<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Spyware Sucks : I ain't happy about this....., Internet Explorer 7</title><link>http://msmvps.com/blogs/spywaresucks/archive/tags/I+ain_2700_t+happy+about+this_2E00__2E00__2E00__2E00__2E00_/Internet+Explorer+7/default.aspx</link><description>Tags: I ain't happy about this....., Internet Explorer 7</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Always pay attention when you install software updates, otherwise you may end up with unwanted add-ins (and foot-in-mouth-disease)</title><link>http://msmvps.com/blogs/spywaresucks/archive/2007/01/13/487544.aspx</link><pubDate>Sat, 13 Jan 2007 04:23:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:487544</guid><dc:creator>sandi</dc:creator><slash:comments>1</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=487544</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2007/01/13/487544.aspx#comments</comments><description>&lt;P&gt;It would be real nice if Andy Beal and his comrades in arms in various online news sites would concentrate more on accuracy, and less on sensationalism.&amp;nbsp; If there is one thing that is sure to raise my hackles, it is misinformation, and grudging "updates".&amp;nbsp; &lt;/P&gt;
&lt;P&gt;There was an article posted on marketingpilgrim.com today, with the by-line "&lt;STRONG&gt;&lt;A class="" href="http://www.marketingpilgrim.com/2007/01/yahoo-switching-ie7-settings-without-permission.html" target=_blank&gt;Exclusive - Yahoo Using Dirty Tactics to Switch Google &amp;amp; Firefox Users?&lt;/A&gt;"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The article states &lt;EM&gt;"Over email, Jarrod Hunt of Text Link Brokers explained how a recent upgrade to Yahoo Messenger includes an innocuous “auto-update” option. When the user gives Yahoo permission to “update” – what they think is just Yahoo Messenger – the updater downloads IE 7 (which we already know to be buggy) and then proceeds to hijack many browser preferences – including search engine settings."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;This is what happened.&amp;nbsp; "Jarrod" uses Yahoo Messenger.&amp;nbsp; Yahoo Messenger prompted Jarrod to install an update.&amp;nbsp; Jarrod agreed.&amp;nbsp; Jarrod went with the default install.&amp;nbsp; Jarrod ended up with an updated Yahoo Mesenger, but he also ended up with the Yahoo Toolbar, his home page was changed, and his search engine defaults were changed.&amp;nbsp; Jarrod accused Yahoo Messenger of installing IE7.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Yahoo Messenger does NOT install IE7&lt;/STRONG&gt;, and it took a comment posted more than&amp;nbsp;8 hours after the article went live stating &lt;EM&gt;"This story is a lie"&lt;/EM&gt; for Jarrod to finally&amp;nbsp;decide to check what version of IE he actually had installed, something that I suggest he should have done in the first place.&lt;/P&gt;
&lt;P&gt;So what went wrong for marketingpilgrim?&amp;nbsp; How&amp;nbsp;could they get something so wrong, and allow an article&amp;nbsp;with such a basic technical inaccuracy to go live?&lt;/P&gt;
&lt;P&gt;First, Jarrod saw that he had tabbed browsing and he assumed that he had IE7, not realising that it was the Yahoo Toolbar that was creating the tabs as we can see from a comment that he posted more than 9 hours after the article went live that&amp;nbsp;said &lt;EM&gt;"I’m looking at the version number in IE. It’s still IE6. I assumed that the new “Tabs” I was seeing were because of an upgrade to IE7. I have had IE6 for years now, and did not plan on upgrading.&amp;nbsp; The new tabs I am seeing are part of Yahoo’s new toolbar. Don’t I feel like an Ass."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Ok, so maybe we can forgive Jarrod his knee-jerk assumptions when he saw the changes on his system.&amp;nbsp; He is obviously unfamiliar with IE7.&amp;nbsp; But why the heck would he automatically assume he has IE7 just because he has tabs?&amp;nbsp; For example, the MSN toolbar gives IE6 users tabs&amp;nbsp;and there are lots of skins and add-ons out there that give IE6 tabs.&amp;nbsp; Not only that, the IE7 GUI changes are far more than just adding tabs to the Web browser as you can see if you check out the screenshots at &lt;A class="" href="http://www.ie-vista.com/" target=_blank&gt;www.ie-vista.com&lt;/A&gt;.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Putting aside the GUI issue, I am also concerned that if Jarrod is unfamiliar with even the basics of IE7 such as what it looks like, then how is he in a position to make an informed judgment about whether or not IE7 should or shouldn't be installed?&amp;nbsp; I see a need for some research on Jarrod's part because IE7 brings with it very important security benefits - IE7, for example, was NOT vulnerable to virtually all of the exploits disclosed since it went into beta last year.&lt;/P&gt;
&lt;P&gt;Andy Beal, on the other hand, is harder to forgive.&amp;nbsp; It seems he &lt;U&gt;did not check&amp;nbsp;his facts&lt;/U&gt; before publishing the article.&amp;nbsp; Did he write to Yahoo and ask for their comments BEFORE going live?&amp;nbsp; Did he wait for a response?&amp;nbsp; Did he install Yahoo Messenger to make sure that he could confirm the bona fides of Jarrod's complaint before going live?&lt;/P&gt;
&lt;P&gt;Third, IE7 is not "buggy".&amp;nbsp; There have now been over 100 million installations of IE7, and if marketingpilgrim's claims about IE7 being buggy were true then my sites, my forums and the newsgroups would be flooded with complaints.&amp;nbsp; Instead, we are seeing no more than the normal problems that occur when software is updated - it is not technically possible to cover all scenarios, and problems do slip through (such as the printing bug a minority of users are having problems with), but that is no reason to advise *everybody* to avoid IE7.&amp;nbsp; Reality is that users are far more likely to be part of the majority who have no problems, than the minority that do.&lt;/P&gt;
&lt;P&gt;I've just checked the "&lt;A class="" href="http://www.marketingpilgrim.com/2006/02/microsoft-ie-70-sucks.html" target=_blank&gt;IE7 is buggy&lt;/A&gt;" column that the article links to - it is dated &lt;STRONG&gt;1 February 2006&lt;/STRONG&gt; and discusses a BETA of IE7 for chrissakes - not only that, it seems that the author tried System Restore *before* going to, you guessed it, Add/Remove Programs, to remove IE7 - he&amp;nbsp;did things ass-backwards.&amp;nbsp; Web sites not displaying properly? That's not an IE7 bug - its actually a problem caused by IE6 in that the affected sites were using various hacks to get around IE6 problems - problems that no longer exist in IE7.&amp;nbsp; IE7 introduced many improvements to CSS compliance, and got rid of some long-standing, often complained about rendering bugs.&amp;nbsp; We knew that there was going to be problems for site owners that used various IE6 specific hacks, and we did all we could to warn site owners during the beta, but it seems the author of that article would prefer the IE6 rendering faults to remain rather than be fixed?&amp;nbsp; As for the 30 blank browser sessions, they are easily fixed, being&amp;nbsp;a simple file type association mis-set.&lt;/P&gt;
&lt;P&gt;Please let me make this perfectly clear.&amp;nbsp; I hate software bundling, and have said so on this blog many times.&amp;nbsp; I hate it that so many free products try to install toolbars or change my Web browser settings, whether it be Yahoo Messenger, or MSN Messenger, or Adobe Acrobat, or Sun Java or the myriad other products that try to do the same thing.&amp;nbsp; The CNET article is right insofar as the default install of Yahoo Messenger changes your Web browsers home page and search engine settings an adds a toolbar and the Yahoo Messenger installation does NOT make it clear that these things will happen.&amp;nbsp; It should NOT be necessary to select 'customise your install' or 'custom install' before you can see the tick boxes for the additional changes.&amp;nbsp; But that being said, my strong dislike for bundling does not cancel out a similarly strong dislike for misinformation.&lt;/P&gt;
&lt;P&gt;If you want to see what happens when Yahoo Messenger is updated, check out this video - for me, at least, the video quality sucks, but at least you can hear the commentary:&lt;BR&gt;&lt;A class="" href="http://news.com.com/1606-2-6144280.html" target=_blank&gt;http://news.com.com/1606-2-6144280.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=487544" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer+7/default.aspx">Internet Explorer 7</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/I+ain_2700_t+happy+about+this_2E00__2E00__2E00__2E00__2E00_/default.aspx">I ain't happy about this.....</category></item><item><title>Internet Explorer 7 Beta 2 Preview Build 5335.5 comes with a little extra tweaking...</title><link>http://msmvps.com/blogs/spywaresucks/archive/2006/03/21/87126.aspx</link><pubDate>Tue, 21 Mar 2006 10:54:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:87126</guid><dc:creator>sandi</dc:creator><slash:comments>1</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=87126</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2006/03/21/87126.aspx#comments</comments><description>&lt;P&gt;&lt;FONT color=#0000ff&gt;&lt;FONT color=#000000&gt;Heads up:&amp;nbsp; the latest IE7 Beta 2 Preview Build seems to include the activex 912945 update described here:&lt;/FONT&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2006/03/04/85409.aspx"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;http://msmvps.com/blogs/spywaresucks/archive/2006/03/04/85409.aspx&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Ok, this is a surprise and a shock.&amp;nbsp; Maybe I've simply missed an announcement or heads up, but I don't remember any mention of the 912945 update being included in build 5335.5.&lt;/P&gt;
&lt;P&gt;Granted, the changes will be included in the next security update, but it would have been nice to have some warning.&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=87126" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer+7/default.aspx">Internet Explorer 7</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/I+ain_2700_t+happy+about+this_2E00__2E00__2E00__2E00__2E00_/default.aspx">I ain't happy about this.....</category></item><item><title>TrendMicro Antispyware for the Web causing issues again - this time nuking the Windows Genuine Validation Tool</title><link>http://msmvps.com/blogs/spywaresucks/archive/2006/03/11/85979.aspx</link><pubDate>Sat, 11 Mar 2006 00:46:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:85979</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=85979</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2006/03/11/85979.aspx#comments</comments><description>&lt;P&gt;&lt;STRONG&gt;&lt;FONT color=#ff0000&gt;Important Update: &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2006/03/15/86345.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2006/03/15/86345.aspx&lt;/A&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;This could prove to be a very serious problem.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;The Windows Genuine Advantage Validation Tool *must* be installed before many downloads are made available to users via Windows Update and the Download Centre.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Trend Micro Antispyware for the Web&amp;nbsp;is&amp;nbsp;detecting the Windows Genuine Advantage Validation Tool KB892130&amp;nbsp;CLSID as Adware_iSearch.&amp;nbsp; Once the CLSID is deleted by TMAS, the user will be re-prompted to download KB892130 the next time he or she goes to Windows Update.&lt;/P&gt;
&lt;P&gt;Check out this thread:&lt;BR&gt;&lt;A href="http://aumha.net/viewtopic.php?t=18492&amp;amp;postdays=0&amp;amp;postorder=asc&amp;amp;start=0"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;http://aumha.net/viewtopic.php?t=18492&amp;amp;postdays=0&amp;amp;postorder=asc&amp;amp;start=0&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I'm going to pass this on to George&amp;nbsp;and Andy at Trend... we need to make sure that SMB product is not being affected in the same way - I'm betting it is.&lt;/P&gt;
&lt;P&gt;Generally the Corporate (SMB) version is updated very quickly when false positives like this are found.&amp;nbsp; Those responsible for the&amp;nbsp;consumer space, including online web scan&amp;nbsp;are much slower to react.&amp;nbsp; &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2005/06/22/54453.aspx"&gt;&lt;FONT color=#0000ff&gt;&lt;STRONG&gt;Trend's history of delay&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;STRONG&gt; in fixing false positives in the consumer versions of Antispyware&amp;nbsp;will be a big problem this time.&amp;nbsp; Please guys, let's get this sorted damned fast.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Charles (aka Chasbox in the&amp;nbsp;aumha.net forum)&amp;nbsp;did very well to draw the connection between TMAS and the Windows Update problem he is seeing. I've confirmed the problem on several PCs.&lt;/P&gt;
&lt;P&gt;Here is the alert.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;IMG src="/photos/spyware_sucks/images/85969/original.aspx"&gt;&lt;/P&gt;
&lt;P&gt;The threat details:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;IMG src="/photos/spyware_sucks/images/85972/original.aspx"&gt;&lt;/P&gt;
&lt;P&gt;The CLSID key being flagged:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;IMG src="/photos/spyware_sucks/images/85974/original.aspx"&gt;&lt;/P&gt;
&lt;P&gt;The key you see is the *only* entry in the Ext folder, therefore must be the source of the alert.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT color=#ff0000&gt;DO NOT ALLOW THE TREND PROGRAMME TO DELETE THE CLSID&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;BTW, Trend Micro Antispyware&amp;nbsp;on the Web seems to be broken in IE7, at least it is for me... had to fire up IE6 on another PC on my network to confirm the false positive.&amp;nbsp; Its a bit hard to select 'Start Scan' when there's no scan button to click on... ;o)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;IMG src="/photos/spyware_sucks/images/85977/original.aspx"&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color=#000000&gt;------------------------------------------------------------------------------&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color=#000000&gt;Update - 12 March 06, 12.10am Perth, WA time (+0800): The false positive has, apparently, been fixed for the &lt;U&gt;packaged product&lt;/U&gt; (pattern 3.31) since 10 March, but NOT the online scan.&amp;nbsp; I know, because I tested the online scan 10 minutes ago.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color=#000000&gt;This is a source of ongoing frustration to me.&amp;nbsp; The packaged product is fixed quickly when a false positive, but the online scan can be left, at times, for months.&amp;nbsp; I despair.&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=85979" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer+7/default.aspx">Internet Explorer 7</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/I+ain_2700_t+happy+about+this_2E00__2E00__2E00__2E00__2E00_/default.aspx">I ain't happy about this.....</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer/default.aspx">Internet Explorer</category></item><item><title>Not happy with Softwarepatch.com</title><link>http://msmvps.com/blogs/spywaresucks/archive/2006/02/05/82579.aspx</link><pubDate>Sun, 05 Feb 2006 09:52:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:82579</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=82579</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2006/02/05/82579.aspx#comments</comments><description>&lt;P&gt;Softwarepatch.com are publicising the IE7 Beta 2 Preview on their site:&lt;BR&gt;&lt;A href="http://www.softwarepatch.com/windows/"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;http://www.softwarepatch.com/windows/&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The site makes no mention of the fact that there are Release Notes available (which, as far as I am concerned,&amp;nbsp;is essential reading), nor does it mention that the download is targeted at Developers and IT Professionals.&amp;nbsp; There is no mention of where and how to get support, nothing about the Developer and IT Pro checklists, nothing about the Technology Overview that is available.&amp;nbsp; All there is is a generic warning about installing Betas.&lt;/P&gt;
&lt;P&gt;And, they're wrong - its not "Beta 2" - it is a *Preview* of what Beta 2, when it is released, will be like.&lt;/P&gt;
&lt;P&gt;I don't think it is a good idea for a third party site to link directly to the IE7 download while at the same time ignoring the documentation that goes with it.&amp;nbsp; If softwarepatch want to pull hits to their site by publicising IE7 Beta 2 Preview then they should link to the Microsoft download page so that their readers get the benefit of the content that is available at &lt;A href="http://www.microsoft.com/windows/ie/ie7/ie7betaredirect.mspx"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;http://www.microsoft.com/windows/ie/ie7/ie7betaredirect.mspx&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=82579" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer+7/default.aspx">Internet Explorer 7</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/I+ain_2700_t+happy+about+this_2E00__2E00__2E00__2E00__2E00_/default.aspx">I ain't happy about this.....</category></item></channel></rss>