*Please note – This scam is based on a legitimate Youtube video that can be found by clicking here.

Scam Type: Malware – Possible Click-jacking / Like-jacking

Trending: April 2011

Why it’s a Scam:

Clicking on the wall post link loads the following page:


This screen informs you that you are missing a video plugin that is required to view the file. If you click “upgrade” in the top right corner the file download box appears. The file they want you to download is XvidSetup.exe. Downloading an executable from a sketchy site like this should be a huge warning flag to you.

We scanned the file at http://virusscan.jotti.org/en and we found the file contains adware.

According to Wikipedia, “Adware, or advertising-supported software, is any software package which automatically plays, displays, or downloads advertisements to a computer. These advertisements can be in the form of a pop-up.[1] The object of the Adware is to generate revenue for its author. Adware, by itself, is harmless; however, some adware may come with integrated spyware such as keyloggers and other privacy-invasive software.”

We also checked the digital signature of the file, and it was signed by appbundler.com. So, we decided to visit appbundler, and this is what we found:


As you can see, this hosting account has been suspended. We have had victims state they were click-jacked and lick-jacked, but we were unable to replicate that behavior. This is definitely a site to be avoided.

How to Deal with the Scam:

If you downloaded and ran the file download, then you should run a complete system scan on your computer with a anti-virus program. Never download and run files from sites unless you are 100% sure they are legitimate and you have checked out the file completely.

