Thursday, December 24, 2009

Microsoft Office Patent Infringement Issue

A while back, Microsoft was sued by a Canadian software company for a patent infringement on some code in the Office products that has to do with Custom XML, which most of us would never see or use.  Microsoft lost the suit and appealed.  This week they lost the appeal and must issue new versions of Word and Office or stop selling it by January 11, 2010.

This has caused some concern from a few of our Clients.  However, it is nothing to worry about.  Microsoft has already corrected the issue and will have the corrected versions of Word 2007 and Office 2007 available by the January 11th date.  Office 2010, scheduled for release in June of 2010 does not contain the affected code.  Existing installations of Word and Office are not affected by the ruling.

Tuesday, December 15, 2009

Serious Adobe PDF Exploit

A serious exploit of Adobe PDF files has been discovered and malicious PDF files are being detected on the Internet since December 11th or so.

There is no patch for this issue at this time and anti-virus applications are not yet able to detect the malware due to how it is packaged. 

The problem appears to be in a JavaScript function inside of Adobe.  If you know how, you can disable JavaScript in Adobe Reader.  (Edit – Preferences – JavaScript – uncheck Enable Acrobat JavaScript).  Note that this may mean some PDFs do not display or act correctly, but it will mitigate the current issue.  Once a patch has been released you can turn it back on if you want.

Of course you should be careful downloading any type of file from the Internet.  However, be extra careful with PDFs at the moment.  Once a patch is released, we will post another article here.

Monday, November 23, 2009

Beware False Virus Warnings

Over the last few weeks, we are seeing a bunch of malware infected workstations, more than normal. What is happening  is the user is seeing a pop up when they are browsing on the Internet.  The pop up indicates that the machine is infected and offers to run a cleanup function.  The problem is that the pop up itself is malware.  If the user clicks anywhere in the window that is popped up the machine is compromised.  Even if they click the X to close the window.

This is being caused by websites that have been compromised.  The user goes to what should be a valid website and gets infected because some malicious code has been injected into the web pages on the site without the site owners knowing.  There have been reports that over 100,000 websites have been infected.

If the user sees a pop up that indicates that there workstation is or may be infected and the message is not a NOD32 (or whatever antivirus they are using) message, they should not click anywhere in the pop up or click the X to close the pop up window.  Their best bet is simply to close any other open applications (not the pop up) and shut down or restart the computer.  Once the computer restarts they should be OK.

Saturday, November 21, 2009

AllScripts v6.0 Available

AllScripts v6.0 has been released.  This is a required update that must be installed by 1/1/2010 to comply with new OASIS-C and Hospice requirements.

The update requires that all laptops do a sync before the update starts and then not be used until the servers and laptops have the update installed.

The update takes longer than normal to install.  It includes the OASIS-C Assessments but they will need to be imported and activated after the update.

Make sure you request the electronic update from AllScripts if your haven’t already.

Horizon 2009 Regulatory Update Re-Released

McKesson has re-released the 2009 Regulatory Update after having problems with the original update.  Updates for versions 10.2.2 an 11.1 are now available.

This is a major update that includes the OASIS-C v2.0 Assessments and Hospice changes that are required to be installed before Jan 1, 2010.  It also includes a few other minor updates.

This update will take longer than normal.  It requires that laptops do a transfer and remove all patients before being installed on the servers.  There are also scripts to be run after the update has been installed.

It is extremely important that agencies review the release documentation before installing this update.  I would also suggest that agencies notify McKesson when you have an anticipated installation date so they can be available should issues occur during the installation.

There is work to be done after the update has been installed so it should be scheduled as soon as possible.