<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
   <channel>
      <title>Wiz&apos;s Computer and Website Security Blog</title>
      <link>http://www.wizcrafts.net/blogs/</link>
      <description><![CDATA[Our blog deals with computer troubleshooting, vulnerability alerts, computer security, spyware &amp; virus removal tools, e-mail threats, anti-spam solutions and website security issues.]]></description>
      <language>en</language>
      <copyright>Copyright 2009</copyright>
      <lastBuildDate>Thu, 02 Jul 2009 17:13:01 -0500</lastBuildDate>
      <generator>http://www.sixapart.com/movabletype/?v=3.37</generator>
      <docs>http://blogs.law.harvard.edu/tech/rss</docs> 

            <item>
         <title>New Nigerian phishing scam targets Hotmail users</title>
         <description><![CDATA[<p>Today I received an unusual phishing scam that I traced to Lagos, Nigeria. It is disguised as an urgent message from the Windows Live Team, to all Hotmail subscribers. The subject was: "LAST WARNING (ACCOUNT ALERT)" - in all capital letters - <em>as is typical of Nigerian 419 scammers</em>. The email claims that Hotmail is overloaded with free user accounts and must prune unused accounts to free up resources. What a bunch of hooey! Anyway, the intended victim is asked for his or her Hotmail address and password (Microsoft already knows this), date of birth (why would Microsoft need that?) and your location. The details are supposed to be filled out in the enclosed form and submitted to the scammers.</p>

<p>This is a phishing scam looking to steal active Hotmail accounts for use as spam sending zombies, using Hotmail's good reputation to avoid email sender blockades. The phished date of birth information can be crosschecked against other stolen or looked up details about you, or they can read your personal details saved in your Hotmail account profile, to perform identity theft. This information would then be sold to more advanced cyber criminals.</p>

<p>The scam email I received today was sent from the IP address 62.173.55.107 which is part of the <acronym title="CIDR = Classless Inter-Domain Routing and is a way of expressing a range of IP addresses">CIDR</acronym> 62.173.32.0/19, which covers all IPs between 62.173.32.0 and 62.173.63.255. <a href="http://whois.domaintools.com/62.173.55.107" rel="external">This CIDR is registered to ipNX Nigeria Limited</a>, in Lagos, NG. </p>

<p>I discuss methods of preventing these Nigerian scam emails from reaching your desktop email clients, or forum members, in my extended comments.<br />
</p>]]></description>
         <link>http://www.wizcrafts.net/blogs/2009/07/new_nigerian_phishing_scam_targets_hotmail_u.html</link>
         <guid>http://www.wizcrafts.net/blogs/2009/07/new_nigerian_phishing_scam_targets_hotmail_u.html</guid>
         <category>Spam Issues</category>
         <pubDate>Thu, 02 Jul 2009 17:13:01 -0500</pubDate>
      </item>
            <item>
         <title>Spybot Search and Destroy Definitions Updated on July 1, 2009</title>
         <description><![CDATA[<p>If you use <a href="http://www.safer-networking.org/en/home/index.html" rel="external">Spybot Search and Destroy</a> to protect your computer against spyware and malware, it is time again to run your manual updates. Malware writers are constantly modifying their programs to evade detection, so anti-malware vendors have to issue regular updates to keep up with the bad guys. New definitions and false positive fixes for Spybot Search and Destroy are usually released every Wednesday. This week's updates were released on schedule on July 1, 2009, as listed below. Some new and altered fake security programs were added to the detections, plus several new Trojans, rootkits and modified spam bots.</p>

<p><strong>Updating Spybot Search and Destroy</strong></p>

<p>Before you update Spybot Search and Destroy make sure you have  <a href="http://www.spybot.info/en/download/index.html" rel="external">the latest official version</a>. Older versions are no longer supported and will cause you a lot of grief when you immunize and scan for problems. Only download Spybot S&amp;D from the official website, at: <a href="http://www.spybot.info/">spybot.info</a>, or from its alternate domain: <a href="http://www.safer-networking.org/">Safer-Networking.org</a>. Fake versions with similar names will rip you off for payment to remove threats, whereas the real Spybot S&amp;D is free (<em>donations gladly accepted</em>).</p>

<p>In case you are new to Spybot S&amp;D, there are two ways to update the program and malware definitions. The preferred method (For Windows PCs) is to go to <b>Start > (All) Programs > Spybot - Search &amp; Destroy > Update Spybot - S&amp;D</b>. The independent update box will open. Leave the default options as is, unless you need all languages or want beta definitions, and click on "Search." Another box will open with "mirror" locations around the world where you can download updates. Select a location nearest to you from the list and click on "Continue." Make sure all updates are checked, then click on "Download." If all definitions are verified as being correct the check marks will disappear from the check boxes and be replaced with green arrow graphics. However, sometimes one or more mirror locations have not updated all of the definitions and you will get a red X for those definitions. Click on Go Back, select a different mirror, and try again. I have consistent success using Giganet or the Safer-Networking servers. When all updates have succeeded, click on "Exit." </p>

<p>Download links and more instructions about using Spybot Search and Destroy are in my article titled <a href="http://www.wizcrafts.net/blogs/2009/06/how_to_use_spybot_search_destroy_to_fight_ma.html">"How to use Spybot Search &amp; Destroy to fight malware"</a>.  </p>

<p>The description of the latest definition updates and false positive fixes are in my extended comments below.</p>]]></description>
         <link>http://www.wizcrafts.net/blogs/2009/07/spybot_search_and_destroy_definitions_update_60.html</link>
         <guid>http://www.wizcrafts.net/blogs/2009/07/spybot_search_and_destroy_definitions_update_60.html</guid>
         <category>Security Program Updates</category>
         <pubDate>Wed, 01 Jul 2009 21:36:40 -0500</pubDate>
      </item>
            <item>
         <title>My Spam analysis for June 22 - 28, 2009</title>
         <description><![CDATA[<p>This is the latest entry in my weekly series about classifications of spam, according to my custom filter rules used by <a href="/mailwasher.html">MailWasher Pro</a>. The categories are shown on the "Statistics" page > "Junk Mail," as a pie chart, based on <a href="/mwp-filters.html">my custom filters and blacklist</a>. The amount of email flagged as spam is shown on the "Summary" page of Statistics.</p>

<p>The volume of spam coming to my various honeypots and user accounts has increased slightly this week. This indicates to me that some of the Botnets that lost their Control and Command servers following the forced shutdown of colocation host <a href="http://www.networkworld.com/community/node/42434?source=NWWNLE_nlt_security_2009-06-05" rel="external">Pricewert</a> have found other server hosts that allow illegal activities. Thus, sleeping zombie bots are awakening and spamming again.</p>

<p>The classifications of spam in my analysis can help you adjust your email filters according to what is most common, on a weekly basis. Most of the spam this week was for various fake pharmacies, which sell illicit and counterfeit pharmaceuticals like Viagra, weight loss scams and phishing scams. </p>

<p>See my extended comments for this week's breakdown of spam by category, for June 22 - 28, 2009 and the latest additions to my custom MailWasher Pro filters</p>]]></description>
         <link>http://www.wizcrafts.net/blogs/2009/06/my_spam_analysis_for_june_22_28_2009.html</link>
         <guid>http://www.wizcrafts.net/blogs/2009/06/my_spam_analysis_for_june_22_28_2009.html</guid>
         <category>Spam Issues</category>
         <pubDate>Sun, 28 Jun 2009 13:33:53 -0500</pubDate>
      </item>
            <item>
         <title>Weekly roundup of vulnerabilities and exploits in the wild</title>
         <description><![CDATA[<p>Here is a summary of this week's vulnerabilities and exploits in the wild, as reported by Secunia, Websense and other security firms. Actually, this has been a quieter week than most.</p>

<p>Websense has been following a website code injection event they named the "<a href="http://tinyurl.com/lddahg" rel="external">Nine Ball Mass Injection</a>," which is a follow-up to the "Beladen" and "Gumblar" mass injection attacks last month This is a situation where cyber criminals exploit vulnerable web application scripts that have not been secured by the webmasters who operate those websites. Too many webmasters use free scripts that are rarely, if ever updated to patch announced vulnerabilities. Hackers send out automatic scripts (a.k.a. robots, spiders) that try to upload hostile files to any website they come across. Once they find an unpatched point of entry they are able to alter the codes on any web pages (usually the home page) they want. In the past, hackers would deface home pages with gibberish or slogans for their causes. Now, it is criminals who sneak in dangerous hidden codes that redirect innocent visitors to hostile websites, where malware is attempted to be downloaded to the victims' computers. Most are successful, because most people do not, or cannot keep up with patches released by every vendor of the add-ons and plug-ins used by their browsers.</p>

<p>Most of the malware being downloaded by the Nine Ball and similar exploits is fake security applications that pretend to scan you computer, announce so many threats found, then demand payment to remove those threats. These are tandem malware programs, with part one being the fake alerts and part two being the fake remover. After you pay to unlock the remover, it only removes the alerts its sister placed there in the first place. You will have submitted your credit or debit card information to cyber criminals in the Former Soviet Union and can expect to have your accounts drained shortly.</p>

<p>The rest of this weeks vulnerabilities and exploits are in my extended comments.</p>]]></description>
         <link>http://www.wizcrafts.net/blogs/2009/06/weekly_roundup_of_vulnerabilities_and_exploi.html</link>
         <guid>http://www.wizcrafts.net/blogs/2009/06/weekly_roundup_of_vulnerabilities_and_exploi.html</guid>
         <category>Vulnerability Alerts</category>
         <pubDate>Fri, 26 Jun 2009 14:42:01 -0500</pubDate>
      </item>
            <item>
         <title>Spybot Search and Destroy Definitions Updated on June 24, 2009</title>
         <description><![CDATA[<p>If you use <a href="http://www.safer-networking.org/en/home/index.html" rel="external">Spybot Search and Destroy</a> to protect your computer against spyware and malware, it is time again to run your manual updates. Malware writers are constantly modifying their programs to evade detection, so anti-malware vendors have to issue regular updates to keep up with the bad guys. New definitions and false positive fixes for Spybot Search and Destroy are usually released every Wednesday. This week's updates were released on schedule on June 24, 2009, as listed below. Lots of new and altered fake security programs were added to the detections, plus several new Virtumonde Trojans and new or modified spam bots.</p>

<p><strong>Updating Spybot Search and Destroy</strong></p>

<p>Before you update Spybot Search and Destroy make sure you have  <a href="http://www.spybot.info/en/download/index.html" rel="external">the latest official version</a>. Older versions are no longer supported and will cause you a lot of grief when you immunize and scan for problems. Only download Spybot S&amp;D from the official website, at: <a href="http://www.spybot.info/">spybot.info</a>, or from its alternate domain: <a href="http://www.safer-networking.org/">Safer-Networking.org</a>. Fake versions with similar names will rip you off for payment to remove threats, whereas the real Spybot S&amp;D is free (<em>donations gladly accepted</em>).</p>

<p>In case you are new to Spybot S&amp;D, there are two ways to update the program and malware definitions. The preferred method (For Windows PCs) is to go to <b>Start > (All) Programs > Spybot - Search &amp; Destroy > Update Spybot - S&amp;D</b>. The independent update box will open. Leave the default options as is, unless you need all languages or want beta definitions, and click on "Search." Another box will open with "mirror" locations around the world where you can download updates. Select a location nearest to you from the list and click on "Continue." Make sure all updates are checked, then click on "Download." If all definitions are verified as being correct the check marks will disappear from the check boxes and be replaced with green arrow graphics. However, sometimes one or more mirror locations have not updated all of the definitions and you will get a red X for those definitions. Click on Go Back, select a different mirror, and try again. I have consistent success using Giganet or the Safer-Networking servers. When all updates have succeeded, click on "Exit." </p>

<p>Download links and more instructions about using Spybot Search and Destroy are in my article titled <a href="http://www.wizcrafts.net/blogs/2009/06/how_to_use_spybot_search_destroy_to_fight_ma.html">"How to use Spybot Search &amp; Destroy to fight malware"</a>.  </p>

<p>The description of the latest definition updates and false positive fixes are in my extended comments below.</p>]]></description>
         <link>http://www.wizcrafts.net/blogs/2009/06/spybot_search_and_destroy_definitions_update_59.html</link>
         <guid>http://www.wizcrafts.net/blogs/2009/06/spybot_search_and_destroy_definitions_update_59.html</guid>
         <category>Security Program Updates</category>
         <pubDate>Thu, 25 Jun 2009 22:57:05 -0500</pubDate>
      </item>
            <item>
         <title>My Spam analysis for June 15 - 21, 2009</title>
         <description><![CDATA[<p>This is the latest entry in my weekly series about classifications of spam, according to my custom filter rules used by <a href="/mailwasher.html">MailWasher Pro</a>. The categories are shown on the "Statistics" page > "Junk Mail," as a pie chart, based on <a href="/mwp-filters.html">my custom filters and blacklist</a>. The amount of email flagged as spam is shown on the "Summary" page of Statistics.</p>

<p>The volume of spam coming to my various honeypots and user accounts has decreased again this week. This is probably attributable to the <a href="http://www.networkworld.com/community/node/42434?source=NWWNLE_nlt_security_2009-06-05" rel="external">forced closure of Pricewert</a>, a spam-friendly hosting company, where Botnet command and control (C&am;C) servers and malware hosting was carried out by its customers, with no action taken by the company to halt those activities. With the C&amp;C controllers offline their Botnets cannot receive updates or new instructions and fall silent, like zombies. Spammers then find other means of delivering their crap to us.</p>

<p>The classifications of spam in my analysis can help you adjust your email filters according to what is most common, on a weekly basis. Much of the spam this week was for the fake pharmacies, which sell illicit and counterfeit pharmaceuticals, Nigerian 419 scams, and dating scams. Also, the volume of phishing scams targeting customers of various banks and credit cards remained strong again this week. </p>

<p>See my extended comments for this week's breakdown of spam by category, for June 15 - 21, 2009 and the latest additions to my custom MailWasher Pro filters</p>]]></description>
         <link>http://www.wizcrafts.net/blogs/2009/06/my_spam_analysis_for_june_15_21_2009.html</link>
         <guid>http://www.wizcrafts.net/blogs/2009/06/my_spam_analysis_for_june_15_21_2009.html</guid>
         <category>Spam Issues</category>
         <pubDate>Sun, 21 Jun 2009 16:29:05 -0500</pubDate>
      </item>
            <item>
         <title>Spybot Search and Destroy Definitions Updated on June 17, 2009</title>
         <description><![CDATA[<p>If you use <a href="http://www.safer-networking.org/en/home/index.html" rel="external">Spybot Search and Destroy</a> to protect your computer against spyware and malware, it is time again to run your manual updates. Malware writers are constantly modifying their programs to evade detection, so anti-malware vendors have to issue regular updates to keep up with the bad guys. New definitions and false positive fixes for Spybot Search and Destroy are usually released every Wednesday. This week's updates were released on schedule on June 17, 2009, as listed below. Some new fake security programs, new Virtumonde Trojans and new or modified bots and rootkits were added to the latest definitions.</p>

<p><strong>Updating Spybot Search and Destroy</strong></p>

<p>Before you update Spybot Search and Destroy make sure you have  <a href="http://www.spybot.info/en/download/index.html" rel="external">the latest official version</a>. Older versions are no longer supported and will cause you a lot of grief when you immunize and scan for problems. Only download Spybot S&amp;D from the official website, at: <a href="http://www.spybot.info/">spybot.info</a>, or from its alternate domain: <a href="http://www.safer-networking.org/">Safer-Networking.org</a>. Fake versions with similar names will rip you off for payment to remove threats, whereas the real Spybot S&amp;D is free (<em>donations gladly accepted</em>).</p>

<p>In case you are new to Spybot S&amp;D, there are two ways to update the program and malware definitions. The preferred method (For Windows PCs) is to go to <b>Start > (All) Programs > Spybot - Search &amp; Destroy > Update Spybot - S&amp;D</b>. The independent update box will open. Leave the default options as is, unless you need all languages or want beta definitions, and click on "Search." Another box will open with "mirror" locations around the world where you can download updates. Select a location nearest to you from the list and click on "Continue." Make sure all updates are checked, then click on "Download." If all definitions are verified as being correct the check marks will disappear from the check boxes and be replaced with green arrow graphics. However, sometimes one or more mirror locations have not updated all of the definitions and you will get a red X for those definitions. Click on Go Back, select a different mirror, and try again. I have consistent success using Giganet or the Safer-Networking servers. When all updates have succeeded, click on "Exit." </p>

<p>Download links and more instructions about using Spybot Search and Destroy are in my article titled <a href="http://www.wizcrafts.net/blogs/2009/06/how_to_use_spybot_search_destroy_to_fight_ma.html">"How to use Spybot Search &amp; Destroy to fight malware"</a>.  </p>

<p>The description of the latest definition updates and false positive fixes are in my extended comments below.</p>]]></description>
         <link>http://www.wizcrafts.net/blogs/2009/06/spybot_search_and_destroy_definitions_update_58.html</link>
         <guid>http://www.wizcrafts.net/blogs/2009/06/spybot_search_and_destroy_definitions_update_58.html</guid>
         <category>Security Program Updates</category>
         <pubDate>Wed, 17 Jun 2009 13:31:53 -0500</pubDate>
      </item>
            <item>
         <title>My Spam analysis for June 8 - 14, 2009</title>
         <description><![CDATA[<p>This is the latest entry in my weekly series about classifications of spam, according to my custom filter rules used by <a href="/mailwasher.html">MailWasher Pro</a>. The categories are shown on the "Statistics" page > "Junk Mail," as a pie chart, based on <a href="/mwp-filters.html">my custom filters and blacklist</a>. The amount of email flagged as spam is shown on the "Summary" page of Statistics.</p>

<p>Spam, spam, spam, spam, spam, spam, spam (<em>from the old Monty Python routine</em>)! The volume of spam coming to my various honeypots and user accounts has held steady this week, still at a relatively low volume (<em>some spammers do prune honeypot accounts from their lists</em>). Some of this is also attributable to the <a href="http://www.networkworld.com/community/node/42434?source=NWWNLE_nlt_security_2009-06-05" rel="external">forced closure of Pricewert</a>, a spam-friendly hosting company, where Botnet command and control servers and malware hosting was carried out by its customers, with no action taken by the company to halt those activities.</p>

<p>The classifications of spam in my analysis can help you adjust your email filters according to what is most common, on a weekly basis. Much of the spam this week was for the fake pharmacies, which sell illicit and counterfeit pharmaceuticals, Nigerian 419 scams, fake Cialis and Viagra. Also, the volume of phishing scams targeting customers of various Australian banks and credit card holders remained in the running this week. </p>

<p>See my extended comments for this week's breakdown of spam by category, for June 8 - 14, 2009 and the latest additions to my custom MailWasher Pro filters</p>]]></description>
         <link>http://www.wizcrafts.net/blogs/2009/06/my_spam_analysis_for_june_8_14_2009.html</link>
         <guid>http://www.wizcrafts.net/blogs/2009/06/my_spam_analysis_for_june_8_14_2009.html</guid>
         <category>Spam Issues</category>
         <pubDate>Sun, 14 Jun 2009 12:42:39 -0500</pubDate>
      </item>
            <item>
         <title>Windows, Firefox, Adobe Reader and Apple QuickTime updated</title>
         <description><![CDATA[<p>There have been significant program updates issued for Microsoft Windows, the Firefox browser, Adobe Acrobat and Reader and Apple's QuickTime browser plug-in. All updates were released this week to fix critical vulnerabilities that were reported and were being exploited by hackers and cyber-criminals. These criminal elements hijack legitimate websites and install hidden codes to redirect innocent visitors to hostile websites loaded with exploit attack codes. </p>

<p>Most of the successful attacks exploit vulnerabilities in browsers (usually Internet <em>Exploder</em>), or their installed add-ons and plug-ins. like Apple QuickTime, Adobe Flash and Reader (and other PDF readers) and Sun's Java plug-in. If any of these items are a vulnerable version you may have your computer hijacked by cyber-criminals who will make it a zombie member of their Botnet. This will turn your PC into a spam machine, or it could be used to attack websites or Governments, with whom the hackers have a difference of opinion.</p>

<p>In order to stay safe from the barrage of hack attacks targeting browsers and their plug-ins it is imperative that you keep Windows and its components and all third party add-ons up to date. One way is to always select the option to automatically check for, download and install updates to those programs. If there is no automatic update mechanism for a program you use you should check to see if it has been updated. This could be at the manufacturer's website, or by using the free <a href="http://secunia.com/vulnerability_scanning/online/" rel="external">Secunia Online Software Inspector</a> (requires current version of Java).</p>

<p>The details of this week's updates are below, in my extended comments.</p>]]></description>
         <link>http://www.wizcrafts.net/blogs/2009/06/windows_firefox_adobe_reader_and_apple_quick.html</link>
         <guid>http://www.wizcrafts.net/blogs/2009/06/windows_firefox_adobe_reader_and_apple_quick.html</guid>
         <category>Application Patches/Updates</category>
         <pubDate>Fri, 12 Jun 2009 13:07:04 -0500</pubDate>
      </item>
            <item>
         <title><![CDATA[How to use Spybot Search &amp; Destroy to fight malware]]></title>
         <description><![CDATA[<p><strong>About Spybot Search &amp; Destroy</strong></p>

<p>Spybot Search &amp; Destroy (S&amp;D), a product of <a href="http://www.safer-networking.org/" rel="external">Safer Networking Ltd.</a>, is a free ("<em>donation-ware</em>") security program that is used by millions of people to fight off spyware, keyloggers, Trojans, Botnet executables, adware, hostile domains, unwanted cookies and other types of malware in the wild. Being freeware it lacks some functions that are commonly implemented in commercial security programs. It has only manual updates, which are usually released once a week, on Wednesdays (<em>see my regular weekly articles about new updates</em>), and limited scanning presets. Most functions must be carried out manually, but hey, it's free! Despite these limitations Spybot S&amp;D is a well respected and effective anti-malware tool to add to your arsenal.</p>

<p>Spybot Search and Destroy can be downloaded for free from either <a href="http://www.spybot.info">www.spybot.info</a>, or from <a href="http://www.safer-networking.org">www.safer-networking.org</a>, or several official mirror sites. Don't fall for fake versions distributed by rogue anti spyware websites. Approved download mirror sites are listed on the <a href="http://www.safer-networking.org/en/mirrors/index.html" rel="external">Spybot S&amp;D downloads page</a>.</p>

<p>Once downloaded you should install the program onto your hard drive. There are installation options to watch for and the options you select will affect the normal operation of the program, when launched. One of the installation options is for the "TeaTimer" module. This is a realtime monitoring component that sits in your System Tray and launches itself into action whenever a change is about to be made to the system, the Registry, or your browser's home or search page. The program pops up little balloon alerts asking if you want to allow or deny the changes, or even notifying you that a suspicious program file was terminated automatically. These balloon popups can be annoying at times, although you can tell TeaTimer to remember your decisions. Unfortunately, there have been several serious false positives reported in the Spybot forums concerning the TeaTimer module deleting harmless files necessary for the operation of other programs or Windows itself. Lately, these false positives are becoming fewer and further between. It is your choice whether you want to use the TeaTimer module. I would keep Windows System Restore turned ON in case TeaTimer renders an important program, or part of Windows itself unusable (<em>use the "Last known good configuration" startup option</em>).</p>

<p>No matter which options you choose to install the program with, always select the option to update the program immediately. You can select or deselect all options later on, using the Advanced Mode. Once installed and updated it is time to Immunize, then scan for threats. These steps are described in my extended comments, along with download and forum links and more instructions about using Spybot Search and Destroy.</p>]]></description>
         <link>http://www.wizcrafts.net/blogs/2009/06/how_to_use_spybot_search_destroy_to_fight_ma.html</link>
         <guid>http://www.wizcrafts.net/blogs/2009/06/how_to_use_spybot_search_destroy_to_fight_ma.html</guid>
         <category>Technical Articles</category>
         <pubDate>Wed, 10 Jun 2009 14:39:47 -0500</pubDate>
      </item>
            <item>
         <title>Spybot Search and Destroy Definitions Updated on June 10, 2009</title>
         <description><![CDATA[<p>If you use <a href="http://www.safer-networking.org/en/home/index.html" rel="external">Spybot Search and Destroy</a> to protect your computer against spyware and malware, it is time again to run your manual updates. Malware writers are constantly modifying their programs to evade detection, so anti-malware vendors have to issue regular updates to keep up with the bad guys. New definitions and false positive fixes for Spybot Search and Destroy are usually released every Wednesday. This week's updates were released on schedule on June 10, 2009, as listed below. Some fake security programs, new Virtumonde Trojans and new or modified rootkits were added to the latest definitions.</p>

<p><strong>Updating Spybot Search and Destroy</strong></p>

<p>Before you update Spybot Search and Destroy make sure you have  <a href="http://www.spybot.info/en/download/index.html" rel="external">the latest official version</a>. Older versions are no longer supported and will cause you a lot of grief when you immunize and scan for problems. Only download Spybot S&amp;D from the official website, at: <a href="http://www.spybot.info/">spybot.info</a>, or from its alternate domain: <a href="http://www.safer-networking.org/">Safer-Networking.org</a>. Fake versions with similar names will rip you off for payment to remove threats, whereas the real Spybot S&amp;D is free (<em>donations gladly accepted</em>).</p>

<p>In case you are new to Spybot S&amp;D, there are two ways to update the program and malware definitions. The preferred method (For Windows PCs) is to go to <b>Start > (All) Programs > Spybot - Search &amp; Destroy > Update Spybot - S&amp;D</b>. The independent update box will open. Leave the default options as is, unless you need all languages or want beta definitions, and click on "Search." Another box will open with "mirror" locations around the world where you can download updates. Select a location nearest to you from the list and click on "Continue." Make sure all updates are checked, then click on "Download." If all definitions are verified as being correct the check marks will disappear from the check boxes and be replaced with green arrow graphics. However, sometimes one or more mirror locations have not updated all of the definitions and you will get a red X for those definitions. Click on Go Back, select a different mirror, and try again. I have consistent success using Giganet or the Safer-Networking servers. When all updates have succeeded, click on "Exit." </p>

<p>Download links and more instructions about using Spybot Search and Destroy are in my article titled <a href="http://www.wizcrafts.net/blogs/2009/06/how_to_use_spybot_search_destroy_to_fight_ma.html">"How to use Spybot Search &amp; Destroy to fight malware"</a>.  </p>

<p>The description of the latest definition updates and false positive fixes are in my extended comments below.</p>]]></description>
         <link>http://www.wizcrafts.net/blogs/2009/06/spybot_search_and_destroy_definitions_update_57.html</link>
         <guid>http://www.wizcrafts.net/blogs/2009/06/spybot_search_and_destroy_definitions_update_57.html</guid>
         <category>Security Program Updates</category>
         <pubDate>Wed, 10 Jun 2009 14:32:30 -0500</pubDate>
      </item>
            <item>
         <title>My Spam analysis for June 1 - 7, 2009</title>
         <description><![CDATA[<p>This is the latest entry in my weekly series about classifications of spam, according to my custom filter rules used by <a href="/mailwasher.html">MailWasher Pro</a>. The categories are shown on the "Statistics" page > "Junk Mail," as a pie chart, based on <a href="/mwp-filters.html">my custom filters and blacklist</a>. The amount of email flagged as spam is shown on the "Summary" page of Statistics.</p>

<p>Spam, spam, spam, spam, spam, spam, spam (<em>from the old Monty Python routine</em>)! The volume of spam coming to my various honeypots and user accounts has held steady this week, still at a relatively low volume (<em>some spammers do prune honeypot accounts from their lists</em>). The classifications of spam in my analysis can help you adjust your email filters according to what is most common, on a weekly basis. Much of the spam this week was for the fake pharmacies, which sell illicit and counterfeit pharmaceuticals, Nigerian 419 and lottery scams, Cialis and Viagra. Also, the volume of phishing scams targeting customers of various Australian banks and credit card holders remained steady this week. </p>

<p>See my extended comments for this week's breakdown of spam by category, for June 1 - 7, 2009 and the latest additions to my custom MailWasher Pro filters</p>]]></description>
         <link>http://www.wizcrafts.net/blogs/2009/06/my_spam_analysis_for_june_1_7_2009.html</link>
         <guid>http://www.wizcrafts.net/blogs/2009/06/my_spam_analysis_for_june_1_7_2009.html</guid>
         <category>Spam Issues</category>
         <pubDate>Sun, 07 Jun 2009 16:05:59 -0500</pubDate>
      </item>
            <item>
         <title>Spybot Search and Destroy Definitions Updated on June 3, 2009</title>
         <description><![CDATA[<p>If you use <a href="http://www.safer-networking.org/en/home/index.html" rel="external">Spybot Search and Destroy</a> to protect your computer against spyware and malware, it is time again to run your manual updates. Malware writers are constantly modifying their programs to evade detection, so anti-malware vendors have to issue regular updates to keep up with the bad guys. New definitions and false positive fixes for Spybot Search and Destroy are usually released every Wednesday. This week's updates were released on schedule on June 3, 2009, as listed below. Some fake security programs, Botnet executables and rootkits were added to the latest definitions.</p>

<p><strong>Updating Spybot Search and Destroy</strong></p>

<p>Before you update Spybot Search and Destroy make sure you have  <a href="http://www.spybot.info/en/download/index.html" rel="external">the latest official version</a>. Older versions are no longer supported and will cause you a lot of grief when you immunize and scan for problems. Only download Spybot S&amp;D from the official website, at: <a href="http://www.spybot.info/">spybot.info</a>, or from its alternate domain: <a href="http://www.safer-networking.org/">Safer-Networking.org</a>. Fake versions with similar names will rip you off for payment to remove threats, whereas the real Spybot S&amp;D is free (<em>donations gladly accepted</em>).</p>

<p>In case you are new to Spybot S&amp;D, there are two ways to update the program and malware definitions. The preferred method (For Windows PCs) is to go to <b>Start > (All) Programs > Spybot - Search &amp; Destroy > Update Spybot - S&amp;D</b>. The independent update box will open. Leave the default options as is, unless you need all languages or want beta definitions, and click on "Search." Another box will open with "mirror" locations around the world where you can download updates. Select a location nearest to you from the list and click on "Continue." Make sure all updates are checked, then click on "Download." If all definitions are verified as being correct the check marks will disappear from the check boxes and be replaced with green arrow graphics. However, sometimes one or more mirror locations have not updated all of the definitions and you will get a red X for those definitions. Click on Go Back, select a different mirror, and try again. I have consistent success using Giganet or the Safer-Networking servers. When all updates have succeeded, click on "Exit." </p>

<p>Download links and more instructions about using Spybot Search and Destroy are in my extended comments, along with the description of the latest definition updates and false positive fixes.</p>]]></description>
         <link>http://www.wizcrafts.net/blogs/2009/06/spybot_search_and_destroy_definitions_update_56.html</link>
         <guid>http://www.wizcrafts.net/blogs/2009/06/spybot_search_and_destroy_definitions_update_56.html</guid>
         <category>Security Program Updates</category>
         <pubDate>Wed, 03 Jun 2009 11:16:03 -0500</pubDate>
      </item>
            <item>
         <title>My Spam analysis for May 25 - 31, 2009</title>
         <description><![CDATA[<p>This is the latest entry in my weekly series about classifications of spam, according to my custom filter rules used by <a href="/mailwasher.html">MailWasher Pro</a>. The categories are shown on the "Statistics" page > "Junk Mail," as a pie chart, based on <a href="/mwp-filters.html">my custom filters and blacklist</a>. The amount of email flagged as spam is shown on the "Summary" page of Statistics.</p>

<p>The volume of spam coming to my various honeypots and user accounts has been steadily increasing over the past month. This is due to the activity of various wounded spam Botnets coming back to life (after the <a href="http://www.wizcrafts.net/blogs/2008/11/spam_volume_drops_after_mccolo_servers_force.html">takedown of McColo</a>), or new ones like the <a href="http://blog.trendmicro.com/pushdocutwail-%E2%80%93-from-russia-with-love-part-2-of-5/" rel="external">Russian Cutwail Botnet</a>, being pressed into service. The classifications of spam in my analysis can help you adjust your email filters according to what is most common, on a weekly basis. Much of the spam this week was for the fake Canadian Pharmacy, which sells illicit and counterfeit pharmaceuticals, Nigerian 419 scams, fake watches and Viagra, "stud" tips and male enhancement scams (same websites). I also saw an increase in Australian banking phishing scams this week. </p>

<p>See my extended comments for this week's breakdown of spam by category, for May 25 - 31, 2009 and the latest additions to my custom MailWasher Pro filters</p>]]></description>
         <link>http://www.wizcrafts.net/blogs/2009/05/my_spam_analysis_for_may_25_31_2009.html</link>
         <guid>http://www.wizcrafts.net/blogs/2009/05/my_spam_analysis_for_may_25_31_2009.html</guid>
         <category>Spam Issues</category>
         <pubDate>Sun, 31 May 2009 15:47:05 -0500</pubDate>
      </item>
            <item>
         <title>Spybot Search and Destroy Definitions Updated on May 27, 2009</title>
         <description><![CDATA[<p>If you use Spybot Search and Destroy to protect your computer against spyware, it is time again to run your manual updates. Malware writers are constantly modifying their programs to evade detection, so anti-malware vendors have to issue regular updates to keep up with the bad guys. New definitions and false positive fixes for Spybot Search and Destroy are usually released every Wednesday. This week's updates were released on schedule on May 27, 2009, as listed below. Somef fake security programs and rootkits were added to the latest definitions.</p>

<p><strong>Updating Spybot Search and Destroy</strong></p>

<p>In case you are new to Spybot S&amp;D, there are two ways to update the program and malware definitions. The preferred method (For Windows PCs) is to go to <b>Start > (All) Programs > Spybot - Search &amp; Destroy > Update Spybot - S&amp;D</b>. The independent update box will open. Leave the default options as is, unless you need all languages or want beta definitions, and click on "Search." Another box will open with "mirror" locations around the world where you can download updates. Select a location nearest to you from the list and click on "Continue." Make sure all updates are checked, then click on "Download." If all definitions are verified as being correct the check marks will disappear from the check boxes and be replaced with green arrow graphics. However, sometimes one or more mirror locations have not updated all of the definitions and you will get a red X for those definitions. Click on Go Back, select a different mirror, and try again. I have consistent success using Giganet or the Safer-Networking servers. When all updates have succeeded, click on "Exit." </p>

<p>Download links and more instructions about using Spybot Search and Destroy are in my extended comments, along with the description of the latest definition updates and false positive fixes.</p>]]></description>
         <link>http://www.wizcrafts.net/blogs/2009/05/spybot_search_and_destroy_definitions_update_55.html</link>
         <guid>http://www.wizcrafts.net/blogs/2009/05/spybot_search_and_destroy_definitions_update_55.html</guid>
         <category>Security Program Updates</category>
         <pubDate>Wed, 27 May 2009 16:45:58 -0500</pubDate>
      </item>
      
   </channel>
</rss>
