<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Cnet tells users 100% guarantee infection in Security</title>
<link>http://www.dslreports.com/forum/r21673856</link>
<description></description>
<language>en</language>
<pubDate>Wed, 09 Dec 2009 22:12:22 EDT</pubDate>
<lastBuildDate>Wed, 09 Dec 2009 22:12:22 EDT</lastBuildDate>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21685309</link>
<description><![CDATA[<A HREF="/useremail/u/465004"><b>ironwalker</b></A> : <div class="bquote"><small>said by  Smokey Bear <A HREF="/useremail/u/1537340"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br><div class="bquote"><small>said by  DarkSithPro <A HREF="/useremail/u/1157962"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>cnet.com<br>Under lock and key<br><br>No matter how savvy of a computer user you are, your computer will be the victim of malware or a virus at some point.<br><br>Pretty bold statement from cnet. What do you guys think?<br> </div>As long people don't download malware from CNET/download.com servers there is a possibilty they remain clean. CNET still offer malware for download.....<br><br><small><i>Edited: typo</i></small><br> </div>Agreed!<br>Why people use these 3rd party download offers is beyond me.<br>I always go to authers site or company's site and if the 3rd party links are affiliated with them I use them, but, only if on the auther/company's site.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21685309</guid>
<pubDate>Mon, 05 Jan 2009 15:38:53 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21681243</link>
<description><![CDATA[<A HREF="/useremail/u/817075"><b>Kiwi</b></A> : I considered the OP topic amusing, as I used to use the CNET downloads to verify new malware, they allowed on their site. Nothing much has changed, it's still malware hell; I suggest they lock their site up and throw away the key.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21681243</guid>
<pubDate>Sun, 04 Jan 2009 19:52:06 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21680374</link>
<description><![CDATA[<A HREF="/useremail/u/937688"><b>FunnyBones</b></A> : I know someone who only uses a live dvd for online with no drives mounted so I agree BS.  :)<br><small>--<br>Are you part of the cattle?</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21680374</guid>
<pubDate>Sun, 04 Jan 2009 16:43:50 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21680048</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : Of course, how do they define "infection?"  Someone could have inactive malware sitting in their browser cache, for example.  Does that count as "infection" by CNet?<br><br>I for one have never had any of my systems infected, except for one time with adware (due to someone else using the computer).  And I've had my AV flag things in my browser cache during a scan, but nothing was active.  So, would I be part of that "100%"?  :D<br><small>--<br>To ISPs:  Leave our ports alone!  If I want ports blocked, I'll do it myself, thank you.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21680048</guid>
<pubDate>Sun, 04 Jan 2009 15:36:13 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21679583</link>
<description><![CDATA[<A HREF="/useremail/u/851210"><b>VirtualLarry</b></A> : <div class="bquote"><small>said by  Woody79_00 <A HREF="/useremail/u/1037783"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>The gist of the matter is that the checking of Software Restriction Policy is done in USER MODE in the process which issued the CreateProcess/LoadLibrary call. This means that the current process can patch itself so that SRP isn't correctly verified. Mark did this by intercepting reads to the Registry (where SRP policies are stored) and returning fake results, Didier did this by searching the registry key names and replacing them with bogus ones (so registry reads would fail.<br><br>Mark Russonivich wrote a program that would allow the disabling of Software Restiction Policy by a "Limited User" without admin rights required </div>But how can a process patch itself, if it isn't running? The point is, somehow, code has to execute, in order to patch around, the code that blocks code from executing.<br>It seems like a catch-22 to me.<br><br>If you want to run proof-of-concept code, fine, but that requires a program that is already allowed to run.<br><br>Are those programs accessable from the internet in some way that would allow that code to run, when prompted by a remote source? If not, then I would say that SRP is very secure.<br><br>For example, assume (I didn't read it) that the program that Mark wrote to bypass SRP was itself an executable. As a limited user running under SRP, how are you going to get that .exe to run, in order to patch SRP, to allow .exes to run? You can't execute it directly out of any directories that you have write access to, and only an admin has write access to the Program Files and Windows directories.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21679583</guid>
<pubDate>Sun, 04 Jan 2009 14:11:56 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21679478</link>
<description><![CDATA[<A HREF="/useremail/u/1537340"><b>Smokey Bear</b></A> : <div class="bquote"><small>said by  dadkins <A HREF="/useremail/u/879997"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Yes! <br>Exactly!<br>Adware, not "dishonest adware", is a part of many people's daily life.<br>In and of itself, "adware" is not malicious and therefore not malware.<br><br>Now, some are more agressive than others, but I am OK with FlashGet as they/it provide(s) a way to turn it off. <br><br> </div>Like you say, concerning FlashGet it isn't "dishonest adware" or "unwanted software", especially not because you was informed about the adware in it and accepted it as part of the "deal".  :)<br><small>--<br>Smokey's Security Forums &raquo;<A HREF="http://www.smokey-services.eu/forum/" >www.smokey-services.eu/forum/</A><br>Smokey's Security Weblog &raquo;<A HREF="http://smokeys.wordpress.com/" >smokeys.wordpress.com/</A><br><i>Site Member ASAP - Alliance of Security Analysis Professionals</i></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21679478</guid>
<pubDate>Sun, 04 Jan 2009 13:52:56 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21679194</link>
<description><![CDATA[<A HREF="/useremail/u/879997"><b>dadkins</b></A> : Yes! <br>Exactly!<br>Adware, not "dishonest adware", is a part of many people's daily life.<br>In and of itself, "adware" is not malicious and therefore not malware.<br><br>Adware is more in the class of shareware than anything bad.<br>Free with advertisements as opposed to popup adware/redirects/hijackers that is only there to deliver ads.<br><br>&raquo;<A HREF="http://en.wikipedia.org/wiki/Adware" >en.wikipedia.org/wiki/Adware</A><br><br>"Adware or advertising-supported software is any software package which automatically plays, displays, or downloads advertisements to a computer after the software is installed on it or while the application is being used."<br><br>Now, some are more agressive than others, but I am OK with FlashGet as they/it provide(s) a way to turn it off. <br>:)<br><small>--<br>Think outside the Fox... <A HREF="http://www.opera.com/">Opera</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21679194</guid>
<pubDate>Sun, 04 Jan 2009 12:27:41 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21679188</link>
<description><![CDATA[<A HREF="/useremail/u/810471"><b>Nanoprobe</b></A> : <div class="bquote"><small>said by  DarkSithPro <A HREF="/useremail/u/1157962"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>cnet.com<br>Under lock and key<br><br>No matter how savvy of a computer user you are, your computer will be the victim of malware or a virus at some point.<br><br>Pretty bold statement from cnet. What do you guys think?<br> </div><br><small>--<br>Two things are infinite: the universe and human stupidity; and I'm not sure about the universe. Albert Einstein<br><br></small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap WIDTH=33%><A HREF="/speak/slideshow/21679188?c=1386565&ret=L2ZvcnVtL3IyMTY3Mzg1Ni54bWw%3D"><IMG TITLE="5202 bytes" BORDER=0 WIDTH=50 HEIGHT=50 SRC="/r0/download/1386565~7635863768e43545a56f30b0b3a47083/BS.gif"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21679188</guid>
<pubDate>Sun, 04 Jan 2009 12:26:26 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21678826</link>
<description><![CDATA[<A HREF="/useremail/u/1037783"><b>Woody79_00</b></A> : No Blackbird, i wasn't directing thart assertion at you in particualr, i just happen to click your name on the reply button. You brought up some very good points blackbird and I don't disagree with them at all. <br><br>you smart enough to know that it takes "layers" to do the best you can to prevent it, some folks belive otherwise but you are not 1 of those folks I can clearly tell.<br><br>Virtual Larry:<br><br>The gist of the matter is that the checking of Software Restriction Policy is done in USER MODE in the process which issued the CreateProcess/LoadLibrary call. This means that the current process can patch itself so that SRP isn't correctly verified. Mark did this by intercepting reads to the Registry (where SRP policies are stored) and returning fake results, Didier did this by searching the registry key names and replacing them with bogus ones (so registry reads would fail.<br><br>Mark Russonivich wrote a program that would allow the disabling of Software Restiction Policy by a "Limited User" without admin rights required<br><br>&raquo;<A HREF="http://blogs.technet.com/markrussinovich/archive/2005/12/12/circumventing-group-policy-as-a-limited-user.aspx" >blogs.technet.com/markrussinovic&middot;&middot;&middot;ser.aspx</A><br><br>Didier Stevens took this to the next level as recently as March of 2008 <br><br>&raquo;<A HREF="http://blog.didierstevens.com/2008/03/06/bpmtk-replacing-gpdisable/" >blog.didierstevens.com/2008/03/0&middot;&middot;&middot;disable/</A><br><br>&raquo;<A HREF="http://blog.didierstevens.com/2008/02/28/introducing-the-basic-process-manipulation-tool-kit/" >blog.didierstevens.com/2008/02/2&middot;&middot;&middot;ool-kit/</A><br><br>&raquo;<A HREF="http://hype-free.blogspot.com/2008/10/limitations-of-software-restriction.html" >hype-free.blogspot.com/2008/10/l&middot;&middot;&middot;ion.html</A><br><br>Software Restriction Policies are just a layer..execution prevention is not the end all protection...once it becomes popualr enough that Malware Authors have to take it into account, it can be bypassed like anything else.<br><br> even on the Nix boxes I maintain for I know there are ways around the firewalls, no firewall is full-proof, The recent router crash test is an exmaple of this.<br><br>I am just saying once you become aware of the realitty of the computer world it gets much easier...<br><br>I think the best rule of thumb is to always use your computer with the mindset that you "may" be compromised...this will promote safer computing practices overall. that's the only point I am trying to make. <br><br>No matter what OP system you use, you should always use layers...layers are like locks...make them go though a few hoops to get in...but locks on computers are like locks in reali life. Locks only keep honest people out. If   some bad guy wants in bad enough, he will get in...its just the nature of the world.<br><br>Good reads nonetheless ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21678826</guid>
<pubDate>Sun, 04 Jan 2009 10:47:22 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21678756</link>
<description><![CDATA[<A HREF="/useremail/u/1537340"><b>Smokey Bear</b></A> : <b>Wikipedia definition malware:</b><br><br>Malware, a portmanteau from the words malicious and software, is software designed to infiltrate or damage a computer system without the owner's informed consent. The expression is a general term used by computer professionals to mean a variety of forms of hostile, intrusive, or annoying software or program code.<br><br>Many computer users are unfamiliar with the term, and often use "computer virus" for all types of malware, including true viruses.<br><br>Software is considered malware based on the perceived intent of the creator rather than any particular features. Malware includes computer viruses, worms, trojan horses, most rootkits, spyware, dishonest adware, crimeware and other malicious and unwanted software. In law, malware is sometimes known as a computer contaminant, for instance in the legal codes of several American states, including California and West Virginia.<br><br>Malware is not the same as defective software, that is, software which has a legitimate purpose but contains harmful bugs.<br><br>&raquo;<A HREF="http://en.wikipedia.org/wiki/Malware" >en.wikipedia.org/wiki/Malware</A><br><small>--<br>Smokey's Security Forums &raquo;<A HREF="http://www.smokey-services.eu/forum/" >www.smokey-services.eu/forum/</A><br>Smokey's Security Weblog &raquo;<A HREF="http://smokeys.wordpress.com/" >smokeys.wordpress.com/</A><br><i>Site Member ASAP - Alliance of Security Analysis Professionals</i></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21678756</guid>
<pubDate>Sun, 04 Jan 2009 10:23:55 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21678711</link>
<description><![CDATA[<A HREF="/useremail/u/723836"><b>33591094</b></A> : I haven't been gotten to yet, cnet...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21678711</guid>
<pubDate>Sun, 04 Jan 2009 10:09:29 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21678658</link>
<description><![CDATA[<A HREF="/useremail/u/879997"><b>dadkins</b></A> : <div class="bquote"><small>said by  james <A HREF="/useremail/u/326902"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>I'd say it's a safe statement to make.<br>Who here can honestly say they have NEVER had to remove a virus or adware from one of their computers?<br>If they were claiming that every computer was at this moment infected, then they'd be wrong.<br> </div>Me! Never had a virus. Period.<br>Adware? Hell, I have purposely installed adware, some adware is pre-installed by computer manufacturers. <br><br>The page doesn't say adware, it's malware. <br>"No matter how savvy of a computer user you are, your computer will be the victim of malware or a virus at some point."<br><small>--<br>Think outside the Fox... <A HREF="http://www.opera.com/">Opera</a></small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/21678658?c=1386527&ret=L2ZvcnVtL3IyMTY3Mzg1Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="245123 bytes" WIDTH=600 HEIGHT=501 SRC="/r0/download/1386527.thumb600~940ff34957f06a7fba62392ca8cdfa9a/ScreenShot013.jpg/thumb.jpg" ALT="Click for full size"></A><br>ONOES!!1 Ads!</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/21678658?c=1386528&ret=L2ZvcnVtL3IyMTY3Mzg1Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="182319 bytes" WIDTH=600 HEIGHT=501 SRC="/r0/download/1386528.thumb600~91d9e68a89b5b831179805677b0967c5/ScreenShot014.jpg/thumb.jpg" ALT="Click for full size"></A><br>Turn off ads and use program anyways. ;-)</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21678658</guid>
<pubDate>Sun, 04 Jan 2009 09:55:30 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21677844</link>
<description><![CDATA[<A HREF="/useremail/u/851210"><b>VirtualLarry</b></A> : <div class="bquote"><small>said by  Woody79_00 <A HREF="/useremail/u/1037783"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>As recently as October of 2008 Windows Software Restriction Policies and Programs like Faronics Anti-Executable can be bypassed by Malware Via "Patching in memory" certain functions and key values in kernel32.dll amongs others, in turn "intercepting" the point of the check and giving errors or "fake values" allowing the executable to run.It still hasn't been patched. </div>But doesn't it require admin privs for that process, to do the in-memory patching of kernel32.dll?<br><br>IOW, if you're running as admin, and malware gets a chance to execute on your machine, you're hosed and likely need a rebuild of the OS to ensure you got rid of it.<br><br>But running as a limited user, in conjunction with Software Restriction Polices, can form a virtually bullet-proof shield against malware getting in in the first place. And that's the whole point.<br><br>So I think that you are spreading FUD by suggesting that these very valid security procedures are useless.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21677844</guid>
<pubDate>Sun, 04 Jan 2009 01:10:15 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21677687</link>
<description><![CDATA[<A HREF="/useremail/u/1140294"><b>Blackbird</b></A> : <div class="bquote"><small>said by  Woody79_00 <A HREF="/useremail/u/1037783"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>No computer is 100% secure... Even though Linux is the most secure of the 3 mentioned, it can be compromised like any other operating system if a person is not careful.<br><br>I do find it humerous though how many people believe that Software Restriction Policies, and certain programs like Faronics Anti-Executable and other execution protection softare will protect them from all danger...<br> </div>If you're directing that latter assertion at me, it's not what I said - or at least, it's not the meaning I intended to convey. My intended point was that there are a number of layered tools and practices (which I consider to fall under the umbrella of "safe hex") that acting together render penetration extremely unlikely... of which using a Deep-Freeze kind of tool happens to be a significant one (but by no means the only one - your Tripwire approach being an alternative case in point). And I don't use either product. Frankly, my core belief is that how a person uses a computer and what he does with it will have far more influence on infectability than anything else. There have been a number of posts in this thread already by users who have used computers for years and never been infected; and there's nothing yet in this thread to cause me to believe that will all suddenly change for them over the next month, or year, or even decade. And it <b>must</b> change if the article's statement is correct.<br><br>Stating that users' computers will all eventually be infected (as the article essentially does) is a far different thing from stating, as you did, that "no computer is 100% secure". No car is 100% secure against theft either, yet not all will be stolen. No house is 100% secure against burglary, yet not all will be victimized. No encryption scheme is 100% secure from cracking, yet most encrypted information will not be compromised. What would be an accurate statement is that computers, rarely being 100% secure in and of themselves, are far more likely to be infected than computers operated with knowledgeable and secure methodologies, using a variety of well-reasoned protective tools - either hardware or software.<br><br>Terms like never, always, 100%, "will" - these are categorical expressions, and lend themselves more to hype and hysteria than to reasoned comparisons and evaluations. To falsify the article's statement, I need only to place a pristine computer disconnected from any wiring into a sealed container, surround it with concrete, and have somebody dig it up in 100 years... I feel completely safe in stating it will still be uninfected. Absurd? Certainly. But it's all about context, isn't it? And context dissolves and undercuts categorical "certainty"...<br><small>--<br>If God wanted us to work with electrons, He'd make them big enough to see...</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21677687</guid>
<pubDate>Sun, 04 Jan 2009 00:25:16 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21677279</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : <div class="bquote"><small>said by  HFB1217 <A HREF="/useremail/u/167991"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>A new form of birth control don't let Bill find out or he may charge for it as well.<br> </div>It could give a whole new meaning to trojans and infections...<br><small>--<br>The greatest dangers to liberty lurk in insidious encroachment by men of zeal, well-meaning but without understanding. -- Justice Louis D. Brandeis</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21677279</guid>
<pubDate>Sat, 03 Jan 2009 22:20:37 EDT</pubDate>
</item>

<item>
<title>Re: Cnet download</title>
<link>http://www.dslreports.com/forum/remark,21676831</link>
<description><![CDATA[<A HREF="/useremail/u/1531837"><b>Its a Secret</b></A> : <div class="bquote"><small>said by  Smokey Bear <A HREF="/useremail/u/1537340"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>...how many other malicious programs are offered by CNET? </div> That's a very good question. I haven't DL'd from cnet/ download.com in years, but I know people who do. I'll have to let 'em know.<br><br>But it is very irresponsible to allow this to happen.<br><small>--<br>"In the future, that which is not mandatory will be illegal"</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21676831</guid>
<pubDate>Sat, 03 Jan 2009 20:37:04 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21676828</link>
<description><![CDATA[<A HREF="/useremail/u/1037783"><b>Woody79_00</b></A> : No computer is 100% secure. Not Linux, not Windows, and not MAC. Even though Linux is the most secure of the 3 mentioned, it can be compromised like any other operating system if a person is not careful.<br><br>I do find it humerous though how many people believe that Software Restriction Policies, and certain programs like Faronics Anti-Executable and other execution protection softare will protect them from all danger...when Mark Russonvich proved this not to be the case at all and quite some time ago<br><br>As recently as October of 2008 Windows Software Restriction Policies and Programs like Faronics Anti-Executable can be bypassed by Malware Via "Patching in memory" certain functions and key values in kernel32.dll amongs others, in turn "intercepting" the point of the check and giving errors or "fake values" allowing the executable to run.It still hasn't been patched.<br><br>you can read bout this here.<br><br>&raquo;<A HREF="http://hype-free.blogspot.com/2008/10/limitations-of-software-restriction.html" >hype-free.blogspot.com/2008/10/l&middot;&middot;&middot;ion.html</A><br><br>the findings are quite telling...how do you know a piece of malware hasn't done this allready? many keyloggers or postloggers(A key logger that actually takes screen shots of your entire screen) will NOT:<br><br>1. slow down your system<br>2. leave any trace whatsoever they are even present<br><br>The malware that Symantec, McAfee and other deem of a quality of "software engineer" are not going to be detected or noticed very easily if at all.<br><br>IMO the only way to reliably detect malware on a system is to throw out signatuares and heuristics and go to "port monitoring"<br><br>In other words, all maware listens to or talks though a port...the security vendors need to focus on this aspect more than anything...even a rookit malware needs to talk on a port or it is useless<br><br>why doesn't Windows have something like Tripwire for Linux? if "anything" has been changed, you will know about it...this is more important then anything else<br><br>I run Tripwire and build my hashes<br><br>I check them once a day<br><br>Before I do a patch update, I run Tripwire and check it<br><br>If vlaues come back ok, I patch my system<br><br>I then rebuild my tripwire database <br><br>this way if "anything" has changed that I did explicitly change, I will know about it....and that is how I can tell if I have been had...Windows has no such thing<br><br>When I 1st started using Linux, I got hacked when I 1st started learning Apache Web Server, didn't have it configured correctly....but since then, I run a few of them for folks and have had no such issues, but I do maintain them..but even with it, its a constant battle<br><br>It would be nice if windows had something like Tripwire..where you  could<br><br>1. Install clean OS.<br>2. Patch and update all apps<br>3. Build tripwire data base<br><br>Every month before patching run tripwire and if all is A ok, patch then rebuild your data base<br><br>This would be the 1 sure fire way to be sure your not compromised, not to mention RKHunter and ChkRoot kit also look for ports that are listening and such and give you a good indicator of where you stand<br><br>Windows needs something like this! I don't just mean netstat, ipconfig or any of that...but something like Tripwire]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21676828</guid>
<pubDate>Sat, 03 Jan 2009 20:35:50 EDT</pubDate>
</item>

<item>
<title>Re: Cnet download</title>
<link>http://www.dslreports.com/forum/remark,21676790</link>
<description><![CDATA[<A HREF="/useremail/u/1537340"><b>Smokey Bear</b></A> : <div class="bquote"><small>said by  FiOS Dan <A HREF="/useremail/u/424692"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Damn disturbing about cnet. I always assuming they screened software before offering it on their site.  :mad:<br> </div>Apparently not. Many people rely on and trust CNET/download.com, obvious all the time they are wrong with their confidence. And now the main question: beside Intelinet Internet Security rogue anti-spyware, how many other malicious programs are offered by CNET?<br><small>--<br>Smokey's Security Forums &raquo;<A HREF="http://www.smokey-services.eu/forum/" >www.smokey-services.eu/forum/</A><br>Smokey's Security Weblog &raquo;<A HREF="http://smokeys.wordpress.com/" >smokeys.wordpress.com/</A><br><i>Site Member ASAP - Alliance of Security Analysis Professionals</i></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21676790</guid>
<pubDate>Sat, 03 Jan 2009 20:28:05 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21676760</link>
<description><![CDATA[<A HREF="/useremail/u/326902"><b>james</b></A> : I'd say it's a safe statement to make.<br>Who here can honestly say they have NEVER had to remove a virus or adware from one of their computers?<br>If they were claiming that every computer was at this moment infected, then they'd be wrong.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21676760</guid>
<pubDate>Sat, 03 Jan 2009 20:21:29 EDT</pubDate>
</item>

<item>
<title>Re: Cnet download</title>
<link>http://www.dslreports.com/forum/remark,21676733</link>
<description><![CDATA[<A HREF="/useremail/u/424692"><b>FiOS Dan</b></A> : Damn disturbing about cnet. I always assuming they screened software before offering it on their site.  :mad:<br><small>--<br><i>Courage is being scared to death but saddling up anyway.</i><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21676733</guid>
<pubDate>Sat, 03 Jan 2009 20:17:22 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21676723</link>
<description><![CDATA[<A HREF="/useremail/u/879997"><b>dadkins</b></A> : One doesn't need to install more than one AV(it's not wise anyways).<br>You can run a online scanner like Housecall or Kaspersky without adverse affects to check if your AV is doing it's job - I do occasionallly.  ;)<br><br>No comment on Norton.  :huh:<br><br>Worst thing thet gets found here is cookies. <br>Cookies don't worry me and scanners can remove as many as they see fit - I'll get more! LOL!  :o<br><small>--<br>Think outside the Fox... <A HREF="http://www.opera.com/">Opera</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21676723</guid>
<pubDate>Sat, 03 Jan 2009 20:15:59 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21676012</link>
<description><![CDATA[<A HREF="/useremail/u/167991"><b>HFB1217</b></A> : <div class="bquote"><small>said by  EGeezer <A HREF="/useremail/u/668609"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>I didn't see the 100% guarantee thing when I went to the CNet download site. <br><br>I did find <A HREF="http://news.cnet.com/8301-13772_3-10123138-52.html?tag=TOCmoreStories.0"><b>this interesting story</b></a> though. :D <br> </div>A new form of birth control don't let Bill find out or he may charge for it as well.<br><small>--<br><b>****aka The</b><b> WIZARD</b><b><i> *** A Founding member of Seti BBR Team Starfire***</i></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21676012</guid>
<pubDate>Sat, 03 Jan 2009 17:34:12 EDT</pubDate>
</item>

<item>
<title>Re: Cnet download</title>
<link>http://www.dslreports.com/forum/remark,21675924</link>
<description><![CDATA[<A HREF="/useremail/u/1537340"><b>Smokey Bear</b></A> : <div class="bquote"><small>said by  Thug21 <A HREF="/useremail/u/1251385"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>I tend to agree - I was being sarcastic with the "cure" part of it.  :D<br> </div>Txs for understanding, because the cure can even be worse than the the infection caused by the downloaded and installed malware...  :uhh:<br><small>--<br>Smokey's Security Forums &raquo;<A HREF="http://www.smokey-services.eu/forum/" >www.smokey-services.eu/forum/</A><br>Smokey's Security Weblog &raquo;<A HREF="http://smokeys.wordpress.com/" >smokeys.wordpress.com/</A><br><i>Site Member ASAP - Alliance of Security Analysis Professionals</i></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21675924</guid>
<pubDate>Sat, 03 Jan 2009 17:15:38 EDT</pubDate>
</item>

<item>
<title>Re: Cnet download</title>
<link>http://www.dslreports.com/forum/remark,21675900</link>
<description><![CDATA[<A HREF="/useremail/u/1251385"><b>Thug21</b></A> : I tend to agree - I was being sarcastic with the "cure" part of it.  :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21675900</guid>
<pubDate>Sat, 03 Jan 2009 17:10:31 EDT</pubDate>
</item>

<item>
<title>Re: Cnet download</title>
<link>http://www.dslreports.com/forum/remark,21675840</link>
<description><![CDATA[<A HREF="/useremail/u/1537340"><b>Smokey Bear</b></A> : <div class="bquote"><small>said by  Thug21 <A HREF="/useremail/u/1251385"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Seems to me that CNET can both the cause and cure  :D<br><br>Pretty cool if you ask me (or even if you don't!).  :)<br> </div>With the cause I agree, regrettably not with the cure: &raquo;<A HREF="http://smokeys.wordpress.com/2008/12/31/cnets-downloadcom-offer-rogue-anti-spyware-for-download/" >smokeys.wordpress.com/2008/12/31&middot;&middot;&middot;ownload/</A><br><small>--<br>Smokey's Security Forums &raquo;<A HREF="http://www.smokey-services.eu/forum/" >www.smokey-services.eu/forum/</A><br>Smokey's Security Weblog &raquo;<A HREF="http://smokeys.wordpress.com/" >smokeys.wordpress.com/</A><br><i>Site Member ASAP - Alliance of Security Analysis Professionals</i></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21675840</guid>
<pubDate>Sat, 03 Jan 2009 16:55:28 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21675764</link>
<description><![CDATA[<A HREF="/useremail/u/1140294"><b>Blackbird</b></A> : The statement's too categorical: "No matter how savvy of a computer user you are, your computer will be the victim of malware or a virus at some point". As it stands, I believe it's incorrect. Admittedly, for <b>many</b> folks it <i>will</i> apply, because of their own security (mis?)behavior and/or because of vulnerabilities in their software. But if somebody's using a decent firewall, correctly running something like Deep Freeze or a quality anti-executable program <i>and</i> is applying educated "safe hex" otherwise, it's hard to imagine how that statement could apply to them in actuality. <br><br>Of course categorical statements <b>do</b> generate headlines and clicks... and revenue...<br><small>--<br>If God wanted us to work with electrons, He'd make them big enough to see...</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21675764</guid>
<pubDate>Sat, 03 Jan 2009 16:33:40 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21675705</link>
<description><![CDATA[<A HREF="/useremail/u/260736"><b>Vampirefo</b></A> : just fud]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21675705</guid>
<pubDate>Sat, 03 Jan 2009 16:16:59 EDT</pubDate>
</item>

<item>
<title>Re: Cnet download</title>
<link>http://www.dslreports.com/forum/remark,21675700</link>
<description><![CDATA[<A HREF="/useremail/u/1251385"><b>Thug21</b></A> : Seems to me that CNET can both the cause and cure  :D<br><br>Pretty cool if you ask me (or even if you don't!).  :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21675700</guid>
<pubDate>Sat, 03 Jan 2009 16:16:00 EDT</pubDate>
</item>

<item>
<title>Re: Cnet download</title>
<link>http://www.dslreports.com/forum/remark,21675693</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> :  <blockquote><small>quote:</small><hr>No matter how savvy of a computer user you are, your computer will be the victim of malware or a virus at some point.<hr></blockquote> <br><br>After a quick review of one CNET offering, <br><br> &raquo;<A HREF="http://www.download.com/Intelinet-Spyware-Remover/3000-8022_4-10888927.html" >www.download.com/Intelinet-Spywa&middot;&middot;&middot;927.html</A> <br><br>I can see where the statement might be true - if you trust CNET for your downloads. <br><br>See &raquo;<A HREF="/forum/r21642028-Intelinet-Internet-Security-definitive-malware">Intelinet Internet Security: definitive malware</A> <br><br>;) <br><small>--<br>The greatest dangers to liberty lurk in insidious encroachment by men of zeal, well-meaning but without understanding. -- Justice Louis D. Brandeis</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21675693</guid>
<pubDate>Sat, 03 Jan 2009 16:14:40 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21675673</link>
<description><![CDATA[<A HREF="/useremail/u/401196"><b>pandora</b></A> : I tend to agree with the statement. For years I ran Norton Internet security, and felt it was doing a great job. Then ran trendmicro's housecall and it found stuff.<br><br>My guess is we are all infected with something, as there are limits to the number of AV products we can install at any time.<br><br>I note another PC which had McAfee scan it as clean, was also found to have malware on it by trendmicro.<br><br>IMO the people most likely to be infected are the non-paranoids who feel confident they aren't infected. <br><br>If you really aren't going to be infected, you've got to run with scripting disabled, and maybe with a text only browser. Not many will do this, anyone really paranoid probably won't be claiming to have a free from malware PC as they're too busy making sure it is clean.<br><small>--<br>"People demand freedom of speech as a compensation for the freedom of thought which they seldom use."</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21675673</guid>
<pubDate>Sat, 03 Jan 2009 16:09:06 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21675604</link>
<description><![CDATA[<A HREF="/useremail/u/879997"><b>dadkins</b></A> : So far, even with countless downloads from Cnet and the like, not one virus.<br><br>Now, I have never proclaimed, and I am still not proclaiming, to be a Security Guru of any sort. <br><br> :huh:<br><small>--<br>Think outside the Fox... <A HREF="http://www.opera.com/">Opera</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21675604</guid>
<pubDate>Sat, 03 Jan 2009 15:53:06 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21675543</link>
<description><![CDATA[<A HREF="/useremail/u/1293405"><b>Jodokast96</b></A> : Nothing surprising there.  The women weren't having sex anyway, for whatever the reason is this week, while the guys were the ones not having sex with any of those women.  The rest of the guys just got some on the side.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21675543</guid>
<pubDate>Sat, 03 Jan 2009 15:39:48 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21675523</link>
<description><![CDATA[<A HREF="/useremail/u/1004057"><b>Kerodo</b></A> : Well.... I have been online for over 12 years now, doing all manner of things, unsavory as well, and have never once been the "victim" of malware or a virus.  So go figure... :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21675523</guid>
<pubDate>Sat, 03 Jan 2009 15:35:49 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21675479</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : I didn't see the 100% guarantee thing when I went to the CNet download site. <br><br>I did find <A HREF="http://news.cnet.com/8301-13772_3-10123138-52.html?tag=TOCmoreStories.0"><b>this interesting story</b></a> though. :D <br><small>--<br>The greatest dangers to liberty lurk in insidious encroachment by men of zeal, well-meaning but without understanding. -- Justice Louis D. Brandeis</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21675479</guid>
<pubDate>Sat, 03 Jan 2009 15:26:43 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21675034</link>
<description><![CDATA[<A HREF="/useremail/u/700900"><b>Tyreman</b></A> : Never say never? :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21675034</guid>
<pubDate>Sat, 03 Jan 2009 13:44:29 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21674451</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : <div class="bquote">No matter how savvy of a computer user you are, your computer will be the victim of malware or a virus at some point.<br><br>Pretty bold statement from cnet. What do you guys think?<br> </div>If I am counting correctly, I have owned 6 different computers (not counting my wife's), and none of them has ever been a victim of malware.<br><br>I have probably had at least 10 different desktop computers at work, and only one of them was ever a victim of malware - a minor virus accidently introduced by a department technician working on the machine.<br><br>I would say that the claim is a gross exaggeration.<br><br>Footnote: if Windows itself is considered malware, then all but three of the machines have had some version of that installed :(<br>Footnote2: for those who consider linux to be malware, many of the machines have had that installed.<br><small>--<br>AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.5</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21674451</guid>
<pubDate>Sat, 03 Jan 2009 11:15:04 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21674360</link>
<description><![CDATA[<A HREF="/useremail/u/1019247"><b>VikingBob</b></A> : Nothing is 100% secure... there is some truth mixed in with the FUD. But if you're "savvy" then the odds are pretty minimal. You probably already have installed/implemented good security already.<br><br>For the average user, the odds of being infected are pretty good! I've cleaned a few machines, and the usual cause in the end is the user. Outdated security software, insecure programs and/or OS, and surfing where you should not. Even when you beat them over the head with how to avoid getting infected, they do it again... a lot of people just don't get it. :mad: Too lazy, or just too thick.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21674360</guid>
<pubDate>Sat, 03 Jan 2009 10:50:38 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21673922</link>
<description><![CDATA[<A HREF="/useremail/u/1531837"><b>Its a Secret</b></A> : Sounds like CNET needs to make money from clicks. FUD, imo.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21673922</guid>
<pubDate>Sat, 03 Jan 2009 07:32:54 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21673882</link>
<description><![CDATA[<A HREF="/useremail/u/917630"><b>Cudni</b></A> : <div class="bquote"><small>said by  DarkSithPro <A HREF="/useremail/u/1157962"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>No matter how savvy of a computer user you are, your computer will be the victim of malware or a virus at some point.<br><br>Pretty bold statement from cnet. What do you guys think?<br> </div>Farting Under Duvet unless of course they mean when someone not computer savvy steals a computer belonging to a savvy user and goes on to fulfil cnet statement. I'm sure there are more hypothetical situations<br><br>Cudni<br><small>--<br>"what we know we know the same, what we don't know, we don't know it differently." <br>Help yourself so God can help you.<br>Microsoft MVP,  2006 - 2008</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21673882</guid>
<pubDate>Sat, 03 Jan 2009 07:10:38 EDT</pubDate>
</item>

<item>
<title>Re: Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21673876</link>
<description><![CDATA[<A HREF="/useremail/u/1537340"><b>Smokey Bear</b></A> : <div class="bquote"><small>said by  DarkSithPro <A HREF="/useremail/u/1157962"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>cnet.com<br>Under lock and key<br><br>No matter how savvy of a computer user you are, your computer will be the victim of malware or a virus at some point.<br><br>Pretty bold statement from cnet. What do you guys think?<br> </div>As long people don't download malware from CNET/download.com servers there is a possibilty they remain clean. CNET still offer malware for download.....<br><br><small><i>Edited: typo</i></small><br><small>--<br>Smokey's Security Forums &raquo;<A HREF="http://www.smokey-services.eu/forum/" >www.smokey-services.eu/forum/</A><br>Smokey's Security Weblog &raquo;<A HREF="http://smokeys.wordpress.com/" >smokeys.wordpress.com/</A><br><i>Site Member ASAP - Alliance of Security Analysis Professionals</i></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21673876</guid>
<pubDate>Sat, 03 Jan 2009 07:09:20 EDT</pubDate>
</item>

<item>
<title>Cnet tells users 100% guarantee infection</title>
<link>http://www.dslreports.com/forum/remark,21673856</link>
<description><![CDATA[<A HREF="/useremail/u/1157962"><b>DarkSithPro</b></A> : cnet.com<br>Under lock and key<br><br>No matter how savvy of a computer user you are, your computer will be the victim of malware or a virus at some point.<br><br>Pretty bold statement from cnet. What do you guys think?<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/21673856?c=1386174&ret=L2ZvcnVtL3IyMTY3Mzg1Ni54bWw%3D"><IMG TITLE="48604 bytes" BORDER=0 WIDTH=510 HEIGHT=309 SRC="/r0/download/1386174~37a4f3afa64f9d6fa260285d99f247c3/infection.JPG"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21673856</guid>
<pubDate>Sat, 03 Jan 2009 06:58:11 EDT</pubDate>
</item>

</channel>
</rss>
