Posted by

Comments

# re: TCP/IP and Internet Security Vulnerabilities

Friday, April 23, 2004 3:51 AM by Harry Waldron

The link to the Infoworld article doesn't work. I was able to find the article, and the correct URL is:

http://www.infoworld.com/article/04/04/20/HNtcpwarning_1.html

# re: TCP/IP and Internet Security Vulnerabilities

Friday, April 23, 2004 6:30 AM by Harry Waldron

Thank you Joy for the feedback, as I've corrected the InfoWorld link :)

# Got Sasser?

Sunday, May 02, 2004 2:40 PM by TrackBack

# MS04-011 & IE6 running on W2K Professional

Sunday, May 02, 2004 9:10 PM by Harry Waldron

Recently I'd been reading the posts concerning the issues found with MS04-011.

I've got another one to add. Several systems I manage running W2K Professional SP4 and kb patched along with IE6 fully patched began to all show signs of inability to move across the internet. At the same time the system's processor would go to 100% CPU usage and remain until I could manage to shut down IE6 with Task Manager.

After reading the Microsoft KB835732, I then took note of the following Microsoft KB article http://support.microsoft.com/default.aspx?kbid=841382

I wondered if this could also apply to the issue I was seeing. After uninstalling MS04-011 from these systems immediately the problem with all these systems went away.

Hopefully between firewalling ports tcp 445, 5554, 9996 and keeping antivirus software up to date I can keep the critters out of the systems till a revised MS04-011 patch comes out addressing this.

G'day,

Kevin

# Got Sasser?

Monday, May 03, 2004 9:54 AM by TrackBack

# Murphy's Law on not patching your PC with Microsoft Security Updates

Tuesday, May 04, 2004 6:55 AM by TrackBack

# MS04-011 Sasser.E (new ports 1022 and 1023)

Sunday, May 09, 2004 3:06 PM by TrackBack

MS04-011 Sasser.E (new ports 1022 and 1023)

# re: Internet Explorer - Two new critical vulnerabilities in the wild

Wednesday, June 09, 2004 6:02 PM by Harry Waldron

Any idea when Microsoft will release a patch?

# re: Internet Explorer - Two new critical vulnerabilities in the wild

Wednesday, June 09, 2004 6:28 PM by Harry Waldron

Looks like Symantec has updated Norton Antivirus 2004 to block the exploit: http://securityresponse.symantec.com/avcenter/venc/data/downloader.trojan.html

# IIS 6.0 Vulnerabilities

Wednesday, June 09, 2004 9:50 PM by TrackBack

# re: Crash Pentium Trojan - (only 4 bytes long)

Friday, June 11, 2004 10:30 AM by Harry Waldron

I think this the old F00F bug that was discovered back in 1997. It's basicly a hardware bug in the Pentium 1 CPU that makes the processor lock up and freeze the entire computer. It does not affect PII and later CPUs.

More information: http://www.x86.org/errata/dec97/f00fbug.htm

Cheers,

/Lars.

# CERT: Cross-Domain Redirect Vulnerability in Internet Explorer

Monday, June 14, 2004 10:04 AM by TrackBack

# CERT: Cross-Domain Redirect Vulnerability in Internet Explorer

Monday, June 14, 2004 10:09 AM by TrackBack

# re: Microsoft Monthly Security Newsletter - Free Registration

Tuesday, June 15, 2004 5:28 PM by Harry Waldron

Interestingly, and perhaps not coincidentally, the volume 1, issue #7 publication of the newsletter has a small bio about MVP, Mr. Harry Waldron. :)

I saw that when I received it several weeks ago. :)

Rick

# re: Commentary on Article: Time to Dump Internet Explorer

Sunday, June 20, 2004 5:31 PM by Harry Waldron

# re: Ethical EMAIL - new DO NOT SPAM Registry

Tuesday, June 22, 2004 5:04 PM by Harry Waldron

Spam has crashed my computer several time, and I have spent several hundred dollars on computer repairs over the past year..
I have spent hours sending replys asking to be remove of email listings, but soon as I do this, I begin to recieve more spam...
NOTE: It has been a no win situation for me!

# re: New IE Browser Helper Objects (BHO) scanning tool

Wednesday, June 30, 2004 9:51 AM by Harry Waldron

How about adding functionality to be able to scan a remote machine for BHO's. This would be great in large enterprise environments.

# re: BEST PRACTICES: Safest way to surf with IE (use limited accounts)

Wednesday, June 30, 2004 10:57 AM by Harry Waldron

If you have just one account would making a limited account highten or lower your security?
I could imagen that an adminaccount not in use could be hacked more easely through the net.

# re: Ject/Scob Attack: IWAP_WWW account on IIS servers

Monday, July 05, 2004 8:44 PM by Harry Waldron

I have IWAP-WWW on my windows xp - it just appeared out of "no where" and I can't even access my "user account" in the control panel...so any suggestions?! Thanks in advance for your help!

# re: VirusTotal - Free analysis of new samples (multiple AV scanners)

Tuesday, July 06, 2004 4:37 AM by Harry Waldron

There's 12 AVs working now (including ClamAV).

# re: Internet Explorer isn't alone on Critical Browser Vulnerabilities

Tuesday, July 06, 2004 1:14 PM by Harry Waldron

I sent you a separate e-mail about what found.
IE6 and AOL9.0 can be be made not vulnerable, by making a simple change to the IE Internet security settings. Click on Custom, and disable "Navigate subframes across domains".
It was reported at http://www.windowsbbs.com/showthread.php?t=32457

# re: Trojan.Ecure - Internet Explorer & Host files attacks continue

Sunday, July 11, 2004 11:23 AM by Harry Waldron

Symantec writeup starts off well. However if you don't have any uptodate av software to detect the files, when you reboot it all starts off again as they didn't check the various startup locations in the registry/program locations. I'm still trying to disinfect my parents-in-law machine.

# re: Microsoft's Spam control resource center

Wednesday, July 14, 2004 10:30 AM by Harry Waldron

The other day a microsoft spam control download popped up on my screen that I attempted to download, but I lost it. How do I get it bacK

# Everyone wanted to make sure I wasn't hyperventilating.....

Monday, July 26, 2004 11:15 PM by TrackBack

# re: Opera 7.53 - Security Update to prevent URL Spoofing

Tuesday, July 27, 2004 9:25 PM by Harry Waldron

Thanks for this, Harry. You would think as a registered user they would let me know.

# re: MasterCard adds new NameProtect service to combat fraud

Wednesday, July 28, 2004 2:13 PM by Harry Waldron

cool...

# MS04-025: IE Rollup patch available as alternative to Windows Update

Saturday, July 31, 2004 9:37 AM by TrackBack

# MS04-025: IE Rollup patch available as alternative to Windows Update

Saturday, July 31, 2004 9:38 AM by TrackBack

# re: Limited Linux AV protection (waiting for 1st major worm)

Sunday, August 08, 2004 10:47 PM by Harry Waldron

I run both Windows and Linux in-house and I, too, wish there were more (any?) choices out there for Linux A/V. The situation is doubly ironic because Linux pioneered so other security tools (Satan, Tripwire, Snort, etc etc).

I'm also curious about why:

1. The Open Source community doesn't take on Linux A/V software as a project (and I confess - *I* don't know how I'd go about initiating such a project myself)

2. The Windows community doesn't collectively throw out that junk garbage Petri dish called "Outlook Express"? *Any* kind of mail client would be better than Outlook when it comes to preventing random infections by naive (e.g. home) users...

IMHO...

# re: Five Great Rules for Wireless Security

Friday, August 13, 2004 10:13 PM by Harry Waldron

Hi Harry


"1. Dont breach your own firewall."
This advice is certainly one way to do it. But more recently the method I've been favoring is to use 802.1x the way microsoft did in their implementation. http://www.microsoft.com/technet/prodtechnol/winxppro/deploy/wlandply.mspx

"2. Dont spurn Media Access Control"
Unfortunately ease of use often trumps security. Raise your hand if you are running DHCP. See what I mean. Almost all of us went for ease of use instead of managing static addresses. It gets unweildy really fast. Instead of collecting hardware addresses which are spoofable use digital certificates in 802.1x. Again see the microsoft article. You get b-directional authentication. Clients are authenticated to the server, server is authenticated to the client.

# re: F-Secure provides Caribe Worm screens of a mobile phone infection

Wednesday, August 25, 2004 5:45 PM by Harry Waldron

i have been infected by this worm and its draining my battery and infecting other bluetooth capable mobile phones. even if i will turn it off (bluetooth) still will send the virus. i tried to format and upgrade my mobile phone and erase the worm. beware of this worm and it is very frustrating.

# re: MS04-028 - ISC releases GDI Scan Tool

Tuesday, September 28, 2004 4:47 PM by Harry Waldron

Hi Harry! Just wanted to let your readers know that we have a tutorial on how to use this tool and interpret its results.

It can be found here:

http://www.bleepingcomputer.com/forums/topict3077.html

# re: MS04-028: Trojan.Ducky A/B exploits GDI+ vulnerabilities

Friday, October 01, 2004 9:19 AM by Harry Waldron

Seems to be that the AV industry is already a week late with this. We got mails with Jpeg attachments containg string Ducky as editor already a week ago mailed as "Feedback" to our website.

Just we were unsure, what's the malicious code in it and didn't want to try it out.

# OCTOBER 2004 - MICROSOFT SECURITY BULLETINS

Saturday, October 30, 2004 3:22 PM by TrackBack

# October 2004 - Microsoft Security Bulletins

Saturday, October 30, 2004 4:32 PM by TrackBack

# Great Article on Spyware on Harry Waldron's Web blog

Thursday, November 04, 2004 4:47 AM by TrackBack

# re: Sober.I Worm - MEDIUM RISK by Secunia

Friday, November 19, 2004 10:52 AM by Harry Waldron

Some websites are saying that the attachments can be *.zip files as well.

# re: Sober.I worm escalated to HIGH RISK by Secunia

Wednesday, November 24, 2004 10:35 PM by Harry Waldron

Something similar is arriving to my Gmail account (25 messages in 5 days) and to my Grex account (3 mails), althout the attachment is a 129 bytes plain text file (no double extension) that contains the info of the attachment that has been filtered by Norton.

They all are built the same but using different subjects and coming from different real sender, the spoofed sender is the same.

----- EXAMPLE OF ONE FROM THE INBOX ----------
From: info@yahoo.fr <info@yahoo.fr>
To: cdrom_drae@gmail.com --> not my e-mail account
Date: Sat, 20 Nov 2004 17:55:41 UTC
Subject: Your Password <KEY:2008>
Parts/attachments:
1 Shown 15 lines Text
2 129 bytes Plain
----------------------------------------
Your password was changed successfully!
++++++ User-Service: http://www.yahoo.fr
++++++ MailTo: postmaster@yahoo.fr
*-*-* Anti_Virus: No Virus was found
*-*-* GMAIL- Anti_Virus Service
*-*-* http://www.gmail.com

<u>Attachment</u>: 'suppression de norton antivirus1.txt'
<blockquote>Content:
Norton AntiVirus a supprimé la pièce jointe suivante : yahoo.6228.doc.com.

Elle était infectée par le virus W32.Sober.I@mm.</blockquote>

=============

The original sender can be found here:

Delivered-To: *******@gmail.com --> My mail account
Received: by 10.38.75.25 with SMTP id x25cs28978rna;
Sat, 20 Nov 2004 10:12:09 -0800 (PST)
Received: by 10.38.171.55 with SMTP id t55mr198713rne;
Sat, 20 Nov 2004 10:12:07 -0800 (PST)
Return-Path: <info@yahoo.fr>
Received: from rkhkangnp.fr (80-***-***-61.adsl.nuria.telefonica-data.net [80.***.***.61]) --> I've masked the original IP
by mx.gmail.com with SMTP id 71si453451rnb;
Sat, 20 Nov 2004 10:12:07 -0800 (PST)
Received-SPF: neutral (gmail.com: 80.***.***.61 is neither permitted nor denied by domain of info@yahoo.fr)
From: info@yahoo.fr
To: cdrom_drae@gmail.com

=============

<u>The subjects of the mails are:</u>
Your Password <KEY:2008>
Password confirmation <KEY:3682>
Registration confirmation <KEY:8459>

I wonder why it keeps sending the txt file as it's only spamming inert mails, maybe a bug in the worm?

# re: W32/Funner.worm (avoid FUNNY.EXE in MSN IM)

Thursday, November 25, 2004 12:11 AM by Harry Waldron

This looks to be some info about this worm. Removal instructions should be at the bottom of the page. If you're not able to log in to your computer to do what the page tells you to do, try booting it in safe mode. That should bypass any virus type startup files, so you can log on without the hassle of the instant relog problems.

# re: W32/Funner.worm (avoid FUNNY.EXE in MSN IM)

Thursday, November 25, 2004 12:11 AM by Harry Waldron

Might help if I actually posted the URL. Heh. Here it is. http://securityresponse.symantec.com/avcenter/venc/data/w32.funner.html

# re: UPDATE YOUR BROWSER - If you have installed Sun's Java VM engine

Thursday, November 25, 2004 11:03 AM by Harry Waldron

Well, as it's not a browser specific bug but a plugin flaw instead everyybody should update their java plugin either using IE, Opera or Firefox.

# re: Lock IT Down: Conduct an internal and external security audit

Tuesday, November 30, 2004 9:29 AM by Harry Waldron

"...information is gathered and problems are identified and analyzed..."

Having done audits/assessments for a number of years (in FTE and consulting positions), one of the most important (and often overlooked) parts of an assessment is communicating the issues to the customer in terms of their business needs.

Sure, it's easy to go on-site and run Nessus or ISS's Internet Scanner (regardless of what anyone says, there are still consultants and consulting organizations that do just that and not a great deal more) and print out a report on company letterhead. Look at a default setup of Nessus, for example...there are no less than 9 warnings for issues that all relate back to null session enumeration. And in a great many cases, this may not be a security issue at all for an organization.

The point is that the assessment team needs to do a thorough job of the assessment, to include interviewing key personnel, reviewing documentation, etc.

"Continuing work"

Agreed. Security is a process, not a point in time.

H. Carvey
"Windows Forensics and Incident Recovery"
http://www.windows-ir.com

# re: Give me a patch and you protect me for a day - Teach me security ....

Tuesday, November 30, 2004 9:39 AM by Harry Waldron

"...how will users react to a new virus attack where the AV vendors don't have signatures out, yet they have infected email attachments to process in their in-boxes?"

Having gone through just such an event, it's not only important to have security awareness training for users, but it's also important to have suitable training for administrators, as well. During the incident I was involved in, I spent my time and energy organizing several sysadmins to assist in containment and eradication procedures, while on admin got on the phone with our A/V vendor. While he was on hold, he decided to do his own "analysis". Since then, I have seen others (CERT members, admins, etc.) attempt to do the same sort of thing...and it's a mess. To often, they spend no time thinking about such things ahead of time, and when they get into a situation in which they feel the need to do *something*, they invariably end up missing some really simple steps along the way. This is seen time and time again in the public lists.

On an aside, the issue of interconnectivity applies to users, as well (bear with me here...). Just as networks are becoming more and more interconnected, one also has to keep in mind that policies and awareness are, too. For example, a company I worked for got hit by an email-borne worm. Users were instructed to (a) do not open email if they don't know the sender, and (b) if they do know the sender, but the attachment doesn't look quite kosher, don't open it. Well, one of our customer's marketeers had a habit of sending jokes and animated files (animated GIFs, Flash movies, etc.) to people he knew, so when the email arrived, the marketing folks who received it immediately double-clicked on the attachment. While we were trying to reiterate and enforce our policies and awareness, we had a customer who wasn't quite on board with that sort of thing.

H. Carvey
"Windows Forensics and Incident Recovery"
http://www.windows-ir.com

# re: Dangerous EMAIL - DANGER there's a 300 foot tall Tsunami approaching

Friday, December 03, 2004 9:50 AM by Harry Waldron

I could send this to my mother in NEBRASKA and she'd head for higher ground...

# Problems with 040?

Saturday, December 04, 2004 9:53 AM by Harry Waldron

I have been hearing of reports that 040 has caused problems, there is a link in the KB now of known issues, but some of the issues I am hearing is that when you install it from WU or AU it does not update all the files. I had someone report to me that after they installed 040, they could no longer invoke an IE object from a link in an email, the browser window would open, but not go anywhere.

Regards.

SE~

# re: Dangerous EMAIL - DANGER there's a 300 foot tall Tsunami approaching

Sunday, December 05, 2004 11:17 AM by Harry Waldron

OMIGOD! A 300 foot tsunami! Quick! Quick! Send an email!

# re: MS04-040: Internet Explorer Cummulative Update (IFRAME FIX)

Sunday, December 05, 2004 6:16 PM by Harry Waldron

It is also important to note that MS04-038 is still required for Windows XP SP2 and Windows Server 2003.

# Secunia: Multiple Browser Injection Vulnerablilities

Wednesday, December 08, 2004 12:59 PM by TrackBack

# re: Secunia: Multiple Browser Injection Vulnerabilities

Wednesday, December 08, 2004 3:59 PM by Harry Waldron

Great write up Harry!!

# Secunia: Multiple Browser Injection Vulnerablilities

Thursday, December 09, 2004 5:18 AM by TrackBack

# re: Mozilla releases Firefox 1.0

Friday, December 17, 2004 7:13 PM by Harry Waldron

I just installed FireFox 1.0 on my computer in an attempt to protect myself from the ones that exploit the holes that exist in MSIE and because my version, MSIE 5.5, has been crashing and locking up my machine to the point where it is almost useless. I cannot upgrade because I am running Windows 98SE and I understand that I would have to upgrade my Windows OS to use a newer version of MSIE. I have not had one crash or system freeze with FireFox.

I am also running McAfee VirusScan as my AV program. Today I happened to surf over to a site that I know has a link to webpdp.gator.com. The address for this and other sites are in my Mcafee list of banned URLs and IPs, but I didn't get the warning from Mcafee. When I went to this address with MSIE the warning came up as expected. I then went to eicar.com with FireFox to test my AV protection. Much to my surprise I was able to download all the test files without any warnings at all. It looks like I am surfing the net without any AV protection at all. I have sent inquires to Mcafee and looked through the McAfee Support Forums for a solution but no luck. The only issue with FireFox and McAfee seems to be the automatic update of the DAT files and the lack of Active X.

I would like to urge all FireFox users to test their browser to make sure that their AV programs are working. In the meantime I'll will be attempting to get some answers from McAfee and Mozilla about this problem. I would appreciate any suggestions or help with this matter.

Donald

# re: Clark Howard's advice on EMAIL phishing scams

Tuesday, December 21, 2004 2:13 PM by Harry Waldron

Here is another Scam!

FROM: THE GAMING CONTROL BOARD
INTERNATIONAL PROMOTIONS/PRIZE AWARD DEPARTMENT

Dear Recipient

RESULTS FOR CATEGORY "A" DRAWS/XMAS BONANZA

Congratulations to you as we bring to your notice, the results of the first Category draws of TRIPPLE WINS INTERNATIONAL SCIENTIFIC GAME PROMOTION. We are happy to inform you that you have emerged a winner under the first Category, which is part of our promotional draws. The draws were held to mark their first international program prior to end of year bonanza for Microsoft users. Participants were selected through a computer ballot system drawn from 25, 000, 00 names/email addresses of individuals and companies from Africa, America, Asia, Australia, Europe, Middle East, and Oceania as part of our International Promotions Program.Two names came as the lucky winners You/Your company email id, attached to ticket number 6422-5-486, with serial number 79-26 drew the lucky numbers 33-92-78-05 (18) consequently won in the First Category.You have therefore been awarded a lump sum pay out of $6.000,000(six million united state dollars)each, which is the winning payout for Category" A"
winners. This is from the total prize money of $12,000,000 shared among the 2 winners in this category.

CONGRATULATIONS!

Your fund is now deposited with our transfer agents Cash Change First Securities INC UK ,and insured in your name. In your best interest and also to avoid mix up of numbers and names of any kind, we request that you keep the entire details of your award strictly from public notice until the process of transferring your claims has been completed, and your funds
remitted to your account.This is part of our security protocol to avoid double claiming or unscrupulous acts by participants/nonparticipants of this program.

We also wish to bring to your notice our end of year premium stakes draw where you stand a chance of winning up to $50 million; we hope that with a part of your prize you will participate in it.

Please contact your claims agent immediately for due processing and remittance of your prize money to a designated account of your choice.

FILE/CLAIMS OFFICER
Mr.Edward Clapton
Financial Director,
Cash Change First Securities INC UK
14 Jupiter House Calleva Park
Aldermaston Reading Berkshire RG7 8NN.
TEL: +44-704-010-6304
TEL: +31-626-322-273
fax: + 31-205-248-858
FAX: +44-870-136-9041
EMAIL:edward_clapton424@mmail.com

you are advised to contact your file/claims officer by email and/or fax within a week of receiving this notice. Failure to do so may warrant disqualification. NOTE: For easy reference and identification, find below your reference. Remember to quote these numbers in every one of your correspondence with your claims agent.

REFERENCE NUMBER: TGA-4GA-65389
Congratulations once again from all our staff and thank you for being part of our promotional program.



Sincerely,

THE LOTTERY COORDINATOR,
TRIPPLE WINS INTERNATIONAL GAMES
JAN LUYKENSTRAAT 59
1071 CS AMSTERDAM
THE NETHERLANDS

N.B: Any breach of confidentiality on the part of the winners will result to disqualification. Please do not reply to this mail box. Contact your claims agent immediately.

___________________________________________________________________________
Mail sent from WebMail service at PHP-Nuke Powered Site
- http://Antanavige.com

# re: Santy -- PHP BB Worm in-the-wild

Wednesday, December 22, 2004 5:50 AM by Harry Waldron

Harry, you are a moderator at forums.mcafeehelp.com, which I believe also runs on a vulnerable version of phpBB....

# CERT Advisory - AWStats Security Vulnerabilities

Friday, February 11, 2005 5:33 AM by TrackBack

# CERT Advisory - AWStats Security Vulnerabilities

Friday, February 11, 2005 5:33 AM by TrackBack

# Microsoft's GhostBuster - New experimental tool to detect Windows Root Kits

Sunday, February 20, 2005 5:58 AM by TrackBack

# Microsoft's GhostBuster - New experimental tool to detect Windows Root Kits

Sunday, February 20, 2005 6:06 AM by TrackBack

# Microsoft's GhostBuster - New experimental tool to detect Windows Root Kits

Sunday, February 20, 2005 6:06 AM by TrackBack

# Microsoft's GhostBuster - New experimental tool to detect Windows Root Kits

Sunday, February 20, 2005 6:14 PM by TrackBack

# Two New repackaged Bagle variants circulating

Wednesday, March 02, 2005 3:32 AM by TrackBack

# New IM Worms Hit MSN Messenger

Tuesday, March 08, 2005 12:25 AM by TrackBack

# Lexis Nexis data theft impacts the privacy of 32,000 US citizens

Sunday, March 13, 2005 4:02 AM by TrackBack

# Lexis Nexis data theft impacts the privacy of 32,000 US citizens

Sunday, March 13, 2005 4:04 AM by TrackBack

# Lexis Nexis security breach - Privacy of 32,000 US citizens compromised

Sunday, March 13, 2005 4:05 AM by TrackBack

# Lexis Nexis security breach - Privacy of 32,000 US citizens compromised

Monday, March 14, 2005 5:39 AM by TrackBack

# McAfee AV LHA Vulnerability - Upgrade to Engine 4400

Tuesday, March 22, 2005 5:56 AM by TrackBack

# McAfee AV LHA Vulnerability - Upgrade to Engine 4400

Tuesday, March 22, 2005 5:56 AM by TrackBack

# Microsoft April Security Updates - MS05-016

Thursday, April 14, 2005 4:18 AM by TrackBack

# Microsoft April Security Updates - MS05-016

Thursday, April 14, 2005 4:18 AM by TrackBack

# Mozilla - Move to latest versions to protect against new Exploits

Monday, April 18, 2005 5:32 AM by TrackBack

# Mozilla - Move to latest versions to protect against new Exploits

Monday, April 18, 2005 5:32 AM by TrackBack

# PC Satisfaction back from the dead as OneCare Live?

Friday, May 13, 2005 7:47 AM by TrackBack

I saw a post today about a new Microsoft product called OneCare Live. This looks strangely familiar to a beta I worked on previously called PC Satisfaction. It was a nice product that just kind of died on the vine...

# Software change management

Friday, June 03, 2005 6:00 AM by TrackBack

# Untitled

Monday, June 27, 2005 7:20 PM by TrackBack

<DIV class=postcolor>Click Here for more information: Secunia Advisory - <A href="http://msmvps.com/harrywaldron/archive/2005/06/07/50934.aspx" target=_blank><STRONG><FONT color=#496690>Secunia Advisory - Mozilla Frame Injection Vulnerability </FONT></...

# CERT WARNING - Targeted Trojan Email Attacks

Saturday, July 09, 2005 5:21 AM by TrackBack

# CERT WARNING - Targeted Trojan Email Attacks

Saturday, July 09, 2005 5:21 AM by TrackBack

# VISA/AMEX cut ties with Card System Solutions after privacy leak

Thursday, July 21, 2005 2:18 PM by TrackBack

# Windows Vista - More secure than reported to combat 1st

Saturday, August 06, 2005 5:24 AM by TrackBack

# MS05-039: Zotob.A Internet Worm -- In-the-wild

Sunday, August 14, 2005 10:16 AM by TrackBack

# Article: Potential for Destructive PC Microcode or BIOS Virus

Saturday, August 27, 2005 6:37 PM by TrackBack

# Watch for $9.95 charges on your credit cards

Thursday, September 08, 2005 12:35 PM by TrackBack

# Backdoor Trojan targets Microsoft Access

Tuesday, October 04, 2005 5:07 AM by TrackBack

# Sober worm is still around; Optix propagating through corporate networks and AOL IM.

Thursday, October 06, 2005 8:20 PM by TrackBack

# Macromedia Flash Player vulnerability in older versions - POC Exploit published

Friday, November 18, 2005 9:24 AM by TrackBack

# Yes, by now I'm sure my IP address has been tracked by the FBI and no, thank you, I don't want to see Paris's videos

Monday, November 21, 2005 10:16 PM by TrackBack

# Microsoft Security Advisory (911302) - Information and workarounds for new IE vulnerability

Tuesday, November 22, 2005 4:57 AM by TrackBack

# Sober.X Worm - Special FBI Warning

Thursday, November 24, 2005 8:28 AM by TrackBack

# Sober.X Worm - Special FBI Warning

Thursday, November 24, 2005 8:30 AM by TrackBack

# Lost Blogs?

Monday, November 28, 2005 11:01 PM by TrackBack

# Blogs posted on myITforum from 11/25/2005 until 11/28/2005

Monday, November 28, 2005 11:04 PM by TrackBack

# Microsoft Security Advisory (911302) - Information and workarounds for new IE vulnerability

Monday, November 28, 2005 11:42 PM by TrackBack

# Sober.X Worm - Special FBI Warning

Tuesday, November 29, 2005 12:16 AM by TrackBack

# Windows Rootkits

Tuesday, November 29, 2005 6:41 AM by TrackBack

# Current recommendations for Malicious WMF Exploits in-the-wild

Thursday, December 29, 2005 7:10 AM by My IT Forum Technology Blogs

# Current recommendations for Malicious WMF Exploits in-the-wild

Thursday, December 29, 2005 7:11 AM by Microsoft Most Valuable Professional

&amp;nbsp;&amp;nbsp; Microsoft has issued Security Advisory 912840&amp;nbsp;for a Vulnerability in Graphics Rendering...

# Current recommendations for Malicious WMF Exploits in-the-wild

Thursday, December 29, 2005 7:12 AM by Microsoft Most Valuable Professional

&amp;nbsp;&amp;nbsp; Microsoft has issued Security Advisory 912840&amp;nbsp;for a Vulnerability in Graphics Rendering...

# Current recommendations for Malicious WMF Exploits in-the-wild

Thursday, December 29, 2005 7:15 AM by Microsoft Most Valuable Professional

&amp;nbsp;&amp;nbsp; Microsoft has issued Security Advisory 912840&amp;nbsp;for a Vulnerability in Graphics Rendering...

# Current recommendations for Malicious WMF Exploits in-the-wild

Thursday, December 29, 2005 7:24 AM by Microsoft Most Valuable Professional

&amp;nbsp;&amp;nbsp; Microsoft has issued Security Advisory 912840&amp;nbsp;for a Vulnerability in Graphics Rendering...

# Current recommendations for Malicious WMF Exploits in-the-wild

Thursday, December 29, 2005 7:26 AM by Microsoft Most Valuable Professional

&amp;nbsp;&amp;nbsp; Microsoft has issued Security Advisory 912840&amp;nbsp;for a Vulnerability in Graphics Rendering...

# Current recommendations for Malicious WMF Exploits in-the-wild

Thursday, December 29, 2005 7:51 AM by Microsoft Most Valuable Professional

&amp;nbsp;&amp;nbsp; Microsoft has issued Security Advisory 912840&amp;nbsp;for a Vulnerability in Graphics Rendering...

# Current recommendations for Malicious WMF Exploits in-the-wild

Thursday, December 29, 2005 7:59 AM by Microsoft Most Valuable Professional

&amp;nbsp;&amp;nbsp; Microsoft has issued Security Advisory 912840&amp;nbsp;for a critical vulnerability in the Windows...

# New WMF variant - McAfee protection to be released in DAT 4664

Saturday, December 31, 2005 8:33 PM by Microsoft Most Valuable Professional

&amp;nbsp;&amp;nbsp; McAfee has just updated their website with information related to the new WMF&amp;nbsp;variant.&amp;nbsp;...

# New WMF variant - McAfee protection to be released in DAT 4664

Saturday, December 31, 2005 8:33 PM by My IT Forum Technology Blogs

# New WMF variant - McAfee protection to be released in DAT 4664

Sunday, January 01, 2006 5:09 AM by Microsoft Most Valuable Professional

&amp;nbsp;&amp;nbsp; McAfee has just updated their website with information related to the new WMF&amp;nbsp;variant.&amp;nbsp;...

# New WMF variant - McAfee protection was released in DAT 4664

Sunday, January 01, 2006 5:17 AM by Microsoft Most Valuable Professional

&amp;nbsp;&amp;nbsp; McAfee has just updated their website with information related to the new WMF&amp;nbsp;variant.&amp;nbsp;...

# New WMF variant - McAfee protection was released in DAT 4664

Sunday, January 01, 2006 6:35 AM by My IT Forum Technology Blogs

# The WMF Exploit - Ideas for system administrators returning to work

Monday, January 02, 2006 6:11 AM by My IT Forum Technology Blogs

# The WMF Exploit - Ideas for system administrators returning to work

Monday, January 02, 2006 6:12 AM by Microsoft Most Valuable Professional


In the various forums I participate in, I saw that many administrators&amp;nbsp;worked during the holiday...

# The WMF Exploit - Ideas for system administrators returning to work

Monday, January 02, 2006 7:39 AM by Microsoft Most Valuable Professional


In the various forums I participate in, I saw that many administrators&amp;nbsp;worked during the holiday...

# The WMF Exploit - Ideas for system administrators returning to work

Monday, January 02, 2006 7:55 AM by Microsoft Most Valuable Professional


In the various forums I participate in, I saw that many administrators&amp;nbsp;worked during the holiday...

# The WMF Exploit - Ideas for system administrators returning to work

Monday, January 02, 2006 7:58 AM by Microsoft Most Valuable Professional


In the various forums I participate in, I saw that many administrators&amp;nbsp;worked during the holiday...

# The official MSN Messenger 8 beta release and Virkel.F virus

Sunday, January 22, 2006 6:32 AM by Microsoft Most Valuable Professional

This entry below in December&amp;nbsp;caused some recent confusion, with the&amp;nbsp;official MSNM 8 beta, which&amp;nbsp;has...

# The official MSN Messenger 8 beta release and Virkel.F

Sunday, January 22, 2006 6:32 AM by My IT Forum Technology Blogs

# The official MSN Messenger 8 beta release and Virkel.F virus

Sunday, January 22, 2006 6:36 AM by Microsoft Most Valuable Professional

This entry below in December&amp;nbsp;caused some recent confusion, with the&amp;nbsp;official MSNM 8 beta, which&amp;nbsp;has...

# Live Messenger 8 &amp;quot;beta&amp;quot; is actually a security risk. (not really the beta)

Sunday, January 22, 2006 9:37 AM by Into the mind of Gerlach

Harry Waldon reports that the &quot;Live Messenger Beta&quot; download is actually a security risk, written by...

# Live Messenger 8 ''beta'' is actually a security risk. (not really the beta)

Sunday, January 22, 2006 9:47 AM by Into the mind of Gerlach

Harry Waldon reports that the &quot;Live Messenger Beta&quot; download is actually a security risk, written by...

# WinAmp 5.13 released to address ZERO DAY exploit

Monday, January 30, 2006 7:40 PM by My IT Forum Technology Blogs

# WinAmp 5.13 released to address ZERO DAY exploit

Monday, January 30, 2006 7:56 PM by Microsoft Most Valuable Professional

&amp;nbsp; Nullsoft has expediently released version 5.13 to address this ZERO DAY attack ISC Informationhttp://www.incidents.org/diary.php?storyid=1080Download...

# Attaque sur PhpBB en pr&amp;#233;paration ?

Monday, March 20, 2006 10:59 AM by Jean-Marc, XP Geek !

En tous cas, les administrateurs de forums PhpBB devraient y prendre garde :
Un bot du nom de FuntKlakow...

# Run phpBB and have a user named FuntKlakow? Might want to nuke that account.

Monday, March 20, 2006 7:55 PM by Aaron Tiensivu's Blog

Rumours on the internets have been rumbling about a new botnet getting ready to unleash the fury on phpBB sites. It could be bunk info, but it is good to be aware.

Links I've found on it so far:

http://www.incidents.org/diary.php?storyid=1201

ht

# createTextRange exploit now being used on over 100 sites and I'm not in the cool kids club

Saturday, March 25, 2006 1:16 PM by Clint's Security Blog

&amp;nbsp;&amp;nbsp;&amp;nbsp; As many of you may know one of the new IE 0 day exploits is spreading and being used...

# Microsoft Security Advisory (917077) - IE createTextRange

Saturday, March 25, 2006 6:28 PM by Rui Quintino

# Microsoft Security Advisory (917077) - IE createTextRange

Saturday, March 25, 2006 6:29 PM by Rui Quintino

# Trend and Symantec provide generic protection

Sunday, March 26, 2006 1:26 PM by Donna's SecurityFlash

From Microsoft MVP Harry Waldron's Security News &amp;amp; Best Practices Blog:&amp;nbsp; Trend and Symantec...

# createTextRange exploit now being used on over 200 sites

Wednesday, March 29, 2006 2:44 PM by Clint's Security Blog

&amp;nbsp;&amp;nbsp;&amp;nbsp; As many of you may know one of the new IE 0 day exploits is spreading and being used...

# Harry speaks: should beta security patches be released to the public?

Thursday, April 06, 2006 9:32 AM by Spyware Sucks

# A very bad use of encryption - GpCode.af Virus - uses RSA 330 bit encryption to hold user files hostage

Tuesday, June 06, 2006 11:52 PM by Aaron Tiensivu's Blog

This is a new one to me. A virus that encrypts your files and then demands you send money to the developer to decrypt your files. Obviously, a bad idea overall, and people are actively working on a 'crack' for the virus already.

More info here:
http:

# Yahoo, world's most popular e-mail, hit by worm

Tuesday, June 13, 2006 12:54 AM by Donna's SecurityFlash

Yahoo Inc., the world's largest provider of e-mail services, said on Monday that a software virus aimed...

# W32.Cuebot-K worm appears as Microsoft antipiracy program

Saturday, July 01, 2006 2:12 AM by Donna's SecurityFlash

The fake Windows Genuine Advantage Tool (wgavn.exe) has been named as W32.Cuebot-K worm by Sophos. ...

# Trend Micro named the fake Windows Genuine Advantage as BKDR_IRCBOT.DB; Published behavior diagram of malware

Saturday, July 01, 2006 9:15 AM by Donna's SecurityFlash

The fake Windows Genuine Advantage Tools is now detected by Trend Micro.&nbsp; They also posted the behavior...

# Vishing

Wednesday, July 19, 2006 6:57 AM by Marshall Harrison - "the gotspeech guy"

It seems that the criminal element is taking phishing to new heights and has evolved into vishing for...

# Firespy proves that just changing your browser isn't enough.

Tuesday, July 25, 2006 4:27 PM by Someone Else

Harry Waldron blogs about the Formspy / Firespy spyware trojan, which is also described by Sophos and

# Firefox malware attack.

Tuesday, July 25, 2006 6:22 PM by Spyware Sucks

From Harry's bloghttp://msmvps.com/blogs/harrywaldron/archive/2006/07/25/105724.aspx "FormSpy (aka FireSpy)...

# Windows PowerShell and the PowerShell Worm

Monday, August 07, 2006 2:53 PM by My IT Forum Technology Blogs

On&nbsp;July 29,&nbsp;2006, a new worm&nbsp;MSH/Cibyz.A&nbsp;surfaced which uses Microsoft's new&nbsp;XP...

# MS06-047: MDROPPER variants manipulate Office vulnerabilities patched in August

Saturday, August 12, 2006 7:14 AM by My IT Forum Technology Blogs

&nbsp;&nbsp; Corporate and home users should install the latest service packs for Office and using the...

# Windows XP SP1 - End of support on October 10, 2006

Thursday, September 14, 2006 11:18 AM by Kurbli

Microsoft will be discontinuing update support for Windows XP SP1 and SP1a effective October 10, 2006

# You've been hacked - Ten Important Steps to take for Recovery

Friday, October 20, 2006 11:28 AM by My IT Forum Technology Blogs

Below are ideas that might help on "what to do" if your web servers are compromised: 1. Isolate

# Time for a rant; how many sites are pointing out that many web browsers are vulnerable to the window injection vulnerability?

Monday, October 30, 2006 6:34 PM by Spyware Sucks

Edit: fix title. Come on guys - are people really so determined to find bad news about IE7 that they

# Windows Vista - Facts from Windows Vista magazine

Wednesday, November 08, 2006 10:43 AM by Kurbli

Döbbenetes mennyiségek: Facts related to the new Windows Vista operating system: 4000 engineers estimated

# Windows Vista - Yes, you'll need Anti-virus protection

Friday, November 10, 2006 6:47 PM by Harry Waldron - Microsoft MVP Blog

Vista represents great security improvements for Windows. Jim Allchin&#39;s comments may be an analogy

# I agree with MVP Harry Waldron's opinion on Vista (all OS in general) security

Saturday, November 11, 2006 10:43 PM by Donna's SecurityFlash

There was a news about Mr. Jim Allchin's interview is misunderstood. BTW, Mr. Allchin r espond to it

# Windows Vista - Anti-Virus Security protection is recommended

Sunday, November 12, 2006 11:26 AM by Harry Waldron - Microsoft MVP Blog

Jim Allchin's recent comments on the enhanced security found in Vista were misinterpreted during a telephone

# Technews &raquo; Blog Archive &raquo; Microsoft Security Updates - November 2006

# Philis.BG worm, aka Looked - McAfee offers free cleaning tool

Monday, November 20, 2006 11:31 AM by Harry Waldron - Microsoft MVP Blog

McAfee offers a free removal tool (special version of STINGER) for the new Philis.BG worm, a.k.a, Looked

# Philis.BG worm, aka Looked - McAfee offers free cleaning tool

Monday, November 20, 2006 11:31 AM by Harry Waldron - My IT Forums Blog

McAfee offers a free removal tool (special version of STINGER) for the new Philis.BG worm, a.k.a, Looked

# Windows Vista - Free security guide available

Tuesday, November 21, 2006 1:14 PM by Kurbli

Microsoft developed a security guide earlier this month that can be helpful in assessing and establishing

# W32.Spybot.ACYR worm - Exploits the unpatched Symantec SYM06-010 issue

Wednesday, November 29, 2006 2:06 PM by Harry Waldron - Microsoft MVP Blog

This new IRC based threat attempts to spread using a number of security exploits, including the SYM06-010

# W32.Spybot.ACYR worm - Exploits the unpatched Symantec SYM06-010 issue

Wednesday, November 29, 2006 2:08 PM by Harry Waldron - My IT Forums Blog

This new IRC based threat attempts to spread using a number of security exploits, including the SYM06-010

# Insecure.org's 2006 list of top 100 Network Testing Tools

Wednesday, November 29, 2006 3:19 PM by Kurbli

Hasznos dolgok. The 2006 edition of this list is available at the following site: http://sectools.org/

# W32.Spybot.ACYR - New Symantec Removal Tool

Thursday, November 30, 2006 2:39 PM by Harry Waldron - Microsoft MVP Blog

Symantec has published a removal tool for the new Spybot.ACYR worm which manipulates the SYM06-010 vulnerability

# W32/HLLP.Philis.bq, Chinese gold farmers and what you can do about it. :)

Monday, December 04, 2006 9:04 AM by Robert Hensing's Blog

Just read a fascinating blog post from the folks over at Secureworks. Basically they noted that W32/HLLP.Philis.bq

# Jim Allchin responds to Windows Vista and the improved protection from malware

Wednesday, December 20, 2006 3:01 PM by Harry Waldron - Microsoft MVP Blog

Jim Allchin provided an EXCELLENT response to Windows Vista and the improved protection from malware

# Luder Happy New Year worm - F-Secure declares MEDIUM Risk

Tuesday, January 02, 2007 8:42 AM by Harry Waldron - Microsoft MVP Blog

F-Secure has declared MEDIUM RISK for the new Luder worm, which is disquised as a "Happy New Year" greeting

# Abode users should move to version 8 to avoid PDF XSS vulnerability

Wednesday, January 03, 2007 3:55 PM by Harry Waldron - Microsoft MVP Blog

Abode users should move to version 8 to avoid the PDF Cross Scripting vulnerability . Version 8 offers

# Abode users should move to version 8 to avoid PDF XSS vulnerability

Wednesday, January 03, 2007 3:55 PM by Harry Waldron - Microsoft MVP Blog

Abode users should move to version 8 to avoid the PDF Cross Scripting vulnerability . Version 8 offers

# Storm Worm - New Waves of variants continue to emerge

Tuesday, January 23, 2007 8:41 AM by Harry Waldron - Microsoft MVP Blog

Users should continue to be cautious and not select any attachments in email from untrusted sources,

# Alert for McAfee users - manual update problems on Windows Vista

Saturday, February 10, 2007 8:02 PM by Spyware Sucks

# The 50 Most Important People on the Web

Wednesday, March 07, 2007 3:16 PM by Donna's SecurityFlash

Here's who's shaping what you read, watch, hear, write, buy, sell, befriend, flame, and otherwise do

# ANI Exploits - Microsoft releasing emergency patch on April 3rd

Monday, April 02, 2007 8:31 AM by Harry Waldron - Microsoft MVP Blog

HTML is now a little more dangerous due to an unpatched issue discovered over the weekend. Microsoft

# ANI Exploits - Microsoft releasing emergency patch on April 3rd

Monday, April 02, 2007 8:31 AM by Harry Waldron - Microsoft MVP Blog

HTML is now a little more dangerous due to an unpatched issue discovered over the weekend. Microsoft

# ANI Exploits - Microsoft releasing emergency patch on April 3rd

Monday, April 02, 2007 8:32 AM by Harry Waldron - My IT Forums Blog

HTML is now a little more dangerous due to an unpatched issue discovered over the weekend. Microsoft

# ANI Exploits - Microsoft releasing emergency patch on April 3rd

Monday, April 02, 2007 8:32 AM by Harry Waldron - My IT Forums Blog

HTML is now a little more dangerous due to an unpatched issue discovered over the weekend. Microsoft

# DDOS attacks against Estonian Government websites

Monday, April 30, 2007 9:10 AM by Spyware Sucks

I originally spotted this article thanks to Harry Waldron&#39;s blog , and what I read there saddens

# re: W32/Almanahe.a - A new root Kid on the block

Saturday, May 05, 2007 7:08 PM by Steo

Harry,

this is indeed a new development. Rootkits are too good to be true for malware writers. One can expect more intricate methods of avoidance in the future.

# re: Kardphisher - Trojan Horse Spoofs Windows Activation

Sunday, May 06, 2007 5:00 AM by Chris Quirke

Malware begats malware... once it's accepted as normal for legitimate vendors to deny you service and demand your input, it's a small SE to posing as such things (as this malware does) and triggering the same or similar payloads.

# re: Cyberspies exploit Microsoft Office using Targeted Attacks

Wednesday, May 09, 2007 1:02 PM by Michael Cain

Found this page while researching the topic:

www.daemon.be/.../targetedattacks.html

It looks at a couple of these "targeted" attacks in detail.

# Password News &raquo; Blog Archive &raquo; Microsoft Security - Check the Strength of your Passwords

Pingback from  Password News  &raquo; Blog Archive   &raquo; Microsoft Security - Check the Strength of your Passwords

# re: Best Security Practices for Internet Safety

Friday, May 25, 2007 7:24 PM by Peter Nader

Shame you didn't mention the forum, but I guess if "a member asked how they might protect themselves better", it has a high percentage of "LCD" users. And, what is a LCD user you may ask. LCD stands for Lowest Common Denominator. While I agree totally with everything listed above, I think the poster was being a little ambitious with Items 5, 6, 7 and 8. 8. Ramp up your security services and lock down unneeded services - now how would a newbie user interpret that? This type of user can be likened to a female car driver [please - no hysterical responses - I have 2 daughters and 1 wife - they will do it for you]. This car driver expects the car to run all the time. They will fill the fuel tank, but everything else is to be done for them. And so it is with their computer. Unless the OS is set up with Automatic Updates then forget it. If a firewall and anti-virus software is installed, it should be of the free variety [there are a few excellent choices out there], and must also auto update. The nag screens. The nagging is simply incomprehensible to most users. The nagging is also incomprehensible to me. I just clicked them all away. The first was expected, the second humorous, and the third didn't even register before I clicked "Allow". And I [think I] know what I'm doing. Let's just hope these LCD's don't participate in any online financial transactions.

# re: Internet Traffic Conditions - Monitoring Sites

Tuesday, May 29, 2007 10:05 PM by Gift Baskets

Internet Storm Center is an excellent tool! I love it.

# CRN review: Vista is no more secure than XP?

Thursday, May 31, 2007 8:50 AM by Harry Waldron - My IT Forums Blog

Thanking Rod for sharing this link, as the MyIT Forums newsletter is one of my &quot;must reads&quot;

# CRN review: Vista is no more secure than XP?

Thursday, May 31, 2007 8:53 AM by Harry Waldron - Microsoft MVP Blog

First of all, good security ain&#39;t solely about operating systems themselves It&#39;s more about the

# MB&#8217;s Windows Security &raquo; Blog Archive &raquo; Vista and XP are equally at peril to malware&#8230; wait, what?

Pingback from  MB&#8217;s Windows Security  &raquo; Blog Archive   &raquo; Vista and XP are equally at peril to malware&#8230; wait, what?

# re: Yahoo Web Beacons "super tracking cookies" - How to Opt-out

Saturday, June 02, 2007 9:02 PM by jimm

Umm, I would think that Yahoo stores your opt-out choice as a cookie. So if you delete cookies after opting out of Yahoo web beacons, you're deleting your opt-out. Note that Yahoo states that "This opt-out applies to a specific browser rather than a specific user." This info would be compatible with a cookie mechanism to store the opt-out info.

# re: New Windows CSRSS unpatched vulnerability

Sunday, June 03, 2007 9:59 PM by Nimda

heh - niiice ...

if you're having a problem getting the forum to recognize a full link, surround it in

# W32/Almanahe.c - New Variant of this Advanced Rootkit

Monday, June 04, 2007 10:26 AM by Harry Waldron - My IT Forums Blog

Based on personally testing corporate AV products head-to-head, I&#39;ve found McAfee provides a robust

# W32/Almanahe.c - New Variant of this Advanced Rootkit

Monday, June 04, 2007 10:27 AM by Harry Waldron - Microsoft MVP Blog

Based on personally testing corporate AV products head-to-head, I&#39;ve found McAfee provides a robust

# re: Celebrating 30 years in the Insurance Profession

Thursday, June 07, 2007 6:08 PM by Corrine

Congratulations!  

(I hope you continue feeling young, as I do after 40 years with the same employer.)

# re: W32.Spybot.ACYR - New Symantec Removal Tool

Thursday, June 14, 2007 3:49 AM by ezzat

W32/Almanahe.c

# re: Apple's new Safari for Windows Browser Beta - Early security issues

Thursday, June 14, 2007 8:40 AM by Kelly

Any first release for a browser on a new OS is likely to have security issues that they didn't think about, which is plainly obvious with this release. :) Still, we'll see how it plays out in the greater market.

# Apple Safari Beta v3.01 for Windows released to fix security issues

Friday, June 15, 2007 12:52 PM by Harry Waldron - Microsoft MVP Blog

Security issues were found with Apple&#39;s Safari beta for Windows, when it was released earlier this

# University Update-Apple Safari-Apple Safari Beta v3.01 for Windows released to fix security issues

Pingback from  University Update-Apple Safari-Apple Safari Beta v3.01 for Windows released to fix security issues

# re: MPACK Hacking Tool used in large scale Web Attack

Thursday, June 21, 2007 8:44 AM by SecurityCzar

So, what can you do about it?  For end users, keep your endpoints patched antivirus up-to-date. For Symantec users, there is a good article at sharpebusinesssolutions.com/savce_upgrade.htm describing how to keep SAV agents healthy and under support. For admins of affected web sites, a simple clean-up of the page is not sufficient - your site administrator’s credentials need to be changed. There are easy to use tools available for MPack to use to reinfect your sites even after you have manually cleaned them up. These automated tools are being fed lists of compromised site admin usernames and passwords, so make sure that you put a strong password on your site admin account.

# re: Yahoo Messenger Exploits - Upgrade to Latest version

Saturday, June 23, 2007 11:26 PM by casey

I hope it's all that they it is because my messenger mean the world to me , anyway good work hope to see more soon chow.

# re: DSL Reports - How to Secure my Computer, a layered approach

Saturday, June 30, 2007 12:46 PM by Securiour

Mostly the computers got infected due to human negligience or actions. The tips given above are good enough to follow to make your pc secure but your actions are still important e.g if you recieve an email containing suspicious email link or attachment never ever try to open it otherwise your actions may cost you.

# Microsoft Patch Watch

Saturday, June 30, 2007 4:28 PM by Microsoft Patch Watch

Pingback from  Microsoft Patch Watch

# It's raining postcards

Saturday, June 30, 2007 6:18 PM by E-Bitz - SBS MVP the Official Blog of the SBS "Diva"

Getting a postcard via email? Don&#39;t click. I actually had a real postcard from a family member the

# &raquo; Security cricism on iphone - Internet computer &#038; network security

Pingback from  &raquo; Security cricism on iphone - Internet computer &#038;  network security

# re: Apple's new iPhone - Will it be secure?

Tuesday, July 03, 2007 4:04 AM by securiour

I think the above security issues are beyond the layman user. The only business environments will consider these issues.

# re: Storm Worm - It's Raining E-Cards (example from email inbox)

Tuesday, July 03, 2007 6:29 AM by Dan

What do I do if I have clicked on the link? I didn't notice that it did anything other than bring up an error page. I have updated and run Spybot and Adware without any results.

Thanks.

# re: Storm Worm - It's Raining E-Cards (example from email inbox)

Tuesday, July 03, 2007 10:21 AM by Harry Waldron

Hi Dan - I'd suggest going to the VirusIntel site referenced below and running some of the free scans, as this is a virus rather than spyware.  If you find a virus, search Google for Nuwar cleaning tools.

If you have the issue of not being able a clean a virus infection, the general advice in this link might help you right away.  Most often a virus cannot be removed message can be resolved by cleaning in SAFE MODE:

HOW TO CLEAN A DIFFICULT VIRUS (Safe mode is the key)

forums.mcafeehelp.com/viewtopic.php

GREAT SITE FOR FREE VIRUS REMOVAL TOOLS

(see left side and ONLINE SCANNERS or FREE REMOVAL TOOLS)

www.virusintel.com/tiki-index.php

# re: Monster.com - Phishing attack, avoid new Monster Job Seeker Tool

Tuesday, July 03, 2007 2:15 PM by Steve Zeigler

I just took the bait (1 July 2007).  It even had my name on it!  Guess I'm screwed.  Am running my virus scan, but damage may already be done.

# re: Privacy Issue - 2.3 million consumer financial records stolen

Tuesday, July 03, 2007 4:58 PM by lion

hi,

i find one related story at this site:

Security CENTRAL Forum

http://www.SCForum.info

# re: Privacy Issue - 2.3 million consumer financial records stolen

Tuesday, July 03, 2007 8:49 PM by Paul Schmehl

Hi, Harry.  Just wanted to say hello and thank you for your blog.  I've been getting your RSS feed for some time now, and I really enjoy reading it.  Thanks for all your hard work for the community.  You're an invaluable source of information and make a large contribution to security worldwide.

# re: Yahoo Messenger Exploits - Upgrade to Latest version

Wednesday, July 04, 2007 11:09 AM by manish

may name is manish hardasani and ithink yahoo sarvise is too good sarvice and best sarvise

# re: Yahoo Messenger Exploits - Upgrade to Latest version

Wednesday, July 04, 2007 11:09 AM by manish

I hope it's all that they it is because my messenger mean the world to me , anyway good work hope to see more soon chow.

# re: Storm Worm - It's Raining E-Cards (example from email inbox)

Wednesday, July 04, 2007 2:04 PM by Dan

Thanks! I am scanning now.

# re: BusinessWeek: Five timeless business scams

Sunday, July 08, 2007 5:04 PM by Jack Payne

Of these five legal scams, invention protection and promotion services are the most insidious--as for taking the "mark" for really big bucks, that is.  Many of these people are so committed, so devoted to their pet, often lifetime, projects, that they will spring for a good chuk of their lifetime savings to see them succeed.

Those perusing the menu of what these con artists have to offer would do well to take long pause in deciding whether they would rather have red meat, or fuzzy green meat.

--Jack Payne

  www.sixhrs.com

# re: Hackers gain shell-level access on iPhone

Monday, July 09, 2007 7:25 PM by Ian from www.thenewsroom.com

Yeah, is anyone suprised? thenewsroom.com/.../456135

# re: New Storm Worm - Warns of Virus, Spyware, Malware

Tuesday, July 10, 2007 9:35 AM by Kactuskaty

I did click on one of these but it said it was a forbidden site. Does this mean it stopped it or should I be concerned?

# Fast-Flux Bot Nets: The Future of Botnets | Project Afterlight. Articles, News, Updates, and Reviews on Technology and Life.

Pingback from  Fast-Flux Bot Nets: The Future of Botnets | Project Afterlight. Articles, News, Updates, and Reviews on Technology and Life.

# re: Excel Forums - Excellent Tips and Techniques Information

Tuesday, July 10, 2007 9:54 PM by Harold

I am working on a formula that has 7 nested IF statements to search a specified cell for different combinations of 3 words with different outputs for all 7 combinations. I had to define ranges and split the formula into 2 seperate formulas to make it work. How do I use the same defined ranges in all the cells in that column?

# re: Monster.com - Phishing attack, avoid new Monster Job Seeker Tool

Wednesday, July 11, 2007 1:43 PM by Amber

How do you get it to stop automatically rebooting? I've already disabled Auto Reboot, but it's still restarting me.

# University Update-Microsoft Windows-Microsoft Security Updates - July 2007

Pingback from  University Update-Microsoft Windows-Microsoft Security Updates - July 2007

# re: Sarbanes Oxley Blackbelt 404 - Excellent Blog Resource

Monday, July 16, 2007 4:36 AM by Mike

Many useful articles related to SOX and other regulatory compliance authority can also be found on www.compliancehome.com/.../SOX.  This website acts as a source of information for many of the regulatory compliance authority such as SOX, HIPAA, OSHA, FISMA, etc.

# University Update-Firefox-Flash Player plug-in - Critical Browser Security Update

Pingback from  University Update-Firefox-Flash Player plug-in - Critical Browser Security Update

# re: Storm Worm - samples of new variants captured (with URLs removed)

Monday, July 23, 2007 6:09 AM by cegjl@eds.com

Hi. Neighbor has sent you a postcard.

See your card as often as you wish during the next 15 days.

SEEING YOUR CARD

If your email software creates links to Web pages, click on your card's direct www address below while you are connected to the Internet:

67.176.97.119

Or copy and paste it into your browser's "Location" box (where Internet addresses go).

We hope you enjoy your awesome card.

Wishing you the best,

Mail Delivery System,

dgreetings.Com

# Corporate Executives targeted in Focused Security Attacks | Stop Spyware Ads

Pingback from  Corporate Executives targeted in Focused Security Attacks | Stop Spyware Ads

# Revue de presse en vrac

Tuesday, July 31, 2007 2:17 PM by Jean-Marc, XP Geek !

Au revoir DirectX 8, vive 10.1 (oui, mais juste pour Vista... SP1 !) Test : Archos 605 WiFi (beau joujou

# re: Opera 9.22 - Security and Vista improvements release

Tuesday, July 31, 2007 5:27 PM by Phil Odendron

Try and keep up.

Opera 9.22 was released 19.07.2007.

www.opera.com/.../windows

But thanks anyway.

# re: Passwords - Are they the weakest link?

Wednesday, August 01, 2007 9:21 AM by Robert

All login systems should have a time-out or lock-out after X number of attempted password to foil dictionary attacks.

# re: Passwords - Are they the weakest link?

Wednesday, August 01, 2007 11:34 AM by PeterRitchie

Great recommendations.  I still run into organizations (e.g. websites) with password restrictions like "must be between 5-8 alpha-numeric characters" even though they use 1024-bit SSL.  Policies like these drastically reduces the security of the site.  Depending on criteria, a 5-8 alphanumeric password is equivalent of 13- to 23-bits of encryption, a far cry from 1024-bit.

# re: Stock Spammers - Now using ZIP files

Thursday, August 02, 2007 10:19 AM by ThinkinOutLoud

Maybe we need to have some central agency issue special encrypted certificates in order for anyone to email anything, If your email doesn't have a cert, it doesn't get mailed.... or received by a mail server. (All isp's would have to jump on the bandwagon).  Then if you are caught spamming, they revoke your cert, and you're dead in the water.

# University Update-Windows Vista-Microsoft Security Updates - August 2007

Pingback from  University Update-Windows Vista-Microsoft Security Updates - August 2007

# re: New Storm Worm - Features dangerous animated e-card links

Thursday, August 16, 2007 9:43 AM by Ron

Thank you for this information. My worst suspicions have been confirmed re the numerous e-card for you emails I have been receiving lately, none of which I have opened as they appeared suspicious, but I am now deleting all of them without opening as they come from "sister"  "family member"  etc and are sent at very unlikely hours from email addresses unknown to me.  You have been a big help.

# re: Storm Worm - Invitations to become club members

Tuesday, August 21, 2007 8:39 PM by buck

i got one of these emails.  why is the numeric web address so dangerous

# re: Storm Worm - Invitations to become club members

Wednesday, August 22, 2007 8:21 AM by Harry Waldron

Hi Buck - Excellent Question ... Specifically for the Storm Worm attacks, the URL contains malware that could automatically download and install on your PC.  Sometimes the website is taken off line by security firms.

Numeric URLs should be considered untrusted in email or websites unless you are familiar with the site based on past experience (e.g., sometimes websites will switch from a DNS to numerical representation).

# re: Article: Best practices for online shopping

Wednesday, August 22, 2007 12:58 PM by Chris Quirke

I'd add two extras:

1)  Do not shop from someone else's computer, including public systems

2)  Do not shop via public WiFi hotspots or over weakly-encrypted WiFi

I see (1) is there in the small print, but IMO it's big enough to warrant its own digit.

On (2), Google( "Black Hat" Hamster )

On 'I keep records in folders labeled by vendor in a folder called “My Received Files.', is that the same "data" location that accumulates ?unsolicited Instant Messenger attachments?  I'd want to keep such hi-risk material outside of the data set and backups thereof, whereas I presume you'd want to retain and backup details of your ecommerce activities.

# re: Storm Worm - Invitations to become club members

Thursday, August 23, 2007 4:51 AM by boris

i got a mail like that (net gambler) and answered that I'm not aware of subscribing to such a thing.

am I in danger just by answering this mail. (the link was not working)

Kind regards

BORIX

# re: Latest Storm Worm - eCards now uses HTML and fake URLs

Friday, August 24, 2007 12:30 PM by Jeff

The wife bit on this one.

What this did was stop the PC from booting and dusted the restore. To get rid of it I started the PC in safemode, ran ad-aware, which got rid of it a bit, not all. I was able then to normally start the PC. I found another spyware app, cannot remember the name. I ran that and it did eliminate this worm.

Jeff

# re: New Storm Worm variant - AV Protection continuing to improve

Sunday, August 26, 2007 1:24 PM by Kerry Lingo MSD

I was infected with Trojan: Cutwail .T on 7-27-2007, date of first report and CA failed to locate until an update on 7-30-07.  It was discovered by the I have CA Secuirty Suite aka whatever they call it updated for XP Prfessional.  

CA Web site had removal instructions and I found NOTHING in regitry entries nor the files allegedly left.  I assume CA cleaned the thing up on a complete scan/cure.

Logs show I acquired this from the website WebMd.com, which reuires a user login.

Thx for this web site.

# re: Latest Storm Worm - eCards now uses HTML and fake URLs

Sunday, August 26, 2007 1:37 PM by Kerry

yep, saw this one and KNEW this had to be worse than it appeared.  My inate senses seem to be treu.  I logged into wife's email and sho 'enof, there it was in some form again.  

NEVER, EVER click on an unsolicited email unless you know the sender, and that is still dangerous!  I have had family members infect me with a latest virus that CA didn't pickup on yet.

Get a GOOD AV prgm, learn to set it up, use it, update even hourly! (Or before opening emails and never ever go to a website a friend includes within a joke.  Remember - no one is running a site for free.  If not infected cookies and .com files want to track everything you do.

# re: Latest Storm Worm - uses fake You-Tube links

Sunday, August 26, 2007 2:26 PM by Kerry Lingo

Rcv'd toda from something like jacobonsjsky@wave.....,com

Email title: Don't send me that stiff Dude.

Text:

I know it is you sending me that email.  Check this out:

(URL to youtube)

Never heard of him and not dumb enough to go to site!

careful please and lets work to end this crap

# re: Email Hoax - Planet Mars at closest distance to earth

Monday, August 27, 2007 12:45 AM by Suzette Stoffberg

Boo! I was really looking forward to this!

# re: Email Hoax - Planet Mars at closest distance to earth

Monday, August 27, 2007 1:06 AM by Mark Mobley

Thank You!

I just got bit by the thing.  It's now 1:01 am in Texas.  I looked out there, (the wheather guys said it would be clear, but it's cloudy as hell) and there's nothing out of the ordinary.....Mark  

P S , I should have known, since I was the only person who even had heard.  Still, I didn't want to miss "the moon turned to blood".  

# re: Latest Storm Worm - uses fake You-Tube links

Monday, August 27, 2007 8:11 PM by BiggSexxy

Got two over the weekend. Both had lol in the subject along with things like "Dude, you're gonna get caught" and "How did you get that on film?"

# re: Latest Storm Worm - uses fake You-Tube links

Saturday, September 08, 2007 8:27 AM by emma

just opened my emails on yahoo after been on a weeks holiday abroad to find 40 messages wanting me to luk at videos on youtube people wud have 2 be stupid to open them

# re: Excel Forums - Excellent Tips and Techniques Information

Saturday, September 08, 2007 3:38 PM by majid memon bhan

hi

i cant make out ur tip

# re: SPAM - 3-D images featured in new wave of attacks

Sunday, September 09, 2007 10:54 AM by RABI.D hAIGHTER

Seems someone somewhere hasn't a clue what 3D images  are..

or is F-Secure's just lacking command of the FI.English language?

# re: New Skype P2P worm spreads through VOIP chat facility

Friday, September 14, 2007 6:33 AM by Call Center Management

<b><a href="www.packet8.net/.../call_center_solution.aspx"title="Call Center Management">Call Center Management</a></b>

Packet8 offers the first fully integrated iPBX call center management solution.

# re: SANS - Free Guide to Network Security

Saturday, September 15, 2007 5:23 AM by nikhil

i need this information for the purpose of presentation in the college on this topic...

# re: Sarbanes Oxley Blackbelt 404 - Excellent Blog Resource

Monday, September 17, 2007 4:56 AM by John

Contingency plan templates created by www.training-hipaa.net can jump start HIPAA, Sarbanes Oxley (SOX), FISMA, ISO 17799 and many other regulations/standards contingency plan project which includes risk assessment, business impact analysis (BIA), business continuity plan (BCP), disaster recovery program (DRP), emergency mode operation plan (EMOP), data backup plan, testing and revision procedures and many other projects.  These templates can also be used by IT departments of different companies, security consulting companies, manufacturing company, servicing companies, financial institutions, educational organizations, law firms, pharmaceuticals & biotechnology companies, telecommunication companies and others.  Any organization large or small can be use these templates

www.training-hipaa.net/.../enterprise_contingency_plan_template_suite.htm

# re: MS06-071: Temp Folders may be left over after XML Core Services update

Thursday, September 20, 2007 2:08 PM by Gil Weldon

This file appeared in my laptop in a new system folder (987cc....) on 13 Dec 2006. It was probably after a Windows update.  I ignored it until now.  I have accidently dragged an important file into the system folder and can't get it out.  Message is:  "access denied." I tried to delete the msxml4-KB927978-enu.log file but also get:  "access denied."  Is there any way to retrieve my important folder from this strange system folder?

# re: MS06-071: Temp Folders may be left over after XML Core Services update

Thursday, September 20, 2007 2:42 PM by Harry Waldron

Hi Gil - You might try booting to SAFE MODE and making sure System Files are visible to Windows Explorer (by setting options).  You also need local ADMIN access to your laptop in order to access any system folder.

If this is a company PC, I'd recommend letting Tech Support help you, as they would have ADMIN rights to accomplish this.  Good luck and I hope you are successful in the recovery process.

# re: MS06-071: Temp Folders may be left over after XML Core Services update

Thursday, September 20, 2007 2:45 PM by Harry Waldron

Also, if this is your own PC -- I'd recommend joining Bleeping Computers and posting in the XP Home and Professional forum (2nd one under Operating Systems)

www.bleepingcomputer.com/.../index.php

# re: MS06-071: Temp Folders may be left over after XML Core Services update

Thursday, September 20, 2007 11:50 PM by Gil Weldon

Thank you very very much.  It worked perfectly.  I got back my important folder and I deleted the strange folder and it's log file.  I had read elsewhere that the folder could be deleted without risk.  I'll look into Bleeping Computers.  Many thanks.

# re: Windows Update - Solution if it stops working after XP repair mode

Tuesday, October 02, 2007 3:09 PM by Santos

Works fine.. THANKS

# re: IRS Phishing Scam - $109.32 Refund offered

Wednesday, October 03, 2007 7:09 AM by Mike

I never recieved 1 "scam/junk email" until I joined "MySpace", In the first week

I recieved 7.  Must be a great source of revenue for them selling our email addresses.

# re: Windows Update - Solution if it stops working after XP repair mode

Thursday, October 04, 2007 1:59 PM by Pablo Maiorino

A lifesaver ! No other solutions worked. Tried deleting softwaredistribution and catroot2 folders in %windir% and %windir%\system32  as per microsoft instructions from a while back when I had this issue.

After using repair was the key. It is strange that no errors are returned. It just fails and  gives no further info.  

Thanks a bunch

Pablo Maiorino

# re: PCI Data Security Standards - The 12 Key Requirements

Friday, October 05, 2007 6:19 PM by Alun Jones

My favourite is requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters.

The immediate nit-picky response is "what if the vendor-supplied defaults for other security parameters are more secure than the non-defaults?"

I don't think they mean that you can't use the defaults if they are secure, just that you shouldn't blindly leave the defaults in place.

# re: Windows Update - Solution if it stops working after XP repair mode

Saturday, October 06, 2007 9:21 AM by Bill

This solution worked for me after seeing the windows update log files spammed with:

Setup encountered an error:  The  update.ver file is not correct.

Setup encountered an error:  The  update.ver file is not correct.

Setup encountered an error:  The  update.ver file is not correct.

# re: Kittykat - New RAR virus threat

Tuesday, October 16, 2007 3:27 PM by MHT

I think i got this stuff on my pc, how am i gonna get rid of it!!

And do you think that the virus could have infekted every single rar fil on my system?!

# re: Kittykat - New RAR virus threat

Tuesday, October 16, 2007 3:45 PM by Harry Waldron

Hi - While this specific virus is over a year old, I'd recommend using the link below (VirusIntel site) and some of the free online or command-line scanners.  Be sure to write down the specific name(s) of any viruses found, so you can match up the right set of cleaning instructions.

GREAT SITE FOR FREE VIRUS REMOVAL TOOLS

(see links on left top side -- "Free Protection and Removal Tools")

www.virusintel.com/tiki-index.php

These older instructions in the McAfee forums may also help.  Most often a complex virus can be cleaned using SAFE MODE:

HOW TO CLEAN A DIFFICULT VIRUS (Safe mode is the key)

forums.mcafeehelp.com/viewtopic.php

# re: Real Player - Zero Day Exploit circulating

Saturday, October 20, 2007 1:20 AM by Thomas Scheidegger

# wikipedia &raquo; Storm Worm - Comprehensive Analysis by Cyber-TA

Pingback from  wikipedia &raquo; Storm Worm - Comprehensive Analysis by Cyber-TA

# people &raquo; iPhone unpatched vulnerability and Exploit

Sunday, October 21, 2007 10:06 AM by people » iPhone unpatched vulnerability and Exploit

Pingback from  people &raquo; iPhone unpatched vulnerability and Exploit

# home &raquo; Nanowire Storage - 100000 year retention with Terabyte storage &#8230;

Pingback from  home &raquo; Nanowire Storage - 100000 year retention with Terabyte storage &#8230;

# Ghillie Suits &raquo; Storm Worm - Now infects PC with different file names

Pingback from  Ghillie Suits &raquo; Storm Worm - Now infects PC with different file names

# Storm Worm &#45; Now infects PC with different file names

Monday, October 22, 2007 8:15 AM by Windows Vista News

New post at msmvps.com

# Storm Worm - Now infects PC with different file names | Echoes of Microsoft

Pingback from  Storm Worm - Now infects PC with different file names | Echoes of Microsoft

# simplyconnections &raquo; Blog Archive &raquo; Storm Worm - manipulates invite your friends to YouTube links

Pingback from  simplyconnections  &raquo; Blog Archive   &raquo; Storm Worm - manipulates invite your friends to YouTube links

# re: Adobe 8 Reader - Now available for free download

Monday, October 22, 2007 6:57 PM by allan

I have installed abode 8 and i am having trouble with my abodeupdater which is using all my cpu and my computer stalls

# ebay &raquo; eBay - Botnet attempts to compromise user account security

Pingback from  ebay &raquo; eBay - Botnet attempts to compromise user account security

# greeting card &raquo; More new Storm worm variants - Electronic greeting cards may be unsafe

Pingback from  greeting card &raquo; More new Storm worm variants - Electronic greeting cards may be unsafe

# online &raquo; Cyber-Security Month - CIO Magazine Articles

Thursday, October 25, 2007 12:24 AM by online » Cyber-Security Month - CIO Magazine Articles

Pingback from  online &raquo; Cyber-Security Month - CIO Magazine Articles

# tube &raquo; Latest Storm Worm - uses fake You-Tube links

Thursday, October 25, 2007 4:13 PM by tube » Latest Storm Worm - uses fake You-Tube links

Pingback from  tube &raquo; Latest Storm Worm - uses fake You-Tube links

# tube &raquo; Latest Storm Worm - Features music video offers

Thursday, October 25, 2007 4:14 PM by tube » Latest Storm Worm - Features music video offers

Pingback from  tube &raquo; Latest Storm Worm - Features music video offers

# internet &raquo; Blog Archive &raquo; Storm worm strikes with DDoS attacks if researchers attempt to &#8230;

Pingback from  internet  &raquo; Blog Archive   &raquo; Storm worm strikes with DDoS attacks if researchers attempt to &#8230;

# tool &raquo; Firecat 1.2 - Firefox based security testing and audit tool

Pingback from  tool &raquo; Firecat 1.2 - Firefox based security testing and audit tool

# tool &raquo; Article: Biometrics - Security Fad or Serious Tool?

Pingback from  tool &raquo; Article: Biometrics - Security Fad or Serious Tool?

# new york &raquo; Storm worm strikes with DDoS attacks if researchers attempt to &#8230;

Pingback from  new york &raquo; Storm worm strikes with DDoS attacks if researchers attempt to &#8230;

# Ghillie Suits &raquo; Major Malicious PDF attack underway using Adobe exploit

Pingback from  Ghillie Suits &raquo; Major Malicious PDF attack underway using Adobe exploit

# credit report com &raquo; Major Malicious PDF attack underway using Adobe exploit

Pingback from  credit report com &raquo; Major Malicious PDF attack underway using Adobe exploit

# www.topcreditcardsadvice.info &raquo; Major Malicious PDF attack underway using Adobe exploit

Pingback from  www.topcreditcardsadvice.info &raquo; Major Malicious PDF attack underway using Adobe exploit

# html &raquo; Storm worm strikes with DDoS attacks if researchers attempt to &#8230;

Pingback from  html &raquo; Storm worm strikes with DDoS attacks if researchers attempt to &#8230;

# www.bestdebtarticles.info &raquo; Major Malicious PDF attack underway using Adobe exploit

Pingback from  www.bestdebtarticles.info &raquo; Major Malicious PDF attack underway using Adobe exploit

# www.bestfinancialadvisor.info &raquo; Major Malicious PDF attack underway using Adobe exploit

Pingback from  www.bestfinancialadvisor.info &raquo; Major Malicious PDF attack underway using Adobe exploit

# www.bestfinancialadvisor.info &raquo; Major Malicious PDF attack underway using Adobe exploit

Pingback from  www.bestfinancialadvisor.info &raquo; Major Malicious PDF attack underway using Adobe exploit

# html &raquo; Major Malicious PDF attack underway using Adobe exploit

Pingback from  html &raquo; Major Malicious PDF attack underway using Adobe exploit

# re: Major Malicious PDF attack underway using Adobe exploit

Sunday, October 28, 2007 12:01 AM by Howard

Internet security requires us to think and act beyond simple system scans and the elimination of threats and risks.  It seems to be a popular train of that to focus only on the removal of problems from ones computer.  I like to think of desktop security as being similar to ones personal health.

Preventative treatment like exercise and a proper diet can help you stay healthy and ward of disease.  The same goes for your computer.  You’ve got to practice or having something in pace to help you with <a href=forums.eeye.com/.../756.aspx>intrusion prevention</a>.  Sure there are medicines to help you get rid of a cold and the like as there are programs to help remove viruses from your computer.  My question is why would you not take preventative measures?  Those who get sick to often die or are never the same again after a big infection not unlike a hard drive.

# home &raquo; Stolen Laptop - Phones Home and is successfully recovered

Pingback from  home &raquo; Stolen Laptop - Phones Home and is successfully recovered

# home &raquo; McAfee Study - Security perceptions verses Reality

Sunday, October 28, 2007 10:56 AM by home » McAfee Study - Security perceptions verses Reality

Pingback from  home &raquo; McAfee Study - Security perceptions verses Reality

# Wedding

Sunday, October 28, 2007 10:41 PM by Wedding

Pingback from  Wedding

# internet explorer &raquo; Internet Explorer - Special URL strings may bypass security &#8230;

Pingback from  internet explorer &raquo; Internet Explorer - Special URL strings may bypass security &#8230;

# My Ghillie &raquo; Trend Micro reports 200% increase in Severe Malware Infections

Pingback from  My Ghillie &raquo; Trend Micro reports 200% increase in Severe Malware Infections

# Ghillie Suits &raquo; Trend Micro reports 200% increase in Severe Malware Infections

Pingback from  Ghillie Suits &raquo; Trend Micro reports 200% increase in Severe Malware Infections

# Trend Micro reports 200% increase in Severe Malware Infections

Monday, October 29, 2007 2:45 PM by Windows Vista News

New post at msmvps.com

# Sporting Goods

Monday, October 29, 2007 10:13 PM by Sporting Goods

Pingback from  Sporting Goods

# Sporting Goods

Tuesday, October 30, 2007 2:14 AM by Sporting Goods

Pingback from  Sporting Goods

# quote &raquo; Trend Micro reports 200% increase in Severe Malware Infections

Pingback from  quote &raquo; Trend Micro reports 200% increase in Severe Malware Infections

# re: Yahoo Messenger Exploits - Upgrade to Latest version

Tuesday, October 30, 2007 7:36 AM by Abdul rauf

download yahoo messanger

# My Ghillie &raquo; New Halloween e-card security threats

Tuesday, October 30, 2007 9:56 AM by My Ghillie » New Halloween e-card security threats

Pingback from  My Ghillie &raquo; New Halloween e-card security threats

# Halloween &raquo; New Halloween e-card security threats

Tuesday, October 30, 2007 10:29 AM by Halloween » New Halloween e-card security threats

Pingback from  Halloween &raquo; New Halloween e-card security threats

# New Halloween e-card security threats

Tuesday, October 30, 2007 10:54 AM by New Halloween e-card security threats

Pingback from  New Halloween e-card security threats

# greeting card &raquo; New Halloween e-card security threats

Tuesday, October 30, 2007 11:56 AM by greeting card » New Halloween e-card security threats

Pingback from  greeting card &raquo; New Halloween e-card security threats

# Halloween News Aggregator &raquo; New Halloween e-card security threats

Pingback from  Halloween News Aggregator &raquo; New Halloween e-card security threats

# 97paths &raquo; Blog Archiv &raquo; New Halloween e-card security threats

Pingback from  97paths  &raquo; Blog Archiv   &raquo; New Halloween e-card security threats

# Storm Worm &#45; New Halloween based attacks

Wednesday, October 31, 2007 10:45 AM by Windows Vista News

There is an interesting post over at msmvps.com

# Halloween News Aggregator &raquo; Storm Worm - New Halloween based attacks

Pingback from  Halloween News Aggregator &raquo; Storm Worm - New Halloween based attacks

# Halloween &raquo; Storm Worm - New Halloween based attacks

Wednesday, October 31, 2007 11:43 AM by Halloween » Storm Worm - New Halloween based attacks

Pingback from  Halloween &raquo; Storm Worm - New Halloween based attacks

# Storm Worm &#45; Excellent Powerpoint Presentation from UCSD

Wednesday, October 31, 2007 4:45 PM by Windows Vista News

New post at msmvps.com

# quote &raquo; New Halloween e-card security threats

Wednesday, October 31, 2007 9:49 PM by quote » New Halloween e-card security threats

Pingback from  quote &raquo; New Halloween e-card security threats

# quote &raquo; Storm Worm - New Halloween based attacks

Wednesday, October 31, 2007 9:49 PM by quote » Storm Worm - New Halloween based attacks

Pingback from  quote &raquo; Storm Worm - New Halloween based attacks

# anti virus &raquo; New Halloween e-card security threats

Wednesday, October 31, 2007 11:06 PM by anti virus » New Halloween e-card security threats

Pingback from  anti virus &raquo; New Halloween e-card security threats

# re: Win32.Agent.brk Trojan - Avoid Funny.ZIP attachment

Thursday, November 01, 2007 9:00 AM by avangi

new at this;probably doing it wrong.always get trojans when downloading players (like active x) if a site says i need a certain player can i safely load it another way?

# ISC &#45; Collection of 31 Best Practices for Cyber&#45;Security Awareness

Thursday, November 01, 2007 9:15 AM by Windows Vista News

Interesting point at msmvps.com

# My Ghillie &raquo; ISC - Collection of 31 Best Practices for Cyber-Security Awareness

Pingback from  My Ghillie &raquo; ISC - Collection of 31 Best Practices for Cyber-Security Awareness

# ISC - Collection of 31 Best Practices for Cyber-Security Awareness

Pingback from  ISC - Collection of 31 Best Practices for Cyber-Security Awareness

# My Ghillie &raquo; Mozilla Firefox 2.0.0.9 Release

Friday, November 02, 2007 8:12 AM by My Ghillie » Mozilla Firefox 2.0.0.9 Release

Pingback from  My Ghillie &raquo; Mozilla Firefox 2.0.0.9 Release

# Mozilla Firefox 2.0.0.9 Release

Friday, November 02, 2007 8:15 AM by Windows Vista News

New post at msmvps.com

# Mozilla Firefox 2.0.0.9 Release

Friday, November 02, 2007 8:56 AM by Mozilla Firefox 2.0.0.9 Release

Pingback from  Mozilla Firefox 2.0.0.9 Release

# Mozilla &#45; Security Vulnerabilities Master List for Products

Friday, November 02, 2007 9:15 AM by Windows Vista News

There is an interesting post over at msmvps.com

# fasterda &raquo; Mozilla Firefox 2.0.0.9 Release

Friday, November 02, 2007 9:22 AM by fasterda » Mozilla Firefox 2.0.0.9 Release

Pingback from  fasterda &raquo; Mozilla Firefox 2.0.0.9 Release

# Password Strength &#45; Length is more important than complexity

Friday, November 02, 2007 1:45 PM by Windows Vista News

Interesting point at msmvps.com

# re: Password Strength - Length is more important than complexity

Friday, November 02, 2007 1:45 PM by Robert

You mean ThisIsAReallyHardPasswordToHack1234 is harder to hack than some nimrod forcing me to remember x4%2F9  ?!!! :-)

# My Ghillie &raquo; Password Strength - Length is more important than complexity

Pingback from  My Ghillie &raquo; Password Strength - Length is more important than complexity

# Password Strength - Length is more important than complexity

Pingback from  Password Strength - Length is more important than complexity

# re: Windows Update - Solution if it stops working after XP repair mode

Sunday, November 04, 2007 5:08 AM by Tri

Wonderfull, thx for the help :)

# re: Storm Worm - Excellent Powerpoint Presentation from UCSD

Monday, November 05, 2007 12:07 AM by Mike Kline

Harry,

Nice post and that was a really good presentation.  Keep up the great work on the blog, your posts are always interesting.

Thanks

Mike

# re: Mespam Trojan - New Storm Worm version spreading as blog comments

Monday, November 05, 2007 11:16 PM by Zac

Do you think it is wise to have an open comment posting option at the completion of this article given the subject matter of the article?  Would requiring posters to register in any way help suppress the threat posed in this article?

# SPAM &#45; Using Google Advanced Search to hide malicious URLs

Tuesday, November 06, 2007 11:15 AM by Windows Vista News

Interesting point at msmvps.com

# Techy News &raquo; Blog Archive &raquo; SPAM - Using Google Advanced Search to hide malicious URLs

Pingback from  Techy News  &raquo; Blog Archive   &raquo; SPAM - Using Google Advanced Search to hide malicious URLs

# hgecom &raquo; SPAM - Using Google Advanced Search to hide malicious URLs

Pingback from  hgecom &raquo; SPAM - Using Google Advanced Search to hide malicious URLs

# quickda

Tuesday, November 06, 2007 8:04 PM by quickda

Pingback from  quickda

# MSDN Magazine &#45; It&#39;s all about Security this month

Wednesday, November 07, 2007 9:15 AM by Windows Vista News

Interesting point at msmvps.com

# MSDN Magazine - It&#39;s all about Security this month

Wednesday, November 07, 2007 10:02 AM by MSDN Magazine - It's all about Security this month

Pingback from  MSDN Magazine - It&#39;s all about Security this month

# Techy News &raquo; Blog Archive &raquo; MSDN Magazine - It&#39;s all about Security this month

Pingback from  Techy News  &raquo; Blog Archive   &raquo; MSDN Magazine - It&#39;s all about Security this month

# Microsoft Windows Live goes Live

Wednesday, November 07, 2007 12:45 PM by Windows Vista News

Did you see the post at msmvps.com

# Techy News &raquo; Blog Archive &raquo; Microsoft Windows Live goes Live

Wednesday, November 07, 2007 1:08 PM by Techy News » Blog Archive » Microsoft Windows Live goes Live

Pingback from  Techy News  &raquo; Blog Archive   &raquo; Microsoft Windows Live goes Live

# youtube &raquo; Storm Worm - manipulates invite your friends to YouTube links

Pingback from  youtube &raquo; Storm Worm - manipulates invite your friends to YouTube links

# 94files &raquo; Blog Archive &raquo; Microsoft Windows Live goes Live

Thursday, November 08, 2007 5:33 AM by 94files » Blog Archive » Microsoft Windows Live goes Live

Pingback from  94files  &raquo; Blog Archive   &raquo; Microsoft Windows Live goes Live

# Web Site Defacements using obuscated script attacks affect 52000 pages

Friday, November 09, 2007 8:15 AM by Windows Vista News

New post at msmvps.com

# Techy News &raquo; Blog Archive &raquo; Web Site Defacements using obuscated script attacks affect 52000 pages

Pingback from  Techy News  &raquo; Blog Archive   &raquo; Web Site Defacements using obuscated script attacks affect 52000 pages

# depotsq &raquo; Blog Archive &raquo; Web Site Defacements using obuscated script attacks affect 52000 pages

Pingback from  depotsq  &raquo; Blog Archive   &raquo; Web Site Defacements using obuscated script attacks affect 52000 pages

# Sarbanes&#45;Oxley turns five years old

Friday, November 09, 2007 3:45 PM by Windows Vista News

New post at msmvps.com

# Techy News &raquo; Blog Archive &raquo; Sarbanes-Oxley turns five years old

Pingback from  Techy News  &raquo; Blog Archive   &raquo; Sarbanes-Oxley turns five years old

# How To Shop Safely Online | Nellie2

Saturday, November 10, 2007 10:41 AM by How To Shop Safely Online | Nellie2

Pingback from  How To Shop Safely Online | Nellie2

# shopping &raquo; Blog Archive &raquo; Article: Best practices for online shopping

Pingback from  shopping  &raquo; Blog Archive   &raquo; Article: Best practices for online shopping

# accounting &raquo; Blog Archive &raquo; Sarbanes-Oxley turns five years old

Pingback from  accounting  &raquo; Blog Archive   &raquo; Sarbanes-Oxley turns five years old

# adobe &raquo; Major Malicious PDF attack underway using Adobe exploit

Pingback from  adobe &raquo; Major Malicious PDF attack underway using Adobe exploit

# angelina &raquo; Stoned.Angelina virus from 1994 found on new Medion Laptops

Pingback from  angelina &raquo; Stoned.Angelina virus from 1994 found on new Medion Laptops

# 2006 &raquo; Blog Archive &raquo; Castlecops PIRT - Prevented over $150 Million in Phishing attack &#8230;

Pingback from  2006  &raquo; Blog Archive   &raquo; Castlecops PIRT - Prevented over $150 Million in Phishing attack &#8230;

# blog &raquo; Castlecops PIRT - Prevented over $150 Million in Phishing attack &#8230;

Pingback from  blog &raquo; Castlecops PIRT - Prevented over $150 Million in Phishing attack &#8230;

# re: Article: Best practices for online shopping

Monday, November 12, 2007 9:01 PM by Corrine

I've had this article bookmarked to add to what seems to be turning in to an annual Holiday Online Shopping Safety reminder.

# re: Cyber Monday - Tips for shopping safely online

Monday, November 12, 2007 9:02 PM by Corrine

I dug this one up again to link to again also.  

# down &raquo; Castlecops PIRT - Prevented over $150 Million in Phishing attack &#8230;

Pingback from  down &raquo; Castlecops PIRT - Prevented over $150 Million in Phishing attack &#8230;

# couple &raquo; Castlecops PIRT - Prevented over $150 Million in Phishing attack &#8230;

Pingback from  couple &raquo; Castlecops PIRT - Prevented over $150 Million in Phishing attack &#8230;

# Microsoft Security Bulletins &#45; November 2007

Tuesday, November 13, 2007 4:15 PM by Windows Vista News

Interesting: msmvps.com

# Seagate &#45; A few Maxtor 3200 hard drives may contain a virus

Tuesday, November 13, 2007 4:15 PM by Windows Vista News

Interesting point at msmvps.com

# Microsoft Security Bulletins - November 2007

Tuesday, November 13, 2007 4:53 PM by Microsoft Security Bulletins - November 2007

Pingback from  Microsoft Security Bulletins - November 2007

# Seagate - A few Maxtor 3200 hard drives may contain a virus

Tuesday, November 13, 2007 4:53 PM by Seagate - A few Maxtor 3200 hard drives may contain a virus

Pingback from  Seagate - A few Maxtor 3200 hard drives may contain a virus

# Web 2.0 - Social Media - Internet News - Blogging &raquo; Microsoft Security Bulletins - November 2007

Pingback from  Web 2.0 - Social Media - Internet News - Blogging &raquo; Microsoft Security Bulletins - November 2007

# Best Practices &#45; Don&#39;t call phone numbers in spam email

Wednesday, November 14, 2007 9:15 AM by Windows Vista News

Interesting: msmvps.com

# Best Practices - Don&#39;t call phone numbers in spam email

Wednesday, November 14, 2007 9:45 AM by Best Practices - Don't call phone numbers in spam email

Pingback from  Best Practices - Don&#39;t call phone numbers in spam email

# re: Best Practices - Don't call phone numbers in spam email

Wednesday, November 14, 2007 9:52 AM by DF

My family's telephone protocol is 1) dont' answer if the Caller-ID says "Private", "Unavailable", or something similar, and 2) Don't use any e-mail message as the source of a telephone number.  Use a different source instead, like a bank statement or telephone book.

# re: Windows Server 2008 provides improved security

Wednesday, November 14, 2007 10:43 AM by Robert

In other news, Sun rises in East...  Shouldn't any new Version of an operating system be an improvement over the prior version?

# Windows Server 2008 provides improved security

Wednesday, November 14, 2007 10:45 AM by Windows Vista News

There is an interesting post over at msmvps.com

# re: Windows Server 2008 provides improved security

Wednesday, November 14, 2007 11:03 AM by Harry Waldron

Yes, I agree with Robert's comment that every OS should include improvements ... The key purpose of this post is share an outline of the specific forthcoming improvements :)

# Techy News &raquo; Windows Server 2008 provides improved security

Wednesday, November 14, 2007 11:08 AM by Techy News » Windows Server 2008 provides improved security

Pingback from  Techy News &raquo; Windows Server 2008 provides improved security

# re: Best Practices - Don't call phone numbers in spam email

Wednesday, November 14, 2007 11:13 AM by Harry Waldron

DF shares some excellent recommendations, as this is similar to the approach we use in our family :)

# Credit Cards: Low Interest Cash Reward Cards &raquo; Best Practices - Don&#39;t call phone numbers in spam email

Pingback from  Credit Cards: Low Interest Cash Reward Cards &raquo; Best Practices - Don&#39;t call phone numbers in spam email

# Credit Cards: Low Interest Cash Reward Cards &raquo; Best Practices - Don&#8217;t call phone numbers in spam email

Pingback from  Credit Cards: Low Interest Cash Reward Cards &raquo; Best Practices - Don&#8217;t call phone numbers in spam email

# www.topcreditcardsadvice.info &raquo; Best Practices - Don&#39;t call phone numbers in spam email

Pingback from  www.topcreditcardsadvice.info &raquo; Best Practices - Don&#39;t call phone numbers in spam email

# www.bestdebtarticles.info &raquo; Best Practices - Don&#39;t call phone numbers in spam email

Pingback from  www.bestdebtarticles.info &raquo; Best Practices - Don&#39;t call phone numbers in spam email

# Visual Studio 2008 &#45; To be released in November

Thursday, November 15, 2007 7:15 AM by Windows Vista News

New post at msmvps.com

# Techy News &raquo; Storm Worm - now uses Geocities based links

Thursday, November 15, 2007 10:39 AM by Techy News » Storm Worm - now uses Geocities based links

Pingback from  Techy News &raquo; Storm Worm - now uses Geocities based links

# re: McAfee releases new Virus Scan engine 5200

Friday, November 16, 2007 6:24 AM by tokiya dlaie

i need this exer.

# Sarbanes&#45;Oxley 404 &#45; Good resources describing IT financial controls

Friday, November 16, 2007 9:15 AM by Windows Vista News

Interesting: msmvps.com

# re: SPAM - Using Google Advanced Search to hide malicious URLs

Monday, November 19, 2007 7:01 PM by Stunned

Why is nobody asking Google to remove the search results that these URLs "get lucky" on?

Here's the URL to their reporting page:

www.google.com/.../removals

# card &raquo; Blog Archive &raquo; Castlecops PIRT - Prevented over $150 Million in Phishing attack &#8230;

Pingback from  card  &raquo; Blog Archive   &raquo; Castlecops PIRT - Prevented over $150 Million in Phishing attack &#8230;

# card &raquo; Blog Archive &raquo; New Halloween e-card security threats

Pingback from  card  &raquo; Blog Archive   &raquo; New Halloween e-card security threats

# AVERT Labs &#45; Major Security threats envisioned for 2008

Wednesday, November 21, 2007 2:15 PM by Windows Vista News

There is an interesting post over at msmvps.com

# Wireless Security &#45; 10 tips to secure your laptop

Monday, November 26, 2007 9:00 AM by Windows Vista News

Did you see the post at msmvps.com

# Apple Quick Time and iTunes Critical Vulnerabilities

Tuesday, November 27, 2007 9:00 AM by Windows Vista News

Interesting: msmvps.com

# mattst88 &raquo; Apple Quick Time and iTunes Critical Vulnerabilities

Pingback from  mattst88 &raquo; Apple Quick Time and iTunes Critical Vulnerabilities

# Stock spam - New MP3 version will try to talk you into it

Tuesday, November 27, 2007 10:17 AM by Stock spam - New MP3 version will try to talk you into it

Pingback from  Stock spam - New MP3 version will try to talk you into it

# re: MS06-071: Temp Folders may be left over after XML Core Services update

Wednesday, November 28, 2007 3:03 AM by sharlene_c

Thank you so much for this blog.  I also retrieved an important folder accidentally placed in the Windows update system folder.  Although I did have a backup copy I was really annoyed that I couldnt do anything with this one hence my search for an answer which led me here.  Thanks again - you're now in my favourites :)

# SQL Server 2008 &#45; Excellent overview of features shared by MVP ...

Wednesday, November 28, 2007 10:00 AM by Windows Vista News

Interesting point at msmvps.com

# Lotus Notes &#45; vulnerable to attack thru &quot;123&quot; extension

Wednesday, November 28, 2007 11:00 AM by Windows Vista News

Interesting: msmvps.com

# Thousands of Malicious Web Page redirects - Be careful with Internet searches

Wednesday, November 28, 2007 11:32 AM by Harry Waldron - My IT Forums Blog

Some updates are noted below on this very serious threat related to malicious web sites that may be offered

# Thousands of Malicious Web Page redirects &#45; Be careful with ...

Wednesday, November 28, 2007 12:00 PM by Windows Vista News

Interesting point at msmvps.com

# Many Credit Card Options &raquo; Blog Archive &raquo; Good E-commerce safety tips from Webroot

Pingback from  Many Credit Card Options  &raquo; Blog Archive   &raquo; Good E-commerce safety tips from Webroot

# Credit Cards: Low Interest Cash Reward Cards &raquo; Good E-commerce safety tips from Webroot

Pingback from  Credit Cards: Low Interest Cash Reward Cards &raquo; Good E-commerce safety tips from Webroot

# re: Good E-commerce safety tips from Webroot

Monday, December 03, 2007 4:12 AM by Ann

Thanks for this information.

# Windows News &raquo; Blog Archive &raquo; Windows XP Service Pack 3 Overview

Pingback from  Windows News  &raquo; Blog Archive   &raquo; Windows XP Service Pack 3 Overview

# Windows News &raquo; Blog Archive &raquo; Storm Worm - Will a New Holiday version surface?

Pingback from  Windows News  &raquo; Blog Archive   &raquo; Storm Worm - Will a New Holiday version surface?

# Microsoft Security Bulletins - November 2007

Wednesday, December 05, 2007 3:15 PM by Microsoft Security Bulletins - November 2007

Pingback from  Microsoft Security Bulletins - November 2007

# Seagate - A few Maxtor 3200 hard drives may contain a virus

Wednesday, December 05, 2007 4:07 PM by Seagate - A few Maxtor 3200 hard drives may contain a virus

Pingback from  Seagate - A few Maxtor 3200 hard drives may contain a virus

# re: Windows Update - Solution if it stops working after XP repair mode

Thursday, December 06, 2007 11:46 AM by roger Louis Gundberg

Worked like a champ! You're a genius!

# Windows News &raquo; Blog Archive &raquo; IE 7 and Firefox - Some Interesting Security Comparisons

Pingback from  Windows News  &raquo; Blog Archive   &raquo; IE 7 and Firefox - Some Interesting Security Comparisons

# happy new year

Friday, December 07, 2007 12:54 AM by happy new year

Pingback from  happy new year

# Windows News &raquo; Blog Archive &raquo; Steve Riley - Excellent Powerpoint presentation on Social &#8230;

Pingback from  Windows News  &raquo; Blog Archive   &raquo; Steve Riley - Excellent Powerpoint presentation on Social &#8230;

# Kim Kommando &#45; offers 7 question quiz for e&#45;commerce shopping

Monday, December 10, 2007 11:01 AM by Windows Vista News

Did you see the post at msmvps.com

# Luc Ippersiel.com ??? My Geek Life &raquo; Blog Archive &raquo; How-To&#8230; Protect Against PIEs

Pingback from  Luc Ippersiel.com ??? My Geek Life  &raquo; Blog Archive   &raquo; How-To&#8230; Protect Against PIEs

# re: Kim Kommando - offers 7 question quiz for e-commerce shopping

Tuesday, December 11, 2007 5:33 AM by sandi

I dispute answer 5 where she says that email password transmissions are encrypted.  They are *not* always encrypted, in fact they are sent in plain text and can be captured as plain text using a network sniffer.

Show me somebody using a wireless hotspot and Outlook Express or Outlook with pop3/smtp, give me a network sniffer and I'll give you their email password.

# re: Windows Update - Solution if it stops working after XP repair mode

Tuesday, December 11, 2007 9:08 PM by Jim

Thanks a lot. Worked like a charm

# re: Kim Kommando - offers 7 question quiz for e-commerce shopping

Wednesday, December 12, 2007 3:13 AM by jerry.j altman

help my screen is incontent €3.500.00 behoordt te geven maar liniet is €5kan toch niet met deze middelen kan ik mijn zoorgdrager niet betalen maar julikie mischien mijn laptop is ge hackt ff denk door DANIÉL Graves;help please deze mensen ook een robert heb er aan gezeten en henk midelburg no problem raad van cliéten mening teld waar ik hoof eeind verantwoordelijke ben

      thanks     adres:jerry .Julius. Altman= monstreseweg 81R huis werk adres

monstersestraat 142c

# re: Windows Update - Solution if it stops working after XP repair mode

Thursday, December 13, 2007 6:45 AM by Andrew

Finally... I've found the solution, and it works. I've been stuffing about for hours with google and searching in forums trying to find a solution, and this is it.

I am so keeping a copy of that batch file on a USB stick for next time I upgrade my motherboard, processor and ram and have to do a revert to the CD rebuild.

Great work Harry, I was really pulling my hair out over this one.

# Microsoft Access &#45; Malicious Exploit in&#45;the&#45;wild

Thursday, December 13, 2007 10:00 AM by Windows Vista News

Interesting: msmvps.com

# Credit Cards: Low Interest Cash Reward Cards &raquo; Malicious DNS servers could enhance Phishing attacks

Pingback from  Credit Cards: Low Interest Cash Reward Cards &raquo; Malicious DNS servers could enhance Phishing attacks

# Movies and Film Blog &raquo; Microsoft Access - Malicious Exploit in-the-wild

Pingback from  Movies and Film Blog &raquo; Microsoft Access - Malicious Exploit in-the-wild

# Microsoft Access - Malicious Exploit in-the-wild

Thursday, December 13, 2007 1:13 PM by Tonys Microsoft Access Blog

&quot;Users should avoid unexpected MDB files found in email or offered as downloads for websites. They

# karlisle &raquo; Malicious DNS servers could enhance Phishing attacks

Pingback from  karlisle &raquo; Malicious DNS servers could enhance Phishing attacks

# karlisle &raquo; Malicious DNS servers could enhance Phishing attacks

Pingback from  karlisle &raquo; Malicious DNS servers could enhance Phishing attacks

# khoike &raquo; Microsoft Security Updates for December 2007 - PATCH NOW

Pingback from  khoike &raquo; Microsoft Security Updates for December 2007 - PATCH NOW

# Microsoft Security Updates for December 2007 &#45; PATCH NOW

Friday, December 14, 2007 9:00 AM by Windows Vista News

Did you see the post at msmvps.com

# Christmas E Cards

Monday, December 17, 2007 8:58 AM by Christmas E Cards

Pingback from  Christmas E Cards

# IT Software Policies &#45; Student Gets Detention for Using FireFox

Monday, December 17, 2007 10:00 AM by Windows Vista News

Interesting point at msmvps.com

# re: Steve Riley - Excellent Powerpoint presentation on Social Engineering Risks

Tuesday, December 18, 2007 8:50 AM by S.Pollak

Also you can find plenty PowerPoint templates and backgrounds on the following site www.poweredtemplates.com/free-ppt-powerpoint-templates.html

# re: IT Software Policies - Student Gets Detention for Using FireFox

Tuesday, December 18, 2007 3:36 PM by Harry Waldron

While this ended up being a hoax, the original post still reflects the need for folks to follow IT security policies, even if they don't always agree:

www.bigspring.k12.pa.us/news.php

# Credit Cards: Low Interest Cash Reward Cards &raquo; Spammed Trojan email - Avoid Happy New Year Exe attachment

Pingback from  Credit Cards: Low Interest Cash Reward Cards &raquo; Spammed Trojan email - Avoid Happy New Year Exe attachment

# Mars - Closest encounter to earth until 2016 (not an email hoax this time)

Tuesday, December 18, 2007 5:50 PM by Harry Waldron - Microsoft MVP Blog

Occasionally, I&#39;ll receive an email hoax as noted below. However, this event is REAL, so please take

# Mars - Closest encounter to earth until 2016 (not an email hoax this time)

Tuesday, December 18, 2007 5:56 PM by Harry Waldron - My IT Forums Blog

Occasionally, I&#39;ll receive an email hoax as noted below. However, this event is REAL, so please take

# re: Dangerous website -- Please don't mispell Google

Wednesday, December 19, 2007 7:18 AM by Xafke

Site is taked down.. Could not connect to server anymore!

# re: Google's Orkut Social Network - New worm infects 400,000 users

Thursday, December 20, 2007 5:05 PM by Jack

Okut is a scam. I think the real new big social networking will be MateCube. I dont think it'll grow as big as facebook, but it will surely become a top player in the industry. http://www.matecube.com

# Wireless News &raquo; Blog Archive &raquo; Wireless Security - 10 tips to secure your laptop

Pingback from  Wireless News  &raquo; Blog Archive   &raquo; Wireless Security - 10 tips to secure your laptop

# Windows Update Fail &raquo; Windows Update - Microsoft&#39;s guidance if it stops working after XP &#8230;

Pingback from  Windows Update Fail &raquo; Windows Update - Microsoft&#39;s guidance if it stops working after XP &#8230;

# Microsoft Windows Update &raquo; Microsoft Security Updates for December 2007 - PATCH NOW

Pingback from  Microsoft Windows Update &raquo; Microsoft Security Updates for December 2007 - PATCH NOW

# Download Windows Update &raquo; Apple Safari for Windows XP and Vista - v3.0.4b Security Release

Pingback from  Download Windows Update &raquo; Apple Safari for Windows XP and Vista - v3.0.4b Security Release

# Download Windows Update &raquo; Apple Safari for Windows XP and Vista - v3.0.4b Security Release

Pingback from  Download Windows Update &raquo; Apple Safari for Windows XP and Vista - v3.0.4b Security Release

# Windows Internet Explorer &raquo; IE 7 and Firefox - Some Interesting Security Comparisons

Pingback from  Windows Internet Explorer &raquo; IE 7 and Firefox - Some Interesting Security Comparisons

# Windows Internet Explorer &raquo; Microsoft Security Updates for December 2007 - PATCH NOW

Pingback from  Windows Internet Explorer &raquo; Microsoft Security Updates for December 2007 - PATCH NOW

# Windows Internet Explorer &raquo; Microsoft Security Updates for December 2007 - PATCH NOW

Pingback from  Windows Internet Explorer &raquo; Microsoft Security Updates for December 2007 - PATCH NOW

# Microsoft Internet Explorer &raquo; Blog Archive &raquo; Microsoft Security Updates for December 2007 - PATCH NOW

Pingback from  Microsoft Internet Explorer  &raquo; Blog Archive   &raquo; Microsoft Security Updates for December 2007 - PATCH NOW

# Microsoft Internet Explorer &raquo; Blog Archive &raquo; IE 7 and Firefox - Some Interesting Security Comparisons

Pingback from  Microsoft Internet Explorer  &raquo; Blog Archive   &raquo; IE 7 and Firefox - Some Interesting Security Comparisons

# Internet Explorer Problem &raquo; Blog Archive &raquo; IE 7 and Firefox - Some Interesting Security Comparisons

Pingback from  Internet Explorer Problem  &raquo; Blog Archive   &raquo; IE 7 and Firefox - Some Interesting Security Comparisons

# Windows Update Software &raquo; Apple Safari for Windows XP and Vista - v3.0.4b Security Release

Pingback from  Windows Update Software &raquo; Apple Safari for Windows XP and Vista - v3.0.4b Security Release

# Windows Update &raquo; Apple Safari for Windows XP and Vista - v3.0.4b Security Release

Pingback from  Windows Update &raquo; Apple Safari for Windows XP and Vista - v3.0.4b Security Release

# CDTs Warning List of Deceptive Music Sites to Avoid

Thursday, December 27, 2007 1:00 PM by Windows Vista News

Did you see this post at msmvps.com

# Windows Vista &raquo; Article: Defending Windows Vista

Friday, December 28, 2007 9:07 AM by Windows Vista » Article: Defending Windows Vista

Pingback from  Windows Vista &raquo; Article: Defending Windows Vista

# Article: Defending Windows Vista

Friday, December 28, 2007 9:30 AM by Windows Vista News

There is an interesting post over at msmvps.com

# re: Storm Worm - Christmas and New Years e-card dangers

Saturday, December 29, 2007 1:04 PM by julea

not to be confused with real good ecards...smilebox is a great program.

# New and Improved Storm Worm botnet coming in 2008

Monday, December 31, 2007 10:43 AM by Harry Waldron - My IT Forums Blog

This new 2008 version of the Storm Worm has improvements in the technical designs as well New and Improved

# New and Improved Storm Worm botnet coming in 2008

Monday, December 31, 2007 10:43 AM by Harry Waldron - Microsoft MVP Blog

This new 2008 version of the Storm Worm has improvements in the technical designs as well New and Improved

# Perl 5.10.0 &#45; First new release in Five Years

Monday, December 31, 2007 11:00 AM by Windows Vista News

There is an interesting post over at msmvps.com

# New and Improved Storm Worm botnet coming in 2008

Monday, December 31, 2007 12:00 PM by Windows Vista News

Did you see this post at msmvps.com

# Perl Coding School &raquo; Blog Archive &raquo; perl news [2007-12-31 18:20:40]

Pingback from  Perl Coding School  &raquo; Blog Archive   &raquo; perl news [2007-12-31 18:20:40]

# Microsoft Office 2007 &#45; Security Guide Available

Monday, December 31, 2007 2:00 PM by Windows Vista News

Did you see this post at msmvps.com

# Windows Server 2008 &#45; Configuring Network Access Protection

Monday, December 31, 2007 2:00 PM by Windows Vista News

Interesting: msmvps.com

# SecTor &#45; Security Conference presentations available

Monday, December 31, 2007 2:00 PM by Windows Vista News

Did you see the post at msmvps.com

# Best Practices &#45; Internet Safety for 2008

Tuesday, January 01, 2008 9:00 AM by Windows Vista News

There is an interesting post over at msmvps.com

# Bigger, Better Storm Worm Botnet for 2008 | Nellie2

Tuesday, January 01, 2008 12:42 PM by Bigger, Better Storm Worm Botnet for 2008 | Nellie2

Pingback from  Bigger, Better Storm Worm Botnet for 2008 | Nellie2

# Storm Worm &#45; New Years e&#45;card example to avoid

Tuesday, January 01, 2008 2:00 PM by Windows Vista News

Did you see the post at msmvps.com

# re: Best Practices - Internet Safety for 2008

Tuesday, January 01, 2008 9:30 PM by IUsedToLikeWindows

errr...or simply ditch windows for Linux.

# re: Best Practices - Internet Safety for 2008

Wednesday, January 02, 2008 11:02 AM by anonymous email

Please note that Anonymizer has become more and more incompatible with WEB 2.0 functions. Especially for file uploads via https.

# Random roundup post Christmas

Wednesday, January 02, 2008 11:07 AM by OfficeRocker!

Hope you had a great Christmas and happy New Year.&#160; I certainly did not work during the break so

# Best Practices for 2008 - Linux and other Operating Systems

Wednesday, January 02, 2008 12:29 PM by Harry Waldron - Microsoft MVP Blog

[l] On January 1st, a post entitled Best Practices - Internet Safety for 2008 shared concepts related

# Best Practices for 2008 - Linux and other Operating Systems

Wednesday, January 02, 2008 12:30 PM by Harry Waldron - My IT Forums Blog

[l] On January 1st, a post entitled Best Practices - Internet Safety for 2008 shared concepts related

# re: Windows Update - Solution if it stops working after XP repair mode

Wednesday, January 02, 2008 3:34 PM by John Morgan

Thank you!  Thank You!  Microsoft's own repair does not give you the real story (whats new).  Tried the Microsoft's manual registration procedure with no success.  The updater kept trying to install the already downloaded updates.  Did not realize that:  "The next time you visit the Windows Update site, you should not have any problem installing the latest patches."  Worked like a charm!

# re: New and Improved Storm Worm botnet coming in 2008

Wednesday, January 02, 2008 5:46 PM by turkeydance

ok. here's my bet. the Internet dies in 2008.

or dies "enough" to scare away 80% of users.

there's site allowing one to gamble on the death

of famous people. i bet on the Internet.

# re: McAfee DAT 5197 - Creating JS/Exploit False Positives

Thursday, January 03, 2008 8:27 AM by Bob Davis

This problem was worse that what is being reported.

The blocked script caused some web sites to not work.

For instance the navigation bar at www.fln.org was blank.

# McAfee DAT 5197 &#45; Creating JS/Exploit False Positives

Thursday, January 03, 2008 10:00 AM by Windows Vista News

Interesting: msmvps.com

# Internet blog &raquo; CDTs Warning List of Deceptive Music Sites to Avoid

Pingback from  Internet blog &raquo; CDTs Warning List of Deceptive Music Sites to Avoid

# Internet blog &raquo; CDTs Warning List of Deceptive Music Sites to Avoid

Pingback from  Internet blog &raquo; CDTs Warning List of Deceptive Music Sites to Avoid

# Internet blog &raquo; Best Practices - Internet Safety for 2008

Pingback from  Internet blog &raquo; Best Practices - Internet Safety for 2008

# re: McAfee Virus Scan 8.5i fails Vista VB100 certification due to update problems

Saturday, January 05, 2008 3:03 AM by Jibz.kassim

i have been attacked by raila odinga that keeps on popping on ma screen am ware of "smss" but am wondering if mcafee 8.5i would work on a visat operated machine its ma 3rd day with no work done help me out pliz

# re: Best Practices - Internet Safety for 2008

Saturday, January 05, 2008 6:17 AM by Louis

Hi ! I read this site its too much nice compatitively and hence I am too much attrected towards it.

May I know that Has anyone heard of The Young Entrepreneur Society ?

# Apply Creditcard &raquo; Best Practices - Internet Safety for 2008

Pingback from  Apply Creditcard &raquo; Best Practices - Internet Safety for 2008

# Best Practices For 2008 - Linux and other Operating Systems | Nellie2

Pingback from  Best Practices For 2008 - Linux and other Operating Systems | Nellie2

# Best Practices For 2008 - Linux and other Operating Systems | Nellie2

Pingback from  Best Practices For 2008 - Linux and other Operating Systems | Nellie2

# re: Windows XP Professional x64 Edition - now available (free upgrade)

Sunday, January 06, 2008 8:32 PM by SARFRAZ KHAN

UPDATE MY WINDOWS WITH EASE AND FREE OF COST AT NET

# &raquo; Malware - Anti-Virus Vendors struggled to keep us protected during &#8230;

Pingback from  &raquo; Malware - Anti-Virus Vendors struggled to keep us protected during &#8230;

# &raquo; Malware - Anti-Virus Vendors struggled to keep us protected during &#8230;

Pingback from  &raquo; Malware - Anti-Virus Vendors struggled to keep us protected during &#8230;

# Anti Virus

Monday, January 07, 2008 11:22 PM by Anti Virus

Pingback from  Anti Virus

# Windows Vista &raquo; Windows Vista - 12 Tips To Boost Your PC&#39;s Performance

Pingback from  Windows Vista &raquo; Windows Vista - 12 Tips To Boost Your PC&#39;s Performance

# Najlepsze Programy, Recenzje, Informacje. &raquo; Blog Archive &raquo; Windows Vista - 12 Tips To Boost Your PC&#39;s Performance

Pingback from  Najlepsze Programy, Recenzje, Informacje.  &raquo; Blog Archive   &raquo; Windows Vista - 12 Tips To Boost Your PC&#39;s Performance

# Windows Vista &#45; 12 Tips To Boost Your PC&#39;s Performance

Wednesday, January 09, 2008 3:30 PM by Windows Vista News

Interesting: msmvps.com

# re: SPAM Email - Best Practices to reduce inflows

Wednesday, January 09, 2008 11:38 PM by Ashi

spamming is surely a threat to cyber space. most of the spammers are also hackers and they break into your pc as soon as you click on their email links. in order to fight the spam threat we need a strong spam filters for our emails which secures us from most of the spam mails. i have heard that http://www.zapak.com is one of the good e-mail service provider who gives maximum protection from most of the spam mails, now thats what we internet lovers require.  

# re: Windows Vista - 12 Tips To Boost Your PC's Performance

Thursday, January 10, 2008 4:09 AM by Chris Quirke

More on 5, please?  AFAIK there's no easy-UI to managing SR, and the .REG approach to SR can only modify the allocated capacity that the shadow copy process shares for both Previous Versions and System Restore.

I don't know of any control over frequency or "depth" (number of days back in time)of Restore Points, other than implicitly limiting "depth" by limiting allocated capacity.

Most of the overhead of SR is continuous, as material changes are backed up in real time.  The only overhead imposed when a Restore Point is created, is the capture of the registry and other key file "snapshot".  

AFAIK, Vista does not periodically compress SR's backup material into .CAB files, as WinME did (the notorious "cabbing" bouts of unexpected disk thrashing) and XP did not.  Whether NTFS compression is invoked, either at creation time or periodically, is unknown to me; nor do I know of settings that may influence this.

# &nbsp; Best Practices - Internet Safety for 2008&nbsp;by&nbsp;IT News

Thursday, January 10, 2008 5:03 AM by   Best Practices - Internet Safety for 2008 by IT News

Pingback from  &nbsp; Best Practices - Internet Safety for 2008&nbsp;by&nbsp;IT News

# re: Malware - Anti-Virus Vendors struggled to keep us protected during 2007

Thursday, January 10, 2008 7:31 AM by Chris Quirke

Do you ever retire old detections?  I ask, because often I find up-to-date scanners miss old malware, such as that present within dumps from old Win95-era HDs etc.

IMO, intervention scanning is a missed opportunity for av vendors, as it may be the only opportunity for a user to test an av product without having to uninstall their existing one.  Windows-based killers such as Stinger, Avast Cleaner etc. are useful, but they don't convey the full detection capabilities of the av's "real" products, and resident malware can defeat them in various ways.

What I'd like to see is an OS-level file-parsing engine built into the WinPE platform, into which multiple av vendors' engines can be plugged.  Each engine would then be efficiently applied in series to each file that is picked up and scanned.

# js/exploit bo | Tv news mag

Friday, January 11, 2008 8:34 AM by js/exploit bo | Tv news mag

Pingback from  js/exploit bo | Tv news mag

# Internet blog &raquo; Microsoft Windows Home Server - How to get started

Pingback from  Internet blog &raquo; Microsoft Windows Home Server - How to get started

# &raquo; Microsoft Windows Home Server - How to get started

Monday, January 14, 2008 12:36 PM by » Microsoft Windows Home Server - How to get started

Pingback from  &raquo; Microsoft Windows Home Server - How to get started

# Microsoft Windows Home Server &#45; How to get started

Monday, January 14, 2008 1:00 PM by Windows Vista News

Did you see this post at msmvps.com

# Microsoft IT Resources - Top 25 blog links on TechNet and MSDN

Wednesday, January 16, 2008 9:25 AM by Curious George on TechNet and more...

BIG hat tip to our very own Eileen B I just noticed that Harry's post has a list of the 25 top blog sites

# Microsoft IT Resources &#45; Top 25 blog links on TechNet and MSDN

Wednesday, January 16, 2008 10:00 AM by Windows Vista News

There is an interesting post over at msmvps.com

# re: W32.Spybot.ACYR - New Symantec Removal Tool

Friday, January 18, 2008 4:34 AM by Issa

Hie there....i can say that i got hit by this worm and my network 0f 40 machines went down not to mention the server itself and we lost ALL DATA ....my machines automaticall backup data at a given time of the day and little did i know that all the data that was being backed was infected and now my servers hit. I am sick and tired of this F@#&ing worm and it seems to avoid all the antiviruses i have used...any suggestions?

# re: MS04-028 - ISC releases GDI Scan Tool

Sunday, January 20, 2008 10:05 AM by Cazzy

I cannot seem to find a way of downloading the GDI tool, it appears to not be available at this time!  Any help welcome!

# Storm Worm - Valentine's Theme and Examples to avoid

Wednesday, January 23, 2008 11:29 AM by Harry Waldron - Microsoft MVP Blog

As previously noted, a new Valentines theme emerged from the Storm worm Botnet last week and copies were

# Storm Worm - Valentine's Theme and Examples to avoid

Wednesday, January 23, 2008 11:36 AM by Harry Waldron - My IT Forums Blog

As previously noted, a new Valentines theme emerged from the Storm worm Botnet last week and copies were

# re: Storm Worm - Valentine's Theme and Examples to avoid

Thursday, January 24, 2008 9:31 AM by Yap

Hi Harry,

I have unfortunately gotten this vicious virus with Mcafee installed in my system.

My manual scan option is disable by the virus.

How do I remove this virus?

Appreciate your help...

Yap

# French Bank SocGen suffers $7.1 Billion loss from inside fraud

Thursday, January 24, 2008 10:00 AM by Windows Vista News

Did you see this post at msmvps.com

# re: PIE (Persistent Identification Element) - Cookies you can't easily delete

Saturday, January 26, 2008 4:22 PM by S. Reed

The excerpt below is taken from the Wikipedia's article on PIE. The last two paragraphs reveal how the Flash Control Panel settings are a sham because they can easily be overridden by Visual Basic Script or similar code running on web pages!!!  There is no way for us to stop this without changing some laws!

Internet Privacy/Persistent Identification Elements

See also: Local Shared Object

Flash Player is an application that, while running on a computer that is connected to the internet, is designed to contemporaneously interact with websites containing Flash content that are being visited online. As such, under certain configurations the application has the potential to silently compromise its users' internet privacy, and do so without their knowledge. By default, Flash Player is configured to permit small, otherwise invisible "tracking" files, known as Persistent Identification Elements (PIE)[3] or Local Shared Object files, to be stored on the hard drive of a user's computer. Sent in the background over the internet from websites to which a user is connected, these files work much the way "cookies" do with internet browsers. When stored on a user's computer, PIE (.sol) files are capable of sending personally sensitive data back out over the internet without the user's knowledge to one or more third parties. In addition, Flash Player is also capable of accessing and retrieving audio and video data from any microphone and/or webcams that might be either built in or connected to a user's computer and transmitting it in realtime over the internet (also potentially without the user's knowledge) to one or more third parties.

While these capabilities can all be affirmatively blocked and/or disabled by the user, the Flash Player application does not provide an internally accessible "preferences" panel to accomplish this. Instead access to the various settings panels necessary to manage the application's "Privacy," "Storage," "Security," and "Notifications" settings can be achieved through a web-based "Settings Manager" page located on the "support" section of the Adobe.com website, or by third party tools (see Local Shared Object). Each of the functions can be enabled/disabled either "globally" to cover all websites, or set differently for individual websites depending on how the user desires Flash Player to be able to interact with each one.

Whilst the Flash Control Panel Settings in theory allow users to protect their Privacy it should be remembered that suitably crafted Visual Basic Script or similar code can overwrite any user defined settings before the Flash Player Plug-in is called by a Webpage.

In addition to cookies, many banks and other financial institutions also routinely install Persistent Identification Elements using Flash Player on users' hard drives when they establish and access their accounts, as do other interactive sites such as "YouTube" and the like.

# Internet Domain Names &#45; Five day grace period abused by malware ...

Tuesday, January 29, 2008 9:00 AM by Windows Vista News

Interesting point at msmvps.com

# Domaining - Information on Domains and Domaining &raquo; Internet Domain Names - Five day grace period abused by malware &#8230;

Pingback from  Domaining - Information on Domains and Domaining &raquo; Internet Domain Names - Five day grace period abused by malware &#8230;

# Storm Worm &#45; Launched one year ago

Tuesday, January 29, 2008 1:00 PM by Windows Vista News

There is an interesting post over at msmvps.com

# Over Five Million unique malware types were created in 2007

Tuesday, January 29, 2008 5:02 PM by Windows Vista News

New post at msmvps.com

# IRS Fake Refund Notices - Actual Example received in email

Thursday, January 31, 2008 9:49 AM by Harry Waldron - Microsoft MVP Blog

As noted in this post , scammers are attempting to trick individuals during the tax season to reveal

# IRS Fake Refund Notices - Actual Example received in email

Thursday, January 31, 2008 9:51 AM by Harry Waldron - My IT Forums Blog

E] As noted in this post , scammers are attempting to trick individuals during the tax season to reveal

# IRS Fake Refund Notices &#45; Actual Example received in email

Thursday, January 31, 2008 12:00 PM by Windows Vista News

Did you see the post at msmvps.com

# ActiveX Vulnerabilities - Facebook, MySpace and Yahoo

Tuesday, February 05, 2008 11:34 AM by ActiveX Vulnerabilities - Facebook, MySpace and Yahoo

Pingback from  ActiveX Vulnerabilities - Facebook, MySpace and Yahoo

# re: ActiveX Vulnerabilities - Facebook, MySpace and Yahoo

Tuesday, February 05, 2008 12:05 PM by Iain House

Check the Datagrid CLSID - too many characters!

Symantec have it wrong on their website, and your one of MANY people who have copied it!

# re: ActiveX Vulnerabilities - Facebook, MySpace and Yahoo

Tuesday, February 05, 2008 5:22 PM by Iain House

The CLSID for Yahoo! Datagrid originally published by Symantec and ISC is incorrect and you have copied it here. Please check the original articles, both of which have now been corrected.

# re: IRS Fake Refund Notices - Actual Example received in email

Monday, February 11, 2008 10:57 AM by Gym Corner Kim Bendixen

Thank, you for clearing this up. I just received this very email