<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-20173187</id><updated>2026-03-18T04:37:14.993-07:00</updated><category term="Updates"/><category term="News"/><category term="Rogue Programs"/><category term="Rogue Alerts"/><category term="Apple"/><category term="Off Topic"/><category term="Spyware Removal"/><category term="Winfixer"/><category term="Me"/><category term="News zango"/><title type='text'>Security Ticker</title><subtitle type='html'>My thoughts on tech, with a security angle</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://securityticker.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default?alt=atom&amp;redirect=false'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default?alt=atom&amp;start-index=26&amp;max-results=25&amp;redirect=false'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>586</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-20173187.post-7506997770170415007</id><published>2025-07-20T23:09:00.000-07:00</published><updated>2025-07-20T23:12:06.005-07:00</updated><title type='text'>Is This Thing Still On? Revisiting Security After 15 Years</title><content type='html'>&lt;p&gt;Wow, this blog is still up. Does anyone still use Blogger? What do people use to find out about security stuff now?&lt;/p&gt;

&lt;p&gt;Back in 2006–2009, antivirus and anti-malware discussions dominated forums and blogs. Today, the security landscape has evolved significantly. Cyber threats have grown more sophisticated, moving far beyond simple viruses and spyware. Ransomware attacks, data breaches, zero-day vulnerabilities, and phishing campaigns are now commonplace. State-sponsored threat actors bring a whole new level of danger.&lt;/p&gt;

&lt;p&gt;I imagine these days people rely on Reddit, but I see &lt;a href=&quot;https://www.bleepingcomputer.com&quot; target=&quot;_blank&quot;&gt;BleepingComputer&lt;/a&gt; and &lt;a href=&quot;https://www.wilderssecurity.com&quot; target=&quot;_blank&quot;&gt;Wilders Security Forums&lt;/a&gt; are still around. My user accounts are still there and I can log into them. I should post something. I&#39;m sure YouTube is also big. Nice to see Krebs on Security is still around. I remember when he was still with the Washington Post.&lt;/p&gt;

&lt;p&gt;So, Blogger might feel a bit vintage now, but security is more dynamic than ever. If you&#39;re still around or stumbled onto this ancient blog, let me know—how are you keeping your digital life secure these days?&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://securityticker.blogspot.com/feeds/7506997770170415007/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/20173187/7506997770170415007?isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/7506997770170415007'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/7506997770170415007'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2025/07/wow-this-blog-is-still-up.html' title='Is This Thing Still On? Revisiting Security After 15 Years'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-9189703468960014096</id><published>2009-08-14T21:12:00.000-07:00</published><updated>2009-08-14T21:24:41.614-07:00</updated><title type='text'>Still Around</title><content type='html'>Been lots of updates that I&#39;ve missed posting about. Been busy with that real world thing. Should be busy soon with Windows 7 and Snow Leopard coming out in the next few months. List of important updates that you should have:&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://support.apple.com/downloads/Mac_OS_X_10_5_8_Update&quot;&gt;Mac OS 10.5.8&lt;/a&gt; &lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.mozilla.com/en-US/firefox/3.5.2/releasenotes/&quot;&gt;Firefox 3.5.2&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Microsoft &lt;a href=&quot;http://www.microsoft.com/security/updates/bulletins/200908.aspx&quot;&gt;security updates for August 2009&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;Lot more, but those are notable. The 10.5.8 update will also update you to Safari 4.0.3 unless you are still using Safari 3.&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityticker.blogspot.com/feeds/9189703468960014096/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/20173187/9189703468960014096?isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/9189703468960014096'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/9189703468960014096'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2009/08/still-around.html' title='Still Around'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-2305636234762346039</id><published>2009-07-14T19:15:00.000-07:00</published><updated>2009-07-14T19:48:08.839-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Updates"/><title type='text'>Windows Security Updates for July 2009</title><content type='html'>Patch Tuesday is here. From the Microsoft Security Bulletin, there are six security updates. There are two for the Windows operating system, one for the Microsoft Office system, one for the Windows Internet Explorer browser, one for Microsoft ISA Server, and one for Microsoft Virtual PC.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Most important I believe is the fix for the &lt;a href=&quot;http://securityticker.blogspot.com/2009/07/internet-explorer-video-active-x.html&quot;&gt;Internet Explorer Video Active X exploit&lt;/a&gt;. Microsoft Security Bulletin MS09-032 patches this one by setting killbits in IE to stop the exploit before it can do anything.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Here are the specific updates:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;MS09-032 - addresses a vulnerability in Microsoft Internet Explorer (KB 973346) - This one is mentioned above with the Video Active X issue.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/MS09-028.mspx&quot;&gt;MS09-028&lt;/a&gt; - addresses a vulnerability in Microsoft Windows (KB 971633) - This addresses vulnerbilities in DirectShow that could allow specially crafted Quicktime files to gain the same rights as the current user. Not good if you are logged in as an admin user, like most people are.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;MS09-029 - addresses a vulnerability in Microsoft Windows (KB 961371) - Embedded OpenType Font Engine which could allow your computer to be taken over.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;MS09-030 - addresses a vulnerability in Microsoft Office (KB 969516)&lt;/div&gt;&lt;div&gt;MS09-031 - addresses a vulnerability in Microsoft ISA Server (KB 970953)&lt;/div&gt;&lt;div&gt;MS09-033 - addresses a vulnerability in Microsoft Virtual PC (KB 969856)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You can see all the gory and boring details on the &lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-jul.mspx&quot;&gt;July 2009 Security Bulletin&lt;/a&gt;. Of course, the easy way to get patched against these threats is to go to &lt;a href=&quot;http://update.microsoft.com&quot;&gt;Windows Update&lt;/a&gt;. &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityticker.blogspot.com/feeds/2305636234762346039/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/20173187/2305636234762346039?isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/2305636234762346039'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/2305636234762346039'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2009/07/windows-security-updates-for-july-2009.html' title='Windows Security Updates for July 2009'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-4191727293575287592</id><published>2009-07-10T20:10:00.001-07:00</published><updated>2009-07-10T20:10:48.346-07:00</updated><title type='text'>Imageshack got Hacked</title><content type='html'>Looks like Imageshack left the backdoor of their server open. All images hosted by them are showing the hacked image, but the wording seems to indicate that no pictures were deleted.&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;font class=&quot;Apple-style-span&quot; size=&quot;4&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: 14px;&quot;&gt;&lt;i&gt;Imageshack, one of the web&#39;s largest image hosts, was attacked tonight by a movement called &quot;Anti-Sec&quot;. The result of the attack has been toreplace all ImageShack hosted images with a manifesto for the movement&amp;nbsp;(below).&lt;/i&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;br&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;font class=&quot;Apple-style-span&quot; size=&quot;4&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: 14px;&quot;&gt;Still breaking, see more plus the hacked image at&amp;nbsp;&lt;a href=&quot;http://mashable.com/2009/07/10/imageshack-hacked&quot;&gt;Mashable&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityticker.blogspot.com/feeds/4191727293575287592/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/20173187/4191727293575287592?isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/4191727293575287592'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/4191727293575287592'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2009/07/imageshack-got-hacked.html' title='Imageshack got Hacked'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-5661174443226256860</id><published>2009-07-07T22:46:00.000-07:00</published><updated>2009-07-07T22:53:52.272-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="News"/><title type='text'>Google Chrome Operating System</title><content type='html'>The &lt;a href=&quot;http://googleblog.blogspot.com/2009/07/introducing-google-chrome-os.html&quot;&gt;Google Chrome blog announced&lt;/a&gt; just recently that they are planing an operating system. Initially geared for netbooks, but I&#39;m sure there&#39;s more in plan. I&#39;m guessing they wpn&#39;t target full blown computers for awhile, but this is probably an extension of Android that Google aready has for the cell phone market.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Google Chrome OS is an open source, lightweight operating system that will initially be targeted at netbooks. Later this year we will open-source its code, and netbooks running Google Chrome OS will be available for consumers in the second half of 2010. Because we&#39;re already talking to partners about the project, and we&#39;ll soon be working with the open source community, we wanted to share our vision now so everyone understands what we are trying to achieve&lt;/blockquote&gt;Google Empire marches on.</content><link rel='replies' type='application/atom+xml' href='http://securityticker.blogspot.com/feeds/5661174443226256860/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/20173187/5661174443226256860?isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/5661174443226256860'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/5661174443226256860'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2009/07/google-chrome-operating-system.html' title='Google Chrome Operating System'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-730343008844506926</id><published>2009-07-06T20:13:00.000-07:00</published><updated>2009-07-06T20:55:57.090-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="News"/><category scheme="http://www.blogger.com/atom/ns#" term="Updates"/><title type='text'>Internet Explorer Video Active X Exploit</title><content type='html'>Been awhile since Windows had a zero day exploit that would allow the bad guys to take over your computer just by visiting a web site. Got one now. All you need to do is to visit a web site that has been set up to use this vulnerability with Internet Explorer and boom, they got you. Apparently, a flaw in Microsoft directShow( MSVIDCTL.DLL ) lets them do it. It does need to be IE 6 or 7 with Windows XP or Windows 2003. Yay! Vista and presumably Windows 7 aren&#39;t affected.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;One way to avoid this is to not use IE. Firefox, Opera, Safari and other browsers aren&#39;t affected. The bad guys could try to open IE or trick you into opening it, so it&#39;s best to the video &lt;a href=&quot;http://support.microsoft.com/kb/972890&quot;&gt;Active X advisory page&lt;/a&gt; and use the fix it button to turn off the part of IE that allows the exploit. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;F-secure detects it as Exploit:W32/Agent.LBV. They have a write up and plug for their free beta of ISTP or ExploitShield that also protect you. Also has video link showing them trying to get infected with it and failing. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;McAfee detects it as Exploit-MSDirectShow.b and has their write up &lt;a href=&quot;http://www.avertlabs.com/research/blog/index.php/2009/07/06/new-attacks-against-internet-explorer/&quot;&gt;here&lt;/a&gt; that says this has been around since last December and only has become widely know recently. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The Registry key that the Microsoft advisory page modifies is this. Best to not mess around in the registry. Might be more, but I&#39;m not going to list them all.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;[HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerActiveX Compatibility{0955AC62-BF2E-4CBA-A2B9-A63F772D46CF}]&lt;/div&gt;&lt;div&gt;&quot;Compatibility Flags&quot;=dword:00000400 &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;More tech details at Microsoft &lt;a href=&quot;http://www.microsoft.com/technet/security/advisory/972890.mspx&quot;&gt;Security Advisory 972890&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityticker.blogspot.com/feeds/730343008844506926/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/20173187/730343008844506926?isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/730343008844506926'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/730343008844506926'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2009/07/internet-explorer-video-active-x.html' title='Internet Explorer Video Active X Exploit'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-3441707232188176763</id><published>2009-07-01T23:35:00.000-07:00</published><updated>2009-07-01T23:59:33.071-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Rogue Alerts"/><category scheme="http://www.blogger.com/atom/ns#" term="Rogue Programs"/><title type='text'>Somewhat new rogue Barracuda Antivirus gets wrath of legit Barracuda Networks</title><content type='html'>Another day, another rogue. This time it&#39;s named Barracuda Antivirus. I guess they wanted to ride the coattails of the real Barracuda firewall products. As usual, the fake Barracuda Antivirus will pop fake warnings and try to goad you into buying it.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The real &lt;a href=&quot;http://www.barracudanetworks.com/ns/news_and_events/index.php?nid=363&quot;&gt;Barracuda Networks&lt;/a&gt; had this to say:&lt;div&gt;&lt;blockquote&gt;This rogue ‘Barracuda Antivirus’ program is in no way affiliated with Barracuda Networks and is just one of a string of recent examples of hackers attempting to spread malicious programs using an established and trusted Internet security brand,” said Stephen Pao, vice president of product management for Barracuda Networks. &lt;/blockquote&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Barracuda is a successor to AntivirusBest. You can probably get rid of it with Malwarebytes Antispyware using the removal guide at &lt;a href=&quot;http://www.bleepingcomputer.com/virus-removal/remove-antivirusbest&quot;&gt;Bleeping Computer&lt;/a&gt; for AntispywareBest. Screen shot of Barracuda Antispyware &lt;a href=&quot;http://forum.malekal.com/barracuda-antivirus-t19892.html&quot;&gt;here&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;More information about the real and legit Barracuda Networks &lt;a href=&quot;http://www.barracudanetworks.com/ns/?L=en&quot;&gt;here&lt;/a&gt;. They make hardware products to filter malware and spam for large networks, not really a home consumer solution.&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityticker.blogspot.com/feeds/3441707232188176763/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/20173187/3441707232188176763?isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/3441707232188176763'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/3441707232188176763'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2009/07/somewhat-new-rogue-barracuda-antivirus.html' title='Somewhat new rogue Barracuda Antivirus gets wrath of legit Barracuda Networks'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-7417917788257393951</id><published>2009-07-01T01:11:00.000-07:00</published><updated>2009-07-01T01:18:17.609-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Apple"/><category scheme="http://www.blogger.com/atom/ns#" term="Updates"/><title type='text'>iPhoto update 8.0.4 available</title><content type='html'>I don&#39;t use iPhoto too much, but it has it uses. There&#39;s a nice 103 MB update for it that fixes the issue from the iPhoto 8.03 update that caused iPhoto to crash. You could work around it by holding the Option key and then choosing your library, but what fun was that. I didn&#39;t have that problem, but this should help those that did.</content><link rel='replies' type='application/atom+xml' href='http://securityticker.blogspot.com/feeds/7417917788257393951/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/20173187/7417917788257393951?isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/7417917788257393951'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/7417917788257393951'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2009/07/iphoto-update-804-available.html' title='iPhoto update 8.0.4 available'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-3481717165997520876</id><published>2009-06-30T21:14:00.000-07:00</published><updated>2009-06-30T22:21:04.302-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="News"/><category scheme="http://www.blogger.com/atom/ns#" term="Updates"/><title type='text'>Firefox 3.5 final available</title><content type='html'>Probably not a secret to most, but the latest version of Firefox is out. A big update, since the version went from 3.0 to 3.5. Most of the changes are underneath, so they aren&#39;t readily apparent. I&#39;ve run it for a few hours and haven&#39;t had any issues. Tried  doing just about everything you can with a browser and it all went well.&lt;br /&gt;&lt;br /&gt;Speed is one thing that Firefox 3.5 is touted as having over the older version. It seems like &lt;a href=&quot;http://www.apple.com/safari/whats-new.html#performance&quot;&gt;everyone&lt;/a&gt; is &lt;a href=&quot;http://www.microsoft.com/windows/internet-explorer/videos.aspx?mname=IE8_Perf_Test2&quot;&gt;touting&lt;/a&gt; their new, even faster browser. I do notice that Firefox doesn&#39;t compare itself to other browsers like Safari and IE but the earlier 3.0 and 2 versions. Safari is still faster for me going loading new pages, but clicking back to ones in your history, it&#39;s still Firefox.&lt;br /&gt;&lt;br /&gt;One thing you&#39;ll see that is new is the &lt;a href=&quot;http://support.mozilla.com/en-US/kb/Private+Browsing&quot;&gt;private browsing&lt;/a&gt; feature. Safari has had it for quite awhile. Google Chrome launched with it and spread awareness, even getting the nickname &quot;porn mode&quot;. Nothing groundbreaking, but handy to have. You can always just clear your private data manually.&lt;br /&gt;&lt;br /&gt;Firefox 3.5 does have one thing that no other browser has. It supports some video types natively, without the need for a plug-in or 3rd party add-on. However, it&#39;s only the open source Ogg file types. Most things people watch online aren&#39;t using this. you can see a &lt;a href=&quot;http://www.mozilla.com/en-US/firefox/video/&quot;&gt;demo&lt;/a&gt; of a video that also showcases the new features. If web developers make more use of Ogg files, then this could be good. My guess is that it won&#39;t mean much until more file types are supported. Wikipedia might be an exception.&lt;br /&gt;&lt;br /&gt;Missing is a top sites feature, like Safari and Opera have. You can get it with add-ons for Firefox, but this is becoming a standard feature of these days. I didn&#39;t think it was a big deal when Opera had it and then when Safari 4 added it. Once i started using it, it was like tabbed browsing. How did I get by without it before?&lt;br /&gt;&lt;br /&gt;Other features include geolocation, the ability to drag tabs to be their own window, and adding a window as a new tab in a different browser window.&lt;br /&gt;&lt;br /&gt;Of course there is security. there&#39;s a whole list of features listed at the &lt;a href=&quot;http://www.mozilla.com/en-US/firefox/features/#security&quot;&gt;Mozilla Firefox security &lt;/a&gt;page. Private browsing and Forget This Site are the new ones listed. Many of the others, like antimalware and antiphising are listed as improved. I haven&#39;t tested those two filters, but they are likely to be weak as they have been in all browsers.&lt;br /&gt;&lt;br /&gt;You can download Firefox 3.5 at www.getfirefox.com now. The internal updater for Firefox 3.0 doesn&#39;t offer it, as of yet.</content><link rel='replies' type='application/atom+xml' href='http://securityticker.blogspot.com/feeds/3481717165997520876/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/20173187/3481717165997520876?isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/3481717165997520876'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/3481717165997520876'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2009/06/firefox-35-final-available.html' title='Firefox 3.5 final available'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-2820979684218119279</id><published>2009-06-30T19:13:00.000-07:00</published><updated>2009-06-30T19:26:33.225-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Rogue Alerts"/><category scheme="http://www.blogger.com/atom/ns#" term="Rogue Programs"/><title type='text'>AVProtection2009 Rogue</title><content type='html'>Saw an &lt;a href=&quot;http://twitter.com/lithium&quot;&gt;alert&lt;/a&gt; today about &lt;a href=&quot;http://www.pandasecurity.com/homeusers/security-info/211191/AVProtection2009&quot;&gt;AVProtection2009&lt;/a&gt;. Like all rogue antispyware programs, it warns users about threats on their computer, which are usually false. It runs a somewhat real looking scan. After the scan, the program will offer to remove the threats if you purchase it. &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Not too many details yet except what&#39;s at the Panda link above.&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/2820979684218119279'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/2820979684218119279'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2009/06/avprotection2009-rpgue.html' title='AVProtection2009 Rogue'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-2923880551069071187</id><published>2009-06-26T17:38:00.000-07:00</published><updated>2009-06-26T17:39:13.174-07:00</updated><title type='text'>SecretService is the latest Rogue antispyware</title><content type='html'>SecretService is the latest rouge antispyware product acording to S! &lt;br&gt;ri. Away from home, so check out his page for more info.&lt;p&gt;&lt;a href=&quot;http://siri-urz.blogspot.com/2009/06/secret-service-rogue.html&quot;&gt;http://siri-urz.blogspot.com/2009/06/secret-service-rogue.html&lt;/a&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityticker.blogspot.com/feeds/2923880551069071187/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/20173187/2923880551069071187?isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/2923880551069071187'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/2923880551069071187'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2009/06/secretservice-is-latest-rogue.html' title='SecretService is the latest Rogue antispyware'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-1705231922433408665</id><published>2009-06-23T20:53:00.000-07:00</published><updated>2009-06-23T21:08:03.279-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Apple"/><category scheme="http://www.blogger.com/atom/ns#" term="Updates"/><title type='text'>Airport and Time Capsule Update 7.4.2</title><content type='html'>Well, here we go. First update and it&#39;s an Apple router one. &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Apple released &lt;a href=&quot;http://support.apple.com/downloads/Time_Capsule_and_AirPort_Base_Station_Firmware_Update_7_4_2&quot;&gt;firmware update 7.4.2&lt;/a&gt; for their A&lt;a href=&quot;http://www.apple.com/wifi&quot;&gt;irport Base Station and Time Capsule&lt;/a&gt; today. Nothing particular for security mentioned, but there are several fixes which are listed as:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Fixes some problems with extending and maintaining connectivity with extended networks&lt;/li&gt;&lt;li&gt;Fixes an issue with clients that enable 802.11 &quot;Power Save&quot;&lt;/li&gt;&lt;li&gt;Fixes connectivity issues with some third-party devices&lt;/li&gt;&lt;li&gt;Fixes an issue when the base station is configured for PPPoE&lt;/li&gt;&lt;li&gt;Fixes some Back To My Mac issues with connectivity and support for third-party routers&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;You don&#39;t have to use an Airport router for a Mac to get online and a Windows computer can use an Airport router. I got a Time Capsule for a good cheap price recently and i like it. It&#39;s an 802.11n router, has an internal hard drive for sharing files and has a USB port that you can connect more hard drives and printers to so all my Macs and PC&#39;s can easily share files and print.&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The wireless range is pretty good. I can turn down the transmit power to 25% and still connect through two outside walls and on the other side of the yard from where the router is. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/1705231922433408665'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/1705231922433408665'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2009/06/airport-and-time-capsule-update-742.html' title='Airport and Time Capsule Update 7.4.2'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-5033090336847090322</id><published>2009-06-22T20:24:00.001-07:00</published><updated>2009-06-22T20:24:37.688-07:00</updated><title type='text'>How to Tell If That Pop-Up Window  Is Offering You a Rogue Anti-Malware Product</title><content type='html'>One thing I run into often, is how to know if that program that is  &lt;br&gt;saying it can fix your spyware and malware woes is actually any good.  &lt;br&gt;As many have found out, even programs that remove malware can be  &lt;br&gt;malware themselves. The infamous SpyAxe (which started me blogging)  &lt;br&gt;was the first mainstream one. That was 2006. Since then, there have  &lt;br&gt;been many, many that have followed. They usually get onto your system  &lt;br&gt;by tricking you into installing a video codec to watch something.  &lt;br&gt;There&amp;#39;s even been some for the Mac. It can be quite confusing figuring  &lt;br&gt;out what is a legit antispyware program and what is a rogue.&lt;p&gt;Sunbelt has a good piece on how to find out. I&amp;#39;ll link to the blog  &lt;br&gt;post since the it&amp;#39;s a pdf file. &lt;a href=&quot;http://sunbeltblog.blogspot.com/2009/06/beginners-guide-is-that-real-anti.html&quot;&gt;http://sunbeltblog.blogspot.com/2009/06/beginners-guide-is-that-real-anti.html&lt;/a&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityticker.blogspot.com/feeds/5033090336847090322/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/20173187/5033090336847090322?isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/5033090336847090322'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/5033090336847090322'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2009/06/how-to-tell-if-that-pop-up-window-is.html' title='How to Tell If That Pop-Up Window  Is Offering You a Rogue Anti-Malware Product'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-8461042121834039017</id><published>2009-06-22T19:37:00.000-07:00</published><updated>2009-06-22T19:48:27.504-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Me"/><title type='text'>I command you to rise from the dead</title><content type='html'>Since using OS X, it&#39;s been no fun to to mess with all the updates for Windows. You don&#39;t have to deal with 90% or more of the garbage that affects Windows. This isn&#39;t to say Windows is no good. I still use it, but nowhere near as much as I used to. Also add the time it takes to filter out all the spam comments that try to get through when comments are enabled, it became tiresome to update this blog. &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;While looking for up to date info on the election crisis in Iran, I finally started using Twitter. It really is the way to find out information as it happens. Anyways, it has invigorated me to get back to this blog. Tried a few times, so let&#39;s see what happens and where it goes. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Oh, Windows 7 certainly has renewed interest in Windows. Running the release candidate and it&#39;s looking good. &lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityticker.blogspot.com/feeds/8461042121834039017/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/20173187/8461042121834039017?isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/8461042121834039017'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/8461042121834039017'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2009/06/i-command-you-to-rise-from-dead.html' title='I command you to rise from the dead'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-8756468299584261241</id><published>2008-12-11T06:16:00.000-08:00</published><updated>2008-12-11T06:26:35.449-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Rogue Alerts"/><category scheme="http://www.blogger.com/atom/ns#" term="Rogue Programs"/><category scheme="http://www.blogger.com/atom/ns#" term="Spyware Removal"/><title type='text'>Antivirus 360 Replaces Antivirus 2009 As New Rogue</title><content type='html'>The Vundo trojan is now using Antivirus 360 in it&#39;s effort to scam money out of victims. The name is play off of &lt;a href=&quot;http://www.symantec.com/norton/360&quot;&gt;Norton 360&lt;/a&gt; it appears. Like all rogue antispyware products, the malware that found it&#39;s way on your computer is from the same group that is trying to sell you the solution.&lt;br /&gt;&lt;a href=&quot;http://www.bleepingcomputer.com/malware-removal/remove-antivirus-360&quot;&gt;&lt;br /&gt;Antivirus 360 removal guide&lt;/a&gt; found Bleeping Computer. Hijackthis log symptoms and files:&lt;br /&gt;&lt;br /&gt;&lt;span name=&quot;intelliTxt&quot; id=&quot;intelliTxt&quot;&gt;O4 - HKCU\..\Run: [13376694984709702142491016734454] C:\Program Files\A360\av360.exe    &lt;br /&gt;&lt;br /&gt;c:\Program Files\A360&lt;br /&gt;c:\Program Files\A360\av360.exe&lt;br /&gt;%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 360.lnk&lt;br /&gt;%UserProfile%\Desktop\Antivirus 360.lnk&lt;br /&gt;%UserProfile%\Start Menu\Antivirus 360&lt;br /&gt;%UserProfile%\Start Menu\Antivirus 360\Antivirus 360.lnk&lt;br /&gt;%UserProfile%\Start Menu\Antivirus 360\Help.lnk&lt;br /&gt;%UserProfile%\Start Menu\Antivirus 360\Registration.lnk&lt;br /&gt;&lt;/span&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/8756468299584261241'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/8756468299584261241'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2008/12/antivirus-360-replaces-antivirus-2009.html' title='Antivirus 360 Replaces Antivirus 2009 As New Rogue'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-8009114270712967976</id><published>2008-12-09T04:02:00.000-08:00</published><updated>2008-12-09T04:38:18.411-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="News"/><title type='text'>Spywareinfo Domain Now Linking Rogues</title><content type='html'>The domain spywareinfo.com once was one of the main sites to help with stopping spyware and helping people remove spyware. Once a good source of information and news, it began a slow decline in 2006 when the owner Mike Healan disappeared from the net for personal reasons. The domain was bought recently and is now hosting links to undesirable removal programs, including Antivirus 2009.&lt;br /&gt;&lt;br /&gt;Spywareinfo&#39;s legacy still lives on. The forums were moved to their own domain and can be found at &lt;a href=&quot;http://www.spywareinfoforum.com/&quot;&gt;&lt;span id=&quot;gtbmisp_18&quot; style=&quot;border: 0pt none ; margin: 0pt; padding: 0pt; background: transparent none repeat scroll 0% 0%; font-family: serif; font-style: normal; font-variant: normal; font-weight: bold; font-size: 100%; line-height: normal; font-size-adjust: none; font-stretch: normal; position: static; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; text-align: left; text-indent: 0pt; text-transform: none; color: red; text-decoration: underline; cursor: pointer;&quot;&gt;&lt;/span&gt;&lt;span id=&quot;gtbmisp_17&quot; style=&quot;border: 0pt none ; margin: 0pt; padding: 0pt; background: transparent none repeat scroll 0% 0%; font-family: serif; font-style: normal; font-variant: normal; font-weight: bold; font-size: 100%; line-height: normal; font-size-adjust: none; font-stretch: normal; position: static; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; text-align: left; text-indent: 0pt; text-transform: none; color: red; text-decoration: underline; cursor: pointer;&quot;&gt;spywareinfoforum&lt;/span&gt;.com&lt;/a&gt; . An archive of the old spywareinfo site can be found at &lt;a href=&quot;http://www.spywareinfoforum.info/&quot;&gt;&lt;span id=&quot;gtbmisp_20&quot; style=&quot;border: 0pt none ; margin: 0pt; padding: 0pt; background: transparent none repeat scroll 0% 0%; font-family: serif; font-style: normal; font-variant: normal; font-weight: bold; font-size: 100%; line-height: normal; font-size-adjust: none; font-stretch: normal; position: static; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; text-align: left; text-indent: 0pt; text-transform: none; color: red; text-decoration: underline; cursor: pointer;&quot;&gt;spywareinfoforum&lt;/span&gt;.info&lt;/a&gt;. While archive of spywareinfo is mostly old and out of date, the forums are current , up to date and a good place to go if you need help.&lt;br /&gt;&lt;br /&gt;More on the change of ownership of spywareinfo:&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://www.spywareinfoforum.com/index.php?s=&amp;amp;showtopic=121410&amp;amp;view=findpost&amp;amp;p=668221&quot;&gt;&lt;/a&gt;Warning at the &lt;a href=&quot;http://www.spywareinfoforum.com/index.php?s=&amp;amp;showtopic=121410&amp;amp;view=findpost&amp;amp;p=668221&quot;&gt;spywareinfoforum&lt;/a&gt; site.&lt;br /&gt;&lt;br /&gt;DSLreports security forums &lt;a href=&quot;http://www.dslreports.com/forum/r21545567-SpywareInfocom-bad-news&quot;&gt;discuss&lt;/a&gt; the change.&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://certifiedbug.com/blog/2008/12/07/spywareinfocom-domain-sold-beware/&quot;&gt;Analysis&lt;/a&gt; of the new links.</content><link rel='replies' type='application/atom+xml' href='http://securityticker.blogspot.com/feeds/8009114270712967976/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/20173187/8009114270712967976?isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/8009114270712967976'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/8009114270712967976'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2008/12/spywareinfo-domain-now-linking-rogues.html' title='Spywareinfo Domain Now Linking Rogues'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-40546997664723652</id><published>2008-12-07T00:26:00.000-08:00</published><updated>2008-12-07T00:28:30.269-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="News"/><title type='text'>Need An Update</title><content type='html'>My poor blog is almost dead. Silly work and real life keeping me from updating it.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/40546997664723652'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/40546997664723652'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2008/12/need-update.html' title='Need An Update'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-5728753519595147613</id><published>2008-09-13T22:39:00.000-07:00</published><updated>2008-09-13T22:50:52.507-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="News"/><title type='text'>Is your Computer running slowly?</title><content type='html'>Whoops, three months went by without a post. Oh well, no time like now to get back to it.&lt;br /&gt;&lt;br /&gt;Malware Removal just put up a page to help with keeping your Windows computer from slowing down and what you can do to keep it from slowing down.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;We get a lot of people coming here complaining of slow running computers, and posting HijackThis logs for us to look at. They suspect that an infection is causing their problem. In a great many cases, Malware is not the cause of the problem, and a few simple procedures are all that it takes to resolve things.&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://www.malwareremoval.com/forum/viewtopic.php?f=168&amp;amp;t=34494&quot;&gt;Is your Computer running slowly&lt;/a&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/5728753519595147613'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/5728753519595147613'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2008/09/is-your-computer-running-slowly.html' title='Is your Computer running slowly?'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-9167763295249807210</id><published>2008-06-11T22:17:00.000-07:00</published><updated>2008-06-11T22:27:13.324-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Rogue Alerts"/><category scheme="http://www.blogger.com/atom/ns#" term="Rogue Programs"/><title type='text'>AntiSpyCheck Rogue Program</title><content type='html'>AntiSpycheck is a new rogue spyware program. It&#39;s installed by the zlob trojan, giving fake alerts that try to get you to purchase it. The zlob trojan disguises itself as a video codec that is supposedly needed to view a video. It really installs spyware to make fake alerts and installs AntiSpyCheck to trick you into buying it.&lt;br /&gt;&lt;br /&gt;Here are some lines from Hijackthis that you may find if you are infected:&lt;br /&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://internetsearchservice.com&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://internetsearchservice.com/ie6.html&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://internetsearchservice.com&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://internetsearchservice.com&lt;br /&gt;O2 - BHO: WarningBHO Class - {56FA7933-DC3E-403b-8D47-BB5E3F345A21} - C:\Program Files\AntiSpyCheck\IEWarning.dll&lt;br /&gt;O2 - BHO: 514852 helper - {9420D9C5-E151-4D83-B9A6-27DE1A7A0E5F} - C:\WINDOWS\system32\514852\514852.dll&lt;br /&gt;O2 - BHO: (no name) - {99BA268B-4021-4739-9945-3C774217FE75} - C:\Program Files\NetProject\sbmdl.dll&lt;br /&gt;O4 - HKLM\..\Run: [AntiSpyCheck 2.1.0] &quot;C:\Program Files\AntiSpyCheck\AntiSpyCheck.exe&quot;&lt;br /&gt;O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe&lt;br /&gt;O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Program Files\NetProject\sbmntr.exe&lt;br /&gt;O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ietoolpro.com/redirect.php (file missing)&lt;br /&gt;O9 - Extra &#39;Tools&#39; menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ietoolpro.com/redirect.php (file missing)&lt;br /&gt;O22 - SharedTaskScheduler: campaniform - {5c7b71bb-6d49-4bdc-b60d-f9fe0481eb5f} - C:\WINDOWS\system32\kfcpnd.dll&lt;br /&gt;&lt;br /&gt;Here are some files that you my have if you are infected with this trojan:&lt;br /&gt;&lt;br /&gt;c:\Program Files\AntiSpyCheck&lt;br /&gt;c:\Program Files\AntiSpyCheck\AntiSpyCheck.exe&lt;br /&gt;c:\Program Files\AntiSpyCheck\IEWarning.dll&lt;br /&gt;c:\Program Files\Mozilla Firefox\extensions\sotfone-tracker@sotfone.ru&lt;br /&gt;c:\Program Files\NetProject&lt;br /&gt;c:\Program Files\NetProject\sbmdl.dll&lt;br /&gt;c:\Program Files\NetProject\sbmntr.exe&lt;br /&gt;c:\Program Files\NetProject\sbsm.exe&lt;br /&gt;c:\Program Files\NetProject\sbun.exe&lt;br /&gt;c:\Program Files\NetProject\scit.exe&lt;br /&gt;c:\Program Files\NetProject\scm.exe&lt;br /&gt;c:\Program Files\NetProject\scu.exe&lt;br /&gt;c:\WINDOWS\system32\kfcpnd.dll&lt;br /&gt;c:\WINDOWS\system32\514852\514852.dll&lt;br /&gt;&lt;br /&gt;For full details and a free removal guide, take a look at Bleeping Computer&#39;s &lt;a href=&quot;http://www.bleepingcomputer.com/malware-removal/antispycheck&quot;&gt;AntiSpyCheck Removal Guide&lt;/a&gt;.</content><link rel='replies' type='application/atom+xml' href='http://securityticker.blogspot.com/feeds/9167763295249807210/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/20173187/9167763295249807210?isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/9167763295249807210'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/9167763295249807210'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2008/06/antispycheck-rogue-program.html' title='AntiSpyCheck Rogue Program'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-8659906842477314928</id><published>2008-06-02T17:54:00.000-07:00</published><updated>2008-06-02T18:45:49.712-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Apple"/><category scheme="http://www.blogger.com/atom/ns#" term="News"/><title type='text'>Internet Explorer Flaw Plus Safari Equals Trouble</title><content type='html'>An undisclosed vulnerability in Internet Explorer, combined with exploiting Safari for Windows&#39; ability to download files without being prompted, apparently allows the bad guys to take over Windows. This affects XP, Vista and IE versions 6 and 7. The unnamed Internet Explorer bug has been around for awhile. Combined with the Windows version of Safari, where files can be downloaded without an option to prompt before doing so, the flaw can be used to &lt;a href=&quot;http://aviv.raffon.net/2008/05/31/SafariPwnsInternetExplorer.aspx&quot;&gt;take over&lt;/a&gt; Windows, reports Aviv Raff.&lt;br /&gt;&lt;br /&gt;The flaw in Internet Explorer uses the calculator program in conjunction with Safari for Windows to make two moderate vulnerabilities into a critical one. Microsoft has issued a &lt;a href=&quot;http://www.microsoft.com/technet/security/advisory/953818.mspx&quot;&gt;bulletin&lt;/a&gt;, but it doesn&#39;t really say too much. Even if Microsoft patches IE, there&#39;s still Safari&#39;s &quot;&lt;a href=&quot;http://www.dhanjani.com/archives/2008/05/safari_carpet_bomb.html&quot;&gt;carpet bomb&lt;/a&gt;&quot; issue that can allow unwanted downloads. Right now, Apple doesn&#39;t appear to want to fix this. Simply adding the option to prompt for all downloads before doing the download would help prevent this. &lt;a href=&quot;http://blogs.stopbadware.org/articles/2008/05/19/safari-security-questioned-sbw-encourages-action&quot;&gt;Stopbadware&lt;/a&gt; wrote on their blog to urge Apple to do so.&lt;br /&gt;&lt;br /&gt;You have to visit a specially crafted web page for this exploit to work. So it is not an all out fiasco. So far, there is not a known use of this problem. Right now, the only guaranteed fix to prevent this is to uninstall Safari for Windows. This may not be a bad idea, since there could be more bugs like this that can be exploited in Safari for Windows, said Raff in an interview with &lt;a href=&quot;http://www.macworld.com/article/133703/2008/06/ms_safari.html&quot;&gt;Macworld&lt;/a&gt;.</content><link rel='replies' type='application/atom+xml' href='http://securityticker.blogspot.com/feeds/8659906842477314928/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/20173187/8659906842477314928?isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/8659906842477314928'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/8659906842477314928'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2008/06/internet-explorer-flaw-plus-safari.html' title='Internet Explorer Flaw Plus Safari Equals Trouble'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-786671921427521953</id><published>2008-05-29T23:02:00.000-07:00</published><updated>2008-05-29T23:09:52.719-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="News"/><category scheme="http://www.blogger.com/atom/ns#" term="Updates"/><title type='text'>Service Pack 3 Available On CD</title><content type='html'>For those who are not on a good Internet connection or one where you are limited in bandwidth, you can get Service Pack 3 on CD now. You can also download a disk image or stand alone installer, which you can use to take home or save for a re-install. Having SP 3 available will help if you do need to re-install, so you won&#39; have to go online and expose yourself to the evils of the Internet. You can check it out on &lt;a href=&quot;http://technet.microsoft.com/en-us/windowsxp/0a5b9b10-17e3-40d9-8d3c-0077c953a761.aspx&quot;&gt;Microsoft TechNet&lt;/a&gt;.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/786671921427521953'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/786671921427521953'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2008/05/service-pack-3-available-on-cd.html' title='Service Pack 3 Available On CD'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-8908718894730634155</id><published>2008-05-28T22:23:00.000-07:00</published><updated>2008-05-28T22:55:28.410-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Apple"/><category scheme="http://www.blogger.com/atom/ns#" term="Updates"/><title type='text'>Mac OS 10.5.3 for leopard, Security Update for Tiger</title><content type='html'>A few hours ago, Apple made the 10.5.3 update available on Software Update. There&#39;s lots of changes and fixes in this one. If you have 10.4 Tiger, you do get a nice set of security updates so you don&#39;t feel left out.  &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The 10.5.3 update details can be found at &lt;a href=&quot;http://support.apple.com/kb/HT1141&quot;&gt;Apple&lt;/a&gt;. The kbase article mentions inprovements or fixes for: Address Book, Automator, Airport, iCal, iChat, Mail, Parental Controls, Spaces, Time Machine and voice Over. I also noticed changes to Back to My Mac and Finder. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;For BTMM, there is now a red, green and yellow indicator for the service. I think it is just checking connectivity to the BTMM servers and successful login. I&#39;m behind a crapy Linksys router that doesn&#39;t like to keep UPnP on, but I get a green light. So I can see the other mac, but connections still fail, as should since Universal Plug n Play isn&#39;t on. &lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Finder now has a more accurate display of uploads to network drives, like iDisk. It used to sit on the closing file and would stay there until the file was finished uploading. That could be another 20 minutes or longer. Now it displays a rough estimate of the time remaining in the upload. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If you have Tiger or haven&#39;t updated to 10.5.3, then you still want to use check updates for &lt;a href=&quot;http://support.apple.com/kb/HT1897&quot;&gt;Security Update 2008-003&lt;/a&gt;. Updates include AFP Server, Apache, AppKit, CFNetwork, CoreFoundation, CoreGraphics, CoreTypes, Common Unix Printing System (CUPS), Flash Player Plug-in, iCal, LoginWindow, Mail, Wiki Server and  more. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I installed 10.5.3 and had no problems. It was faster than the 10.5.2 update. So far, I&#39;v only seen the usual people who seem to have trouble with every update complain. I see no reason to hold off of this set of updates.&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityticker.blogspot.com/feeds/8908718894730634155/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/20173187/8908718894730634155?isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/8908718894730634155'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/8908718894730634155'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2008/05/mac-os-1053-for-leopard-security-update.html' title='Mac OS 10.5.3 for leopard, Security Update for Tiger'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-3457458812622647711</id><published>2008-05-24T20:16:00.000-07:00</published><updated>2008-05-24T20:23:33.374-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Updates"/><title type='text'>Spyware Doctor False Positive Flags Part of XP Service Pack 3</title><content type='html'>Apparantly, Spyware Doctor may be detecting Rundll32.exe as having Trojan-Spy.Pophot.WX. The latest update, 5.09900, should fix this. In any event, you should run Spyware Doctor&#39;s Smart Update t be safe.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/3457458812622647711'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/3457458812622647711'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2008/05/spyware-doctor-false-positive-flages.html' title='Spyware Doctor False Positive Flags Part of XP Service Pack 3'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-7964231443873698623</id><published>2008-05-23T23:53:00.000-07:00</published><updated>2008-05-24T00:26:59.078-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Off Topic"/><title type='text'>MacWindows</title><content type='html'>Since moving to Mac from Windows, it&#39;s been quite refreshing not having to keep multiple security programs running and updated. Sure, I still have several Windows machines here and have used them, but not so much anymore. Now that I have &lt;a href=&quot;http://en.wikipedia.org/wiki/VMware_Fusion&quot;&gt;VMWare Fusion&lt;/a&gt; on my iMac with a 2.8 GHz Core 2 Duo, 4 Gigs of RAM, and 24 inch screen, I can run them all. Now I need to get a 2nd display so I can run Windows Full screen side by side with OS X. I&#39;ve got XP and Vista and can run them at the same time :) Though Aero won&#39;t work while I am running it in virtual machine. I can reboot to Vista using &lt;a href=&quot;http://www.apple.com/macosx/features/bootcamp.html&quot;&gt;Bootcamp&lt;/a&gt; and Aero will pop on.&lt;br /&gt;&lt;br /&gt;Anyways, with all the Windows going on, I&#39;ll need to keep up with the security stuff and will get back to updating here more. I haven&#39;t decided what changes there&#39;ll be, but I think a real template for this blog is past due. One thing to think about is what to display in updates. Most security programs these days have so many updates with similar names, that it&#39;s hard to pick out what it means. It used to be simple. A Look2Me here, a Vundo there and whatever the &lt;a href=&quot;http://securityticker.blogspot.com/2006/05/easy-fix-for-spyware-and-virus-alert.html&quot;&gt;Zlob trojan&lt;/a&gt; was calling itself this week.&lt;br /&gt;&lt;br /&gt;I&#39;ll see what i can come up with.</content><link rel='replies' type='application/atom+xml' href='http://securityticker.blogspot.com/feeds/7964231443873698623/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/20173187/7964231443873698623?isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/7964231443873698623'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/7964231443873698623'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2008/05/macwindows.html' title='MacWindows'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20173187.post-6885097129546792577</id><published>2008-05-23T23:48:00.000-07:00</published><updated>2008-05-23T23:50:26.262-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Updates"/><title type='text'>Spybot Search &amp; Destroy May 21st</title><content type='html'>2008-05-21&lt;br /&gt;&lt;br /&gt;Keylogger&lt;br /&gt;+ KGBKeylogger ++ KGBKeylogger.REFOG ++ SmartPCKeylogger&lt;br /&gt;&lt;br /&gt;Malware&lt;br /&gt;++ AntiSpyCheck ++ BugDoctor + ConOpt.BHO (3) ++ DeusCleaner ++ DoctorCleaner ++ EliteProtector + ErrorDoctor + FakeAlert.cc ++ LiveAntispy ++ MalwareDestructor + MyNetProtector ++ PCSleek.FreeErrorCleaner + Smitfraud-C. ++ Spyburner ++ SpyKill + Trojan-Guarder + Vario.AntiVirus + Win32.BHO.je + Win32.Renos + WinSpyKiller + Worldsecurityonline.FakeAlert&lt;br /&gt;&lt;br /&gt;PUPS&lt;br /&gt;++ SpyPry&lt;br /&gt;&lt;br /&gt;Security&lt;br /&gt;+ Microsoft.Windows.AppFirewallBypass&lt;br /&gt;&lt;br /&gt;Trojan&lt;br /&gt;+ Smitfraud-C.MSVPS + Virtumonde.ddc ++ Win32.Agent.abd ++ Win32.Agent.ark ++ Win32.Agent.byc + Win32.AutoRun ++ Win32.Delf.bj ++ Win32.Friendown + Win32.PcClient.agu + Win32.Small.ih&lt;br /&gt;&lt;br /&gt;Total: 609774 fingerprints in 159642 rules for 3951 products.&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://spybot.info/en/updatehistory/index.html&quot;&gt;http://spybot.info/en/updatehistory/index.html&lt;/a&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/6885097129546792577'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20173187/posts/default/6885097129546792577'/><link rel='alternate' type='text/html' href='http://securityticker.blogspot.com/2008/05/spybot-search-destroy-may-21st.html' title='Spybot Search &amp; Destroy May 21st'/><author><name>Nick</name><uri>http://www.blogger.com/profile/07519189440140156261</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author></entry></feed>