<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Spyware Sucks : Vulnerabilities, viruses and exploits, Security, safety and privacy on the Internet, Internet Explorer 7</title><link>http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/Security_2C00_+safety+and+privacy+on+the+Internet/Internet+Explorer+7/default.aspx</link><description>Tags: Vulnerabilities, viruses and exploits, Security, safety and privacy on the Internet, Internet Explorer 7</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>ALERT: Out of band security patch to be released tomorrow, 17 December at 10.00am Pacific time</title><link>http://msmvps.com/blogs/spywaresucks/archive/2008/12/17/1656924.aspx</link><pubDate>Tue, 16 Dec 2008 21:14:56 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1656924</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1656924</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/12/17/1656924.aspx#comments</comments><description>&lt;p&gt;Announcement here:&lt;br /&gt;&lt;a title="http://blogs.technet.com/msrc/archive/2008/12/16/advance-notification-for-december-2008-out-of-band-release.aspx" target="_blank" href="http://blogs.technet.com/msrc/archive/2008/12/16/advance-notification-for-december-2008-out-of-band-release.aspx"&gt;http://blogs.technet.com/msrc/archive/2008/12/16/advance-notification-for-december-2008-out-of-band-release.aspx&lt;/a&gt;&lt;/p&gt; &lt;p&gt;The patch resolves the actively exploited vulnerability that has been in the press so much in recent days, and which is the subject of this Security Advisory:&lt;br /&gt;&lt;a title="http://www.microsoft.com/technet/security/advisory/961051.mspx" target="_blank" href="http://www.microsoft.com/technet/security/advisory/961051.mspx"&gt;http://www.microsoft.com/technet/security/advisory/961051.mspx&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1656924" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer+7/default.aspx">Internet Explorer 7</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer/default.aspx">Internet Explorer</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer+8/default.aspx">Internet Explorer 8</category></item><item><title>Internet Explorer Protected Mode and other stuff...</title><link>http://msmvps.com/blogs/spywaresucks/archive/2006/08/06/106864.aspx</link><pubDate>Sun, 06 Aug 2006 03:46:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:106864</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=106864</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2006/08/06/106864.aspx#comments</comments><description>&lt;P&gt;For your viewing pleasure.. an excellent video from TechEd&lt;/P&gt;
&lt;P&gt;Windows Vista System Integrity Technologies&lt;BR&gt;&lt;A href="http://www.microsoft.com/emea/itsshowtime/sessionh.aspx?videoid=223"&gt;http://www.microsoft.com/emea/itsshowtime/sessionh.aspx?videoid=223&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Steve Riley is a fun presenter... messy blonde hair, sneakers, red pants, blue shirt, shell fragment necklace, leather wrist bands with tassels and earring &lt;img src="/emoticons/emotion-1.gif" alt="Smile" /&gt;&lt;/P&gt;
&lt;P&gt;My primary interest, when looking at this video with a mind to highlighting it on my blog, was its relevance to IE7.&amp;nbsp; That being said, there are a lot of gems in Steve's presentation.&lt;/P&gt;
&lt;P&gt;I do recommend, if you are technically inclined, that you watch the entire video (but be warned, its more than an hour long).&amp;nbsp; If you don't want to sit through the entire thing, you can jump straight to the section where Steve explains how Protected Mode for Internet Explorer in Windows Vista helps protect users from the bad guys when they are surfing the internet.&lt;/P&gt;
&lt;P&gt;Basically, a user will have to approve up to *three* different dialogue boxes for programmes sourced from the Internet.&amp;nbsp; He or she will have to say:&lt;/P&gt;
&lt;P&gt;1) Yes, I want to run that programme...&lt;BR&gt;2) Yes, I trust the Web site that I got the programme from... &lt;BR&gt;3) Yes, I want to give that application Full (User) Privileges...&lt;/P&gt;
&lt;P&gt;Steve says &lt;EM&gt;"what is the problem that we're trying to solve here... when somebody downloads some attachment and it has some sexually formatted subjectline "click here to see the dancing pigs".. those dancing pigs will win every time won't they... people don't know how to be secure so we have to do it for them..."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;As much as I *dislike* the phrase, there are people out there who just want to see the "dancing pigs" and will say yes to anything and everything to obtain access to said pigs. For them, three prompts will not be enough to stop them from infecting their machines.&amp;nbsp; Heck, they may even complain about the inconvenience.&amp;nbsp; But you know what?&amp;nbsp; MS can only go so far to protect people from themselves.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;After years of very vocal "Windows is too insecure" complaints there are some who complain about how much harder Vista makes things for developers and users - for example:&lt;BR&gt;&lt;A href="http://www.msgpluslive.net/news/2006/08/05/opinions-on-windows-vistas-release-date/"&gt;http://www.msgpluslive.net/news/2006/08/05/opinions-on-windows-vistas-release-date/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Its a little ironic that Patchou is complaining about difficulties when working in Vista, considering the ongoing battle to stop malware being distributed via his sponsor programme (stopping the spread of malware being one of the primary reasons behind the tightening up security in Vista).&lt;/P&gt;
&lt;P&gt;I disagree with Patchou... I say bring on Vista.&amp;nbsp; Reality is that malware pushers are not going to go away voluntarily, nor will people stop trying to earn an income from the pop-ups or banner ads that are used as a conduit to computers by the malware pushers.&amp;nbsp; The bad guys are not going to give up their income stream willingly, and they will continue to look for ways to get their wares on to as many machines as possible, including by deceiving those selling pop-up and banner advertising space.&amp;nbsp;&amp;nbsp;There are people&amp;nbsp;who need to generate an income via pop-ups and sponsors and who have every intention of refusing malware pushers access to their advertising space, but reality is the bad guys are getting in there anyway.&lt;/P&gt;
&lt;P&gt;Attempted malware download via MP Sponsor Programme generated popups:&lt;BR&gt;&lt;A HREF="/blogs/spywaresucks/archive/2006/06/30/103407.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2006/06/30/103407.aspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The bad guys use a myspace banner ad to spread malware:&lt;BR&gt;&lt;A HREF="/blogs/spywaresucks/archive/2006/07/21/105450.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2006/07/21/105450.aspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Myspace again - this time its embedded videos and Zango:&lt;BR&gt;&lt;A href="http://www.vitalsecurity.org/2006/07/interview-with-zango-myspace-affiliate.html"&gt;http://www.vitalsecurity.org/2006/07/interview-with-zango-myspace-affiliate.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;During Steve's presentation he talks about how he did not reduce the privileges granted to his wife's user account, which was a local administrator account, and how his wife's computer was therefore vulnerable to, and ended up being infected by, malware ... Steve mentions that Jesper makes his wife and children run as guest), but Jesper's willingness to lock down his systems is an exception, rather than standard operating procedure out there in the world.&lt;BR&gt;&lt;A href="http://blogs.technet.com/jesper_johansson/archive/2006/06/22/438316.aspx"&gt;http://blogs.technet.com/jesper_johansson/archive/2006/06/22/438316.aspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We have to get used to UAC and no longer being King on our computers.&amp;nbsp; As Steve said, there is no such thing as perfect, hack proof or impenetrable (tell that to some of the Linux/Firefox apologists).&amp;nbsp; He also says &lt;EM&gt;"For every way you can think of to stop a bad guy the bad guy will think of another way. You can't.&amp;nbsp; You cannot know everything that is bad. But what do you know? You know everything that is good... So why not make a statement of what you allow based on what you know is good and then by default block everything else."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;His comments remind me of Peter Tippett and what he said years ago (Peter Tippett, by the way, apparently developed the product that eventually became Norton Antivirus).&lt;/P&gt;
&lt;P&gt;Back in May 2005 I reported on an magazine article about Peter in which Peter said:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"The first version I produced stopped any virus that could be produced. 'No updates required' was the byline.&amp;nbsp; It recorded the state of all software on your system and anything new just wouldn't run ... As an afterthought we added virus signature scanner and sold it to Symantec. ... Symantec felt that nobody could understand the generic new software-blocking stuff, so that feature quietly dropped away.”&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A HREF="/blogs/spywaresucks/archive/2005/05/05/45762.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2005/05/05/45762.aspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We have now reached the stage where needing to stop the bad guys outweighs the need to make things easy for those who cannot understand the "generic new software-blocking stuff" or want to be King on their computer.&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=106864" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer+7/default.aspx">Internet Explorer 7</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category></item><item><title>Thanks Ian! I enjoyed the giggle :)</title><link>http://msmvps.com/blogs/spywaresucks/archive/2006/06/23/102522.aspx</link><pubDate>Fri, 23 Jun 2006 00:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:102522</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=102522</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2006/06/23/102522.aspx#comments</comments><description>&lt;P&gt;One of my loyal readers pointed me to this site, coincidentally after reading my blogpost about the Bit9 assessment which placed Firefox 1.0.7 as the most dangerous non-malicious software out there:&lt;BR&gt;&lt;A href="http://www.cweiske.de/"&gt;&lt;FONT color=#0000ff&gt;&lt;STRONG&gt;http://www.cweiske.de/&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;It seems the owner/author doesn't like IE and is blocking access to IE users. That's his prerogative but its awfully short sighted.&amp;nbsp; Why? Because IE7 is a massive improvement in security and CSS compliance - because Firefox is becoming a bigger target and the bad guys are targetting it more often and if not kept right up to date leaves its users at risk&amp;nbsp;- because even Opera is exploited (&lt;A href="http://www.frsirt.com/english/advisories/2006/1262"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;recent example&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;On further thought, although I did giggle when I first saw the page, now that I've thought further about it the giggling has stopped.&lt;/P&gt;
&lt;P&gt;The author says Opera and Firefox are "better" - how are they better?&amp;nbsp; Better CSS compliance?&amp;nbsp; IE7 has taken great strides in addressing that problem.&amp;nbsp; Are the alternative browsers&amp;nbsp;"safer"?&amp;nbsp; No they are not.&amp;nbsp; As has been said in the past, all the bad guys need is *one* exploit.&amp;nbsp; Firefox and Opera can be and have been targeted - in fact just recently there was a hostile circulating that was &lt;A HREF="/blogs/spywaresucks/archive/2006/06/16/101670.aspx"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;targetting IE *and* Firefox exploits&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;It is dangerous to tell somebody to stop using IE because it is a "paradise for virus programmers" and point them to Opera and Firefox without also warning them to regularly check for security updates for those browsers and practice safe hex.&amp;nbsp; Firefox and Opera are also subject to exploits and vulnerabilities - it concerns me when I see sites that forget to mention that fact.&amp;nbsp; At least with Internet Explorer, if you have Automatic Updates enabled you will be notified of the latest security updates.&lt;/P&gt;
&lt;P&gt;The fanboys need to stop saying "use this - its better".&amp;nbsp;&amp;nbsp;They need to say&amp;nbsp;"use this - its better - but make sure you check back regularly for security updates and patches, and always practice safe hex".&amp;nbsp;&amp;nbsp; Windows Update does not patch Firefox or Opera or any other alternative browser.&amp;nbsp; You have to look after yourself.&amp;nbsp; Remember that.&amp;nbsp; If your friends are using an older version of Firefox, especially one that does not have an inbuilt update ability, warn them that they have to go out and get those updates.&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=102522" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer+7/default.aspx">Internet Explorer 7</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category></item><item><title>Fix: Internet Explorer freezes when using the drop-down address bar list when the fix described in KB908531 is installed</title><link>http://msmvps.com/blogs/spywaresucks/archive/2006/04/14/90914.aspx</link><pubDate>Fri, 14 Apr 2006 05:28:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:90914</guid><dc:creator>sandi</dc:creator><slash:comments>10</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=90914</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2006/04/14/90914.aspx#comments</comments><description>&lt;SPAN&gt;&lt;FONT face=Calibri&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;&lt;EM&gt;Note, HP and Kerio are NOT the only software affected by the problems described in the KB article 918165.&amp;nbsp; Older NVIDIA software is also implicated, and as the KB article states, there may be other third party COM controls or shell extensions causing a problem. In short, don't assume that just because you don't have NVIDIA, HP or Kerio that you'll be safe or that your problems can't be caused by the MS06-015 update.&amp;nbsp; I have personal experience of people being hit by this problem who have none of that software:&lt;BR&gt;&lt;/EM&gt;&lt;A href="http://support.microsoft.com/kb/918165"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;&lt;EM&gt;http://support.microsoft.com/kb/918165&lt;/EM&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;(I have no idea why Stephen ***'s surname doesn't appear properly - all I see is three stars instead of a surname...)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;&lt;A href="http://groups.google.com/group/microsoft.public.windows.inetexplorer.ie6.browser/msg/094143b42d0c3ca2"&gt;&lt;FONT color=#0000ff&gt;Stephen *** of Microsoft has posted to ie6.browser newsgroup&lt;/FONT&gt; &lt;/A&gt;regarding a known problem with MS06-15 / KB908531 wherein Internet Explorer may freeze when you attempt to use the drop-down list in the Address Bar.&amp;nbsp; MS have tracked down the cause of the problem, and it is wide spread enough to be deserving of publicity.&amp;nbsp; I am sure Stephen will forgive me for quoting him verbatim rather than sending you off to the newgroup via Outlook Express or the Communities Web Interface.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;&amp;lt;quote&amp;gt; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;We've determined that the majority of the issues people are having with MS06-015 / KB908531 are due to a bad interaction between the security update and a software component included with various HP hardware devices, including but not limited to printers, scanners, and cameras. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;Here are two fixes which should fix problems caused by the interaction with the HP software:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;Option 1 - Modify the registry&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;BR&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;------------------------------&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;- (If you have multiple user accounts set up) Log onto the computer using an account with Administrator privileges&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;- Click the Start button, then click Run and type "regedit" at the prompt, without the quotes; this will start Registry Editor&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;- Locate the &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached key in Registry Editor&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;- Right click on the key and select New / DWORD Value&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;- Rename the resulting value "{A4DF5659-0801-4A60-9607-1C48695EFDA9} {000214E6-0000-0000-C000-000000000046} 0x401", without the quotes&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;- Right click the value, select Modify, and type "1" into the Value Data field&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;- Close Registry Editor&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;Option 2 - Kill the HP process&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;BR&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;------------------------------&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;- Wait until Internet Explorer, Windows Explorer, or whichever component is encountering problems is in an unresponsive state&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;- Click the Start button, then select Run and type "taskmgr" at the prompt, without the quotes; this will start Task Manager&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;- Locate any instances of hpgs2wnd.exe or hpgs2wnf.exe in Task Manager, then right click on them and select End Process&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;(Note: Option 2 this may disable some HP device-specific functionality until you restart your computer.)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;If your computer is not currently unresponsive, you should only have to do Option 1 or Option 2, not both.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;If your computer is currently unresponsive, you should be fixed by doing Option 2.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;I'm very sorry about the inconvenience this has caused you all; hopefully this will get things back on track.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Please note that MS06-015 fixes a critical security vulnerability, so it's very important that you reinstall it as soon as possible if you've uninstalled it.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Please also keep in mind that disabling Auto Update will leave your computer unprotected even after we release security updates.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;I understand that this experience has been very frustrating for many of you, but I really must still strongly recommend that you leave Auto Update enabled for your own safety. &amp;lt;/quote&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT face=Calibri&gt;Addendum:&lt;SPAN&gt;&amp;nbsp; &amp;lt;quote&amp;gt; &lt;/SPAN&gt;Actually, it appears that I spoke too soon.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Option 2 will correct the problem for the logged-in user, but not for all users on a computer with multiple user accounts.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;For that reason, Option 1 is the preferred option. &amp;lt;/quote&amp;gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=90914" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer+7/default.aspx">Internet Explorer 7</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer/default.aspx">Internet Explorer</category></item><item><title>The eEye hack for the createTextRange vulnerability</title><link>http://msmvps.com/blogs/spywaresucks/archive/2006/03/29/88277.aspx</link><pubDate>Tue, 28 Mar 2006 23:25:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:88277</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=88277</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2006/03/29/88277.aspx#comments</comments><description>&lt;P&gt;Summary:&amp;nbsp; My advice? Don't install it.&lt;/P&gt;
&lt;P&gt;(Please forgive any grammatical or logical flow errors - I'm running real short of time but wanted to get this live before starting my work day).&lt;/P&gt;
&lt;P&gt;Two MS security bloggers have mentioned the eEye "patch" that protects against the createTextRange vulnerability.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/msrc/default.aspx"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;http://blogs.technet.com/msrc/default.aspx&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;BR&gt;&lt;A href="http://blogs.technet.com/ms_schweiz_security_blog/default.aspx"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;http://blogs.technet.com/ms_schweiz_security_blog/default.aspx&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Both bloggers recommend that the patch not be installed.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Ok, I admit - the vulnerability is being exploited. That's bad.&amp;nbsp; But, at the same time we need to have a realistic look at what is going on and compare risk to reward.&amp;nbsp; On balance, after considering all the information I'm privy to (public and private) I have to say that I agree - do not install the third party patch.&lt;/P&gt;
&lt;P&gt;Historically, third party patches and hacks have been problematic.&amp;nbsp; Let's look at a couple of recent examples.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;U&gt;WMF Exploit hack&lt;/U&gt;&lt;BR&gt;The WMF exploit patch was messy - to get the file to stick you had to mess around with cached copies of the file (gdi32.dll is protected by Windows File Protection).&amp;nbsp; The changed file was also causing Windows Update to offer old security patches.&amp;nbsp; Deregistering shimgvw.dll stopped Windows Picture and Fax Viewing from working.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;U&gt;The IE6/IE7 side by side hack&lt;/U&gt;&lt;BR&gt;The IE6/IE7 side by side hack caused various symptoms, including opening a browser window that promptly hangs IE, opening links that render blank, and multiple windows opening when initiating a browser session.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;The eEye hack (I refuse to call it a patch) doesn't fix the CreateTextRange vulnerability... it messes around with how Windows works.&amp;nbsp; We have no way of knowing what may be broken by this change.&lt;/P&gt;
&lt;P&gt;"Ah, but at least I'll be safe" I hear you say.&amp;nbsp; "Safe from what?" says I.&amp;nbsp; Let me explain.&lt;/P&gt;
&lt;P&gt;First, according to &lt;A href="http://www.microsoft.com/technet/security/advisory/917077.mspx"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;http://www.microsoft.com/technet/security/advisory/917077.mspx&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt; "Antivirus companies indicate that attacks that exploit this vulnerability are being effectively mitigated by antivirus software with up-to-date signatures".&amp;nbsp; The antivirus companies that have confirmed they provide protection against known vectors include:&lt;/P&gt;
&lt;P&gt;Symantec&lt;BR&gt;Computer Associates&lt;BR&gt;McAfee&lt;BR&gt;F-Secure Corporation&lt;BR&gt;Panda Software International&lt;BR&gt;Aladdin&lt;BR&gt;Sophos&lt;BR&gt;Eset Software&lt;BR&gt;Trend Micro&lt;BR&gt;Windows Live OneCare&lt;BR&gt;&amp;nbsp;&lt;BR&gt;Do you have up-to-date antivirus? Does it detect files that attempt to exploit the vulnerability?&amp;nbsp; If so, why take the risk with a third party hack?&lt;/P&gt;
&lt;P&gt;Second, sure there are lists going around warning that there are hundreds of sites that are taking advantage of the exploit.&amp;nbsp; But, actually hitting one of those sites is needle-in-a-haystack stuff.&amp;nbsp; Seriously.&amp;nbsp; I've seen real-world, whats-actually-happening statistics that convince me that the risk of being hit by the exploit is not sufficient to risk damage that may be caused to a system's operation by the eEye changes.&lt;/P&gt;
&lt;P&gt;On balance, considering the fact that MS and law enforcement have been very proactive in getting exploit sites shut down, considering the fact that there are not "hundreds" of sites out there (the number is far lower than that), considering the list of antivirus programmes that protect against known vectors, considering the fact that you'll have to be *real* unlucky to hit one of the sites that is still live without being taken by the hand and shown how to get there, and considering there are safer ways to protect yourself against the risk of exploit (disable active scripting or set to prompt), I say don't install the patch.&lt;/P&gt;
&lt;P&gt;BTW, SANS Internet Storm Centre agrees - not with me per se, but with the risk assessment that the eEye patch shouldn't be installed:&lt;BR&gt;&lt;A href="http://www.incidents.org/diary.php?storyid=1226"&gt;&lt;STRONG&gt;http://www.incidents.org/diary.php?storyid=1226&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=88277" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer+7/default.aspx">Internet Explorer 7</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer/default.aspx">Internet Explorer</category></item><item><title>Confirmed: createTextRange vulnerability is being exploited</title><link>http://msmvps.com/blogs/spywaresucks/archive/2006/03/25/87737.aspx</link><pubDate>Sat, 25 Mar 2006 11:21:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:87737</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=87737</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2006/03/25/87737.aspx#comments</comments><description>&lt;P&gt;&lt;A href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=JS%5FDLOADER%2EBXR&amp;amp;VSect=P"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=JS%5FDLOADER%2EBXR&amp;amp;VSect=P&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I do note on the diagram that it stipulates that only&amp;nbsp;the "January edition" of Internet Explorer 7 Beta 2 Preview is vulnerable.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;There has been a lot of confusion about whether the March build (that is, 5335.5) is vulnerable to the createTextRange exploit because, despite the MS Security Blog and the Technet article noting that IE7 Beta 2 Preview Mix06 Build is not affected, other sites stated that the IE7 Beta 2 Preview was affected without stipulating build, and some stated IE7 Beta 2 (not the&amp;nbsp;Preview) was vulnerable ... umm, guys... IE7 Beta 2 hasn't been released to the public yet.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Now, if only MS would update their own advisory (&lt;A href="http://www.microsoft.com/technet/security/advisory/917077.mspx"&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;http://www.microsoft.com/technet/security/advisory/917077.mspx&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt;) which, although it states that IE7 build released on March 20 is not affected, does not list earlier versions of IE7 in the "Related Software" list.&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=87737" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer+7/default.aspx">Internet Explorer 7</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer/default.aspx">Internet Explorer</category></item></channel></rss>