PC Review


Reply
Thread Tools Rate Thread

Add-ons I don't expect

 
 
David Walker
Guest
Posts: n/a
 
      21st Mar 2006
While looking at some friends' computers (trying to make sure they have
no malware) I have seen add-ons, in the Manage Add-Ons dialog, like
this:

HTML Document, Microsoft corporation, Enabled, ActiveX Control,
mshtml.dll
DHTML Edit Control Safe for Scripting, Microsoft Corporation, Enabled,
ActiveX Control, dhtmled.ocx

These seem strange because I don't think HTML is rendered by an ADD-ON
in IE -- it's part of the base functionality.

***I don't have this "HTML Document" ActiveX control add-on in my
system, and I can browse things just fine. *** This is what baffles me.
We both have Windows XP Pro SP2 with the most recent IE6 and all
security updates.

Even though it's a big improvement to have this Manage Add-Ons screen,
it's not clear whether some of these entries are supposed to be here.
I'm sure that mshtml.dll can function without being an ADD-ON to IE.

Can anyone clue me in on these things?

There is another strange one:

Microsoft Licensed Class Manager, Microsoft corporation, Enabled,
ActiveX Control, licmgr10,dll

Second question: When the Manage Add-Ons dialog box says "Microsoft" is
the publisher of an add-on, can we depend on that? Has the publisher
been verified with a certificate, or can any piece of software spoof the
Publisher name in that column of this dialog box?

Thanks.

David Walker
 
Reply With Quote
 
 
 
 
Rob Parsons
Guest
Posts: n/a
 
      22nd Mar 2006
Hi David,

There are documented exploits for these 2 activex controls (search for
mshtml exploit) and I remember a security patch that flagged the kill byte
in the ActiveX Compatibility settings for mshtml to stop scripted popups.

So the first place to start with your friends puter is to ensure they have
all the latest patches. From your description it sounds like they are listed
in the 'Add-ins that have been used by Internet Explorer', so it appears
that they were loaded and used when your friend visited a malicious web page
so there are no components hanging around on the hard disk that you need to
uninstall.

You can download a free utility to check the ActiveX Compatibility values
from http://www.nirsoft.net/utils/acm.html

On my machines the mshtml.dll is flagged as disabled and the dhtml edit
control is enabled.

You may also like to check your friends Security Settings for the Internet
Zone. There is a new option for XP versions to 'Allow scripting of the Web
Browser control' - the default is disabled.


Regards.
"David Walker" <(E-Mail Removed)> wrote in message
news:Xns978D7E83881B9DWalker@207.46.248.16...
> While looking at some friends' computers (trying to make sure they have
> no malware) I have seen add-ons, in the Manage Add-Ons dialog, like
> this:
>
> HTML Document, Microsoft corporation, Enabled, ActiveX Control,
> mshtml.dll
> DHTML Edit Control Safe for Scripting, Microsoft Corporation, Enabled,
> ActiveX Control, dhtmled.ocx
>
> These seem strange because I don't think HTML is rendered by an ADD-ON
> in IE -- it's part of the base functionality.
>
> ***I don't have this "HTML Document" ActiveX control add-on in my
> system, and I can browse things just fine. *** This is what baffles me.
> We both have Windows XP Pro SP2 with the most recent IE6 and all
> security updates.
>
> Even though it's a big improvement to have this Manage Add-Ons screen,
> it's not clear whether some of these entries are supposed to be here.
> I'm sure that mshtml.dll can function without being an ADD-ON to IE.
>
> Can anyone clue me in on these things?
>
> There is another strange one:
>
> Microsoft Licensed Class Manager, Microsoft corporation, Enabled,
> ActiveX Control, licmgr10,dll
>
> Second question: When the Manage Add-Ons dialog box says "Microsoft" is
> the publisher of an add-on, can we depend on that? Has the publisher
> been verified with a certificate, or can any piece of software spoof the
> Publisher name in that column of this dialog box?
>
> Thanks.
>
> David Walker



 
Reply With Quote
 
David Walker
Guest
Posts: n/a
 
      23rd Mar 2006
"Rob Parsons" <(E-Mail Removed)> wrote in
news:#16#(E-Mail Removed):

> Hi David,
>
> There are documented exploits for these 2 activex controls (search for
> mshtml exploit) and I remember a security patch that flagged the kill
> byte in the ActiveX Compatibility settings for mshtml to stop scripted
> popups.
>
> So the first place to start with your friends puter is to ensure they
> have all the latest patches. From your description it sounds like they
> are listed in the 'Add-ins that have been used by Internet Explorer',
> so it appears that they were loaded and used when your friend visited
> a malicious web page so there are no components hanging around on the
> hard disk that you need to uninstall.
>
> You can download a free utility to check the ActiveX Compatibility
> values from http://www.nirsoft.net/utils/acm.html
>
> On my machines the mshtml.dll is flagged as disabled and the dhtml
> edit control is enabled.
>
> You may also like to check your friends Security Settings for the
> Internet Zone. There is a new option for XP versions to 'Allow
> scripting of the Web Browser control' - the default is disabled.
>
>
> Regards.


Thanks, I appreciate the info. I'll look at that page.

But what do these ActiveX controls actually do? Surely you don't need
an activeX control to render HTML.

David
 
Reply With Quote
 
David Walker
Guest
Posts: n/a
 
      23rd Mar 2006
"Rob Parsons" <(E-Mail Removed)> wrote in
news:#16#(E-Mail Removed):

> Hi David,
>
> There are documented exploits for these 2 activex controls (search for
> mshtml exploit) and I remember a security patch that flagged the kill
> byte in the ActiveX Compatibility settings for mshtml to stop scripted
> popups.
>
> So the first place to start with your friends puter is to ensure they
> have all the latest patches. From your description it sounds like they
> are listed in the 'Add-ins that have been used by Internet Explorer',
> so it appears that they were loaded and used when your friend visited
> a malicious web page so there are no components hanging around on the
> hard disk that you need to uninstall.
>
> You can download a free utility to check the ActiveX Compatibility
> values from http://www.nirsoft.net/utils/acm.html
>
> On my machines the mshtml.dll is flagged as disabled and the dhtml
> edit control is enabled.
>
> You may also like to check your friends Security Settings for the
> Internet Zone. There is a new option for XP versions to 'Allow
> scripting of the Web Browser control' - the default is disabled.
>
>
> Regards.


In other words, why do YOU need the DHTML edit control to browse Web
pages and I don't? That's the confusing part. On my system, the DHTML
edit control doesn't appear in that list, either enabled or disabled.

David


 
Reply With Quote
 
Jon Kennedy
Guest
Posts: n/a
 
      24th Mar 2006
The DHTML Edit Control:
http://msdn.microsoft.com/archive/en...rl/default.asp
Basically allows you to edit text, enter info, and do lots of other things
on web pages that use DHTML

The Microsoft Licensed Class Manager is an ActiveX control that is part of
Microsoft's Windows Genuine Advantage program.

From: http://www.microsoft.com/genuine/dow...displaylang=en
Q: What is an ActiveX control, and how is it used in the validation process?

A: An ActiveX control is a small, executable code package that users of
Internet Explorer can download and run on their PCs. The Windows Genuine
Advantage validation process uses the ActiveX control to check the
authenticity of your Windows software. If the ActiveX control successfully
validates your Windows software, it stores a special download key on your PC
for future use.


--

Jon R. Kennedy
Charlotte, NC, USA
(E-Mail Removed)

"David Walker" <(E-Mail Removed)> wrote in message
news:Xns978D7E83881B9DWalker@207.46.248.16...
> While looking at some friends' computers (trying to make sure they have
> no malware) I have seen add-ons, in the Manage Add-Ons dialog, like
> this:
>
> HTML Document, Microsoft corporation, Enabled, ActiveX Control,
> mshtml.dll
> DHTML Edit Control Safe for Scripting, Microsoft Corporation, Enabled,
> ActiveX Control, dhtmled.ocx
>
> These seem strange because I don't think HTML is rendered by an ADD-ON
> in IE -- it's part of the base functionality.
>
> ***I don't have this "HTML Document" ActiveX control add-on in my
> system, and I can browse things just fine. *** This is what baffles me.
> We both have Windows XP Pro SP2 with the most recent IE6 and all
> security updates.
>
> Even though it's a big improvement to have this Manage Add-Ons screen,
> it's not clear whether some of these entries are supposed to be here.
> I'm sure that mshtml.dll can function without being an ADD-ON to IE.
>
> Can anyone clue me in on these things?
>
> There is another strange one:
>
> Microsoft Licensed Class Manager, Microsoft corporation, Enabled,
> ActiveX Control, licmgr10,dll
>
> Second question: When the Manage Add-Ons dialog box says "Microsoft" is
> the publisher of an add-on, can we depend on that? Has the publisher
> been verified with a certificate, or can any piece of software spoof the
> Publisher name in that column of this dialog box?
>
> Thanks.
>
> David Walker


 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
what should i expect? davisr65 Microsoft Outlook Installation 0 8th Apr 2008 07:08 PM
When can I expect SP3 for XPE? Jason Windows XP Embedded 1 11th Jan 2006 11:27 AM
Don't get EOF when I expect it! =?Utf-8?B?RGF2aWQgQW5kZXJzb24=?= Microsoft Access Form Coding 5 29th Jun 2005 11:31 PM
What can i expect? Veritech ATI Video Cards 1 4th Jan 2005 07:30 PM
What should I expect? Jim Scott Windows XP General 16 14th May 2004 04:22 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 12:55 AM.