12.08.2005

Sure you've heard of rootkits, but what about ghostware? Be afraid. Be VERY afraid.

Forget about spyware, the next bad boy to hit windows is called 'ghostware'. Ghostware is loosely defined as malware which can NOT be detected from inside the operating system. Sound scary? Guess what, you could already be infected, and if you are, you are quite bluntly, screwed. Microsoft has no clue what to do about it yet. Microsoft is currently planning on integrating rootkit detection into MS AntiSpyware, but none of their current ideas on ghostware sound terribly plausible. Current best guesses are to use a pre-burned clean copy of the operating system as a 'master' to try to detect the ghostware. Of course you would also need another cd to run the software. How are they going to ensure the computer reboots every night to scan? How are they going to fit your 60 gb system partition on a cd or dvd? Don't ask Microsoft, they have bluntly stated that they need to learn more about it before doing anything. If it takes as long for them to get this fixed as it does most of their patches, we are all screwed.

Here's a link to the full story:
http://www.eweek.com/article2/0,1895,1838294,00.asp

Here's Microsofts own research page on the subject:
http://research.microsoft.com/rootkit/

If you're interested in checking your computer for rootkits, you're best bet is to go to the link at the bottom of this page and download Rootkit Revealer:
http://www.sysinternals.com/Utilities/RootkitRevealer.html

If you're concerned about being infected with ghostware.. like I said, if you are, you're screwed. Keep an eye on these resources for any new developments. The only other people I can think of that have the resources to handle a threat like this are our old friends at the Symantec Antivirus Research Center:
http://sarc.com

Personally, I'm about ready to ditch Windows entirely and switch to Novell SUSE Linux. I'm damn sure gonna pull all my secure crap out of Windows, I'll tell you that.
External Link

12.07.2005

WinMX is back in action

Last I knew the parent company of WinMX was moving offshore. Until that happens, the WinMX community has patched the software so that it works without the need for the WinMX server. Go here, download and install the patch, and you'll be back in action in two shakes. :D

http://www.winmxgroup.com/

I have it installed and running as a primary connection. No apparent viruses or trojans or spyware or anything. I am fairly confident that it's clean, since the WinMX community put it together. However be sure to run your own checks on it before installing it on a server thats in production. ;)

Here's the link to the WinMX Community site:
http://www.winmxworld.com/

Here's the backstory, if anyone is interested:
http://en.wikipedia.org/wiki/WinMX
External Link

Site Meter logo

Google