Skip to main content

Adware posing as a private network client secretly takes screenshots

Adware stuffed into software you can freely download from the internet can secretly take screenshots of your desktop among other sneaky spyware-like capabilities. Dubbed as Zacinlo by Bitdefender, the adware first surfaced in 2012 and mostly targets Windows 10 PCs in North America. The adware was in its most “active” state at the beginning of 2018 since it emerged six years ago. 

Software you can download and use for free sometimes present free secondary software options during installation that you can use or decline. This secondary software is typically bundled to appease “sponsors” supposedly backing the free program you set out to download and install. Although free software can be good for your wallet, bundled software presented during installation could prove catastrophic.  

In this case, the adware poses as a free anonymous virtual private network (VPN) client called s5Mark you can install alongside the original software you intended to use. This VPN client provides a simple easy-to-read interface designed for non-technical web surfers. 

But that client is just a decoy. When the Windows 10 device owner runs the fake VPN client for the first time, it downloads the actual adware components along with a rootkit: Malware that resides at the root of your PC before loading Windows 10. There is also another component called an “updater” that receives instructions and makes updates to the adware and rootkit when needed. 

During installation, the adware will temporarily disable Windows Defender. It can also detect and temporarily disable antivirus solutions from 13 different providers including Bitdefender, Kaspersky, Malwarebytes, Panda, Symantec, and more. The rootkit component is what scans the PC for an antivirus client in the initial installation stages and temporarily shuts them down so the remaining adware components download to the PC. 

The list of what Zacinlo can do is rather lengthy outside the screen capture component. It can stop processes in Windows 10 it deems as “dangerous” to its overall functionality. It can also inject custom JavaScript into secure HTTPS webpages visited by the device owner, re-direct web pages, send information about the desktop environment back to the hackers in charge of the campaign, uninstall and delete any Windows 10 service, and more. 

“We have identified at least 25 different components found in almost 2,500 distinct samples,” the security firm states. “While tracking the adware, we noticed some of the components were continuously updated with new functionalities, dropped altogether or integrated entirely in other components. This once again reinforces our initial assumption that the adware is still being developed as of the writing of this paper.” 

According to Bitdefender’s whitepaper, the winscr.exe component installed by the adware is what takes screenshots of your desktop. It can also send the hackers a list of the file locations of the applications that are set to run automatically when Windows starts and delete files used by processes and services. Other components in the adware’s payload include dataup.exe, regtool.exe, homepageoptimizer.exe, and more. 

The big red flag here is that despite infecting Windows-based PCs since 2012, the spyware won’t infest your PC unless you allow its installation. 

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
What to do if your Intel CPU keeps crashing
Pins on Core i9-12900K.

Despite being among the best processors you can buy, some high-end Intel CPUs have faced a wave of instability over the past few months. Intel is investigating the problem, but the company and its motherboard partners have already worked toward some temporary fixes to improve stability on high-end Intel CPUs -- even if it comes at a performance cost.

Before getting into the fixes, keep in mind that they are temporary. Intel will release a statement on the instability soon, likely with more direct guidance on what affected users should do. In addition, the scope of the problem isn't clear -- if you're not experiencing issues, you shouldn't have anything to worry about.
Who's affected

Read more
HP Envy deals: HP’s most popular laptop starts at $630
An HP Envy 17-inch laptop sits on an office desk.

HP is one of the best laptop brands in the laptop space, with a huge selection of laptops to pick from, including some of the best laptops on the market. More specifically, though, the HP lineup is probably at the top when it comes to versatile and relatively well-valued laptops. While there are quite a few variations and configurations of the HP Envy, we've gone ahead and put together the ones that we think will give you the most bang for your buck. That said, if you haven't found something you're specifically looking for, be sure to check out some of these other great laptop deals as well.
HP Envy x360 2-in-1 laptop 15Z-FH000 — $650, was $900

The HP Envy x360 convertible laptop is a great option for just about anyone, particularly anyone who enjoys the touchscreen functionality of a tablet. It’s well designed and super slim, making it a truly go-anywhere device. Despite its portability, it still has an immersive 15.6-inch touchscreen that’s great for creators, note-takers, and binge watchers. Top notch build quality and durability, fast charging technology, a fingerprint reader, and great battery life round out the top features of the HP Envy x360 convertible touchscreen laptop. It competes well with the best 2-in-1 laptops. Its versatility and all-around capability make it a worthy companion on any desk, and on any lap.

Read more
I use these simple printer tips to save money on ink and toner
Printing is fast and economical with the HP Smart Tank 7602.

The cost of a printer can range from under $100 for some good, low-cost inkjet printers to several hundred for the best color laser printers. However, the price you pay upfront doesn’t include paper, and the included ink and toner only lasts so long.

A bargain printer can end up costing you more overall if the cartridges are small and replacements are expensive. Follow these tips to minimize ink, toner, and paper waste, reducing the ongoing expense of using your printer in the long run.
Print in monochrome
Adobe Acrobat's print settings includes a grayscale option. Digital Trends

Read more