Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, December 6, 2008

Software Goodies

Posted on 4:10 PM by Unknown

Been quite a while since I have posted a roundup of new/improved software finds.

Here you go from the previous weeks’ culling.

  • CompuSec - (freeware) – German proprietary whole disk encryption solution I just discovered this week.  The free version has no limitations and is open to both professional (business/commercial) as well as personal users.  On-line support is available and supports all Windows versions as well as Linux.  Lots of handbooks available and is provided in both German and English flavors. Discussed and reviewed in depth by Leo Laporte and Steve Gibson in a CRC Security Now! podcast session. 

  • TrueCrypt - (freeware) - Free Open-Source On-The-Fly Disk Encryption Software for Windows Vista/XP, Mac OS X and Linux.  Simply the best (IMHO) solution for home users and consumers looking for a fast, efficient, and rock-solid solution to encrypting their laptop/desktop system’s hard-drives to prevent unauthorized data-loss in event of theft of general maliciousness.  Now at version 6.1a.  Anyone who doesn’t use some form of whole-disk encryption with a laptop is probably just asking for eventual trouble, especially if used in a business/enterprise setting.  Desktops are just as vulnerable so don’t forget them as well.

  • PGP Corporation - ($-$$$) Enterprise grade whole-disk encryption software.  Not the only vendor of such out there but one of the leaders in the market.

  • Foxit Reader 3.0 - (freeware) – This major version update brings a larger file size to the previously light alternative PDF reader.  While still “small” in comparison to Adobe Reader, it has gotten a bit more chunky than previous upgrades. It’s still one of the best Free PDF Readers (and then some) in an otherwise large crowd.   I don’t feel like repeating a big list of What's New in 3.0 so hop that link, then grab the updated version.  I don’t think you will be disappointed.

  • CurrPorts - (freeware) – Nirsoft app for viewing/monitoring open TCP/IP ports and connections on Windows now provides information on the total number of remote connections in the program’s status bar as well as port information in the tray-icon tooltip.

  • ShellExView - (freeware) – Nirsoft app for working with shell extensions for Windows now gets a critical feature; support for use with external drives via a command-line option.

  • NK2View - (freeware) – Nirsoft app for working with Outlook’s NK2 file got an update to delete selected items and add items from address bar to the menu system as well as more “accelerator” keys.  Definitely a must have for any sysadmin who supports Outlook users.

  • LSASecretsView- (freeware) – Nirsoft app for viewing LSA (local security authority service) secrets stored on your computer. This version now supports pulling LSA data from a off-line version of Windows 2000/XP/2003. Related: Nir’s LSASecretsDump utility.

  • Secunia Personal Software Inspector (PSI) 1.0 – Now out and polished up.  Previously reviewed RC1 version was great and highly recommended by me. Secunia Personal Software Inspector RC-1: Wowzers!  This new “final” build has experienced some major tweaks and got  some important changes since I last wrote about it in the RC-march up to the final version. 

    • Fix for Windows Vista UAC bug - The Secunia PSI will now start up correctly after a system reboot in Windows Vista
    • Added green icon download icon - The green download icon will indicate that a patch link has been clicked, making it obvious which patches have been requested when applying multiple patches at a time
    • New user interface concept - The user interface has been split into two, a "Simple" and an "Advanced" mode
    • Improved Easy-to-Patch functionality - The Easy-to-Patch has been improved significantly
    • Criticality indication for all programs - The Secunia Advisory criticality rating is now listed for each insecure program found
    • Generally more focus on the security threats each program expose your PC to Secunia Profile recovery - It is possible to recover your Secunia Profile and register the same Secunia Profile on multiple PCs

  • Zoundry Raven for Windows - (freeware) – Looks like this eager bird is about ready to take to wing.  All the standard items and platform support with a nice interface.  Worth checking out.  Also nice is the Portable Application install option. Reviewed by Paul Thurrott in Potential Windows Live Writer competitor at his SuperSite Blog as well as at CyberNet News

  • JavaFX 1.0 Released – As if we didn’t have enough “rich content” applications between Java, Flash, Shockwave, AIR, Silverlight, etc., etc. etc.  Now we are getting JavaFX.  Follow the links to be dully amazed/bored/disinterested depending on your take.

  • PCLinuxOS 2009 is coming soon for release.  I really love this particular Distro and while 2007 has been strong, 2009 should be even more refined.  Hop over to the site to get all the news.

  • KLS Mail Backup - (freeware) – Provides simple backups of Windows mail, Outlook Express, Windows Live applications, Address book,  IE favorites and accounts, as well as various Mozilla programs including Thunderbird and Firefox. Spotted in a KLS Mail Backup makes email, browser backups a snap - Download Squad post.

There you go.

--Claus V.

Read More
Posted in blogging, Link Fest, Linux, PDF's, security, utilities | No comments

Windows 7 News Roundup #4

Posted on 3:19 PM by Unknown

Yep. The road to W7 is littered with news.

  • Windows 7 Beta 1 in 1 week??? - The Stone Blog - Windows Connected
  • A closer look at Windows 7 release dates - Ed Bott’s Windows Expertise

Release date for W7 Beta 1 looks to be sometime around January according to various sources and Ed Bott is picking January 13th for his W7 roulette stake.

However, if you attend an upcoming MSDN Developer Conference and pony up $99 registration fee, you will (eventually) get (by mail) a copy of the Windows 7 Beta DVD when available.  Just how hard-core an early adopter are you?  Windows 7 Beta for MDC Attendees – Bob’s blog.

          Date            City

  • 12/9/08       Houston, TX
  • 12/11/08     Orlando, FL
  • 12/16/08     Atlanta, GA
  • 1/13/09       Chicago, IL
  • 1/13/09       Minneapolis, MN
  • 1/16/09       Washington, DC
  • 1/20/09       New York, NY
  • 1/22/09       Boston, MA
  • 1/22/09       Detroit, MI
  • 1/26/09       Dallas, TX
  • 2/19/09       San Francisco, CA

I’m afraid I’m booked up already for the Houston date, so will have to continue waiting for a TechNet preview release of W7 (if ever offered there) down the road.  I’m not feeling up to Torrenting a version right now.

  • Windows 7 Error Recovery is a punch in the nuts for techies - Within Windows
  • Windows 7 Error Recovery actually works! – AeroXperience Blog

These are some great technical posts how how W7 error recovery “works” at least in early releases.  Reading through them it seems to me that they are successful but are curiously clunky in the recovery process.  I can’t image them staying in this format for the final release.  Vista’s is much more refined.  Although no Windows recovery process has ever seemed easy to understand for non-technical users, Vista and XP to a lesser degree are serviceable. This W7 stuff seems sure to frighten!

  • Windows 7 to report boot progress again, like Windows 2000 - Within Windows
  • YouTube - Windows 7 Build 6956 new animated boot screen video – Pretty!

I just loved this technical look by Rafael inside W7’s boot-progress architecture.  It is surprisingly complicated, yet simple as well.  Here is the golden-part that sent chills down my WIM hacking spine:

In Windows 7, the boot screen is simplified in many ways. It comprises of a single bitmap, loaded from a small Windows Imaging (WIM) file at runtime, and some text rendered on-the-fly. The approach of stuffing a small bitmap inside a WIM may seem a little overkill right now but this was likely done to future-proof boot reporting. I won’t be surprised if we see other boot-related resources (e.g. sounds) housed within the WIM in the near future…

  • Windows 7 - Mobile Broadband – Josh’s Windows Weblog - Windows Connected

Some great initial info on how W7 may support the mobile broadband platform.  This will allow simplified connection to the Net through a cellular modem so you don’t have to get tied up with the connection manager.

A great Google article, the difference between ‘easy’ and ‘simple’; and why this is a problem for Windows 7 - SuperSite Blog

Paul Thurrott opines on how Microsoft is still overreaching on OS design models and why W7 might still fail to please everyone.

But what about Windows 7? As I and others have written, Windows 7 is all about a complete reexamination of the Windows OS. Microsoft has probed into every visible and invisible corner of the system and tweaked virtually everything. The result is, condescendingly, “Vista done right” or, in my mind, simply a very finely tuned tool. As a friend noted via IM the other day, [I’m paraphrasing here], it’s pretty clear that what we’ve seen so far in Windows 7 is it. There’s nothing more coming. And I don’t know whether to be excited by that or freaked.

The problem with Windows 7 is that Microsoft is copying the Mac, again. No, they’ll never really make Windows as simple as Mac OS X, though by God they’re going to try. And the reason they won’t is because you can’t simply erase decades of piling on functionality on top of functionality. Windows will always be a Swiss Army knife. You can’t escape your heritage.

Gotta say, as a long-time Windows user and support person, I think Paul has some very good points and Microsoft is in a lot of danger of digging into a deeper hole that they started in Vista.

Will W7 be good, better, and more refined than previous versions? Sure.

Will that be enough to technically distance itself from Vista in the fickle minds of consumers and enterprise operations? Jury’s still out, but I’m doubtful it will, with Vista still so fresh out of the can.

I’m thinking only the hard-core Windows enthusiasts and fan-boys/girls will be salivating for W7 for the foreseeable future (pre/post final release).

Meanwhile folks in Cupertino orchard are leaning back in their chairs and smiling….

--Claus V.

Read More
Posted in Microsoft, Windows 7 | No comments

Warm things for cool and blustery days

Posted on 2:49 PM by Unknown

Minipost.

For the Belly

I still love RSS feeding the Houstonist for the latest behind the scenes goings on around our fine city of Houston, Texas.

I miss that they seem to have dropped their previous Tech Buzz regular posts.  Not so much  as they often pulled material from my blog, but I liked that local tech-news connection.

Anyway, a surviving post category has been local dining locations, and a top-post this week was Houstonist: One Pho the Money, Two Pho the Show covering two new Pho shop locations about Houston.

I’ve found a few choice Pho picks off Harwin, Fuqua, and recently on Bay Area Boulevard worthy of eating.  I sometimes stop in with a few near the light-rail line on the south-side of downtown with my Dad after work as well.  So I was happy to see this featured and be able to note some new joints to try.

A nice super-big bowl of beef Pho with some torn basil and hoisin sauce does wonders beyond miracles to my soul.

Of Belly “Bear”ers of the round and tumbly kind

I’m a kid at heart.

Give me a cold winter night and a DVD or VHS tape of the classic Winnie the Pooh stories and I am in childlike comfort.

Original Winnie the Pooh drawings » Drawn! The Illustration and Cartooning Blog

This brought me back to all things wonderful.

Hop over to BibliOdyssey: Original Winnie The Pooh Drawings for the full and amazing post up of E.H. Shepard’s brilliantly simple but evocative drawings of our beloved bear and friends.  Peacay also provides some nice commentary on them near the end of the post.

As stated, there is no telling if or how long the image links may survive depending on any copyright challenge requests for posting them, so finish up those stoutness exercises and head on over before they disappear like honey before a bear of very small brain.

….hmmmm.

Wonder how Pho with honey would taste?

--Claus V.

Read More
Posted in art, family, graphics, Texana | No comments

Browser Bullets: #2

Posted on 2:30 PM by Unknown

That last post took a bit longer to compose than I expected.  I’ve got a number more waiting in the wings and I really want to shove them out so I can turn my attention to a series of posts on a subject near and dear to my heart: WinPE boot disk building.

So with no more delay, here are this week’s browser-related links of note:

  • Mozilla to pull antiphishing feature from Firefox 2.0 at Google’s request – Computerworld Security.

This is interesting only as it applies to the older 2.0 version of Firefox. In my old post Firefox 3 Security Blocker: Going In Deep I looked at how the anti-phishing/attack-site protection features worked and how they got their data from Google.  It was heady stuff.

Now because of a protocol being discontinued, this feature will be stripped from the very last Firefox 2.0 build; version 2.0.0.19 to be released in a few weeks.

Firefox 2.x users should make the jump to the 3.0 versions now out for a number of reasons, including performance, security, and GUI enhancements. It’s too bad it this security feature couldn’t have been preserved for the few folks who haven’t decided to make the jump.

  • Second Firefox 3.1 beta due ‘very shortly’ - Business Tech - CNET News

The ffextensionguru and I have been all over this before.  However, there was a new tidbit of info in that article I had not known about as it concerns Firefox 3.1 releases:

One big change in the 3.1b2 is the addition of "Web workers," a feature that lets the browser process tasks in the background. That feature, part of the still-evolving HTML 5 specification, adds another level of sophistication for programmers writing Web applications and gives multicore computers a better way to use their processors' abilities.

He gave one illustration of Web workers in action running a JavaScript program that emulates a decades-old processor design, the 8080. One thread emulates the processor in the background while another handles user interaction such as checking for typing on the keyboard.

This sounds interesting and might help with system and web-application performance for supported pages/applications.

  • Peregrine takes flight... Opera 10.0 Alpha 1 is here! - Opera Desktop Team
  • Screenshot Tour: First Look at Opera 10 - Lifehacker
  • Opera 10 alpha 1 released, brings Acid3 victory – ARS Technica

Though I am remain a staunch Firefox fan (with Chromium closely second) Opera remains near and dear to my heart.  The 9.x builds are a major step forward both in terms of speed and rendering.  Now we are at 10.x alphas in the Opera line.

Granted, this initial 10.0 alpha 1 release primarily introduces the Presto 2.2 JavaScript engine and other performance gains.  It also packs in auto-updating and inline spell checking.  Things that many other browsers already have folded in to their currently released versions.  For those who care, Presto brings with it a 100/100 pixel-perfect score on the Acid3 test.   I think it is something to be proud of and nice to know, but certainly isn’t a deciding factor to me in browser choices (Firefox 3.1b1 gets a slowly earned 84/100 right now and Chromium 0.5.155.0 rips through it with a 100/100 but fails the link test.)

It will install alongside your existing Opera build without interference and seems to be able to share the same profile settings so you can jump between them with no issues.

Certainly worth looking into if you are a browser junkie.

Check out the Lifehacker link for pictures and the ARS post has better technical description of the under-the-hood improvements.

  • Mozilla Webdev » Blog Archive » Socorro wireframes
  • Top Crashers

Only for the hard-core Mozilla junkies, the Mozilla Web Development blog announces that they are working a new deployment of the crash-reporting system (Socorro).

The current page design works, but isn’t particularly easy to navigate or hunt up information in.

Database and form-junkies won’t have any trouble, but for non-technical fans, it is a bit daunting to drill down to the information you want.

The new design takes on a “dashboard” approach that pre-loads the top crashers.

The filter is also much more user intuitive to create your target set.

Hard-core junkies shouldn’t feel abandoned.  Advanced filters will be available and should further refine searches for pin-point searches.

Also curious, while poking around I see that the crash-reporter has already been collecting information on the following 3.1 (beta) builds along with some 3.2 action as well:

  • Firefox 3.1b1
  • Firefox 3.1b1pre
  • Firefox 3.1b2
  • Firefox 3.1b2pre
  • Firefox 3.1b3pre
  • Firefox 3.2a1pre

Like I said, only browser freaks like a few of us (who don’t even code) really would waste their time looking into these reports and stats, but it is fun and curious for the brave few.

--Claus V.

Read More
Posted in browsers, Chrome/Chromium, Firefox, Opera | No comments

Who are u.exe?

Posted on 10:47 AM by Unknown

Since mid-November, I’ve wiped all remnants of AVG Free 8 from my systems and have been diligently trial-testing a new (to me) AV/AM program.

I’m not yet at the point of dropping a review of Sunbelt Software’s VIPRE, but in a vague and general statement as to my feelings toward it at this stage of usage I will say this: it rocks.

I have it loaded on a XP Home desktop, a XP Home laptop, as well as a Vista laptop.  All come with various degrees of hardware/CPU/memory configurations.  So I hope to be able to provide a good and fair overview when ready.

But for now, let’s meet my specific u.exe friend.

U.exe’ve been snake-bit!

I had set up a staggered schedule of scans on the systems and scan results have indicated either potentially unwanted programs (PUPS) which are my sysadmin tools, or the occasional tracking cookies.

So I was a bit disturbed a number of weeks back when a new occupant on my desktop system’s hard-drive was located by the scanner and reported back as a trojan.

The alert was tagged as a Trojan.SVcHost threat under a “severe” risk level.  The threat-description sounded fairly menacing.

When I was able, I checked out the local scan “risk details” and found that the file named “u.exe” had been located in the C:\Documents and Settings\profile-name\Local Settings\Temp folder.  On Vista systems it shows up in the C:\users\profile-name\AppData\Local\Temp\ folder.

Hmmm. 

File names themselves are no indication of the maliciousness or friendliness of a file.  But the name did sound familiar. 

A quick search on my blog turned up the filename as being one I had run across at work in association with a particularly bad malicious worm package.  Not necessarily a match but the location and name certainly now how my full attention.

A u.exe - Google Search turned up all kinds of horrible indicators.  Looked like this really was a baddie!

Feeling pretty bummed and wondering what extent of compromise may have occurred I set to work.  Because this was my home system, I did pursue the “assessment” a bit more loosely in method and manner than I follow at work.

The detected file had been quarantined (and I was not fully familiar with the scanner features), so I was unable to view the properties information.

Looked like I had to go ahead and restore it.  Dangerous but necessary to do due to a possible short-coming in the VIPRE interface.

First, though, I was offered the chance to send it to the mother-ship labs for additional review (of a false positive).  What to do?  The A/V program said it was a threat. It could be. I had no info to say otherwise. Darn!  Feeling bad but fishing for more info I sent in anyway. 

More on this “feature” and related implications in the post-mortem report at this post’s end.

First Contact

With Spidey-Sense tingling due the loaded weapon now hot and armed on my desktop I started work.

First thing was to fire-up CurrPorts so I could see if it started jabbering away on the net if it executed.

I also had to disable the AV programs “active protection” so it wouldn’t keep alerting/removing the file as I worked with it.

I noted the file date, and then ran a scan with additional Nirsoft tools on all the system’s browsers looking for possible correspondence between the file name/time and surfing habits.  Sure that can be faked, but it was a starting point.  Unfortunately, no corresponding leads were found.

A check on the general file-properties found some more information.  Although it also can be faked, it did provide quite a lot of leads to follow.

  • File Version: 2.0.0.0
  • Description: PC Decrapifier
  • Copyright: Jason York, 2008
  • Comments: Free for personal use, other users see http://www.pcderaptifier.com

I went ahead and tossed Strings as well as FileAlyzer at it but though some interesting bits came up, nothing out of the ordinary at first-review.

It has a MD5 of 7eb9d42285d699e0c4b7b1ae9ba7f0f3

I uploaded the file to both jotti and VirusTotal.

The Virus Total report overall came back clean with only eSafe reporting it as a suspicious file and Symantec reporting it as the W32.Harakit.

Curious.

The Jotti report came back clean with only Dr.Web reporting it as the Trojan.Siggen.586 file. 

Hmmm.

Back to those file-property leads then.

Teasing out the PC Decrapifier connection

The PC Decrapifier is an outstanding and beloved freeware utility crafted by Jason York that removes a ton of OEM crapware that comes pre-installed on pre-built Windows systems.  These are the ones you bring home from the store or on-line and once booted, provide an onslaught of unwanted or trial-ware applications.  Most folks leave them on, many of us remove them, but a one-by-one removal process can be a drag. This applications wipe a high percentage of them off the system automatically. How cool is that!  I even host a link-back to this program under my “Claus’s PC Toolbox” sidebar which is something I rarely do for a program, free or paid.

So, finding possible associated links between it and what a number of AV programs report as a trojan was very disturbing.  Was it related or not?

I set a trap.

I downloaded the latest version of PC Decrapifier directly from Jason’s site.  So far so good.  No alerts.

I fired up Process Explorer as well as Process Monitor.  I set a number of filters on Process Monitor related to the malware file as well as PC Decrapifier.  I also started a Snag It video capture of the Process Explorer screen.  Sometimes some processes fire up/close so fast they can’t be screen-captured.

I also removed the u.exe file from the location and monitored the folder.

I executed the downloaded exe file and waited.  I got the wizard and started walking through the steps, right up to the point of applying the removals.

There was the u.exe file popping into the directory.

What have we here?

PC Decrapifier was without a doubt the source of this particular u.exe file.

From the screen capture as monitored by Process Explorer, you can clearly see that the main pc-decrapifier-2.0.0.exe loads a sub-process called pc-decrapifier.exe which then will (very) briefly create the u.exe process.

2008-12-06_095508

Process Monitor’s findings were even better.

image

A fast review of all those 5,615 events showed that, basically, the host file download unpacked the main pcdecrapifier executable which then performs a whole bunch of file/directory/registry checks.  During this process, the u.exe file is created and it then also executes a whole bunch of file/directory/registry checks.

Everything looked on the up-and-up.

By now I had clearly nailed the source of the file, and was reasonably comfortable that the file was legitimate and, in-fact, a false-positive.  I suspected that the false-positive may be caused by the u.exe packing method within the larger PC Decrapifier executable container.  However, I’m not certain if the alert is being caused by the AV due to a signature or heuristics.

Checking in with Jason

Now breathing much more relaxed, I wondered if the developer might be willing to shed some light on why he is using this particular method to execute the program.

I sent off a request for clarification on u.exe and Jason kindly struck up a correspondence.  He has allowed me to quote the gist of his explanation from one of our emails.

The download file uses NSIS (http://nsis.sourceforge.net/Main_Page) which really just unzips the necessary files into the temp folder as you have found.

The u.exe file is a AutoIt script (http://www.autoitscript.com/autoit3/index.shtml) which does use a  UPX packer. With version 2.0, I did convert the main program  completely over to a C++ application, but there were still some custom AutoIT uninstall scripts that I didn't want to rewrite.  So I kept some of them in as a helper application (u.exe)  The C++ application will make numerous calls to this to have it detect if there are applications it can remove.

There you go. Now the whole picture makes perfect sense to me.

Post Mortem

So, in regards specifically to this u.exe file with MD5 of 7eb9d42285d699e0c4b7b1ae9ba7f0f3, the file is harmless (to everything but OEM software crap at least) and is not, in fact malware as best I can determine but an integral part/function of the very awesome The PC Decrapifier utility.

Special appreciation to Jason for being so transparent with his program’s operation and structure.

For a few days, VIPRE had indeed stopped alerting on u.exe and my systems were nice and quiet again.  However the signature/heuristics are once again biting on this particular u.exe file.

I have resent the file to Sunbelt’s team as a false-positive report and also gained some more perspectives on how VIPRE works with quarantined files, as well as have a few kind suggestions for improvement.

First. in my initial encounter with the “trojan” and VIPRE, turns out the file had been created on my system prior to installation of VIPRE.  I hadn’t run The PC Decrapifier application post installation.  Thus it wasn’t found until a “full/deep” system scan kicked off.

When found, the file was alerted on in the (in progress) scan progress page.  Fair enough. However, I had to wait until the entire scan had been completed to get any additional details on the file in particular. Not good.  I would like the ability to get (at least) basic information about file location, properties, etc. mid-scan.

Secondly, once the scan had been completed, I was able to go into the Quarantine area of the program and then click the “Risk Details” button which then only provided me with a summary of the threat facts from Sunbelt as well as the location the file was found in.  I couldn’t get any other information about the file.  To do so I had to restore the file.

Thirdly, once I had wrapped up my “investigation” on my original XP system I ran the PC Decrapifier again on our Vista system.  Since this was a “fresh-run” VIPRE’s “Active Protection” system caught the u.exe “threat” immediately.  And tossed up a notification window.

Ahh!

In the window alert was a link to “show details”.  Clicking that shows a much more detailed report on the file specifics full of great information. (Text-selectable report is shown below underneath the alert window.)

U_exe_VIPRE-rpt

(observation: an MD5 hash in addition to the CRC8 would be nice for cross report checking from other sources.)

versus….

image

Which would you prefer?

I’d personally like to have access to both reports/details from both locations.

I can’t figure out why this same detail report option isn’t available during the scan on items found mid-scan nor why it isn’t offered (and differs) from the “Risk Details” displayed via the quarantine page. Maybe the file is rendered inaccessible to the “advanced” report detail API once in quarantine?  If so, it would be very nice to be generated/logged during the pre-quarantine process.

While average home-users of the product probably could care less, advanced users and researchers could clearly find value in access to the advanced report details while the file is still in quarantine as well as having it accessible mid-scan instead of only during “Active Protection” hits.

Fourthly, for some reason, I had recalled that when I sent the initial false-positive report in, I had the option to add additional comments to the transmission.  However, when I resent, I found that was not the case.  Having the ability to add comments or details to the virus report transmission might allow the reporter to provide great information to the labs allowing them context and information regarding the discovered threat and why/or why not the submitter feels it is in fact a false-positive alert.

Lastly, I would really, really, really like to see just a bit more feedback, even if automated, from files sent by the user to Sunbelt Software for additional analysis out of the quarantine jail.

At a basic level, just a simple return acknowledgement via email (if requested) would be nice to show the file was received.  Kicking it up a notch, a tracking number for the submission would be nice on a return email confirmation.  By providing that I could at least attempt to tie my updated research on the false-positive findings to an early case-file number to cut down on duplicate work in the Sunbelt Labs. Goodness knows we all have to be more productive now-days in IT.

I’m sure I’m not the only one out here who would gratefully provide more of my investigative work directly to Sunbelt lab analysts as we amateur and semi-pro sleuths have time on the side and tease out more details of a suspect file.  Corresponding via a submission case # would be great if more information panned out, or if the Labs requested more details/information themselves.

Finally, I have no idea if Sunbelt labs provides any direct (private) acknowledgment to a reporter it they do independently prove a file was a false-positive.  Instead I seem to have to re-test and see if the new definitions cause a re-alert or not.  Time-consuming at the least, dangerous at the worst if it was in fact a malicious file after-all.

That could be critical information to the end-user/investigator!

Suppose for instance, that in my case, this u.exe had been a false positive to a critical program or system file.  As a “noobie” or unsophisticated user, I may have reported the file anyway, and then allowed VIPRE settings to either permanently delete the file or delete it after a certain number of days.

I might never know that was in fact a false-positive and thus continue on with a critical file now missing from my system.

If I get feedback, I might be able to restore the file once notified it was a false positive, thereby mitigating the long-term damage from removing the file.

These are not intended to be seen as negative criticisms on VIPRE. And I have no idea if they toyed with these "feature” implementations or not, and if so, why they may have been excluded.  Maybe they are in there as advanced settings and I haven’t RTFM deeply enough yet.

However, if I know Alex Eckelberry, I’m sure he will graciously provide some level of feedback on these questions and observations.

That said, so far I’m very pleased with VIPRE overall and this “investigation" was quite fun.

I hope this helps some panicked or confused folks and clears up any questions regarding this particular u.exe’s association with The PC Decrapifier.

--Cheers!

Claus V.

 

Additional Reading:

Antivirus programs unreliable during critical coverage gap – ARS Technical report

Windows Incident Response: Issues with AV – Wonderfully appropriate post by Windows forensics expert and author Harlan Carvey on AV report technical details and consistency.  You can never have enough info on threats discovered via a AV application.

Off the AVG bandwagan. [sic] - Nicholson Security.

More On Why I Think Free Microsoft AV Will Be Good For Consumers - securosis.com’s analysis on the Microsoft “Morro” project’s impact on the AV industry.  Fast but tight read.

Read More
Posted in anti-virus software, malware tools, security, troubleshooting, utilities | No comments

Tuesday, December 2, 2008

Quick Browser and Google Bits

Posted on 6:58 PM by Unknown

Just some browser bits and pieces over the last weeks that might be worth noting

Google Chrome

While still not my main browser (Firefox 3.1b1 takes that slot), Google’s Chrome browser has endeared itself to my heart for its simplicity and style.  I love using it during presentations and trainings.  It really does bring the focus away from the browser and on the content.

That said, it still lacks many basic (IMHO) features. One of which is a bookmarks manager.

That hurdle has now been cleared.

Google Chrome gains a bookmark manager - Download Squad

I’ve tried it and it does add a lot to the Chrome party.  If you haven’t updated your Chrome browser it’s time to do so, for this alone! To do so simply go to "About Google Chrome" in the Tools/Help menu.  The updater should be available.

heise Security UK also points out some other worthwhile additions:

Google has also has brought all of the privacy settings together, and has reworked the pop-up blocker.

A potential security problem has also been eliminated. Until now, local HTML files were able to use XMLHttpRequest to move data to or from the internet, something attackers were able to exploit in order to steal data. Google has now put an end to this.

Also making some news is that upcoming releases of Chrome will also be able to fully support Chrome extensions now that the framework for API development for Chrome extensions has been published. Finally.

Google Chrome: Chrome Extensions On the Way, Adblock Imminent – Lifehacker.

I have to say, of all the Firefox Add-on extensions I use, the two I would most want to see in Chrome versions would have to be (hands down) Adblock Plus and NoScript.

Everything else would be gravy

Mozilla 3.1b3 ?

While I still wait for Firefox 3.1b2 to be released, now comes some interesting news that there might be a 3rd beta in the wings scheduled for Firefox 3.1.

Mozilla eyes extra beta for Firefox 3.1 – LinuxWorld

Previous schedules published by Mozilla had limited Firefox 3.1 to only two betas before moving to a release candidate.

In a long post to the "mozilla.dev.planning" forum, Mike Beltzner, the director of Firefox, said that Beta 3 is necessary to get a feel for the severity of the remaining bugs and an idea of how long it will take developers to eradicate them. In addition, another beta will give more exposure to features landing in the browser only as of Beta 2, which has not yet been released.

Not sure how likely this will be, but if it brings added stability and bug-fixes to key features and functionality to the next version update, I’m all for it.

Fashion your Firefox – Add-ins pre-picked/pre-packaged

Completely unrelated, but interesting none-the-less is the Mozilla sponsored Fashion your Firefox. This page allows you to select a Firefox “functionality theme” and then either select some/all of the suggested Add-ons in one fell swoop.  I really like this as a starting point for new-to-Firefox users as it really helps sort out some great Add-ons to showcase how Firefox is so awesome in flexing to the needs of its users.  And from a Mozilla-blessed standpoint to boot.

Sadly, lacking in the list are any collections that are forensic/pen-testing/security centric.  If you want those you will have to look to the Security Database Tools Watch - FireCAT 1.4 package or pop over to the Package de plugins FireCAT 1.4 (natively in French so here is the English Version a-la Google) and download the compressed file and install away. 

RE: GMail Exploit or Not?

In a late November GSD post, All Over Gmail: Like Stink on a Skunk, I mentioned a possible Gmail flaw that allowed a domain hijacker to drop some incoming mail intercept filters and take over the MakeUseOf blog site among others.  At the time it was unclear if this was a new/old/non-existent exploit. Although more than a few folks thought it was.

Well now that some time has passed, Google officially has said “not so!”

Google Online Security Blog: Gmail security and recent phishing activity

We've seen some speculation recently about a purported security vulnerability in Gmail and the theft of several website owners' domains by unauthorized third parties. At Google we're committed to providing secure products, and we mounted an immediate investigation. Our results indicate no evidence of a Gmail vulnerability.

With help from affected users, we determined that the cause was a phishing scheme, a common method used by malicious actors to trick people into sharing their sensitive information. Attackers sent customized e-mails encouraging web domain owners to visit fraudulent websites such as "google-hosts.com" that they set up purely to harvest usernames and passwords. These fake sites had no affiliation with Google, and the ones we've seen are now offline. Once attackers gained the user credentials, they were free to modify the affected accounts as they desired. In this case, the attacker set up mail filters specifically designed to forward messages from web domain providers.

So according to Google, the impacted users were victims of a phishing attack, not a Gmail exploit.  However, some good proof of concept seems to still show that it could be possible, however unlikely.

So, I still say keep an eye on your Gmail filters and check for anything unwanted and in the meantime, always use the HTTPS access login feature of Gmail just to be safe.

Other related links I collected as this story continued to develop:

Google security denies XSRF reports - Network Security Blog. A very good and brief analysis and commentary on the state of this particular story from security blogger Martin McKeay.

The fact is, I don’t see enough evidence for or against the exploitation of this vulnerability to prove either side of the story.   No amount of fact checking in the blogosphere is going to prove the point, there’s simply not enough known, it’s almost all speculation.  The Google Security team has to deny the report, it’s part of what they do.  But they have done a good thing in strongly suggesting everyone force their Gmail account only use SSL when logging in.  It’s not a perfect solution, but it is a step up from what most people are currently doing.

Gmail Exploit May Aid Domain Hijacking – ReadWriteWeb. Includes timeline of events and breakdown of the story from a wide-angle.

Hole in Google Mail allows mail to be hijacked - heise Security UK. Security site provides their perspective on the issue.

Google GMail E-mail Hijack Technique – GNUCITIZEN old post on 2007 Gmail exploit issues.

Removing your Google Cached pages for deleted content

A very dear and cherished blogger whom I follow found herself out of work some months ago.  Her blogging has continued faithfully but recently took a turn of frustration and extro-spection when she wondered if her blog and its posts were a possible drag on her employment search and application-screening process.

With more and more Net savvy employers doing Google searches for evidence of an applicant’s background on the Net, it is becoming harder and harder to present a “sanitized” version of oneself.  The past can come back and bite you, even when “deleted”. (Related: The End of Online Anonymity –ReadWriteWeb).  I worry for Alvis and constantly coach her to be careful and restrained on what she shares about herself online.  It’s fun now as a teen but when she gets out of college eight or so years from now?  Then what when she starts climbing the career ladder?

Anyway, this particular blogger was contemplating deleting some/many of her previous blog posts.  I commented that while that seemed like a good response, Google’s cache or the Internet Archive makes it harder than ever to really scrub your previous online presence from the net.

That’s good from a research standpoint but bad from a personal-privacy/regret-remediation standpoint.

To learn more about how this can be done, see this post Browsing the Web Using Google Cache – Google Operating System Blog.

Google Cache is a great solution if a web page is down. If you're visiting a site and it returns a 404 error message, you can…do a search on Google for that site (add the cache: operator, so your search query would be something like cache:www.google.com).

Google Cache Hacking - rentzsch.com has more juicy details on this feature.

Instead, after opening my heart up a bit more than usual with perspective and encouragements, I offered some advice that maybe she should instead begin seeding her blog with more technical posts that would indicate her skills and showcase why her technical knowledge would be an asset, instead of just having posts (however wonderful they are) of a strictly personal nature.  Maybe that might work to her advantage as well as providing some balancing professional counterpoint to the personal themed posts.

That said, there are some avenues to getting your content removed from Google cache listings:

Google: Deleting things from Google’s cache – Lifehacker

Removing my own content from Google’s index – Google Webmaster Help Center

If the content is currently in our index, we will remove it after the next time we crawl it. To expedite removal, use the URL removal request tool in Google Webmaster Tools.

Same goes for the Internet Archive’s Wayback machine saved page removal.  From their FAQ

How can I remove my site's pages from the Wayback Machine?

The Internet Archive is not interested in preserving or offering access to Web sites or other Internet documents of persons who do not want their materials in the collection. By placing a simple robots.txt file on your Web server, you can exclude your site from being crawled as well as exclude any historical pages from the Wayback Machine.

Internet Archive uses the exclusion policy intended for use by both academic and non-academic digital repositories and archivists. See our exclusion policy.

Here are directions on how to automatically exclude your site. If you cannot place the robots.txt file, opt not to, or have further questions, email us at info at archive dot org.

These are the only locations that previously Net posted materials may be saved, but might be the most common. 

Feel free to leave other tips on sites that cache pages even when removed and links for the removal process.

As for the dear blogger, she removed that particular post (and it wasn’t cached BTW) and I haven’t heard a response to my comments, but I did notice a few more “technical” posts on her blog.  Good show and best wishes!

Cheers!

--Claus V.

Read More
Posted in blogging, browsers, Chrome/Chromium, Firefox, Gmail, Google, search engines | No comments

Monday, December 1, 2008

Pushing through the wall

Posted on 8:42 PM by Unknown

<deleted> long, rambling, ranting, possibly whiny post about boot disks, av false-positives, too few posts lately, too many valuable links worth sharing, something unkind about RGP contact lenses, and not enough time.

<insert> short honest post advising followers that Claus is here, very tired, having ate too much food, engaged in not nearly enough counter-balancing physical exercise, watched way too many college football games of importance, traveled to too many relatives’ homes on opposites sides of the fair state of Texas—by car, and despite all attempts to the contrary, avoided logging on to any family computer for three days out of a four-day holiday weekend.

I know. Remarkable.

Good news?

My new tailored-fit dress shirts still fit pretty darn well and that this weekend marks the traditional Valca girls’ efforts to trim the tree and home in all-things Christmas.

That means that while I will have to take some time extracting all the boxes from our storage closet, I am allowed in good will to retreat from household activities and keep my distance.

More posts for you!

It’s too early to tell what they may hold, but expect a few jam-packed linkfests, research on an av program’s particular false-positive, and (hopefully) I can begin to bring some closure (and neat lessons learned) to my VistaPE/WinPE 2.0 disk building journey to Hades and back.

Cheers!

--Claus V.

Read More
Posted in blogging, family | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Network Capture Tools and Utilities
    At a conference this week, we had quite a section regarding network captures. The instructor was going on about how you can try to sort ou...
  • It just has to be bigger on the inside…
      Last Christmas, Lavie gifted me with a cute little Jawbone JAMBOX unit. I thought it was pretty cool. It uses a Bluetooth connection t...
  • Mostly Minor Network Notes
    Here are some minor tweaks and features, mostly of a network nature. Manual Uninstall of the Cisco VPN Client « Mobile Expertise -- becaus...
  • Windows Live Mail error 0x80041161
    Dad is working with his father-in-law who has an issue with his Suddenlink web-mail-based “forwarding” handling of messages. Seems that (an...
  • FireCAT 1.5 “Plus” Add-On Collection
    In yesterday’s GSD post I noted the following: Both of these tools brought be back to the excellent FireCAT 1.5 collection of Firefox...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ▼  2013 (83)
    • ▼  November (8)
      • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA uti...
      • ForSec Linkfest - 2013 DST Fallback Edition
      • CryptoLocker Ransomware Info & Free Prevention Sol...
      • Linkfest for the SysAdmins
      • Microsoft Security Essentials/Defender & PowerShell
      • Miscellaneous TrueCrypt linkage
      • PowerShell 4.0 and a tiny “gotcha”
      • New Software Updates + VMware Tools Update fix
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ►  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile