Monday, May 27, 2013



MISC. MEMORIAL DAY RAMBLING









Do you use Skype, or, are you planning on installing it in the near future? If so, I have two words for you: "Be Careful". If you're downloading the software please make sure you are doing it from the correct website and haven't been re-directed to a website that looks like Skype. This may be pure coincidence but last week I ran across two customers who were infected by something related to Skype.

In incident No.1 the user was downloading Skype and as soon as it finished and the install began - they became infected with numerous virus/trojans.

In incident No.2, from what little was passed on to me, Skype was in use previous to infection. Their PC arrived with a variation of the "FBI VIRUS". Working my way through my logical troubleshooting steps I found that it was the Skype.dat file that started the whole thing, so be careful on installations, updates, and Skype messages.


I.E. 10 is still crap and a large percentage of calls regarding Internet access or full access into a secure website end up with a technician un-installing the I.E.10 update which reverts it back to I.E. 9 (the lesser of two evils).

Also, as in many service calls, some infections could have been prevented by applying patches to Adobe Flash, Reader, and Oracle's JAVA.

'Nuff Said,
Brian

Tuesday, May 21, 2013


YIKES!! ARE YOU BEING "SKYPED" ?





While sitting in the waiting room of a Doctors office I was perusing some of my tech-sites when I ran across an article regarding Microsoft, Skype, and Skype users. Apparently Microsoft has been "checking in" on Skype messages just to verify that there isn't any fraud going on, but the article [ed. - which, as usual, I'll have the link to at the end of this Blog Post] went further, and brought up some interesting questions.


The title of the article is:

"Microsoft may be scanning your Skype messages"


Here are some excerpts:

"If you have any expectations about the privacy of your Skype communications, you may want to reassess them. Microsoft appears to be peeking into Skype messages for security reasons..."

"What these recent findings mean is that Skype users can no longer reasonably expect their Skype chats and calls to be private"

“The expectation was what I type to you just goes to you,” he told PCWorld. However, this finding shows that Microsoft is able to monitor some of that.”

Want to read more? You'll find the complete article HERE.

'Nuff Said,
Brian

Wednesday, May 15, 2013



NEWS & UPDATES






The critical patch for users of Internet Explorer 8 is officially out in the wild. My computer downloaded and installed it early this morning. If yours hasn't done it yet, you could check your update settings or just choose "Windows Update" and it should show up in the list of downloads on Microsoft's website.

The FBI virus is still infecting computers, and most of the ones we've seen lately were using a free anti-virus program for protection. After paying to get the darn thing off your computer perhaps you'll pony up and pay for better protection.

NSS Labs, a security testing company, ran several Internet browsers through the wringer to determine which one was best at blocking bad things. They tested:
  • Chrome
  • Apple Safari 5
  • Internet Explorer 10
  • Firefox 19
  • and Opera 12
Who came out the winner? Microsoft's Internet Explorer 10. I find this somewhat humorous because of all the issues we've had with customers having I.E.10 and not being able to access websites previously available, including bank websites.

You can read the whole testing process article HERE.

'Nuff Said,
Brian

Sunday, May 12, 2013

MICROSOFT TO FIX ZERO-DAY EXPLOIT IN I.E.8

Just as the title reads, Microsoft is patching some zero-day exploits in Internet Explorer 8.

Read the article HERE.

'Nuff Said,
Brian

Friday, May 3, 2013


MAIL CALL...







It's been awhile since I shared some emails received, so while I'm hacking out my allergies I thought it would make a good time to do it.

Q. - What is a "PUP"? These sometimes come up on a Malwarebytes scan.

A. - A "PUP" is what security people call nuisance or possibly a program you may not want on your computer. To my knowledge, PUP's do not grow up to become "DOG's".

Q. - My Internet Explorer browser used to say "Windows Internet Explorer". Now, when I open it I see at the top "Babylon Search - Windows Internet Explorer", what happened?

A. - Your browser has been Hijacked by a program called Babylon. It probably has made itself the default homepage (which you can't change) as well as default search engine. Sometimes, I've used Babylon (I think it used to be Yahoo's Babylon) to translate English into French and send an email to my wife in French. The last time I used it they kept trying to get me to add it as a toolbar to make languages conversions easier, but it sounded a little iffy.

So, if you do have this, I'm sure you've tried to un-install it, change search engines and homepages and still have it on your computer. Unless you're ready to spend a lot of time and steps to completely remove it I would:
  1. Try a system restore to a date before that happened. If that fails -
  2. Call a professional in to get rid of it for you. [ed. - shameless plug for SugarlandPC]
Q. - I paid a lot for my anti-virus software and I still got infected. Does Norton really suck?

A. - No, Norton/Symantec is in the TOP 5 of anti-virus suites. The fact is, no matter what you buy cannot stop every virus. We are constantly being bombarded by new viruses, trojans, and old ones that have been modified.

The best thing you can do is make sure the Anti-virus is up to date, run a quick Malwarebytes scan once or twice a month and keep your Adobe Flash updated (as well as JAVA). Don't do it via a pop-up, go directly to their respective websites and upgrade. The links are on the homepage of each.

And that end's the "MAIL CALL" post today -

'Nuff Said,
Brian
Email

Wednesday, May 1, 2013

NOBODY KNOWS, THE TROUBLES YOU HAVE SEEN....
[NOBODY KNOWS YOUR SORROW]




Not exactly security related - yet, however I feel I should alert you to a potential problem with regards to Microsoft's "Internet Explorer". If you have Windows 7 then it's possible they've already slipped an update on your PC when you weren't looking and upgraded I.E. 9 to I.E.10; I've run into a variety of people who had issues which led them to believe they had a virus, or something else was wrong.

If you have any of these symptoms, it would behoove you to check which version of Internet Explorer you have on your PC. The symptoms (to date) are:
  • You can open I.E. and it brings you to your home page but when you click on a link nothing happens.
  • Example - you're a Comcast customer and have them set as your homepage so you can click on MAIL and check your mail. You click - nothing happens.
  • You're in Outlook and get an email with several links (yes, a good email - not a bad one), and you click on the link. Either nothing happens, or it brings up another I.E. windows that remains blank.
  • You try to pull down your favorites - nothing happens
  • You can get to a website, but it won't let you go further than the first page
Of course, these could be symptoms of a virus as well, so proceed with that thought in mind. If you are running I.E. 10 -
  1. Go to control panel
  2. Select "Programs and Features" (this is where you would usually un-install a program)
  3. Click on "View installed updates". The screen will change and you may notice a light green bar slowly moving steadily towards the "X", or if you have a faster PC it may just zip across. In either case, wait until it's done.
  4. Scroll down slowly until you find Internet Explorer 10
  5. Left-click once, to highlight it.
  6. Right-click once and choose un-install. If it asks you "Do you want to un-install this update?" you're fine - continue.
The computer will do it's thing and then reboot, and when it comes back up you should see something akin to "applying updates 35% completed". Wait for it to finish.

Now, open your Internet Explorer and verify it is now I.E. 9, then see if those problems you had went away. Regardless of whether they did or didn't, I'd still open Malwarebytes, update it, and run a quick scan for viruses. BTW - I fixed customers issues on 3 computers today just by doing what I wrote above...

'Nuff Said,
Brian
FIRST BLOG POST OF MAY







Bankers beware! If your bank (or for that matter a hospital) uses an IP-based video camera made by D-Link there is a possibility that a flaw(s) within their system could allow others to tap into it. In a report on Computer World's security site I found this interesting/scary tidbit.

"Core Security's researchers found it was possible to access without authentication a live video stream via the RTSP (real time streaming protocol) as well as an ASCII output of a video stream in the affected models. RTSP is an application-level protocol for transferring real-time data, according to the Internet Engineering Task Force."

Read the whole thing HERE.

'Nuff Said,
Brian