The MS XP Change Analysis Tool creates a list of recent key changes that have been made to a given system. Important things such as new programs, OS updates and drivers. Scott Fendley notes some false positive to be aware of: …some software packages appear to make changes in more places then I even knew was occurring. For example, Symantec Antivirus Corporate Edition changes the path to certain driver files with virus definition updates. These will be reported as: Changed from “\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070326.020\navex15.sys” to “\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070327.019\navex15.sys” Adobe Acrobat apparently also makes regular modifications to the startup folder for its Speed Launcher program. It could be useful to troubleshoot your own XP machine, or someone you’re trying to help out. Another tool to[…]

The Iraq League’s use of Google Earth demonstrates the dual nature of technology/software use. As the communal bloodshed has worsened, some Iraqis have set up advice websites to help others avoid the death squads. One tip – on the Iraq League site, one of the best known – is for people to draw up maps of their local area using Google Earth’s detailed imagery of Baghdad so they can work out escape routes and routes to block. It’s another example of the central role technology plays in the conflict – with the widespread use of mobile phones, satellite television as well as the internet – by all sides and for many purposes. The flip side: Terrorists attacking British bases in[…]

TomTom, makers of a popular (if over-advertised) GPS navigation device, have admitted to a UK security journalist that a number of TomTom GO 910 units shipped with two trojans pre-installed. “It has come to our attention that a small, isolated number of TomTom GO 910’s, produced between September and November 2006, may be infected with a virus. The virus is qualified as low risk and can be removed safely with virus scanning software. Appropriate actions have been taken to make sure this is prevented from happening again in the future.” Seriously, folks. Every single software distributor should have anti-virus installed and updated on every single machine, as a matter of standard policy. The bad PR, combined with the cost of[…]

There’s a proof-of-concept Vista exploit (actually works against Windows 2000 and XP as well) for privilege escalation on a russian language site, as reported by eWeek. Mike Reavey, operations manager of the Microsoft Security Response Center, confirmed that the company is “closely monitoring” the public posting, which first appeared on a Russian language forum on Dec. 15. It affects “csrss.exe,” which is the main executable for the Microsoft Client/Server Runtime Server. More interesting is the other quote later on in the article, describing the economics working against Microsoft these days… The Microsoft confirmation comes hard on the heels of a claim by anti-virus vendor Trend Micro that underground hackers are selling zero-day exploits for Windows Vista at $50,000 a pop.[…]

Even the Starship Enterprise’s computers were broken into by countless aliens. (Quite easily I might add, complete compromise of a starship? Must be running Windows 98). So I won’t blow this comment out of proportion, I think that it was a bit taken out of context: During a telephone conference with reporters yesterday, outgoing Microsoft co-president Jim Allchin, while touting the new security features of Windows Vista, which was released to manufacturing yesterday, told a reporter that the system’s new lockdown features are so capable and thorough that he was comfortable with his own seven-year-old son using Vista without antivirus software installed. Just because you’ve added some new security features (which aren’t out in the public quite yet – give[…]