Windows Secrets

Subscribers: Sign in

Enter your e-mail address to get a free subscription.
We guarantee your privacy
Skip to content
  • Home
  • Newsletter Archives
    • Current
    • LangaList Plus
    • Patch Watch
    • Wacky Web Week
    • Security Baseline
  • E-Books
  • Lounge
  • About us
    • Refunds
    • Privacy Policy
    • Advertise
  • Contact
  • Your Account
    • Upgrade
    • Preferences
    • Bonus Download
    • Unsubscribe
Home>Don't fall for PC scan scams

Windows Secrets Newsletter • Issue 50 • 2005-03-24 • Circulation: over 400,000


Table of contents 
  • Top Story: Don’t fall for PC scan scams
  • Briefing Session: ‘Log Me In’ is free remote access done right
  • Windows Secrets: Web surfers, beware of dangerous waters
  • Patch Watch: Patches are subject to a great deal of FUD
  • Patch Watch: Rules of engagement for patch warfare
  • Hot Tips: BackupFox is new Firefox profile-saver
  • Wacky Web Week: Why wait ’til you’re dead to show in the Louvre?

 
Top Story

Don’t fall for PC scan scams

Brian livingston By Brian Livingston

Thanks to massive publicity about the subject, computer users are now widely concerned that their machines might be infected with "spyware" programs. These applications monitor users’ activities and perhaps transmit to a hacker the users’ passwords and other confidential information. But many Web sites that claim to “scan your computer” to detect spyware are, in fact, spreading spyware themselves.

In one of the latest examples, the U.S. Federal Trade Commission announced on Mar. 11 that Spyware Assassin, a $29.95 program sold by MaxTheatre Inc., was promoted by bogus pop-up windows. These windows falsely claimed, "You have dangerous spyware virus infections on your computer. Click OK  to install the latest free update to fix these errors."

The FTC said that if a computer user clicked OK, a phony "local scan" then reported that spyware has been found, displaying a phony list of supposedly infected files and folders. Both the original message and the "local scan" reported problems even if the computer was free from infections, the FTC said.

The federal agency persuaded the U.S. District Court in Spokane, Wash., where MaxTheatre is based, to issue a temporary restraining order. The site is now shut down.

This kind of scam is now so common on the Web that it’s generating its own macabre jokes. One wag suggested in a Slashdot posting that, if the FTC really got serious, we’d soon see the following story:

  • "The Federal Trade Commission has shut down Microsoft, alleging the company participated in fraudulent practices with its Windows and Office software, which purportedly gave the illusion of an operating system and/or increased productivity at work, even though no improvement was done and in most cases, the user machine would stop working correctly after a day. The company’s site then offered the user a $30 product to enhance security, which the commission reports ‘didn’t do a thing.’“
Impersonating a cleanup service

All kidding aside, the number of bogus programs that now pose as "antispyware" applications is enormous and still growing.

Eric Howes, a security researcher who has published numerous tests of cleanup programs (as described in our Feb. 24 and previous newsletters), has found more than 100 examples of disreputable applications on the Web.

He maintains a detailed list of Rogue/Suspect Antispyware Products on a page at Spyware Warrior, an informational site. The rogue’s gallery includes such programs as "SpyDeleter," a product promoted, according to an FTC complaint, by Sanford Wallace, formerly a well-known spammer. The FTC sought a restraining order against Wallace and a related company, Seismic Entertainment Productions Inc., last October.

In many cases, according to Howes’ listings, rogue programs actually install browser home-page hijackers and open a back door to install other software.

Many computer users are understandably fearful of online threats and click OK to cleanup offers, without first questioning the source of the “alert.” This is one more thing to guard against on the Web.

Unfortunately, some legitimate security companies also offer online scans to detect malware on PCs. Although these companies mean well, I can’t recommend such scans at this time. Even if the company produces a fine software product, any remote scan is subject to false positives. In other words, the scan might detect something on a PC and incorrectly label it malware. If the company then offers to sell a product to clean up the system, it can be accused of engineering the false positives, just as the FTC charged MaxTheatre of doing.

A much better approach is for computer owners to purchase low-cost but effective security programs to clean up their systems and then protect them from further infections. We include a summary of the top-rated programs in our Security Baseline section, below.

Important: Please note that my recommendation against Web scans of PCs does not apply to vulnerability detection sites, such as the excellent Shields Up! service provided by Steve Gibson of the Gibson Research Corp. This service, with your permission, examines a PC’s network connection to determine whether or not it has "open ports" that can be exploited by hackers. Since the testing mechanism needs to be outside your network in order to conduct such vulnerability assessments, Shields Up! provides a valuable service that cannot easily be performed by software you install.

Let’s call it spyware if it qualifies

I wrote in the Feb. 24 newsletter that the distinction between "spyware" and "adware" was meaningless. Since all such programs generate revenue or something else of value for their promoters, they should all be called adware, I said. This would preclude authors of such programs from saying, "Our product is not spyware, it’s adware, which is fine." Programs that control any aspect of your PC without your full knowledge and consent are always a severe security risk and should not be tolerated. (I have always stated that "ad-supported software," where the ads are displayed within an application’s primary window, as with Opera and Google, are fine.)

I now believe I shouldn’t have dissed the term "spyware" so much. The public has come to fear "spyware" because of saturation coverage of the problem in the mass media. For this reason, I’m dropping my objections to the term and the newsletter will use "spyware," "adware," "malware" and other terms as appropriate.

Howes has written to me that definitions of spyware are actually becoming a burden on consumer advocates such as himself. He now feels that the more specific a definition is, the more it may be a trap:
  • "I’m really skeptical at this point that we ever will come up with a term for this kind of software that everyone can live with. The problem is that once you come up with a term and that term becomes even remotely tainted or even hints that the software is in any way undesirable, the people whose software you’re trying to hang that term on are going to object.

    "Just one year ago the industry was pushing the ‘spyware=bad / adware=good’ distinction. Now many of these same companies don’t even want to be associated with the term “adware,” so tainted has that term become.

    "I actually think the right approach now is to push people to stop getting hung up on the precise word(s) you use to name the software, which leads only to useless definitional disputes that the bad guys exploit to wriggle out of your term, and focus on the practices and behaviors of the companies and the software."
Howes provided the most far-reaching analysis of the various problems we face — and terms to describe them — in a paper he submitted to the FTC last year. At that time, he thought a better catch-all term would be "junkware." I recommend his paper to everyone interested in this subject.

The problem isn’t ads, it’s remote control

Unfortunately, the issue of pop-up ads (which are bad enough) has confused the main threat facing us. It isn’t a display of ads that makes a program malware. It’s the fact that the application has (1) the ability to run commands on the infected PC, or (2) download new versions of itself (which may have negative features), or (3) download entirely new programs that aren’t in the best interest of the computer owner.

The fact that a PC user is giving control of the machine to someone other than its owner is the heart of the matter.

If I were writing laws about this, I’d prohibit software that can "morph" its code once installed, except under strict conditions. I believe all such software should be removed automatically by security programs. The user should then be able to see a log of what was removed, and should be able to undo some of the uninstalls, in some cases.

As I noted on Feb. 24, the license for the iSearch Toolbar, an adware program, says it may "without any further prior notice to you… install software from iSearch affiliates; and install Third Party Software." There is absolutely no reason for a legitimate software company to claim the right to install on your PC other programs from other companies, which you may never have heard of.

I believe there’s an enormous financial incentive for adware makers to sell access to their network of PCs to questionable characters. With this temptation, I believe it’s only a matter of time before seriously nasty programs are installed everywhere, making them stronger than the defenders. (At some point, say, they may collectively launch a massive DDoS against the servers of Symantec, McAfee, and other security firms. Some such attacks have already begun. Numerous malware programs alter a PC’s Hosts file so attempts to connect to security firms’ sites fail. These alterations are stopped by installing the leading antispyware apps, which are shown in our Security Baseline section, below)

That’s why I believe all computer users should eradicate this stuff now, and that ISPs should start checking for and eradicating it, too.

Don’t use P2P software that installs spyware

I’ve written previously that file-sharing software usually tries to install spyware. I noted on Jan. 27, for example, that Grokster alone could install as many as 15 separate adware programs.

If you insist on using such peer-to-peer applications — which open connections in your PC that have their own serious security risks — I urge you to read Ben Edelman’s Unwanted Software Installed by P2P Programs.

Edelman, a respected researcher who is a Ph.D. economics candidate at Harvard University, shows the junk you can accumulate from file-sharing applications. Of the five programs he tested, only LimeWire was free from adware. (Edelman discloses that LimeWire has a consulting relationship with him. I believe his results are trustworthy none the less.)

In future issues of the newsletter, I hope to publish a list of Web sites that actually do provide useful PC scanning services without any hint that they might use false positives to sell products. This is an extremely difficult topic to research, because such sites may change at any time, making guarantees difficult. All I can say is: Watch this space.

Our thanks go out to our reader whose handle is Navigatr1 for help in researching this topic. To send us more information about spyware, or to send us a tip on any other subject, visit WindowsSecrets.com/contact. You’ll receive a gift certificate for a book, CD, or DVD of your choice if you send us a comment that we print.


 
Briefing Session

‘Log Me In’ is free remote access done right

Paul thurrott By Paul Thurrott

Windows XP Pro includes Remote Desktop, which is useful for remotely connecting to your PC. But Remote Desktop has trouble with firewalls, and it isn’t available on Windows XP Home Edition, 2000, 9x, or Me. Fortunately, Windows users have a variety of options for remotely accessing your PC. And one of them, surprisingly, costs nothing.

We’ve all been there: You’re stuck at work, in a coffee shop, or halfway around the globe, and you need a file on your home computer. If you’re lucky, you can call a spouse or other family member, and talk them through the process of emailing the file to you. But that’s not an elegant or foolproof system. What you really need is some sort of remote access software.

XP Professional includes such a solution, called Remote Desktop. But if your XP machine is behind a firewall in your home network, and you’re out on the road, good luck making that connection. Users with other Windows versions, including XP Home Edition, are even more out of luck, as they don’t have Remote Desktop at all.

Various third party application makers, of course, have stepped in to fill that gap. These solutions have no problem navigating firewalls automatically. And they use encryption to protect the data traveling over the connection between you and your PC.

Classic remote access

The problem, until recently, was that most of these solutions were pretty expensive. Symantec’s pcAnywhere is the classic remote desktop solution. Available for Windows XP, 2000, 9x/Me, and NT 4, as well as

This article is part of our paid content. Subscribe.

Already a paid subscriber? Click here to login.


 
Windows Secrets

Web surfers, beware of dangerous waters

Chris mosby By Chris Mosby

Like that beach movie that recently aired on CBS-TV, the Internet is infested with hacker "sharks" that are constantly swimming around fishing for computer "food."  Unlike the real thing, these sharks swim with their fin deep underwater and it’s hard to see them coming.

Since the Internet is pretty essential to everyday living to some people, all you can really do is put on that steel-reinforced scuba gear and take a dip.

CSS styles can now infect IE 6

Once again, hackers have found a way turn a perfectly good feature of a Web browser against you.

A Cascading Style Sheet (CSS) is defined by the World Wide Web Consortium as "a simple mechanism for adding style (e.g. fonts, colors, spacing) to Web documents." Used correctly, this formatting feature is a good way to standardize the look and feel of Web sites, while leaving other HTML code untouched.

Unfortunately, this formatting feature can be used against unsuspecting Internet Explorer 6 users, even those who have XP SP2 installed. An unpatched IE weakness allows a hacker to access a user’s computer via a specially crafted CSS file. All that’s needed for this to happen is to use IE to visit a Web site that has the hacker’s CSS file. This may sound far-fetched, but there is already exploit code available on the Web for this vulnerability.

What to do: Until a patch is available, you can take steps to disable style sheets in Internet Explorer.  This can be done by doing the following:

• Step 1: Open the Tools menu in Internet Explorer.
• Step 2:
Click Internet Options and select the Accessibility button towards the bottom left corner.
• Step 3:
In the Formatting section, check all three boxes
• Step 4: Click OK on all dialog boxes you have opened to saved your changes.

Note: This may make some Web sites display improperly or not at all.

The amount of damage that this exploit can do is limited to the rights that a user has on the machine. This is a good argument for logging on to your computer with reduced rights, as was suggested in the March 10, 2005, edition of this newsletter.

For more information, see Microsoft’s MSDN article on safe browsing and a Security Focus bulletin on the IE flaw.

New info leak found in most browsers

If you haven’t figured it out by now, the Web isn’t safe unless you take precautions. Even using a different browser than Internet Explorer doesn’t always protect you from vulnerabilities. The newly popular Firefox browser sometimes has security issues, too.

This has become even clearer recently with information released by Security Focus. According to the security firm’s report, browsers from many different vendors are vulnerable to a weakness that could allow a hacker to gather information from a computer. This information could be user names, file names, and file locations. By itself, this problem is not too much of a threat, but combined with other exploits, the damage done to a computer could be significant.

This problem has been confirmed in all versions of Internet Explorer, Firefox, and Opera. Exploit code for this is already available as well.

What to do: This problem is pretty new, and because the exploit is unpatched, details are hard to come by. Your best plan of action is to follow the IE hardening guidelines detailed in the Nov. 11, 2004, issue of the Windows Secrets Newsletter. Paul Thurrott’s suggestion from the March 10, 2005 edition on running with reduced user rights may also prevent exploits that can leverage this vulnerability.

This article is part of our paid content. Subscribe.

Already a paid subscriber? Click here to login.


 
Patch Watch

Patches are subject to a great deal of FUD

Susan bradley By Susan Bradley

Today is going to be FUD Roundup Day at the ‘ol Patch Corral. You’ve heard of FUD, right? Fear, Uncertainty, and Doubt? Once used only in relation to IBM, then in reference to Microsoft, it seems everyone likes to throw around a bit of FUD these days to get us consumers upset and concerned.

Today we’re going to cover some FUD about operating systems, patching, and — as usual — our ever-present topic, browsers.

FUD 1: April 12, your PC is no longer yours

As I said in last issue’s Patch Watch, April 12 will not be the day you "automatically" receive Windows XP SP2. But if you’re currently on XP SP1, perhaps this is the time to think about finally installing SP2.

Many firms that have not deployed it are in state of being "stuck between their vendors and their applications." The vendors will not certify the service pack — and the firm is unable to install the patch unless the vendors support it.

Personally, I’ve found that all of my line-of-business applications have worked just fine on XP SP2. I had no service agreement to worry about voiding. I tested my applications for full functionality and didn’t even bother with vendor certification.

If you must wait for vendor certification, you should try as best as you can to get them to approve the service pack, if that&#

This article is part of our paid content. Subscribe.

Already a paid subscriber? Click here to login.


 
Patch Watch

Rules of engagement for patch warfare

Mark burnett By Mark Burnett

Over ten years ago, I locked my keys in my car. It was the first time in my life I had ever done this and I have never done it since. But, to this day, my wife still asks me if I have the keys every time I shut the car door. A decade of not locking the keys in my car has done little to gain her trust.

I feel the same way about Windows patches. I’ve been burned enough to think twice every time I let Windows install a hotfix for me. For countless companies around the world, patch management has become a million-dollar nightmare.

I remember the first NT4 server I ever administered. After years of unprivilege, I finally got promoted to use the Administrator login for myself. But I was still so naïve about security — my password was superman.

I remember looking at Microsoft’s list of available hotfixes and being so overwhelmed that I just put it off to deal with later. Of course, the task grew greater each month and finally got to a point where I was so far behind, it was just easier to wait until the next service pack and start over again. It turns out that that approach wasn’t too uncommon among NT administrators.

Windows 2000 was my fresh start

When Windows 2000 came out, I was determined to not let that ever happen again. I studied, dissected, tested, and tracked every new Win2k hotfix that ever came out.

One side-effect of all that study was that it made me acutely aware of all the sloppy patchwork Microsoft put out. It got so bad that I gradually lost all confidence in the system.

So, like my wife, I too began to question; I came up with a list of rules to protect myself. Even after all this time, I still don’t feel comfortable installing a patch without considering at least some of these rules.

To many people, these rules might seem extreme and somewhat paranoid, but I’m a security consultant — people pay me to be paranoid.

Rule 1: Don’t always trust what you read

Microsoft has come a long way in improving the consistency and quality of their KB articles and security bulletins.

But, at one time, this was a big problem. If a KB article said something worked or didn’t work, I simply couldn’t trust it; I had to test it out for myself. And, to my disappointment, my tests too often proved the KB article wrong, further confirming my mistrust.

Rule 2: Don’t always trust what you know

Even if you test something, that doesn’t mean it won’t change. For every security bulletin Microsoft releases, there are dozens of other security-related KB articles that go unnoticed.

This article is part of our paid content. Subscribe.

Already a paid subscriber? Click here to login.


 
Hot Tips

BackupFox is new Firefox profile-saver

We reported in our Mar. 10 issue the untimely demise of the MozBackup Firefox profile-saving tool. Now reader Christopher W. turns us on to a discussion on the Neowin forums regarding a recently developed utility for Firefox called BackupFox. This tool is useful when you’re upgrading Firefox and want to make sure your bookmarks and other preferences are preserved in case anything goes wrong.

At press time, the latest revision of BackupFox is "only" version 0.73, but the author is very good about quickly releasing updates for fixes and new features. Read the first post of the forum to ensure you have the latest version before installing. See: Neowin discussion of BackupFox.

Roboform tracks browser upgrades

In our Mar. 10 issue, we also published reader Les Barnes’ experiences with Roboform after upgrading to Firefox 1.0.1:
  • “I used the paid version of RoboForm, so I was rather upset when the Roboform people said that they don’t make [Mozilla, Firefox, and] Netscape adapters for small browser changes.

    But I did find that I could ‘force’ the installation by showing the Roboform program where the browser was located (since it couldn’t find 1.0.1) and it installed beautifully…”
Andrew Finkle, VP of Business Development at Siber Systems (the makers of RoboForm) wrote in with this response:
  • “This is not entirely correct. Whenever Firefox has a new version, it “breaks” th

    This article is part of our paid content. Subscribe.

    Already a paid subscriber? Click here to login.


 
Wacky Web Week

Why wait ’til you’re dead to show in the Louvre?

Banksy painting   Reuters, the New York Times, and many other news outlets reported today that a British artist who goes by the name Banksy has been hanging hilarious painted spoofs (photo, left) in New York’s Metropolitan Museum of Art and other museums around the world.

The Wooster Collective, a group named after a street in New York City, has posted what it calls exclusive photos of the artwork and how the installations were pulled off. In one case, the collective says, a piece remained on a museum wall for three days before it was discovered and taken down by officials.

Reuters quotes the artist as saying he was inspired to do his pranking by his sister, who he found one day tossing out some of his pictures. When he asked why, she replied, "It’s not like they’re going to be hanging in the Louvre." He says, "I thought why wait until I’m dead." See the photos

YOUR SUBSCRIPTION

The Windows Secrets Newsletter is published weekly on the 1st through 4th Thursdays of each month, plus occasional news updates. We skip an issue on the 5th Thursday of any month, the week of Thanksgiving, and the last two weeks of August and December. Windows Secrets is a continuation of four merged publications: Brian's Buzz on Windows and Woody's Windows Watch in 2004, the LangaList in 2006, and the Support Alert Newsletter in 2008.

Publisher: WindowsSecrets.com, 1218 Third Ave., Suite 1515, Seattle, WA 98101 USA. Vendors, please send no unsolicited packages to this address (readers' letters are fine).

Editor in chief: Tracey Capen. Senior editors: Fred Langa, Woody Leonhard. Copyeditor: Roberta Scholz. Program director: Tony Johnston. Contributing editors: Yardena Arar, Susan Bradley, Scott Dunn, Michael Lasky, Scott Mace, Ryan Russell, Lincoln Spector, Robert Vamosi, Becky Waring. Product manager: Andy Boyd. Advertising director: Eric Gilley.

Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, Support Alert, LangaList, LangaList Plus, WinFind, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of WindowsSecrets.com. All other marks are the trademarks or service marks of their respective owners.

HOW TO SUBSCRIBE: Anyone may subscribe to this newsletter by visiting our free signup page.

WE GUARANTEE YOUR PRIVACY:

1. We will never sell, rent, or give away your address to any outside party, ever.
2. We will never send you any unrequested e-mail, besides newsletter updates.
3. All unsubscribe requests are honored immediately, period.  Privacy policy

HOW TO UNSUBSCRIBE: To unsubscribe from the Windows Secrets Newsletter,
  • Visit our Unsubscribe page.
Copyright © 2012 by WindowsSecrets.com. All rights reserved.

Table of contents

Top-scoring articles in the past 12 months
  • Leaving long cookie trails throughout the Web 5.00
  • Windows-like security for Android devices 5.00
  • Win7′s no-reformat, nondestructive reinstall 4.53
  • The sorry tale of the (un)Secure Sockets Layer 4.42
  • RPV: Win7′s least-known data-protection system 4.33
  • Recovery: the last step in total data security 4.30
  • Time for a .NET update we can’t ignore 4.30
  • Getting the most from Windows Search — Part 1 4.25
  • Revising printing habits saves money and trees 4.25
  • Upgrades end in erratic, partial hangs 4.25
  • Pros and cons of a ‘keyfile’ password 4.21
  • Beating back Duku and a plethora of other threats 4.20
  • Office 2007 gets its final service pack 4.19
  • Putting Registry-/system-cleanup apps to the test 4.19
  • One year and 99 security bulletins later 4.18
  • 1.8TB external drive goes down hard 4.17
  • Don’t pay for software you don’t need — Part 3 4.16
  • Internet Explorer gets another round of patches 4.15
  • Is your free AV tool a ‘resource pig?’ 4.15
  • Vacation’s over; it’s a big round of patches 4.15
  • Remote access leads to remote attacks 4.15
  • Keeping you up to date: say no to .NET — again 4.14
  • Take control of Google’s privacy policy settings 4.14
  • Office File Validation patch leads to problems 4.14
  • The advanced system-recover toolkit 4.13
  • New “419″ scam involves PayPal and Western Union 4.12
  • Readers’ best personal-privacy tips 4.11
  • Getting the most from Windows Search — Part 2 4.11
  • Re-examining Dropbox and its alternatives 4.10
  • Easily edit Windows’ right-click context menus 4.09
Connect with us Follow us on Twitter Connect with us on Facebook View our RSS Feeds
  • Home|
  • Newsletter|
  • About Windows Secrets|
  • Advertise with us|
  • Unsubscribe|
  • Sitemap|
  • Affiliates|
Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, WinFind, Windows Gizmos, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of iNET Interactive. All other marks are the trademarks or service marks of their respective owners.
iNET Interactive Copyright © 2011 iNET Interactive.
All rights reserved.
Terms of Use  |  Privacy Policy
Internet Services
  • Web Hosting Talk
  • HostingCon
  • Hosting Catalog
  • Host Voice
Web Development
  • Hot Scripts
  • DB Forums
Digital Marketing
  • ABestWeb
  • Search Marketing Standard
  • PayPerClickUniverse
  • SEMCompare
Consumer Tech
  • Windows Secrets
  • Overclockers
  • Mac Forums

Learn more about
advertising opportunities across the iNET Interactive Network.

LiquidWeb