<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-674153917791542448</atom:id><lastBuildDate>Tue, 22 Dec 2009 14:16:44 +0000</lastBuildDate><title>miekiemoes' Blog</title><description /><link>http://miekiemoes.blogspot.com/</link><managingEditor>noreply@blogger.com (miekiemoes)</managingEditor><generator>Blogger</generator><openSearch:totalResults>75</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/MiekiemoesBlog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-2262352529749261317</guid><pubDate>Mon, 02 Nov 2009 19:52:00 +0000</pubDate><atom:updated>2009-11-04T01:14:46.425+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Rant</category><title>IOBit Steals Malwarebytes’ Intellectual Property</title><description>Malwarebytes has recently uncovered evidence that a company called IOBit based in China is stealing and incorporating our proprietary database and intellectual property into their software. We know this will sound hard to believe, because it was hard for us to believe at first too. But after an indepth investigation, we became convinced it was true. Here is how we know.&lt;br /&gt;&lt;br /&gt;We came across a &lt;a href="http://forums.iobit.com/showthread.php?t=3325" target="_blank"&gt;post on the IOBit forums&lt;/a&gt; (&lt;a href="http://74.125.95.132/search?q=cache:7AiT5eWEygIJ:forums.iobit.com/showthread.php" target="_blank"&gt;cached version since they deleted the thread&lt;/a&gt; - well, now the cached version got deleted as well. Glad I still have a screenshot, see below) that showed IOBit Security 360 flagging a specific key generator for our Malwarebytes’ Anti-Malware software using the exact naming scheme we use to flag such keygens: &lt;span style="font-weight:bold;"&gt;Don’t.Steal.Our.Software.A.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_AiLE2bg2NHM/SvAYOuLNDeI/AAAAAAAABZo/6ubv9XKLcgA/s1600-h/dontstealoursoftware.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 154px;" src="http://2.bp.blogspot.com/_AiLE2bg2NHM/SvAYOuLNDeI/AAAAAAAABZo/6ubv9XKLcgA/s320/dontstealoursoftware.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5399842594409483746" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Dont.Steal.Our.Software.A, File, G:\Nothing Much\Anti-Spyware\Malwarebytes’ Anti-Malware v1.39\Key_Generator.exe, 9-30501&lt;br /&gt;&lt;br /&gt;Why would IOBit detect a keygen for our software and refer to it using our database name? We quickly became suspicious. Either the forum post was fraudulent or IOBit was stealing our database.&lt;br /&gt;&lt;br /&gt;So we dug further. We accumulated more similar evidence for other detections, and we soon became convinced that this was not a mistake, it was not a coincidence, it was not an isolated event, and it persisted presently in their current database. They are using both our database and our database format exactly.&lt;br /&gt;&lt;br /&gt;The final confirmation of IOBit’s theft occurred when we added fake definitions to our database for a fake rogue application we called Rogue.AVCleanSweepPro. This “malware” does not actually exist: we made it up. We even manufactured fake files to match the fake definitions. Within two weeks IOBit was detecting these fake files under almost exactly these fake names.&lt;br /&gt;&lt;br /&gt;We can’t publicly show all the evidence we found, because it is still our intellectual property: proprietary information about our database internals. But we don’t want you to have to take our word for it either, so we found a way to show you an example illustrating an indisputable pattern of theft.&lt;br /&gt;&lt;br /&gt;Consider the file, &lt;a href="http://www.malwarebytes.org/press/iobit/dummy.exe" target="_blank" &gt;dummy.exe&lt;/a&gt;. It is a harmless dummy executable that runs, displays a “Hello World” message box, and exits. You can see from third-party scans on &lt;a href="http://www.virustotal.com/analisis/7c29a8585563710440e5d2f4e638aeb3a474ebb3c7518b65b509d6bbbb6c029a-1257181353" target="_blank"&gt;VirusTotal&lt;/a&gt;, that no other security vendor flags this executable as malicious or even suspicious.&lt;br /&gt;&lt;br /&gt;We created this dummy executable, then manipulated it slightly so that it matches one of the signatures in our database. We emphasize that it is still not malicious! — the signature is perfectly benign, when not in the context of actual malware, as you can see from the VirusTotal results.&lt;br /&gt;&lt;br /&gt;We scanned the file with our own Malwarebytes’ Anti-Malware software and indeed it was flagged as “Don’t.Steal.Our.Software.A”. We scanned it with IOBit using their current build and database version and it was flagged as the same “Don’t.Steal.Our.Software.A”. We have included &lt;a href="http://www.malwarebytes.org/press/iobit/iobit_dummy.log" target="_blank"&gt;log file&lt;/a&gt; file and a &lt;a href="http://www.malwarebytes.org/press/iobit/screen_iobit_dummy.JPG" target="_blank"&gt;screenshot&lt;/a&gt; of the detection. You can verify by yourself using the dummy executable and their most recent database.&lt;br /&gt;&lt;br /&gt;We have attached two other such dummy executables to this post, so you can see for yourself. One of them, “rogue.exe”, matches our fake Rogue.AVCleanSweepPro (&lt;a href="http://www.malwarebytes.org/press/iobit/screen_iobit_rogue.JPG" target="_blank"&gt;screenshot&lt;/a&gt;) definition, the other “fake.exe”, matches our Adware.NaviPromo definition (&lt;a href="http://www.malwarebytes.org/press/iobit/screen_iobit_fake.JPG" target="_blank"&gt;screenshot&lt;/a&gt;). VirusTotal results for “&lt;a href="http://www.virustotal.com/analisis/b82c8266500f9f546826893576ece950ad5890c8d87f9e1c6f2246fa020185f3-1257185364" target="_blank"&gt;fake.exe&lt;/a&gt;” and “&lt;a href="http://www.virustotal.com/analisis/b80a5478b8f496122e631d020a2539fbd3275809bcf55671e6af263343240294-1257185121" target="_blank"&gt;rogue.exe&lt;/a&gt;” so you can see they are benign. You can see a screenshot of our detections &lt;a href="http://www.malwarebytes.org/press/iobit/screen_mbam.JPG"target="_blank"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;During the course of our investigation, we uncovered additional evidence that IOBit may have stolen the proprietary databases of other security vendors as well. We are in the process of contacting these vendors.&lt;br /&gt;&lt;br /&gt;Malwarebytes intends to pursue legal action against IOBit. We demand IOBit immediately remove all traces of Malwarebytes’ proprietary research and database from their software. We also demand IOBit be delisted from Download.com due to Terms of Service violations. This is criminal: it is theft, it is fraud, and we will not stand for it.&lt;br /&gt;&lt;br /&gt;What can you do to help? If you feel the same way we do about this theft, we encourage you to send an email to hosting services such as Download.com and Majorgeeks.com requesting that all IOBit software be removed.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Copy/paste of the original Article &lt;a href="http://malwarebytes.besttechie.net/2009/11/02/iobit-steals-malwarebytes-intellectual-property/"target="_blank"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Update to this post: &lt;a href="http://malwarebytes.besttechie.net/2009/11/03/iobits-denial-of-theft-unconvincing/" target="_blank"&gt;IOBit’s Denial of Theft Unconvincing&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-2262352529749261317?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/MiekiemoesBlog?a=Zj5bg7MV78M:LIq37Z1q4B8:nQ_hWtDbxek"&gt;&lt;img src="http://feeds.feedburner.com/~ff/MiekiemoesBlog?d=nQ_hWtDbxek" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/MiekiemoesBlog?a=Zj5bg7MV78M:LIq37Z1q4B8:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/MiekiemoesBlog?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/MiekiemoesBlog?a=Zj5bg7MV78M:LIq37Z1q4B8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/MiekiemoesBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/Zj5bg7MV78M" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/Zj5bg7MV78M/iobit-steals-malwarebytes-intellectual.html</link><author>noreply@blogger.com (miekiemoes)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_AiLE2bg2NHM/SvAYOuLNDeI/AAAAAAAABZo/6ubv9XKLcgA/s72-c/dontstealoursoftware.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2009/11/iobit-steals-malwarebytes-intellectual.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-7201943029173273832</guid><pubDate>Fri, 31 Jul 2009 14:43:00 +0000</pubDate><atom:updated>2009-07-31T16:46:33.290+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Mobile</category><title>My New Toy... a HTC Magic</title><description>I finally decided to buy a Smartphone...: &lt;a href="http://www.htc.com/www/product/magic/overview.html"target="_blank"&gt;http://www.htc.com/www/product/magic/overview.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_AiLE2bg2NHM/SnMDUoBxioI/AAAAAAAABWo/PPJZf33t7ZE/s1600-h/htcmagic.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 253px; height: 200px;" src="http://1.bp.blogspot.com/_AiLE2bg2NHM/SnMDUoBxioI/AAAAAAAABWo/PPJZf33t7ZE/s320/htcmagic.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5364635234005518978" /&gt;&lt;/a&lt;br /&gt;&lt;br /&gt;Love at first sight!&lt;br /&gt;Too many options and too much stuff to configure. This will certainly keep me busy for a while....&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-7201943029173273832?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/MiekiemoesBlog?a=hFK7LuCLXug:y1U4oi3RNmk:nQ_hWtDbxek"&gt;&lt;img src="http://feeds.feedburner.com/~ff/MiekiemoesBlog?d=nQ_hWtDbxek" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/MiekiemoesBlog?a=hFK7LuCLXug:y1U4oi3RNmk:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/MiekiemoesBlog?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/MiekiemoesBlog?a=hFK7LuCLXug:y1U4oi3RNmk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/MiekiemoesBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/hFK7LuCLXug" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/hFK7LuCLXug/my-new-toy-htc-magic.html</link><author>noreply@blogger.com (miekiemoes)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_AiLE2bg2NHM/SnMDUoBxioI/AAAAAAAABWo/PPJZf33t7ZE/s72-c/htcmagic.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2009/07/my-new-toy-htc-magic.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-2107469277293709552</guid><pubDate>Wed, 10 Jun 2009 22:45:00 +0000</pubDate><atom:updated>2009-06-12T08:10:30.246+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Malware</category><title>Searchengine Redirects? It could be a patched ws2_32.dll file...</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_AiLE2bg2NHM/SjA6VUvrToI/AAAAAAAABRA/9pxxyj1kSR8/s1600-h/ws2_32.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 106px;" src="http://3.bp.blogspot.com/_AiLE2bg2NHM/SjA6VUvrToI/AAAAAAAABRA/9pxxyj1kSR8/s320/ws2_32.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5345836895709122178" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I was helping someone yesterday (online support via forums) who was complaining about searchengine redirects. Redirections mainly went to mybig-portal.com, virus-detect-soft.com, edmonds.com, us.peeplo.com, directkitchenremodeling.com...&lt;br /&gt;&lt;br /&gt;There are already many different infections responsible for searchengine redirections, I see several different ones every day.... so after a while, it's getting easier for me where to look/search. &lt;br /&gt;The info is mainly gathered from logs (Registry loading points, Rootkit scans, etc).&lt;br /&gt;&lt;br /&gt;However, this one was different. I just couldn't find the culprit. Same scenario as with the first Daonol/JsRedirect/Gumblar variant I discussed &lt;a href="http://miekiemoes.blogspot.com/2008/10/fake-sysaudiosys-causes-searchengine.html"target="_blank"&gt;here&lt;/a&gt; last year (October 2008). &lt;br /&gt;People who know me also know that I will search untill I find it, so I finally found the culprit - a &lt;span style="font-weight:bold;"&gt;patched ws2_32.dll&lt;/span&gt; file. &lt;br /&gt;The ws2_32.dll is a legit Microsoft Windows file that contains the Windows Sockets API used by most Internet and network applications to handle network connections.&lt;br /&gt;In this case, it was patched by malware. Its copies in the dllcache and ServicePackFiles\i386 folder were also affected. Reference thread &lt;a href="http://www.spywareinfoforum.com/index.php?showtopic=124353&amp;st=0"target="_blank"&gt;here&lt;/a&gt;. &lt;br /&gt;It wasn't detected by any scanner yet. Sophos Antivirus will now detect this one as Troj/WShack-B.&lt;br /&gt;&lt;br /&gt;So if you encounter the same and just can't find the culprit of a searchengine Hijack after trying anything else - then it *may be a patched ws2_32.dll file. Don't delete that file if it's indeed patched/infected, but replace it with a clean copy.&lt;br /&gt;If unsure/in doubt, post you issue in the forums.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-2107469277293709552?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/MiekiemoesBlog?a=PpOW3TBs_II:vcCV2DcPAi4:nQ_hWtDbxek"&gt;&lt;img src="http://feeds.feedburner.com/~ff/MiekiemoesBlog?d=nQ_hWtDbxek" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/MiekiemoesBlog?a=PpOW3TBs_II:vcCV2DcPAi4:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/MiekiemoesBlog?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/MiekiemoesBlog?a=PpOW3TBs_II:vcCV2DcPAi4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/MiekiemoesBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/PpOW3TBs_II" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/PpOW3TBs_II/searchengine-redirects-it-could-be.html</link><author>noreply@blogger.com (miekiemoes)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_AiLE2bg2NHM/SjA6VUvrToI/AAAAAAAABRA/9pxxyj1kSR8/s72-c/ws2_32.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2009/06/searchengine-redirects-it-could-be.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-446484987015194173</guid><pubDate>Wed, 06 May 2009 12:38:00 +0000</pubDate><atom:updated>2009-05-06T14:44:36.512+02:00</atom:updated><title>In case you're wondering....</title><description>Yes, I'm still alive, just extremely busy lately. &lt;br /&gt;&lt;br /&gt;It's now already a couple of months that MalwareBytes hired me as Malware researcher, so that's where most of my time goes nowadays. &lt;br /&gt;I've decided I will only blog here once in a while - I hope at least once a month - but I cannot promise anything :-)&lt;br /&gt;&lt;br /&gt;Also... Thank you for the nice mails I've received lately via this blog and sorry I didn't respond earlier. It looks like something went wrong with the "Contact Me" mailform, so a lot of delayed (2 months or so) mails arrived just today. Anyway, this should be fixed now.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-446484987015194173?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/MiekiemoesBlog?a=ksM5BIEiFhI:8Zam_H-yz2s:nQ_hWtDbxek"&gt;&lt;img src="http://feeds.feedburner.com/~ff/MiekiemoesBlog?d=nQ_hWtDbxek" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/MiekiemoesBlog?a=ksM5BIEiFhI:8Zam_H-yz2s:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/MiekiemoesBlog?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/MiekiemoesBlog?a=ksM5BIEiFhI:8Zam_H-yz2s:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/MiekiemoesBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/ksM5BIEiFhI" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/ksM5BIEiFhI/in-case-youre-wondering.html</link><author>noreply@blogger.com (miekiemoes)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2009/05/in-case-youre-wondering.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-833033489024815109</guid><pubDate>Fri, 06 Mar 2009 11:26:00 +0000</pubDate><atom:updated>2009-03-08T07:44:57.451+01:00</atom:updated><title>In between message...</title><description>It's been a while that I've blogged and since I'm going through some major changes in my personal and professional life (maybe new job), I won't have the time and inspiration either to blog in the next couple of weeks. &lt;br /&gt;In a meanwhile... Click the icon to play a little game, so you didn't come here for nothing. :-)&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;a href="http://www.guimp.com/pong_flash.html" target="_new"&gt;&lt;img alt="World's smallest pong game" style="border:0" src="http://users.telenet.be/bluepatchy/miekiemoes/images/pong.gif"/&gt;&lt;/a&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;See you later!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-833033489024815109?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/MiekiemoesBlog?a=cf6PPhxRNU4:DkSVCNmU070:nQ_hWtDbxek"&gt;&lt;img src="http://feeds.feedburner.com/~ff/MiekiemoesBlog?d=nQ_hWtDbxek" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/MiekiemoesBlog?a=cf6PPhxRNU4:DkSVCNmU070:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/MiekiemoesBlog?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/MiekiemoesBlog?a=cf6PPhxRNU4:DkSVCNmU070:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/MiekiemoesBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/cf6PPhxRNU4" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/cf6PPhxRNU4/in-between-message.html</link><author>noreply@blogger.com (miekiemoes)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2009/03/in-between-message.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-7279162783142830208</guid><pubDate>Tue, 17 Feb 2009 13:25:00 +0000</pubDate><atom:updated>2009-02-17T14:35:01.079+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Malware</category><category domain="http://www.blogger.com/atom/ns#">Rant</category><title>Virut and other File infectors - Throwing in the Towel?</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_AiLE2bg2NHM/SZq7Jxmr1WI/AAAAAAAABGc/ohC3OJYjQ0Q/s1600-h/towel.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 250px; height: 166px;" src="http://3.bp.blogspot.com/_AiLE2bg2NHM/SZq7Jxmr1WI/AAAAAAAABGc/ohC3OJYjQ0Q/s320/towel.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5303757287790990690" /&gt;&lt;/a&gt;&lt;br /&gt;I actually wanted to blog about this last week, but didn't find the time yet...&lt;br /&gt;In the last couple of weeks, I noticed a HUGE increase of Virut present on computers. As a matter of fact, 30% of the infected computers I analyzed were infected with Virut. This is bad, really bad... :-(&lt;br /&gt;&lt;br /&gt;Virut is a Polymorphic File Infector that infects .EXE and .SCR files. It opens a Backdoor by connecting to a predefined IRC Server and waits for commands from the remote attacker - for example to download/run more malware on the compromised computer. Emails may be harvested as well.&lt;br /&gt;This &lt;a href="http://vil.nai.com/vil/content/v_154029.htm" target="_blank"&gt;latest variant&lt;/a&gt; may also search for htm, html, asp and php files on the drives and modifies them by inserting an iframe that points to a malicious website. So you can already imagine what may happen if the owner is a webdesigner and uploads the infected webpages.&lt;br /&gt;An excellent write up on this latest variant (and previous one) can also be found here (by Nicolas Brulez): &lt;a href="http://securitylabs.websense.com/content/Blogs/3300.aspx" target="_blank"&gt;http://securitylabs.websense.com/content/Blogs/3300.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Disinfection of the infected webpages should be easy - it's just a matter of deleting the iframe script in it.&lt;br /&gt;The disinfection of the infected exe and scr files is something else...&lt;br /&gt;Since Virut infects legitimate files, the files may not be deleted, but disinfected instead. And that's where the problems start...&lt;br /&gt;Virut was known to be a buggy Virus in the past and it appears that this &lt;a href="http://www.sophos.com/security/blog/2009/02/3130.html" target="_blank"&gt;hasn't changed yet&lt;/a&gt;. We've seen this with other File infectors as well: &lt;a href="http://www.sophos.com/security/blog/2008/05/1436.html" target="_blank"&gt;To Junk Or Not To Junk&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;And because of that, Virut may misinfect a proportion of executable files &gt; result &gt; corrupted file.&lt;br /&gt;The same applies for other File infectors such as Sality.&lt;br /&gt;&lt;br /&gt;If I guide someone with Virut (or any other File Infector) present and their Antivirus cannot properly disinfect it, then I recommend a format and reinstall.&lt;br /&gt;And even though an Antivirus is able to disinfect the files, in a lot of cases, many files will be corrupted anyway &gt; result &gt; many programs won't work &gt; loads of errors &gt; corrupted Windows + there's still no guarantee that the Virus is really gone. &lt;br /&gt;So why bother to clean this if a format and reinstall is the fastest and especially the safest solution?&lt;br /&gt;&lt;br /&gt;And that's why I am blogging about this in the first place, especially since Virut is a very common infection nowadays. It's a pity to see that so many people are struggling with it and whatever they try, nothing helps. Then they ask for support via the forums and in a lot of cases, the one who is helping/guiding won't give up either and posts a new set of instructions to deal with this one. &lt;br /&gt;Unfortunately another failure as result, so again, new instructions are posted... and this may go on and on...sometimes for weeks....&lt;br /&gt;Is this responsible? &lt;br /&gt;I'm not saying it fails everytime, but from what I have seen so far and especially if you're helping someone else with this infection... don't guarantee them a "clean" and errorfree computer afterwards .&lt;br /&gt;&lt;br /&gt;In anyway, that's how I see it. Imho, dealing with such infections is a waste of time and that's why I prefer the fastest and safest solution - which is a format and reinstall.&lt;br /&gt;Many people may see this as "giving up", but I see this different. &lt;br /&gt;After all, I think it would be irresponsible to let the malware "stew" (download/spread/run more malware) for another couple of days/weeks if you already know it's a lost case.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-7279162783142830208?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=QE8Oniom"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=183" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=IjZHJXGM"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=43" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=EVVcDWqq"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/VRvWK08NR-o" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/VRvWK08NR-o/virut-and-other-file-infectors-throwing.html</link><author>noreply@blogger.com (miekiemoes)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_AiLE2bg2NHM/SZq7Jxmr1WI/AAAAAAAABGc/ohC3OJYjQ0Q/s72-c/towel.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2009/02/virut-and-other-file-infectors-throwing.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-2086110790720187243</guid><pubDate>Wed, 04 Feb 2009 15:55:00 +0000</pubDate><atom:updated>2009-02-04T17:09:56.894+01:00</atom:updated><title>Happy Dance - Blog 1 year old!</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://users.telenet.be/bluepatchy/miekiemoes/images/elmo.gif"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 90px; height: 120px;" src="http://users.telenet.be/bluepatchy/miekiemoes/images/elmo.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I started with this blog exactly 1 year ago. I actually didn't expect anything from this since I'm not a writer and don't have enough inspiration either to update my blog every (other) day. &lt;br /&gt;The main goal of this blog was to post some tutorials and thoughts for the "average" user I was helping on forums and newsgroups - so I could link to my blogposts instead of reposting it again and again.&lt;br /&gt;I was already happy with only a few blogposts and actually didn't really plan to update it anyway - only once in a while. &lt;br /&gt;Maybe I could have updated my blog more often with latest Security News etc, but decided not to do so. &lt;br /&gt;However, after a month or two, I saw that some people started to follow this blog and linked to it as well. That was a pleasant surprise.&lt;br /&gt;And that's why I'm still updating this blog with thoughts (mainly rants), tutorials and other (stupid) stuff. &lt;br /&gt;&lt;br /&gt;Anyway, thanks for the comments and feedback I have received so far - I've learned a lot from this and I'm still learning every day!&lt;br /&gt;&lt;br /&gt;Thank you readers!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-2086110790720187243?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=fA8SyLQ1"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=183" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=jbaeVBr2"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=43" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=Qur6ozCB"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/t8Oi-DUfJ0I" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/t8Oi-DUfJ0I/happy-dance-blog-1-year-old.html</link><author>noreply@blogger.com (miekiemoes)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2009/02/happy-dance-blog-1-year-old.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-3405692009414146455</guid><pubDate>Sat, 31 Jan 2009 11:46:00 +0000</pubDate><atom:updated>2009-01-31T14:16:16.924+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">hacks</category><category domain="http://www.blogger.com/atom/ns#">websites</category><title>IX Web Hosting - Reliable?</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_AiLE2bg2NHM/SYQ7HpvERXI/AAAAAAAABFk/gnrzYgCciew/s1600-h/ix.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 117px;" src="http://1.bp.blogspot.com/_AiLE2bg2NHM/SYQ7HpvERXI/AAAAAAAABFk/gnrzYgCciew/s320/ix.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5297424064342934898" /&gt;&lt;/a&gt;&lt;br /&gt;Someone contacted me recently about the &lt;a href="http://miekiemoes.blogspot.com/2008/10/fake-sysaudiosys-causes-searchengine.html" target="_blank"&gt;wdmaud.sys / sysaudio.sys - Win32:Daonol&lt;/a&gt; infection. This because his site was injected with the iFrame Javascript "Yahoo! Counter starts here". People who visit the compromised site will get infected with Win32:Daonol.&lt;br /&gt;Even though he removed all injected code, it came back all the time. Also, he couldn't understand how his site(s) got compromised in the first place.&lt;br /&gt;Until he told me what his webhosting service was..... &lt;span style="font-weight:bold;"&gt;IX Web Hosting&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;A quick google search explained a lot....&lt;br /&gt;&lt;br /&gt;There's even a blog called "&lt;a href="http://ixwebhostwarning.wordpress.com" target="_blank"&gt;&lt;span style="font-weight:bold;"&gt;IX Web Hosting Warning&lt;/span&gt;&lt;/a&gt;" to warn people for this webhosting company.&lt;br /&gt;Quote from their &lt;a href="http://ixwebhostwarning.wordpress.com/about-the-ix-web-hosting-horror/" target="_blank"&gt;About&lt;/a&gt; page:&lt;br /&gt;&lt;br /&gt;&lt;font size="1"&gt;"IX Web Hosting the incompetant cheap web hosting company was hacked in May of this year, and hackers managed to “seed” the servers, which are now injecting 1000’s of  innocent paying customers websites, on a weekly basis. It has gotten so bad, and happened so frequently  that even the backups are infected.&lt;br /&gt;&lt;br /&gt;This has been going on now for almost 8 months!!… Yes that is correct, 8 months, and IX web hosting has still not fixed this massive security issue.&lt;br /&gt;The worst part of this ordeal, is the fact that IX web hosting knows, and has openly admitted to certain people ( myself being one) that they have a massive issue, they still blame the innocent customers that it is their fault."&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;In anyway, that may also explain why so many people got infected with Win32:Daonol lately:&lt;br /&gt;&lt;font size="1"&gt;&lt;a href="http://ixwebhostwarning.wordpress.com/2008/12/24/ix-web-hosting-and-the-yahoo-counter-script-injection/" target="_blank"&gt;http://ixwebhostwarning.wordpress.com/2008/12/24/ix-web-hosting-and-the-yahoo-counter-script-injection/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ixwebhostwarning.wordpress.com/2009/01/11/is-your-site-infected-by-the-yahoo-counter-or-htaccess/" target="_blank"&gt;http://ixwebhostwarning.wordpress.com/2009/01/11/is-your-site-infected-by-the-yahoo-counter-or-htaccess/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;"Thousands of IX web Hosting customers are infected with this code, and they do not even know it! The web Page looks normal, but this can be very dangerous, your website will eventually drop from ALL the mayor search engines, and your domain will be flagged as “Dangerous Malware” by all the search engines."&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;Lesson learned: Avoid IX Web Hosting - Avoid sites being hosted with IX Web Hosting, because you may get infected.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-3405692009414146455?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=I9f5NUbR"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=183" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=qfeHt6tE"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=43" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=P7ezJpiD"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/YqwCd5nVtiA" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/YqwCd5nVtiA/ix-web-hosting-reliable.html</link><author>noreply@blogger.com (miekiemoes)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_AiLE2bg2NHM/SYQ7HpvERXI/AAAAAAAABFk/gnrzYgCciew/s72-c/ix.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2009/01/ix-web-hosting-reliable.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-2267811154189292397</guid><pubDate>Thu, 22 Jan 2009 09:41:00 +0000</pubDate><atom:updated>2009-01-22T17:47:55.906+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Malware</category><title>Miekiemoes rules ?? Yeah right...</title><description>This is about the Searchengine Hijack I &lt;a href="http://miekiemoes.blogspot.com/2008/10/fake-sysaudiosys-causes-searchengine.html" target="_blank"&gt;blogged&lt;/a&gt; about a couple of months ago. Files responsible for this hijack are &lt;span style="font-weight:bold;"&gt;sysaudio.sys&lt;/span&gt; or &lt;span style="font-weight:bold;"&gt;wdmaud.sys&lt;/span&gt;, present in the system32 folder - detected by most scanners as &lt;span style="font-weight:bold;"&gt;Win32:Daonol&lt;/span&gt;.&lt;br /&gt;&lt;a href="http://miekiemoes.blogspot.com/2008/10/fake-sysaudiosys-causes-searchengine.html#IDComment14191939" target="_blank"&gt;Someone&lt;/a&gt; notified me yesterday about a version of Win32:Daonol which is a bit different than other versions.&lt;br /&gt;The malware author(s) decided to add "Miekiemoes rules" under file description in one of its versions. &lt;img src="http://users.telenet.be/bluepatchy/miekiemoes/images/wassat.gif"&gt;&lt;br /&gt;Again, another proof why not to believe what malware tells you :P&lt;br /&gt;&lt;br /&gt;This is what you get when you hover your mouse over the malicious wdmaud.sys: &lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_AiLE2bg2NHM/SXg_k9l5E5I/AAAAAAAABD0/8atWmc2gIiU/s1600-h/miekiemoesrules.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 85px;" src="http://3.bp.blogspot.com/_AiLE2bg2NHM/SXg_k9l5E5I/AAAAAAAABD0/8atWmc2gIiU/s320/miekiemoesrules.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5294051266215351186" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I only have above screenshot. The person who uploaded this screenshot for me already deleted the wdmaud.sys, so no sample available. In anyway, thanks for the screenshot. &lt;br /&gt;&lt;br /&gt;&lt;s&gt;Sample is welcome (only above version). &lt;/s&gt;&lt;br /&gt;Edit - Sample received - Thank you blogreaders :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-2267811154189292397?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=rhpicZso"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=183" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=Lttp2PQQ"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=43" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=gazzisbO"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/MX8_QKCf5ZA" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/MX8_QKCf5ZA/miekiemoes-rules-yeah-right.html</link><author>noreply@blogger.com (miekiemoes)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_AiLE2bg2NHM/SXg_k9l5E5I/AAAAAAAABD0/8atWmc2gIiU/s72-c/miekiemoesrules.gif" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2009/01/miekiemoes-rules-yeah-right.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-7465128751887976472</guid><pubDate>Wed, 14 Jan 2009 14:57:00 +0000</pubDate><atom:updated>2009-01-14T16:21:25.183+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Firefox</category><title>Settings won't save in Firefox</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_AiLE2bg2NHM/SW39dHYurZI/AAAAAAAABDs/GgIWaAs631U/s1600-h/userversusprefs.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 132px;" src="http://2.bp.blogspot.com/_AiLE2bg2NHM/SW39dHYurZI/AAAAAAAABDs/GgIWaAs631U/s320/userversusprefs.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5291163813871005074" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is another common problem I see in forums lately. This especially since more and more malware targets firefox as well.&lt;br /&gt;An example we see in forums lately is "&lt;span style="font-weight:bold;"&gt;Yoog Search&lt;/span&gt;". This is a searchengine Hijacker - comes with a variant of AdRotator/IconAds Adware.&lt;br /&gt;The Firefox startpage + searchengine / Searchsettings get hijacked and even though the malware (responsible for changing startpage+searchengine) is gone/deleted already, if people want to change it back to default again, or change it back to their own startpage / searchengine, firefox won't save the settings.&lt;br /&gt;So after a next Firefox session, the Hijacked startpage / searchengine etc is back again.&lt;br /&gt;&lt;br /&gt;The cause is a &lt;span style="font-weight:bold;"&gt;user.js&lt;/span&gt; file present inside the &lt;a href="http://kb.mozillazine.org/Profile_folder" target="_blank"&gt;Firefox profile folder&lt;/a&gt;. So, in this case the %APPDATA%\Mozilla\Firefox\Profiles\&lt;span style="font-style:italic;"&gt;"identity"&lt;/span&gt; folder.&lt;br /&gt;The user.js file &lt;span style="font-weight:bold;"&gt;does not exist by default&lt;/span&gt; and was in this case added/modified by malware. &lt;br /&gt;This file is used to set or reset preferences to a default value. For example whenever the browser is loaded, the values present in the user.js file will supersede the stored values in the prefs.js file.&lt;br /&gt;The prefs.js file contains the values you can access/modify via about:config or via the preferences in Tools &gt; Options Menu in Firefox.&lt;br /&gt;See &lt;a href="http://kb.mozillazine.org/User.js_file" target="_blank"&gt;here&lt;/a&gt; for more info about the user.js file.&lt;br /&gt;&lt;br /&gt;I've also seen the same where malware changed the Proxysettings and created a user.js file to store the Proxysettings there. Result &gt; once the malware was removed, the user would get the error: "The Proxy Server is Refusing Connections" since the user.js file is still in use.&lt;br /&gt;Some versions of the Ask Toolbar also create a user.js file in the Firefox userprofile, so after uninstalling the Ask Toolbar, the homepage + searches are still set to Ask.com because the user.js file is still present.&lt;br /&gt;&lt;br /&gt;That's why, if you're ever having problems with Firefox that won't save settings like startpage, searchengine, proxysettings etc.., then look if a user.js file is present in the Firefox profile folder and delete or modify it.&lt;br /&gt;The presence of user.js in the Firefox profile folder doesn't necessarily mean that it's a bad file. Many people create their own user.js to supersede the stored values in the prefs.js file. So if you didn't create the user.js file yourself, you may delete it (since it's not present by default anyway).&lt;br /&gt;If you're not sure, just rename it to user.js.bak, or open the file with notepad to see what values are present there.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-7465128751887976472?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=VkYHwITS"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=183" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=1qLQPg6u"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=43" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=elcXXC42"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/xanWNF4ZEvg" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/xanWNF4ZEvg/settings-wont-save-in-firefox.html</link><author>noreply@blogger.com (miekiemoes)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_AiLE2bg2NHM/SW39dHYurZI/AAAAAAAABDs/GgIWaAs631U/s72-c/userversusprefs.gif" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2009/01/settings-wont-save-in-firefox.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-8975556598033322699</guid><pubDate>Mon, 15 Dec 2008 10:05:00 +0000</pubDate><atom:updated>2008-12-15T11:11:05.251+01:00</atom:updated><title>Cold Turkey for X-mas.</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_AiLE2bg2NHM/SUYsH8PAXcI/AAAAAAAABCw/FjmHKDbvrps/s1600-h/coldturkey.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 233px; height: 166px;" src="http://4.bp.blogspot.com/_AiLE2bg2NHM/SUYsH8PAXcI/AAAAAAAABCw/FjmHKDbvrps/s320/coldturkey.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5279956128078257602" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I haven't been online much lately, this for several reasons. One of the reasons is.. I quit smoking!&lt;br /&gt;I was trying to avoid situations where cigs were needed the most. I have to admit that actually every situation where I was allowed to smoke was a reason to smoke. &lt;br /&gt;But the worst situation was when I was using computers - more than 10 hours a day, one cig after another. You can imagine I was smoking a lot!&lt;br /&gt;&lt;br /&gt;I've already tried to quit last year - but that failed. I was going nuts after two days and a cig was my only relief. Sad, isn't it?&lt;br /&gt;After my failure last year, I decided to smoke less. I didn't allow myself to smoke in the house anymore. So everytime I wanted a cig, I had to go outside, or smoke in the garage.&lt;br /&gt;This actually helped a lot, I didn't break my own rule and smoked only the half of what I used to smoke. Even when I was using the computer, instead of having 6 (or sometimes more) cigs in one hour, I only had to go outside 2 or 3 times an hour. (I know, I know, it's still a lot).&lt;br /&gt;&lt;br /&gt;After a couple of months (last week), I was wondering what I was actually doing. This was just silly and I had to stop that.&lt;br /&gt;&lt;br /&gt;My own rule to go outside for a smoke worked like I charm and I never broke that rule. So why can't I make my own rule to quit smoking?&lt;br /&gt;&lt;br /&gt;So, last week, I smoked my last cig and that was it. &lt;br /&gt;&lt;br /&gt;I'm not using any nicotine replacement therapy aids like gum, patches or inhalers. No medications either like Zyban to reduce the craving, no hypnosis, acupuncture.... whatever. Just quit smoking Cold Turkey.&lt;br /&gt;The only thing I used was a book (no, I didn't smoke it) by Allen Carr - "Easy Way To Stop Smoking". As a matter of fact, it is easy if you believe it! &lt;br /&gt;&lt;br /&gt;It's already more than a week I quit smoking and I have to say - it's going pretty well. I've tried to avoid computers as much as possible in the first couple of days. Now I'm "facing" computers again and I don't really feel the "hunger" for a cig. The only thing is -  I still feel the need to stand up 2 or 3 times in an hour to go outside. :-)&lt;br /&gt;I'm like Pavlov's Dog - but then I remember the famous quote by Yoda: "You must unlearn what you have learned". &lt;br /&gt;&lt;br /&gt;Anyway, I'm glad I quit smoking and I'm sure I won't fail this time.&lt;br /&gt;&lt;br /&gt;Happy Holidays!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-8975556598033322699?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=y23KqwcJ"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=183" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=6TrKDzIN"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=43" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=pn27sT9e"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/sAHVNad62x4" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/sAHVNad62x4/cold-turkey-for-x-mas.html</link><author>noreply@blogger.com (miekiemoes)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_AiLE2bg2NHM/SUYsH8PAXcI/AAAAAAAABCw/FjmHKDbvrps/s72-c/coldturkey.gif" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2008/12/cold-turkey-for-x-mas.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-6655466378177683096</guid><pubDate>Sun, 23 Nov 2008 14:31:00 +0000</pubDate><atom:updated>2009-01-22T16:55:04.219+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Prevention</category><title>Please disable Autorun asap!</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_AiLE2bg2NHM/SSlpcL40EuI/AAAAAAAAA7k/VO28FPFiQGs/s1600-h/autorun.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 313px; height: 320px;" src="http://4.bp.blogspot.com/_AiLE2bg2NHM/SSlpcL40EuI/AAAAAAAAA7k/VO28FPFiQGs/s320/autorun.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5271860771762213602" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;We see an increase in USB-Based Malware Attacks lately - See &lt;a href="https://forums.symantec.com/syment/blog/article?blog.id=malicious_code&amp;thread.id=220" target="_blank"&gt;here&lt;/a&gt; and &lt;a href="http://www.cert.org/blogs/vuls/2008/04/the_dangers_of_windows_autorun.html" target="_blank"&gt;here&lt;/a&gt; for more info.&lt;br /&gt;Unfortunately, in the last few weeks, I have seen many cases where the enabled autorun feature caused A LOT of problems afterwards. This means that many are not aware of the dangers yet.&lt;br /&gt;For example.. Some scenarios I have seen in the last couple of weeks are:&lt;br /&gt;&lt;br /&gt;* Computer gets infected with &lt;a href="http://www.eset.sk/buxus/generate_page.php?page_id=20616" target="_blank"&gt;Win32/Sality.NAR&lt;/a&gt; (NOD32 detection). This is a polymorphic file infector which searches local and network drives for files with the .exe extension and infects them by adding a new section that contains the viruscode.&lt;br /&gt;It also copies itself into the root folders of removable drives using a random filename and creates an autorun.inf file to make sure it runs whenever it is inserted into another computer. It also disables most AV scanners by terminating their services/processes, disables Taskmanager, disables Regedit and much more to prevent it being detected or disinfected.&lt;br /&gt;In this case, the user had an USB flashdrive and used it to transfer removal tools etc in order to remove this infection, since no scanners would work. What happened was, since this virus also spreads via removable media, his USB flashdrive became infected &gt; result &gt; His other computer was infected as well!&lt;br /&gt;&lt;br /&gt;* Computer gets infected with &lt;a href="http://www.sophos.com/security/analyses/viruses-and-spyware/w32autorunoy.html" target="_blank"&gt;W32/AutoRun-OY&lt;/a&gt; - This one also spreads via removable drives. This computer is used at home and every user has its own account. Mom, dad, son and daughter. Son loves to play games, but also loves to download games + cracks via illegal resources.&lt;br /&gt;And that's how the computer at home gets infected with W32/AutoRun-OY. No detection since the Antivirus application that was installed was only a trial and was already expired for more than a year. Dad works for a big company and he tranfers his database+files from the computer at work to an USB flashdrive so he can proceed with his work at home. &lt;br /&gt;The usb flashdrive gets infected when he inserts it into the infected computer at home. Since no scanner (because it's outdated) gives an alert and blocks the malware, there's no sign that the computer + Flashdrive is infected.&lt;br /&gt;Dad goes back to work, inserts the flashdrive into his computer at work and... it gets infected as well. No alert, nothing! It appears that the computer at work didn't even have an Antivirus installed !! And, worst part of all was... &lt;a href="http://miekiemoes.blogspot.com/2008/06/virut-is-back-again-sigh.html" target="_blank"&gt;Virut&lt;/a&gt; was also present! See &lt;a href="http://www.f-secure.com/v-descs/virus_w32_virut.shtml" target="_blank"&gt;here&lt;/a&gt; for more info. This is imho a lost case, and especially for business owned computers, it is irresponsible to clean this up manually. Format and reinstall is the fastest and especially &lt;span style="font-weight:bold;"&gt;the safest&lt;/span&gt; solution here.&lt;br /&gt;So, who is to blame here? Imho, everyone is. The son who is responsible for visiting illegal sites in order to download his games + cracks, plus the fact that the Antivirus was outdated, plus the fact that dad uses an USB flashdrive containing corporate information and inserts it into the personal computer (see &lt;a href="http://www.us-cert.gov/cas/tips/ST08-001.html" target="_blank"&gt;here&lt;/a&gt; how to protect your data), plus the fact that the computers at work didn't even have any protection/AV installed.&lt;br /&gt;Anyway, this is so irresponsible, especially when company owned computers are involved.&lt;br /&gt;&lt;br /&gt;* And today, I have another case where someone gets infected with W32/AutoRun-OY, where mom uses an usb flashdrive to transfer files to use at work and is already complaining about the fact that there are "problems". This thread is still in progress and I really hope this isn't a lost case.&lt;br /&gt;&lt;br /&gt;No wonder the &lt;a href="http://blog.wired.com/defense/2008/11/army-bans-usb-d.html" target="_blank"&gt;Military bans disks and USB drives&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This appears to be a common problem nowadays - that's why it is so important to prevent spreading similar infections by disabling Autorun.&lt;br /&gt;&lt;br /&gt;To disable autorun, please read the following tutorials:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.howtogeek.com/howto/windows/disable-autoplay-of-audio-cds-and-usb-drives/" target="_blank"&gt;http://www.howtogeek.com/howto/windows/disable-autoplay-of-audio-cds-and-usb-drives/&lt;/a&gt; (applies for XP Pro since XP Home has no gpedit.msc present)&lt;br /&gt;&lt;a href="http://www.engadget.com/2004/06/29/how-to-tuesday-disable-autorun-on-windows/" target="_blank"&gt;http://www.engadget.com/2004/06/29/how-to-tuesday-disable-autorun-on-windows/&lt;/a&gt;  (aplies for XP Home. Same can be used for XP Pro)&lt;br /&gt;&lt;a href="http://www.howtogeek.com/howto/windows-vista/disable-autoplay-in-windows-vista/" target="_blank"&gt;http://www.howtogeek.com/howto/windows-vista/disable-autoplay-in-windows-vista/&lt;/a&gt; (applies for Vista)&lt;br /&gt;&lt;br /&gt;Some malware removal tools already disable Autorun by default. Don't complain about this. This is an extra security measure and you should have it disabled. If you really want to enable this again - then it's your own responsibility. Don't complain afterwards if you get infected and are responsible for infecting a lot of other computers as well.&lt;br /&gt;&lt;br /&gt;Update: Extra instructions to disable autorun (by US CERT) can be found &lt;a href="http://www.us-cert.gov/cas/techalerts/TA09-020A.html"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-6655466378177683096?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=5q6ZKXbQ"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=183" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=PdlhnpDO"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=43" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=ZWSpEuOD"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/EW4AiOsRM80" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/EW4AiOsRM80/please-disable-autorun-asap.html</link><author>noreply@blogger.com (miekiemoes)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_AiLE2bg2NHM/SSlpcL40EuI/AAAAAAAAA7k/VO28FPFiQGs/s72-c/autorun.gif" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2008/11/please-disable-autorun-asap.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-8163604026726734771</guid><pubDate>Wed, 19 Nov 2008 17:40:00 +0000</pubDate><atom:updated>2008-11-19T19:22:54.766+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">phish</category><title>And another Paypal Phish...</title><description>This is a mail I received in my mailbox one hour ago:&lt;br /&gt;&lt;br /&gt;&lt;font size="1"&gt;&lt;span style="font-style:italic;"&gt;For your protection, we have limited access to your account until additional security&lt;br /&gt;measures can be completed. We apologize for any inconvenience this may cause.&lt;br /&gt;&lt;br /&gt;To review your account and some or all of the information that Pay Pal&lt;br /&gt;used to make its decision to limit your account access, please visit the Resolution Center.&lt;br /&gt;&lt;br /&gt;We encourage you to log in and restore full access as soon as possible. Should access to your&lt;br /&gt;account remain limited for an extended period of time, it may result in further limitations on&lt;br /&gt;the use of your account or may result in eventual account closure.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Click here to resolve the problem.&lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Sincerely,&lt;br /&gt;PayPal Account Review Team&lt;/font&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_AiLE2bg2NHM/SSRZTv1-RKI/AAAAAAAAA60/GxbRI9pvOi4/s1600-h/paypalphish.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 305px;" src="http://3.bp.blogspot.com/_AiLE2bg2NHM/SSRZTv1-RKI/AAAAAAAAA60/GxbRI9pvOi4/s320/paypalphish.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5270435659725554850" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;font size="1"&gt;&lt;span style="font-style:italic;"&gt;&lt;center&gt;Click to enlarge&lt;/center&gt;&lt;/span&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;After I clicked the link, I was presented with this fake page:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_AiLE2bg2NHM/SSRRlSHqSeI/AAAAAAAAA6c/b4o--COh8s0/s1600-h/paypalphish1.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 193px;" src="http://2.bp.blogspot.com/_AiLE2bg2NHM/SSRRlSHqSeI/AAAAAAAAA6c/b4o--COh8s0/s320/paypalphish1.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5270427164891302370" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;font size="1"&gt;&lt;span style="font-style:italic;"&gt;&lt;center&gt;Click to enlarge&lt;/center&gt;&lt;/span&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;Ok, let's enter "my" Email Address and PayPal Password to Log In.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_AiLE2bg2NHM/SSRSqD6JiuI/AAAAAAAAA6k/FT4p51M754s/s1600-h/paypalphish2.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 130px;" src="http://4.bp.blogspot.com/_AiLE2bg2NHM/SSRSqD6JiuI/AAAAAAAAA6k/FT4p51M754s/s320/paypalphish2.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5270428346487507682" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;font size="1"&gt;&lt;span style="font-style:italic;"&gt;&lt;center&gt;Click to enlarge&lt;/center&gt;&lt;/span&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;The usual Logging in screen, which then opened the following page:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_AiLE2bg2NHM/SSRTEK7bVmI/AAAAAAAAA6s/xe6UV6ttMfQ/s1600-h/paypalphish3.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 318px; height: 320px;" src="http://2.bp.blogspot.com/_AiLE2bg2NHM/SSRTEK7bVmI/AAAAAAAAA6s/xe6UV6ttMfQ/s320/paypalphish3.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5270428795048515170" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;font size="1"&gt;&lt;span style="font-style:italic;"&gt;&lt;center&gt;Click to enlarge&lt;/center&gt;&lt;/span&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;They don't only want your Paypal Password, but as you see, A LOT of other information as well - Card number, Expiration date, Card verification number, &lt;span style="font-weight:bold;"&gt;Pin number&lt;/span&gt; and Bank name.&lt;br /&gt;&lt;br /&gt;Anyway, if you became a victim of this Phish, contact Paypal and your Bank immediately and change your Paypal Password asap!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-8163604026726734771?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=BTsrqo0x"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=183" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=3Y3jNZWO"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=43" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=ghWnx9dT"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/V3pLMdnIdmI" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/V3pLMdnIdmI/and-another-paypal-phish.html</link><author>noreply@blogger.com (miekiemoes)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_AiLE2bg2NHM/SSRZTv1-RKI/AAAAAAAAA60/GxbRI9pvOi4/s72-c/paypalphish.gif" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2008/11/and-another-paypal-phish.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-3937335677590373965</guid><pubDate>Sun, 16 Nov 2008 00:34:00 +0000</pubDate><atom:updated>2008-11-18T16:50:59.882+01:00</atom:updated><title>MSN Virus!! No scanners detect it!!!!</title><description>This is a common subject I see in forums lately. &lt;br /&gt;People are complaining about an "MSN Virus" and no scanners can detect it. &lt;br /&gt;This so called "MSN Virus" is responsible for sending links to their contacts list. &lt;br /&gt;Yes, there are indeed some worms, spreading via messenger and infecting your computer, for example the &lt;a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_IRCBOT.RB" target="_blank"&gt;IRCBOT-RB Trojan&lt;/a&gt;  and many other variants.&lt;br /&gt;&lt;br /&gt;However, this one is totally different... and is actually already going on for a while...&lt;br /&gt;&lt;br /&gt;It appears that many aren't aware of this one yet, because I still see so many threads in forums where many AV scanners and other scanners were being used &gt; result &gt; no detections, no strange files, no strange loading points etc.. &lt;br /&gt;Long threads with no ending since they can't find the main cause. &lt;br /&gt;&lt;br /&gt;Actually, the main cause is very simple - The login/password of the MSN account was gathered because they entered that info via the link they received once.&lt;br /&gt;This is an example of a link they receive:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_AiLE2bg2NHM/SR9rwh5SxLI/AAAAAAAAA50/JqNpDN76IfQ/s1600-h/msnphish.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 240px; height: 192px;" src="http://2.bp.blogspot.com/_AiLE2bg2NHM/SR9rwh5SxLI/AAAAAAAAA50/JqNpDN76IfQ/s320/msnphish.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5269048570523337906" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;More detailed info from some older blogposts:&lt;br /&gt;&lt;a href="http://phatybomb.blogspot.com/2008/04/how-to-solve-this-pesky-msn-virus.html" target="_blank"&gt;http://phatybomb.blogspot.com/2008/04/how-to-solve-this-pesky-msn-virus.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blog.spywareguide.com/2008/06/another-site-asking-for-msn-lo.html" target="_blank"&gt;http://blog.spywareguide.com/2008/06/another-site-asking-for-msn-lo.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Links may be different, but the scenario is still the same.&lt;br /&gt;&lt;br /&gt;If you click that link, your browser will open and you are presented with a webpage where it prompts you to enter your MSN Login and Password to proceed. &lt;br /&gt;Ofcourse, the only purpose here is to gather your Login and password so they can (ab)use it to log in into your account and send the same link to your other contacts.&lt;br /&gt;In this case, your computer isn't infected which explains why scanners won't find a thing.&lt;br /&gt;&lt;br /&gt;Solution is simple: &lt;span style="font-weight:bold;"&gt;Change your MSN password&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;As I said, this one is already going on for a while - but in the last couple of days, I see more and more threads in forums about this one - endless threads with several different logs which won't show anything.&lt;br /&gt;That's why, if you think you're dealing with a similar "infection", change your password first and see if that solves your problem. If not, then make sure your Antivirus Scanner is up to date and perform a full scan with it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-3937335677590373965?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=ckc9Cyos"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=183" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=O413bEZL"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=43" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=FQBguOTf"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/Il3Pnim2wo8" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/Il3Pnim2wo8/msn-virus-no-scanners-detect-it.html</link><author>noreply@blogger.com (miekiemoes)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_AiLE2bg2NHM/SR9rwh5SxLI/AAAAAAAAA50/JqNpDN76IfQ/s72-c/msnphish.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2008/11/msn-virus-no-scanners-detect-it.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-7545185400755028658</guid><pubDate>Tue, 11 Nov 2008 11:31:00 +0000</pubDate><atom:updated>2008-11-11T12:41:53.388+01:00</atom:updated><title>Congrats Belsec!</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_AiLE2bg2NHM/SRltdtyy8kI/AAAAAAAAA5s/D_TNaf67Ul0/s1600-h/birthday.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 299px; height: 270px;" src="http://4.bp.blogspot.com/_AiLE2bg2NHM/SRltdtyy8kI/AAAAAAAAA5s/D_TNaf67Ul0/s320/birthday.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5267361596462789186" /&gt;&lt;/a&gt;&lt;br /&gt;For the people who don't know Belsec, check out the blog here: &lt;a href="http://belsec.skynetblogs.be" target="_blank"&gt;http://belsec.skynetblogs.be&lt;/a&gt;&lt;br /&gt;Today, Belsec &lt;a href="http://belsec.skynetblogs.be/tag/1/belsecbirthday" target="_blank"&gt;exists 1 year&lt;/a&gt; - Happy Birthday!!!&lt;br /&gt;&lt;br /&gt;Some exclusive articles, free stuff and other goodies will be posted there this week, so make sure you don't miss it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-7545185400755028658?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=aXswkEAH"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=183" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=0dXOiasi"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=43" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=0jmtDC5e"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/9kNXeXTN51g" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/9kNXeXTN51g/congrats-belsec.html</link><author>noreply@blogger.com (miekiemoes)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_AiLE2bg2NHM/SRltdtyy8kI/AAAAAAAAA5s/D_TNaf67Ul0/s72-c/birthday.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2008/11/congrats-belsec.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-7057006548788594009</guid><pubDate>Mon, 03 Nov 2008 08:15:00 +0000</pubDate><atom:updated>2008-11-03T09:17:56.558+01:00</atom:updated><title>Meet the Medion Family</title><description>A picture of my "Workplace"...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_AiLE2bg2NHM/SQ6zaCvUogI/AAAAAAAAA5k/8YUVlrrR43E/s1600-h/bureau.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 272px;" src="http://1.bp.blogspot.com/_AiLE2bg2NHM/SQ6zaCvUogI/AAAAAAAAA5k/8YUVlrrR43E/s400/bureau.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5264342274436014594" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-7057006548788594009?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=j9WStIom"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=183" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=Ug9qGI5I"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=43" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=jK4UZdjh"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/EePIkMMcJ7Q" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/EePIkMMcJ7Q/meet-medion-family.html</link><author>noreply@blogger.com (miekiemoes)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_AiLE2bg2NHM/SQ6zaCvUogI/AAAAAAAAA5k/8YUVlrrR43E/s72-c/bureau.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2008/11/meet-medion-family.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-4367883668846650752</guid><pubDate>Sun, 02 Nov 2008 16:37:00 +0000</pubDate><atom:updated>2008-11-03T12:24:31.964+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security Products</category><title>HitmanPro 3 - maybe better, but I still have my doubts..</title><description>Mainly dutch users will know this program/removal tool. There were many discussions about it in the past as you will read &lt;a href="http://nl.wikipedia.org/wiki/Hitman_Pro" target="_blank"&gt;here&lt;/a&gt;.&lt;br /&gt;However, the newest version is a bit different. Instead of installing many several different Antispyware and Antivirus removal tools, it now uses a "Scanwolk" or "ScanCloud". This means that potential malware related files are being uploaded there and are being scanned by a couple of different engines. These engines are Eset (NOD32), Avira, PrevX, Emsi Software - a-squared Anti-Spyware and Ikarus Anti-Virus. As far as I know, some of these "Scansoftware" are for free. Correct me if I am wrong.&lt;br /&gt;&lt;br /&gt;This is a littlebit the same principle as Virustotal, but in this case, it happens automatically without users interference.&lt;br /&gt;Previous versions of HitmanPro were for free, however, this time, the new version is different. Scanning stays for free, but to remove what it has found, you have to purchase a license. First you get a trial which is able to remove the found threats - but once that trial has expired, you have to purchase a license..&lt;br /&gt;&lt;br /&gt;Before testing this application, I already had a few remarks....&lt;br /&gt;&lt;br /&gt;* What about false positives the external scanners find. Will HitmanPro remove them as well or not?&lt;br /&gt;* Automatically uploading files to the "ScanWolk" (as how they are calling it) - what about users interference? Is this automatically allowed? Most scanners ask this before users upload potential suspicious files to a server. HitmanPro goes for faster results and uploads automatically without users interference. Ethics???&lt;br /&gt;&lt;br /&gt;Anyway, those were my main concerns, so I decided to give HitmanPro3 a try..&lt;br /&gt;&lt;br /&gt;If I test software, I always try it in a Vmware Image first. In this case, it was Windows XP Pro Service Pack 2.&lt;br /&gt;It was a clean install, only some analysis tools (tools which enumerate windows loading points) were installed.&lt;br /&gt;&lt;br /&gt;I've downloaded HitmanPro 3 and executed it...&lt;br /&gt;Once again, this is a clean Windows XP SP2 install with only some analysis tools present.&lt;br /&gt;&lt;br /&gt;It started with the scan...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_AiLE2bg2NHM/SQ3YVUcdS-I/AAAAAAAAA5c/T0hFGChTwwg/s1600-h/hitman.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 192px;" src="http://2.bp.blogspot.com/_AiLE2bg2NHM/SQ3YVUcdS-I/AAAAAAAAA5c/T0hFGChTwwg/s320/hitman.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5264101400242899938" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Ok, tracking cookies in the first place. You're kidding if people really have to purchase a license to remove these tracking cookies. Easy money..&lt;br /&gt;Anyway.. the other detections.. &lt;br /&gt;Too bad to see it detected one of my favorite analysis tools (OtScanIt.exe) as Trojan.Dos.Win32....&lt;br /&gt;I've uploaded it to Virustotal and came back with the following results: &lt;a href="http://www.virustotal.com/nl/analisis/ab129671f0130d829a70e395ec5b64fa" target="_blank"&gt;http://www.virustotal.com/nl/analisis/ab129671f0130d829a70e395ec5b64fa&lt;/a&gt;&lt;br /&gt;HitmanPro uses the Prevx engine, and in this case, its detected as "Cloaked Malware". This is a heuristic detection and may be a false positive. Not sure where HitmanPro gets the "Trojan.Dos.Win32.." from..&lt;br /&gt;Anyway.. during detection, there is NO WAY where you can deselect what it has found. The only option you get is the "next" button. (and the option to select what subscription you have).&lt;br /&gt;Then, if you click the "next" button, it removes what it found, no matter if it was a false positive or not (after all, you could not deselect in from the main screen). Byebye OtScanIt - I couldn't save you.. :(&lt;br /&gt;And even in my clean Vmware image, HitmanPro decided (without notice) to remove my desktop background and replace it with the 'plain blue standard background'. Is there any reason why? Without notice? So this means that everyone who runs HitmanPro3, no matter if you're infected or not, gets a "blank" desktop afterwards? &lt;br /&gt;&lt;br /&gt;Once again, this was in a clean Windows XP SP2 image. Detections and removal of files that weren't even malicious and deleting valuedatas in keys (without notice) that weren't even malicious...&lt;br /&gt;It also appears that some others were having problems as well with this newest version. For example:&lt;br /&gt;&lt;a href="http://www.techzine.nl/nieuws/18270/SurfRight-brengt-finalversie-Hitman-Pro-3-uit.html" target="_blank"&gt;http://www.techzine.nl/nieuws/18270/SurfRight-brengt-finalversie-Hitman-Pro-3-uit.html&lt;/a&gt; (First reaction present there).&lt;br /&gt;To translate: "I've used it two times and deleted it immediately. The scripts crashed and deleted important files from my PC. BSOD, then a system restore (removed HitmanPro) and everything worked OK again."&lt;br /&gt;&lt;br /&gt;I'm not suprised at all.....&lt;br /&gt;&lt;br /&gt;So the only thing I can say here is... please remove the official version and give it more time to beta test. It's way too dangerous to use/release it in public.&lt;br /&gt;Some important thoughts:&lt;br /&gt;&lt;br /&gt;* Ask for confirmation before uploading potential dangerous files.&lt;br /&gt;* Make sure people can select/deselect what files to remove.&lt;br /&gt;&lt;br /&gt;EDIT: There's indeed an option to select/deselect what files to remove, but only if you rightclick the view and select the "Virus analist view". Many people won't know about that option (I didn't either), so it may be better to make checkboxes to select/deselect in the main view.&lt;br /&gt;&lt;br /&gt;* I can't find a backup/quarantine option. Better to give the option to quarantine what it removed with the option to restore if needed.&lt;br /&gt;&lt;br /&gt;... and some more thoughts that I will post later.&lt;br /&gt;&lt;br /&gt;Extra note... I have NOT tested this on an infected system yet - I'll certainly do this later and see how it acts/reacts - and post the results. My main important point was how it acted/reacted on a NON infected system since many people just love to run tools and even purchase them if not needed.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-4367883668846650752?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=TNb5SR78"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=183" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=W02bDnUH"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=43" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=eOEhs6ek"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/4R6Ot9-y4Jg" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/4R6Ot9-y4Jg/hitmanpro-3-maybe-better-but-i-still.html</link><author>noreply@blogger.com (miekiemoes)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_AiLE2bg2NHM/SQ3YVUcdS-I/AAAAAAAAA5c/T0hFGChTwwg/s72-c/hitman.gif" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2008/11/hitmanpro-3-maybe-better-but-i-still.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-2704611706507594130</guid><pubDate>Mon, 27 Oct 2008 12:32:00 +0000</pubDate><atom:updated>2008-10-27T13:39:15.308+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Rant</category><title>That was a stupid thing to say</title><description>I was helping someone yesterday with a SEVERLY infected computer. This computer was infected for at least 1 year since older malware was still active and running, with on top, newer malware including a File infector, some backdoors, random adware and god knows what else...&lt;br /&gt;So you can imagine there wasn't much we could do about it, this computer was TOAST. &lt;br /&gt;Then this user told me that he was actually &lt;span style="font-weight:bold;"&gt;PROUD&lt;/span&gt; of the fact that he managed to get 4 different computers infected/damaged in a short period of time. &lt;br /&gt;Excuse me? &lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_AiLE2bg2NHM/SQW1FHp4xfI/AAAAAAAAA3c/977_yXhtfro/s1600-h/card2.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 250px; height: 160px;" src="http://4.bp.blogspot.com/_AiLE2bg2NHM/SQW1FHp4xfI/AAAAAAAAA3c/977_yXhtfro/s320/card2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5261810839211001330" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;That's where I ended my support - told him to format and reinstall Windows and never use a computer anymore.&lt;br /&gt;&lt;br /&gt;This is once again an example why some people should be restricted to use computers and is a perfect addition to my previous rant: "&lt;a href="http://miekiemoes.blogspot.com/2008/06/neverending-story.html" target="_blank"&gt;The Neverending story&lt;/a&gt;".&lt;br /&gt;Oh, and yes, I do agree with Eugene's &lt;a href="http://www.securecomputing.net.au/Opinion/123664,eugene-kaspersky-on-the-cybercrime-arms-race.aspx" target="_blank"&gt;Final thoughts&lt;/a&gt; - with the addition that Internet access should be restricted for such people as in above example.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-2704611706507594130?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=JkRCSmsl"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=183" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=LMAYAx3T"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=43" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=9CBtdqIZ"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/AsV1LON4Y8w" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/AsV1LON4Y8w/that-was-stupid-thing-to-say.html</link><author>noreply@blogger.com (miekiemoes)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_AiLE2bg2NHM/SQW1FHp4xfI/AAAAAAAAA3c/977_yXhtfro/s72-c/card2.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2008/10/that-was-stupid-thing-to-say.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-7139601227235380166</guid><pubDate>Mon, 27 Oct 2008 09:24:00 +0000</pubDate><atom:updated>2008-10-27T10:48:00.205+01:00</atom:updated><title>MEDION Akoya Mini 10" Netbook E1210</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_AiLE2bg2NHM/SQWJFyYmGvI/AAAAAAAAA3U/K1qRFBiVxy4/s1600-h/medionnetbook.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 300px; height: 300px;" src="http://1.bp.blogspot.com/_AiLE2bg2NHM/SQWJFyYmGvI/AAAAAAAAA3U/K1qRFBiVxy4/s320/medionnetbook.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5261762472169577202" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Yes, that's going to be my new notebook. This is the Aldi offer in Belgium for this week and since I always wanted a "mini notebook" to take everywhere with me, this looks like the ideal one for me. &lt;br /&gt;My other notebook (older one) died in a meanwhile after the "coffee accident" I &lt;a href="http://miekiemoes.blogspot.com/2008/09/fujitsu-siemens-amilo-rip-for-now.html" target="_blank"&gt;blogged&lt;/a&gt; about last month. I'm still surprised that it worked for a couple of days afterwards, so I could back up important data. So in a way, I was lucky.&lt;br /&gt;&lt;br /&gt;Specifications of the Medion Akoya Mini are:&lt;br /&gt;&lt;br /&gt;1.6Ghz Intel® Atom™ Processor N270&lt;br /&gt;Intel® Atom™ Processor – a new series of very low power processors developed by Intel® especially for Mobile Internet Devices (MIDs) and for a new class of more affordable, smaller and fully functional computer systems built to provide fast, easy internet access. These ‘Netbooks’ are impressive thanks to their ease-of-use, portability, powerful wireless LAN functionality and long battery life.&lt;br /&gt;&lt;br /&gt;Windows® XP Home Edition&lt;br /&gt;(incl. Service Pack 3)&lt;br /&gt;&lt;br /&gt;10" TFT Widescreen Display&lt;br /&gt;1024 × 600 pixels&lt;br /&gt;&lt;br /&gt;80GB SATA hard drive&lt;br /&gt;for more than 16,000 music tracks or photos**&lt;br /&gt;&lt;br /&gt;1GB RAM&lt;br /&gt;&lt;br /&gt;Fast WLAN Wireless LAN 802.11 b/g +&lt;br /&gt;Draft-n with up to 300 MBit/s.*&lt;br /&gt;&lt;br /&gt;Intel® Graphics Media Accelerator 950&lt;br /&gt;&lt;br /&gt;Connectivity&lt;br /&gt;USB 2.0, Memory card reader and much more...&lt;br /&gt;&lt;br /&gt;Integrated webcam&lt;br /&gt;&lt;br /&gt;Connections&lt;br /&gt;&lt;br /&gt;    * Multi-card reader for SD, MMC, Memory Stick&lt;br /&gt;    * 3× USB 2.0&lt;br /&gt;    * 1× VGA out&lt;br /&gt;    * 1× network (RJ45)&lt;br /&gt;    * 1× line out&lt;br /&gt;&lt;br /&gt;Also included&lt;br /&gt;&lt;br /&gt;    * Li-ion battery and mains power adaptor&lt;br /&gt;&lt;br /&gt;Dimensions and Weight&lt;br /&gt;&lt;br /&gt;    * Approx. 260 × 180 × 19/31.5mm&lt;br /&gt;    * Approx. 1.2kg incl. battery&lt;br /&gt;&lt;br /&gt;Bag and Bluetooth dongle are also included. &lt;br /&gt;&lt;br /&gt;And this for 399 euro!&lt;br /&gt;&lt;br /&gt;More info also here: &lt;a href="http://www.medion.de/ms/aldi/md97160/au/flash.html" target="_blank"&gt;http://www.medion.de/ms/aldi/md97160/au/flash.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I guess I'll have to hurry before they are sold out.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-7139601227235380166?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=fABil5Lo"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=183" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=BRnSK0o2"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=43" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=SfUv8uYZ"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/1eA1TwslGBQ" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/1eA1TwslGBQ/medion-akoya-mini-10-netbook-e1210.html</link><author>noreply@blogger.com (miekiemoes)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_AiLE2bg2NHM/SQWJFyYmGvI/AAAAAAAAA3U/K1qRFBiVxy4/s72-c/medionnetbook.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2008/10/medion-akoya-mini-10-netbook-e1210.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-4215363954788834202</guid><pubDate>Mon, 13 Oct 2008 17:44:00 +0000</pubDate><atom:updated>2009-05-19T13:05:58.593+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Malware</category><title>Fake sysaudio.sys causes Searchengine Hijack</title><description>What is this infection about...&lt;br /&gt;It actually loads a script, so searchengine results are loaded within a script. For example, when you research something in google or another searchenigine, you get this when you view the source:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;script scr= //78. 157. 142. 58/&lt;/span&gt; and then the searchengine results.&lt;br /&gt;or &lt;br /&gt;&lt;span style="font-style:italic;"&gt;script scr= //209 .85 .171 .9/&lt;/span&gt; and then the searchengine results.&lt;br /&gt;(more may be present as well)&lt;br /&gt;&lt;br /&gt;So, whenever a popular searchengine is being used, a script is loaded to insert its results. For example, a search for: "How to remove rootkits with icesword", you get irrelevant results. Screenshot here:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://users.telenet.be/bluepatchy/miekiemoes/images/googlered1.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px;" src="http://users.telenet.be/bluepatchy/miekiemoes/images/googlered1.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;This only applies for the first page of the results.&lt;br /&gt;&lt;br /&gt;It looks like stopzilla.com is also promoted via this piece of malware &lt;br /&gt;Example:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://users.telenet.be/bluepatchy/miekiemoes/images/googlered3.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px;" src="http://users.telenet.be/bluepatchy/miekiemoes/images/googlered3.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;As far as I know.. this one is getting installed via a "Yahoo! Counter starts here" javascript (which is a malicious script and not related with Yahoo) injected on many forums/sites/blogs.&lt;br /&gt;&lt;br /&gt;The responsible file for the searchengine hijack is &lt;span style="font-weight:bold;"&gt;sysaudio.sys&lt;/span&gt;, (which is actually a DLL) dropped in the &lt;span style="font-weight:bold;"&gt;%sysdir%&lt;/span&gt; folder (system32 folder).&lt;br /&gt;&lt;br /&gt;Note - &lt;span style="font-weight:bold;"&gt;do NOT confuse&lt;/span&gt; this one with the &lt;span style="font-weight:bold;"&gt;legitimate sysaudio.sys file which is present in the %sysdir%\drivers folder!!!&lt;/span&gt; So &lt;span style="font-weight:bold;"&gt;don't&lt;/span&gt; delete the legitimate %sysdir%\drivers\sysaudio.sys file!&lt;br /&gt;&lt;br /&gt;The loading point for the fake sysaudio.sys is under the &lt;br /&gt;&lt;span style="font-style:italic;"&gt;HKLM\software\microsoft\windows nt\currentversion\drivers32&lt;/span&gt; key &lt;br /&gt;with value and valuedata:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;"aux"="sysaudio.sys"&lt;/span&gt; or &lt;br /&gt;&lt;span style="font-style:italic;"&gt;"aux2"="sysaudio.sys"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Legitimate&lt;/span&gt; valuedata for "aux" should be wdmaud.drv or mmdrv.dll or ctwdm32.dll (those are the most common legitimate ones I've seen so far, there could be more)&lt;br /&gt;&lt;br /&gt;Other files the fake sysaudio.sys may use are &lt;span style="font-style:italic;"&gt;divx.nls&lt;/span&gt; or &lt;span style="font-style:italic;"&gt;ntnet.drv&lt;/span&gt; which is also present in the %sysdir% folder.&lt;br /&gt;(could be more already - newer variants)&lt;br /&gt;&lt;br /&gt;Anyway, this is another method being used to "hide" its presence because it causes confusion with legitimate files/keys. So be cautious if you think you're dealing with this one and do not delete the legitimate sysaudio.sys file present in the system32\drivers folder or "aux" value in the registry. Ask for help if you're not sure.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;UPDATE!!!&lt;/span&gt;&lt;br /&gt;A new variant is Windows\system32\wdmaud.sys &lt;== bad one&lt;br /&gt;The legitimate ones are Windows\system32\wdmaud.drv and Windows\system32\drivers\wdmaud.sys, so don't delete those!!&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;UPDATE2!!!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;And again a new variant around. Malwarebytes' Anti-Malware detects this one as Trojan.Gumblar or Trojan.JSRedir. (previous variants were detected as Trojan.Daonol)&lt;br /&gt;Redirections go for example to 209.85.171.199 - or you see 7.7.7.0 in the status bar.&lt;br /&gt;This time, it uses a random file name. To find out, browse to the &lt;span style="font-style:italic;"&gt;HKLM\software\microsoft\windows nt\currentversion\drivers32&lt;/span&gt; key in the registry and look what's present under the "aux" values (aux1, aux2, aux3, aux4..) One of them is the cause. It's a "weird" looking filepath and name, examples are: "C:\WINDOWS\system32\..\sjkemx.iqd" or "C:\WINDOWS\system32\..\kvlhurx.niq" or "c:\docume~1\%username%\LOCALS~1\Temp\..\herlppj.sna" - note the reference named ".." which actually refers to "go up two levels". To find the file itself, easiest way is via Windows search. If it comes back immediately after you have removed it, you can use the "Hijackthis - Delete on reboot" option, or any other tool that is able to delete files on reboot.&lt;br /&gt;In case you can't launch regedit (crashes when you launch it), rename regedit and try again.&lt;br /&gt;If you're unsure, don't delete anything, but ask help instead.&lt;br /&gt;&lt;br /&gt;Update: &lt;a href="http://mad.internetpol.fr/archives/44-Daonol-Miekiemoes,-Superstar.html" target="_blank"&gt;A Great, detailed writeup by MAD&lt;/a&gt; (French)&lt;br /&gt;&lt;br /&gt;To receive help to remove the infection or similar infections, register at one of the forums present on the right, or register at my personal forum &lt;a href="http://support.bluemedicine.be/mybb/thread-2612.html" target="_blank"&gt;here&lt;/a&gt;. It's a dutch forum but I also give english support.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-4215363954788834202?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=zkS529JF"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=183" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=XNBaNMvi"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=43" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=H03FaNYb"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/OXV6wOyCV74" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/OXV6wOyCV74/fake-sysaudiosys-causes-searchengine.html</link><author>noreply@blogger.com (miekiemoes)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2008/10/fake-sysaudiosys-causes-searchengine.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-2912573770287848179</guid><pubDate>Fri, 03 Oct 2008 08:45:00 +0000</pubDate><atom:updated>2008-10-03T11:00:49.886+02:00</atom:updated><title>Something, somewhere, went terribly wrong.</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_AiLE2bg2NHM/SOXcAMHdsXI/AAAAAAAAAvs/Mi1Fu03S8Ok/s1600-h/something.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_AiLE2bg2NHM/SOXcAMHdsXI/AAAAAAAAAvs/Mi1Fu03S8Ok/s320/something.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5252846436208193906" /&gt;&lt;/a&gt;&lt;br /&gt;A t-shirt I ordered - arrived today...&lt;br /&gt;&lt;br /&gt;I love it!! :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-2912573770287848179?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=BN8C3Beo"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=183" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=DrU1Nia3"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=43" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=Am7Fw75L"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/nTEBu3piW_k" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/nTEBu3piW_k/something-somewhere-went-terribly-wrong.html</link><author>noreply@blogger.com (miekiemoes)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_AiLE2bg2NHM/SOXcAMHdsXI/AAAAAAAAAvs/Mi1Fu03S8Ok/s72-c/something.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2008/10/something-somewhere-went-terribly-wrong.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-3460918862651443281</guid><pubDate>Wed, 01 Oct 2008 13:54:00 +0000</pubDate><atom:updated>2009-02-14T01:26:02.559+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Malware</category><title>MySpace/FaceBook worm causes confusion in HijackThislogs</title><description>This blogpost is actually a warning for people who are helping others to get rid of this worm via &lt;span style="font-weight:bold;"&gt;HijackThis-logs&lt;/span&gt;.&lt;br /&gt;Here's some more info about the worm itself and how it is being spread:&lt;font size="1"&gt;&lt;br /&gt;&lt;a href="http://www.kaspersky.com/news?id=207575670" target="_blank"&gt;http://www.kaspersky.com/news?id=207575670&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pcworld.com/businesscenter/article/149559/malicious_hackers_use_facebook_wall_for_malware_attack.html" target="_blank"&gt;http://www.pcworld.com/businesscenter/article/149559/malicious_hackers_use_facebook_wall_for_malware_attack.html&lt;/a&gt;&lt;/font&gt;&lt;br /&gt;This worm is also known as Net-Worm.Win32.Koobface.*&lt;br /&gt;&lt;br /&gt;People are complaining about Google Redirects, slow computer in general and browser freezing or shutting down whenever they want to log into their FaceBook or MySpace account.&lt;br /&gt;The files responsible for this infection are:&lt;br /&gt;&lt;br /&gt;&lt;font size="1"&gt;&lt;span style="font-style:italic;"&gt;%WinDir%\kenny**.exe (** stands for a number, in this case 16, 17, 18..), runs from HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run with displayname sysftray2&lt;br /&gt;%WinDir%\fmark2.dat&lt;br /&gt;%ProgramFiles%\TinyProxy\TinyProxy.exe or %ProgramFiles%\ProtectService\ProtectService.exe which runs as a service.&lt;/span&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;It also modifies the Proxy to &lt;span style="font-style:italic;"&gt;http=127.0.0.1:8181&lt;/span&gt;&lt;br /&gt;To fix this: &lt;br /&gt;In IE: Tools Menu -&gt; Internet Options -&gt; Connections Tab -&gt;Lan Settings &gt; uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.&lt;br /&gt;In Firefox in Tools Menu -&gt; Options... -&gt; Advanced Tab -&gt; Network Tab -&gt; "Settings" under Connection.&lt;br /&gt;&lt;br /&gt;To remove this infection, just delete the &lt;span style="font-weight:bold;"&gt;%ProgramFiles%\TinyProxy&lt;/span&gt; folder or &lt;span style="font-weight:bold;"&gt;%ProgramFiles%\ProtectService&lt;/span&gt; folder it has created + the %WinDir%&lt;span style="font-weight:bold;"&gt;\fmark2.dat&lt;/span&gt; and %WinDir%\&lt;span style="font-weight:bold;"&gt;kenny**.exe&lt;/span&gt; files + restore proxysettings.&lt;br /&gt;It's recommended that you do this in Windows Safe mode since this infection (mainly the service) is active in Windows normal mode.&lt;br /&gt;There could be newer variants present already.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Now, what's the confusion with HijackThislogs and people who are guiding others with malware removal via HijackThislogs...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Let me explain how HijackThis.exe enumerates the services...&lt;br /&gt;For example, let's take the &lt;span style="font-weight:bold;"&gt;legitimate&lt;/span&gt; Nvidia Display service:&lt;br /&gt;&lt;br /&gt;&lt;font size="1"&gt;&lt;span style="font-style:italic;"&gt;O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe&lt;/span&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;What's between the brackets is the &lt;span style="font-style:italic;"&gt;Servicename&lt;/span&gt;. In this case "&lt;span style="font-weight:bold;"&gt;NVSvc&lt;/span&gt;". That's how the service is registered in the registry.&lt;br /&gt;The &lt;span style="font-style:italic;"&gt;Displayname&lt;/span&gt; is "&lt;span style="font-weight:bold;"&gt;NVIDIA Driver Helper Service&lt;/span&gt;". This is how you see it in services.msc for example. This is also set under the Servicename with value "&lt;span style="font-style:italic;"&gt;Displayname&lt;/span&gt;".&lt;br /&gt;The "C:\WINDOWS\system32\nvsvc32.exe" refers to the "&lt;span style="font-style:italic;"&gt;ImagePath&lt;/span&gt;" value set under the "NVSvc" service. This means the file responsible for running as a service.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;In case there are no brackets, then it means that the Servicename is the same as the Displayname&lt;/span&gt;, for example:&lt;br /&gt;&lt;br /&gt;&lt;font size="1"&gt;&lt;span style="font-style:italic;"&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;/span&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;In this case, "Apple Mobile Device" is the &lt;span style="font-weight:bold;"&gt;servicename and displayname&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;If people check and fix a O23 entry in HijackThis, HijackThis &lt;span style="font-weight:bold;"&gt;doesn't delete&lt;/span&gt; the service, but &lt;span style="font-weight:bold;"&gt;disables&lt;/span&gt; it instead. This means, it changes the "&lt;span style="font-style:italic;"&gt;Start&lt;/span&gt;" valuedata for the service to &lt;span style="font-weight:bold;"&gt;dword:00000004&lt;/span&gt;, which means disabled.&lt;br /&gt;In case when a malicious service is present, if you fix it in HijackThis, &lt;span style="font-weight:bold;"&gt;it won't remove the service. It will only disable it&lt;/span&gt;.&lt;br /&gt;That's why a lot of helpers who are guiding with HijackThislogs &lt;span style="font-weight:bold;"&gt;are teached to delete the service in the registry as well&lt;/span&gt;. The sc delete "servicename" command is the common used command here.&lt;br /&gt;&lt;br /&gt;Now let's compare one of these malicious TinyProxy.exe or ProtectService.exe Services..&lt;br /&gt;That's how they look in a HijackThislog:&lt;br /&gt;&lt;br /&gt;Some examples:&lt;br /&gt;&lt;br /&gt;&lt;font size="1"&gt;&lt;span style="font-style:italic;"&gt;O23 - Service: Network Connections (Netman) - Unknown owner - C:\Program Files\TinyProxy\TinyProxy.exe &lt;br /&gt;O23 - Service: Logical Disk Manager (dmserver) - Unknown owner - C:\Program Files\TinyProxy\TinyProxy.exe&lt;br /&gt;O23 - Service: Apple Mobile Device (Apple Mobile Device) - Unknown owner - C:\Program Files\TinyProxy\TinyProxy.exe&lt;br /&gt;O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\Program Files\TinyProxy\TinyProxy.exe&lt;br /&gt;O23 - Service: Network Connections (Netman)  - Unknown owner - C:\Program Files\TinyProxy\TinyProxy.exe&lt;br /&gt;O23 - Service: NMIndexingService (NMIndexingService) - Unknown owner - C:\Program Files\TinyProxy\TinyProxy.exe&lt;br /&gt;O23 - Service: DHCP Client (Dhcp) - Unknown owner - C:\Program Files\TinyProxy\TinyProxy.exe&lt;br /&gt;&lt;br /&gt;O23 - Service: Application Layer Gateway Service (ALG) - Unknown owner - C:\Program Files\ProtectService\ProtectService.exe&lt;br /&gt;O23 - Service: Workstation (lanmanworkstation) - Unknown owner - C:\Program Files\ProtectService\ProtectService.exe&lt;br /&gt;O23 - Service: Fast User Switching Compatibility (FastUserSwitchingCompatibility) - Unknown owner - C:\Program Files\ProtectService\ProtectService.exe&lt;br /&gt;O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\Program Files\ProtectService\ProtectService.exe&lt;br /&gt;O23 - Service: Computer Browser (Browser) - Unknown owner - C:\Program Files\ProtectService\ProtectService.exe&lt;/span&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;In this case, let's take &lt;font size="1"&gt;&lt;span style="font-weight:bold;"&gt;O23 - Service: Network Connections (Netman) - Unknown owner - C:\Program Files\TinyProxy\TinyProxy.exe&lt;/span&gt;&lt;/font&gt; as an example.&lt;br /&gt;&lt;br /&gt;People who are used to working with HijackThislogs would think: "&lt;span style="font-weight:bold;"&gt;Netman&lt;/span&gt;" is the servicename and "&lt;span style="font-weight:bold;"&gt;Network Connections&lt;/span&gt;" is the Displayname.&lt;br /&gt;Yes, that's how it looks like.&lt;br /&gt;But.. the service "&lt;span style="font-weight:bold;"&gt;Netman&lt;/span&gt;" is a LEGITIMATE service and the Displayname "&lt;span style="font-weight:bold;"&gt;Network Connections&lt;/span&gt;" matches as well as LEGITIMATE. Normally HijackThis whitelists these services.&lt;br /&gt;Now what? Does that mean that this service in the registry was modified and the "Imagepath" value under the "Netman" service was changed to "C:\Program Files\TinyProxy\TinyProxy.exe" instead of  %SystemRoot%\system32\svchost.exe -k netsvcs (which is the default valuedata for this one)?&lt;br /&gt;Yes, that's a possibility... we've seen it before.&lt;br /&gt;In such cases, after you have removed the offending folder C:\Program Files\TinyProxy, you need to restore the default "Imagepath" valuedata again to the legitimate one. &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;HOWEVER&lt;/span&gt;, I found out that this infection isn't modifying any legitimate services at all!&lt;br /&gt;After a bit of research - comparing logs and testing with some dummy services - it appears that this infection &lt;span style="font-weight:bold;"&gt;creates a new service&lt;/span&gt; instead, but makes sure it matches a legitimate service and causes extra confusion in HijackThislogs.&lt;br /&gt;Example: &lt;br /&gt;&lt;br /&gt;Let's create the service:&lt;br /&gt;&lt;br /&gt;&lt;font size="1"&gt;&lt;span style="font-style:italic;"&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Network Connections (Netman)] &lt;br /&gt;"Displayname"="Network Connections (Netman)"&lt;br /&gt;"ImagePath"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,00,69,00,\&lt;br /&gt;  6c,00,65,00,73,00,25,00,5c,00,54,00,69,00,6e,00,79,00,50,00,72,00,6f,00,78,\&lt;br /&gt;  00,79,00,5c,00,54,00,69,00,6e,00,79,00,50,00,72,00,6f,00,78,00,79,00,2e,00,\&lt;br /&gt;  65,00,78,00,65,00,00,00&lt;/span&gt;  &lt;== which translates to %ProgramFiles%\TinyProxy\TinyProxy.exe&lt;br /&gt;&lt;span style="font-style:italic;"&gt;"Start"=dword:00000002&lt;/span&gt; &lt;== which means "autostart"&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;The service "&lt;span style="font-weight:bold;"&gt;Network Connections (Netman)&lt;/span&gt;" isn't legitimate since the legitimate service is actually "&lt;span style="font-weight:bold;"&gt;Netman&lt;/span&gt;".&lt;br /&gt;But, since the "Displayname" in above example matches the servicename here, in HijackThislogs, it will show as:&lt;br /&gt;&lt;br /&gt;&lt;font size="1"&gt;&lt;span style="font-style:italic;"&gt;O23 - Service: Network Connections (Netman) - Unknown owner - C:\Program Files\TinyProxy\TinyProxy.exe&lt;/span&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;While the servicename is actually: "Network Connections (Netman)" and NOT "Netman"!!&lt;br /&gt;&lt;br /&gt;The result of this is.. many helpers look at the servicename in HijackThis (the one between brackets) and since it has a malicious file attached, some don't think further and think that the service itself is malicious as well (without knowing that it may be a legitimate service) &gt; result &gt; they ask to delete the legitimate service from the registry using the sc.exe delete command.&lt;br /&gt;And yes, a Threatexpert report also reveals how it has created its service. Example: &lt;a href="http://www.threatexpert.com/report.aspx?uid=b72eb6f9-00dd-442b-8a08-f095ca088e31" target="_blank"&gt;http://www.threatexpert.com/report.aspx?uid=b72eb6f9-00dd-442b-8a08-f095ca088e31&lt;/a&gt;&lt;br /&gt;In the Threatexpert's example..&lt;br /&gt;"TrkWks" is the LEGITIMATE service, but in this case, as you see in above report, the service: "&lt;span style="font-weight:bold;"&gt;Distributed Link Tracking Client (TrkWks) &lt;/span&gt;" was created.&lt;br /&gt;A slightly bit different from what I've tested with dummy services, but it does make sense. In above example, the service &lt;span style="font-weight:bold;"&gt;has an extra space&lt;/span&gt; after the services name and since the "Displayname" is the same, it will show it like this in a original HijackThislog (since displayname and servicesname matches):&lt;br /&gt;&lt;br /&gt;&lt;font size="1"&gt;&lt;span style="font-style:italic;"&gt;O23 - Service: Distributed Link Tracking Client (TrkWks)  - Unknown owner - C:\Program Files\TinyProxy\TinyProxy.exe&lt;/span&gt; (&lt;s&gt;note the extra empty space after (TrkWks) and -&lt;/s&gt;)&lt;/font&gt;**&lt;br /&gt;&lt;br /&gt;But since people are posting this at forums, &lt;span style="font-weight:bold;"&gt;the forumsoftware strips that empty space anyway&lt;/span&gt;.&lt;br /&gt;The same applies for the threatexpert report itself imho, where it also strips the extra space in the services name/services key if no subkeys are attached.&lt;br /&gt;&lt;br /&gt;** After I have posted this, I noticed that this blogpost also strips the extra space after the services name..&lt;br /&gt;&lt;br /&gt;Anyway.. &lt;span style="font-weight:bold;"&gt;imho&lt;/span&gt;, I'm pretty sure that, whoever developed this infection is well aware of HijackThis and how it displays its entries, this to cause some extra confusion for helpers.&lt;br /&gt;And that's why I posted this warning in the first place, because I've seen it happen a couple of times already. Legitimate services were deleted &gt; result, no internet access anymore or anything else that was broken because of this confusion in HijackThis.&lt;br /&gt;That's why, before you want to delete a service in the registry, make sure first it's not a legitimate service!&lt;br /&gt;&lt;br /&gt;&lt;s&gt;I have not played with this infection itself yet (no samples available) - so my analysis is only based on logs/research and testing.&lt;br /&gt;Samples are welcome. :-)&lt;/s&gt; Samples received. Thanks readers :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-3460918862651443281?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=GzrANC3u"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=183" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=YSbARyxq"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=43" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=Fpg79BeM"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/__SbFNLbF38" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/__SbFNLbF38/myspacefacebook-worm-causes-confusion.html</link><author>noreply@blogger.com (miekiemoes)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2008/10/myspacefacebook-worm-causes-confusion.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-1308617281717213528</guid><pubDate>Fri, 19 Sep 2008 10:52:00 +0000</pubDate><atom:updated>2008-09-21T08:38:06.793+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Rant</category><title>Fujitsu Siemens Amilo - RIP..... for now.....</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_AiLE2bg2NHM/SNOEmPDLPiI/AAAAAAAAAvY/w76y-3FDvKw/s1600-h/ripamilo.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_AiLE2bg2NHM/SNOEmPDLPiI/AAAAAAAAAvY/w76y-3FDvKw/s320/ripamilo.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5247683783226506786" /&gt;&lt;/a&gt;&lt;br /&gt;This was going to happen some day anyway... &lt;br /&gt;I finally managed to spill a full mug of coffee (big size) all over my laptop. &lt;br /&gt;In less than a second, the coffee had covered my entire computer desk. Luckily, my other laptop next to it was on a notebook cooler pad, so that one was saved.&lt;br /&gt;The screen went black immediately, strange noises from underneath... and I sweared like never before.&lt;br /&gt;Unfortunately, the swearing didn't work, so instead, I immediately disconnected the power supply and took out the battery. &lt;br /&gt;I put the unit on its side and the coffee was dripping out. I left it in that position for at least an hour. I cleaned the rest of the mess I made, apart from the stains on the wall (Mr Proper can take care of that).&lt;br /&gt;Then I turned it upside down, opened it and I'm going to let it dry for at least 24 hours.&lt;br /&gt;&lt;br /&gt;In a way, I'm glad I don't like milk and sugar in my coffee, so maybe there's still hope... but I doubt it.&lt;br /&gt;&lt;br /&gt;My dear Fujitsu Siemens Amilo, May The Force Be With You.&lt;br /&gt;&lt;br /&gt;UPDATE! I couldn't wait any longer (waited for two days to let it dry)... so... it's up and running again!! No issues so far - everything works. I was really lucky :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-1308617281717213528?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=Rcs8i1Qe"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=183" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=N3NEKsRY"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=43" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=m0K14s8h"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/bjOPYYwoq08" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/bjOPYYwoq08/fujitsu-siemens-amilo-rip-for-now.html</link><author>noreply@blogger.com (miekiemoes)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_AiLE2bg2NHM/SNOEmPDLPiI/AAAAAAAAAvY/w76y-3FDvKw/s72-c/ripamilo.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2008/09/fujitsu-siemens-amilo-rip-for-now.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-2354185549919640868</guid><pubDate>Wed, 17 Sep 2008 10:33:00 +0000</pubDate><atom:updated>2008-09-17T12:42:11.390+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security Products</category><title>AntiVirus, Internet Security and Total Security Performance Benchmarking by Passmark.</title><description>I actually never really paid attention to comparison/testing reports about Antivirus and Security Suites especially related with "best detection", "best removal" etc etc.. This, since I have my own opinion about this :-)&lt;br /&gt;However, this is a different test, a performance test of several different Antivirus products and Security Suites/Total Security Products by &lt;a href="http://www.passmark.com/" target="_blank"&gt;Passmark&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;- The Performance tests:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;* Boot Time&lt;br /&gt;* Scan Speed&lt;br /&gt;* User Interface launch Speed&lt;br /&gt;* Memory utilization&lt;br /&gt;* Installation Time&lt;br /&gt;* Installation Size&lt;br /&gt;* Registry Key Count&lt;br /&gt;* File Copy, Move and Delete&lt;br /&gt;* Installing Third Party Applications&lt;br /&gt;* Binary File Download Speed&lt;br /&gt;* File Format Conversion&lt;br /&gt;* File Compression and Decompression&lt;br /&gt;* File write, Open and Close&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;- Overal Ranking in comparison with other products:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_AiLE2bg2NHM/SNDdjHS4NCI/AAAAAAAAAvQ/TxEg3dGXvTc/s1600-h/pmbench.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_AiLE2bg2NHM/SNDdjHS4NCI/AAAAAAAAAvQ/TxEg3dGXvTc/s320/pmbench.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5246937161210016802" /&gt;&lt;/a&gt;&lt;span style="font-style:italic;"&gt;&lt;center&gt;Click to enlarge&lt;/center&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;It looks like Norton Internet Security 2009/Norton Antivirus 2009 is a winner here in comparison with previous tests and older versions.&lt;br /&gt;&lt;br /&gt;Anyway, "decide" for yourself and read the full report here: &lt;a href="http://www.passmark.com/ftp/antivirus_09-performance-testing-ed1.pdf" target="_blank"&gt;http://www.passmark.com/ftp/antivirus_09-performance-testing-ed1.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Still, &lt;span style="font-weight:bold;"&gt;imho&lt;/span&gt;, the best way to decide what Antivirus/Security Suite to use (for best performance) is to install it and see how it runs on your computer. After all, every computer is different.&lt;br /&gt;If it runs fine and you're satisfied with the Antivirus or Security Suite, then keep it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-2354185549919640868?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=k0Hx6UgW"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=183" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=iUvKN6Wf"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=43" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=4zQdU5dX"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/mdcV8PFts40" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/mdcV8PFts40/antivirus-internet-security-and-total.html</link><author>noreply@blogger.com (miekiemoes)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_AiLE2bg2NHM/SNDdjHS4NCI/AAAAAAAAAvQ/TxEg3dGXvTc/s72-c/pmbench.gif" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2008/09/antivirus-internet-security-and-total.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-674153917791542448.post-1818782530616213780</guid><pubDate>Sat, 13 Sep 2008 12:45:00 +0000</pubDate><atom:updated>2008-09-13T14:48:56.056+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Me</category><title>I'll be back - (with a Female Schwarzenegger-style voice)</title><description>Many people already contacted me in the last couple of days, wondering where I am, why I'm not that active anymore on forums, my blog etc etc..&lt;br /&gt;Well, I have been really busy lately IRL. This involves, searching for a new job (which is still undecided yet), some family related issues and some other stuff I won't post in public :-)&lt;br /&gt;This is exhausting, I'm tired.. and explains why I'm not that active anymore lately. After all... IRL is still a priority.&lt;br /&gt;However, latest Security threats are still one of my priorities as well - so I'm trying to keep up to date as much as possible. :-)&lt;br /&gt;&lt;br /&gt;Anyway, I'll be back when things are sorted out... which will be soon (I hope) :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/674153917791542448-1818782530616213780?l=miekiemoes.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=292bbc8k"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=183" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=GjsduIVm"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=43" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MiekiemoesBlog?a=b6gkb9JA"&gt;&lt;img src="http://feeds.feedburner.com/~f/MiekiemoesBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MiekiemoesBlog/~4/rT6GgxomcKU" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/MiekiemoesBlog/~3/rT6GgxomcKU/ill-be-back-with-female-schwarzenegger.html</link><author>noreply@blogger.com (miekiemoes)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://miekiemoes.blogspot.com/2008/09/ill-be-back-with-female-schwarzenegger.html</feedburner:origLink></item></channel></rss>
