<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>KYRIAKOS ANASTASAKIS - ΚΥΡΙΑΚΟΣ ΑΝΑΣΤΑΣΑΚΗΣ &#187; spyware</title>
	<atom:link href="http://kyriakos.anastasakis.net/tag/spyware/feed/" rel="self" type="application/rss+xml" />
	<link>http://kyriakos.anastasakis.net</link>
	<description></description>
	<lastBuildDate>Wed, 14 Oct 2009 20:03:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Weird files (advertismen.com and pushowXX.dll)</title>
		<link>http://kyriakos.anastasakis.net/2006/04/17/weird-files-advertismencom-and-pushowxxdll/</link>
		<comments>http://kyriakos.anastasakis.net/2006/04/17/weird-files-advertismencom-and-pushowxxdll/#comments</comments>
		<pubDate>Mon, 17 Apr 2006 10:58:00 +0000</pubDate>
		<dc:creator>Kyriakos Anastasakis</dc:creator>
				<category><![CDATA[Personal]]></category>
		<category><![CDATA[spyware]]></category>

		<guid isPermaLink="false">http://kyriakos.anastasakis.net/blog/2006/04/17/weird-files-advertismencom-and-pushowxxdll/</guid>
		<description><![CDATA[Last night I found on a P2P network an exe file that was supposed to be a screensaver. Well&#8230;yes I did double click! It gave me a usual &#8220;do you want to proceed with the installation?&#8221; window and I said yes! Well&#8230; that was it! It finished the installation, but I could not find any [...]]]></description>
			<content:encoded><![CDATA[<p>Last night I found on a P2P network an exe file that was supposed to be a screensaver. Well&#8230;yes I did double click! It gave me a usual &#8220;do you want to proceed with the installation?&#8221; window and I said yes! Well&#8230; that was it! It finished the installation, but I could not find any new screen saver on the control panel or anywhere else. Weird isn&#8217;t it?</p>
<p>Now, I downloaded a trial version of Ashampoo Uninstaller platinum to see the changes the installation made to my system. I installed Ashampoo and run the &#8220;screensaver&#8221; installer again. This time I noticed that somewhere in the text of the terms and conditions a company named &#8220;ADVERTISMEN.COM&#8221; appeared. Tried to google it but wasn&#8217;t lucky. I also did a DSN lookup of the url and found out that the domain name was registered on the 5th of April of 2006. Is it a new spyware?</p>
<p>Well, after the installation was finished, Ashampoo generated a log file, which showed that the install.exe had installed two files in the windows/system32 folder. The files were called pushow67.dll and pushow55.dll. I used DLL Export Viewer to find out that they exposed one interface called &#8220;Uninstall&#8221;. It also created a registry key under: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ called &#8220;UninstallString&#8221; with value: rundll32.exe C:\WINNT\system32\pushow55.dll Uninstall</p>
<p>It also created another key under: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows called AppInit_DLLs. The value was pushow55.dll.</p>
<p>All this is weird! I deleted the files and the registry entries, run ad-aware and spybot and they didn&#8217;t find anything. Finally I logged to my online banking system (didn&#8217;t enter my real credentials though) running Etheral. After inspecting the packets I didn&#8217;t find anything alarming.</p>
<p>Well&#8230; I am not sure if it is a new spyware, Trojan or something, but I know I should have thought twice before running that bloody exe file. Now I just hope I have cleaned my system from whatever it was!</p>
]]></content:encoded>
			<wfw:commentRss>http://kyriakos.anastasakis.net/2006/04/17/weird-files-advertismencom-and-pushowxxdll/feed/</wfw:commentRss>
		<slash:comments>21</slash:comments>
		</item>
	</channel>
</rss>
