Help Support my Blog!

Virgin Mobile USA
Glasses USA
Amazon
Newegg
VPN4ALL
Netflix
Hulu
CafePress

 

Subscribe to Paul’s Tech Talk Affiliate Marketing Blog

Subscribe to Paul’s Tech Talk Science Fiction Blog

Subscribe to Paul’s Tech Talk Scams Blog

  • Acer 11.6
    Acer 11.6" Laptop 2GB 16GB | C710-2856
    Acer

    Currently  in process review this Acer Chrome book and boy is it nice!

Navigation
Sponsors

Entries in program (44)

Thursday
Aug202009

List of Malware sites for Aug 21, 2009

personalantivirus3


It has been kinda busy today for the Antivirus scareware sites but here they are.


[intlink id="3607" type="post"]Personal Antivirus Scareware Site[/intlink]:




  • check-for-malwarev3.com

  • safeonlinescannerv4.com


[intlink id="4217" type="post"]Internet Antivirus Pro Scareware[/intlink]:

  • fatuus.info


[intlink id="3977" type="post"]Rogue Antivirus scareware sites[/intlink]:

  • antivirusplus2010.com

  • mybestantivirusplus.com

  • internetantivirusplus.com

  • antivirusplus09.com

  • antivirus-plus-now.com

  • yesantivirusplus.com

  • goodantivirusplus.com

  • i-antivirusplus.com

  • nextantivirusplus.com

  • antivirusplus-ok.com

  • getavplusnow.com

  • antivirusplusnow.com

  • getantivirusplusnow.com

  • realantivirusplus09.com

  • freeantivirusplus09.com

  • addedantivirusstore.com

  • addedantivirusonline.com

  • myplusantiviruspro.com

  • yourcountedantivirus.com

  • easyaddedantivirus.com

  • addedantiviruslive.com

  • addedantiviruspro.com



[ad#Scarewaresitesrecommend]

[rating:4/5]

[ad#Scarewaresitesrecommend1]

[ad#SUPERAntiSpyware]

Saturday
Mar142009

Malicious Spammers target Bank of America

I've saw two different security firms talking about Bank of America and I wanted to share with you:

Fake Bank Of America SitePicture from F-secure


[ad#cricket-right-ez]The two sites are F-secure and Pandalabs who are talking about Bank of America and how they try to get you to install malware.  With Adobe having just sent out the new updates last month it looks like spammers are using this to get people to install Malware.


It is also been known to be floating around in Facebook this spam.  So if you get a link going to a site you don't know about to see a video and it says you need a codec or the Adobe update you should turn right around and leave site. You should always type in the url of Your Bank and not go there through links.


From what they are saying it monitors Network traffic and Steals ICQ, POP3, and IMAP passwords.  If you find network traffic going to Hong Kong IP, then it is time to check to make sure all your Virus definitions are up to date and you've installed an Anti-virus and Firewall.  I would encourage  users to report it to Phishtank so that any other unsuspecting user or person going to that site will be warned.

Thursday
Mar122009

Is Google the ultimate news source?

As you know We had a big problem Monday Night and All day Tuesday. If you are a regular reader of this blog, you would of noticed either a 503 or lag. It was due to an article that I released late Monday night about the PIFTS.EXE and the so call conspiracy.

At the time, I was wondering and quite disturbed about what Norton Symantec was doing to the forums. So I blogged about this and wouldn't you know my site was Held Hostage by Google. I kid you not, I had so many people come to my site in under an hour it wasn't even funny.

[ad#cricket-right-ez]So I sit here, asking a really good question is Google the News? I don't know exactly when but according to Wikipedia Google was formed in 1998. The Google Motto is Don't Be Evil, and I guess it makes them look like a news source. When did they get past the news site? I would hazard a guess that it was in late 2004 they started when they when Google gave people the first chance to own the stock on August 19, 2004, when Google became a publicly held company.

I got hit hard by Slashdot, Reddit.com, and Google.  In truthfulness, It was more of searches and people coming from Google than anywhere else. I would say Google was the 90% and and Slashdot and Redidit was 8% and the rest was from other websites for this one article. Now don't get me wrong the 2% of people was my normal amount of people for the day. So you can imagine how many people actually came to my site over this fiasco.

I call this a fiasco because basically it was one that really made me worry about the server going down. People seemed to try to find out about this program and some of them didn't even do any more research than to come to my site? Although I do know a little, I have always considered myself to be a BLUE COLLAR Tech Blogger. So you can just call me "The Blue Collar Tech Blogger" when it comes to things like this. I will never proclaim I know everything and I am still learning every day I blog I learn something new.

So this leaves me with a question on how did Blogs become the news also?  Did we step into the roll of news?  I know there are many blogs out there that are telling the news and are almost as if they are the news.  Is that where this has become Web 2.0?  I throw these questions out to see what type of comment.  I just thought this was a good topic for today to talk about.
Monday
Mar092009

Conspiracy theories run rampent due to PIFTS.EXE

(Looks like some of this was a 4chan gag, check my other post about it)



All of the sudden people around the World are seeing PIFTS.EXE popping up. Norton Antivirus is asking users if they want to accept it. Here what I do know:
Here's some information I pulled from my Zone Alarm Logs. Does this make sense to anyone?
[ad#cricket-right-ez]2009/03/09 18:26:44 -- New Program -- PIFTS.exe -- Destination IP: 67.134.208.160:80 -- outgoing -- blocked -- Destination: ping.lifecycle.norton.com

2009/03/09 18:47:52 -- Program Access -- PIFTS.exe -- Destination IP: -- outgoing -- blocked -- Destination:

2009/03/09 18:48:28 -- Changed Program -- Windows Explorer -- 207.46.248.249.80 -- outgoing -- blocked -- Destination: sa.windows.com
[Via The Symatec Forums]

This indicates that the program tried to change tactics to go out on the net.  I look a look for this and it is SwapDrive.  So this must be an update to Swapdrive but I am unsure as to why it pops up that way.  The other ip is in Africa or at least take the .80 out of the equation and it points to an Africa IP.  (It looks to my mistake in that little part, "to error is human" Check out this  post about it)  Although just recently Norton Decides to Delete that thread and people are really worried about why?  Is this a cover up of some sort because there is a exploit in the Wild that we don't know about?  These are good questions that need to be answered.   Here is what one posted about this just after they deleted the forum thread:

Norton Coverup?  Do you suppose


As you can see people are taking this deletion on the community forum thread very seriously, they know something is not right in Denmark.  I also want to point out this one:


Proof there was a thread



I don't know what Norton is up to but this is making me uneasy.  If they are worried about something that they can't explain or don't want to explain then they have made a mistake.  Some users are really worried now because Norton isn't saying anything at all.  I love this post:

A Conspiracy I see!!

As you can see people see this and are worried, I didn't want these to be taken offline like the first post so I make physical copies to put on my blog.  I want to prove to people that these actually existed.  I would advise people to run Hijackthis to see if you can figure out where this is coming from.  I don't know why they would hide the truth, it will bite them in the end.  Anyone want to comment on this, I am quiet curious??

*UPDATE 12:01 am 03/10/09*

Seems Norton Deleted all post about PIFTS.EXe so I don't know what happened but This will have to come out in the open sooner or later.  I just hope it isn't going to be to late.

Update 12:15am 03/10/09*

Seems people have decided to go to the Zonealarm forums to discuss this:

People are clearing wanting to know why?

You can visit there forums here.  I am getting more curious about this little situation and now tempted to stay up all night watching this!!

[ad#digg-right]I also found this forum thread from BuckeyePlanet.  I am seeing more and more people blogging about this.  So this must be something REALLY big.  Keep sending me comments if you find anything else.  Don't forget to add me on Twitter.

This looks interesting:
[ad#cricket-1]
Even more interestingly now, after posting a single post asking about PIFTS.exe, which was deleted, and a subsequent post to another forum asking about the deleted posts, which got deleted, I've now been blocked from creating new posts or replies on the Norton forums. They really don't want to talk about whatever this was.

And doubly interesting -- or perhaps not, who knows -- not sure if this is standard practice at Symantic or what, but opening the PIFTS.exe in a hex editor shows a large section of the end of the file consists only of "PADDINGXX" repeated over and over. I've got some background in programming and can't think of a good reason why you would need padding like that on a legitimate executable. However, if an executable in an update has been compromised it may require padding such as that to match the original executable's file size or something. But that's just pointless conspiracy theorizing that likely has no basis. It would be nice though to hear from Norton about what the **bleep** this thing is.
[Via Zonealarm Forum]

I don't know but I suspecting an update went wrong at least from all the indications I'm seeing.

I will say you have several options available to you:

  • You could get a Free Anti-virus Software

  • You could run without An Anti-virus (Not a great option, wouldn't suggest it)

  • You could do nothing and wait. (My recommendation until I find out the the full story!!)


Please let's not start a pandemic over this, I am however worried because Norton has yet to release any public information about this?  I will update as needed but please people let's not go to OVERBOARD on this!!

Google Get's rid of the Trend "PIFTS.EXE, no long there.  It was there last night.  Hmm even more questions and answers? (Click image to view it!!)

Proof it was there!!



On a side note, I do not have access to this file. I've had a friend who told me about this and I started to investigate it and as soon as I did that Norton started to kill the messages. That when I knew it was something big. That is why I blogged about it. I do not have the program. I just know that it is being searched really hard because I've had more people coming to my site than usual. So please don't ask about samples, you can comment on this or ask questions. I provide this for the community to let them know!!

(Looks like some of this was a 4chan gag, check my other post about it)

Monday
Mar092009

Fake Emails about Windows Support spam!

According to Trend Micro, Some malicious software is being sent to unsuspecting users about Windows SP1 andSP2 having a error that could damage software or even hardware.  See Trends blog with the photos of the fake spam.

[ad#ad2-right]Although from time to time Microsoft does send out security information to Technet subscribers people have also used this in the past to get people to install Viruses and Malware, like this one that installs TSPY_BANKER.MCL. TSPY_BANKER.MCL monitors the affected user’s online transactions and steals banking related information




Microsoft sends e-mail messages to subscribers of our security communications when we release information about a security software update or security incident. Unfortunately, malicious individuals can and have sent fake security communications that appear to be from Microsoft.


[Via Microsoft]



So if you get an email from Microsoft you'll probably want to delete it.  Any Microsoft communications will be sent from the Update center.  You should never install software that is from an untrusted website.    If you are concerned you should check the web and find out what people are saying about the situation and see if it is a scam or true!!  Remember only you can prevent a virus or Malware!

Wednesday
Mar042009

Microsoft Releases the Patch Information for March

Microsoft Has Released the Patch information For march and This is what is expected to be patch on March 11, 2009:

  • Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (Kb949029) -- This security update resolves several privately reported and publicly reported vulnerabilities in Microsoft Office Excel that could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.  (affected System : Microsoft Office)

  • [ad#ad2-right]
  • Vulnerability in Microsoft Outlook Could Allow Remote Code Execution (Kb949031) -- This security update resolves a privately reported vulnerability in Microsoft Office Outlook. The vulnerability could allow remote code execution if Outlook is passed a specially crafted mailto URI. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. This vulnerability is not exploitable by simply viewing an e-mail through the Outlook preview pane. (affected System : Microsoft Office)

  • Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (Kb949030) -- This security update resolves two privately reported vulnerabilities in Microsoft Office that could allow remote code execution if a user opens a malformed Office file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. (affected System : Microsoft Office)

  • Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution (Kb933103) -- This critical update resolves two privately reported vulnerabilities in Microsoft Office Web Components. These vulnerabilities could allow remote code execution if a user viewed a specially crafted Web page. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.  (affected System : Microsoft Office)


These Four are all Critical and should be applied the week of March 11, 2009.  Their are Seven Patches coming out, but these are the main focus.   According to Microsoft they have released MS08-014, MS08-015, MS08-016 and MS08-017 to better help you find out which ones are affected.

Now is the time to get AutoPatcher ready and make sure it is up to date on any patches that might of came out this month that you didn't know about.  Also consider downloading the new version of Anti-virus and Firewall software while you are it.  In case you come accross a rogue virus and need to disinfect it!!  Some of these patches for this month is due to the EXCEL vulnerability that is out right now and is in the wild, so that should be your top priority once Tuesday come around.  Remember hackers will start exploiting these patches on Wensday and you will be racing against the clock.   One last bit of information for the Mac Users you should also apply these patches they are vulnerable to according to Microsoft.  I'll update as more information becomes available!!
Tuesday
Mar032009

Cracking and Warez sites are Host of Trouble!!

It is nothing to laugh at and should be understood that gamers have no freedom right now.   That said this new Variant to Virux Trojan is in regards to Win32/Vitro Trojan.  It seems tobe infecting .exe and .Scr files just like this.

According to Trend Micro:
[ad#ad2-right]
The downloaded malware include variants under the FAKEAV, TDSS, and VUNDO families. Infection chains, however, are notable for the presence of VIRUT and VIRUX malware. VIRUX and VIRUT attacks were initially about the volume of infected PCs. The numbers are massive enough to worry Web users and security researchers: around 20,000 PCs are infected per day
Read more: "Crack Sites Distribute VIRUX and FakeAV"

Now it seems to be more and more sites with getting computer infected. It also seems the Malware writers are using these servers for helping infect essentially gamers computers. So for the time being, if you have a favorite game and you want to:

  • No-CD Crack (This is good for those who want to play the game without the CD)

  • Key Gen Cracks (This is used for pirated version of a game)

  • Update Cracks (This is used to prevent CD checking or Also prevent Version Checking)

  • Game Cheats (This is usually a small program like a bot or some other way for the gamer to cheat)


And should not be Downloaded or USED!! I don't say that lightly, because Gamers feel they should be able to play any game they want. Although this post will probably make the Gamer developers happy, I do this to tell people that these virus writers are using the gamers to distribute the Virus.   I encourage all the gamers out there, that don't want to loose their games to not download any more of these types of cracks.  It seems the virus writers are wanting to infect systems and slow you down.  You don't want to slowed down do you?  Please consider getting a Firewall and a Free Anti-virus software to better protect your system.
Sunday
Mar012009

Facebook Goes Phishing again

In one of my Previous articles about the Koobface Worm, I talked about the way they were infecting the systems and what you need not do.

It seems that Trend Micro has seen an even more rise in people downloading the WORM_KOOBFACE.AZ and Seems to be on the RISE. This is all done with a Social engineering and Has had some attempts before with this little worm on Facebook.

[ad#ad2-right]After your Infected with this new Variant, it searches for cookies and Sends out a message to people from:
* facebook.com
* hi5.com
* friendster.com
* myyearbook.com
* myspace.com
* bebo.com
* tagged.com
* netlog.com
* fubar.com
* livejournal.com

This seems to be a social engineering Nightmare for these websites and as yet are unsure what else it does but it says the same thing it did before by saying "This is a Video of You on the Street." Which is bogus but none the less people click and think they have to download a codec or update their Flash. Social Engineering is on the rise and will be taken seriously. You should read the full report from Trend on what it does but you also should have an anti-virus and Firewall installed to prevent this from happening in the first place. The only true way of preventing this is not to be fooled, you should NEVER Download from a site you don't know or trust. See all the Facebook articles for more information.
Wednesday
Dec312008

Viacom might be going to HULU

According to some of the news post people are worried about Viacom leaving Time Warner. Now Here's where Viacom might be going digital. What do I mean Digital, I am talking about going to HULU. If Viacom doesn't sign a deal with Time Warner, that would leave a space ope for someone else like Hulu.

So Viacom isn't happy with Time Warner, or They want to go IPTV. Some of the Headlines I'm seeing are:

These are just a few that I am seeing pop up around the internet.  So what does that mean to the internet user?  Well On one of there show's like Dora the Explorer on Nickelodeon will begin to stream some of the shows previews on Dec 29, 2009 for it's next show.  When you go to Nickelodeon Site you get this:

nickplea


[ad#ad2-right]Although this just means they want as much money as possible this does give Hulu the chance to start streaming this type of content easier and probably be able to sign a contract with them without much of a fuss. After all Viacom wants to make money some how. So what can you do to get them to go to Hulu. Email Hulu and tell them and tell them you want Viacom to come to Hulu. If this happens so many things will happen with regards to online media.
Sunday
Dec212008

Warning Signs of Hard Drive Trouble

For every computer there comes a time when you have a problem with hardware or software. This is for those who want to learn the signs of possible fixes for having hard drive problems. Although if you know you're hard drive is dieing then you better back it up as quickly as possible. You will of course need to get the back up software to protect your data.  If you have special drivers you will need to backup yours drivers.  If you have an OEM system then you will need to backup the Hidden Partition.


So what are the warning signs of a hard drive failure:


    [ad#ad2-right]


  • Unexpected freezing of Windows -- When Windows Locks up and you have to reboot or getting a Blue Screen of Death.   You have no choice but to restart because you can't do anything with windows.

  • Losing data files -- if you seem to see files being lost or deleted without your direct input.  It might be a sign of a computer virus or it could be a damaged hard drive.

  • Locking up during boot -- this is most common when you have a hard drive failure, although if you can restart and not be a problem then just keep in mind that it might be the beginning.  The more frequent you have the lockup boot problems the more chance of the hard drive dieing.

  • Hard drive isn't recognized in BIOS-- Although this can be a old hard drive, if the bios can't see it then the problem might be a hard drive failure, usually this is meaning you just have to replace the hard drive.  there's isn't much you can do with this problem, just replace the hard drive.  Most of the time it is a problem inside the Hard drive bios and you really can't fix this, you'd have to send it off to possibly save the hard drive data.

  • Clicking, Scratching, Whirling, Grinding sounds from Hard drive -- This is the most dangerous signs of hard drive failure and means you need to get your data off ASAP.  If you want to hear some of the waring sounds of a dieing hard drive click here.


Although some of these can or can not be a hard drive failure, some can be driver issure or disk defragmentation and should be check out to rule out these problems.   There can be several problems that might be easily fixed.  If you think it is a failure you might try Spinrite.  The program is made by Steve Gibson and he actually has a "Absolute Satisfaction Guarantee".  So if it doesn't work or your not satisfied you aren't out any money.  I've used this in the past for hard drives that are dieing so I could get all the important data off before it died all together.  It is essential that if you can get it working for a short time to get a backup.

Disclaimer: Although spinrite might fix some of the problems associated with a hard drive failure, it might not fix all the problems or any problems.   So it is left up to the user to decide if it is worth it or not to buy it.   I don't recommend this for every situation or every problem only for the off chance that it might let you get the important data off the computer before you lose it.  Use at your own risk.

Wednesday
Dec172008

Digital Convert boxes for Feburary 17, 2008

It being close to the change over, I'd figure I'd show you some of them and talk about them. To better help people make up there minds on what might be there choice of a Digital Converter Box. This is to help people get the most out of there products.

The Specs for this Converter is:

Zenith DTT901 Digital TV Tuner Converter Box


21oyeyvylql_sl160_


  • Digital TV Tuner Coverter Box

  • Analog Pass-Through for Low-Power TV Stations broadcasts

  • On-Screen Program Information with Remote Control

  • Simple Connection to TV with supplied RF Cable

  • Parental Control to Manage TV Programs and advanced Closed Captioning


$59.95 Free Shipping

It could be on sale so check the link for more price options.  I also found this one that is a little more expensive but supposed to be better:
GE 23333 Digital to Analog TV Converter Box
41ht9h42hbl_sl160_


  • Smart Antenna Interface

  • Simple Setup

  • Analog Pass Through

  • Dolby(R) Digital Sound

  • Receives Over-Air Hdtv Signals


$76.99 Free Shipping

These are just some of the ones that I saw online to encourage people to get ready for the change over. If you're not you need to act quickly because it will come in the next few months. You will need this if your are using an antenna and have no other way to watch shows over the air. This will only work where there is a signal. If you want to see what digital channels you have in your area please check Antenna Web. There they will tell you if you have any local channels in your area.
Sunday
Dec142008

Signs of a Computer Infection!

So I was thinking this morning what I missed and I totally missed on how you might be able to tell if you have a computer virus. It does me no good to talk about a virus if you don't know you're infected. I was thinking of the times I had a client who had trouble but wasn't what I thought.

So How do you know?


Some people would say it depends on factors but here are what I call clues that make me suspect a virus:[ad#ad2-right]

  1. Slow or Sluggish computers --  Here is what I know if the computer is really slowing down and have a dual core or quad core.  If you are running a system and sees a lot of hard drive activity even when the computer is idle then it might be a virus or it could be a program doing what it is supposed to be doing.  So this is somewhat of an indication but not always.

  2. Slow internet connection on the computer or on the network -- Due to the fact that most people have a router that is connected to all the computers and if you internet connection on all your systems are slower than normal then you could have a virus.  I use Speed Test website to help determine this.

  3. Corrupt files or Missing files --  Sometimes you have a text documents or files that are missing and you have to pay to get them back.   It's an old scheme and usually once your files have been encrypted you can't get them unencrypted.  So this is why I added this one also because it varies from virus to virus.

  4. Programs don't work like they used to --  This is also a very common association with a virus because virus makers don't have time to test it out on a variety.   Most of the time if you get a call that a program is no longer working tat would be the first thing I'd look at, if not check to see what other programs have been installed lately.

  5. In some cases more files are the Hard drive --  This can be a indication of a virus because the virus might be using the system to host files or other such illegal activity.   Although this is happening less and less it can still be a possibility and should be checked out.   I like to use a graphical tree size program to determine if that is the truth.

  6. Pop ups or Browser redirects -- this is a common thing along the way.  It's always the same and saying something like "you have a virus" or "You unprotected and you might have a virus".  The theme here is to scare the user into buying there product that does not do anything.   It sometimes even looks like a real anti-virus program or spyware program but in truth it is just a scam.  In some cases it will send you to a site because it keeps wanting you to buy the product.

  7. DNS Changes on you -- Some hackers like to have you go through there server so they can watch everything you do online.  They are wanting to get the sensitive information of bank account, and other important accounts.  This is really the ones that need to get off your system asap.


[ad#ad2-left]These are the signs I've seen in the past that would indicate a virus but as with any problem.  You will need to check for all the possibilities.   It is always going to be an issue with people because most people don't know about the signs, now you do and you can now be a better computer user.  It is you who can only fight viruses by knowing all the possible system and only you can defeat a virus.  In the next article I will talk about the tools to help you find and defeat a virus.   This will be a big blog post because I have so much to teach and explain.   If you like these post by all means leave a comment and help spread the word.
Saturday
Dec132008

Figuring out the Email-Worm Win32.Zafi.b

This is another just I just saw on the web and wanted to talk about what this little Worm does and what it's known Aliases:

Email-Worm.Win32.Zafi.b (Kaspersky Lab) is also known as: I-Worm.Zafi.b (Kaspersky Lab), W32/Zafi.b@MM (McAfee), W32.Erkez.B@mm (Symantec), Win32.Hazafi.30720 (Doctor Web), W32/Zafi-B (Sophos), Win32/Zafi.B@mm (RAV), PE_ZAFI.B (Trend Micro), Worm/Zafi.B (H+BEDV), W32/Zafi.B@mm (FRISK), Win32:Zafi-B (ALWIL), I-Worm/Zafi.B (Grisoft), Win32.Zafi.B@mm (SOFTWIN), Worm.Zafi.B (ClamAV), W32/Zafi.B.worm (Panda), Win32/Zafi.B (Eset)

[ad#ad2-left]This worm spreads via the Internet as an attachment to infected messages, and also via local and file-sharing networks.
It is written in Assembler, and packed using FSG. It is 12800 bytes in packed form, and 33292 in unpacked form.


This Worm seems to be running through email and file sharing sites, One thing it tries to do is stop the process and deletes:
fvprotect.exe
winlogon.exe
jammer2nd.exe
services.exe

It attempts to detect antivirus program files on the computer and overwrite them with a copy of itself.

[ad#ad2-right]It also attempts to conduct DoS attacks on the following sites:

www.2f.hu
www.parlament.hu
www.virusbuster.hu
www.virushirado.hu

This seems to be a very big virus and can be removed with the use of Kapersky Virus removal tool for free for this type of virus. In order to prevent this virus in the future the user has to remember about not getting opening unknown documents or emails and not running any unkown program from an unknown file sharing.   Also remember you need to have an anti-virus  and also a firewall to protect yourself in the future.
Thursday
Dec112008

Crafty little Trojan:W32/DNSChanger.ARNF

Saw this post and couldn't resist talking about it.   This was talked about on F-secure.    It looks like they use a program call "Homeview Installer" and after you install it you get the Trojan:W32/DNSChanger.ARNF.   So how do you get that off your system?  Before we talk about that, let's talk about what it does.  According to F-secure:

[ad#ad2-right]



This malware is dropped onto the system by Trojan-Dropper:W32/Agent.FLN. It is used to change the DNS settings on a system so that information such as passwords and credit card details can be retrieved.



[Via F-secure]



What you need to do to get rid of this of this Trojan is to scan your system.   You will also need to understand that this is a really good Trojan, it sees to modify your DNS and also your Registry.   Once you located and destroyed it you will then want to remove all your restore points.  After that you will want to check my other resources to better protect yourself.   You are the only one to prevent a virus from getting on your system.   If you like this one check out my other post as well.
Wednesday
Dec102008

Fix Shutdown Problems in Vista!

[ad]
In the Patch Tuesday update, Microsoft quietly released the patch to fix Windows Vista machine shut problems. This patch should of came sooner.

KB957388

Update for Windows Server 2008 and Windows Vista

Install this update to resolve a set of known application compatibility issues with Windows Server 2008. After you install this item, you may have to restart your computer.

This was not a critical update and it seems to resolve so many issues with compatibility.  One thing it seemed to fix on my system has been the shutdown time.  It is now quite fast, it would normally take me 2 to 3 mins to shutdown, now it does it in less than a Minute.   So if you've not installed this update please install it soon.   I would like to know if people are seeing the same thing I am.   I've found a great resource on fixing it if you are still having problem, it talks about how to check your system performance. Although this is been doing it lately with these programs not loaded or even running, they still seem to cause problems so now I get the feeling it has to do with legacy programs.  This should fix most of the problem with older programs.
Sunday
Dec072008

Facebook : Beware Spam for breakfast. (Virus)

In today's society, we've been to complacent with people with people clicking links for the social group. In one such article on Channel Web, a nice little blog, says this:
[ad#ad2-right]


The worm was discovered by IT security provider Kaspersky Lab, which said the threat, Net-Worm.Win32.Koobface.b, is targeting Facebook users by creating spam messages and sending them to the infected user's friends via the site.

"Unfortunately, users are very trusting of messages left by 'friends' on social networking sites," said Alexander Gostev, senior virus analyst at Kaspersky Lab, in a statement. "So, the likelihood of a user clicking on a link like this is very high."


[Via Channel Web]



This seems to be a problem people thinking that a link someone sends them is a real good link but actually is a link to a video site. According to this article the links people are sending are actually a fake video link, telling you have to download some update to flash player, by downloading this program. The user gets involved with the virus and the fun begins. So how can you prevent this from happening, two ways one is a very good group of software to make sure you have the latest and greatest video codecs. That too can be something they'll say you need and if you've already installed this list of codecs then you know they'll not telling the truth and you can quickly get away from the site laughing.


[ad#ad2-left]What's this program name, it is call the K-lite Mega Codec pack. In this Pack you will be able to play almost everything without having to go download another program. This is done by people who want you to have all the latest codecs installed so you don't have to go by a program you'll only going to use once a month.



Once you've done that, you'll no longer have to worry for the most part about codecs. There will be times when you might have to visit that site and update them but that will be far less.


The other thing you must remember is if it says you must update your player. That should be a sign that there is something. I'll always go to the site and check for example Adobe. If it says I need to update my flash I'll manually type it into my browser. This way you will know you have the latest updates, if you need to update the flash player by all means go to here and update.


If you got the virus I'd check out my Anti-virus and Anti-Spyware page and that should show you will you need to get rid of the Virus. This virus is very easy to get rid of, just download any one of the anti-virus software and install it. Don't forget to update the virus database while your at it. That should fix the problem pretty fast. Remember the only way to prevent from getting the virus is YOU.

Saturday
Dec062008

trojan.zlob removal tricks!!

[ad#ad2-right]
Aliases:
Trojan-Downloader.Win32.Zlob.qyl (Kaspersky)
Trojan-Downloader.Win32.Zlob.qzs (Kaspersky)
Trojan-Downloader.Win32.Zlob.qzn (Kaspersky)
Trojan.Zlob.CPP (BitDefender)
Puper (McAfee)
SystemDefender (Symantec)


Trojan:Win32/Zlob.G is a component of Win32/Zlob that downloads rogue security programs, adware, and additional Win32/Zlob components.

[Via Windows Live OneCare]

[ad#ad2-left]This one just popped up today on my radar it seems to be a very low threat on everyone's radar according to my sources say "Trojan.Zlob.G is a Trojan horse that may download and execute remote files and redirect the Internet Explorer home page and search page."  So to remove this little Trojan you would want to download one an Anti-virus and firewall.   Once you install the software the program should fix the problem for you.   This one seems to be really easy to fix.   So Please read my post on how to better protect your self if you want to prevent this in the future.
Friday
Dec052008

Trojan.PWS.ChromeInject.A is not a Firefox plugin.

A new type of malware designed to harvest web passwords has been detected in-the-wild by BitDefender’s antivirus research labs. This latest e-threat – called Trojan.PWS.ChromeInject.A – is intended to be delivered onto a compromised computer system by other malware for subsequent download into Mozilla Firefox's Plugin folder. Once installed it gets to work every time Firefox is started.

[Via Bitdefender]

[ad#ad2-right]So having seen this I thought I'd come up with ways around this to better protect yourself.  One way to prevent this from getting your sensitive data is to get a program like Sandboxie.   You could stop using Firefox that would be silly, because right now Firefox is more secure than Chrome and Internet Explorer.   I'd also suggest checking out my Anti-spyware page and Anti-Virus page and get some more protection.

The key to this virus protection is just be cautious of where you go and keep all you system update to date to prevent all this from happening.  It is also advisable to not have your passwords saved on Firefox, you should use something like Roboform, it is free  to download and try.  It will encrypt your passwords so if they don't know the master password then they are out of luck.  Roboform is also good for coming up with some strong passwords.  Just some suggestions to prevent from people seeing your sensitive data, you don't want anyone to get that data.
Friday
Dec052008

Are you patched, Secunia Says NO

Secunia BlogThink you've got nothing to worry about, according to Secunia 98% of computers are not fully patched and are vulnerable to some kinda of attack. [ad#digg-right]So I wanted to talk about this a little and give you a few good ways to make sure you are patched.  There are several ways to get your system up to almost 100%.




[ad#ad2-left]Some things to do is make sure you have your Windows systems updated.  This is easy to make sure, if you have an internet connection you can just check for updates.  If you don't know how to do it, it is quite simple, Just go here.    If you have Windows Vista all you have to do is hit Start and type in the search box "Windows Update" and hit Enter and you will be taken to the update page.





If you have a system that is off of the Net you could use the Clone of Autopatcher Program to do it for you.   You also need to update all your secondary programs such as Audacity, Open Office, and other programs that you use weekly.




[ad#ad2-right]If you don't know what you need to update sometimes just having a program check for you can make a really good difference.   The one that I like to use is Appsnap and it actually searches you computer to see what might need to be updated.   I also suggest for the final suggestion is check out my Anti-Virus and Anit-Spyware Resources and make sure you have a firewall and anti-virus software.  This will greatly reduce your chances of getting a virus but that isn't all you have to be careful on what you click on read this article on Some Important programs to prevent yourself from having viruses and Malware!! Read that carefully to better understand how you can protect yourself in the future.
Thursday
Dec042008

Viacom and ATT layoff some people. (12,850 People)

Today, we are announcing a company-wide restructuring plan that includes staffing reductions in all divisions. This will result in a reduction of our worldwide workforce of approximately 7 percent, or about 850 positions. We are also suspending salary increases for the Company's senior level management in 2009. In addition, after a comprehensive review of our operations, we will write down certain programming and other assets. These three actions will bring us significant cost savings and other efficiencies.



[via Gawker]



[ad#ad2-left]This is a Sad day for the telecommunications industry both AT&T and Viacom are laying off people. According to reports Viacom will lay off around 850 people. ATT will layoff 12,000 Jobs. Here's the quote from Associated Press:



AT&T Inc. joined the recession's parade of layoffs Thursday by announcing plans to cut 12,000 jobs, about 4 percent of its work force.



[Via Associated Press]



So in all today total that is 12,850 people who are going to be laid off. This is another set of layoffs but isn't the last to see the whole list of of Layoffs in the Tech industry that I've talked about please click this link. You may find some usefull tidbits if you search my blog enough, I've got some great tips on getting hired and what you should do to be prepared.