Saturday, June 14, 2008

Win32/Glenwiry.P : The Final Chapter

Well, this is the conclusion to my epic glenwiry.P trilogy (in case you missed it, the first two posts were a roller coaster of emotion, drama and raw excitement). I noticed that my latest anti-virus definitions were downloaded when I fired up the computer this morning (8:20am PDT). So I tried the following:
  1. Disconnected my router from the Internet.
  2. Went to the "Tools" tab of the CA antivirus software.
  3. Clicked "Quarantined Items."
  4. Restored the three "wextract.exe" files that were quarantined Thursday night.
  5. Ran a virus scan of the WINDOWS/system32 folder.
  6. Did a happy dance.
With those files rightly restored, the new antivirus definitions didn't think wextract was a bad apple. This more or less confirms that CA blew it, and then they fixed it rather quickly. I guess they decided to hold off on releasing the fix for glenwiry.p until they actually release that trojan into the wild! Ha! Just kidding. Or am I? Maybe? No, really, I am not even sure anymore.

So chances are, if you never had the glenwiry.p problem, you aren't going to see it anytime soon because the current definitions don't produce a false positive, and if you did have the glenwiry.p problem, you can probably go ahead an restore those files. Again, this is just based on my own experience: do whatever you want to do at your own risk. I am not a security expert, I just play one on the web.

Friday, June 13, 2008

Win32/Glenwiry.P follow-up

Just thought I'd post a little follow-up to my post from yesterday. I am still not completely comfortable saying I'm 100% certain that the Computer Associates quarantine of wextract.exe is a false positive, but based on everything I have read and know, it seems like a false positive is most likely. I'll probably leave those files quarantined until either CA issues a fix or my system suffers for not having it available.

I've seen some folks saying it likely ISN'T a false positive (how's that for a weird double negative) because ZoneAlarm has been noted as flagging these files too. Well, turns out that ZA uses the CA anti-virus engine. At least that's what CNET said last summer. If that is still true, I think it provides even more evidence that we are just looking at a bad definition in the CA tools. If I'm wrong about the ZA-CA connection, I hope someone lets me know.

What is really bothering me now is that CA released a fix for a presumable trojan before it was even known to exist in the wild. This is evidenced by the complete lack of any Google hits on Glenwiry.P before this antivirus definition update last night by CA. Even CA's own website doesn't have any information on the Glenwiry.P threat as of the time of this posting. If that's the case, how is it being caught by their antvirus tools? Perhaps they released the fix There has always been speculation and conspiracy theories that antivirus companies may actually create viruses/threats. An interesting business model, indeed. Though, it is a neat trick to catch a "threat" before anyone has ever heard of it, even yourself. But, hey, what the heck do I know? I'm just a once-in-a-while blogger.

Thursday, June 12, 2008

win32/Glenwiry.p fiasco

So I think the most recent update of Computer Associate's virus scan definitions is giving false positives on wextract.exe. If you have real-time scan activated you'll probably get C:/WINDOWS/system32/wextract.exe and C:/WINDOWS/system32/dllcache/wextract.exe quarantined by your anti-virus software. This might prompt Windows to put up a red flag and demand that you insert your operating system install disk. Not sure yet what the best fix is, so I am going to wait out til the next update from CA which should fix the problem. If that doesn't happen soon or my system has problems due to the quarantined/missing wextract.exe, I will probably restore the quarantined item using CA's tools that come with the anti-virus software.

This all did give me quite a scare though since I pride myself on keeping as secure a system as I can considering I am running Windows. Anyway, I hope this post helps somebody not feel as freaked out as I was initially. There isn't much info online as of now.

Oh, as a side note, I would be careful about going to sites you might find by searching for glenwiry. I think many of them are bogus. If you do go to one by mistake, don't try and click any videos posted there. And if you browser goes into a pop-up hell, you should ctrl-alt-del and kill the browser process. That should get you out of the pop-up carousel.

If I learn anything new tomorrow I'll try and update here, but as you can see by my post history, I am not the most prolific blogger.

Saturday, October 27, 2007

RMA my RAM (with no mar on my arm)

My laptop started acting wonky. Specifically, it started to spontaneously restart whenever the computer had been running for, say, 40 seconds. That is quite annoying. After doing a little research online, I figured that I had a bad capacitor. After ripping apart my laptop to look around, I realized that a laptop motherboard doesn't have the kind of capacitors discussed as being part of the capacitor plague. After looking around some more, I became convinced that I probably had a bunk RAM stick. If your computer is spontaneously restarting, you might want to suspect a CPU overheating problem or power supply issue or bad driver problem if the restart happens after more than a few minutes, but should suspect bad RAM if the restart can happen very quickly (sometimes during boot) or still happens when your doing something like checking BIOS. As I was investigating the problem on my laptop I had tried to get into the BIOS and the computer froze (didn't restart because that is a Windows response to the bad RAM) and that was the last clue to me that the RAM was at fault.

I had bought a 1GB stick from Newegg.com (which I highly recommend for all computer component shopping) a little over a year ago. I was able to pull up the old invoice on my Gigaram RAM. I went to the Gigaram website and found their RMA (returned merchandise authorization) policy and followed it. After about 3 weeks total, I had my replacement RAM at only the cost of shipping my broken RAM to them. Could have been faster, but having the lifetime warranty honored was a good feeling. The fact that Newegg kept a copy of my invoice avaialable to me and that Gigaram honored the warranty made this a fairly painless experience. Thanks Gigaram and Newegg.

Thursday, October 04, 2007

More than fair

Saw this in an AP story about Lance Briggs pleading guilty to something:

Defense attorney Frank Himel said he was pleased with the outcome.

"The judge was more than fair, more than fair," Himel said.

I guess my question is: if you are more than fair, aren't you clearly being unfair somewhere? If we decide to split a cookie evenly and I take 60% of if, I was totally more than fair. I guess this comes down to zero-sum games versus not, but I think it is still a silly statement.

Tuesday, August 14, 2007

Michael Vick and the Prisoner's Dilemma

If I ever go back to teaching math, I'll need to remember this week for a great example for a lecture on game theory. We are watching a real-life version of the famous Prisoner's Dilemma. For those unfamiliar with the PD, wikipedia has a good summary. Basically, the problem is described as a scenario where two prisoners are separately brought in for questioning. If either one cooperates with police (confesses and gives up the other guy), they will get a reduced sentence. If neither one cooperates (both keep quiet), then they will both get the lightest sentence possible. However, if one doesn't cooperate while the other does, the non-cooperator will get the harshest sentence possible.

Here is a nice table directly taken from Wikipedia:


Prisoner B Stays Silent Prisoner B Betrays
Prisoner A Stays Silent Each serves six months Prisoner A serves ten years
Prisoner B goes free
Prisoner A Betrays Prisoner A goes free
Prisoner B serves ten years
Each serves five years

From a game theory standpoint, even though it is in the prisoners best interest to not talk to the police, the risk of the harsh sentence entices both prisoners to betray each other.

So, why the heck bring it up now? Well, I think we're seeing this play out right now with the Michael Vick investigation. For those not up on their NFL scandals, Vick has been indicted on charges related to running a dog fighting ring. The really interesting part is that a few of his cohorts were also indicted. One of them already plead guilty a few weeks ago. This started the pressure on the other three, including Vick. Now there has been an announcement that Vick's two other buddies are scheduled to enter pleas later this week. Uh-oh.

If you look at the table above, that could put all of them squarely (or, more precisely, rectangularly) in the lower right box. Granted, I am sort of forcing this analogy a bit especially since there is likely a boatload of evidence coaxing these confessions, but it is still fascinating to watch from a game theoretic standpoint. It is also fascinating to watch in terms of hoping dog torturers get their comeuppances.

Wednesday, August 01, 2007

Yves redux

Alright, I was hard on Yves in my last post about them. So I thought I'd share my latest positive experience with one of their products. I bought some of Yves Meatless Ground. I am a sucker for sales at the grocery store. I understand that many of these "sale" prices are somewhat artificial, but I still go for them, especially when they have those five special words: "Buy one, get one free". Oh yeah. So I got a couple of these fake ground beef things.

Now the trick was to figure out what to do with it. I ended up feeling a bit nostalgic for the cuisine of my youth. Sweet, sweet Hamburger Helper. Lasagna flavor to be exact. Using the fake meat actually was pretty darn good in the HH. I'd say that kids and many adults wouldn't think too much about it if they tried this. The texture is a bit different (bit chewy), but really the flavor comes from the HH packet anyway. And the Meatless ground is a bit cheaper than the real thing. Especially at buy one get one free.