<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; Nick B</title>
	<atom:link href="http://42.kaizeku.com/author/chaoskaizer/feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>How to remove XMSS.exe Win32 AutoRun worm</title>
		<link>http://42.kaizeku.com/windows/xmss-exe-funny-ust-scandal-avi-worm/</link>
		<comments>http://42.kaizeku.com/windows/xmss-exe-funny-ust-scandal-avi-worm/#comments</comments>
		<pubDate>Sat, 16 Feb 2008 11:58:21 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[Worm]]></category>

		<category><![CDATA[autorun.abt]]></category>

		<category><![CDATA[autorun.fj]]></category>

		<category><![CDATA[autorun.m]]></category>

		<category><![CDATA[prank]]></category>

		<category><![CDATA[Virus]]></category>

		<category><![CDATA[win32]]></category>

		<category><![CDATA[xmss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/windows/xmss-exe-funny-ust-scandal-avi-worm/</guid>
		<description><![CDATA[

Yesterday I got a new type of &#8220;Stupid Worm&#8221; hidding in background as xmss.exe. It copied itself on Local disk and Windows Directory (%Windir%). Terminated &#8220;Windows Task Manager&#8221;, Windows Command Prompt (DOS-Prompt) &#38; crashed System Internal Process Explorer (procxp.exe).
Its not a funny video
According to McAfee, this worm is known as W32/Autorun.worm.g.
It can propagate itself over [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/xmss-exe-funny-ust-scandal.png' alt='xmss-exe-funny-ust-scandal.png image by chaoskaizer' width='128' height='128' class="photo thumb- fl rgb-"/>Yesterday I got a new type of &#8220;Stupid Worm&#8221; hidding in background as <em>xmss.exe</em>. It copied itself on Local disk and Windows Directory <small>(%Windir%)</small>. Terminated &#8220;Windows Task Manager&#8221;, Windows Command Prompt (DOS-Prompt) &amp; crashed System Internal <a href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx" class="exturl icn-r1" rel="nofollow robots-nofollow">Process Explorer</a> (procxp.exe).</p>
<h2 class="cb">Its not a funny video</h2>
<p class="xmssexe-descriptions">According to <a href="http://vil.nai.com/vil/content/v_143758.htm" rel="nofollow" class="exturl icn-r1">McAfee</a>, this worm is known as <strong><tt class="di">W32/Autorun.worm.g</tt></strong>.</p>
<blockquote cite="http://vil.nai.com/vil/content/v_143758.htm"><p class="cite">It can propagate itself over removable media and network drives and cause execution of malicious code via an <tt class="di">autorun.inf</tt> file.</p>
</blockquote>
<p><span id="more-217"></span></p>
<h2 class="mgt mgb-">XMSS.exe Win32 AutoRun Files</h2>
<ul class="xoxo exturl">
<li><strong class="fw-"><tt class="di">x:autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">x:xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">x:Funny UST Scandal.avi.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\Funny UST Scandal.avi.exe</tt></strong></li>
</ul>
<h2 class="cb mgt">Fixes Win32 AutoRun.* Worm</h2>
<p>Here&#8217;s a few step to prevent <strong class="fw-">Win32 AutoRun Worm</strong>. </p>
<ol class="xoxo">
<li>Disabled System Restore for Temporary - <a href="http://support.microsoft.com/kb/264887/en-us" class="exturl icn-r1" title="How to Enable and Disable System Restore">KB 264887</a></li>
<li>Boot Windows in Safe Mode - <a class="exturl icn-r1" href="http://support.microsoft.com/kb/315222" title="Safe Mode Boot options in Windows XP">KB 315222</a></li>
<li>
<p>In Windows Safe Mode, Open Windows Registry Editor</p>
<p><tt class="di">Windows Start > Run > Regedit</tt></p>
<li>
<p>Browse to the following registry settings &darr;</p>
<p><tt class="di">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell</tt>
</li>
<li>Replace<br />
<em><tt class="di">explorer.exe, xmss.exe</tt></em> with <em><tt class="di">exporer.exe</tt></em><br />
<img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/xmss-exe-regedit.png' alt='xmss-exe-regedit.png' width="708" height="378" class="mgt mgb" />
</li>
<li>Delete all the following files
<ul class="xoxo">
<li><strong class="fw-"><tt class="di">C\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">C\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">C\Funny UST Scandal.avi.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">X:\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">X:\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">X:\Funny UST Scandal.avi.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\Funny UST Scandal.avi.exe</tt></strong></li>
</ul>
<p class="notice">%Windir% refers to the Windows folder (e.g. C:\Windows, C:\WindowsNT) and X: is drive letters used by a removable or network drive</p>
</li>
<li>Clean All Windows Temporary Files</li>
<li>Restart Windows</li>
</ol>
<h2 class="cb">XMSS.exe Win32 Autorun Variants</h2>
<p><small>VirusTotal.com - Dec 2007 Results.</small></p>
<table border="1">
<tr>
<td>Antivirus</td>
<td>Version</td>
<td>Last Update</td>
<td>Result</td</tr>
<tr>
<td>AhnLab-V3</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>AntiVir</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Authentium</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Avast</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>AVG</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>BitDefender</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Worm.AutoRun.abt</td</tr>
<tr>
<td>ClamAV</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.Autoit-6</td</tr>
<tr>
<td>DrWeb</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>eSafe</td>
<td>-</td>
<td>-</td>
<td style="color: red;">suspicious Trojan/Worm</td</tr>
<tr>
<td>eTrust-Vet</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Ewido</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>FileAdvisor</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Fortinet</td>
<td>-</td>
<td>-</td>
<td style="color: red;">W32/Autoit.BG!tr</td</tr>
<tr>
<td>F-Prot</td>
<td>-</td>
<td>-</td>
<td style="color: red;">W32/Trojan!c4a4</td</tr>
<tr>
<td>F-Secure</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.Win32.Autoit.bg</td</tr>
<tr>
<td>Ikarus</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Virus.Win32.AutoRun.pc</td</tr>
<tr>
<td>Kaspersky</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.Win32.Autoit.bg</td</tr>
<tr>
<td>McAfee</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Microsoft</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>NOD32v2</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Win32/HackAV.P</td</tr>
<tr>
<td>Norman</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Panda</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Suspicious file</td</tr>
<tr>
<td>Prevx1</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.DoS.Win32.Opdos</td</tr>
<tr>
<td>Rising</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Worm.Win32.Autorun.jax</td</tr>
<tr>
<td>Sophos</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Sunbelt</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Symantec</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>TheHacker</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan/Autoit.bg</td</tr>
<tr>
<td>VBA32</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Virus.Win32.AutoRun.pc</td</tr>
<tr>
<td>VirusBuster</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.AutoIt.BB</td</tr>
<tr>
<td>Webwasher-Gateway</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Riskware.HackAV</td</tr>
</table>
<h2 class="mgt mgb-">External Links</h2>
<ul class="xoxo exturl">
<li><a href="http://support.microsoft.com/kb/264887/en-us">How to Enable and Disable System Restore</a></li>
<li><a href="http://support.microsoft.com/kb/315222">Safe Mode Boot options in Windows</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/xmss-exe-funny-ust-scandal-avi-worm/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Firefox 2.0.0.12 Information Leak</title>
		<link>http://42.kaizeku.com/security/exploit/firefox-20012-information-leak-vulnerability/</link>
		<comments>http://42.kaizeku.com/security/exploit/firefox-20012-information-leak-vulnerability/#comments</comments>
		<pubDate>Sun, 10 Feb 2008 11:21:37 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[remote+exploit]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/exploit/firefox-20012-information-leak-vulnerability/</guid>
		<description><![CDATA[

We are going to see Firefox 2.0.0.13 probably by end of this week. Check out this directory transversal code using view-sources: &#038; resource: scheme
view-source:resource:///
translate to file:///C:/Program%20Files/Mozilla%20Firefox/
You can read/include firefox pref settings with this code. &#60;script src=&#8221;view-source:resource:///greprefs/all.js&#8221;&#62;&#60;/script&#62; 
Workaround
Install No-script Add-ons.

Credits
Ronald van den Heetkamp at 0&#215;000000
External Links

Firefox 2.0.0.12 Information Leak POC


]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/12/marvin-apbot-costume-by-chaoskaizer.jpg' alt='Marvin Apbot costume by chaoskaizer' width="100" height="100" longdesc="http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/marvin-apbot-costume-by-chaoskaizer.jpg" />We are going to see Firefox 2.0.0.13 probably by end of this week. Check out this directory transversal code using view-sources: &#038; resource: scheme<br />
<tt class="di">view-source:resource:///</tt><br />
translate to <tt class="di">file:///C:/Program%20Files/Mozilla%20Firefox/</tt></p>
<p>You can read/include firefox pref settings with this code. <tt>&lt;script src=&#8221;view-source:resource:///greprefs/all.js&#8221;&gt;&lt;/script&gt; </tt></p>
<h2 class="cb">Workaround</h2>
<p>Install <a class="exturl icn-r1" href="http://noscript.net/">No-script</a> Add-ons.</p>
<p><span id="more-197"></span></p>
<h2>Credits</h2>
<p><span class="vcard"><a class="url fn microformat icn-r1" href="http://www.0x000000.com/index.php?!=6"><span class="given-name">Ronald</span> <span class="family-name">van den Heetkamp</span></a> at <a class="url org exturl icn-r1" href="http://www.0x000000.com">0&#215;000000</a></span></p>
<h2>External Links</h2>
<ul>
<li><a class="exturl icn-r1" href="http://www.0x000000.com/index.php?i=515">Firefox 2.0.0.12 Information Leak POC</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/exploit/firefox-20012-information-leak-vulnerability/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Google Celebrate Chinese New Year with New Festival Logo</title>
		<link>http://42.kaizeku.com/ranting/google-celebrate-chinese-new-year-with-new-festival-logo/</link>
		<comments>http://42.kaizeku.com/ranting/google-celebrate-chinese-new-year-with-new-festival-logo/#comments</comments>
		<pubDate>Wed, 06 Feb 2008 13:39:51 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Google]]></category>

		<category><![CDATA[ranting]]></category>

		<category><![CDATA[cny]]></category>

		<category><![CDATA[logo]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/ranting/google-celebrate-chinese-new-year-with-new-festival-logo/</guid>
		<description><![CDATA[Google Celebrate Chinese New Year with New Festival Logo Happy Chinese new year]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/lunarnewyear08res.gif' alt='lunarnewyear08res.gif' class="fl" /></p>
<p class="cb">According to <a href="http://en.wikipedia.org/wiki/Chinese_New_Year" class="exturl icn-r">Chinese Lunar Calendar</a> 2008 is the year of the RAT. ~Mickey 8:&gt;</p>
<p><span id="more-191"></span></p>
<h2>External Links</h2>
<ul class="xoxo">
<li><a href="http://www.google.com/holidaylogos99.html">Collections of Google Holiday Logos 1999 - 2007</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/ranting/google-celebrate-chinese-new-year-with-new-festival-logo/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How To Disabled and Removed Microsoft Windows MobSync - Trojan RootKit</title>
		<link>http://42.kaizeku.com/security/vulnerability/how-to-disabled-and-removed-microsoft-windows-mobsync-trojan-rootkit/</link>
		<comments>http://42.kaizeku.com/security/vulnerability/how-to-disabled-and-removed-microsoft-windows-mobsync-trojan-rootkit/#comments</comments>
		<pubDate>Mon, 24 Dec 2007 20:07:00 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[mobile]]></category>

		<category><![CDATA[mobsync]]></category>

		<category><![CDATA[rootkit]]></category>

		<category><![CDATA[Synchronization Manager]]></category>

		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/vulnerability/how-to-disabled-and-removed-microsoft-windows-mobsync-trojan-rootkit/</guid>
		<description><![CDATA[<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/12/mobsyncexe.png' alt='mobsync.exe'  class="fl"/><strong>MobSync</strong> is a <strong>Microsoft Mobile Synchronization Manager </strong>available in Win 2000 &#38; Windows XP</p>
<p class="cl">Excerpt from <a href="http://support.microsoft.com/kb/314512">Microsoft KB 314512</a> Articles (2002)</p>
<blockquote>
The Windows XP Synchronization Manager helps ensure that the files and folders on your mobile device and your desktop computer stay synchronized. With Synchronization Manager, you can be sure you are always working with the latest copy of your data, online or offline.
</blockquote>

<p>Technically MobSync is  part of Windows Memory Management, its prefetch (type of cache) your External Device Contents (Mobile PC, Windows Embed XPE, PDA,database etc .. ) thus helps speed up the Windows booting process by shortening the time external device  programs takes to start up. </p>

<h2>MobSync Issue</h2>
<p>MobSync is registered to run on logon but the process is hidden on others 'Scans Tools' like Autoruns.exe &#038; Process.exe (SysInternal).</p>
QuickFact:
<ul>
	<li> MobSync.exe can record inputs.</li>
	<li> Its hide itself from monitor applications.</li> 
</ul>
Apparently because of its transparencies nature to hide behind windows systems some hackers decide to reverse engineer this programs as a Trojan Rootkit. [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/12/mobsyncexe.png' alt='mobsync.exe' class="fl"/><strong>MobSync</strong> is a <strong>Microsoft Mobile Synchronization Manager </strong>available in Win 2000 &amp; Windows XP</p>
<p class="cl">Excerpt from <a href="http://support.microsoft.com/kb/314512">Microsoft KB 314512</a> Articles (2002)</p>
<blockquote><p>
The Windows XP Synchronization Manager helps ensure that the files and folders on your mobile device and your desktop computer stay synchronized. With Synchronization Manager, you can be sure you are always working with the latest copy of your data, online or offline.
</p></blockquote>
<p>Technically MobSync is part of Windows Memory Management, its prefetch (type of cache) your External Device Contents (Mobile PC, Windows Embed XPE, PDA,database etc .. ) thus helps speed up the Windows booting process by shortening the time external device programs takes to start up. </p>
<h2>MobSync Issue</h2>
<p>MobSync is registered to run on logon but the process is hidden on others &#8216;Scans Tools&#8217; like Autoruns.exe &#038; Process.exe (SysInternal).</p>
<p>QuickFact:</p>
<ul>
<li> MobSync.exe can record inputs.</li>
<li> Its hide itself from monitor applications.</li>
</ul>
<p>Apparently because of its transparencies nature to hide behind windows systems some hackers decide to reverse engineer this programs as a Trojan Rootkit.<br />
<span id="more-101"></span></p>
<h2 class="sep">Should I disabled Mobsync?</h2>
<p>If you used windows for surfing and office works you probably wont need this programs <span style="text-decoration:line-through">(crapware)</span> most modern mobile device has a build in Synchronization Manager and doesnt relies on microsoft mobsync (dependencies issue). Its recommended to disabled this programs as it can hide itself from being monitored and doesnt showup on running process lists. </p>
<h2 class="sep">Step by step guide to disabled MobSync from your windows.</h2>
<ol>
<li>
<h3>Disabled System Restore</h3>
<p>You will need to disabled <a href="http://www.microsoft.com/technet/community/newsgroups/faqsrwxp.mspx"> Windows System Restore</a> (Temporary).</li>
<li>
<h3>View hidden system files</h3>
<p>Suspicious files is known to hide itself as Windows System files. The following settings will set all hidden files viewable so we could removed it.</p>
<ul>
<li>Click on Windows Start &rarr; Control Panel &rarr; Folder Options &rarr; View Tab </li>
<li>Turn on the option to show hidden files</li>
</ul>
</li>
<li>
<h3>Clean Temporary Files and Windows Prefetch Files</h3>
<p>This wont harm your system. Removes all files inside the following directory. <span class="b">Remove the contents only not the folders</span>.</p>
<ul>
<li>C:\temp</li>
<li>C:\windows\temp</li>
<li>C:\Documents and Settings\&lt;username&gt;\Local Settings\Temp</li>
<li>C:\windows\prefetch</li>
</ul>
</li>
<li>
<h3>Boot in SafeMode</h3>
<p>Restart your PC in safe mode. Refer <a href="http://support.microsoft.com/kb/315222">KB 31522</a> on How To Boot in Safe Mode.</li>
<li>
<h3>Disabled MobSync Process</h3>
<ol class="nfo">
<li>Click on start &rarr; Run &rarr; <strong>mobsync</strong></li>
<li> Next, Click on <span style="font-weight:700">Setup</span> buttons</li>
<li> On &#8220;Synchronizations Settings&#8221; Windows <span style="font-weight:700">Logon/Logoff</span> tab un-check all the following options:</p>
<p><tt>Automatically Synchronize the following items:</tt></p>
<ul>
<li>When I log on to my computer</li>
<li>When I log off to my computer</li>
</ul>
</li>
<li>While still in &#8220;Synchronizations Settings&#8221; Windows select the next tab label <span style="font-weight:700">&#8220;on Idle&#8221;</span> un-check the following items:
<ul>
<li>Synchronize the selected items while my computer is idle</li>
</ul>
</li>
</ol>
</li>
<li>
<h3>Removed from system registry</h3>
<p>If you arent familiar with registry you may skip this part. Most normal startup programs can be found at the following registry path.</p>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run
<li>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce</li>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices</li>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce</li>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run</li>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce</li>
</ul>
<p>In Windows XP all loaded &#8220;startup programs&#8221; (start menu/startup items) can be found at <tt>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg</tt></p>
<p><strong>Mobsync registry</strong> <tt>HKLM\Software\Microsoft\Windows\CurrentVersion\syncmgr</tt>
</li>
</ol>
<h2 class="sep">Note on using Rootkit Scanner.</h2>
<ul>
<li><a href="http://aumha.org">James A. Eshelman</a> <a href="http://aumha.org/downloads/hijackthis.exe"> HijackThis</a></li>
<li><a href="http://forum.sysinternals.com/">SysInternal</a> <a href="http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx">RootkitRevealer</a></li>
<li><a href="http://www.f-secure.com">F-secure</a> <a href="http://www.f-secure.com/blacklight/">Blacklight</a></li>
</ul>
<p>Most advance Rootkit has a self mechanism to shutdown the system if any of this programs is identify in the memory. If you had this programs installed its advice to rename the programs first. </p>
<ul>
<li> RootKitRevealer.exe &rarr; RKV.exe</li>
<li>HijackThis &rarr; hjct.exe</li>
</ul>
<h3>How to validate if the running programs is Tempered</h3>
<p>Get <a href="http://www.wmsoftware.com/download.aspx?product=chktrust">Certificate Verification Tool</a> ( WM Software Corp) and verify the programs signature or you could also run Microsoft sigverif.exe (c:\windows\SIGVERIF.TXT) to verify digital signature. </p>
<p>Caveat: Most Rookit is &#8220;padded/mugged&#8221; with unix controls character so its not readable by Windows (ANSI).</p>
<h3>Setupapi.log entries</h3>
<p>Setupapi.log can be found inside <tt>c:\windows\setupapi.log</tt> You need to enabled logging in verbose mode to get proper setup log.<br />
<tt>HKLM\Software\Microsoft\Windows\CurrentVersion\SetupLogLevel</tt></p>
<p>Insert DWORD value 0000FFFF to enabled verbose mode logging</p>
<p>Insert DWORD value 0 to disabled it</p>
<p>Tempered MobSync.exe &#038; similar windows networks files.</p>
<pre class="prebox">
An unsigned or incorrectly signed file
(c:\windows\msdownld.tmp\as03b1e1.tmp\mobilepk.inf) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\msidle.dll to
C:\WINDOWS\SYSTEM\msidle.dll.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\msidle.dll) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\mobsync.exe to
C:\WINDOWS\SYSTEM\mobsync.exe.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\mobsync.exe) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\mobsync.dll to
C:\WINDOWS\SYSTEM\mobsync.dll.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\mobsync.dll) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\sens.dll to
C:\WINDOWS\SYSTEM\sens.dll.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\sens.dll) was installed. Error 0x800b0003:
The form specified for the subject is not one supported or known by the
specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\sensapi.dll to
C:\WINDOWS\SYSTEM\sensapi.dll.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\sensapi.dll) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\senscfg.dll to
C:\WINDOWS\SYSTEM\senscfg.dll.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\senscfg.dll) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\es.dll to
C:\WINDOWS\SYSTEM\es.dll.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\es.dll) was installed. Error 0x800b0003:
The form specified for the subject is not one supported or known by the
specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\esshared.dll to
C:\WINDOWS\SYSTEM\esshared.dll.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\esshared.dll) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\estier2.dll to
C:\WINDOWS\SYSTEM\estier2.dll.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\estier2.dll) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\sage.vxd to
C:\WINDOWS\SYSTEM\sage.vxd.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\sage.vxd) was installed. Error 0x800b0003:
The form specified for the subject is not one supported or known by the
specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\esenu.dll to
C:\WINDOWS\SYSTEM\esenu.dll.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\esenu.dll) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\mobilepk.inf to
C:\WINDOWS\INF\mobilepk.inf.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\mobilepk.inf) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\chnscsvr.hlp to
C:\WINDOWS\help\chnscsvr.hlp.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\chnscsvr.hlp) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\mobilepk.cat to
C:\WINDOWS\SYSTEM\sfp\ie\mobilepk.cat.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\mobilepk.cat) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\mobsync.hlp to
C:\WINDOWS\help\mobsync.hlp.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\mobsync.hlp) was installed. Error
0xe000022f: The third-party INF does not contain digital signature information.
</pre>
<h2>Summary</h2>
<p>What really bother me, is Microsoft Windows Setup API. Any downloaded Microsoft system files has embed sign-in digital signature. Windows installation will validate all setup file and logs out error if the file has a bad signature (third party signature or file being tempered). The flaw is within the Windows Setup API itself. It doesn&#8217;t protect you from installing bad programs. </p>
<p>You should thanks Microsoft developer for making good Installation Programs and reporting tools. it remind you of error but installed it nonetheless.</p>
<h2 class="sep">External Links</h2>
<ul class="xoxo nfo">
<li><a href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/syncmgr/syncmgr/about_system_event_notification_service.asp">MSDN System Event Notification Service (SENS)</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/vulnerability/how-to-disabled-and-removed-microsoft-windows-mobsync-trojan-rootkit/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The Web Standard Group - ACID2 Test page Failed W3C CSS Validation</title>
		<link>http://42.kaizeku.com/owned/acid2-failed-w3c-css-validation/</link>
		<comments>http://42.kaizeku.com/owned/acid2-failed-w3c-css-validation/#comments</comments>
		<pubDate>Sat, 22 Dec 2007 14:53:25 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[owned]]></category>

		<category><![CDATA[acid2]]></category>

		<category><![CDATA[IE8]]></category>

		<category><![CDATA[validation]]></category>

		<category><![CDATA[w3c]]></category>

		<category><![CDATA[web standard group]]></category>

		<category><![CDATA[xhtml]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/owned/acid2-failed-w3c-css-validation/</guid>
		<description><![CDATA[<p>I'm following up recent announcements on IEBLOG <a href="http://blogs.msdn.com/ie/archive/2007/12/19/internet-explorer-8-and-acid2-a-milestone.aspx" rel="nofollow">Internet Explorer 8 and Acid2: A Milestone</a>. To my surprise, the <strong>Web Standard Groups ACID2</strong> Test Page doesn't conform to <strong>W3C CSS Validation</strong>. </p>

<h2 class="sep">The Errors</h2>
9 errors &#038; 31 warnings.
<pre class="prebox">
Sorry! We found the following errors
43 	 Parse Error - second two]
88 	.parser-container div 	Value Error : color orange is not a color value : orange
94 	.parser 	Property error doesn't exist : }
97 	.parser 	Property m rgin doesn't exist : 2em
97 	Parse error - Unrecognized };
99 	.parser 	Value Error : width only 0 can be a length. You must put an unit after your number : 200
100 	.parser 	Value Error : border Lexical error at line 96, column 38. Encountered: "e" (101), after : "! "error;
100 	.parser 	Value Error : border Parse error - Unrecognized }
101 	.parser 	Value Error : background Too many values or values are not recognized : red pink
</pre>
<ul>
	<li>W3c CSS Validation &#8594; <a href="http://jigsaw.w3.org/css-validator/validator?profile=css2&#038;warning=2&#038;uri=http%3A%2F%2Fwww.webstandards.org%2Ffiles%2Facid2%2Ftest.html">http://www.webstandards.org/files/acid2/test.html</a></li>
</ul>
<h2>Full page Screenshot</h2>
<p><a title="ACID2 failed W3C validation" href="http://www.shareapic.net/content.php?id=4999586&#038;owner=noah" rel="nofollow"><img src="http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004999586.png" longdesc="http://www.shareapic.net/preview2/004999586.png" alt="ACID2 failed W3C validation" width="28" height="130" /></a></p>

]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>I&#8217;m following up recent announcements on IEBLOG <a href="http://blogs.msdn.com/ie/archive/2007/12/19/internet-explorer-8-and-acid2-a-milestone.aspx" rel="nofollow">Internet Explorer 8 and Acid2: A Milestone</a>. To my surprise, the <strong>Web Standard Groups ACID2</strong> Test Page doesn&#8217;t conform to <strong>W3C CSS Validation</strong>. </p>
<p><span id="more-105"></span></p>
<h2 class="sep">The Errors</h2>
<p>9 errors &#038; 31 warnings.</p>
<pre class="prebox" style="width:500px;overflow:auto">
Sorry! We found the following errors
43 	 Parse Error - second two]
88 	.parser-container div 	Value Error : color orange is not a color value : orange
94 	.parser 	Property error doesn't exist : }
97 	.parser 	Property m rgin doesn't exist : 2em
97 	Parse error - Unrecognized };
99 	.parser 	Value Error : width only 0 can be a length. You must put an unit after your number : 200
100 	.parser 	Value Error : border Lexical error at line 96, column 38. Encountered: "e" (101), after : "! "error;
100 	.parser 	Value Error : border Parse error - Unrecognized }
101 	.parser 	Value Error : background Too many values or values are not recognized : red pink
</pre>
<ul>
<li>W3c CSS Validation &rarr; <a href="http://jigsaw.w3.org/css-validator/validator?profile=css2&#038;warning=2&#038;uri=http%3A%2F%2Fwww.webstandards.org%2Ffiles%2Facid2%2Ftest.html">http://www.webstandards.org/files/acid2/test.html</a></li>
</ul>
<h2>Full page Screenshot</h2>
<p><a title="ACID2 failed W3C validation" href="http://www.shareapic.net/content.php?id=4999586&#038;owner=noah" rel="nofollow"><img src="http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004999586.png" longdesc="http://www.shareapic.net/preview2/004999586.png" alt="ACID2 failed W3C validation" width="28" height="130" /></a></p>
<p><strong>Update:</strong> Just got ping from <a href="http://blog.kaizeku.com">chaoskaizer</a>. She said the CSS ERROR is part of the Web Standards Test Suit. </p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/owned/acid2-failed-w3c-css-validation/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Block Apple Quicktime ActiveX &#038; RTSP Exploit</title>
		<link>http://42.kaizeku.com/apple/block-apple-quicktime-activex-rtsp-exploit/</link>
		<comments>http://42.kaizeku.com/apple/block-apple-quicktime-activex-rtsp-exploit/#comments</comments>
		<pubDate>Thu, 06 Dec 2007 17:45:50 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Apple]]></category>

		<category><![CDATA[QuickTime]]></category>

		<category><![CDATA[mac]]></category>

		<category><![CDATA[buffer+overflow]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[ie6]]></category>

		<category><![CDATA[ie7]]></category>

		<category><![CDATA[internet+explorer]]></category>

		<category><![CDATA[jikto]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[remote+exploit]]></category>

		<category><![CDATA[RSTP]]></category>

		<category><![CDATA[safari]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/apple/block-apple-quicktime-activex-rtsp-exploit/</guid>
		<description><![CDATA[<p><img width="128" height="128" style="float: left;" alt="Fixes Apple QuickTime" src="http://i.kakkoi.net/leopard/QuickTimePlayer.png" longdesc="http://blog.kakkoi.net/apple/block-apple-quicktime-activex-rtsp-exploit/" title="Quicktime Logo" /><strong style="font-weight:400">Apple QuickTime</strong> contains a stack <a href="http://en.wikipedia.org/wiki/Buffer_overflow" rev="wikipedia:Buffer_overflow" title="buffer overflow" rel="external nofollow">buffer overflow</a> vulnerability in the way it handles the <abbr title="Real Time Streaming Protocol ">RTSP</abbr> Content-Type header. This vulnerability may be exploited by specially crafted RTSP stream protocol</p><strong>Live Example</strong>
<ul class="xoxo nfo">
<li><a href="http://www.gnucitizen.org/blog/backdooring-quicktime-movies/">GNUcitizen- Backdooring QuickTime Movies </a></li>
<li><a href="http://quicktime.tc.columbia.edu/users/iml/movies/mtest.html">Apple QuickTime redirection to the RTSP exploit</a></li>

</ul>
Elia Florio (Symantec) wrap  a good introduction post regarding <a href="http://www.symantec.com/enterprise/security_response/weblog/2007/11/0day_exploit_for_apple_quickti.html">QuickTime 0 day Exploit</a>. 


<h2 style="border-top:1px solid #ccc; margin-top:38px;padding-top:14px">Known Vulnerabilities Proof of concept (milw0rm).</h2>
<ul class="xoxo nfo">
<li><a rel="nofollow" href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY3Mw.curie,80,302">Apple QuickTime 7.3 RTSP Response Content-Type Header Stack Buffer Overflow exploit </a> </li>
<li><a rel="nofollow" href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY2NA.curie,80,302">Apple QuickTime Remote stack rewrite exploit for Internet Explorer 6 &#38; 7</a></li>
<li><a rel="nofollow" href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY1Nw.curie,80,302">Apple QuickTime 7.2/7.3 RTSP Response Universal Exploit (IE7/FF/Opera)</a></li>
<li><a rel="nofollow" href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY1MQ.curie,80,302">Apple Quicktime (Vista/XP Sp2 RTSP RESPONSE) Code Exec Exploit</a></li>
</ul>

<h2 style="margin-top:18px;padding-top:14px">Workarounds</h2>
You may try the following workarounds [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src="http://i.kakkoi.net/leopard/QuickTimePlayer.png" style="float: left" alt="Fixes Apple QuickTime" longdesc="http://blog.kakkoi.net/apple/block-apple-quicktime-activex-rtsp-exploit/" title="Quicktime Logo" height="128" width="128" /><strong style="font-weight: 400">Apple QuickTime</strong> contains a stack <a href="http://en.wikipedia.org/wiki/Buffer_overflow" rev="wikipedia:Buffer_overflow" title="buffer overflow" rel="external nofollow">buffer overflow</a> vulnerability in the way it handles the <abbr title="Real Time Streaming Protocol ">RTSP</abbr> Content-Type header. This vulnerability may be exploited by specially crafted RTSP stream protocol</p>
<p><strong>Live Example</strong></p>
<ul class="xoxo nfo">
<li><a href="http://www.gnucitizen.org/blog/backdooring-quicktime-movies/">GNUcitizen- Backdooring QuickTime Movies </a></li>
<li><a href="http://quicktime.tc.columbia.edu/users/iml/movies/mtest.html">Apple QuickTime redirection to the RTSP exploit</a></li>
</ul>
<p>Elia Florio (Symantec) wrap a good introduction post regarding <a href="http://www.symantec.com/enterprise/security_response/weblog/2007/11/0day_exploit_for_apple_quickti.html">QuickTime 0 day Exploit</a>.<br />
<span id="more-62"></span></p>
<h2 style="border-top: 1px solid #cccccc; margin-top: 38px; padding-top: 14px">Known Vulnerabilities Proof of concept (milw0rm).</h2>
<ul class="xoxo nfo">
<li><a href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY3Mw.curie,80,302" rel="nofollow">Apple QuickTime 7.3 RTSP Response Content-Type Header Stack Buffer Overflow exploit </a></li>
<li><a href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY2NA.curie,80,302" rel="nofollow">Apple QuickTime Remote stack rewrite exploit for Internet Explorer 6 &amp; 7</a></li>
<li><a href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY1Nw.curie,80,302" rel="nofollow">Apple QuickTime 7.2/7.3 RTSP Response Universal Exploit (IE7/FF/Opera)</a></li>
<li><a href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY1MQ.curie,80,302" rel="nofollow">Apple Quicktime (Vista/XP Sp2 RTSP RESPONSE) Code Exec Exploit</a></li>
</ul>
<h2 style="margin-top: 18px; padding-top: 14px">Workarounds</h2>
<p>You may try the following workarounds, as there is no complete patch for this this vulnerability.</p>
<ul id="downloads" class="xoxo nfo">
<li> Block TCP <strong>port 554 </strong> (optionaly 7070) and UDP 6970 through 6999 in your firewall</li>
<li>Update <a href="http://www.apple.com/quicktime/download/">Quicktime</a></li>
<li> <a href="http://blog.kakkoi.net/wp-content/uploads/2007/12/disabledquicktimeactivex-kb240797.reg" title="DisabledQuicktimeActiveX-KB240797">Disabled Apple Quicktime ActiveX control running in Internet Explorer</a> (Windows registry file)</li>
<li>For Firefox - <a href="http://noscript.net/">Noscripts</a> addons</li>
</ul>
<h2 style="border-top: 1px solid #cccccc; margin-top: 38px; padding-top: 14px">Related Links</h2>
<ul class="xoxo">
<li><a href="http://info.internet.isi.edu/in-notes/rfc/files/rfc2326.txt">RTSP - rfc2326 </a> &amp; <a href="http://info.internet.isi.edu/in-notes/rfc/files/rfc1889.txt">RTP - rfc1889 </a></li>
<li><a href="http://docs.info.apple.com/article.html?artnum=307038">Apple Security Update on Safari 3 Beta Update 3.0.4</a></li>
<li><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2002-0252">NVD Database - Buffer overflow in Apple QuickTime</a></li>
<li><a href="http://support.microsoft.com/kb/240797">Microsoft KB240797 - How to stop an ActiveX control from running in Internet Explorer</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/apple/block-apple-quicktime-activex-rtsp-exploit/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Firefox Freeze While on Gmail</title>
		<link>http://42.kaizeku.com/google/firefox-freeze-while-on-gmail/</link>
		<comments>http://42.kaizeku.com/google/firefox-freeze-while-on-gmail/#comments</comments>
		<pubDate>Tue, 04 Dec 2007 07:58:56 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Gmail]]></category>

		<category><![CDATA[Google]]></category>

		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[firefox+freezem firebug]]></category>

		<category><![CDATA[no-scriptsm]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/google/firefox-freeze-while-on-gmail/</guid>
		<description><![CDATA[<img src='http://blog.kakkoi.net/wp-content/uploads/2007/12/gmail.gif' alt='gmail freeze'  style="margin:0pt 5px 1px 0pt;float:left"/>Recent update on Gmail has to many "Remote call" (AJAX) running (every 10secs) in the background. It will get really slow if you has a large numbers of email and spam. I'm suffering the dreaded "<strong>firefox freeze over</strong>" syndrome.

Below is a list of addons that will cause "firefox to freezeeeeeeek".  
<ul>
<li>Firebug<li>
<li> Noscripts.</li>
</ul>
Its advice to disabled both of this addons or revert gmail back to older versions. 

<small>uri code to revert gmail to older versions</small> 
<tt>http://mail.google.com/mail/?ui=1</tt>.


As gmail is getting more crappy with "overload features". I think I should start using <a rel="external" title="Thunderbird Email Client" href="www.mozilla.com/thunderbird/ " rev="mozilla:thunderbird">thunderbird</a> more often. 

p/s:  At this time of writing Google Aps Gmail is still with older version so you wont have this issue. 

]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src="http://blog.kakkoi.net/wp-content/uploads/2007/12/gmail.gif" alt="gmail freeze" style="margin: 0pt 5px 1px 0pt; float: left" />Recent update on Gmail has to many &#8220;Remote call&#8221; (AJAX) running (every 10secs) in the background. It will get really slow if you has a large numbers of email and spam. I&#8217;m suffering the dreaded &#8220;<strong>firefox freeze over</strong>&#8221; syndrome.</p>
<p>Below is a list of addons that will cause &#8220;firefox to freezeeeeeeeee&#8221;.</p>
<ul>
<li>Firebug</li>
<li></li>
<li> Noscripts.</li>
</ul>
<p>Its advice to disabled both of this addons or revert gmail back to older versions.</p>
<p><small>uri code to revert gmail to older versions</small><br />
<tt class="di">http://mail.google.com/mail/?ui=1</tt>.</p>
<p>As gmail is getting more crappy with &#8220;overload features&#8221;. I think I should start using <a href="http://www.mozilla.com/en-US/thunderbird/" rel="external" title="Thunderbird Email Client" rev="mozilla:thunderbird">thunderbird</a> more often.</p>
<p>p/s: At this time of writing Google Aps Gmail is still with older version so you wont have this issue.</p>
<h2 class="cb">Related Posts</h2>
<ul class="xoxo">
<li><a href="/firefox/firefox-20012-security-release/">Firefox 2.0.0.12 Urgent Security Release</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/google/firefox-freeze-while-on-gmail/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to safely remove AcroRd32Info.exe</title>
		<link>http://42.kaizeku.com/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/</link>
		<comments>http://42.kaizeku.com/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/#comments</comments>
		<pubDate>Thu, 29 Nov 2007 13:05:00 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Acrobat Reader]]></category>

		<category><![CDATA[Adobe]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[AcroRd32Info]]></category>

		<category><![CDATA[acrotray]]></category>

		<category><![CDATA[AdobeReader.K]]></category>

		<category><![CDATA[Explorer]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[pdf]]></category>

		<category><![CDATA[prefetching]]></category>

		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/</guid>
		<description><![CDATA[<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/11/acrord32info.jpg' alt='AcroRd32Info' style="float:left;margin-right:3px;margin-bottom: 0px" /><strong><a href="http://www.adobe.com/products/acrobat/readstep2.html">AcroRd32Info</a></strong> is a another creative pieces of crap from <a href="http://www.adobe.com">Adobe</a> a package  for Acrobat Reader. Embed in Windows Explorer Shell, its main role is to start an initial prefetching for PDF documents in the Memory.</p>

<p>To test this program behavior, you will need to open your windows task manager (ctrl+alt+del once) and browse to any folder that contained a PDF documents and stay idle. Within just few seconds <strong>AdobeRd32Info</strong> will be loaded in the background and stay in memory.That was just for  browsing the folder without opening any PDF files yet.</p> 

<p>Windows has a standard prefetch modes and its fairly stable for most of the applications out there. Having a another background prefetcher hook on explorer is plain abusive not to mention its running without the owner permissions.</p> 

<p>AcroRd32Info stay in your memory so consider it as a pest. So how to disabled it?</p>
]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/11/acrord32info.jpg' alt='AcroRd32Info' style="float:left;margin-right:3px;margin-bottom: 0px" /><strong><a href="http://www.adobe.com/products/acrobat/readstep2.html">AcroRd32Info</a></strong> is a another creative pieces of crap from <a href="http://www.adobe.com">Adobe</a> a package for Acrobat Reader. Embed in Windows Explorer Shell, its main role is to start an initial prefetching for PDF documents in the Memory.</p>
<p><span id="more-37"></span></p>
<p>To test this program behavior, you will need to open your windows task manager (ctrl+alt+del once) and browse to any folder that contained a PDF documents and stay idle. Within just few seconds <strong>AdobeRd32Info</strong> will be loaded in the background and stay in memory.That was just for browsing the folder without opening any PDF files yet.</p>
<p>Windows has a standard prefetch modes and its fairly stable for most of the applications out there. Having a another background prefetcher hook on explorer is plain abusive not to mention its running without the owner permissions.</p>
<p>Adobe Reader is cheating. Its understable that with this methods it will improve the Acrobat boot time log, but I dont see much differences when its running in the background preparing to load a single PDF documents, its a pollutions.</p>
<p>AcroRd32Info stay in your memory so consider it as a <span class="hilite-3">pestware</span>.</p>
<p>Here&#8217;s how you can <em>safely</em> removed this programs. </p>
<h3 id="removed">The proper way</h3>
<ul>
<li>open <strong>Adobe AcroRd32</strong></li>
<li>Edit &raquo; Preferences </li>
<li>Select the <strong>internet</strong> categories in the menu list then disabled <br /><strong>Allow fast web view</strong> &#038; <strong>Allow speculative downloading in the background</strong></li>
</ul>
<p>If thats doesnt work, you try this <strong>unrecommended</strong> method to disabled it.</p>
<ul>
<li>Browse to Adobe Reader directory usually at &#8220;Program Files\Adobe\Reader\&#8221; </li>
<li>Find <strong>AcroRd32Info.exe</strong></li>
<li>Rename it from <strong>AcroRd32Info.exe</strong> to <strong>Acro_Rd32Info.exe</strong></li>
</ul>
<h2>Recent Exploit on Adobe Reader</h2>
<h3 id="AdobeReaderK">Exploit:W32/AdobeReader.K</h3>
<p class="notice" style="padding:10px;margin:18px auto;border:1px solid #ccc">From FSECURE, <a href="http://blog.kakkoi.net/uri/d3d3LmYtc2VjdXJlLmNvbS92LWRlc2NzL2V4cGxvaXRfdzMyX2Fkb2JlcmVhZGVyX2suc2h0bWw.curie,80,302" rel="external" title="External site">Exploit:W32/AdobeReader.K</a> is detection of a malicious PDF file that is being heavily spammed through e-mail and it appears as an attachment.<br />
This malicious PDF file takes advantage of a vulnerability on the URI handling of PDF files. This vulnerability affects IE7, Adobe Acrobat, and Adobe Reader on some platforms.<br />
Users should update their Adobe Reader installations. </p>
<h3>Affected Software Versions</h3>
<p>Adobe Reader 8.1 and earlier, Adobe Reader 7.0.9 and earlier. Adobe Acrobat Professional, 3D and Standard 8.1 and earlier versions, Adobe Acrobat Professional, Standard, 3D and Elements 7.0.9 and earlier.</p>
<p>More info on this exploits at <a href="http://blog.kakkoi.net/uri/bnZkLm5pc3QuZ292L252ZC5jZm0_Y3ZlbmFtZT1DVkUtMjAwNy01MDIw.curie,80,302">National Vulnerability Database</a></p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Matt cutts Snippet video - The anatomy of a search result</title>
		<link>http://42.kaizeku.com/google/matt-cutts-snippet-video-the-anatomy-of-a-search-result/</link>
		<comments>http://42.kaizeku.com/google/matt-cutts-snippet-video-the-anatomy-of-a-search-result/#comments</comments>
		<pubDate>Tue, 27 Nov 2007 18:58:15 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Google]]></category>

		<category><![CDATA[google+webmaster]]></category>

		<category><![CDATA[links]]></category>

		<category><![CDATA[matt+cutts]]></category>

		<category><![CDATA[meta]]></category>

		<category><![CDATA[pagerank]]></category>

		<category><![CDATA[seo]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/google/matt-cutts-snippet-video-the-anatomy-of-a-search-result/</guid>
		<description><![CDATA[

Matt cutts (Head of Google Webspam team) explained the important part of meta content.
view the video here

]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>Matt cutts (Head of Google Webspam team) explained the important part of meta content.</p>
<p>view the video <a href="http://www.youtube.com/v/vS1Mw1Adrk0">here</a></p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/google/matt-cutts-snippet-video-the-anatomy-of-a-search-result/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to Block Acces to Unsavory Websites Without using Firewall or third party software</title>
		<link>http://42.kaizeku.com/windows/how-to-block-website-without-using-firewall/</link>
		<comments>http://42.kaizeku.com/windows/how-to-block-website-without-using-firewall/#comments</comments>
		<pubDate>Tue, 27 Nov 2007 17:42:51 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Tips]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[block website]]></category>

		<category><![CDATA[dialer]]></category>

		<category><![CDATA[filtering]]></category>

		<category><![CDATA[firewall]]></category>

		<category><![CDATA[opendns]]></category>

		<category><![CDATA[phissing site]]></category>

		<category><![CDATA[spams]]></category>

		<category><![CDATA[window]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/windows/how-to-block-website-without-using-firewall/</guid>
		<description><![CDATA[

There is many reason why you need to block certain website from being access in your network. below is a &#8220;the few reason why&#8221;. 

It&#8217;s a warez and porn sites.
I don&#8217;t want my employee to view my Competitor Websites.
I&#8217;m using illegal software and It seem necessary to disable the automated online registry checkup. ;p
I&#8217;m against [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>There is many reason why you need to block certain website from being access in your network. below is a &#8220;the few reason why&#8221;. </p>
<ol>
<li>It&#8217;s a warez and porn sites.</li>
<li>I don&#8217;t want my employee to view my Competitor Websites.</li>
<li>I&#8217;m using illegal software and It seem necessary to disable the automated online registry checkup. ;p</li>
<li>I&#8217;m against this [countryname] I want to block all this particular domain from being access.</li>
<li>I hated this [socialnetworksite]</li>
</ol>
<p><span id="more-26"></span></p>
<h2>Safe Blocking</h2>
<p>Here&#8217;s two methods you can safely used to block or redirect unwanted website from being access without using third party software.</p>
<h3>1. Block Website using Windows Host file</h3>
<p>Open Window explorer, browse to <em>C:\WINDOWS\system32\drivers\etc</em> click on the file name &#8220;<strong>host</strong>&#8221; <small>(the file has no extension)</small> make a backup copy first. Then right click view file properties and disabled the read only attributes and open it with a text editor (i.e: notepad).</p>
<h5>Windows host settings instructions note</h5>
<blockquote cite="http://blog.kakkoi.net/windows/how-to-block-website-without-using-firewall/"><p>This file contains the mappings of IP addresses to host names. Each entry should be kept on an individual line. The IP address should be placed in the first column followed by the corresponding host name. The IP address and the host name should be separated by at least one space.</p></blockquote>
<p><tt>route-to target-hostname</tt><br />
example<br />
<tt>127.0.1.1 www.thewebsite.com</tt></p>
<p class="notice">note: 127.0.1.1 is you localhost address this is where you want the target-hostname/website to redirect. thewebsite.com is the targeted website URL.</p>
<p>alternatively you can also redirect it to google<br />
<tt>64.233.167.99 www.thewebsite.com</tt></p>
<p>Save the file and restore back the read only mode, then type in the block address url in your browser see if works.</p>
<h2>OpenDNS filtering</h2>
<p>The second methods is universal, its work on any operating systems. <a href="http://www.opendns.com">OpenDNS</a>filtering. This articles wont teach you how to setup opendns, you can read it at <a href="http://www.opendns.com/support/article/39">https://www.opendns.com/start</a>. After you had setup OpenDNS account. Read their <a href="http://www.opendns.com/support/article/39">KB39 articles</a><br />
<img src="http://blog.kakkoi.net/wp-content/uploads/2007/11/open-dns-blokcdomain.png" alt="open-dns-blokcdomain.png" width="350" /><br />
its pretty much straight forward from there on. I&#8217;m sure you wont have problem configuring opendns filter . everything is just 2 click way.</p>
<h2 class="cb">Example Blocked Lists</h2>
<pre class="prebox">
127.0.0.1	babe.the-killer.bz
127.0.0.1	www.babe.the-killer.bz
127.0.0.1	babe.k-lined.com
127.0.0.1	www.babe.k-lined.com
127.0.0.1	did.i-used.cc
127.0.0.1	www.did.i-used.cc
127.0.0.1	coolwwwsearch.com
127.0.0.1	www.coolwwwsearch.com
127.0.0.1	coolwebsearch.com
127.0.0.1	www.coolwebsearch.com
127.0.0.1	hi.studioaperto.net
127.0.0.1	www.hi.studioaperto.net
127.0.0.1	webbrowser.tv
127.0.0.1	www.webbrowser.tv
</pre>
<p class="notice">Notes: Notice the double entries for each domain <span class="fw">example.com</span> and <span class="fw">www.example.com</span> , You will need both long and short URL for effective blocking. Dont depend on canonical address</p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/how-to-block-website-without-using-firewall/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
