<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>malware &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://en.wordpress.com/tag/malware/</link>
	<description>Feed of posts on WordPress.com tagged "malware"</description>
	<pubDate>Sun, 19 Jul 2009 15:40:16 +0000</pubDate>

	<generator>http://en.wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[Need Spyware, Virus, and Browser Protection? - Free Solutions]]></title>
<link>http://billmullins.wordpress.com/2009/07/19/need-spyware-virus-and-browser-protection-free-solutions/</link>
<pubDate>Sun, 19 Jul 2009 14:06:45 +0000</pubDate>
<dc:creator>Bill Mullins</dc:creator>
<guid>http://billmullins.wordpress.com/2009/07/19/need-spyware-virus-and-browser-protection-free-solutions/</guid>
<description><![CDATA[
Searching out, downloading, and installing free security programs from the Internet may appear to b]]></description>
<content:encoded><![CDATA[
Searching out, downloading, and installing free security programs from the Internet may appear to b]]></content:encoded>
</item>
<item>
<title><![CDATA[Loaris Trojan Remover 2.0.2.1]]></title>
<link>http://paylasimmekani.wordpress.com/2009/07/18/loaris-trojan-remover-2-0-2-1/</link>
<pubDate>Sat, 18 Jul 2009 18:10:29 +0000</pubDate>
<dc:creator>Admin</dc:creator>
<guid>http://paylasimmekani.wordpress.com/2009/07/18/loaris-trojan-remover-2-0-2-1/</guid>
<description><![CDATA[
 Loaris Trojan Remover; bilgisayarınıza bulaşan virüsleri temizlemeye yarayan oldukça başarılı bir ]]></description>
<content:encoded><![CDATA[
 Loaris Trojan Remover; bilgisayarınıza bulaşan virüsleri temizlemeye yarayan oldukça başarılı bir ]]></content:encoded>
</item>
<item>
<title><![CDATA[Completed Guide!]]></title>
<link>http://vileshadow.wordpress.com/2009/07/18/completed-guide/</link>
<pubDate>Sat, 18 Jul 2009 16:05:23 +0000</pubDate>
<dc:creator>vileshadow</dc:creator>
<guid>http://vileshadow.wordpress.com/2009/07/18/completed-guide/</guid>
<description><![CDATA[This is my small guide giving tips on how to stay secure on the internet it is currently up to v1.2.]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>This is my small guide giving tips on how to stay secure on the internet it is currently up to v1.2.3 so I have worked on it for some time. I hope it should be enough to explain and help those computer N00bs (New people) out there! <img src='http://s.wordpress.com/wp-includes/images/smilies/face-smile.png' alt=':)' class='wp-smiley' /><br />
This shall also be linked on the right side of the website under Links called &#8220;Download Protect Yourself From Internet Threats&#8221;</p>
<p><a href="http://cid-a782ff5720c846c6.skydrive.live.com/self.aspx/.Public/Protect%20Yourself%20From%20Internet%20Threats/Protect%20Yourself%20From%20Internet%20Threats%20v1.2.3%20RTW.pdf">Download Protect Yourself From Internet Threats v1.2.3 </a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Spam is a Pain in the Ass!]]></title>
<link>http://billmullins.wordpress.com/2009/07/18/spam-is-a-pain-in-the-ass/</link>
<pubDate>Sat, 18 Jul 2009 15:43:24 +0000</pubDate>
<dc:creator>Bill Mullins</dc:creator>
<guid>http://billmullins.wordpress.com/2009/07/18/spam-is-a-pain-in-the-ass/</guid>
<description><![CDATA[The following statistic bears repeating – last month (June, 09), over 90% of email was spam, and of ]]></description>
<content:encoded><![CDATA[The following statistic bears repeating – last month (June, 09), over 90% of email was spam, and of ]]></content:encoded>
</item>
<item>
<title><![CDATA[Rebel with Cause]]></title>
<link>http://countrycontemplative.wordpress.com/2009/07/18/rebel-with-caus/</link>
<pubDate>Sat, 18 Jul 2009 12:35:22 +0000</pubDate>
<dc:creator>Don</dc:creator>
<guid>http://countrycontemplative.wordpress.com/2009/07/18/rebel-with-caus/</guid>
<description><![CDATA[This is a cross posting from my other blog.
James Dean made a name for himself in the 1950&#8217;s m]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>This is a cross posting from my other <a href="http://www.donwatkins.net">blog</a>.</p>
<p>James Dean made a name for himself in the 1950&#8217;s movie, &#8220;Rebel Without a Cause.&#8221; In the past almost four years I&#8217;ve been determined to show that Linux and in particular Ubuntu Linux is a viable desktop operating system. I&#8217;ve proven it to myself time and again but still it remains an outlier in consumer circles. In the last week I&#8217;ve rebuilt three Windows computers that had been virtually destroyed by malware. In two of the three cases the individuals let their virus protection lapse, in the third the lady was using a well known anti-virus and security solution and she still was victimized. When I returned the computers to their owners I suggested how they could work to keep their machines from becoming infected again.</p>
<p>Lately, I&#8217;ve taken a more active stance promoting both Ubuntu equipped personal computers and Macintosh computers because Windows seems more vulnerable than ever. I can&#8217;t think of anything I do other than iTunes and Quicken which couldn&#8217;t be accomplished on Ubuntu. I&#8217;m able to read blogs, write blogs, send and receive email, participate in social networks, write HTML, and create and update websites. Have I left anything out. That&#8217;s a pretty complete listing. In any event I&#8217;m able to do all of that from my Dell Inspiron 6400 with Ubuntu 9.04. I am definitely plugging Ubuntu, but for you could do the same with Fedora and OpenSuse, PC Linux OS and the other Linux distros. Ubuntu just happens to be my favorite.</p>
<p>Recently I bought my son a MacBook for his home. Why a MacBook and not Ubuntu? Simply so that he could keep up with the Joneses in his life. All his friends have Macs and I thought what the heck. But, really there is no real difference in operating efficiency on Linux or Macintosh OSX. Both are open source at their core and Unix and Linux are much more secure and stable. I have to admit that the Macintosh GUI is compelling, but I still like using two and three buttons on my mouse or touchpad and that&#8217;s not possible with a Mac. In fact that two button dilemma is driving my son a bit batty. He&#8217;s used Windows most of his life and those of us who use Windows and Linux know that a mouse has more than one button and nearly all of our keyboard shortcuts are the same.</p>
<p>I am going to keep pushing Linux and Ubuntu in particular because it&#8217;s the most stable, least costly and most fun operating system on the planet at this time.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shipping Express Inc. aka www.shipping-express-inc.com ]]></title>
<link>http://scamfraudalert.wordpress.com/2009/07/18/shipping-express-inc-aka-www-shipping-express-inc-com/</link>
<pubDate>Sat, 18 Jul 2009 12:30:26 +0000</pubDate>
<dc:creator>Scrub</dc:creator>
<guid>http://scamfraudalert.wordpress.com/2009/07/18/shipping-express-inc-aka-www-shipping-express-inc-com/</guid>
<description><![CDATA[Shipping Express Inc. aka www.shipping-express-inc.com



http://www.shipping-express-inc.com


Doma]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><h2 style="text-align:center;"><span style="color:#000080;">Shipping Express Inc. aka www.shipping-express-inc.com</span></h2>
<table border="0" summary="Overview for the fake scammer bank Shipping Express Inc">
<tbody>
<tr>
<td><a href="http://www.shipping-express-inc.com/" target="_blank">http://www.shipping-express-inc.com</a></td>
</tr>
<tr>
<th>Domain</th>
<td>shipping-express-inc.com</td>
</tr>
<tr>
<th>IpAddress</th>
<td>205.178.145.65</td>
</tr>
<tr>
<th>Site Name</th>
<td>Shipping Express Inc</td>
</tr>
<tr>
<th>Web Host</th>
<td>205.178.145.65  ns50.worldnic.com.,    Network Solutions, LLC , abuse@networksolutions.com</td>
</tr>
<tr>
<th>Email</th>
<td>xv2442f93jp@networksolutionsprivateregistration.com</td>
</tr>
<tr>
<th>Status</th>
<td>dead</td>
</tr>
<tr>
<th>Whois</th>
<td>Domain Name: SHIPPING-EXPRESS-INC.COM<br />
Registrar: NETWORK SOLUTIONS, LLC.<br />
Whois Server: whois.networksolutions.com<br />
Referral URL: http://www.networksolutions.com</p>
<p>Name Server: NS49.WORLDNIC.COM<br />
Name Server: NS50.WORLDNIC.COM<br />
Status: clientTransferProhibited<br />
Updated Date: 26-jun-2009<br />
Creation Date: 26-jun-2009<br />
Expiration Date: 26-jun-2010<br />
Visit AboutUs.org for more information about SHIPPING-EXPRESS-INC.COM<br />
AboutUs: SHIPPING-EXPRESS-INC.COM<br />
&#8220;&#62;http://www.aboutus.org/SHIPPING-EXPRESS-INC.COM&#8221;&#62;AboutUs: SHIPPING-EXPRESS-INC.COM</p>
<p>Registrant:<br />
O&#8217;Prandy, Mary Ann<br />
ATTN: SHIPPING-EXPRESS-INC.COM<br />
c/o Network Solutions<br />
P.O. Box 447<br />
Herndon, VA. 20172-0447</p>
<p>Domain Name: SHIPPING-EXPRESS-INC.COM</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
Promote your business to millions of viewers for only $1 a month<br />
Learn how you can get an Enhanced Business Listing here for your domain name.<br />
Learn more at http://www.NetworkSolutions.com/</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>Administrative Contact, Technical Contact:<br />
O&#8217;Prandy, Mary Ann xv2442f93jp@networksolutionsprivateregistration.com<br />
ATTN: SHIPPING-EXPRESS-INC.COM<br />
c/o Network Solutions<br />
P.O. Box 447<br />
Herndon, VA 20172-0447<br />
570-708-8780</p>
<p>Record expires on 26-Jun-2010.<br />
Record created on 26-Jun-2009.<br />
Database last updated on 28-Jun-2009 09:32:24 EDT.</p>
<p>Domain servers in listed order:</p>
<p>NS49.WORLDNIC.COM 205.178.190.25<br />
NS50.WORLDNIC.COM 205.178.144.25</td>
</tr>
<tr>
<th>Date Added</th>
<td>2009-06-28 22:48</td>
</tr>
<tr>
<th>Updated</th>
<td>2009-06-29 16:17</td>
</tr>
</tbody>
</table>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Oh, Hush Chicken Little - The Sky is Not Falling: Why Cloud Security is Still Safe]]></title>
<link>http://blog.webroot.com/2009/07/17/oh-hush-chicken-little-the-sky-is-not-falling-why-cloud-security-is-still-safe/</link>
<pubDate>Fri, 17 Jul 2009 21:19:33 +0000</pubDate>
<dc:creator>brianczarny</dc:creator>
<guid>http://blog.webroot.com/2009/07/17/oh-hush-chicken-little-the-sky-is-not-falling-why-cloud-security-is-still-safe/</guid>
<description><![CDATA[By Brian Czarny

This week it was impossible to escape the “big news” that Twitter got hacked. The F]]></description>
<content:encoded><![CDATA[By Brian Czarny

This week it was impossible to escape the “big news” that Twitter got hacked. The F]]></content:encoded>
</item>
<item>
<title><![CDATA[Spyware removal στα γρήγορα]]></title>
<link>http://texnikos.wordpress.com/2009/07/17/spyware-removal-%cf%83%cf%84%ce%b1-%ce%b3%cf%81%ce%ae%ce%b3%ce%bf%cf%81%ce%b1/</link>
<pubDate>Fri, 17 Jul 2009 18:21:04 +0000</pubDate>
<dc:creator>fstat</dc:creator>
<guid>http://texnikos.wordpress.com/2009/07/17/spyware-removal-%cf%83%cf%84%ce%b1-%ce%b3%cf%81%ce%ae%ce%b3%ce%bf%cf%81%ce%b1/</guid>
<description><![CDATA[
Όσο καλά προστατευμένος και αν είναι κανείς σήμερα αποκλείεται να μην κολλήσει κάποιον ιο ή κάποιο ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><img class="aligncenter size-full wp-image-73" title="smashed_laptop" src="http://texnikos.wordpress.com/files/2009/07/smashed_laptop.jpg" alt="smashed_laptop" width="480" height="319" /></p>
<p>Όσο καλά προστατευμένος και αν είναι κανείς σήμερα αποκλείεται να μην κολλήσει κάποιον ιο ή κάποιο spyware. Αντιβιωτικά και antispyware υπάρχουν αρκετά και αν μολυνθεί το σύστημά μας το καθαρίζουν αρκετά καλά και χωρίς ιδιάιτερο κόπο. Τι γίνεται στην περίπτωση των λεγόμενων Rogue security software (aka rogueware);</p>
<p>Τα rogueware είναι malware που παρουσιάζεται με τη μορφή antivirus ή antimalware και μας ενημερώνει ότι το σύστημα μας είναι μολυνσμένο και πρέπει να καθαριστεί. Μας αλλάζει το φόντο, ανοίγει πολλά κόκκινα Χ στο tray και αρχίζει να ψάχνει για ιους (και καλά). Ουσιαστικά δεν μας αφήνει να δουλέψουμε με τα συνεχόμενα pop-up και τις προειδοποιήσεις.</p>
<p><img class="size-medium wp-image-71 alignleft" title="rogueware_1" src="http://texnikos.wordpress.com/files/2009/07/rogueware_1.jpg?w=300" alt="rogueware_1" width="300" height="200" /><img class="size-medium wp-image-72 alignnone" title="rogueware_2" src="http://texnikos.wordpress.com/files/2009/07/rogueware_2.jpg?w=300" alt="rogueware_2" width="300" height="225" /></p>
<p>Υπάρχει ένας πολύ γρήγορος τρόπος να αφαιρέσουμε το rogueware και είναι ιδιαίτερα αποτελεσματικός αν εφαρμοστεί στην αρχή της μόλυνσης.</p>
<p>Επαννεκινούμε τον υπολογιστή σε ασφαλή λειτουργία με δίκτυο.</p>
<p>Κατεβάζουμε το <a href="http://www.internetinspiration.co.uk/roguefix.htm">roguefix</a> (<a href="http://www.internetinspiration.co.uk/downloads/roguefix_2.248.bat">αρχείο</a>) που είναι ένα .bat αρχείο και το <a href="http://filehippo.com/download_malwarebytes_anti_malware/download/3720d21e01ad88e7c00f8ac89448197d/">malwarebytes anti-malware</a>.</p>
<p>Εκτελούμε το roguefix και ακολουθούμε τις απλές οδηγίες. Όταν τελειώσει κάνει μόνο του επανεκκίνηση και ξαναμπαίνουμε σε ασφαλή λειτουργία.</p>
<p><img class="aligncenter size-full wp-image-70" title="roguefix" src="http://texnikos.wordpress.com/files/2009/07/roguefix.gif" alt="roguefix" width="480" height="242" /></p>
<p>Εκτελούμε το anti-malware και καθαρίσαμε.</p>
<p>Πιάνει στο 90% των περιπτώσεων δοκιμασμένα.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Global Cyber News Bits, July 17, 2009 from CommunityDNS.]]></title>
<link>http://blog.communitydns.net/2009/07/17/global-cyber-news-bits-july-17-2009-from-communitydns/</link>
<pubDate>Fri, 17 Jul 2009 15:48:45 +0000</pubDate>
<dc:creator>CommunityDNS</dc:creator>
<guid>http://blog.communitydns.net/2009/07/17/global-cyber-news-bits-july-17-2009-from-communitydns/</guid>
<description><![CDATA[ Provided by CommunityDNS, the information in this post consists of news items in the security-based]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><em> Provided by <a href="http://www.communitydns.eu/facts.html"><span style="text-decoration:underline;">CommunityDNS</span></a>, the information in this post consists of news items in the security-based Internet community.</em></p>
<p><strong>China’s population of Web users hits 338 million, surpassing population of the United States</strong></p>
<p>With a Internet penetration, or saturation at only 25.5%, China has 338 million Internet users.  Fueled by rapid economic growth the growth rate since the end of 2008 is 13.4%.  Internet usage via mobile phones increased by 32.1%, representing 155 million users.  By contrast, the U.S. population is just under 307 million with an Internet penetration, or saturation of 70%.</p>
<p>Click <a href="http://www.newsday.com/technology/wire/sns-ap-as-china-internet-boom,0,7770487.story"><span style="text-decoration:underline;">here</span></a> for more information.</p>
<p><strong>U.S. Dept. of Energy builds attack defense network</strong></p>
<p>Pooling data from intrusion detection systems located at disparate DoE sites, the agency is in the beginning stages of deploying a network to more quickly respond to scans.  A new system developed by Argonne National Laboratories will flag things such as port scanning.  Based on information on a port scan from one site firewalls at other sites will be reconfigured to block traffic from the scanning IP address.</p>
<p>The following link provides a way to guard against this vulnerability until Microsoft releases a patch.</p>
<p>Click <a href="http://www.networkworld.com/news/2009/071609-argonne-security.html?fsrc=netflash-rss"><span style="text-decoration:underline;">here</span></a> for more information.</p>
<p><strong>Experts link flood of ‘Canadian Pharmacy’ spam to Russian botnet criminals</strong></p>
<p>Using the power of 8 botnets, Canadian Pharmacy is the largest producer of pharmaceutical-based spam.  Russian cybercrime groups are suspected as the force behind “Canadian Pharmacy”.</p>
<p>As a whole spam has grown 60% between January and June of this year to 150 billion messages per day.  75% of that spam is “pharmaceutical spam” or “pharma spam” with half of the “pharma spam” coming from Canadian Pharmacy.</p>
<p>Click <a href="http://www.networkworld.com/news/2009/071609-canadian-pharmacy-spam.html?fsrc=netflash-rss"><span style="text-decoration:underline;">here</span></a> for more information.</p>
<p><strong>HTC issues Hotfix for Bluetooth Vulnerability in Smartphones</strong></p>
<p>With Bluetooth switched “on” and Bluetooth file sharing “activated”, HTC handsets using Windows Mobile 6 and Windows Mobile 6.1 were vulnerable to attackers who wanted to access all files on a user’s phone.</p>
<p><em><span style="text-decoration:underline;">Comment:</span> This story shows the growing threat to mobile devices.</em></p>
<p>Click <a href="http://www.cio.com/article/497428/HTC_Issues_Hotfix_for_Bluetooth_Vulnerability_in_Smartphones"><span style="text-decoration:underline;">here</span></a> for more information.</p>
<p><strong>Webcams, printers, gizmos – the untold net threats</strong></p>
<p>Interacting with some of the more sensitive parts of a computer network, web interfaces, “gadgets”, such as webcams and printers that connect with computers where never designed to withstand attacks.  The NAS (network-attacked storage) units posed the highest number of threats as the unit was susceptible to all five attack classes.</p>
<p>Other devices that can be found in the “gadget” or “gizmo” category include network switches, routers, photo frames, voice over IP phones and other network equipment.</p>
<p>The devices are generally invisible to anti-virus software so even though a computer may be disinfected the secondary devices can keep infecting.</p>
<p>Click <a href="http://www.theregister.co.uk/2009/07/16/buggy_web_interface_peril/"><span style="text-decoration:underline;">here</span></a> for more information.</p>
<p><strong>Virgin Media sets throttle on hardcore hogs</strong></p>
<p>Virgin Media, UK ISP, will begin throttling back those who tend to hammer the network hardest.  Throttling will take place between 9:00am to 9:00pm for 2% of its customers.  However, If users pay for a more premium service throttling does not apply.</p>
<p>Click <a href="http://www.theregister.co.uk/2009/07/16/vm_throttling_change/"><span style="text-decoration:underline;">here</span></a> for more information.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux malware, sure it's possible]]></title>
<link>http://bambambambam.wordpress.com/2009/07/17/linux-malware-sure-its-possible/</link>
<pubDate>Fri, 17 Jul 2009 15:22:17 +0000</pubDate>
<dc:creator>bambambox</dc:creator>
<guid>http://bambambambam.wordpress.com/2009/07/17/linux-malware-sure-its-possible/</guid>
<description><![CDATA[Update 18th July 2009. If you want to read actual desktop environment developers (i.e. people who wh]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><strong>Update 18th July 2009. </strong>If you want to read actual desktop environment developers (i.e. people who who know loads more than I do) discussing this vulnerability, then <a title="Discuss discuss" href="http://archive.netbsd.se/?ml=xorg-xdg&#38;a=2006-03&#38;t=2724527" target="_blank">this 2006 thread</a> from a Xorg mailing list may interest you. If you want to see the proof that it actually works, then go right ahead and read on.</p>
<p>I tried to ask questions about this on a forum and got banhammered for it. But never mind. I did a bit of research into it and discovered that a <a title="How to write a Linux virus in five eays steps" href="http://www.geekzone.co.nz/foobar/6229" target="_blank">few people</a> <a title="Virus follow-up" href="http://www.geekzone.co.nz/foobar/6236" target="_blank">have</a> <a title="lwn" href="http://lwn.net/Articles/178409/" target="_blank">already</a> <a title="Ubuntu Brainstorm" href="http://brainstorm.ubuntu.com/idea/18028/" target="_blank">documented</a> <a title="Idea: .desktop files can run malware" href="http://brainstorm.ubuntu.com/idea/18132/" target="_blank">this</a> possible vulnerability, and that it <em>is</em> somewhat legitimate. People love to say that the biggest security threat for computers is the users themselves, which is fair enough. Who needs to craft a drive-by download when you can just get the users to click on naked_chix.jpg.exe all by themselves? Linux makes it difficult, but not impossible, for malware to take hold, but it pays to be aware of the dangers, however slight they may be. I don&#8217;t personally believe that there is much of a threat at all, and the particular exploit I&#8217;m about to describe isn&#8217;t very special or clever, either, and can only affect a small number of people. The only thing that <em>is</em> somewhat interesting about it is that it can get root access without drawing attention to itself.</p>
<p><!--more--></p>
<p>And that&#8217;s another thing about root access. Who really needs it? Sure, back when people made viruses to fry people&#8217;s hard-disks, having administrator privileges would have been a godsend. This is classically one of the reasons Windows has been so full of holes. New users were given Admin accounts by default, allowing them to tinker with every aspect of the system (within limits). Viruses run as the normal user could integrate themselves deep within the system utilities that made the operating system work, and from there carry on doing whatever it is they&#8217;re built to do. Of course nowadays, Windows doesn&#8217;t give its users root accounts by default. It has led to gripes because the UAC prompts you get on Vista tend to annoy some people, but the overall concept is sound. But the question remains: do you really need a root account to do the things that today&#8217;s malware does? Certainly not. Root helps, but it&#8217;s hardly necessary.</p>
<p>So any way, onwards we go.  Gnome does a very nice thing. It can override launchers for individual users. All of those lovely launchers you see in the Gnome Menu, well, they are all in /usr/share/applications. Go and take a look. But, they can be overridden by putting your launcher in ~/.local/share/applications. Gnome checks there before it looks for the global launchers, exactly the same way many applications check your home directory for conf files before looking in etc for global confs.</p>
<p>All you need to do to gain root access is make a duplicate launcher for an application that already requires root access. You don&#8217;t even need that, but a user might get suspicious if he&#8217;s prompted for his sudo password when launching Firefox. Synaptic, on the other hand, is a good choice. Let&#8217;s have a look at its desktop launcher in /usr/share/applications:</p>
<div style="margin:5px 20px 20px;">
<div style="margin-bottom:2px;">Code:</div>
<pre style="border:1px inset;overflow:auto;width:620px;height:210px;text-align:left;margin:0;padding:6px;">[Desktop Entry]
Name=Synaptic Package Manager
GenericName=Package Manager
Comment=Install, remove and upgrade software packages
<strong>Exec=gksu --description /usr/share/applications/synaptic.desktop /usr/sbin/synaptic</strong>
Icon=synaptic
Terminal=false
Type=Application
Categories=PackageManager;GTK;System;Settings;
NotShowIn=KDE;
X-Ubuntu-Gettext-Domain=synaptic</pre>
</div>
<p>So, if you were to put a launcher in ~/.local/share/applications that was exactly the same, except that it runs your malware first, then bingo, you&#8217;ve got root. Your malware can then happily go off and add itself to init.d and load up with root privileges every time you boot your machine. So I gave it a go:</p>
<div style="margin:5px 20px 20px;">
<div style="margin-bottom:2px;">Code:</div>
<pre style="border:1px inset;overflow:auto;width:620px;height:194px;text-align:left;margin:0;padding:6px;">[Desktop Entry]
Name=Synaptic Package Manager
GenericName=Package Manager
Comment=Install, remove and upgrade software packages
<strong>Exec=gksu --description /usr/share/applications/synaptic.desktop /home/ryan/ohno.sh</strong>
Icon=synaptic
Terminal=false
Type=Application
Categories=PackageManager;GTK;System;Settings;
NotShowIn=KDE;
X-Ubuntu-Gettext-Domain=synaptic</pre>
</div>
<p>The password dialogue will use the Synaptic description for the prompt when you try to open Synaptic:</p>
<p><img class="aligncenter size-full wp-image-255" title="gksu" src="http://bambambambam.wordpress.com/files/2009/07/gksu.png" alt="gksu" width="580" height="332" /></p>
<p>And then it&#8217;ll execute our virus (ohno.sh) with root privileges:</p>
<p><img class="aligncenter size-full wp-image-256" title="Oh no I is deaded" src="http://bambambambam.wordpress.com/files/2009/07/haxt.png" alt="Oh no I is deaded" width="224" height="155" /></p>
<p>Major bummer.</p>
<p>Any way, I was asked a question about how this rogue synaptic.desktop file gets into your application launcher folder in the first place. And sure, it isn&#8217;t a case of drive-by downloading. <strong>It requires the user to actually run something himself in order to take hold.</strong> This is what&#8217;s known as a trojan horse, and conventional wisdom goes that there is no way the operating system can ever fully guard users against these. The best weapon we have to fight trojan horses is education. This is a crucial point and I can&#8217;t stress it enough.</p>
<p>Some of you may be thinking, &#8220;Sure it could work on idiots, but I&#8217;m not going to arbitrarily execute some random code sent to me by some random guy without checking it first.&#8221; Well, no, of course not. But the tricks malware use to get users to click the OK button can be very devious. One of the attack vectors for the <a title="Fucker!" href="http://en.wikipedia.org/wiki/Conficker" target="_blank">Conficker</a> virus, for instance, involved hijacking the autostart prompt for playable media on Windows. What <em>looked</em> like the button for &#8220;Browse contents&#8221; was actually the option to run the installer for the virus!</p>
<p>Conficker is, admittedly, a special case, because it uses pretty much every method of infection available to Windows malware writers. But can we employ similar tactics to get people to open malware files on Linux? Sure, why not. And it&#8217;s doable with those pesky desktop files, again. On Gnome, the launchers can have any name you desire. In fact, if we make a launcher with the following code,</p>
<div style="margin:5px 20px 20px;">
<div style="margin-bottom:2px;">Code:</div>
<pre style="border:1px inset;overflow:auto;width:620px;height:400px;text-align:left;margin:0;padding:6px;">[Desktop Entry]
Version=1.0
Terminal=false
<strong>Exec=python exploit.py</strong>
Icon=ooo-writer
Type=Application
Categories=Application;Office;WordProcessor;
StartupNotify=false
MimeType=application/msword;application/rtf;application/vnd.ms-works;application/vnd.oasis.opendocument.text;application/vnd.oasis.opend$
InitialPreference=5
<strong>Name=lol.odt
Name[en_GB]=lol.odt</strong>
GenericName=Word Processor
GenericName[en_GB]=Word Processor
Comment=Create and edit text and graphics in letters, reports, documents and Web pages.
Comment[en_GB]=Create and edit text and graphics in letters, reports, documents and Web pages.</pre>
</div>
<p>We shall have the following to gawp at in our Nautilus:</p>
<p><img class="aligncenter size-full wp-image-259" title="This doesn't look good" src="http://bambambambam.wordpress.com/files/2009/07/hrmm1.png" alt="This doesn't look good" width="655" height="508" /></p>
<p>Well, that&#8217;s all well and good. But look at its real name, as it saved on the disk:</p>
<p><img class="aligncenter size-full wp-image-260" title="Oh no!" src="http://bambambambam.wordpress.com/files/2009/07/named.png" alt="Oh no!" width="655" height="510" /></p>
<p>So now we have a desktop launcher, hidden to look like a document file, that actually launches the exploit.py code. And sure enough, when our poor user attempts to open the document:</p>
<p><img class="aligncenter size-full wp-image-261" title="Not again!" src="http://bambambambam.wordpress.com/files/2009/07/notagain.png" alt="Not again!" width="379" height="256" /></p>
<p>In this example, it&#8217;s obvious that there is an exploit, because it&#8217;s unashamedly named right there in the same directory. But there are plenty of ways the desktop launcher could do something dodgy. For instance, you could set it to run a wget command to download and execute a remote exploit from the web. The exploit code itself can be filled with all of the virusy nastiness you would expect. Replacing all of the launchers that require gksu with a buggy version, for instance. Editing someone&#8217;s bashrc to hijack a sudo alias would be trivial, too. Gaining root is really not that difficult, so long as you can get the user to run the original exploit in the first place, by trying to open our dodgy document.</p>
<p>The question now is how does  this launcher get on to the user&#8217;s computer in the first place? It could be emailed to you, it could be sitting on a USB stick someplace. There are many ways it can happen. In fact if your exploit scans Evolution or Thunderbird for your contacts, or perhaps loads up a background process to spam itself to message boards, then it could conceivably become somewhat self-replicating, as all true viruses are.</p>
<p>I&#8217;m not saying this is a sure-fire way to pwn Linux users. Far from it, I actually think it&#8217;s kinda lame. And long_boobs_hair.jpg.exe was lame too, but that still caught people out. All I have described here is one very primitive and highly-specific mode of attack. And so it seems, it&#8217;s been written about many times before. Never mind. I never even considered it before, so I was more than a little bit intrigued to test how much such an attack can achieve. The answer, as with all trojan horses, is everything. <em>If</em> you let it happen.</p>
<p>I&#8217;m probably kidding myself if I think I can get away with posting this without getting any flames, but what the hell, so long at least one person in the world is now just that little more informed about the realities of malware, then I have achieved at least something worthwhile.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Canadian Pharmacy Spam Domains]]></title>
<link>http://scamfraudalert.wordpress.com/2009/07/17/canadian-pharmacy-spam-domains-3/</link>
<pubDate>Fri, 17 Jul 2009 14:49:13 +0000</pubDate>
<dc:creator>Scrub</dc:creator>
<guid>http://scamfraudalert.wordpress.com/2009/07/17/canadian-pharmacy-spam-domains-3/</guid>
<description><![CDATA[
Buying Precription Drugs Online May Be Dangerous
- Consumer Alert -
Drug Enforcement Administration]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><blockquote>
<h1 style="text-align:center;"><span style="color:#ff0000;">Buying Precription Drugs Online May Be Dangerous<br />
- Consumer Alert -<br />
Drug Enforcement Administration Says</span></h1>
</blockquote>
<p><a href="http://www.deadiversion.usdoj.gov/consumer_alert.htm"><img class="aligncenter size-full wp-image-1294" title="warning1" src="http://scamfraudalert.wordpress.com/files/2009/04/warning1.jpeg" alt="warning1" width="500" height="65" /></a></p>
<blockquote>
<h1 style="text-align:center;"><a href="http://www.nabp.net/">National Association of Boards of Pharmacy (NABP)</a></h1>
</blockquote>
<h3 style="font-size:18px;line-height:0;margin-top:40px;"><span style="color:#ff0000;"><span style="text-decoration:underline;">Warning</span></span></h3>
<blockquote><p><strong>&#8220;The Canadian Pharmacy, Canadian/European Pharmacy&#8221;, &#8220;Canadian Healthcare&#8221; and &#8220;US Drugstore&#8221; are brands of one of the most disgusting illegal online pharmacy group well organized </strong><span style="color:#ff0000;"><span style="text-decoration:underline;"><strong>CRIMINAL OPERATION</strong></span></span><strong> of all times. </strong><span style="color:#ff0000;"><strong>&#8220;GREED&#8221; </strong></span><strong>is the driving force behind this operation.  Don&#8217;t let them fool you. They will never send you any genuine drugs. If they ever send anything at all, it may consist of literally anything from sugar to wall plaster, and they certainly don&#8217;t care that you will endanger your health by taking those dangerous counterfeit drugs</strong>.</p></blockquote>
<h2>Domains on Nameserver ns2.growfour.com</h2>
<div style="text-align:center;font-size:.7em;font-weight:bold;margin-top:5px;">
<table style="text-align:left;width:100%;" border="0">
<tbody>
<tr>
<td style="text-align:right;">Entries 1 &#8211; 26 of 26</td>
</tr>
</tbody>
</table>
</div>
<div style="border:1px solid #bbbbbb;margin-top:0;font-size:.8em;">
<table border="0" cellspacing="1" cellpadding="4" width="100%">
<tbody>
<tr style="background-color:#eeeeee;">
<th align="center" valign="middle">Domain</th>
</tr>
<tr style="background-color:#ffffff;">
<td><a href="http://www.trustedsource.org/query/growfour.com">growfour.com</a></td>
</tr>
<tr style="background-color:#f1f1f1;">
<td><a href="http://www.trustedsource.org/query/agethough.com">agethough.com</a></td>
</tr>
<tr style="background-color:#ffffff;">
<td><a href="http://www.trustedsource.org/query/prettydone.com">prettydone.com</a></td>
</tr>
<tr style="background-color:#f1f1f1;">
<td><a href="http://www.trustedsource.org/query/wonderagree.com">wonderagree.com</a></td>
</tr>
<tr style="background-color:#ffffff;">
<td><a href="http://www.trustedsource.org/query/rosyworthy.com">rosyworthy.com</a></td>
</tr>
<tr style="background-color:#f1f1f1;">
<td><a href="http://www.trustedsource.org/query/tirethem.com">tirethem.com</a></td>
</tr>
<tr style="background-color:#ffffff;">
<td><a href="http://www.trustedsource.org/query/undersilent.com">undersilent.com</a></td>
</tr>
<tr style="background-color:#f1f1f1;">
<td><a href="http://www.trustedsource.org/query/lethour.com">lethour.com</a></td>
</tr>
<tr style="background-color:#ffffff;">
<td><a href="http://www.trustedsource.org/query/walkcamp.com">walkcamp.com</a></td>
</tr>
<tr style="background-color:#f1f1f1;">
<td><a href="http://www.trustedsource.org/query/reasoncount.com">reasoncount.com</a></td>
</tr>
<tr style="background-color:#ffffff;">
<td><a href="http://www.trustedsource.org/query/sitsign.com">sitsign.com</a></td>
</tr>
<tr style="background-color:#f1f1f1;">
<td><a href="http://www.trustedsource.org/query/grewduring.com">grewduring.com</a></td>
</tr>
<tr style="background-color:#ffffff;">
<td><a href="http://www.trustedsource.org/query/cornerdeep.com">cornerdeep.com</a></td>
</tr>
<tr style="background-color:#f1f1f1;">
<td><a href="http://www.trustedsource.org/query/musiclucky.com">musiclucky.com</a></td>
</tr>
<tr style="background-color:#ffffff;">
<td><a href="http://www.trustedsource.org/query/thansingle.com">thansingle.com</a></td>
</tr>
<tr style="background-color:#f1f1f1;">
<td><a href="http://www.trustedsource.org/query/isbounce.com">isbounce.com</a></td>
</tr>
<tr style="background-color:#ffffff;">
<td><a href="http://www.trustedsource.org/query/levelarrive.com">levelarrive.com</a></td>
</tr>
<tr style="background-color:#f1f1f1;">
<td><a href="http://www.trustedsource.org/query/bodyseem.com">bodyseem.com</a></td>
</tr>
<tr style="background-color:#ffffff;">
<td><a href="http://www.trustedsource.org/query/bornmind.com">bornmind.com</a></td>
</tr>
<tr style="background-color:#f1f1f1;">
<td><a href="http://www.trustedsource.org/query/alerthour.com">alerthour.com</a></td>
</tr>
<tr style="background-color:#ffffff;">
<td><a href="http://www.trustedsource.org/query/activeawake.com">activeawake.com</a></td>
</tr>
<tr style="background-color:#f1f1f1;">
<td><a href="http://www.trustedsource.org/query/liveevery.com">liveevery.com</a></td>
</tr>
<tr style="background-color:#ffffff;">
<td><a href="http://www.trustedsource.org/query/headten.com">headten.com</a></td>
</tr>
<tr style="background-color:#f1f1f1;">
<td><a href="http://www.trustedsource.org/query/toldan.com">toldan.com</a></td>
</tr>
<tr style="background-color:#ffffff;">
<td><a href="http://www.trustedsource.org/query/streamvictor.com">streamvictor.com</a></td>
</tr>
<tr style="background-color:#f1f1f1;">
<td><a href="http://www.trustedsource.org/query/stoodfriend.com">stoodfriend.com</a></td>
</tr>
</tbody>
</table>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stimul Media and Rx Partners Are The SAME]]></title>
<link>http://scamfraudalert.wordpress.com/2009/07/17/stimul-media-and-rx-partners-are-the-same/</link>
<pubDate>Fri, 17 Jul 2009 14:30:09 +0000</pubDate>
<dc:creator>Scrub</dc:creator>
<guid>http://scamfraudalert.wordpress.com/2009/07/17/stimul-media-and-rx-partners-are-the-same/</guid>
<description><![CDATA[
Today I signed up for two pharmacy affiliate programs: Rx Partners and Stimul Cash (former known as]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><div>
<p>Today I signed up for two pharmacy affiliate programs: <a rel="nofollow" href="http://rx-partners.biz/?wm=6058">Rx Partners</a> and <a rel="nofollow" href="http://www.stimul-cash.com/?aff_id=6057">Stimul Cash</a> (former known as Stimul Media). As you know, signing up for these two is quite hard these days and you are required to have invitation code plus webmaster approval to start making money with them. Here is a conversation with the approval guy (Mark from Rx-Partners):</p>
<ul>
<li>14:58:58 Me: Hello! I want to sign-up with stimul-media but the signup form does not appear. https://www.stimul-media.com/signup.html Please leave offline message if it’s the case.</li>
<li> 11:32:00 stimul-media: please register here http://www2.stimul-cash.com/signup.html</li>
<li> 13:18:31 Me: Hello! How can I sign-up on stimul-cash.com and give credit to a friend that reffered me? Is http://www2.stimul-cash.com/?partner=2331 going to work?</li>
<li> 13:19:22 stimul-media: yes, it will work.</li>
<li> 13:19:34 : ok, thanks</li>
<li> 13:22:22 stimul-media: are you signing up in Rx-parterns as well?</li>
<li> 13:22:38 Me: yes <img src="http://www.bubub.org/blog/wp-includes/images/smilies/icon_smile.gif" alt=":)" /></li>
<li> 13:22:51 Me: how did you know?</li>
<li> 13:23:20 430886685: we run both programs</li>
<li> 13:23:34 Me: I understand</li>
<li> 13:23:42 430886685: can yo uplease tellme how exactly are you planning to advertisie our sites?</li>
<li>I will advertise on http://www.canadianmedsworld.org/ and http://www.thecanadianmedz.org/ , search engine traffic.</li>
<li>13:25:15 430886685: I have apporved your account</li>
<li>13:25:23 Me: ok</li>
<li>13:25:31 Me: thank you</li>
</ul>
<p>That’s a lot of money these dudes are making. Two of the top affiliate programs. Hope this shit will work for me. If you want to sign up with Rx Partners and need an invitation code please leave a comment, I will respond in less than an hour. Also if you need affiliate coaching don’t hesitate to bother me.<br />
Later!</p>
<p><a href="http://www.bubub.org/blog/stimul-media-cash-rx-partners-affiliate/"><img class="aligncenter size-full wp-image-4317" title="stimul-cash - rxpartners" src="http://scamfraudalert.wordpress.com/files/2009/07/stimul-cash-rxpartners.jpg" alt="stimul-cash - rxpartners" width="500" height="1931" /></a></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Canadian Pharmacy - popular-ed-products.com]]></title>
<link>http://scamfraudalert.wordpress.com/2009/07/17/canadian-pharmacy-popular-ed-products-com/</link>
<pubDate>Fri, 17 Jul 2009 14:19:31 +0000</pubDate>
<dc:creator>Scrub</dc:creator>
<guid>http://scamfraudalert.wordpress.com/2009/07/17/canadian-pharmacy-popular-ed-products-com/</guid>
<description><![CDATA[
Buying Precription Drugs Online May Be Dangerous
- Consumer Alert -
Drug Enforcement Administration]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><blockquote>
<h1 style="text-align:center;"><span style="color:#ff0000;">Buying Precription Drugs Online May Be Dangerous<br />
- Consumer Alert -<br />
Drug Enforcement Administration Says</span></h1>
</blockquote>
<p><a href="http://www.deadiversion.usdoj.gov/consumer_alert.htm"><img class="aligncenter size-full wp-image-1294" title="warning1" src="http://scamfraudalert.wordpress.com/files/2009/04/warning1.jpeg" alt="warning1" width="500" height="65" /></a></p>
<blockquote>
<h1 style="text-align:center;"><a href="http://www.nabp.net/">National Association of Boards of Pharmacy (NABP)</a></h1>
</blockquote>
<h3 style="font-size:18px;line-height:0;margin-top:40px;"><span style="color:#ff0000;"><span style="text-decoration:underline;">Warning</span></span></h3>
<blockquote><p><strong>&#8220;The Canadian Pharmacy, Canadian/European Pharmacy&#8221;, &#8220;Canadian Healthcare&#8221; and &#8220;US Drugstore&#8221; are brands of one of the most disgusting illegal online pharmacy group well organized </strong><span style="color:#ff0000;"><span style="text-decoration:underline;"><strong>CRIMINAL OPERATION</strong></span></span><strong> of all times. </strong><span style="color:#ff0000;"><strong>&#8220;GREED&#8221; </strong></span><strong>is the driving force behind this operation.  Don&#8217;t let them fool you. They will never send you any genuine drugs. If they ever send anything at all, it may consist of literally anything from sugar to wall plaster, and they certainly don&#8217;t care that you will endanger your health by taking those dangerous counterfeit drugs.</strong></p></blockquote>
<h3 style="font-family:Arial, Helvetica, Verdana, sans-serif;color:#002b82;font-size:18px;line-height:0;margin-top:40px;"><a href="http://popular-ed-products.com/"><img class="aligncenter size-full wp-image-4314" title="popular-ed-product" src="http://scamfraudalert.wordpress.com/files/2009/07/popular-ed-product.jpg" alt="popular-ed-product" width="500" height="450" /></a></h3>
<h3 style="font-family:Arial, Helvetica, Verdana, sans-serif;color:#002b82;font-size:18px;line-height:0;margin-top:40px;">Address lookup</h3>
<table border="0" cellspacing="0" cellpadding="5">
<tbody>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" align="right" valign="baseline">canonical name</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="baseline"><span style="color:#002b82;font-weight:bold;"><a style="color:#0052f2;text-decoration:none;" href="http://www.popular-ed-products.com/">popular-ed-products.com</a>.</span></td>
</tr>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" align="right" valign="baseline">aliases</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="baseline"></td>
</tr>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" align="right" valign="baseline">addresses</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="baseline"><span style="color:#002b82;font-weight:bold;">88.85.65.165<br />
</span></td>
</tr>
</tbody>
</table>
<h3 style="font-family:Arial, Helvetica, Verdana, sans-serif;color:#002b82;font-size:18px;line-height:0;margin-top:40px;">Domain Whois record</h3>
<p style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;">Queried <span style="color:#002b82;font-weight:bold;">whois.internic.net</span> with &#8220;<span style="color:#002b82;font-weight:bold;">dom popular-ed-products.com</span>&#8220;&#8230;</p>
<pre style="color:black;font-family:'Courier New', monospace;font-size:13px;">   Domain Name: POPULAR-ED-PRODUCTS.COM
   Registrar: KEY-SYSTEMS GMBH
   Whois Server: whois.rrpproxy.net
   Referral URL: http://www.key-systems.net
   Name Server: NS1.STIMUL-MEDIA.COM
   Name Server: NS2.STIMUL-MEDIA.COM
   Status: clientTransferProhibited
   Updated Date: 13-apr-2009
   Creation Date: 02-sep-2008
   Expiration Date: 02-sep-2011

&#62;&#62;&#62; Last update of whois database: Fri, 17 Jul 2009 14:11:38 UTC &#60;&#60;&#60;</pre>
<p style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;">Queried <span style="color:#002b82;font-weight:bold;">whois.rrpproxy.net</span> with &#8220;<span style="color:#002b82;font-weight:bold;">popular-ed-products.com</span>&#8220;&#8230;</p>
<pre style="color:black;font-family:'Courier New', monospace;font-size:13px;">DOMAIN: POPULAR-ED-PRODUCTS.COM

RSP: domaindiscount24.com
URL: http://www.dd24.net

owner-contact: P-VLP199
owner-organization: STIMUL-MEDIA.COM
owner-fname: Vitaly
owner-lname: Petrov
owner-street: Petrozavodskaya st, 16, appt. 123
owner-city: Moscow
owner-zip: 125414
owner-country: RU
owner-phone: 79160248086
owner-email: vitalypetrov76@yahoo.com

admin-contact: P-VLP199
admin-organization: STIMUL-MEDIA.COM
admin-fname: Vitaly
admin-lname: Petrov
admin-street: Petrozavodskaya st, 16, appt. 123
admin-city: Moscow
admin-zip: 125414
admin-country: RU
admin-phone: 79160248086
admin-email: vitalypetrov76@yahoo.com

tech-contact: P-VLP199
tech-organization: STIMUL-MEDIA.COM
tech-fname: Vitaly
tech-lname: Petrov
tech-street: Petrozavodskaya st, 16, appt. 123
tech-city: Moscow
tech-zip: 125414
tech-country: RU
tech-phone: 79160248086
tech-email: vitalypetrov76@yahoo.com

billing-contact: P-VLP199
billing-organization: STIMUL-MEDIA.COM
billing-fname: Vitaly
billing-lname: Petrov
billing-street: Petrozavodskaya st, 16, appt. 123
billing-city: Moscow
billing-zip: 125414
billing-country: RU
billing-phone: 79160248086
billing-email: vitalypetrov76@yahoo.com

nameserver: ns1.stimul-media.com
nameserver: ns2.stimul-media.com</pre>
<h3 style="font-family:Arial, Helvetica, Verdana, sans-serif;color:#002b82;font-size:18px;line-height:0;margin-top:40px;">Network Whois record</h3>
<p style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;">Queried <span style="color:#002b82;font-weight:bold;">whois.ripe.net</span> with &#8220;<span style="color:#002b82;font-weight:bold;">-B 88.85.65.165</span>&#8220;&#8230;</p>
<pre style="color:black;font-family:'Courier New', monospace;font-size:13px;">% Information related to '88.85.64.0 - 88.85.71.255'

inetnum:        88.85.64.0 - 88.85.71.255
netname:        WEBAZILLA
descr:          WebaZilla
country:        NL
admin-c:        WZNL1-RIPE
tech-c:         WZNL1-RIPE
status:         ASSIGNED PA
mnt-by:         WZNET-MNT
mnt-routes:     WZNET-MNT
changed:        bk@webazilla.com 20070209
source:         RIPE

role:           WebaZilla RIPE Manager
address:        WebaZilla B.V.
address:        Postbus 19115
address:        3501DC Utrecht
address:        Netherlands
phone:          +31612253464
fax-no:         +31303100299
e-mail:         noc@webazilla.com
mnt-by:         WZNET-MNT
admin-c:        BK5536-RIPE
tech-c:         BK5536-RIPE
tech-c:         KV1670-RIPE
nic-hdl:        WZNL1-RIPE
changed:        bk@webazilla.com 20070718
source:         RIPE

% Information related to '88.85.64.0/19AS35415'

route:          88.85.64.0/19
descr:          WEBAZILLA
origin:         AS35415
mnt-by:         WZNET-MNT
changed:        bk@webazilla.com 20060728
source:         RIPE</pre>
<h3 style="font-family:Arial, Helvetica, Verdana, sans-serif;color:#002b82;font-size:18px;line-height:0;margin-top:40px;">DNS records</h3>
<p style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;">DNS query for <span style="color:#002b82;font-weight:bold;">165.65.85.88.in-addr.arpa</span> returned an error from the server: <strong>NameError</strong></p>
<table border="0" cellspacing="1" cellpadding="5">
<tbody>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;background-color:#f0f0f0;">name</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;background-color:#f0f0f0;">class</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;background-color:#f0f0f0;">type</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;background-color:#f0f0f0;">data</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;background-color:#f0f0f0;" colspan="2">time to live</td>
</tr>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">popular-ed-products.com</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">IN</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">SOA</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">
<table border="0" cellspacing="0" cellpadding="2" width="100%">
<tbody>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;">server:</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" align="right">ns1.stimul-media.com</td>
</tr>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;">email:</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" align="right">root.stimul-media.com</td>
</tr>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;">serial:</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" align="right">2008102903</td>
</tr>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;">refresh:</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" align="right">10800</td>
</tr>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;">retry:</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" align="right">3600</td>
</tr>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;">expire:</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" align="right">604800</td>
</tr>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;">minimum ttl:</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" align="right">38400</td>
</tr>
</tbody>
</table>
</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" align="right" valign="top">38400s</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">(10:40:00)</td>
</tr>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">popular-ed-products.com</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">IN</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">NS</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">ns2.stimul-media.com</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" align="right" valign="top">38400s</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">(10:40:00)</td>
</tr>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">popular-ed-products.com</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">IN</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">NS</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">ns1.stimul-media.com</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" align="right" valign="top">38400s</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">(10:40:00)</td>
</tr>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">popular-ed-products.com</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">IN</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">A</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">88.85.65.165</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" align="right" valign="top">38400s</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">(10:40:00)</td>
</tr>
</tbody>
</table>
<p style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;">&#8211; end &#8211;</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Spy Emergency Signature Update 515]]></title>
<link>http://spyemergency.wordpress.com/2009/07/17/spy-emergency-signature-update-515/</link>
<pubDate>Fri, 17 Jul 2009 10:49:14 +0000</pubDate>
<dc:creator>spyemergency</dc:creator>
<guid>http://spyemergency.wordpress.com/2009/07/17/spy-emergency-signature-update-515/</guid>
<description><![CDATA[Signature update 515 with publish date 2009/07/17 contains 2788 added or updated entries and is alre]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Signature update 515 with publish date 2009/07/17 contains 2788 added or updated entries and is already available as part of automatic or manual update option.</p>
<p><!--more--></p>
<p>+1178 Trojan.Win32.Malware<br />
+2 Trojan-PSW.Win32.OnLineGames<br />
+20 Trojan.Win32.Chifrax<br />
+50 Malware.Generic<br />
+7 Packed.Win32.PolyCrypt<br />
+368 Backdoor.Win32.Hupigon<br />
+2 RemoteAdmin.Win32.RAdmin<br />
+11 Worm.Win32.AutoRun<br />
+35 Trojan-GameThief.Win32.Magania<br />
+22 Trojan-Downloader.Win32.Agent<br />
+12 Trojan-PSW.Win32.QQPass<br />
+1 PSWTool.Win32.NetPass<br />
+6 Packed.Win32.Krap<br />
+3 Trojan-Banker.Win32.Banbra<br />
+28 Trojan-Dropper.Win32.VB<br />
+44 Trojan.Win32.Agent<br />
+22 Packed.Win32.Klone<br />
+24 Trojan.Win32.Crypt<br />
+16 Trojan-Banker.Win32.Banker<br />
+3 Virus.Win32.Alman<br />
+12 Backdoor.Win32.Poison<br />
+11 Virus.Win32.Parite<br />
+4 Net-Worm.Win32.Kido<br />
+52 Backdoor.Win32.Gen.A<br />
+18 Trojan-Dropper.Win32.Binder<br />
+38 Trojan.Win32.Inject<br />
+1 Exploit.JS.ADODB<br />
+18 Trojan.Win32.Buzus<br />
+3 Trojan-Spy.Win32.FlyStudio<br />
+12 Trojan.Win32.AntiAV<br />
+22 Trojan.Win32.Delf<br />
+3 Backdoor.Win32.Ceckno<br />
+2 Trojan-GameThief.Win32.Nilage<br />
+43 Backdoor.Win32.PcClient<br />
+1 EICAR-Test-File<br />
+2 Trojan.Win32.Vaklik<br />
+3 Backdoor.Win32.SdBot<br />
+1 Trojan-Downloader.MSIL.Agent<br />
+12 Trojan.Win32.Pakes<br />
+1 Trojan-Proxy.Win32.Dlena<br />
+12 Trojan.Win32.Qhost<br />
+6 Trojan-GameThief.Win32.WOW<br />
+15 Trojan-Dropper.Win32.Mudrop<br />
+2 Trojan.Win32.KillAV<br />
+7 Trojan-Downloader.Win32.Banload<br />
+7 Trojan-Downloader.Win32.Delf<br />
+32 Virus.Win32.Virut<br />
+13 Packed.Win32.Katusha<br />
+10 Trojan.Win32.Peed<br />
+4 Trojan-Dropper.Win32.Flystud<br />
+12 Backdoor.Win32.Agent<br />
+1 Trojan-Downloader.Win32.Tiny<br />
+3 Exploit.JS.Agent<br />
+24 Trojan-Spy.Win32.Agent<br />
+36 Trojan-Dropper.Win32.Agent<br />
+2 Backdoor.Win32.DsBot<br />
+13 Trojan-GameThief.Win32.OnLineGames<br />
+5 Trojan-Dropper.Win32.Delf<br />
+8 Trojan-Dropper.Win32.Danseed<br />
+1 Trojan.Win32.Dialer<br />
+1 Trojan.VBS.Starter<br />
+31 Net-Worm.Win32.Generic.D<br />
+13 Exploit.Win32.Generic<br />
+9 Backdoor.Win32.Small<br />
+1 VirTool.Win32.Injector<br />
+9 Trojan.Win32.Midgare<br />
+1 Trojan-Downloader.JS.Agent<br />
+1 Backdoor.Win32.Banito<br />
+2 HackTool.Win32.Kiser<br />
+30 Trojan.Win32.VB<br />
+12 Backdoor.Win32.Bifrose<br />
+1 Delf<br />
+4 Virus.Win32.Sality<br />
+1 Backdoor.Win32.Prorat<br />
+3 Trojan-PSW.Win32.VB<br />
+3 Trojan-Dropper.Win32.Small<br />
+1 Virus.Win32.VB<br />
+2 Backdoor.Win32.GrayBird<br />
+5 Trojan-Spy.Win32.Delf<br />
+5 Trojan-PSW.Win32.Agent<br />
+4 Trojan.Win32.Genome<br />
+6 Trojan.Win32.Vapsup<br />
+1 Trojan-PSW.Win32.LdPinch<br />
+2 Trojan.Win32.Agent2<br />
+1 Email-Worm.Win32.Wangy<br />
+1 Trojan.VBS.Shutdown<br />
+1 Backdoor.Java.JSP<br />
+1 IM-Worm.Win32.Sohanad<br />
+1 Trojan-Clicker.Win32.Densmail<br />
+2 Trojan.Win32.FraudPack<br />
+1 NewDotNet<br />
+1 PSWTool.Win32.WinLogon<br />
+2 Trojan-Downloader.Win32.Adload<br />
+4 Trojan.Win32.CDur<br />
+1 Trojan.BAT.Agent<br />
+3 Backdoor.Win32.Prosti<br />
+4 Trojan.Win32.Zlob<br />
+12 Exploit.Win32.JS<br />
+8 Trojan-Downloader.Win32.VB<br />
+1 PSWTool.Win32.Dialupass<br />
+1 RiskTool.Win32.Crypter<br />
+6 Packed.Win32.Tdss<br />
+6 Backdoor.ASP.Ace<br />
+1 Trojan.Win32.FlyStudio<br />
+4 Trojan-Downloader.VBS.Small<br />
+3 BHO<br />
+1 Exploit.HTML.Iframe<br />
+7 Backdoor.Win32.Delf<br />
+1 Email-Worm.Win32.Iksmas<br />
+2 Worm.Win32.AutoIt<br />
+14 Packed.Win32.Black<br />
+8 Rootkit.Win32.Agent<br />
+1 Worm.Win32.Autorun<br />
+6 Trojan-Downloader.Win32.Small<br />
+1 Net-Worm.Win32.Koobface<br />
+5 Trojan.Win32.Patched<br />
+6 Trojan-Proxy.Win32.Agent<br />
+2 Worm.Win32.Huhk<br />
+1 Virus.MSExcel.Yagnuul<br />
+1 Craagle<br />
+11 Trojan-Clicker.Win32.VB<br />
+1 Trojan-Clicker.Win32.Qhost<br />
+6 Backdoor.Win32.FlyAgent<br />
+2 HackTool.Win32.Sniffer<br />
+1 Trojan-Downloader.NSIS.QQHelper<br />
+1 RiskTool.Win32.HideWindows<br />
+2 Backdoor.Win32.Zdoogu<br />
+2 Trojan.Win32.Slefdel<br />
+1 Trojan-Downloader.WMA.GetCodec<br />
+1 Trojan.Win32.Autoit<br />
+2 Trojan-Dropper.Win32.Crypter<br />
+10 Packed.Win32.PePatch<br />
+1 Zhongsou<br />
+4 Trojan-Dropper.Win32.Joiner<br />
+1 Backdoor.Win32.Rbot<br />
+2 Exploit.Win32.IMG-WMF<br />
+7 Trojan-Downloader.Win32.FraudLoad<br />
+1 Trojan-Spy.Win32.Ardamax<br />
+1 Trojan-Spy.Win32.BZub<br />
+1 Trojan-GameThief.Win32.Ganhame<br />
+2 Trojan.Win32.Vundo<br />
+1 Trojan-Dropper.MSWord.1Table<br />
+1 P2P-Worm.Win32.Palevo<br />
+4 Monitor.Win32.Perflogger<br />
+3 Trojan.BAT.KillAV<br />
+1 Virus.Win32.Tenga<br />
+1 Email-Worm.VBS.Agent<br />
+1 Virus.Win32.Neshta<br />
+1 PSWTool.Win32.PdfCracker<br />
+1 Backdoor.Win32.Turkojan<br />
+1 Backdoor.Win32.NewRest<br />
+1 Trojan.BAT.DelFiles<br />
+5 Dialer<br />
+1 Trojan.Win32.Banker<br />
+1 Virus.Win32.Agent<br />
+2 Trojan-GameThief.Win32.Lmir<br />
+1 Exploit.Win32.Pidief<br />
+1 Worm.Win32.WhiteIce<br />
+1 PSWTool.Win32.PassView<br />
+1 NetTool.Win32.TCPScan<br />
+1 RiskTool.Win32.PsExec<br />
+1 Virus.Win9x.CIH<br />
+1 Trojan.Win32.Zytric<br />
+1 DMCast<br />
+3 Worm.Win32.VB<br />
+1 Backdoor.Win32.Graybird<br />
+1 Dialer.Win32.DialerOffline<br />
+1 AdMoke<br />
+1 PSWTool.Win32.SnadBoy<br />
+3 Trojan-PSW.Win32.Delf<br />
+2 Trojan-Dropper.Win32.FJoiner<br />
+1 P2P-Worm.Win32.Polip<br />
+1 HackTool.Win32.SQLInject<br />
+1 PSWTool.Win32.AirCrack<br />
+1 Trojan-Banker.Win32.Bancos<br />
+1 Trojan.Win32.Tdss<br />
+2 Trojan-Banker.Win32.Qhost<br />
+5 Backdoor.Win32.PoisonIvy<br />
+2 RiskTool.Win32.HideProc<br />
+1 Trojan.Win32.Genlot<br />
+1 RiskTool.Win32.VB<br />
+1 Trojan-PSW.Win32.Element<br />
+1 PSWTool.Win32.Brutus<br />
+1 PSWTool.Win32.Pwdspyhk<br />
+1 Trojan.Win32.KillFiles<br />
+2 Exploit.HTML.CodeBaseExec<br />
+1 PSWTool.Win32.MailPassView<br />
+1 NetTool.Win32.Agent<br />
+1 Backdoor.Win32.RAdmin<br />
+1 Dm<br />
+1 RiskTool.Win32.WFPDisabler<br />
+1 Worm.Win32.Fujacks<br />
+1 Trojan-Clicker.HTML.IFrame<br />
+1 Backdoor.Win32.Shark<br />
+1 Trojan-Downloader.Win32.Bagle<br />
+1 Trojan.Win32.Obfuscated<br />
+1 Astro<br />
+1 Trojan.Win32.Regrun<br />
+1 IM-Flooder.Win32.RoomDestroyer<br />
+1 Packed.Win32.NSAnti<br />
+1 Trojan.Win32.BHO<br />
+1 Trojan-Spy.Win32.Gologger<br />
+1 PSWTool.Win32.SpySharp<br />
+1 Trojan-Downloader.VBS.Psyme<br />
+1 Virus.Win32.VBS<br />
+1 Worm.Win32.Agent<br />
+1 Trojan-Downloader.HTML.Agent<br />
+1 PSWTool.Win32.ProductKey<br />
+2 Virus.Win32.Downloader<br />
+1 Virus.Acad.Bursted<br />
+1 Worm.Win32.Fujack<br />
+2 Trojan-PSW.Win32.QQRob<br />
+2 Hoax.Win32.Bravia<br />
+2 Cinmus<br />
+1 Trojan.Win32.Small<br />
+1 Trojan-Banker.Win32.Banker2<br />
+2 PSW.QQPass<br />
+2 AntivirusPlus<br />
+1 SpywareRemover<br />
+1 Backdoor.Win32.Mex<br />
+1 PSW.Delf<br />
+1 UltimateDefender<br />
+1 Backdoor.Win32.Bifrost<br />
+1 Trojan-Downloader.JS.Small<br />
+2 HackTool.Win32.Patcher<br />
+1 Trojan.Win32.Zapchast<br />
+4 Trojan.Win32.Renos</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Canadian Pharmacy Spam - tirethem.com]]></title>
<link>http://scamfraudalert.wordpress.com/2009/07/16/canadian-pharmacy-spam-tirethem-com/</link>
<pubDate>Fri, 17 Jul 2009 04:49:22 +0000</pubDate>
<dc:creator>Scrub</dc:creator>
<guid>http://scamfraudalert.wordpress.com/2009/07/16/canadian-pharmacy-spam-tirethem-com/</guid>
<description><![CDATA[
Header Analysis
The following IP addresses were extracted from your headers:




IP Address
Probabl]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><span style="font-family:'Trebuchet MS';line-height:normal;"></p>
<h2>Header Analysis</h2>
<p><strong>The following IP addresses were extracted from your headers:</strong></p>
<p></span></p>
<table class="ip-table" style="width:635px;" border="0">
<tbody>
<tr>
<td class="ip-head" style="font-weight:bold;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#e2e2e2;padding-left:8px;background-position:initial initial;border:1px solid #000000;">IP Address</td>
<td class="country-head" style="font-weight:bold;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#e2e2e2;padding-left:8px;background-position:initial initial;border:1px solid #000000;">Probable Country</td>
<td class="country-head" style="font-weight:bold;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#e2e2e2;padding-left:8px;background-position:initial initial;border:1px solid #000000;" colspan="4">Additional Info</td>
</tr>
<tr>
<td class="ip-cell" style="color:#000000;width:200px;padding-left:8px;">131.114.69.63</td>
<td class="country-cell" style="color:#000000;width:200px;padding-left:8px;">Italy (Serra)<a class="note" style="color:blue;text-decoration:none;" href="http://headertool.apelord.com/headers#accuracy">*</a></td>
<td class="whois" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#315ba6;background-position:initial initial;border-color:#8db0f1 #021d4f #021d4f #8db0f1;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://private.dnsstuff.com/tools/whois.ch?ip=131.114.69.63">Whois</a></td>
<td class="google" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#aa3d3d;background-position:initial initial;border-color:#f88f8f #6c0606 #6c0606 #f88f8f;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://groups.google.com/groups?q=131.114.69.63&#38;ie=UTF-8&#38;oe=UTF-8&#38;hl=en&#38;btnG=Google+Search">Google</a></td>
<td class="whois" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#315ba6;background-position:initial initial;border-color:#8db0f1 #021d4f #021d4f #8db0f1;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://private.dnsstuff.com/tools/ipall.ch?domain=131.114.69.63">DNSStuff</a></td>
<td class="google" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#aa3d3d;background-position:initial initial;border-color:#f88f8f #6c0606 #6c0606 #f88f8f;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://www.urgentmessage.org/IPfreely/_i?filter=131.114.69.63">Urgentmessage.org</a></td>
</tr>
<tr>
<td class="ip-cell" style="color:#000000;width:200px;padding-left:8px;">207.115.20.186</td>
<td class="country-cell" style="color:#000000;width:200px;padding-left:8px;">United States (Richardson)<a class="note" style="color:blue;text-decoration:none;" href="http://headertool.apelord.com/headers#accuracy">*</a></td>
<td class="whois" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#315ba6;background-position:initial initial;border-color:#8db0f1 #021d4f #021d4f #8db0f1;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://private.dnsstuff.com/tools/whois.ch?ip=207.115.20.186">Whois</a></td>
<td class="google" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#aa3d3d;background-position:initial initial;border-color:#f88f8f #6c0606 #6c0606 #f88f8f;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://groups.google.com/groups?q=207.115.20.186&#38;ie=UTF-8&#38;oe=UTF-8&#38;hl=en&#38;btnG=Google+Search">Google</a></td>
<td class="whois" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#315ba6;background-position:initial initial;border-color:#8db0f1 #021d4f #021d4f #8db0f1;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://private.dnsstuff.com/tools/ipall.ch?domain=207.115.20.186">DNSStuff</a></td>
<td class="google" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#aa3d3d;background-position:initial initial;border-color:#f88f8f #6c0606 #6c0606 #f88f8f;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://www.urgentmessage.org/IPfreely/_i?filter=207.115.20.186">Urgentmessage.org</a></td>
</tr>
<tr>
<td class="note-cell" style="color:#000000;font-size:9px;font-weight:bold;" colspan="3">* The last IP listed is <em>usually</em> the originating IP address</td>
</tr>
</tbody>
</table>
<p><span style="font-family:'Trebuchet MS';line-height:normal;">Here is the text you submitted, with the IP addresses highlighted:</p>
<p></span></p>
<p>From Douglas Andrews Thu Jul 16 15:16:43 2009<br />
Return-Path:<br />
Authentication-Results: mta118.sbc.mail.mud.yahoo.com  from=yeoy.fi; domainkeys=neutral (no sig); from=yeoy.fi; dkim=neutral (no  sig)<br />
Received: from <strong><span style="color:#ff0000;">131.114.69.63</span></strong> (EHLO flpi184.prodigy.net) <strong><span style="color:#ff0000;">(207.115.20.186)</span></strong><br />
by mta118.sbc.mail.mud.yahoo.com with SMTP; Thu, 16 Jul 2009 15:18:09 -0700<br />
<strong><span style="color:#ff0000;"> Received: from zelgti4 (verita.vet.unipi.it [131.114.69.63] (may be forged))<br />
by flpi184.prodigy.net (8.13.8 inb ipv6 jeff0203/8.13.8) with SMTP id n6GMGhA2014995;<br />
Thu, 16 Jul 2009 15:18:06 -0700</span></strong><br />
Message-ID: &#60;000701ca0663$19d4dcf0$627e2c0a@yeoy.fi&#62;<br />
Reply-To: &#8220;Douglas Andrews&#8221;   &#60;douglas.andrewsip@yeoy.fi&#62;<br />
From: &#8220;Douglas Andrews&#8221;   &#60;douglas.andrewsip@yeoy.fi&#62;<br />
To: ,<br />
<strong> Subject: Have No Problem in BeD, RxMeds online!</strong><br />
Date: Thu, 16 Jul 2009 15:16:43 -0700<br />
MIME-Version: 1.0<br />
Content-Type: text/plain;<br />
format=flowed;<br />
charset=&#8221;windows-1250&#8243;<br />
reply-type=original<br />
Content-Transfer-Encoding: 7bit<br />
Content-Length: 136</p>
<p>An Incredible Canadian_Pharmacy is available at your <span style="border-bottom:1px dashed #0066cc;background:transparent none repeat scroll 0 0;cursor:pointer;">Fingertips</span>!<br />
No <span style="border-bottom:1px dashed #0066cc;background:transparent none repeat scroll 0 0;cursor:pointer;">Doctor</span> Needed! Browse our Site Today! -&#62; <a href="http://tirethem.com/" target="_blank"><span>http://tirethem.com</span></a></p>
<p>_________________________________________________________________________</p>
<p><span style="font-family:'Trebuchet MS';line-height:normal;"> </span></p>
<h2>Header Analysis</h2>
<p><strong>The following IP addresses were extracted from your headers:</strong></p>
<table class="ip-table" style="width:635px;" border="0">
<tbody>
<tr>
<td class="ip-head" style="font-weight:bold;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#e2e2e2;padding-left:8px;background-position:initial initial;border:1px solid #000000;">IP Address</td>
<td class="country-head" style="font-weight:bold;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#e2e2e2;padding-left:8px;background-position:initial initial;border:1px solid #000000;">Probable Country</td>
<td class="country-head" style="font-weight:bold;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#e2e2e2;padding-left:8px;background-position:initial initial;border:1px solid #000000;" colspan="4">Additional Info</td>
</tr>
<tr>
<td class="ip-cell" style="color:#000000;width:200px;padding-left:8px;">97.93.204.30</td>
<td class="country-cell" style="color:#000000;width:200px;padding-left:8px;">United States (Granbury)<a class="note" style="color:blue;text-decoration:none;" href="http://headertool.apelord.com/headers#accuracy">*</a></td>
<td class="whois" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#315ba6;background-position:initial initial;border-color:#8db0f1 #021d4f #021d4f #8db0f1;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://private.dnsstuff.com/tools/whois.ch?ip=97.93.204.30">Whois</a></td>
<td class="google" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#aa3d3d;background-position:initial initial;border-color:#f88f8f #6c0606 #6c0606 #f88f8f;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://groups.google.com/groups?q=97.93.204.30&#38;ie=UTF-8&#38;oe=UTF-8&#38;hl=en&#38;btnG=Google+Search">Google</a></td>
<td class="whois" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#315ba6;background-position:initial initial;border-color:#8db0f1 #021d4f #021d4f #8db0f1;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://private.dnsstuff.com/tools/ipall.ch?domain=97.93.204.30">DNSStuff</a></td>
<td class="google" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#aa3d3d;background-position:initial initial;border-color:#f88f8f #6c0606 #6c0606 #f88f8f;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://www.urgentmessage.org/IPfreely/_i?filter=97.93.204.30">Urgentmessage.org</a></td>
</tr>
<tr>
<td class="ip-cell" style="color:#000000;width:200px;padding-left:8px;">207.115.36.96</td>
<td class="country-cell" style="color:#000000;width:200px;padding-left:8px;">United States (Richardson)<a class="note" style="color:blue;text-decoration:none;" href="http://headertool.apelord.com/headers#accuracy">*</a></td>
<td class="whois" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#315ba6;background-position:initial initial;border-color:#8db0f1 #021d4f #021d4f #8db0f1;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://private.dnsstuff.com/tools/whois.ch?ip=207.115.36.96">Whois</a></td>
<td class="google" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#aa3d3d;background-position:initial initial;border-color:#f88f8f #6c0606 #6c0606 #f88f8f;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://groups.google.com/groups?q=207.115.36.96&#38;ie=UTF-8&#38;oe=UTF-8&#38;hl=en&#38;btnG=Google+Search">Google</a></td>
<td class="whois" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#315ba6;background-position:initial initial;border-color:#8db0f1 #021d4f #021d4f #8db0f1;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://private.dnsstuff.com/tools/ipall.ch?domain=207.115.36.96">DNSStuff</a></td>
<td class="google" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#aa3d3d;background-position:initial initial;border-color:#f88f8f #6c0606 #6c0606 #f88f8f;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://www.urgentmessage.org/IPfreely/_i?filter=207.115.36.96">Urgentmessage.org</a></td>
</tr>
<tr>
<td class="note-cell" style="color:#000000;font-size:9px;font-weight:bold;" colspan="3">* The last IP listed is <em>usually</em> the originating IP address</td>
</tr>
</tbody>
</table>
<p><span style="font-family:'Trebuchet MS';line-height:normal;">Here is the text you submitted, with the IP addresses highlighted:</span></p>
<p>From Humberto Wade Thu Jul 16 12:23:14 2009<br />
Return-Path:<br />
Authentication-Results: mta167.sbc.mail.mud.yahoo.com  from=cw-chamber.co.uk; domainkeys=neutral (no sig); from=cw-chamber.co.uk; dkim=neutral (no  sig)<br />
Received: from <strong><span style="color:#ff0000;">97.93.204.30</span></strong> (EHLO nlpi080.prodigy.net)<strong><span style="color:#ff0000;"> (207.115.36.96)</span></strong><br />
by mta167.sbc.mail.mud.yahoo.com with SMTP; <strong><span style="color:#ff0000;">Thu, 16 Jul 2009 12:21:16 -0700<br />
Received: from vyg3oj2 (static.unknown.charter.com </span></strong><span style="color:#ff0000;"><strong><span style="color:#ff0000;">[97.93.204.30]</span></strong></span><strong><span style="color:#ff0000;"> (may be forged))</span></strong><br />
by nlpi080.prodigy.net (8.13.8 inb ipv6 jeff0203/8.13.8) with SMTP id n6GJKlgD004846;<br />
Thu, 16 Jul 2009 14:21:10 -0500<br />
<strong><span style="color:#ff0000;"> Message-ID: &#60;000701ca064a$dd1d9350$431333e2@cw-chamber.co.uk&#62;</span></strong><br />
Reply-To: &#8220;Humberto Wade&#8221; &#60;hwade_ms@cw-chamber.co.uk&#62;<br />
From: &#8220;Humberto Wade&#8221;<br />
To: , ,<br />
<strong> Subject: great web offer</strong><br />
Date: Thu, 16 Jul 2009 14:23:14 -0500<br />
MIME-Version: 1.0<br />
Content-Type: text/plain;<br />
format=flowed;<br />
charset=&#8221;windows-1250&#8243;<br />
reply-type=original<br />
Content-Transfer-Encoding: 7bit<br />
Content-Length: 137</p>
<p>An Incredible Canadian_Pharmacy is available at your <span style="border-bottom:1px dashed #0066cc;cursor:pointer;">Fingertips</span>!<br />
No <span style="border-bottom:1px dashed #0066cc;cursor:pointer;">Doctor</span> Needed! Browse our Site Today! -&#62; <a href="http://liveevery.com/" target="_blank"><span>http://liveevery.com</span></a></p>
<p>____________________________________________________________-</p>
<p><span style="font-family:'Trebuchet MS';line-height:normal;"> </span></p>
<h2>Header Analysis</h2>
<p><strong>The following IP addresses were extracted from your headers:</strong></p>
<table class="ip-table" style="width:635px;" border="0">
<tbody>
<tr>
<td class="ip-head" style="font-weight:bold;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#e2e2e2;padding-left:8px;background-position:initial initial;border:1px solid #000000;">IP Address</td>
<td class="country-head" style="font-weight:bold;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#e2e2e2;padding-left:8px;background-position:initial initial;border:1px solid #000000;">Probable Country</td>
<td class="country-head" style="font-weight:bold;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#e2e2e2;padding-left:8px;background-position:initial initial;border:1px solid #000000;" colspan="4">Additional Info</td>
</tr>
<tr>
<td class="ip-cell" style="color:#000000;width:200px;padding-left:8px;">65.126.184.100</td>
<td class="country-cell" style="color:#000000;width:200px;padding-left:8px;">United States (Telluride)<a class="note" style="color:blue;text-decoration:none;" href="http://headertool.apelord.com/headers#accuracy">*</a></td>
<td class="whois" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#315ba6;background-position:initial initial;border-color:#8db0f1 #021d4f #021d4f #8db0f1;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://private.dnsstuff.com/tools/whois.ch?ip=65.126.184.100">Whois</a></td>
<td class="google" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#aa3d3d;background-position:initial initial;border-color:#f88f8f #6c0606 #6c0606 #f88f8f;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://groups.google.com/groups?q=65.126.184.100&#38;ie=UTF-8&#38;oe=UTF-8&#38;hl=en&#38;btnG=Google+Search">Google</a></td>
<td class="whois" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#315ba6;background-position:initial initial;border-color:#8db0f1 #021d4f #021d4f #8db0f1;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://private.dnsstuff.com/tools/ipall.ch?domain=65.126.184.100">DNSStuff</a></td>
<td class="google" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#aa3d3d;background-position:initial initial;border-color:#f88f8f #6c0606 #6c0606 #f88f8f;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://www.urgentmessage.org/IPfreely/_i?filter=65.126.184.100">Urgentmessage.org</a></td>
</tr>
<tr>
<td class="ip-cell" style="color:#000000;width:200px;padding-left:8px;">207.115.36.161</td>
<td class="country-cell" style="color:#000000;width:200px;padding-left:8px;">United States (Richardson)<a class="note" style="color:blue;text-decoration:none;" href="http://headertool.apelord.com/headers#accuracy">*</a></td>
<td class="whois" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#315ba6;background-position:initial initial;border-color:#8db0f1 #021d4f #021d4f #8db0f1;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://private.dnsstuff.com/tools/whois.ch?ip=207.115.36.161">Whois</a></td>
<td class="google" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#aa3d3d;background-position:initial initial;border-color:#f88f8f #6c0606 #6c0606 #f88f8f;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://groups.google.com/groups?q=207.115.36.161&#38;ie=UTF-8&#38;oe=UTF-8&#38;hl=en&#38;btnG=Google+Search">Google</a></td>
<td class="whois" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#315ba6;background-position:initial initial;border-color:#8db0f1 #021d4f #021d4f #8db0f1;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://private.dnsstuff.com/tools/ipall.ch?domain=207.115.36.161">DNSStuff</a></td>
<td class="google" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#aa3d3d;background-position:initial initial;border-color:#f88f8f #6c0606 #6c0606 #f88f8f;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://www.urgentmessage.org/IPfreely/_i?filter=207.115.36.161">Urgentmessage.org</a></td>
</tr>
<tr>
<td class="note-cell" style="color:#000000;font-size:9px;font-weight:bold;" colspan="3">* The last IP listed is <em>usually</em> the originating IP address</td>
</tr>
</tbody>
</table>
<p><span style="font-family:'Trebuchet MS';line-height:normal;">Here is the text you submitted, with the IP addresses highlighted:</span></p>
<p>From Lucille J. Stringer Thu Jul 16 10:02:34 2009<br />
Return-Path:<br />
Authentication-Results: mta111.sbc.mail.gq1.yahoo.com  from=crs-ltd.co.uk; domainkeys=neutral (no sig); from=crs-ltd.co.uk; dkim=neutral (no  sig)<br />
Received: from 65.126.184.100  (EHLO nlpi147.prodigy.net) <span style="color:#ff0000;">(207.115.36.161)</span><br />
by mta111.sbc.mail.gq1.yahoo.com with SMTP; Thu, 16 Jul 2009 10:05:49 -0700<br />
<span style="color:#ff0000;"><strong> Received: from 1blry72</strong></span><span style="color:#ff0000;"><strong> ([65.126.184.100])</strong></span><span style="color:#ff0000;"><strong><br />
by nlpi147.prodigy.net (8.13.8 inb ipv6 jeff0203/8.13.8) with SMTP id n6GH54dn028723;<br />
Thu, 16 Jul 2009 12:05:42 -0500</strong></span><strong><br />
</strong> <span style="color:#ff0000;"><strong> Message-ID: &#60;000701ca0637$36f56420$d828ea62@crs-ltd.co.uk&#62;</strong></span><strong><br />
</strong> Reply-To: &#8220;Lucille J. Stringer&#8221;   &#60;lucille_stringer_es@crs-ltd.co.uk&#62;<br />
From: &#8220;Lucille J. Stringer&#8221;   &#60;lucille_stringer_es@crs-ltd.co.uk&#62;<br />
To: , ,<br />
<strong> Subject: Feeling unneeded in bedroom? We can change that..</strong><br />
Date: Thu, 16 Jul 2009 12:02:34 -0500<br />
MIME-Version: 1.0<br />
Content-Type: text/plain;<br />
format=flowed;<br />
charset=&#8221;windows-1250&#8243;<br />
reply-type=original<br />
Content-Transfer-Encoding: 7bit<br />
Content-Length: 137</p>
<p>An Incredible Canadian_Pharmacy is available at your <span style="border-bottom:1px dashed #0066cc;cursor:pointer;">Fingertips</span>!<br />
No <span style="border-bottom:1px dashed #0066cc;background:transparent none repeat scroll 0 0;cursor:pointer;">Doctor</span> Needed! Browse our Site Today! -&#62; <a href="http://liveevery.com/" target="_blank"><span>http://liveevery.com</span></a></p>
<p>________________________________________________</p>
<p><span style="font-family:'Trebuchet MS';line-height:normal;"> </span></p>
<h2>Header Analysis</h2>
<p><strong>The following IP addresses were extracted from your headers:</strong></p>
<table class="ip-table" style="width:635px;" border="0">
<tbody>
<tr>
<td class="ip-head" style="font-weight:bold;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#e2e2e2;padding-left:8px;background-position:initial initial;border:1px solid #000000;">IP Address</td>
<td class="country-head" style="font-weight:bold;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#e2e2e2;padding-left:8px;background-position:initial initial;border:1px solid #000000;">Probable Country</td>
<td class="country-head" style="font-weight:bold;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#e2e2e2;padding-left:8px;background-position:initial initial;border:1px solid #000000;" colspan="4">Additional Info</td>
</tr>
<tr>
<td class="ip-cell" style="color:#000000;width:200px;padding-left:8px;">207.115.20.133</td>
<td class="country-cell" style="color:#000000;width:200px;padding-left:8px;">United States (Richardson)<a class="note" style="color:blue;text-decoration:none;" href="http://headertool.apelord.com/headers#accuracy">*</a></td>
<td class="whois" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#315ba6;background-position:initial initial;border-color:#8db0f1 #021d4f #021d4f #8db0f1;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://private.dnsstuff.com/tools/whois.ch?ip=207.115.20.133">Whois</a></td>
<td class="google" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#aa3d3d;background-position:initial initial;border-color:#f88f8f #6c0606 #6c0606 #f88f8f;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://groups.google.com/groups?q=207.115.20.133&#38;ie=UTF-8&#38;oe=UTF-8&#38;hl=en&#38;btnG=Google+Search">Google</a></td>
<td class="whois" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#315ba6;background-position:initial initial;border-color:#8db0f1 #021d4f #021d4f #8db0f1;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://private.dnsstuff.com/tools/ipall.ch?domain=207.115.20.133">DNSStuff</a></td>
<td class="google" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#aa3d3d;background-position:initial initial;border-color:#f88f8f #6c0606 #6c0606 #f88f8f;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://www.urgentmessage.org/IPfreely/_i?filter=207.115.20.133">Urgentmessage.org</a></td>
</tr>
<tr>
<td class="ip-cell" style="color:#000000;width:200px;padding-left:8px;">140.117.64.102</td>
<td class="country-cell" style="color:#000000;width:200px;padding-left:8px;">Taiwan (Kaohsiung)<a class="note" style="color:blue;text-decoration:none;" href="http://headertool.apelord.com/headers#accuracy">*</a></td>
<td class="whois" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#315ba6;background-position:initial initial;border-color:#8db0f1 #021d4f #021d4f #8db0f1;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://private.dnsstuff.com/tools/whois.ch?ip=140.117.64.102">Whois</a></td>
<td class="google" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#aa3d3d;background-position:initial initial;border-color:#f88f8f #6c0606 #6c0606 #f88f8f;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://groups.google.com/groups?q=140.117.64.102&#38;ie=UTF-8&#38;oe=UTF-8&#38;hl=en&#38;btnG=Google+Search">Google</a></td>
<td class="whois" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#315ba6;background-position:initial initial;border-color:#8db0f1 #021d4f #021d4f #8db0f1;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://private.dnsstuff.com/tools/ipall.ch?domain=140.117.64.102">DNSStuff</a></td>
<td class="google" style="width:80px;font-size:11px;text-align:center;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#aa3d3d;background-position:initial initial;border-color:#f88f8f #6c0606 #6c0606 #f88f8f;border-style:solid;border-width:2px;"><a style="color:#ffffff;text-decoration:none;" href="http://www.urgentmessage.org/IPfreely/_i?filter=140.117.64.102">Urgentmessage.org</a></td>
</tr>
<tr>
<td class="note-cell" style="color:#000000;font-size:9px;font-weight:bold;" colspan="3">* The last IP listed is <em>usually</em> the originating IP address</td>
</tr>
</tbody>
</table>
<p><span style="font-family:'Trebuchet MS';line-height:normal;">Here is the text you submitted, with the IP addresses highlighted:</span></p>
<p>From Ashley J. Novak Thu Jul 16 02:30:44 2009<br />
Return-Path:<br />
<strong><span style="color:#ff0000;"> Authentication-Results: mta143.sbc.mail.mud.yahoo.com  from=londonthing.co.uk;</span></strong> domainkeys=neutral (no sig); from=londonthing.co.uk; dkim=neutral (no  sig)<br />
Received: from 207.115.20.133  (EHLO flpd123.prodigy.net) <span style="color:#ff0000;">(207.115.20.133</span>)<br />
by mta143.sbc.mail.mud.yahoo.com with SMTP; Thu, 16 Jul 2009 05:32:34 -0700<br />
Received: from yj6l901 <span style="color:#ff0000;"><strong>([140.117.64.102])</strong></span><br />
by flpd123.prodigy.net (8.13.8 inb ipv6 jeff0203/8.13.8) with SMTP id n6GCWUvG019198;<br />
Thu, 16 Jul 2009 05:32:32 -0700<br />
<strong><span style="color:#ff0000;"> Message-ID: &#60;000701ca05f8$181184b0$627e2b9a@londonthing.co.uk&#62;</span></strong><br />
Reply-To: &#8220;Ashley J. Novak&#8221; <span style="font-family:'Lucida Grande';white-space:pre-wrap;"> &#60;ashleyjnovaksv@londonthing.co.uk&#62;</span><br />
From: &#8220;Ashley J. Novak&#8221;<br />
To: ,<br />
<strong> Subject: Make her climax multiple times</strong><br />
Date: Thu, 16 Jul 2009 05:30:44 -0400<br />
MIME-Version: 1.0<br />
Content-Type: text/plain;<br />
format=flowed;<br />
charset=&#8221;windows-1250&#8243;<br />
reply-type=original<br />
Content-Transfer-Encoding: 7bit<br />
Content-Length: 136</p>
<div id="_mcePaste" style="position:absolute;left:-10000px;top:14px;width:1px;height:1px;">Content-Length: 136</div>
<p>An Incredible Canadian_Pharmacy is available at your <span style="border-bottom:1px dashed #0066cc;cursor:pointer;">Fingertips</span>!<br />
No <span style="border-bottom:1px dashed #0066cc;background:transparent none repeat scroll 0 0;cursor:pointer;">Doctor</span> Needed! Browse our Site Today! -&#62; <a href="http://tirethem.com/" target="_blank"><span>http://tirethem.com</span></a></p>
<p><span style="font-family:Verdana;line-height:normal;"></p>
<h3 style="font-family:Arial, Helvetica, Verdana, sans-serif;color:#002b82;font-size:18px;line-height:0;margin-top:40px;">Address lookup</h3>
<p></span></p>
<table border="0" cellspacing="0" cellpadding="5">
<tbody>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" align="right" valign="baseline">canonical name</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="baseline"><span class="ipaddr" style="color:#002b82;font-weight:bold;"><a style="color:#0052f2;text-decoration:none;" href="http://www.tirethem.com/">tirethem.com</a>.</span></td>
</tr>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" align="right" valign="baseline">aliases</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="baseline"></td>
</tr>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" align="right" valign="baseline">addresses</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="baseline"><span class="ipaddr" style="color:#002b82;font-weight:bold;">60.191.239.150<br />
203.93.208.86<br />
218.75.144.6<br />
</span></td>
</tr>
</tbody>
</table>
<p><span style="font-family:Verdana;line-height:normal;"></p>
<h3 style="font-family:Arial, Helvetica, Verdana, sans-serif;color:#002b82;font-size:18px;line-height:0;margin-top:40px;">Domain Whois record</h3>
<p style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;">Queried <span class="ipaddr" style="color:#002b82;font-weight:bold;">whois.internic.net</span> with &#8220;<span class="ipaddr" style="color:#002b82;font-weight:bold;">dom tirethem.com</span>&#8220;&#8230;</p>
<pre style="color:black;font-family:'Courier New', monospace;font-size:13px;">   Domain Name: TIRETHEM.COM
   Registrar: CHINA SPRINGBOARD INC.
   Whois Server: whois.namerich.cn
   Referral URL: http://www.namerich.cn
   Name Server: NS1.GROWFOUR.COM
   Name Server: NS2.GROWFOUR.COM
   Name Server: NS3.COUNTFROM.RU
   Name Server: NS4.COUNTFROM.RU
   Name Server: NS5.SIXTHE.COM
   Name Server: NS6.SIXTHE.COM
   Status: ok
   Updated Date: 14-jul-2009
   Creation Date: 14-jul-2009
   Expiration Date: 14-jul-2010

Last update of whois database: Fri, 17 Jul 2009 04:46:46 UTC &#60;&#60;&#60;</pre>
<p style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;">Queried <span class="ipaddr" style="color:#002b82;font-weight:bold;">whois.namerich.cn</span> with &#8220;<span class="ipaddr" style="color:#002b82;font-weight:bold;">tirethem.com</span>&#8220;&#8230;</p>
<pre style="color:black;font-family:'Courier New', monospace;font-size:13px;">
 DomainName : tirethem.com

RSP: China Springboard Inc.
URL: http://www.namerich.cn      

Name Server......................NS5.SIXTHE.COM
Name Server......................NS1.GROWFOUR.COM
Name Server......................NS6.SIXTHE.COM
Name Server......................NS2.GROWFOUR.COM
Name Server......................NS3.COUNTFROM.RU
Name Server......................NS4.COUNTFROM.RU
Status...........................ok
Creation  Date ..................2009-07-14
Expiration Date .................2010-07-14
Last Update  Date ...............2009-07-14

Registrant ID ...................V-X-59142-15723
Registrant Name .................DING JIANHUA
Registrant Organization .........DING JIANHUA
Registrant Address ..............YUHUIDADAO31
Registrant City..................DL
Registrant Province/State .......LN
Registrant Country Code .........CN
Registrant Postal Code ..........116008
Registrant Phone Number .........+86.041128805269
Registrant Fax ..................+86.041128805269
Registrant Email ................loansfg@163.com

Administrative ID ...............V-X-59142-15723
Administrative Name .............DING JIANHUA
Administrative Organization .....DING JIANHUA
Administrative Address ..........YUHUIDADAO31
Administrative City..............DL
Administrative Province/State ...LN
Administrative Country Code .....CN
Administrative Postal Code ......116008
Administrative Phone Number .....+86.041128805269
Administrative Fax ..............+86.041128805269
Administrative Email ............loansfg@163.com

Billing ID ......................V-X-59142-15723
Billing Name ....................DING JIANHUA
Billing Organization ............DING JIANHUA
Billing Address .................YUHUIDADAO31
Billing City.....................DL
Billing Province/State ..........LN
Billing Country Code ............CN
Billing Postal Code .............116008
Billing Phone Number ............+86.041128805269
Billing Fax .....................+86.041128805269
Billing Email ...................loansfg@163.com

Technical ID ....................V-X-59142-15723
Technical Name ..................DING JIANHUA
Technical Organization...........DING JIANHUA
Technical Address ...............YUHUIDADAO31
Technical City...................DL
Technical Province/State.........LN
Technical Country Code ..........CN
Technical Postal Code ...........116008
Technical Phone Number ..........+86.041128805269
Technical Fax ...................+86.041128805269
Technical Email .................loansfg@163.com

; Please register your domains at
; http://www.namerich.cn</pre>
<h3 style="font-family:Arial, Helvetica, Verdana, sans-serif;color:#002b82;font-size:18px;line-height:0;margin-top:40px;">Network Whois record</h3>
<p style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;">Queried <span class="ipaddr" style="color:#002b82;font-weight:bold;">whois.apnic.net</span> with &#8220;<span class="ipaddr" style="color:#002b82;font-weight:bold;">60.191.239.150</span>&#8220;&#8230;</p>
<pre style="color:black;font-family:'Courier New', monospace;font-size:13px;">inetnum:      60.191.239.0 - 60.191.239.255
netname:      JINHUA-TELECOM-LTD
country:      CN
descr:        Jinhua Telecom Co.,ltd
descr:
admin-c:      LW945-AP
tech-c:       CJ54-AP
status:       ASSIGNED NON-PORTABLE
changed:      auto-dbm@dcb.hz.zj.cn 20060824
mnt-by:       MAINT-CN-CHINANET-ZJ-JH
source:       APNIC

role:         CHINANET-ZJ Jinhua
address:      No.155 Xishi street,Jinhua,Zhejiang.321000
country:      CN
phone:        +86-579-2300779
fax-no:       +86-579-2330035
e-mail:       anti_spam@mail.jhptt.zj.cn
trouble:      send spam reports to anti_spam@mail.jhptt.zj.cn
trouble:      and abuse reports to anti_spam@mail.jhptt.zj.cn
trouble:      Please include detailed information and times in UTC
admin-c:      CH55-AP
tech-c:       CH55-AP
nic-hdl:      CJ54-AP
mnt-by:       MAINT-CHINANET-ZJ
changed:      master@dcb.hz.zj.cn 20031204
source:       APNIC

person:       Lujiang Wang
nic-hdl:      LW945-AP
e-mail:       anti_spam@mail.jhptt.zj.cn
address:      NO.155 Xishi Street,Jinhua,Zhejiang.Postcode:321000
phone:        +86-579-3285460
country:      CN
changed:      auto-dbm@dcb.hz.zj.cn 20060824
mnt-by:       MAINT-CN-CHINANET-ZJ-JH
source:       APNIC</pre>
<h3 style="font-family:Arial, Helvetica, Verdana, sans-serif;color:#002b82;font-size:18px;line-height:0;margin-top:40px;">DNS records</h3>
<p style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;">DNS query for <span class="ipaddr" style="color:#002b82;font-weight:bold;">150.239.191.60.in-addr.arpa</span> returned an error from the server: <strong>NameError</strong></p>
<p></span></p>
<table border="0" cellspacing="1" cellpadding="5">
<tbody>
<tr>
<td class="hdr" style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;background-color:#f0f0f0;">name</td>
<td class="hdr" style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;background-color:#f0f0f0;">class</td>
<td class="hdr" style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;background-color:#f0f0f0;">type</td>
<td class="hdr" style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;background-color:#f0f0f0;">data</td>
<td class="hdr" style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;background-color:#f0f0f0;" colspan="2">time to live</td>
</tr>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">tirethem.com</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">IN</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">A</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">203.93.208.86</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" align="right" valign="top">10800s</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">(03:00:00)</td>
</tr>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">tirethem.com</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">IN</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">A</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">218.75.144.6</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" align="right" valign="top">10800s</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">(03:00:00)</td>
</tr>
<tr>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">tirethem.com</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">IN</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">A</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">60.191.239.150</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" align="right" valign="top">10800s</td>
<td style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;" valign="top">(03:00:00)</td>
</tr>
</tbody>
</table>
<p><span style="font-family:Verdana;line-height:normal;"></p>
<p style="color:black;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:13px;">&#8211; end &#8211;</p>
<p></span></p>
<p><span><br />
</span></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Guide for Newbies:  How to Remove a Virus on Windows]]></title>
<link>http://schweickism.wordpress.com/2009/07/16/how-to-remove-a-virus-on-windows/</link>
<pubDate>Fri, 17 Jul 2009 04:42:28 +0000</pubDate>
<dc:creator>schweickism</dc:creator>
<guid>http://schweickism.wordpress.com/2009/07/16/how-to-remove-a-virus-on-windows/</guid>
<description><![CDATA[A few nights ago my brother woke me up sometime around 3:00 in the morning to come look at his compu]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>A few nights ago my brother woke me up sometime around 3:00 in the morning to come look at his computer because it was asking him questions that he didn&#8217;t want to answer.  Predictably, he had just fallen victim to a virus.</p>
<p>One common misconception about viruses is that you can&#8217;t get them if you don&#8217;t go to any shady websites.  This is absolutely wrong.  If your computer is connected to the Internet, then it is at risk even if the web browser isn&#8217;t open&#8230; which leads me to another misconception:  Contrary to common belief, not all viruses even come through a browser.  Here&#8217;s a fun fact for you:  If you buy a new computer without anti-virus software installed, just in the time it takes to download all the Windows updates your entire computer could be taken over so badly that you would have to wipe your hard drive and start over.</p>
<p>I am making this post as a sign of my sympathy to other programmers who find themselves awakened early in the morning by people working late&#8230; but I also am sympathetic to those who would otherwise be paying the Geek Squad some enormous fee for something they could have just done on their own.</p>
<p>If you think you just got a virus, there are a few steps you can try for yourself before paying somebody else an overly-large wad of cash to fix it for you.</p>
<p>Begin by restarting your computer.  You may have to physically hold down the power button to force it to shutdown (in which case you will then have to press it again to start it up).</p>
<p>The first boot screen probably shows you the logo of the company that manufactured your computer (no, NOT the Windows logo; I assure you Windows did not make your computer, it will probably say Dell or HP).  On that first boot screen you should press the <strong>F8</strong> key—NOT the letter F and the number 8, I mean the button at the top of the keyboard labeled F8 (you can probably tell that I&#8217;ve had a lot of experience with clients from these notes).</p>
<p>Pressing the F8 key should bring up a menu (not necessarily immediately, but soon thereafter) asking you how you want to boot into Windows.  Select the option that says &#8220;Start Windows in Safe Mode with Networking&#8221; or the closest to it.  (You can use the up/down arrow keys to make your selection and then press Enter to continue.)</p>
<p>You can think of Safe Mode as a way of starting Windows in a minimal state.  Fewer programs will be running without your knowledge of them.</p>
<p>Now it&#8217;s time to go hunting for your virus.  Open up the file browser by clicking on My Computer (or just plain &#8220;Computer&#8221; if you&#8217;re using Vista or 7).  Open the <strong>C</strong> drive and then open the folder called &#8220;Windows.&#8221;  Click the &#8220;Date Modified&#8221; heading to sort the contents.  Look at the most recent files to see if anything looks suspicious.  If you find anything, Google the name of that file.  You can find something on just about any file you see in that folder.  If it&#8217;s a virus, then you most likely are not the only one who&#8217;s ever been infected with it.</p>
<p>If you find anything from your Googling that suggests the file is malware, then check if there is any specific advice on how to remove it.  If not, simply delete it as you would any other file.</p>
<p>If you don&#8217;t find anything in the Windows folder, then go through the same procedure for the <strong>system</strong> and <strong>System32</strong> folders (and the <strong>SysWOW64</strong> folder if you have 64-bit Windows) which should be sub-folders in the Windows folder.  Those are some of the most commonly infected areas—not to say that a virus wouldn&#8217;t hide elsewhere though.</p>
<p>When in doubt about a file, if you have the installation CD for the version of Windows on your machine, then it is sometimes safer just to try deleting it.  If you delete a Windows file that you shouldn&#8217;t have, you can restore it by inserting the Windows installation CD and selecting &#8220;Repair Windows&#8221; which will automatically replace any missing or corrupt system files.  It takes quite a while for this process to complete, but you get a working computer out of it in the end, so it&#8217;s usually worth while.  You can often use the installation CD even if your computer won&#8217;t boot into Windows because you can make it boot from the disk.</p>
<p>An alternative to using the restore feature found on the installation disk is using the Scannow program that is built-in to Windows.  Simply go to <strong>Start</strong> &#62; <strong>Run</strong> and type &#8220;sfc&#8221; into the dialog box and press enter.  This command is probably just going to end up asking you for the installation disk anyway, but it might save you at least a little bit of time.</p>
<p>If you checked everything that I just told you to, and you still didn&#8217;t find a file that looked like it could be your virus, then the next step is to try running a system restore.</p>
<p>To use the Windows system restore feature, go to <strong>Start</strong> &#62; <strong>All Programs</strong> &#62; <strong>Accessories</strong> &#62; <strong>System Tools</strong> &#62; <strong>System Restore</strong>.  This will provide you with an easy-to-follow wizard that guides you through step-by-step.  It tends to have fairly helpful and in-depth explanations (after all, it does get a lot of use), so I won&#8217;t go into further details on how to use it.</p>
<p>If you tried everything else and doing a system restore does not solve your problem either, then you might actually have to succumb to having somebody else take care of it.  But if this blog post saves even one person a trip to the Geek Squad (or prevents even one person from waking up their tech savvy little brother at 3:00 am) then it will have been well worth my time to write it.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Download Microsoft Security Essentials]]></title>
<link>http://ttcshelbyville.wordpress.com/2009/07/16/download-microsoft-security-essentials/</link>
<pubDate>Fri, 17 Jul 2009 00:18:59 +0000</pubDate>
<dc:creator>SMallard</dc:creator>
<guid>http://ttcshelbyville.wordpress.com/2009/07/16/download-microsoft-security-essentials/</guid>
<description><![CDATA[Recently I gave a link to Microsoft&#8217;s Security Essentials.  The link had been closed and the B]]></description>
<content:encoded><![CDATA[Recently I gave a link to Microsoft&#8217;s Security Essentials.  The link had been closed and the B]]></content:encoded>
</item>
<item>
<title><![CDATA[Utenti standard più liberi con Privilege Manager]]></title>
<link>http://skizzidivita.wordpress.com/2009/07/16/utenti-standard-piu-liberi-con-privilege-manager/</link>
<pubDate>Thu, 16 Jul 2009 21:26:04 +0000</pubDate>
<dc:creator>Dani</dc:creator>
<guid>http://skizzidivita.wordpress.com/2009/07/16/utenti-standard-piu-liberi-con-privilege-manager/</guid>
<description><![CDATA[Immagine di DaisyBurrows
L&#8217;uso degli account limitati (sarebbe meglio chiamarli account standa]]></description>
<content:encoded><![CDATA[Immagine di DaisyBurrows
L&#8217;uso degli account limitati (sarebbe meglio chiamarli account standa]]></content:encoded>
</item>
<item>
<title><![CDATA[The First Virus to Spread via SMS]]></title>
<link>http://iprotectyourdata.wordpress.com/2009/07/16/the-first-virus-to-spread-via-sms/</link>
<pubDate>Thu, 16 Jul 2009 19:35:58 +0000</pubDate>
<dc:creator>travissholt</dc:creator>
<guid>http://iprotectyourdata.wordpress.com/2009/07/16/the-first-virus-to-spread-via-sms/</guid>
<description><![CDATA[A new piece of moblie malware called the &#8220;Sexy Space&#8221; is the first known virus that spre]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>A new piece of moblie malware called the &#8220;Sexy Space&#8221; is the first known virus that spreads via SMS or text message.  The use of mobile bots could allow networks of hackers the ability to steal data or shut down your cell phone remotely.  It is important for users to verify any link that is sent to them via SMS before clicking on any link that sends them to another location.  </p>
<p>For more information, read this article <a href="http://bx.businessweek.com/cyber-security/view?url=http://www.computerworld.com/s/article/9135577/Analysts_see_alarming_development_in_mobile_malware">from Computerworld</a>.  </p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Geeks On Call Weekly Update July 17th]]></title>
<link>http://geeksoncall.wordpress.com/2009/07/16/geeks-on-call-weekly-update-july-17th/</link>
<pubDate>Thu, 16 Jul 2009 17:29:11 +0000</pubDate>
<dc:creator>geeksoncall</dc:creator>
<guid>http://geeksoncall.wordpress.com/2009/07/16/geeks-on-call-weekly-update-july-17th/</guid>
<description><![CDATA[
]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><a class="aligncenter" title="Geeks On Call Newsletter" href="www.geeksoncall.com/weeklyemail/week-8.html" target="_blank"><img class="aligncenter size-full wp-image-263" title="Geeks On Call Weekly Update July 17th" src="http://geeksoncall.wordpress.com/files/2009/07/datalossemail.jpg" alt="Geeks On Call Weekly Update July 17th" width="468" height="672" /></a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ThreatFire AntiVirus is free]]></title>
<link>http://computerhelpers.wordpress.com/2009/07/16/threatfire-antivirus-is-free/</link>
<pubDate>Thu, 16 Jul 2009 16:59:54 +0000</pubDate>
<dc:creator>dvanarsd</dc:creator>
<guid>http://computerhelpers.wordpress.com/2009/07/16/threatfire-antivirus-is-free/</guid>
<description><![CDATA[ThreatFire AntiVirus &#8211; Behavioral Virus and Spyware Protection is freeware (with a fancier pay]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><a href="http://www.threatfire.com/">ThreatFire AntiVirus &#8211; Behavioral Virus and Spyware Protection</a> is freeware (with a fancier pay version also available) with a high rating for protecting your system.  There&#8217;s also a free anti-virus for Macs!</p>
<p>This site also offers Spyware Doctor and Firewall Plus.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Twitter Security Breach...A Reminder About Keeping Passwords Secure]]></title>
<link>http://technicallyageek.wordpress.com/2009/07/16/twitter-security-breach-keep-your-passwords-secur/</link>
<pubDate>Thu, 16 Jul 2009 15:52:00 +0000</pubDate>
<dc:creator>jeditellez</dc:creator>
<guid>http://technicallyageek.wordpress.com/2009/07/16/twitter-security-breach-keep-your-passwords-secur/</guid>
<description><![CDATA[Yesterday it was announced that a Twitter employees e-mail account was hacked into.
The person who h]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Yesterday it was announced that a Twitter employees e-mail account was hacked into.</p>
<p>The person who hacked into it was able to get a lot of information about the company, including its long range plans and estimated revenue growth.</p>
<p>This brings up a few things that I always like to remind those I teach&#8230;</p>
<p>1. Install  anti-virus and anti-spyware software on your computer. Make sure that it&#8217;s being updated on a daily basis and is running a full system scan at least once a week. Yes, even if you have a MAC&#8230;they&#8217;re not 100% secure. Spend that $19-$30 a year for the update subscriptions, it&#8217;s chump change compared to the time and money you&#8217;ll spend getting your  computer made virus free.</p>
<p>2. Your data is not 100% secure on the internet, or even on your computer. If there&#8217;s something you would never want the whole world to see, then don&#8217;t keep it on your computer.</p>
<p>3. Use unique passwords that include numbers and varying characters.</p>
<p>4. Don&#8217;t use the same password for online shopping, as you would for financial accounts such as e-trade, online banking, online credit card account. While I know that the online merchants have a good deal of security they&#8217;re not required to be as secure as the online sites for financial institutions. The financial institutions have to implement more security thanks to the many regulations imposed by the federal government. Although that hasn&#8217;t kept them from being hit either.</p>
<p>5. If you&#8217;re not sure about something that was sent to you, don&#8217;t click or open it. Check with the person its supposed to be from to make sure they sent it. Most of the viruses and re-directs to websites that will infect your computer with a virus have language that is often misspelled or just sounds odd. This goes for text messages you get on your phone as well. Remember&#8230;your phone is a mini-computer.</p>
<p>You can read articles on the incident:</p>
<p>Here &#8211; <a href="http://technologizer.com/2009/07/15/with-online-passwords-dishonesty-can-be-the-best-policy/">http://technologizer.com/2009/07/15/with-online-passwords-dishonesty-can-be-the-best-policy/</a></p>
<p>and here &#8211; <a href="http://www.nytimes.com/2009/07/16/technology/internet/16twitter.html">http://www.nytimes.com/2009/07/16/technology/internet/16twitter.html</a></p>
<p>Let&#8217;s be safe out there folks!</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Safe browsing site check]]></title>
<link>http://googleserppagerankchecker.wordpress.com/2009/07/16/safe-browsing-site-check/</link>
<pubDate>Thu, 16 Jul 2009 15:50:47 +0000</pubDate>
<dc:creator>googleserppagerankchecker</dc:creator>
<guid>http://googleserppagerankchecker.wordpress.com/2009/07/16/safe-browsing-site-check/</guid>
<description><![CDATA[It not your web hosting problem.
It is because:
Most of time web masters download scripts or your si]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><strong>It not your web hosting problem.<br />
It is because:<br />
Most of time web masters download scripts or your site provided  guest  members to  post href codes. The malware may be caused by a java, iframe or other forms of href link.</strong></p>
<p><strong>Here is another good way to check safe browsing site</strong></p>
<p><span style="color:#ff6600;"><strong>http://www.google.com/interstitial?url= other URLs</strong></span></p>
<p><strong>why it is not working ? </strong></p>
<p><strong>I got the message </strong></p>
<p><strong>Forbidden Your client does not have permission to get URL</strong></p>
<p><strong>Actually the result is telling us the site is no malware records recently.</strong></p>
<p><strong>Here is a tool to check safe site:<br />
</strong><span style="text-decoration:underline;"><span style="color:#000000;"><strong><a class="aligncenter" href="http://www.seoserp.com/safe.site.checker/" target="_blank">http://www.seoserp.com/safe.site.checker/</a></strong></span></span></p>
<p><span style="color:#c0c0c0;">other tool to check Search engine position page rank<br />
<a href="http://www.seoserp.com/google.page.rank.checker/" target="_blank">http://www.seoserp.com/google.page.rank.checker/</a></span></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Global Cyber News Bits, July 16, 2009 from CommunityDNS.]]></title>
<link>http://blog.communitydns.net/2009/07/16/global-cyber-news-bits-july-16-2009-from-communitydns/</link>
<pubDate>Thu, 16 Jul 2009 15:42:01 +0000</pubDate>
<dc:creator>CommunityDNS</dc:creator>
<guid>http://blog.communitydns.net/2009/07/16/global-cyber-news-bits-july-16-2009-from-communitydns/</guid>
<description><![CDATA[ Provided by CommunityDNS, the information in this post consists of news items in the security-based]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><em> Provided by <a href="http://www.communitydns.eu/facts.html"><span style="text-decoration:underline;">CommunityDNS</span></a>, the information in this post consists of news items in the security-based Internet community.</em></p>
<p><strong>Zombies bite into Symbian smartphones</strong></p>
<p>YXES-B is the first known spam bot client for 3G phones.  Posing as a legitimate application, the malware will steal the subscriber, phone and network information from its victims.  Spam SMS messages can then be sent to the user’s contacts.  Symbian uses a code-signing process to ensure such threats never happen.</p>
<p>Click <a href="http://www.theregister.co.uk/2009/07/16/mobile_trojan/"><span style="text-decoration:underline;">here</span></a> for more information.</p>
<p><strong>Scam detectives handcuffed</strong></p>
<p>Costing the Australian economy close to $980 million in 2007 alone, cyber scams are having an impact on everyone.  Detectives find chasing the criminals, when the jurisdiction becomes multinational, difficult because scam classification systems are largely incompatible between nations.  While multiple classification schemes exist, a consistent classification scheme does not exist.</p>
<p>The following link provides a way to guard against this vulnerability until Microsoft releases a patch.</p>
<p>Click <a href="http://www.australianit.news.com.au/story/0,24897,25776701-5013044,00.html"><span style="text-decoration:underline;">here</span></a> for more information.</p>
<p><strong>Child protection groups undermine Aussie Firewall</strong></p>
<p>Censordyne, The Australian cyber filter program designed to protect the public from inappropriate and harmful content came under fire from mainstream children’s charities. The charities feel the tens of millions of dollars the program will cost can be diverted to appropriate child protection authorities for the prevention of child abuse.  Also, for parents who wish to protect their children from inappropriate contact should have PC-level filtering software provided.</p>
<p>Click <a href="http://www.theregister.co.uk/2009/07/16/aussie_firewall_childrens_charities/"><span style="text-decoration:underline;">here</span></a> for more information.</p>
<p><strong>New Zealand proposes new “3 strikes” process for P2P users</strong></p>
<p>Having scrapped the law earlier this year, New Zealand has gone back to the drawing board to craft a new 3-strikes law that provides for due process.  If one is disconnected from the Internet for alleged copyright infringements, users should be able to contest the claims, have access to mediation and to possibly appeal penalties to the normal legal system.</p>
<p>Click <a href="http://arstechnica.com/tech-policy/news/2009/07/new-zealand-proposes-new-3-strikes-process-for-p2p-users.ars"><span style="text-decoration:underline;">here</span></a> for more information.</p>
<p><strong>CRTC to decide on new rules for internet service providers</strong></p>
<p>Canada’s Internet regulator is conducting hearings on whether ISPs should be allowed to selectively slow down applications when the Internet is congested.  Citing the popularity of bandwidth hungry applications such as gaming and video should they have the same priority as time sensitive applications such as VOIP or online gaming where delays make playing with other Internet users difficult?</p>
<p>The consensus from consumer and public interest groups, along with businesses and artists believe that practices used by ISPs to deal with congestion were acceptable as long as there was no favoring certain protocols or applications over others.</p>
<p>Click <a href="http://www.cbc.ca/technology/story/2009/07/15/f-internet-traffic-management-crtc-hearings.html"><span style="text-decoration:underline;">here</span></a> for more information.</p>
<p><strong>Internet Regulator Mulls Cybersquatter Block</strong></p>
<p>Already having an advantage of securing domain names based by trademark holders, people are concerned that if 500 additional TLDs arrive on the market costs would mushroom in having to purchase names on all new TLDs just to protect trademarks.  ICANN is considering a centralized website of trademark holders that would create hurdles for non-trademark holders who try to purchase a name that would infringe on an organization’s trademark.  Called the “IP Clearinghouse”, supporters feel such a system would protect them and their budgets from having to defensively register domains.</p>
<p>Click <a href="http://www.newsfactor.com/story.xhtml?story_id=1000096VINBC"><span style="text-decoration:underline;">here</span></a> for more information.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Signed Malware, Revoked]]></title>
<link>http://secblog.symbian.org/2009/07/16/signed-malware-revoked/</link>
<pubDate>Thu, 16 Jul 2009 15:10:50 +0000</pubDate>
<dc:creator>Craig H</dc:creator>
<guid>http://secblog.symbian.org/2009/07/16/signed-malware-revoked/</guid>
<description><![CDATA[A number of blogs and news sites have picked up on a report from Dancho Danchev last week, identifyi]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>A number of blogs and news sites have picked up on a <a href="http://ddanchev.blogspot.com/2009/07/transmitterc-mobile-malware-in-wild.html">report from Dancho Danchev</a> last week, identifying some malware that was submitted to, and signed by, the Symbian Signed portal.</p>
<p>As soon as we were notified of that (the following day) we revoked both the content certificate and the publisher certificate used to sign the malware.  That means that the Symbian software installer will not now install the malware, providing that revocation checking is turned on.  Unfortunately, revocation checking is often turned off by phone manufacturers, because the data traffic could cause problems for people who do not have a data plan as part of their service or who pay for data by volume.</p>
<p>Here&#8217;s how to turn on revocation checking, which we strongly recommend if you have a flat-rate data plan:</p>
<p><!--more-->On S60 3rd and 5th edition, the setting to turn on revocation checks can be found in the application manager, for example:</p>
<p style="padding-left:30px;">Tools &#8594;<br />&#160; &#160; Settings &#8594;<br />&#160; &#160; &#160; &#160;Applications &#8594;<br />&#160; &#160; &#160; &#160; &#160; &#160; App. manager &#8594;<br />&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; Online Certificate Check</p>
<p>On UIQ 3, the setting to turn on revocation checks can be found here:</p>
<p style="padding-left:30px;">Control Panel  &#8594;<br />&#160; &#160; Other  &#8594;<br />&#160; &#160; &#160; &#160; Install  &#8594;<br />&#160; &#160; &#160; &#160; &#160; &#160; Security  &#8594;<br />&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; Enable Revocation Check</p>
<p>Please note that applications not signed by Symbian Signed may not include the URL for the revocation check in the signing certificate.  In these cases, the software installer can direct the revocation check request to a default URL, however at present there is no server in place able to respond to such default requests, so the default URL should be left unset.</p>
<p>So that applications not signed by Symbian Signed (for example, those signed by the phone manufacturer, or self-signed by third parties) can still be installed, the revocation check should not be set to mandatory (for example, &#8220;Must Be Passed&#8221; for S60), it should be left as advisory (for example, &#8220;On&#8221; for S60).</p>
<p>We do have security measures which try to catch submitted malware before it gets signed, and we are currently investigating how those can be improved in the light of this latest incident.</p>
<p><em>Footnote: Earlier today we found that, due to human error in processing the revocation, it wasn&#8217;t being properly reported by the server.  This has now been corrected.</em></p>
</div>]]></content:encoded>
</item>

</channel>
</rss>
