<?xml version="1.0" encoding="US-ASCII"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>ThePCSpy.com content-only feed</title><link>http://www.thepcspy.com/</link><description>ThePCSpy.com - Articles on anything "tech"</description><copyright>Copyright 2001-2006 Oli Warner</copyright><generator>ThePCSpy.com RSS Engine</generator><xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /><meta xmlns="http://pipes.yahoo.com" name="pipes" content="noprocess" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/thepcspyclean" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item><title>Debranding and Unlocking a Samsung M8800 Pixon</title><link>http://feedproxy.google.com/~r/thepcspyclean/~3/y7FElpwwcDE/debranding_and_unlocking_a_samsung_m8800_pixon</link><description>&lt;p&gt;Both Harri and I are on O2. This year we decided to forgo getting new phones with our new contracts, saving us a lot of money on the actual contract but meaning we'd likely pay full whack for a phone. For Harri at least, there was another route: buying a slightly second hand, locked phone off ebay. She found the pink Pixons, fell in love and bought one the next day for around &amp;#163;200. &lt;/p&gt;

&lt;p&gt;We've unlocked phones before so thought, &amp;quot;How hard can it be? Surely there'll either be codes on the interweb or somebody on ebay will be selling them for a quid a shot!&amp;quot;&lt;/p&gt;

&lt;p&gt;Actually, it's a little tougher than we thought. There are several services available, some quite excessive sounding procedures involving servers and data cables, which, at first, make you think &amp;quot;Oh my, this is really complex! It must be worth the &amp;#163;20&amp;quot; until you see there are other services, &amp;#163;4-6 cheaper that only need a serial or IMEI to work.&lt;/p&gt;

&lt;p&gt;But my first port of call had actually been at DealExtreme. It's a Chinese site with various consumer electronics that work but you can practically guarantee aren't made by the people that invented them; for those prices it has to be knock-off. I bought a iSmartSIM 2008. It said it could let any SIM work with any phone all for $4.20-something (inc postage) so I bought one the same day Harri decided to buy the Pixon.&lt;/p&gt;

&lt;p&gt;As it was coming all the way from Hong Kong, I thought there was zero chance it would show up before the phone and it didn't. I started looking around at websites, trying to find a free or near-free way to unlock the phone but nothing worked. I then found a site promising 100% guaranteed &lt;a href="http://www.unlocksamsung.co.uk/samsung/" rel="nofollow" target="_blank"&gt;Samsung unlock codes&lt;/a&gt; for &amp;#163;13.99 ? by far the cheapest I found. So I gave them my IMEI and crossed my fingers.&lt;/p&gt;

&lt;p&gt;But then something really strange happened. DealExtreme managed to ship something to me in under two weeks. Just a few hours after buying the unlock code, the iSmartSIM was here, looking really flimsy, fake and not at all capable of doing what it promised but here, nonetheless. Even more surprising was that it worked. So in a bout of extreme haste, I cancelled the order for an unlock code.&lt;/p&gt;

&lt;img src="http://i.thepcspy.com/blog/20090328-ismartsim.jpg"&gt;

&lt;p&gt;It was only later when Harri was back that I realised we'd been a little too hasty. The iSS worked with my SIM but it was a little tetchy with Harri's. My and Harri's SIMs have a slightly different connector layout but it basically meant I could use her phone with my SIM but she could only use hers 50% of the time. Cutting out. Looking like it was in roaming mode all the time. A bit of a hacktastrophe.&lt;/p&gt;

&lt;p&gt;It's always embarrassing when you accidentally muck people around while deciding what you really want. I went back to &lt;a href="http://www.unlocksamsung.co.uk" rel="nofollow" target="_blank"&gt;Unlock Samsung&lt;/a&gt;, got the unlock code and the next morning had an unlocked Pixon in my hands. I'd heartily recommend them to anybody.&lt;/p&gt;

&lt;p&gt;The next part of the puzzle was getting the scummy and locked down Orange branding off an otherwise beautiful phone. They butchered the software, locking you into using Orange online services. I eventually found &lt;a href="http://darkforestgroup.com/forum/index.php/topic,5.0.html" rel="nofollow" target="_blank"&gt;this thread&lt;/a&gt;. You have to register to download the firmware but that's all free. I then followed &lt;a href="http://darkforestgroup.com/forum/index.php/topic,2.0.html" rel="nofollow" target="_blank"&gt;their guide&lt;/a&gt; and after a couple of hiccoughs had a newer firmware that let you use the phone as Samsung intended. &lt;/p&gt;

&lt;p&gt;I should stress that debranding is not for the easily scared and that it &lt;em&gt;*can*&lt;/em&gt; damage your phone and/or void your warranty. Always backup before doing it and don't do drugs, mmmkay.&lt;/p&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/thepcspyclean?a=y7FElpwwcDE:354Iw9PERmg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/thepcspyclean?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/thepcspyclean?a=y7FElpwwcDE:354Iw9PERmg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/thepcspyclean?i=y7FElpwwcDE:354Iw9PERmg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/thepcspyclean?a=y7FElpwwcDE:354Iw9PERmg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/thepcspyclean?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/thepcspyclean/~4/y7FElpwwcDE" height="1" width="1"/&gt;</description><pubDate>Sat, 28 Mar 2009 11:22:33 GMT</pubDate><author>no@spam.no (Oli)</author><guid isPermaLink="false">http://www.thepcspy.com/read/debranding_and_unlocking_a_samsung_m8800_pixon#2778</guid><feedburner:origLink>http://www.thepcspy.com/read/debranding_and_unlocking_a_samsung_m8800_pixon#2778</feedburner:origLink></item><item><title>Facebook worm</title><link>http://feedproxy.google.com/~r/thepcspyclean/~3/_LBSY5NVfjM/facebook_worm</link><description>&lt;p&gt;I received a wall message &amp;quot;from&amp;quot; an old friend today:&lt;/p&gt;

&lt;img src="http://i.thepcspy.com/blog/20080807-facebookvirus.jpg"&gt;

&lt;p&gt;It's got everything a worm needs. There's the bait, raising my intrigue. There's the payload. &lt;strong&gt;And there's trust.&lt;/strong&gt; &lt;/p&gt;

&lt;p&gt;This isn't as aimless as the random &amp;quot;download this file for a larger pocket-rocket&amp;quot;;&lt;strong&gt; I know the person that Facebook says sent this message&lt;/strong&gt;. In my case, not enough to trust a random .exe, but in many people's cases, this sort of crap might fly!&lt;/p&gt;

&lt;p&gt;Needless to say, Facebook needs to examine its security framework. I see a few possible attack vectors: XSS from fbapps and other sites, fbapp loopholes and a bot running on somebody's PC. At the very least Facebook needs to consider blocking people posting .exe files but this would only serve as a temporary fix as it would be comically trivial to post a link to a page that redirected to a .exe file. &lt;/p&gt;

&lt;p&gt;If you get a message like this, delete it. It's on your wall so other, perhaps less educated people may see it, click it and get infected. Then tell the person that they may have a problem. They need to look closely at the apps they have installed and also strongly consider running a thorough virus scan. &lt;/p&gt;

&lt;p&gt;&lt;strong&gt;But now for the really scary part: AV detection.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I submitted this to an online virus scanner which &lt;a href="http://www.virustotal.com" rel="nofollow" target="_blank"&gt;runs the file through various AVs&lt;/a&gt; at its end and tells you which thought the file was infected. I'm not overly sure which versions and which updates it was running, but that also applies to the real world. People are sometimes lax about applying updates. Anyway, &lt;strong&gt;only 36% of scans registered this as a virus.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Amongst the ones that &lt;strong&gt;didn't&lt;/strong&gt; are some big names: Symantec, McAfee, Kaspersky, Sophos, AVG, Nod32, ClamAV and F-Prot. This is not an exhaustive list. There were many more failures. These brands account for what must be 95-98% of the home and enterprise AV market.&lt;/p&gt;

&lt;p&gt;Some of the ones that passed (and also saying more than &amp;quot;Suspicious file&amp;quot;): AntiVir, Avast, BitDefender, F-Secure, Microsoft and TrendMicro. &lt;/p&gt;

&lt;p&gt;Here's the full table of results:&lt;/p&gt;

&amp;lt;table border=&amp;quot;1&amp;quot;&amp;gt;
	&amp;lt;tr&amp;gt;&amp;lt;td colspan=&amp;quot;4&amp;quot;&amp;gt;File picture_dl.exe received on 08.07.2008 11:18:30 (CET)&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;
	&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;Antivirus&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;Version&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;Last Update&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;Result&amp;lt;/td&amp;lt;/tr&amp;gt;
	&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;AhnLab-V3&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;
	&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;AntiVir&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td style=&amp;quot;color: red;&amp;quot;&amp;gt;DR/Delphi.Gen&amp;lt;/td&amp;lt;/tr&amp;gt;
	&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;Authentium&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;
	&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;Avast&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td style=&amp;quot;color: red;&amp;quot;&amp;gt;Win32:Delf-GNA&amp;lt;/td&amp;lt;/tr&amp;gt;
	&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;AVG&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;
	&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;BitDefender&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td style=&amp;quot;color: red;&amp;quot;&amp;gt;Trojan.Dropper.Delf.Crypt.C&amp;lt;/td&amp;lt;/tr&amp;gt;
	&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;CAT-QuickHeal&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td style=&amp;quot;color: red;&amp;quot;&amp;gt;(Suspicious) - DNAScan&amp;lt;/td&amp;lt;/tr&amp;gt;
	&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;ClamAV&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;
	&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;DrWeb&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;
	&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;eSafe&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td style=&amp;quot;color: red;&amp;quot;&amp;gt;Suspicious File&amp;lt;/td&amp;lt;/tr&amp;gt;
	&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;eTrust-Vet&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;Ewido&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;F-Prot&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;F-Secure&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td style=&amp;quot;color: red;&amp;quot;&amp;gt;Suspicious:W32/Malware!Gemini&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;Fortinet&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;GData&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td style=&amp;quot;color: red;&amp;quot;&amp;gt;Win32:Delf-GNA&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;Ikarus&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;K7AntiVirus&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;Kaspersky&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;McAfee&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;Microsoft&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td style=&amp;quot;color: red;&amp;quot;&amp;gt;VirTool:Win32/DelfInject.gen!T&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;NOD32v2&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;Norman&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;Panda&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td style=&amp;quot;color: red;&amp;quot;&amp;gt;Suspicious file&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;PCTools&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;Prevx1&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td style=&amp;quot;color: red;&amp;quot;&amp;gt;Suspicious&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;Rising&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;Sophos&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;Sunbelt&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td style=&amp;quot;color: red;&amp;quot;&amp;gt;Malware.Win32.CodeAnalyzer!cobra (v)&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;Symantec&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;TheHacker&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;TrendMicro&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td style=&amp;quot;color: red;&amp;quot;&amp;gt;PAK_Generic.001&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;VBA32&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;ViRobot&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;VirusBuster&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;Webwasher-Gateway&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&amp;lt;td style=&amp;quot;color: red;&amp;quot;&amp;gt;Trojan.Dropper.Delphi.Gen&amp;lt;/td&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td colspan=&amp;quot;4&amp;quot;&amp;gt;&amp;#160;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;
	
&lt;p&gt;The payload, in case you're wondering, is a trojan dropper. That can subsequently grab &lt;a href="http://www.thepcspy.com/read/where_spam_comes_from" rel="nofollow" target="_blank"&gt;things for sending spam&lt;/a&gt; and post itself to other people's Facebook profiles.&lt;/p&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/thepcspyclean?a=_LBSY5NVfjM:PaYNBqdX69Y:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/thepcspyclean?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/thepcspyclean?a=_LBSY5NVfjM:PaYNBqdX69Y:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/thepcspyclean?i=_LBSY5NVfjM:PaYNBqdX69Y:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/thepcspyclean?a=_LBSY5NVfjM:PaYNBqdX69Y:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/thepcspyclean?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/thepcspyclean/~4/_LBSY5NVfjM" height="1" width="1"/&gt;</description><pubDate>Thu, 07 Aug 2008 11:35:59 GMT</pubDate><author>no@spam.no (Oli)</author><guid isPermaLink="false">http://www.thepcspy.com/read/facebook_worm#2567</guid><feedburner:origLink>http://www.thepcspy.com/read/facebook_worm#2567</feedburner:origLink></item><item><title>My issues with Linux et al</title><link>http://feedproxy.google.com/~r/thepcspyclean/~3/VpqHLCwghEY/my_issues_with_linux_et_al</link><description>&lt;p&gt;I'll start by reiterating my faith. My name is Oli Warner and &lt;strong&gt;I &lt;em&gt;believe&lt;/em&gt; in open source&lt;/strong&gt;. Everybody has the code, everybody can improve on it and the ?choice? to use one application over another is the ultimate quality control. Despite there being some excellent examples of FOSS (Free and open source software), use some of it for long enough and you'll discover its weaknesses.&lt;/p&gt;

&lt;p&gt;I love Linux but &lt;em&gt;I'm losing my religion.&lt;/em&gt; &lt;/p&gt;

&lt;p&gt;Before you ask me why I'm using the following apps, allow me to tell you that I do shop around. I do try different distributions, different desktops and different combinations of applications. I use everything here because, &lt;em&gt;in my opinion&lt;/em&gt;, it's the best of what's available.&lt;/p&gt;


&lt;h2&gt;Gnome and GTK+&lt;/h2&gt;

&lt;p&gt;Despite it being the primary interface for the most widely used desktop distribution, the Gnome desktop has some serious ideological problems.  &lt;/p&gt;

&lt;p&gt;First up is &lt;strong&gt;configuration&lt;/strong&gt;. Gnome developers seem to share a mantra: configuration is both confusing and evil, and it's their mission to shield users from it. Newsflash: &lt;strong&gt;configuration is useful at times!&lt;/strong&gt; Sane defaults will only get you so far. The first place I ran into this issue was the Places menu. 4 bookmarks or mounts is fine but six is apparently far too many to list and requires truncating: &lt;/p&gt;

&lt;img src="http://i.thepcspy.com/blog/20080626-ubuntu/menu.jpg"&gt;

&lt;p&gt;Doesn't that look intuitive?! It's a usability dream, I'll tell you. Now this would all be fine, if I could change the limit but the variable is hard-coded in the source. I &lt;em&gt;could&lt;/em&gt; download the source, find the file and line, make the edit, compile and re-install, but let's face it, I'd probably cock it up and &lt;strong&gt;life is just too damned short.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;If I had my wish, I'd have a dozen bookmarks because they're so useful, but because of this EPIC FAIL, I stick to four or five. &lt;/p&gt;

&lt;p&gt;Next up is &lt;strong&gt;Nautilus&lt;/strong&gt;, Gnome's answer to Windows' Explorer. In a very similar fashion it manages the desktop and the panels and it's also a file browser. My main complaint lies with the latter. Its file-managing abilities aren't bad but it needs more power. They helpfully include a drop-down box on the tool-bar but it seems a bit overkill; there are only two options within.&lt;/p&gt;

&lt;img src="http://i.thepcspy.com/blog/20080626-ubuntu/nautilusviews.jpg"&gt;

&lt;p&gt;I need a real (a-la Windows) list view. &lt;em&gt;Not details!&lt;/em&gt; List. A small icon and the filename, in columns, scrolling horizontally. Please! Thunar (XFCE's Nautilus) does include this but lacks several important features deemed too heavy for its lightweight parent. Another nice feature would be file details and meta-data when you hover over a file, its content changing depending on the file type. &lt;/p&gt;

&lt;p&gt;The desktop is a bit rough in areas too. Icon alignment works on a rough grid system that might be nice if it worked. &lt;/p&gt;

&lt;img src="http://i.thepcspy.com/blog/20080626-ubuntu/desktopgrid.jpg"&gt;

&lt;p&gt;It allows you to overlap icons, they never ever line up correctly and, all in all, I end up wasting more time arranging icons on my desktop than I ever did under Explorer's fascist regime. I'm sure people enjoy the flexibility of an fluid-ish grid ? but I don't. Please give us the option!&lt;/p&gt;


&lt;h2&gt;Pulseaudio&lt;/h2&gt;

&lt;img src="http://i.thepcspy.com/blog/20080626-ubuntu/pa.jpg"&gt;

&lt;p&gt;Pulseaudio (PA herein) is yet another answer to one of Linux's longest weaknesses: sound. Linux has too many sound ?solutions? that do fairly specific tasks but nothing has all the features to keep people happy. As a result, apps and frameworks (eg SDL) have to support multiple sound output configurations. It's a complete mess and adding PA hasn't helped in recent months. &lt;/p&gt;

&lt;p&gt;Unifying everybody under a fresh banner might sound like a good idea, but all the apps that need sound need to feed through PA. All fine as long as one of two conditions are met: &lt;/p&gt;

&lt;ol&gt;&lt;li&gt;&lt;p&gt;Devs create a PA module to output sound &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;They use PA's virtual inputs. &lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;

&lt;p&gt;The first requires more work but tends to produce a better result. The second requires the devs to use the virtual inputs in a standard manner. The issue, as I've come to understand it, is people don't always follow APIs to the letter. They hack their way around them to get things working.&lt;/p&gt;

&lt;p&gt;My complaint: PA + Wine + Steam + any Steam game = FAIL. &lt;/p&gt;

&lt;p&gt;Steam requires its own sound channel and so does the game. Wine doesn't support PA but that's fine because ALSA lets you do multiple simultaneous sources, so we pick ALSA. The problem is Wine doesn't use the API properly (according to PA devs) and/or PA doesn't implement the ALSA API correctly (according to Wine devs). &lt;/p&gt;

&lt;p&gt;The only workaround involves disabling Wine's sound, then starting Steam, then re-enabling sound, and using virtual-OSS, which only allows one app to connect to it at once. Or dump PA.&lt;/p&gt;

&lt;p&gt;And that's been the situation for months. I've been desperately looking for a sane fix but &lt;strong&gt;until somebody takes some responsibility, it's just us, the users, taking it on the chin&lt;/strong&gt;. I hope it's not another four months before somebody grows a pair and digs in.&lt;/p&gt;

&lt;p&gt;Stability is another issue for me in particular. Sometimes PA'll crash and you can load it back up, but over the past few weeks, it's been crashing and taking the entire system with it. PA crashing could be a symptom of something else. It's still under investigation but at the moment, I'm considering ditching PA.&lt;/p&gt;


&lt;h2&gt;Compiz&lt;/h2&gt;

&lt;img src="http://i.thepcspy.com/blog/20080626-ubuntu/cf.jpg"&gt;

&lt;p&gt;Compiz has quickly become the standard bearer for Linux's desktop abilities. It gives you tons of desktop-wizardry at a tiny portion of Vista's system requirements. What users don't first see are the numerous bugs floating around.&lt;/p&gt;

&lt;ul&gt;&lt;li&gt;&lt;p&gt;Resizing windows properly is deathly slow. The pseudo-resize is inaccurate.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Relatively poor 3d application performance compared to Windows.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Compiz + Wine = even worse performance.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Flash performance is terrible under Compiz. Fullscreen flash is unusable.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Compiz still can't get window positioning right on dual-screen setups. Pop-ups appear on the wrong screen or stuck between the two. You can't rely on Compiz to remember window positions. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Random window manager crashes that don't resurrect themselves, sometimes leaving you.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;

&lt;p&gt;You could blame several of these points on other projects, some of them closed source (Flash, nvidia), but my frustration ends up with Compiz because of the frivolous things they keep churning out. &lt;strong&gt;I know &lt;em&gt;they owe me nothing&lt;/em&gt;&lt;/strong&gt; but it's frustrating when instead of bugs getting fixed, there's another fish tank or snow globe plug-in.&lt;/p&gt;


&lt;h2&gt;Repositories and releases&lt;/h2&gt;

&lt;p&gt;Ubuntu's six month release cycle is there for good reason: stability. By limiting the number of large updates during a cycle, users don't receive any nasty shocks when something suddenly stops working. The problem with this model is application maturity. Only a few a few desktop applications can say they're truly stable or even feature complete at release and this means that lots of the apps in Hardy are outdated just two months after its release.&lt;/p&gt;

&lt;p&gt;Then there are applications that must always be the latest version. Anti-virus scanners. Multiplayer games. The kinds of apps whose updates aren't necessarily security patches but are required for optimal operation.&lt;/p&gt;

&lt;p&gt;Users are free to download the latest source and install it themselves but there must be a better way. Some have suggested implementing a &lt;a href="http://brainstorm.ubuntu.com/idea/1331/" rel="nofollow" target="_blank"&gt;Debian-style ?volatile? repository&lt;/a&gt; which would cover specific apps, as I've described but it's not quite enough in my eyes.&lt;/p&gt;

&lt;p&gt;I would go one further and say that apt needs re-engineering to enable users to choose between three states of upgrade policy on a package-by-package basis:&lt;/p&gt;

&lt;ol&gt;&lt;li&gt;&lt;p&gt;Do not upgrade at all.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Upgrade security and stability patches.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Use bleeding edge.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;


&lt;h2&gt;Ghosts in the machine&lt;/h2&gt;

&lt;p&gt;By definition, these are accumulations of issues causing random-looking behaviour:&lt;/p&gt;

&lt;ul&gt;&lt;li&gt;&lt;p&gt;X crashes&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Mouse de-sensitivity &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Pulseaudio crashes &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Random application crashing (with no reporting) &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;ALSA volume control randomness &lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;

&lt;p&gt;It's extremely difficult to target the issue for each of these. I've reported bugs to Launchpad for most of them but they'll either be ignored or inaccurately assigned as duplicates. &lt;/p&gt;


&lt;h2&gt;Application deficit&lt;/h2&gt;

&lt;p&gt;There are lots and lots of apps for Linux and I've replaced many of the ones I used in Windows with viable alternatives, but what happens when your work-flow depends on specific tasks that just aren't available in a Linux app? &lt;/p&gt;

&lt;p&gt;We're probably still a couple of years off Adobe porting their suite of creative applications across to Linux, so I'm left having to use a VM or Wine for Photoshop (no, The GIMP doesn't do all I need of it), Illustrator (same comment at Inksape) and Fireworks (a pretty unique mix of features).  &lt;/p&gt;

&lt;p&gt;Linux &lt;strong&gt;&lt;em&gt;NEEDS&lt;/em&gt;&lt;/strong&gt; commercial application support. Or Wine needs to get really good.&lt;/p&gt;

&lt;p&gt;On another note, I use Xine UI to play all my video files because it's unobtrusive and you can configure &lt;strong&gt;&lt;em&gt;EVERY&lt;/em&gt;&lt;/strong&gt; shortcut you can imagine, however, its interface (hidden 99% of the time) is ugly and it doesn't play digital TV, requiring me to load Kaffeine. Totem would be okay but it fails on all counts. VLC doesn't handle my mouse shortcuts for some reason. Mplayer is too minimal. SMplayer doesn't do everything.&lt;/p&gt;

&lt;p&gt;Similarly, I've used Thunderbird for years. I used it under Windows so it was my natural choice. However, they've been pretty slow at integrating Outlook-style tools (calendering, todo listing, sync). Evolution is integrated into Gnome. It can display your upcoming items on the main clock and does everything I could want... Except work. Evolution appears to have a pretty critical IMAP bug. I need IMAP more than I need Evolution.&lt;/p&gt;

&lt;p&gt;My point: choice can be an illusion when you're left between a rock and a hard place.&lt;/p&gt;

&lt;p&gt;I've mentioned bugs and vented my frustration that they're not fixed fast enough. This is exacerbated by knowing that it would take somebody with knowledge of the relevant projects just a few hours, if not minutes in some cases, to relieve my stress.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;And I'd be willing to pay them.&lt;/strong&gt; This is a refinement model that FOSS has to seize upon. There needs to be an open marketplace where users can out their woes and ask for developers to ?bid? on bugs. Deliverable through upstream patches and instructions on how to apply and compile, or pre-built packages. Multiple users could share the cost.&lt;/p&gt;

&lt;p&gt;There are obvious downsides to this plan: developers may adjust their behaviour and only do paying work, or, worse still, deliberately place bugs or limit functionality. But I think it's worth that risk. &lt;/p&gt;


&lt;h2&gt;Will I dump Linux?&lt;/h2&gt;

&lt;p&gt;It may look like I've just slammed out ~1600 words blasting Linux and its sub-projects but I could write infinitely more in its favour. And it's constantly improving. No, I'm not leaving Linux. I might be frustrated at the speed of some advancements but I'm sure as more and more developers join projects, more eyes will equate higher quality.&lt;/p&gt;

&lt;p&gt;I still believe.&lt;/p&gt;

&lt;p&gt;In time I hope to be able to resolve my own issues. I'm trying to get into it but it's a pretty steep learning curve for a web developer familiar in VB.NET/C#/PHP. If any of you reading have any tips, tutorials or time to kick me into gear, I'd love to learn.&lt;/p&gt;&lt;/img&gt;&lt;/img&gt;&lt;/img&gt;&lt;/img&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/thepcspyclean?a=VpqHLCwghEY:bvgE9caUb9s:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/thepcspyclean?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/thepcspyclean?a=VpqHLCwghEY:bvgE9caUb9s:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/thepcspyclean?i=VpqHLCwghEY:bvgE9caUb9s:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/thepcspyclean?a=VpqHLCwghEY:bvgE9caUb9s:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/thepcspyclean?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/thepcspyclean/~4/VpqHLCwghEY" height="1" width="1"/&gt;</description><pubDate>Wed, 23 Jul 2008 17:09:05 GMT</pubDate><author>no@spam.no (Oli)</author><guid isPermaLink="false">http://www.thepcspy.com/read/my_issues_with_linux_et_al#2491</guid><feedburner:origLink>http://www.thepcspy.com/read/my_issues_with_linux_et_al#2491</feedburner:origLink></item></channel></rss>
