Slashdot Mirror


Microsoft Refuses To Patch Rootkit-Compromised XP Machines

Barence writes "Microsoft has revealed that its latest round of patches won't install on XP machines if they're infected with a rootkit. In February, a security patch left some XP users complaining of endless reboots and Blue Screens of Death. An investigation followed and Microsoft discovered the problems occurred on machines infected with the Alureon rootkit, which interacted badly with patch KB977165 for the Windows kernel. Now Microsoft is blocking PCs with the rootkit from receiving its new patches. 'This security update includes package-detection logic that prevents the installation of the security update if certain abnormal conditions exist on 32-bit systems,' Microsoft cautions in the patch notes."

330 comments

  1. The Microsoft way! by Neuroticwhine · · Score: 0, Troll

    Microsoft has always held the moto, "If its broke... dont fix it."

    Why would they change that now?

    1. Re:The Microsoft way! by sopssa · · Score: 4, Insightful

      I recall slashdotters complaining that they didn't do CRC check or similar (they do, but the rootkit gave 'real' value and it was worthless).

      Now they're doing the right thing and we get news how they refuse to patch the systems which .dll files have been damaged? Welcome to slashdot.

    2. Re:The Microsoft way! by ciroknight · · Score: 0, Troll

      Now they're doing the right thing and we get news how they refuse to patch the systems which .dll files have been damaged? Welcome to slashdot.

      Why is not patching the system acceptable? Shouldn't it just determine if the DLL was damaged and replace it with the correct, working patched version if it is? Sorry, but automatically throwing their hands up and saying "you're fucked" is the Microsoft shortcut for not being able to fix their own security problems.

      --
      "Victory means exit strategy, and it's important for the President to explain to us what the exit strategy is." G.W.Bush
    3. Re:The Microsoft way! by gzipped_tar · · Score: 5, Informative

      If the kernel is fucked, nothing works any more. Any results from on-line determination of the damage status of the machine itself should be assumed fake because the malware is in control of all local resources. To accurately determine the status of the computer, it must be taken offline.

      Never trust what rooted machines say about themselves...

      --
      Colorless green Cthulhu waits dreaming furiously.
    4. Re:The Microsoft way! by HeronBlademaster · · Score: 4, Insightful

      Shouldn't it just determine if the DLL was damaged and replace it with the correct, working patched version if it is? Sorry, but automatically throwing their hands up and saying "you're fucked" is the Microsoft shortcut for not being able to fix their own security problems.

      Isn't that what they did last time, and it caused bluescreens?

      Do you want every single patch, no matter how small, to try to detect rootkits and, if a rootkit is detected, replace every DLL in the system with known clean copies? That's absurd.

      The problem wasn't that the DLL the patch installed caused bluescreens, it's that DLLs the patch didn't touch - because it wasn't patching them - were now incompatible with the clean (patched) DLL (because they were part of the rootkit).

      What do you propose Microsoft do about it? Patch the DLLs anyway, knowing it will cause bluescreens? Provide the entire slew of kernel DLLs for download via Windows Update, and install all of them every time there's a kernel patch?

      I don't mind what MS is doing at all - they're doing their best to make sure that their users won't get bluescreens, even if they're rooted.

    5. Re:The Microsoft way! by Rockoon · · Score: 4, Informative

      You don't know how computers work, do you?

      The blue screen crashing that this rootkit caused after the previous update was not due to rootkit modifications to the files that were being patched.

      The problems occured because code that was NOT being patched (the rootkit!) was making direct jumps into kernel memory, to offsets that were no longer relevant after the patch.

      --
      "His name was James Damore."
    6. Re:The Microsoft way! by lorenlal · · Score: 1, Flamebait

      You don't know how software development and pointers work, do you?

      To many users, a computer works by doing what they tell it to do, and that's plenty for them to know. "How computers work" is a very broad statement that could mean a number of things that you don't address in the statements following your first one.

      It also makes you sound condescending.

    7. Re:The Microsoft way! by Khyber · · Score: 2, Interesting

      'Never trust what rooted machines say about themselves..."

      Funny, that's usually how I spot a rooted machine. There's a fine difference between "I just don't want to work because I'm a piece of shit" and "I don't want to work because I'm controlled by someone other than you."

      --
      Still waiting on Serviscope_minor to wake up to fucking reality and realize that Jessica Price isn't going to fuck him.
    8. Re:The Microsoft way! by sopssa · · Score: 1, Insightful

      Uh, what are you trying to say?

      Once the machine is rooted or has malware on it that has gained admin/root/kernel access, your best bet is to shut it down, take your documents and reinstall the system. You cannot know where it hides, no matter how knowledgeable you think you are. But you can still save your documents and not reveal banking data or passwords and similar.

    9. Re:The Microsoft way! by Lil'wombat · · Score: 2, Funny

      So this is a vendor software issue? Those rootkit developers should have a better testing process. I'm not going to go to all of the trouble of rooting 100k servers just to have my botnet BSOD on the next update. I demand a refund

      --

      Truth: If it's not one thing, it's another

    10. Re:The Microsoft way! by nigelo · · Score: 4, Funny

      "I'm a people-person. What the hell is wrong with you people?"

      --
      *Still* negative function...
    11. Re:The Microsoft way! by maxwell+demon · · Score: 5, Funny

      What if it hides in the documents?

      --
      The Tao of math: The numbers you can count are not the real numbers.
    12. Re:The Microsoft way! by Yaddoshi · · Score: 5, Insightful

      I agree, I thought the title of this submission was skewed - especially after reading the rest of the article. Microsoft does not appear to be "refusing to patch rootkit infected computers".

      A more accurate title would be something along the lines of: Microsoft attempts to prevent inadvertently bricking XP systems with Windows Updates

      Bear in mind I'm terrible at coming up with titles. Also bear in mind I'm not a big fan of Windows.

    13. Re:The Microsoft way! by Bert64 · · Score: 1

      Well, by refusing to patch an already compromised system they open that system up to getting further malware infections...
      If the system breaks at least it's now offline and will cease sending spam or whatever other malicious things its doing.

      --
      http://spamdecoy.net - free throwaway anonymous email - avoid spam!
    14. Re:The Microsoft way! by Bert64 · · Score: 3, Interesting

      Do they notify the users that they're rootkitted?
      If anything, a bluescreen is a good thing since the rootkitted machine is now offline and no longer sending spam or whatever other malicious things it might be doing.

      --
      http://spamdecoy.net - free throwaway anonymous email - avoid spam!
    15. Re:The Microsoft way! by hairyfeet · · Score: 1

      Because as a PC repairman I can tell you that trick won't work? These bugs ain't the nasties of old, where a simple boot into safe mode and a cleaning fixes you right up. No sir, these babies are naaaasty. Multiple hidden processes, auto replacing of files with its own, hidden reg entries, rootkits, all kinds of really nasty shit.

      MSFT is doing the right thing in this case. There simply isn't any way to really clean these badly infected machines by remote, and trying to patch them while infected will just leave you with a BSOD'd box. Better to pop up a screen that says "We're sorry, but it seems like your computer may be infected. Please take it to your nearest service center to have it checked" than to try to fix this crap by remote and totally hose the machine.

      Not to mention if MSFT disables programs by remote, spyware or not, they'll probably get hit by a wave of lawsuits from spyware vendors claiming their apps are legit. Better to let the user take it to someone who knows what they are doing and let them decide what needs to go.

      --
      ACs don't waste your time replying, your posts are never seen by me.
    16. Re:The Microsoft way! by dhavleak · · Score: 3, Insightful

      That's good for the world in general but bad for the owner of the machine. You're suggesting MS make the decision to fuck over some individual for the good of many? They don't have that mandate.

    17. Re:The Microsoft way! by dhavleak · · Score: 2, Interesting

      Well, by refusing to patch an already compromised system they open that system up to getting further malware infections...

      They're not 'opening up' the system -- they're just leaving it open. It was already like that when they found it.

      If the system breaks at least it's now offline and will cease sending spam or whatever other malicious things its doing.

      Good for us. Bad for the owner. MS cannot fuck the owner on our behalf.

    18. Re:The Microsoft way! by dan828 · · Score: 1

      Because patching it kills the system and results in endless blue-screens and reboots. So yeah, it's not an optimal solution, but breaking the system to the point where it's unusable isn't a good idea either.

    19. Re:The Microsoft way! by jibjibjib · · Score: 3, Insightful

      So now they're actively leaving rootkits online and fucking over the rest of the world for the good of the guy who can't maintain his machine properly? You could argue that they don't have that mandate either.

    20. Re:The Microsoft way! by cybernanga · · Score: 1

      5. 353,000 tons traveling at 650 miles per second creates enormous air resistance - this will heat the reindeer up in the same fashion as spacecrafts re-entering the earth's atmosphere.

      Which is why Rudolph has a red nose!

      --
      www.Buy-Proxy.com - A "buyer-driven" global marketplace.
    21. Re:The Microsoft way! by dhavleak · · Score: 2, Funny

      To do nothing? They need a mandate to not touch a system they don't own?

    22. Re:The Microsoft way! by sopssa · · Score: 0, Troll

      Microsoft isn't a police. They are legally liable if they intentionally damage computer systems.

    23. Re:The Microsoft way! by ffreeloader · · Score: 1

      Hmmm.... MS would be screwing over the machine owner by actually letting them know that their machine has been compromised by having it blue screen? How is that?

      It's somehow NOT screwing over the user to let them go on in ignorance doing their banking, tax prep, online investing, online purchasing, etc... from a compromised machine? How do you figure that? You would rather let an attacker know all your personal information, and have your machine used to compromise other systems, than have your machine blue screen? If you would, I say you have some seriously screwed up priorities.

      --
      "while democracy seeks equality in liberty, socialism seeks equality in restraint and servitude." de Tocqueville
    24. Re:The Microsoft way! by Skuld-Chan · · Score: 1

      Yes they do - it gives a specific error code where if looked up it says "this machine in unable to run Windows Update because it is infected with malware" or something like that.

    25. Re:The Microsoft way! by smash · · Score: 1
      Pretty much this. Once a machine is rooted, sure you may know what the rootkit has done, but who knows what the person with control of the rootkit has done?

      Rooted machines need more than a quick patch or av scan - do that so you can secure your data, back it up and then blow it away and start over. Its the only way to be sure.

      --
      I run: Windows, OS X, Linux, FreeBSD. Just because you have a hammer, doesn't mean everything is a nail.
    26. Re:The Microsoft way! by smash · · Score: 1

      You can scan them, and inspect them relatively easily for corruption. What you can't necessarily scan for with a dumb rootkit remover is modified configuration settings, modified firewall rules, added ipsec tunnels, etc - that weren't done by the rootkit, but by someone with control of it. Sure you could do that manually by going through each and every configuration item on your box, but its a lot quicker and easier to blow it away and start over.

      --
      I run: Windows, OS X, Linux, FreeBSD. Just because you have a hammer, doesn't mean everything is a nail.
    27. Re:The Microsoft way! by smash · · Score: 2

      Well, the proper solution for a rootkitted box IS to replace every DLL and configuration item on the system once the rootkit is removed. Its called an OS wipe and reinstall.

      --
      I run: Windows, OS X, Linux, FreeBSD. Just because you have a hammer, doesn't mean everything is a nail.
    28. Re:The Microsoft way! by dissy · · Score: 1

      Why is not patching the system acceptable?

      Because it is.

      What exactly do you expect patching an already rooted system to accomplish? Those patches won't make it any more secure than it was before the patch. Those patches won't fix any of the security problems they fix on a rooted system.

      What would the point be?

      Best possible case is nothing at all happens and you are just as rooted and insecure as before applying the patches.

      Worse possible case is your system now refuses to boot, or reboots in loops, etc.

    29. Re:The Microsoft way! by dhavleak · · Score: 1
      Microsoft can say "sorry dude -- can't install xyz patch 'cos your system's integrity is suspect". What the user does after than is up to them.

      It's somehow NOT screwing over the user to let them go on in ignorance doing their banking, tax prep, online investing, online purchasing, etc... from a compromised machine? How do you figure that?

      Don't over-complicate the issue. It's just not MS's call to make.

      You would rather let an attacker know all your personal information, and have your machine used to compromise other systems, than have your machine blue screen? If you would, I say you have some seriously screwed up priorities.

      ???
      This is not *my* situation. It's the situation of people who know so little about computers that they don't even know what their situation is. Even for them, MS cannot confer upon itself the power to bluescreen their machines to protect them from themselves. As much as you might wish it, you too do not have the power to give them that mandate. Such is life sometimes. Live with it.

    30. Re:The Microsoft way! by zeugma-amp · · Score: 1

      Good for us. Bad for the owner. MS cannot fuck the owner on our behalf.

      Strange. I thought fuck the consumer" was their business model.

      See WGA

      --
      This is an ex-parrot!
    31. Re:The Microsoft way! by xQx · · Score: 2, Insightful

      Say someone pisses in your pool...

      How do you get the piss out of the pool?

      You don't. It's fucked. You drain the pool and start again.

      Any server administrator worth their salt knows if someone gets in to root / administrator who is not supposed to be there there is only one course of action: Unplug and rebuild.

      You do not try to fix a server that has been compromised in this way, regardless of Operating System. For some reason we get compassionate about home-users who can't afford to fix their computer ... and then we get upset when these computers are used for botnets and spam propagation... WTF?!

      I think it's utterly RESPONSIBLE of Microsoft to withdraw support for someone silly enough to want to keep running an operating system that's been rootkitted.

      Hell, if it were my network I'd be using the rootkit to permanently disable all network connectivity to avoid any further damage. User be damned.

    32. Re:The Microsoft way! by Anonymous Coward · · Score: 0

      Uh, what are you trying to say?

      Once the machine is rooted or has malware on it that has gained admin/root/kernel access, your best bet is to shut it down, take your documents and reinstall the system. You cannot know where it hides, no matter how knowledgeable you think you are. But you can still save your documents and not reveal banking data or passwords and similar.

      Funny how this opinion comes via the same slashdot whose mantra is "physical access makes your actions meaningless to an attacker." Mr. bad guy magically becomes a government supercluster owner capable of cracking passwords that require age-of-the-universe time on our best non-cluster PC's.

      "You cannot know where it hides" means you think the rootkit is uncrackable / unfindable because it was made by the same bad guys that cause IT to go into security theather mode... But *we* have physical access. SURELY, that must mean nothing they can do is 100% effective. I'm half joking, since I would still not feel safe on spyware-cleaned machines where a reformat was skipped to save time and user-related fits. Just realize that to the bad guys we are also "bad guys" with better powers. After all, if more than 50% of all Windows machines were rooted, businesses would not run Windows, and neither would we... and /. would be all over that. Since we are in the good 50%+ side of things, then I say that we're not doing all that badly in the face of our... faceless, non-physical access Russian rootkit overlords

    33. Re:The Microsoft way! by shentino · · Score: 1

      Microsoft isn't responsible for what a rootkit decides to do.

      If I were microsoft, I'd update away, and consider malware infections the same way I would unauthorized tampering with system files by the user. Just update the kernel, and be damned with anything that was played with. For much the same reason that opening a device is usually grounds for voiding the warranty, since the manufacturer can't reasonably be required to support end user tinkering.

      The notion that vendors should go out of the way to actually SUPPORT malware is absurd, let alone the notion that black hats should be dictating terms to OS creators.

    34. Re:The Microsoft way! by shentino · · Score: 1

      But it's not intentional.

      It's more like you take a device into the factory for an upgrade, but unknown to you, someone swiped it, and installed a spy chip inside. When the factory technician opens it up and tries to install the new parts, the spy chip short circuits the whole thing and the device blows up in his face.

    35. Re:The Microsoft way! by dhavleak · · Score: 1

      Strange. I thought rational discourse was more important than dogma.

    36. Re:The Microsoft way! by rdnetto · · Score: 1

      Say someone pisses in your pool...

      How do you get the piss out of the pool?

      Maxwell's demon

      --
      Most human behaviour can be explained in terms of identity.
    37. Re:The Microsoft way! by dhavleak · · Score: 1

      Microsoft isn't responsible for what a rootkit decides to do.

      What kind of crazy logic is this? Their code is downloading the patch and applying it. At this point the ball is in their (MS's) court about how to proceed. It's not the rootkit 'deciding' stuff at this point.

      If I were microsoft, I'd update away, and consider malware infections the same way I would unauthorized tampering with system files by the user.

      They don't get to make that call. If you were actually in MS's position, you would actually make the same call as them. On a random forum on the internet it's easy to make bold claims about what you would do.

      Just update the kernel, and be damned with anything that was played with.

      Again - this is a completely cavalier attitude -- and if you were actually in the position to make the call, not only would you not have the stones, you would also pause to think about it for a second and also realize that you don't have the right to do that.

      For much the same reason that opening a device is usually grounds for voiding the warranty, since the manufacturer can't reasonably be required to support end user tinkering.

      So you're saying the manufacturer gets the right to knowingly brick your system because you've voided your warranty?

      The notion that vendors should go out of the way to actually SUPPORT malware is absurd, let alone the notion that black hats should be dictating terms to OS creators.

      You managed to twist "we won't knowingly BSOD user's systems" into "we support malware"?? Only on slashdot. God knows what you mean by "black hats dictating terms to OS creators" -- nothing in your post made much sense anyway.

    38. Re:The Microsoft way! by shentino · · Score: 1

      I'm just saying it seems rather silly to put MS in the position of walking on egg shells around rootkits to prevent a BSOD that they're not even responsible for causing.

    39. Re:The Microsoft way! by ffreeloader · · Score: 1

      So, MS has no duty whatsoever to notify people that they know have compromised machines? Sorry, but that's pure horseshit and symptomatic of everything that's wrong with our society.

      The principle behind it is no different than a neighbor watching someone back a truck up to your back door and load up all your furniture, appliances, safes, etc..., drive away with everything you own, and never say a word to you about it or call the cops. Does your neighbor have a moral duty to call both you and the cops? Yes. We all have a moral duty to protect each other.

      MS has the same moral duty to those who buy their products when MS discovers their machines are compromised. MS shouldn't be snooping, but if they discover this type of problem during normal operations, like installing updates, then they most certainly have a moral obligation to help those people.

      If you can't understand, or disagree with, the above concepts, I certainly wouldn't want you for a neighbor or acquaintance, or be part of the same workplace with you, and most certainly would never call you friend, as you are not trustworthy.

      As to you, personally, not having a root kitted computer, well, your comments just show you have no empathy as you can't identify with someone else's problem nor visualize what you would want someone to do for you if you were in the victim's shoes. That pretty much explains your lack of understanding with regard to moral obligations.

      --
      "while democracy seeks equality in liberty, socialism seeks equality in restraint and servitude." de Tocqueville
    40. Re:The Microsoft way! by al0ha · · Score: 1

      While I understand your reasoning, please understand the concepts of morality apply only to humans. Microsoft corporation has no moral duty to do anything. Corporations are amoral, they are neither moral nor immoral, and as such they are only obligated to adhere to the rule of law in their pursuit of profit.

      --
      Did you ever wake up in the morning, with a Zombie Woof behind your eyes? -- FZ
    41. Re:The Microsoft way! by dhavleak · · Score: 1

      I'm just saying it seems rather silly to put MS in the position of walking on egg shells around rootkits to prevent a BSOD that they're not even responsible for causing.

      Nobody is putting them in any position. They're not walking on egg shells. They just know what they can and cannot do, and intensionally BSODing a user's system is fairly high on the list of things they cannot do. However it's spun, they're doing the only thing they can/should do.

    42. Re:The Microsoft way! by dhavleak · · Score: 1

      While I understand your reasoning, please understand the concepts of morality apply only to humans.

      Laws exist to project our sense of morality onto corporations. Please lose the condescending tone next time you post.

      Microsoft corporation has no moral duty to do anything.

      They don't have the authority to make a decision on the user's behalf about how to proceed (in the event of failing a system integrity check). Who said anything about morals?

      Corporations are amoral, they are neither moral nor immoral, and as such they are only obligated to adhere to the rule of law in their pursuit of profit.

      That rule of law as I said, is us (humans) projecting our morals onto corporations. If MS were to intentionally BSOD a users system, the user could go to court, and the user would win. MS has no other option here. Where did morals come into this??

    43. Re:The Microsoft way! by dhavleak · · Score: 1

      But it's not intentional. It's more like you take a device into the factory for an upgrade, but unknown to you, someone swiped it, and installed a spy chip inside. When the factory technician opens it up and tries to install the new parts, the spy chip short circuits the whole thing and the device blows up in his face.

      It is intentional. It was not intentional the last time they pused out updates and got burned by Alureon rootkits. The second time around, if they encounter the same number of BSODs it would be intentional at worst, and negligent at best.

    44. Re:The Microsoft way! by dhavleak · · Score: 1

      I'm a dumbass. I just realized you were replying to the other poster -- not to me. In the correct context, I understand what you were saying.

    45. Re:The Microsoft way! by Bert64 · · Score: 1

      Those users are rootkitted, they have by definition already been fucked over.

      --
      http://spamdecoy.net - free throwaway anonymous email - avoid spam!
    46. Re:The Microsoft way! by dhavleak · · Score: 1

      Which doesn't preclude them from getting fucked over some more.

  2. First things first by BadAnalogyGuy · · Score: 5, Insightful

    If the rootkit is still on your computer, maybe you should look into having it removed.

    how shall thee pull out the mote that is in thine eye, when thou thyself beholdest not the beam that is in thine eye? Luke 6:42

    1. Re:First things first by gzipped_tar · · Score: 1

      Theoretically, you're right. Practically, Murphy's Law takes precedence over the Scriptures, and you _will_ find "installing the MS patch" a necessary step in the rootkit removal.

      Jesus Christ administrated, but He's still a newbie in system administration ;)

      --
      Colorless green Cthulhu waits dreaming furiously.
    2. Re:First things first by Skarecrow77 · · Score: 5, Funny

      no! I need the newest microsoft patch so that there are not any new security holes in my computer! I'll deal with that huge gaping sucking chasm of a security hole that's already there, created by the rootkit, at some later date.

    3. Re:First things first by sopssa · · Score: 2, Insightful

      You need the newest microsoft patch that - because of the rootkit and the .dll files it has damaged - will BSOD your system? Somehow someone turned this news into an rant and like it's a bad thing to really make sure the windows update should be able to patch things before proceeding.

    4. Re:First things first by Anonymous Coward · · Score: 0

      Your paraphrase / shortening of the verse doesn't make any sense.

    5. Re:First things first by Skarecrow77 · · Score: 1

      I'm just assuming that my previous post is the standard line of thinking of most of these people. if they can't see a big banner saying "you've been rootkitted. your computer's botnet name is '17004-G81', just so you know" on their desktop, then they don't care I guess.

    6. Re:First things first by Anonymous Coward · · Score: 0

      You prefer the original?

      Pos dunasai legein toi adelfo sou adelfe afes ekbalo to karfos to en toi ofthalmoi sou, autos thn en toi ofthalmoi sou sokon ou blepon; hupokrita, ekbale proton thn dokon ek tou ofthalmou sou, kai tote diabeleis to karfos to en toi ofthalmoi tou adelfou sou ekbalein.

    7. Re:First things first by kseise · · Score: 3, Funny

      Just to be sure that we get this update, I am installing the newest Antivirus 2010 on all of our network machines. This version should pickup the rootkits that Antivirus 2009 left behind. Since I work at the IRS, our systems are absolutely critical to protect this month.

    8. Re:First things first by Anonymous Coward · · Score: 0

      In everything they do, we learn more about what they don't do properly.
      What about their malicious software removal tool?
      , that supposedly scans on updates

      To me, that makes it obviously WORTHLESS if it can't remove this root-kit what good is it?
      What motives do they have to not remove this root-kit,? If None, then this tool cant remove it, the are no other possibilities here.
      What kind of brain detects a root-kits presence, but doesn't remove it? and instead wont install the updates
      Why cant they hire capable people with Brains who would have this tool remove the root-kit then install the updates ?

    9. Re:First things first by Anonymous Coward · · Score: 0

      Actually, there was a previous story about the BSODs people have been receiving and there were many comments suggesting that this is the way to go! If the user's computer gets fucked up because of a root kit, LET IT! We're complaining about all the rooted Windows boxes and about ignorant people that just won't bother to remove the infection, so why not encourage Microsoft to let them download the latest patches, so we can teach them a lesson? I'm running Windows XP SP2 on a computer with no patches and no Antivirus (just FF+ABP) and nothing ever happened to me. I can confirm this, because I'm constantly monitoring my computer's on-line activity through a custom script I set up on my router.

      So, here are some tips: find a clean copy of XP SP2, disable file and printer sharing for all networks, use the latest Firefox with Adblock Plus, read more about the software you are about to install, try to stick to open-source and use siteadvisor.com + virustotal.com. If you insist on running a keygen (won't work with a no-cd or other patches), give it a flavor of Sandboxie, just to be safe. For strange apps that aren't GPU intensive, use VMware or something similar and share files between the host and guest using something like mediafire.com. As a cool tool, not related to security, see Diskeeper (I prefer the 2008 version). You literally install and forget about it (absolutely no customization needed!) and a couple of days after installing it, you begin to feel the difference - disk reads will improve significantly.

      Yes, I am paranoid, but this has kept me safe running the same version of Windows since 2004. Also, if you don't start to play with your registry settings, you can have the same system installed for years (I have it since 2005).

    10. Re:First things first by maxwell+demon · · Score: 1

      Luke 6:42

      Admit it: That's the reason why you quoted it! :-)

      --
      The Tao of math: The numbers you can count are not the real numbers.
    11. Re:First things first by VGPowerlord · · Score: 1

      So, here are some tips: find a clean copy of XP SP2

      Why not XP SP3?

      --
      GLaDOS for President 2016! "Well here we are again. It's always such a pleasure." -- GLaDOS, 2011
    12. Re:First things first by Anonymous Coward · · Score: 0

      Learn to read. I have never read the bible, and it made perfect sense.

    13. Re:First things first by Anonymous Coward · · Score: 0

      If you are so worried about viruses, why the fuck do you use Windows?

      Keeping yourself in the technological Stone Age is the wrong way to go about it.

    14. Re:First things first by Anonymous Coward · · Score: 0

      So you're more worried about a possible future breach of security as opposed to an actual current one.
      So does your fire department hose down houses a block away from the burning one, or the one that's actually on fire?

    15. Re:First things first by dhavleak · · Score: 2, Insightful

      What about their malicious software removal tool that supposedly scans on updates

      The user may not have MSRT on their system. Alureon (the rootkit that caused the last issue) is detectable by every AV software out there and removable by MSRT (and others). We're talking about ultra-computer-phobic/challenged users here.

      To me, that makes it obviously WORTHLESS if it can't remove this root-kit what good is it?

      If a tool isn't installed on a machine, I don't expect it to be able to do much :)

      What motives do they have to not remove this root-kit?

      It's not "this rootkit". It could be any rootkit. They are merely checking if the machine has been compromised, before going ahead with applying the patch. Do you want to include an entire rootkit scanner, removal tool, definition files, etc. with every update you send out on windows update? Do you want to delay the sending of patches (to the rest of the world that keeps their machine clean and healthy and cares about these things) while all this is tested?

      What kind of brain detects a root-kits presence, but doesn't remove it? And instead wont install the updates? Why cant they hire capable people with Brains who would have this tool remove the root-kit then install the updates ?

      You seem to have not applied yourself to the questions you're asking. The answers are plain.

    16. Re:First things first by Anonymous Coward · · Score: 0

      time to switch to Linux my friends

    17. Re:First things first by Anonymous Coward · · Score: 0

      don't you have something to do?

    18. Re:First things first by kandela · · Score: 1

      You have it wrong. They are so worried about viruses *because* they use Windows, not the other way around.

      --
      Conservation of angular momentum makes the world go round.
    19. Re:First things first by smash · · Score: 1

      Probably because it asks for the WGA tool and is incompatible with Microsoft Windows TDK edition.

      --
      I run: Windows, OS X, Linux, FreeBSD. Just because you have a hammer, doesn't mean everything is a nail.
    20. Re:First things first by FrankieBaby1986 · · Score: 1

      They are merely checking if the machine has been compromised, before going ahead with applying the patch. Do you want to include an entire rootkit scanner, removal tool, definition files, etc. with every update you send out on windows update?

      Well, I'd damn well expect that if they decide not to install the update because of the infection, THEN it should tell me about it and perhaps download and run the appropriate MSRT.

      maybe it does, but TFS doesn't say, and I really shouldn't be on /. right now anyway.

      --
      ERROR: SIG NOT FOUND (A)bort, (R)etry, (F)ail?:
  3. Makes sense... by TheSpoom · · Score: 1

    Microsoft isn't really in the business of providing a virus scanner as one of their free updates. Oh wait...

    *continues running Ubuntu*

    --
    It's better to vote for what you want and not get it than to vote for what you don't want and get it.
    - E. Debs
    1. Re:Makes sense... by mwvdlee · · Score: 2, Interesting

      To be fair, does the MS virusscanner detect and remove the rootkit?

      --
      Slashdot social media options: AIM, ICQ, Yahoo, Jabber and Mobile Text. Why no MySpace?
    2. Re:Makes sense... by HerculesMO · · Score: 5, Interesting

      The malicious software removal tool will take care of it. Their antivirus will not.

      They are giving you the tool to get rid of it and then saying you should install your patches afterwards. But they are chastised for not coming up with a all-in-one solution? Jeez.

      --
      The price is always right if someone else is paying.
    3. Re:Makes sense... by NatasRevol · · Score: 0, Troll

      Yes, they are being criticized, and rightly so.

      If Microsoft can detect the rootkit, they can fix it...BEFORE running the patch. It really can't be that hard.

      --
      There are two types of people in the world: Those who crave closure
    4. Re:Makes sense... by clone53421 · · Score: 5, Informative

      And that’s what will happen. Installation of the patch will fail, if the rootkit is detected. The malicious software removal tool will be pushed out and remove the rootkit. And eventually the patch will be installed again since the installation failed the first time, and if the rootkit is gone the patch should install properly.

      --
      Alexander Peter Kristopeit bought his basement from his mommy for one dollar.
    5. Re:Makes sense... by Rakishi · · Score: 4, Insightful

      And if the rootkit remover bricks some systems you'd be yelling at Microsoft for not making it a separate update so users could prepare for it, right? I doubt it matters what MS does, you'd find a reason to think they're wrong no matter what.

      Security updates are security update, malware removal is malware removal. Mixing the two is a horrid idea.

    6. Re:Makes sense... by dhavleak · · Score: 1

      If Microsoft can detect the rootkit

      They don't. They're checking hashes on key platform binaries to check if they're compromised -- that's not the same as detecting the nature of the compromise.

      they can fix it...BEFORE running the patch.

      Detecting = more code. Fixing = more code. Many varieties of rootkits to allow for, not just one. Needs much more testing before sending out patches -- delays sending updates to the rest of the world that acutally does care, and does maintain their machines in a healthy state. Requires user's approval before making changes to the machine, etc.

      It really can't be that hard.

      Because you say so? Very well - how about you write the code to detect and fix an Alureon infection in your reply to this post?

    7. Re:Makes sense... by chaboud · · Score: 2, Insightful

      Man, this so exemplifies the distorted user perspective of the ease of software development. There is a completely workable workflow here: run update twice, but you want Microsoft to code up a little custom fix (possibly requiring a double-restart) that seems like a triviality, right?

      Wrong.

      It takes a long time to write, debug, test, and deploy even small software changes. When non-coders (or even coders) talk about how easy it would be for someone else to do something, alarm bells go off. Microsoft is doing a completely reasonable thing. I won't say that it's the "right thing," because that would imply that there is only one good course of action. Still, this approach is completely fair, easy to use, and safe.

    8. Re:Makes sense... by Anonymous Coward · · Score: 1, Interesting

      I hope that Microsoft will actually display an appropriate error message. I've had issues installing the Indeo disabling patch where it refused to install and didn't display an error message or whatever. At some point I snapped and manually nuked the codec, so I'm good, but really... The guys who write the security updates can't even code up a message box - what's up with that?

    9. Re:Makes sense... by clone53421 · · Score: 2, Interesting

      Well... I really can’t say I have high hopes for that.

      I’ve had numerous updates (okay, 4 or 5) on Windows 7 that failed to install, with no explanation whatsoever. It seemed like more than it really was because it attempted to install the same 3 updates again the next time I shut down. And the next time. And the next. And... every time until I finally went into the update history to figure out what the deal was.

      (In my case I’ve always been able to go onto the Microsoft website, download the update manually, and install it with no problem... just in case anybody else was having this problem. But as far as error messages go... not helpful at all.)

      --
      Alexander Peter Kristopeit bought his basement from his mommy for one dollar.
    10. Re:Makes sense... by clone53421 · · Score: 1

      P.S. I actually can count; it was the same 3 updates over and over, plus 1 or 2 other updates have failed similarly since then and I have dealt with them in the same way. So 4 or 5, altogether.

      --
      Alexander Peter Kristopeit bought his basement from his mommy for one dollar.
    11. Re:Makes sense... by 0p7imu5_P2im3 · · Score: 2, Interesting

      Have you ever tried to code up a message box in Visual C++? It's worse than pulling teeth, especially when your application doesn't need to be interactive otherwise.

      --
      Resistance is futile. Your technological distinctiveness will be added to our own. You will become one with the morgue
    12. Re:Makes sense... by petermgreen · · Score: 4, Insightful

      mmm, and what's this bloody obsession with error codes. I was having trouble with windows update giving an error recently and the only expanatory information was an error code.

      After some time searching online and finding various speculation I eventually found that the code basically translated as "connection problem" and that I should try again later. Why couldn't they have just fucking told me that in the first place?!

      --
      note: i'm known as plugwash most places but i screwd up registering that here somehow in the past and now can't register
    13. Re:Makes sense... by Anonymous Coward · · Score: 0

      I didn't log on because I am afraid of backlash, but this has to be said.

      Well done Microsoft.

    14. Re:Makes sense... by westlake · · Score: 1
      The malicious software removal tool will take care of it. Their antivirus will not.

      Both MSRT and Microsoft Security Essentials will detect and remove Alureon A and its kin.

      Definition first published October 23. Revised March 10.

      That doesn't mean full a repair/recovery of every corrupted file:

      The top ten most commonly-targeted driver files are the following:

      atapi.sys
      iastor.sys
      iastorv.sys
      idechndr.sys
      nvata.sys
      nvatabus.sys
      nvgts.sys
      nvstor.sys
      nvstor32.sys
      sisraid.sys

      Users are advised to boot into a recovery environment and manually replace the file with a clean copy.

      Win32/Alureon may modify DNS settings on the host computer, thus the following steps may be required after the Win32/Alureon removal is complete:

      If the computer has a network interface that does not receive a configuration using DHCP, reset the DNS configuration if necessary.

      If a dial-up connection is sometimes used from the computer, reconfigure the dial-up settings in the rasphone.pbk file as necessary, as Win32/Alureon may set the fields "IpDnsAddress" and "IpDns2Address" in the rasphone.pbk file to the attacker's address. The Microsoft scanner code that automatically removes Win32/Alureon backs up the infected dial-up configuration file to:

      %allusersprofile%\Application Data\Microsoft\Network\Connections\Pbk\rasphone.pbk.bak

      Win32/Alureon

    15. Re:Makes sense... by Anonymous Coward · · Score: 0

      MS does have a nifty tool included with Visual Studio for looking up error codes. You can also look them up with "err.exe." You can also look them up with net helpmsg. Note that some errors will not be in 1-3 of those tools.

    16. Re:Makes sense... by hduff · · Score: 1

      But they are chastised for not coming up with a all-in-one solution? Jeez.

      No, they are being chastised for having designed an OS that is so easy to exploit and for failing to correct those deficiencies, preferring to let their users acquire additional software and expend additional time and money that all could have been avoided had they done a better job.

      Microsoft's poor security and vulnerability have spawned a significant large industry revolving around exploiting it and fix it.

      And the sad part is that sheeple just accept it as part of owning a computer.

      --
      "I believe in Karma. That means I can do bad things to people all day long and I assume they deserve it." : Dogbert
    17. Re:Makes sense... by HerculesMO · · Score: 1

      You do know that OS is about 10 years old at this point, right?

      You might want to try their new one.

      --
      The price is always right if someone else is paying.
    18. Re:Makes sense... by TheSpoom · · Score: 1

      I think it's part of the culture that has been taught to developers for a while to hide errors from the user, and instead log them for the administrator. Is it wise? Probably not in an OS, and definitely not for common errors like a connection issue (which is really more of an exception).

      --
      It's better to vote for what you want and not get it than to vote for what you don't want and get it.
      - E. Debs
    19. Re:Makes sense... by shutdown+-p+now · · Score: 1

      Have you ever tried to code up a message box in Visual C++? It's worse than pulling teeth

      You must have it really easy when it comes to pulling teeth, given that "coding up a message box" in Visual C++ is exactly one function call.

      For the record, it also doesn't matter if your application is interactive or not, so long as it's not a background service - this call will set up its own message pump, so it is completely self-sufficient. It can be a single line by itself inside int main(), and it will still work.

    20. Re:Makes sense... by 0p7imu5_P2im3 · · Score: 1

      Yeah, exactly one function call, that requires derivation from multiple classes in order to get the first parameter. It took twice as long to add in the MessageBox for my non-interactive program as it did to write the thing without it. I don't doubt Microsoft could do it, but it would require a much larger executable than without such code, and with something like 40% of Windows users still on 56K modem connections, that size comes at a premium.

      --
      Resistance is futile. Your technological distinctiveness will be added to our own. You will become one with the morgue
    21. Re:Makes sense... by shutdown+-p+now · · Score: 1

      Yeah, exactly one function call, that requires derivation from multiple classes in order to get the first parameter.

      What "classes"? Win32 API is pure C, it doesn't have classes.

      Do you mean "window classes"? Or are you using some object-oriented framework? If the latter, then your objections should really be to the writers of that framework.

      In any case, it still doesn't make any sense to me, because the first parameter can be NULL. If your application doesn't have any windows in the first place, that is precisely what you should do. E.g. the following is a valid and complete Win32 application:

      #include <windows.h>
      int main() {
        MessageBoxA(NULL, "Hello, world!", NULL, MB_OK);
      }

    22. Re:Makes sense... by 0p7imu5_P2im3 · · Score: 1

      This was a couple years ago, but IIRC, I tried putting NULL and it failed miserably. It's possible they have fixed it since.

      --
      Resistance is futile. Your technological distinctiveness will be added to our own. You will become one with the morgue
    23. Re:Makes sense... by shutdown+-p+now · · Score: 1

      This was a couple years ago, but IIRC, I tried putting NULL and it failed miserably. It's possible they have fixed it since.

      I've no idea what you were doing and where you were putting it, but the code that I've posted above has worked since that function first appeared (which might be Win 1.0, for all I know - it was already there in Win 3.1, before 32-bit transition), and never stopped working in any Windows version. If it did, it would break thousands of Windows applications.

      You keep referring to "non-interactive program", though. I don't know what, precisely, you mean by it, but I have a nagging suspicion that it was a Windows service. If so, then MessageBox wouldn't have worked, because services don't generally have access to UI (since there need not even be any UI to speak of when they run - e.g. before user logs in). The MSDN article even mentions that. In that case, it wouldn't work for you, but then a service/daemon trying to display a UI notification is horribly broken in the first place (who are you showing it to?) - it should use log files for that.

      In any case, in the scenario originally being discussed, it is a normal Windows application, so that does not apply.

    24. Re:Makes sense... by cbiltcliffe · · Score: 1

      My Windows XP computer doesn't have err.exe on it.
      It also doesn't have Visual Studio.

      And net helpmsg doesn't decode any 0x12345678 format errors, which is all I've ever seen anywhere important in Windows.

      Next suggestion?

      --
      "City hall" in German is "Rathaus" Kinda explains a few things......
    25. Re:Makes sense... by cbiltcliffe · · Score: 1

      If Microsoft can detect the rootkit

      They don't. They're checking hashes on key platform binaries to check if they're compromised -- that's not the same as detecting the nature of the compromise.

      This cannot be what they're doing. I cannot believe even Microsoft's marketing department could be this stupid.

      Hash checking will not reveal compromised binaries on a rootkit-infected machine. That's the whole point of a rootkit. It makes the operating system lie to you about the contents and existence of files related to the rootkit.

      Which means the machine will be infected, hash checks will pass, and the machine will BSOD on reboot.

      --
      "City hall" in German is "Rathaus" Kinda explains a few things......
  4. Time to reinstall it all by bobs666 · · Score: 1

    You keep your original software. Time to wipe it and reinstall. Of perhaps boot Linux and get a faster computer.

    1. Re:Time to reinstall it all by Skarecrow77 · · Score: 1

      windows and it's virus propensitiy is pretty much the only reason I'm still running linux as my desktop OS at this point. In pure useability, windows 7 wins, much as I hate to say it.

    2. Re:Time to reinstall it all by Nadaka · · Score: 1

      Not for me. I keep win7 for a few videogames that don't run on linux at all.

      If I want to watch something from my computer on my 42in HDTV and get sound through the hdmi cable?

      In windows 7 I must first turn my TV on and switch it to the apropriate hdmi channel, then reboot my computer or I get no audio.

      In ubuntu, it just works.

      If I plug an standard formatted SD memory card into my computer?

      In windows 7 it won't read the card unless it formats it first, even if it had previously formatted the exact same card card.

      In ubuntu it just works.

      Windows has only two advantages for me.
      It is easier to change my default monitor when using a stretched desktop.
      It runs a handful of video games that I like but don't work on ubuntu or even with wine.

    3. Re:Time to reinstall it all by digitalchinky · · Score: 1

      Clearly you don't 'hate to say it' - you are trolling.

      Windows 7 works for those who like that kind of thing, me, I require virtual desktops, a window manager that doesn't demand click to focus - has highlight copy - middle mouse paste, and on and on and on. Certainly MS Windows can be tweaked to do all these things, but generally not for free, and almost always not without drawbacks.

      So what is it, exactly, that makes Windows 7 better from a usability perspective? I'm curious.

    4. Re:Time to reinstall it all by Anonymous Coward · · Score: 0

      Clearly you don't 'hate to say it' - you are trolling.

      Windows 7 works for those who like that kind of thing, me, I require ...

      Clearly

    5. Re:Time to reinstall it all by Skarecrow77 · · Score: 1

      Yesterday I reformatted my HD after installing an Nvidia GTX 470. I put win7 on one partition, and ubuntu 10.04 beta2 on the other.

      I spent several hours last night fighting with 10.04 because it didn't like that I had a video card released only a week before the OS. I had to download 1 day old drivers from nvidia's site, and install those from command prompt with X shut down... ok that's a bit of a hassle, but whatever. Of course, OS didn't like that, it refused to let me stop the GDM service half the time, finally forced me to do it fully from command line. upon reboot, the x config file was somehow botched, and I had to recreate it a few times before I got it right. this wouldn't have been so bad if the first update manager run didn't immediately break the drivers -again-, forcing me to redownload it and reinstall it -again-. Windows 7? I went to nvidia's site, hit download. hit run. rebooted. I'm golden.

      Additionally, apparently despite documentation otherwise, "Auto" is not the default mount option on fstab mounts for cifs/samba shares, and it took me awhile to figure that out, wondering why mount -a would bring in my windows file server shares, but reboots wouldn't. I thought it must be UID or GID codes put in wrong, or credentials or something like that. Finally figured out it was just them changing defaults to the opposite of what they used to be. Windows 7? I clicked "map network drive", put in the network address, hit ok. That's it.

      finally, on top of all that, I don't have sound on movie files using AAC streams, despite the fact that I had such functionality with the same program in my year-old copy of the same OS. I've installed both gstreamer0.10-plugins-bad, faac, and faad and still nothing.

      I'm hardly about to say that windows 7 is problem free, but linux is quite far from "Just works" for me. I don't -want- to switch back to windows as my "daily driver" OS, but linux isn't exactly making a good case for itself here.

    6. Re:Time to reinstall it all by Anonymous Coward · · Score: 0

      This is the problem with Microsoft because they will not ship CDs with a new computer choosing instead to use a recovery partition which in and of itself could become compromised.

    7. Re:Time to reinstall it all by dhavleak · · Score: 1

      In windows 7 I must first turn my TV on and switch it to the apropriate hdmi channel, then reboot my computer or I get no audio

      Right click the speaker icon in the system tray, select the HDMI source, set it as default. Just Works(tm).

      If I plug an standard formatted SD memory card into my computer? In windows 7 it won't read the card unless it formats it first, even if it had previously formatted the exact same card card.

      Define standard? Doesn't sound right - SD cards Just Work.

    8. Re:Time to reinstall it all by amliebsch · · Score: 1

      Uh...Microsoft doesn't sell computers. Perhaps you meant to blame HP?

      --
      If you don't know where you are going, you will wind up somewhere else.
    9. Re:Time to reinstall it all by Nadaka · · Score: 1

      absolutely wrong.

      The hdmi audio output is not selectable in win 7 because it is "not plugged in" unless the tv is tuned to the hdmi channel during boot up of the machine, even if the cable is never unplugged.

      standard as in fat32, strait from a camera or any other computer. And no, they don't work. Because I have to format every time a card is plugged in, I can only remove files from the computer while in windows.

    10. Re:Time to reinstall it all by Nadaka · · Score: 1

      I am running ubuntu 9.10 and quite happy with it. It could be possible that some of your problems are a result of using the beta testing version of ubuntu.

    11. Re:Time to reinstall it all by david_thornley · · Score: 1

      GP's anecdote beats your anecdote, since GP wasn't complaining about issues with software clearly marked "beta".

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    12. Re:Time to reinstall it all by mat128 · · Score: 1

      Please remember that you tried Ubuntu 10.04 *beta 2*... Comparing a beta version of an OS against a final, second iteration of a major kernel version (vista was 6.0, 7 is 6.1)...
      Also, nVidia puts much more testing in it's Windows drivers than the linux ones, reason being their market is much more on windows than linux, but at least they're trying, unlike ATi (or AMD).

    13. Re:Time to reinstall it all by dhavleak · · Score: 1

      absolutely wrong.

      Easy there. I'm trying to help you.

      The hdmi audio output is not selectable in win 7 because it is "not plugged in" unless the tv is tuned to the hdmi channel during boot up of the machine, even if the cable is never unplugged.

      What TV do you have? On all three of my Win7 machines my panasoic plasma will show up when I plug it in. Rinse/repeat/plug/unplug, it will appear/disappear on queue. When it's present (by whatever means you're using), set it as default -- and you should be all set.

      standard as in fat32, strait from a camera or any other computer. And no, they don't work. Because I have to format every time a card is plugged in, I can only remove files from the computer while in windows.

      Fat32 is not standard for SD cards - exfat is. What camera are you using?

    14. Re:Time to reinstall it all by general_re · · Score: 1

      absolutely wrong.

      The hdmi audio output is not selectable in win 7 because it is "not plugged in" unless the tv is tuned to the hdmi channel during boot up of the machine, even if the cable is never unplugged.

      You've got crappy drivers, then - I can select HDMI out and set it as the default output whether there's anything plugged in or not. Try newer drivers or a better audio card. Either way, it's clearly not the OS.

      --
      ABSURDITY, n.: A statement or belief manifestly inconsistent with one's own opinion.
    15. Re:Time to reinstall it all by dhavleak · · Score: 1

      Hmm.. on further reading it looks like FAT *is* standard and not exfat. I can only conclude that your camera is set to (or defaults to) some other format. You should look at the formatting options for your camera. It's unlikely that the camera cannot format the SD card in a format that Win7 (or any Windows OS) cannot read. It's unlikely that Win7 would ship without being able to read SD Cards from pretty much any mainstream camera. For both parties (Microsoft and camera manufactureres) this is too mainstream a scenario. There is 100% something quirky in your setup, and the issue should be solvable.

    16. Re:Time to reinstall it all by Skarecrow77 · · Score: 1

      I am fully aware that the OS is in beta, but I seriously doubt that they're going to switch the Nvidia GLX version included with the OS within the next 2 weeks, it's damn close to feature lock, if it isn't there already. It's the version included with the OS that's the problem, and removing the included nvidia blob to use one from their website has been a problem at least back to 8.04 (as far back as I cared to check). 2 more weeks isn't going to fix that issue.

      To the best of my knowledge, gstreamer0.10 is the same version that's in 9.10 (don't remember which version I used in 9.04). We're not dealing with cutting-edge stuff there either. Perhaps I'm wrong, but I'm pretty sure that the Totem version in 10.04 is only a minor revision over 9.10 as well. I'll be quite happy if an update manager run gets rid of that problem as well, but again I doubt it. more than likely there's still some other package I need to install and I have no idea what it could possibly be.

      I don't know what's up with the fstab issue. that one may very well be a bug, but I can't understand how I'm the first person to notice it.

      My point was not that "beta os is buggy". my point is "In many (if not most) cases, linux workflows are significantly more difficult, time intensive, and frustrating than similar windows workflowson all but the absolute best case scenarios".

      I'm not a fanboy of either operating system. I'm looking for the best fit for me, and both of them have issues I dislike. I'm quite capible of overcoming Linux problems, I just don't see why I should have to spend that much time doing so.

    17. Re:Time to reinstall it all by Nadaka · · Score: 1

      "What TV do you have? On all three of my Win7 machines my panasoic plasma will show up when I plug it in. Rinse/repeat/plug/unplug, it will appear/disappear on queue. When it's present (by whatever means you're using), set it as default -- and you should be all set. "

      That does not work. Like I said before. the only way for audio to work (in windows 7, it works just fine in ubuntu 9.10) is if the tv is tuned to the hdmi channel while the computer boots, only then can I select hdmi as the audio output. And if the computer boots without the tv tuned, even though it was previously selected as default, it can not detect and does not work. The kind of TV I have is not relevant because it works perfectly in Ubuntu, Dynex if it matters.

      "Fat32 is not standard for SD cards - exfat is. What camera are you using?"

      Alright, that right there tells me you don't know what you are talking about. Fat and fat32 are the most common file systems used on sd and sdhc cards, period. ExFat was only really recommended for the SDXC format last year, and that is still a block level device supporting fat32.

    18. Re:Time to reinstall it all by Nadaka · · Score: 1

      If it was not the OS, why does Ubuntu work flawlessly right out of the box?

    19. Re:Time to reinstall it all by dhavleak · · Score: 1

      "Alright, that right there tells me you don't know what you are talking about."
      The kind of TV I have is not relevant because it works perfectly in Ubuntu, Dynex if it matters."
      I guess you were just spoiling for a fight it looks like. Will have to mark this down as "my anecdote evidence does not match your anecdote". I already acknowledged my error with the file-format before you spewed venom.

    20. Re:Time to reinstall it all by drsmithy · · Score: 1

      So what is it, exactly, that makes Windows 7 better from a usability perspective? I'm curious.

      It doesn't have incredibly annoying UI misfeatures like focus-follows-mouse and highlight copy ?

    21. Re:Time to reinstall it all by Anonymous Coward · · Score: 0

      Yeah, if I want to watch Netflix on my computer in Ubuntu, I just open up Firefox and point it at... damn.

    22. Re:Time to reinstall it all by aztracker1 · · Score: 1

      The last version of Ubuntu I tried, was a release version with broken (regression issues) for video drivers on almost 2/3 of the computers out there (intel integrated graphics). 9.04 on my Eee netbook specifically. Yeah, creating a release that will have a total fail when running even Frozen Bubble fullscreen, or playing flash on more than half the desktop computers in existence isn't a problem.

      --
      Michael J. Ryan - tracker1.info
    23. Re:Time to reinstall it all by Amnenth · · Score: 1

      Drivers.

    24. Re:Time to reinstall it all by Nadaka · · Score: 1

      Possible, likely even. But Ubuntu was sufficiently capable of overcoming whatever driver problems there were and windows 7 simply was not.

      I have not checked in a month or two, but the latest drivers for my hardware didn't fix the problem in windows 7.

    25. Re:Time to reinstall it all by Anonymous Coward · · Score: 0

      He fixed his error regarding the file system long before you replied with your asinine comment. What the hell crawled up your ass? Chill out with the elitist nerd/internet tough guy shit.

    26. Re:Time to reinstall it all by yukk · · Score: 1

      What most people don't realise at all is that pretty much all the hardware out there that Linux is run on was developed for Windows. That means that before it hits the shelves it's been designed and had drivers written to work with Windows. Linux is lucky if it has a "best effort" driver coded by the hardware manufacturer.
      Othewise all these drivers are coded by people supporting Linux and not the hardware.
      That's why stuff "just works" in Windows. That's the way it was designed.
      That's like saying that you bought two Ford gearboxes and when you put one in your Ford it "Just worked" but when you tried to put the other into your Volkswagon you had too much trouble and therefore VWs suck.
      On the other hand you're right and it's unfair to expect your grandmother to get that gearbox into the Volkswagon.

      --
      The trouble with the rat race is that even if you win, you're still a rat." Lily Tomlin
    27. Re:Time to reinstall it all by yukk · · Score: 1

      So what is it, exactly, that makes Windows 7 better from a usability perspective? I'm curious.

      It doesn't have incredibly annoying UI misfeatures like focus-follows-mouse and highlight copy ?

      I think you have it exactly wrong there. I wish it did have useful features exactly like those two.

      --
      The trouble with the rat race is that even if you win, you're still a rat." Lily Tomlin
    28. Re:Time to reinstall it all by Anonymous Coward · · Score: 0

      He's probably jumped through whatever hoops are necessary for Ubuntu and now that's the only audio interface that's configured and audio goes there whether you like it or not. Linux tends to be like that.

    29. Re:Time to reinstall it all by Skarecrow77 · · Score: 1

      Look, I WANT linux to be the best, I'm rooting for it to be the best, but considering I work a job where I solve other people's computer problems for 8-9 hours a day, I don't want to come home to spend my evening trying to fix my own because update manager pulled down a new version of wine or video driver or something.

      Yes yes, I know, OSX is probably what I'm really looking for, and I'd be happy to try it if there wasn't a 100% markup on the hardware involved.

    30. Re:Time to reinstall it all by LinuxIsGarbage · · Score: 1

      I have not seen a computer that ships without a recovery DVD that won't beg you to burn off recovery DVDs. But again it's an OEM issue, not Microsoft.

  5. I understand why MS is doing this... by teknopurge · · Score: 1

    Provided they[MS] provides doco on how to remove the rootkit, I don't take issue with this. This is similar to MS testing a 3rd-party developers product to make sure it works, when in the marketplace it's the job of the 3rd-party shop. Somehow I doubt the rootkit devs are going to get their kit validated by MS as a certified app......

    1. Re:I understand why MS is doing this... by Anonymous Coward · · Score: 0

      "Provided they[MS] provides doco on how to remove the rootkit, I don't take issue with this."
                I don't take issue with it even if they just say "patch denied because your box is pwned." I'm sure they will be more helpful, but...

                It's interesting if they start doing this regularly on patches. One of the big problems with windows has been in effect a lack of package management, if they retrofit in some detection of "non-stock" DLLs etc. in the last few patches for XP it's certainly better than nothing, and certainly better than knocking your box out of comission with a badly interacting update.

                (With all that said, I have 2 gentoo boxes with the rest ubuntu, so windows is not terribly relevant to me personally.)

               

  6. The right thing to do by techno-vampire · · Score: 2, Informative

    If Microsoft has a way of detecting the rootkit, they should make it available separately so that people can test their machines before they try to update them. Of course, this is Microsoft we're talking about, so you know they're not interested in what's right unless it's also profitable.

    --
    Good, inexpensive web hosting
    1. Re:The right thing to do by Skarecrow77 · · Score: 1

      patching 9 year old operating systems that they've "obsoleted" twice now, is "profitable"? really?

    2. Re:The right thing to do by jedidiah · · Score: 1

      It doesn't matter how old XP is.

      It only matters how old the machine is that came pre-installed with it.

      It's moronic and highly anti-consumer to advocate anything else.

      --
      A Pirate and a Puritan look the same on a balance sheet.
    3. Re:The right thing to do by Anonymous Coward · · Score: 0

      It's called the malicious software removal tool. I'm pretty sure it comes down automatically through Windows Update too.

    4. Re:The right thing to do by Anonymous Coward · · Score: 0

      They did. Check out Microsoft Malware Removal Tool, or Windows Defender, or Microsoft Security Essentials.

    5. Re:The right thing to do by willda · · Score: 0

      They do have a way to detect the rootkit.......it's call the malicious software removal tool.

    6. Re:The right thing to do by TrancePhreak · · Score: 2, Informative

      If Microsoft has a way of detecting the rootkit, they should make it available separately so that people can test their machines before they try to update them.

      They do just this. Malicious Software Removal Tool.

      --

      -]Phreak Out[-
    7. Re:The right thing to do by Anonymous Coward · · Score: 0

      This would just make it possible for every rootkit producer to "test" their techniques against the latest patches. There are no perfect ideas, but if MSFT has an effective mechanism for detecting rootkits, there are many good reasons not to make the tool run-on-demand.

    8. Re:The right thing to do by Anonymous Coward · · Score: 0

      Ever heard of their Malicious software removal tool? It downloads every month with their patches and just happens to do that, it IS a separate download, But I suppose its easy to over look something that has only been in place for a couple of years now.

    9. Re:The right thing to do by techno-vampire · · Score: 1
      Ever heard of their Malicious software removal tool?

      As a matter of fact, no. I run a Linux only household and as long as Microsoft has 90%+ market share, such things have only a minor academic interest for me.

      --
      Good, inexpensive web hosting
    10. Re:The right thing to do by maxwell+demon · · Score: 1

      Why would I run a malicious tool? Especially a malicious software removal tool? I'm sure it would remove exactly that software where I can't find the installation media any more! :-)

      --
      The Tao of math: The numbers you can count are not the real numbers.
    11. Re:The right thing to do by 2short · · Score: 1

      Ever heard of their Malicious software removal tool?

      As a matter of fact, no. I run a Linux only household and as long as Microsoft has 90%+ market share, such things have only a minor academic interest for me.

      A "minor academic interest" in such things would imply you are slightly interested in gaining knowledge about them, if not for practical reasons. By complaining that Microsoft is bad for not doing what they actually do ( and what the fine article says they do), it would appear you have more of a "religious (dis)interest" in the facts of the case at hand.

    12. Re:The right thing to do by Fishchip · · Score: 1

      Ahhh, you crazy trend-bucker you. You should use Haiku, it has an even smaller market share!

    13. Re:The right thing to do by thoughtsatthemoment · · Score: 1

      It's more profitable than the user switching to Linux.

    14. Re:The right thing to do by techno-vampire · · Score: 1
      it would appear you have more of a "religious (dis)interest" in the facts of the case at hand.

      Actually, no. I have friends who use Windows. I don't try to "convert" them, because if that's what they like or are used to, there's no reason for them to change. It is, however, nice to know that Microsoft actually does make this tool available, and that anybody using XP who wants to avoid this issue has a good, free way of doing it.

      --
      Good, inexpensive web hosting
    15. Re:The right thing to do by Anonymous Coward · · Score: 1, Insightful

      If HP sold a laptop with DOS or BeOS you would expect support?

    16. Re:The right thing to do by Skuld-Chan · · Score: 1

      Have you even heard of Windows MSRT?

    17. Re:The right thing to do by LinuxIsGarbage · · Score: 1

      If Microsoft has a way of detecting the rootkit, they should make it available separately so that people can test their machines before they try to update them. Of course, this is Microsoft we're talking about, so you know they're not interested in what's right unless it's also profitable.

      http://www.microsoft.com/security/malwareremove/default.aspx

      XP Will keep getting security updates until at least 2014. It was rendered obsolete in early 2007. Try getting OSX Tiger updates. It was dropped like a rock seconds after Leopard came out

    18. Re:The right thing to do by Anonymous Coward · · Score: 0

      If Microsoft has a way of detecting the rootkit, they should make it available separately so that people can test their machines before they try to update them. Of course, this is Microsoft we're talking about, so you know they're not interested in what's right unless it's also profitable.

      http://www.microsoft.com/security_essentials/

    19. Re:The right thing to do by b4dc0d3r · · Score: 1

      I like linux but I run Windows everywhere, and I'm only vaguely aware of this tool. I un-check it every time I do a Windows update, usually with a "Ha, like I'd let you run on my machine" type snark. I wouldn't think it's reasonable to expect a Windows user to be aware of whether it detects rootkits, especially the typical user since auto-updates happen without even registering (or auto-updates are turned off, either way most windows users never even see it). It started out just removing worms and trojans, and I never even expected it to detect rootkits. If I never did Windows Updates manually to filter out genuine advantage and other garbage I'd not even think about it.

      I would trust Rootkit Revealer from Sysinternals before I'd trust something Microsoft sends (yes I know they are the same company). I'm not saying there's a problem with it, in fact Windows Defender seems to be very highly recommended and lightweight compared to free antivirus solutions, so I'm sure MSRT does a fine job on a specific set of known maliciousfiles.

      I have a religious disinterest in this case, since I'm aware of it and refuse to learn about it. The linux poster who knows nothing about it is simply ignorant (not an insult, simply lacking facts). I would classify "minor academic interest" as picking up new information if it comes along and happens to be meaningful to stick, not actively seeking information. The fine line is whether someone actively avoids learning, or simply allows opportunities to slip by. I actively avoid it, and I both know and admit it, but looks like this poster simply lets it slide.

      In fact, most of the Anti-virus vendors are complaining about the unfair monopoly MS has, destroying their business prospects by including Antivirus out of the box. But most of the reporting is on Windows Defender, completely ignoring (or mentioning without much description) the Malicious Software Removal Tool. It's more likely that someone following news for nerds knows about Defender than the MSRT.

      You could have simply said RTFA or included this quote:

      the company has urged users to download its Malicious Software Removal Tool to clean up their machines and run the patch as soon as possible.

      That would have been a much better, and as I illustrated above more accurate, reply than "religious disinterest", unless you meant of the article rather than Microsoft-related stuff.

      So now we have the question of whether a linux user would reasonably be aware of Windows Defender, which constitute the other 20 or so redundant replies to this question. I admit that when I come across a linux antivirus article, I've learned that it does not apply to Windows and so I ignore it. I'd expect the same from a linux user on Windows A/V articles. Surely the A/V industry complaints about Microsoft's monopoly abuse have managed to get through? No, the brain at some point cannot stand any more "Microsoft accused of abusing its monopoly" stories and just skips on.

      The only reason I'm aware of Windows Defender as a Microsoft user and programmer (.NET, T-SQL, Win32, VBS, broken CSS, and some others and semi-active in the ReactOS community so I'm fully entrenched) is because a recent "Ask Slashdot" asked about free antivirus, and almost across the board Defender was the recommendation. I got tired of AVG's continued bloat and silly issues like only using the C drive for updates (which can cause out of diskspace errors, which is made worse because it doesn't clean up after itself), so I read the article - otherwise I would have ignored it.

      Put yourself in someone else's shoes before making a reply, it makes the discussion flow better. I've violated that a few times myself and I cringe when I scroll past those comments in my post history, but I try to do better.

      MSRT history of which files are detected in each release so that someone can correct me if one of the originals was a rootkit (Hackdef was added in April, maybe there was one before that):
      http://support.microsoft.com/?kbid=890830

  7. Lesser of two evils? by HockeyPuck · · Score: 5, Insightful

    Let's see what do I want?

    A) A working machine that has a rootkit installed.
    B) A machine that nolonger works.

    Can you expect MSFT to test their patches against machines that have been modified via rootkits? Or should the patches themselves remove the rootkits. You are assuming that MSFT can remove the rootkit in the first place.

    1. Re:Lesser of two evils? by Anonymous Coward · · Score: 0

      My guess, though I haven't RTFA or anything, is that Microsoft simply does not show the update as available. It seems they could at least show a warning saying the computer probably has a rootkit, since they can detect it anyways.

    2. Re:Lesser of two evils? by spidercoz · · Score: 1, Insightful

      C) A working machine that's immune to rootkits and doesn't have an obsolete OS.

      hint: always choose C.

      --
      "I disapprove of what you say, but I will defend to the death your right to say it." - Evelyn Beatrice Hall, re Voltaire
    3. Re:Lesser of two evils? by clone53421 · · Score: 1

      What is this miraculous machine to which you refer?

      --
      Alexander Peter Kristopeit bought his basement from his mommy for one dollar.
    4. Re:Lesser of two evils? by Rockoon · · Score: 1

      I'm sure that you've HURD of it.

      ..oh..did you want one that actually works and stuff?

      --
      "His name was James Damore."
    5. Re:Lesser of two evils? by Dishevel · · Score: 1

      Immune is a strong word and obsolete would be in the eye of the beholder, but I kind of like Ubuntu. Updates regularly. Works. Never had a virus. Would have to be an idiot to allow it to get rooted. YMMV.

      --
      Why is it so hard to only have politicians for a few years, then have them go away?
    6. Re:Lesser of two evils? by Mordok-DestroyerOfWo · · Score: 1

      My NES has proven remarkably efficient at blocking rootkits. I was able to get one loaded as a test, but I had to blow real hard on it first.

      --
      "Never let your sense of morals prevent you from doing what is right" - Salvor Hardin
    7. Re:Lesser of two evils? by maxwell+demon · · Score: 1

      A sufficiently old car. It's a working machine (assuming it's not broken), it's immune to rootkits (because it has no processor which could run them) and it doesn't have an obsolete OS (it has no OS at all).

      --
      The Tao of math: The numbers you can count are not the real numbers.
    8. Re:Lesser of two evils? by clone53421 · · Score: 2, Funny

      It most certainly does have an Operating System. In fact if it has disc brakes it even has a Disc Operating System...

      --
      Alexander Peter Kristopeit bought his basement from his mommy for one dollar.
    9. Re:Lesser of two evils? by Anonymous Coward · · Score: 1, Insightful

      I want you to have (B).

    10. Re:Lesser of two evils? by IHateEverybody · · Score: 1

      Well Microsoft has been pretty aggressive about pushing its Malicious Software Removal Tool onto computers. So if I were Microsoft and my software detects a rootkit that the MSRT can't remove, I think I'd probably put a higher priority on updating the MSRT so that it can remove the rootkit. And then I can start patching my other software bugs.

      --
      Does this .sig make my butt look big?
    11. Re:Lesser of two evils? by LinuxIsGarbage · · Score: 1

      But what if the user declines to run MRT? Should they then just let the update bork the system?

    12. Re:Lesser of two evils? by spidr_mnky · · Score: 1

      Working? I guess "working against you" is technically "working"...

  8. Misuse of phrase by girlintraining · · Score: 4, Funny

    What ever happened to backwards compatibility? Why, I remember the day when any virus, worm, or piece of malware, would run no matter what!

    --
    #fuckbeta #iamslashdot #dicemustdie
    1. Re:Misuse of phrase by Anonymous Coward · · Score: 0

      Because at some point you have to let the backwards compatibility ride off into the sunset for the good of the majority of your client base. Have you heard of MS still supporting Win 3.1? Have you heard of Apple still supporting the 2E with new software updates? Have you heard IBM patching OS/2 with a new security fix?

    2. Re:Misuse of phrase by Hurricane78 · · Score: 1

      But: Application software: Not so much! ^^

      --
      Any sufficiently advanced intelligence is indistinguishable from stupidity.
    3. Re:Misuse of phrase by VGPowerlord · · Score: 1

      Have you heard of MS still supporting Win 3.1?

      Most Win 3.1 non-filesystem related programs will still run on Windows 7 32-bit. Not on 64-bit though.

      --
      GLaDOS for President 2016! "Well here we are again. It's always such a pleasure." -- GLaDOS, 2011
    4. Re:Misuse of phrase by hairyfeet · · Score: 1

      Actually if you really wanted to run Win3.x programs it is trivial to load DOSBox which will let you run pretty much anything from DOS through Win9X software easily, even on x64. How's THAT for backwards compatibility! That is one of the things I like about Good Old Games, for their older titles they come with a preconfigured DOSBox so it runs like a native app. Nice!

      As far as TFA goes, I doubt really seriously MSFT can do much more than block the infected machines from running Windows update. for those saying "pop up a msgbox"? Most of these newer malware infections are hooked so deep you pretty much can't launch squat, including popping up a msgbox, without the program intercepting it and shutting it down. No CMD, no Run command, no Task Manager, nothing. It goes in and screws with all the permissions for anything other than itself so any attempt and bringing up another program results in "You do not have permission to perform this action. Please contact your system administrator".

      So I doubt if it is anything like the malware that has been crossing my desk lately MSFT can do anything else. The Malicious Software Removal Tool gets its ass royally kicked by this new malware, especially the new "Fake security tool" crap like ST2010 and AV2010. Pretty much all the users can do is take it to a shop, as MSFT probably can't even pop a msgbox on one of those. they may be able to bring up a web page with a warning, but even that is doubtful as many of the new ones hijack all browser requests as well. Trust me they are really nasty bastards to deal with.

      --
      ACs don't waste your time replying, your posts are never seen by me.
    5. Re:Misuse of phrase by LinuxIsGarbage · · Score: 1

      Your 16 bit apps will still run in XP-mode. If you don't have Pro or ultimate, you can get free IE compatability VHDs You can also use trusty old DOS "ed" in Win7 x64

    6. Re:Misuse of phrase by VGPowerlord · · Score: 1

      I didn't mention XP mode, because most users will probably have Home Premium installed and not have it available.

      The free IE compatibility VHDs have a built-in expiration date. I suppose you could change your clock back (remembering to disable the option to set time from the Internet)...

      --
      GLaDOS for President 2016! "Well here we are again. It's always such a pleasure." -- GLaDOS, 2011
  9. And the issue is? by dirk · · Score: 5, Insightful

    I really don't have a problem with this. If the system is already rooted, the patch isn't going to actually help anything since their security is already compromised. And with all the bad press MS received last time over something that was not their fault at all, why should they risk it again? If your system has a serious issue like being rooted, then you have to take care of the issue before you can install the patch. Seems logical to me.

    --

    "Information wants to be expensive" - Stewart Brand, the same guy who said "Information wants to be free"
    1. Re:And the issue is? by rickb928 · · Score: 2, Informative

      If this was all caused by some commercial software, say, Adobe Reader gaining a bug that hosed Windows Update, we would be all over Adobe for breaking Windows Update and denying us our precious patches.

      So far, very little scorn for the rootkit author(s) or their legion of distributors.

      I get alerted to malware of various types, from Javascript exploits to out-and-out rootkits, from several interesting websites I visit frequently. I've been reduced to checking them on my phone, cause so far they haven't taken on an advertiser that delivers Android malware. So far. Even my Ubuntu with Firefox sees attacks.

      Place the blame where it belongs; Malware distributors and authors, lazy/incompetent/naive users clicking away on pretty stuff, and of course the Windows security community for the abject failure that is Windows 'security', in name only. Windows Update is doing the right thing - alerting users to the potential for serious system failure and the cause. Plowing along and bricking systems is irresponsible.

      Rootkits and the ad servers delivering them should be brought up on criminal charges. Surreptitiously installing software on my machine without my permission should be trespass, and punished accordingly, right up the food chain. Yes, that would mean some day a nice man from the FBI coming into a NAP and cutting off fiber connectors. If you run a red light while drunk, you get the full monty. Go all the way and punish malware by shutting down the ad servers that are delivering it, and you will get action.

      Of course, if that fails, then you go to the New York times, for example, and explain why you are shutting down their sites - they chose web ad agencies badly. Tough. Accountability.

      --
      deleting the extra space after periods so i can stay relevant, yeah.
  10. Why bother? by trifish · · Score: 5, Insightful

    Rightfully so. Security patching a rootkit-ed OS is mildly amusing and also a bit redundant. The only way to secure such an OS starts with reformatting the system partition.

    1. Re:Why bother? by gzipped_tar · · Score: 1

      I see your point, but I guess by "redundant" you meant to say "futile", or has my humor filter been rooted?

      --
      Colorless green Cthulhu waits dreaming furiously.
    2. Re:Why bother? by SCPRedMage · · Score: 1

      Actually, I rooted it last night. I used this access to encrypt your humor-related files, and will give you the encryption keys once you wire $1,000,000.00 USD to my overseas bank account.

      --
      My sig can beat up your sig.
    3. Re:Why bother? by ZiggyM · · Score: 1

      Reformatting the hard disk is not enough. The rootkid could hide on some device's firmare or even the graphics card memory. http://www.eweek.com/c/a/Security/Black-Hat-Demonstrations-Shatter-Hardware-Hacking-Myths/

    4. Re:Why bother? by Anonymous Coward · · Score: 0

      Did he say reformatting the hard disk is enough? You need to work on your reading comprehension, dude.

    5. Re:Why bother? by maxwell+demon · · Score: 1

      The only way to secure such an OS starts with reformatting the system partition.

      No, it starts with nuking it from orbit. It's the only way to be sure.

      --
      The Tao of math: The numbers you can count are not the real numbers.
    6. Re:Why bother? by mcgrew · · Score: 1

      Security patching a rootkit-ed OS is mildly amusing and also a bit redundant

      Car analogy: it's like fixing you door lock and leaving the broken out window unrepaired.

  11. Misleading title by Anonymous Coward · · Score: 1, Insightful

    The title is totally misleading. It gives the sense that Microsoft refuses to deliver some patch that fixes the rootkit infection. While in fact Microsoft avoids to deliver the patch to keep the machines in a working (albeit infected) condition.

    I bet that the poster is a fanboi that found his opportunity to bash Microsoft... :-P

    1. Re:Misleading title by SCPRedMage · · Score: 5, Insightful

      Screw that. Deliver the patch, BSOD the idiots, and get them off the net so that they're not a danger to the rest of the world.

      --
      My sig can beat up your sig.
    2. Re:Misleading title by willda · · Score: 0

      Point taken..........fewer bots and such.

    3. Re:Misleading title by AnotherUsername · · Score: 1
      So, if somebody isn't running your pet operating system, or they aren't as technically skilled as you, they automatically deserve everything they get? Your social skills are astounding, to say the least. I bet you get all the ladies.

      "You mean to tell me that you don't know how to set up and admin a Cisco network? You don't know C? Get away from me, whore!"

      The fact that your comment was modded insightful is discouraging, yet expected, to say the least. How sad.

      How about realizing that not everyone is a computer guru, and sometimes people, while doing something 'stupid', may not understand that what they are doing is harmful. Such as clicking on popups for 'security software'. People who are not technically literate may not know not to click on those. They can use the Internet, and use a word processing program, but they don't know the security protocols that come with using computers, because people like you simply harass them and call them idiots because they don't know everything you do.

      I hope you understand that the very same people that you make fun of for not being technically literate can probably run circles around you in other areas. How much do you know about vehicles? Farming? Construction? Plumbing? Healthcare? Be sure to be the supreme expert in all areas of life before you start labeling people idiots.

      --
      I don't like Linux. This doesn't make me a troll.
    4. Re:Misleading title by SCPRedMage · · Score: 1

      Nice strawman argument. Too bad you're full of shit. Knowing not to do stupid shit on the net and to run antivirus software is nowhere near knowing Cisco networks or any form of programming at all, but you do an excellent job trying to equate them.

      I don't think that everyone needs to be as technically literate as I am, but I DO believe that they have the responsibility for what their machines do. And if they're a part of a bot-net, they're sending out spam, participating in DDoS's, etc.

      AND THEY ARE FULLY RESPONSIBLE FOR THAT.

      If patching rooted systems causes them to BSOD, do it. It's probably the ONLY way to FORCE the uneducated user to get his system cleaned.

      I'll admit that I know nothing of vehicle maintenance, farming, construction, plumbing, OR healthcare. But if I try my hand at any of those, I'm responsible for the outcome. If I try a heart-transplant without knowing what the hell I'm doing, I GO TO JAIL. Yeah, that example is pretty extreme, but it should get my point across.

      My point is that yes, these people SHOULD be allowed to use their computers. They SHOULD be allowed to be on the Internet. But they NEED to keep their systems clean, and if they won't take the time to learn, or don't know that they need to, they need a wake-up call. And considering that people have a tendency to stick their heads in the sand and ignore all but the most extreme signs, they need an EXTREME wake-up call. Like, say, their systems suddenly not working, prompting them to either buy a new system (a temporary fix for the root problem), or hire an expert to fix the computer, who will hopefully figure out what actually happened and let them know. Once people understand that they need to not be stupid OR ELSE, they'll learn.

      OR ELSE.

      --
      My sig can beat up your sig.
    5. Re:Misleading title by Fishchip · · Score: 1

      What, did BSODing someone's machine somehow suddenly cut all their ties to the net for life? They'll find other machines, admittedly with newer OSes, but they'll still be in the same old habits.

    6. Re:Misleading title by SCPRedMage · · Score: 1

      Until the next time this happens. If the systems that they use all eventually go down, either they'll get fed up and stop using the Internet, or they'll try to figure out what's going on.

      And even if they don't, a temporary benefit for us is still a benefit...

      --
      My sig can beat up your sig.
    7. Re:Misleading title by aztracker1 · · Score: 1

      Maybe it should change their default browser to IE, without any plugins/addons/toolbars, and point it to a page to download the malicious software removal tool, and microsoft security essentials, with a warning, your machine is compromised... Hell, I wouldn't mind if more broadband ISPs did this as a blind intercept via DNS for requests coming from a compromised system.

      --
      Michael J. Ryan - tracker1.info
    8. Re:Misleading title by Anonymous Coward · · Score: 0

      Actually this is pretty good point.

    9. Re:Misleading title by SCPRedMage · · Score: 1

      A good idea, but I wouldn't be surprised if a large number of people ignored said warning.

      Personally, I think that if an ISP can POSITIVELY identify a customer with a compromised system, they should isolate them from the rest of the network, and forward all their HTTP requests to a webserver explaining what's going on.

      --
      My sig can beat up your sig.
    10. Re:Misleading title by Skuld-Chan · · Score: 1

      I think the idea is to deploy MSRT - let it do its thing, and then the patches will install. That approach seems a bit more sane.

    11. Re:Misleading title by SCPRedMage · · Score: 1

      Except that the kind of user that would stay infected long enough for this to be an issue don't even KNOW about the MSRT, let alone would think that they should use it...

      --
      My sig can beat up your sig.
    12. Re:Misleading title by LinuxIsGarbage · · Score: 1

      Even though it's pushed through Windows update?

    13. Re:Misleading title by aztracker1 · · Score: 1

      That was actually, kind of what I had meant... Generally an ISP *can* know who is infected simply based on outbound mail traffic, let alone other vectors directly. I agree with the isolation, and as I said would do a DNS interception in order to facilitate direction to an isolated set of pages, with a clear label that it's the ISP's page/site.

      --
      Michael J. Ryan - tracker1.info
  12. Microsoft - Pragmatic solution to hard issue. by irreverant · · Score: 5, Interesting

    I think microsoft acted responsibly in this situation. They merely mitigated any future issues these patches might have, they didn't want the same thing to happen again. In this case it was prevention not intervention. Unfortunately, there are many ways to get a rootkit installed on a computer; however, most of the time it's usually the user that infected themselves. This is why there are measures that a user can take to prevent or minimize the occurrence. Microsoft did make a note to remove the infection and then install the patch. If they don't know how to remove the infection or don't know they can download if not purchase one of many anti-virus solutions or pay someone to do it, then maybe the user's should rethink their web browsing behaviors.

    --
    Of all the things I've lost; I miss my mind the most. - Mark Twain
    1. Re:Microsoft - Pragmatic solution to hard issue. by Rich0 · · Score: 1

      I tend to agree. If I were running a megacorp with 30k computers, and it turns out that 1000 of them have a rootkit I'd rather that they didn't just all die at the same time from a random patch.

      Of course, I'd be scanning for stuff like this anyway, so I'd be fixing these problems before they got out of hand.

      Even so, adding a major outage to a major security problem isn't necessarily an improvement.

    2. Re:Microsoft - Pragmatic solution to hard issue. by VGPowerlord · · Score: 2, Insightful

      Microsoft also included some measures in newer versions of Windows to mitigate user stupidity... and even one to mitigate programmer stupidity in Internet Explorer.

      Not that there aren't still holes in those methods... or the user can just be stupid and click Allow.

      --
      GLaDOS for President 2016! "Well here we are again. It's always such a pleasure." -- GLaDOS, 2011
  13. The Important Question by Anonymous Coward · · Score: 0

    So, does this detection result in a message like "Windows Update had an error. Code 0xB302392838271" or "YOU'VE BEEN HACKED!!! GET YOUR COMPUTER FIXED!!!!"?

    1. Re:The Important Question by BadAnalogyGuy · · Score: 2, Informative

      Code 0xB302392838271

      This is why I come to Slashdot. So many computer-literate people...

    2. Re:The Important Question by Anonymous Coward · · Score: 0

      Coool... Windows 42-bit edition!

    3. Re:The Important Question by Anonymous Coward · · Score: 0

      42 may be the Answer, but that's 52 bits...

    4. Re:The Important Question by The+Archon+V2.0 · · Score: 1

      So, does this detection result in a message like "Windows Update had an error. Code 0xB302392838271" or "YOU'VE BEEN HACKED!!! GET YOUR COMPUTER FIXED!!!!"?

      Oh, like those lovely programs XP Antivirus and "Security Tool" do! Yes, I think that trying to scare and confuse the user into an irrational course of action is the way to go.

    5. Re:The Important Question by maxwell+demon · · Score: 1

      Given that only the first hex digit was in the range a-f, the number was very obviously not completely random, and therefore has less than 52 bits of information. 12 digits in the range 0-9 have 39.9 bits of information. Assuming it was not by chance that the first digit was in the range A-F, then this digit also has an entropy of 2.6 bits. The sum of both is 42.5 bits. However, the digit string doesn't seem to be completely random either, so it's not impossible that the extra reduced randomness just removes that half bit, so the total information is actually 42 bits.

      --
      The Tao of math: The numbers you can count are not the real numbers.
  14. Oddly enough... by HerculesMO · · Score: 3, Interesting

    Their Malicious Software Removal Tool (sent out on Patch Tuesday) can remove the rootkit.

    But I won't stop the Slashdotters here from complaining about it.

    --
    The price is always right if someone else is paying.
    1. Re:Oddly enough... by maxwell+demon · · Score: 1

      Their Malicious Software Removal Tool (sent out on Patch Tuesday) can remove the rootkit.

      So the tool to remove it comes in a patch, and patches refuse to install if you are infected?

      --
      The Tao of math: The numbers you can count are not the real numbers.
    2. Re:Oddly enough... by HerculesMO · · Score: 1

      Yes, because they are asking that if you're infected, to remove the problem (using a provided tool) and then try the patches again.

      This really isn't rocket science, is it? Why should MS come up with a solution for only a small percentage of users when they provide the tool to fix it themselves?

      --
      The price is always right if someone else is paying.
    3. Re:Oddly enough... by westlake · · Score: 1
      Their Malicious Software Removal Tool (sent out on Patch Tuesday) can remove the rootkit.

      MSRT and MSE have been able to detect and remove Alureon.A and its kin since October 23, 2009. Virus:Win32/Alureon.A

    4. Re:Oddly enough... by LinuxIsGarbage · · Score: 1

      No. The patch TO PREVENT IT (not remove it) that will cause BSODs if installed on infected systems will refuse to install if it determines the system may be compromised by that exploit.

      The user may opt not to run MRT (it will ask to continue before running). A corporation may deploy the update, but not MRT. One can't assume that MRT was run before the update. I do believe MRT tries to run before updates are installed.

  15. bargaining by shentino · · Score: 0, Troll

    I'd bet that Microsoft is just using the rootkit as leverage to force people to upgrade.

    If anything this will make them EOL XP even faster.

    1. Re:bargaining by Anonymous Coward · · Score: 0

      I'd bet that Microsoft is just using the rootkit as leverage to force people to upgrade.

      http://it.slashdot.org/comments.pl?sid=1620142&cid=31861416

    2. Re:bargaining by LinuxIsGarbage · · Score: 1

      XP (and IE 6) won't EOL any earlier than 2014. They are just trying to prevent users that complain that their system bricked when they installed an update.

  16. Summary title in error by Rockoon · · Score: 5, Informative
    From the article:

    As Microsoft has noted, while the solution prevents users from suffering the misery of Blue Screens of Death, it does leave them unprotected and the company has urged users to download its Malicious Software Removal Tool to clean up their machines and run the patch as soon as possible.

    It isnt that they wont patch these systems, its that they wont automatically install the MSRT, which removes the rootkit, as part of the update.

    ..and to be perfectly honest, who wants the MSRT to be a mandatory component. Things like that are capable of unexpectedly altering the system, something typically frowned upon in enterprise.

    --
    "His name was James Damore."
    1. Re:Summary title in error by slimjim8094 · · Score: 1

      Though to be fair, if you have a rootkit on your corporate machines, the MSRT is the least of your worries.

      --
      I have developed a truly marvelous proof of this comment, which this signature is too narrow to contain.
    2. Re:Summary title in error by Rockoon · · Score: 1

      I still assume that uptime is your biggest worry in enterprise. Compromised security is dealt with in a way that preserves the uptime required to operate the business.

      --
      "His name was James Damore."
    3. Re:Summary title in error by Jeian · · Score: 1

      Things like that are capable of unexpectedly altering the system, something typically frowned upon in enterprise.

      Agreed. Our administrators are perfectly capable of bricking our systems on their own, thank you very much.

  17. Attn infected PC users: Can't have it both ways. by techvet · · Score: 5, Insightful

    First, you beat up Microsoft because their patch trashed machines that were *already* infected. Then you beat them up because they backed off on applying the patches to avoid trashing the machines. Get thee to SuperAntiSpyware and Anti-Malwarebytes and get your machine cleaned up before you complain.

  18. You can't put it off forever! by fred+fleenblat · · Score: 3, Funny

    This just proves that it's a great time for people who have been sticking with XP to take the plunge and upgrade to Windows 2000 Professional.

    1. Re:You can't put it off forever! by Anonymous Coward · · Score: 0

      This just proves that it's a great time for people who have been sticking with XP to take the plunge and upgrade to Windows 2000 Professional.

      No, it proves Microsoft Windows should ONLY be run as a guest operating system inside a virtual machine instance using VirtualBox and GNU/Linux as the host operating system. When infected just copy the backup image over the existing "live" image.

    2. Re:You can't put it off forever! by Anonymous Coward · · Score: 0

      I just installed LinuxMint 8 LXDE on my laptop with 128M ram, and boy does it fly. It still has an XP partition, for auld tyme's sake...

  19. User Experience FAIL by _KiTA_ · · Score: 2, Insightful

    If they have the ability to detect these things, why in the world doesn't a little popup appear in the systray or security center saying "Your system appears to have a form of Malicious Software installed. Windows Updates are currently disabled. Please see your Network Administrator."

    Seriously, the rogue spyware apps do this all the time, why can't Windows itself do it?

    1. Re:User Experience FAIL by Anonymous Coward · · Score: 0

      If they do too much they get sued for putting other companies out of business because of their monopoly. If they do too little you bitch because everybody else does it. And why on earth would they add that functionality to a product as old as XP when there are already products out there that do the same thing for you?

    2. Re:User Experience FAIL by Anonymous Coward · · Score: 0

      Because not receiving one patch that can hose a system so that it's unbootable is different than denying patches that may prevent it from becoming further infected. And secondly not everyone has a Network Administrator to run to. Think of clueless home users.

    3. Re:User Experience FAIL by ashridah · · Score: 1

      because then the malicious software would just start detecting and suppressing the popup? anything already on the system will break. newly downloaded stuff might be able to overcome existing defences by malicious software, OTOH.
      Thus, the game of cat and mouse continues, but at least the cat isn't being completely blind in this scenario.

  20. Re:Attn infected PC users: Can't have it both ways by Anonymous Coward · · Score: 0

    You expect consistency when it comes to bashing Microsoft? You must be new here.

  21. You can't fix stupid by rudy_wayne · · Score: 5, Insightful

    "Microsoft discovered the problems occurred on machines infected with the Alureon rootkit"

    There are many reasons to hate Microsoft, and their QA failure when it comes to security is certainnly one of them. However, the spread of rootkits, viruses and other malware is primarily caused by user stupidity, something that is not Microsoft's fault. In the early days of personal computers I took the time to learn how things worked. If you're having the problem described in this article then you can wipe your hard drive and re-install Windows. If you don't know how to do this, then maybe it's time you learned. If you're not willing to learn, then do the rest of the world a favor and throw your computer out the nearest window.

    1. Re:You can't fix stupid by maxwell+demon · · Score: 1

      However, the spread of rootkits, viruses and other malware is primarily caused by user stupidity, something that is not Microsoft's fault.

      Of course it's Microsoft's fault. If they made the OS so that stupid people were unable to use it, stupid people wouldn't use it and therefore they wouldn't get rootkits on it. :-)

      --
      The Tao of math: The numbers you can count are not the real numbers.
    2. Re:You can't fix stupid by washort · · Score: 1

      However, the spread of rootkits, viruses and other malware is primarily caused by user stupidity

      Hell no. Malware on Windows is directly the fault of Microsoft because they could have designed an OS that was immune to these problems but they haven't. Blaming the users helps no one.

    3. Re:You can't fix stupid by gandhi_2 · · Score: 1

      By running my users as restricted accounts, disabling autorun, and forcing security patches to be auto-installed and forced reboot, i've avoided any real problem for YEARS.

      Is it the car manufacturer's fault you parked your car in sea water and it rusted?

    4. Re:You can't fix stupid by Anonymous Coward · · Score: 0

      If you're having the problem described in this article then you can wipe your hard drive and re-install Windows.
      But why compound the stupidity. Make the stupid stop!
      Install Ubuntu and you will never have to worry about a virus ever again. Over the last decade, I've spent exactly 0 seconds wasting my time worrying about viruses, worms, malware, or any other ilk dreamed up by some kid in his second class of 'introduction to vb on windows'. STOP THE INSANITY!!!

    5. Re:You can't fix stupid by Anonymous Coward · · Score: 0

      If you're not willing to learn, then do the rest of the world a favor and throw your computer out the nearest window.

      I threw the Windows out of the nearest computer instead...

    6. Re:You can't fix stupid by cybernanga · · Score: 1

      In the early days of personal computers I took the time to learn how things worked. If you're having the problem described in this article then you can wipe your hard drive and re-install Windows. If you don't know how to do this, then maybe it's time you learned. If you're not willing to learn, then do the rest of the world a favor and throw your computer out the nearest window.

      When I first learnt to drive, I took the time to learn how things worked. When my engine siezed, I removed it, stripped it down, rebuilt and refitted it. If you don't know how to do this, then maybe it's time you learned. If you are not willing to learn, then do the rest of the world a favour and roll your car off the nearest cliff.

      Email and internet access have become necessities (some countries have even declared internet access to be a human right) you can't expect everyone to be have that level of knowledge. Personal computers need to be more appliance-like, and the user shouldn't be required to know what's inside or how it works to use it.

      Apple appear to be making progress in this regard with the iphone OS, but they keep getting slammed for not being open, and restricting users. Unfortunately this is the trade-off.

      N.B. I have several mac's and I like them, however, I also have several windows machines and a couple of machines running ubuntu, I like those too.

      --
      www.Buy-Proxy.com - A "buyer-driven" global marketplace.
    7. Re:You can't fix stupid by aztracker1 · · Score: 1

      Name one OS that is inherently secure from stupid users installing malware... There isn't one, iPhone/iPod comes close only because of Apples draconian approval process, and tight controls (also maligned).

      --
      Michael J. Ryan - tracker1.info
    8. Re:You can't fix stupid by Anonymous Coward · · Score: 0

      Yeah. In this case the stupidity is they ran Windows.

      Other than that, blaming the user for defects in Micorsoft's products is real bullshit. You can't blame the user for the root kits, it's not their fault for using the product as advertised. It may be their fault for being stupid enough to fall for the advertising implying that Windows might somehow be suitable for any given task .

    9. Re:You can't fix stupid by LinuxIsGarbage · · Score: 0

      Of course it's Microsoft's fault. If they made the OS so that stupid people were unable to use it, stupid people wouldn't use it and therefore they wouldn't get rootkits on it. :-)

      This explains why Linux has few malware, and users.

    10. Re:You can't fix stupid by LinuxIsGarbage · · Score: 1

      If you're having the problem described in this article then you can wipe your hard drive and re-install Windows. But why compound the stupidity. Make the stupid stop! Install Ubuntu and you will never have to worry about a virus ever again. Over the last decade, I've spent exactly 0 seconds wasting my time worrying about viruses, worms, malware, or any other ilk dreamed up by some kid in his second class of 'introduction to vb on windows'. STOP THE INSANITY!!!

      So since you don't have to worry about any nasties on Ubuntu, that means I can just click on that BoA link I got in my email and enter my details right?

      Safe computing has to be practiced on any OS!

  22. can't MS come up with a patch to block rooting? by swschrad · · Score: 3, Interesting

    I mean, they already have the malicious software removal tool, so they could blow the roots away if they wanted to. but what is really needed here is to block the rooting mechanism altogether.

    or go back to the saner architecture of nt 3.0/3.1/3.5, where only the kernel and its designated MS helpers ran at level 0 to start with. the world started to go to hell when they allowed the video driver into level 0.

    --
    if this is supposed to be a new economy, how come they still want my old fashioned money?
    1. Re:can't MS come up with a patch to block rooting? by Anonymous Coward · · Score: 0

      or go back to the saner architecture of nt 3.0/3.1/3.5

      Or upgrade to Vista or later where video drivers can run with low privileges.

    2. Re:can't MS come up with a patch to block rooting? by AndGodSed · · Score: 1

      Remember. He who play in root, eventually kills tree.

    3. Re:can't MS come up with a patch to block rooting? by yuhong · · Score: 1

      or go back to the saner architecture of nt 3.0/3.1/3.5, where only the kernel and its designated MS helpers ran at level 0 to start with. the world started to go to hell when they allowed the video driver into level 0.

      That would have been useless, as the rootkit had nothing to do with the Win32 subsystem. It involved the file system, which has been in kernel mode from the beginning of NT.

    4. Re:can't MS come up with a patch to block rooting? by The+MAZZTer · · Score: 1

      Doesn't the video driver run in user-mode now?

    5. Re:can't MS come up with a patch to block rooting? by StrategicIrony · · Score: 1

      Sure, but not in XP. :-P

      But it IS almost 9 years old already.

      Sheesh. Seems like a lot of people are pretty critical given the situation...

    6. Re:can't MS come up with a patch to block rooting? by Anonymous Coward · · Score: 0

      The problem with this particular rootkit is that it overwrites one of the designated MS helper drivers with malicious code. As for the saner architecture of yore, they are trying to go back in that direction. Windows Vista video drivers are userland, and there's a whole new framework for user mode drivers. Also, 64 bit systems get mandatory driver signing and PatchGuard to try and stop the kernel hooking that rootkits do. Their hands are tied in the name of backwards compatibility on 32-bit, but it's not like they aren't trying on the platforms where they can.

      The fact is that modern malware can piss in your Cheerios with nothing more than limited user privileges. Between holes in IE, Firefox, Flash, Adobe Reader and Java, those privileges aren't hard to get. Security is not easy.

    7. Re:can't MS come up with a patch to block rooting? by Skuld-Chan · · Score: 1

      How would Windows NT 3's architecture protect a user from rootkits? If the kernel is patchable in *any way* (not just video drivers) you are vulnerable. I can't imagine the hordes of security holes in NT 3.x - this was an OS made at a time when really no-one thought about system security.

    8. Re:can't MS come up with a patch to block rooting? by Anonymous Coward · · Score: 0

      Obviously you should go back to 2002 and tell Bill Gate right in his face.

      It happened already, so get over it; Windows 7 does do that any more.

  23. Order by gmuslera · · Score: 0, Redundant

    Couldnt them had included a program to detect and clean that rootkit, then proceed to install the patch instead of just refusing?

    Anyway, having a rootkit active means being walking over thin ice. You could clean it, but it could be used to install something that gives a more direct access, and the rootkit could not be required anymore to do what they want with your machine. Backup data and reinstall should be the recommended way of acting unless you are capable to detect the other changes.

    1. Re:Order by Locke2005 · · Score: 1

      Couldnt them had included...Had you been knowing English long?

      --
      I've abandoned my search for truth; now I'm just looking for some useful delusions.
    2. Re:Order by VGPowerlord · · Score: 1

      Chances are, if it's a rootkit, it's already overwritten the "known good" versions of those files Windows keeps around.

      Plus, they can't guarantee that other files won't be modified by different versions of the same rootkit.

      Other than that, Microsoft already pushes a new version of the Malicious Software Removal Tool through Windows Update every month.

      --
      GLaDOS for President 2016! "Well here we are again. It's always such a pleasure." -- GLaDOS, 2011
  24. classically mindlessly anti-microsoft by circletimessquare · · Score: 3, Insightful

    microsoft doesn't refuse to patch rootkitted systems, microsoft is UNABLE to patch rootkitted system. NO ONE can patch a rootkitted system, of ANY OS. you need to wipe the system and reinstall

    it is ok to be against microsoft, but you have to base your opinion on genuine problems. when you base your opinion on mindless propaganda, you are just another useless partisan in this world: loud, dumb, useless

    --
    intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
    1. Re:classically mindlessly anti-microsoft by Anonymous Coward · · Score: 0

      actually that is not true, given enough time and tools like livecd you can clean rootkits without reinstall. yes its hard but not impossible.
      you won't be sure its clean but you can never be 100% sure about that.

    2. Re:classically mindlessly anti-microsoft by digitalchinky · · Score: 1

      You didn't think about this before you fired off your little opinion piece did you. It is indeed absolutely possible, though one might not necessarily recommend it. All you need to do is boot from another source - mount your compromised file system and then overwrite anything not having a proper hash. This works fine if you keep a hash list based on an uncompromised reference. Think about a 'tripwire' concept.

      In Linux this is trivially simple to do.

    3. Re:classically mindlessly anti-microsoft by Anonymous Coward · · Score: 0

      actually that is not true, given enough time and tools ... you won't be sure its clean but you can never be 100% sure about that.

      So it is true then?

    4. Re:classically mindlessly anti-microsoft by Anonymous Coward · · Score: 0

      Don't use the word partisan so blindly. They have saved more lives than you will ever know. AKA they have killed more communist and nazi fascists than you will ever know. FU communist cock-sucker! The only red you will see is your own blood.

  25. Does it notify the user of why? by Anonymous Coward · · Score: 0

    With them providing a free solution to cleaning the system with MSE I can't be offended by this, but hopefully it explains to the user why it's not installing. (/me did not rtfa)

  26. MSE claimed to work by Bearhouse · · Score: 4, Interesting

    See:

    http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Virus:Win32/Alureon.A

    I've have reasonably good experiences with MSE so far with my Windows users. Anybody else want to weigh in here?

    1. Re:MSE claimed to work by pongo000 · · Score: 1

      I'm by no means a Microsoft fanboi, but I have nothing but good things to say about MSE: It's free, the definition files are updated regularly, and (best of all) it doesn't slow down my laptop even when I'm running a scan. If you're not running MSE, you owe it to yourself to try it out. I can almost promise you that you'll toss whatever antivirus software you're running now.

      MSE, Anti-Malwarebytes, and SpywareBlaster has taken care of everything the big bad world has thrown at my machine.

    2. Re:MSE claimed to work by Bearhouse · · Score: 1

      Fits with my experiences.
      I'd add Spybot S&D to that list...
      http://www.safer-networking.org/en/index.html

    3. Re:MSE claimed to work by Anonymous Coward · · Score: 0

      Did anyone else notice that the definition was last updated two days in the future?

    4. Re:MSE claimed to work by dotancohen · · Score: 1

      Anybody else want to weigh in here?

      Sure, I'll weigh in. This is what I get when I go to the MSE website:
      """
      Not available in your country or region

      You appear to be in a country or region where Microsoft Security Essentials is not available. Thank you for your interest in Microsoft Security Essentials.
      """

      It was translated into 26 languages, none of which are one of the two official languages of my country. Note that I did check only from Kubuntu, I don't actually have a Windows machine.

      --
      It is dangerous to be right when the government is wrong.
    5. Re:MSE claimed to work by gandhi_2 · · Score: 1

      It got better ratings than most of the other AV programs out there.

      If they integrated it with AD so it could be centrally administered....that would be nice. It wold kill Sophos.

    6. Re:MSE claimed to work by macbiv · · Score: 0

      I have been using MSE when I need to install a free AV on a machine for a while now, and it hasn't blown up on me yet. Only on home user machines though- I recommend Vipre for windows and sophos for mac to all my business customers

    7. Re:MSE claimed to work by LinuxIsGarbage · · Score: 1

      MSE is targeted for home users. Microsoft wants corporate users to use "Forefront"

  27. Sensationalism drives page views by Nimey · · Score: 1

    and hence advertising revenue.

    --
    Hail Eris, full of mischief...

    E pluribus sanguinem
    1. Re:Sensationalism drives page views by Anonymous Coward · · Score: 0

      You know, PCPro seems to be really sketchy in this department. They seem to churn out a lot of BS and openly-biased articles. Time to get up in arms.

  28. Re:Attn infected PC users: Can't have it both ways by Anonymous Coward · · Score: 0

    I did no such thing! I was happy with the trashed machine and now they go and do this!

  29. And rightly so. by khasim · · Score: 2, Insightful

    But they are chastised for not coming up with a all-in-one solution?

    Yes. Because when patching, you want the process to be as simple as possible for the END USER.

    The more steps the end user has to follow, the more likely that the end user will make a mistake somewhere.

    If it can be done in one step at the end user's level, then it should be done in one step at the end user's level. No delays.

    1. Re:And rightly so. by StrategicIrony · · Score: 1

      I'm sorry, but I'd be royally pissed of MS was trying to remove third party software from a machine without asking me.

      Malware or not.

      It's not the right place. A very appropriate solution would be to prompt the user

      "A root kit has been detected, please visit the following website for more information and a link to a tool to attempt to fix the issue. This update will not be installed until the issue has been resolved."

      If I saw that message, I would be shocked and amazed at the appropriate response demonstrated. If that happened, I would say MS went above and beyond to accommodate the customer and the security best practice.

    2. Re:And rightly so. by poena.dare · · Score: 1

      And anything more complicated users should PAY ME TO FIX IT! Hurray!

    3. Re:And rightly so. by Anonymous Coward · · Score: 0

      Please find a new hobby. I'm amazed at the outrage people can display over such trivial issues.

    4. Re:And rightly so. by LinuxIsGarbage · · Score: 1

      A very appropriate solution would be to prompt the user

      "A root kit has been detected, please visit the following website for more information and a link to a tool to attempt to fix the issue. This update will not be installed until the issue has been resolved."

      If I saw that message, I would be shocked and amazed at the appropriate response demonstrated. If that happened, I would say MS went above and beyond to accommodate the customer and the security best practice.

      It's scare tactics like that that fake antivirus software uses to get installed. I think the best hope is that MRT gets installed and run during the update cycle.

  30. Um, working for whom? by Colin+Smith · · Score: 2, Insightful

    A) A working machine that has a rootkit installed.

    And is sending all key presses and bank account details to criminals.

     

    --
    Deleted
  31. whoosh! by chaboud · · Score: 1

    That was the sarcasm train, clearly passing you by.

    1. Re:whoosh! by Anonymous Coward · · Score: 0

      Passed him by? Then whose blood, mangled corpse is that scattered along the tracks?

  32. Customer Satisfaction by xerio · · Score: 4, Insightful

    I'm strangely ok with this. If they update the computer and the rootkit conflicts with the new patch and makes the computer unusable, they'll just get blasted for breaking people's computers. But if they don't update the computer, then the person is still able to use it. If they're warned that they can't update because they have a rootkit on their system and they do nothing about it, I feel no sympathy for them. At least Microsoft didn't make their system less operational. They should get rid of the rootkit and then update. If Microsoft let people update while knowing that it would make the computers unusable if they had this rootkit. People would still call foul on Microsoft. This way they're at least giving people a warning and chance to fix their problem, not making the problem worse.

  33. Sad by Voulnet · · Score: 2, Insightful

    Seeing the summary and many of the posts here, it's so sad to see how the internet gave every idiot a podium. It's always going to be catch-22 for Microsoft, even if they donated 40 billion dollars for every open source foundation/cancer research facility in the world. It's sad to see CS graduates, sysadmins and programmers with the mentalities of 4channers. Huh

    1. Re:Sad by JustNiz · · Score: 2, Interesting

      The reason is, no matter how much Microsoft give to charity (and I don't believe they do anyway, its actually Bill & Melinda Gates Foundation who is the big philanthropist ) Cancer Research is not Microsoft's primary activity. Software is.

      Microsoft only care about big corporates interests like the RIAA and MPAA. They absolutely don't care about their own home or small business customers interests. Furthermore they do the bare minimum, their products suck, they strangle innovation, they hold the whole industry back just so they can make more money at any cost. They've made that VERY clear MANY times. Give me one reason why I a non-corp customer and a software developer shouldn't criticise Microsoft for failing to care about my interests or the interests of the industry I work in.

    2. Re:Sad by Anonymous Coward · · Score: 0

      Bill Gates only theoretically donates billions to 'cancer' and 'vaccine' 'research', so that he can have good PR.

      What he actually does is merely INVESTS billions in Big Pharm, to collect profits, all the while claiming that he is 'donating billions to cancer and vaccine research', etc.

      For an eye-opener, visit:
      http://latimes.com/gates

  34. Re:Attn infected PC users: Can't have it both ways by jedidiah · · Score: 1

    Microsoft let the crap get on the machine in the first place.

    They're ultimately responsible any way you try to spin this situation.

    I will say that again s-l-o-w-l-y: It's Microsoft's OS. They are responsible for it. You even paid money for it.

    --
    A Pirate and a Puritan look the same on a balance sheet.
  35. "Updates regularly" by ClosedSource · · Score: 1

    More like Obsoletes regularly. Wait a year to update and you can be SOL.

    1. Re:"Updates regularly" by Anonymous Coward · · Score: 0

      Then you should have accepted the free update that appeared after 6 months.

    2. Re:"Updates regularly" by mat128 · · Score: 1

      Then stay on the LTS releases and have 3 years of support (5 on the server edition) so you don't have to upgrade as often!

    3. Re:"Updates regularly" by Dishevel · · Score: 1

      I am guessing that you just hate Linux. Updates are frequent. It is well supported. You may not like it but that dose not make my suggestion any less valid. You sir may "Have a nice day." Move along now.

      --
      Why is it so hard to only have politicians for a few years, then have them go away?
    4. Re:"Updates regularly" by ClosedSource · · Score: 1

      What suggestion?

    5. Re:"Updates regularly" by LinuxIsGarbage · · Score: 1

      But then you end up stuck with ancient versions of Firefox, Open office, etc. Indeed most new software still works on XP, and many on 2000.

    6. Re:"Updates regularly" by mat128 · · Score: 1

      They keep patching them for security updates, if you don't necessarily need the latest and newest...

    7. Re:"Updates regularly" by Dishevel · · Score: 1

      Ubuntu.

      --
      Why is it so hard to only have politicians for a few years, then have them go away?
  36. iphone patch? by adachan · · Score: 1

    If MS won't support a 10 year old system anymore, I don't stand much of a chance getting my first gen root-kitted iPhone patched then.

  37. Comment removed by account_deleted · · Score: 1

    Comment removed based on user account deletion

  38. Quick and Dirty by DarksideDaveOR · · Score: 0

    It never ceases to amaze me how the company that SHOULD produce some of the best code in the world (given revenue and longevity) instead seems to almost invariable produce code based on the "quickest and cheapest" principle.

    The best customer service in this case would be: "What does this malicious third-party code do that causes our software to crash, and how can we fix that bug permanently." Instead, as usual, they go with, "Oh, malicious third party code makes our software crash? No cake for you, then."

    I wish I could say that decisions like this will lead to MS becoming marginalized, but history doesn't seem to bear that idea out either. Pity.

    1. Re:Quick and Dirty by JustNiz · · Score: 1

      >> It never ceases to amaze me how the company that SHOULD produce some of the best code in the world (given revenue and longevity) instead seems to almost invariable produce code based on the "quickest and cheapest" principle.

      Thats what happens when accountants get more say than engineers in the important decisions. The big problem is that missed sales can't be counted. The real problem is that most people will still buy Microsoft products no matter how bad they get, and Microsoft know it too.

  39. Comment removed by account_deleted · · Score: 1

    Comment removed based on user account deletion

  40. Comment removed by account_deleted · · Score: 1

    Comment removed based on user account deletion

  41. Re:Attn infected PC users: Can't have it both ways by sohp · · Score: 1

    If they patch system can detect the rootkit and not install, why doesn't it remove it and then install? At least give the user the option of doing it, instead of just leaving the user to deal with yet more work.

  42. Re:Hmmmm.... by RiffRaff06078 · · Score: 1
    Can you imagine if the auto industry adopted the same strategies used by Microsoft:

    A: Sell new 2010 automobile

    B: Release new 2011 version of same automobile (with LED widgets!)

    C: Inform everyone who purchased the 2010 model that parts for their model will no longer be available after 2012.

    D: Inform car dealers that they will not be allowed to sell used 2010 models.

    E: Inform gas stations that they must use new nozzles at their pumps that only fit the 2011 models.

    F: Sit back an wonder why people take cheap shots at your company and begin purchasing motorcycles.

    G: File lawsuits against the motorcycle companies for restraint of trade and IP infringement.

    I don't rag on Microsoft because they make a substandard product. I rag on Microsoft because they *force* their new products on their customers, and then treat those customers like thieves until proven otherwise. If I don't want to upgrade from Ubuntu 6, I can still download it and use it if I so choose, and I won't be accused of software piracy if I blow a system board and swap the drive into a new system.

  43. Re:Attn infected PC users: Can't have it both ways by Anonymous Coward · · Score: 0

    Microsoft let the crap get on the machine in the first place.

    How so? Did Microsoft hold a gun to their held and forced them to install the rootkit?

    They're ultimately responsible any way you try to spin this situation.

    That's funny because no one was holding the Linux kernel devs or the Ubuntu devs reponsible for users installing those malware-infected debian packages on their system.

    I will say that again s-l-o-w-l-y: It's Microsoft's OS. They are responsible for it. You even paid money for it.

    That's funny because the only way for Microsoft to stop people from installing this malware on their systems is to do the exact same thing that Apple is maligned on the iPhone and iPad: Only allow approved apps to be installed. If Microsoft were to do this you would be howling over them taking control away from the users to do "whatever they want" with their systems. So basically you're being a fucking hypocrite.

  44. What about legit software being wrongly detected by Anonymous Coward · · Score: 0

    I happen to run DeepFreeze on one of my PCs. Earlier this week I noticed that the MS patches failed during the update process. I didn't think much about it, thinking I would mess with it when I had more time. Then I saw this article today. I will need to do some more research but my understanding is that DeepFreeze functions much like a rootkit to provide its functionality. I run an older copy so perhaps it’s not an issue on newer versions...if this is indeed the problem. I can only wonder how many other legit software packages are out there might be affected by this....once again, if it is the true cause. If anyone out there can already either confirm or refute my suspicions, I would certainly appreciate feedback.

  45. Re:Attn infected PC users: Can't have it both ways by AnotherUsername · · Score: 1

    Microsoft let the crap get on the machine in the first place.

    They're ultimately responsible any way you try to spin this situation.

    I will say that again s-l-o-w-l-y: It's Microsoft's OS. They are responsible for it. You even paid money for it.

    I wasn't aware that Microsoft was to blame when a user went against safe operating practices, such as clicking on pop-ups and opening virus-filled emails. I suppose I was wrong.

    --
    I don't like Linux. This doesn't make me a troll.
  46. Obligatory.... by bmo · · Score: 2, Informative

    http://technet.microsoft.com/en-us/library/cc512587.aspx

    >You can't clean a compromised system by patching it.

    >You can't clean a compromised system by removing the back doors.

    >You can't clean a compromised system by using some "vulnerability remover."

    >You can't clean a compromised system by using a virus scanner.

    >You can't clean a compromised system by reinstalling the operating system over the existing installation.

    >You can't trust any data copied from a compromised system.

    >You can't trust the event logs on a compromised system.

    >You may not be able to trust your latest backup.

    >>>>>The only way to clean a compromised system is to flatten and rebuild.

    Jesper M. Johansson, Ph.D. [YES, HE'S A DOCTOR], CISSP, MCSE, MCP+I

    Security Program Manager
    Microsoft Corporation

  47. ob XKCD by petermgreen · · Score: 1
    --
    note: i'm known as plugwash most places but i screwd up registering that here somehow in the past and now can't register
  48. consider the difference between by circletimessquare · · Score: 1

    theoretically impossible and practically impossible

    you wipe the system: you are now guaranteed a clean system and you spent orders of magnitude less time and effort than the scenario you propose (which doesn't guarantee anything)

    --
    intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
    1. Re:consider the difference between by pclminion · · Score: 1

      Define "wiping the system." There are BIOS level rootkits out in the wild. Wiping the machine properly may involve re-flashing the BIOS. And who's to say that even some lower-level rootkit doesn't exist (reprogrammed CPU microcode? a virus hiding on a Firewire device?) Honestly, I'd just take the motherboard and dump the damn thing in the trash.

      Once you're really rooted, you lose. Don't let it happen in the first place.

      And I'm totally with Microsoft on this one. Rootkits are absolutely unpredictable. A Windows system with a rootkit on it can't even be said to be Windows anymore.

  49. XP support by Happy+Nuclear+Death · · Score: 2, Insightful

    Meh. I'm just glad they're still patching Windows XP.

  50. responsibilities by SMOKEING · · Score: 1

    It is exactly for the reason that I am not an expert in it that I don't do plumbing nor farming. And, the world will be a safer place if plumbers don't do any heavy IT work either.

    There's a clear distinction between (end) users and admins. Apple, for one, tries hard to blur it, but the distinction is there.

    Since when cluelessness is not a excuse? The internets ain't your city park where all dogs wear muzzles and a purse accidentally dropped on the ground will be brought to you by the discreet police no later than in five minutes. If anyone in charge of a computer goes carefree to the point that his computer becomes a zombie, this becomes *my* problem, not just theirs.

    Mod parent poster emphatically up.

  51. Re:Hmmmm.... by VGPowerlord · · Score: 2, Insightful

    I hate to say it, but it's more like this:

    A: Release New OS
    B: No One Adopts New OS
    C: Release Another New OS
    D: Support Expires for Old OS
    E: "SOMEONE" Develops a rootkit\virus\malware that targets old OS.
    F: Anti-Virus keeps the old OS limping along
    G: Anti-Virus vendors keep releasing updates to prevent new viruses\rootkits\etc.
    H: Over time thousands, if not millions of Old OS systems get infected by root kits that the large population isn't aware of.
    I: Create a new patch that specifically, when coupled with the largely ignored\unnoticed rootkit\virus\malware, makes Old OS unuseable.
    J: Choice: switch to Linux or upgrade to New OS.
    K: Laugh histerically as at least 50% upgrade to New OS and you bath in $20 bills soaked in Champaign.
    L: Profit.

    --
    GLaDOS for President 2016! "Well here we are again. It's always such a pleasure." -- GLaDOS, 2011
  52. Applies to all 32bit version of Windows by Anonymous Coward · · Score: 0

    Read the bulletin: http://www.microsoft.com/security/updates/015/

    This detection is enabled on all 32 bit version of windows, Windows 7 included. I guess getting on the Microsoft-hates-XP bandwagon gets more hits... /new here

  53. Same responses to every Microsoft story by Anonymous Coward · · Score: 0

    It doesn't matter what they do or don't do. In fact, we should stop specific stories on Microsoft and just randomly put up "Microsoft: Fuck You" stories every few hours. Then all the MS haters can reply with how much MS sucks. Rinse. Repeat.

  54. No, I've stopped complaining. by Anonymous Coward · · Score: 0

    > Now they're doing the right thing and we get news how they refuse to patch the systems which .dll files have been damaged? Welcome to slashdot.

    Just so you know, I complained last time, but I think they're doing it right this time.

  55. How about something for USER-compromised systems? by damn_registrars · · Score: 1

    They need something for systems that have been screwed up by their own users. Perhaps a patch that prevents administrator users from connecting to websites that use bad javascript?

    --
    Damn_registrars has no butt-hole. Damn_registrars has no use for a butt-hole.
  56. Brick 'em by golfbum · · Score: 1

    I'm fine with msft bricking them. Might finally get some action. Gb

  57. One patch to rule them all by Anonymous Coward · · Score: 0

    Got a problem? Get Ubuntu. DONE! ...unless you are one of those girly types who insist that microsoft hasn't abandoned you and are still holding out some kind of hope that no, they didn't just kick you to the curb, the gutter pee now dripping down your face isn't really from the post free-clinic hooker dropping butt ash and standing above you. No microsoft wouldn't leave you there, abandoned, without a dime to your name in the bad side of town, naked and exposed and a cell-mate toy for all the world (or at least everything sober in a 3 block radius) to have their way with. After all the money you paid them, all their promises, after all the license hoops you jumped through, the "Gold version" disks you installed, the license agreements, the secret decoder ring license codes, they wouldn't just throw you under a bus and leave you there in the cold rain, having taken your data, and passed it not just to the government but to any travelling side show act that offered them something (anything shiny). After all, if you reread your license, the license, they offer full warranty, you, you have ...have someone to choke. You have a 1-800 number, and this one isn't for the Tiajuana phone-sex hotline like their other disks, they actually want to hear from you and, and give you some support or something. The credit card number is just, just so that they can identify that its really you. You are their loyal customer! You supported them! They wouldn't do this to you! You defended them! When others said that their system was crap, it crashed all the time, and you lied and said "NO, MINE IS STABLE!", you bit your tongue, crossed your fingers and defended them! When MS research said that the Linux kernel could do a context switch in 1/10 as much code and 10 times as fast, you said that, that the next major patch would beat the other guys. When, when the others said that theirs was secure, and MS had security holes big enough to drive a bus through, you said NO, microsoft has for a really super-low fee a virus scanner and system protector better than anything in the industry! They wouldn't abandon you, not you! You were their friend, their customer. You were their biggest fan! What the hell happened? Where did it all go?

  58. Rooted means always wipe, reinstall. by Anonymous Coward · · Score: 0

    The fuckheads who think one can "clean" a rootkitted machine with some clicketiclick-magic are mislead or fucking stupid. Well, they use Windows, so it's the second option. Once a machine gets owned it's gone. Total wipe, reinstall from good backup. No matter what OS or even WIndows it is.

    1. Re:Rooted means always wipe, reinstall. by 0123456 · · Score: 2, Interesting

      Once a machine gets owned it's gone. Total wipe, reinstall from good backup. No matter what OS or even WIndows it is.

      Joe Sixpack doesn't have a backup.

      Also, Joe Sixpack probably don't have XP CDs, so he has to install from the 'recovery partition'; I wonder whether any rootkits are installing themselves into the recovery partition so they'll automatically be reinstalled if someone tries to wipe their system and reinstall from scratch?

    2. Re:Rooted means always wipe, reinstall. by smash · · Score: 1

      Joe sixpack is a cock who needs his machine to BSOD and become unrecoverable before he learns.

      --
      I run: Windows, OS X, Linux, FreeBSD. Just because you have a hammer, doesn't mean everything is a nail.
    3. Re:Rooted means always wipe, reinstall. by LinuxIsGarbage · · Score: 1

      Joe sixpack also didn't pay attention when his system that shipped without discs begged and pleaded with him for the past 5 years to burn off recovery DVDs.

      I hate OEM preinstalled bloatware, I hate that they don't ship discs, but no, you're not screwed if you only have a recovery partiton. You're only screwed if you didn't make the discs it asked you to.

    4. Re:Rooted means always wipe, reinstall. by Anonymous Coward · · Score: 0

      That's a great idea!
      *makes a note...*

  59. I've patched it already by Anonymous Coward · · Score: 0

    I installed this patch called "Linux" here. No malware problems, I tell you!

  60. x86 is x86 by skoony · · Score: 0

    well, now we have windows 7. 13 quadgillion tons of crap heaped onto DOS. yes i said it. dos,dos,dos,dos. x86 requires dos. new operating system regards, mike

  61. What about the MPAA? by Anonymous Coward · · Score: 0

    If the video driver isn't running at level 0, how will they be certain you're not copying their movies?

  62. MSRT by Torodung · · Score: 1

    Stands for one of two things:

    Malicious Software Removal Tool

    Microsoft Removal Tool

    Wonder which works better?

    --
    Toro

    (There's a reason Microsoft named the file MRT.exe)

  63. Re:Hmmmm.... by Kitkoan · · Score: 1

    Can you imagine if the auto industry adopted the same strategies used by Microsoft:

    A: Sell new 2010 automobile

    B: Release new 2011 version of same automobile (with LED widgets!)

    C: Inform everyone who purchased the 2010 model that parts for their model will no longer be available after 2012.

    D: Inform car dealers that they will not be allowed to sell used 2010 models.

    E: Inform gas stations that they must use new nozzles at their pumps that only fit the 2011 models.

    F: Sit back an wonder why people take cheap shots at your company and begin purchasing motorcycles.

    G: File lawsuits against the motorcycle companies for restraint of trade and IP infringement.

    I don't rag on Microsoft because they make a substandard product. I rag on Microsoft because they *force* their new products on their customers, and then treat those customers like thieves until proven otherwise. If I don't want to upgrade from Ubuntu 6, I can still download it and use it if I so choose, and I won't be accused of software piracy if I blow a system board and swap the drive into a new system.

    Wow, just wow. I'm not sure where to begin with whats wrong with this post. Lets see, model 2010, 1 year later releases a newer model? Considering WIndows XP was released in August of 2001 and they are only officially stopping support for it on July 13, 2010 completely invalidate that comparison since 2001-2010 isn't 1 year. Vista wasn't even released until 2006, 5 years later... For C. you wrore that the 2010 model that they won't be able to use parts after 2012 again files in the face of everything since Office 2007 (the newest one) runs on Windows XP and was released 6 years later. This doesn't even consider that the new Office 2010 is also going to run on Windows XP... 'Inform dealers not to sell 2010 models'. You were able to buy Windows XP for years after Vista, and for quite some time without paying extra license... ' Inform gas stations they must use new nozzles, ect, again is wrong since Vista and Windows 7 allows backwards compatibilities and newly made software is still made to run on Windows XP (note the Office 2010 again)... If your going to try to make a comparison at least put a pinch of effort into it.

    --
    Attention... all grammer nazi"s! Is they're anything; wrong with: my post,
  64. Hmmmmm another reason to use Microsoft Products... by dogzdik · · Score: 0
    Microsoft - the worlds longest running disaster that has the scummiest of free features and product lock in, and a vertical integration of all their other products.... And their OS doesn't come with any protection... Well it does if you can get your head around 2500 vaguely interrelated security settings, in 120 different parts of the software, with no clear connection between any of them, and you need a PHD in computer science and an astronomical memory, several months to drill down through the all the menus, AND anything that is run, won't run unless it's in administrator mode, which switches off what ever worthless security settings that Microsoft creates, AND I just don't have any more time for that endless shit of issues and security and scanning everything with 10 lots of malware scanners anymore....

    .

    Thank fuck for Linux.

    --

    .

    Voting up, Voting down - If I really gave a fuck about your approval or not, I'd come and ask you.

  65. Re:Sad - yes... but the corporat moron mind :) by dogzdik · · Score: 0
    Yeah... but the management of MS has done a lot of really shitty things - as a business. INCLUDING dumping lots of really shitty software on the market, without any protection - and excluding the issue of having to spend 2 to 3 times as much per anum on security software as what I paid for the software, the bugs in their software have cost me HEAPS in lost time, income and productivity. If I was to pay $200 for their software - the bugs in it over time - being the total cost of ownership - easily come to 50 times the purchase price.

    .

    And it's through many of their unscrupulopus business practices in the face of limited alternatives for consumers - that is how they made their billions

    .

    Their customer service is appalling - especially if you are poor...With the endless drill down menus, the buck passing and stone walling?

    .

    Not interested in their crap....

    .

    So why should our hearts be bleeding for them? - The management of that company are only too happy to rip off the consumer - remember the recent pricing scam by Microsoft for Windoze 7 - the USA has one price and everywhere else in the world pays TWICE that price; and they block online sales from the USA by IP and shipping address?

    .

    You mean that they want to treat consumers like stupid shit? Of course they are going to get lots of flack from people - especially those with long memeories.

    --

    .

    Voting up, Voting down - If I really gave a fuck about your approval or not, I'd come and ask you.

  66. Am I right... by maweki · · Score: 1

    Am I right in my assessment, that they first leave your door wide open. And once a burglar entered and set off the burglar-detection, they refuse to install a lock in your door?

  67. Re:Hmmmm.... by RiffRaff06078 · · Score: 1

    Yeah, okay, the analogy sucked. I was half asleep at my desk when I wrote it. I still stand by the basic argument that Microsoft's tactics of forcing customers to upgrade, combined with their draconian verification protocols, would not be tolerated in other industries.

  68. sieve central. by Anonymous Coward · · Score: 0

    un-f#cking-believable.
    a 10 year old OS and still not safe?
    of course a OS is a complex piece of code (*),
    but jeezus if i just imagine the time i spent online
    with XP and the enormous amount of websites visited,
    it's like having imagined wearing clothes for ten years only
    to find out that i was walking around naked all the freaking time!
    and i paid for that sieve of a operating system.
    is there even one file that hasn't changed from the orig. XP
    to a fully patched (sic) XP today?
    now even worse, dropping support for XP and la-la-la-ing
    people into spending more money for the latest greatest
    secure sieve ver. 7. OMG!
    (*)profit idea, less complex fancy-pansy and more secure OS?! anyone?

  69. Why? by L1feless · · Score: 1

    I couldn't find an answer to this in the article posted but does this patch notify the end user as to why the patch was not installed? After reading it it looked like the patches just simply wouldn't install and it was left to the end user to manually go back and verify that the patches wouldn't install. Rather than an informative message prompting on the screen.

  70. There's no easy solution by Anonymous Coward · · Score: 0

    I'm running a network right now that has several users with their own computer systems. Each individual is a separate entity and therefore we can't really impose standards on their systems as though they were running under a domain architecture. In other words, I have about 110 people with their own computer systems that they are allowed to have WHATEVER they want on them, and there's no easy way to manage them or what they do with them.

    Several months ago one of them was hit by the BSOD because of the Alureon rootkit and the related patch from Microsoft.

    Now it's all find and good to say "Deliver the patch, BSOD the idiots, and get them off the net so that they're not a danger to the rest of the world", but realistically they need to have the systems running again. Since they all manage the computer systems themselves, it's very difficult to catch a rootkit on a system that you haven't looked at in literally months. The BSOD was the only way of knowing they even had the rootkit because it was the only thing that forced them to call me in to look at it. In THIS case, the blue screen was actually crucial in discovering the problem. That said, is preventing this from happening necessarily a good thing?

    What Microsoft could do is deny the downloading of patches, BUT upon detecting the rootkit, inform the user or remove it for the user. My point is that if Microsoft has the ability to detect the rootkit before the patch is installed, why not go the extra step and remove the thing so that they aren't just blacklisted from the patch?

    The problem:
    There are some really clueless computer users out there. They will download crap whether you defend against it or not. They always find a way to do so... Part of the reason is that their computers don't contain the latest patches and security fixes.

    The solution:
    Give those patches and security fixes to the users! If a rootkit or virus is causing problems when a patch is installed, then first detect and remove it BEFORE installing the patch, rather than blocking them out from all patches entirely.

    The thing is... Blocking them from downloading updates to their computer whether it's specific updates or all updates doesn't fix the issue and in fact possibly prevents the issue from being fixed.

    I guess Microsoft's reasoning is that they would have the rootkit, wouldn't have the updates, but at least their buggy virus-laden computer would be semi-functional rather than a useless BSOD machine.

  71. It's more like... by pyrr · · Score: 1

    ...having someone on the highway who doesn't know about cars and is mechanically incompetent. And as a result of said incompetence the car is utterly unmaintained, so it belches whitish-blue smoke (because both oil and coolant are being burned) and holds-up traffic because it can barely maintain speed. It's going to break-down often because critical problems simply aren't addressed until various failures render the vehicle inoperable, and then it's only patched-up enough to get it limping-along again.

    So why aren't all cars which are owned by people who have no mechanical aptitude clunkers of the sort I described above? It's because you don't have to be a master mechanic or have any mechanical aptitude to take your car TO a mechanic for an inspection if you think something might be wrong or to change the oil. You pay the professional to have knowledge and skill in an area you lack those things in. Said mechanic can also answer questions and offer helpful advice to help you get the most life out of your car and keep it running well.

    Cars are machines, computers are machines. Is it really too much to ask that people who don't know much about computers take them in for a tech to look at if they start behaving strangely or running slowly? Or that they run and update anti-malware preventative-maintenance products? So, someone gets BSODed by an update. Such failures doesn't make people idiots because they don't know how to avoid or correct malware problems themselves. They are idiots because they not only couldn't do it themselves, but they also didn't bother to hire a professional to help them out.

    So nope, no sympathy from me either. BSOD them and get 'em off the 'net, just like a ruined clunker alongside the road. At least with computers, there's no real physical damage, the "clunker" can almost certainly be restored to as-good-as-new functionality with an OS install disc and a couple hours of time.

  72. SOPSSA, you intentionally misinform others by Anonymous Coward · · Score: 0

    "But the 3.6.2 update was ALREADY released WELL BEFORE the story was posted (Tuesday March 23, @02:51AM Eastern): https://developer.mozilla.org/devnews/index.php/2010/03/22/firefox-3-6-2-update-now-available-as-free-download/ Firefox 3.6.2 update now available as free download Version 3.6.2 was released THE DAY BEFORE this story even posted! Once again you are caught in your BOLD-FACED LIES, LOL! - by clone53421 (1310749) on Monday April 05, @01:36PM (#31736454) Journal

    Funny how YOU backed up clone53421 above, here on your part in the URL below, regarding firefox though (lol, when clone's information was STALE & OUT OF DATE already too no less):

    http://slashdot.org/comments.pl?sid=1591778&cid=31755996

    AND YET? LMAO:

    FireFox turned up YET ANOTHER SECURITY BUG & right when you shot your big mouth off in that url above on 04/05/2010 above, which had stale out of date information regarding FireFox security issues, & proof of that's taken from here:

    ----

    Mozilla Firefox DOM Node Moving Use-After-Free Vulnerability:

    http://secunia.com/advisories/39175/

    Release Date 2010-04-02
    Last Update 2010-04-06

    ----

    http://slashdot.org/comments.pl?sid=1591778&cid=31755996

    That's where you quote above is from, and, Where Germany advised its peoples to stay away from FireFox 3.6, as they had for IE before that (but, never for Opera).

    (Thus, yet another security bug surfaced in FireFox 3.6.2 in that time frame, yet again, 2x that week it appears (LOL!)).

    sopssa - How stupid do you feel after your backing up that moron clone, sopssa, when he was quoted in error in that rant of his above that opens this posting of mine in reply, and the URL above that shows you backing his stale & out of date information?

    Why?? Because YET ANOTHER SECURITY VULNERABILITY SURFACED THAT DAY OR THE NEXT DAY in FIREFOX, YET AGAIN, lmao...

    "too, Too, TOO EASY!"

    Obviously sopssa, you lost yet again, and backed the wrong poster in clone53421, in such a stupid mistake on hiis part above.

    Obviously, You're too stupid to exist sopssa and it's no small wonder that all you do is post on slashdot all day, as you don't have enough skills or degrees necessary to your name in computing to actually have or hold a job in the sciences of computing.

  73. Sweet no rootkit here! by Junior+J.+Junior+III · · Score: 1

    Well the updates applied successfully, so I guess I'm rootkit free.

    --
    You see? You see? Your stupid minds! Stupid! Stupid!