<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>rootkits &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://wordpress.com/tag/rootkits/</link>
	<description>Feed of posts on WordPress.com tagged "rootkits"</description>
	<pubDate>Fri, 25 Jul 2008 17:45:40 +0000</pubDate>

	<generator>http://wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[Can You Trust Search Engine Results? - Maybe Not]]></title>
<link>http://billmullins.wordpress.com/?p=553</link>
<pubDate>Thu, 03 Jul 2008 17:07:08 +0000</pubDate>
<dc:creator>billmullins</dc:creator>
<guid>http://billmullins.wordpress.com/?p=553</guid>
<description><![CDATA[ Since many of us now have access to GPS, finding the way to Grandma’s house (if you’re Little R]]></description>
<content:encoded><![CDATA[<p><a href="http://billmullins.files.wordpress.com/2008/07/windowslivewritercanyoutrustsearchengineresultsmaybenot-b51aporn-warning-for-wot2.jpg"><img style="border-width:0;margin:0 20px 0 0;" src="http://billmullins.files.wordpress.com/2008/07/windowslivewritercanyoutrustsearchengineresultsmaybenot-b51aporn-warning-for-wot-thumb.jpg" alt="Web of Trust Warning Screen" width="238" height="240" align="left" /></a> Since many of us now have access to GPS, finding the way to Grandma’s house (if you’re Little Red Riding Hood) has never been easier. Not many of us would question the output of a GPS inquiry since it is a technology we are familiar and comfortable with.</p>
<p>An even more familiar technology to the seasoned web surfer is the Internet search engine, and just like most familiar technologies we comfortable with, we are not likely to question a search engines output.</p>
<p><strong>Web of Trust Warning Screen</strong></p>
<p>The question is though, should we question the output? How sure are we that the results are untainted and free of potential harmful exposure to malware or worst?</p>
<p>Recent comments on this issue in Panda Security’s Oxygen 3 E-bulletin on IT security, indicates that Cyber-crooks continue to be unrelenting in their chase to infect web search results. According to Panda “there is a steady increase in the use of custom-built websites designed to drop malicious code on computers, or even the manipulation of legitimate pages in order to infect users with malware.”</p>
<p>PandaLabs maintains that cyber-crooks have begun to opt for a new technique: the manipulation of search engine results, or seeding websites among the top results returned by these engines. When a potential victim visits one of these sites the likelihood of the downloading of malicious code onto the computer by exploiting existing vulnerabilities is high.</p>
<p>Let’s take, as an example, a typical user running a search for “great vacation spots” on one of the popular search engines. Unknown to the user, the search engine returns a malicious or compromised web page as one of the most popular sites. Users with less than complete Internet security who visit this page will have an extremely high chance of becoming infected.</p>
<p>There are a number of ways that this can occur. Cyber-crooks can exploit vulnerabilities on the server hosting the web page to insert an iFrame, (an HTML element which makes it possible to embed another HTML document inside the main document). The iFrame can then activate the download of malicious code by exploiting additional vulnerabilities on the visiting machine.</p>
<p>Alternatively, a new web page can be built, with iFrames inserted, that can lead to malware downloads. This new web page appears to be legitimate. In the example mentioned earlier, the web page would appear to be a typical page offering great vacation spots.</p>
<p>One more common method is the insertion of false dialogue boxes, fake toolbars, and more on sites; all designed to load destructive malware which could include rootkits, password stealers, Trojan horses, and spam bots.</p>
<p>Unfortunately, since Cyber-crooks are relentless in their pursuit of your money, and in the worst case scenario your identity, you can be sure that additional threats are being developed or are currently being deployed.</p>
<p>So what can you do to ensure you are protected, or to reduce the chances you will become a victim?</p>
<p><strong>As I have pointed out in the past on this Blog, the following are actions you can take to protect your computer system, your money and your identity:</strong></p>
<ul>
<li>Install an Internet Browser add-on such as <a href="http://www.mywot.com/" target="_blank">WOT</a> (my personal favorite), which provides detailed test results on a site’s safety; protecting you from security threats including spyware, adware, spam, viruses, browser exploits, and online scams</li>
<li>Don’t open unknown email attachments</li>
<li>Don’t run programs of unknown origin</li>
<li>Disable hidden filename extensions</li>
<li>Keep all applications (including your operating system) patched</li>
<li>Turn off your computer or disconnect from the network when not in use</li>
<li>Disable Java, JavaScript, and ActiveX if possible</li>
<li>Disable scripting features in email programs</li>
<li>Make regular backups of critical data</li>
<li>Make a boot disk in case your computer is damaged or compromised</li>
<li>Turn off file and printer sharing on the computer</li>
<li>Install a personal firewall on the computer</li>
<li>Install anti-virus and anti-spyware software and ensure it is configured to automatically update when you are connected to the Internet</li>
<li>Ensure the anti-virus software scans all e-mail attachments</li>
<li>Be proactive when it comes to your computer’s security; make sure you have adequate software based protection to reduce the chances that your machine will become infected.</li>
</ul>
<p><strong>The free software listed below, in my view, provides better than average malware protection.</strong></p>
<p><a href="http://www.avast.com" target="_blank">avast! 4 Home Edition</a></p>
<p>This anti virus app is a real fighter, scanning files on demand and on access, including email attachments. Let’s you know when it detects mal-ware through its shield function. An important feature is a boot-time scan option which removes mal-ware that can’t be removed any other way.</p>
<p><a href="http://www.free.grisoft.com" target="_blank">AVG Anti-Virus Free Edition 8.0.1</a></p>
<p>Similarly, this program scans files on access, on demand, and on schedule. Scans email; incoming and outgoing. For those on Vista, your in luck, it’s Vista-ready. I have been using this application since its release and it now forms part of my front line defenses. I recommend this one highly.</p>
<p><a href="http://www.lavasoftusa.com" target="_blank">Ad-Aware 2007</a></p>
<p>In my view, Ad-Aware 2007 Free is the best free spyware and adware remover available. It does a relatively good job of protecting against known data-mining, Trojans, dialers, malware, browser hijackers and tracking components. The only downside with the free version; real-time protection is not included.</p>
<p><a href="http://www.threatfire.com" target="_blank">ThreatFire 3</a></p>
<p>ThreatFire 3 blocks mal-ware, including zero-day threats, by analyzing program behavior and it does a stellar job. Again, this is one of the security applications that forms part of my front line defenses. I have found it to have high success rate at blocking mal-ware based on analysis of behavior. Highly recommend this one!</p>
<p><a href="http://www.comodogroup.com" target="_blank">Comodo Firewall Pro</a></p>
<p>The definitive free firewall, Comodo Firewall protects your system by defeating hackers and restricting unauthorized programs from accessing the Internet. I have been using this application for 6 months and I continue to feel very secure. It resists being forcibly terminated and it works as well, or better, than any firewall I’ve paid for. This is one I highly recommend. Amazing that it’s free!</p>
<p><a href="http://www.winpatrol.com" target="_blank">WinPatrol</a></p>
<p>Do you want to get a better understanding of what programs are being added to your computer? Then WinPatrol is the program for you. With WinPatrol, in your system tray, you can monitor system areas that are often changed by malicious programs. You can monitor your startup programs and services, cookies and current tasks. Should you need to, WinPatrol allows you to terminate processes and enable, or disable, startup programs. There are additional features that make WinPatrol a very powerful addition to your security applications.</p>
<p><a href="http://www.sandboxie.com" target="_blank">Sandboxie</a></p>
<p>Surfing the Internet without using Sandboxie is, to me, like jumping out of an airplane without a parachute. Deadly! This application creates a “Sandboxed” protected environment on your machine within which you browse the net. Data that is written to your hard drive is simply eliminated, (or not, your choice), when the sandbox is closed. Utilizing this application allows you to surf the web without the risk of infecting your system with mal-ware or other nasties. This is another security application I have been using for over 6 months and it has yet to let me down. Highly recommended.</p>
<p><a href="http://www.snoopfree.com" target="_blank">Snoop Free Privacy Shield</a></p>
<p>Snoop Free Privacy Shield is a powerful application that guards your keyboard, screen and open windows from all spy software. If you’re serious about privacy, this is a must have addition to your security toolbox. Unfortunately this application does not operate under Vista.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Ferramentas de remoção de Rootkits]]></title>
<link>http://antivirusbrasil.wordpress.com/?p=156</link>
<pubDate>Thu, 26 Jun 2008 13:07:59 +0000</pubDate>
<dc:creator>Antivírus Brasil</dc:creator>
<guid>http://antivirusbrasil.wordpress.com/?p=156</guid>
<description><![CDATA[Ferramentas de remoção de Rootkits
Os rootkits são uma das pragas mais incômodas que um usuário]]></description>
<content:encoded><![CDATA[<h1 style="text-align:center;"><span style="text-decoration:underline;"><span style="color:#ff9900;">Ferramentas de remoção de Rootkits</span></span></h1>
<p style="text-align:justify;">Os rootkits são uma das pragas mais incômodas que um usuário pode adquirir. Além de comprometerem criticamente o desempenho do sistema, permanecem ocultos e geralmente não se deixam vencer por programas antivírus. Apesar de muitos desenvolvedores de softwares de segurança embutirem mecanismos para a detecção deles, a melhor solução ainda é o uso de programas específicos para tratar esse tipo de infecção, como o McAfee Rootkit Detective, AVG Anti-Rootkit<span class="titulo1"> </span><strong>.</strong></p>
<p style="text-align:justify;">São um tipo de vírus diferente. Receberam esse nome por serem um kit com vários aplicativos juntos em apenas um arquivo, que se instala no sistema de tal forma a obter acesso a todo ele; por isso Root, que é o nome dado ao usuário que tem controle total sobre o sistema (também conhecido como administrador).</p>
<p style="text-align:justify;">Essas suítes de softwares maléficos, sempre que acessadas (seja pelo usuário ou pelo escaneamento do antivírus), interceptam o pacote de informações capturado e retiram dali os dados que o identificam como um vírus. Usando essa artimanha, o <em>rootkit</em> não pode ser reconhecido por nenhum antivírus convencional.</p>
<p style="text-align:right;"> <strong>Prevenindo-se:</strong> </p>
<li>Utilize contas de usuários limitadas no Windows, as quais restringem o uso de alguns recursos do sistema que o rootkits utilizam para se instalar.</li>
<li>Seja cauteloso ao baixar arquivos em redes <a href="http://baixaki.ig.com.br/pesquisa.asp?nome=p2p&#38;tipo=1&#38;img.x=0&#38;img.y=0" target="_blank">P2P</a> (peer-to-peer), local onde eles geralmente são distribuídos.</li>
<li>Mantenha seu sistema atualizado. Sempre que disponível, instale as atualizações do Windows, pois elas vêm com correções para falhas de segurança que, se não corrigidas, podem ser usadas para a introdução do <em>rootkit</em> no sistema.</li>
<li>Não utilize programas do tipo <em>cracks</em>, pois além de ilegais, são os principais hospedeiros destas pragas. Além disso, sites que hospedam programas assim, comumente possuem códigos maliciosos que prejudicam seu computador ao serem acessados.Infelizmente, ainda não há programas que previnam este mal, porém se o seu computador estiver se comportando de forma irregular sem motivo, mesmo após a utilização de antívirus e limpadores de registro, não perca tempo em escaneá-lo com o Panda Anti-Rootkit, pois o quanto antes detectado, melhor!</li>
<p style="text-align:center;"><strong><span style="color:#ff0000;"><a href="http://antivirusbrasil.wordpress.com"><img class="size-medium wp-image-102  aligncenter" src="http://antivirusbrasil.wordpress.com/files/2008/04/logo.gif?w=112" alt="" width="112" height="26" /></a></span></strong></p>
<p><strong><span style="color:#ff0000;">Diga adeus aos rootkits!</span></strong></p>
<p style="text-align:justify;">O programa atua vasculhando o sistema atrás de entradas do registro e processos ocultos — principal forma de manifestação dos rootkits. Em seguida, ele relata os itens encontrados em uma lista, da qual você pode remover processos suspeitos ou renomear valores e entradas incoerentes. Como é de se perceber, o uso do <strong><span style="color:#ff0000;">McAfee Rootkit Detective </span></strong>requer experiência no assunto, pois o uso inadequado desta ferramenta pode inutilizar o sistema.</p>
<p style="text-align:center;"><a href="http://download.nai.com/products/mcafee-avert/McafeeRootkitDetective.zip" target="_blank"><img class="size-medium wp-image-119  aligncenter" src="http://antivirusbrasil.wordpress.com/files/2008/04/1517009001_9c068526c8_o1.gif?w=183" alt="" width="183" height="62" /></a></p>
<p style="text-align:center;">___________________________________________________________________________________________</p>
<p style="text-align:center;"><a href="http://antivirusbrasil.wordpress.com/files/2008/03/pandalogo.jpg"><img class="size-medium wp-image-65  aligncenter" src="http://antivirusbrasil.wordpress.com/files/2008/03/pandalogo.jpg?w=300" alt="" width="104" height="96" /></a></p>
<p style="text-align:justify;">O <strong>Panda Anti-Rootkit </strong>é uma ferramenta leve e funcional para detectar e remover <em>rootkits</em>, uma nova espécie de vírus com um sistema muito avançado de programação.<br />
O programa é simples e prático. Sua funcionalidade é resumida em rastrear o sistema na busca de <em>rootkits</em> — verificando principalmente os processos ocultos — e apagar eventuais ocorrências. Ao final, é exibido um relatório com os resultados do escaneamento. Ao contrário de alguns softwares do gênero que apenas revelam os <em>rootkits</em>, o Panda Anti-Rootkit, além de removê-los, também apaga as entradas do registro, processos e arquivos relacionados a eles.
</p>
<p style="text-align:center;"><a href="http://research.pandasoftware.com/blogs/images/AntiRootkit.rar" target="_blank"><img class="size-medium wp-image-119  aligncenter" src="http://antivirusbrasil.wordpress.com/files/2008/04/1517009001_9c068526c8_o1.gif?w=183" alt="" width="183" height="62" /></a></p>
<p>____________________________________________________________________________________________</p>
<p style="text-align:center;"> <img class="size-medium wp-image-60 aligncenter" src="http://antivirusbrasil.wordpress.com/files/2008/03/trend_micro.png?w=253" alt="" width="92" height="108" /></p>
<p style="text-align:justify;"> O <strong>Trend Micro RootkitBuster </strong>é um "caçador" e eliminador de rootkits. Ele procura por arquivos escondidos, entradas de registro, processos e drivers em busca dessas pragas da internet. Basta executar o programa e escolher onde ele deve procurar por rootkits. Em seguida, se ele encontrar alguma ameaça, basta clicar em "Delete Selected Items" e pronto. Se você não desejar eliminar um arquivo encontrado, basta desmarcá-lo na lista.</p>
<p style="text-align:center;"><a href="http://www.trendmicro.com/ftp/products/rootkitbuster/rootkitbusterv1.6.1060.zip" target="_blank"><img class="size-medium wp-image-119  aligncenter" src="http://antivirusbrasil.wordpress.com/files/2008/04/1517009001_9c068526c8_o1.gif?w=183" alt="" width="183" height="62" /></a>____________________________________________________________________________________________</p>
<p style="text-align:center;"><a href="http://antivirusbrasil.files.wordpress.com/2008/06/45181-p.jpg"><img class="size-medium wp-image-158 aligncenter" src="http://antivirusbrasil.wordpress.com/files/2008/06/45181-p.jpg?w=100" alt="" width="100" height="65" /></a></p>
<p style="text-align:justify;">AVG AntiRootKit irá auxiliá-lo na árdua tarefa de combates mais um mal da internet: os <em>rootkits</em>. Agora a Grisoft também entrou na luta contra esses vilões que até pouco tempo eram invisíveis aos olhos de qualquer anti-vírus, devido ao seu funcionamento diferenciado. Há algum tempo foi desenvolvido um sistema de reconhecimento e extinção desse tipo de software. AVG AntiRootKit usa esse sistema para tornar seu computador mais seguro contra ataques inesperados de pragas invisíveis.</p>
<h6 style="text-align:center;"><img class="size-medium wp-image-119  aligncenter" src="http://antivirusbrasil.wordpress.com/files/2008/04/1517009001_9c068526c8_o1.gif?w=183" alt="" width="183" height="62" /></h6>
<p> </p>
<h6 style="text-align:right;">Fonte: <a href="http://baixaki.ig.com.br/pesquisa.asp?nome=rootkits&#38;tipo=1" target="_blank">Baixaki</a></h6>
<p style="text-align:right;"> </p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Dicas de Downloads de Segurança na Internet]]></title>
<link>http://brasilpolitico.wordpress.com/2008/06/16/dicas-de-downloads-de-seguranca-na-internet/</link>
<pubDate>Mon, 16 Jun 2008 03:25:28 +0000</pubDate>
<dc:creator>Fernand Koda</dc:creator>
<guid>http://brasilpolitico.wordpress.com/2008/06/16/dicas-de-downloads-de-seguranca-na-internet/</guid>
<description><![CDATA[McAfee Rootkit Detective
Os rootkits são uma das pragas mais incômodas que um usuário pode adquir]]></description>
<content:encoded><![CDATA[<p style="background:#f1f1f1;text-align:justify;"><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;"><strong>McAfee Rootkit Detective</strong></span></p>
<p style="background:#f1f1f1;text-align:justify;"><span style="font-size:9pt;font-family:Lucida Sans Unicode;"><span style="color:#0000ff;">Os rootkits são uma das pragas mais incômodas que um usuário pode adquirir. Além de comprometerem criticamente o desempenho do sistema, permanecem ocultos e geralmente não se deixam vencer por programas antivírus. Apesar de muitos desenvolvedores de softwares de segurança embutir mecanismos para a detecção deles, a melhor solução ainda é o uso de programas específicos para tratar esse tipo de infecção, como o <strong>McAfee Rootkit Detective</strong>.</span><font face="Lucida Sans Unicode"></p>
<p style="background:#f1f1f1;text-align:justify;"><span style="color:#0000ff;"><strong>Diga adeus aos rootkits!</strong></span></p>
<p><span style="color:#0000ff;">O programa atua vasculhando o sistema atrás de entradas do registro e processos ocultos ? Principal forma de manifestação dos rootkits. Em seguida, ele relata os itens encontrados em uma lista, da qual você pode remover processos suspeitos ou renomear valores e entradas incoerentes. Como é de se perceber, o uso do <strong>McAfee Rootkit Detective</strong> requer experiência no assunto, pois o uso inadequado desta ferramenta pode inutilizar o sistema.</span></p>
<p><span style="color:#0000ff;"><strong>Fácil de usar</strong></span></p>
<p><span style="color:#0000ff;">Seguindo a mesma linha dos produtos da McAfee, o software apresenta um consumo moderado dos recursos do sistema e execução estável. A interface é intuitiva e simples de ser utilizada, exigindo apenas que se conheçam alguns termos da informática.</span></p>
<p><span style="color:#0000ff;">Se o seu computador está com comportamento anormal e os métodos tradicionais não estão solucionando isso, baixe já o <strong>McAfee Rootkit Detective</strong>, um verdadeiro detetive pessoal para encontrar e acabar com os rootkits.</span></p>
<p><span style="color:#0070c0;font-family:Lucida Sans Unicode;font-size:9pt;"><strong><span style="color:#0000ff;">Minha Opinião<br />
</span></strong></p>
<p></span></p>
<p></font></span>
</p>
<p style="background:#f1f1f1;text-align:justify;"> </p>
<p style="text-align:justify;"> </p>
<p style="background:#f1f1f1;text-align:justify;"><span style="font-size:9pt;font-family:Lucida Sans Unicode;"><span style="color:#0000ff;">Com certeza o <strong>McAfee Rootkit Detective</strong> é um dos softwares mais simples de serem utilizados do segmento. Por trás de uma interface gráfica amigável e objetiva, o programa mostrou que possui um poderoso sistema de detecção de rootkits, procurando não apenas por processos como também por entradas ocultas do registro.</span><span style="color:#0070c0;font-family:Lucida Sans Unicode;font-size:9pt;"><span style="color:#0000ff;">Em compensação, essa busca detalhada pode tornar o escaneamento muito demorado, ainda mais se o registro do sistema estiver abarrotado de entradas inválidas. Para obter um melhor desempenho, experimente efetuar a limpeza do registro previamente com um software apropriado. Sugerimos o </span><a href="http://baixaki.ig.com.br/download/CCleaner.htm" target="_blank"><span style="text-decoration:underline;"><span style="color:#0000ff;">CCleaner</span></span></a><span style="color:#0000ff;">.<br />
Se o seu computador esta com comportamento anômalo e o seu antivírus não está dando conta, o McAfee Rootkits Detective é uma excelente opção para lhe ajudar.<br />
</span></p>
<p></span></span>
</p>
<p style="text-align:justify;"> </p>
<p style="background:white;text-align:justify;"><a title="Vista Inspirat BricoPack 1.1" href="http://baixaki.ig.com.br/site/dwnld37281.htm"><span style="font-size:9pt;font-family:Lucida Sans Unicode;text-decoration:underline;"><br />
</span></a>
</p>
<p style="background:white;text-align:justify;"><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;"><strong>Vista Inspirat BricoPack 1.1</strong></span></p>
<p style="background:white;text-align:justify;"><span style="font-size:9pt;font-family:Lucida Sans Unicode;"><span style="color:#0000ff;">Para quem já cansou daquele visual padrão do seu Windows XP e procura um pacote que mude, de vez, o modo como você o vê diariamente, uma boa escolha é o Vista Inspirat Bricopack. Mais do que um simples tema atrativo, o pacote traz uma série de mudanças na aparência do seu sistema, incluindo ícones, papéis de parede e esquemas de janela exclusivos.</span></p>
<p style="background:white;text-align:justify;"> </p>
<p></span>
</p>
<p style="background:white;text-align:justify;"><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;"><strong>A-squared Free</strong></span></p>
<p><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;">A-squared Free é um complemento para o seu antivírus e seu firewall. Os softwares antivírus são especializados em detectar vírus clássicos e muitos deles têm fraquezas na detecção de softwares maliciosos (malwares) como trojans, discadores, worms, spywares e adwares. A-squared Free preenche a lacuna que os malwares exploram.</span></p>
<p><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;"><strong>FireFox 2</strong></span>
</p>
<p style="background:white;text-align:justify;"><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;">O <strong>Firefox</strong> 2 permite que você navegue mais rápido, com mais segurança e eficiência do que qualquer outro browser. Mude hoje mesmo ? o Firefox importa seus favoritos e outras informações. E você ainda pode continuar usando outros navegadores junto com o Firefox.<br />
</span></p>
<p style="background:#f1f1f1;text-align:justify;"><a title="MSN Pictures Displayer 4.5" href="http://baixaki.ig.com.br/site/dwnld35926.htm"><span style="font-size:9pt;font-family:Lucida Sans Unicode;text-decoration:underline;"><br />
</span></a>
</p>
<p style="background:#f1f1f1;text-align:justify;"><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;"><strong>MSN Pictures Displayer 4.5</strong></span></p>
<p style="background:#f1f1f1;text-align:justify;"><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;">MSN Pictures Displayer é o programa que vai facilitar muito a sua vida na hora de escolher seu avatar do Windows Live Messenger. Com ele, você não precisa ficar mudando sua imagem de exibição constantemente, é só escolher as que você mais gosta.<br />
</span></p>
<p style="background:white;text-align:justify;"><a title="Messenger Plus! Live 4.21.270" href="http://baixaki.ig.com.br/site/dwnld41034.htm"><span style="font-size:9pt;font-family:Lucida Sans Unicode;text-decoration:underline;"><br />
</span></a>
</p>
<p style="background:white;text-align:justify;"><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;"><strong>Messenger Plus! Live 4.21.270</strong></span></p>
<p style="background:white;text-align:justify;"><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;">O software que adiciona diversos recursos ao MSN Messenger - agora conhecido como Windows Live Messenger - está de cara nova! Agora com total suporte a mais nova evolução do mensageiro instantâneo da Microsoft.<br />
</span></p>
<p style="background:#f1f1f1;text-align:justify;"><a title="DVD Shrink 3.2.0.15" href="http://baixaki.ig.com.br/site/dwnld38346.htm"><span style="font-size:9pt;font-family:Lucida Sans Unicode;text-decoration:underline;"><br />
</span></a>
</p>
<p style="background:#f1f1f1;text-align:justify;"><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;"><strong>DVD Shrink 3.2.0.15</strong></span></p>
<p style="background:#f1f1f1;text-align:justify;"><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;">DVDShrink é ótimo para ser usado em conjunto com softwares de gravação de DVD, criando cópias de qualquer disco. Para gravar discos você pode usar o Nero ou alternativas gratuitas como o CDBurnerXP e o Infra Recorder. Os arquivos podem ser salvos no seu disco rígido ou como imagem ISO e gravados mais tarde. Por que usar DVDShrink? A maioria dos títulos em DVD é projetado para impedir que você faça cópias. A primeira medida preventiva das produtoras é a criptografia. A maioria dos DVDs é encriptado, isto significa que você não pode copiar os arquivos para o seu PC, e, mesmo se conseguir copiá-los, não será capaz de reproduzi-los. DVDShrink resolve este problemas com algoritmos sofisticados de decriptação. O próximo problema não é tão fácil de resolver. A maioria dos títulos em DVD é simplesmente muito grande para caber, sem modificações, em apenas um disco de DVD-R. DVDShrink soluciona isso ao modificar ou "encolher" os dados do DVD original. DVD Shrink também permite que você recompile seu DVD. É possível criar sua própria compilação a partir de uma ou mais fontes de DVD, ou selecionar apenas as partes que você deseja visualizar ? assim preservando mais espaço no seu backup e propiciando a melhor qualidade. Como funciona? Recentemente, os codificadores atingiram alguma popularidade. Eles são baseados em algoritmos projetados para recomprimir uma transmissão MPEG-2 em tempo real. Esse tipo de programa pode recodificar um filme em DVD inteiro em apenas poucos minutos, pois não precisa decodificar e recodificar o vídeo completo, apenas uma parte dele. Basicamente o que você obtém é uma redução de tamanho (e conseqüentemente na qualidade) melhor do em qualquer outro programa no mesmo estilo. O DVD2One foi o primeiro programa a trabalhar dessa maneira e o DVD Shrink o primeiro programa gratuito do gênero.<br />
</span></p>
<p style="background:white;text-align:justify;"><a title="CoolSMS 1.97.6" href="http://baixaki.ig.com.br/site/dwnld34388.htm"><span style="font-size:9pt;font-family:Lucida Sans Unicode;text-decoration:underline;"><br />
</span></a>
</p>
<p style="background:white;text-align:justify;"><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;"><strong>CoolSMS 1.97.6</strong></span></p>
<p style="background:white;text-align:justify;"><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;">O CoolSMS é um software que tem como principal função o envio de Torpedos SMS através do computador diretamente para o celular, GRÁTIS! O CoolSMS apresenta uma interface amigável e bastante intuitiva, além das vantagens de centralizar o envio de mensagens num único aplicativo, salvar o seu histórico de Torpedos SMS enviados e também possuir agenda para armazenamento e acesso rápido aos contatos! Confira as principais funções deste software que é Cool! ? Envia Torpedos SMS grátis para as maiores operadoras do Brasil, diretamente do seu computador. É rápido e fácil! ? Envia Torpedo SMS individualmente ou para grupos de pessoas (para os amigos do futebol, por exemplo), mesmo os celulares não sendo da mesma operadora. ? Criação da sua agenda de celulares, acessível de qualquer computador com CoolSMS e conectado a internet; ? Classificação dos seus contatos em grupos. Ex: Família, Amigos, Trabalho... ? Ter todo o seu histórico de Torpedos SMS salvo! (opcional); ? Acesso a conteúdos exclusivos de acordo com o seu perfil, diretamente nas abas do CoolSMS; ? Acumular CoolPons (pontos no programa de relacionamento) e trocar por vantagens exclusivas; ? Design moderno e mais fácil de usar;<br />
</span></p>
<p style="background:#f1f1f1;text-align:justify;"><a title=" AVG Free Edition 7.5.467a1008" href="http://baixaki.ig.com.br/site/dwnld4866.htm"><span style="font-size:9pt;font-family:Lucida Sans Unicode;text-decoration:underline;"><br />
</span></a>
</p>
<p style="background:#f1f1f1;text-align:justify;"><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;"><strong>AVG Free Edition 7.5.467a1008</strong></span></p>
<p style="background:#f1f1f1;text-align:justify;"><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;">O AVG é um excelente antivírus, gratuito para uso doméstico. Possui atualizações via web, vasculha a memória do micro, conta com proteção de e-mails e downloads infectados e tem um sistema que já foi aprovado por inúmeros laboratórios independentes<br />
</span></p>
<p style="background:white;text-align:justify;"><a title="Google Earth 4.1.7076" href="http://baixaki.ig.com.br/site/dwnld26308.htm"><span style="font-size:9pt;font-family:Lucida Sans Unicode;text-decoration:underline;"><br />
</span></a>
</p>
<p style="background:white;text-align:justify;"><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;"><strong>Google Earth 4.1.7076</strong></span></p>
<p style="background:white;text-align:justify;"><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;">Com o programa você pode encontrar qualquer localidade na Terra, algumas com tanta precisão que é possível ver ruas, cruzamentos, até hospitais e os restaurantes mais famosos em mapas 3D. Claro que esses recursos não estão presentes em todas as cidades.<br />
</span></p>
<p style="background:#f1f1f1;text-align:justify;"><a title="WinRAR em Português 3.70 beta 8" href="http://www.rarlab.com/rar/wrar37b8br.exe"><span style="font-size:9pt;font-family:Lucida Sans Unicode;text-decoration:underline;"><br />
</span></a>
</p>
<p style="background:#f1f1f1;text-align:justify;"><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;"><strong>WinRAR em Português 3.70 beta 8</strong></span></p>
<p style="background:#f1f1f1;text-align:justify;"><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;">O WinRAR é o mais popular compressor RAR para Windows com gerenciador de arquivos integrado. Ele oferece uma compactação entre 8% e 15% maior que seu concorrente direto, o Winzip. Oferece suporte para RAR e ZIP, além de ACE, ARJ, BZ2, GZ, ISO, JAR etc..</span></p>
<p style="background:#f1f1f1;text-align:justify;"> </p>
<p style="background:#f1f1f1;text-align:justify;"><span style="font-size:9pt;color:#0000ff;font-family:Lucida Sans Unicode;">Fernand Koda</span></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Alternate Data Streams (ADS)]]></title>
<link>http://bughira.wordpress.com/?p=52</link>
<pubDate>Sat, 07 Jun 2008 17:59:27 +0000</pubDate>
<dc:creator>bughira</dc:creator>
<guid>http://bughira.wordpress.com/?p=52</guid>
<description><![CDATA[With the introduction of NTFS file system in Windows NT, Microsoft introduced new concept of having ]]></description>
<content:encoded><![CDATA[<p>With the introduction of NTFS file system in Windows NT, Microsoft introduced new concept of having multiple streams into single file known as Alternate Data Streams (ADS). In this blog i will discuss some advantages and disadvantages of ADS.<br />
Whenever we perform any operations on any file like - reading, writing, editing etc, we did it on the main stream of the file. This alternate data stream can be of binary or ASCII data. We can attach the streams to any file including executables and folders.</p>
<p>The biggest advantage of the ADS is its by default invisibility to the file handling utilities provided by Microsoft Windows like - File explorer, dir command etc. Unlike staganography, adding alternate stream to a file does not affect its original size that makes it almost impossible to detect.</p>
<p>ADS Capability was originally introduced to for compatibility with the Hierarchical File System (HFS) where data sometimes gets forked into separate resources. ADS are used by many legitimate windows programs to store file information such as attributes and temporary storage.<br />
Virus writers can take advantage of these stealth functionalities provided by ADS to hide malicious data in the alternate stream attached with legitimate files and easily defeat normal user and most of the antivirus present.</p>
<p>How to create an ADS:<br />
===============<br />
Following command will create an hiddenFile.txt as ADS with explorer.exe file present in %SystemRoot%<br />
<em>c:\&#62;echo "This is confidential data." &#62;c:\windows\explorer.exe:hiddenFile.txt</em></p>
<p>Following command will allow you to read the data present in the ADS. If you check the size of explorer.exe after attaching the alternate stream, will be exact same.</p>
<p><em>c:\&#62;type c:\windows\explorer.exe:hiddenFile.txt</em><br />
This is confidential data.<br />
c:\&#62;</p>
<p>Attaching executable as an ADS:<br />
=======================<br />
You can even attach executables using ADS and believe me this is where ADS is boon for virus writters. Virus writters can attach malicious executable with the legitimate one and make it execute at every boot time.</p>
<p><em>C:\&#62;copy %SystemRoot%\system32\calc.exe c:\blog\ads\<br />
C:\&#62;type maliciousFile.exe &#62; c:\blog\ads\calc.exe:newCalc.exe<br />
C:\&#62; reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v newLiveUpdate /t REG_SZ /d C:\blog\ads\calc.exe:newCalc.exe<br />
</em><br />
Once these three commands are executed on the victim machine, on every boot program newCalc.exe will automatically gets executed.<br />
To test it, you will need to reboot your system once.</p>
<p>Above things are very simple and does not require any skills, this is what makes it very dangerous. Virus writer can hide most of its virus code into ADS and to keep a small executable that will extract the virus.<br />
Whatever we discuss till now can be considered as an Ugly side(for us) of ADS. Now lets focus on about the removal of ADS from the infected systems.</p>
<p>How to detect ADS:<br />
==============<br />
Unfortunately, there are no windows tool which will scan the file and let you know about the alternate stream attached with the file.<br />
There is one third party utility called <em>lads.exe</em> which you can use to manually scan the file for the presence of the ADS. You can download this tool from <em>http://www.heysoft.de </em></p>
<p>Manually scan following REGISTRY location using <em>regedit </em>tool for the presence of string containing ":" e.g. <em>c:\windows\exeplorer.exe:virus.exe</em></p>
<p>Always be suspecious for the entries in the above locations and delete unwanted entries and like one given in above example.</p>
<p>Lets look at the good side of the ADS. We can use these invisibility feature of ADS for many different purposes.<br />
1) We can attach confidential files or files which we don't want to get deleted accidently to the system files which usually nobody deletes. This is useful especially when system us shared between multiple users.<br />
2) We can store passwords, pin codes in ADS.<br />
3) You can use freeware "Xidie Security Suite" to keep your private data hidden usin ADS. You can download this tool from <em>http://www.xidie.ro</em></p>
<p>How to Delete already created ADS:<br />
========================<br />
As we have already seen, ADS is only supported on NTFS file system. So Moving ADS file on drive fomatted with FAT will remove the ADS present on the moved file.<br />
On the NTFS file system, go to <em>start-&#62;run</em> and type "<em>notepad &#60;path of ADS&#62;</em>"</p>
<p>e.g <em>notepad c:\blog\ads\test.txt:hiddenFile.txt</em><br />
and delete the complete content of the file and save it.</p>
<p>As of now there are very few viruses exists which exploits this ADS functionality but don't get surprised if you see more of those in near future as most of the current anti-viruses are not capable of detecting virus hidden inside ADS.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Free Anti-Rootkits - Kernal Mode Trojan Protection]]></title>
<link>http://billmullins.wordpress.com/?p=452</link>
<pubDate>Sat, 31 May 2008 14:27:52 +0000</pubDate>
<dc:creator>billmullins</dc:creator>
<guid>http://billmullins.wordpress.com/?p=452</guid>
<description><![CDATA[
A rootkit is a malware program, or a combination of malware programs, designed to take low level co]]></description>
<content:encoded><![CDATA[<p><a href="http://billmullins.files.wordpress.com/2008/05/windowslivewriterfreeantirootkitskernalmodetrojanprotecti-929erootkits2.jpg"><img style="border-width:0;margin:0 20px 0 0;" src="http://billmullins.files.wordpress.com/2008/05/windowslivewriterfreeantirootkitskernalmodetrojanprotecti-929erootkits-thumb.jpg" alt="" width="208" height="240" align="left" /></a></p>
<p>A rootkit is a malware program, or a combination of malware programs, designed to take low level control of a computer. In other words, system operations that are generally outside the control of the user. Frequently, they are Trojans or Keyloggers as well.</p>
<p>Techniques used to hide rootkits include concealing running processes from monitoring programs, and hiding files or system data from the operating system. In other words, the rootkit’ files and processes will be hidden in Explorer, Task Manager, and other detection tools.</p>
<p>It’s easy to see then, that if a malware threat uses rootkit technology to hide, it is going to be very difficult to find.</p>
<p>A number of major anti-malware companies though have developed free functional solutions to rootkits. Enter the Rootkit detector which will provide you with the tools to find and delete rootkits, and to help you uncover additional threats rootkits may be hiding.</p>
<p>Generally, rootkit detectors are capable of the following type of scans, although it is important to note that not all scan, or handle rootkits, in precisely the same way.</p>
<p>· hidden processes</p>
<p>· hidden threads</p>
<p>· hidden modules</p>
<p>· hidden services</p>
<p>· hidden files</p>
<p>· hidden Alternate Data Streams</p>
<p>· hidden registry keys</p>
<p>· drivers hooking SSDT</p>
<p>· drivers hooking IDT</p>
<p>· drivers hooking IRP calls</p>
<p>If you think you might have hidden malware on your system, I recommend that you run multiple rootkit detectors. Much like anti-spyware programs, no one program catches everything. To be safe, I use each of the free rootkit detectors listed below on my machines.</p>
<p><strong>Microsoft Rootkit Revealer</strong></p>
<p>Microsoft Rootkit Revealer is an advanced root kit detection utility. Its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit. According to Microsoft, Rootkit Revealer successfully detects all persistent rootkits published at www.rootkit.com, including AFX, Vanquish and Hacker Defender.</p>
<p>Download here: <a href="http://www.download.com/RootkitRevealer/3000-2248_4-10543917.html">www.download.com</a></p>
<p><strong>IceSword</strong></p>
<p>IceSword is a very powerful software application that will scan your computer for rootkits. It also displays hidden processes and resources on your system that you would be unlikely to find in any other Windows Explorer like program. Because of the amount of information presented in the application, please note that IceSword was designed for more advanced users.</p>
<p>Download here: <a href="http://www.majorgeeks.com/Icesword_d5199.html">www.majorgeeks.com</a></p>
<p><strong>GMER</strong></p>
<p>This freeware tool is essentially a combination of Sysinternals’ Rootkit Revealer and Process Explorer. The program can list running processes, modules and Windows services, in addition to scanning for the presence of rootkits.</p>
<p>Download here: <a href="http://www.gmer.net/files.php">www.gmer.net/files.php</a></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[F-Secure Anti-Virus for Windows Servers 8.00.123]]></title>
<link>http://webdigerida.wordpress.com/?p=929</link>
<pubDate>Thu, 29 May 2008 18:28:05 +0000</pubDate>
<dc:creator>jecspawn</dc:creator>
<guid>http://webdigerida.wordpress.com/?p=929</guid>
<description><![CDATA[Um número cada vez maior de novos vírus são encontrados todos os dias, alguns deles com a capacid]]></description>
<content:encoded><![CDATA[<p>Um número cada vez maior de novos vírus são encontrados todos os dias, alguns deles com a capacidade de serem disseminados globalmente no prazo de horas.</p>
<p>Se um vírus entrar em uma rede corporativa, lutar contra ele pode ser difícil e demorado.</p>
<p>As infecções de vírus normalmente provocam perdas financeiras significativas, devido a interrupções na rede, redução na produtividade, dados corrompidos e vazamentos de dados confidenciais.</p>
<p>Mesmo a reputação de uma empresa pode estar em perigo se ela espalhar, sem saber, vírus para seus parceiros comerciais.</p>
<p>A Solução</p>
<p>O F-Secure Anti-Virus for Windows Servers, garante que os usuários que se conectam a servidores de arquivo com máquinas infectadas, não espalhem vírus para ouras máquinas da rede.</p>
<p>Com a F-Secure, a proteção contra vírus é rápida, eficaz e fácil. As instalações e o gerenciamento do antivírus podem ser realizadas remotamente a partir de uma única localização central.</p>
<p>Principais Funcionalidades</p>
<p>·                                 Proteção em tempo real contra vírus, spyware e riskware</p>
<p>·                                 Varredura manual a procura de vírus, spyware e riskware</p>
<p>·                                 Varredura manual a procura de rootkits</p>
<p>·                                 Varredura programada a procura de vírus, spyware, riskware e rootkits</p>
<p>·                                 Atualização automática de assinaturas de vírus, spyware e riskware (é necessário ter conexão com a Internet)</p>
<p>·                                 Suporte a 64 bits</p>
<p>Plataformas Suportadas</p>
<p>·                                 Microsoft Windows 2000 SP4</p>
<p>·                                 Microsoft Windows Server 2003 32-bit</p>
<p>· Microsoft Windows Server 2003 64-bit edition para processadores x64</p>
<p>·                                 Microsoft Windows Server 2008</p>
<p>·                                 Observação: O Windows Server 2003 64-bit edition para processadores Itanium (IA64) não é suportado</p>
<p>Tam.:56.3MB</p>
<p><span style="font-family:Arial;font-size:medium;"><a href="http://rapidshare.com/files/118609027/F-SECURE.ANTI-VIRUS.for.SERVERS.8.00.123.rar" target="_blank">http://rapidshare.com/files/118609027/F-SECURE.ANTI-VIRUS.for.SERVERS.8.00.123.rar</a></span></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Rootkits have nothing to do with gardening]]></title>
<link>http://computerhelpers.wordpress.com/?p=505</link>
<pubDate>Thu, 29 May 2008 17:12:50 +0000</pubDate>
<dc:creator>dvanarsd</dc:creator>
<guid>http://computerhelpers.wordpress.com/?p=505</guid>
<description><![CDATA[Rootkits are one of the newer hazards on the Web, and may include trojans.  They are designed to ta]]></description>
<content:encoded><![CDATA[<p><a title="Rootkits" href="http://en.wikipedia.org/wiki/Rootkits" target="_blank">Rootkits</a> are one of the newer hazards on the Web, and may include <a title="trojans" href="http://en.wikipedia.org/wiki/Trojan_horse_%28computing%29" target="_blank">trojans</a>.  They are designed to take control of your computer with or without your knowledge (usually without) and do who-knows-what with it.</p>
<p>They might report back your activities to somebody (to detect any suspected violations of copyright on music, for example) or something more sinister.</p>
<p>Fortunately, there are a number of programs to detect and deal with rootkits, and some of them are even free.</p>
<p>Find a good one at <a title="Antirootkit.com" href="http://antirootkit.com/software/index.htm" target="_blank">Antirootkit.com</a> .</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Antivirus = Waste of money? and Vista's UAC vs Rootkits]]></title>
<link>http://xerosai.wordpress.com/?p=7</link>
<pubDate>Tue, 27 May 2008 19:15:26 +0000</pubDate>
<dc:creator>xerosai</dc:creator>
<guid>http://xerosai.wordpress.com/?p=7</guid>
<description><![CDATA[Antivirus is &#8216;completely wasted money&#8217;: Cisco CSO

Companies are wasting money on securi]]></description>
<content:encoded><![CDATA[<p><strong><a href="http://www.zdnet.com.au/news/security/soa/Antivirus-is-completely-wasted-money-Cisco-CSO/0,130061744,339289122,00.htm">Antivirus is 'completely wasted money': Cisco CSO</a><br />
</strong></p>
<blockquote><p>Companies are wasting money on security processes — such as applying patches and using antivirus software — which just don't work, according to Cisco's chief security officer John Stewart.</p>
<p>...</p>
<p>"If patching and antivirus is where I spend my money, and I'm still getting infected and I still have to clean up computers and I still need to reload them and still have to recover the user's data and I still have to reinstall it, the entire cost equation of that is a waste. </p>
<p>...</p>
<p>A better way of dealing with the unknown is to use whitelists — where only authorised or approved software can execute, said Stewart.</p>
<p>"I'm sick of blacklisted stuff. I've got to go for whitelisted stuff — I know what that is because I put it there," he said. </p>
<p>...</p>
<p>Chris Thomas, technology specialist for CA's Internet Security business unit, said that antivirus alone did not provide enough protection.</p></blockquote>
<p>Interesting article. First of all, anyone who uses only antivirus to protect their computer(s) deserves to be compromised. A layered approach to security always seems to be the most effective method of protection. Sure there may be alternative operating systems such as linux/unix variants that are generally more secure than Windows but which one dominates the market? </p>
<p><strong><a href="http://www.pcworld.com/businesscenter/article/146256/vistas_despised_uac_nails_rootkits_tests_find.html">Vista's Despised UAC Nails Rootkits, Tests Find</a></strong></p>
<blockquote><p>Vista's UAC has a security feature that marks it out from any other type of Windows security program -- it can spot rootkits before they install. This is one finding buried in a report published in two German computer magazines some months ago after testing by the respected AV-Test.org, which set out to find out how well antivirus programs fared against known rootkits.</p>
<p>The answer: not particularly well ... either for Windows XP, or Vista-oriented products.</p>
<p>Of 30 rootkits thrown at XP anti-malware scanners, none of the seven AV suites found all 30, a similar story to the six web-based scanners assessed. Only four of the 14 specialized anti-rootkit tools managed a perfect score. For Vista, only six rootkits could run on the OS, but the testers had to turn off UAC to get even this far. Vista's UAC itself spotted everything thrown in front of it.</p>
<p>In a period of where Vista has received criticism, Microsoft's programmers can at least point to evidence that UAC is efficient at stopping infections from happening automatically.</p></blockquote>
<p>This should be good news. Rootkits are dangerous and if Vista can spot them before they can be installed then it shows that Microsoft got something right even though quite a few things still need to be fixed in terms of vulnerabilities. Based on the article it should discourage users from disabling UAC since it serves a purpose.</p>
<p>-xerosai</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Drive-by Downloads - The Paradox Created by Firewalls/Security Applications]]></title>
<link>http://billmullins.wordpress.com/?p=437</link>
<pubDate>Mon, 26 May 2008 17:27:27 +0000</pubDate>
<dc:creator>billmullins</dc:creator>
<guid>http://billmullins.wordpress.com/?p=437</guid>
<description><![CDATA[ Your Firewall and Security Applications provide the ultimate in protection while you’re surfing t]]></description>
<content:encoded><![CDATA[<p><a href="http://billmullins.files.wordpress.com/2008/05/windowslivewriter779d42108012-bb2arogue-software-32.png"><img style="border-width:0;margin:0 20px 0 0;" src="http://billmullins.files.wordpress.com/2008/05/windowslivewriter779d42108012-bb2arogue-software-3-thumb.png" alt="" width="240" height="178" align="left" /></a> Your Firewall and Security Applications provide the ultimate in protection while you’re surfing the web, right? Well in a sense they do.</p>
<p>Paradoxically, it’s because current anti-malware solutions are much more effective than they have ever been in detecting worms and viruses, that we’re now faced with another insidious form of attack.</p>
<p>Drive-by downloads are not new; they’ve been lurking around for years it seems, but they’ve become much more common and more crafty recently.</p>
<p>More than three million unique URLs on over 180,000 websites are automatically installing malware via drive-by downloads, according to recent statements by the Google Anti-Malware Team. Google has not been alone in noticing this trend by criminal hackers using these techniques. IBM noted recently, that criminals are directly attacking web browsers in order to steal identities, gain access to online accounts and conduct other illicit activities.</p>
<p>If you’re unfamiliar with the term, drive-by download, they are essentially programs that automatically download and installed on your computer without your knowledge. This action can occur while visiting an infected web site, as previously noted, opening an infected HTML email, or by clicking on a deceptive popup window. Often more than one program is downloaded, for example, file sharing with tracking spyware is very common. Again, it’s important to remember that this can take place without warning, or your approval.</p>
<p>What can you do to ensure you are protected, or to reduce the chances you will become a victim?</p>
<p><strong>The following are actions you can take to protect your computer system:</strong></p>
<ul>
<li>When surfing the web: Stop. Think. Click</li>
<li>Don’t open unknown email attachments</li>
<li>Don’t run programs of unknown origin</li>
<li>Disable hidden filename extensions</li>
<li>Keep all applications (including your operating system) patched</li>
<li>Turn off your computer or disconnect from the network when not in use</li>
<li>Disable Java, JavaScript, and ActiveX if possible</li>
<li>Disable scripting features in email programs</li>
<li>Make regular backups of critical data</li>
<li>Make a boot disk in case your computer is damaged or compromised</li>
<li>Turn off file and printer sharing on the computer.</li>
<li>Install a personal firewall on the computer.</li>
<li>Install anti-virus and anti-spyware software and ensure it is configured to automatically update when you are connected to the Internet</li>
<li>Ensure the anti-virus software scans all e-mail attachments</li>
<li>Install McAfee Site Advisor, WOT, or a similar browser add-on</li>
</ul>
<p>Be proactive when it comes to your computer’s security; make sure you have adequate software based protection to reduce the chances that your machine will become infected.</p>
<p>If you missed "Rogue Security Software on the Rise – What You Need to Know Now!" you can read it <a href="http://billmullins.wordpress.com/2008/02/12/rogue-security-software-on-the-rise-%E2%80%93-what-you-need-to-know-now/" target="_blank">here</a>.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Pay Pal's Security Questioned, Yet Again]]></title>
<link>http://oregonnerd.wordpress.com/?p=33</link>
<pubDate>Mon, 19 May 2008 12:54:19 +0000</pubDate>
<dc:creator>oregonnerd</dc:creator>
<guid>http://oregonnerd.wordpress.com/?p=33</guid>
<description><![CDATA[This time it&#8217;s demonstrably, as you can see here, although as the article is careful to point ]]></description>
<content:encoded><![CDATA[<p>This time it's demonstrably, as you can see <a title="here" href="http://www.theregister.co.uk/2008/05/16/paypal_page_succumbs_to_xss/" target="_self">here</a>, although as the article is careful to point out the weakness hasn't been successfully used as yet.  (Then again, over the years there have been at least 50 eBay stories I've happened upon that somehow never hit the major press.)</p>
<p> </p>
<p>I'm also going to correct something I said recently.  Spybot S &#38; D evidently no longer measures up, as shown by some recent reputable reviews.   If you use <a title="Zone Alarm" href="http://www.zonealarm.com/store/content/dotzone/freeDownloads.jsp;jsessionid=Ix3NHwVmRSAI5NkzYQdc5mzq5NpFEjQJtlVocZEFGkfkll0bHmfJ!664872986!-1062696903!7551!7552!NONE?dc=12bms&#38;ctry=US&#38;lang=en" target="_self">ZoneAlarm</a> and <a title="AVG" href="http://free.grisoft.com/" target="_self">AVG</a> you're pretty well covered; I'm actually using <a title="RuBotted" href="http://www.ghacks.net/2008/01/17/trend-micro-rubotted/" target="_self">RuBotted</a> to cover for rootkits (note this is a beta and not for the faint of heart) and then a suite.</p>
<p> </p>
<p>--Glenn</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[BugCON]]></title>
<link>http://virtualgeeks.wordpress.com/?p=407</link>
<pubDate>Tue, 13 May 2008 23:47:53 +0000</pubDate>
<dc:creator>virtualgeeks</dc:creator>
<guid>http://virtualgeeks.wordpress.com/?p=407</guid>
<description><![CDATA[
BugCON busca reunir a todos los investigadores, desarrolladores y aficionados relacionados al área]]></description>
<content:encoded><![CDATA[<p style="text-align:center;"><img class="aligncenter" src="http://virtualgeeks.files.wordpress.com/2008/05/bugcon-1.png" alt="" /></p>
<p>BugCON busca reunir a todos los investigadores, desarrolladores y aficionados relacionados al área de la seguridad informática y ofrecerles un foro en donde puedan mostrar sus últimas investigaciones en:</p>
<ul>
<li>Técnicas de explotación</li>
<li>Técnicas de intrusión</li>
<li>Prevención de incidentes</li>
<li>Rootkits</li>
<li>Friki stuff</li>
</ul>
<p>El Call For Papers esta abierto, no esperes mas y envia tus propuestas. Estas serán analizadas por un equipo técnico quienes seleccionarán las mejores para presentarlas en BugCON.</p>
<p>La primer edición de BugCON se celebra en instalaciones del Instituto Politécnico Nacional. En modalidades de "non-conferences" de una hora dividas en dos auditorios; uno de ellos dedicado a temas white hat y otro a temas black hat.</p>
<p>Habra conexión inalambrica, concursos y demás cosas de interes, no puedes faltar.</p>
<p>Espero poder asistir al evento para poder comentarles</p>
<p>Desde su pagina oficial <a href="http://zonartm.org/BugCON/index.html">BugCON</a></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Malware by Proxy - Fake Search Engine Results]]></title>
<link>http://billmullins.wordpress.com/?p=393</link>
<pubDate>Thu, 08 May 2008 16:46:18 +0000</pubDate>
<dc:creator>billmullins</dc:creator>
<guid>http://billmullins.wordpress.com/?p=393</guid>
<description><![CDATA[ For the past several months I’ve been watching closely, as the pace of Blog and Internet Forum de]]></description>
<content:encoded><![CDATA[<p><a href="http://billmullins.files.wordpress.com/2008/05/windowslivewritermalwarebyproxyfakesearchengineresults-b28fantivirus3.jpg"><img style="border-right:0;border-top:0;border-left:0;border-bottom:0;margin:0 5px 0 0;" src="http://billmullins.files.wordpress.com/2008/05/windowslivewritermalwarebyproxyfakesearchengineresults-b28fantivirus-thumb1.jpg" alt="" width="163" height="92" align="left" /></a> For the past several months I’ve been watching closely, as the pace of Blog and Internet Forum debate has been escalating regarding fake search engines results and malware.</p>
<p>Recent news on this issue from Panda Security’s Oxygen 3 E-bulletin on IT security, indicates that Cyber-crooks are unrelenting in their chase to infect web search results. According to Panda “there is a steady increase in the use of custom-built websites designed to drop malicious code on computers, or even the manipulation of legitimate pages in order to infect users with malware.”</p>
<p>It was reported recently that fifteen thousand web pages were infected <strong>daily</strong> between January and March of this year; three times the rate of infection noted in the previous year. More disturbing, seventy nine percent of compromised web pages tracked this year were on legitimate web sites; including web sites belonging to Fortune 500 companies, government agencies and ironically, security vendors.</p>
<p>PandaLabs maintains that cyber-crooks have begun to opt for a new technique: the manipulation of search engine results, or seeding websites among the top results returned by these engines. When a potential victim visits one of these sites the likelihood of the downloading of malicious code onto the computer by exploiting existing vulnerabilities is high.</p>
<p>There are several ways that this can occur. Cyber-crooks can exploit vulnerabilities on the server hosting the web page to insert an iFrame, (an HTML element which makes it possible to embed another HTML document inside the main document). The iFrame can then activate the download of malicious code by exploiting additional vulnerabilities on the visiting machine.</p>
<p>Alternatively, a new web page can be built, with iFrames inserted, that can lead to malware downloads. This new web page appears to be legitimate.</p>
<p>Another method is the insertion of false dialogue boxes, fake toolbars, and more on sites; all designed to load destructive malware which could include rootkits, password stealers, Trojan horses, and spam bots.</p>
<p>So what can you do to ensure you are protected, or to reduce the chances you will become a victim?</p>
<p>As I have pointed out in the past, the following are actions you can take to shield your computer system from malware infections:</p>
<ul>
<li>Install an Internet Browser add-on such as <a href="http://www.mywot.com/en/download/ff" target="_blank">WOT</a> which provides detailed test results on a site’s safety; protecting you from security threats including spyware, adware, spam, viruses, browser exploits, and online scams.</li>
<li>Don’t open unknown email attachments</li>
<li>Don’t run programs of unknown origin</li>
<li>Disable hidden filename extensions</li>
<li>Keep all applications (including your operating system) patched</li>
<li>Turn off your computer or disconnect from the network when not in use</li>
<li>Disable Java, JavaScript, and ActiveX if possible</li>
<li>Disable scripting features in email programs</li>
<li>Make regular backups of critical data</li>
<li>Make a boot disk in case your computer is damaged or compromised</li>
<li>Turn off file and printer sharing on the computer</li>
<li>Install a personal firewall on the computer</li>
<li>Install anti-virus and anti-spyware software and ensure it is configured to automatically update when you are connected to the Internet</li>
<li>Ensure the anti-virus software scans all e-mail attachments</li>
</ul>
<p>Be proactive when it comes to your computer’s security; make sure you have adequate software based protection to reduce the chances that your machine will become infected.</p>
<p><strong>The free software listed below, in my view, provides better than average malware protection.</strong></p>
<p><a href="http://www.avast.com" target="_blank">avast! 4 Home Edition</a></p>
<p>This anti virus app is a real fighter, scanning files on demand and on access, including email attachments. Let’s you know when it detects mal-ware through its shield function. An important feature is a boot-time scan option which removes mal-ware that can’t be removed any other way.</p>
<p><a href="http://www.lavasoftusa.com" target="_blank">Ad-Aware 2007</a></p>
<p>In my view, Ad-Aware 2007 Free is the best free spyware and adware remover available. It does a relatively good job of protecting against known data-mining, Trojans, dialers, malware, browser hijackers and tracking components. The only downside with the free version; real-time protection is not included.</p>
<p><a href="http://www.threatfire.com" target="_blank">ThreatFire 3</a></p>
<p>ThreatFire 3 blocks mal-ware, including zero-day threats, by analyzing program behavior and it does a stellar job. Again, this is one of the security applications that forms part of my front line defenses. I have found it to have high success rate at blocking mal-ware based on analysis of behavior. Highly recommend this one!</p>
<p><a href="http://www.comodogroup.com" target="_blank">Comodo Firewall Pro</a></p>
<p>The definitive free firewall, Comodo Firewall protects your system by defeating hackers and restricting unauthorized programs from accessing the Internet. I have been using this application for 6 months and I continue to feel very secure. It resists being forcibly terminated and it works as well, or better, than any firewall I’ve paid for. This is one I highly recommend. Amazing that it’s free!</p>
<p><a href="http://www.winpatrol.com" target="_blank">WinPatrol</a></p>
<p>Do you want to get a better understanding of what programs are being added to your computer? Then WinPatrol is the program for you. With WinPatrol, in your system tray, you can monitor system areas that are often changed by malicious programs. You can monitor your startup programs and services, cookies and current tasks. Should you need to, WinPatrol allows you to terminate processes and enable, or disable, startup programs. There are additional features that make WinPatrol a very powerful addition to your security applications.</p>
<p><a href="http://www.sandboxie.com" target="_blank">Sandboxie</a></p>
<p>Surfing the Internet without using Sandboxie is, to me, like jumping out of an airplane without a parachute. Deadly! This application creates a “Sandboxed” protected environment on your machine within which you browse the net. Data that is written to your hard drive is simply eliminated, (or not, your choice), when the sandbox is closed. Utilizing this application allows you to surf the web without the risk of infecting your system with mal-ware or other nasties. This is another security application I have been using for over 6 months and it has yet to let me down. Highly recommended.</p>
<p><a href="http://www.snoopfree.com" target="_blank">Snoop Free Privacy Shield</a></p>
<p>Snoop Free Privacy Shield is a powerful application that guards your keyboard, screen and open windows from all spy software. I have been using this application for quite some time, and I have been amazed at the number of programs that have requested access to my keyboard and screen; particularly, programs that I am in the process of installing. If you’re serious about privacy, this is a must have addition to your security toolbox.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Symantec coupons - Offer Expires 06/30/08]]></title>
<link>http://andypopps.wordpress.com/?p=3</link>
<pubDate>Wed, 07 May 2008 13:02:11 +0000</pubDate>
<dc:creator>andypopps</dc:creator>
<guid>http://andypopps.wordpress.com/?p=3</guid>
<description><![CDATA[Symantec coupons
Save $5 on Norton AntiVirus 10.0 for Macintosh when purchased via the US store! Cli]]></description>
<content:encoded><![CDATA[<p>Symantec coupons</p>
<p>Save $5 on Norton AntiVirus 10.0 for Macintosh when purchased via the US store! <a href="http://send.onenetworkdirect.net/z/1136/CD96751/">Click Here</a><br />
<a href="http://send.onenetworkdirect.net/z/17796/CD96751/"><img src="http://send.onenetworkdirect.net/42/96751/17796/" border="0" alt="" /></a></p>
<p><a href="http://send.onenetworkdirect.net/z/17796/CD96751/">Save 10% on pcAnywhere</a><br />
Save 10 % of on pcAnywhere products by entering the following coupon code: 08EPPromo.    Offer Expires 07/01/08</p>
<p>Coupon Code: <a href="http://send.onenetworkdirect.net/z/17796/CD96751/">08EPPromo</a><br />
<a href="http://send.onenetworkdirect.net/z/17798/CD96751/"><img src="http://send.onenetworkdirect.net/42/96751/17798/" border="0" alt="" /></a></p>
<p><a href="http://send.onenetworkdirect.net/z/17798/CD96751/">Save 10% on Ghost Solutions Suite</a><br />
Save 10% on Ghost Solutions Suite 2.0 by entering the following coupon code:  08EPPromo  Available in all countries  Offer Expires 07/01/08</p>
<p>Coupon Code: <a href="http://send.onenetworkdirect.net/z/17798/CD96751/">08EPPromo</a><br />
<a href="http://send.onenetworkdirect.net/z/18992/CD96751/"><img src="http://send.onenetworkdirect.net/42/96751/18992/" border="0" alt="" /></a></p>
<p><a href="http://send.onenetworkdirect.net/z/18992/CD96751/">10% off Norton AntiVirus 2008</a><br />
United States - Norton AntiVirus 2008 - 10% off Coupon Offer Expires 06/30/08</p>
<p>Coupon Code: <a href="http://send.onenetworkdirect.net/z/18992/CD96751/">10NAV08</a><br />
<a href="http://send.onenetworkdirect.net/z/18993/CD96751/"><img src="http://send.onenetworkdirect.net/42/96751/18993/" border="0" alt="" /></a></p>
<p><a href="http://send.onenetworkdirect.net/z/18993/CD96751/">Norton Internet Security 2008</a><br />
United States - Norton Internet Security 2008 Offer Expires 06/30/08</p>
<p>Coupon Code: <a href="http://send.onenetworkdirect.net/z/18993/CD96751/">15NIS08</a><br />
<a href="http://send.onenetworkdirect.net/z/18994/CD96751/"><img src="http://send.onenetworkdirect.net/42/96751/18994/" border="0" alt="" /></a></p>
<p><a href="http://send.onenetworkdirect.net/z/18994/CD96751/">$10 off of Norton Internet Security 2008</a><br />
United States - Norton Internet Security 2008 - $10 off  Offer Expires 06/30/08</p>
<p>Coupon Code: <a href="http://send.onenetworkdirect.net/z/18994/CD96751/">10offNIS08</a><br />
<a href="http://send.onenetworkdirect.net/z/19853/CD96751/"><img src="http://send.onenetworkdirect.net/42/96751/19853/" border="0" alt="" /></a></p>
<p><a href="http://send.onenetworkdirect.net/z/19853/CD96751/">Save 15% on Norton Internet Security 2008</a><br />
Australia - Norton Internet Security 2008 - 15% off Coupon Offer Expires 06/30/08</p>
<p>Coupon Code: <a href="http://send.onenetworkdirect.net/z/19853/CD96751/">15NIS08</a><br />
<a href="http://send.onenetworkdirect.net/z/19854/CD96751/"><img src="http://send.onenetworkdirect.net/42/96751/19854/" border="0" alt="" /></a></p>
<p><a href="http://send.onenetworkdirect.net/z/19854/CD96751/">$10 off on Norton Internet Security 2008</a><br />
Australia - Norton Internet Security 2008 - $10 off Coupon Offer Expires 06/30/08</p>
<p>Coupon Code: <a href="http://send.onenetworkdirect.net/z/19854/CD96751/">10offNIS08</a><br />
<a href="http://send.onenetworkdirect.net/z/19855/CD96751/"><img src="http://send.onenetworkdirect.net/42/96751/19855/" border="0" alt="" /></a></p>
<p><a href="http://send.onenetworkdirect.net/z/19855/CD96751/">10% off on Norton Internet Security 2008</a><br />
Australia - Norton Ghost 14.0 - 10% off Coupon Offer Expires 06/30/08</p>
<p>Coupon Code: <a href="http://send.onenetworkdirect.net/z/19855/CD96751/">10NGHST08</a><br />
<a href="http://send.onenetworkdirect.net/z/19856/CD96751/"><img src="http://send.onenetworkdirect.net/42/96751/19856/" border="0" alt="" /></a></p>
<p><a href="http://send.onenetworkdirect.net/z/19856/CD96751/">10% off Norton AntiVirus 11 for Mac</a><br />
Australia - Norton AntiVirus 11 for Mac - 10% off Coupon Offer Expires 06/30/08</p>
<p>Coupon Code: <a href="http://send.onenetworkdirect.net/z/19856/CD96751/">10NAVMAC08</a><br />
<a href="http://send.onenetworkdirect.net/z/19857/CD96751/"><img src="http://send.onenetworkdirect.net/42/96751/19857/" border="0" alt="" /></a></p>
<p><a href="http://send.onenetworkdirect.net/z/19857/CD96751/">10% off Norton AntiBot</a><br />
Australia - Norton AntiBot - 10% off Coupon Offer Expires 06/30/08</p>
<p>Coupon Code: <a href="http://send.onenetworkdirect.net/z/19857/CD96751/">10NAB08</a><br />
<a href="http://send.onenetworkdirect.net/z/19930/CD96751/"><img src="http://send.onenetworkdirect.net/42/96751/19930/" border="0" alt="" /></a></p>
<p><a href="http://send.onenetworkdirect.net/z/19930/CD96751/">10% off Norton AntiVirus 2008</a><br />
UK - Norton AntiVirus - 10% Discount Offer Expires 06/30/08</p>
<p>Coupon Code: <a href="http://send.onenetworkdirect.net/z/19930/CD96751/">10NAV08</a><br />
<a href="http://send.onenetworkdirect.net/z/19931/CD96751/"><img src="http://send.onenetworkdirect.net/42/96751/19931/" border="0" alt="" /></a></p>
<p><a href="http://send.onenetworkdirect.net/z/19931/CD96751/">15% off Norton Internet Security</a><br />
UK - Norton Internet Security - 15% Discount Offer Expires 06/30/08</p>
<p>Coupon Code: <a href="http://send.onenetworkdirect.net/z/19931/CD96751/">15NIS08</a><br />
<a href="http://send.onenetworkdirect.net/z/19932/CD96751/"><img src="http://send.onenetworkdirect.net/42/96751/19932/" border="0" alt="" /></a></p>
<p><a href="http://send.onenetworkdirect.net/z/19932/CD96751/">£10 off Norton Internet Security 2008</a><br />
UK - Norton Internet Security 2008 - $10 Discount Offer Expires 06/30/08</p>
<p>Coupon Code: <a href="http://send.onenetworkdirect.net/z/19932/CD96751/">10offNIS08</a><br />
<a href="http://send.onenetworkdirect.net/z/19933/CD96751/"><img src="http://send.onenetworkdirect.net/42/96751/19933/" border="0" alt="" /></a></p>
<p><a href="http://send.onenetworkdirect.net/z/19933/CD96751/">10% off Norton Ghost 14.0</a><br />
UK - Norton Ghost 14.0 - 10% Discount Offer Expires 06/30/08</p>
<p>Coupon Code: <a href="http://send.onenetworkdirect.net/z/19933/CD96751/">10NGHST08</a><br />
<a href="http://send.onenetworkdirect.net/z/19934/CD96751/"><img src="http://send.onenetworkdirect.net/42/96751/19934/" border="0" alt="" /></a></p>
<p><a href="http://send.onenetworkdirect.net/z/19934/CD96751/">10% off Norton AntiBot</a><br />
UK - Norton AntiBot - 10% Discount Offer Expires 06/30/08</p>
<p>Coupon Code: <a href="http://send.onenetworkdirect.net/z/19934/CD96751/">10NAB08</a><br />
<a href="http://send.onenetworkdirect.net/z/19935/CD96751/"><img src="http://send.onenetworkdirect.net/42/96751/19935/" border="0" alt="" /></a></p>
<p><a href="http://send.onenetworkdirect.net/z/19935/CD96751/">10% off Norton AntiVirus 11 for Mac</a><br />
UK - Norton AntiVirus 11 for Mac - 10% Discount Offer Expires 06/30/08</p>
<p>Coupon Code: <a href="http://send.onenetworkdirect.net/z/19935/CD96751/">10NAVMAC08</a><br />
<a href="http://send.onenetworkdirect.net/z/20236/CD96751/"><img src="http://send.onenetworkdirect.net/42/96751/20236/" border="0" alt="" /></a></p>
<p><a href="http://send.onenetworkdirect.net/z/20236/CD96751/">10% off of Norton AntiBot</a><br />
United States - Norton AntiBot - 10% off Coupon Offer Expires 06/30/08</p>
<p>Coupon Code: <a href="http://send.onenetworkdirect.net/z/20236/CD96751/">10NAB08</a><br />
CART LINK <a href="http://send.onenetworkdirect.net/z/21675/CD96751/">Click Here</a></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Geek+Spyware*]]></title>
<link>http://techpaul.wordpress.com/2008/05/02/geekspyware/</link>
<pubDate>Fri, 02 May 2008 16:50:49 +0000</pubDate>
<dc:creator>techpaul</dc:creator>
<guid>http://techpaul.wordpress.com/2008/05/02/geekspyware/</guid>
<description><![CDATA[I want to apologize to you in advance for a word I will use in this blog from time to time, and that]]></description>
<content:encoded><![CDATA[<p>I want to apologize to you in advance for a word I will use in this blog from time to time, and that word is "geek."</p>
<p>When I was a boy--many years ago now--"geek" was a completely pejorative and insulting word. A "geek" was typically a socially inept, small, quiet, know-it-all (who usually wore glasses) kid who couldn't connect his bat with the softest-thrown baseball or catch a football to save his life...and he used big words <em>all </em>the time. Perhaps in your day you referred to 'him' as a Pointdexter, nerd, dork, or wimp. Back then there was no doubt or question about it--"geek" was a put-down: a derogatory statement. Period.</p>
<p>Today, I proudly declare: I <strong><em>am</em></strong> a geek. When I do, I am not broadcasting my pride in my inability to catch a football. (I can catch; and, even throw a tight spiral.) I am saying that I'm "into" computers and electronic gadgets, and I know a little about how they work.</p>
<p>At some point and time our common usage of the word "geek" has changed. It is no longer used strictly as a 'slam' and a put-down (however, if that <em>is </em>your intent, I believe the other words I listed above are still 100% negative...although Bill Gates may have softened the word "nerd" some...). If, in the course of reading this blog, you see me use the word "geek"--please rest assured that I am <span style="text-decoration:underline;"><a href="http://techpaul.wordpress.com/2007/09/08/virtual-machines-and-you/">a</a>lways</span> using it with the <em>nicest</em> of meanings. I even use "geek" as a compliment. Really.</p>
<p><span style="text-decoration:underline;">Tip of the day:</span> A reader<em> </em>mentioned in a comment to yesterday's post on defragmention that <a href="http://techpaul.wordpress.com/2007/09/08/virtual-machines-and-you/">spyware</a>, if it gets onto and runs on your machine, will cause it to (amongst other unpleasant things!) suffer performance degradation and make it run slower. I intend to spend a fair amount of time discussing <a href="http://en.wikipedia.org/wiki/Category:Malware">malware</a>, and spyware in particular, and how you can combat and remove it. I will return to this topic in the future. But for today I just want to make this point: If you connect to the Web, you <strong>need</strong> to run anti-spyware programs. Notice I that I wrote <em>programs.</em> Plural.</p>
<p>That fact is, no one anti-spyware application is 100% effective at stopping and removing spyware. There are many anti-spyware programs available and some are more effective than others. Some are great at stopping keylogger's but fall down when it comes to Trojan Horses, and others are visa-versa...as an example. So I strongly recommend running two anti-spyware's, in the hopes that one will catch what the other missed. (There are many free anti-spyware applications [and some are adware <em>disguised</em> as anti-spyware, (called "<a title="read my article on rogue anti-spyware programs" href="http://techpaul.wordpress.com/2008/02/06/is-that-anti-spyware-program-really-spyware/" target="_blank">rogue apps</a>")] available. For my more detailed descriptions and a fuller listing of free anti-spyware tools, click <a href="http://aplusca.com/uselinks2.htm">here</a>.) I cannot stress to you strongly enough to install and <strong>run</strong> some kind of anti-spyware program...and preferably, <em>two.</em> In that vein, today I will provide not one, but two, Today's free links.</p>
<p><span style="text-decoration:underline;">Today's free link #1:</span> <a href="http://www.lavasoftusa.com/products/ad_aware_free.php">AdAware SE Personal</a> from Lavasoft. "<em>Ad-Aware 2007 Free remains the most popular anti-spyware product for computer users around the world, with nearly one million downloads every week. Our free anti-spyware version provides you with advanced protection against spyware</em>..."</p>
<p><span style="text-decoration:underline;">Today's free link #2:</span> <a href="http://www.tenebril.com/consumer/spyware/spycatcher-express.php">SpyCatcher Express</a> from Tenebril. From site: "<em>Allows novice PC users to remove aggressive spyware . Stops next-generation, mutating spyware. Blocks reinstallation of aggressive spyware. Removes spyware safely and automatically</em>."</p>
<p>*Original posting 6/13/07</p>
<p>Copyright 2007-8 © Tech Paul. All rights reserved.<a title="post to jaanix" href="http://jaanix.com/post?url=&#38;title=&#38;tags=&#38;note=ℑ="><img style="vertical-align:middle;border-width:0;" src="http://s3.amazonaws.com/jaanix/img/jaanix_mini.png" alt="jaanix" height="16" /> post to jaanix</a></p>
<div></div>
<p><span class="sbmLink"></p>
<table border="0" cellspacing="1" cellpadding="1">
<tbody>
<tr>
<td class="sbmText">Share this post :</td>
<td class="sbmDim"><a class="sbmDim" title="Post it to backflip" href="http://www.backflip.com/add_page_pop.ihtml?url=http://techpaul.wordpress.com/2008/05/02/geekspyware/&#38;title=Tech--for Everyone Geek+spyware" target="_blank"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/backflip4.png" border="0" alt="" /></a></td>
<td class="sbmDim"><a class="sbmDim" title="Post it to buddymark" href="http://buddymarks.com/s_add_bookmark.php?bookmark_url=http://techpaul.wordpress.com/2008/05/02/geekspyware/&#38;bookmark_title=Tech--for Everyone Geek+spyware" target="_blank"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/buddymar4.png" border="0" alt="" /></a></td>
<td class="sbmDim"><a class="sbmDim" title="Post it to del.icio.us" href="http://del.icio.us/post?url=http://techpaul.wordpress.com/2008/05/02/geekspyware/&#38;;title=Tech--for Everyone Geek+spyware" target="_blank"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliciou4.png" border="0" alt="" /></a></td>
<td class="sbmDim"><a class="sbmDim" title="Post it to del.iri.ous!" href="http://de.lirio.us/bookmarks/sbmtool?action=add&#38;address=http://techpaul.wordpress.com/2008/05/02/geekspyware/&#38;title=Tech--for Everyone Geek+spyware" target="_blank"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliriou4.png" border="0" alt="" /></a></td>
<td class="sbmDim"><a class="sbmDim" title="Post it to digg" href="http://digg.com/submit?phase=2&#38;url=http://techpaul.wordpress.com/2008/05/02/geekspyware/&#38;title=Tech--for Everyone Geek+spyware" target="_blank"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/digg14.png" border="0" alt="" /></a></td>
<td class="sbmDim"><a class="sbmDim" title="Post it to furl" href="http://www.furl.net/store?s=f&#38;to=0&#38;u=http://techpaul.wordpress.com/2008/05/02/geekspyware/&#38;ti=Tech--for Everyone Geek+spyware" target="_blank"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/furl4.png" border="0" alt="" /></a></td>
<td class="sbmDim"><a class="sbmDim" title="Post it to reddit!" href="http://reddit.com/submit?url=http://techpaul.wordpress.com/2008/05/02/geekspyware/&#38;title=Tech--for Everyone Geek+spyware" target="_blank"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/reddit4.png" border="0" alt="" /></a></td>
<td class="sbmDim"><a class="sbmDim" title="Post it to shadow" href="http://www.shadows.com/bookmark/saveLink.rails?page=http://techpaul.wordpress.com/2008/05/02/geekspyware/&#38;title=Tech--for Everyone Geek+spyware" target="_blank"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/shadows6.png" border="0" alt="" /></a></td>
<td class="sbmDim"><a class="sbmDim" title="Post it to technorati!" href="http://technorati.com/faves/?add=http://techpaul.wordpress.com/2008/05/02/geekspyware/&#38;title=Tech--for Everyone Geek+spyware" target="_blank"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/technora4.png" border="0" alt="" /></a></td>
<td class="sbmDim"><a class="sbmDim" title="Post it to wists" href="http://www.wists.com/?action=add&#38;url=http://techpaul.wordpress.com/2008/05/02/geekspyware/&#38;title=Tech--for Everyone Geek+spyware" target="_blank"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/wists9.png" border="0" alt="" /></a></td>
<td class="sbmDim"><a class="sbmDim" title="Post it to yahoo!" href="http://myweb.yahoo.com/myresults/bookmarklet?u=http://techpaul.wordpress.com/2008/05/02/geekspyware/&#38;t=Tech--for Everyone Geek+spyware" target="_blank"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/yahoo9.png" border="0" alt="" /></a></td>
<td class="sbmDim"><a class="sbmDim" title="Post it to email" href="mailto:&#38;body=I%20was%20reading%20this%20article%20and%20thought%20that%20you%20might%20like%20this:http://techpaul.wordpress.com/2008/05/02/geekspyware/&#38;subject=Tech--for%20Everyone%20Geek+spyware" target="_blank"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/mail69854.gif" border="0" alt="" /></a></td>
</tr>
</tbody>
</table>
<p> </p>
<p></span></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Free HJT Log Analyzing and Malware Cleaning Services again available on Smokey's]]></title>
<link>http://smokeys.wordpress.com/?p=73</link>
<pubDate>Fri, 25 Apr 2008 01:07:18 +0000</pubDate>
<dc:creator>Smokey</dc:creator>
<guid>http://smokeys.wordpress.com/?p=73</guid>
<description><![CDATA[After a period of a closed HJT Log Analyzing/Malware Cleaning Forum I am pleased to announce that fr]]></description>
<content:encoded><![CDATA[<p>After a period of a closed <a href="http://www.smokey-services.eu/forum/viewforum.php?f=5">HJT Log Analyzing/Malware Cleaning Forum</a> I am pleased to announce that from now on <a href="http://www.smokey-services.eu/forum/index.php">Smokey's Security Forums</a> offer again <strong>HijackThis Log Analyzing &#38; Malware Cleaning related Support, Help and Advice.</strong></p>
<p>This (free) help will only be provided by <strong>full qualified HJT Analyzers/Malware Hunters</strong>, this for reason of maintaining the high standars of my forums: Help and Support <strong>only by qualified people.</strong></p>
<p>Only registered forum members will be helped with solving their malware (related) problems.<br />
Registering on my forum is for free.</p>
<p>Register on Smokey's <a href="http://www.smokey-services.eu/forum/ucp.php?mode=register">here.</a><br />
Ask HJT Log Analyzing/Malware Related Help <a href="http://www.smokey-services.eu/forum/viewforum.php?f=5">here.</a></p>
<p>Smokey</p>
<p><a href="http://www.smokey-services.eu/forum/index.php">Site Owner Smokey's Security Forums</a><br />
<a href="http://asap.maddoktor2.com/">Site Member ASAP - Alliance of Security Analysis Professionals</a></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Υποκριτές και Φαρισαίοι..]]></title>
<link>http://stardust30.wordpress.com/?p=7</link>
<pubDate>Fri, 04 Apr 2008 11:52:58 +0000</pubDate>
<dc:creator>stardust30</dc:creator>
<guid>http://stardust30.wordpress.com/?p=7</guid>
<description><![CDATA[Ακούσατε- ακούσατε,
Σύμφωνα με την ιστοσελίδα:
http://arstechn]]></description>
<content:encoded><![CDATA[<p>Ακούσατε- ακούσατε,<br />
Σύμφωνα με την ιστοσελίδα:<br />
http://arstechnica.com/news.ars/post/20080331-sony-bmgs-hypocrisy-company-busted-for-using-warez.html<br />
και την αντίστοιχη ελληνική του Pc-magazine :<br />
http://www.e-pcmag.gr/modules/news/article.php?storyid=4143<br />
H Sony BMG εγκατέστησε το πρόγραμμα  Ideal Migration της PointDev ΧΩΡΙΣ να αγοράσει τις απαιτούμενες άδειες χρήσης.<br />
Η παραπάνω εταιρεία είναι από τους μεγαλυτερους πολέμιους της πειρατείας..<br />
Επίσης η παραπάνω εταιρεία έχει βάλει σε μουσικά της cd πρόγραμμα που επεμβαίνει στον υπολογιστή έτσι ώστε να κάνεις μόνο ένα αντίγραφο του cd.Το πρόγραμμα αυτό όμως αφήνει κάποιες πύλες ανοικτές στον υπολογιστή κι έτσι ένας έμπειρος hacker μπορεί να μπει στον υπολογιστή σου και να τον κάνει ό,τι αυτός θέλει (να αντιγράψει αρχεία,να τα σβήσει). Το κορυφαίο είναι ότι είναι πολύ δύσκολο (εώς αδύνατο) να το απεγκαταστήσεις.<br />
Μπράβο στη Sony! Εύγε! Θα ακολουθήσουμε το παράδειγμά της!</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Storm Botnets – The Computational Power of Super Computers]]></title>
<link>http://billmullins.wordpress.com/?p=344</link>
<pubDate>Thu, 03 Apr 2008 18:27:37 +0000</pubDate>
<dc:creator>billmullins</dc:creator>
<guid>http://billmullins.wordpress.com/?p=344</guid>
<description><![CDATA[I must admit that I get very tired of opening my email accounts only to see spam email after spam em]]></description>
<content:encoded><![CDATA[<p><a href="http://bp3.blogger.com/_mEJMxFc2RRo/R_UbGkxqnPI/AAAAAAAAANg/gi0T5b6irgI/s1600-h/Storm3.jpg"><img src="http://bp3.blogger.com/_mEJMxFc2RRo/R_UbGkxqnPI/AAAAAAAAANg/gi0T5b6irgI/s400/Storm3.jpg" style="float:left;cursor:pointer;margin:0 10px 10px 0;" border="0" /></a>I must admit that I get very tired of opening my email accounts only to see spam email after spam email, reminding me that enlargement, growth, and natural male enhancement techniques can all be mine if I just click on the enclosed link.</p>
<p class="MsoBodyText">It didn’t take long to establish that the driving force behind the majority of these annoying emails is the well established Storm bot network. Security experts maintain that the Storm bot network continues to be leased to online pharmacy spammers.</p>
<p class="MsoBodyText">The Storm Trojan which first appeared in Europe more than a year ago, takes its name from the content contained in emails relating to extreme bad weather striking parts of Europe at that time.</p>
<p class="MsoBodyText">Those users who were enticed into clicking on links enclosed in the email were directed to a web site that included malevolent code designed to infect Windows PCs with the aim of turning the now infected machine into a spam bot.</p>
<p class="MsoBodyText">The initial success and the continued implementation, in various forms, of this highly sophisticated malware attack has led to the creation of a botnet of unprecedented proportions; a colossal spam-producing network.</p>
<p class="MsoBodyText">According to Bradley Anstis, Vice-President of Products for <a href="http://www.marshal.com/index.asp" target="_blank">Marshal</a>, a leader in integrated email and Internet content security solutions, the Storm botnet was responsible for 20 per cent of all spam email sent in the first quarter of 2008.</p>
<p class="MsoBodyText">Marshall is currently monitoring five botnets, including the Storm botnet, believed to be responsible for approximately 75 per cent of all spam currently in circulation. Heavily promoted products on all of these botnets tend to be male enlargement drugs, replica watches and sexually explicit material. The strategy employed by the owners of these botnets is particular ingenious since there’s a strategic crossover with the products being promoted by all five of these botnets.<span>    </span></p>
<p class="MsoBodyText">Frighteningly it is accurate to say that these botnets are getting increasingly larger every day. According to the U.S. Federal Bureau of Investigation, there are at least 1 million botnetted computers in the U.S.<span>  </span>Worst, some security firms estimate that currently there are as many as 10 million botnetted machines worldwide. In fact, some researchers believe that this may just be the part of the iceberg we can see above the waterline.</p>
<p class="MsoBodyText">Not surprisingly such large numbers of infected machines have produced some of the most powerful networked computer systems in the world. As a result, many industry analysts are convinced malware and phishing attacks from these botnets can be expected to increase in frequency. <span> </span></p>
<p class="MsoBodyText">A more frightening possibility involves the potential power of these botnets being turned against secure computer systems in the government, commercial, and industrial sectors in brute-force attacks. Some have argued a coordinated attack, such as the one we witnessed last year against Estonia’s infrastructure, is inevitable.</p>
<p class="MsoBodyText">For your own benefit it’s obviously important to keep your computer from becoming infected and becoming a part of this problem. Perhaps it’s less obvious that we all share a responsibly to help protect other computer users on the Internet from becoming infected. The way to do that is to ensure that you are part of the solution; not part of the problem created by running an insecure machine, or by engaging in unsafe surfing practices.</p>
<p class="MsoBodyText">As I have pointed out in the past on this Blog, the following are actions you can take to protect your computer system:</p>
<p class="MsoListBullet2"><!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span>        </span></span></span><!--[endif]-->When surfing the web: Stop. Think. Click<br />
<!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span>        </span></span></span><!--[endif]-->Don’t open unknown email attachments<br />
<!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span>        </span></span></span><!--[endif]-->Don’t run programs of unknown origin<br />
<!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span>        </span></span></span><!--[endif]-->Disable hidden filename extensions<br />
<!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span>        </span></span></span><!--[endif]-->Keep all applications (including your operating system) patched<br />
<!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span>        </span></span></span><!--[endif]-->Turn off your computer or disconnect from the network when not in use<br />
<!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span>        </span></span></span><!--[endif]-->Disable Java, JavaScript, and ActiveX if possible<br />
<!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span>        </span></span></span><!--[endif]-->Disable scripting features in email programs<br />
<!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span>        </span></span></span><!--[endif]-->Make regular backups of critical data<br />
<!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span>        </span></span></span><!--[endif]-->Make a boot disk in case your computer is damaged or compromised<br />
<!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span>        </span></span></span><!--[endif]-->Turn off file and printer sharing on the computer.<br />
<!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span>        </span></span></span><!--[endif]-->Install a personal firewall on the computer.<br />
<!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span>        </span></span></span><!--[endif]-->Install anti-virus/anti-spyware software and ensure it is configured to automatically update when you are connected to the Internet<br />
<!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span>        </span></span></span><!--[endif]-->Ensure the anti-virus software scans all e-mail attachments<br />
<!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span>        </span></span></span><!--[endif]-->Install <a href="http://www.siteadvisor.com/download/ff.html" target="_blank">McAfee Site Advisor</a>, <a href="http://www.mywot.com/en/download/ff" target="_blank">WOT</a> (my recommendation), or a similar browser add-on</p>
<p><span class="sbmLink"></p>
<table cellpadding="1" cellspacing="1">
<tr>
<td class="sbmText">Share this post :</td>
<td class="sbmDim"><a href="http://del.icio.us/post?url=http://billmullins.blogspot.com/2008/04/storm-botnets-computational-power-of.html&#38;;title=Storm%20Botnets%20%E2%80%93%20The%20Computational%20Power%20of%20Super%20Computers" target="_blank" title="Post it to del.icio.us" class="sbmDim"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliciou4.png" border="0" /></a></td>
<td class="sbmDim"><a href="http://digg.com/submit?phase=2&#38;url=http://billmullins.blogspot.com/2008/04/storm-botnets-computational-power-of.html&#38;title=Storm%20Botnets%20%E2%80%93%20The%20Computational%20Power%20of%20Super%20Computers" target="_blank" title="Post it to digg" class="sbmDim"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/digg14.png" border="0" /></a></td>
<td class="sbmDim"><a href="http://www.furl.net/store?s=f&#38;to=0&#38;u=http://billmullins.blogspot.com/2008/04/storm-botnets-computational-power-of.html&#38;ti=Storm%20Botnets%20%E2%80%93%20The%20Computational%20Power%20of%20Super%20Computers" target="_blank" title="Post it to furl" class="sbmDim"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/furl4.png" border="0" /></a></td>
<td class="sbmDim"><a href="https://favorites.live.com/quickadd.aspx?marklet=1&#38;mkt=en-us&#38;url=http://billmullins.blogspot.com/2008/04/storm-botnets-computational-power-of.html&#38;title=Storm%20Botnets%20%E2%80%93%20The%20Computational%20Power%20of%20Super%20Computers" target="_blank" title="Post it to live" class="sbmDim"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/live4.png" border="0" /></a></td>
<td class="sbmDim"><a href="http://www.spurl.net/spurl.php?v=3&#38;url=http://billmullins.blogspot.com/2008/04/storm-botnets-computational-power-of.html&#38;title=Storm%20Botnets%20%E2%80%93%20The%20Computational%20Power%20of%20Super%20Computers" target="_blank" title="Post it to spurl" class="sbmDim"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/spurl8.png" border="0" /></a></td>
<td class="sbmDim"><a href="http://technorati.com/faves/?add=http://billmullins.blogspot.com/2008/04/storm-botnets-computational-power-of.html&#38;title=Storm%20Botnets%20%E2%80%93%20The%20Computational%20Power%20of%20Super%20Computers" target="_blank" title="Post it to technorati!" class="sbmDim"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/technora4.png" border="0" /></a></td>
<td class="sbmDim"><a href="http://myweb.yahoo.com/myresults/bookmarklet?u=http://billmullins.blogspot.com/2008/04/storm-botnets-computational-power-of.html&#38;t=Storm%20Botnets%20%E2%80%93%20The%20Computational%20Power%20of%20Super%20Computers" target="_blank" title="Post it to yahoo!" class="sbmDim"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/yahoo9.png" border="0" /></a></td>
<td class="sbmDim"><a href="mailto:&#38;body=I%20was%20reading%20this%20article%20and%20thought%20that%20you%20might%20like%20this:http://billmullins.blogspot.com/2008/04/storm-botnets-computational-power-of.html&#38;subject=Storm%20Botnets%20%E2%80%93%20The%20Computational%20Power%20of%20Super%20Computers" target="_blank" title="Post it to email" class="sbmDim"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/mail69854.gif" border="0" /></a></td>
</tr>
</table>
<p></span></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Book of Month: April]]></title>
<link>http://y2h4ck.wordpress.com/?p=64</link>
<pubDate>Thu, 03 Apr 2008 12:57:19 +0000</pubDate>
<dc:creator>y2h4ck</dc:creator>
<guid>http://y2h4ck.wordpress.com/?p=64</guid>
<description><![CDATA[


Rootkits: Subverting the Windows Kernel


Author: Greg Hoglund, Jamie Butler


Publisher: Addison]]></description>
<content:encoded><![CDATA[<p><img src="http://y2h4ck.wordpress.com/files/2008/04/rootkits.jpg" alt="rootkits.jpg" /></p>
<table class="style_tables" border="0" cellpadding="0" cellspacing="0">
<tr>
<td class="title_book"><a href="http://www.amazon.com/gp/product/0321294319?ie=UTF8&#38;tag=orkspace-20&#38;linkCode=as2&#38;camp=1789&#38;creative=9325&#38;creativeASIN=0321294319" target="_blank">Rootkits: Subverting the Windows Kernel</a></td>
</tr>
<tr>
<td class="desc_book"><b>Author: </b>Greg Hoglund, Jamie Butler</td>
</tr>
<tr>
<td class="desc_book"><b>Publisher: </b>Addison-Wesley Professional</td>
</tr>
<tr>
<td class="desc_book"><b>Year: </b>2005</td>
</tr>
<tr>
<td class="desc_book"><b>Pages: </b>352</td>
</tr>
<tr>
<td class="desc_book"><b>Amazon's book description: </b>Rootkits are the ultimate backdoor, giving hackers ongoing and virtually undetectable access to the systems they exploit. Now, two of the world's leading experts have written the first comprehensive guide to rootkits: what they are, how they work, how to build them, and how to detect them. Rootkit.com's Greg Hoglund and James Butler created and teach Black Hat's legendary course in rootkits. In this book, they reveal never-before-told offensive aspects of rootkit technology--learn how attackers can get in and stay in for years, without detection.</td>
</tr>
</table>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake/Redirected Search Engine Results = Malware]]></title>
<link>http://billmullins.wordpress.com/?p=330</link>
<pubDate>Thu, 27 Mar 2008 16:55:47 +0000</pubDate>
<dc:creator>billmullins</dc:creator>
<guid>http://billmullins.wordpress.com/?p=330</guid>
<description><![CDATA[
For the past several months I’ve been watching closely, as more and more Blog discussions have be]]></description>
<content:encoded><![CDATA[<p><a href="http://bp2.blogger.com/_mEJMxFc2RRo/R-vLo0xqnEI/AAAAAAAAAMI/5_AztD6QT7w/s1600-h/Google+malware.jpg"><img src="http://bp2.blogger.com/_mEJMxFc2RRo/R-vLo0xqnEI/AAAAAAAAAMI/5_AztD6QT7w/s400/Google+malware.jpg" style="float:left;cursor:pointer;margin:0 10px 10px 0;" border="0" /></a><br />
For the past several months I’ve been watching closely, as more and more Blog discussions have been taking place around the topic of search engines results and malware.</p>
<p>Recent news on this issue from Panda Security’s Oxygen 3 E-bulletin on IT security, indicates that Cyber-crooks are unrelenting in their chase to infect web search results. According to Panda “there is a steady increase in the use of custom-built websites designed to drop malicious code on computers, or even the manipulation of legitimate pages in order to infect users with malware.”</p>
<p>PandaLabs maintains that cyber-crooks have begun to opt for a new technique: the manipulation of search engine results, or seeding websites among the top results returned by these engines. When a potential victim visits one of these sites the likelihood of the downloading of malicious code onto the computer by exploiting existing vulnerabilities is high.</p>
<p>There are several ways that this can occur. Cyber-crooks can exploit vulnerabilities on the server hosting the web page to insert an iFrame, (an HTML element which makes it possible to embed another HTML document inside the main document). The iFrame can then activate the download of malicious code by exploiting additional vulnerabilities on the visiting machine.</p>
<p>Alternatively, a new web page can be built, with iFrames inserted, that can lead to malware downloads. This new web page appears to be legitimate.</p>
<p>Another method is the insertion of false dialogue boxes, fake toolbars, and more on sites; all designed to load destructive malware which could include rootkits, password stealers, Trojan horses, and spam bots.</p>
<p>For more information on this, and other threats checkout <a href="http://msmvps.com/blogs/spywaresucks/default.aspx">Spyware Sucks</a>, a great Blog that will keep you up to date on the latest risks to your online safety.</p>
<p>So what can you do to ensure you are protected, or to reduce the chances you will become a victim?</p>
<p>As I have pointed out in the past on this Blog, the following are actions you can take to protect your computer system:</p>
<p>• Don’t open unknown email attachments</p>
<p>• Don’t run programs of unknown origin</p>
<p>• Disable hidden filename extensions</p>
<p>• Keep all applications (including your operating system) patched</p>
<p>• Turn off your computer or disconnect from the network when not in use</p>
<p>• Disable Java, JavaScript, and ActiveX if possible</p>
<p>• Disable scripting features in email programs</p>
<p>• Make regular backups of critical data</p>
<p>• Make a boot disk in case your computer is damaged or compromised</p>
<p>• Turn off file and printer sharing on the computer.</p>
<p>• Install a personal firewall on the computer.</p>
<p>• Install anti-virus and anti-spyware software and ensure it is configured to automatically update when you are connected to the Internet.</p>
<p>• Ensure the anti-virus software scans all e-mail attachments.</p>
<p>Be proactive when it comes to your computer’s security; make sure you have adequate software based protection to reduce the chances that your machine will become infected.</p>
<p>The free software listed below, in my view, provides better than average malware protection.</p>
<p>avast! 4 Home Edition</p>
<p><a href="http://www.avast.com/">www.avast.com</a></p>
<p>This anti virus app is a real fighter, scanning files on demand and on access, including email attachments. Let’s you know when it detects mal-ware through its shield function. An important feature is a boot-time scan option which removes mal-ware that can’t be removed any other way.</p>
<p>AVG Anti-Virus Free Edition</p>
<p><a href="http://www.free.grisoft.com/">www.free.grisoft.com</a></p>
<p>Similarly, this program scans files on access, on demand, and on schedule. Scans email; incoming and outgoing. For those on Vista, your in luck, it’s Vista-ready. I have been using this application since its release and it now forms part of my front line defenses. I recommend this one highly.</p>
<p>Ad-Aware 2007</p>
<p><a href="http://www.lavasoftusa.com/">www.lavasoftusa.com</a></p>
<p>In my view, Ad-Aware 2007 Free is the best free spyware and adware remover available. It does a relatively good job of protecting against known data-mining, Trojans, dialers, malware, browser hijackers and tracking components. The only downside with the free version; real-time protection is not included.</p>
<p>ThreatFire 3</p>
<p><a href="http://www.threatfire.com/">www.threatfire.com</a></p>
<p>ThreatFire 3 blocks mal-ware, including zero-day threats, by analyzing program behavior and it does a stellar job. Again, this is one of the security applications that forms part of my front line defenses. I have found it to have high success rate at blocking mal-ware based on analysis of behavior. Highly recommend this one!</p>
<p>Comodo Firewall Pro</p>
<p><a href="http://www.comodogroup.com/">www.comodogroup.com</a></p>
<p>The definitive free firewall, Comodo Firewall protects your system by defeating hackers and restricting unauthorized programs from accessing the Internet. I have been using this application for 6 months and I continue to feel very secure. It resists being forcibly terminated and it works as well, or better, than any firewall I’ve paid for. This is one I highly recommend. Amazing that it’s free!</p>
<p>WinPatrol</p>
<p><a href="http://www.winpatrol.com/">www.winpatrol.com</a></p>
<p>Do you want to get a better understanding of what programs are being added to your computer? Then WinPatrol is the program for you. With WinPatrol, in your system tray, you can monitor system areas that are often changed by malicious programs. You can monitor your startup programs and services, cookies and current tasks. Should you need to, WinPatrol allows you to terminate processes and enable, or disable, startup programs. There are additional features that make WinPatrol a very powerful addition to your security applications.</p>
<p>Sandboxie</p>
<p><a href="http://www.sandboxie.com/">www.sandboxie.com</a></p>
<p>Surfing the Internet without using Sandboxie is, to me, like jumping out of an airplane without a parachute. Deadly! This application creates a “Sandboxed” protected environment on your machine within which you browse the net. Data that is written to your hard drive is simply eliminated, (or not, your choice), when the sandbox is closed. Utilizing this application allows you to surf the web without the risk of infecting your system with mal-ware or other nasties. This is another security application I have been using for over 6 months and it has yet to let me down. Highly recommended.</p>
<p>Snoop Free Privacy Shield</p>
<p><a href="http://www.snoopfree.com/">www.snoopfree.com</a></p>
<p>Snoop Free Privacy Shield is a powerful application that guards your keyboard, screen and open windows from all spy software. I have been using this application for quite some time, and I have been amazed at the number of programs that have requested access to my keyboard and screen. Particularly, programs that I am in the process of installing. If you’re serious about privacy, this is a must have addition to your security toolbox.</p>
<p><span class="sbmLink"></p>
<table cellpadding="1" cellspacing="1">
<tr>
<td class="sbmText">Share this post :</td>
<td class="sbmDim"><a href="http://del.icio.us/post?url=http://billmullins.blogspot.com/2008/03/fakeredirected-search-engine-results.html&#38;;title=Fake/Redirected%20Search%20Engine%20Results%20=%20Malware" target="_blank" title="Post it to del.icio.us" class="sbmDim"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliciou4.png" border="0" /></a></td>
<td class="sbmDim"><a href="http://digg.com/submit?phase=2&#38;url=http://billmullins.blogspot.com/2008/03/fakeredirected-search-engine-results.html&#38;title=Fake/Redirected%20Search%20Engine%20Results%20=%20Malware" target="_blank" title="Post it to digg" class="sbmDim"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/digg14.png" border="0" /></a></td>
<td class="sbmDim"><a href="http://www.furl.net/store?s=f&#38;to=0&#38;u=http://billmullins.blogspot.com/2008/03/fakeredirected-search-engine-results.html&#38;ti=Fake/Redirected%20Search%20Engine%20Results%20=%20Malware" target="_blank" title="Post it to furl" class="sbmDim"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/furl4.png" border="0" /></a></td>
<td class="sbmDim"><a href="https://favorites.live.com/quickadd.aspx?marklet=1&#38;mkt=en-us&#38;url=http://billmullins.blogspot.com/2008/03/fakeredirected-search-engine-results.html&#38;title=Fake/Redirected%20Search%20Engine%20Results%20=%20Malware" target="_blank" title="Post it to live" class="sbmDim"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/live4.png" border="0" /></a></td>
<td class="sbmDim"><a href="http://www.spurl.net/spurl.php?v=3&#38;url=http://billmullins.blogspot.com/2008/03/fakeredirected-search-engine-results.html&#38;title=Fake/Redirected%20Search%20Engine%20Results%20=%20Malware" target="_blank" title="Post it to spurl" class="sbmDim"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/spurl8.png" border="0" /></a></td>
<td class="sbmDim"><a href="http://technorati.com/faves/?add=http://billmullins.blogspot.com/2008/03/fakeredirected-search-engine-results.html&#38;title=Fake/Redirected%20Search%20Engine%20Results%20=%20Malware" target="_blank" title="Post it to technorati!" class="sbmDim"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/technora4.png" border="0" /></a></td>
<td class="sbmDim"><a href="http://myweb.yahoo.com/myresults/bookmarklet?u=http://billmullins.blogspot.com/2008/03/fakeredirected-search-engine-results.html&#38;t=Fake/Redirected%20Search%20Engine%20Results%20=%20Malware" target="_blank" title="Post it to yahoo!" class="sbmDim"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/yahoo9.png" border="0" /></a></td>
<td class="sbmDim"><a href="mailto:&#38;body=I%20was%20reading%20this%20article%20and%20thought%20that%20you%20might%20like%20this:http://billmullins.blogspot.com/2008/03/fakeredirected-search-engine-results.html&#38;subject=Fake/Redirected%20Search%20Engine%20Results%20=%20Malware" target="_blank" title="Post it to email" class="sbmDim"><img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/mail69854.gif" border="0" /></a></td>
</tr>
</table>
<p></span></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Free Spyware Doctor – Excellent Secondary On-Demand Malware Scanner]]></title>
<link>http://billmullins.wordpress.com/?p=328</link>
<pubDate>Thu, 27 Mar 2008 15:31:17 +0000</pubDate>
<dc:creator>billmullins</dc:creator>
<guid>http://billmullins.wordpress.com/?p=328</guid>
<description><![CDATA[  
As I wrote recently, Spyware Terminator is my current application of choice for active real-time ]]></description>
<content:encoded><![CDATA[<p><!--[if gte mso 9]&#38;gt;     Normal   0                         MicrosoftInternetExplorer4   &#38;lt;![endif]--> <!--  /* Font Definitions */  @font-face 	{font-family:Wingdings; 	panose-1:5 0 0 0 0 0 0 0 0 0; 	mso-font-charset:2; 	mso-generic-font-family:auto; 	mso-font-pitch:variable; 	mso-font-signature:0 268435456 0 0 -2147483648 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} a:link, span.MsoHyperlink 	{color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{color:purple; 	text-decoration:underline; 	text-underline:single;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1371765594; 	mso-list-type:hybrid; 	mso-list-template-ids:-32635604 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;} @list l0:level1 	{mso-level-number-format:bullet; 	mso-level-text:; 	mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in; 	font-family:Symbol;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&#38;gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman";}  &#38;lt;![endif]--></p>
<p class="MsoNormal"><img src="http://billmullins.wordpress.com/files/2008/03/spyware-doctor.jpg" alt="spyware-doctor.jpg" align="left" />As I wrote recently, Spyware Terminator is my current application of choice for active real-time protection in the spyware wars that we, as computer users, are involved in any time we log onto the Internet.</p>
<p class="MsoNormal">Having tested virtually all of the major anti-spyware apps over the last year or more, I’ve settled, for now, on Spyware Terminator primarily due to this strong real-time protection against spyware, adware, Trojans, key-loggers, home page hijackers and other malware threats.</p>
<p class="MsoNormal">&#160;</p>
<p class="MsoNormal">As we all know however, there is no one anti-malware tool that is likely to identify and remove all of the millions of rogue malware that infest the cyber world. So to ensure maximum safety, if that’s even possible, it’s important to have layered defenses in the ongoing fight against malware.</p>
<p class="MsoNormal">&#160;</p>
<p class="MsoNormal">An excellent choice, as a secondary line of defense, is Spyware Doctor Starter Edition from <a href="http://www.pctools.com/spyware-doctor/" target="_blank">PC Tools</a>. http://www.pctools.com/spyware-doctor/<span>  </span>This free version of the award winning program, with its easy to use interface, is used by millions of people worldwide to protect their computers; it’s reported there are a million+ additional downloads every week.</p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal">I have been able to establish through various forums and user groups, that the free version and the paid version have identical detection rates. However, the most important real-time protection functions are disabled in the free version.</p>
<p class="MsoNormal">&#160;</p>
<p class="MsoNormal">File protection is the only real time protection that operates in the free version and unfortunately, this level of real-time protection is inadequate in the current Internet environment.</p>
<p class="MsoNormal">&#160;</p>
<p class="MsoNormal">I would not recommend then, that you use this free version of Spyware Doctor as a stand alone security application because it simply will not offer you adequate protection. Instead, use it only as an on-demand scanner.</p>
<p class="MsoNormal">&#160;</p>
<p class="MsoNormal">Despite this real-time protection shortcoming in the free version, Spyware Doctor has an excellent reputation as a first class security application, and I highly recommend that you add this free version to your security toolbox to be used as a secondary line of defense.</p>
<p class="MsoNormal">&#160;</p>
<p class="MsoNormal"><b>Quick Facts:</b></p>
<p class="MsoNormal">&#160;</p>
<ul style="margin-top:0;" type="disc">
<li class="MsoNormal">Spyware      protection</li>
<li class="MsoNormal">Adware      protection</li>
<li class="MsoNormal">Scan      and Remove</li>
<li class="MsoNormal">Smart      Updates</li>
<li class="MsoNormal">Limited      OnGuard Protection<span>   </span>Note: Be      particularly aware of this limitation.</li>
</ul>
<p class="MsoNormal">&#160;</p>
<p class="MsoNormal">You can download the free Spyware Doctor Starter Edition via <a href="http://pack.google.com/intl/en/pack_installer.html?hl=en&#38;gl=ca" target="_blank">Google Pack</a>, or better yet download this application at <a href="http://www.download.com/Spyware-Doctor-Starter-Edition/3000-8022_4-10704508.html" target="_blank">Download.com</a> and save yourself some hassle.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Ubuntu 8.04 Hardy Heron Alpha 6 Ya disponible]]></title>
<link>http://genlinux.wordpress.com/?p=127</link>
<pubDate>Sun, 09 Mar 2008 03:53:40 +0000</pubDate>
<dc:creator>Cross</dc:creator>
<guid>http://genlinux.wordpress.com/?p=127</guid>
<description><![CDATA[Aquí os traigo la última Alpha pública de Ubuntu. Hablando de novedades lo nuevo que podemos apre]]></description>
<content:encoded><![CDATA[<p>Aquí os traigo la última Alpha pública de <a href="http://www.ubuntu.com/" target="_blank">Ubuntu</a>. Hablando de novedades lo nuevo que podemos apreciar<a href="http://genlinux.wordpress.com/?s=Ubuntu+8.04+Alpha"> frente a las otras Alphas que ya os he comentado</a> estas son las nuevas;</p>
<h3>Integración de ActiveDirectory</h3>
<p><a href="http://likewisesoftware.com/products/likewise_open/" target="_blank">Likewise Open</a> está disponible atraves del repositorio "Universe". Esto permite la integración de Ubuntu con una red de Active Directory. Los usuarios pueden usar sus credenciales AD (ActiveDirectory) para registrarse desde sus Ubuntu's y acceder a cualquier servicio kerberizado que ofreca un servidor Ubuntu.</p>
<h3>Soporte iSCSI</h3>
<p>iSCSI ha sido totalmetne integrado con el kernel, permitiendo a ubuntu montar objetivos iSCSI como un dispositivo más.<br />
iSCSI está disponible en <a href="http://www.ubuntu.com/products/whatisubuntu/serveredition" target="_blank">la versión de Servidor de Ubuntu</a> si iscsi=true (Verdadero) en la linea de comandos del kernel en el principio de la instalación.</p>
<h3>Protección de Memoria</h3>
<p>Se han añadido algunos checkeos adicionales para que así /dev/mem y /dev/kmem solo puedan usarse para acceder al dispositivo de memoria. Estos cambios ayudaran a defendernos contra los <a href="http://es.wikipedia.org/wiki/Rootkit" target="_blank">RootKits</a> y otros códigos maliciosos.<br />
Los 64k más bajos de memoria no podrán ser accesibles por defecto. Esto ayudará a defendernos contra códigos maliciosos que intentan hacer uso de los bugs (Fallos) dee el kernel y convertirlos en vulnerabilidades de seguridad.<br />
Aplicaciones compiladas como Position Independent Executables (PIE &#38;&#38; Ejecutables de Posición Independiente) son ahora puestos en localizaciones inpredecibles haciendo más dificil explotar vulnerabilidades de seguridad.</p>
<p>Aquí podeís encontrar los enlaces para Ubuntu y sus distribuciones hermanas:</p>
<p><a href="http://cdimage.ubuntu.com/releases/hardy/alpha-6/">http://cdimage.ubuntu.com/releases/hardy/alpha-6/</a> (Ubuntu)<br />
<a href="http://cdimage.ubuntu.com/kubuntu/releases/hardy/alpha-6/">http://cdimage.ubuntu.com/kubuntu/releases/hardy/alpha-6/</a> (Kubuntu)<br />
<a href="http://cdimage.ubuntu.com/kubuntu-kde4/releases/hardy/alpha-6/">http://cdimage.ubuntu.com/kubuntu-kde4/releases/hardy/alpha-6/</a> (Kubuntu with KDE4)<br />
<a href="http://cdimage.ubuntu.com/edubuntu/releases/hardy/alpha-6/">http://cdimage.ubuntu.com/edubuntu/releases/hardy/alpha-6/</a> (Edubuntu)<br />
<a href="http://cdimage.ubuntu.com/jeos/releases/hardy/alpha-6/">http://cdimage.ubuntu.com/jeos/releases/hardy/alpha-6/</a> (Ubuntu JeOS)<br />
<a href="http://cdimage.ubuntu.com/xubuntu/releases/hardy/alpha-6/">http://cdimage.ubuntu.com/xubuntu/releases/hardy/alpha-6/</a> (Xubuntu)<br />
<a href="http://cdimage.ubuntu.com/gobuntu/releases/hardy/alpha-6/">http://cdimage.ubuntu.com/gobuntu/releases/hardy/alpha-6/</a> (Gobuntu)<br />
<a href="http://cdimage.ubuntu.com/ubuntustudio/releases/hardy/alpha-6/">http://cdimage.ubuntu.com/ubuntustudio/releases/hardy/alpha-6/</a> (UbuntuStudio)</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Los "rootkits", el malware silente]]></title>
<link>http://prismadigital.wordpress.com/?p=475</link>
<pubDate>Mon, 25 Feb 2008 18:13:14 +0000</pubDate>
<dc:creator>Radamés</dc:creator>
<guid>http://prismadigital.wordpress.com/?p=475</guid>
<description><![CDATA[El &#8220;rootkit&#8221; es una modalidad de malware  donde éste se aloja en el sistema de una for]]></description>
<content:encoded><![CDATA[<p>El "rootkit" es una modalidad de malware  donde éste se aloja en el sistema de una forma que parece "invisible" para el Windows Explorer, el Task Manager y otras herramientas de detección.  Esta característica los hace sumamente peligrosos y se necesitan aplicaciones que sean específicamente para detectarlos y removerlos.  Algunos de estas aplicaciones son:</p>
<ul>
<li><a href="http://www.free.grisoft.com/">AVG Anti-rootkit<br />
</a></li>
<li><a href="http://www.download.com/RootkitRevealer/3000-2248_4-10543917.html">Microsoft Rootkit Revealer</a></li>
<li><a href="http://www.majorgeeks.com/Icesword_d5199.html">IceSword</a></li>
<li><a href="http://www.gmer.net/files.php">GMER</a></li>
</ul>
<p><img src="http://regeditexe.files.wordpress.com/2007/08/rootkit.jpg" align="bottom" height="176" width="169" /><br />
Fuente:  <a href="http://billmullins.wordpress.com/2008/02/25/rootkits-kernel-mode-trojans-%e2%80%93-are-you-protected/">Billmullins</a></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Rootkits - Kernel Mode Trojans – Are You Protected?]]></title>
<link>http://billmullins.wordpress.com/?p=282</link>
<pubDate>Mon, 25 Feb 2008 17:40:26 +0000</pubDate>
<dc:creator>billmullins</dc:creator>
<guid>http://billmullins.wordpress.com/?p=282</guid>
<description><![CDATA[A rootkit is a malware program, or a combination of malware programs, designed to take low level con]]></description>
<content:encoded><![CDATA[<p class="MsoNormal"><img src="http://billmullins.wordpress.com/files/2008/02/rootkits.jpg" alt="rootkits.jpg" align="left" />A rootkit is a malware program, or a combination of malware programs, designed to take low level control of a computer system. Often, they are Trojans or Keyloggers as well.</p>
<p class="MsoNormal">Techniques used to hide rootkits include, concealing running processes from monitoring programs, and hiding files or system data from the operating system. In other words, the rootkit’ files and processes will be hidden in Explorer, Task Manager, and other detection tools.</p>
<p class="MsoNormal">It’s easy to see then, that if a threat uses rootkit technology to hide, it is going to be very difficult to find.</p>
<p class="MsoNormal">All power to the major anti-malware companies though; many have come up with a free serviceable solution to rootkits. Enter the Rootkit detector which will give you the tool to find and delete rootkits, and to uncover the threat rootkits may be hiding.</p>
<p class="MsoNormal">Generally, rootkit detectors are capable of the following type of scans, although it is important to note that not all scan, or handle rootkits, in precisely the same way.</p>
<p class="MsoBodyText" style="margin-left:0.5in;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">        </span></span></span><!--[endif]-->hidden processes</p>
<p class="MsoBodyText" style="margin-left:0.5in;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">        </span></span></span><!--[endif]-->hidden threads</p>
<p class="MsoBodyText" style="margin-left:0.5in;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">        </span></span></span><!--[endif]-->hidden modules</p>
<p class="MsoBodyText" style="margin-left:0.5in;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">        </span></span></span><!--[endif]-->hidden services</p>
<p class="MsoBodyText" style="margin-left:0.5in;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">        </span></span></span><!--[endif]-->hidden files</p>
<p class="MsoBodyText" style="margin-left:0.5in;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">        </span></span></span><!--[endif]-->hidden Alternate Data Streams</p>
<p class="MsoBodyText" style="margin-left:0.5in;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">        </span></span></span><!--[endif]-->hidden registry keys</p>
<p class="MsoBodyText" style="margin-left:0.5in;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">        </span></span></span><!--[endif]-->drivers hooking SSDT</p>
<p class="MsoBodyText" style="margin-left:0.5in;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">        </span></span></span><!--[endif]-->drivers hooking IDT</p>
<p class="MsoBodyText" style="margin-left:0.5in;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">        </span></span></span><!--[endif]-->drivers hooking IRP calls</p>
<p class="MsoBodyText">If you think you might have hidden malware on your system, I recommend that you run multiple rootkit detectors. Much like anti-spyware programs, no one program catches everything. To be safe, I use each of the rootkit detectors listed below on my machines.</p>
<p class="MsoNormal"><b>The following are a number of free rootkit detectors available for download.</b></p>
<p class="MsoNormal"><b>AVG Anti-rootkit</b></p>
<p class="MsoNormal">The AVG Anti-rootkit download is a tiny 414kb, and it installs quickly. Its straightforward, no-frills interface allows a regular search and an in-depth search.<span> </span></p>
<p class="MsoNormal">Download here: <a href="http://www.free.grisoft.com" target="_blank">www.free.grisoft.com</a></p>
<p class="MsoNormal"><b>Microsoft Rootkit Revealer</b></p>
<p class="MsoNormal">Microsoft Rootkit Revealer is an advanced root kit detection utility. Its output lists Registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit. According to Microsoft, Rootkit Revealer successfully detects all persistent rootkits published at www.rootkit.com, including AFX, Vanquish and Hacker Defender.</p>
<p class="MsoNormal">Download here: <a href="http://www.download.com/RootkitRevealer/3000-2248_4-10543917.html" target="_blank">www.download.com</a></p>
<p class="MsoNormal"><b>IceSword</b></p>
<p class="MsoNormal">IceSword is a very powerful software application that will scan your computer for rootkits. It also displays hidden processes and resources on your system that you would be unlikely to find in any other Windows Explorer like program. Because of the amount of information presented in the application, please note that IceSword was designed for more advanced users.</p>
<p class="MsoNormal">Download here: <a href="http://www.majorgeeks.com/Icesword_d5199.html" target="_blank">www.majorgeeks.com</a></p>
<p class="MsoNormal"><b>GMER</b></p>
<p class="MsoNormal">This freeware tool is essentially a combination of Sysinternals’ Rootkit Revealer and Process Explorer. The program can list running processes, modules and Windows services, in addition to scanning for the presence of rootkits.</p>
<p class="MsoNormal">Download here: <a href="http://www.gmer.net/files.php" target="_blank">www.gmer.net/files.php</a></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[The Paradox Created by Firewalls/Security Applications - Drive-by Downloads]]></title>
<link>http://billmullins.wordpress.com/?p=271</link>
<pubDate>Sun, 17 Feb 2008 20:09:34 +0000</pubDate>
<dc:creator>billmullins</dc:creator>
<guid>http://billmullins.wordpress.com/?p=271</guid>
<description><![CDATA[Your Firewall and Security Applications provide the ultimate 