Upon execution the file ecard.exe will run its payload, which is installing a rootkit and then will forcefully reboot the machine.&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;A screenshot of a scan done with RootkitRevealer below shows the file hidden from Windows, but yet still very active.&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/Rw_BwD3hMRI/AAAAAAAAAew/Zz3qO50cnCY/s1600-h/ecard+rootkit.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5120524332759593234" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/Rw_BwD3hMRI/AAAAAAAAAew/Zz3qO50cnCY/s400/ecard+rootkit.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-2220601024034635367?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/2220601024034635367/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=2220601024034635367&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2220601024034635367'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2220601024034635367'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/10/storm-worm-rootkit.html' title='Storm Worm rootkit'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_CRb3gYmxpzA/Rw_BwD3hMRI/AAAAAAAAAew/Zz3qO50cnCY/s72-c/ecard+rootkit.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-1920422449212802669</id><published>2007-09-25T15:49:00.001-07:00</published><updated>2007-09-25T15:51:06.754-07:00</updated><title type='text'>Part of a Botnet</title><content type='html'>After running a Trojan, I checked the network traffic for communications with the outside.&lt;br /&gt;&lt;br /&gt;The Trojan was reporting the name of my computer and other info to a web server... The kind of stats a bot herder might use...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RvmQdD3hMQI/AAAAAAAAAeo/sJwThya5H7o/s1600-h/joiningabotnet.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5114277680784683266" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RvmQdD3hMQI/AAAAAAAAAeo/sJwThya5H7o/s400/joiningabotnet.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-1920422449212802669?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/1920422449212802669/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=1920422449212802669&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/1920422449212802669'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/1920422449212802669'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/09/part-of-botnet.html' title='Part of a Botnet'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/RvmQdD3hMQI/AAAAAAAAAeo/sJwThya5H7o/s72-c/joiningabotnet.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-6477419690066712473</id><published>2007-09-25T15:40:00.001-07:00</published><updated>2007-09-25T15:46:10.967-07:00</updated><title type='text'>Live Messenger infection</title><content type='html'>Running Live Messenger with a lot of (unknown) contacts can be a dangerous thing:&lt;br /&gt;&lt;br /&gt;First a window pops up. It's not a good sign when I haven't touched my browser:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RvmOjD3hMPI/AAAAAAAAAeg/2KCdciKOqeQ/s1600-h/msninfection2.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5114275584840642802" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RvmOjD3hMPI/AAAAAAAAAeg/2KCdciKOqeQ/s400/msninfection2.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;A quick glance at Process Explorer confirms the infection:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RvmOfz3hMOI/AAAAAAAAAeY/VEPv9IuOZBA/s1600-h/msninfection1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5114275529006067938" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RvmOfz3hMOI/AAAAAAAAAeY/VEPv9IuOZBA/s400/msninfection1.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-6477419690066712473?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/6477419690066712473/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=6477419690066712473&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/6477419690066712473'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/6477419690066712473'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/09/live-messenger-infection.html' title='Live Messenger infection'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/RvmOjD3hMPI/AAAAAAAAAeg/2KCdciKOqeQ/s72-c/msninfection2.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-8769230213832890024</id><published>2007-09-20T16:35:00.000-07:00</published><updated>2007-09-20T16:38:46.330-07:00</updated><title type='text'>RogueFest in the UK</title><content type='html'>behappysyst.com hosts a large number of rogues. It is hosted in the UK&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RvMEWj3hMNI/AAAAAAAAAeQ/M2ilV3EEPSA/s1600-h/behappysyst2.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5112434787627380946" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RvMEWj3hMNI/AAAAAAAAAeQ/M2ilV3EEPSA/s400/behappysyst2.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RvMESD3hMMI/AAAAAAAAAeI/4ug783Yi6_Q/s1600-h/behappysyst1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5112434710317969602" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RvMESD3hMMI/AAAAAAAAAeI/4ug783Yi6_Q/s400/behappysyst1.png" border="0" /&gt;&lt;/a&gt;  &lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-8769230213832890024?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/8769230213832890024/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=8769230213832890024&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8769230213832890024'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8769230213832890024'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/09/roguefest-in-uk.html' title='RogueFest in the UK'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/RvMEWj3hMNI/AAAAAAAAAeQ/M2ilV3EEPSA/s72-c/behappysyst2.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-5164587772820123745</id><published>2007-09-18T13:03:00.001-07:00</published><updated>2007-09-18T13:04:19.399-07:00</updated><title type='text'>Fake gaming site installs Trojan</title><content type='html'>This site installs a variant of the Newar Trojan.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RvAvK9rWyqI/AAAAAAAAAeA/jz5o3BIjT3E/s1600-h/arcadestorm.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5111637442467121826" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RvAvK9rWyqI/AAAAAAAAAeA/jz5o3BIjT3E/s400/arcadestorm.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-5164587772820123745?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/5164587772820123745/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=5164587772820123745&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5164587772820123745'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5164587772820123745'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/09/fake-gaming-site-installs-trojan.html' title='Fake gaming site installs Trojan'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/RvAvK9rWyqI/AAAAAAAAAeA/jz5o3BIjT3E/s72-c/arcadestorm.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-7667204318515358053</id><published>2007-09-18T12:58:00.000-07:00</published><updated>2007-09-18T13:01:16.381-07:00</updated><title type='text'>Worm tries to propagate using MySpace posts</title><content type='html'>Dangerous URL posted on a MySpace web page.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RvAuHdrWyoI/AAAAAAAAAdw/McGOutCHX8g/s1600-h/myspace1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5111636282825951874" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RvAuHdrWyoI/AAAAAAAAAdw/McGOutCHX8g/s400/myspace1.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RvAuKdrWypI/AAAAAAAAAd4/PacYK_9X6tA/s1600-h/myspace2.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5111636334365559442" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RvAuKdrWypI/AAAAAAAAAd4/PacYK_9X6tA/s400/myspace2.png" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-7667204318515358053?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/7667204318515358053/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=7667204318515358053&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/7667204318515358053'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/7667204318515358053'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/09/worm-tries-to-propagate-using-myspace.html' title='Worm tries to propagate using MySpace posts'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/RvAuHdrWyoI/AAAAAAAAAdw/McGOutCHX8g/s72-c/myspace1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-6939935912944678954</id><published>2007-09-05T11:26:00.000-07:00</published><updated>2007-09-05T11:37:50.931-07:00</updated><title type='text'>PornTube... dangerous fake codec</title><content type='html'>Watch out for this YouTube imitation... Nasty Trojan when you download a video.&lt;br /&gt;&lt;br /&gt;New Zlob fake codec site: hxxp://zero-codec.com&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/Rt707k1xFMI/AAAAAAAAAdo/6UfCZ37SVao/s1600-h/porntube.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5106788331823371458" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/Rt707k1xFMI/AAAAAAAAAdo/6UfCZ37SVao/s400/porntube.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-6939935912944678954?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/6939935912944678954/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=6939935912944678954&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/6939935912944678954'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/6939935912944678954'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/09/porntube-dangerous-fake-codec.html' title='PornTube... dangerous fake codec'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/Rt707k1xFMI/AAAAAAAAAdo/6UfCZ37SVao/s72-c/porntube.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-917368597414853009</id><published>2007-09-05T08:46:00.000-07:00</published><updated>2007-09-05T08:48:43.058-07:00</updated><title type='text'>Scam or not?</title><content type='html'>&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/Rt7Pek1xFLI/AAAAAAAAAdg/vCc8tHjLVUE/s1600-h/spray.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5106747151676937394" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/Rt7Pek1xFLI/AAAAAAAAAdg/vCc8tHjLVUE/s400/spray.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It may work... but come on, 100% legal???? What's the point in having a license plate then?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-917368597414853009?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/917368597414853009/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=917368597414853009&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/917368597414853009'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/917368597414853009'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/09/scam-or-not.html' title='Scam or not?'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/Rt7Pek1xFLI/AAAAAAAAAdg/vCc8tHjLVUE/s72-c/spray.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-3996738051089326079</id><published>2007-09-04T12:12:00.000-07:00</published><updated>2007-09-04T12:14:46.396-07:00</updated><title type='text'>Porn pop up leads to Zango's website</title><content type='html'>Ran a Trojan that created a pop-up designed to ressemble Youtube videos. On click, you are redirected to Zango's website.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/Rt2uSk1xFKI/AAAAAAAAAdY/B0i_4RgpoZM/s1600-h/zango.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5106429186658079906" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/Rt2uSk1xFKI/AAAAAAAAAdY/B0i_4RgpoZM/s400/zango.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-3996738051089326079?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/3996738051089326079/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=3996738051089326079&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/3996738051089326079'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/3996738051089326079'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/09/porn-pop-up-leads-to-zangos-website.html' title='Porn pop up leads to Zango&apos;s website'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_CRb3gYmxpzA/Rt2uSk1xFKI/AAAAAAAAAdY/B0i_4RgpoZM/s72-c/zango.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-6197162973064463734</id><published>2007-08-30T15:24:00.000-07:00</published><updated>2007-08-30T15:50:32.457-07:00</updated><title type='text'>Well crafted IM Worm</title><content type='html'>I came across an interesting IM Worm today:&lt;br /&gt;&lt;br /&gt;First, I get this IM with a link to follow:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RtdFDE1xFHI/AAAAAAAAAdA/HJvBO5xxWfA/s1600-h/msn1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5104624621788927090" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RtdFDE1xFHI/AAAAAAAAAdA/HJvBO5xxWfA/s400/msn1.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It brings me to this website, that, for some reason ;-), needs me to install the Flash player:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RtdFA01xFGI/AAAAAAAAAc4/V15nDGQ1deo/s1600-h/msn2.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5104624583134221410" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RtdFA01xFGI/AAAAAAAAAc4/V15nDGQ1deo/s400/msn2.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Surprisingly, this "Flash Player" is infected!!!&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RtdE-U1xFFI/AAAAAAAAAcw/ussVmvj7ML4/s1600-h/msn3.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5104624540184548434" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RtdE-U1xFFI/AAAAAAAAAcw/ussVmvj7ML4/s400/msn3.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In case, I didn't download the file, the webpage itself has a malicious and obfuscated code that pushes the installer down my throat:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RtdE7U1xFEI/AAAAAAAAAco/ohDi0qUEhlw/s1600-h/msn4.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5104624488644940866" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RtdE7U1xFEI/AAAAAAAAAco/ohDi0qUEhlw/s400/msn4.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;And to finish the loop, it sends out Instant Messages in my name to all the people on my contact list (to spread the word I suppose).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RtdE301xFDI/AAAAAAAAAcg/YcmtaiVggUI/s1600-h/answer.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5104624428515398706" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RtdE301xFDI/AAAAAAAAAcg/YcmtaiVggUI/s400/answer.png" border="0" /&gt;&lt;/a&gt; &lt;/div&gt;&lt;br /&gt;&lt;div&gt;The culprits:&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RtdJlU1xFJI/AAAAAAAAAdQ/WlvUjUAdrt4/s1600-h/culprits.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5104629608245957778" style="WIDTH: 249px; CURSOR: hand; HEIGHT: 65px" height="65" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RtdJlU1xFJI/AAAAAAAAAdQ/WlvUjUAdrt4/s400/culprits.png" width="287" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-6197162973064463734?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/6197162973064463734/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=6197162973064463734&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/6197162973064463734'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/6197162973064463734'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/08/well-crafted-im-worm.html' title='Well crafted IM Worm'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_CRb3gYmxpzA/RtdFDE1xFHI/AAAAAAAAAdA/HJvBO5xxWfA/s72-c/msn1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-4773173969000231303</id><published>2007-08-29T10:43:00.000-07:00</published><updated>2007-08-29T11:07:14.736-07:00</updated><title type='text'>Fake Google site</title><content type='html'>Drive-by exploit launches when you visit this site. If you use Firefox they trick you into downloading an add-on.&lt;br /&gt;&lt;br /&gt;Another point of interest, clicking on the Sign in link will open the AdultFriendFinder website. Oops..&lt;br /&gt;&lt;br /&gt;To avoid this, check out the URL in the address bar. It is not Google's. Also, Google will never ask you to download additional software to do a search. At least, not right now.&lt;br /&gt;Also, drag your mouse onto the links on the page, and you may see in IE's status bar, that they point to a totally different site.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RtWxkE1xFCI/AAAAAAAAAcY/FOJqXf1OK8Y/s1600-h/fake+google.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5104180986026988578" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RtWxkE1xFCI/AAAAAAAAAcY/FOJqXf1OK8Y/s400/fake+google.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RtWw401xFBI/AAAAAAAAAcQ/TZVkRjPlCVE/s1600-h/fake+google.png"&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-4773173969000231303?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/4773173969000231303/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=4773173969000231303&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4773173969000231303'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4773173969000231303'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/08/fake-google-site.html' title='Fake Google site'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/RtWxkE1xFCI/AAAAAAAAAcY/FOJqXf1OK8Y/s72-c/fake+google.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-8530488557574164163</id><published>2007-08-22T13:53:00.000-07:00</published><updated>2007-08-22T13:57:03.491-07:00</updated><title type='text'>Rogue program makes spelling mistake</title><content type='html'>Malware - not "Malaware". TrustedAntivirus is a rogue anti-spyware program.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/Rsyibk1xE_I/AAAAAAAAAcA/9jlEWviBZU4/s1600-h/trustedantivirus.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5101631072533287922" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/Rsyibk1xE_I/AAAAAAAAAcA/9jlEWviBZU4/s400/trustedantivirus.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RsyijE1xFAI/AAAAAAAAAcI/um4qxHbSO90/s1600-h/trustedantivrus2.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5101631201382306818" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RsyijE1xFAI/AAAAAAAAAcI/um4qxHbSO90/s400/trustedantivrus2.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-8530488557574164163?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/8530488557574164163/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=8530488557574164163&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8530488557574164163'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8530488557574164163'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/08/rogue-program-makes-spelling-mistake.html' title='Rogue program makes spelling mistake'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/Rsyibk1xE_I/AAAAAAAAAcA/9jlEWviBZU4/s72-c/trustedantivirus.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-8463817682928193960</id><published>2007-08-20T13:13:00.000-07:00</published><updated>2007-08-20T13:30:49.519-07:00</updated><title type='text'>New file name for fake ecard</title><content type='html'>&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/Rsn5701xE-I/AAAAAAAAAb4/C58M9MAzcBU/s1600-h/sexecard.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5100882859165553634" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/Rsn5701xE-I/AAAAAAAAAb4/C58M9MAzcBU/s400/sexecard.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/Rsn2EE1xE9I/AAAAAAAAAbw/7Yan2oNsw3M/s1600-h/applet.exe.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5100878602852963282" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/Rsn2EE1xE9I/AAAAAAAAAbw/7Yan2oNsw3M/s400/applet.exe.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-8463817682928193960?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/8463817682928193960/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=8463817682928193960&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8463817682928193960'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8463817682928193960'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/08/new-file-name-for-fake-ecard.html' title='New file name for fake ecard'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/Rsn5701xE-I/AAAAAAAAAb4/C58M9MAzcBU/s72-c/sexecard.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-4909319089340912214</id><published>2007-08-20T10:11:00.000-07:00</published><updated>2007-08-20T10:15:19.074-07:00</updated><title type='text'>Interesting MSN stuff</title><content type='html'>This user's display name is "DO NOT ACCEPT FILES FROM ME".... Well, it makes sense since it is trying to send me some infected files... But still, rather odd.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RsnLYE1xE7I/AAAAAAAAAbg/efquJLSRQkY/s1600-h/msn1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5100831667450352562" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RsnLYE1xE7I/AAAAAAAAAbg/efquJLSRQkY/s400/msn1.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;This one likes to send pictures and other stuff... even after the first No, they continued... Of course, these files are dangerous to open.&lt;/p&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RsnLdU1xE8I/AAAAAAAAAbo/odvtfm_OFUk/s1600-h/msn2.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5100831757644665794" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RsnLdU1xE8I/AAAAAAAAAbo/odvtfm_OFUk/s400/msn2.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-4909319089340912214?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/4909319089340912214/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=4909319089340912214&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4909319089340912214'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4909319089340912214'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/08/interesting-msn-stuff.html' title='Interesting MSN stuff'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/RsnLYE1xE7I/AAAAAAAAAbg/efquJLSRQkY/s72-c/msn1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-2567339708313061548</id><published>2007-08-16T14:34:00.001-07:00</published><updated>2007-08-16T14:37:11.247-07:00</updated><title type='text'>More fake ecard material</title><content type='html'>&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RsTDYE1xE6I/AAAAAAAAAbY/8_Q_Q6qQntc/s1600-h/firefox+ecard.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5099415496473777058" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RsTDYE1xE6I/AAAAAAAAAbY/8_Q_Q6qQntc/s400/firefox+ecard.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;The malware author is taking on Kaspersky... As you can see in the JavaScript exploit. (Html source code)&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;Warning! foul language&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RsTC_k1xE5I/AAAAAAAAAbQ/2wwkt2xRBaw/s1600-h/sourcecode.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5099415075566982034" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RsTC_k1xE5I/AAAAAAAAAbQ/2wwkt2xRBaw/s400/sourcecode.png" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-2567339708313061548?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/2567339708313061548/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=2567339708313061548&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2567339708313061548'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2567339708313061548'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/08/more-fake-ecard-material.html' title='More fake ecard material'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/RsTDYE1xE6I/AAAAAAAAAbY/8_Q_Q6qQntc/s72-c/firefox+ecard.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-7212052566814281471</id><published>2007-08-15T10:40:00.001-07:00</published><updated>2007-08-15T10:42:16.834-07:00</updated><title type='text'>Ecard changes name, same threat</title><content type='html'>If you get one of these emails, stay away from the link as it contains a variant of the Nuwar Trojan.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RsM6j9AaS8I/AAAAAAAAAbA/S9UStJMqj78/s1600-h/postcardnewname.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5098983592459652034" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RsM6j9AaS8I/AAAAAAAAAbA/S9UStJMqj78/s400/postcardnewname.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The ecard.exe file has now been replaced by msdataaccess.exe&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RsM6oNAaS9I/AAAAAAAAAbI/3L1_3goZk1w/s1600-h/ecardaccess.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5098983665474096082" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RsM6oNAaS9I/AAAAAAAAAbI/3L1_3goZk1w/s400/ecardaccess.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-7212052566814281471?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/7212052566814281471/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=7212052566814281471&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/7212052566814281471'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/7212052566814281471'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/08/ecard-changes-name-same-threat.html' title='Ecard changes name, same threat'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_CRb3gYmxpzA/RsM6j9AaS8I/AAAAAAAAAbA/S9UStJMqj78/s72-c/postcardnewname.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-8923835017349382204</id><published>2007-08-14T14:20:00.000-07:00</published><updated>2007-08-14T14:23:09.500-07:00</updated><title type='text'>UN-obfuscated website</title><content type='html'>Whoever hacked this site could have been more discreet... They left a big footprint with their JavaScript exploit appearing top page.&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RsIcu9AaS7I/AAAAAAAAAa4/8lwa-b39XtA/s1600-h/unobfuscated.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5098669321112669106" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RsIcu9AaS7I/AAAAAAAAAa4/8lwa-b39XtA/s400/unobfuscated.png" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-8923835017349382204?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/8923835017349382204/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=8923835017349382204&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8923835017349382204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8923835017349382204'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/08/un-obfuscated-website.html' title='UN-obfuscated website'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/RsIcu9AaS7I/AAAAAAAAAa4/8lwa-b39XtA/s72-c/unobfuscated.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-4145213786478510962</id><published>2007-08-14T14:08:00.000-07:00</published><updated>2007-08-14T14:09:51.922-07:00</updated><title type='text'>Adult website hacked?</title><content type='html'>True or not, thanks for letting users know ;-)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RsIZ_tAaS6I/AAAAAAAAAaw/5CyDnZ-CJtI/s1600-h/adulthacked.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5098666310340594594" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RsIZ_tAaS6I/AAAAAAAAAaw/5CyDnZ-CJtI/s400/adulthacked.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-4145213786478510962?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/4145213786478510962/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=4145213786478510962&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4145213786478510962'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4145213786478510962'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/08/adult-website-hacked.html' title='Adult website hacked?'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/RsIZ_tAaS6I/AAAAAAAAAaw/5CyDnZ-CJtI/s72-c/adulthacked.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-4320397647713818868</id><published>2007-08-13T15:51:00.000-07:00</published><updated>2007-08-13T15:55:52.625-07:00</updated><title type='text'>Malware websites backend</title><content type='html'>Not sure exactly what all the parameters stand for, but those were found on malware host domains. It seems they dynamically update the malware files and also keep stats.&lt;br /&gt;(Click on the pic to enlarge)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RsDg-tAaS3I/AAAAAAAAAaY/xZyQL3qR1QA/s1600-h/backend1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5098322146021231474" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RsDg-tAaS3I/AAAAAAAAAaY/xZyQL3qR1QA/s400/backend1.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RsDhCNAaS4I/AAAAAAAAAag/eVpzurRwDks/s1600-h/backend2.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5098322206150773634" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RsDhCNAaS4I/AAAAAAAAAag/eVpzurRwDks/s400/backend2.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-4320397647713818868?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/4320397647713818868/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=4320397647713818868&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4320397647713818868'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4320397647713818868'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/08/malware-websites-backend.html' title='Malware websites backend'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_CRb3gYmxpzA/RsDg-tAaS3I/AAAAAAAAAaY/xZyQL3qR1QA/s72-c/backend1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-5818859052431382525</id><published>2007-08-10T11:29:00.000-07:00</published><updated>2007-08-10T11:31:24.469-07:00</updated><title type='text'>Fake ecard tries to lure you using real Greeting cards signature</title><content type='html'>&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/Rryu0NAaS2I/AAAAAAAAAaQ/BuDDiVb3Fcc/s1600-h/funnycard.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5097141090144373602" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/Rryu0NAaS2I/AAAAAAAAAaQ/BuDDiVb3Fcc/s400/funnycard.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;The custom link is malicious, whereas the second one is a legitimate ecard website.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-5818859052431382525?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/5818859052431382525/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=5818859052431382525&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5818859052431382525'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5818859052431382525'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/08/fake-ecard-tries-to-lure-you-using-real.html' title='Fake ecard tries to lure you using real Greeting cards signature'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/Rryu0NAaS2I/AAAAAAAAAaQ/BuDDiVb3Fcc/s72-c/funnycard.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-4047354587650133677</id><published>2007-08-09T14:39:00.000-07:00</published><updated>2007-08-09T14:56:31.950-07:00</updated><title type='text'>Malware from China</title><content type='html'>&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RruJn9AaS0I/AAAAAAAAAaA/p-HaTmPvzto/s1600-h/china.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5096818722784037698" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RruJn9AaS0I/AAAAAAAAAaA/p-HaTmPvzto/s400/china.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;VirusTotal scan of one of the items... not widely detected yet.&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RruJzdAaS1I/AAAAAAAAAaI/rD08BaXjb2o/s1600-h/chinab.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5096818920352533330" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RruJzdAaS1I/AAAAAAAAAaI/rD08BaXjb2o/s400/chinab.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-4047354587650133677?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/4047354587650133677/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=4047354587650133677&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4047354587650133677'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4047354587650133677'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/08/malware-from-china.html' title='Malware from China'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_CRb3gYmxpzA/RruJn9AaS0I/AAAAAAAAAaA/p-HaTmPvzto/s72-c/china.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-5531996446641843</id><published>2007-08-07T17:04:00.000-07:00</published><updated>2007-08-07T17:18:35.475-07:00</updated><title type='text'>Peculiar Trojan</title><content type='html'>This Trojan is quite harsh on system resources... It spawns an insane amount of cmd.exe processes.... I like the cascade effect...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RrkIuNAaSyI/AAAAAAAAAZw/luxqMB0PIT8/s1600-h/cmd.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5096114043204815650" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RrkIuNAaSyI/AAAAAAAAAZw/luxqMB0PIT8/s400/cmd.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;Scan from VirusTotal:&lt;br /&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RrkLgdAaSzI/AAAAAAAAAZ4/DzUoF9qJdzc/s1600-h/results.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5096117105516497714" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RrkLgdAaSzI/AAAAAAAAAZ4/DzUoF9qJdzc/s400/results.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-5531996446641843?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/5531996446641843/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=5531996446641843&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5531996446641843'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5531996446641843'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/08/peculiar-trojan.html' title='Peculiar Trojan'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/RrkIuNAaSyI/AAAAAAAAAZw/luxqMB0PIT8/s72-c/cmd.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-8931432966296922821</id><published>2007-08-07T11:30:00.001-07:00</published><updated>2007-08-07T12:30:39.583-07:00</updated><title type='text'>I must have a lot of friends?!?!!</title><content type='html'>&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/Rri6YNAaSwI/AAAAAAAAAZg/Wr4Hq0zUA1c/s1600-h/fakepostcards.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5096027903340727042" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/Rri6YNAaSwI/AAAAAAAAAZg/Wr4Hq0zUA1c/s400/fakepostcards.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;Below are the domains the fake ecards point to:&lt;/p&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RrjIHtAaSxI/AAAAAAAAAZo/UluCUkoqTZc/s1600-h/domains.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5096043013035674386" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RrjIHtAaSxI/AAAAAAAAAZo/UluCUkoqTZc/s400/domains.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-8931432966296922821?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/8931432966296922821/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=8931432966296922821&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8931432966296922821'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8931432966296922821'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/08/i-must-have-lot-of-friends.html' title='I must have a lot of friends?!?!!'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/Rri6YNAaSwI/AAAAAAAAAZg/Wr4Hq0zUA1c/s72-c/fakepostcards.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-5682812876003392292</id><published>2007-08-07T10:41:00.001-07:00</published><updated>2007-08-07T10:42:18.864-07:00</updated><title type='text'>YouTube Spam</title><content type='html'>&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/Rriu6dAaSvI/AAAAAAAAAZY/wQiclE9-0eA/s1600-h/youtube.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5096015297611713266" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/Rriu6dAaSvI/AAAAAAAAAZY/wQiclE9-0eA/s400/youtube.jpg" border="0" /&gt;&lt;/a&gt;  &lt;div&gt;&lt;div&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RriuwNAaSuI/AAAAAAAAAZQ/W8GiATYvpUo/s1600-h/youtubespam.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5096015121518054114" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RriuwNAaSuI/AAAAAAAAAZQ/W8GiATYvpUo/s400/youtubespam.jpg" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-5682812876003392292?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/5682812876003392292/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=5682812876003392292&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5682812876003392292'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5682812876003392292'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/08/youtube-spam.html' title='YouTube Spam'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/Rriu6dAaSvI/AAAAAAAAAZY/wQiclE9-0eA/s72-c/youtube.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-5884859643114315689</id><published>2007-07-31T09:30:00.000-07:00</published><updated>2007-07-31T09:31:45.411-07:00</updated><title type='text'>C'est la Java-naise in my taskbar</title><content type='html'>&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/Rq9jy9AaStI/AAAAAAAAAZI/H8Z39-2iZwU/s1600-h/taskbar.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5093399430600215250" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/Rq9jy9AaStI/AAAAAAAAAZI/H8Z39-2iZwU/s400/taskbar.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-5884859643114315689?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/5884859643114315689/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=5884859643114315689&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5884859643114315689'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5884859643114315689'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/07/cest-la-java-naise-in-my-taskbar.html' title='C&apos;est la Java-naise in my taskbar'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_CRb3gYmxpzA/Rq9jy9AaStI/AAAAAAAAAZI/H8Z39-2iZwU/s72-c/taskbar.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-8210638677041419827</id><published>2007-07-27T14:09:00.001-07:00</published><updated>2007-07-27T14:11:13.517-07:00</updated><title type='text'>Fake warning pop up from Ultimate Defender</title><content type='html'>URL:&lt;br /&gt;hxxp://209.9.170.171/MTgyOjUxMjo=/ucleaner_setup.exe&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RqpfDmBwQdI/AAAAAAAAAZA/jlgM4zeDLRo/s1600-h/udefender.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5091986844047917522" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RqpfDmBwQdI/AAAAAAAAAZA/jlgM4zeDLRo/s400/udefender.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-8210638677041419827?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/8210638677041419827/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=8210638677041419827&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8210638677041419827'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8210638677041419827'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/07/fake-warning-pop-up-from-ultimate.html' title='Fake warning pop up from Ultimate Defender'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_CRb3gYmxpzA/RqpfDmBwQdI/AAAAAAAAAZA/jlgM4zeDLRo/s72-c/udefender.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-3111713435931570475</id><published>2007-07-26T16:29:00.001-07:00</published><updated>2007-07-26T16:30:24.542-07:00</updated><title type='text'>I thought "I" was the Admin</title><content type='html'>&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/Rqkue2BwQcI/AAAAAAAAAY4/va78fN5n7mM/s1600-h/cmd.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5091651961152881090" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/Rqkue2BwQcI/AAAAAAAAAY4/va78fN5n7mM/s400/cmd.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-3111713435931570475?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/3111713435931570475/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=3111713435931570475&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/3111713435931570475'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/3111713435931570475'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/07/i-thought-i-was-admin.html' title='I thought &quot;I&quot; was the Admin'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_CRb3gYmxpzA/Rqkue2BwQcI/AAAAAAAAAY4/va78fN5n7mM/s72-c/cmd.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-8338039500995878203</id><published>2007-07-26T09:57:00.000-07:00</published><updated>2007-07-26T09:59:02.126-07:00</updated><title type='text'>Funny.zip Trojan</title><content type='html'>This file comes as an attachment to a social engineering type of email.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RqjSoGBwQbI/AAAAAAAAAYw/lyvDksM5x94/s1600-h/funnyzip.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5091550964996915634" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RqjSoGBwQbI/AAAAAAAAAYw/lyvDksM5x94/s400/funnyzip.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-8338039500995878203?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/8338039500995878203/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=8338039500995878203&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8338039500995878203'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8338039500995878203'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/07/funnyzip-trojan.html' title='Funny.zip Trojan'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_CRb3gYmxpzA/RqjSoGBwQbI/AAAAAAAAAYw/lyvDksM5x94/s72-c/funnyzip.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-4413580551436812091</id><published>2007-07-23T16:12:00.000-07:00</published><updated>2007-07-23T16:14:11.457-07:00</updated><title type='text'>Exploit Server lists its malware</title><content type='html'>This malicious host has a nice little list of malware items that it lists in an "update.txt" file.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RqU2D2BwQaI/AAAAAAAAAYo/pq7zum81RD8/s1600-h/server+update.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5090534393482592674" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RqU2D2BwQaI/AAAAAAAAAYo/pq7zum81RD8/s400/server+update.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-4413580551436812091?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/4413580551436812091/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=4413580551436812091&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4413580551436812091'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4413580551436812091'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/07/exploit-server-lists-its-malware.html' title='Exploit Server lists its malware'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_CRb3gYmxpzA/RqU2D2BwQaI/AAAAAAAAAYo/pq7zum81RD8/s72-c/server+update.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-3660903901540922251</id><published>2007-07-23T15:22:00.001-07:00</published><updated>2007-07-23T15:25:00.144-07:00</updated><title type='text'>Web exploit</title><content type='html'>Internet Explorer didn't like visiting that website ;-)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RqUqQGBwQZI/AAAAAAAAAYg/1pbn36NiUAQ/s1600-h/IEcrash.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5090521409796456850" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RqUqQGBwQZI/AAAAAAAAAYg/1pbn36NiUAQ/s400/IEcrash.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-3660903901540922251?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/3660903901540922251/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=3660903901540922251&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/3660903901540922251'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/3660903901540922251'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/07/web-exploit.html' title='Web exploit'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/RqUqQGBwQZI/AAAAAAAAAYg/1pbn36NiUAQ/s72-c/IEcrash.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-8077415459959804819</id><published>2007-07-19T14:58:00.000-07:00</published><updated>2007-07-19T15:03:00.424-07:00</updated><title type='text'>Privacy Protector Gallery</title><content type='html'>Stumbled upon a fake codec... and it displayed all these lovely screens on my PC.&lt;br /&gt;This is hilarious.... trying to push a rogue product with, I must say, really nice graphics (do these people hire an art director???)&lt;br /&gt;&lt;br /&gt;Click on the picture to enlarge and have a good laugh (remember though that this is a big scam and a lot of people fall for it).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/Rp_eyi9NWkI/AAAAAAAAAYI/Nk0BP6RRrdA/s1600-h/04.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5089031063910308418" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/Rp_eyi9NWkI/AAAAAAAAAYI/Nk0BP6RRrdA/s400/04.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/Rp_e1S9NWlI/AAAAAAAAAYQ/79gQyoKgzkI/s1600-h/05.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5089031111154948690" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/Rp_e1S9NWlI/AAAAAAAAAYQ/79gQyoKgzkI/s400/05.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt; &lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/Rp_e4C9NWmI/AAAAAAAAAYY/zQt0TGuRUM8/s1600-h/06.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5089031158399588962" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/Rp_e4C9NWmI/AAAAAAAAAYY/zQt0TGuRUM8/s400/06.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/Rp_evi9NWjI/AAAAAAAAAYA/PlzOs5AhElw/s1600-h/03.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5089031012370700850" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/Rp_evi9NWjI/AAAAAAAAAYA/PlzOs5AhElw/s400/03.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/Rp_esi9NWiI/AAAAAAAAAX4/DWkPW_DKpLM/s1600-h/02.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5089030960831093282" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/Rp_esi9NWiI/AAAAAAAAAX4/DWkPW_DKpLM/s400/02.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/Rp_epS9NWhI/AAAAAAAAAXw/wRAOpHPfBpw/s1600-h/01.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5089030904996518418" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/Rp_epS9NWhI/AAAAAAAAAXw/wRAOpHPfBpw/s400/01.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-8077415459959804819?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/8077415459959804819/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=8077415459959804819&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8077415459959804819'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8077415459959804819'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/07/privacy-protector-gallery.html' title='Privacy Protector Gallery'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/Rp_eyi9NWkI/AAAAAAAAAYI/Nk0BP6RRrdA/s72-c/04.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-5076518210030308316</id><published>2007-07-18T11:25:00.000-07:00</published><updated>2007-07-18T11:35:14.461-07:00</updated><title type='text'>Fake greeting cards identified on several different domains</title><content type='html'>I keep receiving emails daily about a supposed Greeting Card waiting for me. Of course no one would send me a card on the email address I made up. So, it is by nature very suspicious.&lt;br /&gt;&lt;div&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;I have started collecting the IPs where the malware is hosted and I realize it is on several networks across the US.&lt;/div&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/Rp5dWC9NWgI/AAAAAAAAAXo/9XaKkxGxQk0/s1600-h/ecardd.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5088607262307342850" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/Rp5dWC9NWgI/AAAAAAAAAXo/9XaKkxGxQk0/s400/ecardd.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/Rp5dLC9NWfI/AAAAAAAAAXg/LJtwATsGeWY/s1600-h/ecardd.png"&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;p&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/Rp5cjy9NWeI/AAAAAAAAAXY/fkD6J4_sIrM/s1600-h/ecardd.png"&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div&gt; &lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-5076518210030308316?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/5076518210030308316/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=5076518210030308316&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5076518210030308316'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5076518210030308316'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/07/fake-greeting-cards-identified-on.html' title='Fake greeting cards identified on several different domains'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/Rp5dWC9NWgI/AAAAAAAAAXo/9XaKkxGxQk0/s72-c/ecardd.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-2055752832675791531</id><published>2007-07-12T13:27:00.001-07:00</published><updated>2007-07-12T13:28:56.700-07:00</updated><title type='text'>Yahoo! Mail protects you from dangerous links</title><content type='html'>Another instance of the fake ecard....&lt;br /&gt;But interesting thing, Yahoo! Mail warns me beforing visiting the bad site.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RpaOzy9NWYI/AAAAAAAAAWg/jbew4xsQsNM/s1600-h/yahoowarning.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5086409849664526722" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RpaOzy9NWYI/AAAAAAAAAWg/jbew4xsQsNM/s400/yahoowarning.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-2055752832675791531?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/2055752832675791531/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=2055752832675791531&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2055752832675791531'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2055752832675791531'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/07/yahoo-mail-protects-you-from-dangerous.html' title='Yahoo! Mail protects you from dangerous links'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/RpaOzy9NWYI/AAAAAAAAAWg/jbew4xsQsNM/s72-c/yahoowarning.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-8779320666750959230</id><published>2007-07-12T12:10:00.000-07:00</published><updated>2007-07-12T12:20:28.734-07:00</updated><title type='text'>The porn connection</title><content type='html'>&lt;div&gt;That's a funny one... I had a fake email address subscribed to a porn newsletter...&lt;br /&gt;I decided to go back to being a good boy and unsubscribed...&lt;br /&gt;Well, first thing I see is a big promotion for a privacy software to delete all my porn pictures. Ah, everything is good to make money these days... (sigh)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RpZ9di9NWWI/AAAAAAAAAWQ/N5aIaSFxSrE/s1600-h/porn1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5086390775714765154" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RpZ9di9NWWI/AAAAAAAAAWQ/N5aIaSFxSrE/s400/porn1.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RpZ9ay9NWVI/AAAAAAAAAWI/pGj0SkCB6U0/s1600-h/porn2.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5086390728470124882" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RpZ9ay9NWVI/AAAAAAAAAWI/pGj0SkCB6U0/s400/porn2.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RpZ9XS9NWUI/AAAAAAAAAWA/QGzqcNgKrtc/s1600-h/porn3.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5086390668340582722" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RpZ9XS9NWUI/AAAAAAAAAWA/QGzqcNgKrtc/s400/porn3.png" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RpZ-yi9NWXI/AAAAAAAAAWY/HMwHj8bWBBk/s1600-h/privacy.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5086392236003645810" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RpZ-yi9NWXI/AAAAAAAAAWY/HMwHj8bWBBk/s400/privacy.png" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;$79.95!!!!??? Wow&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;I think I'll pass on that offer.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-8779320666750959230?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/8779320666750959230/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=8779320666750959230&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8779320666750959230'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8779320666750959230'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/07/porn-connection.html' title='The porn connection'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/RpZ9di9NWWI/AAAAAAAAAWQ/N5aIaSFxSrE/s72-c/porn1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-7431394384782709891</id><published>2007-07-12T10:43:00.000-07:00</published><updated>2007-07-12T10:46:27.572-07:00</updated><title type='text'>Malware creates service using VMware name</title><content type='html'>&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RpZoii9NWTI/AAAAAAAAAV4/aabFBNfxvy8/s1600-h/vmwareservice.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5086367771869927730" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RpZoii9NWTI/AAAAAAAAAV4/aabFBNfxvy8/s400/vmwareservice.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Filename: 1.exe&lt;br /&gt;&lt;br /&gt;It copies itself to the Windows folder under the name vmware (no extension). It also creates a service.&lt;br /&gt;Upon execution the file melts.&lt;br /&gt;&lt;br /&gt;Detected as BackDoor Hupigon...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-7431394384782709891?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/7431394384782709891/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=7431394384782709891&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/7431394384782709891'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/7431394384782709891'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/07/malware-creates-service-using-vmware.html' title='Malware creates service using VMware name'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/RpZoii9NWTI/AAAAAAAAAV4/aabFBNfxvy8/s72-c/vmwareservice.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-7539544468486499198</id><published>2007-07-11T16:43:00.000-07:00</published><updated>2007-07-11T16:44:30.746-07:00</updated><title type='text'>Fake postcard links to malware</title><content type='html'>Another spam email that lures you... The link is bad, of course.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RpVrFoBnVII/AAAAAAAAAVw/-XVKjtHRdq8/s1600-h/fake+postcard.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5086089098572551298" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RpVrFoBnVII/AAAAAAAAAVw/-XVKjtHRdq8/s400/fake+postcard.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-7539544468486499198?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/7539544468486499198/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=7539544468486499198&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/7539544468486499198'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/7539544468486499198'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/07/fake-postcard-links-to-malware.html' title='Fake postcard links to malware'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/RpVrFoBnVII/AAAAAAAAAVw/-XVKjtHRdq8/s72-c/fake+postcard.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-4709727221870712331</id><published>2007-07-10T09:26:00.000-07:00</published><updated>2007-07-10T09:28:41.084-07:00</updated><title type='text'>Spammers use Acrobat Reader to circumvent spam blockers</title><content type='html'>I get lots of spam lately coming in the form of a PDF attached to the email. Let's not get fooled... it's just as bad and annoying.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RpOzYIBnVHI/AAAAAAAAAVo/sTfRRLLWLvk/s1600-h/spam1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5085605631283909746" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RpOzYIBnVHI/AAAAAAAAAVo/sTfRRLLWLvk/s400/spam1.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RpOzVIBnVGI/AAAAAAAAAVg/lY__rO0YACc/s1600-h/spam2.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5085605579744302178" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RpOzVIBnVGI/AAAAAAAAAVg/lY__rO0YACc/s400/spam2.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-4709727221870712331?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/4709727221870712331/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=4709727221870712331&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4709727221870712331'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4709727221870712331'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/07/spammers-use-acrobat-reader-to.html' title='Spammers use Acrobat Reader to circumvent spam blockers'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/RpOzYIBnVHI/AAAAAAAAAVo/sTfRRLLWLvk/s72-c/spam1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-7198252825331200977</id><published>2007-07-09T11:08:00.001-07:00</published><updated>2007-07-09T11:09:57.529-07:00</updated><title type='text'>Fake Worm alert pushes malware</title><content type='html'>&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RpJ5o4BnVFI/AAAAAAAAAVY/EQUGVonlGqE/s1600-h/wormalert.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5085260672395596882" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RpJ5o4BnVFI/AAAAAAAAAVY/EQUGVonlGqE/s400/wormalert.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RpJ5lIBnVEI/AAAAAAAAAVQ/qAEzz9doK20/s1600-h/attack.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5085260607971087426" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RpJ5lIBnVEI/AAAAAAAAAVQ/qAEzz9doK20/s400/attack.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-7198252825331200977?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/7198252825331200977/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=7198252825331200977&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/7198252825331200977'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/7198252825331200977'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/07/faker-worm-alert-pushes-malware.html' title='Fake Worm alert pushes malware'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_CRb3gYmxpzA/RpJ5o4BnVFI/AAAAAAAAAVY/EQUGVonlGqE/s72-c/wormalert.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-674023578720230766</id><published>2007-07-04T09:54:00.001-07:00</published><updated>2007-07-04T09:58:07.951-07:00</updated><title type='text'>Exploit iframe example</title><content type='html'>How a malicious ifrane is inserted into a legit webpage source code and infects your computer:&lt;br /&gt;&lt;br /&gt;Click on the images to enlarge&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RovQ6IBnVDI/AAAAAAAAAVI/UM5qCAk3nJk/s1600-h/library.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5083386301422982194" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RovQ6IBnVDI/AAAAAAAAAVI/UM5qCAk3nJk/s400/library.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RovQ24BnVCI/AAAAAAAAAVA/mKX_trV9avM/s1600-h/chinesewebsite.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5083386245588407330" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RovQ24BnVCI/AAAAAAAAAVA/mKX_trV9avM/s400/chinesewebsite.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RovQx4BnVBI/AAAAAAAAAU4/zRrtOku9KH4/s1600-h/fiddler.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5083386159689061394" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RovQx4BnVBI/AAAAAAAAAU4/zRrtOku9KH4/s400/fiddler.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-674023578720230766?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/674023578720230766/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=674023578720230766&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/674023578720230766'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/674023578720230766'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/07/exploit.html' title='Exploit iframe example'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/RovQ6IBnVDI/AAAAAAAAAVI/UM5qCAk3nJk/s72-c/library.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-415555751926798174</id><published>2007-07-03T14:49:00.001-07:00</published><updated>2007-07-03T14:51:43.677-07:00</updated><title type='text'>Fake MSN Messenger window</title><content type='html'>&lt;div&gt;Don't get fooled by those fake MSN Messenger windows that are part of a website... They tease you in order for you to click on them.... But they are just a redirection to another page... that can contain malicious content...&lt;/div&gt;&lt;div&gt;Social engineering again, and always...&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RorEfIBnVAI/AAAAAAAAAUw/2-V-vpSeXf0/s1600-h/msninside.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5083091168450270210" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RorEfIBnVAI/AAAAAAAAAUw/2-V-vpSeXf0/s400/msninside.png" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-415555751926798174?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/415555751926798174/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=415555751926798174&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/415555751926798174'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/415555751926798174'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/07/fake-msn-messenger-window.html' title='Fake MSN Messenger window'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/RorEfIBnVAI/AAAAAAAAAUw/2-V-vpSeXf0/s72-c/msninside.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-7625232479656230274</id><published>2007-06-14T14:10:00.000-07:00</published><updated>2007-06-14T14:20:52.998-07:00</updated><title type='text'>Pops media toolbar comes bundled with DriveCleaner</title><content type='html'>When installing DriveCleaner, a rogue anti-spyware application, you get prompted for the PopsMedia toolbar install.&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RnGwq6kG8uI/AAAAAAAAAUY/YO_5c539EFY/s1600-h/popsmedia3.png"&gt;&lt;/a&gt;This toolbar sits above your taskbar and harbours the DriveCleaner logo.&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RnGwRKkG8tI/AAAAAAAAAUQ/-DjkJOglSCs/s1600-h/popsmedia.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5076032063963329234" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RnGwRKkG8tI/AAAAAAAAAUQ/-DjkJOglSCs/s400/popsmedia.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RnGw1akG8vI/AAAAAAAAAUg/OsxAc1C7BBQ/s1600-h/popsmedia3.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5076032686733587186" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RnGw1akG8vI/AAAAAAAAAUg/OsxAc1C7BBQ/s400/popsmedia3.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-7625232479656230274?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/7625232479656230274/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=7625232479656230274&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/7625232479656230274'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/7625232479656230274'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/06/pops-media-toolbar-comes-bundled-with.html' title='Pops media toolbar comes bundled with DriveCleaner'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/RnGwRKkG8tI/AAAAAAAAAUQ/-DjkJOglSCs/s72-c/popsmedia.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-2757654489813989638</id><published>2007-06-08T14:21:00.000-07:00</published><updated>2007-06-08T14:36:13.401-07:00</updated><title type='text'>Malware borrows Kaspersky's icon</title><content type='html'>This piece of malware uses the famous Kaspersky Antivirus's icon to disguise itself. VirusTotal scan follows. It doesn't seem to be very known at all. If you PM me,  I can send you a sample.&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RmnIoKkG8rI/AAAAAAAAAUA/fELfa8vGbAc/s1600-h/k.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5073807047565701810" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RmnIoKkG8rI/AAAAAAAAAUA/fELfa8vGbAc/s400/k.png" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RmnK0qkG8sI/AAAAAAAAAUI/sVevpaf3uZM/s1600-h/vt.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5073809461337322178" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RmnK0qkG8sI/AAAAAAAAAUI/sVevpaf3uZM/s400/vt.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-2757654489813989638?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/2757654489813989638/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=2757654489813989638&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2757654489813989638'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2757654489813989638'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/06/malware-borrows-kasperskys-icon.html' title='Malware borrows Kaspersky&apos;s icon'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/RmnIoKkG8rI/AAAAAAAAAUA/fELfa8vGbAc/s72-c/k.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-2150074989042025894</id><published>2007-06-07T17:51:00.000-07:00</published><updated>2007-06-08T11:12:22.692-07:00</updated><title type='text'>Porn madness</title><content type='html'>A video explains things a lot better ;-)&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="350"&gt;&lt;param name="movie" value="http://www.youtube.com/v/7cptpThOWHw"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/7cptpThOWHw" type="application/x-shockwave-flash" width="425" height="350"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-2150074989042025894?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/2150074989042025894/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=2150074989042025894&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2150074989042025894'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2150074989042025894'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/06/porn-madness.html' title='Porn madness'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-1229281317191885610</id><published>2007-06-07T17:12:00.000-07:00</published><updated>2007-06-25T09:36:40.475-07:00</updated><title type='text'>Trojan downloads a spectacular amount of porn pics</title><content type='html'>&lt;div&gt;It started with a nasty Trojan that I monitor using Process Explorer. No IE window is open but the network traffic seems to be on the high... even the CPU is chugging.  The Trojan checks for the following domain at regular intervals, which is hosted by ESTDOMAINS.&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/Rn_u5KkG8wI/AAAAAAAAAUo/CFaNlnEeaf0/s1600-h/ESTdomains.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5080041570552967938" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/Rn_u5KkG8wI/AAAAAAAAAUo/CFaNlnEeaf0/s400/ESTdomains.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RmifoqkG8lI/AAAAAAAAATQ/GAp1oaQqr9o/s1600-h/pe.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5073480501202186834" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RmifoqkG8lI/AAAAAAAAATQ/GAp1oaQqr9o/s400/pe.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RmigfqkG8mI/AAAAAAAAATY/rRRnbJzHHIg/s1600-h/cpu.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5073481446094991970" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RmigfqkG8mI/AAAAAAAAATY/rRRnbJzHHIg/s400/cpu.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RmihOqkG8nI/AAAAAAAAATg/ClKsyRJvF-k/s1600-h/traffic.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5073482253548843634" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RmihOqkG8nI/AAAAAAAAATg/ClKsyRJvF-k/s400/traffic.png" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RmifJKkG8iI/AAAAAAAAAS4/FGw2ESRNwuQ/s1600-h/sites01.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5073479960036307490" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RmifJKkG8iI/AAAAAAAAAS4/FGw2ESRNwuQ/s400/sites01.png" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RmifOKkG8kI/AAAAAAAAATI/yLGIG-xGBoU/s1600-h/sites03.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5073480045935653442" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RmifOKkG8kI/AAAAAAAAATI/yLGIG-xGBoU/s400/sites03.png" border="0" /&gt;&lt;/a&gt; &lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RmifLqkG8jI/AAAAAAAAATA/ReLERYbotXk/s1600-h/sites02.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5073480002985980466" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RmifLqkG8jI/AAAAAAAAATA/ReLERYbotXk/s400/sites02.png" border="0" /&gt;&lt;/a&gt; &lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RmiheqkG8oI/AAAAAAAAATo/eajgk0l3OA4/s1600-h/sites04.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5073482528426750594" style="CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RmiheqkG8oI/AAAAAAAAATo/eajgk0l3OA4/s400/sites04.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RmihzKkG8pI/AAAAAAAAATw/KvEefi7OkAM/s1600-h/tempfiles.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5073482880614068882" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RmihzKkG8pI/AAAAAAAAATw/KvEefi7OkAM/s400/tempfiles.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RmiifakG8qI/AAAAAAAAAT4/7PMIy810qrc/s1600-h/bot.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5073483640823280290" style="CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RmiifakG8qI/AAAAAAAAAT4/7PMIy810qrc/s400/bot.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-1229281317191885610?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/1229281317191885610/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=1229281317191885610&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/1229281317191885610'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/1229281317191885610'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/06/trojan-downloads-spectacular-amount-of.html' title='Trojan downloads a spectacular amount of porn pics'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/Rn_u5KkG8wI/AAAAAAAAAUo/CFaNlnEeaf0/s72-c/ESTdomains.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-4062491534599597073</id><published>2007-06-01T11:46:00.000-07:00</published><updated>2007-06-01T18:41:44.593-07:00</updated><title type='text'>MSN Malware Spreading fast</title><content type='html'>This piece of malware spreads through MSN. One of your contacts will send you an IM, with a zip file, supposedly of photos...&lt;br /&gt;The file turns out to be a nasty piece of malware, not yet very detected by AV companies. Moreover, it won't run under Vmware... making it harder to analyze.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Screenshot of the Instant Message:&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RmBq5wUQV4I/AAAAAAAAASw/A6JFu1jQk-s/s1600-h/msn.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5071170720874125186" style="" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RmBq5wUQV4I/AAAAAAAAASw/A6JFu1jQk-s/s400/msn.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;The file has been packed with Themida and will not run in VM:&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RmBq1QUQV3I/AAAAAAAAASo/BZtzOJuthNY/s1600-h/photopic.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5071170643564713842" style="" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RmBq1QUQV3I/AAAAAAAAASo/BZtzOJuthNY/s400/photopic.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;A view with Filealyzer confirms the presence of Themida in the binary:&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RmBqcQUQV1I/AAAAAAAAASY/MSDxf4-E29o/s1600-h/filealyzer.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5071170214067984210" style="" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RmBqcQUQV1I/AAAAAAAAASY/MSDxf4-E29o/s400/filealyzer.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;A VirusTotal scan:&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RmBqqgUQV2I/AAAAAAAAASg/dm1TqEVjmAs/s1600-h/virustotal.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5071170458881120098" style="" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RmBqqgUQV2I/AAAAAAAAASg/dm1TqEVjmAs/s400/virustotal.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-4062491534599597073?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/4062491534599597073/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=4062491534599597073&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4062491534599597073'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4062491534599597073'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/06/msn-malware.html' title='MSN Malware Spreading fast'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/RmBq5wUQV4I/AAAAAAAAASw/A6JFu1jQk-s/s72-c/msn.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-466205154641878128</id><published>2007-05-29T11:16:00.000-07:00</published><updated>2007-05-29T11:17:03.639-07:00</updated><title type='text'>Same exploit won't work twice</title><content type='html'>&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/RlxuAbGJe5I/AAAAAAAAASI/ztDReDDflo4/s1600-h/useralreadyattacked.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5070048234064935826" style="CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/RlxuAbGJe5I/AAAAAAAAASI/ztDReDDflo4/s400/useralreadyattacked.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-466205154641878128?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/466205154641878128/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=466205154641878128&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/466205154641878128'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/466205154641878128'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/05/same-exploit-wont-work-twice.html' title='Same exploit won&apos;t work twice'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/RlxuAbGJe5I/AAAAAAAAASI/ztDReDDflo4/s72-c/useralreadyattacked.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-4827082691615732269</id><published>2007-05-28T16:34:00.001-07:00</published><updated>2007-05-28T16:47:52.587-07:00</updated><title type='text'>From Movie Codec to Rogue</title><content type='html'>It starts with a fake movie codec... that you may download from a porn site in order to watch a video... But what you don't know is that your machine is in danger from now on.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RltnEbGJe1I/AAAAAAAAARo/N52yekjwYbc/s1600-h/codec.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5069759131226307410" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RltnEbGJe1I/AAAAAAAAARo/N52yekjwYbc/s400/codec.png" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RltnEbGJe1I/AAAAAAAAARo/N52yekjwYbc/s1600-h/codec.png"&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Pop-ups "magically" appear... Funny enough, it's as if they know you have been naughty...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RltnV7GJe3I/AAAAAAAAAR4/bUI9w1z_k2k/s1600-h/pp02.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5069759431874018162" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RltnV7GJe3I/AAAAAAAAAR4/bUI9w1z_k2k/s400/pp02.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;And all of that for a rogue app. to cleanse the machine...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RltnQbGJe2I/AAAAAAAAARw/pAkY7VctdvI/s1600-h/pp01.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5069759337384737634" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RltnQbGJe2I/AAAAAAAAARw/pAkY7VctdvI/s400/pp01.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Of course, you must buy this software to remove those violations...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RltpM7GJe4I/AAAAAAAAASA/Y4I2Fa7LXrY/s1600-h/pp03.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5069761476278451074" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RltpM7GJe4I/AAAAAAAAASA/Y4I2Fa7LXrY/s400/pp03.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;It's a well oiled machine that seems to work :-S&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-4827082691615732269?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/4827082691615732269/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=4827082691615732269&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4827082691615732269'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4827082691615732269'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/05/from-movie-codec-to-rogue.html' title='From Movie Codec to Rogue'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/RltnEbGJe1I/AAAAAAAAARo/N52yekjwYbc/s72-c/codec.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-4066270440137606587</id><published>2007-05-24T11:06:00.000-07:00</published><updated>2007-05-24T12:35:31.477-07:00</updated><title type='text'>Bad Service...</title><content type='html'>At second glance, this ought to be bad...&lt;br /&gt;&lt;p&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RlXUJbGJe0I/AAAAAAAAARc/kdAOyVb8dAg/s1600-h/fakeservice.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5068190214032816962" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RlXUJbGJe0I/AAAAAAAAARc/kdAOyVb8dAg/s400/fakeservice.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-4066270440137606587?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/4066270440137606587/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=4066270440137606587&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4066270440137606587'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4066270440137606587'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/05/bad-service.html' title='Bad Service...'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/RlXUJbGJe0I/AAAAAAAAARc/kdAOyVb8dAg/s72-c/fakeservice.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-8442418606831723032</id><published>2007-05-08T09:13:00.000-07:00</published><updated>2007-05-08T09:17:21.089-07:00</updated><title type='text'>Media Codec Zlob Screenshots</title><content type='html'>That Trojan really tries to scare you... and they're good at it too. I can't help but laugh at it though ;-)&lt;br /&gt;Nice graphics as always... and a touch of humour.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RkCiKU2G0nI/AAAAAAAAAN4/6TQTpKnTxHU/s1600-h/worriedjohn.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5062224279442477682" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RkCiKU2G0nI/AAAAAAAAAN4/6TQTpKnTxHU/s400/worriedjohn.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RkCiG02G0mI/AAAAAAAAANw/IZGG1ZynBdI/s1600-h/winupdate.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5062224219312935522" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RkCiG02G0mI/AAAAAAAAANw/IZGG1ZynBdI/s400/winupdate.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RkCiCU2G0lI/AAAAAAAAANo/w4MRdgcRLQI/s1600-h/severe.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5062224142003524178" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RkCiCU2G0lI/AAAAAAAAANo/w4MRdgcRLQI/s400/severe.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RkCh6k2G0kI/AAAAAAAAANg/Ov_9r0lT8Aw/s1600-h/securitycenter.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5062224008859537986" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RkCh6k2G0kI/AAAAAAAAANg/Ov_9r0lT8Aw/s400/securitycenter.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-8442418606831723032?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/8442418606831723032/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=8442418606831723032&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8442418606831723032'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8442418606831723032'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/05/media-codec-zlob-screenshots.html' title='Media Codec Zlob Screenshots'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/RkCiKU2G0nI/AAAAAAAAAN4/6TQTpKnTxHU/s72-c/worriedjohn.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-1572501887891276873</id><published>2007-05-01T10:45:00.001-07:00</published><updated>2007-05-01T10:45:45.686-07:00</updated><title type='text'>DriveCleaner adds a toolbar</title><content type='html'>&lt;a href="http://bp0.blogger.com/_CRb3gYmxpzA/Rjd8xU2G0jI/AAAAAAAAANI/8RcvoPelcwU/s1600-h/drivecleanertoolbar.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5059649893225124402" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp0.blogger.com/_CRb3gYmxpzA/Rjd8xU2G0jI/AAAAAAAAANI/8RcvoPelcwU/s400/drivecleanertoolbar.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-1572501887891276873?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/1572501887891276873/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=1572501887891276873&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/1572501887891276873'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/1572501887891276873'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/05/drivecleaner-adds-toolbar.html' title='DriveCleaner adds a toolbar'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/Rjd8xU2G0jI/AAAAAAAAANI/8RcvoPelcwU/s72-c/drivecleanertoolbar.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-2103945455738637496</id><published>2007-04-23T15:03:00.000-07:00</published><updated>2007-04-23T15:05:51.265-07:00</updated><title type='text'>A friendly EULA</title><content type='html'>&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/Ri0tuuXZbxI/AAAAAAAAANA/87bjo5esQFo/s1600-h/eula.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5056748237350334226" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/Ri0tuuXZbxI/AAAAAAAAANA/87bjo5esQFo/s400/eula.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-2103945455738637496?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/2103945455738637496/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=2103945455738637496&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2103945455738637496'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2103945455738637496'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/04/friendly-eula.html' title='A friendly EULA'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_CRb3gYmxpzA/Ri0tuuXZbxI/AAAAAAAAANA/87bjo5esQFo/s72-c/eula.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-5624392591928427520</id><published>2007-04-17T15:18:00.001-07:00</published><updated>2007-04-17T16:18:22.783-07:00</updated><title type='text'>Just can't shutdown...</title><content type='html'>&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RiVRI0MheFI/AAAAAAAAAM4/rgLfln_zG5Y/s1600-h/permission.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5054535368685221970" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RiVRI0MheFI/AAAAAAAAAM4/rgLfln_zG5Y/s400/permission.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-5624392591928427520?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/5624392591928427520/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=5624392591928427520&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5624392591928427520'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5624392591928427520'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/04/just-cant-shutdown.html' title='Just can&apos;t shutdown...'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/RiVRI0MheFI/AAAAAAAAAM4/rgLfln_zG5Y/s72-c/permission.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-2618789213597192985</id><published>2007-04-17T15:18:00.000-07:00</published><updated>2007-04-17T15:21:30.364-07:00</updated><title type='text'>Trojan disables download from Firefox</title><content type='html'>&lt;strong&gt;The regular Firefox download page:&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://bp2.blogger.com/_CRb3gYmxpzA/RiVH2kMheDI/AAAAAAAAAMo/pP8AidJc5DM/s1600-h/firefoxnotbugged.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5054525159547959346" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp2.blogger.com/_CRb3gYmxpzA/RiVH2kMheDI/AAAAAAAAAMo/pP8AidJc5DM/s400/firefoxnotbugged.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;strong&gt;The corrupted Firefox download page (see how the link has been removed):&lt;/strong&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RiVH7UMheEI/AAAAAAAAAMw/3RTcfvauOlA/s1600-h/firefoxbugged.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5054525241152337986" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RiVH7UMheEI/AAAAAAAAAMw/3RTcfvauOlA/s400/firefoxbugged.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-2618789213597192985?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/2618789213597192985/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=2618789213597192985&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2618789213597192985'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/2618789213597192985'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/04/trojan-disables-download-from-firefox.html' title='Trojan disables download from Firefox'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_CRb3gYmxpzA/RiVH2kMheDI/AAAAAAAAAMo/pP8AidJc5DM/s72-c/firefoxnotbugged.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-465979098349996332</id><published>2007-04-12T14:35:00.000-07:00</published><updated>2007-04-12T14:36:06.888-07:00</updated><title type='text'>At least, they're polite ;-)</title><content type='html'>&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/Rh6mOEMheCI/AAAAAAAAAMc/_QC6TAMGioM/s1600-h/cheeky+vm+aware+malware.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5052658592530921506" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/Rh6mOEMheCI/AAAAAAAAAMc/_QC6TAMGioM/s400/cheeky+vm+aware+malware.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-465979098349996332?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/465979098349996332/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=465979098349996332&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/465979098349996332'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/465979098349996332'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/04/at-least-theyre-polite.html' title='At least, they&apos;re polite ;-)'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/Rh6mOEMheCI/AAAAAAAAAMc/_QC6TAMGioM/s72-c/cheeky+vm+aware+malware.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-3119493978794616326</id><published>2007-04-03T15:25:00.000-07:00</published><updated>2007-04-03T15:28:23.639-07:00</updated><title type='text'>ANI Exploit</title><content type='html'>A zero day exploit using the animated cursor... Here is a Javascript code that's at the source.&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/RhLU0P9RzmI/AAAAAAAAAMU/Hte4Q_1QK4U/s1600-h/ani.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5049332126337584738" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/RhLU0P9RzmI/AAAAAAAAAMU/Hte4Q_1QK4U/s400/ani.png" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-3119493978794616326?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/3119493978794616326/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=3119493978794616326&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/3119493978794616326'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/3119493978794616326'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/04/ani-exploit.html' title='ANI Exploit'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/RhLU0P9RzmI/AAAAAAAAAMU/Hte4Q_1QK4U/s72-c/ani.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-8416049634923284056</id><published>2007-03-30T10:12:00.000-07:00</published><updated>2007-03-30T10:19:15.366-07:00</updated><title type='text'>MSN Worm pushing exploits</title><content type='html'>There is a new worm being sent in spam emails... upon execution it will (amongst other things) send out a message to all your MSN contacts with a web link that leads to a Trojan.&lt;br /&gt;&lt;br /&gt;Do not open the attachment of course, and always double check before opening a link sent to you by one of your contacts.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp1.blogger.com/_CRb3gYmxpzA/Rg1GNf9RzlI/AAAAAAAAAMM/0uTH8hF1mY4/s1600-h/spam.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5047767955082956370" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_CRb3gYmxpzA/Rg1GNf9RzlI/AAAAAAAAAMM/0uTH8hF1mY4/s400/spam.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/Rg1FJ_9RzkI/AAAAAAAAAME/94LTr2OnoBc/s1600-h/msntrojan.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5047766795441786434" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/Rg1FJ_9RzkI/AAAAAAAAAME/94LTr2OnoBc/s400/msntrojan.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-8416049634923284056?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/8416049634923284056/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=8416049634923284056&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8416049634923284056'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/8416049634923284056'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/03/msn-worm-pushing-exploits.html' title='MSN Worm pushing exploits'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/Rg1GNf9RzlI/AAAAAAAAAMM/0uTH8hF1mY4/s72-c/spam.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-9019107425582505589</id><published>2007-03-22T13:46:00.000-07:00</published><updated>2007-03-22T13:50:50.582-07:00</updated><title type='text'>Trojan that corrupts the Windows license key</title><content type='html'>After running a file called fijnjkie.exe, I had the surprise to see that my Windows copy was not genuine. How nasty is that?!?&lt;br /&gt;&lt;p&gt;&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RgLrXzoIPSI/AAAAAAAAAL4/tq4phz8C_UQ/s1600-h/genuine.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5044853326836415778" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RgLrXzoIPSI/AAAAAAAAAL4/tq4phz8C_UQ/s400/genuine.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-9019107425582505589?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/9019107425582505589/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=9019107425582505589&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/9019107425582505589'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/9019107425582505589'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/03/trojan-that-corrupts-windows-license.html' title='Trojan that corrupts the Windows license key'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/RgLrXzoIPSI/AAAAAAAAAL4/tq4phz8C_UQ/s72-c/genuine.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-5586083044401621534</id><published>2007-03-20T13:21:00.000-07:00</published><updated>2007-03-20T14:00:15.900-07:00</updated><title type='text'>"Windows system servise" "Microsoft Corparation"</title><content type='html'>&lt;a href="http://bp3.blogger.com/_CRb3gYmxpzA/RgBCmToIPJI/AAAAAAAAAKw/VL5lUaRRP1I/s1600-h/windowservise.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5044104808526003346" style="CURSOR: hand" alt="" src="http://bp3.blogger.com/_CRb3gYmxpzA/RgBCmToIPJI/AAAAAAAAAKw/VL5lUaRRP1I/s400/windowservise.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;Check out the spelling... makes you wonder if its a legit one? ;-)&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-5586083044401621534?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/5586083044401621534/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=5586083044401621534&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5586083044401621534'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5586083044401621534'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/03/windows-system-servise.html' title='&quot;Windows system servise&quot; &quot;Microsoft Corparation&quot;'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/RgBCmToIPJI/AAAAAAAAAKw/VL5lUaRRP1I/s72-c/windowservise.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-9112680778101292944</id><published>2007-03-09T15:31:00.000-08:00</published><updated>2007-03-09T15:33:15.688-08:00</updated><title type='text'>Mirar Toolbar "INSTALL COMPLEATE", COMPLEATE??</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_CRb3gYmxpzA/RfHuleWFpMI/AAAAAAAAAKE/4cUDhJ088uY/s1600-h/mirar.png"&gt;&lt;img style="cursor: pointer;" src="http://bp1.blogger.com/_CRb3gYmxpzA/RfHuleWFpMI/AAAAAAAAAKE/4cUDhJ088uY/s400/mirar.png" alt="" id="BLOGGER_PHOTO_ID_5040071785572574402" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-9112680778101292944?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/9112680778101292944/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=9112680778101292944&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/9112680778101292944'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/9112680778101292944'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/03/mirar-toolbar-install-compleate.html' title='Mirar Toolbar &quot;INSTALL COMPLEATE&quot;, COMPLEATE??'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_CRb3gYmxpzA/RfHuleWFpMI/AAAAAAAAAKE/4cUDhJ088uY/s72-c/mirar.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-7572187724973858854</id><published>2007-02-26T13:52:00.000-08:00</published><updated>2007-02-26T13:57:07.671-08:00</updated><title type='text'>You know when it's been hacked</title><content type='html'>Whoever hacked my machine, made a spelling mistake... or maybe couldn't duplicate the original Admin account... Cheap...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_CRb3gYmxpzA/ReNXQ3c7weI/AAAAAAAAAJ0/OnPbqnfCV6o/s1600-h/winlogonhack.png"&gt;&lt;img style="cursor: pointer;" src="http://bp3.blogger.com/_CRb3gYmxpzA/ReNXQ3c7weI/AAAAAAAAAJ0/OnPbqnfCV6o/s400/winlogonhack.png" alt="" id="BLOGGER_PHOTO_ID_5035964755605176802" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-7572187724973858854?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/7572187724973858854/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=7572187724973858854&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/7572187724973858854'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/7572187724973858854'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/02/you-know-when-its-been-hacked.html' title='You know when it&apos;s been hacked'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/ReNXQ3c7weI/AAAAAAAAAJ0/OnPbqnfCV6o/s72-c/winlogonhack.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-5007368708201765117</id><published>2007-02-22T14:43:00.000-08:00</published><updated>2007-02-22T14:45:37.165-08:00</updated><title type='text'>PrivacyProtector: DriveCleaner Variant</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_CRb3gYmxpzA/Rd4cscZZsUI/AAAAAAAAAJc/nXx_4lUewYo/s1600-h/privacyprotector.png"&gt;&lt;img style="cursor: pointer;" src="http://bp2.blogger.com/_CRb3gYmxpzA/Rd4cscZZsUI/AAAAAAAAAJc/nXx_4lUewYo/s400/privacyprotector.png" alt="" id="BLOGGER_PHOTO_ID_5034492983309349186" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_CRb3gYmxpzA/Rd4cwcZZsVI/AAAAAAAAAJk/yHI8k28Y1Cs/s1600-h/DriveCleaner2006.png"&gt;&lt;img style="cursor: pointer;" src="http://bp2.blogger.com/_CRb3gYmxpzA/Rd4cwcZZsVI/AAAAAAAAAJk/yHI8k28Y1Cs/s400/DriveCleaner2006.png" alt="" id="BLOGGER_PHOTO_ID_5034493052028825938" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Obviously, you can stay away from those.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-5007368708201765117?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/5007368708201765117/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=5007368708201765117&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5007368708201765117'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/5007368708201765117'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/02/drivecleaner-variant.html' title='PrivacyProtector: DriveCleaner Variant'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_CRb3gYmxpzA/Rd4cscZZsUI/AAAAAAAAAJc/nXx_4lUewYo/s72-c/privacyprotector.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-428432858818821594</id><published>2007-02-16T14:43:00.000-08:00</published><updated>2007-02-16T14:44:55.879-08:00</updated><title type='text'>A trusted dialer??</title><content type='html'>Looks a little suspicious after reading the text...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_CRb3gYmxpzA/RdYzv8ZZsTI/AAAAAAAAAJQ/D3FkHqDDX6I/s1600-h/dialerssigned.PNG"&gt;&lt;img style="cursor: pointer;" src="http://bp0.blogger.com/_CRb3gYmxpzA/RdYzv8ZZsTI/AAAAAAAAAJQ/D3FkHqDDX6I/s400/dialerssigned.PNG" alt="" id="BLOGGER_PHOTO_ID_5032266532392644914" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-428432858818821594?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/428432858818821594/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=428432858818821594&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/428432858818821594'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/428432858818821594'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/02/trusted-dialer.html' title='A trusted dialer??'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_CRb3gYmxpzA/RdYzv8ZZsTI/AAAAAAAAAJQ/D3FkHqDDX6I/s72-c/dialerssigned.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36446935.post-4560701225648459086</id><published>2007-02-09T09:37:00.000-08:00</published><updated>2007-02-08T16:11:48.984-08:00</updated><title type='text'>New rogue... SpyCrush</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_CRb3gYmxpzA/RcyxiMZZsSI/AAAAAAAAAJE/XrnpIVssfWc/s1600-h/spycrush.png"&gt;&lt;img style="cursor: pointer;" src="http://bp3.blogger.com/_CRb3gYmxpzA/RcyxiMZZsSI/AAAAAAAAAJE/XrnpIVssfWc/s400/spycrush.png" alt="" id="BLOGGER_PHOTO_ID_5029590084867436834" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36446935-4560701225648459086?l=spywarebox.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarebox.blogspot.com/feeds/4560701225648459086/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36446935&amp;postID=4560701225648459086&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4560701225648459086'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36446935/posts/default/4560701225648459086'/><link rel='alternate' type='text/html' href='http://spywarebox.blogspot.com/2007/02/new-rogue-spycrush.html' title='New rogue... SpyCrush'/><author><name>spywarebox</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_CRb3gYmxpzA/RcyxiMZZsSI/AAAAAAAAAJE/XrnpIVssfWc/s72-c/spycrush.png' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
