<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3752395250380321563</id><updated>2011-07-07T22:16:04.899-07:00</updated><category term='virus'/><category term='spyware'/><category term='malware'/><category term='email'/><category term='pc'/><category term='security'/><title type='text'>Compu-Clean</title><subtitle type='html'>Tips, tricks and other useful(less) information for the home and business pc user.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://compu-clean.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3752395250380321563/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://compu-clean.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Del Tice</name><uri>http://www.blogger.com/profile/16885752423389935892</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3752395250380321563.post-2222673711839582109</id><published>2009-06-25T22:48:00.002-07:00</published><updated>2009-06-25T22:54:01.045-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><title type='text'>Beware of Harry Potter!...</title><content type='html'>Be very wary! P2P users that try to download a pirate copy of "Harry Potter and the half-blood prince" may get more than they bargin for. What is happening is that when users are asked to install a stream viewer, they are actually installing malware.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This is yet another reason not to pirate movies on the internet. You never know exactly what you are going to get.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If you think that you have been infected because of this, contact us for assistance.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3752395250380321563-2222673711839582109?l=compu-clean.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://compu-clean.blogspot.com/feeds/2222673711839582109/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://compu-clean.blogspot.com/2009/06/beware-of-harry-potter.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3752395250380321563/posts/default/2222673711839582109'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3752395250380321563/posts/default/2222673711839582109'/><link rel='alternate' type='text/html' href='http://compu-clean.blogspot.com/2009/06/beware-of-harry-potter.html' title='Beware of Harry Potter!...'/><author><name>Del Tice</name><uri>http://www.blogger.com/profile/16885752423389935892</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3752395250380321563.post-8370355579028391216</id><published>2009-06-24T15:19:00.000-07:00</published><updated>2009-06-24T17:24:16.501-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='email'/><category scheme='http://www.blogger.com/atom/ns#' term='pc'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Yet another malicious email link...</title><content type='html'>The other day I received an email in my inbox that, on the surface, looked like it was from Microsoft. Even though Google Apps is extremely proficient at redirecting these to my spam box, it does miss the occasional. As a 20 year veteran in the IT field, I never assume that an email is legitimate without checking several things out. You can also do these things to help prevent the unintentional infection of your computer.&lt;br /&gt;&lt;br /&gt;The first thing that I do is to check any links in the email that I am requested to click. For example, the image below is from a recent email claiming to be a critical update for MS Outlook and Outlook Express. In this example, I right click the link and then choose &lt;span style="font-weight: bold; font-style: italic;"&gt;Copy link address&lt;/span&gt;.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_gXVrOk0_aG8/SkK6sYIQZCI/AAAAAAAAAAc/cb-eXTXuBmU/s1600-h/email_links_check.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 287px; height: 320px;" src="http://2.bp.blogspot.com/_gXVrOk0_aG8/SkK6sYIQZCI/AAAAAAAAAAc/cb-eXTXuBmU/s320/email_links_check.jpg" alt="" id="BLOGGER_PHOTO_ID_5351044578823660578" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;I use Google Apps for my domains email, however, the process should be similar no matter what service you use. Next I open a notepad window and paste the address there for inspection. Typically, there will be something other than the correct address for the originator of the email. In this example, the link reads&lt;br /&gt;&lt;blockquote&gt;http://update.microsoft.com.iXXXXXX.com&lt;/blockquote&gt;NOTE: I have X'd most of the portion of the address that is not the originator as well as the rest of the link as it is irrelevant to this example.&lt;br /&gt;&lt;br /&gt;Had this been a valid email for an update from Microsoft, rest assured that &lt;span style="font-weight: bold;"&gt;update.microsoft.com&lt;/span&gt; would have been the domain without the extra &lt;span style="font-weight: bold;"&gt;.iXXXXXX.com&lt;/span&gt; after it.&lt;br /&gt;&lt;br /&gt;The other thing I do is to check the emails "header information". I will explain how to do this in Google Apps/Gmail. While in the message, click the down arrow next to Reply in the upper right of the message and select Show original. This will open a new window that will show the text in the example below (plus more that I've omitted from this example). If you are using Outlook 2003, see this &lt;a href="http://www.msexchange.org/articles/Outlook-Internet-Headers.html"&gt;article&lt;/a&gt; on how to view the header information.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_gXVrOk0_aG8/SkLAGxgz10I/AAAAAAAAAA0/ixv6y3XQIz4/s1600-h/email_header_check.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 176px;" src="http://3.bp.blogspot.com/_gXVrOk0_aG8/SkLAGxgz10I/AAAAAAAAAA0/ixv6y3XQIz4/s320/email_header_check.jpg" alt="" id="BLOGGER_PHOTO_ID_5351050529872271170" border="0" /&gt;&lt;/a&gt; &lt;span style="color: rgb(51, 51, 255);"&gt;&lt;br /&gt;&lt;br /&gt;The information you would be most concerned with is the Return-Path field (highlighted in the image). As you can see in the example, the Return-Path is definitely NOT from Microsoft. This is a sure sign that the message is not from who it claims.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;One final item that made me suspicious about our example email was that it referenced Outlook Express. Microsoft currently does not offer OE for download and I believe that it is out of its life cycle.&lt;br /&gt;&lt;br /&gt;For the record, I did NOT click on this link and I would recommend you follow suit. Maybe, I will setup a test pc and do it just to see the consequences.&lt;br /&gt;&lt;br /&gt;Thanks for reading this. I welcome any comments (pro and con) as well as suggestions for articles.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3752395250380321563-8370355579028391216?l=compu-clean.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://compu-clean.blogspot.com/feeds/8370355579028391216/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://compu-clean.blogspot.com/2009/06/yet-another-malicious-email-link.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3752395250380321563/posts/default/8370355579028391216'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3752395250380321563/posts/default/8370355579028391216'/><link rel='alternate' type='text/html' href='http://compu-clean.blogspot.com/2009/06/yet-another-malicious-email-link.html' title='Yet another malicious email link...'/><author><name>Del Tice</name><uri>http://www.blogger.com/profile/16885752423389935892</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_gXVrOk0_aG8/SkK6sYIQZCI/AAAAAAAAAAc/cb-eXTXuBmU/s72-c/email_links_check.jpg' height='72' width='72'/><thr:total>1</thr:total></entry></feed>
