Skip to main content

Adware posing as a private network client secretly takes screenshots

Adware stuffed into software you can freely download from the internet can secretly take screenshots of your desktop among other sneaky spyware-like capabilities. Dubbed as Zacinlo by Bitdefender, the adware first surfaced in 2012 and mostly targets Windows 10 PCs in North America. The adware was in its most “active” state at the beginning of 2018 since it emerged six years ago. 

Software you can download and use for free sometimes present free secondary software options during installation that you can use or decline. This secondary software is typically bundled to appease “sponsors” supposedly backing the free program you set out to download and install. Although free software can be good for your wallet, bundled software presented during installation could prove catastrophic.  

Recommended Videos

In this case, the adware poses as a free anonymous virtual private network (VPN) client called s5Mark you can install alongside the original software you intended to use. This VPN client provides a simple easy-to-read interface designed for non-technical web surfers. 

Please enable Javascript to view this content

But that client is just a decoy. When the Windows 10 device owner runs the fake VPN client for the first time, it downloads the actual adware components along with a rootkit: Malware that resides at the root of your PC before loading Windows 10. There is also another component called an “updater” that receives instructions and makes updates to the adware and rootkit when needed. 

During installation, the adware will temporarily disable Windows Defender. It can also detect and temporarily disable antivirus solutions from 13 different providers including Bitdefender, Kaspersky, Malwarebytes, Panda, Symantec, and more. The rootkit component is what scans the PC for an antivirus client in the initial installation stages and temporarily shuts them down so the remaining adware components download to the PC. 

The list of what Zacinlo can do is rather lengthy outside the screen capture component. It can stop processes in Windows 10 it deems as “dangerous” to its overall functionality. It can also inject custom JavaScript into secure HTTPS webpages visited by the device owner, re-direct web pages, send information about the desktop environment back to the hackers in charge of the campaign, uninstall and delete any Windows 10 service, and more. 

“We have identified at least 25 different components found in almost 2,500 distinct samples,” the security firm states. “While tracking the adware, we noticed some of the components were continuously updated with new functionalities, dropped altogether or integrated entirely in other components. This once again reinforces our initial assumption that the adware is still being developed as of the writing of this paper.” 

According to Bitdefender’s whitepaper, the winscr.exe component installed by the adware is what takes screenshots of your desktop. It can also send the hackers a list of the file locations of the applications that are set to run automatically when Windows starts and delete files used by processes and services. Other components in the adware’s payload include dataup.exe, regtool.exe, homepageoptimizer.exe, and more. 

The big red flag here is that despite infecting Windows-based PCs since 2012, the spyware won’t infest your PC unless you allow its installation. 

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Google one-ups Microsoft by making chats easier to transfer
Google Spaces in Google Chat on a MacBook.

In a recent blog post, Google announced that it is making it easier for admins to migrate from Microsoft Teams to Google Chat to reduce downtime. Admins can easily do this within the Google Chat migration menu and connect to opposing Microsoft accounts to transfer Teams data.

Google gave step-by-step instructions for admins on how to transfer the messages. Admins need to connect to their Microsoft account and upload a CSV of the Teams from where they transfer the messages. From there, it requires just entering a starting date for messages to be migrated from Teams and clicking Star migration. Once it's complete, it'll make the migrated space, messages, and conversation data available to Google Workspace users.

Read more
This new VR headset matches Vision Pro’s display at the weight of an iPhone
A closeup show the front panel of the Pimax Dream Air with Pimax logo.

Pimax just announced a new PC VR headset that weighs less than 200 grams and boasts 4K per eye microOLED panels and pancake lenses. That means the Pimax Dream Air matches the display specifications of Apple’s Vision Pro, yet weighs less than an iPhone 16 Pro.

The Dream Air looks quite similar to the Vision Pro, and Pimax undoubtedly drew inspiration from Apple’s design. The renders show a compact, curved headset with a single rear head strap that splits at the back to cup the head.

Read more
The Alienware m16 R2 gaming laptop with RTX 4070 is $500 off
The Alienware m16 R2 on a table in front of a window.

The gaming laptop deals of the holiday season aren't over yet, as there are still some excellent offers, such as Dell's discount for the Alienware m16 R2 with the Nvidia RTX 4070. From its original price of $2,600, the machine is down to $2,100. It's still pretty expensive, but it's actually a steal at that price, and the $500 in savings is huge. You're going to have to be quick in completing your purchase though, as there's no information on how much time is remaining before this bargain expires.

Why you should buy the Alienware m16 R2 gaming laptop
We highlighted the Alienware m16 R2's great gaming performance in our review of the gaming laptop, and this configuration that's on sale comes with the mighty Nvidia GeForce RTX 4070 graphics card. Combined with the Intel Core Ultra 9 185H processor and 64GB of RAM, which doubles the recommended specification from our guide on how much RAM do you need, the Alienware m16 R2 won't have trouble running the best PC games at their highest settings. It's going to be ready for the upcoming PC games of the next few years as well -- it will be a while before you need to start thinking about making any upgrades.

Read more