Thursday, November 29, 2007

DrProtection old-new misleading software

Famous interface+new engine = DrProtection 2.1
"DrProtection is a misleading application that may give exaggerated reports of threats on the computer. "
Symantec
"DrProtection 2.1 is a latest clone of well known DrAntispy rogue antispyware. It generates false positives to trick users into buying full commercial version of this useless program..."
Fix Computer Problem
---
Removal tool with free scan - Spyware Doctor can easily remove DrProtection


Wednesday, November 28, 2007

Adware.BndDrive infection - how to remove

Adware.BndDrive is a new adware program that will install meileading browser helper object and show "Internet Speed Monitor" popups.
Download Spyware Doctor with free scan to get rid of this malware.

Monday, November 26, 2007

beta.openpacket.org updates

Several updates have been made to the http://beta.openpacket.org:8080 site, please stop by and help us continue to test the site.

Cheers,
JJC

InProtect Beta 0.80.2

In the interest of continuing a good thing (although this post is a bit late), we have released a new bugfix version of InProtect 0.80.x. This version is 0.80.2 and can be found at our sourceforge download location.

We hope to have an official release out on or about the new year and are working hard to meet this deadline. I would like to thank all of the users for their feedback and continued support of this project. It is always refreshing and energizing when there is good positive community usage and feedback!

As always, I invite you to join us in freenode or arcnet in #inprotect to tell us about your experiences, issues, bugs and the like.

Regards,
JJC

FreeBSD jabberd port mysql bug

As a quick post (esp since I have not been posting much lately) I recently ran into another issue with jabberd on freebsd. I say another, if you will remember a previous post concerning sasl - http://global-security.blogspot.com/2007/08/pidgin-on-linux-w-jabberd2-on.html.

This has more to do with cleaning up some of the errors that seem to exist in the mysql schema. Specifically, if you install jabberd2 from the ports tree "/usr/ports/net-im/jabberd" and configure it to use mysql as it's storage engine, you will receive several errors in your stdout our log files (depending on your configuration). These errors are generated when a users status changes, i.e. login, logout, away etc... I have included a quick snapshot of the errors below.

Nov 26 14:48:48 secure2 jabberd/sm[1629]: mysql: sql delete failed: Table 'jabberd2.status' doesn't exist
Nov 26 14:50:26 secure2 jabberd/sm[1629]: mysql: sql delete failed: Unknown column 'collection-owner' in 'where clause'
Nov 26 14:51:10 secure2 jabberd/sm[1629]: mysql: sql select failed: Unknown column 'object-sequence' in 'order clause'
Nov 26 14:51:10 secure2 jabberd/sm[1629]: mysql: sql insert failed: Unknown column 'status' in 'field list'
Nov 26 14:52:17 secure2 jabberd/sm[1629]: mysql: sql insert failed: Unknown column 'show' in 'field list'
Nov 26 14:52:58 secure2 jabberd/sm[1629]: mysql: sql insert failed: Unknown column 'last-login' in 'field list'
Nov 26 14:55:46 secure2 jabberd/sm[1629]: mysql: sql insert failed: Unknown column 'last-logout' in 'field list'
Nov 26 14:59:46 secure2 jabberd/c2s[1631]: [7] [192.168.1.2, port=3746] disconnect jid=user@test.com/Home, packets: 15
Nov 26 14:59:46 secure2 jabberd/sm[1629]: session ended: jid=user@test.com/Home
Nov 26 15:00:05 secure2 jabberd/c2s[1631]: [7] [192.168.1.2, port=3932] connect
Nov 26 15:00:05 secure2 jabberd/c2s[1631]: [7] SASL authentication succeeded: mechanism=DIGEST-MD5; authzid=user@test.com
Nov 26 15:00:05 secure2 jabberd/c2s[1631]: [7] bound: jid=user@test.com/Home
Nov 26 15:00:05 secure2 jabberd/c2s[1631]: [7] requesting session: jid=user@test.com/Home
Nov 26 15:00:05 secure2 jabberd/sm[1629]: session started: jid=user@test.com/Home
To remediate this, simply run the following against your jabberd2 mysql database:

CREATE TABLE `status` (
`collection-owner` varchar(256),
`object-sequence` bigint,
`status` text NOT NULL,
`show` text,
`last-login` int DEFAULT '0',
`last-logout` int DEFAULT '0',
PRIMARY KEY (`collection-owner`));
This will get ya going, I'm not gonna go into what's wrong with the script that is included in the jabberd2 install, I think that it's pretty straight forward.

Also note, I will try to post more regularly now but it's been a hectic few weeks for me (new job, family visiting etc...)

Cheers,
JJC

Sunday, November 25, 2007

New Zlob hijacker - www.safetyonlinepage.com

Screenshot
www.safetyonlinepage.com - new crap from Trojan.Zlob-x.a

"SafetyOnlinePage.com
is the latest browser hijacker that results from Zlob trojan infection. SafetyOnlinePage.com generates fake warnings about Myzor.fk@yf infection detected on your computer forcing user to purchase the paid version of rogue anti-spyware programs (VirusHeal, AntiVirGear, VirusProtect and others). SafetyOnlinePage.com may download and install additional spyware to track keystrokes, steal passwords and banking accounts. SafetyOnlinePage.com show deceptive pop-up ads that may appear as regular Windows tray baloon notifications"

www.safetyonlinepage.com technical details
www.safetyonlinepage.com removal tool (Spyware Doctor)

Saturday, November 24, 2007

DeusCleaner - aggresive pop ups. New misleading software

This application scans the system for privacy violations such as Internet cache files. The application frequently displays pop-up windows such as the above pay-for prompt. This prompt is also displayed after restarting the computer. The user must purchase the full version of the application to repair any violations it finds.
Technical details from Symantec
DeusCleaner Remover (Spyware Doctor)