Help Support my Blog!

Virgin Mobile USA
Glasses USA
Amazon
Newegg
VPN4ALL
Netflix
Hulu
CafePress

 

Subscribe to Paul’s Tech Talk Affiliate Marketing Blog

Subscribe to Paul’s Tech Talk Science Fiction Blog

Subscribe to Paul’s Tech Talk Scams Blog

  • Acer 11.6
    Acer 11.6" Laptop 2GB 16GB | C710-2856
    Acer

    Currently  in process review this Acer Chrome book and boy is it nice!

Navigation
Sponsors

Entries in scam (37)

Friday
May222009

Personal Antivirus just scareware

I was going through checking a site brought to my attention from a reader and I went there and yep he told me it might be [intlink id="3114" type="post"]scareware[/intlink] and it was:

mailware-live-pro-scanv1-1

If you click "Cancel" or "Ok" you will still get to this page:

mailware-live-pro-scanv1-2


[ad]It is on the Malicious site : http://maleware-live-pro-scanv1.com.  You can also see it tries to scare you with the tactic of  knowing your IP address and where you are in the world, it's called Geo-ip Location.   It tries to convince you have a virus, but in reality it is just trying to scam you out of money.   Although if you go to the site you will see that there is no company information.  That is the first clue this is a scam or scareware.


Personal Antivirus gets installed in unsuspecting computers by way of exploits, backdoors, Trojans, or unsafe downloading practices.   This usually means that if you have it you should remove it by any means necessary because this software has been know to cause more and more trouble as time goes by.   This software is fake ware, it tries to tell you have a virus and that they can get rid of it.   In fact, this software is not designed with Antivirus engine in it but to illicit pop ups and warning to raise the users security concerns about the computer in question.   Downloading programs from bit torrents or other unsafe ways can and most likely will have these types of programs installed alongside the program you wanted.


*[intlink id="4403" type="post"]Personal Antivirus Scareware Site and How to Remove it[/intlink]*


Threat to System : Moderate



[rating:4/5]




Advice : Do a Complete system scan and make sure you don't have any more hidden malware. Most of the time if you have one Trojan, you usually have more.  Personal Antivirus has been know to have some type of program installed on the system in question and should be removed.



I recommend :

[ad#SUPERAntiSpyware]

On a side not, if you are wondering why I think I know I am not infected with these virus for those who are probably asking that question is because I already have a [intlink id="2205" type="page"]dependable free anti-virus[/intlink] software installed.  Don't forget to visit the Forums for other ways to watch for spyware or scareware.   I will always recommend buying antivirus software from vendors you know and not ones that are fly by the night scams.

Thursday
May212009

Facebook and Twitter Phishing going on today!

According to Techcrunch we have one phishing site ground around peoples inboxes on facebook with it say "Check areps.at".  You go to the site and you will think your at the facebook login but your not.  I wouldn't suggest going to any of these sites, it has been reported by Phishtank.

[ad]Some of the sites to avoid today are : "nutpic.at, bests.at, areps.at, kirgo.at" each site will make you think your at facebook but this is what most will call a [intlink id="3419" type="post"]Phishing scam[/intlink].  Some other things to avoid are some Twitter phshing going on today as well.

According to Trend Micro there is one where the url looks like it is a twitter url but isn't (tvviter[dot]com).  The site is what people would call a typosquatting site.   This makes people think they are on twitter but aren't.   If you go to these to sites and have given out your passowrd, it is strongly recommended that your reset them:

Facebook password reset page

Twitter password Reset Page

If you would like to know more about what phsihing is please check out my blog for more information.  Don't forget to check out the forums for more information on this or just to talk about anything on your mind.

*Some reports I am seeing is some of these sites might be trying to get you to install the [intlink id="2249" type="post"]Koobface virus [/intlink]so please be careful, will update when I find out more.*
Wednesday
May202009

Spyware : Michelle Obama's Ta's Ta's Video

I love this one, I was reading the Sans Report about Michelle Obama Ta's Ta's on Video.  I wanted to investigate this a little further so I went searching around.  I found some comment spam links to a site I will not talk about the links directly.  The site however had a fake video on it :


michelleobamatoplessfake



It looks like if you hit Cancel or Details it keeps trying to tell you need to install an ActiveX Object.   It also makes the user think that there is only one option to use right now.   As you can tell  it makes you think you can't cancel or get details but I did.  I tried to cancel and it kept on popping up trying to get you to install this active X installer.   AVG detects it as:


michelleobamatoplessfake1



[ad]This proves the fact that any Anti-virus software is better than nothing at all.   I also  have talked in the past about [intlink id="2991" type="post"]fake codecs and how they are used maliciously[/intlink] to spread malware to people who aren't up to the job.   I didn't take long to find Phrases such as "Michelle Obama Topless" or "Michelle Obama Topless Video" to find spam comments linking to sites that are hosting these types of malware.  It seemed that in order to get out of the cycle with the Malware site, I had to do a CLT-ALT-DELETE and End the process of Internet Explorer process from Task manager.  It was an infinite loop and could not be closed any other way.  upon trying to go the link again it seems to be a random redirection every time you visit that site the next time I went there, I had a scare message pop up telling me:

michelleobamatoplessfake2



As you can tell this [intlink id="3397" type="post"]pops up with scareware[/intlink] instead of the video and tries to tell you have a virus and you should run a free scan from the site of their choice.   This is an old tactic and still being used but funny if you look at that message one you know it is from a "Webpage" and two there are at least one grammar error?  Can you see it?

You're best bet is not to go clicking on links that people have left in comments.   I am so glad I have moderation turned on and I have to approve each and every post someone comments on.   This is the only way I know how to prevent from being used in the spam campaign.  Remember it is time to update your [intlink id="2205" type="page"]Anti-virus and Firewall [/intlink]if you don't already have it.  Don't forget to visit the Forums and help discuss this problem in detail.
Saturday
May162009

Skype has some Auto-Bots and Friendjungle.com

I was on Skype today and got an instant message from some girl:
skypespam

The Instant message goes like this:
hello there! I was checking people near me and i came across your page, and you seemed interesting.. ;)


Mary Fowler says: Im not crazy about Skype though ... want to check out my picture and profile ?

use this link: http://www.matchshake.com/?id=4004&profile=rockergrl82


you just sign in (it's free) to get to me, my username's rockergrl82.

[ad]It looks like this is an Bot to help fool you into thinking it is a real person.  The link they give me is a redirect link that lands me on "Friendjungle.com".  I am sure no matter what you answer with the question it asks that it will still send you a link.   You can however tell Skype to only allow chat from people on your contact list but that is totally up to you.   There is a story from the Rip-off Report about Friendjungle.com, so it looks like they went from text messaging to Skype chat.  According to Yahoo Answers, this is more or less a way for them to get money from you.   You sign up and before you realize it they are charging your card, so it looks really shady.   Although, To Friendjungle credit, they do have a scam section to help you report these types of incidents.   I don't know if this works well or not but you can at least try.

There are some good comments about this Friendjungle on other sites that really make me wonder if they just don't want your money.  If you get this type of message from someone, either through SMS or Skype, I'd just go along with my life and not register there are more better places to go to find your true love.
Tuesday
May122009

When not to post #twitterpornnames

twitterpornname-security1


I've heard others call this a scam:

twitterpornname-security2


[ad]Now Although I know PCworld has made everyone paranoid that this is a scam.  I want to remind people that it was probably just a for fun.   According to Graham Cluely's blog, He points out why you shouldn't tell people the important information.


I see no evidence this was done to gather your information but Pcworld has sent out the warnings and made people think this was a scam, or a Phishing attack.  Although this could be used to get the information needed for your Gmail or other accounts.


I do recommend deleting those tweets and reminding people that you are the only ones that can prevent identity theft.  Trend Micro talks about this very detail about the subject but again they don't think this was conceived as a phishing attempt.   I'll let you decide but remember tweeting that it is a scam will only keep it on the trends, your best advice is just go on with your life and tell everyone to delete that sensitive information.

Friday
May012009

New address cnuncn.com, old Yahoo email

In my Previous Email about yahoo [intlink id="3330" type="post"]email accounts being use[/intlink]d and then their contacts being deleted.  I recently came across another post about this email but with a new address so I go to the site and see and It looks like the old one:


cnuncnyahooemail


It looks like this site was registered on 9-27-08 and Looks like the other site nekcn.com:


nekcnyahoospam1



[ad#cricket-right-ez]As you can see this looks like the other one, both of them are Chinese websites.  I have heard from one or two users that this is a Scam website trying to scam you out of money.  I am also sure the scammer just started doing this with the emails due to my previous post about this site. I wouldn't purchase anything on these sites. I have created a Forum area to discuss Email scams like this one and warn others of new scams like this one.   I hope you warn the person who sends this out that they have been compromised and should reset there password.  This is one way to gain control over your account.

Remember there are sites out on the net that [intlink id="3407" type="post"]would like to get your email account or your Facebook account [/intlink]and spam people.  The reason being is that contacts people have with each other are more likely to get through the spam filters to the person.   The Email reads:
Dear friend:

What are u doing these days?I am going to recommend a Eshop to you.Yesterday I found a web of a large trading company from China,which is an agent of all the well-known digital product factories,and facing to both wholesalers,retailsalers,and personal customer all over the world. They export all kinds of digital products and offer really competitive and reasonable price and high quality goods for their clients,so i think you will make a big profit if you did business with them.And they promise they will provide the best after-sales-service.If you are interested to do business with them,in my opinion, you can make a trial order to test that.

Their Web address: www.cnuncn.com or www.nekcn.com

[Via Yahoo Answers]

In case someone has a question about this, please feel free to post to Forums and someone will answer it.  It is a good idea to install [intlink id="2205" type="page"]Free Anti-virus and Firewall[/intlink] software to better protect your system.
Monday
Apr202009

A look behind SmartEcard.COM

I saw that Graham Cluely Blog talked about the front page and How this ws used on twitter but Most people who did the IQ test still need to fix your Cell Phone account:

smartecardtest


If people didn't scroll down in the other windows you would of never know there was something you need to watch for.  After you do the 5 questions , you will see this:


smartecard3


then you enter that information and hit continue and it comes up with this:


smartecard2


As you can see the people who put in there Cellular Numbers will want to send an text Message with STOP to short code 86455.  It looks like this is a Subscription service where you pay a monthly for something like this and that you don't need it.   I would guess somehow someone is getting money for each and every person who signs up.  This is most likely a Commission based and the person tried to get people to sign up through the website by saying you have a Ecard or some other thing.

Wednesday
Feb252009

TINYURL being used by scammers and hackers -- How to prevent it!!

With Phishing attempts going on with the TINYURL redirect website, I thought I would show you how you could prevent from going to a site you don't want. Tinyurl.com has a great little feature, although it is a feature based on your cookies. It however will help prevent you from going to a site that you don't know anything that about. It's called the Preview Feature, and is available to any user who wants to use it.

previewtiny


As you can see if you enable it and you go to a click on a tinyurl, you will see this:

http://tinyurl.com/6t7ukk

previewtiny1


[ad#ad2-right]As you can see, if you click any TINYURL links you will automatically be told where that link is redirecting you to. This however only works with there being a cookie left behind in your system to let tell Tinyurl that is has to show the link first. So if you clean your cookies out from time to time, you will need to enable it every time after you clean the browser cookies. This will help prevent you from being phished because you will be able to tell if it is the right site in the first place. If not then you don't have to visit that site. This should be enabled on all Short URL Sites, I hope they make it a mandatory for any site that redirects. This would help stop phishing and scammers because they can't hide behind unknown url. Only time will tell though, these sites are always going to have problems but this would solve so many problems.
Sunday
Jan042009

Old phish becomes new again

According to some reports, this phishing has started up again and is now changed a little web address and when you go to the site it looks like:
Twitter Phish spam

[ad#ad2-right]If you sign into this website with your twitter account information, it sends out a Direct message with these links in them rosalierebyb.blogspot.com redirects to http://twittyblog.access-logins.com/login and the only way you can fix this is to CHANGE YOUR PASSWORD.

I'd also suggest getting a password manager so if you use just one password for all accounts you will easily be able to change them and make the passwords much harder to hack. You do not want your passwords stolen do yo? I suggest Roboform it works really well with password management.
Saturday
Jan032009

New Twitter Phishing -jannawalitax.blogspot.com

I read Chris Prillo's Blog about this and wanted to investigate this even more. When you go to this site it looks like:

http://twitter.access-logins.com/login/ --Phishing site

When you go here the web address is : http://twitter.access-logins.com/login/ and it looks like it was a redirect form the blogspot.com site.   so what I did an experiment and just took off /login/ on the address and this pops up:



Face book fake -- http://twitter.access-logins.com/
[ad#ad2-right]

This website looks to like a facebook website so now you have to ask where is this at: Hunan China.  After I did a whois look up it looks like China is at it again.  These are trying to get on to your account to either spam or use it to get people to install software.   So what are things you can do?  If you have a question about this always check it out.  That is why I like to check everything out with these types of phishing scams.   I don't know why they want twitter accounts, I just know they are doing this now.   So if you get this message:




hey! check out this funny blog about you… jannawalitax . blogspot . com



Just ignore it and possibly blog the twitter account.  That is probably a bot or someone's account been hacked and is no longer valid.   I'll leave that up to you on how you handle that account.   This is to warn people about this account and warn people. Help Protect your password with Roboform, don't just use one password for all accounts.  It also seems to be possible worm, if you think your infected check out my resource on remove the worm.  Here's the link to that talks about this being a worm.

Friday
Jan022009

Are you worried about your identity?

So after the fiasco of the other day, I decided I will talk about security and why you should worry about new websites that you have never heard of.   People are not worrying about there identity and keeping there identity safe.   You see whenever someone signs up to a service without thinking about their password being stored or even used maliciously.   You see when most people don't use more than one or two passwords for all there accounts and then you use the same password with a new website.  Are you asking for your identity to be stolen?  In one of my previous blog posts I talked about not having any privacy on the internet.

So How can you protect your privacy?


When ever I come across a site that I don't know about and I want to protect my account from being compromised I find out what I can from several places:

  1. [ad#ad2-right]Google -- Yes this is quite common to use to find out about what people are saying asking the keywords like is it a scam or what people are saying about the site?  This can be very useful to make sure I don't get scammed by a company for instants the Nationwide marketing scam.  Although this is really important when you get things that sound questionable.  This can be very useful with regards to keep your wallet safe.

  2. Whois Network -- If there is a site you've not heard about and have a question about it you can always do a whois lookup.   This is a great resource for finding out how long the site has been up and who owns it?  The problem with this is most people who have a website aren't worried about security and privacy.   So you make sure this site isn't a phish site or to make sure the site isn't being used improperly.

  3. Sitetiki --  a good site to do some research.   It's a wiki like Wikipedia but for websites and if they are good or bad.  It also has a spammer list for people to watch and make sure not to go to.  These sites are usually redirect spam sites uses for email.


What about Personal privacy?


With this I also want to talk about security online to prevent people from gaining access to your accounts online by guessing the password.  Some sites also like to phish for your account information and use the information gained to take control over your account so here are some useful links to help protect your account information:

  • [ad#cricket-right-ez]Roboform -- This is good for generating a really good random password and remembering it.  This will keep people from guessing the password and also make it easy to come up with another good password.  This will also fill out the required site forms that usually use to sign into website.

  • A good VPN Service --  If your like me and you have to use free wifi from time to time and want to make sure you have privacy on the net.  This is good for security on any open wifi network and you don't want to have anyone watch you while your browse online.  In case someone is interested what VPN's are used for here is the link to let people understand it better.

  • Perfect Paper Passwords -- This is coming from Security now Episode 115 and he talks about this to better help people make the best possible passwords.  Listen to it and it will help you understand more about security.


These are just a few ways to prevent people from gaining access to an account.   After doing some research on this and thinking about this in bigger detail.   I would like to make a public apologies about the fiasco yesterday and what happened.  In all truthfulness everything didn't seem right with the doings of the going on with website.   I also was worried about the twitter spam it was sending out as you started the service.   I didn't know until later that it was a real person trying to make a product twitter users could really use.   I have learned from my experience and I will work harder next time and not be so quick to act next time.   If I was the company that bought that site, I'd also offer a job to both of them for being intuitiveness on coming up with a really good product.
Tuesday
Dec092008

The Next big Wave of Layoffs is Sony. (9,000 workers)

In a report from Engadget, there seems to be more Layoffs going on.   One such one is Sony.  Here is what Engadget said:


[ad#ad2-right]


The bad news from the Japanese consumer electronics industry continues. Sony just announced plans to cut about 8,000 global jobs from its beleaguered electronics business while making unspecified reductions to its seasonal and temporary workforce. The move, as Sony explains it, comes "in response to the sudden and rapid changes in the global economic environment." Ominously, it looks like Sony will also be raising prices in the countries where "Sony makes significant sales" (read: US and Europe) if we're reading this statement correctly:


[Via Engadget]


[ad#ad2-left]In Today's economy, you need to be prepared.  So I thought I bring back some old Favorites of mine and talk about them.  To see the other layoffs that I've talked about CLICK HERE.   If you wanted to know what you can do to be prepared here are some great resources for people who are worried about there jobs:



If you have any others you would like to suggest please leave a comment and let everyone know.   These are hard economic times and we all could use the help.

Monday
Nov102008

Antivirus Professional 2008 uses Scare tactics

[ad#ad2-right-1]
We came across a rogue today called Antivirus Professional 2008 that uses GeoIP Lookup as part of its scare tactics. This site uses Flash and script to create the effect of an online scan, that then attempts to push an installer at the visitor. The NoScript extension for Mozilla Firefox is an excellent way to mitigate against this kind of garbage.

[Via F-secure]



It seems that there is a site out there, that seems to be trying to scare you into downloading there software. If you have any questions about this site please feel free to check out what I've found out:
Registration Service Provided By: ESTDOMAINS INC
Contact: 1.3027224217
Website: http://www.estdomains.com
Domain Name: ANTIVIRUS-ONLINE-SCANNER.COM
Registrant:
N/A
Serento faloimitator@list.ru


Minskay str. 27-14
Kiev
Kiev 237293
UA
Tel. 044.2901732
Creation Date: 07-Jun-2008
Expiration Date: 07-Jun-2009
Domain servers in listed order:
ns2.antivirus-online-scanner.com
ns1.antivirus-online-scanner.com
Administrative Contact:
N/A
Serento faloimitator@list.ru


Minskay str. 27-14
Kiev
Kiev 237293
UA
Tel. 044.2901732
Technical Contact:
N/A
Serento faloimitator@list.ru


Minskay str. 27-14
Kiev
Kiev 237293
UA
Tel. 044.2901732
Billing Contact:
N/A
Serento faloimitator@list.ru


Minskay str. 27-14
Kiev
Kiev 237293
UA
Tel. 044.2901732



[ad#ad2-right]Now as you can see this site is located in Russia, and if that's the case it is probably some virus itself to take control of your system to do what they want with it. So you best advice is if you think you have a virus then check out my recommendations these are all free to download and try. Unlike this site, they are legitimate and actually do what they promise.  If you want to email them you can but It don't think it will help.

*UPDATE on that Website*


According to F-secure that site is now Suspended.  Great job guys.  We are now fighting these people even better than I'd thought.
Sunday
Nov022008

Sites that you need not Visit:

[ad#ad2-right]I've had some Anti-virus problems in the past few weeks and have been trying to see if it is my system or if it was just luck of the draw.  So I did some research and found some sites that you should not go to, or download from.   These sites have been know to spread the fake anti-virus malware software.   So I wanted to warn people of some common websites that have been known to have viruses on them:




  • hxxp://movieportal2008q.com/freemovie/Movie/xxxx/x/ -- this site usually tries to send you the "Trojan.HTML.Zlob.AG" Virus.


  • hxxp://porntubedot.com/xxxxxxxx/WatchFreeMovie.php --This site usually tries to send you the "Trojan.Dropper.SMN" Virus.


  • hxxp://handballfondi.it/xxxxxx1.php -- This site is one of the new Malware sites that looks like Youtube,   When you go to this site they say you need a special to play a video clip.  Most of the time when you get something like this, it is going to try to install Malware. A good broad set of Codecs that you may want to download is called Klite Mega Codec, which if you us that you should never need to download any other codec to play a movie clip from any site online.


  • hxxp://0scanner.com/---censored---/ --  This site usually tries to send you the "Adware.FakeAntiVirus.L" virus.  Another site trying to install malware. [ad#ad2-left]



If you want to check your system, here are some places to go to get a free Anti-virus check:

If you have any other ways sites that we should avoid by all means comment about it. I would love to hear sites that you know are bad!!
Tuesday
Oct282008

Did you Recieve a Check from Shadow Shopper? (Scam)

I just got done checking my sources and here what I know and I will quote:
Will ShadowShopper.com ever send a job to me via regular mail?
Never. We will always contact you via email. If you do receive a letter in the mail claiming to be from ShadowShopper (with a realistic looking logo) and asking you to mystery shop by cashing a large check THROW THAT OFFER AWAY. It is a Nigerian check scam ring pretending to be Shadowshopper. The scam is run out of Canada and the UK, and the check will bounce. Remember, ShadowShopper provides you with hundreds of job opportunities, and for your protection, we do it only via email and our website.


[via Common Questions]

It is a Scam to send you money Via the postal mail and that is why you must not believe what you get in the mail. This is in response to someone telling me they got a check with a different name but for the same reason to cash the check and send money to them.

[ad]



If anyone has any information they would like to add about this by all means talk about it in the comments. I want to hear where the check cam from or who sent it. You should also check out my other article about Nationwide Marketing that is also a Scam.
Page 1 2