PDA

View Full Version : How to stop/prevent Computer Virus' 101




Razinhell
10-08-2005, 07:42 AM
figure it would helpful to everyone if we posted a little helper on how to prevent virus' and ad/spy ware from getting on your computer or getting it off your computer.

#1 Preventive measure is to not be connected to the internet directly. 99% of all viruses, worms, Trojan’s are picked up by computers connected directly to the internet. Connected to the internet means you connect your cable/dsl/dial-up modem directly to the back of you computer. In one study they set up 5 different machines (1 apple, 4 windows (1 Win2k, 1 WinXP, 1 WinXP Service pack 2, 1 Win98 (shits and giggles)). It took the windows 2k machines a little over a half an hour to be infected with a virus/worm/trojan. WinXP with service pack 2 faired much better, but it eventually was infected. All the computers were infected at one point.

How to protect yourself:

FIREWALL
Buy your self a router. Don't buy a wireless router unless you really need it or are willing to set up the security protocols. I still wouldn't bother because even the best wireless router can be easily compromised or some loop hole will be discovered and if you don't update the firmware you will be open for attack. Why a router, because it will prevent your computer from being directly connected to the internet. I won't go into details, just update the router every so often and make sure you change the admin password.

Software Firewall ZoneAlarm (Free) Download Here (http://www.zonelabs.com/store/content/catalog/pro ducts/sku_list_za.jsp?dc=12bms&ctry=US&lang=en&lid=dbtopnav_pro) I feel Microsofts Firewall is inadequate. ZoneAlarm is great. It’s a little tough to learn, but basically it will only allow you to connect to the internet with programs you want to use. I.E. if you open your browser for the first time after installing it a flag will pop up saying what program attempted to access the internet and do you wish to allow it. It may be sometimes difficult to run certain games with Zonealarm as the program will be waiting for a internet response and ZoneAlarm is waiting for you to answer a flagged access and you cannot see the flag on your screen. You can configure that program ahead of time to be allowed access so this doesn't happen. Remember to check the box “Remember this program” for programs you use often otherwise ZoneAlarm will become annoying.

VIRUS SCAN A lot of people have a virus scan, but don't maintain the software. If its not up-to-date then it most likely won't be affective. Rarely do hackers use old viruses. They usually change code and improve. If your virus scan isn't aware of the new version it may or may not block it. If you don't want to pay for it then get a free version from Grisoft AVG Free Edition (http://free.grisoft.com/doc/1)
Excellent virus scan and will update automatically everyday. Update the software engine. Besides updates, older versions of Virus scans aren’t updated anymore yet people will still use them. That McAfee Virus Scan 2001 is so old it probably won’t stop 50% of today’s viruses. If you don’t maintain the software then it will do you no good.

UPDATE YOUR SOFTWARE Update everything you use often. Go to Microsoft’s website and update your operating system, update your browser right away especially if you use it to purchase things, update hardware firmware’s from their prospective companies (sometimes updates cause other problems so watch out and sometimes firmware updates clear all settings on routers). You need to make sure everything is up to date. By not updating software you are allowing a loop hole to get into your system. Network Administrators are #1 for not updating their systems so even the professionals have problems with this. I can remember when Apache (Website running software) had a software security loop hole and about what 80% of the internet websites are run on it and so many of them were running old versions and being compromised. It costs lots of money/time to rebuild a company website. Now you have one computer or so to maintain so updating only takes a few minutes.

E-MAIL Don't open attachments, don't click on links within e-mails and always make sure you know who the sender is. Its easy to spoof a sender of e-mail. Don't be fooled, even the least computer savvy person can learn how to spoof an e-mail and proxy it so that you can never find out the originator. E-mail attachments are #1 on the list of infections within network environments. People just open things without thinking. Certain preventative measures can stop them, Most Virus scan software can proxy your e-mail account (Outlook/Endora/Mozilla and such) so that is scans before you see it. AVG has worked very well for me, but even it can miss them so don't let down your guard. Don't click on links within your browser. They can be written to look like this www.yahoo.com (http://www.msn.com) In this case it looks like a link to yahoo, but is really a link to msn.com. Its just one way to fool you to go to a particular website. Don't be fooled. If you want to go to that website then type it in. If its an e-mail that you were expecting, like an activation for a forum you just signed up for, then it will be fine to click through, just don't blindly click on things. Some legitimate programs are built on the same premise as Virus/Worms. Hotbar is an excellent example and i hate this program. It adds a link to an e-mail which when clicked on will install it to your computer. So if you are using Hotbar to spruce up your e-mail messages then you are also sending out links to others and I’m sure they will click on it thinking you sent it. Hotbar is somewhat clear as to what it will do, but people still are curious and once you click it it will try to install itself. It is easy to uninstall and lists itself in your Add/Remove Programs control panel link. Its just another example of e-mails being a compromise to your security. Just be aware what you are doing and don't click on things unless you were expecting that particular e-mail.

Pictures in e-mail.
When you are sent junk mail usually there are pictures embedded within the e-mail. So when you open the e-mail it will also pull the pictures from the originators website. They send out billions of Spam a day. They have no clue on what e-mail addresses are active and will just send them out blindly. When you open an e-mail and the pictures are embedded it will confirm back to them that your e-mail address was active. Its all through code written within the e-mail. Now you will be put on an active list and probably be sent 10 times the amount of junk mail then before. Newer versions of Outlook and other e-mail programs are starting to not download the pictures unless you allow it. I think even Yahoo has stopped the automatic loading of pictures too. Don’t download those pictures unless you know for sure. If you are expecting a dell coupon or weekly flyer from Buy.com then download the pictures.

DON’T BE FOOLED Yeah I know most of you already know this, but don’t give anyone your password, pin # or any personal information. Phishing scams are very abundant and its because people do think the E-bay can’t access their own systems or the bank has no clue as to access your account because they lost your password. I’ll tell you right now that there is no company that cannot access their own systems directly and no they don’t need your access information to look over accounts.

OTHER SOFTWARE
You can use other programs to prevent things from happening or eliminate ad/spy ware from your computer. 2 good programs I know and use are listed below. You cannot depend on 1 program as no program is perfect and some can miss what others do not. Always update these programs otherwise they won’t be efficient in their tasks.

Ad-Aware - http://www.lavasoftusa.com/software/adaware/ - Is a very good and free program. The free version will find programs either running or residing somewhere on your computer. Remember to always do a Full System scan otherwise you may never eliminate the actual programs on your computer. The full version has a pretty good real-time scanner similar to a virus scan. It can prevent the initial infection of ad/spy ware, but its not free. Ad-aware also allows you to quarantine found items so that you can restore them In the event you disable a program you use that required ad bases software.




Razinhell
10-08-2005, 07:43 AM
Spy-bot Search and Destroy – Is a totally free and found at http://www.safer-networking.org/ . This program is totally free so if you are asked to pay for it then you are at the wrong site. This program has also become a target by various pay ad/spy removal software so you can be fooled into thinking you have spy-bot when you are downloading something else. Either way when you install spybot you can update it before the install, getting the most up-to-date version of the engine. Spy-bot backs up your registry and sets a restore point in the event that removal hurts the operating system. Update spy-bot. Spy-bot also includes Tea-timer which is a program that will prevent about 1173 known programs from installing and running. Spy-bot will also prevent registry changes without you knowing. It becomes a little annoying at first, but use it with the knowledge it will prevent some bad things from installing or changing factors. So basically if you were to change your homepage in Internet Explorer it would pop up with a little window asking you if you would like to allow or disallow the change.

Safe Web Purchasing
Some website I have noticed has various pictures of internet watchdog companies. Some have the BBB or better business bureau picture, but aren’t actually signed up with the better business bureau. Some have verisign Logos, but don’t actually have the secure transactions that verisign authenticates for credit card purchasing. All Verisign websites should have a direct link from verisign logo that authenticates that particular website as an up-to-date member of their listings. Almost all of the internet watchdog companies have links through their logos to their websites that are verifiable and can show a member website’s participation. I have seen some verisign websites with the click through that we no longer members of the verisign company listings so who knows what security that website is using. You can always check out a company at one of the various watch dog groups or BBB.
Learn more about
http://www.verisign.com/products-services/security-services/secured-seal/index.html
http://www.bbb.org/


Those are the basic preventative measures to take and you can go with the idea that your are doing the best you can to protect yourself. Please if you have experience with other programs or knowledge or if anything is incorrect tell me and I will fix it. No program is perfect and none will prevent everything even if they say so. Your best bet is to be careful when you surf the web and make sure your computer is up-to-date.

MacDogg
10-08-2005, 08:49 AM
I didn't read all of that but the headers I saw are important to have.
Nice work on this info.

Me, I have RoadRunner, connected to a Netgear cable/dsl router. On this machine I have MS AntiSpyWare, Norton Internet Security 2005, Mozilla Firefox, Windows Firewall OFF and Windows Auto Updates on.

No Google Toolbar, no Ad-Aware, no HiJack this.

The most important thing...don't go to stupid websites. If you need to, use Mozilla, less chance of getting hit. I normally use IE unless I see a link that looks suspicious.

CaNaDiAn GTO
10-08-2005, 08:55 AM
I dont have a firewall or virus protection. I scan for viruses every so often and its clean. #1 rule is Dont download Free pron...If it looks to good to be ture it usually is...Take it from me i know.

TRAMS_AM
10-08-2005, 01:36 PM
Good write up, thanks!

:thumbs:

cali_broker
10-08-2005, 04:03 PM
Excellent.

drowssap
10-08-2005, 05:12 PM
sticky this puppy!

MountainGoat
10-08-2005, 06:44 PM
Or, get a Mac. :) Sorry, had to throw that in.

Seriously -- great suggestions / recommendations. The most important being use your brain and don't ever think you're safe.

Dangasaur
10-08-2005, 07:29 PM
Your activity determines your security. I've run with just a firewall and windows updates for over a year and I got 1 infection due to my sister checking her email on this computer.

YOU are what causes this stuff, I'm tired of the "I didn't do anything" excuse because either you DID do something or you DIDN'T update your shit.

Get Microsoft Anti-Spyware or SpySweeper, both are the best anti-spyware programs out there.

DagYo!
10-09-2005, 01:03 AM
or just make a nice image and don't worry about all that stupid bs. it takes 5 minutes to run a stupid spyware scan. 3 minutes to have a nice fresh windows install with all your programs preinstalled.

http://ghost.radified.com/

RedThunder
10-09-2005, 02:04 AM
Or, get a Mac. :) Sorry, had to throw that in.

Seriously -- great suggestions / recommendations. The most important being use your brain and don't ever think you're safe.

EXACTLY! :D
-- typed from my Powerbook G4 :D

TRAMS_AM
10-09-2005, 02:06 AM
Or, get a Mac. :) Sorry, had to throw that in.


There aren't enough of them to bother writing viruses for :)

monster5601
10-09-2005, 05:44 AM
The best way is to get rid of MS products. Go to Linux.

LordGriNz
10-09-2005, 05:48 AM
The best way is to get rid of MS products. Go to Linux.

Soon as Linux is on 97% of computers, I'll adopt it....

Holeshot
10-09-2005, 06:36 AM
Soon as Linux is on 97% of computers, I'll adopt it....
Agreed.

drowssap
10-09-2005, 06:43 AM
saying buy a Mac in a thread like this is like a ricer saying I'll kill you in the twisties.

Primemover
10-09-2005, 06:52 AM
or just make a nice image and don't worry about all that stupid bs. it takes 5 minutes to run a stupid spyware scan. 3 minutes to have a nice fresh windows install with all your programs preinstalled.

http://ghost.radified.com/

Reminds me of one of my old jobs. Rule of thumb was "if you can't fix it in fifteen minutes, recore." Recore was their oh-so-lovely term for backup and reimage. Became a bit of a running gag.

Razinhell
10-09-2005, 07:13 AM
Your activity determines your security. I've run with just a firewall and windows updates for over a year and I got 1 infection due to my sister checking her email on this computer.

YOU are what causes this stuff, I'm tired of the "I didn't do anything" excuse because either you DID do something or you DIDN'T update your shit.

Get Microsoft Anti-Spyware or SpySweeper, both are the best anti-spyware programs out there.
This is not an exactly true statement. Yes people will always say they didn't do anything and yet they did do something and it is the cause of their problems. But many hackers use bot programs while their virus/worm program itself checks and searches for new victims. You can have a nice Windows 2000 Professional OS, even updated. If it is exposed to the web directly these bots/programs will eventually come across it. Once they find it they begin to run a whole barage of security loop holes. Sometimes its the operating system, sometimes its 3rd party software running no matter, eventually they will get in. Having a firewall almost guarantee 99.9% you will not become a victim of this kind of attack. Yes a router can be hacked, but is it worth a hackers time, no so they move on to the numerous people who are still at risk.

Apple computers are safer
Safety has nothing to do with your computer being an apple/linux. You guys think that there aren't viruses waiting for your not up-to-date Apple system. Yes there are a percentage less, but there are enough that you should still take precautions. Apple is no different then Mozilla Firefox. As long as the market share for your product is small you are targeted way less. As Mozilla grows, which it has considerably done, you will start to see more security flaws and hacks. Either way no system is secure unless you take the time to secure it, update it and make sure you don't half ass things. I see software that was released a day ago that costs almost 3K to buy and its already been hacked and keygened to death. This is top notch software from a top notch company, but these are top notch hackers with a lot of time. Don't for one minute think that apple/linux has all the smart people. In computer security i always use the idea that If there is someone smart of our side their is alway someone smarter on the otherside.

If you really want a secure system and one that really can never be hacked you can look here. http://www.faronics.com/html/deepfreeze.asp
You basically setup your computer exactly how you would like it to be. Install all software, users and files needed. You then setup DeepFreeze which will make an exact copy in another partition. Everytime you start the computer DeepFreeze will make sure that the bootable partition is exactly the same. That is you cannot save anything to the computer. If you install a program afterwards it will not be there when you start up again. Now you may think this sucks for a personal computer. Well you can buy yourself a USB 2.0 External Harddrive and save anything new their. If you need to install new software you will need to unlock the freezed image otherwise all will be lost. Its an amazingly easy idea and yet very affective.

DagYo!
10-09-2005, 08:25 AM
Reminds me of one of my old jobs. Rule of thumb was "if you can't fix it in fifteen minutes, recore." Recore was their oh-so-lovely term for backup and reimage. Became a bit of a running gag.


exactly. ;) but if you partition your drives, you don't have to back up. just keep everything on the d drive and your good. all i have to back up is my firefox and thunderird profiles. which takes about 30 seconds.

So there you have it. Fresh install of windows xp, with all my programs and settings just the way i like it, in 3 minutes and 30 seconds.

sxty8goats
10-09-2005, 08:47 AM
I dont have a firewall or virus protection. I scan for viruses every so often and its clean. #1 rule is Dont download Free pron...If it looks to good to be ture it usually is...Take it from me i know.

Free pron is safe if you use certian sites. There are only two that I know of. If you are using a site that has a pop up window of any kind, you are in the wrong area.

DagYo!
10-09-2005, 08:48 AM
Free pron is safe if you use certian sites. There are only two that I know of. If you are using a site that has a pop up window of any kind, you are in the wrong area.


just use bittorrent and download full dvd's. much better than surfing the web.

and its so easy. http://thepiratebay.org/howdoidownload.php anything you want at your fingertips.

06GTO6.0
10-09-2005, 11:22 AM
figure it would helpful to everyone if we posted a little helper on how to prevent virus' and ad/spy ware from getting on your computer or getting it off your computer.

#1 Preventive measure is to not be connected to the internet directly. 99% of all viruses, worms, Trojan’s are picked up by computers connected directly to the internet. Connected to the internet means you connect your cable/dsl/dial-up modem directly to the back of you computer. In one study they set up 5 different machines (1 apple, 4 windows (1 Win2k, 1 WinXP, 1 WinXP Service pack 2, 1 Win98 (shits and giggles)). It took the windows 2k machines a little over a half an hour to be infected with a virus/worm/trojan. WinXP with service pack 2 faired much better, but it eventually was infected. All the computers were infected at one point.

How to protect yourself:

FIREWALL
Buy your self a router. Don't buy a wireless router unless you really need it or are willing to set up the security protocols. I still wouldn't bother because even the best wireless router can be easily compromised or some loop hole will be discovered and if you don't update the firmware you will be open for attack. Why a router, because it will prevent your computer from being directly connected to the internet. I won't go into details, just update the router every so often and make sure you change the admin password.

Software Firewall ZoneAlarm (Free) Download Here (http://www.zonelabs.com/store/content/catalog/pro ducts/sku_list_za.jsp?dc=12bms&ctry=US&lang=en&lid=dbtopnav_pro) I feel Microsofts Firewall is inadequate. ZoneAlarm is great. It’s a little tough to learn, but basically it will only allow you to connect to the internet with programs you want to use. I.E. if you open your browser for the first time after installing it a flag will pop up saying what program attempted to access the internet and do you wish to allow it. It may be sometimes difficult to run certain games with Zonealarm as the program will be waiting for a internet response and ZoneAlarm is waiting for you to answer a flagged access and you cannot see the flag on your screen. You can configure that program ahead of time to be allowed access so this doesn't happen. Remember to check the box “Remember this program” for programs you use often otherwise ZoneAlarm will become annoying.

VIRUS SCAN A lot of people have a virus scan, but don't maintain the software. If its not up-to-date then it most likely won't be affective. Rarely do hackers use old viruses. They usually change code and improve. If your virus scan isn't aware of the new version it may or may not block it. If you don't want to pay for it then get a free version from Grisoft AVG Free Edition (http://free.grisoft.com/doc/1)
Excellent virus scan and will update automatically everyday. Update the software engine. Besides updates, older versions of Virus scans aren’t updated anymore yet people will still use them. That McAfee Virus Scan 2001 is so old it probably won’t stop 50% of today’s viruses. If you don’t maintain the software then it will do you no good.

UPDATE YOUR SOFTWARE Update everything you use often. Go to Microsoft’s website and update your operating system, update your browser right away especially if you use it to purchase things, update hardware firmware’s from their prospective companies (sometimes updates cause other problems so watch out and sometimes firmware updates clear all settings on routers). You need to make sure everything is up to date. By not updating software you are allowing a loop hole to get into your system. Network Administrators are #1 for not updating their systems so even the professionals have problems with this. I can remember when Apache (Website running software) had a software security loop hole and about what 80% of the internet websites are run on it and so many of them were running old versions and being compromised. It costs lots of money/time to rebuild a company website. Now you have one computer or so to maintain so updating only takes a few minutes.

E-MAIL Don't open attachments, don't click on links within e-mails and always make sure you know who the sender is. Its easy to spoof a sender of e-mail. Don't be fooled, even the least computer savvy person can learn how to spoof an e-mail and proxy it so that you can never find out the originator. E-mail attachments are #1 on the list of infections within network environments. People just open things without thinking. Certain preventative measures can stop them, Most Virus scan software can proxy your e-mail account (Outlook/Endora/Mozilla and such) so that is scans before you see it. AVG has worked very well for me, but even it can miss them so don't let down your guard. Don't click on links within your browser. They can be written to look like this www.yahoo.com (http://www.msn.com) In this case it looks like a link to yahoo, but is really a link to msn.com. Its just one way to fool you to go to a particular website. Don't be fooled. If you want to go to that website then type it in. If its an e-mail that you were expecting, like an activation for a forum you just signed up for, then it will be fine to click through, just don't blindly click on things. Some legitimate programs are built on the same premise as Virus/Worms. Hotbar is an excellent example and i hate this program. It adds a link to an e-mail which when clicked on will install it to your computer. So if you are using Hotbar to spruce up your e-mail messages then you are also sending out links to others and I’m sure they will click on it thinking you sent it. Hotbar is somewhat clear as to what it will do, but people still are curious and once you click it it will try to install itself. It is easy to uninstall and lists itself in your Add/Remove Programs control panel link. Its just another example of e-mails being a compromise to your security. Just be aware what you are doing and don't click on things unless you were expecting that particular e-mail.

Pictures in e-mail.
When you are sent junk mail usually there are pictures embedded within the e-mail. So when you open the e-mail it will also pull the pictures from the originators website. They send out billions of Spam a day. They have no clue on what e-mail addresses are active and will just send them out blindly. When you open an e-mail and the pictures are embedded it will confirm back to them that your e-mail address was active. Its all through code written within the e-mail. Now you will be put on an active list and probably be sent 10 times the amount of junk mail then before. Newer versions of Outlook and other e-mail programs are starting to not download the pictures unless you allow it. I think even Yahoo has stopped the automatic loading of pictures too. Don’t download those pictures unless you know for sure. If you are expecting a dell coupon or weekly flyer from Buy.com then download the pictures.

DON’T BE FOOLED Yeah I know most of you already know this, but don’t give anyone your password, pin # or any personal information. Phishing scams are very abundant and its because people do think the E-bay can’t access their own systems or the bank has no clue as to access your account because they lost your password. I’ll tell you right now that there is no company that cannot access their own systems directly and no they don’t need your access information to look over accounts.

OTHER SOFTWARE
You can use other programs to prevent things from happening or eliminate ad/spy ware from your computer. 2 good programs I know and use are listed below. You cannot depend on 1 program as no program is perfect and some can miss what others do not. Always update these programs otherwise they won’t be efficient in their tasks.

Ad-Aware - http://www.lavasoftusa.com/software/adaware/ - Is a very good and free program. The free version will find programs either running or residing somewhere on your computer. Remember to always do a Full System scan otherwise you may never eliminate the actual programs on your computer. The full version has a pretty good real-time scanner similar to a virus scan. It can prevent the initial infection of ad/spy ware, but its not free. Ad-aware also allows you to quarantine found items so that you can restore them In the event you disable a program you use that required ad bases software.

Nice info here. I am a Network Administrator for Kodak, and unfortunately I have the task of cleaning up spyware/viruses off of worker's PC's on a regular basis. Recently, my fellow co-workers have been bringing their home PC's to me to get rid of spyware/viruses that they have picked up. If they would just follow the steps you have listed, all would be well....but you know how that goes.

The Black Phantom
10-09-2005, 05:33 PM
Good write up! :thumbs: Got the anti-virus software you recomended (AVG Free) and it works great! :hail: I had previously downloaded Spybot Search and Destroy and I too recomend this software to suplement your anti-virus. :)