<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Jean-Marc, XP Geek ! : Malwares</title><link>http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx</link><description>Tags: Malwares</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Protection contre les virus, logiciels espions et logiciels malveillants : Microsoft Security Essentials</title><link>http://msmvps.com/blogs/docxp/archive/2009/09/29/1728207.aspx</link><pubDate>Tue, 29 Sep 2009 15:32:43 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1728207</guid><dc:creator>jeanmarc</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/docxp/rsscomments.aspx?PostID=1728207</wfw:commentRss><comments>http://msmvps.com/blogs/docxp/archive/2009/09/29/1728207.aspx#comments</comments><description>&lt;p&gt;Et voilà, MSE est disponible. Pour tous ceux qui n’aiment pas les usines à gaz… &lt;/p&gt;  &lt;blockquote&gt;Microsoft Security Essentials est disponible en téléchargement gratuit (&lt;em&gt;WGA doit valider votre licence Windows&lt;/em&gt;) auprès de Microsoft. Il s&amp;#39;agit d&amp;#39;un composant simple à installer, facile à utiliser et toujours à jour pour que vous ayez la garantie que votre PC est protégé par les toutes dernières technologies. Vous pouvez facilement savoir si votre PC est sécurisé : lorsque le voyant est au vert, tout va bien. C&amp;#39;est aussi simple que cela.&lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.microsoft.com/security_essentials/"&gt;Protection contre les virus, logiciels espions et logiciels malveillants | Microsoft Security Essentials&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1728207" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx">Malwares</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Informations/default.aspx">Informations</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Logiciels/default.aspx">Logiciels</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_E900_curit_E900_/default.aspx">Sécurité</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Vista/default.aspx">Vista</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_26002300_233_3B00_curit_26002300_233_3B00_/default.aspx">S&amp;#233;curit&amp;#233;</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/XP/default.aspx">XP</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Windows+7/default.aspx">Windows 7</category></item><item><title>Mise à jour pour la fonctionnalité exécution automatique dans Windows</title><link>http://msmvps.com/blogs/docxp/archive/2009/08/25/1718170.aspx</link><pubDate>Tue, 25 Aug 2009 21:10:14 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1718170</guid><dc:creator>jeanmarc</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/docxp/rsscomments.aspx?PostID=1718170</wfw:commentRss><comments>http://msmvps.com/blogs/docxp/archive/2009/08/25/1718170.aspx#comments</comments><description>&lt;p&gt;Cette mise à jour de la fonctionnalité d’exécution automatique désactive la fonction d’autorun pour les supports USB sous Windows XP, Windows Server 2003, Windows Vista et Windows Server 2008.&lt;/p&gt;  &lt;p&gt;Je vous la recommande chaudement !&lt;/p&gt;  &lt;p&gt;Source : &lt;a href="http://support.microsoft.com/kb/971029"&gt;Mise à jour pour la fonctionnalité exécution automatique dans Windows&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1718170" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx">Malwares</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_E900_curit_E900_/default.aspx">Sécurité</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Vista/default.aspx">Vista</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_26002300_233_3B00_curit_26002300_233_3B00_/default.aspx">S&amp;#233;curit&amp;#233;</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/XP/default.aspx">XP</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Windows+7/default.aspx">Windows 7</category></item><item><title>Autoruns v9.52 et procmon v2.5</title><link>http://msmvps.com/blogs/docxp/archive/2009/07/24/1708410.aspx</link><pubDate>Fri, 24 Jul 2009 11:00:36 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1708410</guid><dc:creator>jeanmarc</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/docxp/rsscomments.aspx?PostID=1708410</wfw:commentRss><comments>http://msmvps.com/blogs/docxp/archive/2009/07/24/1708410.aspx#comments</comments><description>&lt;p&gt;Ces excellents outils viennent d’être mis à jour. Rechargez vos clés USB ! &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;a href="http://technet.microsoft.com/sysinternals/bb963902.aspx"&gt;Autoruns v9.52&lt;/a&gt;: Autoruns v9.52 fixes some minor bugs including one where Ctrl+C didn’t copy the entire entry to the clipboard. &lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;a href="http://technet.microsoft.com/sysinternals/bb896645.aspx"&gt;Procmon v2.5&lt;/a&gt;: This significant update to Process Monitor adds a number of enhancements, including new by-extension and by-directory views in the File Summary dialog, a new Network Summary view, quick filtering in all the summary views, additional IOCTL and error result decoding, and a number of bug fixes.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Source : &lt;a href="http://blogs.technet.com/sysinternals/archive/2009/07/23/updates-autoruns-v9-52-vmmap-v2-2-procdump-v1-2-procmon-v2-5-marks-blog-pushing-the-limits-of-windows-processes-and-threads.aspx"&gt;Sysinternals Site Discussion : Updates: Autoruns v9.52, VMMap v2.2, procdump v1.2, procmon v2.5 | Marks Blog: Pushing the Limits of Windows: Processes and Threads&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1708410" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx">Malwares</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/D_E900_pannages/default.aspx">Dépannages</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Logiciels/default.aspx">Logiciels</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Favoris/default.aspx">Favoris</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_E900_curit_E900_/default.aspx">Sécurité</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Vista/default.aspx">Vista</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_26002300_233_3B00_curit_26002300_233_3B00_/default.aspx">S&amp;#233;curit&amp;#233;</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/D_26002300_233_3B00_pannages/default.aspx">D&amp;#233;pannages</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/XP/default.aspx">XP</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Windows+7/default.aspx">Windows 7</category></item><item><title>0-Day Flash et Acrobat Reader</title><link>http://msmvps.com/blogs/docxp/archive/2009/07/23/1707150.aspx</link><pubDate>Thu, 23 Jul 2009 20:57:12 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1707150</guid><dc:creator>jeanmarc</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/docxp/rsscomments.aspx?PostID=1707150</wfw:commentRss><comments>http://msmvps.com/blogs/docxp/archive/2009/07/23/1707150.aspx#comments</comments><description>&lt;p&gt;C’est une faille d’importance qui frappe le composant flash d’Adobe ainsi qu’Acrobat Reader, même lorsque l’exécution du javascript est désactivée dans A.R…&lt;/p&gt;  &lt;p&gt;L’exploit est actuellement utilisé (in the wild) et le malware ainsi déposé/exécuté récupère les droits de l’utilisateur (vive UAC !).&lt;/p&gt;  &lt;p&gt;Adobe a &lt;a href="http://www.adobe.com/support/security/advisories/apsa09-03.html" target="_blank"&gt;publié un bulletin&lt;/a&gt; sur cette vulnérabilité.&lt;/p&gt;  &lt;p&gt;Source : &lt;a href="http://isc.sans.org/diary.html?storyid=6847" target="_blank"&gt;ISC&lt;/a&gt; via &lt;a href="http://www.securityvibes.com/zero-day-flash-pdf-jsaiz-news-3003326.html"&gt;Communauté SecurityVibes - Flash troué, navigateurs (aussi) affaiblis&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1707150" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx">Malwares</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_E900_curit_E900_/default.aspx">Sécurité</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Vista/default.aspx">Vista</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_26002300_233_3B00_curit_26002300_233_3B00_/default.aspx">S&amp;#233;curit&amp;#233;</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/XP/default.aspx">XP</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/0day/default.aspx">0day</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Windows+7/default.aspx">Windows 7</category></item><item><title>Download details: IE App Compat VHD</title><link>http://msmvps.com/blogs/docxp/archive/2009/03/23/1680700.aspx</link><pubDate>Mon, 23 Mar 2009 21:31:47 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1680700</guid><dc:creator>jeanmarc</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/docxp/rsscomments.aspx?PostID=1680700</wfw:commentRss><comments>http://msmvps.com/blogs/docxp/archive/2009/03/23/1680700.aspx#comments</comments><description>&lt;p&gt;Voici quelques VHD pré-configurés pour tester IE 6 / 7 / 8… et accessoirement quelques exécutables à risque si vous aimez jouer avec le feu… &lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;This download page contains different VPC images, depending on what you want to test.  &lt;ul&gt; &lt;li&gt;&lt;b&gt;IE6-XPSP3.exe&lt;/b&gt; contains a Windows XP SP3 with IE6 VHD file. Expires April 30, 2009  &lt;li&gt;&lt;b&gt;IE7-XPSP3.exe&lt;/b&gt; contains a Windows XP SP3 with IE7 VHD file. Expires April 30, 2009  &lt;li&gt;&lt;b&gt;IE8-XPSP3.exe&lt;/b&gt; contains a Windows XP SP3 with IE8 VHD file. Expires April 30, 2009  &lt;li&gt;&lt;b&gt;IE7-VIS1.exe+IE7-VIS2.rar+IE7-VIS3.rar&lt;/b&gt; contain a Vista Image with IE7 VHD file. Expires 120 days after first run.&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=21eabb90-958f-4b64-b5f1-73d0a413c8ef&amp;amp;displaylang=en"&gt;Download details: IE App Compat VHD&lt;/a&gt;&lt;/p&gt; &lt;p&gt;A utiliser avec &lt;a href="http://www.microsoft.com/downloads/details.aspx?displaylang=fr&amp;amp;FamilyID=28c97d22-6eb8-4a09-a7f7-f6c7a1f000b5" target="_blank"&gt;Microsoft Virtual PC 2007 SP1&lt;/a&gt;, évidemment… ;-)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1680700" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx">Malwares</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_E900_curit_E900_/default.aspx">Sécurité</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Vista/default.aspx">Vista</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_26002300_233_3B00_curit_26002300_233_3B00_/default.aspx">S&amp;#233;curit&amp;#233;</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/IE7/default.aspx">IE7</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/XP/default.aspx">XP</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/IE8/default.aspx">IE8</category></item><item><title>Safari, IE8 et Firefox dans le même panier…</title><link>http://msmvps.com/blogs/docxp/archive/2009/03/21/1680164.aspx</link><pubDate>Sat, 21 Mar 2009 10:10:19 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1680164</guid><dc:creator>jeanmarc</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/docxp/rsscomments.aspx?PostID=1680164</wfw:commentRss><comments>http://msmvps.com/blogs/docxp/archive/2009/03/21/1680164.aspx#comments</comments><description>&lt;p&gt;Il n’a fallu que quelques secondes à Charlie Miller, l’un des participants au concours Pwn2Own organisé par Tipping Point, pour prendre le contrôle complet d’un MacBook par l’intermédiaire du navigateurs Safari qui y était installé.&lt;/p&gt; &lt;p&gt;Dans la même journée, c’est “Nils” qui nous gratifie d’une attaque “drive by download” sur la dernière version du navigateur Internet Explorer, la 8, prenant le contrôle total de Windows 7 sur la machine visée… ainsi que d’une seconde attaque réussie sur le MacBook via Safari..&lt;/p&gt; &lt;p&gt;C’est également ce même participant qui exploite, plus tard dans la journée, un “zero day” sur firefox, signant alors une triple infection de trois navigateurs et deux OS différents.&lt;/p&gt; &lt;p&gt;Heureusement, ces exploits sont maintenant aux mains de la société “Tipping Point”,&amp;nbsp; qui travaille en collaboration avec les différents éditeurs afin de résoudre ces failles.&lt;/p&gt; &lt;p&gt;Sources :&lt;/p&gt; &lt;p&gt;&lt;a href="http://securitygarden.blogspot.com/2009/03/pwn2own-trifecta-safarimacbook-ie8-and.html"&gt;Security Garden: Pwn2Own Trifecta: Safari/MacBook, IE8 and Firefox&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;a title="http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx" href="http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx"&gt;http://blogs.technet.com/ecostrat/archive/2009/03/18/cansecwest-caution-community-at-play.aspx&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;a title="http://dvlabs.tippingpoint.com/blog/2009/02/25/pwn2own-2009" href="http://dvlabs.tippingpoint.com/blog/2009/02/25/pwn2own-2009"&gt;http://dvlabs.tippingpoint.com/blog/2009/02/25/pwn2own-2009&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1680164" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx">Malwares</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_E900_curit_E900_/default.aspx">Sécurité</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Vista/default.aspx">Vista</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_26002300_233_3B00_curit_26002300_233_3B00_/default.aspx">S&amp;#233;curit&amp;#233;</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/XP/default.aspx">XP</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Windows+7/default.aspx">Windows 7</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/IE8/default.aspx">IE8</category></item><item><title>Spybot et IE8 : attention aux ralentissements</title><link>http://msmvps.com/blogs/docxp/archive/2009/03/21/1680152.aspx</link><pubDate>Sat, 21 Mar 2009 09:30:52 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1680152</guid><dc:creator>jeanmarc</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/docxp/rsscomments.aspx?PostID=1680152</wfw:commentRss><comments>http://msmvps.com/blogs/docxp/archive/2009/03/21/1680152.aspx#comments</comments><description>&lt;p&gt;C’est &lt;a href="http://msmvps.com/blogs/donna/archive/2009/03/19/ie8-issues-if-immunization-by-spybot-s-amp-d-is-enabled.aspx" target="_blank"&gt;Donna qui nous met en garde (en anglais)&lt;/a&gt; contre l’association d’IE8 et du module résident de Spybot : lorsque la liste des sites restreints est importante, il peut se produire de forts ralentissements dans IE8, à la fois dans XP et Vista.&lt;/p&gt; &lt;p&gt;Source et liens complémentaires : &lt;a href="http://msmvps.com/blogs/donna/archive/2009/03/19/ie8-issues-if-immunization-by-spybot-s-amp-d-is-enabled.aspx"&gt;IE8 issues if immunization by Spybot-S&amp;amp;D is enabled - Donna&amp;#39;s SecurityFlash&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1680152" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx">Malwares</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_E900_curit_E900_/default.aspx">Sécurité</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Vista/default.aspx">Vista</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_26002300_233_3B00_curit_26002300_233_3B00_/default.aspx">S&amp;#233;curit&amp;#233;</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/XP/default.aspx">XP</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/IE8/default.aspx">IE8</category></item><item><title>Flash Player 10.0.22.87</title><link>http://msmvps.com/blogs/docxp/archive/2009/02/25/1673735.aspx</link><pubDate>Wed, 25 Feb 2009 12:00:06 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1673735</guid><dc:creator>jeanmarc</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/docxp/rsscomments.aspx?PostID=1673735</wfw:commentRss><comments>http://msmvps.com/blogs/docxp/archive/2009/02/25/1673735.aspx#comments</comments><description>&lt;p&gt;APSB09-01 - Flash Player update available to address security vulnerabilities&lt;/p&gt; &lt;p&gt;&lt;br /&gt;&amp;quot;Adobe recommends all users of Adobe Flash Player 10.0.12.36 and earlier &lt;br /&gt;versions upgrade to the newest version 10.0.22.87...&amp;quot;&lt;/p&gt; &lt;p&gt;&lt;a href="http://www.adobe.com/support/security/bulletins/apsb09-01.html"&gt;http://www.adobe.com/support/security/bulletins/apsb09-01.html&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;Si vous n’arrivez pas à faire la mise à jour, rendez-vous ici :&lt;/p&gt; &lt;p&gt;C:\Windows\System32\Macromed\Flash\&lt;/p&gt; &lt;p&gt;et lancez le programme “flashutil…” en ayant pris soin de fermer I.E. avant…&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1673735" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx">Malwares</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Logiciels/default.aspx">Logiciels</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_E900_curit_E900_/default.aspx">Sécurité</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Vista/default.aspx">Vista</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_26002300_233_3B00_curit_26002300_233_3B00_/default.aspx">S&amp;#233;curit&amp;#233;</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/IE7/default.aspx">IE7</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/XP/default.aspx">XP</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Windows+7/default.aspx">Windows 7</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/IE8/default.aspx">IE8</category></item><item><title>Conficker : une compilation de liens utiles</title><link>http://msmvps.com/blogs/docxp/archive/2009/02/13/1671962.aspx</link><pubDate>Fri, 13 Feb 2009 11:53:05 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1671962</guid><dc:creator>jeanmarc</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/docxp/rsscomments.aspx?PostID=1671962</wfw:commentRss><comments>http://msmvps.com/blogs/docxp/archive/2009/02/13/1671962.aspx#comments</comments><description>&lt;p&gt;C’est là :&lt;/p&gt; &lt;p&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=5860&amp;amp;rss"&gt;SANS Internet Storm Center; Cooperative Network Security Community - Internet Security - isc&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1671962" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx">Malwares</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_E900_curit_E900_/default.aspx">Sécurité</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Vista/default.aspx">Vista</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_26002300_233_3B00_curit_26002300_233_3B00_/default.aspx">S&amp;#233;curit&amp;#233;</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/XP/default.aspx">XP</category></item><item><title>[mailbag] Messages RUNDLL et Application Error</title><link>http://msmvps.com/blogs/docxp/archive/2009/02/05/1669406.aspx</link><pubDate>Thu, 05 Feb 2009 21:39:34 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1669406</guid><dc:creator>jeanmarc</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/docxp/rsscomments.aspx?PostID=1669406</wfw:commentRss><comments>http://msmvps.com/blogs/docxp/archive/2009/02/05/1669406.aspx#comments</comments><description>&lt;p align="justify"&gt;Bonsoir à tous et bonsoir à Yvon qui m’écrit :&lt;/p&gt; &lt;p align="justify"&gt;[snip]&lt;/p&gt; &lt;blockquote&gt; &lt;p align="justify"&gt;J&amp;#39;ai 2 fenêtre de messages à l&amp;#39;ouverture de mon ordinateur&lt;br /&gt;1-RUNDLL&lt;br /&gt;Erreur de chargement de C:\PROGRA-1\MYWEBS-1\bar\1.bin\M3PLUGIN.DLL&lt;br /&gt;Le module spécifié est introuvable&lt;/p&gt;&lt;/blockquote&gt; &lt;p align="justify"&gt;Ici, il s’agit d’une barre de recherche MyWebSearch, considérée comme un &lt;a href="http://fr.wikipedia.org/wiki/Logiciel_malveillant" target="_blank"&gt;malware&lt;/a&gt; et qui a certainement été nettoyée incomplètement par un anti-virus ou un anti-malware.&lt;/p&gt; &lt;p align="justify"&gt;La solution pour supprimer ce message consiste à utiliser un utilitaire comme &lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx" target="_blank"&gt;Autoruns&lt;/a&gt; afin d’effacer simplement la ligne rundll32 qui fait appel à ce fichier manquant.&lt;/p&gt; &lt;p align="justify"&gt;Le problème c’est que ce malware a surement laissé d’autres traces que l’on peut découvrir &lt;a href="http://www.pchell.com/support/mywebsearch.shtml" target="_blank"&gt;sur cette page&lt;/a&gt; (en anglais).&lt;/p&gt; &lt;blockquote&gt; &lt;p align="justify"&gt;2-Application Error&lt;br /&gt;Exception EFOpenError in module 1600232252.exe at 0026B93.&lt;br /&gt;Cannot open file&amp;quot;C:\Documents and Setting\All Users\Application Data\1398180795\Langs.udb&amp;quot;. Le fichier spécifié est introuvable.&lt;/p&gt;&lt;/blockquote&gt; &lt;p align="justify"&gt;Dès le premier abord, ce second message est suspect. En effet, le nom de l’exécutable est un nombre qui semble aléatoire et destiné à embrouiller un utilisateur novice. Logiquement, on peut penser avoir affaire à un malware qui aurait du mal à se lancer (heureusement) et la désactivation par Autoruns me semble toute indiquée.&lt;/p&gt; &lt;p align="justify"&gt;Ces 2 erreurs n’augurent rien de bon pour la santé de l’ordinateur et il me semble souhaitable de faire un scan anti-virus complet ainsi qu’un scan avec un bon logiciel anti-malware (un vrai, pas un “&lt;a href="http://mad.internetpol.fr/archives/18-Rogue-Security-Program-XP-Police-Antivirus.html" target="_blank"&gt;rogue&lt;/a&gt;” !!!) tel que &lt;a href="http://www.malwarebytes.org/mbam.php" target="_blank"&gt;MBAM&lt;/a&gt;.&lt;/p&gt; &lt;p align="justify"&gt;Dernier petit conseil, reste méfiant avec les installations de logiciels gratuits, certains sont des malwares camouflés.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1669406" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx">Malwares</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_E900_curit_E900_/default.aspx">Sécurité</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Vista/default.aspx">Vista</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_26002300_233_3B00_curit_26002300_233_3B00_/default.aspx">S&amp;#233;curit&amp;#233;</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/XP/default.aspx">XP</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/mailbag/default.aspx">mailbag</category></item><item><title>MS08-067 : W32.Downadup.B</title><link>http://msmvps.com/blogs/docxp/archive/2008/12/31/1658203.aspx</link><pubDate>Wed, 31 Dec 2008 17:00:25 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1658203</guid><dc:creator>jeanmarc</dc:creator><slash:comments>40</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/docxp/rsscomments.aspx?PostID=1658203</wfw:commentRss><comments>http://msmvps.com/blogs/docxp/archive/2008/12/31/1658203.aspx#comments</comments><description>&lt;p&gt;A tous ceux qui n’ont pas encore installé le patch MS08-067, il est grand temps de le faire…&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;W32.Downadup.B is a worm that spreads by exploiting the &lt;a href="http://www.securityfocus.com/bid/31874"&gt;Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability&lt;/a&gt; (BID 31874). It also attempts to spread to network shares protected by weak passwords and blocks access to security-related Web sites. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Lire la description complète : &lt;a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-123015-3826-99&amp;amp;tabid=1" target="_blank"&gt;W32.Downadup.B - Symantec.com&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Update :&lt;/u&gt;&lt;/strong&gt; On parle certainement &lt;a href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Worm%3aWin32%2fConficker.B" target="_blank"&gt;de la même bestiole ICI&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;&lt;em&gt;Update from comments (thanks to Carlo Pagani) :&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Quick way to kill if you are infected.&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;1. dir *.* /ahs in \System32 folder&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;2. If you see a .DLL file (not always .dll) then you are probably infected.&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;3. Using process explorer, search for the name you see, then close the handle of the file. If you do not find it in process explorer then it is not active yet but proceed to 4 anyway.&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;4. Take ownership of the file&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;5. Delete file&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;6. Check \WINDOWS\TASK for any job file that does not belong there&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;7. Look for Autorun.inf file in root. If there, take ownership and delete&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;8. Reboot&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;9. Enable BITS and Auto update services as the worm disables these.&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;10. Update windows.&lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1658203" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx">Malwares</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_E900_curit_E900_/default.aspx">Sécurité</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Vista/default.aspx">Vista</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_26002300_233_3B00_curit_26002300_233_3B00_/default.aspx">S&amp;#233;curit&amp;#233;</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/XP/default.aspx">XP</category></item><item><title>F-Secure : E-Volution des malwares</title><link>http://msmvps.com/blogs/docxp/archive/2008/11/19/1654550.aspx</link><pubDate>Wed, 19 Nov 2008 12:53:52 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1654550</guid><dc:creator>jeanmarc</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/docxp/rsscomments.aspx?PostID=1654550</wfw:commentRss><comments>http://msmvps.com/blogs/docxp/archive/2008/11/19/1654550.aspx#comments</comments><description>&lt;p&gt;Intéressant :&lt;/p&gt;  &lt;p&gt;&lt;object width="425" height="350"&gt;&lt;param name="movie" value="http://www.youtube.com/v/m5ur7tVzpdw"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/m5ur7tVzpdw" type="application/x-shockwave-flash" width="425" height="350"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1654550" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx">Malwares</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_E900_curit_E900_/default.aspx">Sécurité</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Vista/default.aspx">Vista</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_26002300_233_3B00_curit_26002300_233_3B00_/default.aspx">S&amp;#233;curit&amp;#233;</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/XP/default.aspx">XP</category></item><item><title>Security Update available for Adobe Reader 8 and Acrobat 8</title><link>http://msmvps.com/blogs/docxp/archive/2008/11/08/1653525.aspx</link><pubDate>Sat, 08 Nov 2008 19:28:57 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1653525</guid><dc:creator>jeanmarc</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/docxp/rsscomments.aspx?PostID=1653525</wfw:commentRss><comments>http://msmvps.com/blogs/docxp/archive/2008/11/08/1653525.aspx#comments</comments><description>&lt;p&gt;C’est le moment de patcher, la vulnérabilité est activement exploitée et AUCUN anti-virus ne détecté cette attaque pour le moment…&lt;/p&gt;  &lt;blockquote&gt;Critical vulnerabilities have been identified in Adobe Reader and Acrobat 8.1.2 and earlier versions. These vulnerabilities would cause the application to crash and could potentially allow an attacker to take control of the affected system.&lt;/blockquote&gt;  &lt;p&gt;Source : &lt;a href="http://www.adobe.com/support/security/bulletins/apsb08-19.html"&gt;Adobe - Security Advisories : APSB08-19 - Security Update available for Adobe Reader 8 and Acrobat 8&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1653525" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx">Malwares</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_E900_curit_E900_/default.aspx">Sécurité</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Vista/default.aspx">Vista</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_26002300_233_3B00_curit_26002300_233_3B00_/default.aspx">S&amp;#233;curit&amp;#233;</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/XP/default.aspx">XP</category></item><item><title>Exploit.Win32.MS08-067 : nous y voilà…</title><link>http://msmvps.com/blogs/docxp/archive/2008/11/03/1652949.aspx</link><pubDate>Mon, 03 Nov 2008 20:01:54 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1652949</guid><dc:creator>jeanmarc</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/docxp/rsscomments.aspx?PostID=1652949</wfw:commentRss><comments>http://msmvps.com/blogs/docxp/archive/2008/11/03/1652949.aspx#comments</comments><description>&lt;p&gt;On attendait un petit frère à Blaster, le voici : &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Exploit.Win32.MS08-067.g [Kaspersky Lab]      &lt;br /&gt;&lt;a href="http://www.threatexpert.com/threats/mal-generic-a.html"&gt;Mal/Generic-A&lt;/a&gt; [Sophos]       &lt;br /&gt;Exploit:Win32/MS08067.gen!A [Microsoft]       &lt;br /&gt;Virus.Exploit.Win32.MS08.067.g [Ikarus]&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;A mon avis, ce n’est que le début…&amp;#160;&amp;#160;&amp;#160; :’(&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.threatexpert.com/report.aspx?uid=e3c827ae-eab9-4249-aaba-69f6cc4d5956"&gt;ThreatExpert Report: Exploit.Win32.MS08-067.g, Mal/Generic-A, Exploit:Win32/MS08067.gen!A..&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1652949" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx">Malwares</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_E900_curit_E900_/default.aspx">Sécurité</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Vista/default.aspx">Vista</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_26002300_233_3B00_curit_26002300_233_3B00_/default.aspx">S&amp;#233;curit&amp;#233;</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/XP/default.aspx">XP</category></item><item><title>Un virus qui passe…</title><link>http://msmvps.com/blogs/docxp/archive/2008/10/10/1650480.aspx</link><pubDate>Fri, 10 Oct 2008 15:15:13 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1650480</guid><dc:creator>jeanmarc</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/docxp/rsscomments.aspx?PostID=1650480</wfw:commentRss><comments>http://msmvps.com/blogs/docxp/archive/2008/10/10/1650480.aspx#comments</comments><description>&lt;p&gt;Allez hop, poubelle direct…&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="Virus" border="0" alt="Virus" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/docxp/Virus_5F00_3CE0CDBB.jpg" width="371" height="298" /&gt; &lt;/p&gt;  &lt;p&gt;Microsoft n’envoie jamais de patchs par mail ! Vous avez un doute ? Rendez-vous sur Windows Update et ne vous fiez ni aux mails, ni aux liens contenus dans ceux-ci !&lt;/p&gt;  &lt;p&gt;NB: Windows Defender sonne l’alarme également si on tente de manipuler le fichier joint !&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1650480" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx">Malwares</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Informations/default.aspx">Informations</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_E900_curit_E900_/default.aspx">Sécurité</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Vista/default.aspx">Vista</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_26002300_233_3B00_curit_26002300_233_3B00_/default.aspx">S&amp;#233;curit&amp;#233;</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/XP/default.aspx">XP</category></item><item><title>Flash Player workaround available for "Clickjacking" issue</title><link>http://msmvps.com/blogs/docxp/archive/2008/10/08/1650092.aspx</link><pubDate>Wed, 08 Oct 2008 09:14:48 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1650092</guid><dc:creator>jeanmarc</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/docxp/rsscomments.aspx?PostID=1650092</wfw:commentRss><comments>http://msmvps.com/blogs/docxp/archive/2008/10/08/1650092.aspx#comments</comments><description>&lt;p&gt;A lire, un petit réglage pour votre sécurité :&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Adobe is aware of recently published reports of a ‘Clickjacking’ issue in multiple web browsers that could allow an attacker to lure a web browser user into unknowingly clicking on a link or dialog. It has been determined that this potential &amp;quot;Clickjacking&amp;quot; issue affects Adobe Flash Player. Adobe is working to address this issue in an upcoming update to Flash Player. &lt;/p&gt;    &lt;h5&gt;Solution &lt;/h5&gt;    &lt;h6&gt;Customers:&lt;/h6&gt;    &lt;p&gt;To prevent this potential issue, customers can change their Flash Player settings as follows:&lt;/p&gt;    &lt;ol&gt;     &lt;li&gt;Access the Global Privacy Settings panel of the Adobe Flash Player Settings Manager at the following URL: &lt;a href="http://www.adobe.com/support/documentation/en/flashplayer/help/settings_manager02.html"&gt;http://www.adobe.com/support/documentation/en/flashplayer/help/settings_manager02.html&lt;/a&gt;&lt;/li&gt;      &lt;li&gt;Select the &amp;quot;Always deny&amp;quot; button. &lt;/li&gt;      &lt;li&gt;Select ‘Confirm’ in the resulting dialog. &lt;/li&gt;   &lt;/ol&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.adobe.com/support/security/advisories/apsa08-08.html"&gt;Le bulletin complet ici : Flash Player workaround available for &amp;quot;Clickjacking&amp;quot; issue&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1650092" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx">Malwares</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_E900_curit_E900_/default.aspx">Sécurité</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Vista/default.aspx">Vista</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_26002300_233_3B00_curit_26002300_233_3B00_/default.aspx">S&amp;#233;curit&amp;#233;</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/XP/default.aspx">XP</category></item><item><title>Désactiver l’autorun.inf</title><link>http://msmvps.com/blogs/docxp/archive/2008/10/06/1649862.aspx</link><pubDate>Mon, 06 Oct 2008 10:58:24 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1649862</guid><dc:creator>jeanmarc</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/docxp/rsscomments.aspx?PostID=1649862</wfw:commentRss><comments>http://msmvps.com/blogs/docxp/archive/2008/10/06/1649862.aspx#comments</comments><description>&lt;p&gt; Xavier nous donne une excellente astuce :&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;[…] désactiver l’exécution automatique des fichiers “&lt;em&gt;autorun.inf&lt;/em&gt;” […]&lt;/p&gt;    &lt;p&gt;REGEDIT4     &lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Autorun.inf]      &lt;br /&gt;@=”@SYS:DoesNotExist”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;En fait, cette valeur indique à Windows d’ignorer le fichier autorun.inf !&lt;/p&gt;  &lt;p&gt;Testé et approuvé pour Vista.&lt;/p&gt;  &lt;p&gt;&lt;a target="_blank" href="http://www.collet-matrat.com/?p=491"&gt;Source et article complet.&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1649862" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx">Malwares</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_E900_curit_E900_/default.aspx">Sécurité</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Vista/default.aspx">Vista</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_26002300_233_3B00_curit_26002300_233_3B00_/default.aspx">S&amp;#233;curit&amp;#233;</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/XP/default.aspx">XP</category></item><item><title>Microsoft Security Intelligence Report</title><link>http://msmvps.com/blogs/docxp/archive/2007/10/26/1265389.aspx</link><pubDate>Fri, 26 Oct 2007 15:50:15 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1265389</guid><dc:creator>jeanmarc</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/docxp/rsscomments.aspx?PostID=1265389</wfw:commentRss><comments>http://msmvps.com/blogs/docxp/archive/2007/10/26/1265389.aspx#comments</comments><description>&lt;p&gt;Intéressant à lire si vous vous intéressez à la sécurité et à l&amp;#39;évolution des malwares...&lt;/p&gt; &lt;p&gt;The Microsoft Security Intelligence Report (SIR) provides an in-depth perspective on the changing threat landscape including software vulnerability disclosures and exploits, malicious software (malware), and potentially unwanted software. Each individual report focuses on data and trends observed in either the first or second half of each calendar year and uses historical data to provide context. The purpose of the SIR is to keep Microsoft’s customers informed of the major trends in the threat landscape and to provide valuable insights and security guidance designed to help customers improve their security posture in the face of these threats.&lt;/p&gt; &lt;p&gt;The third volume of the Microsoft Security Intelligence Report (SIR) is now available : &lt;p&gt;&lt;a href="http://www.microsoft.com/security/portal/sir.aspx"&gt;Microsoft Malware Protection Center - Security Intelligence Report&lt;/a&gt; &lt;/p&gt; &lt;p&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=4EDE2572-1D39-46EA-94C6-4851750A2CB0&amp;amp;displaylang=en" target="_blank"&gt;Ou directement ici.&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1265389" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx">Malwares</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Informations/default.aspx">Informations</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_E900_curit_E900_/default.aspx">Sécurité</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Vista/default.aspx">Vista</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_26002300_233_3B00_curit_26002300_233_3B00_/default.aspx">S&amp;#233;curit&amp;#233;</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/XP/default.aspx">XP</category></item><item><title>Sécurité : e-mag sur MPack, IcePack, n404, Torpig et de la Bluepill</title><link>http://msmvps.com/blogs/docxp/archive/2007/09/21/1208693.aspx</link><pubDate>Fri, 21 Sep 2007 17:58:32 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1208693</guid><dc:creator>jeanmarc</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/docxp/rsscomments.aspx?PostID=1208693</wfw:commentRss><comments>http://msmvps.com/blogs/docxp/archive/2007/09/21/1208693.aspx#comments</comments><description>&lt;p&gt;D&amp;#39;accord, c&amp;#39;est une news-letter, mais qui tient plus, à mon avis, du e-mag, tellement le contenu est intéressant. Voyez donc par vous-même :&lt;/p&gt; &lt;ul&gt; &lt;li&gt;Les kits de hacking à la portée de tous : Mpack, IcePack, n404, Fishing Bait, Shark.&lt;/li&gt; &lt;li&gt;Les rootkits basés sur la virtualisation hardware : la BluePill et Vitriol&lt;/li&gt; &lt;li&gt;Les vulnérabilités du mois : flux vidéo vérolés dans MSN Messenger, attaque BIND&lt;/li&gt; &lt;li&gt;Outils : BHODemon, Comodo Personnal Firewall, Recover file, Revo uninstaller&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Bref, un site à bookmarker d&amp;#39;urgence, pour tous ceux qui s&amp;#39;intéressent à la sécurité !&lt;/p&gt; &lt;p&gt;N° 16, Septembre 2007 : &lt;a href="http://www.xmcopartners.com/actu-secu/actu_secu_septembre2007.pdf"&gt; Version PDF&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Bonne lecture !&lt;/p&gt; &lt;blockquote&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;a href="http://www.xmcopartners.com/actualite-securite-vulnerabilite-fr.html" target="_blank"&gt;N° précédents&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1208693" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx">Malwares</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Informations/default.aspx">Informations</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Favoris/default.aspx">Favoris</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_E900_curit_E900_/default.aspx">Sécurité</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Vista/default.aspx">Vista</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_26002300_233_3B00_curit_26002300_233_3B00_/default.aspx">S&amp;#233;curit&amp;#233;</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/XP/default.aspx">XP</category></item><item><title>Malware Removal Starter Kit</title><link>http://msmvps.com/blogs/docxp/archive/2007/09/13/1191879.aspx</link><pubDate>Thu, 13 Sep 2007 17:00:47 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1191879</guid><dc:creator>jeanmarc</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/docxp/rsscomments.aspx?PostID=1191879</wfw:commentRss><comments>http://msmvps.com/blogs/docxp/archive/2007/09/13/1191879.aspx#comments</comments><description>&lt;p&gt;Pour ceux qui l&amp;#39;auraient loupé, voici une intéressante documentation (en anglais) qui vous guidera afin de créer un CD Windows PE contenant des outils de désinfection.&lt;/p&gt; &lt;p&gt;Ce CD vous permettra de scanner un PC, sans avoir à démarrer le système malade et donc sans courir le risque de voir le malware intervenir pour empêcher son nettoyage.&lt;/p&gt; &lt;p&gt;Téléchargement : &lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=6cd853ce-f349-4a18-a14f-c99b64adfbea&amp;amp;displaylang=en"&gt;Download details: Malware Removal Starter Kit&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1191879" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/docxp/archive/tags/Trucs+et+astuces/default.aspx">Trucs et astuces</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Malwares/default.aspx">Malwares</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_E900_curit_E900_/default.aspx">Sécurité</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Vista/default.aspx">Vista</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/S_26002300_233_3B00_curit_26002300_233_3B00_/default.aspx">S&amp;#233;curit&amp;#233;</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/Experimentation/default.aspx">Experimentation</category><category domain="http://msmvps.com/blogs/docxp/archive/tags/XP/default.aspx">XP</category></item></channel></rss>