<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: AVG updates grant full control to Everyone, changes owner? in Security</title>
<link>http://www.dslreports.com/forum/r15603186</link>
<description></description>
<language>en</language>
<pubDate>Thu, 03 Dec 2009 05:59:39 EDT</pubDate>
<lastBuildDate>Thu, 03 Dec 2009 05:59:39 EDT</lastBuildDate>

<item>
<title>Re: AVG fixes, how about AVAST and PC-Cillin?</title>
<link>http://www.dslreports.com/forum/remark,15707061</link>
<description><![CDATA[<A HREF="/useremail/u/326716"><b>redxii</b></A> : It keeps doing that to *all* files every time the updater is run, not just the updated ones. One might notice there is more delay when updating than before installing 385.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15707061</guid>
<pubDate>Fri, 17 Mar 2006 20:10:06 EDT</pubDate>
</item>

<item>
<title>Re: AVG fixes, how about AVAST and PC-Cillin?</title>
<link>http://www.dslreports.com/forum/remark,15700534</link>
<description><![CDATA[<A HREF="/useremail/u/590688"><b>psloss</b></A> : <div class="bquote"><SMALL>said by  redxii <A HREF="/useremail/u/326716"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>yeah</DIV>What's even "curious-er" to me is that those extra ACEs in the DACL are all flagged as "inherit-only" -- even for files!  The complete set of flags (in the added ACEs) is "object inherit ace (OI) + container inherit ace (CI) + "inherit-only" (IO) + "inherited" (ID) or "OICIIOID".<br><br>For example, here's the DACL I pulled off "%ProgramFiles%\Grisoft\AVG Free\avgemc.exe":<br><div class="code"><PRE><span class="codetext">D:<br>(A;ID;0x1200a9;;;BU)<br>(A;OICIIOID;GXGR;;;BU)<br>(A;ID;0x1301bf;;;PU)<br>(A;OICIIOID;SDGXGWGR;;;PU)<br>(A;ID;FA;;;BA)<br>(A;OICIIOID;GA;;;BA)<br>(A;ID;FA;;;SY)<br>(A;OICIIOID;GA;;;SY)<br>(A;ID;FA;;;S-1-5-21-X-Y-Z-1003)<br>(A;OICIIOID;GA;;;CO)</SPAN></PRE></DIV><br>So while the "security problem ACE" is gone, I think you're right -- these additional ACEs appear to be superfluous.<br><br>I'll hasten to add that I stumbled onto <A HREF="http://www.microsoft.com/technet/community/columns/secmgmt/sm1105.mspx">this article</A> again (referenced elsewhere previously) and noted that we've now seen more than one of these "ways to shoot yourself in the foot" employed by products mentioned in this thread...<br> <BLOCKQUOTE><SMALL>said by the article :</SMALL><HR>Shooting Yourself in the Foot with ACLs<br><br>There are many ways to use ACLs, and some lead to the expected result whereas others have dire consequences. In this article, we will look at the following:<br><br>1. Blanket replacement of ACLs<br>2. Replacing Everyone with Authenticated Users<br>3. Failing to understand SDDL<br>4. Misusing inheritance<br>5. Everyone:Full Control DACLs<br>6. Everyone:Deny DACLs<br>7. Null DACLs<br>8. Excessive SACLs<br>9. Lack of SACLs on sensitive files<br><HR></BLOCKQUOTE><br><br>Philip Sloss<br><br><SMALL>--<br>Feedback? e-mail: stuff@lupwa.org<br><br></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15700534</guid>
<pubDate>Thu, 16 Mar 2006 21:25:20 EDT</pubDate>
</item>

<item>
<title>Re: AVG fixes, how about AVAST and PC-Cillin?</title>
<link>http://www.dslreports.com/forum/remark,15699945</link>
<description><![CDATA[<A HREF="/useremail/u/326716"><b>redxii</b></A> : yeah<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15699945?c=982494&ret=L2ZvcnVtL3IxNTYwMzE4Ni54bWw%3D"><IMG TITLE="18932 bytes" BORDER=0 WIDTH=551 HEIGHT=469 SRC="/r0/download/982494~1470ef19b5518bb6b653f71155b89573/update-perms.png"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15699945</guid>
<pubDate>Thu, 16 Mar 2006 20:06:55 EDT</pubDate>
</item>

<item>
<title>Re: AVG fixes, how about AVAST and PC-Cillin?</title>
<link>http://www.dslreports.com/forum/remark,15699889</link>
<description><![CDATA[<A HREF="/useremail/u/590688"><b>psloss</b></A> : <div class="bquote"><SMALL>said by  redxii <A HREF="/useremail/u/326716"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Hopefully they fix it better than AVG, because I don't know what putting each group/user twice in the security descriptor is supposed to accomplish; one coming from "C:\Program Files" and the other from "Parent Object". They are secure, but it's "Stop screwing around and having a field day with changing the default permissions." (and yes it does continue after the initial update)</DIV>Aw, crap...so they still don't know what they're doing, but in a less insecure way now?<br><SMALL>--<br>Feedback? e-mail: stuff@lupwa.org</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15699889</guid>
<pubDate>Thu, 16 Mar 2006 19:58:25 EDT</pubDate>
</item>

<item>
<title>Re: AVG fixes, how about AVAST and PC-Cillin?</title>
<link>http://www.dslreports.com/forum/remark,15699560</link>
<description><![CDATA[<A HREF="/useremail/u/326716"><b>redxii</b></A> : Hopefully they fix it better than AVG, because I don't know what putting each group/user twice in the security descriptor is supposed to accomplish; one coming from "C:\Program Files" and the other from "Parent Object". They are secure, but it's "Stop screwing around and having a field day with changing the default permissions." (and yes it does continue after the initial update)<br> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15699560</guid>
<pubDate>Thu, 16 Mar 2006 19:10:40 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15699344</link>
<description><![CDATA[<A HREF="/useremail/u/854295"><b>Libra</b></A> : I want to thank RedXX1234 for discovering this problem and DP for notifying Grisoft about it.  I am using AVG free and I just received an update yesterday.  The program is 7.1.385 and my Updater is version .384.<br><br>RedXX1234, I was very impressed to see your discovery published at Secunia!<br><br>Sincerely, Libra]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15699344</guid>
<pubDate>Thu, 16 Mar 2006 18:42:19 EDT</pubDate>
</item>

<item>
<title>Re: AVG fixes, how about AVAST and PC-Cillin?</title>
<link>http://www.dslreports.com/forum/remark,15697716</link>
<description><![CDATA[<A HREF="/useremail/u/1001074"><b>toadlife</b></A> : <div class="bquote"><SMALL>said by  EGeezer <A HREF="/useremail/u/668609"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br> toadlife <A HREF="/useremail/u/1001074"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> pointed out that Avast home edition has the same issue, and  geierr <A HREF="/useremail/u/425706"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> indicated possible problems with PC-Cillin home security - have they addressed it too, or is it not an issue with them? <br> </DIV>I <A HREF="http://forum.avast.com/index.php?topic=19862.0">posted the issue</A> along with instructions on how to fix it in the Avast forums. The Avast devs said they are aware of the issue and will be fixing it in the next update.<br><SMALL>--<br>Have problems running your Windows box as a limited user?<BR>Try this...&raquo;<A HREF="http://winsudo.toadlife.net" >winsudo.toadlife.net</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15697716</guid>
<pubDate>Thu, 16 Mar 2006 14:39:34 EDT</pubDate>
</item>

<item>
<title>AVG fixes, how about AVAST and PC-Cillin?</title>
<link>http://www.dslreports.com/forum/remark,15696989</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : I'm impressed that AVG resolved this so quickly - Thanks to  redxii <A HREF="/useremail/u/326716"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> the vulnerabiltiy was discovered and resolved. I will lift my "recommendation embargo" on AVG Monday :)  <br><br> toadlife <A HREF="/useremail/u/1001074"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> pointed out that Avast home edition has the same issue, and  geierr <A HREF="/useremail/u/425706"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> indicated possible problems with PC-Cillin home security - have they addressed it too, or is it not an issue with them? <br><SMALL>--<br>Insert catchy sig line here</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15696989</guid>
<pubDate>Thu, 16 Mar 2006 12:52:51 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15696393</link>
<description><![CDATA[<A HREF="/useremail/u/465004"><b>ironwalker</b></A> : Great work  redxii <A HREF="/useremail/u/326716"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> and thank you for the speedy fix AVG.<br><br>With that said,is there confirmation as to the initial problem being fixed?<br><br>I do have the paid pro version on several pc's and talked a few friends/relatives into purchaseing as well,I'd hate to see this still an issue or similar permissions issues.<br><br>I myself do not see an "obvious" email address.As for Red,I am glad he started this topic and I am glad other security sites made the public aware of this as well.I do not think you(AVG) have anything to worry about.It was brought to light and fixed,nothing more to worry about.Its people like Red that help developers with there product,keeping it quiet is a moot point imo.<br><br>Thanks again<br><SMALL>--<br>Live Free or Die!</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15696393</guid>
<pubDate>Thu, 16 Mar 2006 11:26:33 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15696249</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> :  have any of u guys tried using Steganos???  i used it when i spotted this alert (thanx RedxII) and it went right in and pulled the lot i found that my connection had already been compromised, but steg got rid of it all and also shredded all info 4 avg on my os and also online too.<br>then all i did was download another copy with the new definitions whilst still using stegs email security and that was that.... i rebooted...then uninstalled steg ...rebooted again...put avg back in and its been sorted ever since...<br>steganos r giving a free full install at the moment of suite 7.1.6 and also u can get the full trial of the latest full antivirus package on a try out for nothin at thier site... if its free....why not? its actually a very smooth prog i like it a lot, but i prefer avg 4 its simplicity but 4 this current prob u guys have or r worried about, try going to the steg site ..it wont hurt to check...and its a simple solution..ok?<br><br>go here guys  <br>&raquo;<A HREF="http://www.steganos.com/?layout=web2005&content=products&language=en" >www.steganos.com/?layout=web2005&middot;&middot;&middot;guage=en</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15696249</guid>
<pubDate>Thu, 16 Mar 2006 11:01:51 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15660934</link>
<description><![CDATA[<A HREF="/useremail/u/166306"><b>Jan Janowski</b></A> : Been watching this thread pretty much since inception, as I've 2 AVG Pro licenses, and 2 free ones (On seldom used W98 systems)....<br><br>It is nice to know that the problem was addressed in a timely manner...  Thanks to the poster, and AVG folks...<br><br>The one thing that got my attention on AVG products was, even when I used the "Free" and "Evaluation" versions, before deciding to swtich from my previous AV, was the fact that I could CONTACT THE AV COMPANY..... AND THEY WOULD RESPOND!!!!!   That was one of the Selling Points for me to swtich to AVG Pro.<br><br>Had Norton done this during multiple failed installs on two separate upgrades from 2000 to 2003/2003 versions, I might still be with them!!<br><br>I don't know if companies know of the real Public Relations worth of email support.... <br>If we all were code genius's, we wouldn't need it, but when we do..... It is worth it's weight in GOLD!!<br><br>Thanks to all involved in making this program better!!!<br><SMALL>--<br>Looking for 1939 Indian Motocycle</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15660934</guid>
<pubDate>Sat, 11 Mar 2006 09:26:25 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15650221</link>
<description><![CDATA[<A HREF="/useremail/u/326716"><b>redxii</b></A> : secure@grisoft.cz and security@grisoft.cz ? Not even a Google search shows those e-mail addresses (and no, they are not obvious e-mail addresses). I suppose I couldn't get to the page with those email addresses if I had to enter a non-existant license key.<br><br>I'm wondering why no one caught it before.<br><br>'Nuff of this discussion anyhow..]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15650221</guid>
<pubDate>Thu, 09 Mar 2006 17:53:51 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15649408</link>
<description><![CDATA[<A HREF="/useremail/u/257598"><b>Lappen</b></A> : <div class="bquote"><SMALL>said by Karel Obluk :</SMALL><br><br>It is a pity that the original reporter has not contacted us using the standard e-mail addresses that should be used in such cases (secure@grisoft.cz, security@grisoft.cz etc.) before publicly disclosing this issue. Neverthless, we did our best to release a fix as soon as possible because as minor a problem it was, it definitely was a security problem.<br> </DIV>Well in defence of RedXII1234 I have to say that I aslo am a user of the free version and I have been tryinng to contact avg before, not about this issue but about other things and I have never been able to acctually find a e-mail adress that I can reach you on as a free user of avg, only the forums and web forms for paying customers<br><br>As for RedXII1234 trying or not trying to report this to you I dont have any knowledge about that.<br><SMALL>--<br>I can also be found at the <A HREF="http://forums.spywareinfo.com">SWI Forums</A> as Lappen<BR></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15649408</guid>
<pubDate>Thu, 09 Mar 2006 15:59:44 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15649209</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : The AVG Pro has been fixed and build 384 also resets permissions of files that have their permissions incorrectly set by previous updates. As this was primarily an issue for corporate customers, we wanted to fix it as soon as possible for Professional users. Update for the Free edition will be released by the end of this week, i.e. in less then a week from when the problem has been disclosed.<br>It is a pity that the original reporter has not contacted us using the standard e-mail addresses that should be used in such cases (secure@grisoft.cz, security@grisoft.cz etc.) before publicly disclosing this issue. Neverthless, we did our best to release a fix as soon as possible because as minor a problem it was, it definitely was a security problem.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15649209</guid>
<pubDate>Thu, 09 Mar 2006 15:24:13 EDT</pubDate>
</item>

<item>
<title>Re: Coming - AV rootkits?</title>
<link>http://www.dslreports.com/forum/remark,15649089</link>
<description><![CDATA[<A HREF="/useremail/u/506188"><b>Luka1</b></A> : <div class="bquote"><SMALL>said by  EGeezer <A HREF="/useremail/u/668609"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>This looks like a new opportunity - rootkitting AV programs. Wouldn't it be within malware technology to replace AV engine files with a rooted version of the AV engine that would ignore selected malware, open ports, make connections to bot controllers etc? Why disable AVs when they can "upgrade" them to their liking so the user could see an active AV they think is still protecting them? <br> </DIV>Opportunity.<br><br>This has me curious indeed, because of a recent event on my computer.<br><br>Somewhere around two weeks ago, AVG was doing it's regularly scheduled automatic update. <br><br>It showed to be downloading a file roughly 5830kb in size. (I can't remember the exact number.)<br><br>When that much was downloaded, it just kept right on downloading. By the time it was finished, there was more than 11000kb file size.<br><br>By the time I noticed what was happening, it was too late. It had already finished the download and started the process of updating.<br><br>All other functions of the computer locked up. I couldn't stop it. Then it rebooted without even asking me. <br><br>After the reboot...<br><br>Mailwasher and Process guard were both "new" again. None of my account info was there in mailwasher, and it wanted me to fill out that info. Process guard was in learning mode, and all of my settings/programs/etc were gone.<br><br>And... Now every time that I send out an email with Eudora, (set to offline mode, so I have to ok the single connection each time I send out an email)... I hit the ok for the connection, then the same message comes up again a second time and I have to hit ok for the connection again.<br><br>All of this started with that update to AVG...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15649089</guid>
<pubDate>Thu, 09 Mar 2006 14:59:06 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15639798</link>
<description><![CDATA[<A HREF="/useremail/u/1337382"><b>miraclemax203</b></A> : I'm a AVG 7.1 Pro user. I just installed the new update this morning. Is there a way to tell if AVG fixed the permissions granted to the update files?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15639798</guid>
<pubDate>Wed, 08 Mar 2006 11:24:40 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15639524</link>
<description><![CDATA[<A HREF="/useremail/u/258532"><b>dp</b></A> : <div class="bquote"><SMALL>said by  psloss <A HREF="/useremail/u/590688"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Probably going to take a little while to package for all the distribution channels...it's not showing up yet for the copy of the free version I just tried.  I got one manual download of the 7.1.384 .bin file from the main site, but now there may be some contention issues doing that.<br> </DIV>The update has only been released for the Pro version so far. <br>&raquo;<A HREF="/forum/remark,15639022">AVG 7.1.384 Program Update</A><br><SMALL>--<br>Write your questions down on the back of a $20 dollar bill and send them to me<BR>Microsoft MVP/Windows Security 2004-2006</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15639524</guid>
<pubDate>Wed, 08 Mar 2006 10:38:06 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15639107</link>
<description><![CDATA[<A HREF="/useremail/u/590688"><b>psloss</b></A> : Probably going to take a little while to package for all the distribution channels...it's not showing up yet for the copy of the free version I just tried.  I got one manual download of the 7.1.384 .bin file from the main site, but now there may be some contention issues doing that.<br><SMALL>--<br>Feedback? e-mail: stuff@lupwa.org</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15639107</guid>
<pubDate>Wed, 08 Mar 2006 09:28:26 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15638931</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : It appears the 'fix' has been released by AVG.<br><br>SEE:<br>&raquo;<A HREF="http://www.grisoft.com/doc/28396/lng/us/tpl/tpl01" >www.grisoft.com/doc/28396/lng/us/tpl/tpl01</A><br><br>NOTE: Outlink:<br>&raquo;<A HREF="http://www.grisoft.com/linkout.php?doc=28396&to=http%3A%2F%2Fsecunia.com%2Fadvisories%2F19118%2F" >www.grisoft.com/linkout.php?doc=&middot;&middot;&middot;19118%2F</A><br><br>:)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15638931</guid>
<pubDate>Wed, 08 Mar 2006 08:49:06 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15638535</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : According to Grisoft's conference, new program version is prepared to be released and it also solves this problem.. Hope that definitely..:)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15638535</guid>
<pubDate>Wed, 08 Mar 2006 06:42:39 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15638403</link>
<description><![CDATA[<A HREF="/useremail/u/1001074"><b>toadlife</b></A> : BTW, I shot an email over to Avast regarding the issue with their AV. Hopefully they take it seriously.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15638403</guid>
<pubDate>Wed, 08 Mar 2006 05:05:36 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15627171</link>
<description><![CDATA[<A HREF="/useremail/u/1001074"><b>toadlife</b></A> : <div class="bquote"><SMALL>said by  psloss <A HREF="/useremail/u/590688"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>It certainly doesn't change the effectiveness of the ACE to have an inherited flag from nowhere.  I didn't see anywhere in CACLS to reset inheritance -- are you aware of how to do that with the utility?<br><br>Thanks,<br><br>Philip Sloss<br> </DIV>No. AFAIK, calcs.exe can't reset inheritance. There are some other annoyances with cacls.exe. Microsoft really didn't do a very good job with it.<br><SMALL>--<br>Have problems running your Windows box as a limited user?<BR>Try this...&raquo;<A HREF="http://home.toadlife.net/winsudo" >home.toadlife.net/winsudo</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15627171</guid>
<pubDate>Mon, 06 Mar 2006 19:44:55 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15623319</link>
<description><![CDATA[<A HREF="/useremail/u/590688"><b>psloss</b></A> : Me, too:  good job,  redxii <A HREF="/useremail/u/326716"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15623319</guid>
<pubDate>Mon, 06 Mar 2006 11:14:58 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15623281</link>
<description><![CDATA[<A HREF="/useremail/u/258532"><b>dp</b></A> : <div class="bquote"><SMALL>said by  gkweb <A HREF="/useremail/u/824136"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Hello,<br><br>your findings has been published at secunia :<br>&raquo;<A HREF="http://secunia.com/advisories/19118/" >secunia.com/advisories/19118/</A><br><br>I have received an email notification.<br><br>Good job on this one :-)<br><br>Regards,<br>gkweb.<br> </DIV>Ditto here, kudos to  redxii <A HREF="/useremail/u/326716"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>!<br><SMALL>--<br>Write your questions down on the back of a $20 dollar bill and send them to me<BR>Microsoft MVP/Windows Security 2004-2006</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15623281</guid>
<pubDate>Mon, 06 Mar 2006 11:08:54 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15622889</link>
<description><![CDATA[<A HREF="/useremail/u/824136"><b>gkweb</b></A> : Hello,<br><br>your findings has been published at secunia :<br>&raquo;<A HREF="http://secunia.com/advisories/19118/" >secunia.com/advisories/19118/</A><br><br>I have received an email notification.<br><br>Good job on this one :-)<br><br>Regards,<br>gkweb.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15622889</guid>
<pubDate>Mon, 06 Mar 2006 10:07:49 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15622292</link>
<description><![CDATA[<A HREF="/useremail/u/590688"><b>psloss</b></A> : <div class="bquote"><SMALL>said by  toadlife <A HREF="/useremail/u/1001074"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Actually, this happens when file permission are set using the command-line cacls.exe utility. I use cacls.exe at work to set custom perms for legacy programs, and this weird "bogus inheritance flag" happens every time I use it. I just passed it off as a strange bug, and though nothing more of it, as it didn't hinder the effectiveness of cacls.exe.</DIV>Wasn't aware of that with CACLS, thanks for pointing that out.  It certainly doesn't change the effectiveness of the ACE to have an inherited flag from nowhere.  I didn't see anywhere in CACLS to reset inheritance -- are you aware of how to do that with the utility?<br><br>Thanks,<br><br>Philip Sloss<br><SMALL>--<br>Feedback? e-mail: stuff@lupwa.org</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15622292</guid>
<pubDate>Mon, 06 Mar 2006 07:34:41 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15622023</link>
<description><![CDATA[<A HREF="/useremail/u/258532"><b>dp</b></A> : Grisoft is aware of this issue and a fix is under development. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15622023</guid>
<pubDate>Mon, 06 Mar 2006 04:14:57 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15621525</link>
<description><![CDATA[<A HREF="/useremail/u/1001074"><b>toadlife</b></A> : <div class="bquote"><SMALL>said by  psloss <A HREF="/useremail/u/590688"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>In the screenshot, you can see where the other ACEs are inherited from, but not the one that came from Avast (it says "Parent Object", which I infer to mean that even the OS is confused).<br> </DIV>Actually, this happens when file permission are set using the command-line cacls.exe utility. I use cacls.exe at work to set custom perms for legacy programs, and this weird "bogus inheritance flag" happens every time I use it. I just passed it off as a strange bug, and though nothing more of it, as it didn't hinder the effectiveness of cacls.exe. <br><SMALL>--<br>Have problems running your Windows box as a limited user?<BR>Try this...&raquo;<A HREF="http://home.toadlife.net/winsudo" >home.toadlife.net/winsudo</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15621525</guid>
<pubDate>Mon, 06 Mar 2006 00:58:33 EDT</pubDate>
</item>

<item>
<title>Coming - AV rootkits?</title>
<link>http://www.dslreports.com/forum/remark,15620387</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : This looks like a new opportunity - rootkitting AV programs. Wouldn't it be within malware technology to replace AV engine files with a rooted version of the AV engine that would ignore selected malware, open ports, make connections to bot controllers etc? Why disable AVs when they can "upgrade" them to their liking so the user could see an active AV they think is still protecting them? <br><SMALL>--<br>Insert catchy sig line here</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15620387</guid>
<pubDate>Sun, 05 Mar 2006 21:49:56 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15620179</link>
<description><![CDATA[<A HREF="/useremail/u/615773"><b>hpguru</b></A> : <div class="bquote"><SMALL>said by user=toadlife :</SMALL><br><br>The Home Version.<br><br>Right click on one of the executable files like "ashServe.exe" or "aswUpdSv.exe", both which run under system permissions as services, and  check the perms.<br> </DIV>Not the case here. The screen cap shows the perms which ashserv.exe has inherited from its parent folder. AswUpdSv.exe inherits the same perms. The only files in this folder which are not inheriting perms are those I mentioned above.<br><SMALL>--<br><B><A HREF="http://www.hosts-file.net/">Get hpHOSTS!</A> Member <A HREF="http://asap.maddoktor2.com/">ASAP</A></B><BR><B><A HREF="http://hphosts.mysteryfcm.co.uk/">hpHOSTS Online</A></B><BR><B>Paranoia is no substitute for understanding.</B></SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15620179?c=977099&ret=L2ZvcnVtL3IxNTYwMzE4Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="114539 bytes" WIDTH=600 HEIGHT=443 SRC="/r0/download/977099.thumb600~e98dbf6c0e46d0d87b1d38d37334159c/ashserv.gif/thumb.jpg" ALT="Click for full size"></A><br>ashServ.exe perms</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15620179</guid>
<pubDate>Sun, 05 Mar 2006 21:16:36 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15619893</link>
<description><![CDATA[<A HREF="/useremail/u/425706"><b>geierr</b></A> : Trend Micro PC-cillin Internet Security (which I used for about a year) does almost the same thing to its program folder as well. However, only the Everyone group is listed on the Security tab with the permission set to Full Control of course.<br><SMALL>--<br>Robert L. Geier<BR><BR><B>WFSE/AFSCME Local 1326</B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15619893</guid>
<pubDate>Sun, 05 Mar 2006 20:32:42 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15618629</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : Now I'm wondering what other AV/security products have this vulnerability. I note that AVG Pro has ICSA certification. Seems like ICSA would have some standards on the vulnerability of the products themselves. <br><br>I'd expect these vendors to step up and respond to this issue. If they don't, It'll just reinforce security product critics who feel the Secvendor market is a big shell game. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15618629</guid>
<pubDate>Sun, 05 Mar 2006 16:48:26 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15616775</link>
<description><![CDATA[<A HREF="/useremail/u/1303852"><b>zteardrop</b></A> : Guess you get what you "pay" for. Thats why products like KAV and NAV build their own protection against attacks against their files, processes, registry keys. KAV just hides its processes. NAV 2006 and above have full protection. You can't terminate NAV processes, remove NAV files etc., even if you are admin.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15616775</guid>
<pubDate>Sun, 05 Mar 2006 11:54:42 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15616186</link>
<description><![CDATA[<A HREF="/useremail/u/590688"><b>psloss</b></A> : Here's how the DACLs appear to me for the Avast and AVG installs:<br><br>The Avast file DACLs have inheritance flags in the DACL itself and all the ACEs (all the ACEs here are allow ACEs):<br><div class="code"><PRE><span class="codetext">D:AI (discretionary ACL; auto-inherited)<br>(A;ID;FA;;;WD) (inherited, File All Access/Everyone, boo, hiss)<br>(A;ID;FA;;;S-1-5-21-X-Y-Z-1004) (inherited, File All Access/local account)<br>(A;ID;FA;;;SY) (inherited, File All Access/SYSTEM)<br>(A;ID;FA;;;BA) (inherited, File All Access/Administrators)</SPAN></PRE></DIV><br>(I'm hiding the subauthorities for the machine-relative SID.)<br><br>The inheritance flag itself in Avast's Everyone ACE is still a head-scratcher.<br><br>The AVG DACLs don't have any inheritance indicated in them (no AI or ID strings):<br><div class="code"><PRE><span class="codetext">D: (discretionary ACL)<br>(A;;FA;;;SY) (File All Access/SYSTEM)<br>(A;;FA;;;BA) (File All Access/Administrators)<br>(A;;FA;;;S-1-5-21-X-Y-Z-1004) (File All Access/local account)<br>(A;;0x1301bf;;;PU) ("Special"/Power Users)<br>(A;;0x1200a9;;;BU) ("Read and Execute"/Users)<br>(A;;FA;;;WD) (boo, hiss, again; "File All Access/Everyone")</SPAN></PRE></DIV><br>Comparing these to the DACLs in parent directories and sibling files, it's still hard for me to come to any conclusion about the intentions behind the implementation.  But in general, they need to start doing some kind of system continuity testing, particularly with regard to NT object security.<br><br>...hmmm, OK, here's one conclusion: these are two examples of kludges to NT security.  And they both have very bad side effects.<br><br>Philip Sloss<br><br><SMALL>--<br>Feedback? e-mail: stuff@lupwa.org</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15616186</guid>
<pubDate>Sun, 05 Mar 2006 10:09:23 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15615764</link>
<description><![CDATA[<A HREF="/useremail/u/590688"><b>psloss</b></A> : I'm five hours behind you (well, on this...it's probably worse in other areas).  Just looking at the "live" and autostart "stuff," the startup scanner (aswboot.exe) and the screensaver jumped out as having the Everyone/Full Control ACE.  <br><br>Have to go back and check AVG, but the DACLs that Avast is setting are weird -- the Everyone/Full Control ACE is flagged as inherited from the parent object (the containing directory), but it's not immediately obvious where it's inherited from.  In the screenshot, you can see where the other ACEs are inherited from, but not the one that came from Avast (it says "Parent Object", which I infer to mean that even the OS is confused).<br><br>This sure gives you the warm fuzzies, doesn't it?<br><br>Philip Sloss<br><SMALL>--<br>Feedback? e-mail: stuff@lupwa.org<br><br></SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15615764?c=976747&ret=L2ZvcnVtL3IxNTYwMzE4Ni54bWw%3D"><IMG TITLE="15578 bytes" BORDER=0 WIDTH=551 HEIGHT=469 SRC="/r0/download/976747~e577b1962e61a2726bb998f57b6e4f21/AvastDACL.PNG"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15615764</guid>
<pubDate>Sun, 05 Mar 2006 07:59:24 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15615063</link>
<description><![CDATA[<A HREF="/useremail/u/1001074"><b>toadlife</b></A> : <div class="bquote"><SMALL>said by  redxii <A HREF="/useremail/u/326716"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Avast does it right off the bat! Immediately after installing.<br><br>The Program Files pic doesn't display the whole thing, but you get the picture...<br> </DIV>The sad part about it, is that it doesn't seem to be necessarily at all. I opened up explorer as admin, reset the permissions from the top, so that users could only read, and I was still able to initiate an update session with my user account, and change some settings.<br><SMALL>--<br>Have problems running your Windows box as a limited user?<BR>Try this...&raquo;<A HREF="http://home.toadlife.net/winsudo" >home.toadlife.net/winsudo</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15615063</guid>
<pubDate>Sun, 05 Mar 2006 01:58:35 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15615036</link>
<description><![CDATA[<A HREF="/useremail/u/326716"><b>redxii</b></A> : Avast does it right off the bat! Immediately after installing.<br><br>The Program Files pic doesn't display the whole thing, but you get the picture...<br><SMALL>--<br>"Open Source" == "Close Minded" <A HREF="http://redxii.blogspot.com">Dig into Windows 2000 & XP</A>.</SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15615036?c=976688&ret=L2ZvcnVtL3IxNTYwMzE4Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="72594 bytes" WIDTH=600 HEIGHT=450 SRC="/r0/download/976688.thumb600~107865e23c3b7cff3e35183c117ffbff/AVAST-postinstall-WINDOWS.png/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15615036?c=976690&ret=L2ZvcnVtL3IxNTYwMzE4Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="74338 bytes" WIDTH=600 HEIGHT=450 SRC="/r0/download/976690.thumb600~45a24774a6e84e158dcc623311b90d60/AVAST-postinstall-PROGAMFILES.png/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15615036?c=976691&ret=L2ZvcnVtL3IxNTYwMzE4Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="619156 bytes" WIDTH=600 HEIGHT=450 SRC="/r0/download/976691.thumb600~ca843e54bab20b191ef63ba77a5a77ca/AVAST-postinstall-PROGAMFILES2.PNG/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15615036</guid>
<pubDate>Sun, 05 Mar 2006 01:47:21 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15614991</link>
<description><![CDATA[<A HREF="/useremail/u/1001074"><b>toadlife</b></A> : <div class="bquote"><SMALL>said by  hpguru <A HREF="/useremail/u/615773"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><div class="bquote"><SMALL>said by  toadlife <A HREF="/useremail/u/1001074"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Avast DOES have the same issue. All of the contents below the avast program folder are given a custom ACL that gives "builtin\everyone" full control. A piece of malware could *easily* hijack a computer running avast regardless of the permission level of the user. <br> </DIV>Which version? Pro or Home? I have the home version here and I don't see that. The effected files and folders are below the DATA and Setup folders which I forgot to mention above. That doesn't make it any less a problem however since the virus definitions are in the Setup folder.<br> </DIV>The Home Version.<br><br>Right click on one of the executable files like "ashServe.exe" or "aswUpdSv.exe", both which run under system permissions as services, and  check the perms.<br><br>I'm pretty sure I never messed with the permission in that folder. Uninstalling, nuking the program folder, and reinstalling would verify that the installer actually does modify permissions.<br><SMALL>--<br>Have problems running your Windows box as a limited user?<BR>Try this...&raquo;<A HREF="http://home.toadlife.net/winsudo" >home.toadlife.net/winsudo</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15614991</guid>
<pubDate>Sun, 05 Mar 2006 01:35:43 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15614859</link>
<description><![CDATA[<A HREF="/useremail/u/615773"><b>hpguru</b></A> : <div class="bquote"><SMALL>said by  toadlife <A HREF="/useremail/u/1001074"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Avast DOES have the same issue. All of the contents below the avast program folder are given a custom ACL that gives "builtin\everyone" full control. A piece of malware could *easily* hijack a computer running avast regardless of the permission level of the user. <br> </DIV>Which version? Pro or Home? I have the home version here and I don't see that. The effected files and folders are below the DATA and Setup folders which I forgot to mention above. That doesn't make it any less a problem however since the virus definitions are in the Setup folder.<br><SMALL>--<br><B><A HREF="http://www.hosts-file.net/">Get hpHOSTS!</A> Member <A HREF="http://asap.maddoktor2.com/">ASAP</A></B><BR><B><A HREF="http://hphosts.mysteryfcm.co.uk/">hpHOSTS Online</A></B><BR><B>Paranoia is no substitute for understanding.</B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15614859</guid>
<pubDate>Sun, 05 Mar 2006 01:13:03 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15614260</link>
<description><![CDATA[<A HREF="/useremail/u/1001074"><b>toadlife</b></A> : <div class="bquote"><SMALL>said by  hpguru <A HREF="/useremail/u/615773"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>On second thought, Avast! may have the same issue but I couldn't say it changes the default permissions since I have it installed in a folder on another partition with custome perms. It did however change the perms for the subfolders under D:\Program Files\Alwil Software\Avast4\DATA giving Everyone full control.<br> </DIV>Avast DOES have the same issue. All of the contents below the avast program folder are given a custom ACL that gives "builtin\everyone" full control. A piece of malware could *easily* hijack a computer running avast regardless of the permission level of the user. <br><SMALL>--<br>Have problems running your Windows box as a limited user?<BR>Try this...&raquo;<A HREF="http://home.toadlife.net/winsudo" >home.toadlife.net/winsudo</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15614260</guid>
<pubDate>Sat, 04 Mar 2006 23:10:58 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15613890</link>
<description><![CDATA[<A HREF="/useremail/u/615773"><b>hpguru</b></A> : <div class="bquote"><SMALL>said by  psloss <A HREF="/useremail/u/590688"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><div class="bquote"><SMALL>said by  hpguru <A HREF="/useremail/u/615773"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Avast! me 'arties!</DIV>(Why am I thinking of Yosemite Sam talking to Bugs Bunny?..."I've got you outnumbered, one to one.  Come out and meet your doom.")<br><br>Setup program is downloaded and a little evaluation is on my todo list. </DIV>LOL! :D<br><br>On second thought, Avast! may have the same issue but I couldn't say it changes the default permissions since I have it installed in a folder on another partition with custome perms. It did however change the perms for the subfolders under D:\Program Files\Alwil Software\Avast4\DATA giving Everyone full control.<br><SMALL>--<br><B><A HREF="http://www.hosts-file.net/">Get hpHOSTS!</A> Member <A HREF="http://asap.maddoktor2.com/">ASAP</A></B><BR><B><A HREF="http://hphosts.mysteryfcm.co.uk/">hpHOSTS Online</A></B><BR><B>Paranoia is no substitute for understanding.</B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15613890</guid>
<pubDate>Sat, 04 Mar 2006 22:02:53 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15612483</link>
<description><![CDATA[<A HREF="/useremail/u/258532"><b>dp</b></A> : I've emailed Grisoft and asked them to view this thread. Hopefully they will address this issue promptly.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15612483</guid>
<pubDate>Sat, 04 Mar 2006 17:48:56 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15612474</link>
<description><![CDATA[<A HREF="/useremail/u/590688"><b>psloss</b></A> : <div class="bquote"><SMALL>said by  hpguru <A HREF="/useremail/u/615773"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Avast! me 'arties!</DIV>(Why am I thinking of Yosemite Sam talking to Bugs Bunny?..."I've got you outnumbered, one to one.  Come out and meet your doom.")<br><br>Setup program is downloaded and a little evaluation is on my todo list.<br><br>It does appear that non-admin accounts can perform the workaround that  redxii <A HREF="/useremail/u/326716"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> noted earlier of resetting the parts of the file permissions that are being changed (owner) and made too permissive (discretionary ACL), since "full control" includes <A HREF="http://msdn.microsoft.com/library/en-us/secauthz/security/standard_access_rights.asp">WRITE_DAC and WRITE_OWNER</A>.  <br><br>Although looking at  redxii <A HREF="/useremail/u/326716"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>'s screenshots, it still looks like kind of a mess in AVG's Program Files subdirectory...resetting individual files to inherit their permissions is more precise and more tedious.  And propagating inheritance down from the containing directory might change something that was set explicitly (for a better reason than this, I hope :-) ).  <br><br>I think I'll start with testing the software with the eye patch first...<br><br>Philip Sloss<br><SMALL>--<br>Feedback? e-mail: stuff@lupwa.org</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15612474</guid>
<pubDate>Sat, 04 Mar 2006 17:47:18 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15612362</link>
<description><![CDATA[<A HREF="/useremail/u/615773"><b>hpguru</b></A> : <div class="bquote"><SMALL>said by  psloss <A HREF="/useremail/u/590688"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Yeah, this looks like a showstopper for me right now...although I don't know what I'd recommend as an alternative. </DIV>Avast! me 'arties!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15612362</guid>
<pubDate>Sat, 04 Mar 2006 17:22:47 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15612357</link>
<description><![CDATA[<A HREF="/useremail/u/854295"><b>Libra</b></A> : <div class="bquote"><SMALL>said by  redxii <A HREF="/useremail/u/326716"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>In a command prompt: <B>cacls &lt;filenameordirectory&gt;</B><br><br> </DIV>I don't think I can do cacls on XP Home (but I haven't tried).<br><br>Should we be changing to a different AV?<br><br>Sincerely, Libra]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15612357</guid>
<pubDate>Sat, 04 Mar 2006 17:22:10 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15612224</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : Darn, I just suggested AVG pro to a friend/customer with a half dozen or so systems. I need to tell him to hold off until this is resolved.  <br><SMALL>--<br>Insert catchy sig line here</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15612224</guid>
<pubDate>Sat, 04 Mar 2006 16:57:58 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15612162</link>
<description><![CDATA[<A HREF="/useremail/u/590688"><b>psloss</b></A> : Yeah, this looks like a showstopper for me right now...although I don't know what I'd recommend as an alternative.<br><br>Thanks for bringing this to our attention.<br><br>Philip Sloss<br><SMALL>--<br>Feedback? e-mail: stuff@lupwa.org</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15612162</guid>
<pubDate>Sat, 04 Mar 2006 16:40:31 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15612106</link>
<description><![CDATA[<A HREF="/useremail/u/326716"><b>redxii</b></A> : Pro does it too.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15612106</guid>
<pubDate>Sat, 04 Mar 2006 16:26:51 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15612049</link>
<description><![CDATA[<A HREF="/useremail/u/844746"><b>Joe12345678</b></A> : is just free AVG free? if this is this may just be a way to not  used for free on non home systems and they assume that all home uses are admin.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15612049</guid>
<pubDate>Sat, 04 Mar 2006 16:16:35 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15608749</link>
<description><![CDATA[<A HREF="/useremail/u/326716"><b>redxii</b></A> : In a command prompt: <B>cacls &lt;filenameordirectory&gt;</B><br><br>I am probably falling on deaf ears unless I were a paying customer... In the mean time, thinking about all those other AVG users who even if they are limited users have absolutely no idea...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15608749</guid>
<pubDate>Sat, 04 Mar 2006 01:46:11 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15608477</link>
<description><![CDATA[<A HREF="/useremail/u/854295"><b>Libra</b></A> : Hi RedXII1234,<br>  I'm not comfortable going into safe mode to look at those permissions, but I have AVG7.1 free on my daughter's computer and one time, in a limited account, I tried to delete a WMF test item from the vault, and I wasn't able to.  I also tried to change the results of a scan to accept an item "changed", and I couldn't do that either.  Based on that I didn't think the limited user had rights.  When I tried to make one of those changes I got this error in the Event Viewer:<br><br>Source: AVG<br>Category: error<br>Event ID # 100<br>AVG7.CC plugins.CPluginManager action running failed.  Error 0x80004004.<br><br>Is there a way for you to get this information to Grisoft?  I don't think he visits the AVG forum.<br><br>Sincerely, Libra<br>  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15608477</guid>
<pubDate>Sat, 04 Mar 2006 00:35:34 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15605574</link>
<description><![CDATA[<A HREF="/useremail/u/590688"><b>psloss</b></A> : <div class="bquote"><SMALL>said by  redxii <A HREF="/useremail/u/326716"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><div class="bquote"><SMALL>said by  psloss <A HREF="/useremail/u/590688"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</SMALL><br><br>Yeah, that's not good about the updater, although this type of escalation opportunity is still not at the top of the list in terms of taking over control of a Windows box these days.<br> </DIV>It's still an opportunity, and should be fixed.<br> </DIV>Absolutely agree; however, given that they already have code that appears to add an Everyone/Full Control ACE to DACLs of updated or downloaded files, I'm not sure how sensitive they're going to be to privilege escalation.  Or, how expeditiously this will get fixed.  <br><br>Somewhat randomly, this reminds me of a <A HREF="http://windowsconnected.com/blogs/jerry/archive/2006/02/24/1077.aspx">recent blog post</A> about how terminal session separation in Vista is going to cause some consternation for NAV.  For what it's worth, AVG Free installed on the February Vista CTP...but both attempts I made to open the command center caused the OS to bugcheck.  Going to be an interesting year to see what happens to this category of consumer software.<br><br>Hopefully this issue will gain some traction at Grisoft and maybe the changes to Windows will increase the importance of scouring kludges like this out of their code.<br><SMALL>--<br>Feedback? e-mail: stuff@lupwa.org</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15605574</guid>
<pubDate>Fri, 03 Mar 2006 17:02:03 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15603802</link>
<description><![CDATA[<A HREF="/useremail/u/326716"><b>redxii</b></A> : <div class="bquote"><SMALL>said by  psloss <A HREF="/useremail/u/590688"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Yeah, that's not good about the updater, although this type of escalation opportunity is still not at the top of the list in terms of taking over control of a Windows box these days.<br> </DIV>It's still an opportunity, and should be fixed.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15603802</guid>
<pubDate>Fri, 03 Mar 2006 12:45:52 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15603395</link>
<description><![CDATA[<A HREF="/useremail/u/590688"><b>psloss</b></A> : <div class="bquote"><SMALL>said by  redxii <A HREF="/useremail/u/326716"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>psloss, I already indicated that I was using 7.1 Free edition</DIV>Sorry, went right over that in your original post.  My bad.<br><br>Yeah, that's not good about the updater, although this type of escalation opportunity is still not at the top of the list in terms of taking over control of a Windows box these days.<br><br>A more interesting test would be to try to run this on the latest Vista CTP, though I don't know if AVG is compatible or not (i.e., will even install).<br><br>Philip Sloss<br><SMALL>--<br>Feedback? e-mail: stuff@lupwa.org</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15603395</guid>
<pubDate>Fri, 03 Mar 2006 11:45:08 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15603186</link>
<description><![CDATA[<A HREF="/useremail/u/326716"><b>redxii</b></A> : I found 7.0.308, and then updated it in the limited user. Apparently AVG's drivers are affected too!<br><br>Hopefully I am not the only one that sees a problem with this...<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15603186?c=975894&ret=L2ZvcnVtL3IxNTYwMzE4Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="71251 bytes" WIDTH=600 HEIGHT=450 SRC="/r0/download/975894.thumb600~9542e8fce0bcc2e5a0ad5ba8e50087af/accessenum.png/thumb.jpg" ALT="Click for full size"></A><br>Results for \WINDOWS</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15603186?c=975895&ret=L2ZvcnVtL3IxNTYwMzE4Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="72227 bytes" WIDTH=600 HEIGHT=450 SRC="/r0/download/975895.thumb600~d58ca2fa6d2951ef4b2f4abf6de4aefa/accessenum2.png/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15603186?c=975896&ret=L2ZvcnVtL3IxNTYwMzE4Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="71342 bytes" WIDTH=600 HEIGHT=450 SRC="/r0/download/975896.thumb600~6ba1d0ea083b8109facdfe6dfaad0ef6/accessenum22.PNG/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15603186?c=975897&ret=L2ZvcnVtL3IxNTYwMzE4Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="107940 bytes" WIDTH=600 HEIGHT=450 SRC="/r0/download/975897.thumb600~3487e4dd7fe01cd88c2ed61a63233bd3/newperms.png/thumb.jpg" ALT="Click for full size"></A><br>avg7core.sys</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15603186?c=975898&ret=L2ZvcnVtL3IxNTYwMzE4Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="101731 bytes" WIDTH=600 HEIGHT=450 SRC="/r0/download/975898.thumb600~d6613fba6d203ad188947bcc10c1d9ff/newowner.PNG/thumb.jpg" ALT="Click for full size"></A><br>A limited account is owner of a driver.....</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15603186</guid>
<pubDate>Fri, 03 Mar 2006 11:14:38 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15602974</link>
<description><![CDATA[<A HREF="/useremail/u/326716"><b>redxii</b></A> : That'd be avgcc.exe and it runs as the current user.<br><br>psloss, I already indicated that I was using 7.1 Free edition<br><br>I posted in the AVG forum and the best response so far was "Make sure it isn't conflicting with KAV." First of all, there was and is no KAV on the machine in the pics and on my computer. I have KAV on <I>other</I> machines.<br><br>If someone has an 7.<B>0</B> setup file, please do send...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15602974</guid>
<pubDate>Fri, 03 Mar 2006 10:47:16 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15602064</link>
<description><![CDATA[<A HREF="/useremail/u/590688"><b>psloss</b></A> : Hmmm...well, I got the same thing on an MCE 2005 test install (with no subsequent OS/security updates) -- at least in terms of changing the security descriptors on those files (the .avg update files were also changed to be equally permissive).<br><br>(This is with the free edition, version 7.1.375a716.)<br><br>Unfortunately, some part of AVG also crashed and it began flagging some of its own files and some OS files as being infected.  Going to have to retry now from the top to see if that was a transient.<br><SMALL>--<br>Feedback? e-mail: stuff@lupwa.org</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15602064</guid>
<pubDate>Fri, 03 Mar 2006 07:47:57 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15602008</link>
<description><![CDATA[<A HREF="/useremail/u/590688"><b>psloss</b></A> : Not sure it matters (aside from a testing standpoint), but which version of AVG?  (Free, trial, ???)<br><br>Thanks,<br><br>Philip Sloss<br><SMALL>--<br>Feedback? e-mail: stuff@lupwa.org</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15602008</guid>
<pubDate>Fri, 03 Mar 2006 07:28:44 EDT</pubDate>
</item>

<item>
<title>Re: AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15601731</link>
<description><![CDATA[<A HREF="/useremail/u/1001074"><b>toadlife</b></A> : Bad developers!<br><br>Since AVG's developers seem to lack a clue, another thing to check for is weather or not AVG's tray icon (I assume it has one) is displayed by a service with SYSTEM rights. This opens the machine up to a shatter attack.<br><br>That's getting a little tinfoil hat-ish though. I've never heard of malware that actually used shatter attacks.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15601731</guid>
<pubDate>Fri, 03 Mar 2006 04:33:43 EDT</pubDate>
</item>

<item>
<title>AVG updates grant full control to Everyone, changes owner?</title>
<link>http://www.dslreports.com/forum/remark,15601404</link>
<description><![CDATA[<A HREF="/useremail/u/326716"><b>redxii</b></A> : I'm doing some auditing of permissions with AccessEnum, and was shocked to find out that my user was the owner of some of the files that belong to AVG, and that "Everyone" was set to Full Control. So I reset the permissions, and everything is set to \Program Files\ inheritance, and the owner back to "Administrator". Then I updated AVG. It changed "upd_vers.cfg" and "incavi.avm". I looked at them after the update, and sure enough I was the owner again and Everyone had Full Control.<br><br>The update service runs as SYSTEM, but so does Kaspersky's but Kaspersky 5 does not exhibit this behavior under a limited account. No permissions are changed in KAV.<br><br>I'm runnning:<br>AVG Free 7.1<br>XP Pro<br>limited account, NTFS<br><br>I don't know if the drivers for AVG in system32\drivers are affected, I hadn't checked, but more than likely they are. That is just asking for someone to replace one of AVG's sys files with a rootkit and launching at next boot..<br><br>EDIT: Added pics. These were all done in the context of a limited user (LowPriv).<br><br>Before updating:<br><br>[att=1][att=2]<br><br>After updating:<br><br>[att=3][att=4]<br><br>Accounts:<br>Administrator: Administrator<br>Limited User: LowPriv<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15601404?c=975788&ret=L2ZvcnVtL3IxNTYwMzE4Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="513464 bytes" WIDTH=600 HEIGHT=450 SRC="/r0/download/975788.thumb600~5d6186b1d204e15fb6911cfc0f890141/defaultperms.png/thumb.jpg" ALT="Click for full size"></A><br>Default Permissions</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15601404?c=975789&ret=L2ZvcnVtL3IxNTYwMzE4Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="506302 bytes" WIDTH=600 HEIGHT=450 SRC="/r0/download/975789.thumb600~63a3772d6b918e35b2ca58666f64519a/defaultowner.png/thumb.jpg" ALT="Click for full size"></A><br>Default Owner</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15601404?c=975790&ret=L2ZvcnVtL3IxNTYwMzE4Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="517153 bytes" WIDTH=600 HEIGHT=450 SRC="/r0/download/975790.thumb600~3487e4dd7fe01cd88c2ed61a63233bd3/newperms.png/thumb.jpg" ALT="Click for full size"></A><br>Permissions after update</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15601404?c=975791&ret=L2ZvcnVtL3IxNTYwMzE4Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="510248 bytes" WIDTH=600 HEIGHT=450 SRC="/r0/download/975791.thumb600~2c17f25daf98bfeb8373aeb7a673b253/newowner.png/thumb.jpg" ALT="Click for full size"></A><br>The limited user is now the owner, multiply this by a major AVG update...</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15601404</guid>
<pubDate>Fri, 03 Mar 2006 02:05:48 EDT</pubDate>
</item>

</channel>
</rss>
