﻿<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
  <channel>
    <title>Destroy all Malware</title>
    <link>http://www.destroyallmalware.com/</link>
    <description>This blog is dedicated to revealing and destroy all forms of Malware; SPAM, VIRUS, Adware, Spyware.</description>
    <managingEditor>randy@kbcafe.com</managingEditor>
    <webMaster>randy@kbcafe.com</webMaster>
    <pubDate>Thu, 29 Jun 2006 22:07:16 GMT</pubDate>
    <lastBuildDate>Thu, 29 Jun 2006 22:07:16 GMT</lastBuildDate>
    <copyright>Copyright 2005 Randy Charles Morin</copyright>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <ttl>60</ttl>
    <image>
      <url>http://www.destroyallmalware.com/logo.jpg</url>
      <title>Destroy all Malware</title>
      <link>http://www.destroyallmalware.com/</link>
    </image>
    <rar:archive xmlns:rar="http://tempuri.org">http://www.destroyallmalware.com/archive.xml</rar:archive>
    <item>
      <title>100% Undetectable Malware</title>
      <description>&lt;P&gt;This researcher Joanna Rutkowska claims that she's got a prototype of a AMD Vista x64 malware component that is 100% undetectable.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;A href="http://theinvisiblethings.blogspot.com/2006_06_01_theinvisiblethings_archive.html"&gt;Joanna Rutkowska&lt;/A&gt;: Over the past few months I have been working on a technology code-named Blue Pill, which is just about that - creating 100% undetectable malware, which is not based on an obscure concept. The idea behind Blue Pill is simple: your operating system swallows the Blue Pill and it awakes inside the Matrix controlled by the ultra thin Blue Pill hypervisor. [cut] I would like to make it clear, that the Blue Pill technology does not rely on any bug of the underlying operating system. I have implemented a working prototype for Vista x64, but I see no reasons why it should not be possible to port it to other operating systems, like Linux or BSD which can be run on x64 platform.&lt;/BLOCKQUOTE&gt;
&lt;P&gt;She lost me when the operating system swallowed a blue pill. Obviously a metaphor, but hidden details often turn into algorithmic holes. Either way, this is just a taste of the future.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://theinvisiblethings.blogspot.com/2006_06_01_theinvisiblethings_archive.html"&gt;http://theinvisiblethings.blogspot.com/2006_06_01_theinvisiblethings_archive.html&lt;/A&gt;&lt;/P&gt;</description>
      <link>http://www.destroyallmalware.com/?guid=20060629150612</link>
      <pubDate>Thu, 29 Jun 2006 22:06:12 GMT</pubDate>
      <guid>http://www.destroyallmalware.com/?guid=20060629150612</guid>
      <comments>http://www.destroyallmalware.com/?guid=20060629150612</comments>
      <trackback:ping xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">http://www.destroyallmalware.com/trackback.aspx?guid=20060629150612</trackback:ping>
      <wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/commentapi.aspx?guid=20060629150612</wfw:comment>
      <wfw:commentRSS xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/20060629150612.xml</wfw:commentRSS>
      <category>malware</category>
      <category>vista</category>
      <category>amd</category>
      <category>x64</category>
      <source url="http://www.chipsquips.com/">Sterling Camden</source>
    </item>
    <item>
      <title>People Aggregator Spamming</title>
      <description>&lt;P&gt;&lt;A href="http://jeremy.zawodny.com/blog/archives/006959.html"&gt;Jeremy Zawodny is reporting&lt;/A&gt; that People Aggregator has gone live and is spamming everybody with invites. Marc Canter, one of the guys behind People Aggregator, is &lt;A href="http://blog.broadbandmechanics.com/2006/06/yes-indeed-were-inviting-people-in-now"&gt;denying it's spam&lt;/A&gt;. He claims...&lt;/P&gt;
&lt;BLOCKQUOTE&gt;perhaps anotehr way of looking at Jeremy’s statement is “too many Yahosters are inviting each otehr into the PeepAgg and not working hard enough!”&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Unfortunately, I'm getting invites to email addresses that I haven't used in years and I'm getting invites to auto-responder email addresses. Neither of which someone would knowingly invite. This is spam. Marc continues with...&lt;/P&gt;
&lt;BLOCKQUOTE&gt;So if you’ve contacted me or spammed me in the past 12-15 years - be prepared to be invited into the PeopleAggregator.&lt;/BLOCKQUOTE&gt;
&lt;P&gt;This explains some of the spam I'm receiving. Marc likely subscribed to some of my services and received a auto-responder verification email. Now he's sending invites to those robots. The problem with spam is that eventually even the good guys do it and justify it with dumb statements.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://jeremy.zawodny.com/blog/archives/006959.html"&gt;http://jeremy.zawodny.com/blog/archives/006959.html&lt;/A&gt;&lt;/P&gt;</description>
      <link>http://www.destroyallmalware.com/?guid=20060626185948</link>
      <pubDate>Tue, 27 Jun 2006 01:59:48 GMT</pubDate>
      <guid>http://www.destroyallmalware.com/?guid=20060626185948</guid>
      <comments>http://www.destroyallmalware.com/?guid=20060626185948</comments>
      <trackback:ping xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">http://www.destroyallmalware.com/trackback.aspx?guid=20060626185948</trackback:ping>
      <wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/commentapi.aspx?guid=20060626185948</wfw:comment>
      <wfw:commentRSS xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/20060626185948.xml</wfw:commentRSS>
      <category>peopleaggregator</category>
      <category>email</category>
      <category>spam</category>
    </item>
    <item>
      <title>Voicemail Sucks!</title>
      <description>&lt;P&gt;&lt;A href="http://technology.guardian.co.uk/weekly/story/0,,1802540,00.html"&gt;Charles Arthur&lt;/A&gt;: Voicemail is spectacularly inefficient and I hate it, so please don't leave me a message when you call.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://technology.guardian.co.uk/weekly/story/0,,1802540,00.html"&gt;http://technology.guardian.co.uk/weekly/story/0,,1802540,00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Randy: Couldn't agree more. About a year ago I disabled voicemail on my cell phone because the majority of voice mails were actually solicitations. I still have voice mail at home and I'm not really all that interested in picking up the phone when it rings, because although I want someone to clean my chimney, I don't want them calling every week to tell me they are in my neighbourhood. Now, if only they had a &lt;A href="http://www.iotum.com/"&gt;spam filter for voice calls&lt;/A&gt; that didn't require use of Outlook.&lt;/P&gt;</description>
      <link>http://www.destroyallmalware.com/?guid=20060626155857</link>
      <pubDate>Mon, 26 Jun 2006 22:58:57 GMT</pubDate>
      <guid>http://www.destroyallmalware.com/?guid=20060626155857</guid>
      <comments>http://www.destroyallmalware.com/?guid=20060626155857</comments>
      <trackback:ping xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">http://www.destroyallmalware.com/trackback.aspx?guid=20060626155857</trackback:ping>
      <wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/commentapi.aspx?guid=20060626155857</wfw:comment>
      <wfw:commentRSS xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/20060626155857.xml</wfw:commentRSS>
      <category>voicemail</category>
      <source url="http://jeremy.zawodny.com/">Jeremy Zawodny's Linkblog</source>
    </item>
    <item>
      <title>YPN Showcases spammer? </title>
      <description>&lt;P&gt;I found &lt;A href="http://ypnblog.com/blog/2006/06/21/publisher-spotlight-6/"&gt;YPN's&amp;nbsp;showcasing with Jeremy Shoemaker&lt;/A&gt; pretty disturbing. Jeremy runs a Website called ShoeMoney.com which I recently found was &lt;A href="http://www.destroyallmalware.com/?guid=20060619165653"&gt;spamming me&lt;/A&gt;. I sent Jeremy a reply indicating that spamming was against the AdSense terms. He replied "I guess its a good thing I dont use adsense anymore ;)". I noticed he had converted entirely to YPN. Anybody know the reason? Was he banned from AdSense for spamming? I replied back that &lt;A href="http://docs.yahoo.com/info/guidelines/spam.html"&gt;Yahoo! doesn't permit spamming&lt;/A&gt; either, but haven't heard further. This last email was sent only yesterday and today he's highlighted by YPN. It's pretty disturbing to me that Yahoo! is showcasing a spammer, but it's entirely possible that they don't know he's a spammer, so I'll give them the benefit of the doubt. Please spread this blog entry, if only to educate Yahoo! about who they are dealing with.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://ypnblog.com/blog/2006/06/21/publisher-spotlight-6/"&gt;http://ypnblog.com/blog/2006/06/21/publisher-spotlight-6/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.kbcafe.com/adwords/?guid=20060621114531"&gt;cross-posted&amp;nbsp;from Besting AdWords&lt;/A&gt;&lt;/P&gt;</description>
      <link>http://www.destroyallmalware.com/?guid=20060621115353</link>
      <pubDate>Wed, 21 Jun 2006 18:53:53 GMT</pubDate>
      <guid>http://www.destroyallmalware.com/?guid=20060621115353</guid>
      <comments>http://www.destroyallmalware.com/?guid=20060621115353</comments>
      <trackback:ping xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">http://www.destroyallmalware.com/trackback.aspx?guid=20060621115353</trackback:ping>
      <wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/commentapi.aspx?guid=20060621115353</wfw:comment>
      <wfw:commentRSS xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/20060621115353.xml</wfw:commentRSS>
      <category>yahoo</category>
      <category>ypn</category>
      <category>spam</category>
    </item>
    <item>
      <title>ShoeSpam</title>
      <description>&lt;P&gt;I was very excited to receive the following email (excerpts only) from &lt;A href="http://www.shoemoney.com/"&gt;Jeremy Shoemaker&lt;/A&gt;.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;Hello,&lt;BR&gt;sorry to spam you ;)&lt;/BLOCKQUOTE&gt;
&lt;P&gt;No unsubscribe link and it was obviously&amp;nbsp;an auto-mailer, as it didn't reference me by name or mention anything about me, my blogs or websites. Jeremy is an AdSense publisher and doesn't appear to be aware that SPAMming&amp;nbsp;is against the &lt;A href="https://www.google.com/adsense/localized-terms"&gt;AdSense terms&lt;/A&gt;&amp;nbsp;and is a valid reason for Google to terminate your AdSense account. I've heard Jeremy makes some pretty serious coin via AdSense. You can't stop most SPAM, but I'm entirely sure that by CCing &lt;A href="mailto:adsense-abuse@google.com"&gt;AdSense&amp;nbsp;abuse&lt;/A&gt; on my reply, that Jeremy will think twice next time.&lt;/P&gt;</description>
      <link>http://www.destroyallmalware.com/?guid=20060619165653</link>
      <pubDate>Mon, 19 Jun 2006 23:56:53 GMT</pubDate>
      <guid>http://www.destroyallmalware.com/?guid=20060619165653</guid>
      <comments>http://www.destroyallmalware.com/?guid=20060619165653</comments>
      <trackback:ping xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">http://www.destroyallmalware.com/trackback.aspx?guid=20060619165653</trackback:ping>
      <wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/commentapi.aspx?guid=20060619165653</wfw:comment>
      <wfw:commentRSS xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/20060619165653.xml</wfw:commentRSS>
      <category>spam</category>
    </item>
    <item>
      <title>The SPAM Trademark</title>
      <description>&lt;DIV style="FLOAT: right" __designer:dtid="281474976710660"&gt;
&lt;DIV __designer:dtid="281474976710661"&gt;&lt;A href="http://www.flickr.com/photos/dalangalma/34165623/" __designer:dtid="281474976710662"&gt;&lt;IMG src="http://static.flickr.com/22/34165623_5877f9098a_m.jpg" __designer:dtid="281474976710663"&gt;&lt;/A&gt;&lt;BR __designer:dtid="281474976710664"&gt;&lt;/DIV&gt;
&lt;DIV __designer:dtid="281474976710665"&gt;&lt;A title="Click this link to find out details of the Creative Commons license associated with this image." href="http://creativecommons.org/licenses/by/2.0/" __designer:dtid="281474976710666"&gt;&lt;IMG style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" height=31 alt="There is a Creative Commons license attached to this image." src="http://creativecommons.org/images/public/somerights20.gif" width=88 __designer:dtid="281474976710667"&gt;&lt;/A&gt; &lt;/DIV&gt;&lt;/DIV&gt;
&lt;P __designer:dtid="281474976710668"&gt;&lt;A href="http://news.bbc.co.uk/2/hi/uk_news/wales/south_west/5084002.stm" __designer:dtid="281474976710669"&gt;NetBop has successfully trademarked the term bopspam&lt;/A&gt;, at the objection of Hormel Foods, maker and &lt;A href="http://www.spam.com/ci/ci_in.htm" __designer:dtid="281474976710670"&gt;trademark&lt;/A&gt; holder of Spam, the spiced ham.&lt;/P&gt;
&lt;P __designer:dtid="281474976710671"&gt;&lt;A href="http://news.bbc.co.uk/2/hi/uk_news/wales/south_west/5084002.stm" __designer:dtid="281474976710672"&gt;http://news.bbc.co.uk/2/hi/uk_news/wales/south_west/5084002.stm&lt;/A&gt;&lt;/P&gt;</description>
      <link>http://www.destroyallmalware.com/?guid=20060619094012</link>
      <pubDate>Mon, 19 Jun 2006 16:40:12 GMT</pubDate>
      <guid>http://www.destroyallmalware.com/?guid=20060619094012</guid>
      <comments>http://www.destroyallmalware.com/?guid=20060619094012</comments>
      <trackback:ping xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">http://www.destroyallmalware.com/trackback.aspx?guid=20060619094012</trackback:ping>
      <wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/commentapi.aspx?guid=20060619094012</wfw:comment>
      <wfw:commentRSS xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/20060619094012.xml</wfw:commentRSS>
      <category>spam</category>
      <category>trademark</category>
      <source url="http://blogs.msdn.com/alexbarn/archive/2006/06/18/636606.aspx">Alex Barnett</source>
    </item>
    <item>
      <title>New Vulnerability in Microsoft Excel</title>
      <description>&lt;P&gt;&lt;A href="http://blogs.technet.com/msrc/archive/2006/06/16/436174.aspx"&gt;Mike Reavey&lt;/A&gt;: We've received a single report from a customer being impacted by an attack using a new vulnerability in Microsoft Excel. [cut] In order for this attack to be carried out, a user must first open a malicious Excel document that is sent as an email attachment or otherwise provided to them by an attacker. &lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/msrc/archive/2006/06/16/436174.aspx"&gt;http://blogs.technet.com/msrc/archive/2006/06/16/436174.aspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Randy: Just a reminder. Don't open email attachments unless you know, for a fact, that it doesn't contain a virus.&lt;/P&gt;</description>
      <link>http://www.destroyallmalware.com/?guid=20060616173743</link>
      <pubDate>Sat, 17 Jun 2006 00:37:43 GMT</pubDate>
      <guid>http://www.destroyallmalware.com/?guid=20060616173743</guid>
      <comments>http://www.destroyallmalware.com/?guid=20060616173743</comments>
      <trackback:ping xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">http://www.destroyallmalware.com/trackback.aspx?guid=20060616173743</trackback:ping>
      <wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/commentapi.aspx?guid=20060616173743</wfw:comment>
      <wfw:commentRSS xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/20060616173743.xml</wfw:commentRSS>
      <category>microsoft</category>
      <category>excel</category>
      <category>exploit</category>
    </item>
    <item>
      <title>PayPal Security Flaw allows Identity Theft</title>
      <description>&lt;P&gt;&lt;A href="http://news.netcraft.com/archives/2006/06/16/paypal_security_flaw_allows_identity_theft.html"&gt;Netcraft&lt;/A&gt;: A security flaw in the PayPal web site is being actively exploited by fraudsters to steal credit card numbers and other personal information belonging to PayPal users.&lt;/P&gt;
&lt;P&gt;Randy: Lesson. Never access a website where money or vital personal information is exchanged via a link. Always type the URL by hand in the address bar. The phishing attacks are getting more and more clever.&lt;/P&gt;</description>
      <link>http://www.destroyallmalware.com/?guid=20060616090922</link>
      <pubDate>Fri, 16 Jun 2006 16:09:22 GMT</pubDate>
      <guid>http://www.destroyallmalware.com/?guid=20060616090922</guid>
      <comments>http://www.destroyallmalware.com/?guid=20060616090922</comments>
      <trackback:ping xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">http://www.destroyallmalware.com/trackback.aspx?guid=20060616090922</trackback:ping>
      <wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/commentapi.aspx?guid=20060616090922</wfw:comment>
      <wfw:commentRSS xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/20060616090922.xml</wfw:commentRSS>
      <category>paypal</category>
      <category>phishing</category>
    </item>
    <item>
      <title>Lazy Phisher</title>
      <description>&lt;P&gt;I find the phishers have gotten awefully lazy :-)&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.giveusallyourmoney.com/"&gt;http://www.giveusallyourmoney.com/&lt;/A&gt;&lt;/P&gt;</description>
      <link>http://www.destroyallmalware.com/?guid=20060615035250</link>
      <pubDate>Thu, 15 Jun 2006 10:52:50 GMT</pubDate>
      <guid>http://www.destroyallmalware.com/?guid=20060615035250</guid>
      <comments>http://www.destroyallmalware.com/?guid=20060615035250</comments>
      <trackback:ping xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">http://www.destroyallmalware.com/trackback.aspx?guid=20060615035250</trackback:ping>
      <wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/commentapi.aspx?guid=20060615035250</wfw:comment>
      <wfw:commentRSS xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/20060615035250.xml</wfw:commentRSS>
      <category>phising</category>
    </item>
    <item>
      <title>eBay.co.uk spam</title>
      <description>I seem to be getting quite a few spams related to eBay.co.uk and PayPal redemption code CELEBRATION3. Is eBay becoming a spammer? That would be quite disappointing.</description>
      <link>http://www.destroyallmalware.com/?guid=20060614132336</link>
      <pubDate>Wed, 14 Jun 2006 20:23:36 GMT</pubDate>
      <guid>http://www.destroyallmalware.com/?guid=20060614132336</guid>
      <comments>http://www.destroyallmalware.com/?guid=20060614132336</comments>
      <trackback:ping xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">http://www.destroyallmalware.com/trackback.aspx?guid=20060614132336</trackback:ping>
      <wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/commentapi.aspx?guid=20060614132336</wfw:comment>
      <wfw:commentRSS xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/20060614132336.xml</wfw:commentRSS>
      <category>ebay</category>
      <category>spam</category>
    </item>
    <item>
      <title>Phishing Alert: MySpace </title>
      <description>&lt;BLOCKQUOTE&gt;Websense Security Labs has discovered a phishing attack that attempts to steal the account information of MySpace.com users. A hyperlink is first delivered to victims via AOL Instant Messenger. Users&amp;nbsp;who follow this link are taken to a fraudulent website that spoofs the MySpace.com login page. This page captures their MySpace account information.&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;A href="http://www.websense.com/securitylabs/alerts/alert.php?AlertID=504"&gt;http://www.websense.com/securitylabs/alerts/alert.php?AlertID=504&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Something to be weary of. It's not like losing your MySpace account information is really that important, but I suspect the popularity of MySpace may help educate the average Internet user about phishing attacks.&lt;/P&gt;</description>
      <link>http://www.destroyallmalware.com/?guid=20060605161042</link>
      <pubDate>Mon, 05 Jun 2006 23:10:42 GMT</pubDate>
      <guid>http://www.destroyallmalware.com/?guid=20060605161042</guid>
      <comments>http://www.destroyallmalware.com/?guid=20060605161042</comments>
      <trackback:ping xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">http://www.destroyallmalware.com/trackback.aspx?guid=20060605161042</trackback:ping>
      <wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/commentapi.aspx?guid=20060605161042</wfw:comment>
      <wfw:commentRSS xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.destroyallmalware.com/20060605161042.xml</wfw:commentRSS>
      <category>myspace</category>
      <category>phishing</category>
    </item>
  </channel>
</rss>