<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msinfluentials.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>And finally, standard user malware</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/08/31/and-finally-standard-user-malware.aspx</link><description>Today I finally got wind of my first piece of true standard user malware. MS Antispyware 2008 has turned standard user. The version in question installs the binaries in c:\documents and settings\all users\application data\&amp;lt;something&amp;gt;, and makes</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>re: And finally, standard user malware</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/08/31/and-finally-standard-user-malware.aspx#21939</link><pubDate>Sat, 03 Oct 2009 17:48:02 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21939</guid><dc:creator>Eric Eskam</dc:creator><description>&lt;p&gt;I too am surprised it has taken this long for something like this to appear. &amp;nbsp;If Firefox can install in usermode, why not malware?&lt;/p&gt;
&lt;p&gt;BTW - a handy flowchart to help users decide if they really should click to see the dancing naked pigs:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.intac.net/a-flowchart-to-help-you-decide-when-to-click-past-the-security-warning/"&gt;www.intac.net/a-flowchart-to-help-you-decide-when-to-click-past-the-security-warning&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21939" width="1" height="1"&gt;</description></item><item><title>re: And finally, standard user malware</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/08/31/and-finally-standard-user-malware.aspx#21914</link><pubDate>Thu, 10 Sep 2009 21:21:34 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21914</guid><dc:creator>Hilton Travis</dc:creator><description>&lt;p&gt;G&amp;#39;day Jesper,&lt;/p&gt;
&lt;p&gt;All theswe filth are doing is following Microsoft&amp;#39;s lead with Microsoft Live Mesh and Microsoft Vine which don&amp;#39;t install into Program Files, but into AppData\Local, therefore not requiring elevated rights.&lt;/p&gt;
&lt;p&gt;Now, this is a huge security vulnerability to me - allowing non-Admin users the ability to install applications. &amp;nbsp;WTF was Microsoft thinking?&lt;/p&gt;
&lt;p&gt;Have you tried installing Live Mesh with &amp;quot;Run as Administrator&amp;quot;? &amp;nbsp;What does the error message &amp;quot;Live Mesh: Product does not support running under an elevated account. &amp;nbsp;This class is not configured to support Elevated activation. &amp;nbsp;Error: 80080017&amp;quot;. &amp;nbsp;Now, is that an error message, as a Security professional, that scares the pants off you, or what?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21914" width="1" height="1"&gt;</description></item><item><title>re: And finally, standard user malware</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/08/31/and-finally-standard-user-malware.aspx#21911</link><pubDate>Thu, 03 Sep 2009 20:02:56 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21911</guid><dc:creator>Simon</dc:creator><description>&lt;p&gt;Hey Jesper&lt;/p&gt;
&lt;p&gt;Sorry to hear about your friend being duped into the scam. I had to fix dozens of computer with that stupid malware but luckily, every user just got frustrated instead of giving in to the demand (could also be because they were broke!). But $5,000? I believe the user themselves also have the responsibility to make sure that everything is legit before giving away that much money. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21911" width="1" height="1"&gt;</description></item><item><title>re: And finally, standard user malware</title><link>http://msinfluentials.com/blogs/jesper/archive/2009/08/31/and-finally-standard-user-malware.aspx#21909</link><pubDate>Tue, 01 Sep 2009 11:54:34 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:21909</guid><dc:creator>Larry Seltzer</dc:creator><description>&lt;p&gt;When you think about it, how is anti-malware supposed to detect user malware such as this? If they don&amp;#39;t have a signature for it then there&amp;#39;s nothing in the behavior of the program that could be determined heuristically to be malicious. All the program does is put on a show.&lt;/p&gt;
&lt;p&gt;I&amp;#39;m also told by anti-malware companies that these rogue anti-malware programs are particularly aggressive about their obfuscation techniques.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=21909" width="1" height="1"&gt;</description></item></channel></rss>