Windows Secrets

 

 

   
       
   
Windows Secrets Newsletter • Issue 201 • 2009-06-11 • Circulation: over 400,000

   
   
AD
Free download — update all your drivers   Free download — update all your drivers
DriverCure automatically and instantly updates all your out-of-date drivers and software. This results in a fully optimized PC that runs fast and error-free. DriverCure was developed by a team of over 100 professionals with the goal of a user-friendly application that accomplishes the crucial task of keeping your system up-to-date. Download DriverCure now and update your PC in under 2 minutes!
DriverCure

   
   
Table of contents
TOP STORY: Big-name sites spread latest malware infections
KNOWN ISSUES: IE 8 causes big problems on some PCs
WACKY WEB WEEK: "Dude, I totally meant to do that ..."
LANGALIST PLUS: Will moving the pagefile improve performance?
IN THE WILD: Microsoft still has no patch for DirectShow hole
PATCH WATCH: Critical patches for Internet Explorer 7 and 8

   
       
   
ADS

All-new Optimize 3.0 — free scan   All-new Optimize 3.0 — free scan
Take a few minutes to find out why your PC is so slow. Run the free PC Pitstop Optimize 3.0 scan and receive a free custom report detailing common issues that might be keeping your PC from running at full speed. Over 150 million scans run. Scan now!
PC Pitstop

Try Snagit for screen capture free   Try Snagit for screen capture free
If you see it, you can Snagit. Capture any size image your PC can handle in a snap, and share it just as fast. From something small to an entire page that scrolls, Snagit has you covered. Grab exactly what you want, when you want it, every time. Try it for free!
Snagit

Optimize your PC by updating your BIOS   Optimize your PC by updating your BIOS
Do you want to improve the performance of your PC? Phoenix Technologies' new BIOSAgentPlus is a program that will scan your PC and match the correct BIOS and specific driver updates you need on any desktop or laptop. Scan today for a free report!
BIOSAgentPlus

See your ad here

   
   
TOP STORY

Big-name sites spread latest malware infections

Susan Bradley By Susan Bradley

Going by such names as Gumblar, JSRedir-R, Martuz, and Beladin, a new generation of malware has managed to surreptitiously place malicious JavaScript code on tens of thousands of popular Web sites.

The hacker scripts try to infect site visitors and then attempt to use their compromised PCs to spread the infection to yet other sites.

Over the past month, the security services ScanSafe and Sophos have reported infections on such major Web sites as ColdwellBanker.com, Variety.com, and Tennis.com. Niels Provos reported in the Google security blog on June 3 that sites infected with Gumblar numbered about 60,000. Visitors became susceptible to infection simply by opening the sites in Internet Explorer.

After the script infects a PC, it attempts to spread its code to any Web site accessible via that machine's FTP client, if one is present. Webmasters often use FTP to make changes to the sites they manage. If FTP software is configured to save a webmaster's sign-in information, the malware can edit itself into a Web site's pages.

Once a PC is running this class of malware, the hacker code tries to trick the user into opening infected PDF and Flash files. If the PC has an unpatched version of Adobe Reader, Acrobat, or Flash, opening an infected file can install a keylogger or other malware. In the case of Gumblar, Google search results in an Internet Explorer window are rewritten — in a way that end users may not notice — so the links point to hacker sites laden with infected PDF and Flash.

Security firms have made efforts to block domains that serve as malware destinations in this latest round of attacks. But the bad guys quickly move to substitute other domains in what has been compared to a game of Whack-a-Mole.

Meanwhile, it's not so easy to shut down a well-known, legitimate site that's infected (although many such sites have quickly been cleaned up). You can't protect yourself simply by visiting only "trusted" sites, because there's no easy way for an end user to determine whether a legitimate site is infected.

Fortunately, you can stack the odds in your favor by following the guidelines in the Windows Secrets Security Baseline:

  • Step 1: Use a hardware firewall.
  • Step 2: Install a set of security software.
  • Step 3: Scan your system regularly with a software-update service (more on these below).
  • Step 4: Use Mozilla's Firefox or Google's Chrome browser, both of which are more secure than Internet Explorer.
The rise of a new form of Web-based threat

On May 27, the Microsoft Malware Protection Center blog reported that a malware family Microsoft refers to as Gamburl and Redir was infecting legitimate Web sites by embedding malicious scripts in the sites' HTML code. A system running Windows XP could become infected simply by opening a seemingly trustworthy site. (Gumblar, also called JSRedir-R and Martuz, doesn't affect Vista PCs, according to the Unmask Parasites blog.)

Once an XP machine is infected, passwords for FTP sites are retrieved and placed into a file called sqlsodbc.chm. This file is a legitimate SQL help file in Windows XP and 2000, but it's not used on Vista machines.

To determine whether Gumblar has struck your PC, test sqlsodbc.chm, which is located in XP's C:\Windows\System32 folder:

  • Step 1. Download the free FileAlyzer program from the Softpedia site and install the program on your system.

  • Step 2. Press the Windows key and E to open an Explorer window. Navigate to the C:\Windows\System32 folder, right-click the sqlsodbc.chm file, choose Analyze file with FileAlyzer 2, and note the file size and SHA1 hash value. (See Figure 1.)

    FileAlyzer file-check utility
    Figure 1. The FileAlyzer utility checks the sqlsodbc.chm file to determine whether your PC is infected with Gumblar.

  • Step 3. Compare the file size and SHA1 hash value with the listing of good file types published on the Microsoft Malware Protection Center blog. If the file doesn't check out, update your machine's anti-malware software and run a full system scan. The scan should find and clean out the infection. On my test PC, the sqlsodbc.chm file had the expected values, which proved that the system wasn't infected.
Once your copy of sqlsodbc.chm comes up clean, you need to take steps to ensure that it stays that way. Download the latest virus definitions for your antivirus software. Also, ensure that Adobe Reader, Acrobat, Flash Player, and all your other third-party media players and applications have the latest patches.

Home and small-business users can run a free update checker such as Shavlik Patch, which you can download from the vendor's site. (Note that the program requires the free Google Desktop, which is available on Google's site.) A complete review of Shavlik Patch and several competing update programs is in my May 28 top story.

For business networks, I recommend Shavlik's NetChk Protect. I use this utility — which costs from U.S. $104 for two seats — to patch my own firm's network. You can find information about NetChk Protect on Shavlik's site.

For an added measure of protection, configure your PC to use the OpenDNS service, which lets you block categories of sites that you don't visit. You'll find complete instructions for making the required changes to your router on the OpenDNS tutorial page.

To make OpenDNS your DNS server, you can run your router's advanced settings program and manually set its DNS options to 208.67.222.222 and 208.67.220.220. (See Figure 2.)

OpenDNS settings dialog
Figure 2. Make OpenDNS your primary and secondary DNS server in your router's DNS settings to block potentially dangerous sites.

It's theoretically possible to manually enter in the OpenDNS settings page the URLs of sites you want to block. But trying to keep up with the latest list of Gumblar sites is nearly impossible. ScanSafe's STAT Blog indicates that the rate of Gumblar infection is slowing. But new infected domains — all of which use China's .cn top-level domain — are popping up as fast as others are being shut down.

Boost XP's defenses against Gumblar-like attacks

If you feel your XP system needs more protection — for example, you own a PC used by unsupervised teenagers — consider creating user accounts that lack administrator privileges. Granted, XP's limited accounts are often a pain to use because they restrict downloads, settings changes, and other common actions. An article on Microsoft's site explains limited user accounts and describes how to set them up.

Fortunately, the type of limited accounts in the forthcoming Windows 7 will be much easier to use. This is because the most common applications will run properly under Win7 without administrator rights. Steve Friedl's Unixwiz.net site includes a Tech Tip that describes Windows 7's enhanced User Account Control.

Gumblar definitely makes Web surfing with Internet Explorer more hazardous. If your PC is infected, merely searching in Google for seemingly innocent topics can lead you to a site you never intended to visit.

Google's Niels Provos recommends in his Top 10 Malware Sites blog that people use Firefox, Chrome, or another browser that taps into Google's Safe Browsing API. The API blocks Web destinations on Google's list of potentially dangerous sites, which the company claims to update continuously.

Here are some additional ways you can protect yourself:
  • Make a full system backup. Create a backup of your PC using drive-imaging software such as the $50 Acronis True Image Home. (A 15-day free trial can be downloaded from the Acronis site.) Be ready to roll back to a prior image should your PC become infected.

  • Use Windows SteadyState. This free program "freezes" a machine, preventing changes that could be harmful. For more information and a download link, visit the product page on Microsoft's site. (Windows Genuine Advantage validation is required for the download.)

  • Browse in a sandbox. WS senior editor Ian "Gizmo" Richards described free sandbox programs in an Oct. 16, 2008, article. A sandbox lets you open suspicious links without putting your system's security at risk.

  • Don't use Internet Explorer. All versions of IE are vulnerable to Gumblar and similar Web threats, but especially IE 6 is an infection waiting to happen. If a site or application requires Internet Explorer, update to IE 8 if you can. If you can't, download IE 7 as a bare minimum (although it's by no means a remedy). You can download IE 7 from Microsoft's Download Center and IE 8 from the browser's page on Microsoft's site.

    If you simply must use IE 6 because some site or application requires it, urge the errant developers to make their code support the latest version of IE instead.

    For tips on running and optimizing Firefox, Chrome, and other non-IE browsers — including OpenDNS and the security-enhancing NoScript extension for Firefox — see a comprehensive six-part article at MaximumPC.com.
Some of the above precautions may sound like paranoia, but I consider them the digital equivalent of locking your car doors and staying out of dark alleys.

Susan Bradley recently received an MVP (Most Valuable Professional) award from Microsoft for her knowledge in the areas of Small Business Server and network security. She's also a partner in a California CPA firm.

Table of contents

   
   
ADS

Free CompTIA exam preparation   Free CompTIA exam preparation
For a limited time, ExamForce is offering Windows Secrets readers a free download of our popular CompTIA A+ exam prep. Includes both the CompTIA A+ Essentials and CompTIA A+ IT Technician. Hundreds of questions, answers, and detailed explanations.
ExamForce CramMaster for CompTIA A+

Your old drivers are slowing down your PC   Your old drivers are slowing down your PC
Driver Detective provides the most up-to-date drivers specific to your computer, including all major-brand OEMs (Dell, HP, Compaq, Toshiba, etc.) and generic brands. We access a database of over 9.2 million device-associated drivers — the largest driver update database on the Internet. Driver Detective saves you endless hours of work and aggravation normally associated with updating drivers.
Driver Detective

Get your message seen by 400,000 readers   Get your message seen by 400,000 readers
Does your company offer a product or service? Now you can place an ad in the Windows Secrets Newsletter and be seen by more than 400,000 active buyers of PC hardware and software. Bid as much or as little as you like to get the ideal ad placement. Take advantage of our all-new design interface, allowing larger images and longer text, and get updated stats in real time!
Windows Secrets Newsletter

See your ad here

   
   
KNOWN ISSUES

IE 8 causes big problems on some PCs

Dennis O'Reilly By Dennis O'Reilly

The new version 8 of Microsoft's Internet Explorer browser has some features that version 7 doesn't.

But that's no guarantee that upgrading to IE 8 will go smoothly on your PC.

The perils of software updates were brought home to computer-repair business owner Bob Millard as he attempted to heal the XP systems of three clients who had recently moved from IE 7 to IE 8:
  • "I have a computer repair business. In the last two weeks, I've had to fix three XP laptops after the installation of IE 8 made them inoperable. In each case, after the update, the desktop on each of these computers was blank except for the desktop wallpaper.

    "It didn't matter whether you started the system in normal or safe mode, all desktop items — including the taskbar — were missing. The only way I could get them back was by using one of my bootable utilities that would allow me access to the restore points. On two of these laptops, restoring back a few days corrected the problem.

    "On one of them, even though I got all the desktop functions restored, I didn't have Internet access or any access to USB devices. I tried to remove IE 7 (IE 8 was gone after the restore) but there was no remove/uninstall option in the Add/Remove Programs window.

    "I was able to use a remove-IE7 utility that I have [IE7 EasyRemove, available at the Drive Headquarters site] to get back to IE 6, and now the system is working again.

    "Bottom line: There are big issues in Internet Explorer 8 land."
Bob told me that he subsequently reinstalled IE 7 on two of the laptops and everything worked as expected. However, the third still lacked USB access and had other problems with IE 7 installed, so Bob left IE 6 on that machine — at least until he could find the required fix.

Despite the potential pitfalls, I recommend that if you must use Internet Explorer, install the latest version that won't trash your system. If IE 8 crashes and burns, revert to IE 7. If IE 7 brings you grief, roll back to IE 6 — but only long enough to get things working again. Old versions of IE are too insecure for today's scary Web.

Bob Millard will receive a gift certificate for a book, CD, or DVD of his choice for sending a tip we printed. Send us your tips via the Windows Secrets contact page.

The Known Issues column brings you readers' comments on our recent articles. Dennis O'Reilly is technical editor of WindowsSecrets.com.

Table of contents

   
   
WACKY WEB WEEK

'Dude, I totally meant to do that ...'

Near miss By Katy Abby

In the world of extreme sports, there's never a dull moment. We office-dwellers, on the other hand, get our cheap thrills by living vicariously through the exploits of others. Don't get me wrong: cubicle life begets its own set of dangers — carpal tunnel, stiff neck, tendonitis, oh my! — but somehow, it's not quite the same.

Take a look at this exhilarating compilation of death-defying near misses, outlandish athletic feats, and unbelievable footage of the world's luckiest bank robbers. They're sure to get your heart racing without your ever leaving the comfort of your swivel chair! Play the video

Table of contents

   
   
BONUS DOWNLOAD

Spam-Proof Your E-Mail Address, 3rd Edition
Antispam e-book is our free bonus to you
To celebrate the Windows Secrets Newsletter's 200th issue — which was published on June 4 — we're giving away this month a revised 3rd edition of Spam-Proof Your E-Mail Address. My 32-page PDF e-book, suitable for printing and storing in a three-ring binder, explains tricks anyone can use to reduce 97% of the spam that an e-mail address would otherwise attract. The e-book sells for $9.95, but all subscribers can download it completely free, now through July 1, as part of our festivities. To get yours, simply use the link below, update your preferences page with current information, and a download page will appear. Enjoy! —Brian Livingston, editorial director

All subscribers: Set your preferences and download your bonus

   
   
PERMALINKS

Use these permalinks to share info with friends

We love it when you include the links shown below in e-mails to your friends. This is better than forwarding your copy of our e-mail newsletter. (When our newsletter is forwarded, some recipients click "report as spam," and corporate filters start blocking our e-mails.)

The following link includes all articles this week: http://WindowsSecrets.com/comp/090611

Free content posted on June 11, 2009:

 
You get all of the following in our paid content:

Get our paid content by making any contribution

12 months of paid content

There's no fixed fee! Contribute whatever it's worth to you
Readers who make a financial contribution of any amount by June 17, 2009, will immediately receive the latest issue of our full, paid newsletter and 12 months of new paid content. Pay as much or as little as you like — we want as many people as possible to have this information.
 
Julissa in El Salvador

A portion of your support helps children in developing countries
Each month, we send a full year of sponsorship to a different child. Your contributions in June are helping us to sponsor Julissa, an 8-year-old girl from El Salvador. Save the Children channels development aid from donors to Julissa and her community. We also sponsor kids through Plan USA and other respected agencies. More info

Use the link below to learn more about the benefits of becoming a paid subscriber!

More info on how to upgrade

Thanks in advance for your support!

   
   

Table of contents

   
   
YOUR SUBSCRIPTION

The Windows Secrets Newsletter is published weekly on the 1st through 4th Thursdays of each month, plus occasional news updates. We skip an issue on the 5th Thursday of any month, the week of Thanksgiving, and the last two weeks of August and December. Windows Secrets resulted from the merger of several publications: Brian's Buzz on Windows and Woody's Windows Watch in 2004, the LangaList in 2006, and the Support Alert Newsletter in 2008.

Publisher: WindowsSecrets.com LLC, Attn: #120 Editor, 1700 7th Ave., Suite 116, Seattle, WA 98101-1323 USA. Vendors, please send no unsolicited packages to this address (readers' letters are fine).

Editorial Director: Brian Livingston. Senior Editor: Ian Richards. Editor-at-Large: Fred Langa. Technical Editor: Dennis O'Reilly. Program Director: Tony Johnston. Program Manager: Ryan Biesemeyer. Web Developer: Damian Wadley. Research Director: Katy Abby. Copyeditor: Roberta Scholz. Contributing Editors: Susan Bradley, Scott Dunn, Mark Joseph Edwards, Michael Lasky, Woody Leonhard, Ryan Russell, Becky Waring.

Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, Support Alert, LangaList, LangaList Plus, WinFind, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of WindowsSecrets.com LLC. All other marks are the trademarks or service marks of their respective owners.

HOW TO SUBSCRIBE: Anyone may subscribe to this newsletter by visiting our free signup page.

WE GUARANTEE YOUR PRIVACY:

1. We will never sell, rent, or give away your address to any outside party, ever.
2. We will never send you any unrequested e-mail, besides newsletter updates.
3. All unsubscribe requests are honored immediately, period.  Privacy policy

HOW TO UNSUBSCRIBE: To unsubscribe from the Windows Secrets Newsletter,
Copyright © 2009 by WindowsSecrets.com LLC. All rights reserved.

Table of contents