<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Spyware Sucks : Internet Explorer, Vulnerabilities, viruses and exploits, Security, safety and privacy on the Internet</title><link>http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer/Vulnerabilities_2C00_+viruses+and+exploits/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx</link><description>Tags: Internet Explorer, Vulnerabilities, viruses and exploits, Security, safety and privacy on the Internet</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>ALERT: Out of band security patch to be released tomorrow, 17 December at 10.00am Pacific time</title><link>http://msmvps.com/blogs/spywaresucks/archive/2008/12/17/1656924.aspx</link><pubDate>Tue, 16 Dec 2008 21:14:56 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1656924</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1656924</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/12/17/1656924.aspx#comments</comments><description>&lt;p&gt;Announcement here:&lt;br /&gt;&lt;a title="http://blogs.technet.com/msrc/archive/2008/12/16/advance-notification-for-december-2008-out-of-band-release.aspx" target="_blank" href="http://blogs.technet.com/msrc/archive/2008/12/16/advance-notification-for-december-2008-out-of-band-release.aspx"&gt;http://blogs.technet.com/msrc/archive/2008/12/16/advance-notification-for-december-2008-out-of-band-release.aspx&lt;/a&gt;&lt;/p&gt; &lt;p&gt;The patch resolves the actively exploited vulnerability that has been in the press so much in recent days, and which is the subject of this Security Advisory:&lt;br /&gt;&lt;a title="http://www.microsoft.com/technet/security/advisory/961051.mspx" target="_blank" href="http://www.microsoft.com/technet/security/advisory/961051.mspx"&gt;http://www.microsoft.com/technet/security/advisory/961051.mspx&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1656924" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer+7/default.aspx">Internet Explorer 7</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer/default.aspx">Internet Explorer</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer+8/default.aspx">Internet Explorer 8</category></item><item><title>MS06-042 has been re-released</title><link>http://msmvps.com/blogs/spywaresucks/archive/2006/08/24/109380.aspx</link><pubDate>Thu, 24 Aug 2006 22:24:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:109380</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=109380</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2006/08/24/109380.aspx#comments</comments><description>&lt;P&gt;The problematic MS06-042 update has been re-released:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS06-042.mspx"&gt;http://www.microsoft.com/technet/security/Bulletin/MS06-042.mspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Hotfix 923782 has been replaced by the new security update 918899. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=109380" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer/default.aspx">Internet Explorer</category></item><item><title>Possible fixes for crashes caused by MS06-042 (KB918899)</title><link>http://msmvps.com/blogs/spywaresucks/archive/2006/08/12/107385.aspx</link><pubDate>Fri, 11 Aug 2006 23:51:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:107385</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=107385</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2006/08/12/107385.aspx#comments</comments><description>&lt;P&gt;&lt;STRONG&gt;Note: An new version of 918899 was planned for release by 22 August for **IE6 SP1** users.&amp;nbsp; Unfortunately, an issue with the new version has forced the delay of&amp;nbsp;the updated patch for a few days, but it has now been released.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I am very grateful for, and indebted to, some pretty amazing people and resources that actively share information about problems with patches and security issues.&amp;nbsp; Its thanks to those resources that I am able to pass on information such as that in this post which has been combined from information in a couple of lists, one security focused, one related to patch management ..... so thanks all &lt;img src="/emoticons/emotion-1.gif" alt="Smile" /&gt;&lt;/P&gt;
&lt;P&gt;There are reports of MS06-042 causing crashes when PeopleSoft is installed.&amp;nbsp; One noted crash involves 0xC0000005 in NTDLL.DLL&lt;/P&gt;
&lt;P&gt;Affected OS listed in the KB are IE6SP1 installations on the following operating systems:&lt;/P&gt;
&lt;P&gt;Microsoft Windows XP Professional (SP1 only?)&lt;BR&gt;Microsoft Windows XP Home Edition (SP1 only?)&lt;BR&gt;Microsoft Windows 2000 Professional Edition (???)&lt;BR&gt;Microsoft Windows 2000 Service Pack 4 &lt;BR&gt;Microsoft Windows 2000 Advanced Server (???)&lt;/P&gt;
&lt;P&gt;The fix for people using PeopleSoft, taken from the windows.update newsgroup, is:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;In PIA, navigate to "PeopleTools -&amp;gt; Web Profile -&amp;gt; Web Profile Configurations". Search for your webprofile. In the "General" tab, uncheck the following: &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Compress Responses = unchecked &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Compress Response References = unchecked &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Compress Query = unchecked [If you have PT8.44, please ignore since Compress Query does exist in PT8.44] &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Save your webprofile changes and you must bounce your PIA.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Another suggested fix is to disable "Use HTTP 1.1" via IE Tools, Internet Options, Advanced Tab:&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Note, a hotfix is available if this fixes your problem.&amp;nbsp; Internet Explorer 6 Service Pack 1 unexpectedly exits after you install the 918899 update&lt;BR&gt;&lt;A href="http://support.microsoft.com/kb/923762/en-us"&gt;http://support.microsoft.com/kb/923762/en-us&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Sage CRM and CA Unicentre users - try the workaround and the hotfix - do not uninstall the patch unless you have no other alternative (SAGE... &lt;A href="http://www.21crm.ca/newsl/TechFlashAug162006.htm"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;you need to work out the difference between a PATCH and&amp;nbsp;a SERVICE PACK&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;)&amp;nbsp; (SANS - &lt;A href="http://isc.sans.org/diary.php?storyid=1607"&gt;why are you not suggesting the workaround or hotfix&lt;/A&gt;&amp;nbsp;instead of install IE7, uninstall the patch, or use a different browser???)&lt;/P&gt;
&lt;P&gt;Another suggested fix is to uninstall MS06-042, edit the registry to ensure the following key exists, reinstall MS06-042, then reboot:&lt;/P&gt;
&lt;P&gt;[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer]&lt;BR&gt;"QFEInstalled"=dword:00000001&lt;/P&gt;
&lt;P&gt;The Technet article is here:&lt;BR&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS06-042.mspx"&gt;http://www.microsoft.com/technet/security/Bulletin/MS06-042.mspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Good luck all, I hope this helps.&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=107385" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer/default.aspx">Internet Explorer</category></item><item><title>Cumulative update for Internet Explorer released (MS06-042, KB918899)</title><link>http://msmvps.com/blogs/spywaresucks/archive/2006/08/08/107084.aspx</link><pubDate>Tue, 08 Aug 2006 22:26:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:107084</guid><dc:creator>sandi</dc:creator><slash:comments>10</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=107084</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2006/08/08/107084.aspx#comments</comments><description>&lt;P&gt;Information here:&lt;BR&gt;&lt;A href="http://support.microsoft.com/?kbid=918899"&gt;http://support.microsoft.com/?kbid=918899&lt;/A&gt;&lt;BR&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/ms06-042.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms06-042.mspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I note that Siebel will finally be releasing an update to address the changes forced to activex by the EOLAS suit during Spring of 2006 (NH spring, not SH)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=107084" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer/default.aspx">Internet Explorer</category></item><item><title>Fix: Internet Explorer freezes when using the drop-down address bar list when the fix described in KB908531 is installed</title><link>http://msmvps.com/blogs/spywaresucks/archive/2006/04/14/90914.aspx</link><pubDate>Fri, 14 Apr 2006 05:28:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:90914</guid><dc:creator>sandi</dc:creator><slash:comments>10</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=90914</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2006/04/14/90914.aspx#comments</comments><description>&lt;SPAN&gt;&lt;FONT face=Calibri&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;&lt;EM&gt;Note, HP and Kerio are NOT the only software affected by the problems described in the KB article 918165.&amp;nbsp; Older NVIDIA software is also implicated, and as the KB article states, there may be other third party COM controls or shell extensions causing a problem. In short, don't assume that just because you don't have NVIDIA, HP or Kerio that you'll be safe or that your problems can't be caused by the MS06-015 update.&amp;nbsp; I have personal experience of people being hit by this problem who have none of that software:&lt;BR&gt;&lt;/EM&gt;&lt;A href="http://support.microsoft.com/kb/918165"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;&lt;EM&gt;http://support.microsoft.com/kb/918165&lt;/EM&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;(I have no idea why Stephen ***'s surname doesn't appear properly - all I see is three stars instead of a surname...)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;&lt;A href="http://groups.google.com/group/microsoft.public.windows.inetexplorer.ie6.browser/msg/094143b42d0c3ca2"&gt;&lt;FONT color=#0000ff&gt;Stephen *** of Microsoft has posted to ie6.browser newsgroup&lt;/FONT&gt; &lt;/A&gt;regarding a known problem with MS06-15 / KB908531 wherein Internet Explorer may freeze when you attempt to use the drop-down list in the Address Bar.&amp;nbsp; MS have tracked down the cause of the problem, and it is wide spread enough to be deserving of publicity.&amp;nbsp; I am sure Stephen will forgive me for quoting him verbatim rather than sending you off to the newgroup via Outlook Express or the Communities Web Interface.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;&amp;lt;quote&amp;gt; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;We've determined that the majority of the issues people are having with MS06-015 / KB908531 are due to a bad interaction between the security update and a software component included with various HP hardware devices, including but not limited to printers, scanners, and cameras. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;Here are two fixes which should fix problems caused by the interaction with the HP software:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;Option 1 - Modify the registry&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;BR&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;------------------------------&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;- (If you have multiple user accounts set up) Log onto the computer using an account with Administrator privileges&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;- Click the Start button, then click Run and type "regedit" at the prompt, without the quotes; this will start Registry Editor&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;- Locate the &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached key in Registry Editor&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;- Right click on the key and select New / DWORD Value&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;- Rename the resulting value "{A4DF5659-0801-4A60-9607-1C48695EFDA9} {000214E6-0000-0000-C000-000000000046} 0x401", without the quotes&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;- Right click the value, select Modify, and type "1" into the Value Data field&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;- Close Registry Editor&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;Option 2 - Kill the HP process&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;BR&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;------------------------------&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;- Wait until Internet Explorer, Windows Explorer, or whichever component is encountering problems is in an unresponsive state&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;- Click the Start button, then select Run and type "taskmgr" at the prompt, without the quotes; this will start Task Manager&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;- Locate any instances of hpgs2wnd.exe or hpgs2wnf.exe in Task Manager, then right click on them and select End Process&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;(Note: Option 2 this may disable some HP device-specific functionality until you restart your computer.)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;If your computer is not currently unresponsive, you should only have to do Option 1 or Option 2, not both.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;If your computer is currently unresponsive, you should be fixed by doing Option 2.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;I'm very sorry about the inconvenience this has caused you all; hopefully this will get things back on track.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Please note that MS06-015 fixes a critical security vulnerability, so it's very important that you reinstall it as soon as possible if you've uninstalled it.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Please also keep in mind that disabling Auto Update will leave your computer unprotected even after we release security updates.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;I understand that this experience has been very frustrating for many of you, but I really must still strongly recommend that you leave Auto Update enabled for your own safety. &amp;lt;/quote&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;Addendum:&lt;SPAN&gt;&amp;nbsp; &amp;lt;quote&amp;gt; &lt;/SPAN&gt;Actually, it appears that I spoke too soon.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Option 2 will correct the problem for the logged-in user, but not for all users on a computer with multiple user accounts.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;For that reason, Option 1 is the preferred option. &amp;lt;/quote&amp;gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=90914" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer+7/default.aspx">Internet Explorer 7</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer/default.aspx">Internet Explorer</category></item><item><title>The eEye hack for the createTextRange vulnerability</title><link>http://msmvps.com/blogs/spywaresucks/archive/2006/03/29/88277.aspx</link><pubDate>Tue, 28 Mar 2006 23:25:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:88277</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=88277</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2006/03/29/88277.aspx#comments</comments><description>&lt;P&gt;Summary:&amp;nbsp; My advice? Don't install it.&lt;/P&gt;
&lt;P&gt;(Please forgive any grammatical or logical flow errors - I'm running real short of time but wanted to get this live before starting my work day).&lt;/P&gt;
&lt;P&gt;Two MS security bloggers have mentioned the eEye "patch" that protects against the createTextRange vulnerability.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/msrc/default.aspx"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;http://blogs.technet.com/msrc/default.aspx&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;BR&gt;&lt;A href="http://blogs.technet.com/ms_schweiz_security_blog/default.aspx"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;http://blogs.technet.com/ms_schweiz_security_blog/default.aspx&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Both bloggers recommend that the patch not be installed.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Ok, I admit - the vulnerability is being exploited. That's bad.&amp;nbsp; But, at the same time we need to have a realistic look at what is going on and compare risk to reward.&amp;nbsp; On balance, after considering all the information I'm privy to (public and private) I have to say that I agree - do not install the third party patch.&lt;/P&gt;
&lt;P&gt;Historically, third party patches and hacks have been problematic.&amp;nbsp; Let's look at a couple of recent examples.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;U&gt;WMF Exploit hack&lt;/U&gt;&lt;BR&gt;The WMF exploit patch was messy - to get the file to stick you had to mess around with cached copies of the file (gdi32.dll is protected by Windows File Protection).&amp;nbsp; The changed file was also causing Windows Update to offer old security patches.&amp;nbsp; Deregistering shimgvw.dll stopped Windows Picture and Fax Viewing from working.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;U&gt;The IE6/IE7 side by side hack&lt;/U&gt;&lt;BR&gt;The IE6/IE7 side by side hack caused various symptoms, including opening a browser window that promptly hangs IE, opening links that render blank, and multiple windows opening when initiating a browser session.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;The eEye hack (I refuse to call it a patch) doesn't fix the CreateTextRange vulnerability... it messes around with how Windows works.&amp;nbsp; We have no way of knowing what may be broken by this change.&lt;/P&gt;
&lt;P&gt;"Ah, but at least I'll be safe" I hear you say.&amp;nbsp; "Safe from what?" says I.&amp;nbsp; Let me explain.&lt;/P&gt;
&lt;P&gt;First, according to &lt;A href="http://www.microsoft.com/technet/security/advisory/917077.mspx"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;http://www.microsoft.com/technet/security/advisory/917077.mspx&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt; "Antivirus companies indicate that attacks that exploit this vulnerability are being effectively mitigated by antivirus software with up-to-date signatures".&amp;nbsp; The antivirus companies that have confirmed they provide protection against known vectors include:&lt;/P&gt;
&lt;P&gt;Symantec&lt;BR&gt;Computer Associates&lt;BR&gt;McAfee&lt;BR&gt;F-Secure Corporation&lt;BR&gt;Panda Software International&lt;BR&gt;Aladdin&lt;BR&gt;Sophos&lt;BR&gt;Eset Software&lt;BR&gt;Trend Micro&lt;BR&gt;Windows Live OneCare&lt;BR&gt;&amp;nbsp;&lt;BR&gt;Do you have up-to-date antivirus? Does it detect files that attempt to exploit the vulnerability?&amp;nbsp; If so, why take the risk with a third party hack?&lt;/P&gt;
&lt;P&gt;Second, sure there are lists going around warning that there are hundreds of sites that are taking advantage of the exploit.&amp;nbsp; But, actually hitting one of those sites is needle-in-a-haystack stuff.&amp;nbsp; Seriously.&amp;nbsp; I've seen real-world, whats-actually-happening statistics that convince me that the risk of being hit by the exploit is not sufficient to risk damage that may be caused to a system's operation by the eEye changes.&lt;/P&gt;
&lt;P&gt;On balance, considering the fact that MS and law enforcement have been very proactive in getting exploit sites shut down, considering the fact that there are not "hundreds" of sites out there (the number is far lower than that), considering the list of antivirus programmes that protect against known vectors, considering the fact that you'll have to be *real* unlucky to hit one of the sites that is still live without being taken by the hand and shown how to get there, and considering there are safer ways to protect yourself against the risk of exploit (disable active scripting or set to prompt), I say don't install the patch.&lt;/P&gt;
&lt;P&gt;BTW, SANS Internet Storm Centre agrees - not with me per se, but with the risk assessment that the eEye patch shouldn't be installed:&lt;BR&gt;&lt;A href="http://www.incidents.org/diary.php?storyid=1226"&gt;&lt;STRONG&gt;http://www.incidents.org/diary.php?storyid=1226&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=88277" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer+7/default.aspx">Internet Explorer 7</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer/default.aspx">Internet Explorer</category></item><item><title>Confirmed: createTextRange vulnerability is being exploited</title><link>http://msmvps.com/blogs/spywaresucks/archive/2006/03/25/87737.aspx</link><pubDate>Sat, 25 Mar 2006 11:21:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:87737</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=87737</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2006/03/25/87737.aspx#comments</comments><description>&lt;P&gt;&lt;A href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=JS%5FDLOADER%2EBXR&amp;amp;VSect=P"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=JS%5FDLOADER%2EBXR&amp;amp;VSect=P&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I do note on the diagram that it stipulates that only&amp;nbsp;the "January edition" of Internet Explorer 7 Beta 2 Preview is vulnerable.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;There has been a lot of confusion about whether the March build (that is, 5335.5) is vulnerable to the createTextRange exploit because, despite the MS Security Blog and the Technet article noting that IE7 Beta 2 Preview Mix06 Build is not affected, other sites stated that the IE7 Beta 2 Preview was affected without stipulating build, and some stated IE7 Beta 2 (not the&amp;nbsp;Preview) was vulnerable ... umm, guys... IE7 Beta 2 hasn't been released to the public yet.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Now, if only MS would update their own advisory (&lt;A href="http://www.microsoft.com/technet/security/advisory/917077.mspx"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;http://www.microsoft.com/technet/security/advisory/917077.mspx&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;) which, although it states that IE7 build released on March 20 is not affected, does not list earlier versions of IE7 in the "Related Software" list.&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=87737" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer+7/default.aspx">Internet Explorer 7</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer/default.aspx">Internet Explorer</category></item><item><title>Patchou - still the bullshit continues...</title><link>http://msmvps.com/blogs/spywaresucks/archive/2006/02/21/84385.aspx</link><pubDate>Tue, 21 Feb 2006 13:51:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:84385</guid><dc:creator>sandi</dc:creator><slash:comments>4</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=84385</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2006/02/21/84385.aspx#comments</comments><description>&lt;P&gt;Check out this thread:&lt;BR&gt;&lt;A href="http://www.msghelp.net/showthread.php?tid=55990&amp;amp;page=1"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;http://www.msghelp.net/showthread.php?tid=55990&amp;amp;page=1&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;It contains the&amp;nbsp;most amazing bullshit... is it surprising that malware has such a hold when such justifications.... such bullshit... ok, I'm getting grumpy here.. hands off keyboard.&lt;/P&gt;
&lt;P&gt;Look at this:&lt;BR&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2005/12/05/78084.aspx"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;http://msmvps.com/blogs/spywaresucks/archive/2005/12/05/78084.aspx&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Let me tell you something... Patchou's version of lop.com may, according to him,&amp;nbsp;be modified, and "harmless" according to some of the we-love-patchou naivettes in his forum, but I tell you right now that it isn't modified enough to stop underage kids being exposed to the crap exposed in my blog entry above.&amp;nbsp; Patchou has my email address.&amp;nbsp; Those behind lop.com have my email address - I know - I have emails that prove that they know how to get in touch with me - so, *if* they have fixed things there is no excuse for not emailing me to tell me.&lt;/P&gt;
&lt;P&gt;Do you think it is ok to hide behind an EULA?&amp;nbsp; I don't.&lt;/P&gt;
&lt;P&gt;Honestly, the msgplus thread above is indicative of the ridiculous, inane, uninformed, uneducated commentary that is the norm for msgplus supporters.&lt;/P&gt;
&lt;P&gt;I ask you, in all&amp;nbsp;of&amp;nbsp;the crap in that thread.. the insults about how the OP was bored with "Mimesweeper"and all the other inane insults ... how often is the actual issue addressed.... the issue being the *fact* that msplus uses lop.com as a sponsor... forget all the Paris Hilton bullshit..how many concerns have been addressed and how many have been yelled down by &lt;A href="http://redwing.hutman.net/~mreed/warriorshtm/howlers.htm"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;http://redwing.hutman.net/~mreed/warriorshtm/howlers.htm&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;or &lt;A href="http://redwing.hutman.net/~mreed/warriorshtm/swarm.htm"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;http://redwing.hutman.net/~mreed/warriorshtm/swarm.htm&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Patchou says that "the lop package, in general, is safe to install".&amp;nbsp; All I can say is BWWWWWWWWWWWWHAHAHAHHAHAHAHAHA. Just who are you kidding?"&amp;nbsp; &lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=84385" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer/default.aspx">Internet Explorer</category></item></channel></rss>