Unsolved

This post is more than 5 years old

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

15409

August 13th, 2013 04:00

8/13/13 - Microsoft Updates, AdBlock PLUS, HostsMan, SAS

Today is "Microsoft Tuesday" --- the SECOND Tuesday of the month --- on which Microsoft is expected to release its monthly cycle of Windows critical/security updates.   Based on previous history, they should become available at 1 P.M. (USA - Eastern Daylight Saving Time).

Please use Windows (or Automatic) Updates to determine which updates are applicable to your particular system

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

August 13th, 2013 04:00

Windows Malicious Software Removal Tool (MSRT, or MRT)  for August, version 5.3

http://www.microsoft.com/en-us/download/malicious-software-removal-tool-details.aspx

Reminder:  As noted a few months ago, this is a new link, which automatically detects the appropriate version (32-bit or x64) for your computer's operating system.

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

August 13th, 2013 11:00

The following 3 updates are rated CRITICAL:

MS13-059 Cumulative Security Update for Internet Explorer (2862772

MS13-060 Vulnerability in Unicode Scripts Processor Could Allow Remote Code Execution (2850869)

MS13-061 Vulnerabilities in Microsoft Exchange Server Could Allow Remote Code Execution (2876063)

 

==================

The following 5 updates are rated IMPORTANT:

MS13-062 Vulnerability in Remote Procedure Call Could Allow Elevation of Privilege (2849470)

MS13-063 Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2859537)

MS13-064 Vulnerability in Windows NAT Driver Could Allow Denial of Service (2849568)

MS13-065 Vulnerability in ICMPv6 could allow Denial of Service (2868623)

MS13-066 Vulnerability in Active Directory Federation Services Could Allow Information Disclosure (2873872) 

==================================

 

P.S. (for Ron) Yep, some dotNETs included

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

August 13th, 2013 14:00

AdBlock PLUS 1.0 for IE

https://adblockplus.org/releases/adblock-plus-10-for-internet-explorer-released

 

Remarks:  

1) AdBlock PLUS is a very popular add-on that has long been around for other browsers (e.g., Firefox), but this is the first time it's [at least partially] compatible with IE.

2) Users of the current build of Avast8 have Avast's AdBlocker (powered by AdBlock PLUS) available to them, without having to download a separate program.

5 Journeyman

 • 

5.8K Posts

 • 

17.3K Points

August 13th, 2013 15:00

HostsMan 4.1.96

HostsMan is a freeware application that lets you manage your Hosts file with ease.

Changelog:

•added: update source manager allows custom hosts file name inside compressed files;
•added: multiple selection in Exclusion List and Update Source Manager;
•changed: Editor now allows file loading to be interrupted;
•changed: improved memory usage;
•changed: removed dependency on gdiplus.dll;
•changed: updated Editor's UI;
•changed: other minor UI tweaks;
•changed: replaced XML parser;
•fixed: file loading locks Editor's window until complete;
•fixed: preview in Backup Manager becomes unreliable when preview generation is interrupted;
•fixed: certain errors were not fixed during hosts file update;
•fixed: fails to load legacy exclusion list files;
•fixed: minor bugs.

More info and download:
http://www.abelhadigital.com/hostsman

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

August 13th, 2013 16:00

SUPERAntiSpyware (SAS) 5.6. build 1030 has been released.   The full program can be downloaded from http://www.superantispyware.com/download.html (or popular mirror sites including MajorGeeks and FileHippo).

No changelog is available yet.

I'm waiting for the program's internal updater to find, download, and install the update.

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

August 15th, 2013 03:00

SUPERAntiSpyware (SAS) 5.6. build 103is now being pushed via the internal updater. 

Technology Changes

  • Internet Explorer 10 cookie support
  • Streamlined user interface options
  • Enhanced definition updater
  • Internet connectivity optimizations
  • Miscellaneous bug fixes

Remark:   Since using IE 10, I noticed that SAS wasn't finding "lots" of cookies, as it had been doing with IE 8.   Today's program update apparently addressed this "issue", with a new/aggressive IE 10 cookie scanning mechanism:   Instead of finding 5 cookies, as it had regularly been doing for several months, it now found 48 !

As a rule, cookies are harmless text files.   Harmless, in that they pose no virus threat.  However, they do contain information, which can potentially be abused by spyware.   Nonetheless, I don't allow myself to become obsessed with them.

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

August 15th, 2013 06:00

Microsoft pulls critical Patch Tuesday fix for Exchange 2013

For users of Exchange Server 2013, Microsoft has pulled MS13-061 Vulnerabilities in Microsoft Exchange Server Could Allow Remote Code Execution (2876063):

Microsoft is aware of an issue with the 2874216 updates affecting Exchange Server 2013 Cumulative Update 1 and Microsoft Exchange Server 2013 Cumulative Update 2 that could cause Exchange Server to stop indexing mail on servers. Microsoft has removed the updates from Windows Update and the Download Center and is investigating the issue. Microsoft will release new packages once the issue has been resolved.

=============================

Separately, Microsoft is acknowledging that there may be a "minor" issue with MS13-063: Vulnerabilities in Windows kernel could allow elevation of privilege:

"Some users may experience issues with certain games after they install security update 2859537. In some cases, users may not successfully start and sign in to the games.  Microsoft is researching this problem and will post more information in this article when the information becomes available".

 

============================

 

See http://nakedsecurity.sophos.com/2013/08/15/microsoft-pulls-critical-patch-tuesday-fix-for-exchange-2013/

and  https://technet.microsoft.com/en-us/security/bulletin/ms13-061

https://support.microsoft.com/kb/2859537

5 Journeyman

 • 

5.8K Posts

 • 

17.3K Points

August 16th, 2013 12:00

Re: SAS 5.6. build 1032 and cookies in Win7/IE10:

I certainly agree cookies are not worth obsessing over, which is why I rarely run an on-demand SAS scan, which has detected only cookies on my systems over many years. Your post intrigued me, however. My concern was that I now might unintentionally delete login cookies, which I keep for convenience, by running this more aggressive SAS.

However, FWIW, I ran this latest build of  SAS in both "Critical Point Scan" and "Quick Scan" modes, and neither scan detected any of the 27 cookies (mostly login cookies from trusted websites, presumably) I have moved to "Cookies to Keep" in CCleaner>Options>Cookies. This on a Win7x64/sp1 system using IE 10.

For comparison, I have chosen to let CCleaner "Keep" 80 cookies from trusted websites over many years on my XP/sp3/IE8 system, which is actually the desktop that I use to do most of my browsing. I don't know how many of these cookies are for login, or how many enable other website functions. No doubt several have expired over the years. But again, this latest build of SAS detected no cookies with a "Critical Point" scan, and only one Adware cookie with a "Quick Scan" (from, of all places, "Nakedsecurity/Sophos.com"). I let SAS delete this cookie, since I don't log in to Sophos.

In short, SAS does not seem to detect login cookies in Win 7/IE10, when CCleaner is used as a cookie manager to protect them. I think CCleaner is the better tool to detect and clean unwanted cookies, for those who worry about these things.

My best advice is to avoid running routine SAS on-demand scans. If you really feel the need for re-assurance, run its "Critical Point" scanner only. (It is also the quickest scan).

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

August 16th, 2013 13:00

Joe wrote: "In short, SAS does not seem to detect login cookies in Win 7/IE10, when CCleaner is used as a cookie manager to protect them".

I'm surprised that SAS is "interacting"/"coordinating" with CCleaner in any way!   I don't see why that should be the case... unless you're aware of some documentation to that effect. 

5 Journeyman

 • 

5.8K Posts

 • 

17.3K Points

August 16th, 2013 14:00

Joe wrote: "In short, SAS does not seem to detect login cookies in Win 7/IE10, when CCleaner is used as a cookie manager to protect them".

I'm surprised that SAS is "interacting"/"coordinating" with CCleaner in any way!   I don't see why that should be the case... unless you're aware of some documentation to that effect. 

I worded that a bit poorly. I didn't mean to imply any interaction between SAS and CCleaner. Just reporting my experience that the latest SAS seemed no more agressive on my systems at detecting/removing cookies. In fact, the one adware cookie SAS found and deleted was in CCleaners "Keep" list, so clearly CCleaner does not protect cookies against SAS detection/removal.

CCleaner seems to work well at removing unnecessary cookies, and has never deleted any cookie I have instructed it to keep. The protection I referred to was CCleaner preventing removal of wanted cookies by its own scans.

I should add that I have configured IE8 and IE10 to block all first and third party cookies except for the sites I whitelist, which probably accounts in large part for my findings.

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

August 16th, 2013 15:00

Joe wrote:  "I should add that I have configured IE8 and IE10 to block all first and third party cookies except for the sites I whitelist, which probably accounts in large part for my findings".

I'd say that's definitely the reason why you're not getting a plethora of cookies.   I have my IE cookie privacy set to MEDIUM HIGH, which allows most first-party cookies, while blocking many/most third party cookies.   It's also blocking those cookies generated from SpywareBlaster's database.

No Events found!

Top