Help Support my Blog!

Virgin Mobile USA
Glasses USA
Amazon
Newegg
VPN4ALL
Netflix
Hulu
CafePress

 

Subscribe to Paul’s Tech Talk Affiliate Marketing Blog

Subscribe to Paul’s Tech Talk Science Fiction Blog

Subscribe to Paul’s Tech Talk Scams Blog

  • Acer 11.6
    Acer 11.6" Laptop 2GB 16GB | C710-2856
    Acer

    Currently  in process review this Acer Chrome book and boy is it nice!

Navigation
Sponsors

Entries in Anti-Virus (37)

Wednesday
Aug212013

How Malwarebytes Pro and SuperAntiSpyware Pro keeps me safe!

Virus - Don't let it get in the window

Malwarebytes and me!

I’ve been using Malwarebytes Pro for the past few years.   Ever since 2009, I’ve used Malwarebytes Pro has always been my go to for getting rid of those really hard to get rid of viruses and malware!  I must say I haven’t had a virus or malware on my system yet.   I often travel to libraries and other such places where you never know what may happen.  Even though I use VPN4ALL, also to help protect my privacy, it doesn’t make me invisible to viruses and malware!

Over the Past 4 years!

I’ve had to disinfect my sisters computers and some other family members who have yet to learn that you have to keep your antivirus up to date and current.   The problem is AVG and other are only valid for one year.   Unlike them, Malwarebytes Pro is a lifetime license.   No matter how long you use your laptop or desktop you keep getting updates on software and virus definitions.  

SuperAntispyware and Malwarebytes!

I use SuperAntispyware Pro and Malwarebytes Pro in tandem when I need to remove a virus or malware.   Both of these are sponsors of the blog, and I earn a little commission when you buy using these links.  With each of these you get a lifetime license and this saves me money because I don’t have to worry about buying a anti virus license every year or two.   I’ve probably saved several hundred dollars from not having to buy new licenses.  Although I am probably one of the few who know about what could happen if you click links your not sure of.   So by saying these have stopped me from getting a virus may be a overstatement on my part. 

I could go on!

If I just kept talking about these two products you would probably get tired of hearing me.   I have had much success with both of these products to keep and also help get rid of those really troublesome viruses and malware that may be hidden on your system.   This isn’t going to be over but this will be coming back.   If you know someone who might need to know about a good Antivirus Software or Antimalware software.   Send them to these two sites and I am sure there problems are going to go away quickly.

Tuesday
Jan172012

Scareware sites being sent through email!

setup_security_defender_622.exe Chrome Scareware site on a Linux system!

Don't try this home!


If you are not careful you could easily get infected with spyware, or worms. I on the other hand know how to fix the problem if it happens or how to prevent it in the first place. I was using a live Kubuntu CD to do my test with the link that was given to me, so I didn't have to worry to much about infections.  The URL which was given to me was "[Website]/wp-content/plugins/(random letters and numbers)".   You could easily tell that it was just spam because there was no subject or anything else but a link in the email.   I did this a number a times and I got some very interesting websites:

  • http://scan27.delfasd.co.in (scareware site, See picture above)

  • http://wikimedicinepatients.eu (Canadian Pharmacy) [WHOIS]

  • http://systemtestnow.com  (Scareware site I think) [WHOIS]

  • http://scan7.oggnot.co.in

  • http://update17.oggnot.co.in


Never Run an unexpected Program!


I knew this was scareware site because it automatically sent me a file "setup_security_defender_622.exe".   I decided to check it out even more so I submitted to Jotti and you can see what they said by clicking the filename.   I also submitted it to the Virustotal to see what it said and I wasn't surprised but again, you should never run programs that your not expecting.    This is a really old scareware tactic that is still being used today and your self be taken advantage of.

Antivirus is KEY!


To prevent viruses, if your on a computer you really should consider buying an Antivirus.  There is even Antivurs for Macintosh machines, and Linux if your interested.   I don't know if you really need a Linux antivirus but I guess it wouldn't hurt to have it.   I think they are far behind Mac/Windows Antivurus programs but yet they are getting better.   You never really know what is needed in the future but you should be ready when it comes.

Which Antivirus Software do you use?


I am quite curious as to which you use when it comes to having an antivirus software.   By all means leave a comment and tell me which one you use or if you found another website that you have found, and I'll investigate it and tell others about it.

Paul Sylvester




Enhanced by Zemanta
Friday
May222009

Personal Antivirus just scareware

I was going through checking a site brought to my attention from a reader and I went there and yep he told me it might be [intlink id="3114" type="post"]scareware[/intlink] and it was:

mailware-live-pro-scanv1-1

If you click "Cancel" or "Ok" you will still get to this page:

mailware-live-pro-scanv1-2


[ad]It is on the Malicious site : http://maleware-live-pro-scanv1.com.  You can also see it tries to scare you with the tactic of  knowing your IP address and where you are in the world, it's called Geo-ip Location.   It tries to convince you have a virus, but in reality it is just trying to scam you out of money.   Although if you go to the site you will see that there is no company information.  That is the first clue this is a scam or scareware.


Personal Antivirus gets installed in unsuspecting computers by way of exploits, backdoors, Trojans, or unsafe downloading practices.   This usually means that if you have it you should remove it by any means necessary because this software has been know to cause more and more trouble as time goes by.   This software is fake ware, it tries to tell you have a virus and that they can get rid of it.   In fact, this software is not designed with Antivirus engine in it but to illicit pop ups and warning to raise the users security concerns about the computer in question.   Downloading programs from bit torrents or other unsafe ways can and most likely will have these types of programs installed alongside the program you wanted.


*[intlink id="4403" type="post"]Personal Antivirus Scareware Site and How to Remove it[/intlink]*


Threat to System : Moderate



[rating:4/5]




Advice : Do a Complete system scan and make sure you don't have any more hidden malware. Most of the time if you have one Trojan, you usually have more.  Personal Antivirus has been know to have some type of program installed on the system in question and should be removed.



I recommend :

[ad#SUPERAntiSpyware]

On a side not, if you are wondering why I think I know I am not infected with these virus for those who are probably asking that question is because I already have a [intlink id="2205" type="page"]dependable free anti-virus[/intlink] software installed.  Don't forget to visit the Forums for other ways to watch for spyware or scareware.   I will always recommend buying antivirus software from vendors you know and not ones that are fly by the night scams.

Tuesday
May192009

MobileMe Who me? Could this be Phishing?

Photo By : Richard Thomas
Photo By : Richard Thomas

MobileMe one of Apples latest software packages, recently started getting emails claiming they need to update their credit card information.


 


It seems that along with Twitter, Facebook, and PayPal Phishing are on the rise. I know this was going to happen do to the fact of the recession. I've seen more and more attempts to send people to the Canadian Pharmacy and to sell you drugs that I wouldn't recommend buying it online.


 


Some things I am wondering is when will Apple release they are having to protect their consumers from these types of attacks? I've talked about the Apple Botnets and how they will become more and more prevalent due to the fact users think they can never get a virus. See the Apple Ads in 2007 to prove my point.


 


So let's talk about online safety, and help those who might need help. Some of my thoughts to help keep the Apple People happy are:


 





  • [ad]Don't go Downloading Illegal stuff – This is mostly how they malware authors are getting Mac users to install malicious software. You think you downloading the I-Life 09 but are really installing a virus.




  • Don't click links in Email – This is so tempting because it easier to just click and have it open up automatically but most of the time if you click a link that says it is going to http://www.apple.com/support (That is how they fool you).




  • Don't give out your email on twitter – This is also something you should follow more and more, because you don't want to get a virus or spam from making your email public. There are ways to see your deleted twitter message so that isn't going to be hard to find those emails.




  • It's time to install Macintosh Anti-virus software – Yes you heard me, I know there are a few Mac Anti-virus software's out there. You should also make sure to keep that up to date.




Now is when Apple should start suggesting security, but they have stopped recommending it for so long. The Malware authors are getting restless with anticipation. I can only guess what they will try next but it will happen. Sooner or later you will get a virus so bad that Apple will start recommending it on there site. When that day comes, I'll be so happy because that means Apple software isn't that bad. I just hope Apple realizes it before it's too late. They've had so much Apple don't Virus propaganda thrown at it's consumers it is no wonder they aren't worried about Security.



Wednesday
May132009

Casino Spammers still user Yahoo for Spam : Could this be Malware?

It just shows you just how one Geocities was taken down by Yahoo who owns it, the spammers have to come up with more ways to get you to download there software.

[ad]In my previous post about [intlink id="3199" type="post"]Casino programs[/intlink],  They were using Geocities to host the page for the link to the download.

casinosmartdownload


It seems to be linking to "http://bestwinscasino.com/SmartDownload.exe".  From [intlink id="3199" type="post"]previous post[/intlink] I talked about what that program did but I wanted to do another test with CWSandbox and see what has change. It looks like they must be having problems lately,  So If you want to do your own test and send me the link by all means.  I don't know what is going on but, it probably is like the other post about wanting to do some bad things.  Virustotal has some anti-virus programs flagging this so I am unsure of the Harmlessness of this file but I wouldn't install this software.  According to Avinti this program is a trojan dropper.  So Iwill let you decide on installing this software or not.


While the CWSndbox checks for malware, I went to Whois and looked up the domain.   Very interesting,  According to Whois this domain is located in China?  You don't say, we've heard a lot of stuff coming from China from Graham Cluely Blog.  So it only makes me wonder what they are attempting to do now.  I do know never download a file you haven't heard off


This is a good time to install some [intlink id="2205" type="page"]Free Anti-virus and Free Firewall [/intlink]software to better protect your system.

Monday
Apr272009

Scareware sites to pop up with Swine flu epidemic

This was to be expected when it comes to something that most people are worried about:


I'm sure it won't be long before purveyors of rogue anti-virus products begin using search engine optimization techniques around the term "swine flu" to drive people to sites that try to scare people into buying the worthless software.


[Via Security Fix]


[ad#cricket-right-ez]

I am sure myself that this will undoubtedly start showing up in SEO routines.  This will most likely be like the Pifts.exe [intlink id="3114" type="post"]scareware that popped up after the scare[/intlink].


This is just a matter of time before  someone tries to either sale you something or trick you into watching a video that supposed to be helpful.  The Video will most likely try telling you need to [intlink id="2991" type="post"]install a fake codec or update Flash[/intlink].


Your best advice is if you get to a site that wants you to install something just to hit the back button or close down your browser.   Never install software from a site you just game to without doing a little research.


I would also assume that there would be [intlink id="2970" type="post"]scareware sites that will pop up in search engines[/intlink] to scare you into buying fake anti-virus software, claiming you have a virus.  You can bet in no time flat that there will be some kinda of search term that will want to scare the user into buying something that really isn't.   I would always recommend the [intlink id="2205" type="page"]free versions of Anti-virus[/intlink], if you can't afford the paid.  This way you are safer then if you didn't have any anti-virus.   I'd Also recommend a [intlink id="2205" type="page"]Free Firewalls[/intlink] also to help protect your computer from contacting any malicious site without your knowledge.


Be on the lookout for sites that do this, you can also discuss sites you have seen that have done this in my Forums this way you can help other users out and prevent people from being scammed.

Wednesday
Apr152009

Mebroot becomes More Stealthier!!

Well Here is something we should all be on the look out for:
[ad#cricket-right-ez]
Thousands of Web sites have been rigged to deliver a powerful piece of malicious software that many security products may be unprepared to handle.

Mebroot inserts program hooks into various functions of the kernel, or the operating system's core code. Once Mebroot has taken hold, the malware then makes it appear that the MBR hasn't been tampered with.

[Via Pcworld Magazine]

I will be updating my [intlink id="2205" type="page"]Malware Resource[/intlink] for the Prevx Software, but this looks to be a very bad root kit.  From my understanding most of the security related software.   It seems this little program will become even harder to detect and remove.   It also looks like this is ready to start infecting people with this root kit.   You should update every part of your system from [intlink id="3327" type="post"]Windows Patches[/intlink] to Browser. [intlink id="2229" type="post"] Securnia once said[/intlink] that most people are not patched fully!!  Just like the [intlink id="3301" type="post"]Conficker Worm[/intlink], if your not fully patched and keeping anti-virus and Firewalls on your system then you might as well be walking on nails.
Monday
Apr062009

Securing your Windows Machines

After a Long day at work, you sometimes feel like there isn't much you want to talk about. Then this idea comes to me? Why do people blog and why do people talk about security?

I've come to realize something, I'm not one who was grew up understanding bits from bytes. I grew up as any family does fighting with my siblings.

Having been blogging the past few years, it seems like only yesterday that I started blogging. Cliche I know but still very much true. Most blogs do what they know, I aim to learn and teach each day I blog. Like days like this when the world is pretty much quite and the [intlink id="3214" type="post"]remnants of the conficker[/intlink] worm dies to a rumble.

[ad#cricket-right-ez]So how do you secure your Windows Machine?

After a day long battle with  my wife's system, I grow to wonder if there is something I should do differently with how to prevent Viruses and Worms on her system.  So I've groomed my Knowledge base and come up with 5 good points when it comes to locking down your Windows Machines:

  • [intlink id="994" type="post"]Lock down your Router/Modem[/intlink]  -- Some people don't know that having an insecure router with weak passwords is a way to get on another system.   This can easily be prevented if the users takes some steps to prevent. it.  Although if a hacker wants to break your encryption and find your Signal there is really nothing you can do but try to prevent that.

  • [intlink id="2205" type="page"]Firewall and Anti-virus[/intlink] --  Although I know people think I am a broken record this will always be something I encourage for everyone who reads my blogs.  I will never stop beating people over the head with this.   Seeing the [intlink id="3272" type="post"]Conficker map[/intlink] tells me there are quite a few without an Anti-virus or a Firewall, which might of given someone a heads up find out if they do or not!!

  • [intlink id="2984" type="post"]Disabling AutoRun[/intlink] --  This can prevent a USB stick from installing software it shouldn't.  Remember Microsoft has issued an statement on how to disable it for sure.  Although I must say The Security Now episode 187 seems to talk about this really well and how to make sure you do disable it the right way.

  • Make sure it is a Limited user account --  Most people always run as administrator when in fact that sometimes makes you more vulnerable to viruses, worms, and trojans.   Any software you install as an administrator will automatically be given Administrator rights.  That can be very bad when it comes to virus and such.

  • [intlink id="2883" type="post"]Keep your System up to date[/intlink] -- This is essental for people who to prevent exploits to be used against you.  Although  if your like me and you want to make sure your software is up to date some of that can be done with [intlink id="553" type="post"]APPSNAP[/intlink].


With These tips, your system can be a little more safer.  Just remember there is no perfect way to protect your systems 100% only some of the time.  The rest depends on you, because your the last layer of defense.  Also it isn't a bad idea to [intlink id="2407" type="post"]back up your system from time to time[/intlink].
Thursday
Apr022009

Microsoft issues Advisory KB969136 (Zero Day Exploit in the Wild)

Well, this had to happen sooner or later.  It looks like Powerpoint can be exploited with a Remote Code Execution.   So Microsoft today has issued an Advisory for KB969136.

In there post they say:
[ad#cricket-right-ez]
At this time, we are aware only of limited and targeted attacks that attempt to use this vulnerability. If you suspect that you were target for such an attack, you can scan your computer with the Windows Live OneCare safety scanner. The malicious PPT files are detected as Exploit:Win32/Apptom.gen. Microsoft will take the appropriate action to protect our customers, which may include providing a solution through our monthly security update release process, or an out-of-cycle security update, depending on customer needs.

Products affected are Microsoft Office PowerPoint 2000 Service Pack 3, Microsoft Office PowerPoint 2002 Service Pack 3, and Microsoft Office PowerPoint 2003 Service Pack 3. Microsoft Office PowerPoint 2007 is not affected.
[Via Microsoft Blog]

Microsoft has even added a diagram on how an attacker could implement this into an email.

So what do you need to know:

If you receive a Power Point presentation from someone you aren't expecting either scan it good with a[intlink id="2205" type="page"] free anti-virus[/intlink]. There are no major workarounds to this because Microsoft is telling people not to open the Power Point files directly. I tend to agree you should however know if you are expecting something from someone by either emailing them back or if it's an office situation pick up that phone for the time being. I am sure Microsoft will issue this patch in the coming months probably May or June at the earliest. I don't think it will be April Patch Tuesday, they could however make this an out of cycle if enough hackers start to use this.

According to Micrsoft the Windows Live One care picks this up as Win32 Exploit so I am sure other [intlink id="2205" type="page"]Anti-virus Software will do the same[/intlink].   Just for the time being you will want to scan any presentations that come your way.  I will update the blog as more information becomes available!!
Tuesday
Mar312009

Just Google Conficker and you'd be surprise

Countdown to March First is on it's way or already depending on your location and People have been sending tweets about the 60 Minutes coverage of the Conficker:

conflickermarch


As you can tell over the last week Google trends is showing a mountain of people looking for this information.  I am so glad the media has talked about this but it has mad a hysteria or frenzy of people trying to find information on this little worm or some are calling a virus.



[ad#cricket-right-ez]

Now I must remind you that [intlink id="2715" type="post"]Conficker.a[/intlink], [intlink id="2754" type="post"]Conflicker.B[/intlink], [intlink id="3214" type="post"]Conficker.C[/intlink], and [intlink id="3236" type="post"]Conficker.D[/intlink] are the only worms or viruses out there and that you should really [intlink id="2205" type="page"]protect yourself from every virus[/intlink] because there are more viruses or worms out there than this one.


There are several Free Anti-virus options Available:




  • Clamwin -- I've been trying this one out over the past month and it seems to work just as good as the others.

  • Avast Home Edition — AVG does better than this one but people seem to like this so I have to add this for people who like this better than the others.

  • AVG Anti-Virus Free Edition 8.5.283 — This is another free one that can remove viruses really easily. Download this and you don’t have to worry to much.

  • Avira Antivirus — This is a free anti virus software that some people like.  I like AVG myself, it’s all user preference on which one you want to use.


As you can tell I have sever options available in my [intlink id="2205" type="page"]Malware Resource page[/intlink] for you to use this is just a few that can be helpful when trying to protect your system.  With Conflicker disabling your windows update and if you have a lot of systems you need to update your patches, I'd go with [intlink id="2883" type="post"]Autopatche[/intlink]r this little program will help install the necessary Windows updates.  You should follow Microsoft advice when you are trying to fix the your system with regards to the Conflicker.    Remember this is not the only computer threat out on the internet but be vigilant with where you go and what you.   You are the last line of defense when it comes to protecting your money, your identity, and you computer.

Although if you have a lot of systems that your are worried has the conflicker worm, Arstechnica released information on easily detecting this worm.  This looks like a positive step in stoping this worm.
Saturday
Mar282009

Hotmail accounts get compromised!!

I received an email on a list and wanted to warn people:
[ad]
Dear friend,
i would like to introduce a good company who trades mainly in electornic products. Now the company is under sales promotion, all the products are sold nearly at its cost. They provide the best service to customers,they provide you with original products of good quality,and what is more,the price is a surprising happiness to you! It is realy a good chance for shopping.just grasp the opportunity,Now or never!
The web address: http://www.nekcn.com

Seems this is being sent from Hotmail accounts. There are a number of ways someone could be getting a hold of your email address. According to Microsoft forums this seems to delete your email contacts and also send out this in the same time. This seems to be a new spam campaign for this one company. I would guess someone bought advertising from this company and the advertiser is doing some really unmoral things.

There are several ways someone hotmail account could be sending out these emails. It could be a [intlink id="2650" type="post"]phishing attempt like they did with Twitte[/intlink]r. They could of done a dictionary attack on each account to find the password, that I why [intlink id="2646" type="post"]I suggest having a password generator[/intlink]. It could of been a virus, and if that is the case you would need to [intlink id="2205" type="page"]check your system out for the virus[/intlink]. I would guess it is the first two, because I am unsure of if you can have pop3 account or not. I don't use Hotmail but people seem to be using it.

If you recieve this email, I'd email the account responsible to let them know that they have sent this.  I would also like to know if it was a virus or how they account got compromised.   Remember only you can prevent from getting a virus, nothing else works better than yourself.
Tuesday
Mar102009

Let's Clear this up -- PIFTS.EXE

I just wanted to clear up some things about PIFTS.EXE.  I read a Most Interesting Article about this over at Bleeping Computers.  He talks about how tested this on his system and I'll quote:
After reading about this file here and here, I asked around on BleepingComputer.com for one of our users to submit a sample of the file to me. Once I received the file, I ran it on a test box while running a file monitor, to see what it accesses, and Wireshark, to see what it does on the network. What I found was that the program appears to be quite innocent, and from the hostname it connects to, we could have guessed as to what it does. It appears that when you update Norton it connects to stats.norton.com and lets the server know someone has installed an update, what the update was, what program it was for, and whether it was successful. Now, I am not saying that Norton should be contacting one of their servers and reporting this type of information without a user's permission or even knowledge, but there is no conspiracy theory between Norton, Google, Microsoft, African Nations, and little green men.

[Via Bleeping Computers]

[ad#cricket-right-ez]So Let's Talk about this a little more, It does connect to stats.norton.com and tell norton that it it has installed the update.  Like he says, I agree although Notron isn't trying to be the bad guy. I, like everyone else, also thought something was amiss when they started deleting forums post.  Instead of locking them down.  You see it makes them look suspicious and that started a flurry of people posting about this.  I do know they should of been truthful from the get go.  I just heard about this today and wanted to remind people that I meant what I said.  Don't go overboard because your think your trust with a company was mislead. You know that they have to protect their service to prevent unauthorized access to there software and get what money they deserve.  However They should of been open from the start with this on there main page or in the forums talking about how this happened in the first place.
In Symantec's defense, when I first heard about this earlier this morning, I noted privately to a couple of folks that some of the comments being left on the Symantec forum bore many of the hallmarks of "4Chan," (a.k.a. "anonymous"), a virtual community that thrives on playing practical jokes and causing trouble online. The summary about this incident posted to News-for-nerds site Slashdot this morning links to a key 4Chan forum.

[Via Bleeping Computers]

Now they couldn't say something like this either in there forums as a sticky note or on there Website?  This was why they started to delete the forum threads without telling anyone what happened.  I understand they have the right to delete what they want when they want, it was probably an over zealous moderator.  I wanted to clear this up a little so the virus theories and the conspiracy theories would go away.   I know some website are being over zealous over this and claiming it is doing things it isn't.  I was just trying to inform but others seemed to run with it and come up with all kinds of theories.  So please let's take a deep breathe and understand that you have several options as to what you want to do.  I haven't recommended people removing Norton, and I still don't recommend removing from your system.  I will always tell people that there is Free versions of Anti-virus and Firewalls available.    Like I said in my previous post these were post made by people on the forums and I was taking screen shots to proof that there was something going on.

I hope this clarify what is going on with Norton Antivirus. I'll still recommend it for people who can afford it, because it does a good job on anti-virus.

[READ More about this at Symantec]
Tuesday
Mar102009

Fake Scareware Sites Popup after the Pifts.EXE Conspiracy

There Seems to Be a Fake site that are popping up today right after what happened with PIFTS.EXE. I just happen to Google it to see what people are talking about and this appears on the front page.

Not a real site!!

As you can see this leads to a server in Poland and once you go to it you see:

Not a real virus scanner



I will be reporting this to Phishtank. This is scareware which means  there is no real VIRUS because and you
Should never believe the screens when you see something like this. According to Wikipedia:

[ad#ad2-right]Some websites display pop-up advertisement windows or banners with text such as: "Your computer may be infected with harmful spyware programs. Immediate removal may be required. To scan, click 'Yes' below." These websites go as far as saying that a user's job, career, or marriage would be at risk. Products using advertisements such as these are often considered scareware. serious scareware applications qualify as Rogue software.
[Via Wikipedia]

So if you are worried you have a virus or think you have a virus I would advise you to download one of the free Many anti-virus software and firewall. This is nothing new with the companies who are doing this but don't buy anything because people are trying to scare you into thinking you have a virus. That rarely is a valid software and you should use the ones that you trust. If you find a site like that please report them to Phishtank and other sites that way we can protect everyone who goes there.

Monday
Mar092009

Conspiracy theories run rampent due to PIFTS.EXE

(Looks like some of this was a 4chan gag, check my other post about it)



All of the sudden people around the World are seeing PIFTS.EXE popping up. Norton Antivirus is asking users if they want to accept it. Here what I do know:
Here's some information I pulled from my Zone Alarm Logs. Does this make sense to anyone?
[ad#cricket-right-ez]2009/03/09 18:26:44 -- New Program -- PIFTS.exe -- Destination IP: 67.134.208.160:80 -- outgoing -- blocked -- Destination: ping.lifecycle.norton.com

2009/03/09 18:47:52 -- Program Access -- PIFTS.exe -- Destination IP: -- outgoing -- blocked -- Destination:

2009/03/09 18:48:28 -- Changed Program -- Windows Explorer -- 207.46.248.249.80 -- outgoing -- blocked -- Destination: sa.windows.com
[Via The Symatec Forums]

This indicates that the program tried to change tactics to go out on the net.  I look a look for this and it is SwapDrive.  So this must be an update to Swapdrive but I am unsure as to why it pops up that way.  The other ip is in Africa or at least take the .80 out of the equation and it points to an Africa IP.  (It looks to my mistake in that little part, "to error is human" Check out this  post about it)  Although just recently Norton Decides to Delete that thread and people are really worried about why?  Is this a cover up of some sort because there is a exploit in the Wild that we don't know about?  These are good questions that need to be answered.   Here is what one posted about this just after they deleted the forum thread:

Norton Coverup?  Do you suppose


As you can see people are taking this deletion on the community forum thread very seriously, they know something is not right in Denmark.  I also want to point out this one:


Proof there was a thread



I don't know what Norton is up to but this is making me uneasy.  If they are worried about something that they can't explain or don't want to explain then they have made a mistake.  Some users are really worried now because Norton isn't saying anything at all.  I love this post:

A Conspiracy I see!!

As you can see people see this and are worried, I didn't want these to be taken offline like the first post so I make physical copies to put on my blog.  I want to prove to people that these actually existed.  I would advise people to run Hijackthis to see if you can figure out where this is coming from.  I don't know why they would hide the truth, it will bite them in the end.  Anyone want to comment on this, I am quiet curious??

*UPDATE 12:01 am 03/10/09*

Seems Norton Deleted all post about PIFTS.EXe so I don't know what happened but This will have to come out in the open sooner or later.  I just hope it isn't going to be to late.

Update 12:15am 03/10/09*

Seems people have decided to go to the Zonealarm forums to discuss this:

People are clearing wanting to know why?

You can visit there forums here.  I am getting more curious about this little situation and now tempted to stay up all night watching this!!

[ad#digg-right]I also found this forum thread from BuckeyePlanet.  I am seeing more and more people blogging about this.  So this must be something REALLY big.  Keep sending me comments if you find anything else.  Don't forget to add me on Twitter.

This looks interesting:
[ad#cricket-1]
Even more interestingly now, after posting a single post asking about PIFTS.exe, which was deleted, and a subsequent post to another forum asking about the deleted posts, which got deleted, I've now been blocked from creating new posts or replies on the Norton forums. They really don't want to talk about whatever this was.

And doubly interesting -- or perhaps not, who knows -- not sure if this is standard practice at Symantic or what, but opening the PIFTS.exe in a hex editor shows a large section of the end of the file consists only of "PADDINGXX" repeated over and over. I've got some background in programming and can't think of a good reason why you would need padding like that on a legitimate executable. However, if an executable in an update has been compromised it may require padding such as that to match the original executable's file size or something. But that's just pointless conspiracy theorizing that likely has no basis. It would be nice though to hear from Norton about what the **bleep** this thing is.
[Via Zonealarm Forum]

I don't know but I suspecting an update went wrong at least from all the indications I'm seeing.

I will say you have several options available to you:

  • You could get a Free Anti-virus Software

  • You could run without An Anti-virus (Not a great option, wouldn't suggest it)

  • You could do nothing and wait. (My recommendation until I find out the the full story!!)


Please let's not start a pandemic over this, I am however worried because Norton has yet to release any public information about this?  I will update as needed but please people let's not go to OVERBOARD on this!!

Google Get's rid of the Trend "PIFTS.EXE, no long there.  It was there last night.  Hmm even more questions and answers? (Click image to view it!!)

Proof it was there!!



On a side note, I do not have access to this file. I've had a friend who told me about this and I started to investigate it and as soon as I did that Norton started to kill the messages. That when I knew it was something big. That is why I blogged about it. I do not have the program. I just know that it is being searched really hard because I've had more people coming to my site than usual. So please don't ask about samples, you can comment on this or ask questions. I provide this for the community to let them know!!

(Looks like some of this was a 4chan gag, check my other post about it)

Thursday
Mar052009

I hate Snopes Spam

As you know Snopes is used to find out about urban Legend and Rumors:

I received a Virus alert from my RSS feed about Email virus warning.  It even adds a Snope URL.  The Author just copies and pasted the virus warning into the blog without even going to Snopes.
[ad#ad2-right]
According to Snopes and I'll quote:
Although the Postcard virus is real, it isn't a "BIG VIRUS COMING" (it's already been around in multiple forms for a long time now), it will not "burn the whole hard disc" of your computer, CNN didn't classify it as the "worst virus" ever, and it doesn't arrive in messages bearing a subject line of 'Invitation.'

[Via Snopes]

Now as you can tell the link described in the blog post was "http://www.snopes.com/computer/virus/postcard.asp". If you went there, you'd have seen this as a not really true and some parts of this might be but that part about burning your Hard drive or even consider the Worst virus isn't true.

Some things you need to consider before forwarding anything is:

  • Is it completely True?

  • Is it Legitimate?  (True blown warning about something like a product recall  or something important like that)

  • Does it Say to Forward? (if so it is probably not wise)

  • is it from a Friend (If so you might want to remind the friend nicely that it isn't nice to send spam)


If you follow some of these suggestions you'll be making the Internet a far better place for everyone.  Remember if you don't know, it's time to learn.  if you do know, it is time to teach.  These are the fundamental aspects of using the internet the right way.  Also if it is a fake virus warning you should tell them to get a Free Anti-virus and Firewall to better protect them.  Also  remind them that if they keep their system updated then they shouldn't be too worried.  Remember only you can prevent a Computer Virus and it's up to you keep your system up to date.
Friday
Feb272009

Rogue Fake Codecs on the Rise

Panda Labs has been talking about Adware/VideoPlay and they are seeing a lot of variants on this.   They even play a game, find the difference in the installation screen:



Now as you can see this look to be the same agreement in all those difference installation.  Some things to consider Never install any software from a website that you don't know Nothing about about.

Panda Labs also talks about these new variants in regards to what they do:

This file spreads by making copies of itself in the removable drives and it also creates an autorun.inf in order to be run when they are accessed. This file collects the data stored in the browsers, such as cookies, passwords, profiles, email accounts, etc, and connects to a remote address to send the information.
[Via Panda Labs Blog]

[ad#ad2-right]As you can see this makes you have very little security with your system.  I talk about Identity theft, and why you should always worry about your identity.   This however will make your passwords less secure and maybe even compromise you system to the point of having a data breach.   You need to be careful when you come by this, some fake codecs have been know to be scareware.  In which, the fake codecs installs a Trojan to tell you have a virus and try to make you buy a fake program to get rid of the Virus.  In one of my recent posts about Codecs and Facebook, I talked about the K-Lite Mega Codec Pack and how that will prevent you from installing these sociable links from friends and family.  The nice thing about this pack is it install all the really good codecs that you might come across on the web.  If you have this installed and there's a website that says you need a special codec, you'd know that it is either a fake codec or the author who made the video doesn't standardize.   In which case you will be more willing to leave that site without installing that codec.

If you follow these steps and also consider installing an Anti-virus and Firewall, you will be in a much better shape then when you first started out. Remember only you can prevent from getting a virus. You should also consider doing the registry edit that will prevent Autorun. As you can tell these new variants also are spread through USB and other removable media. This is the other way these programs are using to infect other systems.
Monday
Feb232009

You won't make money from W32:Sality.ao

People should be cautious of the making money because there is a variant out there trying to leverage the users into thinking they can make money.

McAfee Says "W32/Sality.ao is a parasitic virus that infects Win32 PE executable files. It infects files (*.exe and *.scr files) on the local, network and removable drives by overwriting code in the entry point of the original file and saving the overwritten code in its virus body. It then appends the virus body to the host file."

Aliases for this Virus is:



  • Virus.Win32.Sality.y (Ikarus)






  • W32/Sality.AE (Norman)



  • W32/Sality.AH (Panda)



  • W32/Sality.AK (F-Prot)



  • Win32.KUKU.a (Rising)




  • Win32/Sality.AA (VET)


These links should help people understand it it.   You can visit my Malware Resources to help remove this virus.  Something to consider before removing this is to disable your restore points.

Remember there's no easy to make money, the only real way is to work hard.  According to my research the Anti-virus companies have ways to remove this virus and as long as you update your database.
Friday
Feb202009

PDF Zero Day Vulnerability in the Wild

From sources all over the internet, Adobe made a sent out a Security bulletin yesterday:
APSA09-01 (Buffer overflow issue in versions 9.0 and earlier of Adobe Reader and Acrobat)

[ad#ad2-right]A critical vulnerability has been identified in Adobe Reader 9 and Acrobat 9 and earlier versions. This vulnerability would cause the application to crash and could potentially allow an attacker to take control of the affected system. There are reports that this issue is being exploited.

Adobe Plans on patching this March 11, 2009

and According to some other reports are saying:
Symantec Security Response has received several PDF files that actively exploit a vulnerability in Adobe Reader. We are continuing to remain in contact with Adobe on this vulnerability in order to ensure the security of our mutual customers.

[via Symantec]

With PDF files being used all over the business world, this will create undo problems with the IT Field.  This also could be used to make Botnets and make the network involved become sluggish.   It must be warned that there are a whole wide variety of possibilities that could be done with this exploit.  Shadowserver Foundation recommends disabling the Javascript in your Adobe Reader.  Until the patch comes out you will need to be careful on what you open up and possibly check each and every PDF with an Anti-virus.  This should help minimize the likely hood of getting a virus or Trojan, but is not going to be a 100%.  The only way you can prevent a 100% right now is not to use PDFS until they have Fixed this problem.
Thursday
Feb192009

PolyMorphic Win32:Vitro Most Viraulent Virus

This seems to be an virus that is getting some people hit hard.   I wanted to blog about this because of the nature of Virus and Trojans.   I have read reports that this might be from Online Movies, and I have to say this is one reason why you must stay away from certain online movies.  I am going to take a guess that this virus requires a special CODEC, and you downloaded it and installed it.  It Could also be the update the Adobe Flash player idea to but still results in getting the Virus.

As I said before you take a risk when you go to sites you don't trust or know anything about.   You also should know that if you need a "SPECIAL" codec, you should just go on to another site.  These sites that claim they need this special codec means only one thing they want to install something without your Knowledge.

So what is this Virus:


The Virut family of viruses uses polymorphism to hide from all anti-virus protection, it infects executable files. File infection makes it very hard to repair a system that has been infected. W32/Vitro injects code in running processes and hooks the following functions in ntdll.dll which transfers control to the virus every time any of these function calls are made.

* NtCreateFile
* NtCreateProcess
* NtCreateProcessEx
* NtOpenFile
* NtQueryInformationProcess

[via Avast Forums]

After you get this very bad Virus you are done for.  You would need to install the Operating system from backups or even start a new.   This seems to be building this week and there isn't much you can do once your infected.  I do recommend a good Anti-virus and Firewall but that wouldn't fix the problem right now.  You will need to pull your backups out and start the process.  I suggest a complete wipe and then do the Restoring the backups.  This little virus likes to infect any .EXE it can so just restoring the Windows Directory will not help.  Remember only you can prevent from getting infected.
Wednesday
Feb182009

Tech Journalist breaks the silence -- Journalist got Pwned!!

It was another ordinary day for this tech journalist. He had just waken up from his lovely dreams and hadn't realized that he was being baited with Phish. Yes that is correct he actually gave out his password to an Phish site and didn't know it.

I have to admit that he didn't hide it, in fact he decided to post about how he got Pwned and what happened.

The Face Of A Facebook Phishing Scam The Face Of A Facebook Phishing Scam
[Click Picture to see the full story]


[ad#ad2-right]As you can see the site : Facebookcom.awardspace.com is a phishing site and should never give out your information to third parties.   Some things to remember if you get an email with a link sometimes won't send you to the real link.  This can be easily done just like blogging.  You don't know where you will end up when you click an email link.   One thing to remember is if in doubt log into facebook the old fashion way and see for yourself.

You could be the next person to have your Identity taken away from you.  So what should you do to prevent this type of phishing attacks, assume any email you get from Facebook, Myspace, Twitter, and Any other Social Sites to be a possible phish email.   These are always going to be a problem for these sites.  The spammers want access to be able to spam your friends and family with links, or to make you look foolish.  This is the reason they do it for Money or just for laughs.

One thing to remember is having a strong password will make it that much harder for you to be phished because if you can't remember it you will be more careful.  I will keep preaching this having a good Firewall and Anti-virus will also prevent you from getting viruses from these type of phishing attacks.  It will also make it much more harder to go to sites that smell like Phish.  Remember only you can keep your identity a secret.