Malicious Spammers target Bank of America
Comments OffI’ve saw two different security firms talking about Bank of America and I wanted to share with you:
Picture from F-secure
It is also been known to be floating around in Facebook this spam. So if you get a link going to a site you don’t know about to see a video and it says you need a codec or the Adobe update you should turn right around and leave site. You should always type in the url of Your Bank and not go there through links.
From what they are saying it monitors Network traffic and Steals ICQ, POP3, and IMAP passwords. If you find network traffic going to Hong Kong IP, then it is time to check to make sure all your Virus definitions are up to date and you’ve installed an Anti-virus and Firewall. I would encourage users to report it to Phishtank so that any other unsuspecting user or person going to that site will be warned.
Is Google the ultimate news source?
Comments OffAs you know We had a big problem Monday Night and All day Tuesday. If you are a regular reader of this blog, you would of noticed either a 503 or lag. It was due to an article that I released late Monday night about the PIFTS.EXE and the so call conspiracy.
At the time, I was wondering and quite disturbed about what Norton Symantec was doing to the forums. So I blogged about this and wouldn’t you know my site was Held Hostage by Google. I kid you not, I had so many people come to my site in under an hour it wasn’t even funny.
I got hit hard by Slashdot, Reddit.com, and Google. In truthfulness, It was more of searches and people coming from Google than anywhere else. I would say Google was the 90% and and Slashdot and Redidit was 8% and the rest was from other websites for this one article. Now don’t get me wrong the 2% of people was my normal amount of people for the day. So you can imagine how many people actually came to my site over this fiasco.
Thinking back to PIFTS.EXE.
Comments OffThinking to this very incident looks to something out of the movie “Lemony Snicket’s A Series of Unfortunate Events“. I won’t go into much detail but here is what I want answers to about the PIFTS.EXE. You see after I have read a great article talking in detail about this, I have also come to the conclusion something isn’t right.
Although, in Norton’s defense there seems to be a lot of information that they have to sort through. I’ll admit this information people are asking should be really simple to find in the Symantec Databases somewhere. I will not say they are hiding anything major but I do think something is going on that we are not aware of. Here’s some other thoughts to considers? If Norton needed to find out who was using Windows 7, couldn’t they of asked or even made a simple site redirect to find that information, after all anytime you visit a site you have that information sent to the stats. I could in theory find out how many visitors are visiting from Macs and how many are on older systems. That would be very easy to do with Google Analytics.
Conspiracy theories run rampent due to PIFTS.EXE
(Looks like some of this was a 4chan gag, check my other post about it)
All of the sudden people around the World are seeing PIFTS.EXE popping up. Norton Antivirus is asking users if they want to accept it. Here what I do know:
Here’s some information I pulled from my Zone Alarm Logs. Does this make sense to anyone?
2009/03/09 18:26:44 — New Program — PIFTS.exe — Destination IP: 67.134.208.160:80 — outgoing — blocked — Destination: ping.lifecycle.norton.com2009/03/09 18:47:52 — Program Access — PIFTS.exe — Destination IP: — outgoing — blocked — Destination:
2009/03/09 18:48:28 — Changed Program — Windows Explorer — 207.46.248.249.80 — outgoing — blocked — Destination: sa.windows.com
[Via The Symatec Forums]
This indicates that the program tried to change tactics to go out on the net. I look a look for this and it is SwapDrive. So this must be an update to Swapdrive but I am unsure as to why it pops up that way. The other ip is in Africa or at least take the .80 out of the equation and it points to an Africa IP. (It looks to my mistake in that little part, “to error is human” Check out this post about it) Although just recently Norton Decides to Delete that thread and people are really worried about why? Is this a cover up of some sort because there is a exploit in the Wild that we don’t know about? These are good questions that need to be answered. Here is what one posted about this just after they deleted the forum thread:
Are you Email domains being blocked by Cricket?
Comments OffSo I got this Tweet from Mai_ling on twitter and she said:
So I did some digging around the net and found it is something that is a common practice for ISP’s to block PORT 25. If you want to find out if Cricket is blocking your mail service you can easily follow these instructions to see if port 25 is actively being blocked. So what are some options in fixing this little problem.
You could set up your email client to receive on port 25 but send out on the SMTP server of Gmail. This would be useful for people who want to send mail out but not have to change there email address. People will still see it coming from whatevername@whatever.com. You can tell Thunderbird to send out on the port and yet use your domain as your email address.
Another possible solution that may work for some is to sign up for Google Apps. The downside of this is It cost 50$ a year but that is 4.20$ a month to be added on to your Cricket Modem charge. This looks promising and has a 30 day trial so, if it works then you will know before you have to pay for anything. This should be dealt with by Cricket, they should have a way for there customers to send and receive email without having to jump through hoops to send email and receive email.
Fake Emails about Windows Support spam!
Comments OffAccording to Trend Micro, Some malicious software is being sent to unsuspecting users about Windows SP1 andSP2 having a error that could damage software or even hardware. See Trends blog with the photos of the fake spam.
Microsoft sends e-mail messages to subscribers of our security communications when we release information about a security software update or security incident. Unfortunately, malicious individuals can and have sent fake security communications that appear to be from Microsoft.
[Via Microsoft]
So if you get an email from Microsoft you’ll probably want to delete it. Any Microsoft communications will be sent from the Update center. You should never install software that is from an untrusted website. If you are concerned you should check the web and find out what people are saying about the situation and see if it is a scam or true!! Remember only you can prevent a virus or Malware!
How do you like your Cricket USB Modem?
Lately I talked about the A600 USB 3G modem and Now I want to hear from the Readers? You see I can’t do my best reviewing these with comments from the readers, that being you.
Click the picture to send me email, just remember to replace “AT” with “@”.
So I want to hear what you think about either the USB UM100 Modem or the A600 USB 3g Modem? Here a re a few things to answer when you write your email.
Something will go to the people who email me? I want to publish some of these comments on my blog for all to read. I want to hear if what I am publishing helps you? I will even give your credit as to who wrote it. If you have a site or something you want to promote by all means add that to your testimonial. Here’s the basic questions that should be talked about:
- Which one did you buy? (Cricket USB A600 or Cricket USB UM100)
- Did you Upgrade from the Cricket USB UM100 to the Cricket USB A600?
- Are you using it for travel or Primary internet?
- Is it for business or Pleasure?
When do you “Never Fold”
Comments OffSo I got this email and wanted to show you just how try to get you to link to their site:

I got this email and wanted to talk about how people link to sites they shouldn’t. Although this a real site, I had my doubts from the get go. You see it talks about sending 21 visitors to my site. I got to the site Neverfold.net which after I looked and there I am but I wonder why? Because Poker and Calicanis have nothing in common with Poker or at least news and all that.

I hate Snopes Spam
Comments OffAs you know Snopes is used to find out about urban Legend and Rumors:
I received a Virus alert from my RSS feed about Email virus warning. It even adds a Snope URL. The Author just copies and pasted the virus warning into the blog without even going to Snopes.
According to Snopes and I’ll quote:
Although the Postcard virus is real, it isn’t a “BIG VIRUS COMING” (it’s already been around in multiple forms for a long time now), it will not “burn the whole hard disc” of your computer, CNN didn’t classify it as the “worst virus” ever, and it doesn’t arrive in messages bearing a subject line of ‘Invitation.’[Via Snopes]
Now as you can tell the link described in the blog post was “http://www.snopes.com/computer/virus/postcard.asp”. If you went there, you’d have seen this as a not really true and some parts of this might be but that part about burning your Hard drive or even consider the Worst virus isn’t true.
Some things you need to consider before forwarding anything is:
- Is it completely True?
- Is it Legitimate? (True blown warning about something like a product recall or something important like that)
Microsoft Releases the Patch Information for March
Comments OffMicrosoft Has Released the Patch information For march and This is what is expected to be patch on March 11, 2009:
- Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (Kb949029) — This security update resolves several privately reported and publicly reported vulnerabilities in Microsoft Office Excel that could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. (affected System : Microsoft Office)
Cracking and Warez sites are Host of Trouble!!
It is nothing to laugh at and should be understood that gamers have no freedom right now. That said this new Variant to Virux Trojan is in regards to Win32/Vitro Trojan. It seems tobe infecting .exe and .Scr files just like this.
According to Trend Micro:
The downloaded malware include variants under the FAKEAV, TDSS, and VUNDO families. Infection chains, however, are notable for the presence of VIRUT and VIRUX malware. VIRUX and VIRUT attacks were initially about the volume of infected PCs. The numbers are massive enough to worry Web users and security researchers: around 20,000 PCs are infected per day
Read more: “Crack Sites Distribute VIRUX and FakeAV“
Now it seems to be more and more sites with getting computer infected. It also seems the Malware writers are using these servers for helping infect essentially gamers computers. So for the time being, if you have a favorite game and you want to:
- No-CD Crack (This is good for those who want to play the game without the CD)
- Key Gen Cracks (This is used for pirated version of a game)
- Update Cracks (This is used to prevent CD checking or Also prevent Version Checking)
A Sneak Peak at the A600 3G Broadband Cricket Card
Comments OffSo I was doing a little research and found this nugget from my Affiliates Network:
Features:
Removable Memory Format: microSD
Storage Capacity External memory up to 4GB
Text Messaging Yes
Contact Directory Yes
Language English/Spanish
Wireless Capabilities:
Technology CDMA
Mode Tri-Band
Data Transfer Speed 3G (EVDO Rev 0, Rev A) and 1x
USB Broadband Modem (A600) Looks interesting, and I am thinking this will be the next thing the company will start Advertising for. Right now though, it cost 119$ with a 50$ Mail in Rebate and you spend 69$. With a CDMA only USB Card like the UM100, you know the speed of that. Now According to Wikipedia for 3G and I’ll quote:
Thus users sold 3G service may not be able to point to a standard and say that the speeds it specifies are not being met. While stating in commentary that “it is expected that IMT-2000 will provide higher transmission rates: a minimum speed of 2Mbit/s and maximum of 14.4Mbit/s for stationary users, and 348 kbit/s in a moving vehicle,”
You won’t make money from W32:Sality.ao
Comments OffPeople should be cautious of the making money because there is a variant out there trying to leverage the users into thinking they can make money.
McAfee Says “W32/Sality.ao is a parasitic virus that infects Win32 PE executable files. It infects files (*.exe and *.scr files) on the local, network and removable drives by overwriting code in the entry point of the original file and saving the overwritten code in its virus body. It then appends the virus body to the host file.”
Aliases for this Virus is:
- PE_SALITY.JER (Trend Micro)
- Virus.Win32.Sality.aa (Kaspersky)
- Virus.Win32.Sality.y (Ikarus)
- Virus:Win32/Sality.AM (Microsoft)
- W32.Sality.AE (Symantec)
- W32/Sality-AM (Sophos)
- W32/Sality.AE (Norman)
- W32/Sality.AH (Panda)
- W32/Sality.AK (F-Prot)
- Win32.KUKU.a (Rising)
- Win32.Sality.OG (BitDefender)
- Win32/Sality.AA (VET)
These links should help people understand it it. You can visit my Malware Resources to help remove this virus. Something to consider before removing this is to disable your restore points.
Remember there’s no easy to make money, the only real way is to work hard. According to my research the Anti-virus companies have ways to remove this virus and as long as you update your database.
Being a Bad BOT!
I had the strangest thing happen today, Seemed a Bad Bot was Crawling my pages. I was getting at least 60 page views an hour from this bad Bot!! The individual IP’s of this Bad Are:
65.208.151.112
65.208.151.113
65.208.151.114
65.208.151.115
65.208.151.116
65.208.151.117
65.208.151.118
65.208.151.119
Anyways It bothers me that when you do a Google Search for this company, it comes back with no company. Some people have already did there research and have come up with very little.
I dug even more and some are saying this might be Homeland Security, and I have my own thoughts on this. I might be paranoid myself but if there is no company out there and the IP keeps coming back, I assume it is BAD mojo. Some people worry that it is a hacker probing for vulnerabilities and that worried me.
I decided with the Help from Godaddy, to ban the lot of IPs. I figure someone is trying to get information or trying something they shouldn’t, I’ll stop it myself. If you have Wordpress and are also having problems with this ip, you can ban it by adding this to your HtAccess file:
ThePirateBay might be blocked in the US
Comments OffI was looking around on Google and thought I just for giggles check out the Piratebay complaints. I tried going to the site and here’s what Popups:
Tools for Virus Removal : The ones I like to use!
Comments OffIn this post I want to talk about virus removal tools that I like to use when I need to remove a virus. Some thing to consider when using these tools are:
Each of these have to be dealt with differently because each requires something different. Like rootkits if you have one installed and know that it is a rootkit you only options are to download some rootkit removers like:
- Sopho’s Anti-rootkit remover – This is good for those more known viruses and can remove several types of rootkits. This isn’t the only one I use, but it is a part of group that does the rootkit removing for me.
- Microsoft Rootkit Revealer – This is good for proving there is a rootkit. I’ve not seen it not detect a rootkit. Most of the time when I find a rootkit from the other rootkit revealers this one actually dos better with information.
- Panda Anti-Rootkit Remover — This one is another one I use when the other ones can’t remove it. Each one does remove certain rootkit differently and works better than the other.
Uncovering a Virus/Trojan
Comments OffGetting done with the first part really got my juices flowing. I was shopping looking and thinking about this next article. I came up to only one option turning this into a 3-5 length post due to all the content that I will have. So where did we leave off? Oh that is right figuring out if you have a virus/Trojan. The instant I made a post about this 12 hours later someone make a comment and here is what he said:
I can’t wait to read part two of this article. I always wondered how you’d know you’re infected if a virus don’t want to be detected and no virus definitions are yet available, because the virus is so new.
Now the truth is anytime a Virus does something it usually leaves a footprint somewhere and somehow. Even the hardest working hacker can’t plan for all possibilities and that is where we begin. I have been helping people for a while with viruses and know that no matter how hard the virus tries to hide you can usually find it relatively quickly and easily do to virus check here are the ways I’ve done to figure out if they may or may not have a virus/Trojan.
What is a Virus and Why do I have one
After seeing more and more the updates coming from the net. I wanted to talk about what a Computer Virus or Trojan is and how you get it. So how did you could of gotten a Virus in the first place. So here are some information to consider:
The vulnerability of operating systems to viruses
So what does that mean to you? Most of the times when you get a virus you have a vulnerability in some place in your Operating system and it is either something that has not be known by Microsoft, Apple, and Linux or is know as a Zero-day Exploit.
A zero-day (or zero-hour) attack or threat is a computer threat that tries to exploit unknown, undisclosed or patchfree computer application vulnerabilities. The term Zero Day is also used to describe unknown or Zero day viruses.
[Via Wikipedia]
This is one of the most used because if it is an unknown exploit by the Operating System creators then they have a longer to us the exploit. Most of the time hackers like to use this because that means there is a possibility of finding even more vectors to infect other systems. You see if they can get on one system they can then find ways to get on other systems.
Google let your work from home with Task Lists!!
Comments OffAs the day go by we have all have tasks, and that means we have to keep a way to remember them. Google decided to add that to there Google Mail. Pcworld said it the right way:
[Via Pcworld]
Facebook : Beware Spam for breakfast. (Virus)
Comments OffIn today’s society, we’ve been to complacent with people with people clicking links for the social group. In one such article on Channel Web, a nice little blog, says this:
The worm was discovered by IT security provider Kaspersky Lab, which said the threat, Net-Worm.Win32.Koobface.b, is targeting Facebook users by creating spam messages and sending them to the infected user’s friends via the site.
“Unfortunately, users are very trusting of messages left by ‘friends’ on social networking sites,” said Alexander Gostev, senior virus analyst at Kaspersky Lab, in a statement. “So, the likelihood of a user clicking on a link like this is very high.”
[Via Channel Web]
This seems to be a problem people thinking that a link someone sends them is a real good link but actually is a link to a video site. According to this article the links people are sending are actually a fake video link, telling you have to download some update to flash player, by downloading this program. The user gets involved with the virus and the fun begins. So how can you prevent this from happening, two ways one is a very good group of software to make sure you have the latest and greatest video codecs. That too can be something they’ll say you need and if you’ve already installed this list of codecs then you know they’ll not telling the truth and you can quickly get away from the site laughing.
Facebook Virus strikes again
Comments Off
“Look you were filmed all naked!” read the subject header on one iteration of the virus-spreading message, which is being sent automatically from infected accounts to the “friend” list for that account. Clicking the link usually takes users to a page that looks like YouTube, and a pop-up message advises the user to download a Flash plug-in. The download contains the virus, which replicates by contacting everyone on the victim’s Facebook friend list and advancing the hoax.[Via Boston Media]
Is this Windows 7?
Comments OffAs you can see that looks to be the final release of the start screen. In the past they haven’t change the start screen, it looks to be really polished and ready for use with Windows 7. If anything, I think the boot screen will be permanent and definitely not temporary. On a Side note, I found this video as well:
I also found one more little Video that looks to be promising, it’s called Windows 7 Super bar. This little Video looks convincingly like this will be kept in Windows 7 but you know how Microsoft is on beta’s. Any how, Here’s this one:
Windows 7 Super Bar from Paul Jenkins on Vimeo.
Hello Twitter, Goodbye Pounce!

In a move that feels more like a cruel prank than a financial strategy, Six Apart has purchased Pownce–only to shut the company down. The blogging company acquired the micro-blogging site for an undisclosed sum before announcing that it would shut Pownce in a mere two weeks.
[via PcMag]
Although if Six Apart was smart they should of tried to Monitize the service but I guess they just wasted there money in buying Pounce. They wanted something else from the company that owned Pounce but not sure what.
Black Friday gets way out of hand!!! (No JOKE)
Comments Off
OK, Black Friday has officially gotten out of hand. A 34-year-old WalMart employee was trying to hold back the crowds at a Long Island store this morning at 5am, when they took the doors off their hinges and stormed the store. The man fell down and was trampled by over 200 people as he gasped for air. It’s sad and despicable, and it’s equally the fault of the dehumanized shoppers and the WalMart store it happened at.
[via Gizmodo]
Cricket USB UM100 Broadband Wireless Modem Review.
The UM100c is No Longer Available, Please check out the Cricket A600 Modem Review Or the UM185 Broadband modem. The UM185 modem might be a replacement to the UM100.
After a full week of playing around with this USB wireless, I wanted to talk about it. So let’s break it down into pieces.
- (USB Broadband A600 Modem card for Free after Instant online rebates and Mail in rebate Free shipping & first month free! Shop today.)
- Installation – The installation of the USB was not to difficult. I did have to do some more steps than this: Install the Software, then hooked up the USB device to the USB port.
- Manual Activated the Broadband – For some reason in my area they had several people have problems with the broadband activation. So I had to activate it manually!!
After that all went well, I was on the internet just a cruising along. I did however wonder why I was getting such a slow response speed. When I went traveling I thought I would share some of my local results with you to better show you my speed. All these test were done at
Paypal is having troubles today.
According to Sue Bailey and I’ll quote:
Many sellers are reporting a problem this morning with PayPal withdrawals: attempting to move cash to your bank account throws up an error page beginning Sorry, an error occurred after you clicked the last link.
[Via Tamebay]
It seems to be something going on with Paypal. I’ve not tried it to day but I might just to see what happens. If anyone else is having this trouble let me know. Accord to Sue it seems to be limited to Merchants but that doesn’t mean sellers and others are having the same trouble. I also don’t know if it is just affecting the United Kingdom area or not but I wanted to let everyone know that this might affect you to. So let’s find out if it is affecting the US also.
Peek Email tops Time Gadget of the Year!
Comments Off
Go Vote and lets make our voice heard!!
Windows update is getting a revision!
Comments Off“Over the next couple of months, we’ll be rolling out another infrastructure update to the Windows Update agent (client code),” said an unidentified Microsoft employee on the Windows Update team’s official blog. “This update makes it possible for users to install more than 80 updates at the same time.”
[via Computer World]
Now if your like me and have several computers who need to be updated at a given schedule, you sometimes worry about these updates that come along that might just break your system. I have been using a program call Offline Updater, which does what Autopatcher does really nicely. So why is Microsoft sending out this patch? Two reasons, one they want you to be able to update your operating System without hurting your system integrity.
Now lets talk about the integrity of having to reboot your system. You see, every time you reboot the system, it causes the system hardware some strain. It is something like having starting up a car, sooner or later you will have the starter go out, because of to much start up.
Sony recalls 340,000 batteries.
Comments Off
Sony Recalls Notebook Computer Batteries Due to Previous Fires
The following product safety recall was voluntarily conducted by the firm in cooperation with the CPSC. Consumers should stop using the product immediately unless otherwise instructed.
Name of Product: Rechargeable, lithium ion batteries containing Sony cells used in Fujitsu Computer Systems Corporation, Gateway Inc., Sony Electronics Inc., and Toshiba America Information Systems Inc. notebook computers.Units: About 340,000 batteries (an additional 3,080,000 battery packs were sold worldwide)
Battery Cell Manufacturer: Sony Energy Devices Corp., of Japan
Hazard: These lithium ion batteries can overheat, posing a fire hazard to consumers.
Incidents/Injuries: There have been 16 reports of notebook computer batteries overheating, causing minor property damage and two minor burns. All of these reported incidents and injuries have been associated with earlier recalls of notebook computer batteries containing these Sony cells. There have been no incidents involving batteries sold by the notebook manufacturers participating in this announcement.
Some bloggers are Hyping Windows 7 operating System.
After looking around the blogosphere, I’ve come to the realization that people are starting to get hyped up over Windows 7. In one blog post from it.toolbox.com:
Windows 7 is due to hit beta and release in 2009, and odds are likely that if the pundits, all of us on the blogosphere and other places like PC World, Cnet, and others all agree that this works the way a computer was supposed to work will help drive sales. What is also interesting is that Microsoft is really pushing to get this puppy out. Along with the bloat are gone the five years of development.
[Via It.Toolbox.com]
I totally agree with what he is saying on the possibility to have an operating system actually do what it is told. Some things people have been looking for in there Searches in regards to Windows Vista are:













