<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Spyware Sucks : Security, safety and privacy on the Internet, I ain't happy about this....., Internet Explorer 7</title><link>http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/I+ain_2700_t+happy+about+this_2E00__2E00__2E00__2E00__2E00_/Internet+Explorer+7/default.aspx</link><description>Tags: Security, safety and privacy on the Internet, I ain't happy about this....., Internet Explorer 7</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>TrendMicro Antispyware for the Web causing issues again - this time nuking the Windows Genuine Validation Tool</title><link>http://msmvps.com/blogs/spywaresucks/archive/2006/03/11/85979.aspx</link><pubDate>Sat, 11 Mar 2006 00:46:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:85979</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=85979</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2006/03/11/85979.aspx#comments</comments><description>&lt;P&gt;&lt;STRONG&gt;&lt;FONT color=#ff0000&gt;Important Update: &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2006/03/15/86345.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2006/03/15/86345.aspx&lt;/A&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;This could prove to be a very serious problem.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;The Windows Genuine Advantage Validation Tool *must* be installed before many downloads are made available to users via Windows Update and the Download Centre.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Trend Micro Antispyware for the Web&amp;nbsp;is&amp;nbsp;detecting the Windows Genuine Advantage Validation Tool KB892130&amp;nbsp;CLSID as Adware_iSearch.&amp;nbsp; Once the CLSID is deleted by TMAS, the user will be re-prompted to download KB892130 the next time he or she goes to Windows Update.&lt;/P&gt;
&lt;P&gt;Check out this thread:&lt;BR&gt;&lt;A href="http://aumha.net/viewtopic.php?t=18492&amp;amp;postdays=0&amp;amp;postorder=asc&amp;amp;start=0"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;http://aumha.net/viewtopic.php?t=18492&amp;amp;postdays=0&amp;amp;postorder=asc&amp;amp;start=0&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I'm going to pass this on to George&amp;nbsp;and Andy at Trend... we need to make sure that SMB product is not being affected in the same way - I'm betting it is.&lt;/P&gt;
&lt;P&gt;Generally the Corporate (SMB) version is updated very quickly when false positives like this are found.&amp;nbsp; Those responsible for the&amp;nbsp;consumer space, including online web scan&amp;nbsp;are much slower to react.&amp;nbsp; &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2005/06/22/54453.aspx"&gt;&lt;FONT color=#0000ff&gt;&lt;STRONG&gt;Trend's history of delay&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;STRONG&gt; in fixing false positives in the consumer versions of Antispyware&amp;nbsp;will be a big problem this time.&amp;nbsp; Please guys, let's get this sorted damned fast.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Charles (aka Chasbox in the&amp;nbsp;aumha.net forum)&amp;nbsp;did very well to draw the connection between TMAS and the Windows Update problem he is seeing. I've confirmed the problem on several PCs.&lt;/P&gt;
&lt;P&gt;Here is the alert.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;IMG src="/photos/spyware_sucks/images/85969/original.aspx"&gt;&lt;/P&gt;
&lt;P&gt;The threat details:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;IMG src="/photos/spyware_sucks/images/85972/original.aspx"&gt;&lt;/P&gt;
&lt;P&gt;The CLSID key being flagged:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;IMG src="/photos/spyware_sucks/images/85974/original.aspx"&gt;&lt;/P&gt;
&lt;P&gt;The key you see is the *only* entry in the Ext folder, therefore must be the source of the alert.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT color=#ff0000&gt;DO NOT ALLOW THE TREND PROGRAMME TO DELETE THE CLSID&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;BTW, Trend Micro Antispyware&amp;nbsp;on the Web seems to be broken in IE7, at least it is for me... had to fire up IE6 on another PC on my network to confirm the false positive.&amp;nbsp; Its a bit hard to select 'Start Scan' when there's no scan button to click on... ;o)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;IMG src="/photos/spyware_sucks/images/85977/original.aspx"&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color=#000000&gt;------------------------------------------------------------------------------&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color=#000000&gt;Update - 12 March 06, 12.10am Perth, WA time (+0800): The false positive has, apparently, been fixed for the &lt;U&gt;packaged product&lt;/U&gt; (pattern 3.31) since 10 March, but NOT the online scan.&amp;nbsp; I know, because I tested the online scan 10 minutes ago.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color=#000000&gt;This is a source of ongoing frustration to me.&amp;nbsp; The packaged product is fixed quickly when a false positive, but the online scan can be left, at times, for months.&amp;nbsp; I despair.&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=85979" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer+7/default.aspx">Internet Explorer 7</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/I+ain_2700_t+happy+about+this_2E00__2E00__2E00__2E00__2E00_/default.aspx">I ain't happy about this.....</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer/default.aspx">Internet Explorer</category></item></channel></rss>