<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-82060746239645894</id><updated>2012-01-30T04:57:27.366-08:00</updated><title type='text'>Noob blogger...</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://athansj.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://athansj.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Athan</name><uri>http://www.blogger.com/profile/06568460519084492565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://lh4.ggpht.com/_Cn4enf1IhOA/SXQC-SIOQKI/AAAAAAAAAX4/Uv5O02-GHlk/s720/DSC_0184.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>14</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-82060746239645894.post-7169098832141459992</id><published>2011-12-10T05:13:00.001-08:00</published><updated>2011-12-10T05:55:39.125-08:00</updated><title type='text'>Beware to all Paypal users!</title><content type='html'>&lt;div style="text-align: left;"&gt;I just found a fake email having the below message:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;&lt;hide&gt;From: Paypal&lt;/hide&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Subject: Suspicious Payment&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;PayPal Customer, &lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;You Made A Payment to www.thetattooshop.co.uk . &lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Your £5.00 GBP payment is in proccess. &lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;If you are not redirected within 10 seconds. &lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Log In To &lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;http://www.paypal.co.uk&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;To receive a refund. &lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;PayPal , &lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Purchase Protection Department.&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This is the usual view of most emails in which the sender's email address is not shown. So how can we say it is fake? Please do the standard procedure of verifying the email.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;1. Before panicking, make sure to verify who or what really is the sender's email address. In this case, I find the sender not directly from Paypal: spprtppdptm@ppal.com &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;2. Before clicking any URL from the email message body, make sure it does not contain hyperlinks that points to different site. In this fake email, the http://www.paypal.co.uk contains the hyperlink that points to the site: http://andybrwny.altervista.org/evl/index.html&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You can mouse over to the URL from the email message body BUT WITHOUT CLICKING IT:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://4.bp.blogspot.com/-US4ttiaQHiM/TuNfNBceB9I/AAAAAAAAImA/h5qd_RBbu44/s1600/img1-fake%2Bemail.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img src="http://4.bp.blogspot.com/-US4ttiaQHiM/TuNfNBceB9I/AAAAAAAAImA/h5qd_RBbu44/s400/img1-fake%2Bemail.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5684491832002480082" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 340px; height: 319px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Mousing over the URL will show where the hyperlink is pointing at the bottom left of the browser. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The said site pretends to be a Paypal site to steal your Paypal credentials, you can see below image:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://2.bp.blogspot.com/-2PpqYOon7Ro/TuNdXpQO25I/AAAAAAAAIl0/dUAgJm--ggM/s1600/img1-fake%2Bpaypal%2Bsite.JPG" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img src="http://2.bp.blogspot.com/-2PpqYOon7Ro/TuNdXpQO25I/AAAAAAAAIl0/dUAgJm--ggM/s400/img1-fake%2Bpaypal%2Bsite.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5684489815464008594" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 287px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Please note the URL which is not really the Paypal site.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;3. If verified to be a fake email, please report it to help others.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;4. In case you clicked the URL and logged in to the fake Paypal site. Login to the real Paypal site and change your password ASAP before it's too late... or maybe you can call Paypal Customer Service to report it.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;That's it for today and hope this helps... Thanks for reading!&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/82060746239645894-7169098832141459992?l=athansj.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://athansj.blogspot.com/feeds/7169098832141459992/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://athansj.blogspot.com/2011/12/beware-to-all-paypal-users.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/7169098832141459992'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/7169098832141459992'/><link rel='alternate' type='text/html' href='http://athansj.blogspot.com/2011/12/beware-to-all-paypal-users.html' title='Beware to all Paypal users!'/><author><name>Athan</name><uri>http://www.blogger.com/profile/06568460519084492565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://lh4.ggpht.com/_Cn4enf1IhOA/SXQC-SIOQKI/AAAAAAAAAX4/Uv5O02-GHlk/s720/DSC_0184.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-US4ttiaQHiM/TuNfNBceB9I/AAAAAAAAImA/h5qd_RBbu44/s72-c/img1-fake%2Bemail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-82060746239645894.post-654200896222181009</id><published>2011-03-18T16:46:00.000-07:00</published><updated>2011-03-18T17:04:23.520-07:00</updated><title type='text'>Facebook Likejacking attack 3</title><content type='html'>&lt;div style="text-align: left;"&gt;Another Likejacking found on Facebook a minute ago...&lt;/div&gt;&lt;div&gt;I found the below post from my news feed and the play image seems suspicious.&lt;/div&gt;&lt;div&gt;&lt;a href="http://3.bp.blogspot.com/-tXWTUYOb4sI/TYPwnDI579I/AAAAAAAAIh8/P_fqJ7Npnyw/s1600/01-post.jpg"&gt;&lt;img src="http://3.bp.blogspot.com/-tXWTUYOb4sI/TYPwnDI579I/AAAAAAAAIh8/P_fqJ7Npnyw/s400/01-post.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5585572516517769170" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 154px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;After clicking the link from the facebook post, it will be redirected to the below site:&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;http://video25.info/pan/&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://3.bp.blogspot.com/-5_0pkb3_p9U/TYPwnVh8yuI/AAAAAAAAIiE/7GQ8QsI4sAQ/s1600/02-site.jpg"&gt;&lt;img src="http://3.bp.blogspot.com/-5_0pkb3_p9U/TYPwnVh8yuI/AAAAAAAAIiE/7GQ8QsI4sAQ/s400/02-site.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5585572521454652130" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 189px; " /&gt;&lt;/a&gt;&lt;div style="text-align: left;"&gt;I'm not going to explain how it works but if you need details, the technique is the same as my &lt;a href="http://athansj.blogspot.com/2011/03/another-facebook-likejacking.html"&gt;previous blog&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;The below shows how many users that were tricked by this attack as of this writing. And it continue to increase every refresh of the page. &lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://3.bp.blogspot.com/-i_xpC0hWxyI/TYPxixOu0QI/AAAAAAAAIiM/PY1IkKkfNac/s1600/03-like.jpg"&gt;&lt;img src="http://3.bp.blogspot.com/-i_xpC0hWxyI/TYPxixOu0QI/AAAAAAAAIiM/PY1IkKkfNac/s400/03-like.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5585573542502519042" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 47px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;If you suspect you've been infected by this attack, just go with the below link and click the UNLIKE button (note: If there's no UNLIKE button, DO NOT CLICK THE LIKE BUTTON)&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.facebook.com/plugins/like.php?href=http://video25.info/pan/"&gt;http://www.facebook.com/plugins/like.php?href=http://video25.info/pan/&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/82060746239645894-654200896222181009?l=athansj.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://athansj.blogspot.com/feeds/654200896222181009/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://athansj.blogspot.com/2011/03/facebook-likejacking-attack-3.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/654200896222181009'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/654200896222181009'/><link rel='alternate' type='text/html' href='http://athansj.blogspot.com/2011/03/facebook-likejacking-attack-3.html' title='Facebook Likejacking attack 3'/><author><name>Athan</name><uri>http://www.blogger.com/profile/06568460519084492565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://lh4.ggpht.com/_Cn4enf1IhOA/SXQC-SIOQKI/AAAAAAAAAX4/Uv5O02-GHlk/s720/DSC_0184.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-tXWTUYOb4sI/TYPwnDI579I/AAAAAAAAIh8/P_fqJ7Npnyw/s72-c/01-post.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-82060746239645894.post-3121261261241543610</id><published>2011-03-15T05:57:00.000-07:00</published><updated>2011-03-15T06:39:34.893-07:00</updated><title type='text'>Autorun Malware Protection for Win7</title><content type='html'>&lt;div style="text-align: left;"&gt;My mistake that I haven't updated the previous blog on &lt;a href="http://athansj.blogspot.com/2009/11/autorun-malware-protection.html"&gt;Autorun Malware Protection&lt;/a&gt; which is not applicable in Windows 7. So I decided to create another write up about it.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Below is the steps on how to totally disable the Auto Play feature of Windows 7.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;1. Open the Local Group Policy Edit via the below instructions:&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;1.1 Click Start or Hold windows key from keyboard and press &lt;i&gt;R&lt;/i&gt; &lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;1.2 Then type &lt;i&gt;gpedit.msc&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;2. A window will show up and browse the below items from the left side of the Local Group Policy Editor window:&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;2.1 &lt;i&gt;Computer Configuration&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;  &lt;/span&gt;-&gt; Administrative Templates&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;   &lt;/span&gt;-&gt; Windows Components&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;    &lt;/span&gt;-&gt; Autoplay Policies&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;2.3 At the right side, you can see settings about the Autoplay policies same as below:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://2.bp.blogspot.com/-_AEU9yduK0s/TX9j0OQ42VI/AAAAAAAAIhs/LcoHukjkgx0/s1600/01-gpedit.jpg"&gt;&lt;img src="http://2.bp.blogspot.com/-_AEU9yduK0s/TX9j0OQ42VI/AAAAAAAAIhs/LcoHukjkgx0/s400/01-gpedit.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5584291811795982674" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 214px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="text-align: center;"&gt;Figure A. gpedit.msc&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;3. Enable each one of the settings from the Autoplay policies and set it the same as the below:&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/-1_Bb_vrvEJg/TX9jz0FXcrI/AAAAAAAAIhk/aiwjaOw5SKs/s1600/02-turn%2Boff%2Bautoplay.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/-1_Bb_vrvEJg/TX9jz0FXcrI/AAAAAAAAIhk/aiwjaOw5SKs/s400/02-turn%2Boff%2Bautoplay.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5584291804768334514" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 370px; " /&gt;&lt;/a&gt;&lt;div style="text-align: center;"&gt;Figure B. Turn off Autoplay&lt;/div&gt;&lt;div style="text-align: center;"&gt; &lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/-OaP8nfDawV4/TX9jzo_-bBI/AAAAAAAAIhc/EcGEOENsvHs/s1600/03-dont%2Bset.jpg"&gt;&lt;img src="http://2.bp.blogspot.com/-OaP8nfDawV4/TX9jzo_-bBI/AAAAAAAAIhc/EcGEOENsvHs/s400/03-dont%2Bset.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5584291801792932882" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 370px; " /&gt;&lt;/a&gt;&lt;div style="text-align: center;"&gt;Figure C. Don't set always&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/-LObjnwMp7M4/TX9jzRfFmuI/AAAAAAAAIhU/6S2uZVGCHSU/s1600/04-non%2Bvolumes.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/-LObjnwMp7M4/TX9jzRfFmuI/AAAAAAAAIhU/6S2uZVGCHSU/s400/04-non%2Bvolumes.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5584291795480976098" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 370px; " /&gt;&lt;/a&gt;&lt;div style="text-align: center;"&gt;Figure D. Turn off Autoplay for non volume devices&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/-7GM4SOb0zao/TX9jzeDpR3I/AAAAAAAAIhM/vTxT6n2_1Qw/s1600/05-behavior.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/-7GM4SOb0zao/TX9jzeDpR3I/AAAAAAAAIhM/vTxT6n2_1Qw/s400/05-behavior.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5584291798855534450" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 370px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Figure E. Default Behavior&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;4. After the above mentioned settings, close the Local Group Policy Editor window.&lt;/div&gt;&lt;div style="text-align: left;"&gt;5. Then go to Control Panel&lt;/div&gt;&lt;div style="text-align: left;"&gt;6. Click on the Hardware and Sound&lt;/div&gt;&lt;div style="text-align: left;"&gt;7. Click on the AutoPlay&lt;/div&gt;&lt;div style="text-align: left;"&gt;8. Uncheck the &lt;i&gt;Use AutoPlay for all media and devices&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;9. Then set all possible fields to &lt;i&gt;Take no action &lt;/i&gt;same as below:&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://1.bp.blogspot.com/-WQaKH5E73O8/TX9ow4gEzVI/AAAAAAAAIh0/6uzWRPsPDVc/s1600/06-take%2Bno%2Baction.jpg"&gt;&lt;img src="http://1.bp.blogspot.com/-WQaKH5E73O8/TX9ow4gEzVI/AAAAAAAAIh0/6uzWRPsPDVc/s400/06-take%2Bno%2Baction.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5584297251972631890" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 311px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;Figure F. Take no action&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Note: This will disable the Autoplay on all media type devices. This is also needed to be disabled because there are malwares that tries to infect media type such as CDs, DVDs and etc.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If you find problems with the step by step instructions. Just let me know.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/82060746239645894-3121261261241543610?l=athansj.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://athansj.blogspot.com/feeds/3121261261241543610/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://athansj.blogspot.com/2011/03/autorun-malware-protection-on-win7.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/3121261261241543610'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/3121261261241543610'/><link rel='alternate' type='text/html' href='http://athansj.blogspot.com/2011/03/autorun-malware-protection-on-win7.html' title='Autorun Malware Protection for Win7'/><author><name>Athan</name><uri>http://www.blogger.com/profile/06568460519084492565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://lh4.ggpht.com/_Cn4enf1IhOA/SXQC-SIOQKI/AAAAAAAAAX4/Uv5O02-GHlk/s720/DSC_0184.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-_AEU9yduK0s/TX9j0OQ42VI/AAAAAAAAIhs/LcoHukjkgx0/s72-c/01-gpedit.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-82060746239645894.post-5101993118739520667</id><published>2011-03-13T04:58:00.000-07:00</published><updated>2011-03-13T05:32:27.481-07:00</updated><title type='text'>Japanese Tsunami event used in Likejacking Attack</title><content type='html'>&lt;div style="text-align: left;"&gt;We all know what happened to Japan last friday and almost everyone is being curious and wanted to see pictures, videos and etc about the event.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;While browsing my Facebook, I've seen the below post from my news feed.&lt;/div&gt;&lt;div&gt;&lt;a href="http://2.bp.blogspot.com/-QjmIULENgDI/TXyyUDkfYpI/AAAAAAAAIgk/5RA-ZxebXEs/s1600/01-post.jpg"&gt;&lt;img src="http://2.bp.blogspot.com/-QjmIULENgDI/TXyyUDkfYpI/AAAAAAAAIgk/5RA-ZxebXEs/s400/01-post.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5583533695658058386" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 394px; height: 121px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Figure A. FB Post&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I click the link from the above Facebook post and found the below site which is very suspicious. &lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;&lt;i&gt;http://spinavideo.com/&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://3.bp.blogspot.com/-a1h88yQgXCo/TXyyUJ88jNI/AAAAAAAAIgs/3QHMHNYS2jY/s1600/02-site.jpg"&gt;&lt;img src="http://3.bp.blogspot.com/-a1h88yQgXCo/TXyyUJ88jNI/AAAAAAAAIgs/3QHMHNYS2jY/s400/02-site.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5583533697371245778" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 185px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Figure B. The site&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Then I started to analyze...... and I found out that this is another Facebook likejacking.....&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Again, the same technique as before, it uses a hidden iframe to hide the liking of page...&lt;/div&gt;&lt;div&gt;&lt;a href="http://1.bp.blogspot.com/-8GlaQjEOfac/TXy01reQK9I/AAAAAAAAIhE/dBgbhHH50jE/s1600/05-iframe.jpg"&gt;&lt;img src="http://1.bp.blogspot.com/-8GlaQjEOfac/TXy01reQK9I/AAAAAAAAIhE/dBgbhHH50jE/s400/05-iframe.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5583536472328252370" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 35px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Figure C. Hidden iframe&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Then it contains code to make the hidden iframe follow the mouse where ever it goes so that once the user clicks the fake play image, the user will like the page without the user consent. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://3.bp.blogspot.com/-lxJzE8ejHMg/TXy01ThT8YI/AAAAAAAAIg8/ahu9j0WCi7c/s1600/04-mouse%2Bevent.png"&gt;&lt;img src="http://3.bp.blogspot.com/-lxJzE8ejHMg/TXy01ThT8YI/AAAAAAAAIg8/ahu9j0WCi7c/s400/04-mouse%2Bevent.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5583536465898631554" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 100px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Figure D. Mouse event&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;As of this writing, the below shows the total likes of the site which means the total number of users were tricked by the site.&lt;/div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-V-seEE8wYL0/TXyyUfjXrDI/AAAAAAAAIg0/EQw6PRq7X5A/s1600/03-likes.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 48px;" src="http://3.bp.blogspot.com/-V-seEE8wYL0/TXyyUfjXrDI/AAAAAAAAIg0/EQw6PRq7X5A/s400/03-likes.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5583533703169551410" /&gt;&lt;/a&gt;&lt;div&gt;&lt;div style="text-align: center;"&gt;Figure E. The likes&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span class="Apple-style-span"&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/span&gt;&lt;/div&gt;If you think you were tricked by this site, just visit the below link and UNLIKE the page &lt;i&gt;(Note: if you're not seeing the Unlike button just leave the page and DO NOT CLICK THE LIKE BUTTON)&lt;/i&gt;:&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.facebook.com/plugins/like.php?href=http://spinavideo.com/"&gt;http://www.facebook.com/plugins/like.php?href=http://spinavideo.com/&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Be aware about these kind of attacks. Well, there are ways to identify if the site is suspicious specially in this site (Figure B). As you can see the site contains Youtube logo but it is not actually the Youtube website, from that point you should know that it may cause you trouble when you continue browsing the page.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/82060746239645894-5101993118739520667?l=athansj.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://athansj.blogspot.com/feeds/5101993118739520667/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://athansj.blogspot.com/2011/03/japanese-tsunami-event-used-in.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/5101993118739520667'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/5101993118739520667'/><link rel='alternate' type='text/html' href='http://athansj.blogspot.com/2011/03/japanese-tsunami-event-used-in.html' title='Japanese Tsunami event used in Likejacking Attack'/><author><name>Athan</name><uri>http://www.blogger.com/profile/06568460519084492565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://lh4.ggpht.com/_Cn4enf1IhOA/SXQC-SIOQKI/AAAAAAAAAX4/Uv5O02-GHlk/s720/DSC_0184.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-QjmIULENgDI/TXyyUDkfYpI/AAAAAAAAIgk/5RA-ZxebXEs/s72-c/01-post.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-82060746239645894.post-1892888860101442299</id><published>2011-03-10T03:40:00.000-08:00</published><updated>2011-03-10T04:59:53.471-08:00</updated><title type='text'>DHL Delivery Notification</title><content type='html'>&lt;div style="text-align: left;"&gt;I received an email from DHL saying that a parcel was sent to my home address and it includes an attachment which a malicious executable. If you also receive this email, please delete the email immediately or report to your Security Vendor. Below is the example of the Spam mail:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://2.bp.blogspot.com/-0njt-iU9XP0/TXi51GEz8dI/AAAAAAAAIgU/A7oZwYLQVt0/s1600/02-email.jpg"&gt;&lt;img src="http://2.bp.blogspot.com/-0njt-iU9XP0/TXi51GEz8dI/AAAAAAAAIgU/A7oZwYLQVt0/s400/02-email.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5582416059940729298" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 387px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Figure A. The Mail&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This kind of attack becomes popular these past year where the email address used to be the legitimate domain like example from Figure A, it uses &lt;i&gt;infofuiwzuo@dhl.com &lt;/i&gt;which the user may believe that is actually from a DHL specially if the user who receives this email attack really waiting for a parcel from DHL.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Based on the message of the email, the attached file is a document. The truth is, it is an executable file that uses a PDF icon as shown in Figure B to fake the user that it is really a document. This is effective when the file extension is hidden. One problem is that hidden file extension is the default settings of Windows. So most users that uses this default settings has a high chance to be vulnerable in this Social Engineering attack. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://2.bp.blogspot.com/-yN7o9uFvf0I/TXi51P0_WBI/AAAAAAAAIgc/H2BKIJqTWtw/s1600/01-icon.jpg"&gt;&lt;img src="http://2.bp.blogspot.com/-yN7o9uFvf0I/TXi51P0_WBI/AAAAAAAAIgc/H2BKIJqTWtw/s400/01-icon.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5582416062558722066" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 177px; height: 31px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Figure B. The Icon&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;File Information: &lt;/div&gt;&lt;div&gt;&lt;i&gt;Filename: DHL_notification.exe&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;File size: 35,328 bytes&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;MD5: 64901CFDFB576D7C7C1D4F1F240315E2&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;SHA-1: B6C5A7D097CDCC9B71B010C7CFCEDDE6D0616E3F&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;File behavior:&lt;/div&gt;&lt;div&gt;Upon Execution it drops a copy of itself as the below filename:&lt;/div&gt;&lt;div&gt;%Application Data%\Adobe\AdobeUtil.exe&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;It attempts to create the below folders if does not exist:&lt;/div&gt;&lt;div&gt;%Application Data%\Adobe&lt;/div&gt;&lt;div&gt;%Application Data%\Adobe\plugs&lt;/div&gt;&lt;div&gt;%Application Data%\Adobe\shed&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;It also attempts to drop the below files:&lt;/div&gt;&lt;div&gt;%Application Data%\Adobe\AdobeUtil .exe&lt;/div&gt;&lt;div&gt;%Application Data%\Adobe\adb.cer&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;It attempts to create a shortcut of the copy of itself to Windows startup folder which serves as its Automatic execution technique:&lt;/div&gt;&lt;div&gt; %Startup Folder%\AdbUpd.lnk&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Note: %Startup Folder% is usually %User's Folder%\Start Menu\Programs\Startup&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;It tries to download and execute the files from the below URLs:&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;i&gt;http://62.122.73.203/548.exe - &lt;a href="http://www.threatexpert.com/report.aspx?md5=7395664374123f84b9df71334c66a69f"&gt;ThreatExpert File Analysis&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;http://d34ghqarfrgad.com/ftp/ftpplug2.dll&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;http://d34ghqarfrgad.com/lol.exe&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;http://erherg34gsafwe.com/ftp/base.bin&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/82060746239645894-1892888860101442299?l=athansj.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://athansj.blogspot.com/feeds/1892888860101442299/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://athansj.blogspot.com/2011/03/dhl-delivery-notification.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/1892888860101442299'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/1892888860101442299'/><link rel='alternate' type='text/html' href='http://athansj.blogspot.com/2011/03/dhl-delivery-notification.html' title='DHL Delivery Notification'/><author><name>Athan</name><uri>http://www.blogger.com/profile/06568460519084492565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://lh4.ggpht.com/_Cn4enf1IhOA/SXQC-SIOQKI/AAAAAAAAAX4/Uv5O02-GHlk/s720/DSC_0184.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-0njt-iU9XP0/TXi51GEz8dI/AAAAAAAAIgU/A7oZwYLQVt0/s72-c/02-email.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-82060746239645894.post-2718749861303800696</id><published>2011-03-08T04:11:00.000-08:00</published><updated>2011-03-08T05:38:53.465-08:00</updated><title type='text'>Another Facebook Likejacking Attack</title><content type='html'>&lt;div style="text-align: left;"&gt;This will be fast, if you're not familiar with Facebook likejacking, &lt;a href="http://athansj.blogspot.com/2011/03/facebook-likejacking-attack.html"&gt;please see my previous blog about it&lt;/a&gt;.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Just now, I found another site which have the facebook likejacking attack. Below is the screenshot of the site as of this writing (Figure A).&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Website: &lt;i&gt;http://video.findisuper.com/lol-dieser-frau-kann-man-keinen-wunsch-abschlagen/&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-2PCa9UMQFUE/TXYdHnktqfI/AAAAAAAAIfI/YN8SI9Mf2iU/s1600/01.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 188px;" src="http://4.bp.blogspot.com/-2PCa9UMQFUE/TXYdHnktqfI/AAAAAAAAIfI/YN8SI9Mf2iU/s400/01.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5581680804891568626" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Figue A. The Site&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Well, the same technique used from my &lt;a href="http://athansj.blogspot.com/2011/03/facebook-likejacking-attack.html"&gt;previous blog&lt;/a&gt; that contains code to make the hidden iframe  follow the mouse pointer Below is the code. &lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://4.bp.blogspot.com/-ceJI5bf_LxQ/TXYdHicpUcI/AAAAAAAAIfQ/vHbZQC4ZbGg/s1600/02.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/-ceJI5bf_LxQ/TXYdHicpUcI/AAAAAAAAIfQ/vHbZQC4ZbGg/s400/02.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5581680803515552194" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 147px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Figure B. Mouse Event&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;The interesting part is instead of using the Facebook like plugin that is usually used from the previous likejacking attack that I know, in this site, it uses a script from Facebook and a certain Facebook API&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Facebook Like Plugin (previously used):&lt;/div&gt;&lt;div style="text-align: left;"&gt;http://www.facebook.com/plugins/like.php?href=&lt;url&gt;&lt;/url&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;It uses the below code to have a hidden iframe which points to fbLike.html&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-sLBJjQmPB3I/TXYdHz6lvdI/AAAAAAAAIfY/fMr28XiGceI/s1600/03.jpg"&gt;&lt;img src="http://1.bp.blogspot.com/-sLBJjQmPB3I/TXYdHz6lvdI/AAAAAAAAIfY/fMr28XiGceI/s400/03.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5581680808204549586" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 17px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Figure C. Hidden Iframe&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;The below code from fbLike.html shows the liking of page GUI in a different way (instead of Facebook Like Plugin). This will be hidden from the site because it is loaded via hidden iframe ( from Figure C).&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://2.bp.blogspot.com/-4LN1tUhVNQQ/TXYdIJOFr8I/AAAAAAAAIfg/7s5Otvx3jv8/s1600/04.jpg"&gt;&lt;img src="http://2.bp.blogspot.com/-4LN1tUhVNQQ/TXYdIJOFr8I/AAAAAAAAIfg/7s5Otvx3jv8/s400/04.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5581680813923479490" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 100px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Figure D. fbLike.html&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;I believe they are doing this new approach to avoid detection from Security Softwares because basically, the Facebook Like plugin is easy to detect that when it is hidden and added some additional filter, it can be tagged as malicious. But this time, since it doesn't use the Facebook Like plugin, I believe it will not be detected.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Once a facebook user has been attacked by this likejacking, A message on the user's facebook wall will be posted that the user likes the page, example below:&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://1.bp.blogspot.com/-wRZb09r8HVI/TXYoth26REI/AAAAAAAAIfw/4NYcRFeLlTU/s1600/06.jpg"&gt;&lt;img src="http://1.bp.blogspot.com/-wRZb09r8HVI/TXYoth26REI/AAAAAAAAIfw/4NYcRFeLlTU/s400/06.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5581693550820213826" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 113px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Figure E. User's wall&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;If you suspect you've been infected by this attack, just go with the below link and click the UNLIKE button (note: If there's no UNLIKE button, DO NOT CLICK THE LIKE BUTTON)&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.facebook.com/plugins/like.php?href=http://video.findisuper.com/lol-dieser-frau-kann-man-keinen-wunsch-abschlagen/"&gt;http://www.facebook.com/plugins/like.php?href=http://video.findisuper.com/lol-dieser-frau-kann-man-keinen-wunsch-abschlagen/&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;When I started this blog the users that liked the page as below:&lt;/div&gt;&lt;div&gt;&lt;a href="http://2.bp.blogspot.com/-stMMf3mc9BE/TXYnGVjUjSI/AAAAAAAAIfo/-DqrqDK1b4I/s1600/05.jpg"&gt;&lt;img src="http://2.bp.blogspot.com/-stMMf3mc9BE/TXYnGVjUjSI/AAAAAAAAIfo/-DqrqDK1b4I/s400/05.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5581691777990298914" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 30px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;Upon finishing the blog, see the below stat:&lt;/div&gt;&lt;div&gt;&lt;a href="http://4.bp.blogspot.com/--g762fuT8-o/TXYp5admUFI/AAAAAAAAIf4/iVyHZT-9O8E/s1600/07.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/--g762fuT8-o/TXYp5admUFI/AAAAAAAAIf4/iVyHZT-9O8E/s400/07.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5581694854505058386" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 38px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Thanks for reading. ^_^&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/82060746239645894-2718749861303800696?l=athansj.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://athansj.blogspot.com/feeds/2718749861303800696/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://athansj.blogspot.com/2011/03/another-facebook-likejacking.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/2718749861303800696'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/2718749861303800696'/><link rel='alternate' type='text/html' href='http://athansj.blogspot.com/2011/03/another-facebook-likejacking.html' title='Another Facebook Likejacking Attack'/><author><name>Athan</name><uri>http://www.blogger.com/profile/06568460519084492565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://lh4.ggpht.com/_Cn4enf1IhOA/SXQC-SIOQKI/AAAAAAAAAX4/Uv5O02-GHlk/s720/DSC_0184.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-2PCa9UMQFUE/TXYdHnktqfI/AAAAAAAAIfI/YN8SI9Mf2iU/s72-c/01.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-82060746239645894.post-3594078068952261301</id><published>2011-03-04T02:12:00.000-08:00</published><updated>2011-03-05T17:05:30.315-08:00</updated><title type='text'>Facebook Likejacking attack</title><content type='html'>&lt;div style="text-align: left;"&gt;It’s been a while since I updated this blog. I’ve been busy in the past year so for now, I’m still finding a time to make one. ^_^&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;div style="text-align: left;"&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;I want to share with you about the likejacking attack on Facebook. Basically, the likejacking is not new. It was publicly disclosed a long time ago maybe a year or so. I noticed that most likejacking attacks are not blocked by Security companies. &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;First what is likejacking? &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p style="margin-top:4.8pt;margin-right:0in;margin-bottom:6.0pt;margin-left: 0in;line-height:18.0pt"&gt;&lt;span class="Apple-style-span"&gt;&lt;b&gt;&lt;i&gt;&lt;span style="font-size: 10pt; font-family: Arial, sans-serif; "&gt;Likejacking&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span class="apple-converted-space"&gt;&lt;i&gt;&lt;span style="font-size: 10pt; font-family: Arial, sans-serif; "&gt; &lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;i&gt;&lt;span style="font-size: 10pt; font-family: Arial, sans-serif; "&gt;is a&lt;span class="apple-converted-space"&gt; &lt;/span&gt;&lt;a href="http://en.wikipedia.org/wiki/Hacker_(computer_security)" title="Hacker (computer security)" style="background-attachment:initial; background-origin: initial;background-clip: initial;background-color:initial; background-position:initial initial;background-repeat:initial initial"&gt;&lt;span&gt;malicious technique&lt;/span&gt;&lt;/a&gt;&lt;span class="apple-converted-space"&gt; &lt;/span&gt;of tricking users of a website into posting a&lt;span class="apple-converted-space"&gt; &lt;/span&gt;&lt;a href="http://en.wikipedia.org/wiki/Facebook" style="background-attachment:initial; background-origin: initial;background-clip: initial;background-color:initial; background-position:initial initial;background-repeat:initial initial"&gt;&lt;span&gt;Facebook&lt;/span&gt;&lt;/a&gt;&lt;span class="apple-converted-space"&gt; &lt;/span&gt;status update for a site they did not intentionally mean to "like."&lt;sup id="cite_ref-Sophos_9783_0-0"&gt;&lt;a href="http://en.wikipedia.org/wiki/Likejacking#cite_note-Sophos_9783-0" style="background-attachment:initial;background-origin: initial;background-clip: initial; background-color:initial;background-position:initial initial;background-repeat: initial initial"&gt;&lt;span&gt;[1]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-top:4.8pt;margin-right:0in;margin-bottom:6.0pt;margin-left: 0in;line-height:18.0pt"&gt;&lt;i&gt;&lt;span style="font-size: 10pt; font-family: Arial, sans-serif; "&gt;&lt;span class="Apple-style-span"&gt;The term "likejacking" came from a comment posted by Corey Ballou&lt;sup id="cite_ref-corey_ballou_1-0"&gt;&lt;a href="http://en.wikipedia.org/wiki/Likejacking#cite_note-corey_ballou-1" style="background-attachment:initial;background-origin: initial;background-clip: initial; background-color:initial;background-position:initial initial;background-repeat: initial initial"&gt;&lt;span&gt;[2]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt;&lt;span class="apple-converted-space"&gt; &lt;/span&gt;in the article&lt;span class="apple-converted-space"&gt; &lt;/span&gt;&lt;span&gt;How to "Like" Anything on the Web (Safely)&lt;/span&gt;, which is one of the first documented postings explaining the possibility of malicious activity regarding Facebook's "like" button.&lt;sup id="cite_ref-readwriteweb_likejacking_2-0"&gt;&lt;a href="http://en.wikipedia.org/wiki/Likejacking#cite_note-readwriteweb_likejacking-2" style="background-attachment: initial; background-origin: initial; background-clip: initial; background-color: initial; "&gt;&lt;span&gt;[3]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;i style="mso-bidi-font-style:normal"&gt;~According to Wikipedia - &lt;a href="http://en.wikipedia.org/wiki/Likejacking"&gt;http://en.wikipedia.org/wiki/Likejacking&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;And here is the example that I found today……….&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;I found the below post from my Facebook news feed.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" align="center" style="text-align:center"&gt;&lt;a href="http://2.bp.blogspot.com/-AIMkiuUbThI/TXC835mAVzI/AAAAAAAAIdg/_-Bsxvnb3Aw/s1600/FigureA.jpg"&gt;&lt;img src="http://2.bp.blogspot.com/-AIMkiuUbThI/TXC835mAVzI/AAAAAAAAIdg/_-Bsxvnb3Aw/s400/FigureA.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5580167606851098418" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 132px; " /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p class="MsoNormal" align="center" style="text-align:center"&gt;Figure A&lt;/p&gt;&lt;p class="MsoNormal" align="center" style="text-align:center"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Clicking the link will open a new browser and go to the site &lt;i style="mso-bidi-font-style:normal"&gt;miley-respect.info&lt;/i&gt;. When I analyzed the site, it contains code that several redirections takes place as below:&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;http://miley-respect.info -redirects_to- http://www.omg-girl.info/ -redirects_to- http://www.omg-girl.info/ -redirects_to- http://jerrynoob.info/np&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Well if we think deeply there are several possible reasons why they are doing this kind of redirection chain.&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Calibri;mso-bidi-theme-font:minor-latin"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"&gt;1. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Easy to change the end point of the attack.&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Calibri;mso-bidi-theme-font:minor-latin"&gt;&lt;span style="mso-list:Ignore"&gt;2.&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Not easy to track if you only got the end point or before the end point domain.&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Calibri;mso-bidi-theme-font:minor-latin"&gt;&lt;span style="mso-list:Ignore"&gt;3.&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;And there’s much more… haha.&lt;/p&gt;&lt;p class="MsoListParagraphCxSpLast" style="text-indent:-.25in;mso-list:l0 level1 lfo1"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Then after the redirections and as of this writing, it will end up to the site &lt;i style="mso-bidi-font-style:normal"&gt;http://jerrynoob.info/np&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Below is the screenshot of the site. &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt; &lt;a href="http://4.bp.blogspot.com/-052JIWoR3kU/TXC9M7_uQzI/AAAAAAAAIdo/ecKZZg-cwRo/s1600/figureB.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/-052JIWoR3kU/TXC9M7_uQzI/AAAAAAAAIdo/ecKZZg-cwRo/s400/figureB.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5580167968273089330" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 192px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://4.bp.blogspot.com/-052JIWoR3kU/TXC9M7_uQzI/AAAAAAAAIdo/ecKZZg-cwRo/s1600/figureB.jpg"&gt;&lt;/a&gt;&lt;p class="MsoNormal" align="center" style="text-align:center"&gt;Figure B&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: left;"&gt;It is basically spoofing the Youtube. But that’s not it. What the users don’t know is the hidden agenda of this page. It has a hidden iframe that is not seen on the page using the below code:&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: left;"&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: 12px; line-height: 13px;"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: Georgia, serif; font-size: 16px; font-style: normal; line-height: normal; "&gt;&lt;a href="http://2.bp.blogspot.com/-TlpF3o1OZqs/TXDAMzJs26I/AAAAAAAAIeY/imY68UYpw1M/s1600/code1.jpg"&gt;&lt;img src="http://2.bp.blogspot.com/-TlpF3o1OZqs/TXDAMzJs26I/AAAAAAAAIeY/imY68UYpw1M/s400/code1.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5580171264433904546" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 54px; " /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: left;"&gt;If you’re not aware of this code, it basically hide the liking page of facebook example it hides the below gui:&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: left;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;div style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-rPfFEE--Eaw/TXC9T_7Bz1I/AAAAAAAAIdw/u5gnKgQfBKs/s1600/FigureC.jpg"&gt;&lt;img src="http://3.bp.blogspot.com/-rPfFEE--Eaw/TXC9T_7Bz1I/AAAAAAAAIdw/u5gnKgQfBKs/s400/FigureC.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5580168089586224978" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 314px; height: 27px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;Figure C&lt;/div&gt;&lt;p class="MsoNormal" align="center" style="text-align:center"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: left;"&gt;You will notice that this is not seen on the page (Figure A). The interesting part is the strategy use on how the user will like the page without knowing it. With regards the hidden iframe, it also contains code that the hidden iframe will follow the mouse pointer wherever it goes on the page. With this, since the user is aiming to watch the video, the user will just click the video play image and that makes clicking the hidden facebook like button (Figure C). Below is the code that does the trick on following the mouse pointer.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: left;"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: 12px; line-height: 13px; "&gt;&lt;i&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height: normal"&gt;&lt;span class="Apple-style-span"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: Georgia, serif; font-style: normal; "&gt;&lt;a href="http://4.bp.blogspot.com/-BmWNBYFEvLw/TXDANIGBsAI/AAAAAAAAIeg/HmNhsCBdRgw/s1600/code2.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/-BmWNBYFEvLw/TXDANIGBsAI/AAAAAAAAIeg/HmNhsCBdRgw/s400/code2.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5580171270055636994" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 91px; " /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Moreover, after liking the site without knowing it there will be a new post on your Facebook news feed that you liked the page.&lt;/div&gt;&lt;p class="MsoNormal" style="text-align: left;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;div style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-PD9SzuD7qa4/TXC9drxurlI/AAAAAAAAId4/wbNNzCge684/s1600/FigureD.jpg"&gt;&lt;img src="http://3.bp.blogspot.com/-PD9SzuD7qa4/TXC9drxurlI/AAAAAAAAId4/wbNNzCge684/s400/FigureD.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5580168255977205330" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 379px; height: 122px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;Figure D&lt;/div&gt;&lt;p class="MsoNormal" align="center" style="text-align:center"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: left;"&gt;In this case, your friends that saw the post that you liked the page may become interested and will do the same thing and get infected. This is like a WORM attack in Facebook that people get infected without their consent. &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: left;"&gt;Well, that’s not all. After liking it there will be a popup of some kind a verification before viewing the video. As below.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;div style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-7NOfWX8BeoM/TXC9lb_zczI/AAAAAAAAIeA/kfQDuTrDFVQ/s1600/FigureE.jpg"&gt;&lt;img src="http://3.bp.blogspot.com/-7NOfWX8BeoM/TXC9lb_zczI/AAAAAAAAIeA/kfQDuTrDFVQ/s400/FigureE.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5580168389180224306" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 195px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;Figure E&lt;/div&gt;&lt;p class="MsoNormal" align="center" style="text-align:center"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: left;"&gt;Well, most of these verifications end up getting your mobile phone number which may lead to a service subscription that charges your mobile account for money and the bad thing about it is it’s hard to unsubscribe which causes loss of money.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;a href="http://1.bp.blogspot.com/-SjXW0Jylh3s/TXC9rwqXmoI/AAAAAAAAIeI/4LhbKXhckGI/s1600/FigureF.jpg"&gt;&lt;img src="http://1.bp.blogspot.com/-SjXW0Jylh3s/TXC9rwqXmoI/AAAAAAAAIeI/4LhbKXhckGI/s400/FigureF.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5580168497806678658" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 198px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://1.bp.blogspot.com/-SjXW0Jylh3s/TXC9rwqXmoI/AAAAAAAAIeI/4LhbKXhckGI/s1600/FigureF.jpg"&gt;&lt;/a&gt;&lt;p class="MsoNormal" align="center" style="text-align:center"&gt;Figure F&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: left;"&gt;This mobile subscription is legal, but as you can see, users finding it in a malicious way. So beware!&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: left;"&gt;Another interesting part is after finishing this blog, there are more and more users liking it, yes that's means more and more facebook users are getting infected. As you can see in Figure C, when I started writing, it only has 2,619 likes. And now go on look below:&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;div style="text-align: center;"&gt;&lt;img src="http://3.bp.blogspot.com/-CDKwEqILz30/TXC90oLGqCI/AAAAAAAAIeQ/ZkRmwl9N6X4/s400/FigureG.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5580168650146883618" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 33px; color: rgb(0, 0, 238); -webkit-text-decorations-in-effect: underline; " /&gt;&lt;/div&gt;&lt;div&gt;Figure G&lt;/div&gt;&lt;p class="MsoNormal" align="center" style="text-align:center"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: left;"&gt;Let see how it goes.&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: left;"&gt;I believe there's more into this attack that myself is missing. Well, as of now, this is all I have. &lt;/p&gt;&lt;p class="MsoNormal" style="text-align: left;"&gt;BTW, If you think you are infected by this FB likejacking and want to remove the Facebook post from your news feed, go to the below URLs and click the Unlike button (&lt;i&gt;Note: if you're not seeing the Unlike button just leave the page and DO NOT CLICK THE LIKE BUTTON&lt;/i&gt;):&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: left;"&gt;&lt;a href="http://www.facebook.com/plugins/like.php?href=http://miley-respect.info&amp;amp;layout=standard&amp;amp;show_faces=false&amp;amp;width=450&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=80"&gt;http://www.facebook.com/plugins/like.php?href=http://miley-respect.info&amp;amp;layout=standard&amp;amp;show_faces=false&amp;amp;width=450&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=80&lt;/a&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: left;"&gt;&lt;a href="http://www.facebook.com/plugins/like.php?href=http://jerrynoob.info/np/&amp;amp;layout=standard&amp;amp;show_faces=false&amp;amp;width=450&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=80"&gt;http://www.facebook.com/plugins/like.php?href=http://jerrynoob.info/np/&amp;amp;layout=standard&amp;amp;show_faces=false&amp;amp;width=450&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=80&lt;/a&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: left;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: left;"&gt;Thanks for reading. ^_^&lt;/p&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;====================================&lt;/div&gt;&lt;div style="text-align: left;"&gt;Update - March 4, 2011 4:58 AM PST&lt;/div&gt;&lt;div style="text-align: left;"&gt;See below, after couple of hours more and more FB users were infected.....&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://4.bp.blogspot.com/-27-fRfqUL6s/TXDh3IyZS0I/AAAAAAAAIeo/8-1Qit_gPTI/s1600/5am.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/-27-fRfqUL6s/TXDh3IyZS0I/AAAAAAAAIeo/8-1Qit_gPTI/s400/5am.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5580208275679955778" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 37px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;div style="text-align: left; "&gt;====================================&lt;/div&gt;&lt;div style="text-align: left; "&gt;Update - March 4, 2011 4:45 PM PST&lt;/div&gt;&lt;div style="text-align: left; "&gt;See below, again more and more FB users getting infected.....&lt;/div&gt;&lt;div&gt;&lt;a href="http://1.bp.blogspot.com/-VlgMvjd5r4M/TXGHzNL5xLI/AAAAAAAAIew/Yt87kj6olAM/s1600/4pm.jpg"&gt;&lt;img src="http://1.bp.blogspot.com/-VlgMvjd5r4M/TXGHzNL5xLI/AAAAAAAAIew/Yt87kj6olAM/s400/4pm.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5580390727071417522" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 46px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="text-align: left; "&gt;====================================&lt;/div&gt;&lt;div style="text-align: left; "&gt;Update - March 5, 2011 2:45 AM PST&lt;/div&gt;&lt;div style="text-align: left; "&gt;See below, Sigh... more and more FB users getting infected.....&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://1.bp.blogspot.com/-MGWupfXeFDI/TXIUYK7kU0I/AAAAAAAAIe4/2Y0EEZh2Vy4/s1600/245am.jpg"&gt;&lt;img src="http://1.bp.blogspot.com/-MGWupfXeFDI/TXIUYK7kU0I/AAAAAAAAIe4/2Y0EEZh2Vy4/s400/245am.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5580545293749080898" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 41px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="text-align: left; "&gt;====================================&lt;/div&gt;&lt;div style="text-align: left; "&gt;Update - March 5, 2011 1:18 PM PST&lt;/div&gt;&lt;/div&gt;&lt;div&gt;No need to worry about it anymore, the site is now blocked by Facebok.&lt;/div&gt;&lt;div&gt;&lt;a href="http://1.bp.blogspot.com/-mrHDGBvMo-Y/TXKpFFPAbHI/AAAAAAAAIfA/ioxJXlY4s6w/s1600/unavailable.jpg"&gt;&lt;img src="http://1.bp.blogspot.com/-mrHDGBvMo-Y/TXKpFFPAbHI/AAAAAAAAIfA/ioxJXlY4s6w/s400/unavailable.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5580708793035025522" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 120px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;Thank you for sharing this blog with your friends and for your comments. ^_^ &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left; "&gt;&lt;a href="http://4.bp.blogspot.com/-27-fRfqUL6s/TXDh3IyZS0I/AAAAAAAAIeo/8-1Qit_gPTI/s1600/5am.jpg"&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/82060746239645894-3594078068952261301?l=athansj.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://athansj.blogspot.com/feeds/3594078068952261301/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://athansj.blogspot.com/2011/03/facebook-likejacking-attack.html#comment-form' title='15 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/3594078068952261301'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/3594078068952261301'/><link rel='alternate' type='text/html' href='http://athansj.blogspot.com/2011/03/facebook-likejacking-attack.html' title='Facebook Likejacking attack'/><author><name>Athan</name><uri>http://www.blogger.com/profile/06568460519084492565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://lh4.ggpht.com/_Cn4enf1IhOA/SXQC-SIOQKI/AAAAAAAAAX4/Uv5O02-GHlk/s720/DSC_0184.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-AIMkiuUbThI/TXC835mAVzI/AAAAAAAAIdg/_-Bsxvnb3Aw/s72-c/FigureA.jpg' height='72' width='72'/><thr:total>15</thr:total></entry><entry><id>tag:blogger.com,1999:blog-82060746239645894.post-6568504144810969612</id><published>2009-12-25T06:11:00.000-08:00</published><updated>2010-01-01T13:29:35.829-08:00</updated><title type='text'>We've got FakeAV during Christmas</title><content type='html'>Just found another popular FakeAV malware that is not yet detected by most AV vendors.&lt;br /&gt;&lt;br /&gt;File information:&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;Filename: Start.exe&lt;/span&gt;&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;File size: 250,624 bytes&lt;/span&gt; &lt;span style="FONT-STYLE: italic"&gt;&lt;br /&gt;MD5: A0B4084581CD7C00C078532201CA1A14&lt;/span&gt;&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;SHA1: BD040DA889DA8333AE66C60B48B3E2951066834C&lt;/span&gt; &lt;span style="FONT-STYLE: italic"&gt;&lt;br /&gt;CRC-32: 4379A7A9&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Upon execution, this FakeAV malware creates a random folder in Application Data folder of the current user, then it drops a copy of itself to the created random folder using a filename with 4 random characters plus the name "sysguard.exe"&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;Example: C:\Documents and Settings\winuser\Local Settings\Application Data\cdauwq\hfbesysguard.exe&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;It creates the following autostart registry:&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt; &lt;span style="FONT-STYLE: italic"&gt;&lt;br /&gt;{random characters} = {Malware dropped path and filename}&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;example:&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt; &lt;span style="FONT-STYLE: italic"&gt;&lt;br /&gt;bryeqfww = "C:\Documents and Settings\winuser\Local Settings\Application Data\cdauwq\hfbesysguard.exe"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This malware will then display the following message from windows taskbar.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Cn4enf1IhOA/SzTJsuhxwFI/AAAAAAAAICM/udNpc6bQNjk/s1600-h/01.JPG"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 393px; DISPLAY: block; HEIGHT: 127px; CURSOR: pointer" id="BLOGGER_PHOTO_ID_5419178021874679890" border="0" alt="" src="http://2.bp.blogspot.com/_Cn4enf1IhOA/SzTJsuhxwFI/AAAAAAAAICM/udNpc6bQNjk/s400/01.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;It will then display a fake Antivirus software scanning in the affected computer.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Cn4enf1IhOA/SzTJ6zaslYI/AAAAAAAAICU/T6kymnBvOt8/s1600-h/02.JPG"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 257px; CURSOR: pointer" id="BLOGGER_PHOTO_ID_5419178263705326978" border="0" alt="" src="http://2.bp.blogspot.com/_Cn4enf1IhOA/SzTJ6zaslYI/AAAAAAAAICU/T6kymnBvOt8/s400/02.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;It also displays a warning message indicating that the affected computer is infected.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Cn4enf1IhOA/SzTKD-FpxCI/AAAAAAAAICc/JBSH_AY6Jrg/s1600-h/03.JPG"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 120px; CURSOR: pointer" id="BLOGGER_PHOTO_ID_5419178421188674594" border="0" alt="" src="http://3.bp.blogspot.com/_Cn4enf1IhOA/SzTKD-FpxCI/AAAAAAAAICc/JBSH_AY6Jrg/s400/03.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;Clicking the button "Yes, remove threats" will display the following&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Cn4enf1IhOA/SzTKEauxxcI/AAAAAAAAICk/Qvf_BzaUGfE/s1600-h/04.JPG"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 277px; CURSOR: pointer" id="BLOGGER_PHOTO_ID_5419178428877358530" border="0" alt="" src="http://1.bp.blogspot.com/_Cn4enf1IhOA/SzTKEauxxcI/AAAAAAAAICk/Qvf_BzaUGfE/s400/04.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;Clicking on the "Activate your Antivirus Software" will open an internet explorer that leads to the following url that makes you order the Fake Antivirus using a credit card transaction:&lt;br /&gt;hxxp://platinum-soft.net/purchase?r=%Version%&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;note: %Version% is the version of the FakeAV malware.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Cn4enf1IhOA/SzTKE25TavI/AAAAAAAAIC0/Mb_XuOiC6gQ/s1600-h/06.JPG"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 223px; CURSOR: pointer" id="BLOGGER_PHOTO_ID_5419178436437699314" border="0" alt="" src="http://1.bp.blogspot.com/_Cn4enf1IhOA/SzTKE25TavI/AAAAAAAAIC0/Mb_XuOiC6gQ/s400/06.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;This malware may also display the following image:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Cn4enf1IhOA/SzTKEqq2rGI/AAAAAAAAICs/XbBVcpJd3zQ/s1600-h/05.JPG"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 285px; DISPLAY: block; HEIGHT: 280px; CURSOR: pointer" id="BLOGGER_PHOTO_ID_5419178433155869794" border="0" alt="" src="http://3.bp.blogspot.com/_Cn4enf1IhOA/SzTKEqq2rGI/AAAAAAAAICs/XbBVcpJd3zQ/s400/05.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This malware is capable of stopping and terminating processes that is executed in the affected computer. Once the user executed any file, it will display a message indicating that process is infected.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Cn4enf1IhOA/SzTKFfVSVhI/AAAAAAAAIC8/rVJkd78AxCI/s1600-h/07.JPG"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 382px; DISPLAY: block; HEIGHT: 118px; CURSOR: pointer" id="BLOGGER_PHOTO_ID_5419178447292487186" border="0" alt="" src="http://2.bp.blogspot.com/_Cn4enf1IhOA/SzTKFfVSVhI/AAAAAAAAIC8/rVJkd78AxCI/s400/07.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;This malware may open Internet Explorer to visit 1 of the following url:&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;-platinum-soft.net&lt;br /&gt;-platinum-soft.microsoft.com&lt;br /&gt;-91.212.127.236&lt;br /&gt;-193.169.13.12&lt;br /&gt;-www.viagra.com&lt;br /&gt;-www.porno.org&lt;br /&gt;-www.porno.com&lt;br /&gt;-www.adult.com&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This FakeAV malware also capable of removing files, services, registries and processes which are related to real malwares.&lt;br /&gt;It kills processes and delete its file that contains the following process names:&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;pp1_.exe&lt;br /&gt;ld__.exe&lt;br /&gt;freddy__.exe&lt;br /&gt;SYSDLL.exe&lt;br /&gt;%sysroot%\DSSAGENT.EXE&lt;br /&gt;regsvr32.exe&lt;br /&gt;dhcp\svchost.exe&lt;br /&gt;regsvr32.exe&lt;br /&gt;dhcp\svchost.exe&lt;br /&gt;%System%\sopidkc.exe&lt;br /&gt;reader_s.exe&lt;br /&gt;antit.exe&lt;br /&gt;Temp\spoolsv.exe&lt;br /&gt;Temp\csrss.exe&lt;br /&gt;Temp\services.exe&lt;br /&gt;nksmnz.exe&lt;br /&gt;CSmileysIM&lt;br /&gt;xpdeluxe.exe&lt;br /&gt;fbtre_.exe&lt;br /&gt;fbtre__.exe&lt;br /&gt;mstre__.exe&lt;br /&gt;mstre_.exe&lt;br /&gt;braviax.exe&lt;br /&gt;AntiVirus_Pro.exe&lt;br /&gt;pav.exe&lt;br /&gt;NetFilter.exe&lt;br /&gt;gamevance32.exe&lt;br /&gt;wmsdkns.exe&lt;br /&gt;gav.exe&lt;br /&gt;SiteRankTray.exe&lt;br /&gt;RegMech.exe&lt;br /&gt;pctsGui.exe&lt;br /&gt;pctsTray.exe&lt;br /&gt;pctsAuxs.exe&lt;br /&gt;WindOptimizer.exe&lt;br /&gt;mdmcls32.exe&lt;br /&gt;cfgmng32.exe&lt;br /&gt;hpoopm__.exe&lt;br /&gt;m3SrchMn.exe&lt;br /&gt;mwsoemon.exe&lt;br /&gt;ALCXMNTR.EXE&lt;br /&gt;PC_Antispyware2010.exe&lt;br /&gt;gamevance32.exe&lt;br /&gt;gamevance32.exe&lt;br /&gt;psystem.exe&lt;br /&gt;tsc.exe&lt;br /&gt;AntivirusPro_2010.exe&lt;br /&gt;rlvknlg.exe&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Removing the following services:&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;dhcpsrv&lt;br /&gt;sopidkc&lt;br /&gt;pctsSvc.exe&lt;br /&gt;sdAuxService&lt;br /&gt;sdAuxService&lt;br /&gt;sdCoreService&lt;br /&gt;websrvx.exe&lt;br /&gt;MyWebSearchService&lt;br /&gt;mwssvc.exe&lt;br /&gt;WinSvchostManager&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;deletes the following files:&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;%Startup folder%\ChkDisk.dll&lt;br /&gt;%Startup folder%\ChkDisk.lnk&lt;br /&gt;MWSOEMON.EXE&lt;br /&gt;%System%\wmsdkns.exe&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Deletes the following registry key:&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;HKLM\SOFTWARE\AntivirusPro_2010&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;deletes the following registry values:&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;HKCU\Control Panel\dont load "scui.cpl"&lt;br /&gt;HKCU\Control Panel\dont load "wscui.cpl"&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "AppInit_DLLs"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Removes Browser Helper Object (BHO) with following CLSIDs:&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;{00000250-0320-4dd4-be4f-7566d2314352}&lt;br /&gt;{00A6FAF1-072E-44cf-8957-5838F569A31D}&lt;br /&gt;{07B18EA1-A523-4961-B6BB-170DE4475CCA}&lt;br /&gt;{100EB1FD-D03E-47FD-81F3-EE91287F9465}&lt;br /&gt;{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}&lt;br /&gt;{13197ace-6851-45c3-a7ff-c281324d5489}&lt;br /&gt;{15421B84-3488-49A7-AD18-CBF84A3EFAF6}&lt;br /&gt;{15651c7c-e812-44a2-a9ac-b467a2233e7d}&lt;br /&gt;{2BA1C226-EC1B-4471-A65F-D0688AC6EE3A}&lt;br /&gt;{332BE9D8-025A-452e-BF78-A077F9D3F84A}&lt;br /&gt;{37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8}&lt;br /&gt;{38101cce-5999-48eb-815b-d942e1f715c6}&lt;br /&gt;{3937DEA7-2769-ADDF-B533-20E7D249A547}&lt;br /&gt;{4D25F921-B9FE-4682-BF72-8AB8210D6D75}&lt;br /&gt;{4e1075f4-eec4-4a86-add7-cd5f52858c31}&lt;br /&gt;{4E3A97D3-9F15-4067-D0F9-241CC9CC9541}&lt;br /&gt;{4e7bd74f-2b8d-469e-92c6-ce7eb590a94d}&lt;br /&gt;{500BCA15-57A7-4eaf-8143-8C619470B13D}&lt;br /&gt;{547395D9-934A-CED6-B851-F238C86079E5}&lt;br /&gt;{549B5CA7-4A86-11D7-A4DF-000874180BB3}&lt;br /&gt;{5929cd6e-2062-44a4-b2c5-2c7e78fbab38}&lt;br /&gt;{5C255C8A-E604-49b4-9D64-90988571CECB}&lt;br /&gt;{5dafd089-24b1-4c5e-bd42-8ca72550717b}&lt;br /&gt;{5E5EFA8F-9F53-418E-B78E-44866667A404}&lt;br /&gt;{5fa6752a-c4a0-4222-88c2-928ae5ab4966}&lt;br /&gt;{622cc208-b014-4fe0-801b-874a5e5e403a}&lt;br /&gt;{63F7460B-C831-4142-A4AA-5EC303EC4343}&lt;br /&gt;{6c517f1e-249d-b518-be84-9995ecc10183}&lt;br /&gt;{70FEAD04-A7FD-4B89-B814-8A8251C90EF7}&lt;br /&gt;{7E853D72-626A-48EC-A868-BA8D5E23E045}&lt;br /&gt;{85661731-3340-E784-488A-D053E986CF73}&lt;br /&gt;{8674aea0-9d3d-11d9-99dc-00600f9a01f1}&lt;br /&gt;{873D5AB4-47F5-401F-B9E0-B14A65D2BB53}&lt;br /&gt;{965a592f-8efa-4250-8630-7960230792f1}&lt;br /&gt;{9c5b2f29-1f46-4639-a6b4-828942301d3e}&lt;br /&gt;{A3BC75A2-1F87-4686-AA43-5347D756017C}&lt;br /&gt;{A57EE9D7-0534-496A-B2B0-E95866D0C1B0}&lt;br /&gt;{A7327C09-B521-4EDB-8509-7D2660C9EC98}&lt;br /&gt;{A77D3539-581D-450C-9E44-A84C415A6172}&lt;br /&gt;{AAAE832A-5FFF-4661-9C8F-369692D1DCB9}&lt;br /&gt;{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}&lt;br /&gt;{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}&lt;br /&gt;{C5428486-50A0-4a02-9D20-520B59A9F9B2}&lt;br /&gt;{C5428486-50A0-4a02-9D20-520B59A9F9B3}&lt;br /&gt;{c6c7b2a1-00f3-42bd-f434-00aaba2c8953}&lt;br /&gt;{CCC7A320-B3CA-4199-B1A6-9F516DD69829}&lt;br /&gt;{cf021f40-3e14-23a5-cba2-717765728274}&lt;br /&gt;{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}&lt;br /&gt;{fc3a74e5-f281-4f10-ae1e-733078684f3c}&lt;br /&gt;{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}&lt;br /&gt;{ffff0001-0002-101a-a3c9-08002b2f49fb}&lt;br /&gt;{02478D38-C3F9-4efb-9B51-7695ECA05670}&lt;br /&gt;{35B8D58C-B0CB-46b0-BA64-05B3804E4E86}&lt;br /&gt;{CDBFB47B-58A8-4111-BF95-06178DCE326D}&lt;br /&gt;{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}&lt;br /&gt;{07B18EA9-A523-4961-B6BB-170DE4475CCA}&lt;br /&gt;{0ED403E8-470A-4a8a-85A4-D7688CFE39A3}&lt;br /&gt;{4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22}&lt;br /&gt;{BEAC7DC8-E106-4C6A-931E-5A42E7362883}&lt;br /&gt;{CB0D163C-E9F4-4236-9496-0597E24B23A5}&lt;br /&gt;{DBC80044-A445-435b-BC74-9C25C1C588A9}&lt;br /&gt;{F64619FF-E19F-4016-BF9C-147CFF821B46}&lt;br /&gt;{14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6}&lt;br /&gt;{201f27d4-3704-41d6-89c1-aa35e39143ed}&lt;br /&gt;{ee57e883-3ec3-b6db-9f84-3122750c3c02}&lt;br /&gt;{20c3c057-2213-48f9-bd6b-3ce3388e75ee}&lt;br /&gt;{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}&lt;br /&gt;{CC3CD2A8-2892-4CC4-A30F-E25921AC65C0}&lt;br /&gt;{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}&lt;br /&gt;{5CA3D70E-1895-11CF-8E15-001234567890}&lt;br /&gt;{BA603215-23F2-42AD-F4E4-00AAC39CAA53}&lt;br /&gt;{E8DAAA30-6CAA-4b58-9603-8E54238219E2}&lt;br /&gt;{21608B66-026F-4DCB-9244-0DACA328DCED}&lt;br /&gt;{A5DBD8CB-DF8A-4992-A655-B155216F6AFB}&lt;br /&gt;{D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A}&lt;br /&gt;{3041d03e-fd4b-44e0-b742-2d9b88305f98}&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Although this FakeAV malware has capabilities to remove real malwares (which a real Antivirus capabilities), it still poses a fake infection report to the affected computer and asking the user to buy the software product to remove the threats in which may only expose Personal and Credit Card information to the malware writer.&lt;br /&gt;&lt;br /&gt;As of this writing (12/26/2009), this FakeAV sample that was found is not yet detected by most legitimate Antivirus software (please click the image below). So beware.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Cn4enf1IhOA/SzTPJGE1yRI/AAAAAAAAIDE/PIi3dW9WlmU/s1600-h/virustotal.JPG"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 223px; DISPLAY: block; HEIGHT: 400px; CURSOR: pointer" id="BLOGGER_PHOTO_ID_5419184006790236434" border="0" alt="" src="http://4.bp.blogspot.com/_Cn4enf1IhOA/SzTPJGE1yRI/AAAAAAAAIDE/PIi3dW9WlmU/s400/virustotal.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Removal instructions:&lt;br /&gt;1. Open the Search companion by pressing "Windows Start key+F" or Ctrl+F in my computer&lt;br /&gt;2. In the search companion, click on the All files and folders&lt;br /&gt;3. In the "Look in", browse for %root%\Documents and settings&lt;br /&gt;4. Then click on the More advanced options and check the box "Search hidden files and folders"&lt;br /&gt;5. Type the following string to the "All or part of the file name" text box:&lt;br /&gt;&lt;span style="FONT-STYLE: italic; FONT-WEIGHT: bold"&gt;*sysguard.exe&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Cn4enf1IhOA/SzTgJ6QuuqI/AAAAAAAAIDM/-xwTNCIf080/s1600-h/removal-01.JPG"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 248px; DISPLAY: block; HEIGHT: 354px; CURSOR: pointer" id="BLOGGER_PHOTO_ID_5419202712496421538" border="0" alt="" src="http://4.bp.blogspot.com/_Cn4enf1IhOA/SzTgJ6QuuqI/AAAAAAAAIDM/-xwTNCIf080/s400/removal-01.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;6. Then click search.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Cn4enf1IhOA/SzTgKALpsQI/AAAAAAAAIDU/77XRKhA6qEo/s1600-h/removal-02.JPG"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 283px; CURSOR: pointer" id="BLOGGER_PHOTO_ID_5419202714085732610" border="0" alt="" src="http://4.bp.blogspot.com/_Cn4enf1IhOA/SzTgKALpsQI/AAAAAAAAIDU/77XRKhA6qEo/s400/removal-02.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;7. Once found, note the malware path and filename and rename the file to any filename.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Cn4enf1IhOA/SzTgKbWVzLI/AAAAAAAAIDc/rR3P3I_74js/s1600-h/removal-03.JPG"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 286px; CURSOR: pointer" id="BLOGGER_PHOTO_ID_5419202721378323634" border="0" alt="" src="http://1.bp.blogspot.com/_Cn4enf1IhOA/SzTgKbWVzLI/AAAAAAAAIDc/rR3P3I_74js/s400/removal-03.JPG" /&gt;&lt;/a&gt;8. Restart the computer (or you can logoff and logon so that services will not stop)&lt;br /&gt;9. After restart (or relogon) browse for the renamed malware file, and delete it.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Cn4enf1IhOA/SzTgKtbgSCI/AAAAAAAAIDk/0G1d2cXbMeU/s1600-h/removal-04.JPG"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 284px; CURSOR: pointer" id="BLOGGER_PHOTO_ID_5419202726231820322" border="0" alt="" src="http://1.bp.blogspot.com/_Cn4enf1IhOA/SzTgKtbgSCI/AAAAAAAAIDk/0G1d2cXbMeU/s400/removal-04.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;10. To remove the autostart registry, open registry editor or execute regedt32.exe&lt;br /&gt;11. In the left panel, browse for the following registry entry:&lt;br /&gt;&lt;span style="FONT-STYLE: italic; FONT-WEIGHT: bold"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;br /&gt;12. In the right panel, locate the data with the same as the noted malware path and filename.&lt;br /&gt;13. Delete the registry value once found.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Cn4enf1IhOA/SzTgK1VwB4I/AAAAAAAAIDs/PX5PvPCOp74/s1600-h/removal-05.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 206px; CURSOR: pointer" id="BLOGGER_PHOTO_ID_5419202728355170178" border="0" alt="" src="http://2.bp.blogspot.com/_Cn4enf1IhOA/SzTgK1VwB4I/AAAAAAAAIDs/PX5PvPCOp74/s400/removal-05.jpg" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/82060746239645894-6568504144810969612?l=athansj.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://athansj.blogspot.com/feeds/6568504144810969612/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://athansj.blogspot.com/2009/12/weve-got-fakeav-during-christmas.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/6568504144810969612'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/6568504144810969612'/><link rel='alternate' type='text/html' href='http://athansj.blogspot.com/2009/12/weve-got-fakeav-during-christmas.html' title='We&apos;ve got FakeAV during Christmas'/><author><name>Athan</name><uri>http://www.blogger.com/profile/06568460519084492565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://lh4.ggpht.com/_Cn4enf1IhOA/SXQC-SIOQKI/AAAAAAAAAX4/Uv5O02-GHlk/s720/DSC_0184.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Cn4enf1IhOA/SzTJsuhxwFI/AAAAAAAAICM/udNpc6bQNjk/s72-c/01.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-82060746239645894.post-2214302044220937818</id><published>2009-12-08T05:49:00.000-08:00</published><updated>2010-01-01T13:28:39.013-08:00</updated><title type='text'>Online Video leads to FakeAV malware.</title><content type='html'>I Just found a popular FakeAV malware from a certain site while browsing and searching for some anime series on the internet. When visiting the host site of the FakeAV malware, it will prompt you to install a fake Video ActiveX Object.&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;div&gt;&lt;div&gt;&lt;div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 287px" id="BLOGGER_PHOTO_ID_5412862360738926082" border="0" alt="" src="http://1.bp.blogspot.com/_Cn4enf1IhOA/Sx5Zo3XtDgI/AAAAAAAAIAs/XvsJ1DJ3Se4/s400/image1.JPG" /&gt;&lt;br /&gt;Clicking the continue button will download the FakeAV Malware. This FakeAV malware will come with the filename "install.exe".&lt;br /&gt;File information:&lt;br /&gt;Filename: install.exe&lt;br /&gt;file size: 1,255,489 bytes&lt;br /&gt;MD5: 6D4DCF6FAC03E32D6C26A8AF7FC9A060&lt;br /&gt;SHA1: 9A45F91A2DDCD295472736E3C4B5C5F17541CF67&lt;br /&gt;CRC-32: 372C2196&lt;br /&gt;&lt;br /&gt;Once you download and execute the install.exe from the said site, it will pop up the following message box:&lt;br /&gt;&lt;br /&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 243px; DISPLAY: block; HEIGHT: 119px" id="BLOGGER_PHOTO_ID_5412862366938900386" border="0" alt="" src="http://2.bp.blogspot.com/_Cn4enf1IhOA/Sx5ZpOd5J6I/AAAAAAAAIA0/QfR-s2zGG1E/s400/pop+up+window.JPG" /&gt;&lt;br /&gt;During execution, this FakeAV malware will create a random folder in the following folder:&lt;br /&gt;%root%:\Documents and Settings\All Users\Application Data\&lt;br /&gt;&lt;br /&gt;then, it will drop a copy of itself with a random filename in the created folder.&lt;br /&gt;(example: C:\Documents and Settings\All Users\Application Data\23572019\23572019.exe)&lt;br /&gt;&lt;br /&gt;Then it will create the following autostart registries:&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;%random% = "%FakeAV path and Filename%"&lt;/span&gt;&lt;br /&gt;(example: 23572019 = "C:\DOCUME~1\ALLUSE~1\APPLIC~1\23572019\23572019.exe")&lt;br /&gt;&lt;br /&gt;It will also create the following registry entry:&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\%random%&lt;/span&gt;&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;FirstRun = hex:%random%&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This FakeAV malware will then display a Fake scanning of Security tool.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_Cn4enf1IhOA/Sx5aMQHFQjI/AAAAAAAAIBk/szPdofh7Ui0/s1600-h/close.JPG"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 297px" id="BLOGGER_PHOTO_ID_5412862369688852322" border="0" alt="" src="http://4.bp.blogspot.com/_Cn4enf1IhOA/Sx5ZpYtiF2I/AAAAAAAAIA8/EmZMS-_0Z6k/s400/fakeav.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;If you close the fake Security tool window, it will display a message with an icon from the taskbar.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_Cn4enf1IhOA/Sx5aMQHFQjI/AAAAAAAAIBk/szPdofh7Ui0/s1600-h/close.JPG"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 364px; DISPLAY: block; HEIGHT: 112px" id="BLOGGER_PHOTO_ID_5412862968675516978" border="0" alt="" src="http://3.bp.blogspot.com/_Cn4enf1IhOA/Sx5aMQHFQjI/AAAAAAAAIBk/szPdofh7Ui0/s400/close.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;Once the fake scanning is finish, it will display a window that shows your system is infected by several malwares.&lt;br /&gt;&lt;br /&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 337px" id="BLOGGER_PHOTO_ID_5412862372019243906" border="0" alt="" src="http://4.bp.blogspot.com/_Cn4enf1IhOA/Sx5ZphZJC4I/AAAAAAAAIBE/_D-q52jTUJ8/s400/fakeav2.JPG" /&gt;&lt;br /&gt;Clicking the "Remove all threats now" will display a window to activate this Fake Security tool.&lt;br /&gt;&lt;br /&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 275px" id="BLOGGER_PHOTO_ID_5412862382898139122" border="0" alt="" src="http://4.bp.blogspot.com/_Cn4enf1IhOA/Sx5ZqJ63z_I/AAAAAAAAIBM/5BIrqP_BYYU/s400/fakeav3.JPG" /&gt;&lt;br /&gt;If you click to activate this Fake Security tool, it will connect to 1 of the following site to display a payment method on activating this fake Security tool:&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;1. hxxp://invoicefish.com/buy2.php?affid=33220&lt;/span&gt; &lt;span style="FONT-STYLE: italic"&gt;&lt;br /&gt;2. hxxp://invoiceerica.com/buy2.php?affid=33220&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 300px" id="BLOGGER_PHOTO_ID_5412862965320033474" border="0" alt="" src="http://1.bp.blogspot.com/_Cn4enf1IhOA/Sx5aMDnEpMI/AAAAAAAAIBc/tX6TUzP3Pc4/s400/fakeav4.JPG" /&gt;&lt;br /&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 300px" id="BLOGGER_PHOTO_ID_5412862963442715586" border="0" alt="" src="http://3.bp.blogspot.com/_Cn4enf1IhOA/Sx5aL8nfC8I/AAAAAAAAIBU/aMRq0wb0G-8/s400/fakeav5.JPG" /&gt;&lt;br /&gt;Providing your credit card information is the same as giving it to the hacker.&lt;br /&gt;&lt;br /&gt;Additional behavior&lt;br /&gt;This FakeAV malware is also capable of dropping of shortcut in windows desktop with filename "Security Tool.lnk". This shortcut points to the dropped malware file.&lt;br /&gt;&lt;br /&gt;It also modify the following registry value to change the wallpaper of the infected machine:&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="FONT-STYLE: italic"&gt;HKEY_CURRENT_USER\Control Panel\Desktop&lt;/span&gt;&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;From: &lt;/span&gt;&lt;span style="FONT-STYLE: italic"&gt;Wallpaper &lt;/span&gt;&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;To: &lt;/span&gt;&lt;span style="FONT-STYLE: italic"&gt;_Wallpaper&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;It is also capable of connecting to the following site:&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;hxxp://yourprotectiongroup.com/in.php?affid=33220&amp;amp;url=5&amp;amp;win=&lt;span style="FONT-WEIGHT: bold"&gt;%windows version%&lt;/span&gt;+%FakeAVversion%&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;where &lt;span style="FONT-STYLE: italic"&gt;%windows version%&lt;/span&gt; is 1 of the following which depends on the affected system:&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;-Unknown&lt;/span&gt; &lt;span style="FONT-STYLE: italic"&gt;&lt;br /&gt;-Windows NT 3&lt;/span&gt; &lt;span style="FONT-STYLE: italic"&gt;&lt;br /&gt;-Windows NT 4&lt;/span&gt; &lt;span style="FONT-STYLE: italic"&gt;&lt;br /&gt;-Windows 95&lt;/span&gt; &lt;span style="FONT-STYLE: italic"&gt;&lt;br /&gt;-Windows 98&lt;/span&gt; &lt;span style="FONT-STYLE: italic"&gt;&lt;br /&gt;-Windows ME&lt;/span&gt; &lt;span style="FONT-STYLE: italic"&gt;&lt;br /&gt;-Windows 2000&lt;/span&gt; &lt;span style="FONT-STYLE: italic"&gt;&lt;br /&gt;-Windows XP&lt;/span&gt; &lt;span style="FONT-STYLE: italic"&gt;&lt;br /&gt;-Windows 2003&lt;/span&gt; &lt;span style="FONT-STYLE: italic"&gt;&lt;br /&gt;-Windows Vista&lt;/span&gt; &lt;span style="FONT-STYLE: italic"&gt;&lt;br /&gt;-Windows Seven&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Connection to the said site will report the version of windows OS and the FakeAV installed in the affected system to the malicious site. As of this writing (12/9/2009), the &lt;span style="FONT-STYLE: italic"&gt;in.php&lt;/span&gt; contains code that may update a copy of the FakeAV malware by connecting to the following site:&lt;br /&gt;&lt;span style="FONT-STYLE: italic"&gt;hxxp://yourprotectiongroup.com/downloader.php?affid=00000&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;It also contains code that may display another fake infection report.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Cn4enf1IhOA/Sx7qCag0uhI/AAAAAAAAICE/AegM79eSHwY/s1600-h/alert.gif"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 306px; CURSOR: pointer" id="BLOGGER_PHOTO_ID_5413021129343547922" border="0" alt="" src="http://2.bp.blogspot.com/_Cn4enf1IhOA/Sx7qCag0uhI/AAAAAAAAICE/AegM79eSHwY/s400/alert.gif" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is a technique by the malware writers to expose your user and credit card information.&lt;br /&gt;Also, As of this writing (12/8/2009), this FakeAV sample that I found is not yet detected by most legitimate Antivirus software (please click the image below). So beware.&lt;br /&gt;&lt;br /&gt;&lt;div style="TEXT-ALIGN: center"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Cn4enf1IhOA/Sx5l7qbKVnI/AAAAAAAAIB8/yZUJhj4dEWg/s1600-h/AV.JPG"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 182px; DISPLAY: block; HEIGHT: 400px; CURSOR: pointer" id="BLOGGER_PHOTO_ID_5412875877820814962" border="0" alt="" src="http://1.bp.blogspot.com/_Cn4enf1IhOA/Sx5l7qbKVnI/AAAAAAAAIB8/yZUJhj4dEWg/s400/AV.JPG" /&gt;&lt;/a&gt;&lt;a href="http://www.virustotal.com/analisis/9c2093ae8ac71c2fc3a82ca08995a0ee30b458eb7c2337dd435979e308362cbe-1260282624"&gt;Click here for the original scan result&lt;/a&gt;&lt;br /&gt;&lt;div style="TEXT-ALIGN: left"&gt;&lt;br /&gt;[12/9/2009 updates]&lt;br /&gt;Another downloaded file that is not yet detected by most legitimate Antivirus software&lt;br /&gt;File information:&lt;br /&gt;Filename: install.exe&lt;br /&gt;file size: 1,256,001 bytes&lt;br /&gt;MD5: A8005F760480B1B7F20D2EEC30C7FF80&lt;br /&gt;SHA1: 9DFC5084A749210FD76840DE49C376517FC34543&lt;br /&gt;CRC-32: 7B203701&lt;span style="TEXT-DECORATION: underline"&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/11a6d9b3f28e91a407563a616745ad14deb006bb89cacebefcaa59ae23e3adeb-1260317489"&gt;Click here for the scan result.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/82060746239645894-2214302044220937818?l=athansj.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://athansj.blogspot.com/feeds/2214302044220937818/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://athansj.blogspot.com/2009/12/video-codecs-points-to-fake-av-malware.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/2214302044220937818'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/2214302044220937818'/><link rel='alternate' type='text/html' href='http://athansj.blogspot.com/2009/12/video-codecs-points-to-fake-av-malware.html' title='Online Video leads to FakeAV malware.'/><author><name>Athan</name><uri>http://www.blogger.com/profile/06568460519084492565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://lh4.ggpht.com/_Cn4enf1IhOA/SXQC-SIOQKI/AAAAAAAAAX4/Uv5O02-GHlk/s720/DSC_0184.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Cn4enf1IhOA/Sx5Zo3XtDgI/AAAAAAAAIAs/XvsJ1DJ3Se4/s72-c/image1.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-82060746239645894.post-145788333835017751</id><published>2009-12-01T04:02:00.000-08:00</published><updated>2009-12-09T15:23:21.401-08:00</updated><title type='text'>Master Boor Record (MBR) rootkit malware removal</title><content type='html'>Trojan malwares nowadays are capable of writing their malicious code to the Master Boot Record (MBR) of a bootable drive. It’s another way of an auto start technique which includes hiding itself from users. MBR rootkit malwares usually comes with a driver rootkit component that contains all the payloads. The main goal of this MBR rootkit malware technique is to load the driver rootkit component before Windows starts. Security companies named this kind of malwares as MBR Rootkit, Mebroot or Sinowal.&lt;br /&gt;&lt;br /&gt;How it works?&lt;br /&gt;The MBR rootkit malware saves a copy of the original Master Boot Record (MBR) in other sector of hard drive, and then it writes its own malicious MBR to load its malicious routine together with the original MBR of the hard drive. Regarding the driver rootkit component, it is not dropped as a file, but it is written in a portion of the hard drive as its stealth mechanism technique. Another malicious code is written in some sector of the hard drive to load the driver rootkit component before loading Windows.&lt;br /&gt;&lt;br /&gt;How to clean?&lt;br /&gt;There are ways to remove this MBR rootkit malware, but be cautious on following the instructions, because we are dealing with the Master Boot Record of a hard drive which may damage the MBR and causes loss of data.&lt;br /&gt;&lt;br /&gt;Anyways, here are the easiest and safe steps that I know to remove/clean your infected Master Boot Record:&lt;br /&gt;1. Download the tool MBR rootkit detector from the below link:&lt;br /&gt;&lt;a href="http://www2.gmer.net/mbr/mbr.exe"&gt;http://www2.gmer.net/mbr/mbr.exe&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://athan.cjb.net/mbr.zip"&gt;-Mirror-&lt;/a&gt;&lt;br /&gt;Note: The tool from the mirror link is compressed and password protected (password: novirus). Also, it may not be the updated tool but it is the tool that I use as of this writing.&lt;br /&gt;&lt;br /&gt;2. Using the command prompt (cmd.exe), run the “mbr.exe”. Check if you are really infected.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Cn4enf1IhOA/SxUG3pUbXII/AAAAAAAAIAE/CmTOMCZ-kN8/s1600/1.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 198px;" src="http://1.bp.blogspot.com/_Cn4enf1IhOA/SxUG3pUbXII/AAAAAAAAIAE/CmTOMCZ-kN8/s400/1.JPG" alt="" id="BLOGGER_PHOTO_ID_5410238080409623682" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;3. Once your are infected, run the mbr.exe again but this time with the parameter “-f” to fix/clean your Master Boot Record, please see below command:&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;font-family:lucida grande;" &gt;mbr.exe –f&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;You should see the message “original MBR restored successfully!”&lt;span style="text-decoration: underline;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Cn4enf1IhOA/SxUIuZk30ZI/AAAAAAAAIAc/ge4vfcTw38U/s1600/2.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 198px;" src="http://4.bp.blogspot.com/_Cn4enf1IhOA/SxUIuZk30ZI/AAAAAAAAIAc/ge4vfcTw38U/s400/2.JPG" alt="" id="BLOGGER_PHOTO_ID_5410240120588063122" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;4.    Then restart your computer.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;After restart, when you run the mbr.exe again, you should see the line “user &amp;amp; kernel MBR ok” and should not have the line “MBR rootkit infection detected!......”.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Cn4enf1IhOA/SxUI6Fd-ZxI/AAAAAAAAIAk/WApWuxvdNtk/s1600/3.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 198px;" src="http://2.bp.blogspot.com/_Cn4enf1IhOA/SxUI6Fd-ZxI/AAAAAAAAIAk/WApWuxvdNtk/s400/3.JPG" alt="" id="BLOGGER_PHOTO_ID_5410240321348855570" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;As long as you have the MBR ok message, just ignore the other messages, Some malicious code in your hard drive sector may still exist but rest assured that it will not run anymore because you already have a clean Master Boot Sector. ^_^&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/82060746239645894-145788333835017751?l=athansj.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://athansj.blogspot.com/feeds/145788333835017751/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://athansj.blogspot.com/2009/12/master-boot-record-mbr-rootkit-malware.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/145788333835017751'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/145788333835017751'/><link rel='alternate' type='text/html' href='http://athansj.blogspot.com/2009/12/master-boot-record-mbr-rootkit-malware.html' title='Master Boor Record (MBR) rootkit malware removal'/><author><name>Athan</name><uri>http://www.blogger.com/profile/06568460519084492565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://lh4.ggpht.com/_Cn4enf1IhOA/SXQC-SIOQKI/AAAAAAAAAX4/Uv5O02-GHlk/s720/DSC_0184.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Cn4enf1IhOA/SxUG3pUbXII/AAAAAAAAIAE/CmTOMCZ-kN8/s72-c/1.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-82060746239645894.post-2554898197293913784</id><published>2009-11-30T06:40:00.000-08:00</published><updated>2009-11-30T07:09:26.892-08:00</updated><title type='text'>Restore deleted files</title><content type='html'>I would like to share a very useful tool that I am using to restore deleted files (even emptied from recycle bin). I use this tool whenever I accidentally delete my files (for being stupid. haha).&lt;br /&gt;&lt;br /&gt;This is a free tiny program that doesn't need to be installed.&lt;br /&gt;&lt;a href="http://athan.cjb.net/file_restoration.zip"&gt;Click here to download the tool&lt;/a&gt;&lt;br /&gt;File information:&lt;br /&gt;Filename: &lt;a href="http://athan.cjb.net/file_restoration.zip"&gt;file_restoration.zip&lt;/a&gt;&lt;br /&gt;File size: 164,299 bytes&lt;br /&gt;MD5: B27AB9D8DF4BDA6E4D9D9FE280CD358E&lt;br /&gt;&lt;span style="font-style: italic;"&gt;note: the archive is password protected, password is: &lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;novirus&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;How to use:&lt;br /&gt;1. Double click the Restoration.exe&lt;br /&gt;2. Select a drive (location of the deleted file).&lt;br /&gt;3. Input the filename of the file then click the "search deleted file" button.&lt;br /&gt;4. Select a listed file.&lt;br /&gt;5. Click "Restore by copying" button.&lt;br /&gt;6. Specify the location you want to restore to.&lt;br /&gt;&lt;br /&gt;Enjoy! ^_^&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/82060746239645894-2554898197293913784?l=athansj.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://athansj.blogspot.com/feeds/2554898197293913784/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://athansj.blogspot.com/2009/11/restore-deleted-files.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/2554898197293913784'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/2554898197293913784'/><link rel='alternate' type='text/html' href='http://athansj.blogspot.com/2009/11/restore-deleted-files.html' title='Restore deleted files'/><author><name>Athan</name><uri>http://www.blogger.com/profile/06568460519084492565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://lh4.ggpht.com/_Cn4enf1IhOA/SXQC-SIOQKI/AAAAAAAAAX4/Uv5O02-GHlk/s720/DSC_0184.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-82060746239645894.post-3859150833043957282</id><published>2009-11-30T05:52:00.000-08:00</published><updated>2009-11-30T06:21:29.004-08:00</updated><title type='text'>Multiple Yahoo Messenger</title><content type='html'>Do you have 2 or more yahoo accounts that you need to use in yahoo messenger at the same time? No Worries! This can be done in 1 machine (using Windows OS).&lt;br /&gt;&lt;br /&gt;A simple trick to run yahoo messenger multiple times so you can use multiple accounts at the same time. All you have to do is modify something in windows registry.&lt;br /&gt;Here are the steps:&lt;br /&gt;1. Open Notepad.&lt;br /&gt;2. Copy the following in the opened Notepad:&lt;br /&gt;&lt;span style="font-style: italic; font-weight: bold;font-size:78%;" &gt;REGEDIT4&lt;br /&gt;[HKEY_CURRENT_USER\Software\Yahoo\pager\Test]&lt;br /&gt;"plural"=dword:00000001&lt;/span&gt;&lt;br /&gt;Note: just replace the dword:00000001 to dword:00000000 if you want to disable multiple instance of yahoo messenger.&lt;br /&gt;3. Save the file as MultipleYM.reg.&lt;br /&gt;4. Locate and right click on the file MultipleYM.reg and click on Merge&lt;br /&gt;5. Click Yes on the Prompt.&lt;br /&gt;&lt;br /&gt;This trick does not need to restart Windows, you can now run the yahoo messenger multiple times and login all your accounts.&lt;br /&gt;&lt;br /&gt;Enjoy! ^_^&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/82060746239645894-3859150833043957282?l=athansj.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://athansj.blogspot.com/feeds/3859150833043957282/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://athansj.blogspot.com/2009/11/multiple-yahoo-messenger.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/3859150833043957282'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/3859150833043957282'/><link rel='alternate' type='text/html' href='http://athansj.blogspot.com/2009/11/multiple-yahoo-messenger.html' title='Multiple Yahoo Messenger'/><author><name>Athan</name><uri>http://www.blogger.com/profile/06568460519084492565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://lh4.ggpht.com/_Cn4enf1IhOA/SXQC-SIOQKI/AAAAAAAAAX4/Uv5O02-GHlk/s720/DSC_0184.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-82060746239645894.post-3042716629072191302</id><published>2009-11-29T08:11:00.000-08:00</published><updated>2011-03-15T06:41:39.882-07:00</updated><title type='text'>Autorun Malware Protection</title><content type='html'>Windows has a feature known as AutoPlay and AutoRun. These features are designed to run applications automatically from devices such as disk drives, floppy drives, usb flash drives cd/dvd drives. This feature is dependent on a certain file "autorun.inf", which is a configuration file that contains information on application that will launch by Windows.&lt;br /&gt;&lt;br /&gt;Example: Most disc installers uses the AutoPlay feature of Windows, it uses the file "Autorun.inf" so that once the disc is inserted in a cd/dvd drive, Windows will launch the setup of the installer from the disc automatically.&lt;br /&gt;&lt;br /&gt;This feature is exploited by the malwares for its propagation routine, they usually drop a copy of itself in all drives (from A to Z) together with the file "Autorun.inf". Their objective is to infect the removable drives (such as floppy disk, flash drives, usb hard disks) so that when these infected drives are inserted to another machine with the AutoPlay/Autorun feature turned on, that machine will also be infected by the malware.&lt;br /&gt;&lt;br /&gt;Here is the solution to block the autorun for all devices:&lt;br /&gt;1. Open Notepad.&lt;br /&gt;2. Copy the following to the Notepad:&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-family:verdana;"&gt;&lt;em&gt;REGEDIT4&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;em&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\autorun.inf]&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;em&gt;@="@SYS:DoesNotExist"&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;3. Save the file as DisableAutorun.reg.&lt;br /&gt;4. Right click on the file DisableAutorun.reg and click on Merge&lt;br /&gt;5. Click Yes on the Prompt.&lt;br /&gt;6. Restart Windows to take effect.&lt;br /&gt;&lt;br /&gt;For a brief explanation, this registry entry will make Windows tag the autorun.inf as not present in all drives, like it doesn't exist.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Well, this is only tested on Windows XP, I haven't tried it in Windows Vista or earlier version.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;===========================================&lt;/div&gt;&lt;div&gt;Update - March 15, 2011 - 6:00 AM PST&lt;/div&gt;&lt;div&gt;This is tested only in Windows XP and is &lt;i&gt;_NOT_&lt;/i&gt; applicable on Windows 7. &lt;/div&gt;&lt;div&gt;For Windows 7 instructions please click below:&lt;/div&gt;&lt;div&gt;&lt;a href="http://athansj.blogspot.com/2011/03/autorun-malware-protection-on-win7.html"&gt;Autorun Malware Protection for Win7&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/82060746239645894-3042716629072191302?l=athansj.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://athansj.blogspot.com/feeds/3042716629072191302/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://athansj.blogspot.com/2009/11/autorun-malware-protection.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/3042716629072191302'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/3042716629072191302'/><link rel='alternate' type='text/html' href='http://athansj.blogspot.com/2009/11/autorun-malware-protection.html' title='Autorun Malware Protection'/><author><name>Athan</name><uri>http://www.blogger.com/profile/06568460519084492565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://lh4.ggpht.com/_Cn4enf1IhOA/SXQC-SIOQKI/AAAAAAAAAX4/Uv5O02-GHlk/s720/DSC_0184.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-82060746239645894.post-1287199858752416892</id><published>2009-11-29T05:43:00.000-08:00</published><updated>2011-03-15T06:48:24.635-07:00</updated><title type='text'>Phishing on Facebook</title><content type='html'>To all facebook users, beware if one of your friends post a message in your wall with links, there are several reports that malwares are using facebook to redirect a user to a phishing site to steal your facebook account's password.&lt;br /&gt;&lt;br /&gt;Here's the example of the message with the malicious link that might be posted on your wall:&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;img style="margin: 0px auto 10px; text-align: center; width: 400px; display: block; height: 151px;" id="BLOGGER_PHOTO_ID_5409527815213233218" alt="" src="http://1.bp.blogspot.com/_Cn4enf1IhOA/SxKA4xRhNEI/AAAAAAAAH_0/1rSgTz1M7DU/s400/fb-wallpost.JPG" border="0" /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div style="text-align: left;"&gt;&lt;ul&gt;&lt;li&gt;http://WWW.SHRINKURL%2EUS/ntrurpwkthx?2230&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;note: The message and link may change but it will still point the user to the phishing site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Once you click the link, it will redirect you to a fake facebook site (phishing site), entering your email and password to this fake facebook site will expose your facebook account to the hacker (owner of phishing site).&lt;br /&gt;&lt;br /&gt;Fake facebook website (Phishing site):&lt;br /&gt;&lt;ul&gt;&lt;li&gt;http://122.141.86.112/facebook.com.login.php&lt;/li&gt;&lt;/ul&gt;&lt;img style="margin: 0px auto 10px; text-align: center; width: 400px; display: block; height: 223px;" id="BLOGGER_PHOTO_ID_5409525711641511314" alt="" src="http://2.bp.blogspot.com/_Cn4enf1IhOA/SxJ--U28BZI/AAAAAAAAH_s/T3fgKAQ6zWw/s400/fake_facebook.JPG" border="0" /&gt;&lt;br /&gt;&lt;br /&gt;Please always check the address bar on your browser that the domain site you are viewing is from facebook before logging in. (it should be &lt;a href="http://www.facebook.com/"&gt;h&lt;i&gt;ttp://www.facebook.com/&lt;/i&gt;&lt;/a&gt; _NOT_ &lt;i&gt;http://-somethingelse-/facebook.com&lt;/i&gt;)&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/82060746239645894-1287199858752416892?l=athansj.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://athansj.blogspot.com/feeds/1287199858752416892/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://athansj.blogspot.com/2009/11/phishing-on-facebook.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/1287199858752416892'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/82060746239645894/posts/default/1287199858752416892'/><link rel='alternate' type='text/html' href='http://athansj.blogspot.com/2009/11/phishing-on-facebook.html' title='Phishing on Facebook'/><author><name>Athan</name><uri>http://www.blogger.com/profile/06568460519084492565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://lh4.ggpht.com/_Cn4enf1IhOA/SXQC-SIOQKI/AAAAAAAAAX4/Uv5O02-GHlk/s720/DSC_0184.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Cn4enf1IhOA/SxKA4xRhNEI/AAAAAAAAH_0/1rSgTz1M7DU/s72-c/fb-wallpost.JPG' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
