Sunday, January 13, 2008

This Weekend in Security News

How many extras did Steven Spielberg use when filming the intense and gripping 24-minute Normandy beach scene in Saving Private Ryan? I'm still not sure but it was amazing and heart-wrenching.

Some clever graphic artists decided to see if they could recapture a bit of the drama on a shoe-string budget, with just three actors and some very clever editing.

Their work is very educational and amazing.

Storming Normandy on a budget » Drawn!

Similarly, keeping systems safe and secure against threats doesn't take a hoard of thousands, with the right tools, knowledge, skills and determination, you too can win the battle against security threats.  (I'm sure having a green-screen might be helpful as well, somehow.)

Few more interesting posts on the computer security front.

On Testing Considerations

Security zone: the trouble with testing anti-malware - Computer Weekly's David Harley considers issues with testing anti-malware products.  The article itself is pretty light-reading but Mr. Harley proposes that two main issues with testing anti-malware products exist:

● For some reason anti-malware testing attracts many people who are not well-versed in testing methodologies in general.

● Even worse, it also attracts people who have a somewhat distorted idea of what this type of software is and how it works. (I will not dispute that the research community has, to some extent, brought that upon itself by cultivating a secretive, ultra-paternalist culture.)

At a technical level, this may be true of, say, a spreadsheet program, too. However, when people review a spreadsheet program or a word processing program, they take a lot for granted: when did you last see a review of a spreadsheet program that included a check of the mathematical or statistical functions?

Mr. Harley concludes that while there are some organizations that are trustworthy (he offers up Virus Bulletin and ICSA Labs as examples) what is needed is convincing other "casual testers" that they should follow improved methodologies for reviewing and testing anti-malware products.

Before I recommend a product, I do research on the Net, from other bloggers, I check forums of trusted anti-malware communities, and then I do test-runs on virtual systems.  If all these check out good, if the product is stable, not slathered in bloatware or other (to me) unneeded functions, performs a variety of scans, updates the DAT signature files frequently, and is effective at removing malware I encounter in the field, I'm usually happy.  Unfortunately, there are still a lot of rogue anti-malware products out there, waiting to mislead the desperate or the unknowing.

See also this link-laden article, also from Computer Weekly: Prevent malware infection with malware detection tools

Super-Duper Suite of Tools

Erwan's Lab - (freeware) - I'm not sure how I stumbled across this IP sniffer utility and utility suite but it is a pretty good collection. Does require WinPcap.  Includes basic networks traffic sniffing features like filter, decode, replay, parse…

The IP tools include (among other things): Bandwidth monitor, adapter statistics (IP & NDIS), a wireless stumbler, list and manage routes, enable & disable host as a router, list and manage open ports and attached processes, view network config (interfaces, adapters, parameters), spoof ARP (and do ARP cache poisoning), TCP, UDP, ICMP, DHCP, change MAC address, DNS (advanced) Query, DNS Server, Local resolver, DHCP Server (with PXE support), DHCP Discover,  Whois Query, Mail client (SMTP & MAPI). TCP tools include: TCP ping, TCP half scan, Time-Daytime client/server, HTTP Server, FTP Server, HTTP Proxy, Telnet Bouncer, FTP Bouncer, LPR Client,  UDP tools (MSSQL Ping, SNMP ping, SSDP ping, Syslog client/server, Time-Daytime client/server, TFTP server), ICMP tools (Ping, GetBestRoute, GetRTTAndHopCount), TCP/UDP bounce port.

On Microsoft networks: Spoof net send, Shutdown remote windows, Display remote windows properties, Netapi services, Terminal Services processes and sessions, Winspool services, remote drivers, remote AT jobs, remote scheduled tasks, Logged on users, Dump remote users, manage DHCP services, MS SQL processes, MS Perf counters, remote processes, remote event logs.

Password tools include: Protected storage (IE, Outlook Express, …) , LSA secrets, Dialup Passwords , XP Credentials ( MSN, network shares, …) , IE history, Reveal asterisks / hidden passwords, RDP passwords, MSAccess passwords, enum WEP keys, MS SQL enterprise manager passwords, Known default passwords.

Other / System tools include: Manage processes, Opened files, Windows Handles, Events for processes/events/files changes, bandwidth tester (based on iperf), manage windows devices, VBS script editor, WMI browser, Create maps with Graphviz, manage ACL's.

Whew!  That's a real bundle of stuff!

Screenshots at the bottom of the page.

More Trojan Spoofing of Legitimate Malware Products

The other day in my Anti-Rootkit Tools Roundup Revisited post, I mentioned that you need to beware of "fake" tools - especially hard when they take on the GUI of a trusted tool. I specifically referenced the Fake RootkitBuster Busted! post from TrendLabs Malware Blog.

Turns out they aren't the only ones...and surely won't be the last.

Prevx and Trend Micro targeted by spammers.  Seems that ant-malware company Prevx also has a rogue version of their product being offered.  This version seems to toss up a "register now" box that requests users to enter their name and email address so (at best) it is a email address harvester. However, there could be worse things lurking under the surface.

What is really alarming about this event, is that the rogue product was actually being offered for download from CNet|Download.com directly!  Even though one component that makes this site so popular is that they have tested all the downloadables and certified them as "spyware free".

This then becomes yet another reminder that just because you have "trusted download sources" you should still always scan them carefully before installing.  Check the reviews as well if offered as it was noted in the reviews here that it was a trojan by several community members.

Prevx Computer Security Investigator (CSI)

While tracking down the previous story, I checked out the real Prevx product, CSI.

Prevx CSI - (free scans) - is a tiny download and requires no installation (but apparently does have an optional "embedded" installer if you choose to use it).

Compatible with XP and Vista, the application quickly scans for active infections like spyware, Trojans, key loggers, viruses, rootkits, adware, screen watchers and many more types of malware. In my trial-runs, the product ran very quickly and found no threats.

It is free for personal and business use, but there is one "gotcha." If you want to use the product to clean your system, if anything is found, then you will have to purchase an activated version of Prevx CSI Removal and Cleanup.

So to be clear, while Prevx is freeware, it functions only as a scanner, not a cleaner.

However, if you are doing malware-response, this still might be a great tool to add to your fighters-kit.  The scans are fast and do identify the exe file causing the issue.  It might be a good "first-pass" tool to quickly see if your system has issues.  If so, you could (and should) follow up with additional freeware anti-malware tools to clean the infection, consider purchase of Prevx's CSI Removal and Cleanup program, or if you are an advanced anti-malware buster, remove it manually yourself with your wicked-l33t haxor-busting skilz.

Malwarebytes Tool Updates

Mawarebytes offers some really great tools, including their new beta product Malwarebytes’ Anti-Malware (for scanning for and removing malware), FileASSASSIN (for killing locked files), and the wonderful RogueRemover FREE (for removing rogue anti-malware products).

Two other fantastic products they have have been recently updated:

RegASSASSIN - (freeware) - Not a commonly needed tool, but it will effectively remove stubborn registry keys by resetting the key's permissions and then deleting it. New version is 1.03.

StartUpLite - (freeware) - disable or remove all known unnecessary startup entries from your computer and thus quicken the startup procedure of your system. New version is 1.07. What makes this program different from other auto-start inspectors/editors (like Sysinternal's AutoRuns) is that it doesn't offer you a list of ALL the startup group items. Instead it offers you a list of recommended auto-start entries you can safely disable without crashing your system.  It is a nice tool for newbies and those who are not sure about what they shouldn't disable, but want to try to improve system performance.  It's a clever tool and often overlooked.

Trend Micro Tools

Yes, Trend Micro took over the perennial anti-malware tool, Trend Micro HijackThis.  They have slowly continued minor updates and improvements to the program.

Now they have a new anti-malware tool worth looking into.

TrendSecure | Trend Micro RUBotted (Beta) - (freeware) - Runs on Windows 2000, XP, 2003, and Vista systems.

[It] is a small program that runs on your computer, watching for bot related activities. RUBotted intelligently monitors your computer's system behavior for activities that are potentially harmful to both your computer and other people's computers. RUBotted monitors for remote command and control (C&C) commands sent from a bot-herder to control your computer. Additionally, RUBotted watches for an array of potentially malicious bot-related activities, including mass mailing - a common activity performed by a bot-infected computer.

RUBotted co-exists with your existing AV software, providing advanced bot specific behavior monitoring. RUBotted does not rely on frequent, network intensive updates to ensure your computer's continued protection.

So you would be able to run this alongside existing security programs to monitor for malicious software activity on a system.

See also a related application ThreatFire AntiVirus (not from Trend Micro).

Of course, this gets into a discussion about just how much anti-malware protection you should have running at one time.  If you feel you need to have, say five to ten of these utilities running all at once, you might want to reconsider your web-surfing behavior or even go with an Apple or Linux operating system solution instead.  Still, I like having a variety of protective tools to offer the friends and family members I provide support to.

But that is a post for another day...

--Claus

New or Improved Software Offerings

Not a lot of new software offerings this week. But there are a few noteworthy ones you might be interesting in looking into.

BluetoothView -(freeware) - New NirSoft utility that allows you to monitor the Bluetooth activity around you.

For each detected Bluetooth device, it displays the following information: Device Name, Bluetooth Address, Major Device Type, Minor Device Type, First Detection Time, Last Detection Time, and more.

BluetoothView can also notify you when a new Bluetooth device is detected, by displaying a balloon in your taskbar or by playing a small beep sound.

This could be a really fun tool if your laptop supports Bluetooth!  See what's going on around you! As Nir Sofer points out, if your neighbors (or your own kids) have Bluetooth enabled devices, you can see when they come and go by "tracking" the devices.  Cool and creepy!

Revo Uninstaller - (freeware) -  Freeware - uninstall, delete, remove unwanted programs and traces easily.

What's new in Revo Uninstaller version 1.42:

  • Added new cleaning options to Windows Cleaner tool
  • Improved user interface of Windows Cleaner tool
  • Improved handling of Microsoft Windows Installer (MSI) based installations
  • Added showing empty leftover folders after scanning
  • Added detection of grouped taskbar buttons in Hunter mode
  • Bug Fixed in Hunter mode - Detecting similar applications on desktop
  • New languages are added!

KeePass 1.10 - (freeware) - This is my favorite password manager, and the latest version packs quite a few new additions, some of which I've highlighted below.

New Features:

  • Added configuration file caching (highly increases performance when running KeePass from slow devices like USB sticks).
  • Added mini mode (must be configured in the INI file manually; in mini mode, a lot of functionality is hidden; see help file - Technical FAQ).
  • Added password generator option to exclude/omit user-specified characters in generated passwords.
  • Added option to disallow repeating characters in generated passwords (both character set-based and pattern-based).
  • Moved security-reducing / dangerous password generator options to a separate 'Advanced' dialog (if you enable a security-reducing option, the 'Advanced' button in the password generator window is shown in red).
  • Internal random number generator is now additionally seeded using random bytes provided by the system's default CSP.
  • Internal random number generator is now additionally seeded using a newly generated 128-bit GUID.
  • A default user name for new entries can now be specified in 'File' -> 'Database Settings'.

Improvements:

  • Changed field order: password follows user name now (note: if you use your previous configuration file, the columns in the main window will be ordered the old way; to change it, drag&drop the column headers manually to adjust the order).
  • Improved startup time.
  • Improved search performance.
  • Improved internal menu handling.
  • Improved print options dialog (replaced "export" by "print", excluded irrelevant export options, ...).
  • Optimized performance of process memory protection algorithm.
  • Minor improvements in the installer.
  • Minor dialog text improvements.

Bugfixes:

  • Password generator does not crash any more when trying to generate a password using an empty pattern + random permuting.
  • The Ctrl-Alt-K global hot key correctly brings the KeePass main window to front when it's hidden behind other windows.
  • Changing the state of the 'Randomly permute characters of password' option now correctly selects the '(Custom)' profile.

Java SE 6 Update 4 Release - (freeware) - This week version 4 of Java SE 6 has been released. So far, neither the internal Java updater or the Web Site are finding or reflecting the new version release just yet.  If you want it early (which is probably a good idea) you will want to manually download and install it.  Most home users will want to just get the Java Runtime Environment (JRE) 6 Update 4 version.  Download it and install.  Then go back and do a manual uninstall of the JRE 6 Update 3 version from your Control Panel's Add/Remove program list to remove the vulnerable version.

AutoRuns v9.02 - (freeware) - This update from Sysinternals fixes a bug where Autoruns would crash when deleting the last item on the Everything page.

TcpView v2.53 - (freeware) - This update from Sysinternals addresses a memory leak.

OpenedFilesView - (freeware) - This NirSoft tool allows you to view opened/locked files in your system (sharing violation issues).  Version 1.12 fixes the following issue: On Vista, OpenedFilesView now automatically requires to run as administrator (When User Account Control is turned on).

Get them before they are gone!

--Claus

This Week in Vista News

I've collected a few interesting bits of news on the Vista front this week.

Comodo Firewall Updated - Fixes Vista Update Problem

In my post Vista KB942763 Update Failure and Solution I tracked own an issue with Comodo's firewall (Defense+) causing some Windows Updates for Vista to fail.  There were a number of workarounds, with the most consistent one being to uninstall Comodo, install the update, then reinstall Comodo.

Luckily, the programmers at Comodo have been hard at work and just released a new version of Comodo Firewall 3.0 Pro that fixes the Vista update issue.

Version 3.0.15.277

  • Fixed the bug causing Windows Updates to fail in Windows Vista.
  • Fixed the bug causing Windows to show "Access Denied" message while deleting a folder.

If you are interested, go download the new and Vista-improved version.

Display the Administrator Login Account

Even if you decide to set up one of your Vista profiles with "administrator" rights, sometimes it still doesn't allow you to do what you want.  You will have to elevate your permissions to "administrator" anyway, or even do some "elevated-permissions" command-line jujitsu to accomplish what used to be pretty simple in XP or Windows 2000.

One alternative is to just log in under the "Administrator" account and not your "administrator" account.

But how do you get it to show up on your login screen?

Open a command prompt in administrator mode by right-clicking and choosing "Run as administrator."  Now type the following command:

net user administrator /active:yes

That should get it showing up next time you get to the login screens.

To disable it, repeat the elevated command-line mode and type net user administrator /active:no

--tip via Lifehacker

If you do choose to display the Administrator account, I would highly advise putting a password on it to keep other users from getting in over your head on the system.

Updated Vista SP1 RC1 Refresh Released

I'm still not brave enough to put any of the current SP1 releases on our Vista laptop yet.  I'm waiting for the final version.

The first round release of this version was only offered to about 15,000 beta testers using a direct (for them) download link.

Now it has been opened up to the public.

You still need to uninstall your current Vista SP1 RC version (if you installed an earlier version) before you put this one on.

More details here: TweakVista.com - Updated Vista RC1 build - Public Release!

It's pretty clever what the Microsoft public download link for the RC1 Refresh does.  The service pack is actually delivered to your Vista machine (if enabled) via Windows Updates.  If you download and run the nicely named "Windows Update Experience for RC Refresh Public Availability.exe" file, it actually creates a series of registry keys that allows Windows Updates to see and deliver the Vista SP1 RC1 Refresh version to your system.

ITsVista broke open that exe file to show the actual registry key setting commands, if you are interested in peeking at them.

Tiny and Beautiful Vista Mini-Apps

Ave's Vista Apps page offers us some wonderfully simple and beautiful applications to add a touch of class to Vista (and XP) systems. All are freeware.

  • Glass Toasts - "replaces the standard plain "balloon" style notifications with an Areo-style window effect."  Very pretty.

  • 3D User Picture - "replaces the user picture in Vista's start menu with a pretty 3D animated one."

  • Thumbnail Sizer - "easily change the size of Vista's Window thumbnails that show when one hovers over the taskbar button for the window."

  • AveDesktopSites - "replacement for the Active Desktop utility that is no longer present in Windows Vista. The application will now show websites on the desktop, but, unlike Active Desktop, they can not be interacted with."

  • Desktop Effects - "an application that adds special effects to your desktop. Forget the old boring and static wallpaper! Show a dynamic photo slideshow on your desktop, or just use it to scribble notes."

  • Extra Desktops - "is an application that allows to use extra desktops, besides the normal desktop. Use a desktop for storing your downloads, use one filled with your regularly played MP3, use another one for the files of that project you are currently working on. With Extra Desktops, there is no need anymore to browse to all these folders you regularly use: simply hit a key, and the files are right there on your desktop!"

  • Vista Folder Background - "In Vista, the ability to have custom backgrounds in explorer folders is gone. This small application makes folder backgrounds possible again."

I'm sure you will be able to find at least one of these tiny-tweaks helpful on your system.

All programs require Visual Studio 2005 SP1 Runtime Files to be installed on the system.

Hard Drive Monitoring in Vista

Yes, I gave you a slew of tools to monitor your hard-drive last week.

However, 4sysops reminds us that Vista has its own tool to help you see just what is going on that hard-drive: How to find out what keeps your hard drive busy under Windows Vista.

  1. Click the Vista Start Orb,
  2. In the Start Search bar, type perfmon  You should see perfmon.exe appear at the top.
  3. Select it to launch.
  4. The Reliability and Performance Monitor window will appear.
  5. Find the "Disk" bar under the graphs and click the drop-arrow on the bar's right-hand side.
  6. The information should display.

This area lists the following information in sortable columns: Image (program name), PID (process ID), File (path to running program), Read (B/min), Write (B/min), IO Priority, and Response.

I still prefer Sysinternal's Process Monitor myself, but this is a great "on-hand" tool when you need one.

Mark Minasi's Vista Tips Extravaganzas

Ever since I dug up Mark Minasi's Windows tips newsletters back when I was figuring out ImageX and WinPE 2.0 , I've been keeping an eye on his site for the next installments.  His tips are very detailed and educational.

Two new newsletters were released this week and are defiantly worth checking out.

Newsletter #59 January 2007 (Meet Windows PE) - Nice refresher on WinPE 2.0. What it is, what it does, how to build it.  I've already covered all this before in my earlier posts, but there is still some good information to review here if you are familiar with it.

Newsletter #60 January Late 2007 Building Vista Install Scripts - This excellent and very well illustrated post covers how to use a basic Autounattend.xml file to script a Vista installation.  Then he gets deep into using the Windows System Image Manager (WSIM) to build advanced Autounattend system setup scripts.  It is a very good overview and hands-on primer on how to use this tool.  While not something that most home users would ever use, if you deploy, or will be deploying multiple Vista systems and you want to cut down the installation and configuration times.

--Claus

Daughter, Dad, and Daily Chores

We are not really a pro-NFL household.

However, for some reason Alvis has now decided she is a die-hard Dallas fan.  So we made plans last weekend to spend Sunday camped out together, dad and daughter, in front of the widescreen TV and watch the playoff game together.  Unfortunately, we both had long lists of chores to complete first.

Dad had to cover the laundry, scrub-down all the bathrooms, vacuum the floors, clean the kitchen, and haul out the trash.

Alvis had to do her homework, do the first-pass cleaning of her bathroom, and get her room organized.

Once done with that, we ran out to the pharmacy together to restock some bathroom items and grab some of Lavie's prescriptions.  Oh yes, Alvis had to pick out a hair-coloring kit.  It's a normal thing for us to be found considering which of several shades of hair-color we should go with.  Alvis thinks her natural hair color is a bit uneven, so Lavie has cleared Alvis to periodically have it colored.

Since we were getting close to the kickoff time, Alvis suggested we make a bunch of finger-snack plates for the game/dinner.

So we swung by the grocery store and picked up some summer sausages, various cheeses, fancy crackers, a few bags of chips, and hot-fries.  We grabbed some root-beer cans.  For some reason, Alvis was in the mood for pistachios as well.  When we got home, I wrapped up some loose ends on laundry swaps (washer to drier).

Then dad colored Alvis's hair.

That is something else.  Alvis's hair extends way past her shoulder-blades, so there is just enough hair-color mix to get it, but barely.  The hardest part coloring long hair is that it tends to get matted so I have to carefully use a wide-toothed comb to keep it neat and even.  I think this is the third time we've done the coloring so I'm getting much better managing it.

Thirty minutes later we had the color rinsed out, conditioned and Alvis was delighted with the results of the new color choice.  She thinks it matches that of her cousin's.  It's a rich brown-blonde color and looks very becoming on her.

We got the food put out and the buffet started right as the game began.

So far the Dallas game has been pretty good.  (Alvis's actual interest it it appears to be about a 7 on a 1-10 scale.)  But we are having fun.  Lavie just shakes her head when she comes in to check on us.

When the game is over, I've promised Lavie I'll color her hair next.  She already has the box out on the counter.

Maybe I'm in the wrong business....

A husband and father's day is never done.

Now if I can talk them into folding and putting up the laundry...what are the odds?

--Claus

Saturday, January 12, 2008

What Did EULA Say?

All too often when installing new software or registering for new websites, I am presented with a EULA (End User License Agreement).

I try (usually) to read through these things to make sure I'm not selling my system's soul to shady practices.

However, some of it can be a real pain in the rump to read through.

There are two great resources I know of to ease the process of understanding just what you are agreeing to.

For comparisons, I am going to use Google's Terms of Service.  However just about any EULA that you can copy/paste should work fine in both of these tools. That includes those found on websites as well as those that appear during (pre/post) software application installations.

Spyware Guide's EULA Analyzer

SpywareGuide.com EULA Analyzer - (web resource) - Click the big "Start EULA Analyzer" button on the page, copy and paste the text from the target EULA and click the "Start Analyzer" button.

You can add a Title, URL and optionally save the EULA and create a bookmark for linkage. (example from my run).

Results may displayed in a detailed analysis, legal layout, or reading battery format.

You get a count of characters, words, sentences, and several readability scores.

There is a summary section which provides the flagged characteristic count and breakdown.

The tool will quickly pick out and flag any particular phrases it finds noteworthy for special attention with bold blocks on the left-hand side of the Details section.  If you click the "change viewing mode" link at the bottom it will return the original content format with flagged sections highlighted and accompanying notations.

Run-time to perform the analysis depends on the loads of the servers as well as the complexity and size of the EULA in question.

In my pass of the Google Terms of Service, it found 11 characteristics; with 8 references to advertising, one reference to on-line promotions, one reference to tracking or monitoring, and one reference to monitoring of usage.

Spyware Guide notes:

Some people who can benefit from this tool include:

  • Parents who want to analyze the privacy impact of software their children might by downloading on P2P networks.
  • IT administrators who must rapidly evaluate whether a program is suitable to reside on their network or carries privacy risks that might violate corporate policies.
  • The tool might also be useful for educators teaching e-commerce classes to students about the implications of online contracts.
  • Government bodies that wish to perform further analysis on a EULA for legislative research
  • The EULA analyzer is a perfect tool for independent spyware researchers who frequently analyze the EULA as a regular part of their practice and volunteer efforts.
  • Attorneys or legal professionals who want to dissect EULAs for legal research.

SpywareGuide's tool isn't "portable" since it runs off their servers.  However, it is a great starting point and should be reachable when you need it.

Javacool Software's EULAlyzer

EULAlyzer personal - (free for personal and educational use) - Unlike the web-based solution of Spyware Guide, this product can be installed locally on a system.  (It seems to be working fine on my USB stick as well where I copied it to from my Program Files folder.)

Once installed, launch the program and you are presented with the main window.  Here you can check for updates to the application, scan a new EULA, view your statistics and any saved EULA's you set to keep.  It also has a link to the EULA Research Center (on-line) where you can submit interesting EULA finds to them to improve the product's detection algorithms.  This is a nice "community-building" touch.

If you click the Analyze option, you can either paste your own copied text into the area, or use the handy capture tool to accomplish the same thing.

Click "Analyze" and let it rip!  It is very fast.

The results get a EULA Interest ID code, a results window which allows for each category item to be expanded to see the details along with a color-coded interest-level bar,  as well as a summary conclusion on the EULA overall.

You can search the EULA text for key words, save, and "submit online" from this page as well.

In my pass of the Google Terms of Service with this tool, it flagged text in the following categories: Advertising (12 references), Promotional Messages (1 references), Third Party (4 references), Web Site Address (7 references), and Without Notice (2 references).

The Interest Level color-coded bar I noted should alert you if the terms are very suspicious or restrictive.  I've seen some 8's before on one or two EULA's, but the Google's tend to be mostly average "5" level scores.

EULAlyzer is a really neat and clever product.  I really like it and find it wonderfully helpful in trying to quickly get a feel for a products EULA.  If I find one that gets very high (bad) marks that might set off some warning bells in my head and I will take a closer look at the product and/or do more on-line research.

Javacool Software notes about their product:

EULAlyzer can analyze license agreements in seconds, and provide a detailed listing of potentially interesting words and phrases. Discover if the software you're about to install displays pop-up ads, transmits personally identifiable information, uses unique identifiers to track you, or much much more.

The Benefits

  • Discover potentially hidden behavior about the software you're going to install
  • Pick up on things you missed when reading license agreements
  • Keep a saved database of the license agreements you view
  • Instant results - super-fast analysis in just a second

Also available is EULAlyzer Pro - ($) - This version included EULA-Watch which runs "real-time" in your system to intercept and decode EULA's automatically when encountered in a software install, automatic updates, and coverage of all new version releases during the 1-year license timeframe.

Final Thoughts

These tools are not meant to replace a full reading of the EULA, nor are they considered "legal" advice.  They do however, quickly bring up content found that might be of significant concern or note.

In today's murky waters of what rights you "think" you have and what rights companies and providers "might" be extending you, it's a good thing to always stay informed and aware.

High marks (in a good way) to both these tools!

--Claus

Move that Window! and Quick Screen-saver Launching

Last month I was fussing about how I when I use an application at work on my secondary monitor, I sometimes forget to close it out on my primary laptop screen.  Then when I am mobile and launch it, it reruns on the missing secondary screen.

If the program uses an .ini file I just edited it and set the X and Y display values back to 0,0 to get the program to open on my laptop display.  Sometimes that's not an option and I am stuck.

Ashley over at CyberNet News posted this very simple tip.

Ashley's tips are simple.

  1. Right-click on the application in the system-tray,
  2. Select "Move"
  3. Take a stab in the dark and try to use the move-cross cursor on the phantom space to drag the application back, or
  4. ...just press the keyboard arrow-keys to move the application window back to your laptop monitor.

It really isn't any easier that this.

But if you really want to use a GUI solution, here is a great alternative.

Windows Seizer

Window Seizer - (freeware) - This is a standalone (portable) single exe file application that brings a wealth of helpful info-at-a-glance items for all the windows open and running on your system, including memory usage , window handle, class name, parent handle, window visibility, process ID, status, filename, path, X coordinate, Y coordinate, width, and height.  These are all great items to know if you are hunting down the source of a malware-generated window.  With that information, you can drill down directly to the source of your troubles.

However, besides just information, you get additional functions you can run on the windows such as selecting a window item and bring it to the foreground, "Close all IE windows" which will force-close all Internet Explorer windows.  Very useful when your system has been attacked by a malware bot that has just opened up hundreds of the things.  You can close one window, selected windows, or all windows. Show hidden and blank captions for windows that aren't visible on the desktop.

Finally, there is my favorite function: Move to 1,1.  This moves the target window back to the top,leftmost screen position.  Very handy when you can't drag a window back to your desktop with the mouse (due to user error, malware programs, or launching on a phantom dual-monitor desktop as is often my case).

I really like the options this utility provides and it is a great single-exe file solution to many malware and window launching issues.

Related program:

WinLister - (freeware) - NirSoft tool to display the list of opened windows on your system and perform some simple and handy functions on the open windows it discovers.  Also finds and displays (0,0) sized windows (if enabled) sometimes used by malware or other legitimate programs.  It's a very neat tool that might enlighten you on just all the windows your Windows system really is running, without your knowledge.

RE: Manual Screen Saver launching

Just the other day, I was looking for a way to manually kick-start my screen saver.  Normally I set it to engage just after 10 minutes of non-activity.

However, sometimes I want to manually start it, like when I am sitting down for lunch, meeting with someone, or have my laptop in a meeting.

Right now I am using the 9031: FLIQLO Flip-Clock Screensaver. It is really simple, but provides a nice and bold time-display on my monitor.

I could have just done the simple thing of making a shortcut to the desktop of one of the system's screensaver .scr files. Double click it and most should run immediately.

A search on Google turned up some various mini-apps that did the same thing.

I wanted a bit more bang for my punch, but also wanted to integrate it in my RocketDock toolbar.

Here is what I did.

  1. Download NirCmd (freeware) from NirSoft and unpacked it into a folder.
  2. Drug the program icon onto my RocketDock toolbar.
  3. Opened the icon settings options for this toolbar item.
  4. Change the default icon to a more suitable one of a monitor.
  5. Typed "screensaver" in the Arguments line.
  6. Saved the changed.

NirCmd is a freeware command-line tool that performs a great-number of handy actions.  Since one of the things it can do is to launch your screensaver this seemed like a great tool.  Also, since RocketDock supports arguments for its items, I could easily tweak the icon so it just ran the screensaver launch immediately.  Handy!

Now when I want to watch/launch my flip-clock screensaver, I just click one icon on my toolbar and it fires right up!

--Claus

Anti-Rootkit Tools Roundup Revisited

It was just a year ago that I tried my hand at collecting useful Windows applications that could help scan a system to identify potential root-kits.

I encourage you to return to it and re-read it. The principles still remain.

  • Rootkits are bad...and can still be found being deployed using holes in unpatched systems.
  • Rootkits work their magic by (basically) hooking into the most basic levels of the system kernel so that normal attempts to find them fail as they are hidden and/or pass false data off to the requests.
  • Identification requires specialized software tools that work around those tricks, or booting "off-disk" with an alternative boot system from the target disk and then examining it "from the outside looking in," statically.

Rootkits are slowly making their way back into the geek-news circles with notice of a new (old) Master Boot Record (MBR) rootkit that has been slowly evolving from concept to in the wild deployments.

This post gives a great timeline of this particular item, from Proof of Concept (eEye) back in 2005 to release in late 2007 by attackers. GMER has a great writeup and comparison of it against the PoC version.

Generally, as the Handler's Diary posts, Windows users who are fully patched with their Microsoft Updates should be safe. If you aren't patched, you need to be.

So it was in this backdrop that I decided to revisit my pile of portable anti-rootkit tools to see which ones needed to be updated, if any new ones had been made, and update the list I keep for reference.

Beware of "fake" tools - especially hard when they take on the GUI of a trusted tool. I encourage you to verify your sources. Fake RootkitBuster Busted! - TrendLabs Malware Blog

Note: All products, unless otherwise noted, are freeware.

My Portable USB Anti-Rootkit Tools

Through trial and error, these are the anti-rootkit tools I have found which seemingly will run successfully off a USB drive. Others may also exist, but these are the ones I rely on the most (in alphabetical order).

  • AVG Anti-Rootkit Free Edition - Simple interface. Pretty speedy.

  • Bitdefender Rootkit Undercover - no longer found on the site. Linked to Major Geeks download pile site.

  • CatchMe Scanner - Userland rootkit detector from the GMER team.

  • F-Secure Blacklight - Restrictive wizard interface, but easy to use for the uninitiated.

  • DarkSpy- Chinese developed tool. Supports process, kernel mode, file, registry scan (disabled in test version) and hidden port detection. Screenshot via Antirootkit.com.

  • GMER - The tool that's got everyone in a fuss! Scans for hidden processes, services, files, registry keys, drivers, and hooks. Also allows some system function monitoring. Highly regarded by the antirootkit professionals. More screenshots (while the site is up).

  • Helios Lite - New product developed to be portable from the original Helios team.

  • HookExplorer - Tiny little application. Displays import address table (IAT) hijacks and "detour style hooks." Lots of information in the tiny display!

  • IceSword - Developed in China but nicely translated into English. Busy interface but updated often. Has some advanced tools like the ability to "reboot and monitor" during the boot process. More information over on the Anti-rootkit blog description page.

  • McAfee Rootkit Detective Beta - "McAfee Rootkit Detective Beta is a program designed and developed by McAfee Avert Labs to proactively detect and clean rootkits that are running on the system." Nice interface.

  • Panda Anti-Rootkit - See product guide - beta software. Looks at hidden drivers, processes, modules, files, registry items, hooks. Not a lot of user options...scan, clean, and view results. Download link/info page via antirootkit.com.

  • Rootkit Detector - Composed of both a file system module and an IAT Analysis Module

  • RootKit Hook Analyzer - Reports on any system hooks and modules and displays findings.

  • Rootkit Revealer -From the Sysinternal's team. Easy to use, but does often turn up documented false-positives. Just identifies suspicious processes...you are on your own to delete them with other methods and applications. Better for system checking and monitoring, rather than protection and removal in-of-itself.

  • Rootkit Unhooker - Link to page on antirootkit.com for download and info. Interestingly, this team has now joined Microsoft. Maybe their talents will get folded into the Sysinternal's Rootkit Revealer product.

  • SEEM - Multi-purpose system reporting tool that has an interesting interface. Includes a rootkit scanner as part of it's features. Website (translated from French) has quite a bit of good information on rootkits and as they apply to their program. Download page (kinda hard to find in French). Get the English version unless you know French.

  • Sophos Anti-Rootkit- "Sophos Anti-Rootkit provides an extra layer of detection, by safely and reliably detecting and removing any rootkit that might already have secreted itself onto your system." Note: Registration required for download from the vendor's site (or just get it from Major Geeks directly). The utility itself is free.

  • Trend Micro RootkitBuster - Runs scans in five system areas and exports a nice log file. You can then opt to remove the detected items.

Anti-Rootkit Blog's Vista-Compatible Anti-Rootkit List

Anti-Rootkit Blog posted a list of seven rootkit scanners they found will work well on Vista systems. They have nice screen shots as well.

    1. F-Secure Blacklight

    2. GMER

    3. Icesword

    4. Rootkit Hook Analyser

    5. Rootkit Revealer

    6. Rootkit Unhooker

    7. Unhackme

Additional Anti-Rootkit Tools that are still Kicking Around

I've cleaned up my old list to reflect products that have been retired or were now dead-links. These remain.

  • Gromozon, Rustock, Haxdor related removal tools - Specialized and targeted rootkit removal tool list via Antirootkit.com

  • Aries Sony Rootkit Remover - Tool to remove the Sony/BMG DRM CD protection software.

  • Archon Scanner - More of a process, injection, hooking scanner. But has other specialties as well. - current version was beta and has expired...developer's promise new one sometime.

  • Avira Rootkit Detection - Beta product disabled after 1-4-07. See Antirootkit.com's page for file.

  • Helios - Behavior-based, not signature based detection. Interesting interface and approach. Worth looking at. Requires .NET framework to be installed. Developers offer videos as well of their tool in action.

  • HiddenFinder - trialware - Shows hidden processes and drivers on a system and then allows for killing of the desired process.

  • Process Master - trialware - API comparison tool.

  • System Virginity Verifier - Tool developed by Joanna Rutkowska to validate system integrity by checking important Windows System components targeted by hidden malware. She also provides links to some related PowerPoint presentations.

  • Unhackme - trialware - limited to 10 runs until license purchased and entered - In standard, "Roaming" and "Professional" editions. University of Minnesota's Safe Computing page documents rootkit removal tutorial with Unhackme.

More Information for the Interested

I've copied this information from my last post, because these sources remain excellent reviews on rootkits and the professionals who study and defend against them.

Finally, these links provide more names and references for additional anti-rootkit tools. I haven't tracked down or tested many of them. Pursue at your own efforts and risks.

See you in the skies...
Claus