<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><title type="html">Harry Waldron - Corporate IT Security </title><subtitle type="html">Security Developments, Software Updates and Best Practices </subtitle><id>http://msmvps.com/blogs/harrywaldron/atom.aspx</id><link rel="alternate" type="text/html" href="http://msmvps.com/blogs/harrywaldron/default.aspx" /><link rel="self" type="application/atom+xml" href="http://msmvps.com/blogs/harrywaldron/atom.aspx" /><generator uri="http://communityserver.org" version="4.1.40407.4157">Community Server</generator><updated>2009-06-10T08:51:00Z</updated><entry><title>McAfee DAT 5664 - False Positives may affect Compaq/HP drivers</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2009/07/04/mcafee-dat-5664-false-positives-may-affect-compaq-hp-drivers.aspx" /><id>/blogs/harrywaldron/archive/2009/07/04/mcafee-dat-5664-false-positives-may-affect-compaq-hp-drivers.aspx</id><published>2009-07-04T15:01:00Z</published><updated>2009-07-04T15:01:00Z</updated><content type="html">&lt;p&gt;For McAfee users, I&amp;#39;m sure also AVERT Labs is correcting this issue.&amp;nbsp; Still, it&amp;#39;s worthwhile to monitor developments, as I&amp;#39;m staying on DAT 5663 on my corporate PC until this issue is resolved. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;McAfee DAT 5664 - False Positives may affect Compaq/HP drivers&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://community.mcafee.com/showthread.php?t=231901"&gt;http://community.mcafee.com/showthread.php?t=231901&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.theregister.co.uk/2009/07/03/mcafee_false_positive_glitch/"&gt;http://www.theregister.co.uk/2009/07/03/mcafee_false_positive_glitch/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt; IT admins across the globe are letting out a collective groan after servers and PCs running McAfee VirusScan were brought down when the anti-virus program attack their core system files. In some cases, this caused the machines to display the dreaded blue screen of death. Details are still coming in, but forums here and here show that it&amp;#39;s affecting McAfee customers in Germany, Italy, and elsewhere. A UK-based Reg reader, who asked to remain anonymous because he was not authorized by his employer to speak to the press, said the glitch simultaneously leveled half of a customer&amp;#39;s 140 machines after they updated the latest virus signature file.&lt;/p&gt;
&lt;p&gt;Based on anecdotes, the &lt;strong&gt;glitch appears to be caused when older VirusScan engines install DAT 5664&lt;/strong&gt;, which McAfee seems to have pushed out in the past 24 hours. Affected systems then begin identifying a wide variety of legitimate - and frequently crucial - system files as malware. &lt;strong&gt;Files belonging to Microsoft Internet Explorer, drivers for Compaq computers,&lt;/strong&gt; and even the McAfee-associated McScript.exe were being identified as a trojan called &lt;strong&gt;PWS!hv.aq&lt;/strong&gt;, according to the posts and interviews.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1697971" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>July 4th based Malware circulating </title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2009/07/04/july-4th-based-malware-circulating.aspx" /><id>/blogs/harrywaldron/archive/2009/07/04/july-4th-based-malware-circulating.aspx</id><published>2009-07-04T12:02:00Z</published><updated>2009-07-04T12:02:00Z</updated><content type="html">&lt;p&gt;&amp;nbsp;Malicious emails are being spammed related to the themes of: &lt;strong&gt;Independence Day, the Fourth of July and fireworks shows&lt;/strong&gt;. Please&amp;nbsp;avoid&amp;nbsp;related email messages/attachments, special&amp;nbsp;website links, and You-Tube links.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-49.gif" alt="Cake" /&gt; &lt;strong&gt;July 4th based Malware circulating &lt;br /&gt;&lt;/strong&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=6727"&gt;http://isc.sans.org/diary.html?storyid=6727&lt;/a&gt;&lt;br /&gt;&lt;a href="http://securitylabs.websense.com/content/Alerts/3431.aspx"&gt;http://securitylabs.websense.com/content/Alerts/3431.aspx&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.eset.com/threat-center/blog/?p=1244"&gt;http://www.eset.com/threat-center/blog/?p=1244&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.symantec.com/connect/blogs/waledac-july-campaign"&gt;http://www.symantec.com/connect/blogs/waledac-july-campaign&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-49.gif" alt="Cake" /&gt; &lt;strong&gt;Waldac.DU Information&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://blog.trendmicro.com/waledac-celebrates-independence-day-too/"&gt;http://blog.trendmicro.com/waledac-celebrates-independence-day-too/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_WALEDAC.DU"&gt;http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_WALEDAC.DU&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt; The malicious Web sites in the current attack also have a &lt;strong&gt;July 4 or fireworks theme&lt;/strong&gt; within the domain name. ThreatSeeker has been monitoring the registration of these domains.&lt;strong&gt; Should the user click on the video, which is designed to appear to be a YouTube video, an .exe is offered&lt;/strong&gt;. When downloaded the .exe would install the&lt;strong&gt; latest Waledac variant onto the user&amp;#39;s machine&lt;/strong&gt;.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1697939" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Cold Fusion web sites compromised when HTML editor enabled </title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2009/07/03/cold-fusion-web-sites-compromised-when-html-editor-enabled.aspx" /><id>/blogs/harrywaldron/archive/2009/07/03/cold-fusion-web-sites-compromised-when-html-editor-enabled.aspx</id><published>2009-07-03T13:55:00Z</published><updated>2009-07-03T13:55:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-37.gif" alt="Storm" /&gt; &lt;strong&gt;Web ADMINS should ensure the HTML text editor is secured as it may be automatically installed by default&lt;/strong&gt; on some versions of Cold Fusion studio.&amp;nbsp;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-60.gif" alt="Lightning" /&gt;&lt;strong&gt; Large # of Cold Fusion web sites&amp;nbsp;compromised in past 24 hours&lt;/strong&gt;&amp;nbsp;&lt;br /&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=6715"&gt;http://isc.sans.org/diary.html?storyid=6715&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE&lt;/strong&gt;: There have been a &lt;strong&gt;high number of Cold Fusion web sites being compromised in last 24 hours&lt;/strong&gt;. It appears that the attackers are exploiting web sites which have older installations of some Cold Fusion applications. These applications have vulnerable installations of FCKEditor, which is a very popular HTML text editor, or CKFinder, which is an Ajax file manager.&lt;/p&gt;
&lt;p&gt;The vulnerable installations allow the attackers to upload ASP or Cold Fusion shells which further allow them to take complete control over the server. It appears that there are two attack vectors (both using vulnerable FCKEditor installations though) that the attackers are exploiting. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;How to disable the HTML editor to improve safety&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.codfusion.com/blog/post.cfm/cf8-and-fckeditor-security-threat"&gt;http://www.codfusion.com/blog/post.cfm/cf8-and-fckeditor-security-threat&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1697693" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>MOTB - Month of Twitter Bugs Begins</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2009/07/01/motb-month-of-twitter-bugs-begins.aspx" /><id>/blogs/harrywaldron/archive/2009/07/01/motb-month-of-twitter-bugs-begins.aspx</id><published>2009-07-01T22:09:00Z</published><updated>2009-07-01T22:09:00Z</updated><content type="html">&lt;p&gt;Security research testing of the Twitter API will be conducted during the month of July.&amp;nbsp; The stated goal is to bring awareness to the need for strengthening security in this very popular and flexible social network messaging facility. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;MOTB Daily Findings published here&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.twitpwn.com/"&gt;http://www.twitpwn.com/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Security Researcher Aviv Raff shares mission statement&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://aviv.raffon.net/2009/06/15/MonthOfTwitterBugs.aspx"&gt;http://aviv.raffon.net/2009/06/15/MonthOfTwitterBugs.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;QUOTE: Today, three years after the &amp;ldquo;Month of Browser Bugs&amp;rdquo;, I&amp;rsquo;ve decided to declare July 2009 as &amp;ldquo;Month of Twitter Bugs&amp;rdquo; (MoTB). I&amp;rsquo;m doing so in order to raise the awareness of the Twitter API issue I recently blogged about. MoTB could have been easily converted to any other &amp;ldquo;Month of Web2.0 service bugs&amp;rdquo;, and I hope that Twitter and other Web2.0 API providers will work closely with their API consumers to develop more secure products.&lt;/p&gt;
&lt;p&gt;Below is the 1st documented vulnerability related to shortened URLs that may be shared in these micro-blog messages:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;MoTB #01: Multiple vulnerabilities in bit.ly service&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.twitpwn.com/2009/07/motb-01-multiple-vulnerabilities-in.html"&gt;http://www.twitpwn.com/2009/07/motb-01-multiple-vulnerabilities-in.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt; &amp;quot;bit.ly allows users to &lt;strong&gt;shorten, share, and track links (URLs).&lt;/strong&gt; Reducing the URL length makes sharing easier. bit.ly can be accessed through our website, bookmarklets and a robust and open API. bit.ly is also integrated into several popular third-party tools such as Tweetdeck.&amp;quot;&lt;/p&gt;
&lt;p&gt;bit.ly has a large user base (who doesn&amp;#39;t click bit.ly links?). However, with such a poor response rate to security vulnerabilities, and with such a poorly coded website, in terms of security, we can only hope for the best. &lt;strong&gt;Please be careful clicking those shortened URLs...&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1697522" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Credit Cards - Where and what you buy could affect your credit </title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2009/07/01/credit-cards-where-and-what-you-buy-could-affect-your-credit.aspx" /><id>/blogs/harrywaldron/archive/2009/07/01/credit-cards-where-and-what-you-buy-could-affect-your-credit.aspx</id><published>2009-07-01T21:52:00Z</published><updated>2009-07-01T21:52:00Z</updated><content type="html">&lt;p&gt;This informative article shares an awareness that credit card purchase patterns could be used as part of the analysis in determining whether someone is a higher credit risk.&amp;nbsp;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What You Buy, Where You Shop May Affect Your Credit&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.walletpop.com/credit/credit-cards/article/what-you-buy-where-you-shop-may-affect/544639"&gt;http://www.walletpop.com/credit/credit-cards/article/what-you-buy-where-you-shop-may-affect/544639&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt; As credit card companies continue to tighten their lending standards on card users, some are using purchasing data -- gleaned from millions of card transactions processed daily -- to weed out who may or may not be good credit risks. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Have you used your credit card at merchants specializing in secondhand clothing, retread tires, bail bond services, massages, casino gambling or betting? Your credit card issuer may be taking note -- and making decisions about your creditworthiness based on your purchasing behavior. The reason: Buying used clothing or retread tires may be an indication of financial distress and a preamble to missed credit card payments or defaults.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The recent credit crunch has placed greater emphasis on using the data to predict who may be a higher credit risk. Credit card issuers have said people living in states hard hit by foreclosures, such as Florida, Nevada and California (referred to as the &amp;quot;sand states&amp;quot;) may be considered increased risks by virtue of the fact that they live there. People who shop at the same establishments where subprime borrowers shop also may be considered higher risk.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1697520" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Firefox 3.5 released today</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2009/06/30/firefox-3-5-released-today.aspx" /><id>/blogs/harrywaldron/archive/2009/06/30/firefox-3-5-released-today.aspx</id><published>2009-06-30T14:52:00Z</published><updated>2009-06-30T14:52:00Z</updated><content type="html">&lt;p&gt;I use Firefox as a complementary browser&amp;nbsp;and the latest new version became available today.&amp;nbsp; The upgrade from 3.0.11 went well and so far there are no issues in using&amp;nbsp;the new version&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Firefox 3.5 Home Page&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.com/en-US/firefox/"&gt;http://www.mozilla.com/en-US/firefox/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Firefox 3.5 Key Features&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.mozilla.com/en-US/firefox/features/"&gt;http://www.mozilla.com/en-US/firefox/features/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1697351" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Malicious SPAM related to passing of Michael Jackson and Farrah Fawcett</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2009/06/27/malicious-spam-related-to-passing-of-michael-jackson-and-farrah-fawcett.aspx" /><id>/blogs/harrywaldron/archive/2009/06/27/malicious-spam-related-to-passing-of-michael-jackson-and-farrah-fawcett.aspx</id><published>2009-06-27T12:47:00Z</published><updated>2009-06-27T12:47:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-29.gif" alt="Music" /&gt; &lt;img src="http://msmvps.com/emoticons/emotion-53.gif" alt="Movie" /&gt;&amp;nbsp;&amp;nbsp;Malware writers often use tragic&amp;nbsp;news events to trick users into opening malicious website links, YouTube video links,&amp;nbsp;or attachments.&amp;nbsp; While&amp;nbsp;most AV vendors have coverage in place, &lt;strong&gt;please avoid these types of email messages&lt;/strong&gt; that are now actively circulating.&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#8b0000;"&gt;
&lt;p&gt;&lt;span style="color:#8b0000;"&gt;&lt;img src="http://msmvps.com/emoticons/emotion-60.gif" alt="Lightning" /&gt;&lt;strong&gt; Malicious SPAM related to passing of Michael Jackson and Farrah Fawcett&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;
&lt;p&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=6646"&gt;http://isc.sans.org/diary.html?storyid=6646&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a target="_blank" href="http://isc.sans.org/diary.html?storyid=6658"&gt;http://isc.sans.org/diary.html?storyid=6658&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a target="_blank" href="http://sanesecurity.blogspot.com/2009/06/michael-jackson-virus-already.html"&gt;http://sanesecurity.blogspot.com/2009/06/michael-jackson-virus-already.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a target="_blank" href="http://www.avertlabs.com/research/blog/index.php/2009/06/25/bad-news-oportunity-to-spread-malware/"&gt;http://www.avertlabs.com/research/blog/index.php/2009/06/25/bad-news-oportunity-to-spread-malware/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a target="_blank" href="http://securitylabs.websense.com/content/Alerts/3426.aspx"&gt;http://securitylabs.websense.com/content/Alerts/3426.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a target="_blank" href="http://vil.nai.com/vil/content/v_132277.htm"&gt;http://vil.nai.com/vil/content/v_132277.htm&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a target="_blank" href="http://www.avertlabs.com/research/blog/index.php/2009/06/26/michael-jackson-news-affects-web-traffic/"&gt;http://www.avertlabs.com/research/blog/index.php/2009/06/26/michael-jackson-news-affects-web-traffic/&lt;/a&gt;&lt;/p&gt;
&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt; michael jackson virus already&amp;nbsp;&lt;img src="http://forums.mcafeehelp.com/images/smilies/frown.gif" alt="0" border="0" class="inlineimg" /&gt;&amp;nbsp; Well, it didn&amp;#39;t take long for the &amp;quot;them&amp;quot; to abuse the situation did it? &lt;img src="http://forums.mcafeehelp.com/images/smilies/frown.gif" alt="0" border="0" class="inlineimg" /&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;The spam email appears to &lt;strong&gt;&lt;span style="color:#ff0000;"&gt;offer a link to a YouTube video&lt;/span&gt;&lt;/strong&gt;, but instead sends the recipient to a Trojan Downloader hosted on a compromised Web site. The file offered is called &lt;span style="color:#ff0000;"&gt;&lt;strong&gt;Michael.Jackson.videos.scr&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1696853" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Scareware and other Rogue security programs</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2009/06/22/scareware-and-other-rogue-security-programs.aspx" /><id>/blogs/harrywaldron/archive/2009/06/22/scareware-and-other-rogue-security-programs.aspx</id><published>2009-06-22T20:45:00Z</published><updated>2009-06-22T20:45:00Z</updated><content type="html">&lt;p&gt;Below are some excellent articles and awareness on this popular form of attack. These programs are improving in their methods of emulating Anti-virus programs and should be avoided as they are difficult to clean.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Excellent Article on Scareware and other Rogue security programs&lt;/strong&gt; &lt;br /&gt;&lt;a href="http://lastwatchdog.com/scareware-attacks-spreading-twitter-google-legit/"&gt;http://lastwatchdog.com/scareware-attacks-spreading-twitter-google-legit/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.usatoday.com/tech/news/2009-06-09-cybergangs-scareware-hackers_N.htm"&gt;http://www.usatoday.com/tech/news/2009-06-09-cybergangs-scareware-hackers_N.htm&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt;&amp;nbsp; In some cases, the fake software you buy may actually provide you with some nominal protection. &lt;strong&gt;But mostly for your $30 to $80 the only thing you get is temporary relief from the obnoxious dialogue boxes, and misleading hard drive scans.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;HOW SCAREWARE TRICKERY ENSNARES INTERNET USERS&lt;/strong&gt; &lt;br /&gt;1 Criminals buy blocks of ad space on websites, intermittently slipping in a tainted ad.&lt;br /&gt;2 Just visiting a webpage with a tainted ad causes a fake warning box to appear.&lt;br /&gt;3 Clicking &amp;quot;OK&amp;quot; or &amp;quot;Cancel&amp;quot; launches the same thing: a &amp;quot;free scan.&amp;quot;&lt;br /&gt;4 After you&amp;#39;ve been lured into a fake &amp;quot;free&amp;quot; scan of your PC:&lt;br /&gt;5 The bogus scan will purport to find a virus infestation.&lt;br /&gt;6 Ensuing boxes steer the user to activate &amp;quot;Personal Antivirus,&amp;quot; on left.&lt;br /&gt;7 The activation prompts take the user to a shopping cart.&lt;br /&gt;8 Declining to place an order triggers endless fake scans.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What is Scareware&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/Rogue_software"&gt;http://en.wikipedia.org/wiki/Rogue_software&lt;/a&gt;&lt;br /&gt;&lt;a href="http://whatis.techtarget.com/definition/scareware.html"&gt;http://whatis.techtarget.com/definition/scareware.html&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE&lt;/strong&gt;: Scareware is a type of&lt;strong&gt; malware designed to trick victims into purchasing and downloading useless and potentially dangerous software&lt;/strong&gt;. Scareware, which generates pop-ups that resemble Windows system messages, usually purports to be antivirus or antispyware software, a firewall application or a registry cleaner. The messages typically say that a large number of problems -- such as infected files -- have been found on the computer and the user is prompted to purchase software to fix the problems.&lt;strong&gt; In reality, no problems were detected and the suggested software purchase may actually contain real malware. &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Scareware programs produced by those companies include: &lt;strong&gt;DriveCleaner, WinAntivirus, ErrorSafe, WinFixer and XP Antivirus&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1696238" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Spoofed Microsoft Outlook Critical Update spammed in email</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2009/06/22/spoofed-microsoft-outlook-critical-update-spammed-in-email.aspx" /><id>/blogs/harrywaldron/archive/2009/06/22/spoofed-microsoft-outlook-critical-update-spammed-in-email.aspx</id><published>2009-06-22T19:02:00Z</published><updated>2009-06-22T19:02:00Z</updated><content type="html">&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt;&lt;img src="http://msmvps.com/emoticons/emotion-57.gif" alt="Email" /&gt; As many folks realize &lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="color:green;"&gt;Microsoft does not distribute updates by email&lt;/span&gt;&lt;/b&gt;. However, Microsoft will alert users who have signed up for Patch Tuesday notifications, that new updates are available.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-family:Times New Roman;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt;In the links below, Trend Labs notes a &lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="color:red;"&gt;highly deceptive email that contains authentic looking HTML and valid Microsoft site links.&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Even the wording appears to be legitimate.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;The email address is also spoofed to appear as if it originated from &amp;quot;Microsoft Customer Support&amp;quot;.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-family:Times New Roman;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt;Fortunately, spoofed email headers often end up in the &lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="color:red;"&gt;spam&lt;/span&gt;&lt;/b&gt; or bulk mail folders automatically.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;As Trend Labs notes, a best practice of hovering over email links would reveal a different one than shown in the document.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-family:Times New Roman;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt;Finally, when notified of any vendor updates it&amp;#39;s always best to go to home site to check directly (rather than using the email link).&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;However, this particular attack could trick some users as it has some resembles to a Microsoft security notification. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-family:Times New Roman;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="color:maroon;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt;Trend Labs - &amp;ldquo;Critical Update&amp;rdquo; Leads to Critical Info Theft&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;a href="http://blog.trendmicro.com/critical-update-leads-to-critical-info-theft/"&gt;&lt;span style="font-family:Times New Roman;color:#800080;font-size:small;"&gt;http://blog.trendmicro.com/critical-update-leads-to-critical-info-theft/&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;a href="http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FZBOT%2EBTS&amp;amp;VSect=T"&gt;&lt;span style="font-family:Times New Roman;color:#800080;font-size:small;"&gt;http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FZBOT%2EBTS&amp;amp;VSect=T&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-family:Times New Roman;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="color:maroon;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt;Spoofed &amp;ldquo;Critical Update&amp;rdquo; appears to originate from Microsoft &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;a href="http://www.trendmicro.com/vinfo/images/blog/062209_fig1.gif"&gt;&lt;span style="font-family:Times New Roman;color:#800080;font-size:small;"&gt;http://www.trendmicro.com/vinfo/images/blog/062209_fig1.gif&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-family:Times New Roman;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="color:maroon;"&gt;QUOTE&lt;/span&gt;&lt;/b&gt;&lt;span style="color:maroon;"&gt;:&lt;/span&gt; Microsoft Corporation regularly issues updates to fix bugs and security vulnerabilities in its software products. These updates are meant to protect its users from different attacks that depend mainly on exploiting these documented bugs. Close to the weekend, &lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="color:red;"&gt;we identified spam claiming to be a Microsoft Outlook and Outlook Express critical update that &amp;ldquo;offers the highest levels of stability and security.&amp;rdquo;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-family:Times New Roman;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt;A tricky difference here is that all the links in the email (the links to Contact Us, Privacy Statement, Trademarks, and Terms of Use) are legitimate&amp;ndash;except one. The URL where the &amp;ldquo;critical update&amp;rdquo; may be downloaded looks legitimate, &lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="color:green;"&gt;but hovering over the hyperlink&lt;/span&gt;&lt;/b&gt; (or checking the source code of the mail) reveals a totally different destination.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-family:Times New Roman;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt;Our engineers confirm that the list was containing several names of &lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="color:red;"&gt;banking institutions&lt;/span&gt;&lt;/b&gt;, among other &lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="color:red;"&gt;social networking targets&lt;/span&gt;&lt;/b&gt; like Facebook and MySpace, and media sites YouTube and Flickr. The list can be viewed here. Note that the said list may be changed at any time.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-family:Times New Roman;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt;How does the scam work? Whenever the &lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="color:red;"&gt;user visits any of the monitored sites, the Trojan starts logging keystrokes.&lt;/span&gt;&lt;/b&gt; It then saves gathered information (which presumably includes sensitive information like&lt;b style="mso-bidi-font-weight:normal;"&gt; &lt;span style="color:red;"&gt;user name and password, credit card information&lt;/span&gt;&lt;/b&gt;&lt;span style="color:red;"&gt;,&lt;/span&gt; etc.) in a file and then sends the file to a dedicated server.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1696232" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Dating Services SPAM - phishing attacks and other dangers</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2009/06/20/dating-services-spam-phishing-attacks-and-other-dangers.aspx" /><id>/blogs/harrywaldron/archive/2009/06/20/dating-services-spam-phishing-attacks-and-other-dangers.aspx</id><published>2009-06-20T14:32:00Z</published><updated>2009-06-20T14:32:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-57.gif" alt="Email" /&gt; &lt;strong&gt;&lt;span style="color:#006400;"&gt;SPAM email should always be deleted without opening it&lt;/span&gt;&lt;/strong&gt; or any accompanying attachments.&amp;nbsp; Daily, I receive numerous copies of dating services and other&amp;nbsp;SPAM&amp;nbsp;in my personal email.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://forums.mcafeehelp.com/images/smilies/eek.gif" alt="0" border="0" class="inlineimg" /&gt;&amp;nbsp;Some key dangers include tricking users to visit &lt;strong&gt;&lt;span style="color:#ff0000;"&gt;malicious websites&lt;/span&gt;&lt;/strong&gt; or to &lt;span style="color:#ff0000;"&gt;&lt;strong&gt;reveal credit card or personal information &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Trend Labs shares some dangers in a good awareness article below:&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; &lt;a href="http://blog.trendmicro.com/deceitful-advertisement-thru-dating-spam/"&gt;http://blog.trendmicro.com/deceitful-advertisement-thru-dating-spam/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt; Today we have noticed an increase in the amount of dating spam mails containing phrases such as: &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="color:#ff0000;"&gt;I&amp;rsquo;m emailing you because I like you&lt;br /&gt;wanted to let you know about my profile&lt;br /&gt;you have been invited to join&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The link in the spam points to an adult-dating web page, as well as a profile on the right corner of the screen with a huge clickable ad that says, &lt;strong&gt;&lt;span style="color:#ff0000;"&gt;CLICK HERE TO CHAT FOR FREE.&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Following the link opens a page where the &lt;strong&gt;&lt;span style="color:#ff0000;"&gt;visitor is asked to register by providing an email address and password.&lt;/span&gt;&lt;/strong&gt; Afterward the visitor&amp;rsquo;s browser opens a new site where he/she is prompted to create a preferred chat handle (username). Users tempted to correctly fill up the forms from the shown web pages provide a free service to the cybercriminals as they &lt;strong&gt;&lt;span style="color:#696969;"&gt;reveal their valid email addresses, passwords, and credit card information. &lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1695915" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Nine-Ball Mass Injection attack compromises 40,000 Websites</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2009/06/19/nine-ball-mass-injection-attack-compromises-40-000-websites.aspx" /><id>/blogs/harrywaldron/archive/2009/06/19/nine-ball-mass-injection-attack-compromises-40-000-websites.aspx</id><published>2009-06-19T20:08:00Z</published><updated>2009-06-19T20:08:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-60.gif" alt="Lightning" /&gt;&amp;nbsp; Please be careful with website visitations as malicious attacks continue to compromise some sites that may not be locked down well from a security standpoint.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Nine-Ball Mass Injection attack compromises 40,000 Websites&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.eweek.com/c/a/Security/40000-Web-Sites-Compromised-in-Mass-Attack-227486/"&gt;http://www.eweek.com/c/a/Security/40000-Web-Sites-Compromised-in-Mass-Attack-227486/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://securitylabs.websense.com/content/Alerts/3421.aspx"&gt;http://securitylabs.websense.com/content/Alerts/3421.aspx&lt;/a&gt;&lt;br /&gt;&lt;a href="http://vil.nai.com/vil/content/v_141590.htm"&gt;http://vil.nai.com/vil/content/v_141590.htm&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt; Websense Security Labs has detected another&lt;strong&gt; large mass injection attack in the wild after the Beladen and Gumblar attacks&lt;/strong&gt;. We are calling this mass compromise&lt;strong&gt; Nine-Ball because of the final landing site&lt;/strong&gt;. We have been tracking the Nine-Ball mass compromise &lt;strong&gt;since 6/03/2009&lt;/strong&gt;. To date, &lt;strong&gt;over 40,000 legitimate Web sites have been compromised with obfuscated code that leads to a multi-level redirection attack&lt;/strong&gt;, ending in a series of drive-by exploits that if successful install a trojan downloader on the user&amp;#39;s machine.&lt;/p&gt;
&lt;p&gt;After redirection, the exploit payload site returns highly obfuscated malicious code. The malicious code attempts to exploit &lt;strong&gt;MS06-014&lt;/strong&gt; (targeting MDAC) and CVE-2006-5820 (targeting&lt;strong&gt; AOL SuperBuddy&lt;/strong&gt;), as well as &lt;strong&gt;employing exploits targeting Acrobat Reader and QuickTime&lt;/strong&gt;. The MS06-014 exploit code will download a Trojan dropper with low AV detection rate. This dropper drops a dll with the name SOCKET2.DLL to Windows&amp;#39; system folder. This file is used to&lt;strong&gt; steal user information.&lt;/strong&gt; The malicious PDF file, served by the exploit site, also has very low AV detection rate.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1695882" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Microsoft Security Essentials (MSE) Beta version to be released soon</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2009/06/18/microsoft-security-essentials-mse-beta-version-to-be-released-soon.aspx" /><id>/blogs/harrywaldron/archive/2009/06/18/microsoft-security-essentials-mse-beta-version-to-be-released-soon.aspx</id><published>2009-06-19T01:46:00Z</published><updated>2009-06-19T01:46:00Z</updated><content type="html">&lt;p&gt;Several reports are circulating in the media for a &lt;strong&gt;new&amp;nbsp;Microsoft consumer security product&lt;/strong&gt; that will soon be announced.&amp;nbsp; As sometimes early reports contain inaccuracies, the official announcements by the company should only be considered at this point.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;Hopefully, MSE will successful in providing basic&amp;nbsp;security protection. WGA validation also seems to be a reasonable requirement for the enhanced malware protection this product will offer.&amp;nbsp; Once official Microsoft announcements are published, we&amp;#39;ll know more regarding this new product.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt;&lt;strong&gt; Microsoft Security Essentials (MSE) Beta version to be released soon&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=913455"&gt;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=913455&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.informationweek.com/news/security/app-security/showArticle.jhtml?articleID=218100195"&gt;http://www.informationweek.com/news/security/app-security/showArticle.jhtml?articleID=218100195&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pcmag.com/article2/0,2817,2348996,00.asp"&gt;http://www.pcmag.com/article2/0,2817,2348996,00.asp&lt;/a&gt;&lt;br /&gt;&lt;a href="http://news.cnet.com/8301-1009_3-10268040-83.html"&gt;http://news.cnet.com/8301-1009_3-10268040-83.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.windowslive.com/Connect/Post/14eb0c3e-78fc-4e21-8783-c4521a4d83a6"&gt;http://www.windowslive.com/Connect/Post/14eb0c3e-78fc-4e21-8783-c4521a4d83a6&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blogs.zdnet.com/microsoft/?p=3120"&gt;http://blogs.zdnet.com/microsoft/?p=3120&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blogs.zdnet.com/Bott/?p=1067"&gt;http://blogs.zdnet.com/Bott/?p=1067&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;PC Magazine - Early in-depth evaluation&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.pcmag.com/article2/0,2817,2348998,00.asp"&gt;http://www.pcmag.com/article2/0,2817,2348998,00.asp&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt; Microsoft Corp. today said it will release a public beta of its free antimalware software, now called &lt;strong&gt;Microsoft Security Essentials, formerly &amp;quot;Morro,&amp;quot; next Tuesday for Windows XP, Vista and Windows 7. &amp;quot;&lt;/strong&gt;This is security you can trust,&amp;quot; said Alan Packer, general manager of Microsoft&amp;#39;s antimalware team, when asked to define how it differs from rivals, both free and not. &amp;quot;And&lt;strong&gt; it&amp;#39;s easy to get and easy to use&lt;/strong&gt;.&amp;quot; He stressed the Security Essentials&amp;#39; &lt;strong&gt;real-time protection&lt;/strong&gt; over its scanning functions, which are both integral to any security software worth its weight. &amp;quot;Rather than scan and clean, which it also does, &lt;strong&gt;it&amp;#39;s trying to keep you from being infected in the first place,&amp;quot;&lt;/strong&gt; Packer said.&amp;nbsp; Microsoft will not give Security Essentials to everyone who wants it, however. PCs running a copy of Windows that Microsoft decides is counterfeit or pirated -- &amp;quot;non-genuine&amp;quot; in its parlance -- cannot download a copy of the security software.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1695835" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Month of Twitter Bugs - July 2009</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2009/06/18/month-of-twitter-bugs-july-2009.aspx" /><id>/blogs/harrywaldron/archive/2009/06/18/month-of-twitter-bugs-july-2009.aspx</id><published>2009-06-19T01:38:00Z</published><updated>2009-06-19T01:38:00Z</updated><content type="html">&lt;p&gt; Hopefully, the Twitter site administrators can respond promptly to &lt;strong&gt;proof-of-concept&lt;/strong&gt; vulnerabilities that are crafted by Aviv Raff, a highly experienced security research expert.&amp;nbsp; &lt;strong&gt;Users should be alert for any major issues that surface.&lt;/strong&gt;&amp;nbsp; Most importantly, be careful with all forms of communication keeping a good focus on &lt;strong&gt;privacy and security.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Month of Twitter Bugs - July 2009&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://blogs.zdnet.com/security/?p=3632"&gt;http://blogs.zdnet.com/security/?p=3632&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt; A well-known security researcher plans to use the month of July to expose serious vulnerabilities in the Twitter ecosystem. The Month of Twitter Bugs, a project which launches on &lt;strong&gt;July 1&lt;/strong&gt;, is the handiwork of &lt;strong&gt;Aviv Raff&lt;/strong&gt;, a researcher known for his work on&lt;strong&gt; Web-based security&lt;/strong&gt; issues.&amp;nbsp; Raff, who previously warned that the Twitter API is ripe for abuse, says the project will disclose a&amp;nbsp; combination of cross-site scripting &lt;strong&gt;(XSS)&lt;/strong&gt; and cross-site request forgery &lt;strong&gt;(CSRF)&lt;/strong&gt; flaws that&lt;strong&gt; put Twitter users at risk of malicious hacker attacks.&lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1695833" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>MS Advisory 971778 - Directshow Exploit circulating in-the-wild</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2009/06/18/ms-advisory-971778-directshow-exploit-circulating-in-the-wild.aspx" /><id>/blogs/harrywaldron/archive/2009/06/18/ms-advisory-971778-directshow-exploit-circulating-in-the-wild.aspx</id><published>2009-06-19T00:38:00Z</published><updated>2009-06-19T00:38:00Z</updated><content type="html">&lt;div class="content"&gt;&lt;img src="http://msmvps.com/emoticons/emotion-53.gif" alt="Movie" /&gt; Exploits are circulating for this unpatched vulnerability that mainly affects some special options for Quick Time. The FixIt workaround provides an easy-to-use workaround for now and can be easily disabled if it breaks needed Quick Time functionality:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://msmvps.com/emoticons/emotion-21.gif" alt="Yes" /&gt; &lt;strong&gt;FixIt Registry update can provide protection&lt;/strong&gt; &lt;br /&gt;(can be enabled/disabled easily)&lt;br /&gt;&lt;a target="_blank" href="http://support.microsoft.com/default.aspx/kb/971778"&gt;http://support.microsoft.com/default.aspx/kb/971778&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;More details can be found in links below:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://msmvps.com/emoticons/emotion-60.gif" alt="Lightning" /&gt; &lt;strong&gt;DirectShow Exploits circulating in wild&lt;/strong&gt;&lt;br /&gt;&lt;a target="_blank" href="http://myitforum.com/cs2/blogs/cmosby/archive/2009/06/18/directshow-exploit-in-the-wild-symantec-security-response-blog.aspx"&gt;http://myitforum.com/cs2/blogs/cmosby/archive/2009/06/18/directshow-exploit-in-the-wild-symantec-security-response-blog.aspx&lt;/a&gt;&lt;br /&gt;&lt;a target="_blank" href="https://forums2.symantec.com/t5/blogs/blogarticlepage/blog-id/vulnerabilities_exploits/article-id/198"&gt;https://forums2.symantec.com/t5/blogs/blogarticlepage/blog-id/vulnerabilities_exploits/article-id/198&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Technical Details on current exploit&lt;/strong&gt;&lt;br /&gt;&lt;a target="_blank" href="http://www.symantec.com/security_response/writeup.jsp?docid=2009-061001-1828-99&amp;amp;tabid=2"&gt;http://www.symantec.com/security_response/writeup.jsp?docid=2009-061001-1828-99&amp;amp;tabid=2&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; &lt;strong&gt;Key Microsoft Links&lt;/strong&gt;&lt;br /&gt;&lt;a target="_blank" href="http://www.microsoft.com/technet/security/advisory/971778.mspx"&gt;http://www.microsoft.com/technet/security/advisory/971778.mspx&lt;/a&gt;&lt;br /&gt;&lt;a target="_blank" href="http://support.microsoft.com/default.aspx/kb/971778"&gt;http://support.microsoft.com/default.aspx/kb/971778&lt;/a&gt;&lt;br /&gt;&lt;a target="_blank" href="http://blogs.technet.com/msrc/archive/2009/05/28/microsoft-security-advisory-971778-vulnerability-in-microsoft-directshow-released.aspx"&gt;http://blogs.technet.com/msrc/archive/2009/05/28/microsoft-security-advisory-971778-vulnerability-in-microsoft-directshow-released.aspx&lt;/a&gt;&lt;br /&gt;&lt;a target="_blank" href="http://blogs.technet.com/srd/archive/2009/05/28/new-vulnerability-in-quicktime-parsing.aspx"&gt;http://blogs.technet.com/srd/archive/2009/05/28/new-vulnerability-in-quicktime-parsing.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; &lt;strong&gt;Additional Links&lt;/strong&gt;&lt;br /&gt;&lt;a target="_blank" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1537"&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1537&lt;/a&gt;&lt;br /&gt;&lt;a target="_blank" href="http://secunia.com/advisories/35268"&gt;http://secunia.com/advisories/35268&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;QUOTE&lt;/strong&gt; (Secunia): According to Microsoft, the vulnerability is currently being actively exploited.&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1695827" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Autorun Worms - Infect more than just USB Flash Drives</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2009/06/15/autorun-worms-infect-more-than-just-usb-flash-drives.aspx" /><id>/blogs/harrywaldron/archive/2009/06/15/autorun-worms-infect-more-than-just-usb-flash-drives.aspx</id><published>2009-06-15T14:46:00Z</published><updated>2009-06-15T14:46:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-29.gif" alt="Music" /&gt; Microsoft is adjusting Autorun technology for XP to provide the improved safety Vista currently supports.&amp;nbsp; AVERT Labs shares an awareness that any portable storage device (e.g., MP3 player, Digital Picture frame, Digital Camera, etc) may also be vulnerable to Autorun malware attacks. Additionally, these worms&amp;nbsp;often infect unprotected network shares, as well as compromising accounts with weak passwords.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-53.gif" alt="Movie" /&gt; Autorun Worms - Infect more than just USB Flash Drives&lt;br /&gt;&lt;a href="http://www.avertlabs.com/research/blog/index.php/2009/06/11/worms-dig-further-than-thumb-drives/"&gt;http://www.avertlabs.com/research/blog/index.php/2009/06/11/worms-dig-further-than-thumb-drives/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt;&amp;nbsp;&amp;nbsp;Here&amp;rsquo;s a little quiz: Which of the following devices may be &lt;strong&gt;susceptible to AutoRun worms?&amp;nbsp; &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Answer - Most USB devices that you can plug into your computer that have storage&lt;/strong&gt;.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;How many of you have an &lt;strong&gt;MP3 player&lt;/strong&gt;? How many of you plug the device into more than one computer? Bingo, that&amp;rsquo;s a vector for replication. How about a &lt;strong&gt;digital video camera&lt;/strong&gt;, or a &lt;strong&gt;digital picture frame&lt;/strong&gt;? Yep, they can also be infected. Just imagine this one: &amp;ldquo;Here you go grandma, a picture of little Bobby. Oh, and a little surprise to go with it, as well.&amp;rdquo;&amp;nbsp; &lt;strong&gt;Devices such as MP3 players are just glorified storage drives with additional functions&lt;/strong&gt;. One unintended aspect of this functionality may be to assist in worm propagation.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1695457" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Windows Update - Resolving Download Failed issue for MS09-025</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2009/06/13/windows-update-resolving-download-failed-issue-for-ms09-025.aspx" /><id>/blogs/harrywaldron/archive/2009/06/13/windows-update-resolving-download-failed-issue-for-ms09-025.aspx</id><published>2009-06-13T14:53:00Z</published><updated>2009-06-13T14:53:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-31.gif" alt="Time" /&gt; In almost all cases, Windows Update (or &lt;strong&gt;preferably Microsoft Update&lt;/strong&gt;) works accurately.&amp;nbsp; I usually update manually right way without waiting on Automated Updates to start.&amp;nbsp; &lt;strong&gt;Windows Update can be immediately invoked&lt;/strong&gt;&amp;nbsp;by selecting the Windows Update option found in the IE8 Safety Shield icon&amp;nbsp;or other methods.&lt;/p&gt;
&lt;p&gt;All &lt;strong&gt;work PCs were updated without issues&lt;/strong&gt; for the June 2009 security updates.&amp;nbsp; However, I encountered a rare error on our family PC at home.&amp;nbsp; A total 10 of 11 updates were&amp;nbsp;downloaded and installed properly.&amp;nbsp; After rebooting, security update &lt;strong&gt;MS09-025&lt;/strong&gt; continued to experience &lt;strong&gt;&amp;quot;Download Failed&amp;quot;&lt;/strong&gt; message.&amp;nbsp; I noted a temporary folder on C: created by the June updates that may have been a factor.&lt;/p&gt;
&lt;p&gt;After 3 tries using Windows Update, I then went to &lt;a href="http://www.microsoft.com/downloads/en/default.aspx"&gt;&lt;strong&gt;Microsoft Download site&lt;/strong&gt;&lt;/a&gt; to manually&amp;nbsp;download the&amp;nbsp;MS09-025&amp;nbsp;patch.&amp;nbsp; As a starting point, I &lt;strong&gt;searched using keyword MS09-025 to locate the specific update&lt;/strong&gt; that needed to be applied.&amp;nbsp; After locating the XP security patch, I downloaded and installed this patch manually outside of the regular Windows Update process.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; &lt;strong&gt;Microsoft&amp;#39;s Download Site&lt;/strong&gt; &lt;br /&gt;&lt;em&gt;Search by bulletin or KB # to find a specific security update for your O/S&lt;br /&gt;&lt;/em&gt;&lt;a href="http://www.microsoft.com/downloads/en/default.aspx"&gt;http://www.microsoft.com/downloads/en/default.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;After successfully installing MS09-025 and rebooting, I &lt;strong&gt;reinvoked Windows Update to ensure there are no updates left to be applied&lt;/strong&gt;. This final step ensured the special manual update process was successful.&amp;nbsp; We are now properly up-to-date at home with these important protective patches.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1695210" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Opera 10 Beta - New Innovations</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2009/06/11/opera-10-beta-new-innovations.aspx" /><id>/blogs/harrywaldron/archive/2009/06/11/opera-10-beta-new-innovations.aspx</id><published>2009-06-11T16:40:00Z</published><updated>2009-06-11T16:40:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; I&amp;#39;ve used Opera as a complementary browser since the free &amp;quot;ad-bar&amp;quot; version first&amp;nbsp;surfaced several years ago.&amp;nbsp; Thankfully the ad bar was later removed and Opera has enjoyed a&lt;strong&gt; good track record in security, innovation, and web standards support&lt;/strong&gt;. While less popular than IE or Firefox, it offers a sophisticated and reliable browser environment.&amp;nbsp; It is working well so far in early testing.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Opera 10 Beta - New Innovations&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.eweek.com/c/a/Web-Services-Web-20-and-SOA/Opera-10-Beta-Adds-Turbo-Mode-Makes-Improvements-to-Tabbed-Windows-669426/"&gt;http://www.eweek.com/c/a/Web-Services-Web-20-and-SOA/Opera-10-Beta-Adds-Turbo-Mode-Makes-Improvements-to-Tabbed-Windows-669426/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt; The Opera 10 beta includes new features&amp;mdash;including a &lt;strong&gt;Turbo mode&lt;/strong&gt; that aims to speed slow connections&amp;mdash;that will likely find their way into rival browsers in the future.&amp;nbsp; &lt;strong&gt;Ever wonder what features will be found in the next generation of Web browsers? &lt;/strong&gt;Well, usually there&amp;rsquo;s one easy way to find out: Just check out the latest version of Opera.&amp;nbsp; Opera may not be the best known or most used Web browser out there, but, over the years, it has been one of the most innovative. Often, features that become mainstays across browsers appeared first in Opera.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Opera 10 Beta - Features&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.opera.com/browser/next/"&gt;http://www.opera.com/browser/next/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Opera 10 Beta - Download &lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.opera.com/browser/download/?ver=10.00b1"&gt;http://www.opera.com/browser/download/?ver=10.00b1&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Opera 10 Beta - Blog&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://my.opera.com/desktopteam/blog/"&gt;http://my.opera.com/desktopteam/blog/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Opera 10 Beta - New Features&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.opera.com/docs/changelogs/windows/1000b1/"&gt;http://www.opera.com/docs/changelogs/windows/1000b1/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-55.gif" alt="Idea" /&gt; &lt;strong&gt;KEY NEW FEATURES&lt;/strong&gt;&lt;br /&gt;* Opera Turbo Mode&lt;br /&gt;* Automatic updates&lt;br /&gt;* Crash logging&lt;br /&gt;* Inline spelling checker&lt;br /&gt;* 100/100 and pixel-perfect on the Acid3 test&lt;br /&gt;* Significantly improved performance, particularly on CSS/HTML rendering&lt;br /&gt;* Opera Mail HTML Compose support&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1695004" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Microsoft Security June 2009 Updates - IMPORTANT Patch Tuesday Updates</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2009/06/10/microsoft-security-june-2009-updates-important-patch-tuesday-updates.aspx" /><id>/blogs/harrywaldron/archive/2009/06/10/microsoft-security-june-2009-updates-important-patch-tuesday-updates.aspx</id><published>2009-06-11T00:15:00Z</published><updated>2009-06-11T00:15:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-31.gif" alt="Time" /&gt; &lt;strong&gt;Every monthly update should be applied as soon as possible&lt;/strong&gt;.&amp;nbsp;&amp;nbsp;Often we are racing against the clock to patch all systems to make them safer from exploits that will emerge or may already be found in-the-wild.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-30.gif" alt="Star" /&gt; The June 2009 security release has&amp;nbsp;&lt;strong&gt;10 security updates&lt;/strong&gt; that&amp;nbsp;cover&lt;strong&gt; 31 vulnerabilies&lt;/strong&gt; that apply to &lt;strong&gt;Windows, IE, Office, and&amp;nbsp;IIS&lt;/strong&gt;.&amp;nbsp; So far these installed updates&amp;nbsp;are working well and&amp;nbsp;without issues on my PCs.&amp;nbsp; As some of patched vulnerabilities have working exploits, it is important for everyone to &lt;strong&gt;PATCH NOW&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Microsoft Security June 2009 Updates - IMPORTANT Patch Tuesday Updates&lt;/strong&gt;&lt;br /&gt;&lt;a href="https://www.microsoft.com/technet/security/bulletin/ms09-jun.mspx"&gt;https://www.microsoft.com/technet/security/bulletin/ms09-jun.mspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;MS09-018 - Vulnerabilities in Active Directory Could Allow Remote Code Execution (971055)&lt;br /&gt;MS09-019 - Cumulative Security Update for Internet Explorer (969897)&lt;br /&gt;MS09-020 - Vulnerabilities in Internet Information Services (IIS) Could Allow Elevation of Privilege (970483)&lt;br /&gt;MS09-021 - Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (969462)&lt;br /&gt;MS09-022 - Vulnerabilities in Windows Print Spooler Could Allow Remote Code Execution (961501)&lt;br /&gt;MS09-023 - Vulnerability in Windows Search Could Allow Information Disclosure (963093)&lt;br /&gt;MS09-024 - Vulnerability in Microsoft Works Converters Could Allow Remote Code Execution (957632) &lt;br /&gt;MS09-025 - Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (968537)&lt;br /&gt;MS09-026 - Vulnerability in RPC Could Allow Elevation of Privilege (970238)&lt;br /&gt;MS09-027 -&amp;nbsp; Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (969514)&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#810081;"&gt;&lt;img src="http://msmvps.com/emoticons/emotion-55.gif" alt="Idea" /&gt; &lt;strong&gt;Excellent Analysis of updates&lt;/strong&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=6538"&gt;http://isc.sans.org/diary.html?storyid=6538&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blog.trendmicro.com/june-2009-microsoft-and-adobe-security-updates/"&gt;http://blog.trendmicro.com/june-2009-microsoft-and-adobe-security-updates/&lt;/a&gt;&lt;br /&gt;&lt;a href="https://forums2.symantec.com/t5/blogs/blogarticlepage/blog-id/vulnerabilities_exploits/article-id/197"&gt;https://forums2.symantec.com/t5/blogs/blogarticlepage/blog-id/vulnerabilities_exploits/article-id/197&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1694930" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Microsoft asking for help with SysInternals Survey </title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2009/06/10/microsoft-asking-for-help-with-sysinternals-survey.aspx" /><id>/blogs/harrywaldron/archive/2009/06/10/microsoft-asking-for-help-with-sysinternals-survey.aspx</id><published>2009-06-10T13:53:00Z</published><updated>2009-06-10T13:53:00Z</updated><content type="html">&lt;p&gt;&lt;strong&gt;Microsoft asking for help with SysInternals Survey &lt;br /&gt;&lt;/strong&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=6544"&gt;http://isc.sans.org/diary.html?storyid=6544&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE&lt;/strong&gt;: Hands-down the best tools for determining what is going on on a Windows system are Mark Russinovich&amp;#39;s and Bryce Cogswell&amp;#39;s Sysinternals Tools.&amp;nbsp; Frequent contributor Roseman has pointed out that Microsoft is asking for your help improving the Sysinternals tools. Over at the Microsoft Technet blog they are requesting Sysinternals users to take a short survey.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/sysinternals/archive/2009/06/08/short-sysinternals-customer-survey.aspx"&gt;http://blogs.technet.com/sysinternals/archive/2009/06/08/short-sysinternals-customer-survey.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE&lt;/strong&gt;: Sysinternals Customer Survey &amp;ndash; We could use your help.&amp;nbsp; We&amp;#39;re looking into who uses the Sysinternals tools and what other Microsoft tools you use. Please take this very short questionnaire (7 questions max. depending on how you answer). We won&amp;rsquo;t ask you who you are, your email or anything that can identify you. - Thanks&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1694901" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry><entry><title>Conficker still infecting approximately 50,000 PCs daily</title><link rel="alternate" type="text/html" href="/blogs/harrywaldron/archive/2009/06/10/conficker-still-infecting-approximately-50-000-pcs-daily.aspx" /><id>/blogs/harrywaldron/archive/2009/06/10/conficker-still-infecting-approximately-50-000-pcs-daily.aspx</id><published>2009-06-10T12:51:00Z</published><updated>2009-06-10T12:51:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://msmvps.com/emoticons/emotion-37.gif" alt="Storm" /&gt;&amp;nbsp; Recently, I saw articles stating that the Gumblar website injection attacks were gaining strength and could become worse than Conficker.&amp;nbsp; Gumblar was a very sophisticated malware attack, that took off like wildfire a couple of weeks ago.&amp;nbsp; Thankfully, this new threat has almost faded away, as the malware hosting websites were quickly shutdown by authorities. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Experts: Gumblar attack is alive, worse than Conficker&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://news.cnet.com/8301-1009_3-10251779-83.html"&gt;http://news.cnet.com/8301-1009_3-10251779-83.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Gumblar Attacks Dying Off&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://blogs.pcmag.com/securitywatch/2009/06/gumblar_attacks_dying_off.php"&gt;http://blogs.pcmag.com/securitywatch/2009/06/gumblar_attacks_dying_off.php&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Conficker is still alive and well, as it continues to infect up to 50,000 PCs daily. Users need to stay up-to-date on all security updates and AV protection.&amp;nbsp; We should follow major evolving threats, as sophisticated stealth attacks continue to circulate. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Conficker still infects approximately 50,000 PCs daily&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://viewfromthebunker.com/2009/05/20/conficker-continues-to-spread/"&gt;http://viewfromthebunker.com/2009/05/20/conficker-continues-to-spread/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.networkworld.com/news/2009/052109-conficker-still-infecting-50000-pcs.html"&gt;http://www.networkworld.com/news/2009/052109-conficker-still-infecting-50000-pcs.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;QUOTE:&lt;/strong&gt; The worm is infecting about &lt;strong&gt;50,000 new PCs each day&lt;/strong&gt;, according to researchers at Symantec, who reported Wednesday that the U.S., Brazil and India have been hit the hardest.. &amp;quot;Much of the media hype seems to have died down around Conficker/Downadup, but &lt;strong&gt;it is still out there spreading far and wide&lt;/strong&gt;,&amp;quot; Symantec said in a blog post.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1694900" width="1" height="1"&gt;</content><author><name>harry</name><uri>http://msmvps.com/members/harry/default.aspx</uri></author></entry></feed>