<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Making IT Easy &#187; Malware</title>
	<atom:link href="http://www.gunthy.net/blog/tag/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gunthy.net/blog</link>
	<description>IT for normal people...</description>
	<lastBuildDate>Mon, 30 Jan 2012 10:49:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<image>
<link>http://www.gunthy.net/blog</link>
<url>http://gunthy.m0nk3y.com/blog/wp-content/mbp-favicon/monitor.ico</url>
<title>Making IT Easy</title>
</image>
		<item>
		<title>Microsoft secretly installs Firefox add-on</title>
		<link>http://www.gunthy.net/blog/2009/06/microsoft-secretly-installs-firefox-add-on/</link>
		<comments>http://www.gunthy.net/blog/2009/06/microsoft-secretly-installs-firefox-add-on/#comments</comments>
		<pubDate>Tue, 02 Jun 2009 08:24:37 +0000</pubDate>
		<dc:creator>Gunthy</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[add-on]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[unwanted]]></category>

		<guid isPermaLink="false">http://www.gunthy.net/blog/?p=259</guid>
		<description><![CDATA[We all know our good friends at Microsoft are not shy for a stunt here and there, but now they really hit the jackpot&#8230; Brian Krebs from The Washington Post has been advising the average Windows user on various things. A while ago, people started asking him if they could trust a Service Pack for [...]]]></description>
			<content:encoded><![CDATA[<p>We all know our good friends at Microsoft are not shy for a stunt here and there, but now they really hit the jackpot&#8230;</p>
<p><a href="http://voices.washingtonpost.com/securityfix/2009/05/microsoft_update_quietly_insta.html" target="_blank">Brian Krebs from The Washington Post</a> has been advising the average Windows user on various things. A while ago, people started asking him if they could trust a Service Pack for the .Net framework. While you probably are well aware about .Net, what it is and what it does, many people are not. So Brian took it upon himself to test the SP and after some time gave it a go.</p>
<p>However, it seems now that when installing this update, Microsoft is so friendly to add their own add-on for FireFox. While it is nice to see that MS is acknowledging FF as a major player in the browser world, it is not the normal way to install add-ons. One of the great features of FF has always been it extendability, but moreover the choice what &amp; when to extend it.</p>
<p><span id="more-259"></span></p>
<p>No big deal right? Let&#8217;s just go and remove this unwanted extension. Right, this would work with any other developer, but we are dealing with Microsoft, which means the &#8216;Uninstall&#8217; button is disabled, and removing the add-on is only possible through some obscure registry hacks, with which you don&#8217;t only risk in breaking the good operation of your favorite browser, but also your whole OS when you don&#8217;t really know what you&#8217;re doing.</p>
<p>Nobody really knows how this add-on behaves, but personally I don&#8217;t like this situation at all. Like Brian says in his article, it makes you wonder what else Microsoft&#8217;s installs behind your back&#8230; Maybe calling this malware is a bit over the top, but nevertheless I&#8217;m going to tag this post with it, since such behaviour is typical for malware, and it&#8217;s not because it&#8217;s coming from MS that we should keep one eye closed.</p>
<p>It&#8217;s already bad enough the Redmond company does not seem to be able to create a decent browser of their own, but now they seem to have to mess up the work of others as well. I for one am not very happy with this. In fact this makes me going to avoid Microsoft software even more than before, and I hope the same for you as well&#8230; Remember, it&#8217;s for your own good <img src='http://www.gunthy.net/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> .</p>
]]></content:encoded>
			<wfw:commentRss>http://www.gunthy.net/blog/2009/06/microsoft-secretly-installs-firefox-add-on/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Downadup/Conflicker spreading havoc</title>
		<link>http://www.gunthy.net/blog/2009/01/downadupconflicker-spreading-havoc/</link>
		<comments>http://www.gunthy.net/blog/2009/01/downadupconflicker-spreading-havoc/#comments</comments>
		<pubDate>Tue, 20 Jan 2009 09:04:05 +0000</pubDate>
		<dc:creator>Gunthy</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[conflicker]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://gunthy.m0nk3y.com/blog/?p=186</guid>
		<description><![CDATA[It&#8217;s been a while now that this worm has been spreading around on the Net, but apparently after all this time, it&#8217;s still out there, alive and kicking more than ever before. Downadup is one of the nastiest worms I&#8217;ve seen in my professional history. Having quite the amount of hands-on experience with it myself, [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a while now that this worm has been spreading around on the Net, but apparently after all this time, it&#8217;s still out there, alive and kicking more than ever before.</p>
<p>Downadup is one of the nastiest worms I&#8217;ve seen in my professional history. Having quite the amount of hands-on experience with it myself, I can say that I haven&#8217;t seen such a persistent one before. And I&#8217;m not alone&#8230; F-Secure reported Friday in a <a href="http://www.f-secure.com/weblog/archives/00001584.html" target="_new">blog-post</a> that they estimate the number of affected machines to be over 8 million. <em>EIGHT MILLION!!!</em> My god&#8230;</p>
<p>So what happened? Well the worm seems to be detected first late September, using a flaw in one of Windows&#8217; services which allowed it to brute-force account passwords it spread rapidly. Once successful, it starts spreading itself through network shares, USB-sticks and other computers affected by the same security hole. Late October, Microsoft released an emergency patch to fix the hole, but a lot of machines still remain unpatched, thus very vulnerable.</p>
<p>A lot of corporate networks got infected as the worm spread havoc using the exploit. It locked users out of their accounts by keeping on guessing the password. Once on the machine, it starts securing the places it uses by removing all access rights to parts of the file system and registry, making it very hard to remove. Once your network is infected, it feels like your efforts to wipe out the worm are like carrying water to the sea. Counter-measures like installing the MS-patch and updating your anti-virus solution do help, but seem to only slow down the spreading. Use of USB sticks should definitely be heavily restricted, or if possible be banned completely.</p>
<p>To make things worse, the worm in some cases renders the infected computer useless, using methods like stopping services or using excessive bandwidth. It&#8217;s ability to install third-party malware such as trojans and other viruses, which gives full control over the machine to the worm author(s), doesn&#8217;t help either.</p>
<p>I think we haven&#8217;t seen the last of this one yet. The biggest question I think is, if you ever get your network clean again, how can you be sure no remnants are left behind. After all, as with any virus or malware, can you ever be sure you are completely safe? I guess only time will tell&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.gunthy.net/blog/2009/01/downadupconflicker-spreading-havoc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft to drop Live OneCare for a light/free version</title>
		<link>http://www.gunthy.net/blog/2008/11/microsoft-to-drop-live-onecare-for-a-lightfree-version/</link>
		<comments>http://www.gunthy.net/blog/2008/11/microsoft-to-drop-live-onecare-for-a-lightfree-version/#comments</comments>
		<pubDate>Thu, 20 Nov 2008 09:07:40 +0000</pubDate>
		<dc:creator>Gunthy</dc:creator>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Morro]]></category>
		<category><![CDATA[OneCare]]></category>

		<guid isPermaLink="false">http://gunthy.m0nk3y.com/blog/?p=136</guid>
		<description><![CDATA[Microsoft announced on Tuesday that they will stop providing the Live OneCare and started working on free consumer security software. They will continue to provide support for Onecare, but will no longer develop the platform anymore. The new software, codenamed &#8216;Morro&#8217; is supposed to be a light version of OneCare.  The program will be used [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft <a href="http://www.microsoft.com/presspass/press/2008/nov08/11-18NoCostSecurityPR.mspx" target="_blank">announced</a> on Tuesday that they will stop providing the Live OneCare and started working on free consumer security software. They will continue to provide support for Onecare, but will no longer develop the platform anymore.</p>
<p>The new software, codenamed <em>&#8216;Morro&#8217;</em> is supposed to be a light version of OneCare.  The program will be used to detect viruses and other types of malware. Other features that are present on OneCare, like the defragmentation and backup tool, will not be included in Morro.</p>
<p>This is probably a good thing for the consumer market, but don&#8217;t get too enthusiastic. After all, we&#8217;re still talking about Microsoft here. While I don&#8217;t have any experience with their current suite, I doubt it is as good as other commercial or even free alternatives. On the other hand, they know the Windows system better than anyone else, so if they take this thing serious enough, this might just become something all Windows-users want!</p>
<p>Surely to be followed&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.gunthy.net/blog/2008/11/microsoft-to-drop-live-onecare-for-a-lightfree-version/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

