Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Sunday, February 27, 2011

Process Hacker 2.12

Process Hacker is a free and open source process viewer and memory editor with unique features such as powerful process termination. It can show services, processes and their threads, modules, handles and memory regions.

 key features

· A simple, customizable tree view with highlighting showing you the processes running on your computer.
· Detailed performance graphs.
· A complete list of services and full control over them (start, stop, pause, resume and delete).
· A list of network connections.· Comprehensive information for all processes: full process performance history, thread listing and stacks with dbghelp symbols, token information, module and mapped file information, virtual memory map, environment variables, handles, ...
· Full control over all processes1, even processes protected by rootkits or security software. Its kernel-mode driver has unique abilities which allows it to terminate, suspend and resume all processes and threads, including software like IceSword, avast! anti-virus, AVG Antivirus, COMODO Internet Security, etc. (just to name a few).
· Find hidden processes and terminate them. Process Hacker detects processes hidden by simple rootkits such as Hacker Defender and FU.
· Easy DLL injection and unloading2 - simply right-click a process and select "Inject DLL" to inject and right-click a module and select "Unload" to unload!
· Many more features...

Thursday, February 24, 2011

Avast Free Antivirus 6.0.1000

avast! Free Antivirus often outperforms our competitors´ paid-for products in independent tests, leading in both security features and scanning speed. In fact, AV-Comparatives.org rated avast! the fastest out of 20 antivirus programs!
Having antivirus protection is critical and, fortunately, easier than ever. Download now and in just a few minutes you’ll be enjoying the peace of mind that comes from having the best and fastest online protection available.

 avast! Free Antivirus is perfect for people who send e-mails and surf popular websites. avast! is a package of applications that aim to protect your computer from a possible virus infection or other malware threat. If you use it correctly, and in combination with other programs such as data backup utilities, it will significantly reduce the risk of your computer being attacked or infected by a virus, and thus the risk of losing important or private data. These help files have been created to help you understand how the program works as a whole, as well as describing the properties and functions of its component parts. We assume the user has knowledge of basic terms and the basic skills needed to use the Windows operating system. If you are not familiar with terms such as "folder", "file", or "window", or what it means to "activate a window" or "click a button", we recommend that you consult the appropriate user manual before proceeding.

Avast Pro Antivirus 6.0.1000

Full antivirus and anti-spyware protection, with the next generation virtualzation technology.
Avast Pro Antivirus employs complete virtualization technology to increase your protection. Any application can be run in the virtual Sandbox environment, to prevent attackers from reaching your PC. What's more, the avast! SafeZone gives you an isolated desktop fortress for even more sensitive operations.


avast! is a package of applications that aim to protect your computer from a possible virus infection or other malware threat. If you use it correctly, and in combination with other programs such as data backup utilities, it will significantly reduce the risk of your computer being attacked or infected by a virus, and thus the risk of losing important or private data.These help files have been created to help you understand how the program works as a whole, as well as describing the properties and functions of its component parts. We assume the user has knowledge of basic terms and the basic skills needed to use the Windows operating system. If you are not familiar with terms such as "folder", "file", or "window", or what it means to "activate a window" or "click a button", we recommend that you consult the appropriate user manual before proceeding.

Monday, February 21, 2011

Norman Malware Cleaner 1.8.3 2011.02.20

Norman Malware Cleaner is a Norman program utility that may be used to detect and remove specific malicious software (malware).
Note that it should not be used as a substitute for running normal proactive antivirus protection, but rather as a reactive tool to handle systems that are already infected.


 By downloading and running the program below it will clean an infected system completely:
  • kill running processes that are infected
  • remove infections from disk (including ActiveX components and browser helper objects)
  • reveal and remove rootkits
  • restore correct registry values
  • remove references created by malware in hosts file
  • remove windows firewall rules for malicious programs
System requirements
  • Supported operating systems: Windows 98, Me, NT, 2000, XP, 2003, Vista, 2008 and 7.
  • Operating systems not supported: Windows 95
  • Note! This tool will not work in Windows Safe Mode. Please run Windows in Normal Mode.

In some cases Norman Malware Cleaner may require that you restart the computer to completely remove an infection:

 Note
To give Norman Malware Cleaner the best working conditions possible, we recommend that you start the computer in Safe mode before running the program.

To do this, tap the F8 key on your keyboard during startup, before Windows starts, and select Safe mode from the menu that appears.

Pressing the F8 key at just the right time may be a little difficult (after the firmware POST process completes, but before Windows displays graphical output). If the F8 method does not work, repeat the procedure, but press the F8 key more quickly, or press it several times.

On some (older) computers, the F8 key method may not work. In these Windows versions you may also configure your computer to start in Safe mode through the System Configuration Utility (msconfig).


Thursday, February 17, 2011

Norton 360 5.0.0.125

Norton 360 the ultimate in protection from the industry leader in security software. Norton 360 allows you to deny digital dangers no matter what you do, or where you go online.

This beta version of Norton 360 Version 5.0 is the fastest, most effective all-in-one solution we have ever offered. Try it now and receive a special discount on the full version once the beta ends! Norton 360 Version 5.0 provides comprehensive, automated protection for your PC, files, and online identity.


The latest upgrade of Norton 360 offers:
  • superior performance
  • improved protection
  • easier and faster backups

Norton 360 v5 includes:
- Award winning speed, performance and protection technologies with automatic backup and PC tune-up to keep you safe, secure and running at top speed.
- Effortless to use and works quietly in the background.
- Safe Web Scanner checks your Facebook Wall and News Feed for bad links and other threats right from your Norton Control Center.
- Exclusive Norton Insight Technology protects you from download dangers no matter which browser, instant messenger or file sharing program you use*.
- Norton Recovery Tools can help when PCs become infected with difficult to remove “scareware” programs or they get so infected by threats that are deeply buried in the PC’s operating system that special tools are required to remove them.
- Additional feature integration includes:
          o Norton SafeWeb keeps you safe while searching, browsing and shopping.
          o Parental Controls Management tracks your kids latest online activity to help keep them safe from online dangers.
          o Norton World Protection Map informs you of cyber-threats that have been blocked in your area.

- Supported programs include: Internet Explorer, Firefox, AOL, Chrome, Safari, Opera, QQ, MSN Messenger, MSN Explorer, Yahoo (IM), MSN, Outlook, Windows Mail, Thunderbird, Limewire, Bittorrent, FileZilla.

Download Norton 360  5.0.0.125

Saturday, September 4, 2010

System Explorer 2.3.4.3171

System Explorer is free, awards winning software for exploration and management of System Internals.
 


This small software includes many usefull tools which help you Keep Your System Under Control. With System Explorer You get also fast access to File Database which help you to determine unwanted processes or threats. System Explorer is translated into 21 languages and is available for download in installer and portable version.

Result of comparation is displayed in tree view and text list. Can be used for analysation of product installers/uninstallers (like Total Uninstall). Performance graphs for monitoring usage of system resources in time. Easy check of suspicious files via VirusTotal. Easy search details about file/process via online databases. Easy access to System Utilities.


 Download Installer Version

Download Portable Version

System Explorer 2.3.4.3171

System Explorer is free, awards winning software for exploration and management of System Internals.
 


This small software includes many usefull tools which help you Keep Your System Under Control. With System Explorer You get also fast access to File Database which help you to determine unwanted processes or threats. System Explorer is translated into 21 languages and is available for download in installer and portable version.

Result of comparation is displayed in tree view and text list. Can be used for analysation of product installers/uninstallers (like Total Uninstall). Performance graphs for monitoring usage of system resources in time. Easy check of suspicious files via VirusTotal. Easy search details about file/process via online databases. Easy access to System Utilities.


 Download Installer Version

Download Portable Version

Child Lock 1.6


Lock the keyboard and mouse to stop those wandering little fingers.


Can be set to autolock after a period of inactivity - stops little fingers once you have left the PC.
Can block out windows control keys - switch out of the current application (provided the app is running fullscreen such as a game)


Can slow down the mouse, stop autorepeat - assists young ones just getting used to a mouse and keyboard.



Download

Child Lock 1.6


Lock the keyboard and mouse to stop those wandering little fingers.


Can be set to autolock after a period of inactivity - stops little fingers once you have left the PC.
Can block out windows control keys - switch out of the current application (provided the app is running fullscreen such as a game)


Can slow down the mouse, stop autorepeat - assists young ones just getting used to a mouse and keyboard.



Download

Wednesday, September 1, 2010

BitDefender QuickScan for Firefox 0.9.9.34

BitDefender QuickScan is a very fast antivirus scanner, able to determine in a matter of seconds (up to 1-2 minutes on first-time scans) if a system is infected with malware.
Whenever you need a quick check or a second opinion, such as before logging into your favorite game, when using your bank account or buying something online, use Quickscan, directly from your browser.

BitDefender QuickScan takes full advantage of the "in-the-cloud" scanning service and is capable to detect active malware in less than a minute, taking just a fraction of the system resources needed by a regular virus scan.

Please note that Quickscan does not provide a virus cleaning service. If quickscan detects a threat, it is advisable to use an antivirus service (such as the one provided at www.malwarecity.com/scan8/ie.html )

Privacy and safety information:
Quickscan does not modify or delete any file on your system and only uploads executable files for checking (i.e. NO documents or other data files are sent).

Add to FireFox

BitDefender QuickScan for Firefox 0.9.9.34

BitDefender QuickScan is a very fast antivirus scanner, able to determine in a matter of seconds (up to 1-2 minutes on first-time scans) if a system is infected with malware.
Whenever you need a quick check or a second opinion, such as before logging into your favorite game, when using your bank account or buying something online, use Quickscan, directly from your browser.

BitDefender QuickScan takes full advantage of the "in-the-cloud" scanning service and is capable to detect active malware in less than a minute, taking just a fraction of the system resources needed by a regular virus scan.

Please note that Quickscan does not provide a virus cleaning service. If quickscan detects a threat, it is advisable to use an antivirus service (such as the one provided at www.malwarecity.com/scan8/ie.html )

Privacy and safety information:
Quickscan does not modify or delete any file on your system and only uploads executable files for checking (i.e. NO documents or other data files are sent).

Add to FireFox

SpywareBlaster 4.4


 Spyware, adware, browser hijackers, and dialers are some of the most annoying and pervasive threats on the Internet today. By simply browsing a web page, you could find your computer to be the brand-new host of one of these unwanted fiends!

The most important step you can take is to secure your system.

And SpywareBlaster is the most powerful protection program available.
Multi-Angle Protection

  • Prevent the installation of ActiveX-based spyware and other potentially unwanted programs.
  • Block spying / tracking via cookies.
  • Restrict the actions of potentially unwanted or dangerous web sites.
No-Nonsense Security SpywareBlaster can help keep your system secure, without interfering with the "good side" of the web. And unlike other programs, SpywareBlaster does not have to remain running in the background. It works alongside the programs you have to help secure your system.

Download

SpywareBlaster 4.4


 Spyware, adware, browser hijackers, and dialers are some of the most annoying and pervasive threats on the Internet today. By simply browsing a web page, you could find your computer to be the brand-new host of one of these unwanted fiends!

The most important step you can take is to secure your system.

And SpywareBlaster is the most powerful protection program available.
Multi-Angle Protection

  • Prevent the installation of ActiveX-based spyware and other potentially unwanted programs.
  • Block spying / tracking via cookies.
  • Restrict the actions of potentially unwanted or dangerous web sites.
No-Nonsense Security SpywareBlaster can help keep your system secure, without interfering with the "good side" of the web. And unlike other programs, SpywareBlaster does not have to remain running in the background. It works alongside the programs you have to help secure your system.

Download

Saturday, August 7, 2010

Self-protection from malware




Introduction

There are several levels where you can set up protection mechanisms in order to minimize the risk of falling victim to malware. Different protection mechanisms are needed depending on which danger situation we are discussing. One useful way to look at the protection situations is like this:
  1. Personal awareness (actions prior to exposure)
  2. Protection by software
  3. Procedures when infected
In this two-part security article we will examine what you as a user can do to yourself against malicious software - the personal awareness protection scheme. These are actions that come into effect even before any security software are involved in any protection attempts.
Personal awareness may be the most important protection instrument to your disposal. And it is even free! However, it does require a particular mind-set in order to function properly.
The clue can be summarized in these three words:
Use common sense!
In the following we shall examine some of the dangers that you may be exposed to, and how common sense, a few simple procedures, and a critical mind-set, can protect you.

Social engineering

Almost all techniques that are used to try to trick you into performing an action that results in an infection of your computer, boil down to social engineering. A person or persons with criminal intent want to persuade you to do something that has a consequence that you did not expect (or want).
The social engineering schemes vary from the ridiculously simple (sending a message with nothing but a link, hoping that recipients will click the link), to the sophisticated (investigating the recipients before contact and designing specially crated personal messages) – and everything in between.
Since the different social engineering schemes are so varied, one cannot make a complete list of how they look. The ambition should rather be for each and every one of us to recognize typical patterns, and thus avoid being tricked.
At the end of article series we will identify some such patterns.

Examples and discussion

Here are some typical scenarios where your increased awareness may protect you from infection attempts.

Links in instant messaging programs

There are a lot of instant messaging (IM) programs in use in the Internet community. These may be used as spreading devices for malware by at least two different techniques:
  1. An IM account is compromised and the person who has taken control over the account uses this to send messages to those who are in the owner’s contact list. These messages can be tailor-made and potentially quite convincing and thereby difficult to protect against.
     
  2. A computer is infected by malware, which sends instant messages – usually links - to persons in the contact list. These messages will often be easy to spot as they may not be similar to the way you normally communicate with the person who sent you the message.
One message of type 2 may look like the one below received in Windows Live Messenger. Typical is that the message is in English and consist of a short text with a link. Even more common is a message with a link only. The sender’s status often appears as Away when the message is sent (and thereby not able to contact for verification of the message’s validity).
As we shall see later, clicking on such a link may turn out to be quite dangerous.
 Click image to enlarge
In order to protect yourself against this type of attacks, consider the following:
  • Does your friend/colleague usually contact you without any introduction?
  • Does your friend/colleague usually use the language that the message shows?
  • Is the content of the message in line with your friend/colleagues usual behavior?
If the answer is ‘no’ to any of these questions, you should not click on the link.
If you suspect that something smells fishy even if the answer is ‘yes’ to all questions, you might still take the extra precaution and verify with the person at the other end that the message is legitimate. This may take some extra seconds, but may turn out to be a smart use of your time.

Obfuscated links in email messages

One of the most used devices for social engineering is the good old email message.
One of the most famous, and successful examples of using email as a social engineering vehicle, happened ten years ago when millions of computer users around the world received an email with the subject ILOVEYOU and a body text with this sentence:
kindly check the attached LOVELETTER coming from me.
The alleged love letter was the attachment LOVE-LETTER-FOR-YOU.TXT.vbs.
Vast numbers of people clicked and were subsequently infected with the Loveletter or I-Love-You malware.
The malware spreaders these days are usually a least a bit more sophisticated. A typical social engineering email nowadays might look like this:
Click image to enlarge
Characteristics are:
  • a friendly subject line,
  • a body text in html format aimed to pick the recipient’s interest,
  • a link to a web page – this will often appear to be to a well-known and trusted web site.
Since this email is written in html format, the link that appears as seen in the email text may be completely different from what the link actually leads to when clicking on it. The real link will be displayed in the email client’s status bar at the bottom of the window when you hover the mouse pointer over the email link. As you can see from the image above, clicking the link does not take you to the www.cool.imagelibraryonline.net.woah-imgs/ address, rather to the more suspect-looking www.terribly-dangerous-web.com site.
Here is another example of a typical email designed to try to trick the recipient:
Click image to enlarge
Another social engineering attempt, aimed at users of the social network Facebook. The Facebook community has a huge number of members, and the probability is high that recipients of this email are Facebook members. However, none of the three links in this email (the Sign In button, the http://www.facebook.com/home.php URL and the “here” link do actually link to any Facebook resource.
An important lesson to learn from these examples is that links in messages are dangerous to click on. A more secure way is to copy and paste the text into the browser or tediously type it into the browser.

Manipulating search engine results

Big media events are loved by cyber criminals. They may be used to trigger social engineering schemes like those shown above, and they can be used in at least one totally different manner.
It is a fact that big media events like the swine flu pandemic, the volcano eruption in Iceland, the world’s championship in football and similar, inspire people to use search engines to search for new and updated information about the events.
By registering domain names (Internet names) that are associated with the event in question, and crafting web pages that are specially designed to satisfy search engines’ requirements, malicious web sites/pages may be “seeded” to appear near the top of results from search engines.
The events most suited for search engine manipulation are those that appear suddenly, like disasters. Specially crafted malicious web sites may then be created quickly and not compete with the real stuff about the event. Web sites about well-planned events will have had months to grow and already obtained good search engine results, are more difficult to compete with.
Such a malicious web site will unfortunately not offer particularly useful information about the searched-after event – it will rather only attempt to infect the customer with malicious program code.
You will find more information about manipulating search engines in this security article from last year.

Next part

In the next article in this series we shall examine more closely 
  • infected web sites
  • characteristics of social engineering attempts
  • protection against unknown threats

Infected web sites

There are two different types of infected web sites/pages:
  1. Those where the person with malicious intent herself has set up the web server and controls it. This type is normally the easiest ones to spot, even though some are quite clever and may replicate legitimate sites regarding look and feel, and have an address similar to the legitimate site. www.nicefeaturessite.com and www.nicefeatureesite.com look quite similar, but proof-reading will show that an ‘s’ in the former has been substituted by an ‘e’ in the latter.
     
  2. Legitimate sites that have malicious elements. This may be because the site has been compromised and malicious elements have been inserted, or because the administrator of the legitimate web site has been tricked to add for example a malicious advertisement or another type of banner.
Recent studies indicate that the most malicious web sites are by far of type 2 above. Some studies show more than 90%.
A full examination of the different techniques used for inserting malicious elements on a web site is beyond the scope of these article. An Internet search will reveal lots of interesting information if you want more in-dept details. Suffice it to say in this context that some techniques used are:
  • Cross Site Scripting (XXS),
  • PDF files that exploit vulnerabilities in this file format,
  • Malicious scripts (Javascripts or Active scripts),
  • Malicious flash elements that exploit vulnerabilities in the flash player,
  • Invisible IFRAMEs that loads malicious web elements,

Characteristics of social engineering attempts

It is close to impossible that you can be able to protect yourself against well-planned, targeted social engineering attempts. However, there are quite a few characteristics of the more mundane type, which are useful to remember.
Knowing these may save you from becoming a victim to scams of the kind each and every one of us are likely to be exposed to.
After all, few of us will ever experience a targeted attack directed at one person. Only particularly "interesting" persons merit such exceptional effort on an attacker’s side. Most of us are (unfortunately?) not that interesting.

A typical social engineering attack will often consist of some of the following or similar elements:
  • Phrases that obviously intend to pick your curiosity.
  • A link that turns out to be another one than the one displayed in the message.
  • The displayed link is often to a well-known respectable organization.
  • A message from an acquaintance of yours that is not in his or hers usual manner.
  • A message from a completely unknown person.
  • A message from yourself!

Protection against unknown threats

By increasing your awareness the way we have described in this and the previous article, you are better protected against typical, popular and traditional infection attempts.
More importantly, however, is that as a spin-off from your increased awareness, you are better equipped against infection attempts using completely new spreading mechanisms. It is a fact that whenever a new “device” is used for malware spreading, our previous, well-learned protection mechanisms tend to be completely forgotten. This issue has been discussed in several of our security articles the recent years - see for example this article from March this year.
By focusing on awareness rather than relying on previous knowledge and protection by software, you are less inclined to be infected.

Useful resources

Useful information about social engineering trends and examples can be found all over the Internet.
Some recommended resources with general information as well as information about the latest threats are:
  • Norman’s Security center: http://www.norman.com/security_center/ (this section of our web)
  • SANS’ Storm center: http://isc.sans.org/ 
  • Different countries’ CERT (Computer Emergency Response Team) web sites and mailing list. (Use a search engine to find your own local CERT.)
  • Lots of other security organizations’ web sites and independent blogs.
Source

Self-protection from malware




Introduction

There are several levels where you can set up protection mechanisms in order to minimize the risk of falling victim to malware. Different protection mechanisms are needed depending on which danger situation we are discussing. One useful way to look at the protection situations is like this:
  1. Personal awareness (actions prior to exposure)
  2. Protection by software
  3. Procedures when infected
In this two-part security article we will examine what you as a user can do to yourself against malicious software - the personal awareness protection scheme. These are actions that come into effect even before any security software are involved in any protection attempts.
Personal awareness may be the most important protection instrument to your disposal. And it is even free! However, it does require a particular mind-set in order to function properly.
The clue can be summarized in these three words:
Use common sense!
In the following we shall examine some of the dangers that you may be exposed to, and how common sense, a few simple procedures, and a critical mind-set, can protect you.

Social engineering

Almost all techniques that are used to try to trick you into performing an action that results in an infection of your computer, boil down to social engineering. A person or persons with criminal intent want to persuade you to do something that has a consequence that you did not expect (or want).
The social engineering schemes vary from the ridiculously simple (sending a message with nothing but a link, hoping that recipients will click the link), to the sophisticated (investigating the recipients before contact and designing specially crated personal messages) – and everything in between.
Since the different social engineering schemes are so varied, one cannot make a complete list of how they look. The ambition should rather be for each and every one of us to recognize typical patterns, and thus avoid being tricked.
At the end of article series we will identify some such patterns.

Examples and discussion

Here are some typical scenarios where your increased awareness may protect you from infection attempts.

Links in instant messaging programs

There are a lot of instant messaging (IM) programs in use in the Internet community. These may be used as spreading devices for malware by at least two different techniques:
  1. An IM account is compromised and the person who has taken control over the account uses this to send messages to those who are in the owner’s contact list. These messages can be tailor-made and potentially quite convincing and thereby difficult to protect against.
     
  2. A computer is infected by malware, which sends instant messages – usually links - to persons in the contact list. These messages will often be easy to spot as they may not be similar to the way you normally communicate with the person who sent you the message.
One message of type 2 may look like the one below received in Windows Live Messenger. Typical is that the message is in English and consist of a short text with a link. Even more common is a message with a link only. The sender’s status often appears as Away when the message is sent (and thereby not able to contact for verification of the message’s validity).
As we shall see later, clicking on such a link may turn out to be quite dangerous.
 Click image to enlarge
In order to protect yourself against this type of attacks, consider the following:
  • Does your friend/colleague usually contact you without any introduction?
  • Does your friend/colleague usually use the language that the message shows?
  • Is the content of the message in line with your friend/colleagues usual behavior?
If the answer is ‘no’ to any of these questions, you should not click on the link.
If you suspect that something smells fishy even if the answer is ‘yes’ to all questions, you might still take the extra precaution and verify with the person at the other end that the message is legitimate. This may take some extra seconds, but may turn out to be a smart use of your time.

Obfuscated links in email messages

One of the most used devices for social engineering is the good old email message.
One of the most famous, and successful examples of using email as a social engineering vehicle, happened ten years ago when millions of computer users around the world received an email with the subject ILOVEYOU and a body text with this sentence:
kindly check the attached LOVELETTER coming from me.
The alleged love letter was the attachment LOVE-LETTER-FOR-YOU.TXT.vbs.
Vast numbers of people clicked and were subsequently infected with the Loveletter or I-Love-You malware.
The malware spreaders these days are usually a least a bit more sophisticated. A typical social engineering email nowadays might look like this:
Click image to enlarge
Characteristics are:
  • a friendly subject line,
  • a body text in html format aimed to pick the recipient’s interest,
  • a link to a web page – this will often appear to be to a well-known and trusted web site.
Since this email is written in html format, the link that appears as seen in the email text may be completely different from what the link actually leads to when clicking on it. The real link will be displayed in the email client’s status bar at the bottom of the window when you hover the mouse pointer over the email link. As you can see from the image above, clicking the link does not take you to the www.cool.imagelibraryonline.net.woah-imgs/ address, rather to the more suspect-looking www.terribly-dangerous-web.com site.
Here is another example of a typical email designed to try to trick the recipient:
Click image to enlarge
Another social engineering attempt, aimed at users of the social network Facebook. The Facebook community has a huge number of members, and the probability is high that recipients of this email are Facebook members. However, none of the three links in this email (the Sign In button, the http://www.facebook.com/home.php URL and the “here” link do actually link to any Facebook resource.
An important lesson to learn from these examples is that links in messages are dangerous to click on. A more secure way is to copy and paste the text into the browser or tediously type it into the browser.

Manipulating search engine results

Big media events are loved by cyber criminals. They may be used to trigger social engineering schemes like those shown above, and they can be used in at least one totally different manner.
It is a fact that big media events like the swine flu pandemic, the volcano eruption in Iceland, the world’s championship in football and similar, inspire people to use search engines to search for new and updated information about the events.
By registering domain names (Internet names) that are associated with the event in question, and crafting web pages that are specially designed to satisfy search engines’ requirements, malicious web sites/pages may be “seeded” to appear near the top of results from search engines.
The events most suited for search engine manipulation are those that appear suddenly, like disasters. Specially crafted malicious web sites may then be created quickly and not compete with the real stuff about the event. Web sites about well-planned events will have had months to grow and already obtained good search engine results, are more difficult to compete with.
Such a malicious web site will unfortunately not offer particularly useful information about the searched-after event – it will rather only attempt to infect the customer with malicious program code.
You will find more information about manipulating search engines in this security article from last year.

Next part

In the next article in this series we shall examine more closely 
  • infected web sites
  • characteristics of social engineering attempts
  • protection against unknown threats

Infected web sites

There are two different types of infected web sites/pages:
  1. Those where the person with malicious intent herself has set up the web server and controls it. This type is normally the easiest ones to spot, even though some are quite clever and may replicate legitimate sites regarding look and feel, and have an address similar to the legitimate site. www.nicefeaturessite.com and www.nicefeatureesite.com look quite similar, but proof-reading will show that an ‘s’ in the former has been substituted by an ‘e’ in the latter.
     
  2. Legitimate sites that have malicious elements. This may be because the site has been compromised and malicious elements have been inserted, or because the administrator of the legitimate web site has been tricked to add for example a malicious advertisement or another type of banner.
Recent studies indicate that the most malicious web sites are by far of type 2 above. Some studies show more than 90%.
A full examination of the different techniques used for inserting malicious elements on a web site is beyond the scope of these article. An Internet search will reveal lots of interesting information if you want more in-dept details. Suffice it to say in this context that some techniques used are:
  • Cross Site Scripting (XXS),
  • PDF files that exploit vulnerabilities in this file format,
  • Malicious scripts (Javascripts or Active scripts),
  • Malicious flash elements that exploit vulnerabilities in the flash player,
  • Invisible IFRAMEs that loads malicious web elements,

Characteristics of social engineering attempts

It is close to impossible that you can be able to protect yourself against well-planned, targeted social engineering attempts. However, there are quite a few characteristics of the more mundane type, which are useful to remember.
Knowing these may save you from becoming a victim to scams of the kind each and every one of us are likely to be exposed to.
After all, few of us will ever experience a targeted attack directed at one person. Only particularly "interesting" persons merit such exceptional effort on an attacker’s side. Most of us are (unfortunately?) not that interesting.

A typical social engineering attack will often consist of some of the following or similar elements:
  • Phrases that obviously intend to pick your curiosity.
  • A link that turns out to be another one than the one displayed in the message.
  • The displayed link is often to a well-known respectable organization.
  • A message from an acquaintance of yours that is not in his or hers usual manner.
  • A message from a completely unknown person.
  • A message from yourself!

Protection against unknown threats

By increasing your awareness the way we have described in this and the previous article, you are better protected against typical, popular and traditional infection attempts.
More importantly, however, is that as a spin-off from your increased awareness, you are better equipped against infection attempts using completely new spreading mechanisms. It is a fact that whenever a new “device” is used for malware spreading, our previous, well-learned protection mechanisms tend to be completely forgotten. This issue has been discussed in several of our security articles the recent years - see for example this article from March this year.
By focusing on awareness rather than relying on previous knowledge and protection by software, you are less inclined to be infected.

Useful resources

Useful information about social engineering trends and examples can be found all over the Internet.
Some recommended resources with general information as well as information about the latest threats are:
  • Norman’s Security center: http://www.norman.com/security_center/ (this section of our web)
  • SANS’ Storm center: http://isc.sans.org/ 
  • Different countries’ CERT (Computer Emergency Response Team) web sites and mailing list. (Use a search engine to find your own local CERT.)
  • Lots of other security organizations’ web sites and independent blogs.
Source

Norman Malware Cleaner 2010


Norman Malware Cleaner is a Norman program utility that may be used to detect and remove specific malicious software (malware).
Note that it should not be used as a substitute for running normal proactive antivirus protection, but rather as a reactive tool to handle systems that are already infected.

By downloading and running the program below it will clean an infected system completely:

  • kill running processes that are infected
  • remove infections from disk (including ActiveX components and browser helper objects)
  • reveal and remove rootkits
  • restore correct registry values
  • remove references created by malware in hosts file
  • remove windows firewall rules for malicious programs

System requirements

  • Supported operating systems: Windows 98, Me, NT, 2000, XP, 2003, Vista, 2008 and 7.
  • Operating systems not supported: Windows 95
  • Note! This tool will not work in Windows Safe Mode. Please run Windows in Normal Mode.

In some cases Norman Malware Cleaner may require that you restart the computer to completely remove an infection: 

 Note
To give Norman Malware Cleaner the best working conditions possible, we recommend that you start the computer in Safe mode before running the program.

To do this, tap the F8 key on your keyboard during startup, before Windows starts, and select Safe mode from the menu that appears.

Pressing the F8 key at just the right time may be a little difficult (after the firmware POST process completes, but before Windows displays graphical output). If the F8 method does not work, repeat the procedure, but press the F8 key more quickly, or press it several times.

On some (older) computers, the F8 key method may not work. In these Windows versions you may also configure your computer to start in Safe mode through the System Configuration Utility (msconfig).


Download : Norman Malware Cleaner 2010.08.06

Norman Malware Cleaner 2010


Norman Malware Cleaner is a Norman program utility that may be used to detect and remove specific malicious software (malware).
Note that it should not be used as a substitute for running normal proactive antivirus protection, but rather as a reactive tool to handle systems that are already infected.

By downloading and running the program below it will clean an infected system completely:

  • kill running processes that are infected
  • remove infections from disk (including ActiveX components and browser helper objects)
  • reveal and remove rootkits
  • restore correct registry values
  • remove references created by malware in hosts file
  • remove windows firewall rules for malicious programs

System requirements

  • Supported operating systems: Windows 98, Me, NT, 2000, XP, 2003, Vista, 2008 and 7.
  • Operating systems not supported: Windows 95
  • Note! This tool will not work in Windows Safe Mode. Please run Windows in Normal Mode.

In some cases Norman Malware Cleaner may require that you restart the computer to completely remove an infection: 

 Note
To give Norman Malware Cleaner the best working conditions possible, we recommend that you start the computer in Safe mode before running the program.

To do this, tap the F8 key on your keyboard during startup, before Windows starts, and select Safe mode from the menu that appears.

Pressing the F8 key at just the right time may be a little difficult (after the firmware POST process completes, but before Windows displays graphical output). If the F8 method does not work, repeat the procedure, but press the F8 key more quickly, or press it several times.

On some (older) computers, the F8 key method may not work. In these Windows versions you may also configure your computer to start in Safe mode through the System Configuration Utility (msconfig).


Download : Norman Malware Cleaner 2010.08.06

Thursday, August 5, 2010

Kaspersky Virus Removal Tool 2010


Kaspersky Virus Removal Tool 2010 serves for curing computers infected with viruses and other malware.

AVPTool 2010 is another name for Kaspersky Virus Removal Tool 2010 the former being frequently used on Kaspersky Lab official forum.

   
Installation Guide of Kaspersky Virus Removal Tool 2010

The difference between Kaspersky Virus Removal Tool 2010 and other Kaspersky Lab
software is:
  1. Kaspersky Virus Removal Tool 2010 is freeware.
  2. Kaspersky Virus Removal Tool 2010 can work together with installed Kaspersky Lab/ third-party antivirus software.
    There is one exception however. Combination of Kaspersky Internet Security 2010 and Kaspersky Virus Removal Tool 2010 has a number of features described here.
  3. Kaspersky Virus Removal Tool 2010 does not have a function allowing to update its antivirus database. The only way to actualize the tool is to download it again from Kaspersky Lab servers and install it. It is also necessary to uninstall older version of Kaspersky Virus Removal Tool 2010 before installing a newer one.
    Your computer may crash to BSOD, hang, etc. in the result of simultaneous execution of more than one version of Kaspersky Virus Removal Tool 2010.
  4. Kaspersky Virus Removal Tool 2010 is unsuitable for providing resident protection on computers.
    After successful disinfection of a computer, it is recommended to uninstall Kaspersky Virus Removal Tool 2010 and install a fully-functional antivirus application.
  5. The only function of the tool is scan-on-demand. It cannot work in real-time mode.

In order to install Kaspersky Virus Removal Tool 2010, perform the following actions:
  • in the Setup Wizard click the Next button
  • read the license agreement
  • check I accept the agreement
  • click the Next button
  • select the folder you want to install the application in (click Browse button), or use the folder by default (C:\Documents and settings\\desktop\Virus Removal Tool)
  • click the Next button
The Setup Wizard automatically copies the files on your hard disk and runs Kaspersky Virus Removal Tool 2010

In order to run automatic scan of your computer by Kaspersky Virus Removal Tool 2010 click the Start scan button on the Autoscan tab in the main window:
Once the scan task is started, the program will detect and automatically delete all known viruses, rootkits, Trojan programs and worms.
By default Kaspersky Virus Removal Tool 2010 scans for viruses System memory, Disk boot sectors and Hidden startup objects. In the main window on the Autoscan tab you can define the scan area by checking the necessary scan areas.
In order to modify the scan settings, on the Autoscan tab in the Security level area click the Recommended link and then select Settings.
The Scope tab:
  • All files. With this option, all objects will be scanned without exception 
  • Files scanned by format - this option scans only potentially infected files – files which viruses can intrude. Before searching for viruses in an object, its internal header is analyzed for the file format (txt, doc, exe, etc.). 
  • Files scanned by extension. In this case, the program will only scan potentially infected files, and in doing so, the file format will be determined by extension. 
  • Skip files scanned longer than. Check this option and enter the maximum scan time for an object. Then, if this time is exceeded, this object will be removed from the scan queue 
  • Scan archives – scan .rar, .arj, .zip, .cab, .lha, .jar, and .ice archives.
  • Scan installation packages - scan installation packages of programs.
  • Scan embedded OLE objects– scan objects embedded in files (for example, Excel spreadsheets or a macros). 
  • Parse e-mail formats – scan e-mail files and e-mail databases. 
  • the Additional... button:
    • Do not unpack large compound files. Check this option and enter the maximum size for an object. Then, if this size is exceeded, this object will be removed from the scan queue.
The Additional tab:
  • Heuristic analysis – a method to detect new malicious programs by the actions they produce in the operating system. The heuristic analyzer can be set to one of the following scan levels: Light scan, Medium scan, High scan.
  • Signature scan of vulnerabilities - enables scan and detection of vulnerabilities of your system, based on databases (signatures) created by Kaspersky Lab's specialists.
  • Rootkit scan – enables scan and detection of the utilities which hide actions of malicious programs in the operating system.
  • Deep scan – enables more detailed/extended scan of the utilities which hide actions of malicious programs in the operating system. 
  • Enable Self-Defense - protect the application's files and processes from being interacted by viruses.





In order to manually disinfect your computer using Kaspersky Virus Removal Tool 2010, perform the following actions:
  • After the software installation is completed open the main application window of the tool 
  • Go to the Manual Disinfection tab 
  • Click the button Gathering system information
  • Wait until the system information has been collected
  • click the link Open folder to open the folder where the report is saved
  • register on the Kaspersky Lab’s forum 
  • in the Virus-related issues branch create a new topic with the detailed description of the symptoms of computer infection 
  • to the topic attach the report file of the Wizard work avptool_sysinfo.zip
  • thoroughly read answers from Kaspersky Lab’s experts and virus analysts
  • follow all the instructions from Kaspersky Lab's experts and virus analysts.

 Download : Kaspersky Virus Removal Toll 2010

Kaspersky Virus Removal Tool 2010


Kaspersky Virus Removal Tool 2010 serves for curing computers infected with viruses and other malware.

AVPTool 2010 is another name for Kaspersky Virus Removal Tool 2010 the former being frequently used on Kaspersky Lab official forum.

   
Installation Guide of Kaspersky Virus Removal Tool 2010

The difference between Kaspersky Virus Removal Tool 2010 and other Kaspersky Lab
software is:
  1. Kaspersky Virus Removal Tool 2010 is freeware.
  2. Kaspersky Virus Removal Tool 2010 can work together with installed Kaspersky Lab/ third-party antivirus software.
    There is one exception however. Combination of Kaspersky Internet Security 2010 and Kaspersky Virus Removal Tool 2010 has a number of features described here.
  3. Kaspersky Virus Removal Tool 2010 does not have a function allowing to update its antivirus database. The only way to actualize the tool is to download it again from Kaspersky Lab servers and install it. It is also necessary to uninstall older version of Kaspersky Virus Removal Tool 2010 before installing a newer one.
    Your computer may crash to BSOD, hang, etc. in the result of simultaneous execution of more than one version of Kaspersky Virus Removal Tool 2010.
  4. Kaspersky Virus Removal Tool 2010 is unsuitable for providing resident protection on computers.
    After successful disinfection of a computer, it is recommended to uninstall Kaspersky Virus Removal Tool 2010 and install a fully-functional antivirus application.
  5. The only function of the tool is scan-on-demand. It cannot work in real-time mode.

In order to install Kaspersky Virus Removal Tool 2010, perform the following actions:
  • in the Setup Wizard click the Next button
  • read the license agreement
  • check I accept the agreement
  • click the Next button
  • select the folder you want to install the application in (click Browse button), or use the folder by default (C:\Documents and settings\\desktop\Virus Removal Tool)
  • click the Next button
The Setup Wizard automatically copies the files on your hard disk and runs Kaspersky Virus Removal Tool 2010

In order to run automatic scan of your computer by Kaspersky Virus Removal Tool 2010 click the Start scan button on the Autoscan tab in the main window:
Once the scan task is started, the program will detect and automatically delete all known viruses, rootkits, Trojan programs and worms.
By default Kaspersky Virus Removal Tool 2010 scans for viruses System memory, Disk boot sectors and Hidden startup objects. In the main window on the Autoscan tab you can define the scan area by checking the necessary scan areas.
In order to modify the scan settings, on the Autoscan tab in the Security level area click the Recommended link and then select Settings.
The Scope tab:
  • All files. With this option, all objects will be scanned without exception 
  • Files scanned by format - this option scans only potentially infected files – files which viruses can intrude. Before searching for viruses in an object, its internal header is analyzed for the file format (txt, doc, exe, etc.). 
  • Files scanned by extension. In this case, the program will only scan potentially infected files, and in doing so, the file format will be determined by extension. 
  • Skip files scanned longer than. Check this option and enter the maximum scan time for an object. Then, if this time is exceeded, this object will be removed from the scan queue 
  • Scan archives – scan .rar, .arj, .zip, .cab, .lha, .jar, and .ice archives.
  • Scan installation packages - scan installation packages of programs.
  • Scan embedded OLE objects– scan objects embedded in files (for example, Excel spreadsheets or a macros). 
  • Parse e-mail formats – scan e-mail files and e-mail databases. 
  • the Additional... button:
    • Do not unpack large compound files. Check this option and enter the maximum size for an object. Then, if this size is exceeded, this object will be removed from the scan queue.
The Additional tab:
  • Heuristic analysis – a method to detect new malicious programs by the actions they produce in the operating system. The heuristic analyzer can be set to one of the following scan levels: Light scan, Medium scan, High scan.
  • Signature scan of vulnerabilities - enables scan and detection of vulnerabilities of your system, based on databases (signatures) created by Kaspersky Lab's specialists.
  • Rootkit scan – enables scan and detection of the utilities which hide actions of malicious programs in the operating system.
  • Deep scan – enables more detailed/extended scan of the utilities which hide actions of malicious programs in the operating system. 
  • Enable Self-Defense - protect the application's files and processes from being interacted by viruses.





In order to manually disinfect your computer using Kaspersky Virus Removal Tool 2010, perform the following actions:
  • After the software installation is completed open the main application window of the tool 
  • Go to the Manual Disinfection tab 
  • Click the button Gathering system information
  • Wait until the system information has been collected
  • click the link Open folder to open the folder where the report is saved
  • register on the Kaspersky Lab’s forum 
  • in the Virus-related issues branch create a new topic with the detailed description of the symptoms of computer infection 
  • to the topic attach the report file of the Wizard work avptool_sysinfo.zip
  • thoroughly read answers from Kaspersky Lab’s experts and virus analysts
  • follow all the instructions from Kaspersky Lab's experts and virus analysts.

 Download : Kaspersky Virus Removal Toll 2010