Sunday, September 8, 2013

WHAT ARE "PUP" AND "PUM" FILES?

email
I SEE A TON OF THESE ON VIRUS SCANS




Are these good, bad, or ugly? Let's look at PUP first. PUP can stand for "Potentially Unwanted Program" or, in the realm of the Sony "Playstation" it would be "Playstation Update Package".

I think we can discount the Playstation description when doing virus scans on a computer, but if these pop up on your virus scan it can be difficult to determine what their purpose is. On a PC, a "PUP" can be a Virus, Spyware, or Adware program. Because Anti-Virus programs can't determine whether it's good, bad, or ugly I usually select "CHECK ALL" to remove them.

PUM

PUM's are typically more dangerous, the letters standing for "Potentially Unwanted Modification" and usually are used for re-directing your browser to another website that may not look at all like where you wanted to go, or, looks just like the website and when you put in your login name and password the bad guys have it. 

This is usually done via "Proxy" which can be accomplished through several methods:
  • In Internet Explorer there is a proxy section [under Internet options] which can be activated and a specific IP address put in the proper place so you go there first.
  • In the HOSTS file the hacker can put various website names like Amazon, Chase, Walmart, Target, etc. and each website points to the same IP address, directing you to their fake server.
  • The registry can be hacked as well, and found in this location:
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer
In any case if you're scanning your PC with Malwarebytes and when it ends you see 203 viruses found, don't have a heart attack - they will most likely be PUP's and PUM's. There may be one that has been "check marked" because Malwarebytes could determine it was bad, and leave all the other unchecked, but my advice is to right-click on a check-box and select "Check all", then let the program delete them.

In the case of Malwarebytes it will have you do a restart right away. I would select NO, then go to My Computer, right-click on it and select properties, disable the restore points (which may now be infected) and THEN restart your computer. Once it's up and running go back and turn the restore points back on, go back to Malwarebytes, run another update, then select a FULL scan [ed.- just to be sure].

'Nuff Said,
Brian

Friday, September 6, 2013

HELL JUST FROZE OVER

email

I NEVER THOUGHT I'D SEE THE DAY, BUT...





For at least 10 years there has been a documented "BUG" / "SECURITY HOLE" in Microsoft Outlook and the preview pane. Most people seem to like having the preview pane ON because as they click on each message they can see if it's worth opening, but what I have told my customers throughout the years is that if you use the preview pane it's just like opening an email.

What does that mean? It means if there is some hidden HTML malware code in the message, just by viewing it in the pane you are activating it as if you had just clicked on the message and opened it yourself, thus infecting your computer. As each version of Outlook came out many of us hoped that the hole would be patched - but it was not to be.

Well, next week around Tuesday or Wednesday Microsoft is finally releasing a patch that will, according to them, patch the hole. It's time to celebrate!

'Nuff Said,
Brian

Monday, September 2, 2013

SETTING UP YOUR HOME WIRELESS NETWORK PT.2


WIRELESS NETWORKING 101 - PART 2







Let's refresh both of our memories! You are either setting up your first wireless network or replacing the old one that died, and if it's the old one that died it's probably looks like the one below -

A very good wireless router for it's time, but like everything there is change. If you've never set up a wireless router before you may want to use the CD that came with it and choose the "Wireless Wizard" which will get you "ON-THE-AIR" relatively fast.

If you're a brave soul, you can try to configure it without the CD and by using it's IP address and your browser, have a go at it. This isn't such a bad idea; sure, you'll make mistakes and probably reset the router to it's out-of-the-box settings a few times, but by doing it you'll learn a little more how it works.

If you're the person who doesn't have the time, or even care how it works you'll call someone in like SugarLandpc to do it all for you. No fuss - no muss.

And, you could always use the setup CD and then go into the wireless router to see how it's configured. Not all, but some routers have the option to make a backup of it's configuration and it yours does I would suggest doing so.

Just remember:
  • First of all things, you don't want your router sitting on top of the modem. The heat vents from the modem are often on the top, so it's slowly baking your router.
  • You want WPS disabled
  • You should change the SSID (name) or the router to something else, and not your name.
  • You should have some security setup on the router, but you'll have to check all of your wireless equipment to make sure they will all work with the setting you've chosen. Sometimes older laptops won't connect to the router because when it was made because certain types of security weren't around. And I've run into new devices that wouldn't work unless I set the router to the oldest security setting.
  • The wifi password should be difficult, yet fairly easy to remember or at the least, written down in your notepad of passwords. A simple name wouldn't suffice because if someone was intent on getting onto your wifi they would do a brute force dictionary type attack, and if the word is in the dictionary it will eventually find it.
  • As I said in Part 1, a password doesn't have to be one word, it could be a sentence or phrase. I believe my example was: itrainsinspain. You could leave it at that or substitute and "i" for a 1, so it would be 1tra1ns1nspa1n, or, use the original and add a "!" somewhere in the password (beginning, middle, end, etc.)
  • Once it's set up, try all of your wireless devices to make sure they'll work. If one or two don't, you may have to try and older security setting.
  • As well, once set up, walk around your house to see if you have any dead spots or very weak signal connection. It may be that, if possible you'll have to move the router to a different position or at least a higher location. Many times I've walked into a residence to find the wireless router sitting next to the modem - on the floor.
  • Once you are satisfied that you've done the best you can, change the admin password that allows access to your routers configuration. If someone can figure out what router you have, it's not hard to Google for the default admin login and password.
I suppose one last thing should be mentioned. Just because you've bought the latest, fastest, most powerful wireless router available it will only do these things with wireless equipment that can take advantage of it. Otherwise you'll probably get the same signal you got before with your old router. And if you suddenly lose all Internet access, what should you do? That's right - call your Internet provider to see if there is an outage in your area. And I always recommend that you purchase a UPS (uninterruptable power supply) with an AVR circuit in it. This will prevent an untimely modem or router death.

'Nuff Said,
Brian 

Sunday, September 1, 2013

TROJAN + CRAIGSLIST = TROUBLE

Email

HOT OF THE PRESS!!







Apparently a Trojan Horse is working it's way through "Craigslist",infecting unsuspecting users with a fake and free software program.
Solera's Director of Threat Research, Andrew Brandt said "Anytime a computer is infected with malware, the box is owned by someone else and they can use it to do all kinds of different things"

YE OLD TROJAN HORSE


 The viewer sees a link to a fake program called "Adobe Photo Loader", and once the link is clicked on the malware turns the computer into a botnet PC which then posts links for another program which if clicked on infects the users phone so all of their activity can be monitored or recorded by the people behind this, so please be careful on what you click on -

'Nuff Said,
Brian

Wednesday, August 28, 2013

SYMANTEC'S MID-YEAR INTELLIGENCE REPORT


NOT QUITE MID-YEAR, BUT IT'S ALL I HAVE





I caught a link to the "Symantec May/June Intelligence" white paper and thought I'd read it here and there when I had time and then let you know if there were any HUGE threats in cyberspace. It starts off with a summary by Ben Nahorney who said mobile (cell phone) threats weren't as bad this year as they were at the same type last year, and the Spam rate had dropped to 67% (from 71.9% in the first quarter of this year). I feel like I'm writing about employment vs. unemployment percentages for some reason, but let's continue past the summary.

This is where the numbers get a bit scary: The number of identities (like yours or mine) exposed so far this year were 77,996,740, and that's a lot of people folks. Bot-zombie computers dropped from over 300 thousand to a mere 162 thousand in May.

Mobile malware variants (a variation of malware already out-and-about) dropped from 748 in March to 312 in May. It goes without saying [ed. - yet I'll say it] that the majority of these were Android based. And just to prove I really didn't know there was one, here is an excerpt:

May 24  "A highly respected media organization became the latest high
profile hacking victim of the Syrian Electronic Army (SEA). The
SEA has been targeting the websites and social media accounts
of well-regarded news organizations"


Regarding the number of identities breached, they had a simple chart that confirms that a picture (or chart) is worth a thousand words.


As well, another nifty chart regarding data breaches -

How many times have we heard of some big company or government employee losing a laptop?
I've been asked a lot about where the Malware comes from, but occasionally I'm asked about "SPAM". "Where does all of this stuff come from?" customers ask. See chart below.


I'll let those tired eyes of yours get back to a baseball stats to check on the Red Sox,

'Nuff Said
Brian

Tuesday, August 27, 2013

WINDOWS 8.1


WILL IT BE GOOD, BAD, OR JUST PLAIN UGLY?






Microsoft has said that the 8.1 update is ready for RTM (release to manufacturers) even though it isn't finished, and may not until it's close to be ready for Windows 8 users to download [ed. - which was previously set for October 17th]. Unlike previous releases IT professionals and developers will not get access to 8.1 two weeks prior to it's release as they have had in the past. It seems like Windows 8 and now 8.1 has a perpetual cloud hovering over them.

From what I've read, Windows 8 users will get a "Start" button, but it will lead to the Metro interface rather than the typical Start/programs/show all programs and other features not available in Windows 8. That was several months ago, so it's possible this may have changed - we'll have to see.

XP-Z

About a week ago I read a serious (with some dark humor) article written by Gregg Keizer, entitled XP-Z with story content relating to Microsoft pitching Windows XP users off the cliff next March/April. He wrote:

"Call them the "walking dead" of vulnerabilities. Call it XP Z -- "Z" for zombies."

You can find the article HERE. While the reference to zombies was funny to me, the lack of further security patches or even one last Service Pack will make some people abandon XP for whatever is available, while other will take their chances. Perhaps some users should hedge their bets by purchasing Windows 7 now, before they stop selling it, then find a computer to put it on. Or you can keep reading further down the Blog...

NEW YORK TIMES - HIT AGAIN

Apparently the New York Times was hacked recently, by what some have called the "Syrian Electronic Army" (I didn't know there was one, did you?). You can read all about the exciting news from the article, HERE.

NSA STUFF

I'm sure you heard a lot about the NSA and other agencies snooping in on our phone calls, emails etc. and how many companies like Google and others are coming clean with information about this issue. Well Facebook said they had approximately 25,000 requests from the Government in just the first half of this year. Once again, whatever you post online will stay there forever, so watch those P's and Q's...

SPEAKING OF: Gregg Keizer

Well, I was several paragraphs ago, he has another article about XP and Microsoft, stating that Microsoft will continue to make patches for XP after the spring 2014 deadline - but it will be a pay-for-patch operation. On one hand they want XP to go away, yet on the other hand Microsoft will milk XP users for all $$$ they can. This article can be found HERE.

That's it for today -

'Nuff Said,
Brian
email 

Thursday, August 15, 2013

CREEPY THOUGHT



OF COURSE, IT'S ABOUT MICROSOFT






Stats of late show that Windows 8 has a very small market share (under 4% I believe), while Windows 7 is growing and currently at-or-about 17%, and the bane of Microsoft's existence has been Windows XP, which I think is still used on 40% of the computers in the world. They've tried this, they've tried that, but Microsoft can't seem to kill it off.

In the first quarter of next year (March?) all support for XP ends. That means no security patches for I.E.8 or the OS itself. This has been known for awhile.

As of late I've been reading about how XP computers will be a "Hackers Haven" after the support ends because they can they attack a variety of exploits that will remain unpatched [ed. - are you still with me?].

So if the "stats" remain about the same what could Microsoft do? Easy. Just before the support ends they can push down the last security patches that XP will ever see, adding so many holes in the OS that users will leap to the next OS like rats jumping off a burning ship as their computers continue to be infected. The end result: 0% XP computers and Microsoft is suddenly selling the latest OS like hotcakes.

Creepy thought...

'Nuff Said,
Brian