A Nurse with a Gun

Saturday, December 13, 2008

A U.S. district court has halted a massive "scareware" scheme that falsely claims your computer is infected with viruses, spyware and illegal pornography, and then solicts you to purchase bogus removal products.

The FTC states over one million consumers were duped into paying for spurious and malicious programs that did absolutely nothing other than spy on their computer usage.

The fraudulent products involved are WinFixer, WinAntivirus, DriveCleaner, ErrorSafe, and XP Antivirus. If you have any of this crap on your computer, get rid of it.

Labels:

Saturday, November 29, 2008

Norton Internet Security 2009

I subscribed to Norton Internet Security 2009 this morning. It's been nine days since the trial version was installed on my computer, and I'm impressed. Click to enlargeThe actual installation was performed remotely and tweaked by a Symantec technician.

I initially ran a full system scan, and found malware including Vundo. I then disabled system restore, and I ran the scan again, and destroyed it. Finally, I went to Safe Mode and rescanned to wipe trojan blood off the walls.

Over the past nine days, it has run quietly in the background of my computer. It updates every five minutes or so, or on demand. I have it set to run a full system scan each night. The time spent running a full system scan is of course dependent on the amount of data that must be scanned, but NIS2009 manages to get mine done in 28 minutes. Work continues uninterrupted as Norton scans or downloads updates. I forget it's happening. If you are already at the brink of memory overload, you may have difficulties, but NIS2009 uses very little resources to get the job done.

Boot time for my computer is increased by approximately 30-45 seconds. Norton Internet Security 2009 also allows me to run Spybot Search & Destroy, Malwarebytes Anti-Malware, Click to enlargeAdvanced System Care Free 3.0.0, and AVG Anti-Virus Free Edition. I like to have multiple tools in my toolbox.

Now I know everyone has their favorites and their prejudices, and I'm sure to get a couple of "Get a Mac" comments. Cries of "Get a Mac" are little more than cries to get a Glock. In computer software, what meets one person's needs may not necessarily meet the needs of another. I am not a computer geek, although I do know my way around the guts of Windows. I use my computer as a tool, not as a toy. Norton Internet Security 2009 is meeting my needs. It continually monitors my system, staying in the background, and it doesn't impede me one bit. If you have avoided Norton products in the past because they were resource hogs, I don't blame you. They were. You might want to take a look at what Norton has accomplished with this package though. It might not be right for you, but then again, how will you know if you don't take a look? In short, Norton Internet Security 2009 works for me.

Geek.com Review

Hardware Geeks Review

CNET Review

AppScout Review

PC Mag Review

WSJ Review

Labels: ,

Friday, November 28, 2008

Malwarebytes

I installed the latest version of Malwarebytes' Anti-Malware 1.30 a few days ago. Each day since, I have updated the program and scanned my computer with it.

From dedicated2Spyware.com:
"There are loads of malware removers on the net today and most of them are lightweight applications, which usually means they’re fast and don’t have many features. One such lightweight application is Malwarebytes’ Anti-malware."
This free program has some advantages. Frequent updates are available. You can update Malwarebytes’ Anti-malware every 24 hours. It will scan all drives, or any you select. It will scan specific files with a right click on the file..

Malwarebytes’ Anti-Malware has consistently found trojans or keyloggers on my system. What Norton Internet Security 2009 finds but is at a loss to deal with, Malwarebytes incapacitates, shreds and occasionally blasts into oblivion. It seems to be a capable adjunct to my existing software. Notches on it's belt include Trojan.BHO.H, Trojan.Vundo, Trojan.Agent, and Trojan.Downloader.

Update: I have discovered that these items "found" by Malwarebytes Anti-Malware were not threats at all, but lures to encourage free users to upgrade to the purchased version of the software. Not nice Malwarebytes.

Labels:

Monday, November 24, 2008

Blogroll Deletion

I have removed Oddee.com from my blogroll. Last night, while visiting that website, it attempted to insert a trojan.Pidief.D into my computer. Next a Tidserv!inf insertion was attempted. Later in the evening and this afternoon, I confirmed Oddee as the launch pad for both these malicious programs. Oddee, you aren't worth it.

I advise all readers to avoid Oddee.com.

I advise all readers to upgrade their Adobe reader to Adobe 9.

Dark Roasted Blend....... You may be next.

Labels: ,

Saturday, November 22, 2008

Black Monday

Global spam levels decreased by as much as 75 per cent after the neutering of McColo, a US web host that provided the foundation for most of the world's spam. In a effort of online vigilante justice, California based McColo was disconnected by its internet service providers, Global Crossing and Hurricane Electric, following a four month investigation. A report published this week identified McColo as the host of 40 different kiddie porn sites, one of which garnered up to 25,000 visitors a day, counterfeit pharmaceutical web sites, fake designer goods web sites and malware disguised as security products. Even so, there has been no announcement of any US law enforcement action against the company.

IronPort tracks daily spam volumes and publishes their findings online in real time. They showed a 70 per cent drop in spam after McColo was clipped. Unfortunately, McColo relocated overseas, hooking up with Swedish ISP TeliaSonera and has begun to re-establish itself. One fortuitous event in the forced eviction is that McColo apparently could not save their botnet.

Meanwhile, November 24 has been dubbed "Black Monday" following predictions the date will usher in the latest information harvesting malware. Anti-virus protection manufacturers have repeatedly demonstrated that the Thanksgiving holiday time shows a dramatic spike in spyware, malware, trojans and viruses as Americans begin going online shopping for Christmas presents. As more people turn to cyberspace to help them find better prices in a sagging economy, as well as to save time and gasoline, cyberthugs stand ready to virtually mug them and relieve them of their money.

Although email greeting card attachments remain a staple, cyberthugs are infecting users through more current methods. The recent presidential election was a golden opportunity exploited by criminals in cyberspace. An onslaught of Barack Obama related emails and websites offer new video clips of "amazing" Obama speeches, fresh interviews and administration predictions. An Obama sex video was another hook, as well as anti-Obama lures towards cyberinfestations. When the user attempts to view the video, they are taken to a website and told they must first download the latest version of Adobe Flash. The downloaded program is a fake, containing a trojan capable of stealing sensitive data. Modern viruses, trojans and keyloggers tansmit a detailed log of everything the victim enters into their keyboard back to the cyberthug. Passwords, credit card numbers, and even the ability to control one's own computer are compromised.

Another form of cyberthuggery that is emerging is holding the victim's data for ransom. Malware locks away access to personal files and requires a transfer of cash via the internet to restore access to the owner. Software is available that is capable of duplicating keys that appear in online photos, making even real world property vulnerable.

So what can the end user do? Many users have become complacent, considering it the norm to have some infestations of malware on their computers. Coping with malicious garbage on your hard drive should not be the norm. It is far easier to keep the stuff off your hard drive than it is to eradicate it afterwards.

If you use an Administrator account for your day to day usage, you are needlessly placing yourself at risk. This account should only be used when you want to change or install something on your computer. On Windows XP you can create three types of users, Limited User, Power User and Administrator. Use Limited User for every person on the computer and only one Administrator account, password protected for installations or system changes.

Internet Explorer is one big juicy target for cyberthugs. Switching to another web browser such as Opera or Firefox lowers your profile and makes you less of a target.

If you run Windows, keep it updated. As vulnerabilities are found and exploited, Microsoft tosses out band-aids and patches. Install them. If you are really concerned about the vulnerabilities in Windows, or if you are still trucking along with Windows 98, consider Linux instead.

Run a firewall, or two. Keep them updated. Obtain effective anti-virus software and keep it updated. Scan regularly, and become proficient in the interpretation and use of your protection software. It does you no good if it's turned off or only half effective.

Realize that very little is free. Use anti-virus software to examine attachments to emails and website downloads before opening them. If you are in doubt type the name of the program into Google and check the results for words such as "trojan," "spyware," "virus," or "malware." While viruses spread automatically, trojans require user input to install them. Resist the temptation to open and install programs on your hard drive that you have not previously researched and vetted.

If all else fails, copy your documents, or better yet, upload them to a secure cyberspace host for retrieval at a later date. Write down the password to the host. Dump your operating system, reinstall it, and learn from the experience. After all, it's only the internet.

Cybercriminals gearing up for Cyber Monday

Labels: , ,

Friday, November 21, 2008

Virtuemundo Fini

It appears that Virtuemundo can be declared dead on my computer. Checking into the security history of Norton Internet Security 2009, I have found that at 17:24 today NIS 2009 detected and blocked a trojan known as Vundo......... Twice.

I am surfing easily, and without any perceptible slowing of anything. Initial Windows start-up is a bit slower, perhaps 45 seconds. I think I can officially close the book on the problem I was having. Thank you to those who volunteered to assist.

In case you ever wondered what computer viri, trojans, and such look like, visit Malwarez.

Labels:

Thursday, November 20, 2008

Virtuemonde Update

Last night I went to the Kaspersky website and downloaded a trial version of Kaspersky Internet Security 2009. When I started to install it, I recieved a dialog box telling me it would uninstall my then present version of Norton Internet Security 2007. Kaspersky also required that I uninstall SpyBot Search & Destroy. I decided that if the Kaspersky suite was that powerful, I would hold it in reserve.

I browsed to the Symantec website to download a trial version of Norton Internet Security 2009. Installing Norton Internet Security 2009 vaporized my previous version of the program. To make matters worse, after installing it I was dismayed to find that because I already had Norton Internet Security on my computer, I would have to subscribe at a cost of $49.99 to activate the trial version. I decided to contact tech support via chat and cry foul. Here is the transcript of my chat session.
Mr. Xavier Breath has entered room.

We are experiencing higher than usual service times. Please wait and an analyst will be with you shortly.

We are experiencing higher than usual service times. Please wait and an analyst will be with you shortly.

We are experiencing higher than usual service times. Please wait and an analyst will be with you shortly.

We are experiencing higher than usual service times. Please wait and an analyst will be with you shortly.

We are experiencing higher than usual service times. Please wait and an analyst will be with you shortly.

We are experiencing higher than usual service times. Please wait and an analyst will be with you shortly.

We are experiencing higher than usual service times. Please wait and an analyst will be with you shortly.

We are experiencing higher than usual service times. Please wait and an analyst will be with you shortly.

We are experiencing higher than usual service times. Please wait and an analyst will be with you shortly.

We are experiencing higher than usual service times. Please wait and an analyst will be with you shortly.

Rajmohan P has entered room.

Rajmohan P(Wed Nov 19 21:13:30 CST 2008)>You are being transferred to Rajmohan P.

Rajmohan P(Wed Nov 19 21:13:33 CST 2008)>Welcome to Norton Support, my name is Raj Mohan. Can I please have a minute to go through the information you have provided?

Mr. Xavier Breath(Wed Nov 19 23:13:48 CST 2008)>sure

Mr. Xavier Breath(Wed Nov 19 23:14:06 CST 2008)>I decided to upgrade my internet security today and Norton's product was looking good in the reviews I have read.

Rajmohan P(Wed Nov 19 21:14:53 CST 2008)>Hi Xavier, I see that activating your Norton AntiVirus.

Mr. Xavier Breath(Wed Nov 19 23:15:46 CST 2008)>I downloaded your 15 day free trial version of Norton Internet Security 2009 from the symantec website and am unable to start the product because I am a prior customer of Norton. My last version was Norton's IS 2007. The trial version of Norton Internet Security 2009 uninstalled the 2007 version that came with my computer. I do not have a disc to reinstall what I previously had. I cannot start the 15 day trial version because it requires me to pay for a $49.99 subscription renewal.

Rajmohan P(Wed Nov 19 21:17:06 CST 2008)>Thanks, your case number is 081119-005742, please write this down.

Rajmohan P(Wed Nov 19 21:17:15 CST 2008)>If we get disconnected for any reason, please follow these instructions to reconnect this chat (we recommend that you to note down the link and code). You'll need to do this within a couple of minutes of being disconnected:

1) Open up Internet Explorer and then go to www.norton.com/connectme
2) Enter the [Connection Code] 293493 3) Click on [Submit]

Rajmohan P(Wed Nov 19 21:17:18 CST 2008)>Are you chatting with me from the computer that has the issue?

Mr. Xavier Breath(Wed Nov 19 23:17:32 CST 2008)>Yes.

Rajmohan P(Wed Nov 19 21:18:07 CST 2008)>Do you have your 25 digit product key?\

Mr. Xavier Breath(Wed Nov 19 23:19:28 CST 2008)>No, I do not. Your product has now changed my home page.

Mr. Xavier Breath(Wed Nov 19 23:19:46 CST 2008)>It is tossing up pop-ups right and left.

Mr. Xavier Breath(Wed Nov 19 23:20:52 CST 2008)>I cannot remove the pop-ups because I do not know if they are from your product or more malware.

Rajmohan P(Wed Nov 19 21:21:32 CST 2008)>May I know if you have purchased CD version of Norton program or download version?

Mr. Xavier Breath(Wed Nov 19 23:21:58 CST 2008)>Is aniti-virusproccan.com one of your sites?

Mr. Xavier Breath(Wed Nov 19 23:22:18 CST 2008)>I downloaded your 15 day free trial version of Norton Internet Security 2009 from the symantec website and am unable to start the product because I am a prior customer of Norton. My last version was Norton's IS 2007. The trial version of Norton Internet Security 2009 uninstalled the 2007 version that came with my computer. I do not have a disc to reinstall what I previously had. I cannot start the 15 day trial version because it requires me to pay for a $49.99 subscription renewal.

Mr. Xavier Breath(Wed Nov 19 23:22:47 CST 2008)>Are you reading what I have written?

Rajmohan P(Wed Nov 19 21:22:47 CST 2008)>No, aniti-virusproccan.com is not one of our sites.

Rajmohan P(Wed Nov 19 21:22:53 CST 2008)>Yep.

Rajmohan P(Wed Nov 19 21:23:04 CST 2008)>You have to purchase renewal.

Mr. Xavier Breath(Wed Nov 19 23:23:21 CST 2008)>For a "free" trial version?

Rajmohan P(Wed Nov 19 21:23:25 CST 2008)>Yes.

Mr. Xavier Breath(Wed Nov 19 23:23:47 CST 2008)>I would like to try your trial version of Norton Internet Security 2009 prior to purchase or renewal of any subscription.

Mr. Xavier Breath(Wed Nov 19 23:24:00 CST 2008)>I had planned to purchase it at retail if I decided to keep a Norton product on my computer. The previous version was slow, unweildy, inefficient, and it missed a good bit of malware. I want to know the effectiveness of Norton Internet Security 2009 before I lay down any cash.

Rajmohan P(Wed Nov 19 21:24:02 CST 2008)>Okay

Rajmohan P(Wed Nov 19 21:24:45 CST 2008)>Okay

Mr. Xavier Breath(Wed Nov 19 23:25:01 CST 2008)>Is that possible?

Rajmohan P(Wed Nov 19 21:25:57 CST 2008)>Yes.

Mr. Xavier Breath(Wed Nov 19 23:26:12 CST 2008)>How?

Rajmohan P(Wed Nov 19 21:27:08 CST 2008)>Xavier, I can connect to your computer and work to resolve the problem from here, while you sit back and watch.

This is a secure connection, and I won't access any personal information on your computer. If at any point you are concerned, you can disconnect me by clicking on the [End] button. I'd encourage you to view the troubleshooting from your end.

If for any reason you need to leave your computer, let me know via the chat window and we'll disconnect the remote session and resume once you're back.

Shall we go ahead with the remote connection?

Mr. Xavier Breath(Wed Nov 19 23:27:55 CST 2008)>Be my guest

Mr. Xavier Breath(Wed Nov 19 23:28:17 CST 2008)>One quick question....... Will Norton Internet Security 2009 efficiently and thoroughly eradicate the virtuemundo trojan?

Rajmohan P(Wed Nov 19 21:28:20 CST 2008)>To set up a connection:
1. Please click on the link http://www.norton.com/link
2. Enter in the 6 digit pin code 570632 and click [Connect to technician].
3. You will now see a prompt to accept the connection. Please click on [Yes]. It may take a few minutes for me to connect.

Rajmohan P(Wed Nov 19 21:28:32 CST 2008)>Yes.

Mr. Xavier Breath(Wed Nov 19 23:29:37 CST 2008)>I'm getting a pop-up that says the current chat session will end if I navigate away is that normal?

Rajmohan P(Wed Nov 19 21:29:54 CST 2008)>No.

Rajmohan P(Wed Nov 19 21:30:08 CST 2008)>Please open a Internet explorer webpage and type www.norton.com/link

Let me know when you are being asked for a 6-digit pin code.

Mr. Xavier Breath(Wed Nov 19 23:31:44 CST 2008)>Ok, it's asking........

Mr. Xavier Breath(Wed Nov 19 23:32:00 CST 2008)>Same one?

Rajmohan P(Wed Nov 19 21:31:59 CST 2008)>Use the pin given below 570632 and click on "Connect to Technician".

Next you will be prompted for Run, Save or Cancel. Click on Run to start the remote session

Rajmohan P(Wed Nov 19 21:32:05 CST 2008)>If you get a any prompts to block or unblock the program from Windows, click on "Unblock". On further prompts, click on Yes or Continue if you are being asked for.

Mr. Xavier Breath(Wed Nov 19 23:33:15 CST 2008)>logmeinrescue.exe is that you?

Rajmohan P(Wed Nov 19 21:33:24 CST 2008)>Yes.

Mr. Xavier Breath(Wed Nov 19 23:34:53 CST 2008)>Is this you? http://anti-virusproscan.com/2009/1/en/_freescan.php?nu=770522169011

[11:33 PM] Connecting to Rescue Gateway: control.app04.logmeinrescue.com...
[11:33 PM] Connected to Rescue Gateway. A support representative will be with you shortly.
[11:34 PM] Chat session established with Rajmohan.
[11:34 PM] Remote control started.

Rajmohan P(Wed Nov 19 21:34:49 CST 2008)>Now, I can access your computer and we will check for the issue.

Rajmohan P(Wed Nov 19 21:35:03 CST 2008)>No.

[11:52 PM] Rajmohan has ended the session.
[11:52 PM] Remote control ended.

Rajmohan P(Wed Nov 19 21:48:40 CST 2008)>We have activated your Norton Internet Security.

Rajmohan P(Wed Nov 19 21:48:57 CST 2008)>May I know the home page you want to set?

Mr. Xavier Breath(Wed Nov 19 23:49:05 CST 2008)>I see the virtumonde trojan is still active

Rajmohan P(Wed Nov 19 21:49:16 CST 2008)>Please run full system scan.

Mr. Xavier Breath(Wed Nov 19 23:49:44 CST 2008)>my homepage is correct now, that was it.

Rajmohan P(Wed Nov 19 21:50:05 CST 2008)>Okay

Mr. Xavier Breath(Wed Nov 19 23:50:20 CST 2008)>I'm impressed

Rajmohan P(Wed Nov 19 21:50:26 CST 2008)>Before I go, can I check that you're ok with the resolution I've provided?

Mr. Xavier Breath(Wed Nov 19 23:51:02 CST 2008)>Yes. I'd like to publish this chat on my blog to inform other people who might be considering your product. I have a readership of close to 4000 users per day. Customer service is often a factor in the choice of products purchased. Do I have your consent for publication?

Rajmohan P(Wed Nov 19 21:51:26 CST 2008)>Yes.

Mr. Xavier Breath(Wed Nov 19 23:51:47 CST 2008)>You did a fantastic job sir. Kudos.

Rajmohan P(Wed Nov 19 21:52:00 CST 2008)>You may receive a survey by email regarding this support
session and we'd really appreciate it if you could take a few moments to respond once it arrives. If you'd like to take up a specific issue with my manager you can send an email to Symantecmanagement@e4e.com

Rajmohan P(Wed Nov 19 21:52:02 CST 2008)>Thank you for contacting us. It's been my pleasure to assist you.
Of course, once the trial version of Norton Internet Security 2009 had been activated, I did a full system scan.

Nothing.

I went back to SpyBot Search & Destroy. I updated, immunized and scanned. Virtuemonde was still present, malicious as ever. I surfed a bit. Pop-ups galore. Every webpage rendered a pop-up window. I tried Mozilla. Pop-ups. Opera. Pop-ups. I scanned with Advanced Windows Care V2. Virtuemonde. tuzivard.dll and uganwerd.dll. f-monde gave me no joy. Dr. Delete committed malpractice. After a bit of research, I decided to try VundoFix V7.0.0 as suggested by one of my anonymous readers. VundoFix did not even see the trojan. It said all was well.

All was not well. I could not do squat without another pop-up window.

After work today, I decided to take a look again. As soon as I went to my desktop, Norton Internet Security 2009 popped up a window informing me I was infected with Vundo. No shit.

At least Norton Internet Security 2009 saw it. Click to enlargeThen, it showed me how to corner it, quarantine it, and kill it. This evening, I am surfing free.

I want to thank everyone, anonymous or not, who took the time to offer suggestions. I wasn't about to purge my hard drive and start from a clean slate again. I had done that several times years ago. In fact, I have been known to shotgun a PCU or two. I wasn't tossing in the towel that easily.

Norton Internet Security 2009 does not seem to be slowing down my web surfing or the use of my computer. It allows me to use SpyBot Search & Destroy, as well as other programs to agument it's capabilities. Perhaps the Virtuemuno trojan had to wiggle a little bit and try to morph into something new before Norton could spot it. Perhaps Norton updated with new data specific to my infestation. I'm not sure why it slipped through the cracks initially, but I have a feeling there is Virtuemundo blood on the walls of my hard drive.

Sometimes I think that personal computing is a lot like guns. There is a lot of well intentioned opinion of what is best, of which method is superior. Often times there are many paths and what is best for one person may not be for another. In the next week or so, I will decide if Norton's new Internet Security Suite meets my needs without impeding my productivity or my enjoyment of the web.

In related news, I'm back to watching Jodi Miller on You Tube as well. I guess the Vundo trojan was screwing that up too.

Labels: ,

Wednesday, November 19, 2008

More Inner Tubes Issues

It seems as though I cannot view You Tube videos from their site. I've downloaded the new Flash player and installed it. I've made sure scripting is enabled. I've rebooted. I still get this message.
"Hello, you either have JavaScript turned off or an old version of Adobe's Flash Player. Get the latest Flash player."
There are other venues available, although I will miss Jodi Miller and News Busted. Strangely, I can still view embedded You Tube videos on other web pages.

Meanwhile Virtuemonde seems to be gone, or at least quiet. Several blows from f-vmonde seem to have done the sonovabitch in. is still regenerating on my system. The latest offending files are system32\yogeresi.dll and system32\tirowefa.dll.

So, I am researching which internet security suite would best meet my needs. It seems the two real players are the old standby Norton, and a new contender Kaspersky. Whichever one I chose, getting rid of Virtuemonde and like trojans is top priority.

Norton has the reputation, but it is also well known, and as such, it also falls into the list of worthy targets for hackers. The newcomer (at least to me) Kaspersky has keylogger protection via a virtual keyboard, as well as the advantage of not being as common a target. I just don't know how reliable it is though.

I think I will try the free trial of Kaspersky and a free trial of Nortons and see how it goes......

More about Kaspersky Internet Security 2009

More about Norton Internet Security 2009

The Best Security Suites for 2009

Labels: ,

Sunday, November 16, 2008

Virtumonde

I think I finally got Virtumonde out of my system. Virtumonde, AKA the Vundo Trojan, Virtumondo and MS Juan is a trojan horse that causes popups and advertising for bullshit antispyware programs, as well as other problems including slowing of the processor and denial of service with some high traffic websites such as Google. I am not certain where I picked it up from.

I got rid of it by running Spybot Search & Destroy several times with the modem physically disconnected, and forcing reboots several times. Virtumonde inserts itself in your memory and attaches to Explorer.Exe and Winlogon. They must be stopped before trying to remove the virus. Without Winlogon, there is no way to reboot your computer. You have to force a reboot, because when Winlogon cranks up again, the virus files will be replicated. Virtumonde DLL files are usually designated by eight random upper and lower case characters and stored in the Windows system32 directory. Unless you remove the DLL files first, while they are running, the DLL file will simply rename itself and replicate. Nasty stuff.

If you want the best in spyware protection, you don't have to pay for it. Spyware Search & Destroy is absolutely free, and is constantly updated. You can flip the switches any way you desire. The support is through an international internet forum and is quite efficient. Do consider donating to help support the cause.

Update: It's back. The offending files are: system32\sejuvoma.dll, system32\jejuvusu.dll, system32\yizesoko.dll, system32\turakana.dll, and system32\jeziluku.dll

I'm going for Dr. Delete.



Update: So far, so good. It looks like Dr. Delete euthanized those little sonovabiches.

Update: Nope. Dr. Delete failed. I'm trying f-vmonde. The offending files are: system32\supilime.dll and system32\pihimage.dll.

Labels: , ,

Friday, October 17, 2008

Adobe Upgrade

A vulnerability in Adobe Flash Player 9.0.124.0 and earlier versions are actively being exploited across the internet. Attackers are posting malicious links on internet forums and in emails taking advantage of security flaws. Patches are not yet available.

The latest version of Adobe Flash Player version 10.0.12.36 is not vulnerable to these attacks. Consider upgrading immediately.

Labels:

Saturday, August 02, 2008

Sitemeter is Gone

I have removed Sitemeter from this blog. Last evening, my IE browser suddenly refused to display my own blog. Mozilla was fine. I allow a minimum of web bugs, bots and other crap, while running some decent software to prevent my browser being overloaded with surplus crap.

On troubleshooting, I discovered that it was the Sitemeter webbot on my blog that was causing the problem. My browser is also refusing to display any website running Sitemeter, or the Sitemeter website. I'm not what certain whether the Sitemeter webot was manipulated by someone else, or if the folks at Sitemeter have done to manipulate what was once a passive and peaceful 'bot. Honestly, I don't care. I'm not having any predatory bots in my blog, and they aren't taking any bites out of my browser. It is a manually run check, with manually downloaded updates.

If Sitemeter should change their bot back to what it once was, I may re-install it. Then again, maybe not. I don't really look at it anymore anyway.

I'm presently running some spybot software on my computer to check things out. If you do not have an effective spybot eradicator, one of the best ones is free, and obtainable at Spybot Search & Destroy. It will take care of 'bots, trojans, malware, PUPS, keyloggers and dialers. Updates are free and provided in a more timely manner than any other program I've found.

If anyone has any further information, post it in the comments section. Comment to let me know you were here, OK?

Related Stories with Solutions

Sitemeter Bug Breaks Internet

Internet Explorer Cannot Open the Site Operation Aborted

Fix: IE7 with Sitemeter: Operation Aborted

Operation Aborted

Update Aug 8 2008: I got around to reinstalling Sitemeter. If any further problems occur, I'm dumping it.

Labels: ,

Tuesday, January 03, 2006

MSA 912840 Vulnerability

Be careful out there. On Tuesday, December 27, 2005, Microsoft became aware of public reports of malicious attacks on some customers involving a previously unknown security vulnerability in the Windows Meta File (WMF) code area in the Windows platform.

Upon learning of the attacks, Microsoft mobilized under its Software Security Incident Response Process (SSIRP) to analyze the attack, assess its scope, define an engineering plan, and determine the appropriate guidance for customers, as well as to engage with anti-virus partners and law enforcement.

Microsoft confirmed the technical details of the attack on December 28, 2005 and immediately began developing a security update for the WMF vulnerability on an expedited track.

Microsoft has completed development of the security update for the vulnerability. The security update is now being localized and tested to ensure quality and application compatibility. Microsoft’s goal is to release the update on Tuesday, January 10, 2006, as part of its monthly release of security bulletins. This release is predicated on successful completion of quality testing.

The update will be released worldwide simultaneously in 23 languages for all affected versions of Windows once it passes a series of rigorous testing procedures. It will be available on Microsoft’s Download Center, as well as through Microsoft Update and Windows Update. Customers who use Windows’ Automatic Updates feature will be delivered the fix automatically.

• In a Web-based attack scenario, an attacker would have to host a Web site that contains a Web page that is used to exploit this vulnerability. An attacker would have no way to force users to visit a malicious Web site. Instead, an attacker would have to persuade them to visit the Web site, typically by getting them to click a link that takes them to the attacker's Web site.

• In an E-mail based attack involving the current exploit, customers would have to be persuaded to click on a link within a malicious e-mail or open an attachment that exploited the vulnerability. At this point, no attachment has been identified in which a user can be attacked simply by reading mail.

• An attacker who successfully exploited this vulnerability could only gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

• By default, Internet Explorer on Windows Server 2003, on Windows Server 2003 Service Pack 1, on Windows Server 2003 with Service Pack 1 for Itanium-based Systems, and on Windows Server 2003 x64 Edition runs in a restricted mode that is known as Enhanced Security Configuration This mode mitigates this vulnerability where the e-mail vector is concerned although clicking on a link would still put users at risk. In Windows Server 2003, Microsoft Outlook Express uses plain text for reading and sending messages by default. When replying to an e-mail message that is sent in another format, the response is formatted in plain text.

Source
Another Source

Labels: