header



Welcome to the Micro Center Tech Support Blog!
Find free technical support on a variety of products featured at Micro Center and plenty of how-tos on new technology. Start searching our Blog below or search our Tech Center archives »

Can't find what your looking for? Take advantage of our Tech Support services »

Join the MC Tech Support Community Forum: Get direct advice from the Knowledge Experts @ Micro Center.
Click here to access the Forum »

Search This Blog

Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Tuesday, June 11, 2013

Tech Tip: How to clean out the Windows Hosts file if malware has tampered with it

Viruses attack computers not just by posting pop-up ads for phony software. They also cripple the computer's basic functions so that the virus is difficult to get rid of. One of the chief objectives of viruses is to prevent internet browsers from going to web sites chosen by the user. There are several ways that viruses steer a browser away from its intended destination. Sometimes they install a Proxy Server into the web browser (See Part 3 in this series, "How to clear the Proxy Server setting"). At other times a virus will insert unwanted IP addresses into the network settings (See Part 4 in this series, "How to reset Static IP addresses to dynamic IP addresses"). A third way that viruses hijack internet connections is rarer, but it does happen. If previous attempts at solving the problem do not work, it is worth investigating a Windows feature called the Hosts file.

The WindowsHosts file serves to map user-friendly and familiar web site addresses (such as Google) to the actual IP addresses that are behind such names (such as 216.239.51.99). The Hosts file is sometimes used by network administrators for managing fixed networks. Unfortunately, it is also a target for viruses that want to hijack a computer's internet connectivity. Fortunately, however, if the Hosts file has been attacked and unwanted material written into it, the file can be manually cleaned.

The Hosts file is located deep in the Windows folder. It is not easy to find, but following these steps will help you locate it, inspect it and-if necessary-clean it up.

First, you need to open up the Windows text editor called Notepad. (For Windows Vista, 7 and 8, this needs to be launched with administrator privileges.) Depending on which version of Windows you have, this is done differently:

1) In Windows XP:

  • Click on the Start button
  • Click the Run button in the menu
  • Type notepad in the box, hit the Enter key

2) In Windows Vista:

  • Click on the Start button
  • Type notepad in the search box
  • Right-click the Notepad program in the list
  • Click Run as administrator in the drop-down menu
  • Click Yes to allow the program to make changes (if this option appears on the screen)

3) In Windows Vista:

  • Click on the Start button
  • Type notepad in the search box
  • Right-click the Notepad program in the list
  • Click Run as administrator in the drop-down menu
  • Click Yes to allow the program to make changes (if this option appears on the screen)

4) In Windows 8:

  • Open the Charms menu and click on the Search Charm
  • Type “notepad” in the Apps search window
  • Right-click the program Notepad that appears in the results in the upper left corner
  • In the taskbar that opens at the bottom of the screen, click Run as administrator
  • Click Yes to allow the program to make changes (if this option appears on the screen)

When notepad is opened up, you will see a new window for the Notepad text editor that looks like this:

notepad 

notepad

With the Notepad application open click on File in the menu bar, then click on Open in the drop-down menu (as indicated by the red arrow, above).

To locate the Hosts file, start with a double-click on the C drive in the left panel, then the Windows folder, the System32 folder, the drivers folder, and finally the etc folder. Once the etc folder is open, click on Text documents (*.txt) and drop down to the next option which is All files (*.*). If you are in the correct folder, you will see a list of 3 to 5 files in the window, as shown below. Now, double-click the Hosts file (circled) to open it up in the text editor.

All files

The example below is of an actual hijacked Hosts file. All the lines of text that are preceded by the # sign are legitimate (comments). All the others were inserted by a virus to steer users in various countries to the unintended IP address of 74.50.127.5 (the web site designed by the virus author) instead of Google.

hijacked host file

To remove the intruding instructions in the host file is simply a matter of deleting the lines that are not wanted. Using Notepad, move the cursor to the area (as highlighted, above) and delete those lines, leaving the original lines in the Hosts file.

A clean Hosts file will look something like this:
clean Hosts file

When finished editing, simply save the file, reboot the computer, and try to use your browser normally. Hopefully, the experience of being steered away from desired web sites will be gone, and you will be able to browse freely.

For more assistance contact Technical Support here.

Monday, October 8, 2012

Tech Tip of the Day: How to download, install, and run SUPERAntiSpyware

Description: Are you concerned about possible spyware, adware, malware, or similar problems on your computer? Does your computer seem to run very slow? SUPERAntiSpyware is a utility that may help you to diagnose and repair these types of problems.

These days there can be a new virus or infection created every three seconds, and computer users need to be ready for the next attack that could be made on their systems. Along with routine Windows maintenance addressing concerns such as cleaning up temporary files or repairing registry errors, running multiple scans from AntiVirus and AntiMalware programs can help to take care of these problems. There is a program called SUPERAntiSpyware that scans your computer for infections, temporary files, registry errors and things like that in just one scan, and then makes recommendations for corrections to the system that it can make.

  1. To download the program, you can go directly to the program's website http://www.superantispyware.com - be sure to understand any terms and conditions of the program.
  2. Go ahead and download the installer, saving it to a location on your computer where you will be able to find it easily, and then run the installer as shown in the picture.

    download the installer
  3. Once finished, open the program and the user will be greeted with a home screen as shown here.

    home screen

  4. Just click "Scan your Computer" to get a full scan under way and let the program work for you.

    Scan your Computer

  5. Once finished, the scans will provide a result pop up as shown below. Click the continue button to delete the threats.

    continue

  6. Once the deletion process has completed, click the Finished button.

    Finished

  7. The program will then ask you to reboot or reboot later, it is best to save and close all programs then reboot your computer for the changes to go into effect.

    *In this and similar situations, it is important for the end user to understand that they are obtaining utility programs such as this one from known reputable sources. If you are unsure of the source being reputable, it can be possible for rogue programs to present themselves as solutions when, in fact, they are actually "problems in disguise" that will make things worse instead of better.
For more assistance contact Technical Support here.

Friday, August 3, 2012

Tech Tip of the Day: How to download and run Chameleon by Malwarebytes

** THIS POST HAS BEEN UPDATED **

Malwarebytes Chameleon is a tool that was developed in order to get Malwarebytes Anti-Malware running when blocked by an active infection on a user's system.

It accomplishes this in several ways, but in order to run, Chameleon itself must be able to run in spite of the infection as well.  That's where the filenames come in and is the reason you'll find files like 'svchost.exe', 'winlogon.exe' and 'iexplore.exe' among others within the Chameleon folder.  Those are actually just renamed copies of the main Chameleon executable, mbam-chameleon.exe.  The reason that we do this is because infections, particularly rogue/fake antivirus programs, will often block processes from launching simply based on their file or process names, or they will only allow certain 'whitelisted' processes to run.  These whitelisted processes are often a user's internet browser (hence the use of names like 'firefox.exe' and 'iexplore.exe') or critical system processes (hence 'svchost.exe', 'winlogon.exe' and 'rundll32.exe').

There are several methods for launching Chameleon itself, depending on the situation that the user is dealing with. 
Malwarebytes provides a help file called 'chameleon.chm' which is accessible via the START menu under All Programs\Malwarebytes' Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk'.  This is the best and simplest way to use Chameleon as all the user has to do is open the help file and follow the instructions.

Unfortunately, launching the help file is not always possible, so
Malwarebytes does provide other methods to get Chameleon running.
 
If Malwarebytes Anti-Malware is already installed but the Chameleon help file will not open, the user may attempt to launch the Chameleon executables manually by browsing to their Malwarebytes Anti-Malware program folder under 'Chameleon' and double-clicking on the executables located there one by one until they find one which is able to launch which will be indicated by a command prompt window providing instructions on what to do next to run Chameleon.

Once Chameleon is up and running, it will attempt to update Malwarebytes Anti--Malware's database, kill all malicious processes running in memory, and then initiate a scan with Malwarebytes Anti-Malware.  Upon completion of the scan, the user may remove the infections from their system, rebooting if required, and their system should be running normally again, free of infection.

If Windows Explorer is not running, the same method can be used to launch the help file or executables by using Windows Task Manager and simply browsing to the location of the files and trying to open them one by one that way.

Now, if Malwarebytes Anti-Malware is not already installed, Chameleon can get it installed for the user. 
Malwarebytes has provided Chameleon as a separate download available here on their website: http://www.malwarebytes.org/products/chameleon

All the user needs to do is download that file, extract it to a new folder in a convenient location such as their desktop, and then attempt to use the included help file (Chameleon.chm) to run Chameleon.  If the help file will not open, then the user should proceed with the same method applied above by double-clicking on each of the provided Chameleon executables one by one until they find one that opens.

Upon opening, the user should follow the onscreen instructions and Chameleon will proceed to download and install Malwarebytes Anti-Malware for the user and then will proceed to run through the same process as described above (updating the database, killing malicious processes and performing a scan).


*All information provided by Samuel E. Lindsey of Malwarebytes Corporation

Tuesday, April 24, 2012

Tech Tip of the Day: How to use a HOSTS File to proactively defend your Windows computer against most known Malware programs

Description: This article describes the processes of installing and updating a 3rd party HOSTS file to provide a strong layer of defense against most known forms of malware, immunizing your system from many malicious programs before they become a threat.

Background: The HOSTS file is a File used by the Windows operating system to map the location of computers or web addresses on its network. It is similar in function to the Domain Name System (DNS) which maps server Internet Protocol (IP) addresses to domain names, such as ‘google.com’ (Google’s Top-Level Domain [TLD]), which directs internet traffic to the IP address of one of Google’s servers, such as ‘72.14.204.105’. As such, it is important to be very careful when making any changes to this system. Fortunately, there are several reputable groups which actively maintain and test custom HOSTS file configurations which are freely available on the internet today.

This guide will cover the installation process for two popular HOSTS files which are regularly tested and are considered safe to use. It is important to choose only one guide to follow, as attempting to install multiple HOSTS files can lead to conflicts.

Note: If you are attempting to follow this guide on a computer connected to a home or work network, please contact your Network Administrator before continuing, as making changes to the HOSTS file may affect network connectivity in certain situations.

  1. MVPS HOSTS
    • Download ‘hosts.zip’ from the following web page:
      http://winhelp2002.mvps.org/hosts.htm

      hosts.zip
    • Extract the contents of the ‘hosts.zip’ file by Right Clicking on the file from within Windows Explorer and selecting the ‘Extract All’ option from the menu.

      extract all
    • Right click on ‘mvps.bat’ and select the ‘Run as Administrator’ option from the menu.
      • Click ‘Continue’ in the User Account Control (UAC) prompt, if one appears.
      • In Windows XP, or if the ‘Run as Administrator’ option is not available, you may simply Double-Click on ‘mvps.bat’ or Right Click on the file and select ‘Open’ from the menu.

        Run as admin
    • Press Any Key when prompted.
      • The window background should turn Blue and display a message stating
        "THE MVPS HOSTS FILE IS NOW UPDATED", signifying that the process has completed successfully.

        completed
    • Restart Your Computer to complete the installation.

  2. Spybot - Search & Destroy
    • Download Spybot-S&D from one of the Mirror Sites listed at this link:
      http://www.safer-networking.org/en/mirrors/index.html

      Download Spybot
    • Double-Click on the .exe file you just downloaded (the file should be named ‘spybotsd162.exe’ or something similar) and follow the Installation Wizard to install the program.

      Installation Wizard
    • Start Spybot-S&D by Double-Clicking on the Icon on your desktop or from the Start Menu by clicking on the Start Button in the lower left corner of your screen and going to ‘All Programs’ » ‘Spybot - Search & Destroy’ and Clicking on the ‘Spybot - Search & Destroy’ Link from the list.

      Search and Destroy

      • The First time you run the program, you may be presented with an Initial Setup Wizard window. Click ‘Next’ on this window and follow the steps to complete the initial setup and updating of the program.

        Next
    • On the Main ‘Spybot - Search & Destroy’ window, click the ‘Immunize’ option from the Menu Bar on the Left.

      Spybot

      • The program will run a quick scan to check the current protection status of your computer.
    • Click the ‘Immunize’ button to begin the immunization process.
      • This may take some time depending on the specifications of your computer.

        Immunize
    • Restart your computer to complete the installation.
For more assistance contact Technical Support here.

Tuesday, April 10, 2012

Tech Tip of the Day: How to run Kaspersky TDSSKiller

Description: Run this tool if you get can infection on your PC.

The Kaspersky TDSSKiller is a good tool to run on an infected computer as it can find different forms of malware and adware that may be lurking in the background of a user's PC which a standard antivirus scan may miss. It is also a good tool when trying to find out if the PC possibly has a rootkit on it.

  1. First download the TDSSKiller from the manufacturer's website, currently:
    http://support.kaspersky.com/faq/?qid=208283363
  2. Once downloaded, run the executable file to start the application. Click on the Change Parameters option to add additional options to your scan.

    TDSSKiller

  3. Click the Start Scan option and allow the scan to completely go through the user's computer.

    Start scan

  4. Once finished the user should get a screen similar to the one above if no threats or infections are found. If infections were found, you would be given options on what to do with them such as ignore, quarantine, or kill/delete.
For more assistance contact Technical Support, click here.

Thursday, February 9, 2012

Tech Tip of the Day: How to download and use Malwarebytes

Malware is shorthand for "malicious software" and is used to describe an entire group of programs that includes advertising, tracking, key-logging, ID or credit theft or that cause other bad or undesirable activity. Malwarebytes specializes in fighting malware.

(including Free, Trial, or Retail versions)
  1. Go to www.malwarebytes.org. Follow the download link to download.cnet.com and click on "Download Now" icon (not the "Start Download" buttons - which link to other stuff.) Alternatively, purchase a full version of Malwarebytes in the software aisle or Service Department at Micro Center. The full version includes a LIFETIME subscription and active background monitoring.


welcome
  1. Run Malwarebytes Installer. If installer does not work, there may be a virus present which is interfering. In that case, complete the following, but after restarting the system in "Safe Mode with Networking"
    To start windows in Safe Mode, do the following.
    1. Tell windows to Shut Down (not sleep or hibernate).
    2. Press power button
    3. Continually tap F8 until the Windows Start Menu appears (black screen with white text).
    4. Use Up/Down arrow keys to select "Safe Mode with Networking", press enter
  2. Make sure there is an active internet connection.
  3. Start Malwarebytes by double clicking the icon on the desktop or from the Start, Programs list.
  4. Click on Update tab. Click on "Check for Updates" button. Malwarebytes will search for updates, download and install them.


If you have a network connection during the installation, Malwarebytes should update automatically, otherwise, check for updates before starting a scan.
  1. Click on the "Scanner" tab. Select "Perform full scan" (this takes the most time, but is recommended for the first time scan on an infected system), or "Perform quick scan". Click on the "Scan" button to start.


A Full Scan can take anywhere from 10 min. to 2 hrs. Malwarebytes will highlight in red details of infected files found.
  1. When scan finishes, click "Show Results" button. A list of viruses, security issues, or any malware found will appear.
  2. If the items are not selected, do so, and then click "Remove Selected" button. The malicious files or registry issues will be removed.
  3. Restart the computer in normal windows mode. If Malwarebytes detected and removed threats in Safe Mode, it is recommended to repeat the scan process in normal mode to look for additional threats.
For more assistance contact Technical Support here.

Wednesday, December 21, 2011

Computer Viruses and How to Avoid Them

What is the difference between "malware" and a virus?


Malware is shorthand for "malicious software" and is used to describe an entire group of programs that includes advertising, tracking, key-logging, ID or credit theft or that cause other bad or undesirable activity. Simply explained, a "virus" is a computer program that invades or infects a user's computer by replication from another source (a disk, a USB flash drive, a network or the Internet), and then performs malicious functions on the new host computer. It's the malicious functionality that poses the problem, and for that reason viruses could be also called "malware."

 

A virus is just one type of Malware.
A virus is just one type of Malware.


There are many different undesirable things that computer malware does. Earlier viruses simply performed mischievous tasks, such as deleting data or program files. But the authors of newer malware are driven by the desire to steal enough sensitive data in order to eventually steal money. Some are thus designed to scan and send information from a victim’s computer back to the author of the malware. Still others keep track of actual keystrokes typed by an unsuspecting user. Some plant annoying "popup" advertisements on a computer. There are a few types of malware that will perform any of the above, but also attach themselves to email addresses so that they get automatically sent to the user’s address list to replicate on an ever growing number of systems. Sophisticated malware might even install itself on the hidden "boot sector" of a computer hard drive, or try to make a network server vulnerable to a hacker (a person who gains unauthorized access to a computer network). But, the most common type of malware, by far, is the malicious program that deceitfully disguises itself as a good or useful program, seeking to get results which the user did not intend.

The fact is that malware has caused billions of dollars in losses to computer users. People have lost valuable data and have had personal and financial identities stolen. Whole companies have been compromised or crippled by malware infections. At the very least, the average user suffers from the slowdown or complete hijacking of their system through a malware infection. It is therefore imperative for computer users to know some basics about viruses, or "malware," in order to protect themselves.

Types of malware

  1. Virus - The original malware. Malicious code attaches itself to other program files so that the execution of the host file also executes the malicious code. The malicious code also causes the virus to replicate itself by copying its code onto removable media or other computers in a network. Back in the 1980s, the first "in the wild" viruses spread themselves mostly through shared floppy disks, and performed everything from pranks to data destruction. By the 1990s, Internet "bulletin boards" were unwitting spreaders of viruses. Today, very little malware is of the virus type.
  2. Trojan - These comprise 75% or more of all malware, according to security experts. As the name from classical Greek mythology suggests, Trojans operate by deceit, tricking a computer user to trust a fraudulent program. Most Trojans are actually a complex of files - pop-ups that steer the unsuspecting user to a harmful website, or just install more malware, even when clicked to shut down; downloaders that bring in supporting malware programs; hijackers that shut down operating system functions and security; bots that may use the host computer as a slave to the malware author’s intentions; backdoors that make an infected computer open to free scanning by the malware author. Trojans operate independently of other programs, and thus do not need to attach themselves to other executable files as a classic virus does. The most popular Trojans, these days, masquerade ironically as anti-virus programs. The user experiences sudden low computer performance, and then sees a pop-up offer with a phony virus scan report, urging the user to purchase the program offered as a solution to the computer problems they are experiencing. Naive and unsuspecting users then type personal information into the form provided (including name, address and credit card info). This information is never used to purchase the phony software. Rather, the Trojan authors use the stolen info to open new credit card accounts in the user’s name, and then sell those accounts on the underground market within minutes of receiving it.
  3. Worm - A Trojan that has the capacity to infect computers from other infected systems by scanning for IP addresses on vulnerable computers on the Internet or within a network, then replicating itself. Many phony anti-virus programs start out as a worm infection. Worms are also notorious for attaching themselves to email address lists. Users falsely believe that Trojan infections come mostly from certain "dangerous" or risky websites. In truth, worms may employ any website that users visit as stepping stones to their computers.
  4. Spyware - Software programs that "spy" on users, observing data, keystrokes, screens and/or web sites visited. This is a broad category of malware and includes everything from adware to keyloggers (see below). Unlike viruses, Trojans and worms, spyware typically does not self-replicate by infecting other computers or removable media, but is downloaded through Internet connections.
  5. Keylogger - A particular type of spyware that is designed to steal "live" information. It secretly keeps track of such things as the user’s keyboard keystrokes, video screens, or streaming network data, and transmits that information back to the malware author. This malware attack is more rare, but it poses the serious risk of loss of private identity information, including credit cards, bank account info, Social Security numbers, and computer passwords.
  6. Rootkit - A stealth program that allows continual unauthorized access to a computer by a person unknown to the user. This malware replicates itself on a victim’s computer usually as a worm or a Trojan. It quickly shuts down user account controls and security designed to prevent unauthorized access. It can then steal and transmit info or simply provide a "back door" for a hacker. Rootkits are usually quite sophisticated, and often include the ability to deflect detection from weaker and more modest anti-virus programs.
  7. Phishing - Typically an email message that is "fishing" for personal information. The victim receives a randomly sent message that appears to be an official request from an Internet service provider, a bank or some other service or organization. The graphics in the message typically look professional and authentic, though the grammar in the message is sometimes suspiciously bad. An appeal is made to the user to provide "lost" information. However, NO organization or bank will ever seek information this way. Such fraud should always be reported to the organization or service that is being used as a cover.
  8. Adware - The most benign of all types of malware, it can still annoy users with commercially-charged pop-ups and reduced system performance. Adware often gets installed without user’s consent, and often when downloading program updates, trial software and games or other services. Some adware functions as spyware by tracking the user’s favorite web sites and targeting the user with advertising that is likely to be the most appealing. Adware can hijack web-search functions. The most common form of adware is the browser "toolbar," which ostensibly provides services such as search windows and quick-access icons. These toolbars slow computer and Internet performance, take screen space from web pages, and can even be a conduit for more serious malware.
    Prevent and cure  
    Prevent and cure

How to Prevent Malware Infections

The best way to be free of malware infections is to take preventative measures rather than relying upon removal after infection. Once infected, a computer is often very difficult to clean. Some malware will destroy a computer’s operating system, or make it so difficult to recover that wiping the hard drive and reinstalling the operating system, programs and data is the only solution. This is usually quite a chore, may be expensive if the user does not have the technical know-how and may be personally costly if the user’s own data has not been previously backed up. There are several preventive measures that every computer user can take:
  1. Utilize a good anti-virus program. There is no substitute for this measure. Avoid the seduction of free anti-virus programs and the ones that come with Internet service providers, as they only do a mediocre job of prevention. A $40 to $50 investment in a good anti-virus program with an annual license to update itself regularly is pretty inexpensive insurance.
  2. Manually scan your computer with an anti-virus program. All good anti-virus programs come with manual scanning features. Most will let you set a schedule for automatic scanning. This is good to do once a week, or every month, and especially if you see any suspicious activity on the computer screen.
  3. Update key programs every time. The Ziff-Davis network cited a study done in Denmark earlier in 2011 utilizing results from half a million computers. The conclusion of the study was that some 99% of common malware infections could be avoided simply by updating Windows security patches, Internet Explorer, Java, Adobe Flash and Adobe Reader. The reason? Malware authors attempt to gain access to computers through weaknesses which the updates are written to prevent.
    (See: ZDNet - The Ed Bott Report, Oct 7, 2011. Summary: Want to avoid being attacked by viruses and other malware? Two recent studies reveal the secret: regular patching. A fully patched system with a firewall enabled offers almost complete protection against drive-by attacks and outside intruders.
    www.zdnet.com/blog/bott/if-your-pc-picks-up-a-virus-whose-fault-is-it/4039)
  4. Use a hardware firewall. The SPI (Stateful Packet Inspection) firewalls that come with most newer routers is a great way to close unused ports and prevent hackers from intrusion. Even single computer homes and offices can benefit greatly from the use of a router. While utilizing a router’s hardware firewall, you may also use your operating system’s software firewall. Beware of using third-party software firewalls (such as those included with anti-virus software) which serve to slow down a computer. If you’re using a wireless router, make sure to encrypt your network with WPA or WPA2 level encryption, never the older and simpler WEP encryption.
  5. Uninstall browser toolbars. Toolbars are the quarter-inch wide strips that layer near the top of a web browser. While some toolbars may be useful on a limited basis, they all steal screen space and clog up your Internet bandwidth only to provide revenue for the author. By definition, toolbars communicate with their authors, thus opening a vulnerability "hole" while the PC user is online. Utilizing the add/remove function in Windows machines is the best way to rid a computer of these browser plugins. Some of the most common toolbars include: AIM, AOL, Ask, Bing, Crawler, Dogpile, eBay, Google, My Way, My Search, My Web Search, Yahoo, etc.
  6. Regularly delete browser cookies and "Temporary Internet Files." This is performed from within the browsers, themselves. Malware can hide amongst these files.
  7. Do not click on pop-ups - shut them down alternatively. If you DO get a suspicious pop-up window, try using the "Alt-F4" combination to get rid of it rather than clicking on it and risking an unintended installation of a virus. If that combination does not work to close a window, use the Microsoft Windows "Task Manager" ("Ctrl-Shift-Esc") and the "Applications" tab. Simply click once on the listed application and then click the "End Task" button. After a forced-close, some browsers will attempt to recover the last page you were on the next time you restart. Select "No" or have it go to your Home Page instead.
  8. Use an Anti-Malware application and keep it updated. While Anti-Virus applications will detect and block viruses, worms, and other programs that spread by design, they do not always detect or block programs that you allow to install on the computer. Clicking on pop-up advertising windows, opening, email or Instant messaging attachments, or downloading and installing games or other programs can trigger the installation of an undesirable application. Using a program to scan your computer periodically for programs your antivirus may miss is recommended. Programs like MalewareBytes, Spy Sweeper, or SuperAntiSpyware may catch and remove malware.

Security and Urban Legends

While it is important to be informed about the facts regarding malware, methods of infection, and methods of prevention, it is also just as important to know that there are some common public beliefs that are just not true. Here are some common "urban legends" that are patently false:
  1. Anti-virus software companies conspire to write viruses so they can stay in business. Many computer users are tempted to believe this falsehood, but only because they do not understand how lucrative the criminal activity of malware authoring has become. If legitimate software companies were the actual criminals, someone would have blown the whistle years ago. The actual malware criminals enjoy both anonymity (they attack unseen from anywhere in the world) and impunity (there are limited resources and jurisdiction for prosecuting them, even when observed).
  2. Viruses come mostly from questionable web sites. Computer users also typically believe that infections are the result of using social, illegal downloading or pornographic web sites. However, the fact is that malware infections such as worms and Trojans can attack from anywhere, and may use any legitimate and otherwise well-guarded web site as a stepping stone from one infected PC to another.
  3. Free anti-virus programs are just as good as the paid-for programs. This is demonstrably not true. Observe the results of serious testing labs. If ever there were a good application of the "you-get-what-you-pay-for" principle, it would apply with anti-virus programs. Simply put, you pay for regular and effective program and virus definition updates. Licensed programs are anxious to push out good updates - often daily - to their customers. They want our business year after year, and therefore work hard to distribute good products, and largely succeed at it.
    (See: AV Comparatives - Independent Tests of Anti-Virus Software. www.av-comparatives.org)

Summary

Don’t let the threat of malware infections stop you from using the rich resources of computing. Just use your computer wisely. Utilize the measures outlined above. And exercise a healthy dose of suspicion about what you see on your computer screen, short of being paranoid. There is no reason why the careful computer user cannot buy things with a credit card, do banking and investments, and send critical business data over the Internet If possible, encrypt the data you are sending or utilize a VPN (Virtual Private Network). Certainly, you should never carry out financial transactions over a public wireless network. In spite of the risks - which are present primarily in the midst of carelessness - computers provide a powerful tool for use both on and off the Internet

For more assistance contact Technical Support here.

Friday, November 11, 2011

How to Use a HOSTS File to Proactively Defend Your Windows Computer against Most Known Malware Programs

Description: This article describes the processes of installing and updating a 3rd party HOSTS file to provide a strong layer of defense against most known forms of malware, immunizing your system from many malicious programs before they become a threat.

Background: The HOSTS file is a File used by the Windows operating system to map the location of computers or web addresses on its network. It is similar in function to the Domain Name System (DNS) which maps server Internet Protocol (IP) addresses to domain names, such as ‘google.com’ (Google’s Top-Level Domain [TLD]), which directs internet traffic to the IP address of one of Google’s servers, such as ‘72.14.204.105’. As such, it is important to be very careful when making any changes to this system. Fortunately, there are several reputable groups which actively maintain and test custom HOSTS file configurations which are freely available on the internet today.

This guide will cover the installation process for two popular HOSTS files which are regularly tested and are considered safe to use. It is important to choose only one guide to follow, as attempting to install multiple HOSTS files can lead to conflicts.

Note: If you are attempting to follow this guide on a computer connected to a home or work network, please contact your Network Administrator before continuing, as making changes to the HOSTS file may affect network connectivity in certain situations.
  1. MVPS HOSTS
    • Download ‘hosts.zip’ from the following web page: http://winhelp2002.mvps.org/hosts.htm

      hosts.zip

    • Extract the contents of the ‘hosts.zip’ file by Right Clicking on the file from within Windows Explorer and selecting the ‘Extract All’ option from the menu.

      extract all

    • Right click on ‘mvps.bat’ and select the ‘Run as Administrator’ option from the menu.
      • Click ‘Continue’ in the User Account Control (UAC) prompt, if one appears.
      • In Windows XP, or if the ‘Run as Administrator’ option is not available, you may simply Double-Click on ‘mvps.bat’ or Right Click on the file and select ‘Open’ from the menu.

        Run as admin

    • Press Any Key when prompted.
      • The window background should turn Blue and display a message stating "THE MVPS HOSTS FILE IS NOW UPDATED", signifying that the process has completed successfully.

        completed

    • Restart Your Computer to complete the installation.

  2. Spybot - Search & Destroy
    • Download Spybot-S&D from one of the Mirror Sites listed at this link: http://www.safer-networking.org/en/mirrors/index.html

      Download Spybot

    • Double-Click on the .exe file you just downloaded (the file should be named ‘spybotsd162.exe’ or something similar) and follow the Installation Wizard to install the program.

      Installation Wizard

    • Start Spybot-S&D by Double-Clicking on the Icon on your Desktop or from the Start Menu by Clicking on the Start Button in the Lower Left corner of your screen and going to ‘All Programs’ » ‘Spybot - Search & Destroy’ and Clicking on the ‘Spybot - Search & Destroy’ Link from the list.

      Search and Destroy

      • The First time you run the program, you may be presented with an Initial Setup Wizard window. Click ‘Next’ on this window and follow the steps to complete the initial setup and updating of the program.

        Next

    • On the Main ‘Spybot - Search & Destroy’ window, Click the ‘Immunize’ option from the Menu Bar on the Left.

      Spybot

      • The program will run a quick scan to check the current protection status of your computer.
    • Click the ‘Immunize’ button to begin the immunization process.
      • This may take some time depending on the specifications of your computer.

        Immunize

    • Restart Your Computer to complete the installation.
For more assistance contact Technical Support here.

Thursday, June 30, 2011

Tips for Securing Your Wireless Network


Wireless security

1. Set a Router Password

Failing to set or change the default password of your wireless router or access point is probably one of the most common security holes in home networks. The reason is that even if you take all the other suggested steps with SSID, WEP and WPA settings, wireless transmission of data is not 100% secure. If someone succeeds in accessing your network, the security settings in the router cannot be changed without access to the menus. Changing the password helps prevent someone from granting themselves access to your network, changing your router settings, or worst-case, locking you out of your own equipment.

Wifi router

While most routers and access points require configuring the device through a physical cable connection, some will allow you access to the setup menus through the wireless connection. For this reason, you should make it a point to change both the name (SSID) and password for your router as your first order of business.

2. Change the SSID - (Service Set IDentifier)
Many Operating systems and client applications give you some way to browse available wireless networks. Changing the SSID from the manufacturer's default makes it slightly more difficult to determine "known" information about the router (like its capabilities or default passwords.) But if a router is configured not to broadcast the SSID, then a casual passerby will not be able to connect without manually configuring their client settings. This means they either have to monitor wireless activity and capture network packets to analyze, or know the SSID in advance.

When the SSID broadcast feature is disabled on a router, the list of available wireless networks (on the client) will not display it in the list. To access a wireless network router that has the SSID "hidden" you must create a connection setting that has the SSID entered manually. To do this under Windows XP, click on the option to "Change Advanced Settings" in the Wireless Connection Wizard. From here you can add a new connection, specify the SSID (as it was entered in your router) and specify other settings required for the connection such as WEP and the associated encryption keys.

Changing the name (SSID) helps identify your specific network, which can be useful if there are multiple Wireless networks in your business or immediate neighborhood. Hiding the SSID won't keep "them" out, but it will slow "them" down.

3. Turn On Encryption:

WEP - Wired Equivalent Privacy
Security encryption provides a good layer of you can enable for your wireless network is WEP encryption. Although WEP encrypts your data, people using special network utilities may be able to collect enough information to identify the WEP key that is in use. Once they have the SSID and WEP key, then they can access the network. Like the SSID, WEP won't prevent a determined hacker from accessing your network, but it will prevent or discourage the casual "war drivers" and neighbors.

Choices for WEP security may be presented in several ways, but the core features work out to: no encryption, 64-bit encryption or 128-bit encryption. (Microsoft and some of the wireless vendors may describe this as 40 bit and 104 bit encryption.)

WEP encryption codes can be entered as a hexadecimal string (numbers 0-9 letters a-f), or generated with a text-based pass-phrase. (The pass-phrase is used to create the hexadecimal string.) If the method to generate the string is not consistent between your different clients, you may need to copy or manually enter the resulting hexadecimal string from one device, and then paste or manually enter it into the rest of the network configuration boxes.

The Wireless Networking Wizard that is part of Windows XP Service Pack 2 includes a method of saving this configuration detail to a USB flash drive (or other storage media) to transfer the necessary settings to other XP SP2 systems.

WPA (Wi-Fi Protected Access)
Some routers and clients may support enhanced security features that are stronger than WEP encryption. WPA automatically rotates or changes the encryption key, making it more difficult for eavesdroppers to determine the codes necessary to access your network. All of your devices must support the feature to be able to take advantage of this, so check your documentation. If you are using equipment from assorted manufacturers, and one piece does not support WPA, then you must decide whether to use WPA - but not with that adapter, or not to use WPA on your network.

4. Use MAC (Media Access Control) address filtering
Most routers support this feature. To determine the hardware (MAC) address for your wireless network adapter, examine the details of your wireless adapter properties or use the text IP configuration utility with the /ALL switch (IPCONFIG /ALL). You can manually enter this address into a client list through the router's setup menus. Once a list of your known adapters has been entered and the MAC filtering feature is active, only devices with these addresses will have access to the router. Again, there are ways around this, but only if the hacker is really determined to get into your equipment.

MAC filtering must be enabled in the router or access point. Once this has been done, there should be a section to select or enter the MAC Address of the wireless client that you want to have access on the network. Devices that are not in the MAC address list will not be able to connect to the network.

The MAC address for your adapter can be found on a label on the adapter itself in most cases, although if this is a wireless adapter built-in to a notebook computer, you will find it easier to just check the network connection status. To do this, open your Network Connections, either from the Control Panel or by right clicking on "My Network Places" and selecting "Properties". Double click on your wireless connection icon to open the status window. Click the "Details" button to display the current configuration details and the MAC address (Physical Address) at the top of the list.

Most routers will allow you to add MAC address from a list of devices that have recently connected to the router. Verify that the MAC address you select is the one that matches your client computer.

5. Other Network Security
Hiding the SSID, using WEP, WPA and MAC Address filtering are all features of Wireless Networking; In addition to these, you should take general Internet and networking security precautions as well. Standard security measures would include Virus Scanning, Firewalls, and restricting your resources being shared.

[caption id="attachment_218" align="alignnone" width="300" caption="Antivirus applications like ESET NOD32 can catch individual threats as they get downloaded to your system."]ESET NOD32 program[/caption]

Virus Scanning
Virus scanners with current definition files will generally scan any file or attachment that gets saved to your computer. Most Anti-Virus programs scan the files as they arrive, even in the background, blocking or deleting threats before they can infect your system. When sharing your hard drive or directory on the network, most will detect infected files as they arrive, even from "trusted" users on the network.

[caption id="attachment_219" align="alignnone" width="300" caption="Malware programs can bypass your antivirus application if the bad guys trick you into installing something. Like antivirus apps, anti-malware apps can be used to keep your system clear of threats."]Malwarebytes[/caption]

Malware
Unlike viruses, malware can bypass your firewall and even antivirus security because many of these threats are "invited in" by the user. Malware (malicious software) can take several forms, including key-loggers, anti-malware apps, addware, and spyware, just to name some of the more common ones. There has always been a risk to specific programs or browsers, and some malware can target these to attack systems across multiple platforms.

Keep in mind, that any system, Macintosh, PC, or Linux can be infected. Linux is reasonably secure, only because there are so many different versions and implementations available, making it difficult to consturct a program to attack your specific OS. This does not make it invunerable, just less likely to be on the receiving end of most malware.

[caption id="attachment_220" align="alignnone" width="300" caption="A fake security application shows up after users are tricked into installing it - on a Macintosh."]Malware example[/caption]

Macintosh likewise enjoyed a similar status, being based on Unix, and having a much smaller market share. But that has been changing, and we have seen more malware and viruses both on this platform.

Firewalls
Firewalls are software that monitor and block suspicious network activity. Windows XP has a basic firewall that can be enabled for any network connection, including Wireless connections. Starting with Service Pack 2, a more robust version that allows you more configuration options is installed. Vista and Windows 7 both have more aggressive firewalls than XP.

The main feature of the Windows Firewall is to block external threats from accessing your computer over your network. Third party Firewalls can expand on the features to monitor activity generated by the various programs on your computer, alerting you to suspicious behavior as it occurs. This has the advantage of detecting (and blocking) Spyware and Adware types of software, that are attempting to report your activity or sending personal information out to the Internet.

Resource Sharing
As with any network, you can share printers and files on the network. But without some sort of security, anyone connecting to your network can access these resources. For this reason, sharing your files on the network can be a risk to either privacy or the security of the system itself.

If you share your C: drive for example, you are allowing people on the network access to all of the files on the drive, and not just ones that might be in your pictures or documents folder. There would be network access open to your system files, to the hidden boot files, and to your programs and data files as well.

If an unknown someone were to alter or delete one of the critical system files, it is possible that your system would not be able to start the next time you power on. If a program directory were deleted, that application would have to be re-installed before you could use it again. And if you lose the only copy of your report or thesis paper, you could be out of luck in more ways than one.

What can you do to prevent this type of issue? The easiest way to avoid problems like this is not to share printers and files on the network, but if you need to do so, only share the folder that contains files that you want others to be able to access. In simple terms, share individual folders and not drives.

You can also restrict access to files that are being shared by creating a read-only share. When you share a folder, one of the options is to "Allow others to make changes to the files." By leaving this check box blank, others can access your shared folder and the files you place inside, but they cannot delete or change the files themselves.

If you want to get really paranoid under Windows XP Professional (sorry, not supported with the Home version), or you just like the level of control that was standard in Windows NT or Windows 2000, then turn off "Simple File Sharing" under the folder options. When this feature is disabled, you can set security and access permissions for folders or individual files. Additional levels of security can be set, allowing you to allow one user read-only access, and another full-modification access. You can prevent the folder directory from being shown, but allow access to a file if they know the name.

To enable or disable simple file sharing under Windows XP, open My Computer, select "Folder Options" from the Tools menu, select the "View" tab and scroll to the bottom of the checkmark list. To be able to grant permissions to a specific user, you will have to add users from "User Accounts" in the control panel. If you get thoroughly confused after looking at this, change it back by replacing the check mark next to "Use Simple File Sharing".

Tuesday, March 29, 2011

How to Determine When Your ESET Product License Expires

If you are not sure when your ESET license expires, there is a way in the program to determine when it will expire:
  1. First, you will need to open ESET NOD32 or ESET Smart Security. Click on the Start button in the bottom left corner of your screen.
  2. Open All Programs, located just above the Start button.
  3. Select the ESET folder and open the ESET Antivirus program or Smart Security program.


  4. This will open the Protection Status page. The date on the “License valid until” line is the date your ESET product will expire.

NOTE: If you just renewed, activated, and entered your new username and password, then this line may not appear. That is normal. It will be displayed after the program does an automatic update.

Resources:
MicroCenter Tech Support Online. ESET Help. http://www.microcentertech.com/eset/

Wednesday, January 19, 2011

Virus ALERT: Palladium Pro and System Tool

The "Palladium Pro" and "System Tool" are the latest versions of more fake anti-virus programs similar to  "Security Tool". Both programs pretend to operate as a virus scan, but in effect, install a computer virus which takes over your system’s processes.

Palladium Pro Program


The Palladium Pro virus works by launching a bogus Microsoft Security Essentials alerts and stating that the system requires a virus scan. Once the virus scan is initiated, Palladium Pro installs the malware onto your system. To remove the Palladium virus, you will need to terminate the application’s process and install Malwarebytes to remove the program.

To Remove Palladium Pro:

  1. Start the Windows Task Manager by clicking Ctrl, Alt, Delete together.


  2. Click on the Processes tab.
  3. Locate the Palladium program named “palladium.exe”.
  4. Select the palladium.exe process and click End Process. This will suspend the Palladium Pro software.
  5. In the Windows Task Manager, go to File » New Task.
  6. Type in “explorer.exe” in the Open field, then click OK. This will open your Windows desktop.
  7. Download a copy of Malwarebytes software here » http://www.malwarebytes.org



  8. Follow the instructions to run a system scan and file removal.


System Tools Program

The System Tools program is associated with the same family of fake anti-virus programs as Security Tool. This software floods the system with false virus alerts and instructs the user to run the virus scan.

To Remove System Tools:
  1. Start the Windows Task Manager by clicking Ctrl, Alt, Delete together.
  2. Click on the Processes tab.
  3. Locate the program file. It is usually represented by a set of random characters followed by the ".exe" extension.
  4. Download a copy of Malwarebytes software here »http://www.malwarebytes.org
    If your computer prevents you from downloading the file, you can download Malwarebytes from another system and copy the file to your infected system to install. Or, you will need to update the Internet Options in Internet Explorer by modifying the default LAN settings to NOT use a proxy server for your LAN settings.
  5. Follow the instructions given by Malwarebytes to run a system scan and file removal.
IMPORTANT: Never install any program or run a virus scan without verifying the source. If you suspect that your system is infected, use industry-approved programs such as ESET, McAfee, Symantec or Webroot. If you need further assistance, contact Micro Center Tech Support at www.mctsol.com.


Reference:
Bleepingcomputer.com. Palladium Pro Removal
http://www.bleepingcomputer.com/virus-removal/remove-palladium-pro

Bleepingcomputer.com. System Tool Removal
http://www.bleepingcomputer.com/virus-removal/remove-system-tool

Microsoft Support Forum. Palladium Removal.
http://social.answers.microsoft.com/Forums/en/msescan/thread/6e837554-4374-4709-8e51-e878ac8817e1

Microsoft Support. Microsoft Windows Malicious Software Removal Tool.
http://support.microsoft.com/kb/890830