Protecting yourself against viruses

Greg Anderson greg@planetbeagle.com
Mon, 13 Nov 2000 11:57:47 -0800


---------------------- multipart/alternative attachment
Hi all,

On the subject of protecting yourself against viruses and other destructive attachments, here's a short article that appeared in PC Magazine, detailing how Windows and Outlook can trick you into launching a program when you think you're just opening a text file.  It also tells you a simple modification you can make to your system that will help lessen the chances that you'll be stung.

Regards,
Greg Anderson

ps: This article can be viewed at http://www.zdnet.com/pcmag/stories/solutions/0,8224,2635292,00.html


Poisonous Scraps

Document scraps look innocent but can invoke malicious commands easily. We show you how to identify and defuse them.

By Neil J. Rubenking
October 2, 2000

Microsoft invented the scrap object as a wrapper for OLE data. Launching a scrap invokes any program defined in the object's properties. The scrap object's icon is almost identical to the text document's icon. Windows Explorer hides the associated .shs extension even when it's configured to show all extensions, so an e-mail attachment named Report.txt.shs would be displayed as Report.txt. This seemingly innocent attachment can invoke any command at all: How about FORMAT C:? The only surprise is that malicious use of this feature has only begun recently.

Here's how to remove the camouflage that makes scrap objects dangerous. Launch REGEDIT (or better, our RegEdit+ utility) and navigate to HKEY_CLASSES_ROOT\ ShellScrap. Find the value named NeverShowExt in the right-hand pane and delete it. Do the same for HKEY_CLASSES_ROOT\DocShortcut.

Now launch Windows Explorer, choose Folder Options from the View menu, and click the File Types tab. Select Scrap object from the list, click Edit, and click Change Icon. Browse to Pifmgr.dll (in the Windows System folder) and select the last icon -- a bundle of dynamite! Do the same for the Shortcut into a document file type. 

Visit http://www.pc-help.org/security/scrap.htm to learn more. You'll be amazed and alarmed.



___________________________________________________________________
Greg Anderson                                 greg@PlanetBeagle.com 

---------------------- multipart/alternative attachment
An HTML attachment was scrubbed...
URL: https://www.moypiano.com/ptg/pianotech.php/attachments/ee/c1/3e/20/attachment.htm

---------------------- multipart/alternative attachment--



This PTG archive page provided courtesy of Moy Piano Service, LLC