Preventing Internet and Spyware Attacks
February 16, 2005 - by Ric D.
VERY IMPORTANT Information
Latest Security Hazards HAZARDOUS SECURITY ALERT

Revised Mar 20, 2006
Page 1
The Webpage links spoken of,
avsubmit@submit.microsoft.com (virus/worm/trojan/etc samples)
windefend@submit.microsoft.com (spyware samples)
You need to do the following when submitting a malware to Microsoft:
Note: You may also submit URL (a website name or page or an HTML based email) that might infect a system with any type of malware.
You can get a free web based virus scan at these locations. These won't stop you getting infected, you need an anti-virus monitor for that. They are useful to double check you regular virus scanner on those occasions where you wonder if you are infected:
http://housecall.trendmicro.com//
http://www.pandasoftware.com/activescan/
http://makeashorterlink.com/?I213211E4
F-Secure Online Virus Scanner
MicroWorld AntiVirus Toolkit Utility (MWAV)
Get rid of Viruses, Spyware and Adware from your computer. Just download and run. No installation of this software required. (Please note that the FREE version will only scan your computer and NOT clean any infection that it finds.)
http://www.mwti.net/products/mwav/mwav.asp
UPDATES Frequently.
*Note* Some scans do not remove the Virus but it will inform you that you have it then go back to the first link where you can find the removal tool and get rid of that nasty. Thanks for looking into it.
The spyware problem is growing and infection rates for the most malicious types of spyware are continuing to increase.
According to a report, spyware has spread voraciously across the globe. The most malicious types of spyware - Trojans, keyloggers and system monitors - continue to infect online users at alarming rates.
Scan your PC for harmful Spyware, Adware and Keylogging software for FREE!............
Webroot Software Free Spy Audit
By FaceTime Security Labs, makers of the X-Cleaner Spyware Remover
eTrust Pest Scanner
X-Cleaner Spyware Remover
AuditMyPC's Spyware Test
"+" For those Apple/Mac users, Anti-Spyware for the Mac There are more questions from Mac users about anti-spyware. At this time, the only anti-spyware program that we know of for the Mac is: MacScan
- Tighten the Settings in Internet Explorer.
- Do NOT run as Administrator or an account with Administrator privileges, or use Drop my Rights
- Build a Layer of Protection - there are enough freeware products available on the Internet that there is no excuse for not having an adequate defence. Add an anti-spyware program that has "real-time" protection such as Microsoft's Anti-Spyware (Windows Defender (Beta 2) ) - Grisoft's AVG is a very popular (freeware) Antivirus
- Microsoft has several new (beta) products "BETA" is for those that know but I can say the Live one is OK for the common people but "ONE CARE" IS for those who know what they are doing.- Windows Live Safety Center and Windows OneCare
SpinRite surprises many people when it reports that their drives are running WAY too hot.
The reason I'm writing is to share the news with you and your readers of a terrific and important new service which Steve and TechTV's Leo Laporte are offering: Every Thursday afternoon they spend 20 to 25 minutes creating an audio column about personal computer security called "Security Now!".
http://www.GRC.com/securitynow.htm
The audio columns can be automatically downloaded through an standard RSS feed "podcast" (for podcast people) or downloaded in two sizes directly from the Security Now! page on Steve Gibson's site.
Stay current and make this your "Homepage" Steve keeps up-to-date better than most.
http://www.grc.com/default.htm
Then click on the word "SheildsUP!" and read the pages on the bottom after hitting the proceed button. On this next page you could click on the all service ports button to check your connection, Messenger Spam to learn more about cookies and *Most Important* read these pages Please see Explain this to me! below for information about Windows File Sharing and Internet port vulnerabilities.
The following pages provide additional background, insight, and assistance:
http://www.grc.com/su-explain.htm
*********************************************************************************************************************************************************
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
************Security Updates************
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Allow time for each update and scan to finish successfully, although scanning of each system should only be done once all systems are completely updated.
HINTS;
Your computer should be disconnected from the internet in order to perform the system *scans*.
If any downloading difficulties arise, run Spybot Search and Destroy.
To prevent unwanted spyware and adware from being installed behind your back, you need to install all the latest;Critical Updates; from Microsoft. Doing so is easier than you might think. Microsoft has an entire Windows Update site devoted to automatically updating users' systems with all the latest fixes and patches for a wide range of Microsoft software, including Windows, Office (Word, Excel, PowerPoint, Access), and Internet Explorer. It is strongly suggested you to take your system past the Windows Update site and let that site download and install the appropriate fixes for your computer . Doing so just might save you some grief and headaches down the road:
Windows Update http://windowsupdate.microsoft.com
Notice on the main page these words, " | Windows Family | Windows Marketplace | Office Family | Microsoft Update" Much of the update process at Windows Update is automated, so it's, simple and convenient. The Windows Update site will install a small program to analyze the software on your system and recommend the appropriate fixes. This process takes only a few minutes. Once Windows update has finished analyzing your system, you'll be presented with a menu of downloads that Windows Update deems appropriate for your computer. At a minimum you should let Windows Update install the fixes marked as Critical Updates. The other available updates (Recommended updates, Drivers and Enhancements) are optional. Check the boxes for the updates that you wish to install (Critical Updates are checked by default). Then click the appropriate button to start the download and installation process. You'll be shown a summary of the updates that you've selected, and then you'll presented with a "License Agreement." After you Click through the "License Agreement," the download and installation process will start. Since the entire download and installation process is automated, there's almost nothing for you to do except reboot the computer after all the updates have been installed.
Connect to the internet via Internet Explorer, Select the Tools menu, Select Windows Update once the windows update screen appears, select Express Install, install all critical updates; others are your option (if you need them)
Verify that all updates have been installed by disconnecting from the internet, Re-Starting the computer, Re-connecting to the net and following the above instructions again.
There is a way to test your antivirus program yourself, with absolute safety. Not only that, you can find out how well and/or if you have an AV program installed, and you don’t have to be a geek, nerd or computer tech to accomplish it. EICAR (formerly the European Institute for Computer Antivirus Research) provides a "test string" in various forms that will trigger your scanner, but IS NOT itself a virus and will not harm your computer. Here are the simple instructions.
To test your virus scanner:
Go to: http://www.eicar.org/anti_virus_test_file.htm
Scroll down to the middle of the page where you see a string of code written, and read the section below the string. (You can also read the section above, but it really doesn’t apply to anyone but vendors of antivirus programs.)
1. Copy the string of code in the middle of the page, and save it in Notepad on your desktop as "eicar.com".
2. Download "eicar com.zip" and "eicarcom2.zip" and save them to your desktop.
3. Run your antivirus program.
--Any scanner should find the file "eicar.com".
--Any scanner worth using should also find the file "eicar com.zip".
--A really good scanner will find all three files: "eicarcom2.zip" is the original code string inside a zip file inside another zip file. A program that scans that deep will find just about any virus.
If your AV program fails to find any or all of the files, consider downloading.....
2. Avast! Home Edition:
http://download15.avast.com//eng/programs.html
Just follow the instructions to load it. You will need to give your registering e-Mail address but do not worry they do not spam you. This program updates often and automatically and works all the time.
*SC 2006 Award Finalists!*
Sc 2006 Awards avast! antivirus has been selected as one of this years finalists in the SC Awards, beating off stiff competition and leading the race in the last 4 contenders for the much coveted industry award.
*NOTE* If your downloading this for the first time be sure to register!!
Either register thru the site Emsisoft itself or once you launch the program you'll see a blue link saying log in or register here. click on this and it will take you to emsisofts domain. check the address bar to be absolutely sure ;)
Yes they ask for your email address and they need it for they send you the code you require to enter in the program to get your updates.
Be sure to take out the check marks of things you do not wish!!
Click on the A2 icon in the bottom left of the screen.
Select Update A2 online
Select Next,
Quit
Close the screen
Trojan Finder Scan:
Scan Computer for malware dysfunctions
Scan Selected Folders
OK
Quit
Close the program via the top right “X”
More Help with Pic's seen here....
http://tomcoyote.org/SPYBOT/index2.php
File Size: 5,037 KB
http://www.security-related.com/spybotsd14.exe
Download Spybot’s Latest Version (currently 1.4) *It's recommended to use the integrated update function immediately after download and on regular times to get the current include files (those get revised regularly)!*
Install in your language of choice.
Create a Registry Back up
Update the program hence you should be on line here.
It's recommended to use the integrated update function immediately after download and on regular times to get the current include files.
Immunize--this is suggested so that all of the known Hacker sites or ad sites cannot direct your computer to their sites.
Create your icons where you choose
Start the program.
Remember this program does not ask you for any money but Donations are appreciated as it takes money to provide the updates for you.
In the top left, click on the word “mode”, and select advanced.
When the warning box appears, select yes.
You’ll see some bars created in the bottom left hand corner of the screen.
Click on the settings bar
Click on the file sets on the main screen.
In the file sets place check marks in the vacant boxes
Now in the left side, click on the word “settings”
Click on advanced for which ever icon you chose to use. FOR XP USERS...under the Main settings header click on the boxes that have "Create" as the first word.
Scroll down to "Bug Report" place check marks on all but the attach spy files and just below in the show expert buttons in results list.
Now click on the tools bar
Place a check mark on every box provided.
Down the left hand side will display a menu, check the following items to verify that everything is set properly.
Click on.....
RESIDENT and be sure that both boxes are check marked
ACTIVE X, BHOs, and BROWSER PAGES, to see that there are check marks in each line, if not check with Google.
IE TWEAKS is where you can change your explorer's name if you wish
*HOST FILE* - Very important to hit the green plus sign here to ensure these bad pages never get a connection from your computer.
OPT OUT is automatic install for your computer.
PROCESS LIST is for your computer knowledge to see you can observe it and learn the changes if you wish.
SYSTEM INTERNALS is a great check for your registry if you have ever done any Uninstalling from your computer this will clean your registry
SYSTEM STARTUP is good if you know what to disable. Simply click on an item (under the area of the command line), on the right are two arrows pointing to the right, if you click on them, an explanation will appear to the right. If it says not typically required it is suggested that you remove the check mark. Spybots Tea Timer (on the systems tray, the right of the clock in the bottom right of the screen) will then tell you a global entry has changed and if you did, you can easily allow this change, but remember to click the little box for the program to remember this change.
UNINSTALL INFO will tell you what you have on your computer
WINSOCK LSPs is a good way to ensure that everything running on your computer has validation (green check mark) if not, you'll have to try and remove the bad items.
Now you can do your Spybot S&D search scan.
Update:
Open Spybot by clicking on the icon on the bottom left bar or through
Start? All Programs>
Select Search for Updates
Select all updates by right clicking and clicking on select all
Click on Download Updates
Take note on what is being updated for some updated items need to be manually placed in your program. e.g. immunization rules update means you'll have to do the following....
Select Immunize (off to the left side)
Click on OK
Select Immunize the + to the left side, near the top)
At the end of the immunization, you should have 2 green check marks to the left of your screen, if not, go back and re-immunize)
Note that not only should you "immunize" each time one updates
YOU Should Also update your "Hosts FILE" this "Hosts file is under the tool bar to the left you'll see these words in the darkened area click on the words and click on the + sign to get the current hosts files.
Spybot Scan:
Check for problems
Allow the program to scan your entire computer!
When there is no bar going across the bottom you will see how many problems are found in what time frame (bottom Left corner of Spybot Program :)
Select all
Fix selected problems
Remove Problems? Yes! Then click OK
Now lets continue cleaning other problems your computer may have......
Select Tools (off to the bottom left)
System Internals
Check
If there are any problems, right click in the white area of your screen
Click on Select all
Click on Fix selected problems
Delete any prompts that appear
Close the program
This is where you should be careful for you need to be aware of how much RAM is on your computer and how much your using now also. PC Audit will assist you with this too I believe. If your unsure about the RAM try the above links for spyware scans. I do not yet have a viable solution.
INFO
Windows Defender (Beta 2)
DOWNLOAD
http://www.microsoft.com/downloads/details.aspx?FamilyId=435BFCE7-DA2B-4A6A-AFA4-F7F14E605A0D&displaylang=en
*OR*
is offered as free (with 1 year license). Receive free 1 year antispyware protection by eTrust. eTrust PestPatrol Anti-Spyware is your comprehensive anti-spyware solution.
Extensive Pest Database - Our industry-leading spyware research team monitors global Internet traffic to identify and protect you from all of the major spyware threats:
Spyware – discloses your personal information to third parties
Adware – displays unwanted advertising and slows your PC to a crawl
Keyloggers – steal your passwords and other confidential data by recording your keystrokes
Browser Hijackers – change your homepage and search results to lead you toward certain websites and deny you access to others
Remote Access Trojans (RATs) – enable attackers to control your PC from a remote location
FREE Automatic Pest Updates – new variations of spyware are launched every day to get past outdated anti-spyware software. This feature downloads and updates the pest database automatically to protect you against the latest spyware threats.
On-Demand & Scheduled Scanning – gives you the flexibility to scan your entire PC or select specific disks, files and folders for a customized scan. Schedule automatic scans or scan whenever you like.
Active Protection – monitors your PC in real-time to kill pests in memory and remove spyware cookies before they disclose your surfing habits to a third party.
Automated Alerts & Logs – alerts you whenever a new pest is detected, gauges its threat level and provides you with links to the pest database where you can get more information. You can define “safe lists” and “exclusion files” so that authorized applications can bypass pest detection.
Special offer by eTrust Germany:
eTrust EZ Antivirus 2005 and eTrust Pestpatrol Anti-Spyware 2005 for FREE, 1 year license and updates included.
The offer is valid until ?.
Download from http://www.ca.com/de/dsin/
Download PestPatrolv5.exe (16 MB)
http://www.ca.com/de/dsin/PESTPATROL_V5.EXE
A bit complex, be sure to get the full awareness from the website in order to use it properly. The xp-AntiSpy is a little utility that lets you disable some built-in update and authentication 'features' in WindowsXP. For example, there's a service running in the background which is called 'Automatic Updates'. I don't know what this service transfers from my machine to other machines on the internet, especially the MS ones. So I play it safe and disable such functions. If you like, you can even disable these functions manually, by going through the System and checking or unchecking some check boxes. This will take you approximately half an hour. But why wast time when a little neat utility can do the same in 1 minute? This utility was successfully tested by lots of users, and was found to disable all the known 'Suspicious' Functions in WindowsXP. It's customizable, but comes up with the Default settings, which are recommended. This utility is DONATION WARE! This means, you don't have to pay anything for this program and you can give it to anyone who's interested in it, as long as you don't sell it. If you find this tool useful, and wanna gimme something back, think about donating a small amount of money.
http://xp-antispy.org/content/view/12/40/
See the box on lower right that says mirror sites to get it downloaded.
Download it install it and again just connect to the internet for the updates it will do everything automatically for the first time :)
Update:
Click on the Ad Aware Icon on the bottom left bar
Select Check for Updates Now
Select Connect
Select OK once the new box appears
Select OK
Select Finish once the new box appears
Click on the “X”
AdAware Scan:
Start
Perform full system scan
Next
Right click on the description names
Select all
Next
OK to remove items
Click on top right “X” to close program
Currently you should be a version is or higher than 60.667.000!
*A major UPDATE!!*
Double click on the Zone Alarm icon on the bottom Right Bar
Open up the screen by clicking on the arrow pointing down to the right
If you select the product information folder, this will indicate which version is running
Select Preferences
Select Check for Updates *if you have an update*
Send, OK
Select the Status Screen
Close the screen by clicking on the arrow pointing up to the left
Close (“X”)
*if you have an update*
1. Be sure to notice where you place it on your computer
2 scan it with your Antivirus program AVG or Avast or BitDefender to be quick right click
3 After it scans and comes back clean, Double click the exe to install it to get the updated version
4. If your Av says infected scan your entire computer then go and get it again *not too likely* but if so also check now with your trojan scanner.
There is no need to scan with Zone Alarm it's just a firewall.
SpywareBlaster 3.5.1
http://www.javacoolsoftware.com/spywareblaster.html
"SpywareBlaster doesn't scan and clean for spyware - it prevents it from ever being installed. How? By setting a 'kill bit' for the CLSIDs of spyware ActiveX controls, it prevents the installation of any of them from a webpage. You can run Internet Explorer with Active-X enabled, but you will never even get a 'Yes/No' box popped up, asking you to install a spyware Active-X control (Internet Explorer will never download or run it!). All other Active-X controls or plug-ins will work fine. The SpywareBlaster database contains information on these known spyware Active-X controls. Make sure you run the Check For Updates feature frequently to get the latest database! (And make sure you check the new items to protect your system against them!) As a side benefit, setting this 'kill bit' will also prevent the spyware Active-X from running, in many cases, if it is already installed on your system."
From Toni's site..."4th Feb 2006 I have a constant problem with bandwidth, that's a known issue. Please people if you have any problems downloading, running or installing my software, see: Forum thread.
The File size Needs to match!! = 2,795
http://personal.inet.fi/business/toniarts/files/EClea2_0.exe
>Zip file
http://personal.inet.fi/business/toniarts/files/EClea2_0.zip
EasyCleaner is a small program which searches Windows' registry for entries that are pointing nowhere. EasyCleaner also lets you delete all kinds of unnecessary files like temps, backups etc. You can search for duplicate files and you can view some interesting info about your disk space usage! You are also able to manage startup programs, invalid shortcuts and add/remove software list. ToniArts may not be held accountable in any way if EasyCleaner affects your computer in a negative way. List of some features:
* Very nice interface!
* Finds invalid registry entries ----> deleting them speeds up your computer!
* Finds duplicate files ----> deleting them will free disk space!
* Finds all unnecessary files like backups, temps etc. ----> deleting them will free disk space!
* Finds all invalid shortcuts ----> deleting them will free disk space and increase usability!
* Manage programs starting at Windows startup! ----> who knows, you might even catch a virus before it gets serious!
* Manage Windows' add/remove software listing!
* Easily remove Internet Explorer's temporary Internet files, history and cookies!
* Very user friendly!
* Shows some interesting info about your disk space usage.
* Very customizable.
* Multi-language support!
* Uses only little amount of resources while running!
* Huge help file which gives you every little detail about EasyCleaner!
* And much more...
This program gets better....
Cleans the following:
Internet Explorer Temporary files, URL history, cookies, Autocomplete form history, index.dat.
!Firefox! a suggested Browser at Mozilla.org *till IE 7 comes out.*
Temporary files, URL history, cookies, download history.
Windows
Recycle Bin, Recent Documents, Temporary files and Log files.
Registry cleaner
Advanced features to remove unused and old entries, including File Extensions, ActiveX Controls, ClassIDs, ProgIDs, Uninstallers, Shared DLLs, Fonts, Help Files, Application Paths, Icons, Invalid Shortcuts and more... also comes with a comprehensive backup feature.
Third-party applications
Removes temp files and recent file lists (MRUs) from many apps including Opera, Media Player, eMule, Kazaa, Google Toolbar, Netscape, MS Office, Nero, Adobe Acrobat, WinRAR, WinAce, WinZip and many more...
100% Spyware FREE
This software does NOT contain any Spyware, Adware or Viruses.
Now when using the program, please do the following... Open the program and in the left hand side you'll see a blue coloured square to scan your registry, and the broom to sweep your temp and recycler. There will be a button on each to run or scan at the bottom near the centre and another off to the right to correct what was found.
the download link....
http://www.filehippo.com/download_ccleaner/
Description: Features include:
Easy to use interface
Huge database (over 3800 entries)
Constantly updated
Fastest scanning engine (~2 million trojans/sec) Inspects ZIP, RAR, ARJ, ACE and CAB archives Finds stealth trojans using our exclusive FileSpect(TM) technology TCActive! stops trojans before they can activate Interactive trojan database browser Install and uninstall No conflicts with any programs
Operating systems supported:
Windows95
Windows98
WindowsME
WindowsNT4 Workstation
WindowsNT4 Server
Windows2000 Pro
Windows2000 Server
WindowsXP Home
WindowsXP Pro
http://www.moosoft.com/thecleaner/cleaner4.exe

Warning!
I once said I run BitDefender Antivirus and Avast together although one is not actively scanning, Donna told me this, Please read.
SUPPORTED means the maker of the antivirus software continues in providing product updates and upgrades. An antivirus (or any security tool) that do not have development (updates/upgrades) is in my humble opinion, a product to stay away. Malware isn’t using old tricks so your antivirus program should continue to support the software by providing detections and program updates and upgrades. Sticking with old version shouldn’t be put into practise just because it is the one you like/prefer and/or it is free. Old versions is usually not supported. There are times unsupported versions is OK to use but be sure it is not a security tool. A security tool prevents malware.
UP-TO-DATE means your antivirus software (or any security tool) has the latest detections. Running an antivirus with old detections is useless. You are are putting your computer at HIGH RISK and you are posing a threat to other users because your computer is maybe sending out malware to some of your contacts. You should also run a malware scan regularly. It is also a good idea to use the program’s scheduler or Windows Schedule Task to manage the scan schedule. As for getting all the protection you can get… it depends on how a person is using the internet and the computer but the best thing to do is follow the best practise that were published by:
* Sophos
http://www.sophos.com/virusinfo/bestpractice/
* Microsoft
http://www.microsoft.com/athome/security/viruses/intro_viruses_protect.mspx
Like you, I don’t want to use a computer by only maintaining it everyday but I want to enjoy using the computer and the internet so one of my practises is by keeping a good full system backup twice a month or whenever I feel like backing-up. If anything happens, I don’t have to worry of losing any settings, files and the system. Learn more about backups in:
* Data Backup vs System Backup
http://dozleng.com/internetsecurity/?p=73
* Why you should backup
http://www.microsoft.com/athome/security/update/backup.mspx
Again, *one (1) antivirus program is enough*. No user is getting extra protection by installing more than 1 antivirus program. If you need to know whether the system is infected and you want to use another antivirus scanner, run an online virus scan:
When writing e-Mails
Using the BCC (Blind Carbon Copy) feature of one's email client to send messages to more than one recipient is also recommended, as it helps protect against the spread of viruses as well as protect the privacy of recipients' addresses. More info on this and on how to BCC here:http://www.cs.rutgers.edu/~watrous/bcc-for-privacy.html

BCC, which stands for blind carbon copy, allows you to hide recipients in email messages. Unlike addresses in the To: field or the CC: (carbon copy) field, addresses in the BCC: field cannot be seen by other users.
Trojans are often not caught by virus scanning engines, because these are focused on viruses, not Trojans. Catching such threats would require the use of a Trojan scanner (a.k.a Trojan cleaner, Trojan remover, anti-Trojan, a-Squared). see, http://www.windowsecurity.com/trojanscan/
There is more things one could see on the next page *or* Back to the Meeting Page
See anything that you think requires my attention? Well then feel free to click on
image. I will respond either soon or immediately!
Truth is the way things are.