<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>My DigitalZone &#187; Computer Security</title>
	<atom:link href="http://mydigitalzone.net/category/computer-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://mydigitalzone.net</link>
	<description></description>
	<lastBuildDate>Fri, 15 Jan 2010 04:34:05 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Phishing</title>
		<link>http://mydigitalzone.net/2009/12/18/phshing/</link>
		<comments>http://mydigitalzone.net/2009/12/18/phshing/#comments</comments>
		<pubDate>Fri, 18 Dec 2009 23:45:21 +0000</pubDate>
		<dc:creator>Jenny</dc:creator>
				<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Trojan Horse]]></category>

		<guid isPermaLink="false">http://mydigitalzone.net/?p=437</guid>
		<description><![CDATA[<style type="text/css">
<!--
.nmstitle {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 13px;
	text-transform: capitalize;
	color: #003333;
}

.nmsdesc {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 12px;

	color: #003333;
}
-->
</style>




Photo by Don Hankins
Phishing is a general term associated with a fraudulent attempt to gain access to a person&#8217;s important personal information, such as credit card account numbers, user names, and password, and in some cases, the social security number.  The number and variety of phishing attempt are increasing rapidly.  Bad guys use [...]]]></description>
			<content:encoded><![CDATA[<style type="text/css">
<!--
.nmstitle {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 13px;
	text-transform: capitalize;
	color: #003333;
}

.nmsdesc {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 12px;

	color: #003333;
}
-->
</style><p id="top" /><script type="text/javascript"><!--
google_ad_client = "pub-2241621611203959";
/* DZone_posts336x280, created 1/2/09 */
google_ad_slot = "2956728885";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script><br />
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><img src="http://www.mydigitalzone.net/images/phishing.jpg" alt="Phishing" width = 400 height = 320 /></p>
<div xmlns:cc="http://creativecommons.org/ns#" about="http://www.flickr.com/photos/23905174@N00/1594411528/" align = right><a rel="cc:attributionURL" href="http://www.flickr.com/photos/23905174@N00/">Photo by Don Hankins</a></div>
<p><strong>Phishing</strong> is a general term associated with a fraudulent attempt to gain access to a person&#8217;s important personal information, such as credit card account numbers, user names, and password, and in some cases, the social security number.  The number and variety of phishing attempt are increasing rapidly.  Bad guys use emails to deliver an innocent-looking email with malicious contents.  Sometimes, they use text messages asking for a person to call a certain phone number to obtain personal information.  </p>
<p>The email/text message pretend to be from financial institutions (<strong>banks, credit unions, or credit card companies</strong>), <strong>PayPal</strong></p>
<p>Obviously, emails and text messages appear to be from legitimate sources so the recipient think that they need to take some actions (click on a link in an email or call a certain phone number) to remedy the situation described in the email.  Those situations include that:</p>
<ul>
<li><strong>your account is being suspended;</strong></li>
<li><strong>your account is being deactivated</strong>;</li>
<li><strong>unusual transaction on your account</strong>; or</li>
<li><strong>missing information on your account</strong>.</li>
</ul>
<p>The above are examples of phishing attempts pretending to be a financial institution.  There are some new varieties that pretend to be a package delivery companies, such as UPS, FedEx, or USPS.</p>
<p>Here&#8217;s an example email for the UPS case.</p>
<blockquote><p>Sorry, we were not able to deliver postal package you sent on October the 19th in time because the recipient address is not correct.<br />
Please print out the invoice copy attached and collect the package at our office.<br />
If you do not receive package in ten days you will have to pay 6$ per day.</p>
<p>Your UPS</p></blockquote>
<p>Apparently, we need to be able to distinguish the legitimate email from the bogus ones.  Here are some basic rules to spot the bad ones.</p>
<ul>
<li><strong>generic greetings</strong><br />
Example: Dear XXXX Bank customer: (instead of Dear <i>your_real_name</i></li>
<li><strong>legitimate-looking link in the body of the email</strong><br />
The link may look legitimate but if you hover the mouse over it, the real link address is pointing to a different address.</li>
<li><strong>legitimate-looking attachment with &#8220;.zip&#8221; or &#8220;.doc&#8221; extension.</strong><br />
Don&#8217;t be fooled.  <strong>The only thing that the bad guys want is for you to click the link.</strong>Just one click on the fraudulent email will install and deploy some executable file that contain a trojan horse (a malicious program that opens a back door to your PC and steal your personal information by sending your keystrokes of your important user name and password.</li>
</ul>
<p>So, the key is <strong>not to click a link in an email and do not click the attachment unless you are sure it is from a legitimate source.</strong>  The Chase (credit card) site has an extensive example of fraudulent email <a href="https://www.chase.com/index.jsp?pg_name=ccpmapp/privacy_security/fraud/page/fraud_examples">here</a>.  </p>
<p>Like most of you, I use the internet online access to manage a lot of things, so I do receive many legitimate emails from them.  I&#8217;ve make it a rule not to click any links in an email.  When I receive an email about one of my account, I open up a new internet session and access it separately, not from the email.</p>
<p>Hope this helps you a bit.</p>
]]></content:encoded>
			<wfw:commentRss>http://mydigitalzone.net/2009/12/18/phshing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AVAST Detecting Win32:Delf-MZG</title>
		<link>http://mydigitalzone.net/2009/12/02/avast-detecting-win32delf-mzg/</link>
		<comments>http://mydigitalzone.net/2009/12/02/avast-detecting-win32delf-mzg/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 04:29:51 +0000</pubDate>
		<dc:creator>Jenny</dc:creator>
				<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[Avast!]]></category>
		<category><![CDATA[False positive]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://mydigitalzone.net/?p=470</guid>
		<description><![CDATA[<style type="text/css">
<!--
.nmstitle {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 13px;
	text-transform: capitalize;
	color: #003333;
}

.nmsdesc {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 12px;

	color: #003333;
}
-->
</style>



Ah.  The annoyance started about 30 min. ago.  AVAST!, Malwarebyte&#8217;s excellent software for detecting/removing malware, started to detect tons of tons of trojans, especially Win32:Delf-MZG, like crazy.  I took it seriously and started a full scan.  Then, it recommended to do a memory scan after a reboot.  I did it. [...]]]></description>
			<content:encoded><![CDATA[<style type="text/css">
<!--
.nmstitle {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 13px;
	text-transform: capitalize;
	color: #003333;
}

.nmsdesc {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 12px;

	color: #003333;
}
-->
</style><p id="top" /><script type="text/javascript"><!--
google_ad_client = "pub-2241621611203959";
/* DZone_posts336x280, created 1/2/09 */
google_ad_slot = "2956728885";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script><br />
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Ah.  The annoyance started about 30 min. ago.  AVAST!, Malwarebyte&#8217;s excellent software for detecting/removing malware, started to detect tons of tons of trojans, especially Win32:Delf-MZG, like crazy.  I took it seriously and started a full scan.  Then, it recommended to do a memory scan after a reboot.  I did it.  I chose to remove all the suspicious ones.  I think it detected over 30.  Most of the files were audio/video-related.  Some dlls for SUPER (video conversion software) and GoldWave (audio editor).  </p>
<p>I took a note &#8230;. Win30: Delf-MZG&#8230;. did a google search after the reboot.  It sounds like it&#8217;s the update from AVAST! has some problem.  Some people started to discussed it about an hour ago over at <a href="http://answers.yahoo.com/question/index?qid=20091202191236AA96njt">Yahoo Answers</a>, and one poster suggested to go to the AVAST user forum.  Overall, it sounds like a lot of them are just false positives but I&#8217;ll keep an eye on it.  I&#8217;m heading to the AVAST/Malware bytes&#8217; site right now.</p>
<p>It&#8217;s really annoying.  It&#8217;s happening for many people today, Dec. 2nd, 2009 at around 10 p.m., U.S. Central time.</p>
<p><strong>Update</strong><br />
Guess it was too late.  It looks like all of the alerts were false positive.  See <a href="http://win32delf-mzg.blogspot.com/2009/12/win32delf-mzg.html">this</a>.  I tried to use GoldWave and Super but they didn&#8217;t work because I chose to delete suspicious files.  The deleted files are not in the recycle bin, so I need to reinstall those programs.  So far, my laptop itself is working fine.</p>
<p><strong>So, ignore the AVAST warnings and take NO action.  Do not choose to delete files!</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://mydigitalzone.net/2009/12/02/avast-detecting-win32delf-mzg/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Secure USB Flash Drive</title>
		<link>http://mydigitalzone.net/2009/05/03/secure-usb-flash-drive/</link>
		<comments>http://mydigitalzone.net/2009/05/03/secure-usb-flash-drive/#comments</comments>
		<pubDate>Sun, 03 May 2009 21:02:12 +0000</pubDate>
		<dc:creator>Jenny</dc:creator>
				<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Sandisk U3]]></category>
		<category><![CDATA[USB flash drive]]></category>

		<guid isPermaLink="false">http://mydigitalzone.net/?p=188</guid>
		<description><![CDATA[<style type="text/css">
<!--
.nmstitle {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 13px;
	text-transform: capitalize;
	color: #003333;
}

.nmsdesc {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 12px;

	color: #003333;
}
-->
</style>
  When you lose an USB flash drive, what makes you worry is probably the data stored on the drive.  The contents of the drive are priceless for some, depending on how they use the flash drive.  There are two ways to secure the drive.  One is to buy a flash [...]]]></description>
			<content:encoded><![CDATA[<style type="text/css">
<!--
.nmstitle {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 13px;
	text-transform: capitalize;
	color: #003333;
}

.nmsdesc {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 12px;

	color: #003333;
}
-->
</style><p id="top" /><script type="text/javascript"><!--
google_ad_client = "pub-2241621611203959";
/* DZone_posts336x280, created 1/2/09 */
google_ad_slot = "2956728885";
google_ad_width = 336;
google_ad_height = 280;
// --></script><br />
<script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"></script> <img src="http://www.mydigitalzone.net/images/flash_drive.jpg" alt="USB Flash Drive" width="250" height="250" /> When you lose an USB flash drive, what makes you worry is probably the data stored on the drive.  The contents of the drive are priceless for some, depending on how they use the flash drive.  There are two ways to secure the drive.  One is to buy a flash drive with built-in security mechanism and the other is to use software to encrypt the content of the drive.<br />
<br />
<strong>USB Flash Drives with Security Mechanism</strong></p>
<ul>
<li><a href="http://www.amazon.com/gp/product/B000NWVAFO?ie=UTF8&amp;tag=dizitalzone-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=B000NWVAFO">SanDisk 4GB Cruzer Micro USB Flash Drive with U3</a><img style="border:none !important; margin:0px !important;" src="http://www.assoc-amazon.com/e/ir?t=dizitalzone-20&amp;l=as2&amp;o=1&amp;a=B000NWVAFO" border="0" alt="" width="1" height="1" /> <a href="http://www.amazon.com/gp/product/B000NWVAFO?ie=UTF8&amp;tag=dizitalzone-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=B000NWVAFO"><img src="http://www.mydigitalzone.net/images/318K2lethlL._SL160_.jpg" border="0" alt="" /></a><img style="border:none !important; margin:0px !important;" src="http://www.assoc-amazon.com/e/ir?t=dizitalzone-20&amp;l=as2&amp;o=1&amp;a=B000NWVAFO" border="0" alt="" width="1" height="1" /> This drive is getting excellent reviews.  It features include:
<ol>
<li>4 GB capacity</li>
<li>Retractable USB connector</li>
<li>Brilliant amber LED</li>
<li>U3 smart enabled</li>
<li>Loaded with the following U3 programs: CruzerSync synchronization software, SignupShield password manager, SKYPE, and AVAST antivirus software</li>
<li>Dimensions: 7.94mm x 20.6mm x 57.15mm (D x W x L)</li>
<li>Hi-Speed USB 2.0 certified (backwards compatible with all USB 1.1 ports)</li>
<li>Compatible with Windows 2000, SP4 and XP</li>
</ol>
<p>Even though the amazon site says &#8220;U3 functionality only supported on Windows 2000 (SP4 and later) &amp; XP,&#8221; one reviewer says it works with Vista.  It is very affordable as <a href="http://www.amazon.com/gp/product/B000NWVAFO?ie=UTF8&amp;tag=dizitalzone-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=B000NWVAFO">amazon.com sells it for $12.49</a><img style="border:none !important; margin:0px !important;" src="http://www.assoc-amazon.com/e/ir?t=dizitalzone-20&amp;l=as2&amp;o=1&amp;a=B000NWVAFO" border="0" alt="" width="1" height="1" />.</li>
<li><a href="http://www.amazon.com/gp/product/B000RXYV5U?ie=UTF8&amp;tag=dizitalzone-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=B000RXYV5U">IronKey 4 GB Secure Hardware-Encrypted USB 2.0 Flash Drive</a><img style="border:none !important; margin:0px !important;" src="http://www.assoc-amazon.com/e/ir?t=dizitalzone-20&amp;l=as2&amp;o=1&amp;a=B000RXYV5U" border="0" alt="" width="1" height="1" /> <a href="http://www.amazon.com/gp/product/B000RXYV5U?ie=UTF8&amp;tag=dizitalzone-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=B000RXYV5U"><img src="http://www.mydigitalzone.net/images/31C6Jw%2BEA1L._SL160_.jpg" border="0" alt="" /></a><img style="border:none !important; margin:0px !important;" src="http://www.assoc-amazon.com/e/ir?t=dizitalzone-20&amp;l=as2&amp;o=1&amp;a=B000RXYV5U" border="0" alt="" width="1" height="1" /> This drive seems to be the one that&#8217;s built for security.  It uses a hardware encrypted, military grade encryption to protect the data.  The reviews are pretty good and the only drawback I see is it price, $127.47.</li>
<li><a href="http://www.fujitsu.com/global/news/pr/archives/month/2009/20090417-02.html">Secure USB Memory Device by Fujitsu</a><br />
<img src="http://www.fujitsu.com/img/PR/2009/20090417-02a.jpg" alt="Fujitsu USB drive" width="170" /> This is a new product developed by Fujitsu and I&#8217;m not sure if it&#8217;s in the market yet.  According to the press release by Fujitsu on April 17, 2009,</p>
<blockquote><p>
	Fujitsu Laboratories Limited and Fujitsu Laboratories of America, Inc. today announced the development of two new technologies designed to prevent the unwanted disclosure of data from lost universal serial bus (USB) memory devices and prevent uploads to file-sharing networks: a USB memory device technology that after a fixed period of time automatically erases data stored on the USB memory, and a file redirect technology<sup>(<a href="http://www.fujitsu.com/global/news/pr/archives/month/2009/20090417-02.html#footnote0">1</a>)</sup> which ensures that the data from the USB memory device can only be stored on a specified server. This creates a secure environment that protects confidential information and allows USB memory devices to be used as a convenient way to safely carry customer data back to one&#8217;s own company to manage the data.
</p></blockquote>
<p>This sounds neat.  This may not be for home/casual users but I can see that the corporate IT department may be interested in the product.</p>
<ul>
<li> <strong>Encryption Software</strong>
<ul>
<li><a href="http://www.truecrypt.org/">TrueCrypt</a> TrueCrypt is open source software that is popular to secure USB drives.  It offers various encryption methods as you can see from this photo. <img src="http://www.mydigitalzone.net/images/true_crypt.gif" alt="TrueCrypt" width = 400 height = 200 />
<p> <script src="http://www.assoc-amazon.com/s/link-enhancer?tag=dizitalzone-20&amp;o=1" type="text/javascript"></script><br />
<noscript>&amp;amp;lt;br /&amp;amp;gt;     &amp;amp;lt;img src=&#8221;http://www.assoc-amazon.com/s/noscript?tag=dizitalzone-20&#8243; mce_src=&#8221;http://www.assoc-amazon.com/s/noscript?tag=dizitalzone-20&#8243; alt=&#8221;" /&amp;amp;gt;&amp;amp;lt;br /&amp;amp;gt; </noscript></li>
</ul>
</li>
</ul>
</li>
</ul>
<input id="gwProxy" type="hidden"><!--Session data--></input>
<input id="jsProxy" onclick="jsCall();" type="hidden" />
]]></content:encoded>
			<wfw:commentRss>http://mydigitalzone.net/2009/05/03/secure-usb-flash-drive/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Rootkit: Malware and Trojan</title>
		<link>http://mydigitalzone.net/2009/04/16/rootkit-malware-and-trojan/</link>
		<comments>http://mydigitalzone.net/2009/04/16/rootkit-malware-and-trojan/#comments</comments>
		<pubDate>Fri, 17 Apr 2009 05:58:50 +0000</pubDate>
		<dc:creator>Jenny</dc:creator>
				<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[Avast!]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Malwarebytes]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[Rootkit Buster]]></category>
		<category><![CDATA[Trend Micro]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://mydigitalzone.net/?p=138</guid>
		<description><![CDATA[<style type="text/css">
<!--
.nmstitle {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 13px;
	text-transform: capitalize;
	color: #003333;
}

.nmsdesc {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 12px;

	color: #003333;
}
-->
</style>




I spent half a day last weekend to help my friend to battle with a computer infected with trojans.  Lots of them.  They were persistent and difficult to remove.  Malwares like AntiVirus 2008 or AntiVirus 2009 as described in this post were easier to remove compared with the ones I encountered last [...]]]></description>
			<content:encoded><![CDATA[<style type="text/css">
<!--
.nmstitle {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 13px;
	text-transform: capitalize;
	color: #003333;
}

.nmsdesc {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 12px;

	color: #003333;
}
-->
</style><p id="top" /><script type="text/javascript"><!--
google_ad_client = "pub-2241621611203959";
/* DZone_posts336x280, created 1/2/09 */
google_ad_slot = "2956728885";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script><br />
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br />
<a href="http://www.amazon.com/gp/product/B001DQFLMC?ie=UTF8&#038;tag=latinballroom-20&#038;linkCode=as2&#038;camp=1789&#038;creative=9325&#038;creativeASIN=B001DQFLMC"><img border="0" src="/images/amazon/61lfqIQbhoL._SL160_.jpg"></a><img src="http://www.assoc-amazon.com/e/ir?t=latinballroom-20&#038;l=as2&#038;o=1&#038;a=B001DQFLMC" width="1" height="1" border="0" alt="" style="border:none !important; margin:0px !important;" /></p>
<p>I spent half a day last weekend to help my friend to battle with a computer infected with trojans.  Lots of them.  They were persistent and difficult to remove.  Malwares like AntiVirus 2008 or AntiVirus 2009 as described in <a href="http://mydigitalzone.net/2008/12/01/malware/">this post</a> were easier to remove compared with the ones I encountered last week.  Basically, AntiVirus 2008 and AntiVirus 2009 are malware that uses scare tactics to make users to buy their own virus removal software.  The ones I encountered at my friend&#8217;s house turned out to be a kind called &#8220;<strong>rootkit</strong>.&#8221;</p>
<p>According to <a href="http://en.wikipedia.org/wiki/Rootkit">wikipedia</a>, &#8220;A rootkit is a software system that consists of a program, or combination of several programs, designed to hide or obscure the fact that a system has been compromised&#8230; An attacker may use a rootkit to replace vital system executables, which may then be used to hide processes and files the attacker has installed, along with the presence of the rootkit. Access to the hardware, e.g., the reset switch, is rarely required, as a rootkit is intended to seize control of the operating system.&#8221;  This is a <strong>serious</strong> threat.  </p>
<p>The computer in question has a good working McAfee Virus scan and its On Access scan window keeps popping up saying that trojan was found and deleted.  That&#8217;s how my friend found about their existence.  The reason he asked my help was that it looks like it was catching the same gourp of files again and again, even though the virus scan said it had deleted them.  Some of the files were in windows\system32\drivers.  They were systemntmi.sys, amd64si.sys, i386si.sys, amd64si.sys, and lots of others.</p>
<p>So, there I was.  Trying various other software.  I tried Malwarebytes&#8217; Anti-Malware.  It found a bunch of infections.  Like over 50.  It said it had removed them.  Reboot.  Scanned again.  Strange.  It found them again.  Removed.  Reboot.  I used Avast!  Reboot.  I used Trend Micro Rootkit Buster.  Reboot.  As I said earlier, the trojans were persistent.  I decided to take a break at that point to do more research on the issue.</p>
<p>What I will do this weekend is to do an <strong>OS reinstal</strong>l this weekend.  As <a href="http://en.wikipedia.org/wiki/Rootkit">the wikipedia article</a> says, &#8220;Even if the nature and composition of a rootkit is known, the time and effort of a system administrator with the necessary skills or experience would be better spent re-installing the operating system from scratch.&#8221;  </p>
<p>Oh well.  I&#8217;m looking at two system restore projects within a week!  </p>
]]></content:encoded>
			<wfw:commentRss>http://mydigitalzone.net/2009/04/16/rootkit-malware-and-trojan/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Stolen Yahoo Email Password</title>
		<link>http://mydigitalzone.net/2009/01/11/stolen-yahoo-email-password/</link>
		<comments>http://mydigitalzone.net/2009/01/11/stolen-yahoo-email-password/#comments</comments>
		<pubDate>Sun, 11 Jan 2009 07:22:55 +0000</pubDate>
		<dc:creator>Jenny</dc:creator>
				<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[Yahoo email]]></category>

		<guid isPermaLink="false">http://mydigitalzone.net/?p=63</guid>
		<description><![CDATA[<style type="text/css">
<!--
.nmstitle {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 13px;
	text-transform: capitalize;
	color: #003333;
}

.nmsdesc {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 12px;

	color: #003333;
}
-->
</style>



My friend’s Yahoo email password got stolen and her account was used to send spam emails.  Cases like this seem to be increasing as you’ll find lots of hits on Google if you search for “stolen password.”  
She didn’t know how her password got stolen.  She only found that out because one [...]]]></description>
			<content:encoded><![CDATA[<style type="text/css">
<!--
.nmstitle {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 13px;
	text-transform: capitalize;
	color: #003333;
}

.nmsdesc {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 12px;

	color: #003333;
}
-->
</style><p id="top" /><script type="text/javascript"><!--
google_ad_client = "pub-2241621611203959";
/* DZone_posts336x280, created 1/2/09 */
google_ad_slot = "2956728885";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script><br />
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br />
My friend’s Yahoo email password got stolen and her account was used to send spam emails.  Cases like this seem to be increasing as you’ll find lots of hits on Google if you search for “stolen password.”  </p>
<p>She didn’t know how her password got stolen.  She only found that out because one of her friends had informed her about the spam email.  When she checked the sent mail box, she saw the spam email she never sent.  So, it means that somebody stole her password and used her account, rather than faking the email address.  </p>
<p>I immediately asked her to change the password.  She was lucky that the person who used her account didn’t change the password.  If that was the case, she could’ve locked out of her email account.</p>
<p>I also asked her to check the detailed header of the spam email, and it turned out that the email was originating from China.  (You can see the full header by clicking on “Full Headers” at the bottom of the mail in Classic Mail or at the upper-right part in the new Yahoo Mail.)</p>
<p>Her case was a good lesson for me.  Changing passwords regularly and using complex passwords are easy ways to ensure more security but I wasn’t doing it as often as I should have been.  From now on, I’ll be more careful about passwords.</p>
]]></content:encoded>
			<wfw:commentRss>http://mydigitalzone.net/2009/01/11/stolen-yahoo-email-password/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Remove Antivirus 2008</title>
		<link>http://mydigitalzone.net/2008/12/01/malware/</link>
		<comments>http://mydigitalzone.net/2008/12/01/malware/#comments</comments>
		<pubDate>Mon, 01 Dec 2008 07:00:55 +0000</pubDate>
		<dc:creator>Jenny</dc:creator>
				<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Anti-Malware]]></category>
		<category><![CDATA[Antivirus 2007]]></category>
		<category><![CDATA[Antivirus 2008]]></category>
		<category><![CDATA[Antivirus 2009]]></category>
		<category><![CDATA[Malwarebytes]]></category>

		<guid isPermaLink="false">http://mydigitalzone.net/?p=11</guid>
		<description><![CDATA[<style type="text/css">
<!--
.nmstitle {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 13px;
	text-transform: capitalize;
	color: #003333;
}

.nmsdesc {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 12px;

	color: #003333;
}
-->
</style>



Antivirus 2008 is malware and is becoming rampant.  It is extremely annoying and oftentimes makes a computer unoperable with its pop-ups and fake warnings.  According to Wikipedia, Malware is &#8220;software designed to infiltrate or damage a computer system without the owner&#8217;s informed consent.&#8221;  Most people get infected with Antivirus 2008 by installing [...]]]></description>
			<content:encoded><![CDATA[<style type="text/css">
<!--
.nmstitle {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 13px;
	text-transform: capitalize;
	color: #003333;
}

.nmsdesc {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 12px;

	color: #003333;
}
-->
</style><p id="top" /><script type="text/javascript"><!--
google_ad_client = "pub-2241621611203959";
/* DZone_posts336x280, created 1/2/09 */
google_ad_slot = "2956728885";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script><br />
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br />
Antivirus 2008 is malware and is becoming rampant.  It is extremely annoying and oftentimes makes a computer unoperable with its pop-ups and fake warnings.  According to <a href="http://en.wikipedia.org/wiki/Malware">Wikipedia</a>, Malware is &#8220;software designed to infiltrate or damage a computer system without the owner&#8217;s informed consent.&#8221;  Most people get infected with Antivirus 2008 by installing a fake codec for audio or video files or by installing software that hides malicious software in the package.  <strong>You can remove Antivirus 2008 with free software called &#8220;Anti-Malware&#8221; by Malwarebytes.  So, do not buy software that Antivirus 2008 recommends.</strong></p>
<p><strong>Infections</strong><br />
It has many variants but the main characteristics of this malware is to rely on <strong>scare tactics</strong> (about virus infection on the PC) and to convince the user to <strong>buy Virus removal software</strong> online.  When Antivirus 2008 gets installed on a computer, it will start giving warnings about viruses on the computer.  It will ask the user to scan the computer with Antivirus and will show the results.  All the infections shown in the result window are actually fake, planted by Antivirus 2008 itself.  When the user tries to remove infections, he/she will be notified that the removal capability is disabled with the free version of Antivirus and only the purchased version will be able to remove the infections.  </p>
<p>Here are a few screenshots of the Antivirus warnings.<br />
<img src="http://www.mydigitalzone.net/images/antivirus_2008_1.jpg" alt="Anti-Virus 2008" width = 500 height = 400 /><br />
<img src="http://www.mydigitalzone.net/images/antivirus_2008_2.jpg" alt="Anti-virus 2008" width = 500 height = 400 /></p>
<p><strong>Removal</strong><br />
It is possible to remove Antivirus 2008 manually; however, it is a complicated process and can be intimidating if you are not familiar with computers.  There is excellent software that can take care of Antivirus 2007/2008/2009 infections and other malware problems.  The software is free for basic uses, and you don&#8217;t need to buy an upgraded paid version.  Please go to <a href="http://www.malwarebytes.org/">Malwarebyte&#8217;s home page, </a>download <a href="http://www.malwarebytes.org/mbam.php">Anti Malware</a>, install it, scan your computer, and follow the directions.  I&#8217;ve used this software many times on my and my friend&#8217;s computer.  It is effective and easy to use.</p>
<p><strong>Additional software for precaution and regular maintenance</strong><br />
I also recommend to use <a href="http://www.lavasoft.com/?domain=adaxis.net">Lavasoft&#8217;s Ad-Aware</a>.  One note of caution for this software is that their latest version seems to be a bit buggy, at least on my computer.  This software scans for spyware and other malware that can cause problems.</p>
]]></content:encoded>
			<wfw:commentRss>http://mydigitalzone.net/2008/12/01/malware/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
