Thursday, October 18, 2007

Skype, the new messenger spam vehicle.


Many of you are aware of the 'messenger' spam pop-ups that plague most machines prior to XP SP2. These types of pop-ups are commonly found on porn and warez related websites.

Unless you've been offline for the last several years, you're also probably aware of the Skype network. Skype allows users to instant message each other, make free or low cost VoIP calls, and host virtual meetings.

As with any popular service, the bad guys will target the users. This evening I received a messenger type spam as an instant message from another Skype user.

The message stated I was infected with malicious trojans, and I should visit http:// www. alertmonitor .org/?q=updatescan (spaces added to protect from accidental clicks) to remove the infection.

How could I resist? I visited the site from my Linux laptop. The image on the right is what I saw during the system scan this website performed for me. Lo and behold, I have three windows viruses on my system (see below). Which either means this software is fake, or its got piss poor detection. At last count BitDefender reported over 150,000 unique malicious files on my laptop.


Please use common sense and don't visit unsolicited links. Additionally, don't believe everything you read - the alertmonitor site is a scam.

Labels: ,

Wednesday, July 18, 2007

WinAntiSpyware2007

Many people are downloading this application after being duped by popup's that say the user is infected.
Once the application is downloaded, it runs a "spyware" scan which appears legitimate, however if you watch closely it flags things which don't actually exist. I ran this program on a new image of Windows XP Home . Before running the installer, this image had never been connected to the internet.


(DISOG Photo, Windows XP Home SP1)



This program doesn't appear to actually do anything malicious. Rather, it plays on the ignorance of users by confusing them into thinking they are infected.

For Spyware and Adware protection, we recommend Spybot S&D and LavaSoft's Ad-aware.

(b50add21bda401cc1d028241da0d6605) WinAntiVirusPro2007Install.exe infected: Trojan.Downloader.TY
Downloads: http://download.cdn. winsoftware.com/ files/WinAntiSpyware2007FreeSetup.exe (e0361f7ef2ea36257f9a894f8accb984)

Watch for connections to *.winsoftware.com. and *.winantispyware.com

PS, for those of you who still run as administrator.....

Labels: ,