AMAZON

Showing posts with label SOFTWARE. Show all posts
Showing posts with label SOFTWARE. Show all posts

Friday, September 25, 2009

Avira AntiVir Premium 8.1.00.331

Avira AntiVir Premium 8.1.00.331

Avira AntiVir Premium enhances the comprehensive protection of the Avira AntiVir Personal - Free Antivirus with important security and configuration functions and protects you against viruses, worms, Trojans, ad/spyware, dialers, bots and dangerous drive-by downloads.

Premium functions:
- Low system resources used;
- Control Center for monitoring, administering and controlling the entire program;
- Central configuration with user-friendly standard and advanced options and ontext-sensitive help;
- Scanner (On-Demand Scan) with profile-controlled and configurable search for all known types of virus and malware;
- Guard (On-Access Scan) for continuous monitoring of all file access attempts;
- MailGuard (POP3- and SMTP-Scanner) for the permanent checking of emails for
viruses and malware. Checking of email attachments is included;
- Exclusive download server for faster updates;
- User-defined update intervals;
- Phishing and Rootkit Protection.

NEW: Version 8 offers:
- An enhanced interface graphical interface,
- A modularized AV-search engine for improved scan performance,
- An integrated failsafe security system, and SMTP support for AntiVir MailGuard,
- NEW modules: WebGuard and Rescue System.

Download:
Code:
http://rapidshare.com/files/125867033/Avira_AntiVir_Premium_8.1.00.331.www.legendaryhackerz.com.rar

pass:
Code:
http://www.legendaryhackerz.com lintasberita

Spyware Doctor 6.0 Final

Spyware Doctor 6.0 Final


[Image: g33agydbxjfiq25gef0v.jpg]

Spyware Doctor Tools:
- Spyware & Adware Scanner Keylogger
- Guard Popup
- Blocker Phishing
- Protector Real Time
- Protection Browser
- Guard Spyware Cookie
- Guard Malware
- Immunizer

Spyware Doctor Key Features:
• Comprehensive Malware Protection
Spyware Doctor provides protection against identity theft, stealthy spyware, aggressive adware, browser hijackers, malicious ActiveX objects, malware Trojans, tracking cookies, keyloggers, dialers, and other malware. The optional anti-virus module also protects your computer from viruses, worms, Trojan horse threats, and other malicious infections.
• Constant Real-time Protection
Through its unique OnGuard feature Spyware Doctor provides constant protection against malware. OnGuard works by blocking both known and unknown malware threats before they can install and cause any harm to a computer. OnGuard constantly monitors for malicious behavior involving spyware processes, tracking cookies, malicious ActiveX objects, browser hijackers, keyloggers, Trojans and more.
• Advanced Detection and Removal Technology
- By running an Intelli-Scan™, Full Scan or Custom Scan, Spyware Doctor will inspect the computer for all types of spyware and virus1 infections. Spyware Doctor is top rated by industry experts as being extremely effective in removing particularly nefarious threats such as rootkits and keyloggers2.
- The unique Intelli-Scan™ feature is specifically designed to hunt swiftly and kill active running spyware threats in as little as 3 minutes3, attributed to the intuitive and patent-pending spider scanning technology. This new technology works intelligently by using a combination of signature and behavioral scanning techniques to quickly and effectively identify internet threats.
• Protection against zero-day threats - Behavioral Heuristic Detection
Spyware Doctor delivers effective zero day protection against rootkits and keyloggers (in both scanning and OnGuard real-time areas) by monitoring for suspicious behavior and blocking applications that exhibit signs of malicious activity.
• Advanced Rootkit Detection
Spyware Doctor is capable of detecting and removing hidden processes and files associated with complex threats and rootkits. Using behavioral techniques, rootkits and other items that attempt to hide themselves deep in the computer operating system are effectively detected and removed.
• Works silently in the background with low CPU usage
When in monitoring mode Spyware Doctor has been designed to work silently in the background, with little impact to the end user, threats are blocked and removed without any system impact, while only a small alert window is displayed to advise the user it has been protected against an attack. When running a scan, the CPU Priority settings allow users to lower the priority of the scanning in order to reduce CPU usage and impact to the computer while in use. Selecting this option may increase scan time but will ease CPU usage when other applications are running at the same time.
• Automatic and silent Smart Updates
Frequent updates to detect and guard computers against new threats and viruses as well as provide enhancements to Spyware Doctor are automatically installed and downloaded through the Smart Update function. Threat signatures are updated every business day or within hours of a high risk malware outbreak to protect you from the latest online threats.
• Most internationally awarded anti-spyware product
Spyware Doctor is consistently awarded editors choice and top rating by numerous internationally recognized and respected industry publications, making Spyware Doctor the most internationally awarded anti-spyware product.

Additional Add-ons:
• Virus Protection
Available as an optional add-on to Spyware Doctor, the anti-virus component provides protection against all kinds of viruses, worms, Trojan horse threats, and other malicious infections to ensure complete protection against internet threats. It is recommended to install the anti-virus add-on if there is no other virus protection on the computer.
• Email Protection
Email Guard provides protection against, and instantly removes, spyware and viruses being sent or received via e-mails. All popular e-mail applications (such as Outlook Express™ & Netscape® Mail and Thunderbird) that use POP, IMAP or SMTP are supported by Email Guard.
• Internet Browsing Protection
Site Guard provides advanced protection against potential malicious websites and phishing attacks where dangerous site are masquerading as legitimate e-Commerce sites. Site Guard will detect malicious websites and block access to them, ensuring the computer cannot be infected.
Designed for Windows® Vista™ 32-bit, XP and 2000.

What's New in Spyware Doctor 6.0 :
• Latest protection from unknown threats
- Spyware Doctor now has Behavior Guard, providing you with the latest pro-active behavioral-based technology against zero-day (never seen before) threats. Built on the award-winning ThreatFire technology, Behavior Guard has been seamlessly incorporated into Spyware Doctor to offer you leading protection. This new technology protects you when some anti-virus products give up! Read more about behavior-based protection.
• Improved detection capabilities:
- Spyware Doctor has been enhanced to improve detection effectiveness. In particular, each individual signature created in the threat database is optimized so that it is capable of detecting multiple variations of malware threats (threat variants) while maintaining minimal system resource usage (memory footprint).
• Swift clean-up for heavily infected computers:
- Spyware Doctor is able to detect and remove threats on heavily infected computers faster and easier than ever before. Sometimes your computer is so highly infected that you may find yourself unable to install or run security software except when in the ‘safe mode’ of Windows.
- In these cases, malware consumes computer resources so resulting in lengthy scanning and removal times. is now armed with the technology to scan in safe mode faster and more effectively by forcing your computer to take a higher priority over the scan than the malware and other software attempting to run on your system.
• Improved Hacker Defense :
- Further improvements have been included to enhance our own defense against malware threats attempting to interfere with the effectiveness of Spyware Doctor . Our hacker defense system means you can rest assured that your computer system has the most comprehensive protection while ensuring that malware threats don’t impede on the functionality or effectiveness of Spyware Doctor.
- The new hacker defense utilizes a particular feature available in Windows Vista (known as ASLR) to make it difficult for hackers to exploit or gain control over Spyware Doctor .
• Other enhancements:
o Support for Windows Security Centre in Windows Vista Service Pack 1
o The real-time protection module is now referred to as Intelli Guard®
o Enhanced error reporting to assist with diagnosis of program crashes (hackers!).

Download | 15012 KB
Code:
http://rapidshare.com/files/124461078/Spyware_Doctor_6.0.0.354_updatable.rar lintasberita

BitDefender Antivirus 2009

BitDefender Antivirus 2009 Build 12.0.10 Final(32Bit)

[Image: lqsi2q0z3immmt8d1h60.jpg]

A professional antivirus program including security features
BitDefender Antivirus 2009 was designed to be provide advanced proactive protection against viruses, spyware, phishing attacks and identity theft, without slowing down your PC.

BitDefender AntiVirus 2009 - Superior Proactive Protection from Viruses, Spyware, and other e-Threatsthat wont slow you down!
BitDefender provides security solutions to satisfy the protection requirements of today's computing environment, delivering effective threat management to home and corporate users. BitDefender Antivirus is a powerful antivirus and antispyware tool with features that best meet your security needs. Ease of use and automatic updates make BitDefender Antivirus an install and forgetproduct.

BitDefender a global provider of award-winning antivirus software and data security solutions, has launched BitDefender 2009 its new line of security solutions providing state-of-the-art proactive protection from todays most damaging viruses, spyware, hackers, spam, phishing attacks, and other common Internet security threats.


Features:


· Confidently download, share and open files from friends, family, co-workers and even total strangers!
Improved: Scans all web, e-mail and instant messaging traffic for viruses and spyware, in real-time
Proactively protects against new virus outbreaks using advanced heuristics

· Protect your identity: shop, bank, listen, watch privately and securely
Blocks attempted identity theft (phishing)
Improved: Prevents personal information from leaking via e-mail, web or instant messaging

· Guard your conversations with top-of-the line encryption
Instant Messaging Encryption

· Play safe, play seamlessly!

Improved: Reduces the system load and avoids requesting user interaction during games

· Get fine-tuned performance from your computer !
Uses few system resources
Laptop mode prolongs battery life
Improved: Scans all web, e-mail and instant messaging traffic for viruses and spyware, in real-time
Proactively protects against new virus outbreaks using advanced heuristics

· Family network protection
Manage the security of your home network from a single location. BitDefender software from other computers in the network can be remotely configured, while tasks such as scans, backups tune-ups and updates can be run on-demand or scheduled to run during off-hours.

· Hassle Free Hourly Updates
Hourly updates ensure that you are protected against the latest threats without pushing a button. Lost program files are not a problem either. In the rare event of file damage due to PC problems, BitDefender automatically repairs and updates itself.

Download | 53859 KB
Code:
http://rapidshare.com/files/139859604/BitDefender_12.0.10_ByMechoDownload.rar
pass: mechodownload lintasberita

Friday, September 11, 2009

How To Clean An Infected Computer

How To Clean An Infected Computer....


Cleaning an infected computer today has become harder than ever. To effectively clean your system you must first learn a little about what you are trying to get rid of and what tools you need to get the job done. I'm going to try to give you some of the background, followed by the basics of getting rid of these pests.

Today there are a variety of things that can infect your computer such as viruses, worms, trojans and spyware. I refer to all of them as malware since that word seems to best describe them and covers both viral and spyware related issues. I find it best to use a multi-pronged approach to fighting malware, so I use several software programs to find and get rid of them. Hopefully, by giving you a little of the background, you will be able to learn what tools to use and when to use them so that you may clean your computer of the malware you may encounter.

Viruses were the first computer bugs, and anti-virus (AV) software was made specifically to detect and get rid of these. Worms are a little different than viruses, which is one reason why AV software has had a harder time catching them. Next came trojan horses, usually just called trojans. These are very different than both viruses and worms. They actually take advantage of the weaknesses that are inherent in AV software. For one, most trojans actually try to hide from being detected by AV software. They also work "smarter" by creating hidden copies of themselves so that when they do get detected and cleaned, they can re-infect the computer with the hidden copy right after the AV software cleans the original infection. Basically, trojans are AV software's worst nightmare simply because AV software wasn't designed to specifically go after this type of threat. Today, AV software is much better at detecting all types of malware. With the release of AVG 8.x.xxx... it now combines both an antivirus with an antispyware scan to help users fight both viral and spyware related issues.

Spyware isn't a new breed of malware. It is simply a combination of various computer exploits and they utilize various combinations of scripts, trojans and worms. Currently they take advantage of trojans the most since they are harder to detect and clean properly. Anti-spyware (AS) software was created specifically for detecting and cleaning this type of malware, so when it comes to trojans and some worms, AS or a combined AV/AS software is much better equipped to fight these than the AV only types of software such as the earlier versions of AVG.

A new varient of spyware is the Rogue type of malware software. This type of software pretends to be useful utils like antispyware, antivirus, hard drive and/or registry cleaning utilities but really their only goal is to sell you their useless software or to install other spyware onto your system. They do this by falsely stating you are infected by something or have other issues that could affect the performance of your system. They usually are installed using the "drive by installation" method that happens when you may visit various malicious websites, often installing without your knowledge.

There is also another type of detection that AVG and most good AS softwares will detect and they are only detected because of their potential security risk if a user was unaware of their existance. AVG calls this type of software Potentially Unwanted Programs ( PUPs )... others may refer to them as hacktools, riskware, or simply "not-a-virus". These are normally very useful utilities.. but since they can also be used for harm, AVG and other utils will detect them so the user is aware of their existance. Examples of these are utilities to recover forgotten passwords, forgotten software keys ( like the Windows install key ), IP scanners, remote control software and a variety of similar utils. If you have any of these installed or on your system, you will want to exclude them from detection with whichever utility you are scanning for malware with... or at the very least do not have them removed when you are cleaning the system up. Remember that these are not malware and do not do damage to your system BUT if you are unaware of their existance, it could be a sign that a hacker may have placed them on your system to do harm. A quick rule of thumb, if you are aware of their existance leave them on your system... if not quarantine them and check out what they really are later.

I suppose I should also cover one last subject before moving on to the cleanup steps... Tracking Cookies. AVG as well as most antispyware utils do detect these and each has a specific but different list of the ones they will find. These ARE NOT MALWARE.. they can do no harm or damage to your system. They do however represent a potential invasion of your privacy since they can be used to track your internet browsing habits. So unless you have setup your browser to block them or use a specialized utility to do that... you will always find these detected. So do not be alarmed by their presence.. clear them if you want ( I always clear mine )... but also understand that they will likely return the next time you happen to visit a website that may use them.

First, you will need to get some software programs to help you. The following programs are what I use personally. Not only do I trust them, but they are also free for personal use. The companies that provide the free software, also provide software that they sell for use in a commercial environment. Usually, the free versions are just as good but simply don't have as many of the extra features which make the commercial versions even more attractive to use.

Anti-Spyware Software

For Windows 98 & later

• Spybot S&D - You can find it at [www.spybot.info] Latest version is v1.6.2.46

( NOTE: When installing Spybot, I recommend that you disable the option for TeaTimer which is enabled by default so it doesn't affect your cleaning efforts. If you wish you can enable it later but do so only after you finish cleaning the system. )

For Windows 2000, Windows NT, Windows XP & Vista only

• MalwareByte's Anti-Malware - You can find it at [www.malwarebytes.org] Latest version is v1.34

Anti-Virus Software

For Windows 2000, Windows XP (inc. 64bit version) & Vista (inc. 64bit version)

• AVG Technologies Free Edition - You can find it at [free.grisoft.com] - English version, [gratis.avg.it] - Italian version, [free.avg.de] - German version, [gratuit.avg.fr] - French version, [free.avg.com] - Japanese version, [free.avg.com] - Brazilian Portuguese version, [free.avg.com] - Dutch version, [free.avg.com] - Latin America Spanish version, [free.avg.com] - Polish version, [free.avg.es] - Spanish version, [free.avg.com] - Portuguese version, [free.avg.cz] - Czech version, [www.avg.com.tr] - Turkish version, [www.avg.in] - Indian (English) version, [www.avgkorea.com] - Korean version & [www.avgtaiwan.com] - Taiwanese version Latest version is v8.5.387

First you will want to download each of the above programs and then install them. After you install them, you MUST update them so you will have the latest protection. If you don't update these programs and you are infected with the latest parasites, you will not be able to effectively detect and clean them from your computer, so remember to update, update, update. Most if not all of the definition files for these utils are now updated daily.

Now that you have downloaded, installed and updated all of the above utils... Print this article so you can refer to it later and disconnect your computer from the internet. This is an important step and will remove one way that a malware may use to re-infect your computer.

With the release of AVG 8.x now combining both antivirus and antispyware into one product, I have now switched from scanning with it last, to scanning with it first since it now detects more malware than any of the others. I also use the different AS software packages in a specific order so that I go after the tougher problems first and the easiest ones last.

Turn off System Restore

• WinME and WinXP have a cool feature called System Restore. It is used to restore your computer to an earlier configuration in case of a problem. The only problem is that it wasn't made with malware in mind, and often it can't tell the difference between an infected file and a good file, so it can as easily restore an infected file if it had been in a protected area, effectively re-infecting your computer right after you have cleaned it. Because of this, it is recommended to turn off System Restore before you test, and when you're done, turn it back on so you are still protected from standard computer problems.

• For WindowsME

Click Start, Settings, and then click Control Panel.
Double-click the System icon. The System Properties dialog box appears.

NOTE: If the System icon is not visible, click "View all Control Panel options" to display it.

Click the Performance tab, and then click File System.
Click the Troubleshooting tab, and then check Disable System Restore.
Click OK. Click Yes, when you are prompted to restart Windows.

• For WindowsXP

Click Start.
Right-click the My Computer icon, and then click Properties.
Click the System Restore tab.
Check "Turn off System Restore" or "Turn off System Restore on all drives."
Click Apply.
When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
Click OK.

• For Win Vista

1. Open System by clicking the Start button , clicking Control Panel, clicking System and Maintenance, and then clicking System.
2. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
3. To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK.


Carefully Look at Windows Add/Remove programs for suspicious programs

• Many of the spyware threats actually install into your system just like a regular program. Many may appear to be utilities that you may think are helpful but in reality aren't. Look for add-an toolbars, while toolbars like those provided by Google, MSN, Yahoo and other are great utils, there are many more that aren't and if in doubt check it out to see if ones you have are parasitic. Another common exploit are the Search helpers, WinTools, Gator products, IE Helper, Comet Cursor and many others just to name a very few. Peer-to-Peer (P2P) programs are another common source for these and even the ones that doen't come with spyware themselves are a high security risk that may lead to your system being infected or to spread infections like these. Remove all suspicious programs, if you accidentaly remove the wrong item, you may always re-install them later.

Run Disk Clean-Up

• This actually comes with Windows and has been installed by default since Windows 98. You can find it by clicking the Start Button and then going to Programs / Accessories / System Tools / Disk Clean-up. I recommend selecting all of its options except the ones for Office Setup Files and Compress Old Files if you have them. While you may select those if you wish, they aren't as important. This will clean up all of the temporary files so your testing will go faster, and may also delete any spyware that may hiding there if the spyware isn't already running. To clear systems that have System Restore you will need to select the second tab and click the button for clearing this.

Run AVG 8.x.xxx

• Most antivirus programs, including AVG, by default have their settings to only scan executable files in an attempt to speed up looking for infections. While most of the time this is just fine, the newest threats that can infect your computer have started getting sneaky on how they hide their files making it easier for them to reinfect your system if your antivirus program detected and removed their executable file. To help also detect these "backup" files that the infection leaves on your system, you should in my opinion, make a couple of changes to what your AVG scans during these tests from just executable files to all files.

• To change AVG's settings during a scan, open AVG's User Interface.
Click the Computer scanner tab, then under the Scan whole computer area, select Change scan settings. Unselect Scan infectable files only and select all other checkmarks with the Automatically heal/remove infections and Scan for Tracking Cookies as options I'll let you decide if you want enabled or not.

• Now AVG will scan all of the files when you scan your computer. This will take longer to complete, but I feel it is a small price to pay for the added security it provides.

Run MalwareByte's Anti-Malware

• Select to perform a Full Scan and then click the Scan button. This is another specialized util that not only targets Rogue spyware but other malware as well. This currently targets malware and rogues from 931+ vendors ( the malware authors ). The malware that is targeted in this category is very actively being updated by their authors because of the potential they have for making money. As with all antispyware utils, update this often and before each use to help give you the edge in fighting these malware.

Run Spybot Search and Destroy

• When you run it, it will automatically select all the spyware that it finds, if there is something you don't want to get rid of for some reason, deselect it and then let Spybot fix all of the rest of the problems that it finds. This program also will ask to restart your computer so it can test again if it has problems removing something, so let it.

• Run the scans again in Safe Mode. This will keep many of the parasites from loading and being able to hide from your protection software. To access Safe Mode on most versions of Windows, start tapping the [F8] key after you first start or restart your system, start tapping it before you ever see a Windows Splash Screen and continue until you get the Menu where you may select it from the list. On WinNT, this is called VGA mode and on Win2k you actually start tapping just after the first splash screen shows. For Detailed instructions see Restarting Your Computer in Safe Mode

These procedures should have cleaned most cases of infection that you will find. Yes I said MOST because there are some infections that are very hard to detect and remove. Generally, if you have one of these, you will need the assistance of an expert to help you get rid of it.

When you believe you are finished, remember to turn System Restore back on if you had turned it off.

I recommend testing for parasites as often as you can, probably at least once a month if not more. The sooner you catch them, the less damage they can do to your computer, and the less chance of a hacker finding your sensitive information such as checking account info, passwords, etc.

Windows Tip

Windows itself, by default, hides certain files, system folders or file extentions from the user to make it easier to navigate. If you are having to find an infected file or just one you are looking for, this can cause you to not find it. If you wish you may change this to show all of the files on your computer.

Open your My Computer icon (Either from your desktop or the Start Menu)
Click the Tools menu and select Folder Options(on older systems it may be in the View menu)
Select the View tab and scroll through the Advanced settings
Enable or disable the following (using a checkmark to enable)

enable - Show hidden files and folders
disable - Hide extentions for known file types
disable - Hide protected operating system files (WinME and WinXP only)

Now click Apply and Ok

For Win Vista info. see this link [www.howtogeek.com].

How to find an embedded infection

AVG 8 Free now detects infections in areas that it was unable to before. The most notable are ones embedded inside of archives. Since AVG can't determine if you created the archive or if it was a parasite that created it, they leave these alone so you may have a chance to recover uninfected files from the archive and then you simply delete the archive when done. Infections that are inside of an archive aren't a direct threat to your system unless the file gets extracted to allow it to run. Grisoft has chose this method because it is safer for your data that the archive may contain.

For someone that is new to looking for these embedded infections, it can be a little confusing with the way that AVG will list the file because it also must include the archive file name that contains it in the full path/filename. The following is an example that I made up to highlight the info so you will know which filename to look for so you may either extract files and or delete the correct file. I will color code these for you, but AVG will not.

AVG will give you a name like...

C:\Windows\Temp\InfectedArchive.cab:\InfectedFile.exe

The location of the file is in C:\Windows\Temp
The archive that contains the infection is InfectedArchive.cab
And the actual infected file inside of the archive is InfectedFile.exe

Note the ":\" that seperates the archive from the file it contains.
After you have recovered any files inside of the archive that you may want to keep (other than the infected one that is) just simple delete the whole archive.. in this example the file to delete would be InfectedArchive.cab

It looks harder than it really is.. just remember the file you want to look for is named just before the last ":\"

Most of the time, you won't have any files to recover inside of the archives. The only time this isn't true is if it is an archive that you had created yourself. If you didn't create it.. just delete and move on. lintasberita

Tuesday, September 8, 2009

Anti Virus Smadav

Keep Care Your PC with Smadav 6.3 | Update Smadav
Joe Engressia, Tuesday, September 8, 2009

smadavlogo.jpgDownload Anti Virus Smadav Rev 6.3 September 2009

This is the awaited, SmadAV Rev 6.3 2009 For those who have not already and download previous Anti virus SmadAV Rev 6 2009. Smadav parties have done some bug fixes & false alarm on the revision this time. When you find a bug or LOCAL NEW VIRUS that has not been detected Smadav Rev 6 2009, please report them immediately on this site www.smadav.net. So, for ALL USERS SMADAV recommended the ROUTINE / EVERY DAY visit to this site to download the latest revision Smadav Rev 6.3 2009.


Included in Smadav rev 6.3 2009 Engine :

Eradicating more than 100 last local virus on Agustus 2009
The Viruses are album bokep, yuyun, fullhouse, sandra dewi, mbah surip, etc.
Scanner
Super Fast and became the fastest in the WORLD (Can be your own).
Smart Protection
It has smart protection that is better than smadav Rev 6
Registry Cleaner
Smadav Rev 6.3 2009 has supported Windows Vista
Cleaner
Not only remove but also Clearing (Heal) document from the virus.
Protector
Protect your computer from virus attacks at any time, you will feel safe.
Update
now, You can update via Internet or off line as well as AVG, Avira.
Intelligence
A Smadav like "The Virus Exterminator" is on your computer.
Portable
Smadav can be used in Windows ME/2000/NT/XP/Vista. No need to install.
SmadLock Flashdisk
Once locked with Smadav, Your USB flash will be safe to go everywhere without fear of virus infection. Features the latest in the WORLD

Related Link to Download Smadav :

* Download Smadav 6.3 2009
http://www.smadav.net/smadav63.zip

* Download The Last Update Smadav 2009
http://tolearnfree.blogspot.com/search/label/Anti Virus lintasberita

Clean Virus With Avast

avast! Virus Cleaner - free virus removal tool

avast! Virus Cleaner is available free for every user. This tool will help you remove selected worm infections from your computer.
Free virus & worm removal tool

If, despite all the security measures you take, your computer gets infected by a virus or worm, it is necessary to disinfect your system somehow. While for some viruses the only 100% reliable method of disinfection is restoring your system from backups, for many common infections this is not really necessary and the virus/worm can be removed quite easily.

Removing the infection
The worms often schedule themselves to be run automatically when you start your operating system; some of them even register themselves to be run when any other application is started. Removing such a worm is not as simple as deleting it - when you just delete the worm file, your operating system might not be able to start your applications (such as Explorer) any more.

So, in order to properly remove the worm from your computer, it is often necessary to make additional fixes in your system registry, delete the links from your Startup Folder etc. Here the avast! Virus Cleaner comes - it will find and remove selected worms from your computer, as well as fix the registry and startup items to make sure your system will work correctly after the disinfection.

Many worms - when activated - create additional working files on your hard disk. Even though these files alone are harmless, they are useless and they should not be there. When avast! Virus Cleaner detects and removes a known worm from your computer, its working/temporary files are removed as well. The same applies for worm-specific registry entries etc.

List of known worms
avast! Virus Cleaner is currently (in version 1.0.211) able to identify and remove the following worm families:

* Win32:Badtrans [Wrm]
* Win32:Beagle [Wrm] (aka Bagle), variants A-Z, AA-AH
* Win32:Blaster [Wrm] (aka Lovsan), variants A-I
* Win32:BugBear [Wrm], including B-I variants
* Win32:Ganda [Wrm]
* Win32:Klez [Wrm], all variants (including variants of Win32:Elkern)
* Win32:MiMail [Wrm], variants A, C, E, I-N, Q, S-V
* Win32:Mydoom [Wrm] (variants A, B, D, F-N - including the trojan horse)
* Win32:Nachi [Wrm] (aka Welchia, variants A-L)
* Win32:NetSky [Wrm] (aka Moodown, variants A-Z, AA-AD)
* Win32:Nimda [Wrm]
* Win32:Opas [Wrm] (aka Opasoft, Opaserv)
* Win32:Parite (aka Pinfi), variants A-C
* Win32:Sasser [Wrm] (variants A-G)
* Win32:Scold [Wrm]
* Win32:Sinowal [Trj] - variants AA, AB
* Win32:Sircam [Wrm]
* Win32:Sober [Wrm], variants A-I, J-K
* Win32:Sobig [Wrm], including variants B-F
* Win32:Swen [Wrm], including UPX-packed variants
* Win32:Tenga
* Win32:Yaha [Wrm] (aka Lentin), all variants
* Win32:Zafi [Wrm] (variants A-D)

Disinfection process in detail
By default, avast! Virus Cleaner does all the work automatically. When you start it and press the "Start scanning" button, the following will be done:

1. The operating system memory will be scanned, and if any known worm is found, the worm process is terminated - thus avoiding further spreading. If it is not possible to terminate the worm process (it could happen e.g. with Nimda worm that uses a fake library to run inside other processes), the worm will be deactivated in memory to stop its spreading.
2. Your local hard disks will be scanned.
3. The "startup items" (such as the system registry, Startup Folder(s), etc.) will be scanned. References to worms found in memory or on disk will be removed or fixed.
4. Infected files, identified in point 2, will be removed or fixed (as needed).
5. Additional working/temporary files created by the identified worms will be removed.
6. If restarting the computer is needed to finish the disinfection process (e.g. when a file could not be removed because it was currently in use, or if the deactivated worm process is still present), the user is notified and asked whether the restart should be done immediately.

avast! Virus Cleaner - Main Window

For experienced users, various command-line arguments can be used to customize the program behavior. The list of command-line arguments will be displayed when started with /? parameter. Note: the command-line arguments are intended for experienced users only! Changing the default parameters may result in incomplete disinfection that may render your operating system nonfunctional, as noted above.

Important notes

1. During the scanning process, it is highly recommended not to start any applications. As already pointed out, some worms will start automatically when any other application is started. Running worm processes are terminated/deactivated only during the first phase of the avast! Virus Cleaner scanning; if you activate the worm again in the middle of the scanning process (by starting another application, such as Notepad, Explorer, ...), the worm will probably not be removed from your computer!
2. Turn off any resident (on-access) antivirus protection before running avast! Virus Cleaner. avast! Virus Cleaner has to access the infected files to be able to identify and remove them. The resident protection, however, might not permit it - and the worm could not be removed from your computer! Do not forget to activate the resident protection again after avast! Virus Cleaner has finished the disinfection.
3. avast! Virus Cleaner should be used in case you know or suspect that your computer is infected. It is not meant as an antivirus solution for everyday use! Use e.g. avast! 4 Home/Professional to protect your computer.
4. To work correctly, the Cleaner requires administrator privileges when running on Windows NT/2000/XP/2003 operating systems. On an infected computer, however, it might not be wise to log in as a privileged user (administrator) - it may help the worm to spread even further. Therefore, you can start avast! Cleaner as a restricted user and enter the administrator login name and password directly into an avast! Virus Cleaner dialog; in such a case, the Cleaner will be run with the privileged user access rights - however, the privileged user will not be actually logged on, and none of his/her startup files will be processed.

Solving other problems
If you have deleted a virus or worm file associated to a vital file type - and now you cannot run your applications anymore, avast! Virus Cleaner may help you as well. All you have to do is run avast! Virus Cleaner "somehow". If, for example, only the association for .EXE files has been corrupted, you may run the avast! Virus Cleaner by renaming it to a .COM file. The other extensions you may try are .SCR, .BAT, .PIF (on Windows NT/2000/XP/2003, you may try .CMD as well). If none of these extensions works (Windows is still reporting "Cannot find 'xyz.exe'" when you try to start the tool), you can use avast! Virus Cleaner itself as a replacement for the missing file. However, you have to know the name of the missing file to do that; if you know it, just rename the avast! Virus Cleaner file to the missing name (and move it to the corresponding folder, if necessary). Now, starting any application should bring up avast! Virus Cleaner instead. As soon as it starts, it detects that some of the vital file associations are corrupted, reports the problem and allows you to fix it immediately.
avast! Virus Cleaner Free Download
http://www.avast.com/eng/down_cleaner.html

Please download the free avast! Virus Cleaner tool from this page.
The latest version is 1.0.211, built on 11.5.2007. lintasberita

Sunday, December 14, 2008

WHICH IS SAFER,INTERNET EXPLORER OR FIREFOX

WHICH SAFER,INTERNET EXPLOREE OR FIRFOX ?

There is a lot of discussion going on about the relative safety of Internet Explorer vs. Firefox. In this article I say why I think most of the commentary is missing the point.


--------------------------------------------------------------------------------



The battle over the question in the title has been raging in discussions all over the Internet. Unfortunately, this is the wrong question. In fact, it is a meaningless question unless a lot of additional factors are considered. Security is a multidimensional problem and cannot be usefully discussed in the kind of simplistic comparisons that are being made.

I am not a professional security expert but there are some pretty obvious points that can be raised about how you define what is meant by “security”. The most popular way seems to be a kind of numerology where somebody with a vested interest like Symantec purports to count “vulnerabilities” or even “possible” vulnerabilities. The conditions where these vulnerabilities apply are usually not specified. Many questions have to be asked before any meaningful assessment of the severity of a problem can be made, For example, does having a firewall prevent them? Do typical anti-malware packages detect them? Does the user have to click on a link or do something stupid for the problem to apply? Can the problem be fixed by changing a default setting? How long does it take before a patch can be made? Not all “vulnerabilities” are created equal. A so-called vulnerability may be “potentially” very dangerous but not be a problem in practice because it easily fixed by standard measures or can only be incurred because of stupidity. So this numbers game looks very misleading to me.

The whole subject is quite complicated but in an attempt to keep this discussion reasonably short I suggest we replace the single question of the title with three questions (all pertain to Windows systems):

1. Which browser is safer for experienced computer users?

2. Which browser is safer for average computer users?

3. Which browser is safer for careless, uninformed or clueless computer users?

The answer to question 1 is that either browser will do. What browser is used by an experienced person is a matter of personal habits and preferences about different browser features. An experienced user knows what security precautions must be taken and will rarely get a problem just because of the browser that is being used. Personally, I use both Internet Explorer (IE) and Firefox. I prefer Firefox for most things but some sites only work in IE.

Next let’s consider question 2. The term “average” computer user covers a lot of different people so only a few generalities can be stated. The average PC user is not going to be familiar with the details of security measures but most will be aware that they need some kind of defense. If they have a PC bought in recent years they will have quite a bit of automatic protection such as anti-virus programs that update themselves and at least the Windows XP firewall. Also Windows update will be set to run unattended. Many PC users also have installed entire security suites. It is important to note the presence of these security measures because otherwise the question of which browser to use is moot.

For those people who have enough other security in place so that they can turn their attention to browser security, one question concerns updates. Both IE and Firefox have periodically been found to have security holes. IE has an apparent advantage in that it is automatically updated whereas at present Firefox has to be patched manually. Typical PC users can be lax about updating so that looks like a point for IE. However, this possible advantage is much lessened or even disappears because Microsoft can take many weeks to issue a patch for a known problem. Firefox patches come out within a few days after a problem is revealed. Which browser has the advantage here? For those who would keep up with the Firefox updates, I give the nod to Firefox on this particular issue. For procrastinators, maybe IE is better but future versions of Firefox are supposed to also update automatically. Note added later: Firefox version 1.5 is scheduled for release at the end of November, 2005. It contains an automatic update feature and that removes any advantage IE had for procrastinators.

There are also other security factors such as ActiveX, which I have discussed in detail on another page. On the issue of ActiveX, individual PC users will have to balance convenience with safety to decide on a browser. Knowledgeable users can configure IE to avoid ActiveX problems but I wonder how many average PC users will actually do what’s necessary. From a theoretical point of view, I think Firefox is safer because it doesn’t support ActiveX but from a practical view it can sometimes be inconvenient that some pages won't work for any browser but IE.

What about the average PC user who has an older system with Windows 98/Me? These people are totally ignored by most commentators but there are still quite a few of them around. They will be missing a lot of the security that Microsoft has added to IE in Windows XP SP2. Personally, I think that these systems are safer with Firefox. However, there is the psychological barrier that many people have about installing a whole new browser when they already have one in place. Also, IE has to be used for certain sites and this is another obstacle to using Firefox. For these users, I think that the theoretical answer to question 2 clearly is Firefox. In practice, however, most of these users will probably stick with IE. Hopefully, they will have enough security measures in effect to obviate the newer IE exploits that they are exposed to.

Now we come to question 3. This one is easy to answer. It doesn’t matter what this group uses for a browser. These are the ones that do not use firewalls or do not install security updates or blithely click on any old link. They have much bigger problems than what browser to use. Unfortunately, their problems are our problems, too. This group is where most of the worms and Trojans hide out. It is also where the crackers get their “zombie” machines to carry out Distributed Denial of Service attacks and conduct various criminal activities.

I have framed the discussion in terms of who the intended user is. To really discuss the issue of browser security would require a much more complicated metric. However, I think the discussion helps illustrate my contention that measuring security is not simple and that there is no easy answer that applies to everybody for the question of which browser is safer to use. If you held a gun to my head and demanded that I choose a browser for everybody, I would personally pick Firefox. But you still have to use IE for some sites like Windows Update whether you like it or not. And I haven’t even mentioned Opera or Netscape.

I am very interested to hear what you have to say about all this. Log on to http://tips.vlaurie.com and let me know what you think. lintasberita

WHAT IS TROJAN HORSE

TROJAN AND HORSE

In addition to the viruses and worms discussed on the previous page, there is a third kind of malware known as a"Trojan horse" which we consider next.




--------------------------------------------------------------------------------

What is a Trojan horse?
The term Trojan horse is applied to malware that masquerades as a legitimate program but is in reality a malicious application. It may simply pretend to be a useful program or it may actually contain a useful function as cover for a destructive one. Screen savers are often used as a carrier. Trojan horses do not replicate themselves as do viruses and worms. However, a Trojan horse can be part of the payload of a worm and can be spread to many machines as part of a worm infestation. Many Trojan horses have been sent out as email attachments.

One favorite use of Trojan horses is to allow a malicious hacker ( more properly called a "cracker") to use systems of unsuspecting owners for attacking other machines or as zombies. Another use is for relaying spam or pornography. Yet another use is to steal account passwords and then relay them back to someone for fraudulent use. Trojans can also be destructive and wipe out files or create other damage. Recently, phishing scams have been making use of Trojans.

Sometimes social engineering is used to induce people to click on a link. Here's one that enticed people to try to download some photos:

Osama Bin Ladin was found hanged by two CNN journalists early Wednesday evening. As evidence they took several photos, some of which I have included here. As yet, this information has not hit the headlines due to Bush wanting confirmation of his identity but the journalists have released some early photos over the internet.

Instead of photos what they got was a Trojan.

Defenses
Many Trojans are recognized by the major anti-virus programs. However, not all Trojans have characteristics that trigger anti-virus programs so additional software is recommended. The spyware programs discussed on the next page should be considered as well as the references in the sidebar.

It is essential in the present conditions to have a firewall. The Internet is a two-way street. Unless your computer is properly protected, it is all too easy for unwanted visitors to gain access to your computer while you are on-line. Once into your system, a cracker can plant a Trojan or worm or do other harm. Good firewall software can make your computer invisible to all except the most determined cracker. Further, most firewalls will warn you if programs on your computer try to connect to the Internet without telling you. That will help to warn you if you get an infection. Note, however, that some Trojans may hide by piggybacking on essential services like your email client.

Unless they had a broadband Internet connection, I used to tell people that they probably did not need a firewall. However, hacking has reached the point where everyone, even those with dial-up connections, needs a firewall. My firewall keeps a log of the attempts that are made to probe my computer and once in a while I check it out of curiosity. The attempts are unceasing and come from all over the world. (I know because I look up some of the IPs.) Even my wife's dial-up AOL account is probed all the time. Many of these probes are not malicious but I see no reason to take chances on the good will of all these strangers.

The present version of Windows XP has half a firewall built in. Unfortunately, it monitors only incoming traffic and therefore is of no help in warning about programs on your computer that call up Internet sites without telling you. Also, note that that you have to specifically enable it. (Service Pack 2 turns it on by default.). I recommend a more robust program. If you want to, you can go for one of the commercial suites that include a firewall together with a variety of other programs. However, there are several very good free programs. The sidebar contains references.

Spyware and Adware
These types of pest are related to Trojans but are a little less destructive. They are discussed on the next page. lintasberita

WHAT ARE SPYWARE AND ADWARE

SPYWARE AND ADWARE


The incidence of problem programs called "spyware" (or in their more benign forms "adware") has reached the point where Congress is even considering a law about it. Here's some facts about spyware and adware and ways to defend your computer.




--------------------------------------------------------------------------------

What are Spyware and Adware?
Spyware, adware and their variations are programs or applets that get installed on your computer by a download from the Internet. (You could also get them on a disk from somebody but that is less common.). There are basically three scenarios where problems arise:

1. You knowingly download and install something but do not understand all the functions of the program.

2. You download and install one thing but other things are installed along with it that you do not know about.

3. Something is downloaded and installed without your knowledge.

There are many software downloads available on the Internet that call themselves freeware. Quite a few of these are, in fact, free and come without strings. In the end, however, the cost of any software has to paid for by somebody, somehow. One way to support the cost of software is through advertising that is downloaded and displayed on the user’s computer along with the software. Many useful and reputable programs are now distributed this way. Often they come both in a version that is “free” (but with ads) and in a version that has no ads but has to be paid for. As long as the user is told up-front about the ads and about any tracking that might be going on, this form of adware has a perfectly legitimate role. For example, I use the adware version of the Opera browser. I do not use the browser very often and I wouldn’t pay for it but I am willing to have small ads running when I do use it. Actually, they are unobtrusive and I pay them no attention. [Note added later: Opera is now free.]

Note that I said that I was willing for ads to run while I was using the program. Less scrupulous software distributors may have pop-up windows showing ads whether you are using their program or not. Even worse offenders graduate to “spyware” and contain a component running all the time in the background to track your viewing habits on the Internet (and possibly other things). Your preferences are relayed to advertisers so that ads may be targeted specifically to what is perceived to be your interests. For example, if you visit a lot of sports sites on the Web, you may find ads for athletic equipment showing up on your computer.

Legitimate programs are straightforward in alerting you that advertising banners or pages will be downloaded to your computer and shown to you whenever you try to use that program. Others are less up front and bury the notice about ads and other actions in the EULA (End User License Agreement). Having seen this type of turgid legalese innumerable times when using Microsoft applications, most of us just click the “I agree” button without reading the stuff. If you do read the EULA thoroughly, you may find that you have signed away all your rights to privacy. How legally binding this really is, I am not competent to say, but personally I find the implications disconcerting. Still other software packages do not even bother with hiding details in the legalese but simply carry out surreptitious actions on your system without notifying you beforehand.

Drive-by Downloads or Foistware
Not content to entice you into using their spyware by providing some useful function, some firms download stuff to your computer whether you want it or not. Many Web sites have ad banners that contain download links. If you accidentally click on the ad, you may initiate a download. Some of these ads contain messages that your system "may" be infected with a virus or otherwise impaired in order to lure you into clicking on something. Depending on your browser security settings, you may then receive some unwanted software automatically or get the standard Windows pop-up message asking, "Do you accept this download?" If you click "Yes," spyware is installed. Note that the presence of a security certificate is no guarantee that something is not spyware. An example of a download window for a well-known problem program is shown in the figure below.


Sometimes, just viewing a page is sufficient. Many of these downloads take advantage of ActiveX controls in Internet Explorer (IE). The settings for Internet security zones in IE can be configured to prevent this. Also, Windows XP Service Pack 2 increases the security in this area of IE. Other browsers generally are not susceptible to ActiveX downloads. However, most browsers with insecure settings can be made to run Javascript or certain other types of code.

Lists of these types of spyware are available at the spyware database references given in the sidebar. Unless you are sure about a program, check it out on these lists before installing.

Other Problems
One issue is to how much of your privacy is invaded by the ad tracking. To some degree, it is the nature of an individual’s personal psychology that decides what is private. Some people are unconcerned while others react violently to the notion of being tracked. Privacy is a large subject and beyond the scope of this article but several references are given in the sidebar.

However you may feel about the privacy issues, the practical matter is that spyware uses your computer resources and bandwidth and often causes sluggish behavior or even crashes. Some spyware like the very popular file-sharing program Kazaa may even use your idle CPU time for whatever computational purposes they see fit. Many PC users have suffered significant degradation or worse for their system from the presence of spyware.

The most severe cases where the spyware is actually malicious and either causes deliberate damage to your system or uses your system for some nefarious purpose is usually considered a Trojan horse and is considered on the previous page.

Defenses
Because of the proliferation of spyware, many programs are now available for detecting spyware and cleaning it out. Anti-virus programs do not detect most spyware because the programs do not have the characteristics of a virus. Thus a separate application is needed that specifically targets spyware. Links to two free programs, "AdAware" and "SpyBot Search & Destroy" are given in the sidebar along with references for others. Unlike ant-virus programs, where installing more than one program is not recommended, it is a good idea to clean your system with consecutive application of two or more spyware removers. According to PC Magazine , the commercial programs Spy Sweeper and Spyware Doctor are the two best anti-spyware programs. PC World also chooses Spy Sweeper as its top ranked program.

Firewalls that monitor programs on your system that attempt to connect to the Internet will give you warning of the presence of spyware. The Windows XP firewall does not have this capability so one of the firewalls mentioned in the references in the sidebar is recommended. If another firewall is installed, turn off the Windows XP version. The update SP2 automatically enables the Windows XP firewall.

It's a good idea to check what programs run automatically at startup. Windows 98/Me systems can use MSConfig and Windows XP systems can use the services console to see what is running in the background. Unwanted programs can be detected and disabled. Any spyware can then be removed.

Avoiding spyware in the first place is the best defense. Use common sense in installing software. Check out any potential download with the spyware databases given in the references in the sidebar. Exercise caution when visiting strange Web sites.

Some references recommend disabling ActiveX entirely. While this will prevent many unwanted controls from installing, it will also break useful applications. A less drastic procedure is outlined on another page. Using the Firefox or other non-Microsoft browser is another recommendation for those who wish to avoid ActiveX problems. However, any commonly used browser is still susceptible to other types of script and the security settings for scripting should be consulted. lintasberita

WHAT IS VIRUS & WORM

VIRUSES AND WORMS

It seems to be inherent in human nature that any activity involving large numbers of people will include some who behave in a harmful, anti-social way. Thus on the Internet there is a constant threat from malicious software or "malware." Two common types of malware are "viruses" and "worms."


--------------------------------------------------------------------------------



What a virus is
A virus is a self-replicating program that spreads by inserting copies of itself into programs or documents that already exist on a computer. The name comes from an analogy with biological viruses. These cannot reproduce by themselves but make use of the functions of infected cells to spread. Similarly, a computer virus makes use of the executable code in legitimate programs to carry out its purposes. A virus may be designed to be destructive to a system or to be a prank. In either case, the virus will rapidly reproduce itself until the system may be overwhelmed. Viruses spread to other systems when infected programs are copied to another machine. Documents with executable code like Word macros can also be vectors of infection. A very common method of spreading viruses is by attachments to email . Today a variant of a virus known as a worm is more often used.

What a worm is
Viruses and worms are often lumped together in the single category of virus but there is technical distinction. A worm differs from a virus in that it contains all the code it needs to carry out its purposes and does not depend on using other programs. Most recent instances of malware have been worms, spread primarily by email. Worms are designed to replicate rapidly and to use the Internet or other networks to spread with great facility. They may contain code to damage or erase files or may carry other malicious payloads. On a number of occasions, large numbers of computer systems have been brought down by worms. In addition to the damage from whatever payload they carry, the sheer number of worm copies can bring systems to a halt.

A very common method of spreading is by use of any email addresses on an infected computer. The worm searches address books, temporary Internet caches and other possible sources of email addresses. The worm then mails out random infected fake messages. It may use the addresses it finds not only as recipients but also may spoof mail to show them as senders. It may also combine random pieces of addresses into new fake addresses. All the messages will contain an attachment that is infected. None of this activity may be known by the owner of the infected machine and may go on for weeks or months. A single infected machine can send out thousands of worm-carrying messages.

Anti-virus programs
Most people know that anti-virus software is a necessity and most computers come with some form of anti-virus program already installed. (Note that anti-virus is a catchall term that refers to a variety of malware.) All the major programs check email as well as scanning your system. However, new viruses appear every day and anti-virus programs are only as good as their database or definitions of viruses. A program can't recognize a new virus unless it has been kept up to date. Anti-virus programs contain update features and these are automatic in the newer major programs. However, the big vendors like Symantec and McAfee no longer give unlimited free updates but start to charge after some initial period ranging from 3 months to 1 year. Very often people do not subscribe to the new updates and let their protection lapse. This leaves the computer open to any new virus that comes along. Actually, it may be better to periodically buy a whole new version of whatever anti-virus program you use. I have often found rebate offers that make the new program cheaper than the update subscription.

Personally, I find both the Norton and McAfee programs to be very heavy users of system resources. An alternative is one of the free programs like Grisoft AVG. In the past, Symantec's Norton has always seemed to get much better reviews for efficacy against infection than the freebies but a recent review by the magazine PC World indicates that there are several free programs that now provide acceptable levels of protection. Tech Support Alert gives a critique of the various free programs and describes an effective computer defense that uses free programs.

Firewalls
Worms have also been spread by intruders planting them directly on unprotected computers connected to the Internet. A firewall is essential to guard against such occurrences and is discussed in more detail on the next page.

Trojan horses
Another form of malware is the "Trojan horse" and we consider that on the next page. lintasberita