The following email is being sent to potential victims:
The blackout in the brackets after E-mail Service is a user id at an email account. I suspect the hackers bought the email address from a reseller and the email belongs to someone in our community.
The link is unusual and is probably the way future "bad links" will be made. It is a "tinyurl" Tinyurl is a web site that changes a long internet address into a short one. In this case, the url is http://tinyurl.com/q6ornxn This is called "cloaking" when it is used by black hackers. I can run an "unshortener" to get back the long url. However, when I do for this url it says it is not recognized. So this is not good at all.
A source of computer tips and secrets for friends, neighbors, and family of Duane Leet. Noone reading this blog is tracked and no information is associated with anyone.
Monday, July 27, 2015
Wednesday, July 22, 2015
Calls from 546-659-4152: what's going on?
Calls from this number are fraudulent and are costing our neighbors money. Too many are falling for it. The frauds call the same phone number several times a day. Your caller ID does not give a name. Out of curiosity or whatever you finally answer. Let me give you the details on what they do:
You know the drill, but this is serious now.
- The tell you that you have some malware on your computer (If you can understand them. The person on the other end has a very thick east Asian accent.)
- They will ask you to run eventvwr, an application that shows the log of all activities on your computer. (For windows, go to This log will always have warning messages and errors in it. It has nothing to do with malware or viruses.) It is normal operation to get errors. But they tell you that you have malware and viruses and your computer is in danger. They ask to log on to your computer to fix the erros.
- They ask you to download Teamviewer (you might already have it, but that doesn't matter) You give them an ID and password that teamviewer generates and they get control of your computer (Note that I use Teamviewer too. Teamviewer is not the problem; the problem is the person on the other end. )
- They will start asking for money. They will get your credit card information. (If you have fallen for this fraud, the credit card info is probably being sold on the criminal market. Get a new credit card.)
- They will run a number of free, open source and readily available programs that will always show that your computer has some problems. I think their favorite is CCleaner, which everyone should be using. You don't have to pay $100 for them to use it
- They may have you agree to a contract. If you do that, then you may not be able to stop payment on your credit card by reporting the fraud.
You know the drill, but this is serious now.
- Don't use your social security number as a method for verifying who you are.
- Don't fall for any of these fraudulent computer service outfits. In fact, if you want to, play them along and act stupid to waste their time. You can even let them on a computer you don't care to restore and keep them going as long as you can.
- Long passwords. Don't use the same password twice. Change your passwords.
- Always use https: as your internet site prefix. That sets a secure connection.
- Don't save any important documents "on line" without encrypting them. I can tell you how if you call.
- Stay away from suspicious sites and don't download any free software without validating that the site is trustworthy.
- PDF files still contain poison pills. So do Flash files (Video streaming files). It is getting to the point where other technology is being used to display video. You could turn off the Flash plugin and see if it is really used that much for what you do.
Monday, July 13, 2015
Fix-My-Computer Dude Update
In a previous blog entry I described the Fix-My-Computer Dude scam. This scam and many others like it have "technicians," supposedly from Microsoft, calling to tell you that they have detected a problem on your computer. You let them on your computer, show you "problems" and then try to get you to buy a service, perhaps up to $300/year. If you balk, then some scammers will start a program that destroys the data on your hard drive. (This doesn't necessarily happen with the Fix-My-Computer group.)
Well, there is more to the story. After I published the blog entry, I got comments that extolled the virtues of "Fix-My...". Apparently, the outfit has people trolling the internet for negative comments and they try to "correct" the misconception. For your entertainment, here is a screen shot of their comments:
Well, there is more to the story. After I published the blog entry, I got comments that extolled the virtues of "Fix-My...". Apparently, the outfit has people trolling the internet for negative comments and they try to "correct" the misconception. For your entertainment, here is a screen shot of their comments:
Is Window 10 Free... Forever, or Do You Have to Pay an Annual Fee After the First Year?
Well, it is almost time for Windows 7 and 8 users to be able to get the free upgrade to Windows 10. But there has to be a catch, right? The most common catch going around the internet is that it seems to be free for the first year, but, since Microsoft is moving to a rental model for programs, a fee will be charged for each year after the first. What is the truth? To summarize what is known:
For details, read http://www.forbes.com/sites/gordonkelly/2015/06/17/windows-10-free-for-1-year-what-happens-next/
- Windows 10 will be a free upgrade for Windows 7 and 8 users for the life of the current computer. There will be no annual fee. But only for the current computer.
- You will be able to download a full installation disk for Windows 10, so you will not be stuck with a use until fail scenario, or a use until you add something to the PC/tablet/smartphone scenario.
- Windows 10 free upgrade will not be available to Vista and XP users.
- There isn't any special support program for Windows 10. You get help from me, your own local IT expert, or from the Microsoft knowledge base. Fee for service through a contractor will be available on the Microsoft website.
For details, read http://www.forbes.com/sites/gordonkelly/2015/06/17/windows-10-free-for-1-year-what-happens-next/
Caller ID and Spoofing
Do you have caller ID on your phone line? I do. Increasingly, I am getting unsolicited calls from my local area code that are unsolicited and even dangerous (The ones that say your computer has been hacked.). This practice, called "spoofing," is a direct and conscious business decision on the part of the caller to avoid FCC regulations regarding unsolicited phone calls and caller id. For the regulations, in readable form, see https://www.fcc.gov/guides/caller-id-and-spoofing. "Intrastate calls are not subject to the caller id regulations." When I asked the last spoofer, who was marketing technical literature, including literature on internet security, why the company was using local numbers, she quickly and seamlessly replied that it was so I would have a local number to return the call. Ha!
So this is getting ridiculous.
I guess the response from us has to be NEVER answer a local call that doesn't give caller ID information you recognize. Let them leave a message.
And I'm outing eWeek (PCWeek) as the spoofer in this last case. Shame!
By the way, there are many computer and smart phone apps that will provide you with "spoofing" capability. For example, one can be downloaded at (don't bother going there unless you go in sandbox mode and as a incognito browse session) http://www.spoofcard.com/. Unbelievable!
So this is getting ridiculous.
I guess the response from us has to be NEVER answer a local call that doesn't give caller ID information you recognize. Let them leave a message.
And I'm outing eWeek (PCWeek) as the spoofer in this last case. Shame!
By the way, there are many computer and smart phone apps that will provide you with "spoofing" capability. For example, one can be downloaded at (don't bother going there unless you go in sandbox mode and as a incognito browse session) http://www.spoofcard.com/. Unbelievable!
Friday, June 26, 2015
Saving to Google Drive from Google Mail
Often I get emails that are really documents; eg, travel reservations, receipts, minutes... There is a way to save them to your Google Drive as a PDF file with two clicks. You can google "save gmail to google drive" and get many hits; one is http://lifehacker.com/quickly-save-an-email-to-google-drive-with-google-cloud-1593199317 The summary is:
- Click the little print icon at the top of your gmail email.
- You will get a Print dialog page. If the Destination field doesn't say "Save to Google Drive", click the change button under that. Find the entry "Save to Google Drive" and click it. If you don't see it in the selection list, click "More" at the bottom of the list.
- Back at the Print dialog page, click Print. Off it goes as a PDF to your drive
Thursday, June 18, 2015
Recent Corporate Hacks and What You Can Do to Protect Yourself
The US government has been hacked... I got my notice today that I was "on the list." South Carolina has been hacked. Lastpass has been hacked. Basically, you can be assured that information about everyone on line is in multiple databases being sold to nations, terrorist organizations, companies, and individuals that mean to do you harm. The information they have includes at least
Please begin using two factor authentication on all accounts that offer it. I use it. This is a difficult topic to describe in a written/short tutorial. Instead, please go to this UTube and follow what it says: https://www.youtube.com/watch?v=7VUPuf6uwi4. You can google "Youtube two step verification" and add whatever search terms you want to get other training videos.
For those using Lastpass, Lastpass uses two-step verification, but you have to start it. Furthermore, it uses, among others, "Google Authenticator," which makes it "easier" to supply the verification number. To start Lastpass two-step authentication, go to your "My Lastpass Vault" and open your account settings (on the left navigator). When the new view pops up, click "Multifactor options" in the top menubar. Follow the directions. You can select from many different smartphone applications as your "authentication helper," but if you are on google, you might as well have all your authenticator function in one place.
If you need help, let me know...
- Your name
- Your email address
- Some preferences on your buying habits
- Something about your past employment or activities
Please begin using two factor authentication on all accounts that offer it. I use it. This is a difficult topic to describe in a written/short tutorial. Instead, please go to this UTube and follow what it says: https://www.youtube.com/watch?v=7VUPuf6uwi4. You can google "Youtube two step verification" and add whatever search terms you want to get other training videos.
For those using Lastpass, Lastpass uses two-step verification, but you have to start it. Furthermore, it uses, among others, "Google Authenticator," which makes it "easier" to supply the verification number. To start Lastpass two-step authentication, go to your "My Lastpass Vault" and open your account settings (on the left navigator). When the new view pops up, click "Multifactor options" in the top menubar. Follow the directions. You can select from many different smartphone applications as your "authentication helper," but if you are on google, you might as well have all your authenticator function in one place.
If you need help, let me know...
Subscribe to:
Posts (Atom)