<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Security Manifest : ANNOUNCEMENTS</title><link>http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx</link><description>Tags: ANNOUNCEMENTS</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Microsoft MVP Conference!</title><link>http://msmvps.com/blogs/trafton/archive/2005/09/27/68125.aspx</link><pubDate>Wed, 28 Sep 2005 03:08:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:68125</guid><dc:creator>trafton</dc:creator><slash:comments>3</slash:comments><description>I'm currently in Bellevue, Wash., a suburb of Seattle about 50 miles north of my hometown, for the MVP conference.  It is quite a cultural difference (it's an entire county away!), but hopefully I'll get used to it.  :)

I'll try to post pictures of interesting things when I get back.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=68125" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx">ANNOUNCEMENTS</category></item><item><title>Return</title><link>http://msmvps.com/blogs/trafton/archive/2005/08/14/62724.aspx</link><pubDate>Mon, 15 Aug 2005 00:47:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:62724</guid><dc:creator>trafton</dc:creator><slash:comments>1</slash:comments><description>I have returned from my vacation, which bled into yet another vacation to beautiful Toronto, a rich and diverse city.  I was simply astounded by the number of languages that I couldn't even recognize!

I hope everyone is having a good summer and tolerating the heat.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=62724" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx">ANNOUNCEMENTS</category></item><item><title>Vacation!</title><link>http://msmvps.com/blogs/trafton/archive/2005/07/18/58008.aspx</link><pubDate>Mon, 18 Jul 2005 18:53:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:58008</guid><dc:creator>trafton</dc:creator><slash:comments>2</slash:comments><description>I will be on vacation for about a week and a half on the beautiful Olympic Peninsula.  Ergo, posting will be limited unless there is a notable virus outbreak.

Hope everyone out there is having a wonderful summer!&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=58008" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx">ANNOUNCEMENTS</category></item><item><title>Renewed!</title><link>http://msmvps.com/blogs/trafton/archive/2005/01/05/29830.aspx</link><pubDate>Wed, 05 Jan 2005 21:43:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:29830</guid><dc:creator>trafton</dc:creator><slash:comments>1</slash:comments><description>&lt;P&gt;I got a welcome&amp;nbsp;surprise in the mail today - a notification that I have been awarded as an &lt;A href="http://mvp.support.microsoft.com/"&gt;MVP&lt;/A&gt; for the second year, which I suppose makes me a sophomore member of the program. I am honored to continue to be in this wonderful program with such great people.&lt;/P&gt;
&lt;P&gt;To Microsoft and my fellow MVPs, a *huge* thank you - you rock! :)&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=29830" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx">ANNOUNCEMENTS</category></item><item><title>Happy New Year!</title><link>http://msmvps.com/blogs/trafton/archive/2005/01/01/29102.aspx</link><pubDate>Sat, 01 Jan 2005 09:22:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:29102</guid><dc:creator>trafton</dc:creator><slash:comments>2</slash:comments><description>&lt;P&gt;The fireworks just ended over the Seattle Space Needle and I just wanted to drop in to wish everyone a happy and safe new year!&lt;/P&gt;
&lt;P&gt;I thought this picture might be especially appropriate given the season&amp;nbsp;(hopefully one that no one reading this will ever get to see first-person):&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.isdnllc.com/tech/windows/happy99_removal.html"&gt;&lt;IMG src="http://www.n00bshop.com/trafton/happy99.gif"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Being that this is the new year, I also put up a new theme for the blog as well as added a blogroll, which I will hopefully have many entries to add to in the future. Enjoy everyone, and do have a good 2005!&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=29102" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx">ANNOUNCEMENTS</category></item><item><title>"In Absentia"</title><link>http://msmvps.com/blogs/trafton/archive/2004/08/27/12462.aspx</link><pubDate>Fri, 27 Aug 2004 15:15:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:12462</guid><dc:creator>trafton</dc:creator><slash:comments>1</slash:comments><description>Various things (educational advancement, email troubles, acts of God) have conspired so that I was unable to update the Security Manifest for the entire month of August. I will start updating again, more frequently than before, I hope, come September, unless I somehow underestimate the difficulty of various schedules.&lt;BR&gt;&lt;BR&gt;My apologies.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=12462" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx">ANNOUNCEMENTS</category></item><item><title>False Positive Problem Probably Solved</title><link>http://msmvps.com/blogs/trafton/archive/2004/06/18/8456.aspx</link><pubDate>Fri, 18 Jun 2004 17:01:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:8456</guid><dc:creator>trafton</dc:creator><slash:comments>7</slash:comments><description>&lt;H3&gt;Exploit-MhtRedir.gen Detection Should Be Fixed&lt;/H3&gt;
&lt;P&gt;I've discovered what I'm pretty sure is the root problem of the detections of Exploit-MhtRedir.gen on this blog. The detection was limited to &lt;EM&gt;McAfee VirusScan &lt;/EM&gt;and was due to the program misinterpreting quoted text as malicious code. There was no infection in the page, and at no time did this quoted content (which was from a Secunia alert) present any security risk to visitors of the blog.&lt;/P&gt;
&lt;P&gt;I'm trying to work out why &lt;EM&gt;VirusScan &lt;/EM&gt;detected the code but not other antivirus programs, and it appears to be a case of &lt;EM&gt;VirusScan &lt;/EM&gt;using a more general detection string. If you receive any detection from this page, please feel free to tell me about it.&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=8456" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx">ANNOUNCEMENTS</category></item><item><title>Probable False Positive on this Blog</title><link>http://msmvps.com/blogs/trafton/archive/2004/06/18/8453.aspx</link><pubDate>Fri, 18 Jun 2004 16:53:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:8453</guid><dc:creator>trafton</dc:creator><slash:comments>32</slash:comments><description>&lt;H3&gt;McAfee Detects Exploit-MhtRedir.gen&lt;/H3&gt;
&lt;P&gt;For some reason, it appears that a single antivirus product - &lt;EM&gt;McAfee VirusScan &lt;/EM&gt;- has been detecting the virus Exploit-MhtRedir.gen in this blog. It looks like this is an incorrect detection so far, but I am working on trying to figure out what exactly is causing the problem. If you are using any other antivirus program and are getting a detection for this page, I'd love it if you could inform me. So far, no other program I've tested has triggered this detection.&lt;BR&gt;&lt;BR&gt;Thank you and sorry for any inconvenience.&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=8453" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx">ANNOUNCEMENTS</category></item><item><title>Vacation Miscellanea</title><link>http://msmvps.com/blogs/trafton/archive/2004/06/04/7576.aspx</link><pubDate>Fri, 04 Jun 2004 15:04:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:7576</guid><dc:creator>trafton</dc:creator><slash:comments>11</slash:comments><description>&lt;h3&gt;No Updates this Weekend, Part of Summer&lt;/h3&gt;
&lt;p&gt;This weekend, I will be in Portland, Ore., visiting some family friends, so I'm afraid I probably won't be able to update &lt;em&gt;Security Manifest&lt;/em&gt; unless there is a seriously major outbreak. In addition, part of the summer I will be staying  in Blyn, Wash., near Sequim, where I will have no Internet connection. Updates will be limited to a few times per week. Of course, there are many other great resources which you can access from the random links which appear on the left of the page.&lt;br /&gt;&lt;br /&gt;Have a good weekend! Hopefully the nice summer weather most people are having will stick around...&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=7576" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx">ANNOUNCEMENTS</category></item><item><title>New Virus Write-Up: W97M.Nobody</title><link>http://msmvps.com/blogs/trafton/archive/2004/05/24/7047.aspx</link><pubDate>Mon, 24 May 2004 21:09:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:7047</guid><dc:creator>trafton</dc:creator><slash:comments>1</slash:comments><description>&lt;h3&gt;Word Macro/IRC Worm&lt;/h3&gt;
&lt;p&gt;A write-up for the IRC worm and Microsoft Word macro virus W97M.Nobody can now be found &lt;a href="http://msmvps.com/trafton/posts/7045.aspx"&gt;here&lt;/a&gt;.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=7047" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx">ANNOUNCEMENTS</category></item><item><title>New Article: Finding Virus Information Online</title><link>http://msmvps.com/blogs/trafton/archive/2004/05/22/6963.aspx</link><pubDate>Sat, 22 May 2004 17:42:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:6963</guid><dc:creator>trafton</dc:creator><slash:comments>25</slash:comments><description>&lt;h3&gt;Strategies for Virus Info Searching&lt;/h3&gt;
&lt;p&gt;I've posted a new article about finding information on viruses. You can access it by clicking on “Finding Virus Info“ under links or by clicking &lt;a href="http://www.msmvps.com/trafton/posts/6962.aspx"&gt;here&lt;/a&gt;.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=6963" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx">ANNOUNCEMENTS</category></item><item><title>Bad Timing, Literally</title><link>http://msmvps.com/blogs/trafton/archive/2004/05/11/6265.aspx</link><pubDate>Tue, 11 May 2004 23:31:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:6265</guid><dc:creator>trafton</dc:creator><slash:comments>11</slash:comments><description>&lt;h3&gt;Time Should Be (Sort Of) Correct Now&lt;/h3&gt;
&lt;p&gt;For some reason, probably the server configuration, the time was displaying as GMT -11 (my time zone is GMT -8, but it subtracts three hours for some reason.) It is now PST/-8 as it should be (which is GMT -5 in the configuration.) Sorry for any inconvenience.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=6265" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx">ANNOUNCEMENTS</category></item><item><title>Removed Outbreak Warning for Sasser.B</title><link>http://msmvps.com/blogs/trafton/archive/2004/05/08/6088.aspx</link><pubDate>Sat, 08 May 2004 16:10:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:6088</guid><dc:creator>trafton</dc:creator><slash:comments>26</slash:comments><description>&lt;h3&gt;&lt;font color="#ffa500"&gt;Follow-Up:&lt;/font&gt; Five Days Since Initial Outbreak, Downgrade Appropriate&lt;/h3&gt;
&lt;p&gt;I have just removed the outbreak warning for W32/Sassser.worm.B. Although Secunia still &lt;a href="http://secunia.com/virus_information/9147/sasser.b/"&gt;rates&lt;/a&gt; it as a High risk, at five days old, it is unlikely that it is any longer an outbreak as much as a very widespread worm. Speaking of Secunia, I have also added it to the Recommended Links area, which now can be scene in place of the Sasser.B outbreak warning.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=6088" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx">ANNOUNCEMENTS</category><category domain="http://msmvps.com/blogs/trafton/archive/tags/FOLLOW-UPS/default.aspx">FOLLOW-UPS</category></item><item><title>SpreadList Added to Page</title><link>http://msmvps.com/blogs/trafton/archive/2004/05/02/5795.aspx</link><pubDate>Sun, 02 May 2004 16:17:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5795</guid><dc:creator>trafton</dc:creator><slash:comments>14</slash:comments><description>&lt;h3&gt;New Feature: SpreadList&lt;/h3&gt;
&lt;p&gt;I have added a small section to this page, by the name of SpreadList. SpreadList is an informal and non-scientific list of what viruses have been spotted, either via arriving in my inbox or by support requests on the Microsoft Newsgroup. More information and the list can be found here:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://msmvps.com/trafton/posts/5794.aspx"&gt;http://msmvps.com/trafton/posts/5794.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;A link has also been added to the side bar.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5795" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx">ANNOUNCEMENTS</category></item><item><title>New "Recommended Link" Feature</title><link>http://msmvps.com/blogs/trafton/archive/2004/04/30/5740.aspx</link><pubDate>Sat, 01 May 2004 00:05:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5740</guid><dc:creator>trafton</dc:creator><slash:comments>5</slash:comments><description>&lt;h3&gt;When There's No News, Recommended Links Will Appear&lt;/h3&gt;
&lt;p&gt;I have added a quick JavaScript that selects from a range of excellent security-related links and displays one along with a description. Certain links come up more often than others; a randomization method is used (and the JavaScript is indeed poor; I will improve it when I get a chance, but I was going for functionality on the most part.) I hope you will all enjoy this feature, and I also hope to add a wider range of links in the future.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5740" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx">ANNOUNCEMENTS</category></item><item><title>A Few Quick Words on "Outbreak Warnings"</title><link>http://msmvps.com/blogs/trafton/archive/2004/04/28/5605.aspx</link><pubDate>Wed, 28 Apr 2004 17:37:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5605</guid><dc:creator>trafton</dc:creator><slash:comments>4</slash:comments><description>&lt;h3&gt;&lt;font color="#008000"&gt;Follow-Up:&lt;/font&gt; The Why, How, and When&lt;/h3&gt;
&lt;p&gt;I should explain the “outbreak notification” warning for Bagle.AA. This is mainly there because I want to post additional news, but Bagle.AA is so news-worthy it should remain somewhat prominent so people browsing this page would see it. Thus, the idea for the outbreak warning was developed.&lt;br /&gt;&lt;br /&gt;An outbreak warning is basically little more than a notification on the screen added when the following conditions are met:&lt;br /&gt;&lt;br /&gt;- The worm in question is spreading quickly and is at least Medium-High at one location with strict ratings.&lt;br /&gt;- Most antivirus companies at least rate the virus Medium.&lt;br /&gt;- Spread potential is quite high (mass-mailers mostly.)&lt;br /&gt;- Detection for this worm was instituted in response to the sudden outbreak, as opposed to just starting to spread after a week or so.&lt;br /&gt;&lt;br /&gt;Exceptions will be made to the last two rules if necessary.&lt;br /&gt;&lt;br /&gt;For worms that constitute a Medium-High risk, the warning period is between 24 and 48 hours; a High risk worm would be 48 to 72 hours and until it is downgraded to Medium, while a High-Outbreak worm would be until it is downgraded to Medium or at least a week has passed.&lt;br /&gt;&lt;br /&gt;The company ratings I look at most are McAfee and Symantec's, as they tend to put the most stock into their risk ratings. Symantec rates on a 1-5 scale, 1 being equivalent to McAfee's Low, 2 to their Low-Profiled, 3 to their Medium, 4 to their High, and 5 to their High-Outbreak (Symantec has never rated a worm this.) Typically, Medium-on-Watch worms at McAfee are either 3's or 4's.&lt;br /&gt;&lt;br /&gt;Bagle.AA will probably be downgraded in 24 hours or so unless more companies upgrade it to High risk.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5605" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx">ANNOUNCEMENTS</category><category domain="http://msmvps.com/blogs/trafton/archive/tags/FOLLOW-UPS/default.aspx">FOLLOW-UPS</category></item><item><title>Osama bin Laden Capture Virus Spam</title><link>http://msmvps.com/blogs/trafton/archive/2004/04/22/5356.aspx</link><pubDate>Thu, 22 Apr 2004 20:30:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5356</guid><dc:creator>trafton</dc:creator><slash:comments>4</slash:comments><description>&lt;h3&gt;&lt;font color="#000000"&gt;“Psyme“ Variant Spammed in Form of Osama Capture Information&lt;/font&gt;&lt;/h3&gt;
&lt;p&gt;Panda Software reports that a new variant of VBS/Psyme is currently spreading. The latest nefarious pathogen comes in the form of an email with the subject “Osama Bin Laden Captured”. The message goes like this:&lt;br /&gt;&lt;br /&gt;&lt;font face="Courier New"&gt;Hey, Just got this from CNN, Osama Bin Laden has been captured! Goto the link below to view the pics and to download the video if you so wish: (DANGEROUS ADDRESS REMOVED) “Murderous coward he is”. God bless America!&lt;/font&gt;&lt;font face="Times New Roman"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;The message may also come as a source from BBC. Either way, when the victim-to-be clicks on the machine, a variant of VBS/Psyme is downloaded by the name of VBS/Psyme.C. The VBS/Psyme family uses the overwriting of local files by exploiting ADODB.Stream object.&lt;br /&gt;&lt;br /&gt;One must suspect that Panda is slightly hyping this; one would be right. These sort of spammings are not rare, but if indications are true, the spam is a tad wider than average. Users should be cautious and not click on suspicious links such as these.&lt;/p&gt;
&lt;h3&gt;&lt;font color="#000000"&gt;Improved Site Categories&lt;/font&gt;&lt;/h3&gt;
&lt;p&gt;A quick note: You'll notice now that security and virus alerts are sorted by urgency. This should allow easier access to this information sorted by risk. Note that every category includes higher risks, so “Security (Medium)” will also include risks in “Security (Urgent)” and “Security (Very Urgent)”. How does the scale work? Low is a notable inclusion that really isn't that viable in the field. Medium is a risk between low and medium, or an exploit/virus likely to be seen in the field soon, but now. Urgent is either fast spread or a potentially very dangerous exploit/virus that could spread quickly. Very Urgent is a very dangerous exploit/virus that is spreading. For instance, this VBS/Psyme variant is low, while the notification to patch because exploits for the April patches were found in the wild was Urgent, and a new NetSky variant found in the field but getting mostly low (but a few medium) risk ratings was rated as Medium.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5356" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/VIRUSES/default.aspx">VIRUSES</category><category domain="http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx">ANNOUNCEMENTS</category></item><item><title>New Section: In-Depth Virus Descriptions</title><link>http://msmvps.com/blogs/trafton/archive/2004/04/17/5141.aspx</link><pubDate>Sat, 17 Apr 2004 19:05:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5141</guid><dc:creator>trafton</dc:creator><slash:comments>4</slash:comments><description>&lt;p&gt;A new section can now be viewed under “Virus Descriptions” on the FAQ part of the links section (the bar to your left.) From the description:&lt;br /&gt;&lt;br /&gt;”There are a number of viruses that have a good amount of information published online, but it seems to be scattered across a number of difficult-to-find web sites. The intention of this database is to organize and describe a collection of common but poorly documented viruses. It will be updated with a new description each week. The two fields represent a mathematically-calculated 100-based risk scale, and then the viruses sorted alphabetically.”&lt;br /&gt;&lt;br /&gt;The first write-up to be added is for the Kazaa-based high-level file infecter W32.HLLP.Hantaner. I hope to add one per week as the section grows. Hopefully you will find it informative and helpful.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5141" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx">ANNOUNCEMENTS</category></item><item><title>New Article Available: Submitting Virus Samples</title><link>http://msmvps.com/blogs/trafton/archive/2004/04/11/4888.aspx</link><pubDate>Sun, 11 Apr 2004 16:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:4888</guid><dc:creator>trafton</dc:creator><slash:comments>552</slash:comments><description>&lt;p&gt;I just posted an article I wrote detailing the various antivirus vendors and how to submit samples to them. I hope to update this with more vendors as time goes on, as well as more details, especially about the isolation of infected files, something which is quite difficult to do over the Internet. You can find the article &lt;a href="http://msmvps.com/trafton/posts/4887.aspx"&gt;here&lt;/a&gt;. I have also added it to the FAQ links section under “Submitting Virus Samples.”&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=4888" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx">ANNOUNCEMENTS</category></item><item><title>Hello World</title><link>http://msmvps.com/blogs/trafton/archive/2004/04/09/4821.aspx</link><pubDate>Fri, 09 Apr 2004 12:34:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:4821</guid><dc:creator>trafton</dc:creator><slash:comments>8</slash:comments><description>&lt;p&gt;&lt;em&gt;Originally posted: Wednesday, April 7th, 2004 at 10:42 PM PDT. This should be the first post before The Daily Update, but .Text got the times messed up. Oh well.&lt;/em&gt;&lt;/p&gt;
&lt;h3&gt;Greetings&lt;/h3&gt;
&lt;p&gt;Hello and welcome to the uncreatively titled &lt;i&gt;Security Manifest&lt;/i&gt; (I &lt;a href="mailto:trafton@jazz2online.com"&gt;welcome&lt;/a&gt; any suggestions for a more colorful handle.) I'd like to start out with a note on the use of "manifest" in the title instead of, say, "blog": this is not really a traditional blog, &lt;i&gt;per se&lt;/i&gt;. Actually, I am probably just kidding myself. This is pretty much a blog, but the word "blog" has always sounded to me like some sort of bad-tasting Scandinavian dessert dish. As for more serious issues, read on.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;h3&gt;Who?&lt;/h3&gt;
&lt;p&gt;My name is Benjamin Johnstone-Anderson. I’m a 14-year-old student from Washington state in the United States. I enjoy sunsets, long walks on the beach, and people who don’t wait a month to apply critical security patches. Also, I was awarded as a Microsoft &lt;a href="http://mvp.support.microsoft.com/"&gt;MVP&lt;/a&gt; (Most Valuable Professional) for Windows Security, specifically for work on breaking virus news at the McAfeeHelp &lt;a href="http://forums.mcafeehelp.com/"&gt;&lt;font color="#000088"&gt;Forums&lt;/font&gt;&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;h3&gt;What?&lt;/h3&gt;
&lt;p&gt;Ideally, &lt;i&gt;Security Manifest&lt;/i&gt; will provide a competent collection of security information from many sources in a prompt and accurate manner. On most days, there will be one post on &lt;i&gt;SM&lt;/i&gt; containing a summary of the day’s events in the security field, and perhaps a few additional points of note. On more active days, &lt;i&gt;El Manifesto&lt;/i&gt; may have several additional posts for up-to-the-minute updates. This may increase or decrease for temporarily periods of time as schedules allow. Information will be collected from various sites, such as news wires, antivirus vendor sites, industry publications, and the usual other suspects. &lt;br /&gt;&lt;br /&gt;I will do my best to present an accurate, marketing-free news source. However, due to the fast-changing nature of the security world, wires sometimes cross, but &lt;i&gt;The Manifest&lt;/i&gt; will do its darnedest to filter out the most plausible, and hopefully correct, details. Although the most complete information will be provided, it is not recommend anyone utilize &lt;i&gt;SM&lt;/i&gt; for mission-critical business. It is targeted primarily to security-aware techies and intermediates with a will to expand their horizons.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;h3&gt;Conflicts of Disinterest&lt;/h3&gt;
&lt;p&gt;The cynical may point out that working as a volunteer on the McAfeeHelp Forums and being a Microsoft MVP could cause a conflict of interest. Sure, I’m a human with good knowledge of the security world, and this means I have opinions. Chief among these are that customers should feel free to chose their own operating systems, antivirus programs, firewalls, and software in general. My job as a Microsoft MVP is to support people using Microsoft products with improving their experiences on them. My best knowledge is in Windows, as it is the only operating system I use much, and this is why I will focus on Windows security. Most security news is Windows-related, in fact, and my intent is not to fan the flames of any sort of software war, but to provide information about how users can protect themselves.&lt;br /&gt;&lt;br /&gt;I will make no stance on what constitutes a better antivirus program. Really, most every virus scanner these days can detect most every common virus. For those truly concerned about technical details, I recommend &lt;i&gt;Virus Bulletin&lt;/i&gt;, which publishes an occasional highly controlled review of most major antivirus programs, and some smaller ones, and tests them against a recent list of viruses that are spreading in the field. As obvious from these tests, all of the programs are generally fairly matched, and which one to chose is a personal question which I will not comment on.&lt;br /&gt;&lt;br /&gt;I will, however, recommend free removal tools as I see fit. McAfee’s &lt;i&gt;Stinger&lt;/i&gt; is more or less unique in this realm, as it does not specifically constrict the scan to one worm. For those on slower connections, this may not be the best choice, which is why I’ll also recommend a remover specific to that worm if it is available.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;h3&gt;Thanks&lt;/h3&gt;
&lt;p&gt;Thanks go out for various things to Kelly Marshall, Jurren Bouman, the McAfeeHelp.com Forum staff, all of the Windows Security MVPs (and Susan Bradley, who manages to do ten things at once better than anyone else can do one). Special thanks go to Harry Waldron and Jerry Bryant.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;h3&gt;The Future&lt;/h3&gt;
&lt;p&gt;I hope to soon move &lt;i&gt;Security Manifest&lt;/i&gt; to a better server, as LiveJournal really isn't the proper place. Any suggestions are more than welcomed, especially those regarding hosting.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=4821" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/ANNOUNCEMENTS/default.aspx">ANNOUNCEMENTS</category></item></channel></rss>