Saturday, November 18, 2006

27 steps to prevent computer virus/Trojans.


picture courtesy-- London Times.
Read on to be aware of the 27 steps that will help you prevent your PC from getting infected with those deadly viruses. Some of these steps are common but many of them are not so common. So read carefully and stay protected.

1.Always be careful when it comes to e-mails that have attachments. If files contain EXE, COM or VBS as extensions then they are most likely able to cause harm to computers. Do not open it.

2.Do not open attachments when they are from people you do know, if the mail does not clearly refer to them. If they have a virus, then it can send mails to you. Therefore, only open attachments of which it makes sense to refer to.

3.Do not open video files from sources you are not sure. The new way of sending viruses is by using video files. It has already started so watch out for it. It was only recently that Anti-virus firm McAfee warned Windows users that the company had discovered a worm, dubbed W32/Realor, actively infecting Real Media files. The infected video files do not contain an exploit for the RealOne or Real players, but a hyperlink that points to a malicious website. It could be just the beginning to a new way of virus distribution.

4.While talking over the messenger use the file transfer option only if it is necessary and if you know the person at the other end well enough. Even if the person is known to you his computer might be infected with a virus. So make sure he too has an update anti-virus on his PC.

5.If a friend sends a file over the messenger do not open it unless it is the file you and your friend is sure is not infected.

6.Never dowload files send by unknown people.

7.Always have an up to date version of your messenger.

8.Be careful when trading any kind of files through your messenger or by any other means.

9.Always scan files on floppy disk or zip disk before using it. As you know an infected file from a disk that you have borrowed or which have been used on some another computer which has been infected can infect a clean PC.

10.Often attachments sent from a Mac will have not have any extensions. So in that case it is not possible to tell the type of the file. So as a precaution do not open attachments that has no extensions at all.

11.Always check the file extensions of any file arriving from a source.To see the file extensions Open Windows Explorer or My Computer. On the menu, choose View > Options to open the Options dialog box. If there is a View tab, click it. If there is not View tab, click the File Types tab. Then uncheck (by clicking its checkbox) "Hide file extensions for known file types." Click OK to close the dialog box. Usually by default windows does not show extensions. But once you checked the file extensions go back and hide the file extensions.

12.Even a picture file can be infected with a virus or Trojan. In 2004 a picture posted on the Usenet was infected with a trojan. It exploited the Internet Explorer. All the Antivirus programmes are capable of dealing with it now. But you never know what is in the making. Since it has been proved that it is possible it is good to be on the safer side. Any picture that floats in email or any unfamiliar sites which entices you to view it should be dealt with caution. Even though now a days a picture spreading a virus is only a remote possibility, the very reason that it is possible is a scary thing.

13.Word documents (.doc), Excel documents, and other files can contain macros that functions as viruses. But now a days all AntiVirus checks for these. But still excercise caution when it comes to unkown sources. A well known macro virus was the melissa virus and the cybernet virus.

14.Sometimes the virus warnings themselves are a farce. So think again before you start spreading the word or press the panic button at your end. Many reports of viruses are hoaxes. Many of these arrive through emails and instant messages. So if you have a doubt and before dealing with those kind of viruses double check it. The sites listed below are the ones you can use to verify a hoax message before you make sure they are for real. If you don't find them there google it.

F-secure's virus hoax related page.
Symantec's related page.
Mcafee's related page.

15.If you download a file from popular sites like Rapidshare before downloading look at the link and if you see the extensions like .exe, .scr, .bat etc:- be warned. SOmeone might load a file at Rapidshare or similar popular sites and spread the word luring you to download it. Or even after you download the zip or rar files look for the extension of the file it contains and scan it. If the extension sound fishy never touch it. For example a movie file with a .exe extension.

16.The file types that are the most dangerous are the files with the .exe, .com, .scr, .vbs, .cmd, .bat and .reg extensions because they contain programs and not documents. Take note of that and keep it in the back of your mind before opening it.

17.Do not visit websites that are unfamiliar. If you want to visit them turn off all your javascript options and Active X and cookies too. Many of the malicious websites asks the user to turn on the Java script or Active X. If a site is not a familiar one and has enticing words to invite you to the site and needs you to turn on the Java script and/or Active X then be careful. Some malicious sites can even infect you with a virus even if your java script and Active x is turned off. That is why you always need to have a up to date Anti-virus.

18.Don't visit warez sites especially key generators. A very small KB file that comes as a key generator once clicked can easily open up a can of worms or viruses.

19.There is always a danger of freely sharing computer programs and system disks, or downloading files and software through file-sharing applications such as BitTorrent, KaZaA etc:-

20.Excercise proper caution when using your personal disk space (e.g., floppy disks) on public computers or other computers that are used by more than one person.

21.Always running your Windows computer as an administrator or power user is not advised. A programme downloaded and executed when you have the administrator priveleges can even go to the root.

22.One of the ways to ensure that you don't get a rootkit virus is by accepting only digitally signed drivers.

23.Even AntiVirus softwares can have vulnerabilities. So always check for the latest news about the Antivirus software you are using. Very recently (nov.16 06) one of the top Antivirus progs, Panda, was found to be having highly critical vulnerabilities by the security firm Secunia. See the report here.

24.Remember Trojan.Bakloma.A. virus that came out in August 2006? If not let me refresh your memory. A link in the email claiming to be from Norton(Symantec) asked the users to download a removal tool for a new virus by following the link. Immediately as the user went to the site that was linked the virus Trojan.Bakloma.A. was automatically downloaded. So watch out for emails or suspicious links anywhere that asks you to update your Antivirus by following the link. All good Antivirus progs allows you to update through the software installed on your pc.

25.Use a firewall,Anti Spyware, Anti-Trojan, Anti-Virus and Anti Rootkits and update it everyday if possible.

26.Regulary update security patches from your browser and Operating system vendor.

27.Check for the latest virus threats by visiting the top ranked AntiVirus providers and security firms. Some of the sites you can visit are:-

Secunia the security firm.
Mcafee's threat center.
Bitdefender's info center.


Related Reading:-
What are Rootkit viruses and free RootKit detecting softwares.
Best Free Antivirus Softwares

Wednesday, November 15, 2006

What are Rootkits and free RootKit detecting softwares.

RootKits
For anyone who is familiar with computer terminologies knows what it means to have the priveleges of the user at the root level. It simply means that that user has the administrative powers. So if a programme has the same priveleges it means that it can bury itself into the operating system's Application Program Interface (API). It will this have the power to be the middle man between the operating system and the programs that rely on it, deciding what those programs can see and do. Sitting in that position it can mask itself from any normal anti-virus programmes. If an application tries to get the contents of a directory which holds one of the rootkit's files it has the ability to censor the file name from the list. It even has the power to hide anything the person that has put the root kit in the PC wants hidden like password lists, mp3 files etc:-

All sorts of other tools useful for abuse can be hidden using rootkits. This includes tools for further attacks against computer systems the compromised system communicates with such as sniffers and keyloggers.

Usually after putting the root kit on the PC the attacker has to connect to the system through an open port on the PC just like using any other back door programmes. But the difference here is that like I mentioned earlier root kits are not easily detected by normal AntiVirus tools.

Rootkits are typically not malicious by themselves but are used for malicious purposes by viruses, worms, backdoors and spyware. A virus combined with a rootkit produces what was known as full stealth viruses in the MS-DOS environment.

One of the scariest thing is that once your computer is compromised by the hacker (a computer attached to the Internet that has been compromised by a security cracker, a computer virus, or a trojan horse is called a Zombie computer)it can be used for further attack by the hacker and it will appear that it orginated from the compromised computer instead of the hacker's machine.

One of the ways to make sure you don't contribute to the installing of a root kit in your PC is by accepting only digitally-signed device drivers.

F-Secure's Blacklight.
F-secure the Finland based Internet security services firm offers a free and very effective tool which can even be used by beginners to eliminate the Rootkits. It comes in a very small size (808 kb) and is called Blacklight. It has two versions.

One is the GUI(graphical user interface) version and the other one is the command line version. The GUI version is very easy to use even for beginners. The scan takes around 5 minutes. The software is a beta version and is free to use till Jan 2007.

Currently it is the only Rootkit detector with a combination of GUI and expert detection which makes it easy to use for beginners. All other Rootkit detectors like Rootkit Revealer and Gmer are for advanced users.

If the Rootkit detector detects the hidden rootkit files or the files that have been hidden by rootkit then the scan will show the list. To remove the files first you need to rename the malware files by hitting the "rename" button. You can untag the non malware files by using the "untag" button before hitting the "clean" button.

It is important to note that rootkits can hide legitimate processes and files. So when selecting the files you would like to rename one should make sure you are only renaming the spyware/malware files. If you rename the wrong files it will cause problems to the state of your machine.

Once you hit the "clean" button the files that you renamed will be made inactive by the scanner and will appear with a .ren extension after re-starting the PC. And you will get a notepad that shows the list. Look at the list and delete the .ren files from your PC.

You can download both the Blacklight(F-secure) GUI version and command line version here.

The command line version can be used by people who are comfortable with command lines and it also has an expert mode. The default mode is the normal mode. For the command line version help you can visit the F-secure related page.

Two other tools.
If you want to use more than one Rootkit detector and is an advanced user you can try Rootkit Revealer and Gmer. Both are free softwares.

Related reading:-
Best Free AntiVirus softwares.
27 steps to prevent Virus/Trojans.
Anti-Rootkit for Windows Vista.

Tuesday, November 14, 2006

Best Free Antivirus Softwares

Ok there are a lot of anti-virus progs out there. But as always with whatever we do when we set out to buy something or in this case to give them the freedom to sit on our PC and place our faith in them, let us filter the bad out there and narrow down on the best choices among the free Antivirus softwares.


AVG ver 7.5.4
This latest version of AVG is a great free AntiVirus tool. Rapid virus database updates are available for the lifetime of the product. Version 7.5.4 includes improved virus detection based on better heuristics and NTFS data streams scanning; a smaller installation and update files; and an improved user interface. The newest version is also compatible with Windows Vista.

It is easy to install and use and has real-time antivirus protection of files and e-mails, maximum security - recent certifications include VB100%, ICSA, and WestCoast Labs Checkmark. And as usual it offers regular and automatic database and program updates
It supports both Windows and Linux.
Get it from CNET Download.com!

Avira AntiVir PersonalEdition Classic 7 6.36.01.01

This latest version features enhanced protection against unknown boot-sector viruses, issuing alerts for boot sectors suspicious formats. Through the permanent update of the detection engine, the protection is ensured constantly: the user can set the product to download any updates when available, thus keeping you clean and safe.

Avira PersonalEdition Classic constantly and rapidly scans your computer for malicious programs (such as viruses, Trojans, backdoor programs, hoaxes, worms, dialers etc.), monitoring every action executed by the user or by the operating system and being able to react promptly when a malicious program is detected.




Avast! Home Edition 4.7.892

This latest version is a free complete ICSA certified antivirus software for home noncommercial use. Avast includes the following components: On Demand Scanner--with skinnable simple interface--just select what do you want to scan in which way and press the Play button; On Access Scanner--special providers to protect the most of available e-mail clients; Instant Messaging--ICQ, Miranda; Network traffic--intrusion detection--lightweight firewall; P2P protection for Kazaa, BitTorrent; Web shield--monitors and filter all HTTP traffic; NNTP Scanner--scans all Usenet Newsgroup traffic and all operations with files on PC.


Get it from CNET Download.com!

  • Free online scanning by all the top ranked AntiVirus software makers:-
One thing everyone should keep in their mind is that all t he free softwares are good but not as good as the paid softwares. And the good thing is that all the paid softwares offer free online scanning and one would want to take advantage of that.

BitDefender--Free online scanning ..go here.
Mcafee--Free online scanning..go here.
Kaspersky--Free online scanning..go here.
F-secure--Free online scanning..go here.
Symantec(Norton)--Free online scanning go here.

Keep in mind that all these online scanners use Java script and Active X and hence you need to have Internet Explorer ver.5.0 (ver 4.0 in the case of BitDefender) or higher to take advantage of these free online scanners.

Like any other security software whether it is an AntiVirus or Anti-Spyware it is always good to use a combination of at least two. But using two Anti-virus software at the same time or two firewalls at the same time can lead to a clash and sometimes even a PC crash. So when it comes to Anti-virus it is always good to have one good software installed on your PC and use the free online scanning offered by another.

Note:- It is very true that no free Anti-virus comes close to the top paid Anti-virus such as Bit defender, Mcafee and kaspersky when it comes to performance. If you want real protection you have shell out that 40 or 30 dollar. With an avg of more than 10 new virus breaking out each day it is always nice to be on the safer side. But it is better to have some protection rather than having no protection at all. A good Anti-virus, firewall, Anti-Trojan and Anti-spyware/malware are the four essential softwares everyone should have on their PC for protection. Constantly upgrade each of these and all the OS and browser patches supplied by the vendors.

Special Mention:- Among paid Anti-virus softwares that NOD 32 Anti-virus is making waves now a days with it's light weight features that goes very low on CPU usage. Available on many platforms, including DOS, Linux, and NetWare, NOD32 has great speed and very excellent virus protection.

The Control Center layout and modules are a little bit confusing. The terminology is very technical. It is best for experts who would love the customization abilities and scanning power. But not an ideal choice for beginners.

Among the many feature it has is one called Dmon which scans every document before you open it in the background to prevent from script attacks and you won't even realise it. That is just one of the features available. You can get a good review of the software at softpedia.com.

Or visit the Nod32 website.

Related reading:-
27 steps to prevent Virus/Trojans.

What are rootkit viruses and steps to prevent them.

Saturday, November 11, 2006

Two free tools to organize your audio files.

This article (only this article) has been moved to techbreak.net

Three free utilties to keep you safe on the net.

Scan your computer online for viruses with this F-secure free scan.

As you know F-Secure is a highly reputed internet security provider based in Finland. It is always good to scan your pc with more than one anti-virus since one might detect a virus the other can't. But as you know having two anti-virus suite installed on your Pc might lead to a clash. So instead you can always have one installed on your Pc and utilise the online scan provided by another. So take advantage of this free scan folks.

But before you go to the site keep in mind it supports the following Operating systems:-

* Windows 2000
* Windows XP

And supports the following web browsers:

* Microsoft Internet Explorer 6.0 or higher.
* JavaScript needs to be enabled.
* You need to have ActiveX enabled.

F-secure online scan.


Netcraft tool bar.

If you guys remember, it was a netcraft tool bar user that spotted the fake myspace page that was used for phishing and reported it. Netcraft has been around since a long time and they are the people who keeps tab of all the phishing sites and the new Opera 9.1 which is slated to be released soon will also have a anti-phishing (or anti-fraud) feature that checks the live database constantly updated by Netcraft. So when you use a tool bar utility provided by one of the masters of anti-fraud technology you can be sure that you are at least one more step closer to being fully protected.

Download the netcraft tool bar.


ZoneAlarm firewall.

I would say that this is definitely one of the best firewalls out there. Steve Gibson, one of the pioneers in the field of security constantly keeps tracks of the security issues through this site grc.com and his Gibson Research corporation has been backing Zonealarm. It is one of the firewalls that has passed his leak test with flying colors. And moreover it is very user friendly so for home users who does not know much about the technicalities this is a very easy to handle firewall.

This is one of the firewalls that keep your ports stealthed on the net. A stealthed port means anyone using a port scanner with a malicious intend will never even see that such ports exist on your machine and because of that they won't be able to see that your machine exists on the net.

ZoneAlarm is free for individual and not-for-profit charitable entity use (excluding governmental entities and educational institutions).

Download zonealarm. (13.3 MB)

Or visit the publisher's website.

Also, check out the step by step guide to configuring ZoneLlarm.

Related reading:-
Everything you want to know about Phishing attacks.
Opera's new 9.1 browser.
Also if you check the category Computer/Internet/Software/Tech related. You might find some useful
tools and articles that will help you stay safe on the net. Since this site is new am constantly updating the contents. So check regularly for updates folks.

Highly critical vulnerabilities in Firefox and Windows OS

Mozilla Firefox and SeaMonkey Multiple Vulnerabilities.

Secunia has reported some highly critical multiple vulnerabilities in Mozilla firefox and SeaMonkey which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting attacks, and potentially compromise a vulnerable system.

For more details read the report.

Microsoft XMLHTTP ActiveX Control Code Execution Vulnerability

Also it seems Secunia has found yet another vulnerability with a Microsoft product and this time it is not Explorer but it is with the Operating system. It is a extremely critical vulnerability.

The vulnerability is already being actively exploited so everyone needs to stay guarded and take the necessary precaution.

See the report.

Related reading:-

Microsoft and Secunia at it again. And FireFox 2 too affected?

Yet another security flaw spotted in IE 7 today.

All IE 7 and Firefox 2 Vulnerabilities as of date.

Google