<?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2" -->
<rss version="2.0">
    <channel>
        <title>Lowyat.NET: Latest topics by crynobone</title>
        <description></description>
        <link>http://forum.lowyat.net/</link>
        <lastBuildDate>Tue, 23 Jun 2026 00:06:24 +0800</lastBuildDate>
        <generator>FeedCreator 1.7.2</generator>
        <item>
            <title>Warning: Unresponsive Script</title>
            <link>http://forum.lowyat.net/topic/350563</link>
            <description>This what I got when while browsing Lowyat.NET Main Page. If you left in long enough the error will appear. I know it nothing but Memory Leak is something we should prevent right</description>
            <author>crynobone</author>
            <category>Feedback and Helpdesk</category>
            <pubDate>Sat, 07 Oct 2006 15:34:16 +0800</pubDate>
        </item>
        <item>
            <title>[Attention] Trojan in Utusan Website</title>
            <link>http://forum.lowyat.net/topic/307487</link>
            <description>I just got this info from &lt;a href='http://www.mycommet.net/index.php?showtopic=1162' target='_blank'&gt;http://www.mycommet.net/index.php?showtopic=1162&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;!--QuoteBegin--&gt;&lt;div class='quotetop'&gt;QUOTE&lt;/div&gt;&lt;div class='quotemain'&gt;&lt;!--QuoteEBegin--&gt;Assalamualaikum,&lt;br /&gt;&lt;br /&gt;Thank you for reporting to us. We had checked www.utusan.com.my and&lt;br /&gt;we confirm that the below site linked in www.utusan.com.my, that&lt;br /&gt;provides free web statistics contains a downloader Trojan and Java applets,&lt;br /&gt;which are components of a malicious Java archive file (JAR).&lt;br /&gt;&lt;br /&gt;The link which is embedded in the web counter icon is as below:&lt;br /&gt;&lt;br /&gt;&lt;a href='http://y.extreme-dm.com/s/?tag=felixm' target='_blank'&gt;http://y.extreme-dm.com/s/?tag=felixm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Once clicked on the above link, it is redirected to a malicious site&lt;br /&gt;&lt;a href='http://ilead.itrack.it,in' target='_blank'&gt;http://ilead.itrack.it,in&lt;/a&gt; which a downloader Trojan and malicious Java&lt;br /&gt;applets will be downloaded into PCs browsing your site.&lt;br /&gt;&lt;br /&gt;The downloader Trojan and the malicious Java applets found to be&lt;br /&gt;downloaded from the above malicious site are:&lt;br /&gt;&lt;br /&gt;TROJ_ANICMOO.AL&lt;br /&gt;&lt;br /&gt;Details on the TROJ_ANICMOO is available at:&lt;br /&gt;&lt;br /&gt;Symantec&lt;br /&gt;&lt;a href='http://www.symantec.com/avcenter/venc/data....anicmoo.c.html' target='_blank'&gt;http://www.symantec.com/avcenter/venc/data....anicmoo.c.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;JAVA_BYTEVER.AC&lt;br /&gt;JAVA_BYTEVER.AB&lt;br /&gt;JAVA_BYTEVER.A&lt;br /&gt;&lt;br /&gt;Details on the JAVA_BYTEVER.AC, AB, A&lt;br /&gt;&lt;br /&gt;TrendMicro&lt;br /&gt;&lt;a href='http://www.trendmicro.com/vinfo/virusencyc...JAVA_BYTEVER.AC' target='_blank'&gt;http://www.trendmicro.com/vinfo/virusencyc...JAVA_BYTEVER.AC&lt;/a&gt;&lt;br /&gt;&lt;a href='http://www.trendmicro.com/vinfo/virusencyc...JAVA_BYTEVER.AB' target='_blank'&gt;http://www.trendmicro.com/vinfo/virusencyc...JAVA_BYTEVER.AB&lt;/a&gt;&lt;br /&gt;&lt;a href='http://www.trendmicro.com/vinfo/virusencyc...=JAVA_BYTEVER.A' target='_blank'&gt;http://www.trendmicro.com/vinfo/virusencyc...=JAVA_BYTEVER.A&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;We had communicated with Utusan&amp;#39;s Admin and advised him to check/remove any&lt;br /&gt;untrusted sites linked in their site as the untrusted sites could be malicious&lt;br /&gt;and may contain malicious programs that can be downloaded into users&amp;#39; machines&lt;br /&gt;that browse the site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Steps to clean up PCs infected with the above malicious programs are as below.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To clean up PCs infected with the downloader Trojan:&lt;br /&gt;&lt;br /&gt;1) Disconnect the infected PCs from the network&lt;br /&gt;2) Patch the PCs with the Microsoft Security Bulletin MS05-002,&lt;br /&gt;against a vulnerability in Cursor and Icon Format Handling Could&lt;br /&gt;Allow Remote Code Execution.&lt;br /&gt;&lt;br /&gt;The patch can be downloaded at:&lt;br /&gt;&lt;a href='http://www.microsoft.com/technet/security/...n/MS05-002.mspx' target='_blank'&gt;http://www.microsoft.com/technet/security/...n/MS05-002.mspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;NOTE: The patch can be downloaded from a clean PC into a media and&lt;br /&gt;then install the patch into the infected PC.&lt;br /&gt;&lt;br /&gt;3) Disable System Restore for Windows XP/ME&lt;br /&gt;&lt;br /&gt;4) Install an Anti-virus software and update the anti-virus&lt;br /&gt;software with latest signature files.&lt;br /&gt;&lt;br /&gt;List of Anti-virus softwares is available at:&lt;br /&gt;&lt;a href='http://www.mycert.org.my/anti-virus.htm' target='_blank'&gt;http://www.mycert.org.my/anti-virus.htm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;NOTE: The Anti-virus software can be downloaded from a clean PC into&lt;br /&gt;a media and then install the Anti-virus into the infected PC.&lt;br /&gt;&lt;br /&gt;5) Scan the infected PC with unupdated version of Anti-virus software&lt;br /&gt;and delete files detected as Trojan.Anicmoo.&lt;br /&gt;&lt;br /&gt;6) Re-scan the PC with an updated version of Anti-virus to confirm&lt;br /&gt;the PC is clean.&lt;br /&gt;&lt;br /&gt;7) Enable System Restore for Windows XP/ME&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To remove PCs infected with the malicious Java Applet:&lt;br /&gt;&lt;br /&gt;1) Disconnect the infected PC from the network.&lt;br /&gt;2) Patch the infected PC with the Microsoft Security Bulletin MS03-011,&lt;br /&gt;against a flaw in Microsoft VM Could Enable System Compromise&lt;br /&gt;&lt;br /&gt;The patch can be downloaded at:&lt;br /&gt;&lt;a href='http://www.microsoft.com/technet/security/...n/MS03-011.mspx' target='_blank'&gt;http://www.microsoft.com/technet/security/...n/MS03-011.mspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;NOTE: The patch can be downloaded from a clean PC into a media and&lt;br /&gt;then install the patch into the infected PC.&lt;br /&gt;&lt;br /&gt;3) Disable System Restore for Windows XP/ME&lt;br /&gt;&lt;br /&gt;4) Install an Anti-virus software and update the anti-virus&lt;br /&gt;software with latest signature files.&lt;br /&gt;&lt;br /&gt;List of Anti-virus softwares is available at:&lt;br /&gt;&lt;a href='http://www.mycert.org.my/anti-virus.htm' target='_blank'&gt;http://www.mycert.org.my/anti-virus.htm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;NOTE: The Anti-virus can be downloaded from a clean PC into a media and&lt;br /&gt;then install it into the infected PC.&lt;br /&gt;&lt;br /&gt;5) Scan the infected PC and delete any files detected as JAVA_BYTEVER.AC,&lt;br /&gt;JAVA_BYTEVER.AB and JAVA_BYTEVER.A.&lt;br /&gt;&lt;br /&gt;OR&lt;br /&gt;&lt;br /&gt;Download ad-aware to remove the Java Applet:&lt;br /&gt;&lt;a href='http://www.lavasoft.de/software/adaware/' target='_blank'&gt;http://www.lavasoft.de/software/adaware/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;6) Re-scan the PC with an updated version of Anti-virus to confirm&lt;br /&gt;the PC is clean.&lt;br /&gt;&lt;br /&gt;7) Enable System Restore for Windows XP/ME.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Preventive Measures:&lt;br /&gt;&lt;br /&gt;1) Always make sure your PC is regularly updated with latest patches.&lt;br /&gt;Lates patches can be downloaded at:&lt;br /&gt;&lt;br /&gt;&lt;a href='http://update.microsoft.com/microsoftupdat...t.aspx?ln=en-us' target='_blank'&gt;http://update.microsoft.com/microsoftupdat...t.aspx?ln=en-us&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;2) End users may also consider to install pop up blocker to block pop&lt;br /&gt;up messages appearing on PCs.Some pop up blockers that can be downloaded&lt;br /&gt;free from the Internet are:&lt;br /&gt;&lt;br /&gt;Pop up stopper by panicware&lt;br /&gt;Pop up blocker by earthlink.net&lt;br /&gt;Noadware by noadware,net&lt;br /&gt;Google toolbar&lt;br /&gt;&lt;br /&gt;3) Users are recommended to change their username/password to their PC&lt;br /&gt;once their PC is cleaned.&lt;br /&gt;&lt;br /&gt;We hope this is of hope and do contact us if you need our further&lt;br /&gt;assistance.&lt;br /&gt;&lt;br /&gt;Thanks&lt;br /&gt;- -roziah&lt;!--QuoteEnd--&gt;&lt;/div&gt;&lt;!--QuoteEEnd--&gt;</description>
            <author>crynobone</author>
            <category>Security &amp;amp; Privacy</category>
            <pubDate>Thu, 29 Jun 2006 14:46:56 +0800</pubDate>
        </item>
        <item>
            <title>[bad html removed]</title>
            <link>http://forum.lowyat.net/topic/287832</link>
            <description>IFRAME got blocked? I can&amp;#39;t type &amp;lt; IFRAME &amp;gt; properly and by the way IFRAME do have it uses now and then.&lt;br /&gt;&lt;br /&gt;&lt;a href='http://forum.lowyat.net/index.php?showtopic=287735&amp;view=findpost&amp;p=7084664' target='_blank'&gt;http://forum.lowyat.net/index.php?showtopi...dpost&amp;p=7084664&lt;/a&gt;</description>
            <author>crynobone</author>
            <category>Feedback and Helpdesk</category>
            <pubDate>Sat, 13 May 2006 10:14:32 +0800</pubDate>
        </item>
    </channel>
</rss>
