Updates 2012-01-10

Hi, Folks!

Microsoft released 8 updates addressing vulnerabilities in Microsoft Windows, Windows Media Player, Media Center, developer tools, MSRT, and junk mail filters (under 20mb). This includes security updates. Multiple reboots are required. Unlike a normal monthly Windows Update cycle, this month requires two reboots for most systems – visit Windows Update, check for updates, install all of them, reboot, return to Windows Update, check for updates, install all of them, and reboot again. On some systems the second reboot may not be required.
http://update.microsoft.com/

Adobe Reader and Acrobat updates were released today for all current supported versions (70-205mb). This is a security update. A reboot is required. Use Help, Check for Updates within each Reader/Acrobat application to get the current version.

Don’t make it “easier”, make it “easy”.

I read that in an article last month, and it really spoke to me. My clients have repeatedly asked me to make the update process “easier.”

Easier isn’t good enough.

Throughout any given month I remove malware and viruses from dozens of computers. In every single case the malware used either a known software exploit (for which a patch was available, but not installed) or used a common social engineering tactic that the user could have easily been trained to avoid.

These infections take anywhere from a few minutes to several hours to remove, often costing clients upwards of $200 labor per event. But that’s only the direct costs, there are indirect costs, too. When your computer is infected, chances are it’s by a trojan that has shared your activity, usernames and passwords with the author of the malware. Your email, Facebook, MySpace, and Google accounts are compromised. And chances are, your files have been accessed and possibly shared as well. This all adds up to a total invasion of your privacy, added liability and an increased risk of exploitation.

You’ve no doubt received an email from a close friend or family member that’s been “stranded in London” or needs an “immediate cash transfer” to avoid a default judgment? Perhaps you were called by “Microsoft” who has told you that you’ve got a virus, and all you need to do to let them fix it is visit a website and type in a code…and just days later discover thousands of dollars missing from your bank accounts or fraudulent credit card transactions. It happens…and far more often than you might think.

I post these update notifications regularly – at least one or two per month – and many of my clients look at the list of updates and are simply afraid to go below the top section, so most of the updates that apply to their system are never installed. They often don’t even know what software has been installed on their computers.

I want to fix that. And it’s going to be “easy”!

Don't worry, dude, Shawn's got your back.Now that broadband access is far more widely available in Tuolumne County (and much of the rest of the world, so don’t be shy if you’re not local), I’m expanding my online update services and lowering prices! For the low price of $40/month I will now perform all updates for any single personal computer throughout the month. Additional computers are only $15/month. If that’s not a sweet enough offer: If you do get a virus while a subscriber to this service, I’ll discount the monthly subscription cost from my virus removal services. You’ll still come out ahead – and more secure.

Interested? Call or email now.
209-565-1273
shawn@12pointdesign.com

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Driver Updates

If you’re using this hardware – these updates are for you.

BullZip PDF Printer 7.2.0.1338 adds support for both Microsoft.NET Framework 2.0 and 4.0, and several minor tweaks. This is not a security update.
http://www.bullzip.com/products/pdf/info.php#download

Internet Updates

One or more of these are likely to be of interest to everyone.

FileZilla 3.5.3 fixes several non-security bugs, and adds a keyboard shortcut for comparison options. This is not a security update.
http://filezilla-project.org/

Codec Updates

One or more of these are likely to be of interest to everyone.

Win7 Codec Package 3.3.8 updates included codecs. To install the update, you must uninstall and reinstall the application. This is not a security update.
http://shark007.net/win7codecs.html

Win x64 Codec Support 3.3.8 updates included codecs. This update applies only to 64-bit computers, and requires either the Win7 Codec Package or the Windows Vista Codec package. This is not a security update.
http://shark007.net/x64components.html

Media Updates

These are unlikely to be of interest to most people.

CDBurnerXP 4.4.0.2905 corrects several bugs and adds a command line option. This is a security update.
http://cdburnerxp.se/

Picasa 3.9.1.535 fixes various bugs. This should be treated as a security update. Use Help, Check for Updates, or download the updated installer from:
http://picasa.google.com/

Office Updates

One or more of these are likely to be of interest to most people.

Artweaver 3.0.2 fixes a couple minor bugs. This is not a security update.
http://www.artweaver.de/

Notepad++ 5.9.8 is a security update to the plugin loader and plugin manager. This is a security update.
http://notepad-plus-plus.org/

Utility Updates

These are unlikely to be of interest to most people.

RoboForm 7.6.9 fixes a Chrome integration bug. This is not a security update.
https://12pd.com/click?rfe

Goodsync 9.0.0.2 fixes a handful of non-security bugs. This is not a security update.
https://12pd.com/click?goodsync

Windows Image Writer 0.4 improves large drive support, and corrects a number of bugs. This is not a security update.
https://launchpad.net/win32-image-writer/

Intel SSD Toolbox 3.0.2 corrects several SMART, drive compression and hardware compatibility issues. This is not a security update.
http://www.intel.com/support/go/ssdtoolbox/index.htm

Web Package Updates

These are likely to be of interest only to web developers.

WordPress 3.3.1 is a security update to the 3.3 branch. If you’re using WP 3.3, you MUST update to this version. This version also includes more than a dozen other changes, including corrections to menu, encoding and multisite upload capacity determination. This is a security update. Use the WP updater, or download the current version here:
http://wordpress.org/

PHP 5.3.9 is a security update. This build corrects multiple issues including significant security issues. This is a security update.

BuddyPress 1.5.3.1 corrects several non-security bugs, including several server and theme compatibility changes. This is not a security update.
http://wordpress.org/extend/plugins/buddypress/

Dada Mail 4.9.1 adds Amazon SES support, and provides several templating bugfixes. This is not a security update.
http://dadamailproject.com/download/

Coppermine Gallery 1.5.18 is a security update. If you use Coppermine on your site, update immediately. This is a security update.
http://coppermine-gallery.net/

Email Log 0.5 corrects a deprecated function call. This is not a security update.
http://wordpress.org/extend/plugins/email-log/

Really Simple CAPTCHA 1.4 corrects a security bug in the recent 1.3 release (plain text answer file). This is a security update.
http://wordpress.org/extend/plugins/really-simple-captcha/

WPtouch 1.9.37 corrects several display issues and improves CSS for certain browsers. This is not a security update.
http://wordpress.org/extend/plugins/wptouch/

That’s all for now folks. Keep it clean out there.

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2011-11-08

Hi, Folks!

Patch Tuesday is here again, and is extremely light this month.

Microsoft released updates to Windows, Windows Mail, Outlook, MSRT, TCP/IP and LDAPS. This includes security updates. These updates weigh in at less than 10mb. A reboot is required.
http://update.microsoft.com/

Apple released updates for various printer drivers, Aperture, and iPhoto. Use the Apple Software Updater to obtain the most current versions. This includes security updates.

Adobe released stability updates to a variety of CS products, including InDesign, Premiere, InCopy and others. Select your installed product from the list here to find any specific updates:
http://www.adobe.com/downloads/

Be aware that on months with an ‘early’ Patch Tuesday, such as this one, several vendors, including Apple and Adobe, tend to release the bulk of their updates on the third Tuesday, not the second. Expect next week to include several security updates from these vendors.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need.

Driver Updates

If you’re using this hardware – these updates are for you.

iOS 5.0 is now generally available for supported iPhone, iPad, iPod and AppleTV products. iOS 5 adds over 200 new features including a notifications window, better application management, improved reminders, Twitter support, camera improvements, email formatting and other mail and calendar features, and various accessibility improvements. This includes security updates. Use iTunes to install this update – and be patient, it’s around 700mb.

Sn0wBreeze 2.8b10 enables jailbreaking iOS 5. This is not a security update.
http://iphoneroot.com/utilities/

ATI Catalyst 11.10 adds newer hardware support, better performance for various games and applications, and correcting several crash and display corruption bugs. This is not a security update.
http://sites.amd.com/us/game/downloads/Pages/radeon_win7-64.aspx

GMail Drive FS 1.0.18 improves support for Google Apps accounts, corrects a login issue and adds a Shell Command Bar. This is not a security update, but is required of all users of this driver in order to continue to operate correctly.
http://www.viksoe.dk/code/gmail.htm

Browser Updates

One or more of these are likely to be of interest to everyone.

Firefox 8.0 corrects several security and stability issues, disables add-ons by default, improves performance of HTML5 audio and video tags and context menus. This is a security update. Use Help, About to get the most current version.

Email Updates

One or more of these are likely to be of interest to everyone.

Thunderbird 8.0 corrects several security and stability issues, removes the folder switching pane widget, and disables add-ons by default. This is a security update. Use Help, About to get the most current version.

OutlookAttachView 1.95 adds ‘/extractall’ and the ability to scan only recent messages for attachments. This is not a security update.
http://www.nirsoft.net/utils/outlook_attachment.html

Internet Updates

One or more of these are likely to be of interest to everyone.

FileZilla 3.5.2 corrects several bugs related to password storage and the queue. This is not a security update.
http://filezilla-project.org/

uTorrent 3.0 Build 25824 corrects a stability issue for large files. This is not a security update.
http://www.utorrent.com/

Codec Updates

One or more of these are likely to be of interest to everyone.

Win7 Codec Package 3.2.4 updates included codecs, and fixes a significant settings bug. To install the update, you must uninstall and reinstall the application. This is not a security update.
http://shark007.net/win7codecs.html

Win x64 Codec Support 3.2.5 updates included codecs, and fixes a significant settings bug. This update applies only to 64-bit computers, and requires either the Win7 Codec Package or the Windows Vista Codec package. This is not a security update.
http://shark007.net/x64components.html

Media Updates

These are unlikely to be of interest to most people.

CDBurnerXP 4.3.9.2783 improves spanning behavior, adds drag and drop ability for DVD Video folders, improved startup time, and several 64-bit compatibility issues. This is not a security update.
http://cdburnerxp.se/

Winamp 5.622 corrects several security and stability bugs. This is a security update.
http://www.winamp.com/media-player/en

Office Updates

One or more of these are likely to be of interest to most people.

Notepad++ 5.9.6.1 corrects a crash bug and improvements to folder processing and project manager. This is not a security update.
http://notepad-plus-plus.org/

Security Software Updates

One or more of these is likely to be of interest to most people.

Wireshark 1.6.3 provides several dozen updates including various bugfixes, improved protocol support, and stability issues. This should be considered a security update.
http://www.wireshark.org/

MSRT 4.2 adds support for detection and removal of Duqu and improves scanning quality. This is a security update.
http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=585D2BDE-367F-495E-94E7-6349F4EFFC74

Capture Updates

These are unlikely to be of interest to most people.

VideoCacheView 2.02 fixes a caching performance issue. This is not a security update.
http://www.nirsoft.net/utils/video_cache_view.html

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 8.1.3.2 offers significant performance improvements, library updates, various minor bugfixes, stability and pathplayer fixes. This is not a security update.
http://www.dvdfab.com/download.htm

Utility Updates

These are unlikely to be of interest to most people.

Intel SSD Toolbox 3.0.1 improves hardware and OS support, adds drive health and life estimation display, and export support. This is not a security update.
http://www.intel.com/support/go/ssdtoolbox/index.htm

RoboForm 7.6.2 corrects a number of bugs in Firefox and Chrome, crash issues with corrupted site icons and display improvements. This should be considered a security update.
https://12pd.com/click?rfe

USBDeview 1.96 improves USB hub detection. This is not a security update.
http://www.nirsoft.net/utils/usb_devices_view.html

WakeMeOnLan 1.21 adds tray support and corrects a bug in netrange scanning. This is not a security update.
http://www.nirsoft.net/utils/wake_on_lan.html

Wireless Network Watcher 1.32 adds several new options to the tray context menu. This is not a security update.
http://www.nirsoft.net/utils/wireless_network_watcher.html

Virtual Machine Updates

These are unlikely to be of interest to most people.

VirtualBox 4.1.6-74713 corrects several crash, screen corruption, networking and stability bugs. This should be treated as a security update.
http://www.virtualbox.org/wiki/Downloads

Web Package Updates

These are likely to be of interest only to web developers.

DotNetNuke 06.01.00 corrects multiple security issues related to messaging and browser caching. This is a security update.
http://dotnetnuke.codeplex.com/

Contact Form 7 3.0.1 improves WP 3+ compatibility, file type options, and security improvements. This is a security update.
http://wordpress.org/extend/plugins/contact-form-7/

Zemanta 0.8.2 improves API key processing. This is not a security update.
http://wordpress.org/extend/plugins/zemanta/

Recurly 1.1.3 improves behavior of percentage discount coupons. This is not a security update.
http://js.recurly.com/

That’s all for now folks. Keep it clean out there.

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/