Is it just me, or are they pushing rogues at download.com? hxxp://www.download.com/Anti-Spyware/3000-8022_4-10852406.html?tag=mncol&cdlPid=10852407
Virus Total analysis of installer
http://www.virustotal.com/analisis/e3498d5...9c28b794a77667b
Hmm, it is removed now. I will upload the installer setupxv.exe
redwolfe_98
Nov 8 2008, 12:01 AM
according to this article, yes, malware was being distributed through ads at "download.com":
http://malwaredatabase.net/blog/index.php/...ownloadcom-ads/
grinler
Nov 8 2008, 02:53 AM
Saw it yesterday. They were advertising XP Antispyware 2009 at the time.
This was not the ad. Google translated from danish language
http://translate.google.com/translate?u=ht...sl=da&tl=en
Raid
Nov 11 2008, 01:08 AM
I've been monitoring several urls for 0day samples of that particular named setupxv.exe file. I wonder if it's the same. Either of you still have it? If so, please attach it here.
STL
Nov 11 2008, 01:22 AM
"Upload failed. The file was larger than the available space".
I emailed it to Marcin right after my first post.
sho-dan
Nov 11 2008, 02:46 AM
Hello Dustin
I will pm you a site, where you can pickup the google ads for the setupxv.exe! you'll be very suprise.
STL
Nov 12 2008, 11:41 AM
bugmenot
Nov 15 2008, 04:22 PM
is malware bytes effective enough to remove the rogue programme antispyware 2009 or do i have to access the registry to remove it?