Insanity Run Rampant — Antivirus Pro System (scareware)
Comments OffSome of you would want to ask me why I am calling this title an usual title. In fact it is quite simple, I have been at the hospital since early this morning. While I was there I had some intriguing things happen. I was watching a person cruise the internet while they were at work. This is someone who is supposed to answer the phones and such. Then I see this POP UP, this draws my attention. “You SYSTEM Has Spyware”. This was my first thought, Scareware. The Popup said it was for “Antivirus Pro System”.

Since this was a Hospital computer, I couldn’t get a real screen shot of this but there are plenty examples out there, just like that one above. Anyways what worries me is how System Admins are allowing employees to surf the web while at work on company time. It also makes for a bad experience with their family. It also concerns me about the fact that while that computer is infected some of the patients records could be leaked online.
Electric Company fear Mongering gone wrong!!
Comments OffI saw this talking going on at Arstechnica and SANS Interenet are Talking about the Elecric Company Fear mongering. Here’s what Ars Says:
It sounds like something straight out of Hollywood. Current and former US security officials have reported that foreign nations have penetrated the cybersecurity barriers surrounding the US electrical grid, water system, and even financial networks. Although no known attempts have been made to activate the booby traps said black hats left behind, such sleeper cells could activate suddenly during a war or crisis, plunging the nation into a disaster only Bruce Willis and that Mac dude could avert.
[Via Arstechnica]
WASHINGTON — Cyberspies have penetrated the U.S. electrical grid and left behind software programs that could be used to disrupt the system, according to current and former national-security officials.
[Via Wall Street Journal]
Now let’s talk about this, This is being a talked about on a friends Podcast, The Caffination Podcast. This is where I have figure we should talk about this. I think Sans Internet Storm says it better than I could:
Are You and Your Friends Fine — Virus Spam
Comments OffLogged into my Google Email and was checking my spam to see what I see and this one draws my attention:
I think I know where this is leading me but I click the link and this website with the Reuters logo pops up:
Now as you can tell this looks authentic but when I did go to this site, AVG detected some trojan. It blocked it, but the file that it is downloaded called “save.exe” and I have talked about flash player fake updates. I have seen other blogs talking about dirty bomb news report leads to malware. I don’t know about you but if I wanted to update my flash player, I go to the source and not use any links. It is wise not to download any programs or files and run them without properly checking them out for viruses and Trojans. You should have a firewall and anti-virus running at all times and that will help but it is your actions that help your prevent from getting viruses or Trojans.
Is Google the ultimate news source?
Comments OffAs you know We had a big problem Monday Night and All day Tuesday. If you are a regular reader of this blog, you would of noticed either a 503 or lag. It was due to an article that I released late Monday night about the PIFTS.EXE and the so call conspiracy.
At the time, I was wondering and quite disturbed about what Norton Symantec was doing to the forums. So I blogged about this and wouldn’t you know my site was Held Hostage by Google. I kid you not, I had so many people come to my site in under an hour it wasn’t even funny.
I got hit hard by Slashdot, Reddit.com, and Google. In truthfulness, It was more of searches and people coming from Google than anywhere else. I would say Google was the 90% and and Slashdot and Redidit was 8% and the rest was from other websites for this one article. Now don’t get me wrong the 2% of people was my normal amount of people for the day. So you can imagine how many people actually came to my site over this fiasco.
Thinking back to PIFTS.EXE.
Comments OffThinking to this very incident looks to something out of the movie “Lemony Snicket’s A Series of Unfortunate Events“. I won’t go into much detail but here is what I want answers to about the PIFTS.EXE. You see after I have read a great article talking in detail about this, I have also come to the conclusion something isn’t right.
Although, in Norton’s defense there seems to be a lot of information that they have to sort through. I’ll admit this information people are asking should be really simple to find in the Symantec Databases somewhere. I will not say they are hiding anything major but I do think something is going on that we are not aware of. Here’s some other thoughts to considers? If Norton needed to find out who was using Windows 7, couldn’t they of asked or even made a simple site redirect to find that information, after all anytime you visit a site you have that information sent to the stats. I could in theory find out how many visitors are visiting from Macs and how many are on older systems. That would be very easy to do with Google Analytics.
Fake Emails about Windows Support spam!
Comments OffAccording to Trend Micro, Some malicious software is being sent to unsuspecting users about Windows SP1 andSP2 having a error that could damage software or even hardware. See Trends blog with the photos of the fake spam.
Microsoft sends e-mail messages to subscribers of our security communications when we release information about a security software update or security incident. Unfortunately, malicious individuals can and have sent fake security communications that appear to be from Microsoft.
[Via Microsoft]
So if you get an email from Microsoft you’ll probably want to delete it. Any Microsoft communications will be sent from the Update center. You should never install software that is from an untrusted website. If you are concerned you should check the web and find out what people are saying about the situation and see if it is a scam or true!! Remember only you can prevent a virus or Malware!
Getting to the A600 Program Files
Comments OffSo you want to see this screen when you plug in the A600 Broadband Card:


Uninstall THE USB DRIVERS for A600
C:\Program Files\Cricket\USB DRIVERS\Uninstall.EXE
Once you do that you will see need to reboot and then try to insert the A600 Modem into the USB slot. It should pop up with t hat screen or you should see the drive become available.
I’ve also took the drive and copied the program files into a sub Directory of the 4 Gig drive installed in the A600 and I decided to help everyone else out by uploading the self-extracting program to rapid share:
Cricket-A600-Program.exe Bit torrent file
This is the file I created on Memory card for when I need it. If you are uncomfortable downloading this because your worried about virus, then follow the directions on how to uninstall the software to get to your Cricket software for the A600. I did this to make it easier later on to re-install the software without having to uninstall software. Let me know if this helps. You should consider downloading Free Anti-virus Software and free Firewalls to protect your system if you haven’t already!!
Reviewing the 3G A600 Cricket Modem
So I got the Modem and wanted to test out the speed being stationary, So I go to my usual site Speedtest.net look at the speed, check below for speed.
As you can see this went fairly well. It does depend on your Cricket Coverage area. So you want to hear all about it.
First thing if you are upgrading from the UM100 Broadband Card, You’ll want to uninstall the Quicklink Software. To do that you can uninstall it by going to:
Computer > C: Drive > Program Files > Cricket > Quicklink > UNWISE.EXE
(This will uninstall the Quicklink software, I’d suggest after you uninstall it you reboot.)

How does the USB Modem work?
Once you do that you can then insert the A600 Modem into your USB. The Nice thing about this is the software for the Modem is on the Modem itself, so you don’t loose the CD for the modem. It currently only supports Windows and MAC OSX operating system but I have seen there is a work around to use the A600 Modem with Linux if your wondering.Once you insert it into the USB you’ll find you have a new Drive. It will say a Cricket CD Drive with 24 megs used. You’ll want to run that program on the Cricket CD and that will install the software.
I hate Snopes Spam
Comments OffAs you know Snopes is used to find out about urban Legend and Rumors:
I received a Virus alert from my RSS feed about Email virus warning. It even adds a Snope URL. The Author just copies and pasted the virus warning into the blog without even going to Snopes.
According to Snopes and I’ll quote:
Although the Postcard virus is real, it isn’t a “BIG VIRUS COMING” (it’s already been around in multiple forms for a long time now), it will not “burn the whole hard disc” of your computer, CNN didn’t classify it as the “worst virus” ever, and it doesn’t arrive in messages bearing a subject line of ‘Invitation.’[Via Snopes]
Now as you can tell the link described in the blog post was “http://www.snopes.com/computer/virus/postcard.asp”. If you went there, you’d have seen this as a not really true and some parts of this might be but that part about burning your Hard drive or even consider the Worst virus isn’t true.
Some things you need to consider before forwarding anything is:
- Is it completely True?
- Is it Legitimate? (True blown warning about something like a product recall or something important like that)
Cracking and Warez sites are Host of Trouble!!
It is nothing to laugh at and should be understood that gamers have no freedom right now. That said this new Variant to Virux Trojan is in regards to Win32/Vitro Trojan. It seems tobe infecting .exe and .Scr files just like this.
According to Trend Micro:
The downloaded malware include variants under the FAKEAV, TDSS, and VUNDO families. Infection chains, however, are notable for the presence of VIRUT and VIRUX malware. VIRUX and VIRUT attacks were initially about the volume of infected PCs. The numbers are massive enough to worry Web users and security researchers: around 20,000 PCs are infected per day
Read more: “Crack Sites Distribute VIRUX and FakeAV“
Now it seems to be more and more sites with getting computer infected. It also seems the Malware writers are using these servers for helping infect essentially gamers computers. So for the time being, if you have a favorite game and you want to:
- No-CD Crack (This is good for those who want to play the game without the CD)
- Key Gen Cracks (This is used for pirated version of a game)
- Update Cracks (This is used to prevent CD checking or Also prevent Version Checking)
Facebook Goes Phishing again
Comments OffIn one of my Previous articles about the Koobface Worm, I talked about the way they were infecting the systems and what you need not do.
It seems that Trend Micro has seen an even more rise in people downloading the WORM_KOOBFACE.AZ and Seems to be on the RISE. This is all done with a Social engineering and Has had some attempts before with this little worm on Facebook.
* facebook.com
* hi5.com
* friendster.com
* myyearbook.com
* myspace.com
* bebo.com
* tagged.com
* netlog.com
* fubar.com
* livejournal.com
This seems to be a social engineering Nightmare for these websites and as yet are unsure what else it does but it says the same thing it did before by saying “This is a Video of You on the Street.” Which is bogus but none the less people click and think they have to download a codec or update their Flash. Social Engineering is on the rise and will be taken seriously. You should read the full report from Trend on what it does but you also should have an anti-virus and Firewall installed to prevent this from happening in the first place. The only true way of preventing this is not to be fooled, you should NEVER Download from a site you don’t know or trust. See all the Facebook articles for more information.
Viacom might be going to HULU
Comments OffAccording to some of the news post people are worried about Viacom leaving Time Warner. Now Here’s where Viacom might be going digital. What do I mean Digital, I am talking about going to HULU. If Viacom doesn’t sign a deal with Time Warner, that would leave a space ope for someone else like Hulu.
So Viacom isn’t happy with Time Warner, or They want to go IPTV. Some of the Headlines I’m seeing are:
- Time Warner Cable Loses Viacom: MTV, Nickelodeon, Comedy Central To Go Dark
- Dispute Between Time Warner and Viacom May Affect Cable Shows
- Viacom could pull MTV off Time Warner Cable
- Viacom And Time Warner Cable Play Chicken; Programmer To Pull Networks Over Fee Dispute
These are just a few that I am seeing pop up around the internet. So what does that mean to the internet user? Well On one of there show’s like Dora the Explorer on Nickelodeon will begin to stream some of the shows previews on Dec 29, 2009 for it’s next show. When you go to Nickelodeon Site you get this:

Using Skype with Cellular BroadBand Modems
Comments OffIf your like me you will want to make sure you have the best possible speed and connection with your broad band modem. Here are a few articles to better help with you get the best possible speed with a broad band modem like a Cricket modem:
- Cricket USB UM100 Broadband Wireless Modem Review.
- Get your Cricket Broadband to Activate Manually!
- Cricket Broad Band Modem Extended Review 12/23/08
- Cricket Wireless Broadband Card — How to get better speed!
Some other things to consider are:
These will start to make it better for you to use a modem and get the best possible speeds from the modem. You have to realize what your coverage area is. There are many factors in regards to your modem speed but that is something that you will have to figure out how to get better speeds.
How do you use Skype with your Cellular broad band modem?
Somethings to remembers with your broadband modem is you won’t have a good connection no matter how hard you try. Most cellular carriers don’t want you to us it with VOIP(Voice of Internet Protocol). So you will have to pay close attention to how you use the bandwidth and what you are doing while making a VOIP call.
Panatech PX-500 PCMCIA Sprint EVDO BroadBand Card
Comments OffThe Pantech PX-500 wireless mobile broadband card for Sprint gives you data communication access for your PC laptop anywhere you roam on the Sprint network at faster speeds than ever before. EV-DO rev A compatibility gives you download speeds of up to 3.1 Mbps and beefy upload speeds of up to 1.8 Mbps. Simple to use, the Pantech PX-500 wireless mobile broadband card lets you surf the Internet, send and receive email and text messages, and connect to corporate networks from just about anywhere.
Technical Specs:
- Dimensions – 4.57 in x 2.13 in x 0.51 in
- Weight – 1.8 oz
- Data Download Speed – EV-DO rev A (Up to 3.1 Mbps Down/1.8 Mbps Up), EV-DO rev 0 (2.4 Mbps Down/153 Kbps Up), 1xRTT
- Download Protocol – CDMA 850, 1900
- Compatible Carrier – Sprint PCS
- Network Compatibility – CDMA 850, 1900
- 3G Data Speeds – Yes
Compatibility Features
- Device Supports Data Plans – Yes
- Available For Purchase Without Service Plan – Yes
Disaster preparation 101 — Data backup
Comments OffIn this one I will talk about Disaster, it happens to all of us from time to time. A fire, a earthquake, a stolen laptop or any number of ways. So what happens to your data, is it stored on the laptop? Is it important very sensitive data? Could you get fired if you lost that data?
Microsoft to Release KB961051 on the Dec 17, 2008
Comments OffAccording to McAfee and I will quote:
December 16, 2008: Microsoft has announced an out-of-cycle patch release for a critical, remote-code-execution, vulnerability in Microsoft Internet Explorer (CVE-2008-4844). The patch, to be released on December 17, will address the vulnerability across multiple versions on Internet Explorer running on supported Windows platforms.
[via McAfee Threat Center]
Signs of a Computer Infection!
Comments OffSo I was thinking this morning what I missed and I totally missed on how you might be able to tell if you have a computer virus. It does me no good to talk about a virus if you don’t know you’re infected. I was thinking of the times I had a client who had trouble but wasn’t what I thought.
So How do you know?
Some people would say it depends on factors but here are what I call clues that make me suspect a virus:
- Slow or Sluggish computers – Here is what I know if the computer is really slowing down and have a dual core or quad core. If you are running a system and sees a lot of hard drive activity even when the computer is idle then it might be a virus or it could be a program doing what it is supposed to be doing. So this is somewhat of an indication but not always.
- Slow internet connection on the computer or on the network — Due to the fact that most people have a router that is connected to all the computers and if you internet connection on all your systems are slower than normal then you could have a virus. I use Speed Test website to help determine this.
Cricket Wireless Broadband Card — How to get better speed!
After buying the card last month, I did a quick review about the broadband card. I wanted to talk about the speed problems that I had when I first used the modem. Here is how to possibly getting better speeds when you use your card. First off, you will need to disconnect from the internet and go to your quicklink mobile application:

You will click on “Tools” and then hit ‘Activation’. If you have it fail on your the first time you should reboot your system then try to do the activation after reboot that should fix the activation problem.
As you can see after I did the activation of the modem, my speed went way up from the last review. I thought I should talk about how you could possibly fix this. I called tech support over this to get a better speed.
Uncovering a Virus/Trojan
Comments OffGetting done with the first part really got my juices flowing. I was shopping looking and thinking about this next article. I came up to only one option turning this into a 3-5 length post due to all the content that I will have. So where did we leave off? Oh that is right figuring out if you have a virus/Trojan. The instant I made a post about this 12 hours later someone make a comment and here is what he said:
I can’t wait to read part two of this article. I always wondered how you’d know you’re infected if a virus don’t want to be detected and no virus definitions are yet available, because the virus is so new.
Now the truth is anytime a Virus does something it usually leaves a footprint somewhere and somehow. Even the hardest working hacker can’t plan for all possibilities and that is where we begin. I have been helping people for a while with viruses and know that no matter how hard the virus tries to hide you can usually find it relatively quickly and easily do to virus check here are the ways I’ve done to figure out if they may or may not have a virus/Trojan.
Figuring out the Email-Worm Win32.Zafi.b
Comments OffThis is another just I just saw on the web and wanted to talk about what this little Worm does and what it’s known Aliases:
Email-Worm.Win32.Zafi.b (Kaspersky Lab) is also known as: I-Worm.Zafi.b (Kaspersky Lab), W32/Zafi.b@MM (McAfee), W32.Erkez.B@mm (Symantec), Win32.Hazafi.30720 (Doctor Web), W32/Zafi-B (Sophos), Win32/Zafi.B@mm (RAV), PE_ZAFI.B (Trend Micro), Worm/Zafi.B (H+BEDV), W32/Zafi.B@mm (FRISK), Win32:Zafi-B (ALWIL), I-Worm/Zafi.B (Grisoft), Win32.Zafi.B@mm (SOFTWIN), Worm.Zafi.B (ClamAV), W32/Zafi.B.worm (Panda), Win32/Zafi.B (Eset)
It is written in Assembler, and packed using FSG. It is 12800 bytes in packed form, and 33292 in unpacked form.
This Worm seems to be running through email and file sharing sites, One thing it tries to do is stop the process and deletes:
fvprotect.exe
winlogon.exe
jammer2nd.exe
services.exe
It attempts to detect antivirus program files on the computer and overwrite them with a copy of itself.
www.2f.hu
www.parlament.hu
www.virusbuster.hu
www.virushirado.hu
What is a Virus and Why do I have one
After seeing more and more the updates coming from the net. I wanted to talk about what a Computer Virus or Trojan is and how you get it. So how did you could of gotten a Virus in the first place. So here are some information to consider:
The vulnerability of operating systems to viruses
So what does that mean to you? Most of the times when you get a virus you have a vulnerability in some place in your Operating system and it is either something that has not be known by Microsoft, Apple, and Linux or is know as a Zero-day Exploit.
A zero-day (or zero-hour) attack or threat is a computer threat that tries to exploit unknown, undisclosed or patchfree computer application vulnerabilities. The term Zero Day is also used to describe unknown or Zero day viruses.
[Via Wikipedia]
This is one of the most used because if it is an unknown exploit by the Operating System creators then they have a longer to us the exploit. Most of the time hackers like to use this because that means there is a possibility of finding even more vectors to infect other systems. You see if they can get on one system they can then find ways to get on other systems.
CBS Confirms the Axe of Layoffs for CNET
Comments Off
CBS throws the gauntlet and says in a statement :
CBS Interactive continues its integration process, which now calls for the further combination of several portions of the division into unified groups oriented around similar content. This important move allows us to better align our premium content for our audiences and our advertisers, and also results in reduction in certain areas that are now duplicated in the new organization structure. We believe these moves are necessary to continue building CBS Interactive into the most creative, most efficient, most profitable and fastest growing Internet company in the media business.”
Internet Explorer still has a Vulnerability after Tuesday Patch!!
Comments OffI just read this on several blogs and thought I’d share the details with you, it seems that Microsoft didn’t know there was a problem with this Bug/Vulnerability. Computer world has a great article and says this:
“The updates Microsoft released yesterday do not address this possible vulnerability,” a Microsoft spokesman said today in an e-mail reply to questions, “but I can tell you that Microsoft is investigating these new public claims of a possible vulnerability in Internet Explorer.”
[Via ComputerWorld]
I can only hope that Microsoft fixes this Vulnerability soon, I would take a guess that they will try to get this out on the patch cycle if not they will push it out after. Some things to remember with IE(Internet Explorer) is only use it with Microsoft Updates. I also Suggest downloading FireFox and checking out my Anti-virus and Anti-Spyrware Page for ways to prevent from getting a virus.
The Important Windows patches Released Today
Comments OffAs many of you know we talked about the Non-critical patches that Microsoft will release today. IF you want to read those please go and check it out. I’ll be talking about the REALLY important ones that Microsoft has kept tight until now. These are the more important ones but I will list the ones that I previous talked about to better help people recognize the non-important ones:

These are just the tip of the iceberg. although this list are not A lot. I’d wanted to let people know about what people coin “Exploit Wednesday“. I really don’t know if this is a Myth or actually does exist but I’d figure we discuss the problems associated with installing the critical updates and try to tell you which ones should be installed As soon as possible. Though people have in the past used a Virtual Machine to see if there is any problem, that should be your first step if you don’t want to have any problems with these updates. I don’t suggest testing it more than a couple days. Here are some good Virtual Machine software to try out yourself:
trojan.zlob removal tricks!!
Comments OffAliases:
Trojan-Downloader.Win32.Zlob.qyl (Kaspersky)
Trojan-Downloader.Win32.Zlob.qzs (Kaspersky)
Trojan-Downloader.Win32.Zlob.qzn (Kaspersky)
Trojan.Zlob.CPP (BitDefender)
Puper (McAfee)
SystemDefender (Symantec)Trojan:Win32/Zlob.G is a component of Win32/Zlob that downloads rogue security programs, adware, and additional Win32/Zlob components.
[Via Windows Live OneCare]
Trojan.PWS.ChromeInject.A is not a Firefox plugin.
Comments Off
A new type of malware designed to harvest web passwords has been detected in-the-wild by BitDefender’s antivirus research labs. This latest e-threat – called Trojan.PWS.ChromeInject.A – is intended to be delivered onto a compromised computer system by other malware for subsequent download into Mozilla Firefox’s Plugin folder. Once installed it gets to work every time Firefox is started.[Via Bitdefender]
The key to this virus protection is just be cautious of where you go and keep all you system update to date to prevent all this from happening. It is also advisable to not have your passwords saved on Firefox, you should use something like Roboform, it is free to download and try. It will encrypt your passwords so if they don’t know the master password then they are out of luck. Roboform is also good for coming up with some strong passwords. Just some suggestions to prevent from people seeing your sensitive data, you don’t want anyone to get that data.
Are you patched, Secunia Says NO
Comments Off
Think you’ve got nothing to worry about, according to Secunia 98% of computers are not fully patched and are vulnerable to some kinda of attack.
If you have a system that is off of the Net you could use the Clone of Autopatcher Program to do it for you. You also need to update all your secondary programs such as Audacity, Open Office, and other programs that you use weekly.
Microsoft issues Vista patches out of Monthly Patch Cycle!

Microsoft issues Out of cycle patch for Vista. These patches are as Followed:
An update rollup is available for the Microsoft Windows Imaging Component (WIC) in Windows Vista or in Windows Server 2008. This update rollup resolves the problems that are documented in the following articles in the Microsoft Knowledge Base:
954708 An update to add support for the serialization of complex Extensible Metadata Platform (XMP) data types in the Windows Imaging Component945060 There may be inconsistencies in the Extensible Metadata Platform (XMP) and Exchangeable Image File (EXIF) values for an image file in Windows Vista and in Windows XP
The Windows Portable Device (WPD) API collects and transfers Software Quality Metrics (SQM) data to Microsoft servers. The SQM data is collected only on an opt-in basis through the Microsoft Customer Experience Improvement Program. An update is available that disables the collection and transfer of SQL data to Microsoft servers.
This update affects Windows Vista-based computers, Windows Vista Service Pack 1 (SP1)-based computers, and Windows Server 2008-based computers that are in the Microsoft Windows Media Player Customer Experience Improvement Program.
Cricket USB UM100 Broadband Wireless Modem Review.
The UM100c is No Longer Available, Please check out the Cricket A600 Modem Review Or the UM185 Broadband modem. The UM185 modem might be a replacement to the UM100.
After a full week of playing around with this USB wireless, I wanted to talk about it. So let’s break it down into pieces.
- (USB Broadband A600 Modem card for Free after Instant online rebates and Mail in rebate Free shipping & first month free! Shop today.)
- Installation – The installation of the USB was not to difficult. I did have to do some more steps than this: Install the Software, then hooked up the USB device to the USB port.
- Manual Activated the Broadband – For some reason in my area they had several people have problems with the broadband activation. So I had to activate it manually!!
After that all went well, I was on the internet just a cruising along. I did however wonder why I was getting such a slow response speed. When I went traveling I thought I would share some of my local results with you to better show you my speed. All these test were done at
Reports are coming in that WPA is no longer secure!
Comments OffAccording to a media reports, Erik Tews and Martin Beck claim that they have found a way to unlock the Temporal Key Integrity Protocol (TKIP) key, used by WPA, to read data sent from a wireless router to laptop computers. According to the researchers, the key can be cracked in 12-15 minutes.
[via Sophos]
According to Sophos, they are claim that people can now watch what you are doing on a Wireless router to a laptop. Although this isn’t to be unexpected this is a very serious out come. It is now easier to watch what people are doing online. So does that mean people can see everything you do? Not necessary. According to some people this is harder than it seems, most of the websites you visit are not encrypted, but websites that use the “https” protocol are more safer to use online. You should be safe if you are buying things online as long as you are sure it is secure. Some other steps to take to help make it harder to unencrypte your wireless single is to use Roboform promotion codes you will get for 10% or 20% off the purchase price!!











