Showing posts with label Security Terminology..... Show all posts
Showing posts with label Security Terminology..... Show all posts

Dec 16, 2007

Tips to select AntiVirus

So you made the decision to Select an AntiVirus (AV) to safeguard your system. But stuck with what to look for in the AV?
------------------------------
Here are some of the tips that will help you in selecting the best AV for your computer:
- Load on System
- Type of subscription
- Ease of Upgradation
- Technical Support
- Frequency of the definitions or updates
Load on System
One of the common complaints from the users is that AV is taking lot of system resources. I think the problem could be caused at the startup of the computer where the most of the programs are configured to load and slow down the system. One way to get around this is to disable or delay or the startup of other applications. Remember it is very essential that AV loads at startup and not at a later time because some of the threats tend to load at startup and if they are allowed to load, they could even disable the AV.
Some of the other tips include, increasing the system RAM or Memory. Not only does this speed up the computing, but also allows you to multitask. Here is an easy and simple way to selectively allow programs to start:
1. Go to Start > Run
2. Type MSCONFIG
3. Click on the Startup tab
4. Uncheck the programs like Adobe, Winamp, MSN /Yahoo/Gtalk Messenger and etc
5. Click OK
Technical Support
Believe me, one factor that is going to have a major impact on your peace of mind is the Technical Support from your vendor on their product. I have seen people tear their hairs on the issues that can arise out of the blue.
Most of the problems arise while installing the product. Make sure you read the minimum hardware requirements, supported OS, incompatibility with other products before you decide to zero in on any product. Such information is published in the vendor website.
NOTE: You should Install and Use only One AntiVirus at a time. Having multiple AV to protect your system can cause all of them to malfunction and allow a threat to affect your system!
Technical support can be free or charged. Normally, free technical support is restricted to Knowledge Base Articles and Email or Chat support. KB articles are a good source of information for known issues and solutions for them. Some AV vendors even run support forum, where the solution comes from people like you and me.
Paid support comes in the form of Telephone calls. Here also you may have to go through the maze of IVRs to actually get to talk to the agent. By the time you get to talk to the agent you may be zapped, this does not end here….but to actually get the solution to your problem, you will have to shell out some money which may not be worthwhile. The charge for the paid support is almost equal to the half of the product price! (remember online search engines Google, Yahoo and MSN search are your friends!)
Frequency of virus definitions/updates
Well, if you think just installing an Antivirus would protect your system, hang on. You will also need to download the updates or antivirus definitions to keep up with the new threats. In this fast changing world of technology, newer threats in the form or Viruses, Worms and Trojans (Click here to read the difference between Viruses Worm and Trojans) come out each day. While it may be difficult for AV companies to keep the pace with all of them, some AV Vendors use heuristics to at least quarantine some of these. Symantec for example uses a technology called as Bloodhound to isolate the malicious threats for which complete information is not known. The common practice is this space for most AntiVirus vendors is to release the updates on a weekly basis. However, if there is an outbreak, the definitions to cure the same are released instantly to prevent any zero day attacks. Read the product information at the vendor’s site carefully to know the frequency of updates. An AV that does not get definitions on a periodic use may not be of much use.
Suggestion: Configure your AV to automatically download and install the updates as and when new updates are released.
Ease of Upgradation
The standard practice in the AntiVirus (AV) vendor space is that each year a newer version of the product is released. More often than not, you may end up upgrading to the newer version. Upgradation basically means installing a newer version over the existing version. So ensure that the AV you buy has the good track record of clean upgradation.
Some AV applications are known to have issues while upgrading from an older version to newer version. If not done correctly, they may leave traces in the registry and can cause major issues while installing. So watch out while you decide to Upgrade or Renew for Updates.
Type of Subscription
AV products generally have usage license for a period of one year. That is you pay and use for one year and after which you will have to renew it in order to receive the AV Updates / Virus definitions. Know the difference between Upgrade and Update.
An update is a periodic Antivirus definition or signature release from the vendor. This can be periodic, for example Symantec releases its Virus definition every Wednesday. Updates include Virus definitions, program improvements, patches etc.
An upgrade is the iteration in the version of the product. For example, you are using Norton Antivirus (NAV) 2007 and it is reaching its one year period and Symantec has now released NAV 2008. You will be presented an option to upgrade to the newer version or continue using the older version by renewing the subscription fees, in which case you will continue to use NAV 2007.
An upgrade normally costs little more than renewal and its better to go for an upgrade because there will bound to be improvements in the newer version.

Nov 22, 2007

Collection of Antivirus links

1.Kaspersky

2. Active Virus Shield by AOL

3. ZoneAlarm with KAV Antivirus

4. F-Secure

5. BitDefender Professional

6. BullGuard

7. Ashampoo

8. eScan

9. Nod32

10. CyberScrub

11. Avast Professional

12. AVG

13. F-Prot

14. McAfee

15. Panda

16. Norman

17. ArcaVir

18. Norton Professional

19. PC-Cillin

20. Sophos Sweep

21. Comodo

22. Abacre

23. A-Squared Anti-Malware

24. ClamWin

25. quickheal

26. Avira

27. Windows Live OneCare

28. Principal AntiVirus

There aren’t many free antivirus solutions that made the list, or were even tested for that matter. Active Virus Shield is completely free. Both AVG and Avast have a free version that they offer, but their paid solutions were tested instead.

Nov 3, 2007

Removing Virus......

folder option Problem
u r pc is infected with some virus or disabled by Someone
may be ravmon.exe
t removes folder options from list
u hav got some tools like RRT to remove restrictions like folder option
u can view all folders(hidden also) after using that tool
download the tool and enjoyyyyyyyy
or
1.Execute Regedit (shortcut, or StartMenu -- Run, and type regedit ..)
2. move with mouse to menu in Regedit's window and go to Edit -- Find (or simply stroke Ctrl+F)
3. Type HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\E xplorer
4. and finally - find REG_DWORD entry, named NoFolderOptions (if it is there at all, but probably it is) See, if mentioned entry has value 1 ... If it has, simply change it to 0, and that should do the trick
drives don open with doubleclick
The symptom occurs because when autorun.vbs is created by trojan horse or virus.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
Userinit=userinit.exe,autorun.exe
Finally, autorun.bat will call wscript.exe to run autorun.vbs.
When antivirus or security software detected the autorun.vbs file as infected, the file will be deleted or removed or quarantined. However, other files (autorun.*) and registry value still referring to autorun.vbs, and this document no longer exists, hence the error when users double
click to open a drive folder. To correct and solve this error, follow this steps:
Run Task Manager (Ctrl-Alt-Del or right click on Taskbar)
Stop wscript.exe process if available by highlighting the process name and clicking End Process.
Then terminate explorer.exe process.
In Task Manager, click on File -> New Task (Run…).
Type “cmd” (without quotes) into the Open text box and click OK.
Type the following command one by one followed by hitting Enter key:
del c:\autorun.* /f /s /q /a
del d:\autorun.* /f /s /q /a
del e:\autorun.* /f /s /q /a
c, d, e each represents drive letters on Windows system. If there are more drives or partitions available, continue to command by altering to other drive letter. Note that you must also clean the autorun files from USB flash drive or portable hard disk as the external drive may also be infected. then in Task Manager, click on File -> New Task (Run…).
Type “regedit” (without quotes) into the Open text box and click OK.
Navigate to the following registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Check if the value name and value data for the key is correct (the value data of userint.exe include the path which may be different than C drive, which is also valid, note also the comma
which is also needed):
“Userinit”=”C:\WINDOWS\system32\userinit.exe,”
If the value is incorrent, modify it to the valid value data.
Or
whenever u bring a USB from an untrusted source, or u are suspicious, u right click the drive --->explore. This way the trojan, if present wont run. Also, if a drive doesnt open due to trojan, for the time being u can open it by right click drive--->explore. After that u can unhide hidden files and system files from the folder options to search for suspicious files and folders and remove/rename them. In USBs, the trojans come with an autorun.ini/.inf and the trojan program which gets executed by the script in the autorun.ini/inf Lets see wether your system is infected or not... Download HijackThis
Install and run this software
Click "Do a system and save logfile"
There are chances of possible malware present in your system that's why i suggested this software.
desktop_ini Trojan
well this is a nearly harmless virus, i'm also infected with this...........but don't worry do the following go to my computer right-click on C drive and choose serch option enter the keyword u mention & click on search(after enablibg all options except case sensitive from more advanced option) after finishing search select all what the search shows and press shift+del do the same for remaining drives
Brontok Worm Problem
Brontok is a computer worm, which spreads through emails and USB drives.There are so many variants of brontok but they basically work Similarly. How do I know if my system is infected? You can’t start Regedit.exe
When trying to start any other registry editor, the system restarts The system also restarts when executing certain EXE files The presence of the following files:
%WINDIR%\eksplorasi.pif
%UserProfile%\Local Settings\Application Data\smss.exe
%UserProfile%\Local Settings\Application Data\services.exe
%UserProfile%\Local Settings\Application Data\lsass.exe
%UserProfile%\Local Settings\Application Data\csrss.exe
%UserProfile%\Local Settings\Application Data\inetinfo.exe
%UserProfile%\Local Settings\Application Data\winlogon.exe
%UserProfile%\Start Menu\Programs\Startup\Empty.pif
%UserProfile%\Templates\WowTumpeh.com
%WINDIR%\%CURRENT_USER%’s Setting.scr
%WINDIR%\ShellNew\bronstab.exe
All these files have the size of the worm’s main executable: 42,028
Bytes (About 42 KB).

What does it do?
Disable Folder Optionsa
Disable Registry Editor
Installs itself in the startup
When in memory, it will restart the system if any program involving the Registry is started
How to remove Brontok?
Download and run this brontok removal tool from Bitdefender. This tool Will kill the brontok process, restore folder options and registry.

orkut is blocked with message
Due to the attack of w32.USBWorm , the users may not be able to use Mozilla Firefox. And, when you use Internet explorer to open Orkut, you see a message. Also, the hidden files are not shown, even if we have selected Show hidden files in Folder Options.To resolve this problem, click here after you complete the below given steps.
Warning: Turn off System Restore before following these steps.
Tip: Its better to do the work in Safe mode.
You can try the following steps to resolve the problem:
Steps:
1. Press Ctrl+Alt+Del to open Task Manager. (Task Manager Disabled?)
2. Go to the Processes tab.
3. Click on Image Name tab to sort in accordance to name.
4. look for Image Name svchost.exe . There will be many, but click on which has User Name as
your user name .
5. After clicking on it, press Delete button (or click on End Process button). Click on Yes for confirmation.
6. Soon after the above step is done, select Run (?) from Start menu.
Type as follows:
C:\heap41a and press Enter. (Where C: is the Windows drive)
That takes you to a hidden folder heap41a in Windows drive.
7. Delete all files in that folder.
8. Now, start Registry Editor. (Start > Run > regedit) [(No Run?)(Regedit disabled?)]
9. Press Ctrl+F . Type heap41a and press Enter.
You can find two entries while you are finding, such as..
C:\heap41a\svchost.exe
C:\heap(some number)\std.txt
Delete both the entries.
10. Close the Registry Editor.

Oct 30, 2007

Security Terminology...

Anti-virus: Software that scans your pc for viruses, worms, and Trojans using up-to-date virus signatures. Once found, the program can remove, or quarantine the virus and (ideally) keep it from performing whatever malicious duties is was sent to do.
Attack: An attempt by an unauthorized individual or program to gain control over aspects of your pc for various purposes.
Backdoor: This is sometimes referred to as a trapdoor, and is a feature in programs that the original programmer puts into the code in order to fix bugs or make other changes that need to be made. However, if this information becomes known to anyone else it poses a potential security risk.
Firewall: A firewall refers to either a software or hardware device that basically protects your internal network from any outside threat or any unauthorized Internet access from the inside.
Hijacking: An attack whereby an active, established, session is intercepted and used by the attacker. Hijacking can occur locally if, for example, a legitimate user leaves a computer unprotected. Remote hijacking can occur via the Internet.
Hole: A known flaw in code that can compromise the security of your system by allowing unauthorized access.
HTTPS (Hypertext Transfer Protocol Secure): This is a version of http that is far more secure and is used (or should be used) in areas of the web where sensitive information is being used or exchanged.
Key: These are the names of Windows Registry components that are responsible for keeping the settings in Windows. Every time a program gets added to or uninstalled from a pc the Registry gets changed. If a virus gets into your system and makes changes to your registry keys it can cause serious performance changes.
Key loggers: These are used in legitimate programs but have been a favorite of hackers for years. Basically, what a key logger does is log your keystrokes for however long it is configured for. Hackers use these types of programs to find important information like usernames and passwords for sensitive accounts or highly secure areas.
@mm: This is usually seen at the end of a virus name i.e. W32netsky@mm and signifies that this virus is a mass mailer. A mass mailer is the term for a virus that upon infection can mail itself out to email addresses that it harvests from various areas of your hard drive—especially your address book. Sometimes you will see the designation with only one "m" at
the end of the virus name this stands for mailer and this kind of virus can only ride along with email messages you send.
Here are some more security terms that you should become familiar with.
Macro virus: Code written to take advantage of Hotkey" abilities to deliver its payload or replicate. Macros are hotkeys—key combinations that you can record and link to a single or fewer keystrokes.
Payload: This is the portion of the virus that is released into your system; it isn t always destructive but is always unwanted.
Port: The protocol stacks TCP/IP which is the protocol of the Internet (for the most part). There are several small parts to an Internet address, or IP address. While the IP address is your logical location on the web, the port number is an identifier for the service you would like to use on the system you re connecting to.
*A port has always been a tough concept to grab but is a very important component in fighting off hackers, Firewalls are so important because they deny any accesses to or from ports that you haven t granted access to. A firewall is an absolute necessity for broadband users.
Protocol: A set of rules and standards to govern the exchange of data between computers and related devices. There are protocols in almost every aspect of computers from web design to programming to network administration.
Replication: After a virus successfully infects a PC it usually starts to copy itself. Then it tries to infect either different parts of your system, or other systems, usually through address books or shared network files. This is usually one of the chief missions of a virus and by means of replication viruses can grow and infect new systems at an exponential rate.
Security response: The process of research, creation, delivery, and notification of responses to viral and malicious code threats, as well as operating system, application, and network infrastructure vulnerabilities.
SMTP: Simple Mail Transport Protocol. This is an email protocol that is responsible for moving mail from mail server to mail server.
Variant: A modification to the original virus code in an attempt to either throw antivirus software companies off, or create a different effect from the virus.
Virus definitions file: These are data files used by antivirus programs to help them identify and deal with viral attempts to infect your system.
About Virus......? Definitions
What is a Virus?
A virus is a manmade program or piece of code that causes an unexpected, usually negative, event. Viruses are often disguised games or images with clever marketing titles such as "Me, nude."
What is a Worm?
Computer Worms are viruses that reside in the active memory of a computer and duplicate themselves. They may send copies of themselves to other computers, such as through email or Internet Relay Chat (IRC).
What is a Trojan Horse?
A Trojan horse program is a malicious program that pretends to be a benign application; a Trojan horse program purposefully does something the user does not expect. Trojans are not viruses since they do not replicate, but Trojan horse programs can be just as destructive.
Many people use the term to refer only to non-replicating malicious programs, thus making a distinction between Trojans and viruses
What is spy-ware?
Spy-ware is Internet jargon for Advertising Supported software (Ad-ware). It is a way for shareware authors to make money from a product, other than by selling it to the users. There are several large media companies that offer them to place banner ads in their products in exchange for a portion of the revenue from banner sales. This way, you don't have to pay for the software and the developers are still getting paid. If you find the banners annoying, there is usually an option to remove them, by paying the regular licensing fee.
Known spywares
There are thousands out there, new ones are added to the list everyday. But here are a few:
Alexa, Aureate/Radiate, BargainBuddy, ClickTillUWin, Conducent Timesink, Cydoor, Comet Cursor, eZula/KaZaa Toptext, Flashpoint/Flashtrack, Flyswat, Gator, GoHip, Hotbar, ISTbar, Lions Pride Enterprises/Blazing Logic/Trek Blue, Lop (C2Media), Mattel Brodcast, Morpheus, NewDotNet, Realplayer, Songspy, Xupiter, Web3000, WebHancer, Windows Messenger Service.
How to check if a program has spyware?
The is this Little site that keeps a database of programs that are known to install spyware.
Check Here: http://www.spywareguide.com/product_search.php
If you would like to block pop-ups (IE Pop-ups).
There tons of different types out there, but these are the 2 best, i think.
Try: Google Toolbar (http://toolbar.google.com/) This program is Free
Try: AdMuncher (http://www.admuncher.com) This program is Shareware
If you want to remove the "spyware" try these.
Try: Lavasoft Ad-Aware (http://www.lavasoftusa.com/) This program is Free
Info: Ad-aware is a multi spyware removal utility, that scans your memory, registry and hard drives for known spyware components and lets you remove them. The included backup-manager lets you reinstall a backup, offers and multi language support.