Category: General Rants
Posted by: Pei
Oh man, I can’t believe I fell for the ‘click me’ virus attack. I’ve not been suckered in YEARS. Any way – this is how it started – I got an IM from Mark from Windows Live Messenger asking me to view his 'Facebook' picture. Unfortunately I don't have a screenshot of that, but Jeff received the same thing:



This just looked so innocent.


The doofus that I am, I accepted the file, and as soon as it downloaded (which was very quick – much faster than my grey celled neurons could fire apparently), I clicked to Open which then opened a Winzip file with the following window.



Again, not thinking at all, I double clicked on photo07-04.pif (ARG HOW COME I DID NOT NOTICE THAT IT WAS A PIF FILE ?!?) which froze my pc, with the msn window blinking sporadically.

Immediately I realized what happened and called at Jeff to unplug the wireless router while I slammed the ‘OFF’ button on the laptop; praying and hoping the word document I was working on had been saved prior to that.

By that time, the virus had spread itself to my contacts and Jeff received an IM apparently from me, with an attached zip file.



I then went on my desktop, kicked off an older version of msn and IM’ed all online and offline contacts telling them not to open any files that came from me. Fortunately most of them realised what it was and declined to accept the file, with exception of Seow Ping; whom I hope is able to recover. (Marts later confirmed that it only sent itself to online contacts. Phew!)

Once that was done, I fearfully turned on my laptop, hoping that the virus is benign and apart from reproducing itself to all my contacts, it has not touched my hard disk at all.

Checking for Virus files



The first thing I did was to do a quick search on my hard disk for *.pif – it found three instances of the virus file (you can only see one in the screenshot above because I’ve deleted the other two and kept this one to test my anti-virus against it). It stored itself as:

1. An MSDOS shortcut called ‘photo-07-04’ within ‘C:\Documents and Settings\Pei\Local Settings\Temp’. <-- this file was probably produced when I doofusly double clicked the .pif file within the zipped file.

2. A zipped file called ‘picture07-04.zip’ within ‘C:\Documents and Settings\Pei\My Documents\My Received Files’.

3. A zipped file called 'picture07-04.zip' located in ‘C:\Windows’.

If you want to double check, make sure to do a search for ‘picture07-04’ and ‘photo07-04’ in all local disks.


Offending file located in 'My Received Files' for Windows Live Messenger


Checking the registry

I believe that it also stored itself in the registry. To check this:
1. Go to Start --> Run. Type ‘Regedit’ and press Enter.
2. On file menu, go to Edit --> Find
3. Type in photo07-04 and then click ‘Find’

I found an entry in the following folder - HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache, and promptly deleted it. It was only a few minutes later that I realised I wanted to blog about this so that other people can be aware that I regretted doing it before taking a screenshot. The entry in the registry referred to the following path: C:\Documents and Settings\Pei\Local Settings\Temp\photo07-04 (although I cannot be sure if it was the zip file or the pif file or the MSDOS shortcut it referred to).

Jeff thought that the MUICache registry entry may be a red herring as it probably listed down most recently launched file from the shell, so after a bit of digging, it looks like he may be right. In any case, I wasn't going to let it stay in there so I nuked that entry with a index finger jabby action on the Delete key.

I did another search within the registry for 'picture07-04' and found two string entries in
[HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\filemenu] called 'C:\WINDOWS\picture07-04.zip' - one pointing to 'C:\Documents and Settings\Pei\My Documents\My Received Files' and the other to 'C:\Windows'. Whilst this did not look too ominous as it probably referred to the most recently opened zip files, I deleted both entries any way.

I also ran a complete scan on all local drives using company anti-virus AVG – it came out clean, must to my disappointment as I had expected that file I left in the 'My Received Files' folder to be detected. Then again, Jeff did say that this was probably a fairly new virus as we could not find any reference to it on the web. Also, I don't think that AVG scans IM entries and files.


A clean bill of health.. according to AVG.


I then plugged our wireless router back on, and connected to Symantec Online and did an online check. Had to agree and consent to all legal stuff, enabled ActiveX and Javascript scripting, but once that was done, it toddled off and did its thing. 1.5 hours later, it was done although it did not check compressed files - see below.


This isn't really good enough, is it?


So apparently, other than the zip file that I've got in 'My Received Files' folder, it appeared that I was virus-free, according to both AVG and Symantec online. This could mean two things:

1. I really am virus-free
2. It's too new to be detected, and I am essentially screwed.

Little did I know...

Anyway, I decided to rename the extension of the file to picture07-04.bad.

Just in case.

At precisely 4.00pm, Messenger spammed all my online contacts again. But this time, no files were attached:


Jeff's clock had reset to 06.30 for some bizarre reason,
but this was received at 4pm.


Reinstalling MSN
I thought that barring a complete reformat and rebuild (which I REALLY don't want to do), the next logical step should be to reinstall the damn thing:

1. Go to Start --> Control Panel --> Add/Remove Programs, 2. Remove Windows Live Messenger. Does not require reboot.
3. Go online to download the latest one
4. Reinstall.

Once the reinstall completed, I modified laptop time to 17.59pm, and waited to see if it would spam again on the hour - as I was guessing that was its behaviour, based on what happened earlier.

I got Marts to monitor for me, but nothing went out, so I am cautiously hopeful. I really don't want to rebuild my laptop as it would be such a pain... but it WOULD serve me right.

Any way, that's how I spent my Sunday afternoon on one of the hottest summer days in the UK so far. At least this will teach me to be more careful and NOT TO DOUBLE-CLICK ANY PIF FILES.

** UPDATE **
For those who land on this page looking for solution to the virus please click here and read the comment.

Posted at 17:32 PM
Email this entry to a friend
Category: General Rants
Posted by: Pei
I wrote this while sitting down at Starbucks Shepherd's Bush on Thursday, about 45 minutes early for the training I am supposed to deliver on client site today. I know this is one of the things Waz has boycotted, based on his principals about not buying, using, eating anything from Israel or Jewish in nature. I think that's alright.

But I am a lot more base than that, and I enjoy my coffee (though I have cut down quite a bit) and sitting in the 'decadent' coffee shop with my notebook on my lap, enjoying jazz or whatever I've got on my Sony really kicks off my creative writing juice.

It's actually where I work best, and if I can find a Starbucks near me, with a nice butt-hugging sofa next to an electrical point where I can plug in my notebook, I'd stay there for hours.

On another note - I am going to Brussels this weekend to see Suzi. She's an old friend with whom I have lived with for a few months in Brighton some ten years back. We've both gone through a lot in our personal lives, but have kept in touch. She had since married a dutch (I call him Bastard) who is a nasty character. Having come from a dysfunctional family, she thought that marriage was her escape route. She was quite wrong.

Not only was he emotionally abusive, but he kept her as a slave - taking all her money, keeping her at home to look after her two beautiful kids and basically, cook and clean for him with nothing in return. During my last trip there about two years ago, I saw how he treated her and the kids, and promptly encouraged her to seek legal help. She was beaten, emotionally and spiritually, and the desolate depression had stole her soul. I could not bear to see that, so I gave her the needed 'push' to get herself some professional help.

Almost two years later, she has divorced and is now separate from the Bastard. Whilst the courts awarded her custody of the children, she did not get any alimony from the Bastard ex-husband, who works for ******, raking in more than £5000 every month. Aside from approximately £125 per child he pays per month, he gives her nothing.

Bastard bastard bastard.

So I am going to see her after all this time, to bring her her Asam Laksa Maggi Mee, Milo, malaysian foodie things (I'm giving her my 'stock' because I can always go home to buy some more. She has only been back about twice within the last 5 years, and the last one was to go to her father's funeral). I also got her loads of toys and clothes for the kids.

We'll walk around Brussels, talk a lot, shop a lot, and generally have a blast. She's not had a holiday since... I dont know. The kids will be with bastard ex-husband this week, so she will have time to be free and just have a worry-free weekend. Anyway that's it for now.

Posted at 12:56 PM
Email this entry to a friend
Category: General Rants
Posted by: Pei
Which means we lost the Wokingham house.

Goshdarnit.

For want of stronger swear words.

Posted at 17:07 PM
Email this entry to a friend
Category: General Rants
Posted by: Pei
...got Mr Clarksona sound beating from the Malaysian government. He thought that the Kelisa was an "unimaginative junk, with no soul, no flair and no passion" - and proceeded to blow it up. ABSOLUTE CLASS!



Apparently "Perodua had not received a single complaint from UK owners," according to Minister Abdul Raman Suliman. But maybe it is because it hasn't sold at all? Ok, maybe approximate 2422.03 units were sold in the UK if you believe THIS report. It doesn't give a time frame though, per year? Per month? Since it was launched in 2001? Ah found it over here.

Apparently the Kelisa has been bought by more than 2400 poor sods in the UK between 2001 and 2007, averaging 346 cars a year. That is piss poor.

Anyway you have to see this. It's just top class.



Having lived in the UK for the past 8 years, I have never seen a Kelisa. Or a new saga or wira (manufactured by Proton, our 'largest' car manufacturer in Malaysia). Most of the protons I see have a K-L registration (i.e. 1992/93). Any Malaysian who has ever own a Proton or Perodua car will tell you honestly, they are rubbish. Absolute crap. I just don't have Jeremy's large repertoire of descriptive adjectives to describe it. Just as atrocious as the Perodua website.

A mere 'dink' would crumple a Kanchil. A small tap would crush a Kenari. A nudge would crumble a Nippa. They sell well in Malaysia because of the government's high entry barrier for imported cars. So that our industry would 'succeed'. So that we would have 'more jobs'. So that we can hit our Wawasan 2020 (Vision 2020) of becoming a Developed nation.

This is just blatant protectionism. The only thing we have got out of this is a bunch of lazy politicians whose hypocritical stance just beggers belief. They'd spout rubbish about quality of Malaysian made goods but would shamelessly drive around in imported Mercedes and buy Italian furniture and foreign goods.

Quality of manufacturing is so poor that stuff like cars barely make the European safety standard. Here you go - one star on safety for the Kelisa. And the really sad thing is that it just shows how little regard the government has for the lives of the local Malaysians. What's worst is that it affects the poor because this segment of the population just cannot afford the steep price of a safer imported car.

It is ever more obvious during festive season - "Over the 15 days to Nov. 10, when Malaysia celebrated the Muslim festival of Hari Raya Aidilfitri and the Hindu holiday of Deepavali, 233 people died in 13,462 accidents" according to a Bloomberg report. Also, "Road accidents in Malaysia claimed 5,623 lives last year and have killed more than 5,200 people each year since at least 2001".

One big factor is that (ok I am making a sweeping statement here) Malaysians are also really really bad drivers who are generally rude and discourteous. This culture contributes to the high accident rate as much as poorly manufactured vehicles they race around in.

I used to be an ugly driver. You have to be to 'survive' on the Malaysian roads - otherwise you get honked, cussed or worse - beaten up in a road rage accident. Having lived here for so long though, I have found driving in the UK to be an incredibly pleasant experience. Anger, stress and frustration on the roads are almost non-existent. And now I am far too chicken to drive back home, and leave that to my lovely accomodating parents to ferry us around when we are there. Or we stick to taxis. I can't face driving in Malaysia again.

It's just that I realize how dangerous it can be to how blasé some drivers are (you know who you are!)... it really is like gambling with your own life. Accident rates can be easily reduced by drivers driving more carefully, more mindfully, more courteously, and in safer cars. I am glad that my family have got rid of all the cheap tinny Protons (well except for my brother's wira) and moved onto Toyota, which has much better safety features.

Anyway, I shall now get off my high horse. This Jeremy Clarkson thing brought up by some clueless politicians in Malaysia got me bristling.

Posted at 20:02 PM
Email this entry to a friend
Category: General Rants
Posted by: Pei
Andy had been working non-stop since the new year, doing weekends, running himself down - so when I found out that he had fallen sick it came as no surprise. That's why I am in Portsmouth today instead of him.

However, I am supposed to be installing a new component of the product by our supplier which I have never done before, and like most other (cough) professional product, the documentation is scarce, difficult to obtain (wasn't on the BMC website) and I only managed to get a copy from a kind-hearted consultant.

However, the documentation was poorly written and DID NOT mention that the add-on product would:
- stop the web services, which would
- KILL the live site, which would
- result in my mangled corpse hanging from a flagpole.

Good thing I decided to test it out on my virtual machine first, otherwise I would be so dead. It's a brand new product to me - never seen it before, never installed/configured/implemented it.

I am really lucky I've got a lot of goodwill and brownie points with this client, who understands that I have been thrown in the deep end (I was also honest in saying I have no experience with this add-on) so they are giving me some breathing space and not pressuring me too much. Really need it as the add-on is a bit of a nightmare - am attempting to restore the client db on my virtual pc which is causing a lot of issue and headache at the moment.

It's a survey product - randomly sending out survey forms when calls are closed, based on certain rules set up on the server end. One would have thought that such a small/simple/mini add-on would be dead easy to set up..

but no...

My character needs building. Apparently.

Posted at 11:37 AM
Email this entry to a friend

24/01: Crap

Category: General Rants
Posted by: Pei
Lost my glasses yesterday. It was almost exactly the same way I lost my old one about 6 years ago. I had placed it in my bag in (I thought) a secure pocket as it was flurrying and it was a bit too cold for me to unzip my bag and take out the spectacle case. I think that when I took out my hat, the glasses fell out too.

This incident happened before, only the last time was in a restaurant where we were celebrating X'mas in my first company. Took out my blue fleece hat and the ultra-light pair of glasses fell out, and I didn't notice for ages because only one of my eye is a duffer, and my other eye compensates for it most of the time.

I only notice that I am semi-blind when I try to read or do something a bit more microscopic. I have a spare at home (although they are a tad unfashionable but o well, that's my punishment for being so careless).

I seem to keep losing stuff, I think I must start super-glueing my possessions to me, so I don't lose them.

At the moment, I am a semi blind one-eye pirate.

Arrrrr.





Posted at 07:17 AM
Email this entry to a friend
Category: General Rants
Posted by: Pei
I've been trying to bar my Ipaq IMEI number since my handbag got stolen. Orange (our provider) said they can't do it because they did not provide the handset (BULLSHIT) and the police can't do it because they don't (WHY!??!) and HP can't do it (ok granted, they could only log it as stolen and send a swat team if they call for support).

THis is SO BULLSHIT. Sorry, you can tell I am not pleased. A friend who had a contact in Vodafone said that they can block IMEI numbers of stolen phone that connect to their network. But Orange was just utterly useless.

"Hello, I had my phone stolen (have crime reference number here) and need to block the IMEI number of the handset."

"Was the handset provided by Orange?"

"No, my husband bought me that phone."

"Then I am sorry, there's nothing we can do because we didn't provide the handset."

"So tell me what can I do to block it?"

"Nothing, you will just have to deal with it."

"WHAT!!!!!!!!!!!!"



I called my friend to ask his Vodafone contact for help but the phone had never connected to their network. So it looks like there is nothing I can do to stop the b***** from either using the handset or selling it on ebay to some sucker to use it.

Honestly, my original feeling about this was - I hope the thief had better be like poor, destitute, starving and desperate and is stealing so that she didn't have to prostitute her body away. Otherwise, I hope she gets hoards of fleas, ticks, and lice in all hairy crevice of her body.

Anyway time for dinner. Continue rant later.

Posted at 19:10 PM
Email this entry to a friend
Category: General Rants
Posted by: Pei
Does anybody else find this remotely farsicle (ok I can't spell) or ridiculous??

Heather Mills is launching a charity record to pay tribute to George Best, where the money goes to the Donor Family Network. Don't get me wrong, I am all for charity. But it's almost like... Let's make a movie extolling the paragon of virtue that is Saddam and give the proceeds to the family of those he tortured and killed.

It's in such bad taste that I really don't know what to say. George Best has GOT himself a brand new liver, which he then proceeded to destroy and kill himself in the process. What is the message here? Use this man as an example of why we should ALL give up our organs? So rich and indulgent people who have weakness for alcohol or decadent lifestyle can make our sacrifice a laughable act?

Sorry, but I just feel that this is so inappropriate and .. well, plain crap. I don't think that raising awareness or charity is bad, but this is done in the WRONG context, with the wrong person as a centrepiece.

Ok I've had my say. I will now shut up.

Posted at 16:58 PM
Email this entry to a friend
Category: General Rants
Posted by: Pei
I've had a bad week last week - screwed up twice, and am lucky I still have a job. I had dropped the ball on two cases I was handling, but did some quick damage control which probably not only salvaged my pride but my butt ;)

On client site in Portsmouth, sitting twiddling thumbs at the mo. We are supposed to be going live with the new system, however the new SQL Server db cannot see the Oracle Server (old db to be decommissioned) for the data migration because the SQL server has been moved to the DMZ, and the firewall ports locked down. The company had outsourced its router/dns control to a third party and they've had to make it a sev one to turn on the correct port - only to find that the Oracle Listener uses a dynamic port allocation, which means that it might not do it anyway.

Am hoping we get to finish it tonight, otherwise it is no-go and I'll have to come back here another time to do it again. Not hugely keen on that because I'd would prefer to go home tomorrow.

The cilent had actually left the testing so late that I was only given a "list of issues" last Thursday, along with an earful why they have not been resolved which (cough) was actually caused by the late testing/training. Which was fixed by me coming over a day earlier to resolve their bulky list of issues brought up during testing/training last week.

But then again - that's the nature of IT projects, and here I am doing some PR and damage control. It's really nothing major, but a good exercise in managing expectation. People who wait until the last minute to do stuff always create headache for themselves. Man, I must be an expert in this arena!

So I do my best to pacify ruffled feathers, and today we are meant to do the final tidying up before go-live ... which has been scheduled for 8pm after migrating all the data. However, we are still waiting for the link to be connected (something the server guys should have picked up when they decided to move the new server into the DMZ), so... it's either a very long and late night for us, or rescheduling.

Thankfully my boss is here with me today and hopefully things go well so my butt can be perserved for yet another day.

I have become rather attached to it.

Posted at 18:00 PM
Email this entry to a friend
Category: General Rants
Posted by: Pei
Sometimes. Unbelievable but true. By 1pm today, we had done 3 things that would have taken weeks in the UK.

1. I had dropped into my clinic and had blood extracted for a cholesterol & liver function test (without appointment)

2. Mum had dropped into her local medical centre, booked an x-ray for her spine (on advice of her chiropractor), and it was less than 45 minutes before she had snaps taken of her innards and received not only the 6 beautifully developed black and white classic pictures of her bones but she also had a report! Granted it was a brief report but it seemed pretty good nonetheless.

3. We had gone to my local HSBC bank and had my Internet banking password reset after some embarrasing explanation of how dad had blocked it.

Can you imagine that? Last year I had to see a specialist for my liver problem and it was just a couple of snaps before I had my ultrasound to diagnose the problem and was given a diagnosis within the hour. No long waiting list and awful NHS waiting.

Banks are also super efficient. And all this in Malaysia. I keep comparing how UK is so much slower, and inefficient.

I think it's because if you are too protected you lose the edge. If you believe that the government will take care of you whether you are in a job or not, then you will become brain dead (or sort of). You will lose the edge to try and better yourself. Competition just sorts of wanes.

Heckle me if you want, but only those who do not get comfortable with the status quo are those who get ahead. And in Malaysia, if you don't work - you don't get paid, and you don't get fed. That's as good a motivator as any.

Of course the old, weak and those less fortunate do not get the attention they deserve. I guess the problem is that if you look after them, able bodied fraudsters will try and wheedle into that category.

That's my 2c. Some ways, I think UK is more backwards than in Malaysia. Some ways, the opposite is true.

Today I saw the weaknesses that is so present in the UK.

Posted at 19:06 PM
Email this entry to a friend