A wide variety of boot problems have been reported with Windows XP SP3, fortunately many of them are very fixable.

Windows XP remains a standard throughout much of the IT community, and remains popular among consumers as well. Thus many consumers are pleased that Windows XP Service Pack 3 is back in action, after being pulled a week for a software fix. The new service pack provides additional useful features, numerous bugfixes, and minor performance improvements.

Unfortunately some users are also finding that it provides their computer with an endless reboot loop. First, to dispel a common misconception, the reboot itself has nothing to do with a problem with XP SP3. Rather, the problem is during the boot, which results in a crash. In the case of the crash, Windows XP behaves correctly -- it reboots the computer and asks the user if they want to boot into safe mode, defaulting to a normal boot if no option is selected.

Users are not happy about the developments. Michael Faklis posting on the Windows XP discussion board, vents, "My external disks are having trouble starting up, which results in Windows not starting up. After three attempts [to install XP SP3] with different configurations each time, System Restore was the only way to get me out of deep s**t."

The source of many of the problems has been traced to manufacturers, which takes a bit of heat off Microsoft. Perhaps the single biggest problem appears to be caused by Hewlett Packard's configuration choices. By default HP deploys the driver intelppm.sys on all their computers, including those with AMD processors. The driver provides power-management, but only for Intel machines. On AMD machines a second driver, amdk8.sys is also added, which performs the same functionality for AMD processors.

If your machine's HP part number ends in a 'z', you probably have an AMD processor. Or you could just peek inside. Either way, if you have an AMD machine, you will likely experience crashes when you install Windows XP SP3. This is really not Microsoft's fault as HP is installing an unsupported configuration by adding both drivers. To fix the problem, if you haven't added SP3 yet, just type "disable intelppm" in the command prompt or run "sc config intelppm start= disabled" if you already installed it and can only boot to safe mode.

Another problem seems to occurring on certain motherboards, which affects USB devices. Users found a simple fix to this problem -- some report that by plugging in a USB storage device their computer will boot normally, but without the device attached it will crash. For non-AMD/HP users, this remains an option if dealing with crashes. Also some have found that switching the mouse from USB to PS/2 port (via the adapter to the round PS/2 port) fixes the problem, indicating it may be an issue with USB mouse drivers.

Additionally, users of AMD's Catalyst 8.4 drivers have also reported some crashes. To see if the video driver is the issue, boot to VGA mode. If it works, the video driver may be to blame. One isolate report of an NVIDIA related crash also occurred, but it was unreported what driver was used. Other miscellaneous crashes appear to be due to systems with multiple hard disks.

A very helpful resource to deal with the problems is provided by Microsoft MVP in Windows Security, Jesper Johansson, who offers additional helpful details to these and other potential problems and their fixes on his blog.

As Johansson points out, the most extreme solution when none other can be found is simply to uninstall XP SP3. To do this, refer to the Microsoft Knowledge Base article on the topic.

While Windows XP is receiving some bad press due to the crashes, again, it appears that most of the crashes are due to hardware issues stemming from unsupported configurations, and thus the blame fall largely to the PC manufacturers, and the makers of component drivers. Fortunately, the majority of the problems have easy fixes that do not even requiring uninstalling the Service Pack.

Similar problems occurred with Windows Vista SP1, though in that case the blame ended up resting with a Microsoft pre-install update. It is fairly typical for a Service Pack to take some computers out of commission, particularly one for an OS with as large an operating base and as varied a hardware environment as Windows XP. Nonetheless, such problems are serious concerns for users affected, and those potentially at risk.

Read More......
Friday, January 18, 2008

Poisoned websites attack visitors


Thousands of small web shops have been unwittingly poisoned with malicious code that infects PC users who visit.

Security experts said the sophisticated attack had succeeded on a larger scale than many other similar attacks.

Once installed on a Windows machine the malicious code steals passwords, browser data as well as login names for bank accounts and online games.

The attack is proving hard to defend against for both sites being hit and PC users who are caught out.

Big hitter

Security researchers at ScanSafe, Finjan and Secure Works separately discovered the nest of poisoned websites. Estimates of how many sites have been enrolled into the attack vary. ScanSafe said it knew of about 230 but Secure Works and Finjan believe the total could be as high as 10,000.

Yuval Ben-Itzhak, chief technology officer of Finjan, said it had been following the attack since early December when it noticed an increase in the number of attacks using poisoned websites.

"It's safe to say that there are thousands of these out there," he said. He added that it was hard to get an accurate picture of just how many had been hit because security firms had limited resources to scan all potential targets.

Writing on the ScanSafe blog Mary Landesman said many of the poisoned sites were small "mom and pop" web shops rather than large web retailers. Despite this, she wrote, many had large numbers of visitors because they did well in web searches for particular products and services.

Sites enrolled by the ongoing attack include trade papers, travel firms, ad brokers, estate agents, butchers, hotel booking sites and car spare specialists.

Although all the websites that have become poisoned hosts use the same server and remote administration software, researchers have struggled to spot all the ways they are being compromised.

"We know some of the methods," said Mr Ben-Itzhak, "they are trying to exploit known vulnerabilities in open source content management software that the sites are using."

Spotting the attack code on a site was very difficult, he said, because every time a new user visited the code got a new, random five character name. If a visitor returned the malicious code identified them and did not launch a second attack.

Open Windows

Simon Heron, managing director of security firm Network Box, said: "It looks like the rootkit type technique that we have been worried about for the last two or three years. It's very clever."

A rootkit hides itself deep inside an operating system in an attempt to avoid detection.

Mr Heron said the code injected on the websites scanned the machine of any visiting Windows user to see if any one of 13 separate vulnerabilities were present.

It looked for vulnerabilities in browsers, instant messaging programs, document readers and media players, he said.

The code installs a small trojan through any one of these loopholes then lies dormant until a user types in data that it is interested in - such as login names for online banks or games such as World of Warcraft.

As yet the trojan installed on a PC is not recognised by many widely used anti-virus programs.

Philippe Courtot, founder and head of security firm Qualys, said small web shops and companies were increasingly becoming a target for criminally-minded hackers.

"Small businesses do not have the money to protect themselves," he said.

He added that hosting firms who owned and ran the servers on which these firms place their websites, viewed security as something extra they had to do rather than build it in.

"Hosting companies, for them today, adding security is a cost," he said.

Story from BBC NEWS:
http://news.bbc.co.uk/go/pr/fr/-/2/hi/technology/7193993.stm

Read More......
Monday, January 14, 2008

Warning on stealthy Windows virus


Security experts are warning about a stealthy Windows virus that steals login details for online bank accounts.

In the last month, the malicious program has racked up about 5,000 victims - most of whom are in Europe. Many are falling victim via booby-trapped websites that use vulnerabilities in Microsoft's browser to install the attack code. Experts say the virus is dangerous because it buries itself deep inside Windows to avoid detection.

Old tricks

The malicious program is a type of virus known as a rootkit and it tries to overwrite part of a computer's hard drive called the Master Boot Record (MBR). This is where a computer looks when it is switched on for information about the operating system it will be running.

"If you can control the MBR, you can control the operating system and therefore the computer it resides on," wrote Elia Florio on security company Symantec's blog. Mr Florio pointed out that many viruses dating from the days before Windows used the Master Boot Record to get a grip on a computer.

Once installed the virus, dubbed Mebroot by Symantec, usually downloads other malicious programs, such as keyloggers, to do the work of stealing confidential information. Most of these associated programs lie in wait on a machine until its owner logs in to the online banking systems of one of more than 900 financial institutions. The Russian virus-writing group behind Mebroot is thought to have created the torpig family of viruses that are known to have been installed on more than 200,000 systems. This group specialises in stealing bank login information.

Security firm iDefense said Mebroot was discovered in October but started to be used in a series of attacks in early December. Between 12 December and 7 January, iDefense detected more than 5,000 machines that had been infected with the program. Analysis of Mebroot has shown that it uses its hidden position on the MBR as a beachhead so it can re-install these associated programs if they are deleted by anti-virus software. Although the password-stealing programs that Mebroot installs can be found by security software, few commercial anti-virus packages currently detect its presence. Mebroot cannot be removed while a computer is running.

Independent security firm GMER has produced a utility that will scan and remove the stealthy program. Computers running Windows XP, Windows Vista, Windows Server 2003 and Windows 2000 that are not fully patched are all vulnerable to the virus.

Story from BBC NEWS:
http://news.bbc.co.uk/go/pr/fr/-/2/hi/technology/7183008.stm

Read More......
Wednesday, January 9, 2008

Copying CDs could be made legal


Copying music from a CD to a home computer could be made legal under new proposals from the UK government.

Millions of people already "rip" discs to their computers and move the files to MP3 players, although the process is technically against copyright law.

Intellectual property minister Lord Triesman said the law should be changed so it "keeps up with the times".

Music industry bodies gave a cautious welcome to the proposals, which are up for public consultation until 8 April.

The changes would apply only to people copying music for personal use - meaning multiple copying and internet file-sharing would still be banned.

Owners would not be allowed to sell or give away their original discs once they had made a copy.

Sales concerns

"To allow consumers to copy works and then pass on the original could result in a loss of sales," the proposals warn.

UK music industry body the BPI said it supported the move to clarify the law for consumers, but warned that any changes should not damage the rights of record companies.

The Association of Independent Music (Aim) said the proposals did not go far enough - pointing out that CDs could become obsolete in the next decade.

It said that, once CDs are replaced, the law could be misused to "open the floodgates to unstoppable copying", adding that it would like to see copyright holders compensated when music was copied.

Lord Triesman said the proposed changes would explore "where the boundaries lie between strong protection for right holders and appropriate levels of access for users".

The proposals also suggest schools and libraries should be given greater flexibility in how they use copyrighted material like CDs and DVDs, and suggests parodies of songs and films could be made exempt from copyright law.

The consultation follows the Gowers Review of Intellectual Property, which recommended that aspects of the intellectual property system should be reformed.

Story from BBC NEWS:
http://news.bbc.co.uk/go/pr/fr/-/2/hi/entertainment/7176538.stm

Published: 2008/01/08 12:07:30 GMT

© BBC MMVIII

Read More......


NASA develops PPA system to up the safety and accuracy of civil and research aircraft

The PPA system will help keep the C-20A Gulfstream III flying level so the UAVSAR radar pod can scan geoseismic hot spots. (Source: US Army)


The Wide Area Augmentation System (WAAS) is just now finally entering into civil aviation navigation in the United States. WAAS provides a GPS based means for aircraft to maintain a flight path by issuing level correction vectors. The end result is that the plane flies on a prescribed level path -- either from a previous flight or a computer generated path -- and follows the path to an accuracy of 30 feet.

Not one to rest on their laurels, NASA is keeping the ball rolling developing an even better system, dubbed the Platform Precision Autopilot (PPA). One significant advantage of PPA over WAAS is that due to its usage of GPS satellites and traditional techniques WAAS can only operate with 75 degrees of latitude in the northern and southern hemispheres. For PPA, which NASA plans to use in research planes which travel over Greenland and the Arctic, NASA also uses GPS but it boosts the range by relaying real-time GPS correction-vectors along Iridium’s satellite phone network to allow for navigation anywhere on the global.

NASA makes significant gains in accuracy between PPA and WAAS. WAAS's accuracy of 30 feet has been beefed up to 15 feet with PPA, a two-fold improvement. NASA hopes to become even more accurate, and is shooting for an accuracy of a few millimeters.

The final step after grabbing the more accurate GPS data is to combine it with 40 Hz input data from the aircraft's laser gyro-driven Inertial Navigation Unit (INU). Combining these signals the aircraft's onboard computer outputs positional and guidance information. This is used to autopilot the plane, but the output is displayed in traditional instrument landing system (ILS) form. Pilots will be able to read and understand it, and take corrective actions if necessary in case of system malfunction or failure. By implementing ILS, the system can become FAA-certified, paving the way for its eventual adoption on commercial aircraft.

The system was developed at NASA's Dryden Flight Research Center in Edwards, CA, which worked in conjunction with NASA's Jet Propulsion Laboratory (JPL) in Pasadena, CA. The system is designed to be utilized for NASA's Unmanned Aerial Vehicle Synthetic Aperture Radar (UAVSAR), a radar system designed at NASA's JPL under the guidance of NASA engineer Scott Hensley. The UAVSAR is a radar system which broadcasts microwaves in the 1.2 GHz range from an L-Band aperture.

NASA intends to use the UAVSAR for precision mapping of terrain, particularly with unmanned vehicles to map and monitor sites of extreme geologic activity. The UAVSAR is very flexible and can electronically adjusts its signal, allowing it to be mounted on a wide variety of vehicles, but it requires a system like PPA to maintain a steady enough altitude for it to get good images.

The UAVSAR will be mounted aboard NASA's C-20A Gulfstream III, which will be used as a test of PPA's accuracy and whether it operates sufficiently for the UAVSAR system's readings. NASA plans to log 140 hours of test flights before August 2008. Since the Gulfstream III operates outside civilian air space it will not need a permit to use the UAV which takes 90-days due to a somewhat archaic processing system. The test platform will allow NASA to instantly map hot zones of geologic activity. Satellite SAR systems currently exist, but they only flyby a location with 24 to 45 days, so being in the right place at the right time for short-term events is unlikely.

NASA continues to lead the way in international aviation and its PPA and UAVSAR systems are no exception. The PPA is especially promising to not only allow cutting edge research flights, but also promises to evolve and America's next generation of civilian aircraft safer.

Read More......