Text Spammer: (631) 398-2764

I just received another Text-Spam on my mobile phone. I have neither heard of them nor dealt with them.

The text spam is coming from (631) 398-2764.

The Spam says:

You’ve been chosen for a FREE NFL Jersey! Click here to choose your team jersey: www.myfreeoffersite.com/jerseyfree

myfreeoffersite.com is registered through GoDaddy.com. You can file complaint to GoDaddy here.

myfreeoffersite.com redirects through multiple addresses and landed on http://walmart.mygiftcarddeal.com/

mygiftcarddeal.com is registered through namecheap.com and protected through WhoisGuard.

According to FCC, this type of “marketing” does violate CAN-SPAM Act.

You should file form 1088G to report this violation.

File a complaint on FCC site http://esupport.fcc.gov/complaints.htm

You can also call 1-888-CALL-FCC (1-888-2255-322) voice; 1-888-TELL-FCC (1-888-8355-322) TTY.

Carrier IQ 2, The Quickening

It is inevitable for the Carrier IQ controversy dominating the headlines. This should be a bigger story than the overblown “Locationgate” story.

The Carrier IQ controversy has attracted the attention of Al Franken, US Senator from Minnesota; maybe he heard the page from applefanboy.com. Apple made a statement, saying that they have abandoned Carrier IQ with iOS 5 in most of their products. HTC say they don’t receive data from Carrier IQ. The story goes on and on.

Yes, you should be wearing your tin foil hat.

The Verge has great coverage on Carrier IQ controversy.

Malware Alert: Cloud AV 2012

On Wednesday November 23rd, 2011; the day before Thanksgiving Day I received a call.

“Hey, just want to let you know I was using my computer and Cloud AV 2012 just installed itself.”

Yeah, that’s a Malware.

I was getting ready for my Thanksgiving trip, so I had to work on this malware problem later. Bleeping Computer has a great instructions on removing Cloud AV 2012.

I am documenting what I’m doing to remove Cloud AV 2012.

  • I want to know if  Combofix can completely remove Cloud AV 2012. I ran Combofix in Safe Mode with Networking. It took about 15 minutes for Combofix to find some malware and removing them, unfortunately it is not enough.
  • The next step is to run Malwarebytes’ Anti-Malware.
  • I ran Spybot – Search and Destroy to clean up whatever part of malware it can find.
  • I ran Combofix again, and it found a few leftover Cloud AV 2012 files.
  • Reboot the computer a few times and so far I do not see any suspicious activities.

I’m going to put this computer on quarantine for a few days and see if Cloud AV 2012 is completely gone.

 

Backify versus Livedrive, the thickening plot.

Backify fires back at Livedrive by sending emails to signed-up users.

Dear <inser name here>,

We are writing to you in regards to the recent action taken by LiveDrive to close your backup/briefcase account.

Backify used to be a reseller for LiveDrive.com‘s services. Recently we were having some issues with their serive and they were literally unable to provide a solution to our problems. More information about these issues can be read on our homepage at www.backify.com. Tired of the service provided by LiveDrive, we asked them to close our reseller account. It may be noted that at no point did we ask them to close the accounts of our customers. But they went ahead and shut down the accounts of every Backify customer.

For every customer’s account, we have paid in advance a full year’s fee. So, the step taken by LiveDrive to close our customers’ accounts without refunding us is totally illegal, and we are considering our legal options at this time. Since your account was already paid fully for one year in advance, we request you to get in touch with LiveDrive and ask them to restore your service. Their customer support email address is support@livedrivesupport.com

Additionally, we understand that you may have spent considerable time/effort/bandwidth to upload your files to LiveDrive’s servers and by deleting your files/data without any notice they may have violated several laws. We also advice you to get legal help in case you suffered losses due to this sudden termination of service by LiveDrive.

Thanks,
Backify Team

To be honest, I’d like to take the position of doop‘s own Neutral President.

Persistence of bootkit

Platform: Windows XP, Windows Vista and Windows 7.

Symptoms, but not limited to:

  • Search results using browser search box including Chrome and Internet Explorer 9 Omnibox are redirected to other sites.
  • Internet Explorer is running in the background on login, using large amount of memory.

After long troubleshooting sessions I figured out that a bootkit was present on this computer.

A bootkit hides itself by modifying the master boot record.

The particular bootkit I was dealing with was not detected by Combofix, Malwarebytes’ Anti-Malware and many others. The only anti-malware program detected the bootkit was Hitman Pro 3.5.

If you are dealing with a persistent malware infection that redirects search results, try using numbers of anti-malware softwares. In addition to that, search for “Google redirect virus” using an uninfected computer. The malware redirects search result system-wide. On the infected system, search results were redirected on Internet Explorer, Safari, Chrome and Firefox. The malware will redirect search results on any browsers installed on the system.

It is almost 5 o’clock in the morning. I have not had a minute of sleep. I’ll clean up this post later.