Help Support my Blog!

Virgin Mobile USA
Glasses USA
Amazon
Newegg
VPN4ALL
Netflix
Hulu
CafePress

 

Subscribe to Paul’s Tech Talk Affiliate Marketing Blog

Subscribe to Paul’s Tech Talk Science Fiction Blog

Subscribe to Paul’s Tech Talk Scams Blog

  • Acer 11.6
    Acer 11.6" Laptop 2GB 16GB | C710-2856
    Acer

    Currently  in process review this Acer Chrome book and boy is it nice!

Navigation
Sponsors

Entries in Spam (56)

Wednesday
May202009

Spyware : Michelle Obama's Ta's Ta's Video

I love this one, I was reading the Sans Report about Michelle Obama Ta's Ta's on Video.  I wanted to investigate this a little further so I went searching around.  I found some comment spam links to a site I will not talk about the links directly.  The site however had a fake video on it :


michelleobamatoplessfake



It looks like if you hit Cancel or Details it keeps trying to tell you need to install an ActiveX Object.   It also makes the user think that there is only one option to use right now.   As you can tell  it makes you think you can't cancel or get details but I did.  I tried to cancel and it kept on popping up trying to get you to install this active X installer.   AVG detects it as:


michelleobamatoplessfake1



[ad]This proves the fact that any Anti-virus software is better than nothing at all.   I also  have talked in the past about [intlink id="2991" type="post"]fake codecs and how they are used maliciously[/intlink] to spread malware to people who aren't up to the job.   I didn't take long to find Phrases such as "Michelle Obama Topless" or "Michelle Obama Topless Video" to find spam comments linking to sites that are hosting these types of malware.  It seemed that in order to get out of the cycle with the Malware site, I had to do a CLT-ALT-DELETE and End the process of Internet Explorer process from Task manager.  It was an infinite loop and could not be closed any other way.  upon trying to go the link again it seems to be a random redirection every time you visit that site the next time I went there, I had a scare message pop up telling me:

michelleobamatoplessfake2



As you can tell this [intlink id="3397" type="post"]pops up with scareware[/intlink] instead of the video and tries to tell you have a virus and you should run a free scan from the site of their choice.   This is an old tactic and still being used but funny if you look at that message one you know it is from a "Webpage" and two there are at least one grammar error?  Can you see it?

You're best bet is not to go clicking on links that people have left in comments.   I am so glad I have moderation turned on and I have to approve each and every post someone comments on.   This is the only way I know how to prevent from being used in the spam campaign.  Remember it is time to update your [intlink id="2205" type="page"]Anti-virus and Firewall [/intlink]if you don't already have it.  Don't forget to visit the Forums and help discuss this problem in detail.
Wednesday
May132009

Casino Spammers still user Yahoo for Spam : Could this be Malware?

It just shows you just how one Geocities was taken down by Yahoo who owns it, the spammers have to come up with more ways to get you to download there software.

[ad]In my previous post about [intlink id="3199" type="post"]Casino programs[/intlink],  They were using Geocities to host the page for the link to the download.

casinosmartdownload


It seems to be linking to "http://bestwinscasino.com/SmartDownload.exe".  From [intlink id="3199" type="post"]previous post[/intlink] I talked about what that program did but I wanted to do another test with CWSandbox and see what has change. It looks like they must be having problems lately,  So If you want to do your own test and send me the link by all means.  I don't know what is going on but, it probably is like the other post about wanting to do some bad things.  Virustotal has some anti-virus programs flagging this so I am unsure of the Harmlessness of this file but I wouldn't install this software.  According to Avinti this program is a trojan dropper.  So Iwill let you decide on installing this software or not.


While the CWSndbox checks for malware, I went to Whois and looked up the domain.   Very interesting,  According to Whois this domain is located in China?  You don't say, we've heard a lot of stuff coming from China from Graham Cluely Blog.  So it only makes me wonder what they are attempting to do now.  I do know never download a file you haven't heard off


This is a good time to install some [intlink id="2205" type="page"]Free Anti-virus and Free Firewall [/intlink]software to better protect your system.

Monday
May112009

Email from Inspot : STD? I don't think so!

The Email looks like this:
stdspam1

[ad]It looks to be from Inspot.org.  I thought it was some malicious site with software but I couldn't find it.   I imagine this is trick because I've been faithful to my wife since we got married and I've seen the doctor and gotten blood taken from me.

This is most likely an awareness, if you have a regular family doctor and you want to get tested that would be my suggestion.   You don't have to go to this place.  I am sure I don't have an STD because if I have it my wife would and she had 3 Kids so they would of found out.   I know of only one person I had had contact with before my wife and I also know where she lives, she had kids also.  So I would of found out way before this like 5 years ago.

Anyway this is most likely a trick if you see the last line "Internet Notification Service for Parters or Tricks."  That tells me this a joke but If you are worried go see you doctor, just to be cautious.   Although this isn't security related it is always good practice to get a checkup from time to time.
Sunday
May102009

TweetTornado and What that means to Twitter

I had an interesting person follow me today and I want to talk about How Twitter Needs to fix this problem:twitteruserspam

[intlink id="3501" type="post"]In my previous post[/intlink], I talked about Twitter needing to fix spam problems and here's why.  It's Called Tweet Tornado and you pay $100 for this program a Month.  On the Page,  they talk about downloading this software and using it:

tweettornado1

[ad]Now as you can on there website this plainly states this is SPAM.   I wouldn't install this software or even use it because  of the possibility of having a Virus, Trojan, or even Malware attached to the program.  I can say now that what I've seen of this website is that Twitter needs to come up with a way to fix this problem.  I must warn you that if you do start using this software, you might end up with not internet or even worse if Twitter decides to come after you for damages to bandwidth.   This  software violates Twitter TOS:
You must not abuse, harass, threaten, impersonate or intimidate other Twitter users

You must not modify, adapt or hack Twitter.com or modify another website so as to falsely imply that it is associated with Twitter.com .

You must not create or submit unwanted email to any Twitter members ("Spam")

As you can tell by using this software you are using a Bot that one probably is Spamming by means of either your current users or creating accounts and using the account to post a message with keywords.    This will ultimately come down to Twitter to fix problem because this will create more bandwidth problems for Twitter and will start costing money for Twitter.   Twitter users want this to be a free service but sooner or later if Twitter doesn't do anything Twitter users will start paying for their mistake.   Twitter will need to Modify it's Terms of Service to Help prevent spam on the network because they have a Duty to it's users to make this a safe place for teens and young children because some of these sites as you've seen on [intlink id="3501" type="post"]my previous post[/intlink] are not safe for kids.   Twitter needs to consider that there are Young people on their service Teens and Kids over the age of 13 unless Twitter wants to make it so you have to be an Adult to use there service.  That could happen but I am sure this will not happen.

I also did not directly link to the website and I also made it so you can't find the website easily but If twitter wants to know the website they can email me and I'll share them the website, I have no problem tell them!   I post this to show how Twitter needs to think about changing there TOS and also implement changes to ways to help prevent spam.
Saturday
May092009

Come on Twitter add Tweet filters -- Ways to prevent twitter spam!

So I am on twitter tonight and I find some common themes:

  • [intlink id="3493" type="post"]Have you ever heard about paid surveys ? I'm making way over $4000 per month working part time .www.hothotjoboffers.com [Keyword][/intlink]

  • Visit www.nakedoncam.info for 100% FREE LIVE CAM GIRLS! #Lobster Jeremy Mayfield Wolverine #startrek Happy Mothers Day


[ad]As you can see this is starting to get bad.   I don't know why Twitter can't fix this, by making filter rule that prevent new users from posting the same thing others have or even putting in some Captcha's and Email verification.  This would stop it really quickly but I am sure I would hear from people that these wouldn't stop them from coming.  Yes that is true but it would stop some to a lot of them from posting.   They want people to come to there site and they are abusing the Twitter.

On any given day you can search for anything with twitter and come up with some valuable information.  Now this seems to be more and more spam.   There needs to be a way for twitter to stop this but I guess they dont' want to ruin the experience for new users.

As a long time user of Twitter, I would like to keep using it but since Oprah came to twitter it seems [intlink id="3344" type="post"]Oprah[/intlink] has brought some media attention to our little universe and that in turn has brought the spam people.

Twitter needs to get it's act together and come up with a way to fix some of these types of spam before it becomes to hard to use twitter.  This also causes load issues with bandwidth and other such problems when Twitter is abused you see the result.   So I hope people retweet this post and tell people to look at this and then tell Twitter to Fix this problem.   The more that tweets to fix this problem the more they will listen.
Saturday
May092009

Hothotjoboffers equals Twiitter Spam

Saw this on the Twitscoop API and had to talk about it:
hothotjoboffersspam1

If you go to the site Hothotjoboffers.com you will be redirected to:




hothotjoboffersspam2 www.makemoneytakingsurveys.org

Now I know more about this then anyone.  I see these types of scams where you can make money by doing survey's but there are some common princples to consider.  Although I have real doubts to this site because when you try to exist it displays:


hothotjoboffersspam3



[ad]

I always wonder why spam and other sites alike try to persuade you to stay and look.  When that happens I am thinking to myself, "Yes I am sure and that little box really makes me mad".   I assume someone bot is making the post to twitter and I wish Twitter would create a rule for this.   This would stop this type of spam from getting to us and others.   Same Text coming from newly created accounts less than a hour with let's give it 5 max should be prevented from posting until they are verified by either email or other such ways.


I don't know if you can truely get paid for doing surveys but I know if I did want to I would look for sites that are free and not ones where you have to pay to find good surveys.   This just sounds like a waste of money and time.

Wednesday
Apr152009

Dear Friend Spam Emails from Yahoo

The email from our[intlink id="3233" type="post"] old friend has come back[/intlink] into now compromising Yahoo accounts by sending out this email:
Dear friend:
What are u doing these days?I am going to recommend a Eshop to you.Yesterday I found a web of a large trading company from China,which is an agent of all the well-known digital product factories,and facing to both wholesalers, retailsalers,and personal customer all over the world. They export all kinds of digital products and offer really competitive and reasonable price and high quality goods for their clients,so i think you will make a big profit if you did business with them.And they promise they will provide the best after-sales-service.If you are interested to do business with them,in my opinion, you can make a trial order to test that.
Their Web address: www.nekcn.com

In what seems to be the way of this advertisment company, it seems they have been doing what they did with Hotmail.  Deleting your contact list and emailing your friends with this message.  Now I am thinking it is being done by them [intlink id="2660" type="post"]Phishing for the password and Account name[/intlink], they probably set up an web page to look like Hotmail or Yahoo.  One thing to remember to do is check to see that you address bar looks like this:

yahoomailloginYou should make sure you see the "https", meaning that is a encrypted login and also make sure you see either Mail.yahoo.com or Login.yahoo.com.  If you see anything else included in your the screen like maybe a .ru or .pl then you aren't logining into the true yahoo account.  Obviously the website shouldn't be trusted until they advertise the right way, and find ways to advertise online other than spam.  If you get an email saying you need to do something with your Hotmail account or yahoo mail account you should not click any links and go to the site manually to investigate the problem.  You should never click links in email that you don't know where they are going.  Thanks to Jazzcorner for Alerting me that they have started to do this with yahoo.  I am betting the next one will be for Google Mail, or Gmail as some will call it. It wouldn't hurt to have a [intlink id="2205" type="page"]firewall and Anti-virus[/intlink] and also check your system out just to be sure.
Saturday
Mar282009

Hotmail accounts get compromised!!

I received an email on a list and wanted to warn people:
[ad]
Dear friend,
i would like to introduce a good company who trades mainly in electornic products. Now the company is under sales promotion, all the products are sold nearly at its cost. They provide the best service to customers,they provide you with original products of good quality,and what is more,the price is a surprising happiness to you! It is realy a good chance for shopping.just grasp the opportunity,Now or never!
The web address: http://www.nekcn.com

Seems this is being sent from Hotmail accounts. There are a number of ways someone could be getting a hold of your email address. According to Microsoft forums this seems to delete your email contacts and also send out this in the same time. This seems to be a new spam campaign for this one company. I would guess someone bought advertising from this company and the advertiser is doing some really unmoral things.

There are several ways someone hotmail account could be sending out these emails. It could be a [intlink id="2650" type="post"]phishing attempt like they did with Twitte[/intlink]r. They could of done a dictionary attack on each account to find the password, that I why [intlink id="2646" type="post"]I suggest having a password generator[/intlink]. It could of been a virus, and if that is the case you would need to [intlink id="2205" type="page"]check your system out for the virus[/intlink]. I would guess it is the first two, because I am unsure of if you can have pop3 account or not. I don't use Hotmail but people seem to be using it.

If you recieve this email, I'd email the account responsible to let them know that they have sent this.  I would also like to know if it was a virus or how they account got compromised.   Remember only you can prevent from getting a virus, nothing else works better than yourself.
Tuesday
Mar242009

New spam Campaign -- Casino Anyone?

Looks like there is a new Campaign going on with regards to having VIP access.

geocitiesspam


So I go to the site:


geocitiesspam1



[ad#cricket-right-ez]

I decide to have a little fun and download the file.  The Filename is "Smartdownload.exe".  Now you shouldn't install any software or programs from sites you don't know about or have any idea of what changes are going to be made.  I use CWSandbox to better understand this file.  Here are a few thinks I've found:




  • This program connects to three different IP's [Your broadband Modem,200.122.168.237, and 212.201.100.136]

  • It also Changes your Autoexec.bat file.  (Not good)

  • Changes access flags on several different program (not good either)

  • It also tries to be Anonymous.  If you checks the logs out your self you will find it very interesting.

  • It looks like it connects to the servers every time you boot up!! (Not good either)


I don't know what it is trying to do but everything I see about this file makes me think this is trying to avoid virus detection.  I ran Kasperky and Avast file check, it came up clean.   I think what happens is you download the virus after you install this software.  I wouldn't download this or install it, even though it advertise you 800% free that has to be scam or just a flat lie to get you to install software.  Everything about this program doesn't make me want to to install this software, although it doesn't seem to be a virus.  It however does make me want to delete the file.  Remember to use[intlink id="2205" type="page"] Anti-virus and Firewalls[/intlink], that is your first line of defense.
Thursday
Mar122009

Spam email : Patients can access our chemist via the Internet 24/7

In today time Spammers are really trying to get people to open emails.  I was checking my spam folder making sure I didn't have anything in there that shouldn't be when I saw this email.  I was curious like everyone else who see's this message, because why would yu need a chemist?  So for fun I open it up and find the message.

For instants:

funnyspam1


The Link leads me to this:


funnyspam2


[ad#cricket-right-ez]

Now I know some people are needed these types of pills to keep the Mojo going, but I must warn people that these sites are dangerous.  Just like this email the spammer used something so unusal and still kept the truth in the header.   I'm not sure I'd want to buy anything from Russland, Or Sosonovy Bor.


I will tell you this, from my own experience with these types of drugs, you must be careful what you prescriptions you take.  One drug can interact with another drug and make you sick or possible even kill you.   That is why it is so important to see your doctor and get the right medication for you needs.  These mojo drugs can increase blood pressure or have some side effect that you can't handle or tolerate.  So when these spammers want you to buy Cialis or Vigra, I encourage you not to.  You will be far better off going to your doctor and getting the right presicription then buy these over the internet.  Who knows if they are this shady with emails, would you trust them with your credit card?  I wouldn't, that is for sure.

Thursday
Mar052009

I hate Snopes Spam

As you know Snopes is used to find out about urban Legend and Rumors:

I received a Virus alert from my RSS feed about Email virus warning.  It even adds a Snope URL.  The Author just copies and pasted the virus warning into the blog without even going to Snopes.
[ad#ad2-right]
According to Snopes and I'll quote:
Although the Postcard virus is real, it isn't a "BIG VIRUS COMING" (it's already been around in multiple forms for a long time now), it will not "burn the whole hard disc" of your computer, CNN didn't classify it as the "worst virus" ever, and it doesn't arrive in messages bearing a subject line of 'Invitation.'

[Via Snopes]

Now as you can tell the link described in the blog post was "http://www.snopes.com/computer/virus/postcard.asp". If you went there, you'd have seen this as a not really true and some parts of this might be but that part about burning your Hard drive or even consider the Worst virus isn't true.

Some things you need to consider before forwarding anything is:

  • Is it completely True?

  • Is it Legitimate?  (True blown warning about something like a product recall  or something important like that)

  • Does it Say to Forward? (if so it is probably not wise)

  • is it from a Friend (If so you might want to remind the friend nicely that it isn't nice to send spam)


If you follow some of these suggestions you'll be making the Internet a far better place for everyone.  Remember if you don't know, it's time to learn.  if you do know, it is time to teach.  These are the fundamental aspects of using the internet the right way.  Also if it is a fake virus warning you should tell them to get a Free Anti-virus and Firewall to better protect them.  Also  remind them that if they keep their system updated then they shouldn't be too worried.  Remember only you can prevent a Computer Virus and it's up to you keep your system up to date.
Friday
Feb272009

Rogue Fake Codecs on the Rise

Panda Labs has been talking about Adware/VideoPlay and they are seeing a lot of variants on this.   They even play a game, find the difference in the installation screen:



Now as you can see this look to be the same agreement in all those difference installation.  Some things to consider Never install any software from a website that you don't know Nothing about about.

Panda Labs also talks about these new variants in regards to what they do:

This file spreads by making copies of itself in the removable drives and it also creates an autorun.inf in order to be run when they are accessed. This file collects the data stored in the browsers, such as cookies, passwords, profiles, email accounts, etc, and connects to a remote address to send the information.
[Via Panda Labs Blog]

[ad#ad2-right]As you can see this makes you have very little security with your system.  I talk about Identity theft, and why you should always worry about your identity.   This however will make your passwords less secure and maybe even compromise you system to the point of having a data breach.   You need to be careful when you come by this, some fake codecs have been know to be scareware.  In which, the fake codecs installs a Trojan to tell you have a virus and try to make you buy a fake program to get rid of the Virus.  In one of my recent posts about Codecs and Facebook, I talked about the K-Lite Mega Codec Pack and how that will prevent you from installing these sociable links from friends and family.  The nice thing about this pack is it install all the really good codecs that you might come across on the web.  If you have this installed and there's a website that says you need a special codec, you'd know that it is either a fake codec or the author who made the video doesn't standardize.   In which case you will be more willing to leave that site without installing that codec.

If you follow these steps and also consider installing an Anti-virus and Firewall, you will be in a much better shape then when you first started out. Remember only you can prevent from getting a virus. You should also consider doing the registry edit that will prevent Autorun. As you can tell these new variants also are spread through USB and other removable media. This is the other way these programs are using to infect other systems.
Tuesday
Feb242009

Oh My I got the Presidents Attention!!

I just got an email telling me:

Barack H Obama (PresidentBarak) is now following your updates on Twitter.

So I go to the click the link and I see this:
barakobamspam


Wow, I didn't know I was this influental to get the Presidents attention(NOT).

barakobamspam1
http://www.economygrantprogram.com/


After checking out the profile I see that it has a link to a site that basically asking for your personal address and your email account. After I go check the site I see in really small catch you have to pay 3.95 for Shipping and Handling. Well You know what they say, nothing ever is Free. This looks to be a way to get email addresses to spam in the long run. I wouldn't give them any information because this is looking to be a scam and I hate scams. You best bet is to go on with your life and report this spam to twitter. This however got my attention because of the who it was, and that is probably why they chose the name. It is however quite funny. :)
Monday
Feb232009

Being a Bad BOT!

badbot1

I had the strangest thing happen today, Seemed a Bad Bot was Crawling my pages. I was getting at least 60 page views an hour from this bad Bot!! The individual IP's of this Bad Are:
65.208.151.112
65.208.151.113
65.208.151.114
65.208.151.115
65.208.151.116
65.208.151.117
65.208.151.118
65.208.151.119


[ad#ad2-right]After the first initial hour of this going on, I started wondering what this bot was doing.   I did some more research into this little bot.   I did find out it is owned by Kintiskton LLC.  (Twitter Search)

Anyways It bothers me that when you do a Google Search for this company, it comes back with no company.  Some people have already did there research and have come up with very little.

I dug even more and some are saying this might be Homeland Security, and I have my own thoughts on this.   I might be paranoid myself but if there is no company out there and the IP keeps coming back, I assume it is BAD mojo.  Some people worry that it is a hacker probing for vulnerabilities and that worried me.

I decided with the Help from Godaddy, to ban the lot of IPs.  I figure someone is trying to get information or trying something they shouldn't, I'll stop it myself.   If you have Wordpress and are also having problems with this ip, you can ban it by adding this to your HtAccess file:

order allow,deny
deny from 65.208.151.112
deny from 65.208.151.113
deny from 65.208.151.114
deny from 65.208.151.115
deny from 65.208.151.116
deny from 65.208.151.117
deny from 65.208.151.118
deny from 65.208.151.119
allow from all


This is how you block those ip in the HtAccess file. Thanks to Wordpress for showing me how.
Thursday
Feb192009

Careless Facebook profiling can lead to Identity Theft!

I just got in contact with a old friend from High school and another friend of mine suggest the new friend. I was looking at her profile and couldn't believe what I saw:

Something users shouldn't do!!!As you can see this is not good I was amazed at how many people are giving out there birthdays and who they are married to to friends and family. So we heard about how people are claiming they need help or are in need of desperate money. This is nothing new, as you know people are having hard economy times and people are using the social engineering to scam people out of money.

I feel that I should warn people the important necessity.   You shouldn't be broadcasting your DOB and who your married to to your friends, just in case they get hacked.
Recent activity indicates that identity thieves are hacking into trustworthy profiles before selling on the login details to interested parties. This information is used by spammers to target legitimate users, posting misleading links on their "walls" – personalized message boards.

[Via Computing.Co.UK]

This deservese a little mind and a lot of understanding.   By the spammers hacking into facebook accounts they have the chance to scam or spam people with links to possibly have a virus or trojan installer.

[ad#ad2-right]For example This one blog talks about the Virus:
Symantec's Norton Antivirus software has flagged this as a "high risk" Infostealer.Gampass virus. More info on this particular Trojan vius is here. (Note: Symantec warns the risk level is "low," since it originated in 2006, but this new Facebook email is a new iteration of the same virus.)

You might be inclined to click on this link because it's from a friend, but they did not intentionally send it to you -- and yes, their Facebook photo is attached, too.

[Via Sync-blog]

facebookident2Now I went searching through my friends list and also found this little bit of information.  As you can see this one is asking for people to use there account to scam people out of money.  They could use this to find out even more information of the Other partner and make you believe your talking to the real deal.   Saying they need money because they are stuck over seas or something like that.   I've seen this on other blogs where people have sent money to "friends" but are actually people who are the scammers.  Then if you send the money you are out of luck with your money and possibly your friends to.  I am sure there are more but this is prime examples of what you shouldn't do and why.

So what can you do to prevent Identity Theft and/or being scammed?


    [ad#cricket-right-ez]
  • Roboform Review — A Password Manager that will help protect your passwords from key loggers and other such phishing sites.    I strongly recommend it to to all who are security minded. (Never use the same password for all your accounts)

  • Are you worried about your identity? -- This is good information in checking out sites that might be questionable.  You can find out what type of site it by using your brains.

  • Old Phish Become New again -- This is blog post about twitter and what may happen if you did give out your password.   This is a good example of why you never should give out your password to third party websites.

  • Twitter Spammers a getting more smarter -- This is also good example of what happens when you see become friends with someone who isn't real.   You could be the next to be spammed and/or impersonated.


If you follow some common steps you to could prevent from being the victim or getting your Identitiy stolen.   Some things to remember is Never tell anyone your Birthday the whole date like someone did on twitter a few days ago.  It's nice that they are growing older but that gives people that much more information to use to steal your money or your idenitiy.   Think before you give out any personal information like Age, Married, who your married to and anything that might be used to be able to access your account or your impersonate you.  Remember only you can prevent from being scammed or lossing your identity, you wouldn't want to have to pay for your mistakes.
Thursday
Feb192009

PolyMorphic Win32:Vitro Most Viraulent Virus

This seems to be an virus that is getting some people hit hard.   I wanted to blog about this because of the nature of Virus and Trojans.   I have read reports that this might be from Online Movies, and I have to say this is one reason why you must stay away from certain online movies.  I am going to take a guess that this virus requires a special CODEC, and you downloaded it and installed it.  It Could also be the update the Adobe Flash player idea to but still results in getting the Virus.

As I said before you take a risk when you go to sites you don't trust or know anything about.   You also should know that if you need a "SPECIAL" codec, you should just go on to another site.  These sites that claim they need this special codec means only one thing they want to install something without your Knowledge.

So what is this Virus:


The Virut family of viruses uses polymorphism to hide from all anti-virus protection, it infects executable files. File infection makes it very hard to repair a system that has been infected. W32/Vitro injects code in running processes and hooks the following functions in ntdll.dll which transfers control to the virus every time any of these function calls are made.

* NtCreateFile
* NtCreateProcess
* NtCreateProcessEx
* NtOpenFile
* NtQueryInformationProcess

[via Avast Forums]

After you get this very bad Virus you are done for.  You would need to install the Operating system from backups or even start a new.   This seems to be building this week and there isn't much you can do once your infected.  I do recommend a good Anti-virus and Firewall but that wouldn't fix the problem right now.  You will need to pull your backups out and start the process.  I suggest a complete wipe and then do the Restoring the backups.  This little virus likes to infect any .EXE it can so just restoring the Windows Directory will not help.  Remember only you can prevent from getting infected.
Saturday
Feb072009

Twitter Spammers are getting more smarter

I got an interesting email about someone following me. I went to go check out there profile and Guess what I see:
calvinhodges1


As you cann se this account only had one post but people seem to be following back due to the picture and the bio.   I checked the account about 30 mins later and here I will show you:

calvinhodges2


[ad#ad2-right]It seems that if people see it has a picture and a bio that doesn't sound like it is is advertising anything, they will simply follow them back.  That really isn't a good idea.   Sooner or later they will start sending out spam to people who are following just because they haven't been caught.   I also checked out the Web site they have new there bio and it leads to http://www.squidoo.com/twittertipstricks. I hope the website knows their link is being used by a spammer. Although this could be a 2 for one deal for having there link also being used for spammer so they can get traffic to there site. I would be worried my ISP doesn't cut my website due to THE TOS. Although I serious doubt it would happen I do know it could happen. So users are being fooled by spammers, and people aren't looking hard enough into the account. Users should be warned they shouldn't just follow back if it looks like it is a person. I know this is a robot and expect it soon to start sending out spam to all those people who are following.   I just thought I'd share what I found out.  If you clicked on the tinyurl.com it sends you to Partnerwithpaul.com website which talks about making money like all other spam.   Just be careful you don't end up having regrets on following people who are bots.