The info is here -- networks need to work harder to stop this and SOMEBODY needs to sue these guys!

for those curious. Civil Suit Filed It would appear there is some private litigation underway as detailed by this rather interesting blog connecting the outfit to "ByteHosting" and one Marc Cohen who is being What's up whit Dat? Millions of users have spyware installed on their machines because of this and it must be stopped.

Check out http://www.spywarewarrior.com, http://www.benedelman.org, and http://www.vitalsecurity.org (Paperghost, aka Chris Boyd) for more information. Look into the actionscript for certain patterns. Sample ad: Actual flash file: WorkHomeCenter SWF Sample Bad redirect: http://pcturbopro.com/.storage/index.php?p=5&ax=1&ex=1&ed=2&h=10&j=1&[...] Sample install: http://cdn.downloadcontrol.com/files/installers/cab/PCTurboProInstallerFree.cab Matchservice.com

Now The ULTIMATE Prevention::: Get hold of Deep Freeze from faraonics. All Rights Reserved. JUST IN CASE Ghost Tips: Do not use any compression when you make backups. Note, for all I know, some of the less reputable/well known companies below could very well be associated with Errorsafe.

Apparently it went over well since we are doing a "compressed" encore presentation at FaceTime Communications- via WebEx. I wish Joseph the best of luck as I am not found of people that create such software. Cheeseball81, Mar 25, 2006 #15 Sponsor This thread has been Locked and is not open to further replies. here Actionscripts I've posted are all still encrypted/obfuscated.

Director I/T Members 4,310 posts OFFLINE Local time:10:52 AM Posted 16 December 2005 - 03:44 PM Yes Use this link at the bottom of that posthttp://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe "Nothing could be finer Leave a comment here or drop me an email and I'll get you in contact with Joseph and maybe he'll be able to win at least one victory in the war Pressing any key will cause a "Blue Screen of Death" this is normal, do not worry! Victim: UFO Afterlight Sample creative: Actual flash file: UFO Afterlight SWF Actionscript: ufoafterlight.txt Victim:Shopathometv.com Sample creative: Actual flash file: ShopAtHomeTV SWF Actionscript: shopathome.txt Victim: Casino Ace King Sample creative: Actual flash

Puh-lease. https://www.bleepingcomputer.com/forums/t/37683/winfixer-and-virtumonde-problems/ When running, it can be found in the Task manager and stopped, but before long it will re-install and start up again. Thanks for posting! This is often called "partner sprawl", but there should be an I/O, there should be a paper trail…somewhere along the line someone has to be accountable.

elwedriddsche on 26 March, 2008 at 11:38 PM said: The information Setsune posted can be found by looking up public records, no insider knowledge required. get redirected here Not got an account? Reply sketchie Follow 0 followers 0 badges Offline 0 ReputationRep: Follow 15 27-04-2006 11:08 (Original post by AT82) ActiveX is just Microsoft technology though and nothing really do with the web. I have seen a lot of nasty things with obfuscated or encrypted Javascript in general- I can think of the World Cup Javascript Page Header Injection or the ancient Spazbox case,

On this page I will catalogue all instances of this scam that I have observed. Just click on the cross in the corner repeatedly and it will go away. Open the flash file with Action Script Viewer. http://realink.org/solved-winfixer/solved-winfixer-problem.html We want to know what you think of our new app!

Wayne currently works as a Security Consultant on Social Media and operates a consultancy on digital worlds. I have also been browsing EBay quite a bit lately. Bochner tried federal agencies and state task force officials.

Those turkeys had an entire scam ring going on if you noticed Moore's reply.

The examples he cites have been "decompiled" so I do not know for sure, but I note there is a subtle difference between obfuscation and encryption. I am speculating here, but I am guessing since MediaPlex (VCLK) leased their ad server technology- that leaves aQuantive in the mix as serving up an that made a call to I noted this at ReveNews after the discovery of the "scareware" being served up through Windows Live Messenger (previously known as MSN IM) and I commented on MSFT's negative eCPM…I have Below are snippets of relevant network data - the full logs are available for inspection and use by the appropriate authorities… and she goes on to make this editorial comment…

TheJynXeD on 28 March, 2008 at 7:02 PM said: Les, that Setsune is me Anyhow, it's been quite awhile since I last dealt with removing WinFixer. when trying to look at a profile I get an error "view error: Question `p_gender`: Function `print_radio($param_name, $value, $sources, $style, ‘ ‘);` doesn't exists, Session halted." Whois Registration: Administrative Contact: YouTube. http://realink.org/solved-winfixer/solved-winfixer-problem-fixed.html In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time: C:\Documents and Settings\All Users\Application Data\Mail Dupe 1 Tray C:\DOCUMENTS AND

Page updated, actionscript can be found here: canada.txt. Click Create and you're done. Thank you! If you want to get rid of the viruses you have to purchase the program except that the program doesn't actually remove the viruses because it's what put them there in

