<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Steve Dodson's WebLog</title><link>http://blogs.technet.com/b/stevedod/</link><description>...just a beta engineer supporting 25 million Windows Defender users...</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>From the End to Edge and Beyond Episode 24</title><link>http://blogs.technet.com/b/stevedod/archive/2013/01/25/from-the-end-to-edge-and-beyond-episode-24.aspx</link><pubDate>Fri, 25 Jan 2013 17:00:02 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3548404</guid><dc:creator>stevedod</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/stevedod/rsscomments.aspx?WeblogPostID=3548404</wfw:commentRss><comments>http://blogs.technet.com/b/stevedod/archive/2013/01/25/from-the-end-to-edge-and-beyond-episode-24.aspx#comments</comments><description>&lt;p&gt;Come on over and see me talk with Yuri about computer trends in security and how we are looking at solving customer problems.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://technet.microsoft.com/en-us/video/from-end-to-edge-and-beyond-episode-24.aspx"&gt;http://technet.microsoft.com/en-us/video/from-end-to-edge-and-beyond-episode-24.aspx&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3548404" width="1" height="1"&gt;</description></item><item><title>I'm back?</title><link>http://blogs.technet.com/b/stevedod/archive/2011/04/27/i-m-back.aspx</link><pubDate>Wed, 27 Apr 2011 21:45:47 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3424767</guid><dc:creator>stevedod</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/stevedod/rsscomments.aspx?WeblogPostID=3424767</wfw:commentRss><comments>http://blogs.technet.com/b/stevedod/archive/2011/04/27/i-m-back.aspx#comments</comments><description>&lt;p&gt;&lt;span style="font-family: trebuchet ms,geneva;"&gt;We all go out into the blogosphere with the intent to have tons of time to work, play, and write blogs. It appears that the last of these has been awfully neglected over the past few years (sorry). I think I'll have some things to talk about here and there, so I'll re-activate my blog - yay!&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: trebuchet ms,geneva;"&gt;I'll start out with a few things that have happened since my last postings.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: trebuchet ms,geneva;"&gt;1) I moved into a Security Premier Field Engineer role at Microsoft. This has allowed me to go onsite and meet face to face with customers around the world.&lt;br /&gt;2) I got my pilots license. Flying around the area is such a great thrill.&lt;br /&gt;3) I am developing a new tool which we use with large customers to determine security risk of operating systems across an enterprise.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: trebuchet ms,geneva;"&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;4) This&amp;nbsp;weekend, I'll be riding my bicycle in the MS-150&amp;nbsp;here in Dallas. It's a huge challenge for me, but allows some great fundraising for a great cause. I am sure to be&amp;nbsp;sore from the experience.&lt;/strong&gt; &amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: trebuchet ms,geneva;"&gt;Over the next few months, I'll have a lot to share on many of these work and non-work topics. I hope you find them beneficial and fun :)&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: trebuchet ms,geneva;"&gt;-steve&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3424767" width="1" height="1"&gt;</description></item><item><title>Microsoft Malware Removal Starter Kit</title><link>http://blogs.technet.com/b/stevedod/archive/2007/07/11/microsoft-malware-removal-starter-kit.aspx</link><pubDate>Wed, 11 Jul 2007 18:58:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1503387</guid><dc:creator>stevedod</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/stevedod/rsscomments.aspx?WeblogPostID=1503387</wfw:commentRss><comments>http://blogs.technet.com/b/stevedod/archive/2007/07/11/microsoft-malware-removal-starter-kit.aspx#comments</comments><description>&lt;P&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;Yesterday evening, the antimalware team shipped a new tool which should be helpful to small and medium sized orgs. This guide is designed for IT professionals (who may be wearing many hats) in&amp;nbsp;the&amp;nbsp;small business setting. The&amp;nbsp;kit provides recommendations and tools to assist in removing problematic&amp;nbsp;malware from your environment.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;You can&amp;nbsp;find this tool at the following URL:&lt;BR&gt;&amp;nbsp;&lt;A href="http://www.microsoft.com/technet/security/guidance/disasterrecovery/malware/default.mspx"&gt;http://www.microsoft.com/technet/security/guidance/disasterrecovery/malware/default.mspx&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;If you have suggestions about this tool, send us e-mail to &lt;A href="mailto:secwish@microsoft.com"&gt;secwish@microsoft.com&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;While you are at it, feel free to also visit the Malware Protection Center Portal at the following URL:&lt;BR&gt;&lt;A href="http://www.microsoft.com/security/portal"&gt;http://www.microsoft.com/security/portal&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;I hope to make more posts as new technology is released to help our customers get and stay secure.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;-steve&lt;/SPAN&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1503387" width="1" height="1"&gt;</description></item><item><title>Deploying Defender Definitions with WSUS</title><link>http://blogs.technet.com/b/stevedod/archive/2006/07/17/442146.aspx</link><pubDate>Mon, 17 Jul 2006 19:02:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:442146</guid><dc:creator>stevedod</dc:creator><slash:comments>4</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/stevedod/rsscomments.aspx?WeblogPostID=442146</wfw:commentRss><comments>http://blogs.technet.com/b/stevedod/archive/2006/07/17/442146.aspx#comments</comments><description>&lt;P&gt;One of the cool things about Windows Defender is that we still give system administrators the ability to deploy&amp;nbsp;definition updates by using WSUS. I have just written a KB article on setting up the WSUS server to download and deploy Defender definitions. &lt;/P&gt;
&lt;P&gt;You can find this KB at: &lt;A href="http://support.microsoft.com/kb/919772"&gt;http://support.microsoft.com/kb/919772&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;As always, please feel free to comment on the ways we can make Windows Defender better for you all!&lt;/P&gt;
&lt;P&gt;-steve&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=442146" width="1" height="1"&gt;</description></item><item><title>Microsoft Windows AntiSpyware is now……”Windows Defender”</title><link>http://blogs.technet.com/b/stevedod/archive/2005/11/04/413701.aspx</link><pubDate>Sat, 05 Nov 2005 00:32:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:413701</guid><dc:creator>stevedod</dc:creator><slash:comments>777</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/stevedod/rsscomments.aspx?WeblogPostID=413701</wfw:commentRss><comments>http://blogs.technet.com/b/stevedod/archive/2005/11/04/413701.aspx#comments</comments><description>&lt;FONT face=Verdana&gt;Over the last few months we have been working hard on creating the next version of the Microsoft anti-spyware technology. Today, we are announcing the new name for this technology… Microsoft Windows Defender. Does this mean a lot is changing?? Well... YES – and all for the better!! As part of our development process, we have been lurking in the newsgroups, listening and talking to customers to hear how we can make this release better. &lt;BR&gt;&amp;nbsp;&lt;BR&gt;It is going to be a part of VISTA!&lt;BR&gt;The biggest announcement we are making is that Windows Defender will be a part of Vista when it releases. You will be able to run another spyware product instead of Windows Defender if you would like. Although I may shed a small tear, you will be able to disable or turn off Windows Defender and install whichever 3rd party anti-spyware application you would like. The really cool thing is that the Windows Security Center in Vista will be redesigned to detect if an Anti-Spyware application such as Windows Defender is running and operating normally.&amp;nbsp; &lt;BR&gt;&amp;nbsp;&lt;BR&gt;New Signature Update Mechanism.&lt;BR&gt;That’s great and all, but what about some technical info about Windows Defender? Well I have something for you folks as well…Instead of writing our own update engine for this technology, we have teamed up with Windows Update to deliver signatures to you through Automatic Updates. This is an excellent way of us utilizing an existing Microsoft technology to deliver spyware signature updates to you –neat!&lt;BR&gt;&amp;nbsp;&lt;BR&gt;There are many more cool items coming soon which I will blog about later. In the meantime, look for more announcements here and on the antimalware team blog (&lt;/FONT&gt;&lt;a href="http://blogs.technet.com/antimalware"&gt;&lt;FONT face=Verdana&gt;http://blogs.technet.com/antimalware&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Verdana&gt;).&lt;BR&gt;&amp;nbsp;&lt;BR&gt;-steve&lt;/FONT&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=413701" width="1" height="1"&gt;</description></item><item><title>anti-malware engineering team blog released today</title><link>http://blogs.technet.com/b/stevedod/archive/2005/11/01/413473.aspx</link><pubDate>Tue, 01 Nov 2005 22:33:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:413473</guid><dc:creator>stevedod</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/stevedod/rsscomments.aspx?WeblogPostID=413473</wfw:commentRss><comments>http://blogs.technet.com/b/stevedod/archive/2005/11/01/413473.aspx#comments</comments><description>&lt;P&gt;&lt;FONT face=Verdana&gt;If you read my blog off and on (more off recently), you may be interested in the team blog located at the following location:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;a href="http://blogs.technet.com/antimalware"&gt;&lt;U&gt;&lt;FONT color=#0000ff&gt;&lt;FONT face=Verdana&gt;http://blogs.technet.com/antimalware&lt;/FONT&gt;&lt;/U&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Verdana color=#0000ff&gt; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color=#0000ff&gt;&lt;FONT face=Verdana color=#000000&gt;Jason Garms has posted the first intro to this blog &lt;a href="http://blogs.technet.com/antimalware/archive/2005/11/01/413466.aspx"&gt;http://blogs.technet.com/antimalware/archive/2005/11/01/413466.aspx&lt;/A&gt;, and these blogs will be a good place to check in with the developers and program managers of some of the security products here at Microsoft. &lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;-steve&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color=#0000ff size=2&gt;&lt;FONT color=#000000&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;&lt;/FONT&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=413473" width="1" height="1"&gt;</description></item><item><title>Microsoft Client Protection Announcement</title><link>http://blogs.technet.com/b/stevedod/archive/2005/10/06/412120.aspx</link><pubDate>Thu, 06 Oct 2005 18:14:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:412120</guid><dc:creator>stevedod</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/stevedod/rsscomments.aspx?WeblogPostID=412120</wfw:commentRss><comments>http://blogs.technet.com/b/stevedod/archive/2005/10/06/412120.aspx#comments</comments><description>&lt;P&gt;&lt;FONT face=Verdana&gt;Today we are announcing the new product line to help protect business systems against virus, spyware and rootkits. This new product line is called "Microsoft Client Protection." More information can be found at the following links:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;Q&amp;amp;A With Mike Nash &lt;BR&gt;&lt;/FONT&gt;&lt;A href="http://www.microsoft.com/presspass/features/2005/oct05/10-06ClientProtection.mspx"&gt;&lt;FONT face=Verdana&gt;http://www.microsoft.com/presspass/features/2005/oct05/10-06ClientProtection.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;Steve Balmer's Security Strategy&lt;BR&gt;&lt;/FONT&gt;&lt;A href="http://www.microsoft.com/presspass/press/2005/oct05/10-06SecuritySpeechPR.mspx"&gt;&lt;FONT face=Verdana&gt;http://www.microsoft.com/presspass/press/2005/oct05/10-06SecuritySpeechPR.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=412120" width="1" height="1"&gt;</description></item><item><title>AntiSpyware and OneCare Live</title><link>http://blogs.technet.com/b/stevedod/archive/2005/08/11/409019.aspx</link><pubDate>Thu, 11 Aug 2005 20:42:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:409019</guid><dc:creator>stevedod</dc:creator><slash:comments>43</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/stevedod/rsscomments.aspx?WeblogPostID=409019</wfw:commentRss><comments>http://blogs.technet.com/b/stevedod/archive/2005/08/11/409019.aspx#comments</comments><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT style="BACKGROUND-COLOR: #ffffff" face=Verdana&gt;Today when I came in to the office, I was made aware of an issue which stated that a Microsoft Representative was quoted as saying Windows AntiSpyware would no longer be available for free. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT style="BACKGROUND-COLOR: #ffffff" face=Verdana&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT style="BACKGROUND-COLOR: #ffffff" face=Verdana&gt;The statement quoted in many forums is not true. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT style="BACKGROUND-COLOR: #ffffff" face=Verdana&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT style="BACKGROUND-COLOR: #ffffff" face=Verdana&gt;As we have been saying since day one, Microsoft Windows AntiSpyware will be available at no charge to licensed users of Windows. Users who validate their Windows install through WGA will be allowed to download the AntiSpyware beta, as well as the full standalone version of AntiSpyware when it releases to the web. This has not changed since Bill Gates announced this information at the RSA conference in February. The enterprise version of Windows AntiSpyware is targeted to companies who want to centrally manage their Windows AntiSpyware infrastructure. The enterprise version of Windows AntiSpyware will be available for a cost (which has not been determined yet). &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;For users who want more services including AntiVirus, computer backup, and AntiSpyware we will be offering Windows OneCare live. Windows OneCare Live is currently in beta, but when it releases to the web it will be available to users with a cost. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT style="BACKGROUND-COLOR: #ffffff" face=Verdana&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT style="BACKGROUND-COLOR: #ffffff" face=Verdana&gt;There are many exciting security offerings coming from Microsoft over the next year and I am just glad they let me blog about these exciting things happening at Microsoft!&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=409019" width="1" height="1"&gt;</description></item><item><title>AntiSpyware (Beta) Build 615 Releasing This Evening</title><link>http://blogs.technet.com/b/stevedod/archive/2005/07/18/407849.aspx</link><pubDate>Tue, 19 Jul 2005 03:30:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:407849</guid><dc:creator>stevedod</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/stevedod/rsscomments.aspx?WeblogPostID=407849</wfw:commentRss><comments>http://blogs.technet.com/b/stevedod/archive/2005/07/18/407849.aspx#comments</comments><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;It has been a few weeks since the last update, and the A/S team needed some work to do so we decided that we should release build 615 to the web. Actually, we wanted to correct an issue found with the signature update mechanism and we wanted to get an updated build out there this week. Starting in the next hour or so, beta testers will be able to download the updated build from the web (&lt;A href="http://www.microsoft.com/spyware"&gt;http://www.microsoft.com/spyware&lt;/A&gt;) or wait for the automatic update to the software. Also addressed in this release is an improvement on how Windows AntiSpyware beta provides information to the user about processes running on a PC. Because of a limitation in the installer, users will have to reboot as soon as they update the package. We are working on reducing the reboot requirement for beta 2. We have been testing this new build for about a week now and it does resolve the signature update issue. Please post to the newsgroups if you see any issues or have any comments on this new build. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;-steve&amp;nbsp; &lt;BR&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=407849" width="1" height="1"&gt;</description></item><item><title>Claria Detection in AntiSpyware</title><link>http://blogs.technet.com/b/stevedod/archive/2005/07/11/407525.aspx</link><pubDate>Mon, 11 Jul 2005 18:34:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:407525</guid><dc:creator>stevedod</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/stevedod/rsscomments.aspx?WeblogPostID=407525</wfw:commentRss><comments>http://blogs.technet.com/b/stevedod/archive/2005/07/11/407525.aspx#comments</comments><description>&lt;DIV&gt;
&lt;DIV id=""&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;Claria has been receiving a lot of news lately, and so I figured I would re-post what is going on over here in regards to this. We put the following statement on our website as well (&lt;/FONT&gt;&lt;A href="http://www.microsoft.com/athome/security/spyware/software/claria_letter.mspx"&gt;&lt;FONT face=Verdana&gt;http://www.microsoft.com/athome/security/spyware/software/claria_letter.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Verdana&gt;):&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;"This week we received some questions around Microsoft's classification of Claria software in our Microsoft Windows AntiSpyware (Beta). We wanted to take this opportunity to clear up any misconceptions and explain our current policies and practices.&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;
&lt;DIV id=""&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;As you may know, the analysis of software is based on a single set of objective criteria, which can be found on our web site: &lt;/FONT&gt;&lt;A title=/athome/security/spyware/software/isv/analysis.mspx href="outbind://39-000000009BA7FCD2F4F6BA4F9B4D330BFE8E80CB0700DC8ADAFDD60EE446BCC4391F065CFDF80000058F00070000C7C4A42E1B9A2740B0BDF39D9BB22B4B00000859E7930000/athome/security/spyware/software/isv/analysis.mspx"&gt;&lt;FONT face=Verdana&gt;Windows AntiSpyware (Beta): Analysis approach and categories&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Verdana&gt;.&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;
&lt;DIV id=""&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;Microsoft offers all software companies the opportunity to request a review of how Microsoft classifies their products through our vendor dispute process. In January, Claria filed a request for Microsoft to reevaluate some of its products. Upon review of their software against our criteria, we determined that continued detection of Claria's products was indeed appropriate. We also decided that adjustments should be made to the classification of Claria software in order to be fair and consistent with how Windows AntiSpyware (Beta) handles similar software from other vendors. At the end of March, we communicated to Claria the result of our analysis through our standard process.&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;
&lt;DIV id=""&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;We take software analysis for Windows AntiSpyware (Beta) very seriously and handle all vendor requests in the same manner. All software is reviewed under the same objective criteria, detection policies, and analysis process. Absolutely no exceptions were made for Claria. Windows AntiSpyware (Beta) continues to notify our users when Claria software is found on a computer, and it offers our users the option to remove the software if they desire.&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;
&lt;DIV id=""&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;Microsoft is committed to helping protect our customers from spyware and other unwanted software by providing guidance and technology solutions. We firmly believe that people should have complete control over what runs on their computers.&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;
&lt;DIV id=""&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;Today, anti-spyware vendors use different approaches, definitions, and types of criteria for identifying and categorizing spyware and other potentially unwanted software. This has limited the industry’s ability to have a broad, coordinated impact in addressing the problem. That is a key reason Microsoft is a founding member of the Anti-Spyware Coalition, a group of technology companies and anti-spyware companies working alongside public interest groups to address key spyware issues.&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;
&lt;DIV id=""&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;Meanwhile, Microsoft Windows AntiSpyware (Beta) is an initial beta release and we continue to receive valuable feedback from customers, which is helping our development of the final version of Windows AntiSpyware. We encourage people to provide feedback at &lt;/FONT&gt;&lt;A title=mailto:WASFeed@microsoft.com href="mailto:WASFeed@microsoft.com"&gt;&lt;FONT face=Verdana&gt;WASFeed@microsoft.com&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Verdana&gt; and stay up-to-date on the latest developments on Windows AntiSpyware at &lt;/FONT&gt;&lt;A title=/athome/security/spyware/software/default.mspx href="outbind://39-000000009BA7FCD2F4F6BA4F9B4D330BFE8E80CB0700DC8ADAFDD60EE446BCC4391F065CFDF80000058F00070000C7C4A42E1B9A2740B0BDF39D9BB22B4B00000859E7930000/athome/security/spyware/software/default.mspx"&gt;&lt;FONT face=Verdana&gt;Microsoft Windows AntiSpyware (Beta) Home&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Verdana&gt;."&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;Please do give us feedback in the newsgroup or&amp;nbsp;in the e-mail alias as we are making decisions for future builds based on this feedback.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;-steve&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=407525" width="1" height="1"&gt;</description></item><item><title>AntiSpyware (beta) Build 613 Released Today</title><link>http://blogs.technet.com/b/stevedod/archive/2005/06/23/406767.aspx</link><pubDate>Thu, 23 Jun 2005 18:55:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:406767</guid><dc:creator>stevedod</dc:creator><slash:comments>50</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/stevedod/rsscomments.aspx?WeblogPostID=406767</wfw:commentRss><comments>http://blogs.technet.com/b/stevedod/archive/2005/06/23/406767.aspx#comments</comments><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana&gt;Just a few minutes ago, we released the latest build of Windows Antispyware to the public. This build will resolve issues which will make using this product better for users. Starting today, users will start to see the automatic update mechanism fire off and advise users know&amp;nbsp;they have a new update available. Some of the big improvements are:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT face=Verdana&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;FONT face=Verdana&gt;&lt;SPAN style="mso-list: Ignore"&gt;1)&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Software expiration will be extended to December 31, 2005. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;FONT face=Verdana&gt;&lt;SPAN style="mso-list: Ignore"&gt;2)&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Alerts Moving Quickly Across the Screen : Messages which move quickly off the screen when the start bar is not docked horizontally are also fixed. Users who dock their start bar on the sides of their screen will now be able to read messages generated from Microsoft Windows AntiSpyware (beta). &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;FONT face=Verdana&gt;This issue is what we dubbed the “Flying Toast Issue” and one which I was passionate about getting fixed in this refresh build. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;FONT face=Verdana&gt;&lt;SPAN style="mso-list: Ignore"&gt;3)&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Support for Long Descriptions:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Users of older builds only have access to the short descriptions which ship as part of the signatures. These short descriptions only provide limited information about potentially unwanted software. Long descriptions in build 613 will help users by giving them more information about the potentially unwanted software detected on their PCs. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;FONT face=Verdana&gt;&lt;SPAN style="mso-list: Ignore"&gt;4)&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Improved Winsock LSP removal mechanism:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In some cases, removing spyware LSPs, or can disrupt network functionality. Through enhancements made in this beta refresh, we’ve lessened the chance that this problem will occur. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Verdana&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana&gt;This is a very exciting release, and one which will greatly improve the user experience on this excellent product.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana&gt;-steve&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=406767" width="1" height="1"&gt;</description></item><item><title>Command Line Options for Microsoft AntiSpyware (beta 1)</title><link>http://blogs.technet.com/b/stevedod/archive/2005/04/21/404046.aspx</link><pubDate>Thu, 21 Apr 2005 21:37:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:404046</guid><dc:creator>stevedod</dc:creator><slash:comments>161</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/stevedod/rsscomments.aspx?WeblogPostID=404046</wfw:commentRss><comments>http://blogs.technet.com/b/stevedod/archive/2005/04/21/404046.aspx#comments</comments><description>&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;It has been a busy few months on the Anti-Spyware team, and I have learned a lot about the product while supporting millions of users in a newsgroup format. Here is a cool feature I ran into the other day…executing antispyware with switches through the command line!&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;To do this, open up a command prompt and change to the c:\program files\microsoft antispyware directory. Then use the switches below:&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;GIANTAntiSpywareMain.exe [-parameters] [-parameters]&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT color=#000080&gt;-update : start an update check&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT color=#000080&gt;-scan : scan [-optional scan parameters]&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;FONT color=#000080&gt;Optional scan parameters:&amp;nbsp;&amp;nbsp; [-withMainUI]&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [-schedule] &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [-withUI]&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [-withResultUI]&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;Here is an example: “&lt;FONT color=#000080&gt;&lt;STRONG&gt;GIANTAntiSpywareMain.exe -scan –withui -withresultsui -schedule&lt;/STRONG&gt;&lt;/FONT&gt; ”&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;o:p&gt;Feel free to play with the switches and let me know if it is beneficial to be able to do this.&lt;BR&gt;&lt;/P&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=404046" width="1" height="1"&gt;</description></item><item><title>"Tracking" Cookies in Anti-Spyware Applications</title><link>http://blogs.technet.com/b/stevedod/archive/2005/02/23/378972.aspx</link><pubDate>Wed, 23 Feb 2005 20:07:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:378972</guid><dc:creator>stevedod</dc:creator><slash:comments>4</slash:comments><description>&lt;p&gt;&lt;font face="Verdana"&gt;As a user of many anti-spyware applications over the years, one item has always bothered me when removed by antispyware applications. That item is "tracking" cookies.&amp;nbsp;Many people in the industry know what cookies are, and how they can be used, but I do not think my parents would know anything about cookies. In my opinion, the industry has created a scare tactic in order to make a "problem" seem worse than it really is. I see this a lot when people are reporting that one program is better than another in respect to cookies. I really do not see how someone can make that argument. I can write a program which deletes n+1 files if I want until I reach a point where there are no more files to delete. &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font face="Verdana"&gt;So why is this a problem?? Users do not know what files are good or bad, and therefore rely on the application to determine this for them. But if I am the programmer for another application, I could delete all good and bad files and then say... " We delete more files than Product X." The end user then says... "Of course..I want the other product...more is better!!" These users will then end up losing some settings which were never malicious in the first place. This leads me to the last thought...&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font face="Verdana"&gt;Cookies by themselves are not malicious; they are text files with settings. Cookies can be a part of some application which calls on the text file in order to send information to a 3rd party, but end the end, they are only text files. In order for "tracking" cookies to be of use, a &lt;span style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;corresponding &lt;/span&gt;application needs to be running in the background and grab information off this file. I think this is where anti-spyware applications need to be focusing their efforts&amp;nbsp;- removal of the application which uses these text files instead of blowing away all good and bad cookies.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font face="Verdana"&gt;I think the cookie argument will go on for a while, but as long as the end user cannot discern what is good versus what is bad, the industry needs to work on improving the logic of removing applications as opposed to deleting all cookies.&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=378972" width="1" height="1"&gt;</description></item></channel></rss>