Guide to Internet Security

DR STRANGELOVE

Registered User
Forum Member
Mar 13, 2003
27,355
51
0
Toronto, Canada
Copied and pasted....


More and More computers im seeing just aren't secure, so i made this guide up. It includes the links and the directions. Lets also make this thread for posting other security tips and things.



SLEEKLUXURY'S GUIDE TO COMPUTER SECUIRTY ?SLEEKLUXURY2004

Ok.......so now you set up your DSL or Cable modem even ISDN, & even if you don't and your on dial-up, your ready to surf the web, at high speeds or low speeds, and not give a care about the stuff out there, just search the net right? wrong. You may want to do that, but the truth is the world isn't all nice, there are bad people out there hackers, and if your unprotected from worms, Trojans, and viruses, its like jumping into a swarm of bees stark naked, your going to get stung, bad. So here are some security tips you should try before you go out and surf the net, carefree:

1. WINDOWS UPDATE
You should make sure your Operating System is up-to-date, meaning having the latest patches, if your not sure if your Operating System is up-to-date, then Click Here and Click "Scan for Updates" and install any install any "Critical Updates and Services Packs" found. The windows XP and Driver Updates are not needed, but are recommended. Reboot the PC if you have to.


2. ANTI-VIRUS
This is probably the most important thing next to having a firewall, an Anti-Virus subscription. The web is not all good, malicious code, Trojans, and viruses can be installed without you even knowing it 98% of the time. You could just be surfing the net and catch a Worm. That's why Virus scanners are important, some are free and some aren't, here are some good ones.

NOT FREE:
Norton Anti-Virus? 2004, by Symantec is a reliable, and probably the most common used Virus Scanner out there, it has earned many Virus Bulletin awards for its virus detecting and cleaning excellence. This one is $49.95, or your have the option to buy a bundle for $49.95, yes the same price, that comes with the Norton Anti-Virus? 2004, and:
? Norton? Personal Firewall
? Norton? Privacy Control
? Norton AntiSpam?
? Norton? Parental Control
Downloading after buy from the site is cheaper, and mailing the product is a little more, but it worth it.
FOR MORE INFO ON THIS PRODUCT INCLUDING ITS SPECS:
http://www.symantecstore.com/dr/sat...;CACHE_ID=39910

Mcafee also offers great Virus scanning and cleaning, I have Mcafee and it hasn't ever done me wrong, its help in the hard times a lot, I would recommend this. Prices range from $34.95 to the Pro Version for $59.99 and the security suite for $69.99. Downloading after buy from the site is cheaper, and mailing the product is a little more, but it worth it.
FOR MORE INFO ON THESE PRODUCTS INCLUDING THERE SPECS:
http://us.mcafee.com/root/catalog.asp?catid=av

Free Virus scanners:
There are some free Virus Scanning programs:
AVG offers Virus Protection for free, I have experience with this one as well, and as far as I can see, it works, it picked up a Trojan for me, I found it easy. You get almost all you would with the ones you pay for, Updates, Outlook Integration for protection from email born viruses, and a shield that constantly scans invisibly. You get the basic Interface, and the free version has no Technical Support. They also offer a full version for a little over $33.
http://www.grisoft.com/us/us_dwnl_free.php


Avast 4 Home Edition also offers free Virus Protection for non-commercial uses. I haven't tried this one, but im sure this one is good to. More info can be found at:
http://www.avast.com/i_idt_226.html

AntiVir Personal Edition is free, i haven't used it, but i heard it works well:
http://www.free-av.com/index.htm

There are many other Virus Scanners out there:
http://www.google.com/search?hl=en&...amp;q=antivirus

There are also many online scanners that are updated constantly at least once a day:
Mcafee: http://us.mcafee.com/root/mfs/default.asp?cid=9435 (Mcafee does require that you create a login account but it is free, only hard drive scan)

Trend Micro: http://housecall.trendmicro.com/hou.../start_corp.asp (Free requires no Login, lets you scan floppy, CD/DVD drives, and Hard Drive and can auto clean them)

Bit Defender: http://www.bitdefender.com/scan/Msie/index.php (Free no log in, Scans hard drive, floppy drive, and CD/DVD drives. Also features auto cleaning, archiving scanning, memory scanning and email scanning, and shared document scanning)

Panda Active Scan: http://www.pandasoftware.com/activescan/ (Does require your email address, free with no login, scans compressed files, disinfects files, scan emails, use the heuristic scan technique to detect un-known (in-the-wild) viruses, neutralizes Trojans, Lets you scan any part of the computer that you want to)

Symantec: http://security.symantec.com/sscv6/...e&venid=sym (Free and scans your hard drive for Viruses & Trojans)

RAV online scan: http://www.ravantivirus.com/scan/indexie.php You can input your email address if you want to receive things from them if not you don?t have to, scans emails, folders, documents, or your whole PC, auto cleaning function, scanning of archives, unpacks executables, and smart scan)

3. ***FIREWALL***
Now this is a must if you surf the Internet and don't want your information or Data on your computer to be looked at, if your unprotected, anyone can just see your system, even get a hold of information such as Credit Card Info, steal Private Info, Card Statements, Social Security Info, Tax info. (i.e. Records), and passwords and other Private things, and could even lead to Identity Theft. Here are some Firewalls:

Zone Alarm

Zone Alarm offers a Free firewall and two others for buy, I use the free Firewall, and I find it very useful and it has stopped many things I didn't want from connecting to the Internet. The free one can be found at:
http://www.zonelabs.com/store/conte...lid=zadb_zadown

The ones for sale offer a higher level of security and more options like tracing where the attacks come from. They can also be found at:
http://www.zonelabs.com/store/conte...sku_list_za.jsp

The plus Version which offers more options than the free. The pro version offers the most options including pop-up/ad blocking, cookie control, and cache cleaning. If your not sure which product is right for you, answer some questions at:
http://www.zonelabs.com/store/conte...jsp?lid=pdb_za2
and the page will tell you which one has the options you want. Most likely the Pro version, which I think is the best one.

Mcafee
Mcafee also does Firewalls, I used this once, until my subscription ran out, but if I weren?t lazy, I would go buy this, Mcafee offers tracking and offers a high level of security between the Internet and your Hard-Drive, where all you do is stored.

This Firewall can be found at:
http://us.mcafee.com/root/package.asp?pkgid=103
Check out there Bundled versions to, for more security and better performance.

Symantec's Norton? Personal Firewall 2004 offers a high level of protection from hackers, It keeps hackers from viewing your PC as do all firewalls, and also has ad-blocking, also protects data being sent out via Instant Messengers, and Office Attachments.
Symantec's Norton? Personal Firewall 2004 offers a phenomenal firewall, it can be found at:
http://www.symantec.com/sabu/nis/npf/

FOR MORE FIREWALLS:
http://www.google.com/search?hl=en&...&q=firewall


4. SPYWARE
Alright this is one of the big Privacy issues on the Internet, Spyware, its cookies or a file put on your PC to track or Monitor your Internet Surfing habits, or to send information to the site that put it there on how you use there product or site. Spyware is basically little "Trackers" and if your like me, your don?t want these on your PC they can cause a noticeable slow in internet speeds and can lead to systems crashes. So how do you get rid of this stuff, well thank goodness its easy and free thanks to these programs:

Ad-Aware 6.0 Personal Build 181. This is probably the most used Spyware scanner and cleaner in the world right now, I use it, Who doesn't??? Its a must. Comes with free updates and everything. You can get more information about it and Downloaded it at:
http://www.lavasoftusa.com/

Before you scan with Ad Aware, check for updates of the reference file by using the "web update".

Then ........
Make sure the following settings are made and on -------"ON=GREEN"
From main window :Click "Start" then " Activate in-depth scan"

Then......
Click "Use custom scanning options>Customize" and have these options on: "Scan within archives" ,"Scan active processes?,? Scan registry", "Deep scan registry" ,"Scan my IE Favorites for banned URL" and "Scan my host-files"
 
Last edited:

DR STRANGELOVE

Registered User
Forum Member
Mar 13, 2003
27,355
51
0
Toronto, Canada
Then.....
Go to settings(the gear on top of Ad Aware)>Tweak>Scanning engine and tick "Unload recognized processes during scanning" ...........then........"Cleaning engine" and "Let windows remove files in use at next reboot"

Then...... click "proceed" to save your settings.
SPYBOT SEARCH & DESTROY:
Spybot S&D scans your PC using bots to find things such as dialers, some Trojans, and spyware on your PC. Spybot S &D is easy to run, just be sure to click ?search for updates? and download them. Advanced mode is also handy, with a start-up list, where you can choose witch programs you want to run at start-up and other things such as a secure file shredder that makes sure the files your drag in there and chop away can never be recovered again.
Download from: http://www.safer-networking.org/

HIJACK THIS
This is a program that scans your computer and collects information on what your computer has running. after scanning it creates a log that you can save, if your open the log, copy everything and paste it on this site in a post, someone will be happy to help you out with removal tips. DO NOT CHECK AND REPAIR ANY THING IF YOU ARE UNSURE. YOU CAN CAUSE SERIOUS DAMAGE TO YOUR OPERATING SYSTEM.
It can be downloaded at:
http://mjc1.com/mirror/hjt/
Then just click save log after you have scanned, copy and paste it to a post on to a tech site, and someone will help you to get rid of the bad stuff, just don't delete anything unless you are completely 100% sure. YOU RUN THIS PROGRAM AT YOUR OWN RISK.
You can post the log at Techguy Support Forums:
http://forums.techguy.org/f54/s (Just create a new account, to start you cant just hit "New Thread" at the top right, and then hit "Register"

SPYWARE BLASTER
This is a program that keeps spyware from being installed in the first place, it doesn't clean spyware up. It catches the methods and programs that spyware uses to install itself and terminates the installation of the spyware. Helping to keep your PC spyware free.
It can be found at:
http://www.javacoolsoftware.com/spywareblaster.html
The program is free, but a donation is an option.

Spyware Guard
http://www.wilderssecurity.net/spywareguard.html

This should be used along with Spyware Blaster for the highest security, stops spyware .exe's and .cab's from being executed protects your browser from Hijacking, stops it from being downloaded from Internet Explorer while your surfing.

WHAT IS THIS PROCESS?
Found a process and not sure what in the world it is? LIUtilities has a lists of processes arranged in alphabetical order for you to quickly browse through and get more information on the processes are divided into 3 categories, Security Risks, System Processes, and Applications.
http://www.liutilities.com/products...processlibrary/


Ok, so now you?re all secure right? Good. Good. Now let?s test. First lets go to:
http://security.symantec.com/sscv6/...e&venid=sym
and you can do a Virus check, but the main thing is the internet security scan, scan your computer by clicking start, and see what it comes up with, read the details, and if your unsure, then post a reply right here, and you can get some help.
If you want to run another then Sygate & Security Metrics have one:
SYGATE
http://scan.sygate.com/
If it is unable to find out your computer name and what services you are running, then your good. If it can, your might want to increase the security level.
SECURITY METRICS
Just choose which option you want, server, or home office/personal, and run the scan. It will come up with which ports are in danger, and you can ask for an email recommendation from them on what to do to keep that port from being in danger in the future.

Port Scanners. For testing Internet Security:

http://www.dslreports.com/scan/

http://www.pcflank.com/scanner_s1.htm

POP-UP TEST: Did one of the programs you get have a pop-up blocker, then you can test it at:
http://www.popuptest.com/
If you don?t have one then the google toolbar integrates into Internet Explorer and gives you a search bar and a free pop-up blocker. It can be found at:
http://toolbar.google.com/


Other Recommendations & Software:
Anti-Pop-Up
http://toolbar.google.com/
From google.com is a search bar and also a Pop-Up Ad Blocker, which stops many pop-ups.

AvantBrowser...IE based, with built in Pop-Up Blocker http://www.avantbrowser.com/
More at...
http://forums.techguy.org/t187630/s.html

INTERNET CLEANERS:
MyPrivacy 4.1.9 (FREE)
http://download.com.com/3000-2144-1...tml?tag=lst-0-3
ilSystem Wiper 2.2 (FREE)
http://download.com.com/3000-2144-1...ml?tag=lst-0-19
Washee 1.2 (FREE)
http://download.com.com/3000-2144-1...ml?tag=lst-0-24
Internet Sweeper 1.7.1 (FREE)
http://download.com.com/3000-2144-9...ml?tag=lst-0-14
R-Wipe & Clean 3.0 (15-Day Trial, $28.99 to buy, includes Overwriting of files (Makes them unrecoverable), And also Wipes hard Drive Free Space (Cleans files that you deleted in the pass, beyond recovery) Uses 4 types of Security Levels, Low to Very Secure) If you do the wipe free hard drive space then don?t worry if all of a sudden your hard-drive is all full, the program creates temporary files that are a few gigs, but as soon as it is done it removes them. It is recommended to leave the computer alone when doing this.
http://download.com.com/3000-2144-10247293.html
Alright, well then, now your all secure, and ready to surf the internet, good luck to you, and may you never have a problem with the internet and hackers and other bad things. Thank you.
 

DR STRANGELOVE

Registered User
Forum Member
Mar 13, 2003
27,355
51
0
Toronto, Canada
This advice is reposted from the advice given by Tony Klein, the acknowledged spyware & malware expert who supports many forums on the net.

I have added a few minor updates to it

You usually get infected because your security settings are too low.

Here are a number of recommendations that will help tighten them, and which will contribute to making you a less likely victim:

1) Watch what you download!
Many freeware programs, and P2P programs like Grokster, Imesh, Kazaa and others are amongst the most notorious, come with an enormous amount of bundled spyware that will eat system resources, slow down your system, clash with other installed software, or just plain crash your browser or even Windows itself.

2) Go to IE > Tools > Windows Update > Product Updates, and install ALL Security Updates listed.
It's important to always keep current with the latest security fixes from Microsoft. Install those patches for Internet Explorer, and make sure your installation of Java VM is up-to-date. There are some well known security bugs with Microsoft Java VM which are exploited regularly by browser hijackers.

3) Go to Internet Options/Security/Internet, press 'default level', then OK.
Now press "Custom Level."
In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to 'prompt', and 'Initialize and Script ActiveX controls not marked as safe" to 'disable'.

Now you will be asked whether you want ActiveX objects to be executed and whether you want software to be installed.
Sites that you know for sure are above suspicion can be moved to the Trusted Zone in Internet Option/security.

So why is activex so dangerous that you have to increase the security for it?
When your browser runs an activex control, it is running an executable program. It's no different from doubleclicking an exe file on your hard drive.
Would you run just any random file downloaded off a web site without knowing what it is and what it does?

And some more advice:

4) Install Javacool's SpywareBlaster It will protect you from all spy/foistware in it's database by blocking installation of their ActiveX objects.
Download and install, download the latest updates, and you'll see a list of all spyware programs covered by the program (NOTE: this is NOT spyware found on your computer)
Press "select all", then "kill all checked", and you're done.
The spyware that you told Spywareblaster to set the "kill bit" for won't be a hazard to you any longer.
Although it won't protect you from every form of spyware known to man, it is a very potent extra layer of protection.
Don't forget to check for updates every week or so.

Let's also not forget that SpyBot Search and Destroy has the Immunize feature which works roughly the same way.
It can't hurt to use both.

5) Another brilliant program by Javacool we recommend is SpywareGuard.
It provides a degree of real-time protection solution against spyware that is a great addition to SpywareBlaster's protection method.

An anti-virus program scans files before you open them and prevents execution if a virus is detected - SpywareGuard does the same thing, but for spyware! And you can easily have an anti-virus program running alongside SpywareGuard. It now also features Download Protection and Browser Hijacking Protection!

6) IE-SPYAD puts over 5000 sites in your restricted zone, so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

7) The IE hosts file blocks ads, banners, cookies, web bugs, and even most hijackers. This is accomplished by blocking the Server that supplies these little gems.
Example - the following entry 127.0.0.1 ad.doubleclick.net blocks all files supplied by the DoubleClick Server to the web page you are viewing. This also prevents the server from tracking your movements.It Now includes most major parasites, hijackers and unwanted Search Engines!
In many cases this can speed the loading of web pages by not having to wait for these ads, banners, hit counters, etc. to load.
This also helps to protect your Privacy by blocking servers that track your viewing habits, known as "click-thru tracking".

However as time has progressed the focus of this project has changed from blocking ads/banners to protecting the user from the many parasites that now exist on the Internet. It doesn't serve much purpose if you block the ad banner from displaying, but get hijacked by a parasite from an evil script or download contained on the web site. The object is to surf faster while preserving your Safety, Security and Privacy.

Incidentally, another site with an enormous amount of information on computer security, and which is well worth a visit is http://www.wilders.org/

Finally, after following up on all these recommendations, why not run Jason Levine's Browser Security Tests.
They will provide you with an insight on how vulnerable you might still be to a number of common exploits.

And make sure your Antivirus and firewall is switched on and kept updated
 

DR STRANGELOVE

Registered User
Forum Member
Mar 13, 2003
27,355
51
0
Toronto, Canada
I STRONGLY URGE ALL OF YOU TO SCAN YOUR CPU WITH THE FOLLOWING!!!! Panda Active Scan:


http://www.pandasoftware.com/activescan/
(Does require your email address, free with no login, scans compressed files, disinfects files, scan emails, use the heuristic scan technique to detect un-known (in-the-wild) viruses, neutralizes Trojans, Lets you scan any part of the computer that you want to)
 

DR STRANGELOVE

Registered User
Forum Member
Mar 13, 2003
27,355
51
0
Toronto, Canada
click on SCAN PC, click on NEXT, make up a fake email addy and click SEND, let it download th files, then click on ALL MY COMPUTER!! It will then scan your CPU, some of you will find stuff that is on there that you never thought was present.

I just helped Chrryblstr scan his cpu and Ad-Aware found 98 objects, SPYBOT found about 10 objects, PANDA FOUND 2 trojans and 1 virus, and then with HIJACKTHIS it found the following on CHRRYBLASTR's computer. Here is a link from the source

http://forums.techguy.org/t213506/s.html



First and foremost, get the CoolWebshredder from the site below:

http://www.spywareinfo.com/~merijn/downloads.html

Run it and have it "fix" all identified problems. Then reboot and check and "fix" any entries in the HijackThis Scanlog that remain. Have the browser closed when you click "fix".

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cus...//www.yahoo.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/cus...://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/cus...://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about :blank

O2 - BHO: (no name) - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL

O2 - BHO: (no name) - {43FA5935-E36E-4937-8127-A90191B2EC68} - C:\WINNT\system32\domain11.dll
O2 - BHO: (no name) - {72557F9F-13AE-44C9-B3D7-5091B599027C} - C:\WINNT\system32\smail11.dll

O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL

O4 - HKLM\..\Run: [sysmon] C:\WINNT\system32\sysmon45.exe

Then reboot and delete the sysmon45.exe in c:\winnt\system32.

You may have to have "show hidden files" checked in Folder Options > View to find it.

After this, you need to install, UPDATE, and run Spybot or Ad-aware or both following directions here:

Spybot Instructions and Download
Ad-Aware Home Page and Ad-Aware 6: Reference Guide by Winchester73

To prevent future infections, you should install the ByteVerifier updates from Microsoft Windows Update.

ByteVerifier:

http://support.microsoft.com/default.aspx?kbid=828026
http://www.microsoft.com/technet/tr...in/ms03-011.asp

Another Scanlog should be posted after completing the above.

Also as it is a certainty that these and future infections are likely associated with P2P, that should be uninstalled as well.


not good, but now his CPU runs like an animal

if anyone needs help with HIJACK THIS, please let KMA or myself know and we would be more than willing to help. better yet, look at this page, register and you can ask them for help. The TECH members are very knowledgable and helpful.


http://forums.techguy.org/forumdisplay.php?s=&forumid=54
 
Bet on MyBookie
Top