Showing posts with label Windows XP. Show all posts
Showing posts with label Windows XP. Show all posts

Friday, April 05, 2013

Microsoft Products Reaching End of Support


The products listed in the table below are major products reaching end of support in the next six months.  Of significance is Windows 7 operating systems without Service Pack 1 (SP1) installed.  If you have not updated or are not sure if you have SP1 installed, see Windows 7 Service Pack 1 (SP1) Added to Automatic Update which includes instructions on how to check if it has been installed.

As a reminder, end of support is just a year away for Windows XP SP3 and Office 2003.  Support for Windows XP SP3 and Office 2003 ends on April 8th, 2014.

What does it mean when support ends?

The most significant change is that the end of support means that there will be no new security updates.  There will also not be any non-security hotfixes, free or paid assisted support options, or online technical content updates.

From the Microsoft Support Lifecycle Policy Newsletter:

     
The following list represents some of the products reaching end of support in the next 6 months. For a comprehensive list of Microsoft products and their lifecycle policy timelines, please search the Support Lifecycle Product Database.

 Product  End Date
 SQL Server 2000 SP4  April 9, 2013
 Windows Server Amp Web Server 2008 R2  April 9, 2013
 Windows 7 SP0*  April 9, 2013
 Visual FoxPro 8.0 Professional Edition  April 9, 2013
 Commerce Server 2002  July 9, 2013
 Dynamics SL7 SP3  July 9, 2013
 SharePoint Services 2.0  July 9, 2013
 Visual J# .NET 1.1 Redistribution Package  July 9, 2013
 Windows Automotive 4.2  July 9, 2013
 Windows CE .NET 4.2  July 9, 2013

* After April 9, 2013, no Security Updates will be issued for Windows 7 RTM. To remain secure, and continue getting Security Updates, customers are encouraged to upgrade to Windows 7 SP1.

References



Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Wednesday, February 20, 2013

Happy 1st Anniversary, Sysnative.com!


Sysnative.com Anniversary


It was one year ago today that hosting and vBulletin 4 software license were purchased by site owner and fellow Microsoft MVP John Griffith, for the express purpose of BSOD App development at Sysnative.com

A year later and not only was the goal of further development of the Sysnative BSOD App achieved (and ongoing), but also Sysnative has grown into a full-fledged support forum.  A wonderful and talented group of people have contributed to making Sysnative a wonderful place to both provide and obtain help.

If you need help, would like to learn more about analyzing BSOD's or see the amazing work being done solving Windows Update and other computer problems, join us at Sysnative.com!  Membership and help are free.  Only registration is required. 

To get a taste for the wide range of areas covered, see Lots of help here...this tells you where to find it



Additional information:  Sysnative - What is it?


Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Wednesday, May 30, 2012

Sysnative - What is it?

*

Sysnative is a term that has two meanings.  For those interested in the technical explanation, refer to the section on Sysnative in 64-Bit Windows operating systems below.

The other use of Sysnative, and the usage of interest to readers of Security Garden, is that it is the domain name for Sysnative.com.

What is special about Sysnative.com?  Let's find out.

About Sysnative.com

At one time or another, most people who use the Windows operating system have experienced the dreaded "Blue Screen of Death" (BSOD) -- until Windows 8, a strange blue screen filled with numbers and codes, completely incomprehensible to most everyone.

Granted, there are occasions where a shutdown/restart or evoking "Last Known Good Configuration" appear to have resolved whatever issue caused the BSOD.  More times than not, however, help is needed to trace the source of the problem.  This is where Sysnative.com comes in to play.

Sysnative.com is the result of a vision of Microsoft MVP, John Griffith. John, known in forum communities as jcgriff2, specializes in Blue Screen of Death (BSOD) Kernel dump analysis.  John also enjoys a reputation as an expert Windows forensic troubleshooter, typically sought by Windows Vista and Windows 7 owners after all else has failed.

John developed an application for use by BSOD OPs known as the "jcgriff2 BSOD File Collection app". The output, including mini kernel memory dumps, is used by BSOD Analysts who assist computer users in tracking down the source of the BSODs plaguing their computers.

John also developed BSOD kernel dump file scripts that automate many of the mundane tasks performed by the Windbg GUI. The scripts allow the running of multiple BSOD kernel dump files vs. running dumps one-by-one with Windbg.  In addition, the scripts also incorporate a direct interface to the Driver Reference Table, known as DRT, created by former Microsoft MVP John Carrona for driver look-ups.

The contributions by many talented people who are involved in analyzing the data compiled by John's application have made the "jcgriff2 BSOD File Collection app" and the "jcgriff2/niemiro BSOD Dump Processing Scripts" the tools of choice for BSOD Kernel Dump Analysis.

Should you be faced with the dreaded Blue Screen of Death, expert assistance is available from the many talented analysts at Sysnative.com.  Registration at the site is free, as is the help.  Follow the BSOD Posting Instructions and rest assured, help is on the way!

Wait, there is more!

That is correct.  Help isn't limited to BSOD crash analysis, debugging and error reports.  Getting Help with Windows Update/SFC is also very popular at Sysnative with people who have Windows Update issues.  Help and information are available from Microsoft MVPs, Windows Insider MVPs,, Microsoft MCCA's as well others knowledgeable in Microsoft Windows Operating Systems, Security, Programming, Networking, Graphics, and Games.

*Sysnative Logo

The logo for Sysnative.com, displayed above, was created by a very talented graphic designer.  I have long been acquainted with the designs he has made for ASAP members and member sites and was very excited when he volunteered to create a logo for Sysnative.com.

Aside from the fantastic Sysnative logo, one of my favorite examples of this talented designer, known on various help forums as NJustice or N_J, is the artwork and website design for Amelia Eisenhauer, a talented young singer.

If you or someone you know are in the market for a custom design, I heartily recommend contacting Amazing Dezigns.

Sysnative in 64-Bit Windows 

The Sysnative alias was first seen with Windows Vista.  The Sysnative folder is used by a 32-bit application to access the native system folder instead of the %WinDir%\System32 folder.  In addition, WOW64 recognizes the Sysnative folder as a special alias.  As a result, the file system does not redirect access away from the Sysnative folder. This mechanism is flexible and easy to use and the Sysnative folder can be used to bypass file system redirection.

Additional information is available at MSDN in "File System Redirector". 



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...



Wednesday, April 18, 2012

Understanding Microsoft Anti-Malware Software

Microsoft provides a variety of security products for both consumers as well as business environments.  With multiple products available, there is bound to be questions and, occasionally, confusion on which product to use. 

This article is presented to help clarify questions about the variety of Microsoft anti-malware products.  (Updated:  08Oct2014)

Microsoft Security Essentials

Microsoft Security Essentials (MSE) is an antivirus, anti-malware, anti-spyware software providing real-time protection for your computer.  Microsoft Security Essentials is free for home users as well as small and medium businesses with up to ten (10) PC's.  If your business has more than 10 PCs and, therefore, it is against the license terms to use MSE, consider System Center 2012 Endpoint Protection, described below.

MSE works on Windows 7, Windows Vista and Windows XP*.  However, your PC must run genuine Windows to install Microsoft Security Essentials.  Beware of rogue/scam offerings and only download Microsoft Security Essentials from the Microsoft Safety & Security Center.

Definition updates for MSE are obtained automatically through the program or downloaded directly from the Microsoft Malware Protection Center (MMPC) Portal.  You may also be offered updates through Windows Update.

Note*With Windows XP having reached "end of life" on April 8, 2014, Microsoft has stopped providing Microsoft Security Essentials for download for that operating system.  Definitions will continue to be available for Windows XP until July 15, 2015.  See Microsoft antimalware support for Windows XP.
 

Windows Defender (Windows 8)

Adding to the confusion between the anti-spyware program named Windows Defender and the boot-scan software Windows Defender Offline, is Windows Defender installed on Windows 8. In addition to including all of the same features as Microsoft Security Essentials, Windows Defender on Windows 8 will interface with Windows secured boot, a new Window 8 protection feature.

On a PC that supports UEFI-based Secure Boot, Windows secured boot will help ensure that all firmware and firmware updates are secure.  By loading only properly signed and validated code in the boot path, the entire Windows boot path up to the anti-malware driver will be checked to ensure that it has not been tampered with. 

Like Microsoft Security Essentials, definition updates for Windows Defender on Windows 8 are obtained automatically through the program or downloaded directly from the Microsoft Malware Protection Center (MMPC) Portal.  You may also be offered updates through Windows Update.

Note:   Do not attempt to install Microsoft Security Essentials on Windows 8.  It is incompatible with Windows 8.  Windows Defender on Windows 8 incorporates the antivirus engine of Microsoft Security Essentials.  If you elect to install a different antivirus product on Windows 8, Windows Defender will be disabled.

Microsoft Safety Scanner

The Microsoft Safety Scanner is a no-frills scanner to help remove viruses, spyware, and other malicious software. The Microsoft Security Scanner will work with your existing antivirus software but it is not a replacement for a resident antivirus software program.

The Microsoft Safety Scanner works on Windows 7, Windows Vista and Windows XP.  There is no charge to use the Microsoft Safety Scanner and there is no requirement to prove Windows is genuine.

The Microsoft Safety Scanner expires ten (10) days after being downloaded. The reason for the expiration time is at the point of downloading the Microsoft Safety Scanner, it installs the most recent definitions from the Microsoft Malware Protection Portal (MMPC). Due to the frequency of definition updates, even after one day, the definitions are outdated.  The Microsoft Safety Scanner uses the same definitions that are used for Microsoft Security Essentials and Microsoft Forefront.

For instructions on the use of the Microsoft Safety Scanner, you may be interested in this brief tutorial:   How to Use the New Microsoft Safety Scanner.

Malicious Software Removal Tool

The Malicious Software Removal Tool (MSRT) scans for select malware only. Microsoft releases an updated version of the MSRT on the second Tuesday of each month along with security updates.  Additional updates are added as needed to respond to security incidents.  The current list of targets for removal is available at Families Cleaned by the Malicious Software Removal Tool.  

The MSRT works on Windows 7, Windows Vista, Windows XP, Windows Server 2003, or Windows Server 2008 and is available from Microsoft Update, Windows Update and the Microsoft Download Center.

As explained in Microsoft KB Article 890830, the Microsoft Malicious Software Removal Tool is not a substitute for antivirus software.  There is no real-time protection and, as shown in the above-referenced list of families cleaned, the MSRT is targeting specific prevalent malicious software that is actively running on the computer.

Windows Defender Offline

Originally named Microsoft Standalone System Sweeper, the released tool was renamed "Windows Defender Offline". The original tool had long been a part of the Microsoft Diagnostics and Recovery Toolset (DaRT) for Microsoft Enterprise customers.

Windows Defender Offline is a recovery tool currently available from Microsoft.  The tool is not a general, all-purpose scanner and is not a replacement for an updated antivirus program.  Rather, it is to help start an infected PC and perform an offline scan to identify and remove rootkits and other advanced malware.

Windows Defender Offline can also be used in situations where antivirus software fails to install or the program that is installed is unable to detect or remove malware from the computer.

A unique feature of Windows Defender Offline is if a rootkit or other advanced malware is detected on your PC by Microsoft Security Essentials, Windows Defender, Forefront Endpoint Protection or System Center Endpoint Protection, you will be prompted to download and run Windows Defender Offline.

For additional information on setting up and scanning with Windows Defender Offline, refer to the tutorial created under the former name, Standalone System Sweeper, at Setting Up the Microsoft Standalone System Sweeper Beta, Now Windows Defender Offline.

Windows Defender (Anti-Spyware)

Windows Defender anti-spyware software is available for installation on Windows XP and Windows Server 2003.  Windows Defender is pre-installed on Windows Vista, Windows 7 and Windows Server 2008 (enabled if the Desktop Experience feature is installed).  It is not an anti-malware software.  Rather, it is a free active system monitor that provides real-time protection against pop-ups, slow performance, and security threats caused by spyware and other unwanted software.

Windows Defender can be downloaded from the Windows Download Center 
Note:  Microsoft Security Essentials as well as Windows Defender on Windows 8 include the anti-spyware engine of Windows Defender.

Microsoft Forefront

Update December 17, 2013:

"Today, Microsoft is announcing important changes to the roadmaps of Forefront Identity Manager (FIM) and Forefront Unified Access Gateway (UAG):
  • We plan to ship another major release of FIM in the first half of calendar year 2015
  • Microsoft will not deliver any future full version releases of Forefront UAG and the product will be removed from price lists on July 1, 2014.
Microsoft remains committed to delivering the identity and access capabilities offered in FIM (identity and access management).  Some Forefront UAG scenarios (secure application publishing and remote access) are addressed with new capabilities available in Windows Server 2012 R2 today."
See the complete article, "Important Changes to the Forefront Product Line"

 ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

The Microsoft Forefront product line was revamped, with most of the product line discontinued, although maintenance and support continues through the standard Microsoft support product life cycle. (See Important Changes to Forefront Product Roadmaps.)

Remaining in the product line are Forefront Unified Access Gateway 2010 and Forefront Identity Manager 2010 R2, security products for business customers.  These products are designed to be centrally managed and integrated into IT infrastructure products.

Microsoft Forefront is intended to scale to many thousands of users.  It uses the same definitions as Microsoft Security Essentials and the Microsoft Safety Scanner.

Microsoft Exchange Online Protection

The Exchange Online Protection service was formerly called Forefront Online Protection for Exchange.  As a spam filtering and anti-malware service integrated with Office 365 services.

Windows Intune Microsoft Intune*

Microsoft Intune is an Enterprise Solution that provides PC Management and Security in the Cloud.  It is an end-to-end Microsoft solution that brings together Windows cloud services for PC management and endpoint protection with a Windows 7 Enterprise upgrade subscription.

Through the web-based console, IT Staff can centrally manage and secure all the company PCs.  Windows Intune includes support for Windows RT, Windows Phone 8, iOS, and Android platforms.

Included in the numerous features of Windows Intune is malware protection, using the same definitions Microsoft Forefront and Microsoft Security Essentials.

 ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

October 8, 2014 Update, Quote, Windows Intune to be renamed to Microsoft Intune - The Windows Intune Team Blog:
"Today we are announcing that in its next major update, coming later this year, Windows Intune will be renamed to Microsoft Intune.

This change reflects Microsoft’s ongoing strategy for Intune as a cloud-based mobile device management (MDM) and mobile application management (MAM) solution. The “Microsoft Intune” name more accurately represents Intune’s capabilities, supporting both iOS and Android platforms, in addition to Windows. It is also in alignment with our commitment to embrace the new dynamics of the workplace, and increase employee productivity by enabling them to work wherever and whenever they want on any device, while helping IT keep corporate information secure.

Intune is included in the Enterprise Mobility Suite (EMS) which is Microsoft’s comprehensive and cost-effective solution for addressing consumerization of IT, BYOD, and SaaS challenges. The suite also includes Azure Active Directory Premium and Azure Rights Management."

Enterprise Mobility Suite

Enterprise Mobility Suite is the comprehensive cloud solution to address consumerization of IT, BYOD, and SaaS challenges. The suite is the most cost effective way to acquire all of the included cloud services:
  • Microsoft Azure Active Directory Premium
  • Windows Intune
  • Microsoft Azure Rights Management

System Center 2012 Endpoint Protection

Microsoft System Center 2012 Endpoint Protection was previously known as Forefront Endpoint Protection 2010.  System Center 2012 Endpoint Protection provides the ability to consolidate desktop security and management in a single solution.

System Center 2012 Endpoint Protection is built on System Center 2012 Configuration Manager.  It provides a single, integrated platform that reduces your IT management and operating costs.

Questions and Answers

Q.  Does the Microsoft Safety Scanner include all of the definitions included in the Malicious Software Removal Tool?
A.  Yes, at the time of download, the Microsoft Safety Scanner will include the same target families as the Malicious Software Removal Tool.  However, the Microsoft Safety Scanner includes more than specifically targeted prevalent malicious software.

Q.  Does the Malicious Software Removal Tool include definitions that are not included in the Microsoft Safety Scanner?
A.  No, although if the timing is such that additional targeted families or variants were added to the Malicious Software Removal Tool after the download of the Microsoft Safety Scanner, those families or variants would obviously not be in the already downloaded Microsoft Safety Scanner.

Q.  In terms of detection and removal, does the Microsoft Safety Scanner offer what the Malicious Software Removal Tool offers?
A.  The Malicious Software Removal Tool has specific malicious targets whereas the Microsoft Safety Scanner targets not only the same specifically targeted malicious programs as the Malicious Software Removal Tool, but also targets the same viruses, spyware, and other malicious software included in Microsoft Security Essentials and Microsoft Forefront.

Q.  Do users need both the Microsoft Safety Scanner and Malicious Software Removal Tool?
A.  The simple answer is No.  In point of fact, if you are using Microsoft Security Essentials as your antivirus product, you theoretically do not need either the Microsoft Safety Scanner or the Malicious Software Removal Tool.  However, there are instances where, for one reason or another, there is a problem updating MSE or the need to clean a computer that does not have Internet access.  Another valuable use of these tools is if your computer has a virus that your current antivirus software missed or is unable to remove.

Q.  Is there any point in running both the Microsoft Safety Scanner and Microsoft Security Essentials?
A.  No.  The Microsoft Safety Scanner uses the same definitions as Microsoft Security Essentials.  However, if Microsoft Security Essentials detects a rootkit or other advanced malware on your computer, you may be prompted to run Windows Defender Offline.

Q.  Can I download both the 32 bit and the 64 bit versions of the Microsoft Safety Scanner to a USB stick and take to another computer to run the correct version for the destination machine?
A.  I suggest that you create a separate folder for each version of the download as both the 32-bit and 64-bit versions are named the same, as msert.exe.

Q.  How do I know if I have the latest definitions?
A.  The change log for the latest definitions for not only Microsoft Security Essentials but also Microsoft Forefront and Windows Defender is available from the Microsoft Malware Protection Center (MMPC) Portal.
Q.  I installed Microsoft Security Essentials and now Windows Defender isn't available.  Why?
A.  The anti-spyware engine and real-time protection of Windows Defender are incorporated in Microsoft Security Essentials and Windows Defender on Windows 8. 
Q.  Does Microsoft provide server and cloud security software and services?

AWindows Intune provides both PC management and cloud security features.  For Microsoft servers, the Microsoft System Center 2012 Endpoint Protection consolidates desktop security and management in a single solution.



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Thursday, January 06, 2011

Microsoft Fix it Available for Security Advisory 2490606

Two days ago, Microsoft released Security Advisory 2490606 to address a publicly disclosed vulnerability affecting Microsoft Windows Graphics Rendering Engine, Microsoft was not aware of any public attacks.  That has since changed and Microsoft has started to see targeted attacks.  As explained in the Security Advisory,

"An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the logged-on user. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights."

It is important to note that the vulnerability does not affect Windows 7 or Windows Server 2008 R2.  However, it does affect Windows Vista, Windows Server 2003, and Windows XP.


In addition to the common sense advice to enable a firewall, get software updates (including third-party software) and install antivirus software, Microsoft has created a Fix it solution as a workaround option for some scenarios. To enable the solution until a security update is released, download and run Microsoft Fix it 50590.  After a security update is released, merely reverse the process by downloading and running Microsoft Fix it 50593.


Enable:  Microsoft Fix it 50590
Disable: Microsoft Fix it 50593









Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Tuesday, January 04, 2011

Microsoft Security Advisory 2490606


Microsoft released Security Advisory 2490606 to address a publicly disclosed vulnerability affecting Microsoft Windows Graphics Rendering Engine on Windows Vista, Windows Server 2003, and Windows XP.  The vulnerability does not affect Windows 7 or Windows Server 2008 R2.

Microsoft is not currently aware of any affected customers or of any active attacks, which could occur from visiting a specially crafted malicious Web page or opening a malicious Word or PowerPoint file. Accounts configured as a limited user (fewer user rights) would be less affected by an attack then those running as administrator.  Be sure to apply the latest Microsoft security updates to help make sure that your computer is as protected as possible.

Additional information is available in the MSRC post and the Security Advisory, linked below.


References:


Clubhouse Tags: Clubhouse, Microsoft, Windows, Security, Advisory, Vulnerabilities, Information, Windows XP,


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Thursday, December 30, 2010

How to Block the New Fast Flux Botnet

The folks at Shadowserver have reported on a new spam campaign that, at first looked like the holiday e-card scams that have been around for many years.  After closer inspection of the details, it appears that it could be the next generation of Storm Worm or Waledac.

Below you'll find a list of subjects in the spam campaign reported by Stephen Adair in New Fast Flux Botnet for the Holidays: Could it be Storm Worm 3.0?.  The e-mails are coming from all over the Internet with spoofed sender addresses.
Greeting for you!
 Greeting you with heartiest New Year wishes
 Greetings to You
 Happy New Year greetings e-card is waiting for you
 Happy New Year greetings for you
 Happy New Year greetings from your friend
 Have a happy and colorful New Year!
 l want to share Greeting with you (Shadowserver note: the first letter is an L)
 New Year 2011 greetings for you
 You have a greeting card
 You have a New Year Greeting!
 You have received a greetings card
 You've got a Happy New Year Greeting Card!
The email contains a link to a compromised website.  Clicking the link results in a redirect to one of the new malicious domains being used by the botnet.  As explained in the report, "these are fast flux domains that will frequently return a new IP address each time they are resolved."


From New Fast Flux Botnet for the Holidays: Could it be Storm Worm 3.0?, the currently known domains hosting the botnet, whose purpose is to install malware, are listed below with the appropriate entry to add to your HOSTS file if you wish to block the domains.

If you use WinPatrol, it is easy to edit the HOSTS File, regardless of whether you are running Windows XP, Windows Vista or Windows 7,

  • Right-click on Scotty in the system tray to launch WinPatrol, selecting "Options".
  • Windows Vista and Windows 7 Users: Accept any UAC Prompts
  • Click "View HOSTS file", which will launch in Notepad
  • In Notepad copy/paste the following entries:

    127.0.0.1  bethira.com

    127.0.0.1  bitagede.com
    127.0.0.1  cifici.com
    127.0.0.1  darlev.com
    127.0.0.1  elberer.com
    127.0.0.1  envoyee.com
    127.0.0.1  leolati.com
    127.0.0.1  makonicu.com
    127.0.0.1  nurealla.com
    127.0.0.1  scypap.com
    127.0.0.1  suedev.com
    127.0.0.1  teddamp.com
    127.0.0.1  eplarine.com

  • Click File > Save
  • Close Notepad
  • Close WinPatrol


If you do not use WinPatrol (you should!), you can manually edit the HOSTS file.  It just takes a bit more effort.

With default Windows installations, the HOSTS file is located at C:\Windows\System32\drivers\etc.  If you use Windows 7, it is necessary to first click on Start, type in Notepad and then right-click on Notepad and choose Run as Administrator.  Then, for all systems (Windows XP, Windows Vista and Windows 7), right-click hosts and select to open with Notepad. 


This is an example of what you will see when Notepad launches the HOSTS File:

# Copyright (c) 1993-2009 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
#      102.54.94.97     rhino.acme.com          # source server
#       38.25.63.10     x.acme.com              # x client host

# localhost name resolution is handled within DNS itself.
#    127.0.0.1       localhost
#    ::1             localhost

After the last line in the HOSTS file, paste the entries below
127.0.0.1  bethira.com
127.0.0.1  bitagede.com
127.0.0.1  cifici.com
127.0.0.1  darlev.com
127.0.0.1  elberer.com
127.0.0.1  envoyee.com
127.0.0.1  leolati.com
127.0.0.1  makonicu.com
127.0.0.1  nurealla.com
127.0.0.1  scypap.com
127.0.0.1  suedev.com
127.0.0.1  teddamp.com
127.0.0.1  eplarine.com

Save and close Notepad. 

Your HOSTS file has been updated and those malware domains have been blocked.

Clubhouse Tags: Clubhouse, Security, Privacy, How-To, Information, Tutorial, Family Safety, Windows Vista, Windows 7, Windows XP,


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Friday, October 16, 2009

MS09-054: IE and Firefox Attack Surface

The Security Research & Defense blog provided additional information on the attack surface for the IE Security Bulletin MS09-059, Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (975467). As explained:

“A browse-and-get-owned attack vector exists. All that is needed is for a user to be lured to a malicious website. Triggering this vulnerability involves the use of a malicious XBAP (XAML Browser Application). Please not that while this attack vector matches one of the attack vectors for MS09-061, the underlying vulnerability is different. Here, the affected process is the Windows Presentation Foundation (WPF) hosting process, PresentationHost.exe.

While the vulnerability is in an IE component, there is an attack vector for Firefox users as well. The reason is that .NET Framework 3.5 SP1 installs a “Windows Presentation Foundation” plug-in in Firefox”

In other words, if you happen upon a malicious website, with the Windows Presentation Foundation (WPF) plug-in enabled in Firefox, your computer is vulnerable.

Recommendations:

Internet Explorer

Although XBAP is disabled in IE8 on Win2k8 and Win2k3, that is not the case for IE7 or other operating systems. To disable this setting, edit the security settings in the Internet Zone as follows:

Launch Internet Explorer --> Click Tools --> Security Tab --> in Internet, click Custom level. Under .NET Framework --> XAML browser applications, Change the setting to Disable:

IE_NetFramework


Firefox:

The WPF plug-in was installed in Firefox with .NET Framework 3.5. To disable the plug-in, do the following:

Click Tools --> Add-ons --> Click the Plugins Tab.
Select “Windows Presentation Foundation”, and click “Disable”.

FF_DisableWPF

To uninstall the “Windows Presentation Foundation” plug-in from Firefox, see to Microsoft KB Article 963707, How to remove the .NET Framework Assistant for Firefox.




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Thursday, November 20, 2008

Planning on Upgrading from XP to Windows 7?

I am sure a lot of people who decided to hold off on the upgrade from Windows XP to Windows Vista were now looking to waiting until 2009 when Windows 7 is RTM. As Ed Bott clearly explains in No upgrades from XP to Windows 7?

"If that’s your strategy, you probably need to be aware that, at least in the current not-a-beta release, upgrades from XP to Win7 are blocked. (I don’t know whether this restriction will be in the final edition as well, but I bet it is.) You can do a clean install only, with all your old Windows files going to a Windows.old directory and none of your files and settings transferred (you can, however, use Windows Easy Transfer to save settings first and restore them later).

So the compatibility issues you’re ignoring right now aren’t going to go away. If you have apps or hardware drivers that only work on XP and aren’t compatible with Vista, you’re going to have those same issues with Windows 7, which isn’t going to magically fix anything."






Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Tuesday, November 18, 2008

Windows Live OneCare Ending, Morro No-Cost Replacement

Microsoft announced today that the company is discontinuing Windows Live OneCare (WLOC), although support will continue for current WLOC subscribers until the subscriptions expire. WLOC is an all-in-one suite that includes a number of non-security features that most subscribers ignored (i.e., printer sharing and automated PC tune-up).

I am wondering if the indication in the PressPass announcement that "Morro" will be a stand-alone download providing malware protection for the Windows XP, Windows Vista and Windows 7 operating systems implies that Morro will supplement or replace Windows Defender. Since Morro won't be available until the second half of 2009 (perhaps introduced with Windows 7?)


PressPass Announcement:
Code-named “Morro,” this streamlined solution will be available in the second half of 2009 and will provide comprehensive protection from malware including viruses, spyware, rootkits and trojans. This new solution, to be offered at no charge to consumers, will be architected for a smaller footprint that will use fewer computing resources, making it ideal for low-bandwidth scenarios or less powerful PCs.
. . .

“Because uptake of standard anti-malware is low around the world, particularly in developing nations, the availability of basic protection for anyone who wants it is all the more important,” said Roger Kay, founder and president of Endpoint Technologies Associates. “By offering such basic protection at no charge to the consumer, Microsoft is promoting a safer environment for PCs, service providers and e-commerce itself, since it is through unprotected PCs that the worst threats are introduced to the system as a whole.”

“Morro” will be available as a stand-alone download and offer malware protection for the Windows XP, Windows Vista and Windows 7 operating systems. When used in conjunction with the ongoing security and privacy enhancements of Windows and Internet Explorer, this new solution will offer consumers a robust, no-cost security solution to help protect against the majority of online threats.

Hat tip: Paddy

References
:




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Friday, July 18, 2008

Windows Search 4 Coming Soon

As you may recall, I introduced you to Windows Talk Blog the other day. It was from James' post, Possible Vista 'Speed-up'?, that I was led to an article by Jeff Alexander and from there to a Microsoft description of Windows Search 4, which in turn led to a half-dozen short demos that show how you can get the most from Search in Windows Vista or Windows XP.

You get the picture, one good link always seems to lead to another. However, when I saw the reminder by the Microsoft Update Product Team today that Microsoft is planning to release Windows Search (KB 940157) via Windows Update late this month, I knew it was time to pull together all the resources I located after reading James's post for Security Garden readers (as well as my own future reference!)

According to the Microsoft Product Update Team, if you have Windows XP, Windows Search 4.0 will be an "Optional Update". Windows Search 4.0 will be shown as a "Recommended Update" for Windows Vista SP1. It is important to note that the installation of Windows Search 4.0 will involve a re-indexing of the data on the computer. See the details in Reminder - Windows Search 4 coming to WU soon...

To learn about Windows Search 4.0, refer to the collection of references below.

References:




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Monday, June 30, 2008

Windows XP SP3 Hotfix

Early this month, I reported that Symantec had addressed the issues customers using Norton 2008 experienced when installing Windows XP Service Pack 3 or Windows Vista Service Pack 1.

Based on a post by dickw at LandzDown Forum, I learned that Microsoft has provided a hotfix for users who have installed Windows XP Service Pack 3 with an antivirus application still running during the installation, which could result in Device Manager not showing any devices and/or and Network Connections not showing any network connections.

The hotfix is available at Update for Windows XP (KB953979).

Before installing SP3, I recommend reviewing the following:
References:



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Thursday, June 19, 2008

Microsoft Security Bulletin MS08-030 Revised

For Windows XP SP2 and Windows XP SP3 only:

Microsoft identified quality issues with Microsoft Security Bulletin MS08-030, which was originally released June 10, 2008. The original version of MS08-030 did not effectively address the vulnerability MS08-030 was intended to address. The intended fix is in the Bluetooth stack in Windows that could allow remote code execution.

Microsoft has provided updated versions of the affected security updates and re-issued MS08-030. This is a critical update and it is recommended that it be re-applied as soon as possible.

Note: All other versions of the security update provide protection against the issues discussed in the security bulletin.

Refererences:

MSRC: MS08-030 Re-released for Windows XP SP2 and SP3
TechNet: MS08-030


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Friday, June 06, 2008

Norton 2008 Fix for XP SP3 and Windows Vista SP1

Symantec has addressed the issues customers using Norton 2008 have experienced when installing Windows XP Service Pack 3 or Windows Vista Service Pack 1. If you are using Norton 2008, please see FAQ: Upgrading to Windows XP Service Pack 3 or Windows Vista Service Pack 1 with your Norton 2008 product installed.

This solution will address one or more of the following issues::
  • Windows Device Manager is empty
  • Missing Wireless network adaptors or other hardware devices
  • Unable to connect using a wireless adapter
If you have already installed XP SP3 or Vista SP1 Symantec has developed a tool to remove the registry entries that were added during the Windows XP Service Pack 3 or Windows Vista SP 1 upgrade.

For Norton 2008 subscribers who have not yet installed the service packs, install Symantec's LiveUpdate solution first. This prevents the issues from occurring. Ensure that you run LiveUpdate and restart your computer before installing the Service Pack.

See FAQ: Upgrading to Windows XP Service Pack 3 or Windows Vista Service Pack 1 with your Norton 2008 product installed.



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Saturday, May 31, 2008

Windows XP SP3 Available on CD

After over eight years, I was finally able to obtain a reasonable broadband connection, leaving behind all those many years of dial-up. However, I know a lot of people still use dial-up to connect to the internet, some because it is the only means available and others based on financial considerations.

I know that downloading updates on dial-up can be painful at best. Fortunately, Windows XP users can now obtain Service Pack 3 on CD. I do not know the cost of the CD for other regions. For the United States, it appears to be $3.99 USD.

From TechNet:
Windows XP Service Pack 3 (SP3)

Updated May 6, 2008

Windows XP Service Pack 3 (SP3) is now available for download and install via Windows Update and the Microsoft Download Center. Windows XP SP3 includes all previously released updates for the operating system, in addition to a small number of new updates. Windows XP SP3 will not significantly change the Windows XP experience.

Installation media and documentation on disc for Windows XP SP3 may sometimes refer to Windows XP SP2. Windows XP SP2 installation guide instructions apply to Windows XP SP3.

Before installing SP3, I recommend reviewing the following:
Order the Windows XP Service Pack 3 CD:
Asia | Europe and Africa | North America | South America

via Security Ticker




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Friday, May 30, 2008

Microsoft Security Advisory 953818 Combined Attack With Apple’s Safari on Windows Platform

This alert is to notify you that on 30 May 2008 Microsoft released Security Advisory 953818, "Blended Threat from Combined Attack Using Apple’s Safari on the Windows Platform".

From the advisory:

Summary:

Microsoft is investigating new public reports of a blended threat that allows remote code execution on all supported versions of Windows XP and Windows Vista when Apple’s Safari for Windows has been installed. Safari is not installed with Windows XP or Windows Vista by default: it must be installed independently or through the Apple Software Update application. Customers running Safari on the affected platforms should review this advisory.

At the present time, Microsoft is unaware of any attacks attempting to exploit this blended threat. Upon completion of this investigation, Microsoft will take the appropriate measures to protect our customers. This may include providing a solution through a service pack, the monthly update process, or an out-of-cycle security update, depending on customers’ needs.

Mitigating Factors:

Customers who have changed the default location where Safari downloads content to the local drive are not affected by this blended threat.

Recommendations:

Review Microsoft Security Advisory 953818 for an overview of the issue, details on affected components, mitigating factors, suggested actions, frequently asked questions (FAQ) and links to additional resources.

References:



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Wednesday, May 21, 2008

What's in Windows XP SP3?

What is in Windows XP Service Pack 3? Just take a look at Microsoft KB Article 946480, "List of fixes that are included in Windows XP Service Pack 3", published today. That is a some list.

Have you ever wondered why people who analyze HijackThis logs and propose fixes for malware removal at some time during the process also instruct the person receiving help to install the latest service pack? The reason is that, in addition to other patches and fixes, Service Packs include all of the security updates issued since either the time the software was released or last the Service Pack.

Our goal is not only to help get the infected computer clean but also provide suggestions to help the computer owner keep it that way. Having Service Packs installed is one step in that process.

List of Fixes in Windows XP Service Packs:

Windows XP Service Pack 3: Microsoft KB Article 946480
Windows XP Service Pack 2: Microsoft KB Article 811113
Windows XP Service Pack 1a: Microsoft KB Article 324720


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Sunday, May 18, 2008

XP SP3 Failure with Spyware Doctor 5.5 or earlier

It was reported in Microsoft Knowledge Base Article 951403 that "Spyware Doctor 5.5 or earlier versions of Spyware Doctor may cause Windows XP Service Pack 3 to stop responding when you try to install or to uninstall the service pack". Fortunately, the solution only requires disabling Spyware Doctor 5.5 (or earlier versions) during the install or uninstall process of Windows XP SP3.

Once again, the reminder to see the instructions at Recommendations before you install Windows XP Service Pack 3 before installing SP3 or, for that matter, making any major system change. Another good read is Harry Waldron's instructions in Windows XP SP3 - Read all prerequisites for a successful installation.

Considering the headaches with a damaged install, isn't it worth the extra time to prepare first?



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Friday, May 16, 2008

Rumors of Extended Availability of Windows XP

Blogs, forums and news articles are filled with reports about Dell, HP and Lenova making Windows XP available after the June 30, 2008, OEM license availability date.

Until or unless Microsoft extends the date of product support for the Windows XP family and license availability, it certainly seems that vendors would be committing a major disservice to the public by continuing to offer the Windows XP operating system . As the date currently stands, mainstream support for Windows XP ends in April 2009, less than 10 months away. Extended support expires in 2014 (security fixes free all other help paid).

Rather than jeopardizing the security of their customers' computers, it appears that OEM manufacturers would rather put them at risk by selling an outdated operating system. Windows Vista was released to manufacturing over 18 months ago. Certainly sufficient time has lapsed for vendors to upgrade software to be compatible with Windows Vista. If this hasn't happened, you can be assured that it is intentional on the part of the vendor and the product will likely not be updated.

The one exception to the availability of Windows XP is for OLPC's (One Laptop Per Child) XO laptops. While the end date for all other OEM and retail licenses of Windows XP operating systems have a June 30, 2008 end date, the new OEM end date for will be the Ultra Low-Cost PCs will be the later of either June 30, 2010, or one year after the general availability of the next version of Windows.

References:




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Thursday, May 15, 2008

Windows XP SP3 and the Reboot Loop

Many people are aware of the issue with SP3 on OEM (original equipment manufacturer) machines with an AMD chip on an image that was originally Intel-based. The Microsoft Update Product Team blog describes the problem in More on Windows XP Service Pack 3...

"The problem is a registry value, present on images created w/ Intel processors, that causes a driver (intelppm.sys) to load at boot. When intelppm.sys attempts to load on an AMD-based system upon the install of SP3, it causes a blue screen and the continuous reboot."
Although the Update Product Team reports that a filter will be added to block SP3 from affected systems and are investigating a fix (See Edit Note below), Jesper has a complete explanation of the problem as well as a tool he has created to easily repair affected computers. You can find it at "Does your AMD-based computer boot after installing XP SP3?".

Please note that SP3 is not on Automatic Updates yet. It is, however, available from Windows Update. Also remember that Microsoft is providing free, unlimited installation and compatibility support for Windows XP Service Pack 3 (SP3) through April 14, 2009. Additional information is available at http://support.microsoft.com/oas/default.aspx?ln=en-us&prid=11273&gprid=522131


Edit Note 12 June 2008:
See *Update for Windows XP (KB953356)*

Locale: English

Deployment: Windows Update, Microsoft Update, Automatic Updates, WSUS, and Catalog

Classification: High Priority, Non-Security

Target platforms: Windows XP

Approximate file sizes: ~ 509KB

Description:
Install this update to resolve an issue in which your computer may
restart continuously after you upgrade to Windows XP Service Pack 3 on
systems with non-Intel processors. After you install this item, you may
have to restart your computer.
http://support.microsoft.com/kb/894199






Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...