October 2012 - Posts

Fake NY Airlines email

image

 

There really isn’t any excuse for being fooled by this stuff when hovering over the hyperlink makes it so obvious that something is not quite right…

Your Photos spam

You don’t want to open that attachment – honest.

 

image

FTC Finalizes Settlements with Businesses that Exposed Consumers Sensitive Information by Installing Peer-to-Peer File-Sharing Software on Corporate Computer Systems

“Following a public comment period, the Federal Trade Commission has accepted as final settlements with two operations it charged with illegally exposing the sensitive personal information of thousands of consumers by allowing peer-to-peer file-sharing software to be installed on their corporate computer systems.  Settlements with Utah-based debt collector EPN, Inc., and Georgia auto dealer Franklin Budget Car Sales, Inc., will bar misrepresentations about the privacy, security, confidentiality, and integrity of any personal information collected from consumers.  Both companies also must establish and maintain comprehensive information security programs.”

Source: http://www.ftc.gov/opa/2012/10/franklinepn.shtm

 

Franklin's Budget Car Sales, Inc Complaint and Decision and Order
http://www.ftc.gov/os/caselist/1023094/121026franklinautomallcmpt.pdf
http://www.ftc.gov/os/caselist/1023094/121026franklinautomalldo.pdf

Checknet, Inc. Complaint and Decision and Order
http://www.ftc.gov/os/caselist/1123143/121026epncmpt.pdf
http://www.ftc.gov/os/caselist/1123143/121026epndo.pdf

14th MVP award…

My first MVP award (for supporting users of Internet Explorer and the now long defunct Outlook Express) was back in 1999…

Then I was moved to Internet Explorer only….

Then Consumer Security: Training…

On 1 October I was awarded MVP status for the 14th year in a row Smile

Posted by sandi with no comments
Filed under:

Fake eFax Corporate email…

I don’t remember seeing one of these before… fake, of course.

image

Fake LinkedIn invitations

I receive LinkedIn emails regularly – this (fake) one looks like realistic, until you hover over the hyperlink…

image

And in more good news… FTC has launched a major crackdown on telemarket tech support scams

Details here:
http://www.ftc.gov/opa/2012/10/pecon.shtm

 

Parties:
Federal Trade Commission, Plaintiff, v. Pecon Software Ltd., also doing business as Pecon Services LLC, Pecon Services, Inc.; Pecon Infotech Ltd.; Pecon Software UK Ltd.; Mahesh Kumar Shah, also known as MK Shah; Prateek Shah; Sujoy Roy; Zulfiquar Ali; and Vikas Kumar Gupta, Defendants
(United States District Court for the Southern District of New York)

Federal Trade Commission, Plaintiff, v. PCCare247 Inc.; PC Care247 Solutions Private Limited; Connexxions Infotech Inc.; Connexxions IT Services Private Limited, also doing business as Connexxions InfoTech Services Pvt. Ltd.; Vikas Agrawal, also known as Vikas Agarwal; Navin Pasari; Anuj Agrawal; Sanjay Agarwalla; and Parmeshwar Agrawal, Defendants
(United States District Court for the Southern District of New York)

Federal Trade Commission, Plaintiff, v. Zeal IT Solutions Pvt Ltd. and Kishore Ghosh, Defendants
(United States District Court for the Southern District of New York)

Federal Trade Commission, Plaintiff, v. Lakshmi Infosoul Services Pvt Ltd., Somenath Das, and Piyush Kheria, Defendants
(United States District Court for the Southern District of New York)

Federal Trade Commission, Plaintiff, v. Mikael Marczak, also known as Michael Marczak, also doing business as Virtual PC Solutions, First PC Solution, Direct PC Solution, Virtual IT Supports, and Global Innovative Services, and Wahid Ali, Defendants
(United States District Court for the Southern District of New York)

Federal Trade Commission, Plaintiff, v. Finmaestros, LLC, also doing business as technogennie, 24x7pchelp, 24x7pctech, and Transfront Solutions; New World Services, Inc., also doing business as Megabites, Solutions Inc., MegaBites Solutions, LLC, also doing business as Mega Bits, Inc.; Greybytes Cybertech P. Ltd., also doing business as Bluesystemcare, BSC, and 24x7 PCHelp; Shine Solutions Private Limited; Sanjeev K. Sood, also known as Sanjiv K. Sood; and Animesh Bharti, Defendants
(United States District Court for the Southern District of New York)

FTC versus Innovative Marketing and others

Good news.  Remember Innovative Marketing? They were involved in “scareware” years ago, and the scareware and the lawsuit have been featured many times on this blog (scareware names such as WinFixer, WinAntiVirus, WinAntiVvirusPro,  WinAntiSpyware, Popupguard, WinFirewall, InternetAntispy, WinPopupguard, ComputerShield, WinAntispy, PCsupercharger, ErrorSafe, SysProtect, DriveCleaner, SystemDoctor  and ErrorProtector have all been associated with Innovative Marketing).

Much has happened over the years in the Courts but one question that remained was Kristy Ross (once Sam Jain’s girlfriend), who continued to fight on after her fellow defendants settled, or simply ignored the lawsuit and had judgment entered against them. Kristy herself, though she got herself a lawyer, failed to answer and respond to any discovery requests and to appear at trial (see http://ftc.gov/os/caselist/0723137/121002winfixeropinion.pdf).

The FTC has announced a “joint and several” judgment of more than $163 million against the final defendant Kristy Ross (of course, whether they actually get the money is a different matter – the bench trial against Ross was held “in absentia”):
http://ftc.gov/opa/2012/10/winfixer.shtm

Sam Jain is still a fugitive as is Sundin.  Jain has allegations of mail and wire fraud against him as well as domestic and international money laundering. 

Fake Quickbooks emails: “IRS Approved 2012 W-2 and 1099 Tax Forms ? Order Before the Rush”

Here’s a new twist on an old story… as always, if you hover over a hyperlink you can see that the emails are not legitimate.

image

 

   image

Fake Sony Prize spam…

Got this today (phone spam, not email).  It’s actually a good example of what to watch out for…

“You have been chosen to receive a free gift. Go to http:// www .sony.com.au.ircontest.info and enter code **** to claim it and tell us where to ship it”.

Notes:

  1. Hyperlink broken for safety.
  2. The hyperlink is designed to look like it will take you to “sony.com.au” when in fact it will take you to “ircontest.info”.  If the URL was sony.com.au/ircontest.info it would belong to Sony, but because it is sony.com.au.ircontest.info (a full stop, not a slash) you will end up at a subdomain of ircontest.info, not sony.com.au (clear as mud?)

ircontest.info
ICANN Registrar: GoDaddy.com
Created: 25 September 2012

IP: 200.63.46.138 (Panama, Panamaserver.com)

Registration details hidden by Domains By Proxy, LLC.

Shares IP at time of writing with appletesting.info, frcontest.info, frgiveaway.info, grcontest.info, grgiveaway.info, idiotpages.com

Malvertizing and PDFs…

I’m seeing reports of malvertizements automatically opening PDFs. These PDFs use exploits to try and infect a user’s computer.

It’s very important to make sure that if you have Adobe Reader (or other PDF apps) installed on your computer that you make sure that they are properly patched.  I ordinarily commend Secunia PSI as an easy way to help stay on top of patches that may be required for software that is installed on your computer, but it requires admin rights (not good if you’re a standard user) and doesn’t work if you access the internet via a proxy.  I certainly couldn’t get it to run on my Win7 box running as a standard user – it came up with a proxy error even though I wasn’t actually using a proxy.

Anyway, it’s available here – who knows, maybe you’ll have more luck.

http://secunia.com/vulnerability_scanning/personal/