January 2005 - Posts
W32/Sober.k@MM
Virus Name: ------------------- W32/Sober.k@MM Alias: ------------------- W32/Sober-J WORM_SOBER.J Email-Worm.Win32.Sober.j W32.Sober.J@mm E-mail Subject: ------------------- Ey du DOOF Nase, warum beantw... I've got YOUR email on my account!! E-mail Body: ------------------- (German) Warum beantwortest Du meine E-Mails nicht? Kommen meine Mails nicht mehr bei dir an oder so??? Habe mir jetzt extra...
Weekly Top 5 Virus Incidents - Computer Associates
============================================= Weekly Top 5 Virus Incidents ============================================= The table below lists the top 5 virus and malware files submitted to Computer Associates during the week from January 24 to 30, 2005. 1. Win32.Netsky.P http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=38650 2. Win32.Lovgate.AB http://www3.ca.com/securityadvisor/virusinfo...
MMS 2005 - Presentation on the Code Repository
LS35 myITforum Code Repository Speaker(s): Ron Crumbaker , Dan Thomson Session Level(s): 400 We are the myITforum version of Microsoft's Scripting Guys! I'm Ron Crumbaker; and this is my partner Dan Thomson! We're going to show you The Code Repository, Various Code Packs for the Code Repository and Various Resources as examples of what we do, and how these will help you in your day to day job. Oh,...
AutoPatcher XP January 2005, AutoPatcher for Windows XP SP2
www.autopatcher.com General Information This release is based on the all-new AutoPatcher 5.0. Although it was made with Windows XP SP2 (English) in mind, it will load on any (English) Windows version, showing only the items which match the running environment. For those wondering what the new release includes, here's the list: Windows XP SP2 - Critical Updates KB834707: Cumulative Security Update for...
Misprinted 800 number in some versions of Intuit's TurboTax software sends customers to phone sex operation.
Misprinted 800 number in some versions of Intuit's TurboTax software sends customers to phone sex operation. http://news.com.com/Taxpayers get unexpected return--sex chat/2100-1012_3-5557315.html?part=rss&tag=5557315&subj=news.1012.5
Senator Hillary Clinton, former first lady, collapses while giving a speech in Buffalo, New York state, US media report.
Senator Hillary Clinton, former first lady, collapses while giving a speech in Buffalo, New York state, US media report. For more details: http://www.bbc.co.uk/news
How to optimize Office Access and Jet database engine network performance with Windows 2000-based and Windows XP-based clients
SUMMARY When you run a Microsoft Jet database engine-based program, such as Microsoft Office Access, on your Microsoft Windows 2000-based or Microsoft Windows XP-based computer, the program may appear slower and less responsive than you expect. This article contains information about how you can optimize network performance for Windows 2000-based and Windows XP-based computers. Doing this can make...
W32/Sober.k@MM
W32/Sober.k@MM contains its own SMTP engine source/target email addresses are harvested from the victim machine outgoing messages maybe in English or German Mail Propagation spoofs the "From" header of constructed messages The worm is packed with UPX. Mail Propagation The worm extracts target email addresses from the victim machine, and writes them to the file DATAMX.DAM in the %SysDir% . For example...
[SA14061] Windows Registry Key Locking Denial of Service
http://secunia.com/advisories/14061/ Secunia Advisory: SA14061 Release Date: 2005-01-31 Critical: Not critical Impact: DoS Where: Local system Solution Status: Unpatched OS: Microsoft Windows 2000 Advanced Server Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Professional Microsoft Windows 2000 Server Microsoft Windows NT 4.0 Server Microsoft Windows NT 4.0 Server, Terminal Server...
Code Repository call for Code Pack Scripts
We (Dan Thomson and I) are wanting to gather up some more code so we can release another Code Pack for the Code Repository. http://www.myitforum.com/blog/rcrumbaker/archive/2004/12/01/178.aspx - Code Repository Links We are wanting to collect as many scripts as possible so we can get them included in our next Code Packs. If you are willing to share any of your bat, cmd, hta, html, ipf, js, jse, kix...
Blog Spam
I've noticed that Spammers for Blogs (at least the two blogs I maintain) upload their SPAM on Sunday Night and/or Saturday Nights. With the way RSS Feeds work, it allows sites such as the Online Poker Sites to get their sites to the top of the Search Engines Lists by SPAMMING links on various Blogs as comments. One good thing about Blogs, as an Admin...I can go in and delete any comment I want. So...
Running CHKDSK on a Clustered Server
http://www.myitforum.com/blog/rcrumbaker/articles/2768.aspx
Sober Up - F-secure is reporting
Sober up A new Sober variant is going around, sending variable emails with English and German content. This one is also known as "Reblin" or "Email-Worm.Win32.VB.af". Source: http://www.f-secure.com/weblog/#00000455
Microsoft SMS 2003 Inventory Tool for Dell Update
http://www.microsoft.com/downloads/details.aspx?FamilyID=92a9bb94-1806-487b-a697-92492bf8cc8e&DisplayLang=en Microsoft SMS 2003 Inventory Tool for Dell Update SMS 2003 Inventory Tool for Dell Updates is an add-on to SMS 2003 SP1 that enables customers to use the SMS 2003 Software Update Management feature update their Dell servers. Customers will be able to deploy BIOS, firmware, and driver updates...
New KB - SMS 2003 891999
Systems Management Server 2003 891999 The Systems Management Server 2003 Toolkit 2 documentation contains incorrect information about the Site Boundary command-line tool The original article on Microsoft.com can be found here. Microsoft Legal Links Terms of use Security & Privacy Accessibility
New KB - SMS 2.0 891778
Systems Management Server 2.0 891778 Additional network traffic may occur when you run the Security Update Inventory Tool or the Microsoft Office Inventory Tool for Updates in a Systems Management Server 2.0 environment
Mark USB as Read Only
http://www.myitforum.com/blog/rcrumbaker/articles/2690.aspx
Need to recover from a corrupted quorum log or disk on a Windows 2000 Cluster?
http://www.myitforum.com/blog/rcrumbaker/articles/2689.aspx
New KBs - SMS 2003 and SQL 2000
SQL Server 2000 890637 FIX: A 17883 error is written to the SQL Server 2000 error log and the LogWriter component does not yield correctly 867677 You receive an ODBC error when you use BCP in SQL Server 2000 Systems Management Server 2003 886687 "Failed source list update for product" error message is logged in the Srcupdatemgr.log file on a Systems Management Server 2003 client computer
MyDoom - One year and counting
Great read over at zdnet about MyDoom - http://news.zdnet.com/2100-1009_22-5553419.html?tag=nl.e589 100 Million emails...impressive!!
Windows Update v6 Beta Coming Soon
Got this from neowin.net Windows Update v6 Beta Coming Soon Microsoft Beta co-ordinator, Roger Holland, has just informed current testers of Windows Update v5 that version 6 of the update service is due to hit beta soon. The Windows Update v5 beta ended late last year and Windows Update v5 is the current release that millions of users across the world are using. In an email to testers Holland thanks...
Virus Wars - Return of the Bagle
The mass-mailing virus is starting to spread worldwide, antivirus firms have warned. http://news.com.com/Bagle virus makes a return/2100-7349_3-5553360.html?part=rss&tag=5553360&subj=news.7349.5
PSP - Taking orders!!
Online-retailer EBGames becomes first major U.S. retailer to start taking advance orders for Sony's new handheld game machine. http://news.com.com/Pay now, play later with PSP/2100-1043_3-5553223.html?part=rss&tag=5553223&subj=news.1043.5
Google Video Search
http://video.google.com/ Just checked it out...not too bad for the few minutes I searched it.
Microsoft Windows Indexing Service query validation vulnerability
Microsoft Windows Indexing Service query validation vulnerability Microsoft Windows contains a vulnerability that may allow remote attackers to execute arbitrary code. http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=32230
Microsoft Windows Cursor and Icon format handling vulnerability
Microsoft Windows Cursor and Icon format handling vulnerability Microsoft Windows contains a vulnerability that may allow remote attackers to execute arbitrary code. http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=32219
Microsoft Windows Kernel cursor, animated cursor, and icon format file processing vulnerabilities
Microsoft Windows Kernel cursor, animated cursor, and icon format file processing vulnerabilities Microsoft Windows Kernel contains multiple vulnerabilities that can allow remote attackers to cause a denial of service condition. http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=32140
W32/Bagle.bj@MM
W32/Bagle.bj@MM This is a mass-mailing worm with the following characteristics: contains its own SMTP engine to construct outgoing messages harvests email addresses from the victim machine the From: address of messages is spoofed contains a remote access component (notification is sent to hacker) copies itself to folders that have the phrase shar in the name (such as common peer-to-peer applications;...
Bagle.AY upgraded to level 2
f-secure is reporing Bagle.AY upgraded to level 2 Due to the increased number of reports we just upgraded Bagle.AY to Radar Level 2 Source: http://www.f-secure.com/weblog/#00000452
Yet another new Bagle variant
f-secure.com is reporting Yet another new Bagle variant - Bagle.AY has been found from several different countries early morning on January 27th, 2005 EET. This variant is similar to the last evening Bagle.AX . On 27/01/05 At 08:11 AM Source: http://www.f-secure.com/weblog/#00000451
More Posts
Next page »