<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AVG Blogs &#187; AVG Web Threat Update: Week 22</title>
	<atom:link href="http://blogs.avg.com/news-threats/avg-web-threat-update-week-22/feed/?withoutcomments=1" rel="self" type="application/rss+xml" />
	<link>http://blogs.avg.com</link>
	<description>AVG Blogs</description>
	<lastBuildDate>Fri, 24 May 2013 07:35:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>AVG Web Threat Update: Week 22</title>
		<link>http://blogs.avg.com/news-threats/avg-web-threat-update-week-22/</link>
		<comments>http://blogs.avg.com/news-threats/avg-web-threat-update-week-22/#comments</comments>
		<pubDate>Wed, 06 Jun 2012 10:52:46 +0000</pubDate>
		<dc:creator>TomK</dc:creator>
				<category><![CDATA[News & Threats]]></category>
		<category><![CDATA[AVG Threat Update]]></category>
		<category><![CDATA[digital security]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[latest news]]></category>
		<category><![CDATA[Latest threats]]></category>
		<category><![CDATA[scamming]]></category>
		<category><![CDATA[security awareness]]></category>
		<category><![CDATA[security news]]></category>

		<guid isPermaLink="false">http://blogs.avg.com/?p=13975</guid>
		<description><![CDATA[1.  “Canadian pharmacy” uses phony YouTube video to attract business The AVG Web Threats Research team this week found a “Canadian pharmacy” site that has loaded up YouTube with phony videos really intended to game search engine results and draw visitors to their site. &#160; A YouTube search for “nail technician schools in Houston” turns [...]]]></description>
			<content:encoded><![CDATA[<p><strong>1. </strong> <strong>“Canadian pharmacy” uses phony YouTube video to attract business</strong></p>
<p>The AVG Web Threats Research team this week found a “Canadian pharmacy” site that has loaded up YouTube with phony videos really intended to game search engine results and draw visitors to their site.</p>
<p>&nbsp;</p>
<p>A YouTube search for “nail technician schools in Houston” turns up three legitimate hits about schools, then a lot of other interesting results &#8212; each linking to pillsrx24.com. That domain was registered by someone in Moscow, Russia, who appears to live in a pleasant residential section near the Academy of Science botanical gardens in the northern suburbs (thanks Google street view.)</p>
<p>&nbsp;</p>
<p>Clicking out the first link presents 26 seconds of video from a Fox news piece on the Food and Drug Administration investigation of questionable eye lash conditioner, then a link to a “pharmacy” site where a visitor can allegedly purchase Lumigan, a drug used to treat glaucoma. The video was uploaded by someone using the name “GerardviWomack”.</p>
<p><a href="http://blogs.avg.com/wp-content/uploads/2012/06/image001.png"><img class="alignnone size-full wp-image-13991" title="image001" src="http://blogs.avg.com/wp-content/uploads/2012/06/image001.png" alt="" width="1168" height="855" /></a></p>
<p><a href="http://blogs.avg.com/wp-content/uploads/2012/06/image003.png"><img class="alignnone size-full wp-image-13992" title="image003" src="http://blogs.avg.com/wp-content/uploads/2012/06/image003.png" alt="" width="1045" height="791" /></a></p>
<p>&nbsp;</p>
<p>A Google search for Lumigan, interestingly enough, presents a link to Gerardvi’s/Fox News’ “Eyelash Wars” video.</p>
<p><a href="http://blogs.avg.com/wp-content/uploads/2012/06/image005.png"><img class="alignnone size-full wp-image-13993" title="image005" src="http://blogs.avg.com/wp-content/uploads/2012/06/image005.png" alt="" width="936" height="911" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Oh, and “GerardviWomack”? He posted 21 similar videos on YouTube last month:</p>
<p><a href="http://blogs.avg.com/wp-content/uploads/2012/06/image007.png"><img class="alignnone size-full wp-image-13994" title="image007" src="http://blogs.avg.com/wp-content/uploads/2012/06/image007.png" alt="" width="1049" height="789" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Web users, of course, should be aware of the dangers of purchasing drugs from questionable web sites which usually sell phony products or simply exist to steal credit card information. The YouTube videos demonstrate the elaborate lengths to which these untrustworthy operators will go to get their advertising in front of you.</p>
<p>&nbsp;</p>
<p><strong>2. Blackhole-linked ransom ware page under construction</strong></p>
<p>This would be funny if ransom ware wasn’t a miserable problem for those who get infected with it. Someone who is writing a ransom ware page that is installed by the Blackhole exploit kit has it “live” while he’s working on it. Notice the text that says “test.”</p>
<p><a href="http://blogs.avg.com/wp-content/uploads/2012/06/image009.png"><img class="alignnone size-full wp-image-13995" title="image009" src="http://blogs.avg.com/wp-content/uploads/2012/06/image009.png" alt="" width="987" height="550" /></a></p>
<p>&nbsp;</p>
<p><strong>Two days previous to that view was this:</strong></p>
<p><strong><a href="http://blogs.avg.com/wp-content/uploads/2012/06/image011.png"><img class="alignnone size-full wp-image-13996" title="image011" src="http://blogs.avg.com/wp-content/uploads/2012/06/image011.png" alt="" width="987" height="527" /></a><br />
</strong></p>
<p>&nbsp;</p>
<p><strong> </strong></p>
<p><strong>3. New Rogue GUIs</strong></p>
<p><strong> </strong></p>
<p>Below is a sampling of the graphic interface variants, many delivered by the Blackhole exploit kit that we’ve seen in the last week:</p>
<p>&nbsp;</p>
<p>Antivirus Protection 2012 rogue</p>
<p><img class="alignnone size-full wp-image-13997" title="image013" src="http://blogs.avg.com/wp-content/uploads/2012/06/image013.jpg" alt="" width="1168" height="837" /></p>
<p>&nbsp;</p>
<p><strong> </strong></p>
<p>Windows Antivirus Rampart rogue</p>
<p><a href="http://blogs.avg.com/wp-content/uploads/2012/06/image015.png"><img class="alignnone size-full wp-image-13998" title="image015" src="http://blogs.avg.com/wp-content/uploads/2012/06/image015.png" alt="" width="1168" height="855" /></a></p>
<p><strong> </strong></p>
<p>Windows Guard Tools rogue<strong></strong></p>
<p><a href="http://blogs.avg.com/wp-content/uploads/2012/06/image017.png"><img class="alignnone size-full wp-image-13999" title="image017" src="http://blogs.avg.com/wp-content/uploads/2012/06/image017.png" alt="" width="1168" height="855" /></a></p>
<p><strong> </strong></p>
<p>Windows Multi Control System rogue</p>
<p><a href="http://blogs.avg.com/wp-content/uploads/2012/06/image019.png"><img class="alignnone size-full wp-image-14000" title="image019" src="http://blogs.avg.com/wp-content/uploads/2012/06/image019.png" alt="" width="1168" height="855" /></a></p>
<p><strong> </strong></p>
<p>Windows Pro Safety rogue</p>
<p><a href="http://blogs.avg.com/wp-content/uploads/2012/06/image021.png"><img class="alignnone size-full wp-image-14001" title="image021" src="http://blogs.avg.com/wp-content/uploads/2012/06/image021.png" alt="" width="1168" height="855" /></a></p>
<p><strong> </strong></p>
<p>Windows Safety Maintenance rogue</p>
<p><a href="http://blogs.avg.com/wp-content/uploads/2012/06/image023.png"><img class="alignnone size-full wp-image-14002" title="image023" src="http://blogs.avg.com/wp-content/uploads/2012/06/image023.png" alt="" width="1168" height="855" /></a></p>
<p><strong> </strong></p>
<p>Windows Ultimate Security Patch rogue</p>
<p><strong> <a href="http://blogs.avg.com/wp-content/uploads/2012/06/image025.png"><img class="alignnone size-full wp-image-14003" title="image025" src="http://blogs.avg.com/wp-content/uploads/2012/06/image025.png" alt="" width="1168" height="855" /></a></strong></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&#8211; AVG Threat Research Group</p>
<p>&nbsp;</p>
<div class="nr-shortcode" style="float:left;width:100%;\">
<div class="nr_clear"></div>	
	<div id="nrelate_related_2" class="nrelate nrelate_related nrelate_ nr_ nr_120"></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_').removeClass('nrelate_');</script>
	<![endif]-->
	
	<script type="text/javascript">
	/* <![CDATA[ */
		
		var entity_decoded_nr_url = jQuery('<span/>').html("http://api.nrelate.com/rcw_wp/0.51.1/?tag=nrelate_related&keywords=AVG+Web+Threat+Update%3A+Week+22&domain=blogs.avg.com&url=http%3A%2F%2Fblogs.avg.com%2Fnews-threats%2Favg-web-threat-update-week-22%2F&nr_div_number=2").text();
		nRelate.getNrelatePosts(entity_decoded_nr_url);
	/* ]]&gt; */
	</script>
<div class="nr_clear"></div></div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_1" class="nrelate nrelate_related nrelate_ nr_ nr_120"></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_').removeClass('nrelate_');</script>
	<![endif]-->
	
	<script type="text/javascript">
	/* <![CDATA[ */
		nRelate.domain = "blogs.avg.com";
		var entity_decoded_nr_url = jQuery('<span/>').html("http://api.nrelate.com/rcw_wp/0.51.1/?tag=nrelate_related&keywords=AVG+Web+Threat+Update%3A+Week+22&domain=blogs.avg.com&url=http%3A%2F%2Fblogs.avg.com%2Fnews-threats%2Favg-web-threat-update-week-22%2F&nr_div_number=1").text();
		nRelate.getNrelatePosts(entity_decoded_nr_url);
	/* ]]&gt; */
	</script>
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://blogs.avg.com/news-threats/avg-web-threat-update-week-22/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
