The blog

Kids’ laptop riddled with spyware!

I was depressed to read this post from a Microsoft blogger who claims to be involved with security: Argh! Kids’ laptop riddled with spyware!

I downloaded the current beta version of MS’ new Anti-SpyWare tool yesterday and installed it on my kids’ laptop. When I ran the scan, I found something like 16 different types of SpyWare installed. The trigger was starting up IE on the machine and being greeted with something called the “Megasearch” tool bar!

I can say that the new Anti-SpyWare tool seems to do a really good job. Of course with SpyWare, you don’t know what you don’t know. There could be another dozen SpyWare packages installed on my system that the tool didn’t detect, but at least I know I got some. Oh well, what are you going to do?…

Jeebus, the last thing I want to hear from someone who works at Microsoft is this sort of defeatist attitude. Especially when they’re involved in security. What are you going to do? Back up the kid’s data. Wipe the hard disk and reinstall Windows and all programs. Set up safeguards to make sure no unwanted programs get installed again. Ban Kazaa and anything lke it. Give the kid a Limited user account.

It works.

Yet another reason to install SP2

In the comments to an earlier post, someone noted a screen shot of an ActiveX dialog box that included the “Always trust content from this company” option. He asked the obvious question: Why isn’t there a “Never trust content…” option?

Short answer: There is. But only if you’re running the latest Windows version.

If you’ve installed Windows XP Service Pack 2, you’ll find that the wording in this dialog box has been changed to specifically refer to installing software rather than the confusing “trust content” wording. Here’s what the new dialog box looks like; note that you first have to click the Information Bar to display this dialog box and then you have to click a More Options button to see these settings:

Never_install

We noted this important change in Windows XP Inside Out, Second Edition and the larger Windows XP Inside Out Deluxe, Second Edition), both of which cover SP2 thoroughly:

In earlier versions of Windows XP, the dialog box used with signed downloads included a check box that allowed you to specify that you always trusted the publisher using that certificate. By selecting this check box, you could automatically install future downloads from your favorite publishers without having to see the Security Warning dialog box every time.

Windows XP SP2 adds the counterpart to that feature—a check box that lets you identify a publisher as untrusted. If you determine that a particular company’s widely distributed ActiveX controls and programs don’t belong on your computer, you can designate that publisher as untrusted, and no user of your computer will be able to install software that uses that publisher’s digital certificate.

If you haven’t installed SP2 yet, this is yet another reason to do so. If you’re holding off because you’ve heard bad things about SP2, please do some more reading starting here. SP2 is quite safe and reliable, and the few known issues are relatively easy to deal with.

Support the fight against spyware

This makes my blood boil. At Spyware Warrior, Suzi just posted the full text of a letter she received from the legal counsel for iDownload. They’re demanding that she remove pages that refer to their product as spyware and/or malware. Suzi says:

As owner of this domain, netrn.net, the home of this blog, I am currently obtaining legal counsel and evaluating my options. I will post additional details as they develop.

I have firsthand experience with this company’s products. When I was doing testing for a post on “poisoned media files” I ran across a Windows Media video file that attempted to install the iDownload product on my computer. The ActiveX dialog box called it a “Required: Media Player Version 9 Update.” It is, of course, no such thing. That description is an out-and-out lie. Eric L. Howes documented the installation process at Broadband Reports and captured the following screen:

Idownload

Legal bills are expensive. Even when you’re right, you can go bankrupt just protecting yourself and your good name. Which is why I just clicked the PayPal Donate button on Suzi’s blog and sent her some financial support.

This appears to be an orchestrated campaign to stifle all criticism of this company, because the same legal team sent a nearly identical letter to CastleCops.com as well. In addition, someone recently targeted anti-spyware activist Ben Edelman’s site for a massive denial-of-service attack.

Is iDownload’s software bad for you? I don’t have enough personal knowledge to say. But many authoritative sources seem to believe it is so.

  • Symantec, an acknowledged leader in the security software industry and maker of Norton AntiVirus, unequivocally labels iDownload’s iSearch Toolbar as “spyware.” The Symantec listing describes its behavior as follows: “Spyware.ISearch is an Internet Explorer Browser Helper Object and functions as a toolbar. It is a search hijacker and also tracks user activity on a remote server at isearch.com.”
  • Trend Micro, a respected maker of AntiVirus software, calls the iDownload.com product Adware. Its description begins: “This adware may be downloaded while browsing the Internet without a user’s consent. It attempts to block popup windows and redirect a browser to its server, which is http://www.isearch.com.”
  • Tenebril, a respected maker of security software, lists iSearch in its Spyware Research Center. Its description says, “ This is a hijacker application. Hijackers take control of your web browser’s settings, and usually change your homepage, search page or other default pages to point to web sites owned by the hijacker. Since the hijackers can make money just based on the number of visits to their web sites, they benefit from forcing you to view their web sites each time your web browser opens.”
  • The database at Spywaredata.com includes seven instances of iDownload’s toolbar.dll, all of them classified under the parasite label.

The license agreement for the iSearch software includes the following text:

By installing the Software, you understand and agree that the Software may, without any further prior notice to you, automatically perform the following: display advertisements of advertisers who pay a fee to iSearch and/or it’s partners, in the form of pop-up ads, pop-under ads, interstitials ads and various other ad formats, display links to and advertisements of related websites based on the information you view and the websites you visit; store non-personally identifiable statistics of the websites you have visited; redirect certain URLs including your browser default 404-error page to or through the Software; provide advertisements, links or information in response to search terms you use at third-party websites; provide search functionality or capabilities; automatically update the Software and install added features or functionality or additional software, including search clients and toolbars, conveniently without your input or interaction; install desktop icons and installation files; install software from iSearch affiliates; and install Third Party Software.

In addition, you further understand and agree, by installing the Software, that iSearch and/or the Software may, without any further prior notice to you, remove, disable or render inoperative other adware programs resident on your computer, which, in turn, may disable or render inoperative, other software resident on your computer, including software bundled with such adware, or have other adverse impacts on your computer.

This company lies when it offers the software to an unsuspecting user. The license agreement this company wrote, which they know the average user will not read, admits that the software may install additional software or remove programs already on your computer without your knowledge or input (or obviously, your consent). And the company freely admits that its software may have “other adverse impacts on your computer.”

Does this sound like a program you want to install?

Please, support Suzi. Click the PayPal Donate button on Suzi’s blog and help her out.

Updated: Suzi responds to iDownload.

The security software industry wants you to be afraid

I’ve been writing a lot about the flaws in the commercial security software business lately. Today, Joe Wilcox at Microsoft Monitor inadvertently provided an excellent illustration of why this industry is so fundamentally flawed. Joe had an experience with a Symantec software package today that made him think Symantec is doing a great job of protecting him. Based on his post today, I think he came to exactly the wrong conclusion. He wrote:

A few minutes ago, Norton AntiVirus 2005 warned that it had detected and blocked an attempted intrusion into my computer. Huh? I quickly clicked on the pop-up warning before it retracted into the Windows toolbar. My wireless router has a built-in firewall, Outlook wasn’t retrieving e-mail and the Web browser was closed, so I wondered from where the intrusion could come. According to NAV 2005: MSN Messenger 7 Beta.

NAV 2005 identified the virus as the “Master Paradise Trojan,” which is by no means new. If my flu-drugged memory is accurate, the virus is circa late 1990s. So, why am I seeing it now? That’s a question I’ll seek to answer later today.

But the attempted intrusion, assuming NAV 2005 correctly identified the virus, is reminder the many ways a virus can infect a Windows operating system–in this case through instant messaging. [emphasis added]

That’s a big assumption. I read Symantec’s write-up on the MasterParadise Trojan horse program, and I also read F-Secure’s description. This program runs on Windows 95, 98, and NT 4.0, none of which Joe is running. The remote user can configure it to use any port to make a connection. Symantec says, “There have not been any reports of this program breaking through a firewall.”

So what happened? I believe Joe got a false positive from a firewall. Now, I get annoyed when I get a false positive. I consider it a failure on the part of the security vendor. Missing a real threat is much worse, of course, but a false positive is still a failure and can lead to unpleasant consequences if it convinces you to delete a perfectly innocent file or remove a program that’s perfectly safe. At a minimum, a security program should give me the technical details of what it discovered so I can troubleshoot for myself.

Here’s what I think really happened. Any application installed on your computer can attempt to create an outgoing connection. When it does so, it uses the well-known port number for the remote service and assigns an arbitrary port number to listen on. You can see this very easily for yourself by running netstat from a command prompt. Each line shows a local (incoming) port number and the port used for the outgoing connection. In this case, it sounds like one connection from the Messenger beta used the arbitrary port number 3129, which turned out to be the same as the default port used by this ancient Trojan. 

This recent post from a Java newsgroup quotes the following response from Symantec to a nearly identical issue:

I understand from your message that you are receiving the following
alert from the Norton AntiVirus (NAV):

“Default Block Master Paradise Trojan horse” blocked communication.

Kenneth, this alert message does not indicate the presence of the
Master Paradise Trojan horse on your system. This issue can happen if
javaw.exe is using the local port 3129 on your system. This port is
usually used by Master Paradise Trojan horse program.

Please note that there is a block rule for Master Paradise Trojan horse
under Trojan Rules section in Internet Worm Protection. This rule
monitors activities and communications through the local port 3129.
When it finds a communication through the local port 3129, it will
display this alert message.

Carl Siechert and I warn about this potentially confusing issue in Windows Security Inside Out:

Trojan horse programs often use port numbers that are also used by legitimate programs and system components. Do not assume that a system has been infected simply because you see a program listening on a port number that is known to be used by a particular Trojan horse. For example, the “Sockets de Trois” Trojan often uses port 5000, but so does the legitimate Simple Service Discovery Protocol (SSDP) Discovery Service. In addition, your computer assigns incoming ports using arbitrary numbers beginning with 1024. One of these dynamic port numbers might match a number that’s also used by a Trojan horse program; be sure to look at the port number on the destination computer before concluding that your computer has been compromised.

But that’s not what Joe did. Instead, he concludes (incorrectly, I believe) that he dodged a cyber-bullet:

NAV 2005 detected and quashed the attempted intrusion on my HP Pavilion zd8000 notebook. HP did right by shipping the portable preloaded with the security software and providing a colorful eight-page pamphlet, “Get Secure: Protecting Your Computer.” If not for NAV 2005’s instant-messaging monitoring, looks like the Master Paradise Trojan would have infected my test computer. So, I’m feeling quite charitable to both HP and Symantec. Perhaps the best marketing is the consumer’s good experience, and one no vendor should ignore.

This conclusion is misguided, in my opinion. And it illustrates everything that is wrong with the commercial security software business. Joe feels good because the software told him it had protected him, even though the likelihood that this was an actual attack is microscopic. The lesson that Joe is unwittingly sending to the vendors in question is, “Give me more false positives, because the more times you tell me you’ve protected me from something, the more I’ll feel like I’ve gotten my money’s worth from your software.” If he had a better security program, it would have realized that this outgoing connection was just fine and would not have given him any warning at all.

That is just wrong. On a healthy computer with multiple layers of security, most threats should be blocked or neutralized before the user ever sees them. Getting lots of warnings is a sign that one of those layers isn’t working as well as it should. But that’s exactly the opposite of what motivates developers of security software today.

Windows XP Media Center Edition 2005 setup instructions

Charlie Owen’s new blog is up and running, and his first substantive post includes some very detailed content for anyone thinking of going the do-it-yourself Media Center route. His collection of Windows XP Media Center Edition 2005 Setup Instructions consist of four PDF files that explain (and show in great detail) how to back up and restore WMP10 licenses; replace your video card and add a TV tuner; add a second hard drive; and install an OEM copy of Windows XP Media Center Edition 2005.

In all, these documents list more than 100 steps, complete with screenshots and tips. Even if you’re sure you know what you’re doing, this is a useful checklist to make sure you haven’t forgotten anything.

Hunter S. Thompson, R.I.P.

Author Hunter S. Thompson Kills Himself

I remember seeing HST when I was at UCLA, studying journalism, more than 30 years ago. It was just after Fear and Loathing on the Campaign Trail had come out. The book, and Hunter’s amazing voice, had a huge impact on me.

Many, many years later, I was on a Ziff-Davis junket in Aspen and our small group ran into Hunter while we were out snowmobiling. He was driving a convertible Cadillac, with a gorgeous woman sitting next to him. When he saw us, he pulled out a rifle and waved it around, muttering all the while about needing to get down a bet on that day’s NFL playoff game. We retreated, quietly, and someone in our group called 911.

A couple days later, I was at a hotel in New York when my publisher’s assistant called and told me that a deputy from the Pitkin County Sheriff’s Office wanted to speak with me about the incident. He asked if I had ever felt threatened. I said no, I honestly didn’t. He wasn’t pointing the gun at us, just waving it around.

HunterSThompson

I asked the deputy if he had to investigate cases like this very often. He paused for almost a minute and finally said, “Well, Hunter is Hunter.”

Indeed.

Hunter, you’ll be missed.

Here are some additional remembrances for your reading pleasure:

Continue reading “Hunter S. Thompson, R.I.P.” →

A closer look at MSN Desktop Search

Hmmm. I may have to take a closer look at MSN Desktop Search based on Michael Sippey’s updated review:

A couple of months back I posted a shoot-from-the-hip review of MSN’s Desktop Search beta. I’m here to recant. Eat my words. Take it all back. Because I now love the thing.

Lots of great hands-on suggestions for tweaking the interface so it’s more useful and productive, too.

(Via FirstAdopter.com.)

Joel Spolsky doesn’t trust Microsoft AntiSpyware

Joel Spolsky of Joel on Software is rightly considered one of the smartest developers around. When he writes something, it gets read – especially in Redmond. So his remarks yesterday on Microsoft AntiSpyware deserve a fair parsing:

So far, it looks like this is a nifty program, and consumers should be happy that Microsoft has announced it will be free, but it really, really would have been nice for us here in the software industry if Microsoft had set a price on this thing just to provide some air cover for the other companies working on spyware removal. This is not a software category where a monopoly monoculture will be a good thing.

I think he got this one wrong on two counts. First, the antispyware industry has already established itself as a category where most programs are free. Ad-Aware and Spybot S&D are the two most widely used utilities. Lavasoft, which makes Ad-Aware, has a free version that is presumably its most popular product; Patrick M. Kolla, developer of Spybot S&D, gives the program away for free. There are paid antispyware programs (most notably PestPatrol) but increasingly antispyware features are being folded into larger security suites as added features. Both Symantec and Trend Micro have begun adding spyware detection and removal features to their flagship antivirus programs, for instance.

Which leads me to my second point: Antispyware software should be free. There are gazillions of unethical companies out there that make a living selling deceptive programs that fool unsuspecting users into paying for their worthless “protection” by falsely detecting threats where none exist. When this type of software is a profitable category, it encourages companies to use hype and scare tactics to create threats where none exist.

Joel continues:

Not only that, but I wonder if Microsoft can run an antispyware product without huge conflicts of interest. For example, will they block all the spyware that Real installs on your system? While Real is suing them? Especially when blocking spyware from Real will just give Real more ammunition to use against Microsoft in court? And the next time Microsoft needs a DRM favor from your friendly neighborhood media conglomerate, will the media conglomerate demand exemption from Antispyware removal for their adware in exchange for supporting Windows Media 37.0, with the new brain-zapping feature that prevents you from humming any song unless you bought the performance rights?

Well, that’s a problem already with the the “free” product, as Lavasoft and PestPatrol discovered earlier this week when they removed one widely derided adware program (WhenU) without alerting users.

There’s always going to be suspicion when a single company is making go/no-go decisions on whether a program should be considered a threat or benign. That’s why I like the community-based approach introduced by GIANT AntiSpyware (the original developer of the antispyware product that Microsoft purchased). Microsoft has committed to keeping the SpyNet community as a key part of the final release.

I would like to see as much transparency as possible from all security vendors, especially when you’re talking about products that are legal but unethical. The products in this category aren’t viruses, pushed into the world by anonymous vandals. These are typically commercial products, released by identified companies. The bar to removal should be high (although the user should be able to make the level of protection more stringent). One thing I like about Microsoft AntiSpyware is that it is first and foremost a preventive measure. It alerts you when a program is trying to sneak an auto-starting module into the Registry or change your home page, and it gives you the power to stop damage before it can occur. The real problem with spyware comes when it sneaks onto a computer. Anything that Microsoft can do to prevent Windows from being misused in this fashion is a Good Thing.

Why was Media Player updated?

Updated March 2…

eWeek is out with a news story headlined “Microsoft Updates Media Player to Thwart Spyware Threat”. As far as I can tell, this story is almost completely inaccurate.

Microsoft Corp. has released an update for its flagship Windows Media Player to protect users from a known threat of spyware infection.

Microsoft said the update … installs two components on end users’ computers and will add “additional integrity checks to the DRM [digital rights management] system.”

The company made no mention of a spyware infection, but a spokesperson confirmed the new version of the player was released after Microsoft confirmed that malicious hackers were using the copy-protection mechanism to install spyware, adware, dialers and computer viruses on unsuspecting PC users.

The article refers to the Update for Windows Media Digital Rights Management-enabled players (WindowsMedia-KB891122–x86). I’m still testing, but I see nothing in the KB article that documents this fix that would indicate there is any protection for users. It appears that the spokesperson is in error and the reporter simply accepted the inaccurate statement.

To make matters more confusing, an update to Windows Media Player 10 was also released this week, without any documentation of what was changed. Yesterday, Ed Oswald at BetaNews talked with a Microsoft spokesperson who said that this update was the promised fix to the spyware/adware issue:

Microsoft on Wednesday issued an updated Windows Media Player 10 to correct a potential security issue that could allow an attacker to mislead users into downloading malware or viruses instead of a license to playback DRM content.

A spokesperson for Microsoft confirmed that the new WMP release, marked build 3802, was the promised update to take care of issues related to the player’s digital rights management functions.

Needless to say, at least one of these stories is just plain wrong, and I strongly suspect that both are wrong.

CNET News.com has a slightly expanded story that contains similar assertions:

The Redmond, Wash., giant on Tuesday introduced an update to its Windows Media Player, which included changes aimed at blocking the Japanese hackers’ work, as well as a security update.

[…]

The new update also addresses a problem exposed a month ago, in which the Media Player and its digital rights management software could be used to show ads–or even to lure unsuspecting Web surfers into downloading harmful software onto their hard drives, security researchers said.

The process exploited a feature of the Media Player content protection, which allows protected files to pop up a Web page with information about a video or song license. In such a case, that page could be loaded with automatic spyware download mechanisms, Spanish security company Panda Software said.

 

The new update to the Media Player software contains a setting that allows consumers to request that they be notified any time their computer is going onto the Internet to obtain a content license. By default, this option will be turned off, but computer users can turn it on, Caulton said.

I’ve installed the Digital Rights update on a test PC and compared its options to those on a computer without the update. I can’t find any option in Windows Media Player 10 that matches the description in this story. If it’s there, it’s well hidden. It may be that the option is only available in Windows Media Player 9, but I’ll need to do further testing to see whether that’s the case.

[Update: In a comment to this post, Ben Edelman notes that he has tested the patch with WMP9 and found that it does not change the behavior observed before installing the patch. Ben’s comment includes links to a screen shot and a video of his results showing exactly how the exploit can deceive a naive user. Warning: The end of the video contains explicit sexual content that some viewers may find offensive.]

[Update, March 2: For a follow-up on this story, see “How to Fumble a Security Update.”]