<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>rotas»sator &#187; Spyware and Adware</title>
	<atom:link href="http://rotassator.com/category/safe-computing/spyware-and-adware/feed/" rel="self" type="application/rss+xml" />
	<link>http://rotassator.com</link>
	<description>Random musings on safe computing, God, music, technology and anything else that comes to mind</description>
	<lastBuildDate>Thu, 15 Jul 2010 15:52:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>The Sony rootkit debacle</title>
		<link>http://rotassator.com/2005/11/the-sony-rootkit-debacle/</link>
		<comments>http://rotassator.com/2005/11/the-sony-rootkit-debacle/#comments</comments>
		<pubDate>Mon, 21 Nov 2005 23:18:02 +0000</pubDate>
		<dc:creator>Steve</dc:creator>
				<category><![CDATA[Safe computing]]></category>
		<category><![CDATA[Spyware and Adware]]></category>

		<guid isPermaLink="false">http://rotassator.com/?p=67</guid>
		<description><![CDATA[On and off for a couple of weeks, Iâ€™ve been trying to work out how to put the whole Sony rootkit mess in terms that donâ€™t make the average person run screaming for the hills. <a href="http://rotassator.com/2005/11/the-sony-rootkit-debacle/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>On and off for a couple of weeks, I&#8217;ve been trying to work out how to put the whole Sony rootkit mess in terms that don&#8217;t make the average person run <strong>screaming for the hills</strong>.</p>

<p>I think Robert Vamosi describes the whole debacle pretty well in <a href="http://reviews.cnet.com/4520-3513_7-6388181-1.html?tag=nl.e501" title="Article at cNet by Robert Vamosi">Security Watch: To be &#8220;0wned&#8221; by Sony</a>, so I&#8217;ll let him do the work for me. <img src='http://rotassator.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>

<p><span id="more-67"></span></p>

<blockquote cite="http://reviews.cnet.com/4520-3513_7-6388181-1.html?tag=nl.e501">
It was a grand experiment that failed miserably: As a means of copy-protecting its music, Sony employed a piece of software from First4Internet. But the technology, as used by Sony, did two bad things: First, it hid itself on computers by using root-kit technology; and second, it opened a remote access connection that called out to Sony (or one of its agencies). This exposed users&#8217; computers to worms that took advantage of the stealth technology.

Sony has agreed not to put root-kit technology on future music CDs as a means of protecting its copyrights. But this story is far from over. There are at least two lawsuits pending. There are also viruses poised to take advantage of already-infected PCs worldwide, the number of which may be much higher than anyone previously thought. Worse, Sony&#8217;s fix for the problem may not be any more secure than the original root kit.

<cite><a href="http://reviews.cnet.com/4520-3513_7-6388181-1.html?tag=nl.e501" title="Article at cNet by Robert Vamosi">Security Watch: To be &#8220;0wned&#8221; by Sony</a> &#8212; Robert Vamosi</cite>
</blockquote>

<p>I&#8217;m not sure about his assertion that this was ever a &#8220;grand experiment&#8221; (!), but he sums up the problems pretty well.</p>

<p>Many antispyware companies have already released tools to remove Sony&#8217;s intrusive and buggy software, but <strong>not all of them work very well</strong>. Some &#8220;fixes&#8221; could possibly kill your installation of Windows, so you need to be careful about removing the offending software.</p>

<p>The mess is serious enough that Microsoft has released updates for its <a href="http://www.microsoft.com/athome/security/spyware/software/default.mspx" title="Windows AntiSpyware Beta">AntiSpyware software</a> (soon to be known as &#8220;Windows Defender&#8221;&#8230; who chose <em>that</em>?) that remove the offensive rootkit component of Sony&#8217;s software and will do the same with the December release of their <a href="http://www.microsoft.com/security/malwareremove/default.mspx" title="Microsoft updates this tool every month">Malicious Software Removal Tool</a> that is part of the regular Windows Update schedule.</p>

<h4>Removing the Sony rootkit</h4>

<p>If you recently played a newish Sony CD in your PC and think you might have it, <a href="http://www.microsoft.com/athome/security/spyware/software/default.mspx" title="Windows AntiSpyware Beta">download Microsoft&#8217;s AntiSpyware Beta</a> (it&#8217;s good &#8211; why don&#8217;t you already have it? <img src='http://rotassator.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  ), install it and get the latest updates. A full scan should detect the Sony software if it&#8217;s on your system.</p>

<p>Blessings,
<cite>Steve</cite></p>

<h5>Updates</h5>

<ul>
    <li><a href="http://www.smh.com.au/news/breaking/texas-eff-sue-sony-over-spyware/2005/11/22/1132421627766.html">Sydney Morning Herald &#8212; Texas, EFF sue Sony over &#8216;spyware&#8217;</a></li>
    <li><a href="http://www.sysinternals.com/blog/2005/11/sony-no-more-rootkit-for-now.html" title="Sysinternals: Sony: No More Rootkit - For Now">Manual rootkit removal instructions</a> &#8212; Most stable uninstall method outlined at Sysinternals</li>
    <li><a href="http://www.techweb.com/wire/174400646" article="TechWeb Article: Scotch Tape Stymies Sony Copy Protection">Cripple Sony&#8217;s copy protection using only Scotch tape</a></ul>

<p class="listening">[Listening to <a href="http://www.amazon.com/exec/obidos/redirect?tag=rotassator-20&#038;path=tg/detail/-/B000002KM3" title="A brilliant and frenetic album of modern big-bandish jazz fusion"> Jaco Pastorius, Word of Mouth</a> &#8212;  Crisis ]</p>
]]></content:encoded>
			<wfw:commentRss>http://rotassator.com/2005/11/the-sony-rootkit-debacle/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Killing the keylogger</title>
		<link>http://rotassator.com/2005/08/killing-the-keylogger/</link>
		<comments>http://rotassator.com/2005/08/killing-the-keylogger/#comments</comments>
		<pubDate>Mon, 15 Aug 2005 02:04:52 +0000</pubDate>
		<dc:creator>Steve</dc:creator>
				<category><![CDATA[Safe computing]]></category>
		<category><![CDATA[Spyware and Adware]]></category>

		<guid isPermaLink="false">http://rotassator.com/?p=62</guid>
		<description><![CDATA[Hopefully this will be the final update for this nasty parasite - Sunbelt have released a removal tool. <a href="http://rotassator.com/2005/08/killing-the-keylogger/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Hopefully this will be the final update about the <a href="http://rotassator.com/2005/08/identity-theft-on-a-massive-scale/" title="Identity theft on a massive scale">nasty</a> <a href="http://rotassator.com/2005/08/more-info-about-the-recent-identity-theft-keylogger/" title="More info about the recent identity theft keylogger">parasite</a> that is the <strong>SSA-Keylogger</strong>.</p>

<p><span id="more-62"></span></p>

<p>Sunbelt have announced the release of a removal tool that is available for free public download.</p>

<ul>
    <li><a href="http://research.sunbelt-software.com/ssaclean.cfm" title="SSA-Keylogger Clean">Sunbelt Software: SSA-Keylogger Cleaner</a></li>
</ul>

<p>If you&#8217;re concerned that you might have contracted this vicious bout of thievery, <a href="http://research.sunbelt-software.com/ssaclean.cfm" title="SSA-Keylogger Clean">download the cleaner software</a> and run it on your PC.</p>

<p>Further update info can be <a href="http://netrn.net/spywareblog/archives/2005/08/12/update-on-id-theft-keylogger/" title="Spyware Warrior: Update On ID Theft Keylogger">found at Spyware Warrior</a>.</p>

<p>Blessings,
<cite>Steve</cite></p>

<p class="listening">[Listening to <a href="http://www.amazon.com/exec/obidos/redirect?tag=rotassator-20&#038;path=tg/detail/-/B000003446" title="An amazing collection of music from a true jazz legend">Charles Mingus, Passions of a Man</a> &#8212; Wednesday Night Prayer Meeting]</p>
]]></content:encoded>
			<wfw:commentRss>http://rotassator.com/2005/08/killing-the-keylogger/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More info about the recent identity theft keylogger</title>
		<link>http://rotassator.com/2005/08/more-info-about-the-recent-identity-theft-keylogger/</link>
		<comments>http://rotassator.com/2005/08/more-info-about-the-recent-identity-theft-keylogger/#comments</comments>
		<pubDate>Thu, 11 Aug 2005 01:31:57 +0000</pubDate>
		<dc:creator>Steve</dc:creator>
				<category><![CDATA[Safe computing]]></category>
		<category><![CDATA[Spyware and Adware]]></category>

		<guid isPermaLink="false">http://rotassator.com/?p=61</guid>
		<description><![CDATA[SunbeltBlog and Spyware Warrior have posted more information regarding last weekâ€™s discovery of a massive identity theft ring. <a href="http://rotassator.com/2005/08/more-info-about-the-recent-identity-theft-keylogger/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://sunbeltblog.blogspot.com/" title="Sunbelt Software">SunbeltBlog</a> and <a href="http://netrn.net/spywareblog" title="Spyware Warrior: Waging the war against spyware">Spyware Warrior</a> have posted more information regarding <a href="/2005/08/identity-theft-on-a-massive-scale/" title="Identity theft on a massive scale">last week&#8217;s discovery of a massive identity theft ring</a>.</p>

<p><span id="more-61"></span></p>

<p>Sunbelt has also released an update for their excellent <a href="http://www.ihatespyware.com/" title="Sunbelt CounterSpy">CounterSpy software</a> and has announced that they will also release a standalone utility to be released later today.</p>

<p>Further reading material:</p>

<ul>
<li><a href="http://sunbeltblog.blogspot.com/2005/08/keylogger-from-hell.html" title="Article at SunbeltBlog">The keylogger from hell</a> (<cite><a href="http://sunbeltblog.blogspot.com/" title="Sunbelt Software">SunbeltBlog</a></cite>)</li>
<li><a href="http://sunbeltblog.blogspot.com/2005/08/fix-for-srvssa-keylogger.html" title="Article at SunbeltBlog">Fix for the Srv.SSA-KeyLogger</a> (<cite>SunbeltBlog</cite>)</li>
<li><a href="http://netrn.net/spywareblog/archives/2005/08/10/announcement-regarding-keylogger-used-in-id-theft/" title="Article at Spyware Warrior">Announcement Regarding Keylogger Used in ID Theft</a> (<cite><a href="http://netrn.net/spywareblog" title="Spyware Warrior: Waging the war against spyware">Spyware Warrior</a></cite>)</li>
<li><a href="http://netrn.net/spywareblog/archives/2005/08/09/what-to-do-in-case-of-id-theft/" title="Article at Spyware Warrior">What to do in case of ID Theft</a> (<cite>Spyware Warrior</cite>)</li>
</ul>

<p>Make sure to check out Spyware Warrior&#8217;s <a href="http://netrn.net/spywareblog/archives/2005/08/09/what-to-do-in-case-of-id-theft/" title="Article at Spyware Warrior">What to do in case of ID Theft</a> if you think you might have already been stricken with a keylogging spy.</p>

<p>Blessings,
<cite>Steve</cite></p>

<p class="listening">[Listening to <a href="http://www.amazon.com/exec/obidos/redirect?tag=rotassator-20&#038;path=tg/detail/-/B000AAXIEA" title="An intimate album of songs to the Almighty">Kathryn Scott, Satisfy</a> &#8212; At The Foot Of The Cross (Ashes to Beauty)]</p>
]]></content:encoded>
			<wfw:commentRss>http://rotassator.com/2005/08/more-info-about-the-recent-identity-theft-keylogger/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Identity theft on a massive scale</title>
		<link>http://rotassator.com/2005/08/identity-theft-on-a-massive-scale/</link>
		<comments>http://rotassator.com/2005/08/identity-theft-on-a-massive-scale/#comments</comments>
		<pubDate>Tue, 09 Aug 2005 05:10:28 +0000</pubDate>
		<dc:creator>Steve</dc:creator>
				<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[Safe computing]]></category>
		<category><![CDATA[Spyware and Adware]]></category>

		<guid isPermaLink="false">http://rotassator.com/?p=60</guid>
		<description><![CDATA[If you weren't too worried about online privacy before, it's time you were concerned. <a href="http://rotassator.com/2005/08/identity-theft-on-a-massive-scale/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>If you weren&#8217;t too worried about online privacy before, it&#8217;s time you were concerned.</p>

<p>Last week, <a href="http://sunbeltblog.blogspot.com/2005/08/massive-identity-theft-ring.html" title="Sunbelt Software: Massive Identity Theft Ring">Sunbelt Software</a> uncovered an <strong>identity theft operation</strong> so large, it has <strong>made security professionals feel sick to the stomach</strong>.</p>

<p><span id="more-60"></span></p>

<p>Some articles by those more learned than myself:</p>

<ul>
<li><a href="http://sunbeltblog.blogspot.com/2005/08/massive-identity-theft-ring.html" title="Article at SunbeltBlog">Massive identity theft ring</a> (<cite><a href="http://sunbeltblog.blogspot.com/" title="A blog about activities, products and ideas at Sunbelt Software">Sunbelt Software</a></cite>)</li>
<li> <a href="http://sunbeltblog.blogspot.com/2005/08/identity-theft-update.html" title="Article at SunbeltBlog">Identity Theft Update</a> (<cite>Sunbelt Software</cite>)</li>
<li><a href="http://netrn.net/spywareblog/archives/2005/08/05/massive-id-theft-ring-discovered/" title="Article at Spyware Warrior">Massive ID Theft Ring Discovered</a> (<cite><a href="http://netrn.net/spywareblog" title="Spyware Warrior: Waging the war against spyware">Spyware Warrior</a></cite>)</li>
<li><a href="http://sunbeltblog.blogspot.com/2005/08/more-on-identity-theft-ring.html" title="Article at SunbeltBlog">More on the identity theft ring</a> (<cite>Sunbelt Software</cite>)</li>
<li><a href="http://netrn.net/spywareblog/archives/2005/08/07/update-on-id-theft-ring/" title="Article at Spyware Warrior">Update on ID Theft Ring</a> (<cite>Spyware Warrior</cite>)</li>
<li> <a href="http://sunbeltblog.blogspot.com/2005/08/identity-theft-what-to-do.html" title="Article at SunbeltBlog">Identity Theft? What to do?</a> (<cite>Sunbelt Software</cite>)</li>
</ul>

<p>The scale of this is staggering. Internet users can not afford to be ignorant about internet safety anymore.</p>

<p>If you haven&#8217;t installed a software firewall, <em>it&#8217;s time to go and install one now</em>. I&#8217;ll post about some good firewalls sometime, but if you&#8217;re looking for one now, you won&#8217;t go wrong with the <a href="http://www.zonelabs.com/store/content/catalog/products/sku_list_za.jsp?lid=nav_za" title="ZoneAlarm free firewall">ZoneAlarm free version</a>.</p>

<p>On today&#8217;s internet, <strong>you&#8217;re asking for trouble</strong> if you don&#8217;t have a decent firewall.</p>

<p>Blessings,
<cite>Steve</cite></p>

<p class="listening">[Listening to <a href="http://www.amazon.com/exec/obidos/redirect?tag=rotassator-20&#038;path=tg/detail/-/B0000069NM" title="One of the funkiest, laid-back albums ever, featuring Sco and MMW">John Scofield, A Go Go</a> &#8212; Chicken Dog]</p>
]]></content:encoded>
			<wfw:commentRss>http://rotassator.com/2005/08/identity-theft-on-a-massive-scale/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Associated Press: spin doctors for Claria?</title>
		<link>http://rotassator.com/2005/08/associated-press-spin-doctors-for-claria/</link>
		<comments>http://rotassator.com/2005/08/associated-press-spin-doctors-for-claria/#comments</comments>
		<pubDate>Fri, 05 Aug 2005 02:02:19 +0000</pubDate>
		<dc:creator>Steve</dc:creator>
				<category><![CDATA[Safe computing]]></category>
		<category><![CDATA[Spyware and Adware]]></category>

		<guid isPermaLink="false">http://rotassator.com/?p=59</guid>
		<description><![CDATA[By the tone of todayâ€™s article in the Sydney Morning Herald, it sounds like Associated Press (the source for the article) are being paid for some advertising space via their articles (gosh, do they do that?). <a href="http://rotassator.com/2005/08/associated-press-spin-doctors-for-claria/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>By the tone of <a href="http://www.smh.com.au/news/technology/online-ad-pioneer-shuns-popups/2005/08/04/1123125842106.html" title="Online ad pioneer shuns pop-ups">today&#8217;s article in the Sydney Morning Herald</a>, it sounds like Associated Press (the source for the article) are being paid by Claria for some advertising space via their articles <em>(gosh, do they do that?)</em>.</p>

<p><span id="more-59"></span></p>

<p>Although making mention of (previous) negative press, the article tends to use <strong>nice, happy words</strong> to describe Claria&#8217;s new software direction like &#8220;tailored&#8221;, &#8220;personalised&#8221; and &#8220;more value&#8221;. The article also finishes with a short Q&amp;A session, <em>as if straight from the mouth of the beast</em>.</p>

<p>Some quotes&#8230;</p>

<blockquote cite="http://www.smh.com.au/news/technology/online-ad-pioneer-shuns-popups/2005/08/04/1123125842106.html">
Larry Ponemon, one of three outside privacy consultants hired by Claria, said complaints about privacy stem more from annoyance with pop-ups rather than any data collected. Non-adware companies might capture more data but get fewer complaints, he said.

<cite><a href="http://www.smh.com.au/news/technology/online-ad-pioneer-shuns-popups/2005/08/04/1123125842106.html" title="Article at SMH">Online ad pioneer shuns pop-ups</a> &#8212; SMH</cite>
</blockquote>

<p>What, so it&#8217;s OK to collect user&#8217;s data since people generally complain <em>more</em> about &#8220;annoyance with pop-ups&#8221;?</p>

<blockquote cite="http://www.smh.com.au/news/technology/online-ad-pioneer-shuns-popups/2005/08/04/1123125842106.html">
Claria still must win over the websites which once sued it. Eagle said most had been willing to listen, even if they have yet to sign deals.

Advertisers who have shunned pop-ups, meanwhile, had been more willing to run traditional ads through Claria, Eagle said, though he declined to name any of the 250 advertisers participating in BehaviourLink&#8217;s pilot.

Elias Plishner, head of the interactive group at Universal McCann ad agency, said many companies which previously weren&#8217;t willing to &#8220;dip their toes into behaviour marketing&#8221; might now be willing to give Claria a chance.

<cite><a href="http://www.smh.com.au/news/technology/online-ad-pioneer-shuns-popups/2005/08/04/1123125842106.html" title="Article at SMH">Online ad pioneer shuns pop-ups</a> &#8212; SMH</cite>
</blockquote>

<p>Any company involved in this slimy business will come out of it with muck on them. <strong>You can&#8217;t &#8220;dip your toes&#8221; into sewerage without stinking of something</strong>.</p>

<p>I hope the internet community aren&#8217;t just holding their noses.</p>

<p>Blessings,
<cite>Steve</cite></p>

<h4>Further reading</h4>

<ul>
    <li>Related AP stooges can be <a href="http://www.google.com/search?lr=&#038;ie=UTF-8&#038;oe=UTF-8&#038;q=Online%20ad%20pioneer%20shuns%20pop-ups" title="Google search for this article title">Googled at will</a>.</li>
</ul>

<p class="note">P.S. Thanks to <a href="http://www.rowen.id.au/blog/" title="Sailing Close To The Wind">Rowen</a> for the link.</p>

<p class="listening">[Listening to <a href="http://www.amazon.com/exec/obidos/redirect?tag=rotassator-20&#038;path=tg/detail/-/B000000V1A" title="A glorious live album of Celtic-flavoured rock, displaying brilliant performances all round">Iona, Heaven's Bright Sun</a> &#8212; When I Survey]</p>
]]></content:encoded>
			<wfw:commentRss>http://rotassator.com/2005/08/associated-press-spin-doctors-for-claria/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
