CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 949
Comments: 28
block bottom
spacer spacer

Spyslay: New Rogue?

 
Post new topic   Reply to topic       All -> FavForums -> Rogue Anti-Spyware [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
TeMerc

Captain
Captain
Premium Member

Joined: Apr 24, 2004
Posts: 557

MVP Premium

PostPosted: Fri Sep 21, 2007 3:00 am    Post subject: Spyslay: New Rogue?
Reply with quote

I just had a user join up with a link to spyslayDOTcom/anti-spyware.

As soon as you click the page, you get re-directed to a System Doctor download!! A well known rogue.

BAD news!

For those with SiteAdvisor reviewr status, please add your comments or mimic mine:
http://www.siteadvisor.com/sites/spyslay.com/

Google search for 'spyslay' brings up most of the forums this guy is spamming:
http://www.google.com/search?q=spyslay&rls=com.microsoft:en-us:IE-SearchBox&ie=UTF-8&oe=UTF-8&sourceid=ie7&rlz=1I7ADBS

From one:

Quote:
Posted by: genry-morgan Sep 20 2007, 03:23 AM
hello there!
i have got a online journal. i have recieved a lot of spam in my blog recently. could anyone tell me how to get antispam filter or something else to protect my blog? spamers send there much links. spamers are bothering me !
but i should say that once i got a advantage from them. they have sent me some links to someanti virus programme. so i decided to visit this site because my PC started to work slowly. i found there a proposition to download anti virus programme. after installing it, the program deleted all spyware from my computer!!! even such progams as Kaspersky and Nod32 could not find it!!!! i could not even think that there are so many spyware in my computer!!! you could click by one of this links. searching spyware on your PC is free!!! here are the link.
hxxp://www.spyslay.com/anti-spyware/
So that guys are not so useless, i think)))


hasta la vista
This one needs to go into the rogues gallery pronto.

Admins need to add spyslayDOTcom to ban filters

I've not done any research beyond a quick Google search, just spreading the word right now.


_________________
Ultimate Countermeasures Page
Malware Advisor Blog
Back to top
View users profile Send private message Visit posters website
TeMerc

Captain
Captain
Premium Member

Joined: Apr 24, 2004
Posts: 557

MVP Premium

PostPosted: Fri Sep 21, 2007 5:32 am    Post subject:
Reply with quote

From here:
http://www.bluetack.co.uk/forums/index.php?s=a0f50a8d071c7b831053221f2dea4d15&showtopic=17685&st=0&#entry83425

Quote:
I caught this guy on two of my forums and blocked him already.

"genry-morgan" (gooffy@spyslay.com) is coming from:

61.60.74.118 - GSN, Taiwan Government Service Network.:61.60.32.0-61.60.127.255
and
210.42.140.5 - Hubei Provincial Education Commission :210.42.140.0-210.42.141.255

Both ranges look like they belong in a couple of our lists, if not there already. ;]

My forums are now blocking:
61.60.74.*
210.42.140.*
210.42.141.*


_________________
Ultimate Countermeasures Page
Malware Advisor Blog
Back to top
View users profile Send private message Visit posters website
TeMerc

Captain
Captain
Premium Member

Joined: Apr 24, 2004
Posts: 557

MVP Premium

PostPosted: Fri Sep 21, 2007 3:28 pm    Post subject:
Reply with quote

Courtesy of nossirah:
http://spyslay.com/ reverse IP :

Quote:
A-bts.com
Cigbuy.com
Djdot.com
Elite-pokers.com
I-drugsstore.com
Iqxn.com
Mailkon.com
Medpil.com
Medpil.us
Medqx.com
Ocxz.com
Oczx.com
Oilby.com
On-line-med.com
Payqx.com
Pokerscards.com
Qxlb.com
Rixrx.com
Sensecasino.com
Spymurder.com <<<-- This page is winantivirus
Spyslay.com
Yoursmed.com


_________________
Ultimate Countermeasures Page
Malware Advisor Blog
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rogue Anti-Spyware All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer