Category Archives: Misc

Misc Information

TCPView & AutoRuns vs Undetectable Backdoor

5
Filed under Downloads, Misc, Personal, Security News
Tagged as , , ,

Intro:
We’re going to useTCPView to check active network traffic and AutoRuns to check and see what’s loading with Windows.

Scenerio:
The user is complaining of system slowness. Upon looking at the workstation I noticed AVG Free Edition, Spybot Search and Destroy installed and Windows Firewall enabled. Pretty standard novice user protection plan. Almost a given this system is infected.

Analysis:
I close Firefox and all open applications. Open TCPView and right off the bat I see outbound traffic to *.CO.UK using Firefox to make the remote connection. This is common in backdoors to use reverse connection methods. Once you execute the backdoor, it binds to a common process (IE, Firefox) and then reverse connects to the attacker. The reason for binding to a common process such as Internet Explorer or Firefox, is the fact that most novice users create rules for their software firewall and select “always allow” for common processes. This way the user isn’t bothered every time they open Firefox with “Do You want to allow firefox.exe access…” This is perfect for the backdoor, you’ve allowed unrestricted access outbound through firefox. Strike 1 for this novice user.

tcpview1

Port 95? Firefox should only be allowed access on port 80 and 443 (HTTP / HTTPS) Now that I know the user is infected, I need to find out what the file is called, where it lives, and why AVG’s superior detection is showing a clean system. I load AutoRuns and check for the suspicious Logon items. Bingo Bango! I see scchost.exe (not to be confused with svchost.exe, which is actually legit in most cases) loading upon reboot and it’s stored safely from novice users in the system32 folder. Now, 100% sure that is the backdoor, I would like AVG to agree, so I attempt to update AVG and check the file, No! AVG insists the file is clean. OK, to the USB drive for MalwareBytes. Sure enough a nice password stealer has been detected. Strike 2 for trusting AVG (signature based detection).

malwarebytes

MalwareBytes detected and removed the password stealer, I then put in the KAV rescue disk to scan the system and everything came back clean. In the end, I convinced the user to let me perform a clean install and even teach this user how to properly use Firefox (w/NoScript). Reminding the user that the software firewall is only as good as the user and that the AntiVirus program is only as good as its definitions.

Conclusion:
TCPView provided you with the information needed to see you have unauthorized access to a server in the UK. AutoRuns was able to show us the malicious file loading with Windows. The actual detection and removal is up to you and your utilities, however TCPView and AutoRuns gave you the heads up. On the flip side, the backdoor successfully executed and called home on the system. Being that it’s a password stealer, the information it was programmed to gather completed successfully.

I call this one a DRAW. Why? because a backdoor is designed to go unnoticed and AVG let it do just that, but with a few basic programs you can see that your system is not preforming normally. Also, after detecting the backdoor, I installed it on a virtual machine and after about 18 hours of leaving it alone, it downloaded a new executable and maintained a connection to the client. This shows that we caught it early enough on the users computer to detect and remove it before it phoned home for the latest instructions.

It’s Offical, Bush is a failure!

6
Filed under Misc

Google Search: Failure

Just when I my love for Google started to fade off…

Searching google for the word, Failure. I was expecting to see my first relationship at number one with my attempt to fly off my parents deck at a close second. Little did I know, I wasn’t even close, out of 529,000,000 possibilities, you’ll notice President Bush is number one on the list! I have to admit, this is hands down the most honest result I have received from a search.

The only question is, Did bush pay Google AdWords too put him at the top of this search? It wouldn’t surprise me!

Gas War – We’ve lost the battle, lets win the war!

4
Filed under Misc, Personal

Gas Chart

Intro:
Looks like we’re off to a killer “May Day” month. I don’t know about everyone else but I’m tired of sitting around watching the gas prices shoot up through the sky. A 100.00 gas refund from the government isn’t going to last nearly as long as these prices do. It’s time we as the consumers work together to do our part, otherwise you have no right to complain.I don’t know if it’s true, but I was told that Russia and China are working together with Iran to take away our oil shipments and reroute the oil to China and Russia. This leaving our country in an economic disaster. I’m sure we have plenty of oil in reserve as well as coming from IRAQ to where we shouldn’t be affected for sometime now.

The Plan:
Phillip Hollsworth offered this good idea.

This makes MUCH MORE SENSE than the “don’t buy gas on a certain day” campaign that was going around last April or May. The oil companies just laughed at that because they knew we wouldn’t continue to “hurt” ourselves by refusing to buy gas. It was more of an inconvenience to us than it was a problem for them.
Please read on and join with us! By now you’re probably thinking gasoline priced at about $1.50 is super cheap. Me too! It is currently $3.35 for regular unleaded in California. Now that the oil companies and the OPEC nations have conditioned us to think that the cost of a gallon of gas is CHEAP at $1.50 – $1.75, we need to take aggressive action to teach them that BUYERS control the marketplace….. not sellers.

With the price of gasoline going up more each day, we consumers need to take action. The only way we are going to see the price of gas come down is if we hit someone in the pocketbook by not purchasing their gas! And, we can do that WITHOUT hurting ourselves.

How? Since we all rely on our cars, we can’t just stop buying gas. But we CAN have an impact on gas prices if we all act together to force a price war.

Here’s the idea:
For the rest of this year, DON’T purchase ANY gasoline from the two biggest companies (which now are one), EXXON / MOBIL. If they are not selling any gas, they will be inclined to reduce their prices. If they reduce their prices, the other companies will have to follow suit.

But to have an impact, we need to reach literally millions of Exxon and Mobil gas buyers. It’s really simple to do! Now, don’t wimp out at this point…. keep reading and I’ll explain how simple it is to reach millions of people.

Acting together we can make a difference. If this makes sense to you, please pass this message on. I suggest that we not buy from EXXON/MOBIL UNTIL THEY LOWER THEIR PRICES AND KEEP THEM DOWN. If we show we have control, this will show we can’t be pushed around.

Your Part:
Spread the idea, promote the idea. Don’t sit around and wait for our government to take control of this issue. Please leave feedback and feel free to comment!!

Reference:
I orginally recieved this in an email from a friend. Instantly I thought this was a great idea and decided to turn that email into a blog. I remember paying .73 a gallon when I was 17, the sad thing is I’m only 24. Look at what happened over 7 years…

My Part:
I decided that blogging about this and not buying gas from Exxon/Mobil wasn’t enough. Currently my Google Adsense account (money I make off the ads on my site) is at 92.38. I’m going to donate that as well as 100.00 of my own money in promoting this idea on Google Adwords. I’m tracking all the stats via Google Analytics and will keep the blog updated with stats of how many visitors and what locations are helping. At the end of the month if this isn’t successfully generating hits I’ll stop promoting it on Google. However, until the Gas prices have dropped I’ll keep this post up.

Thank you for taking the time in reading about this!!

TextPayMe – The paypal for 2006?

1
Filed under Misc, Uncategorized


SignUp at TextPayMe

Well, what can I say about this handy little service. When I first read it, I thought this is pointless. Then I sat and thought about it for a few days. Yeah! This is useful, How many times have I been busy working or on the road and my girlfriend says, “Jordan, can you please transfer me 100.00 for my hair and nails?” True, normally I would laugh it off and advise to get a part time job, however on a special day I might feel so inclined.

Good news? Of course, the good news is they’re going to give you a free 5.00 for signing up. Not that 5.00 makes me start to river dance, but the fact that I can sign up for free and transfer money for free all from my cell phone. So if nothing more give it a try, if you think it’s pointless give it a try for FREE and prove yourself right!

I enjoy it. If this is something you enjoy click on the banner below and let the txt being!


SignUp at TextPayMe

FIGHTAIDS@SETI

0
Filed under Misc, Personal

FIGHTAIDS@SETI

FightAIDS@Home (Launched November 21, 2005)
FightAIDS@Home is a project focused on using computation methods to identify candidate drugs that have the right shape and chemical characteristics to block HIV protease. This approach is called “Structure-Based Drug Design”, and according to the National Institute of General Medical Sciences, it has already had a dramatic effect on the lives of people living with AIDS.

I was never one for the SETI@HOME space projects back in the day. However, now that Berkley is controlling the SETI project and the fact that this is for AIDS rather than Extraterrestrial Intelligence. I decided to go ahead and donate my computers idle time to this research project. My uncle being infected with HIV for over 15 years, I know the importance of this research and for something that doesn’t cost me a penny, I cannot turn my head. If this is something you feel you’re interested in, I highly recommend helping out for this cause.

More Information: FIGHTAIDS@Home or World Community Grid

Download: Join the Fight