Showing posts with label spyware. Show all posts
Showing posts with label spyware. Show all posts

Saturday, November 09, 2013

Fun games foster security awareness

Phishing Scams - avoid the bait
The U.S. government has a great site to learn more about being smart and safe online. It's called OnGuard Online. The site includes some simple online games that let you check your "smarts" about safe computing.

You may learn something new or maybe just reinforce good habits. Either way, visit the site.

Below are links to some interactive video quizzes:

Saturday, October 19, 2013

Windows Defends

The Windows 8.1 update detected that my ZoneAlarm for Windows 8.0 was not compatible with 8.1. It then took the below actions.
  1. Disabled ZoneAlarm
  2. Enabled Real-Time Protection using Windows Defender
  3. Displayed an Action Center notice about ZoneAlarm.
  4. Gave a link in the Action Center notice directly to the ZoneAlarm web page about the incompatibility and fix status
Congratulations, Microsoft! Great job of:
  • Defending the customer's computer
  • Alerting the customer to a security issue with their software
  • Displaying crucial information about the customer's product
  • Providing a direct link to the customer's Anti-Malware app developer page about the issue and its status
Wow! These update-related actions are a truly excellent  automatic adjustment to a bad security situation. After reading the Action Center notice, I opened Windows Defender and fully expected to have to manually set it up. It was already running real-time protection!

This is one of the best customer-oriented software behaviors I have seen in a long time. Again, kudos to Microsoft for a job well-done.

Saturday, March 21, 2009

Does that email pass the smell test?

We get lots of email messages every day. How do you tell what's a fake (and likely to try to hurt you) and what's not? Carnegie Mellon's Software Engineering Institute produced a set of checks that are still valid. It's the KREVS "test".
  • The Know test. Do you already know the sender?
  • The Received test. Have you received safe emails from the sender before?
  • The Expect test. If the email has an attachment, were you expecting to get it?
  • The Virus test. Does the message pass a virus-check? (Make sure your Antivirus program also checks your email messages).
  • The Sense test. Does it look right? Are there unexpected misspellings? Does it "smell" in any way?

If an email messages fails any of the above tests, delete it. Even if an email messages passes all 5 tests above, it still might be malicious. Be paranoid; the "bad guys" really are out to get you. Criminal attack attempts using email are increasing rapidly.

If the email is from a person you already know, still be careful. Call them and see if they really sent any unexpected attachment.

Friday, November 28, 2008

Beware nasty Mebroot trojan

Beware of malware called Sinowal (also as Mebroot) captures bank and similar data. A gang of Internet criminals have been using this and even morphing the malware to temporarily fool antivirus software.

Windows Secrets contributing editor Woody Leonhard likens Mebroot to "a parasitic operating system that runs inside Windows". [Disclaimer: I subscribe to the paid version of "Windows Secrets" newsletter. Prior to that subscribed for years to the paid version of Fred Langa's "LangaList" newsletter, which is now integrated into Brian Livingston's "Windows Secrets" newsletter. I highly recommend Windows Secrets anyone concerned about or interested in PCs.]

Leonhard says that his experience is that a lot of systems get infected with Mebroot (Sinowal) because the owners did not keep up with Adobe Reader, Adobe Flash, or Apple Quicktime security patches. You can manually check for such patches, set the apps to automatically check for updates, or (even better), install the free Secunia Personal Software Inspector (PSI) and scan for programs that need updating.

In October 2008 Brian Krebs, Washington Post, alerted readers to the "virtual heist" going on. Mebroot infects the Master Boot Record (MBR) of your PC and sends personal data to its "owners". Krebs says that the criminals have stolen over half a million credit and debit card account in the past few years.

While Symantec lists the malware's risk as low, if your data gets stolen, it won't be a little thing to you. Here are some actions Symantec and I recommend to reduce your risk of malware infections:

  • Use a firewall
  • Enforce complex passwords for all users of your computer
  • Use the lowest level access privileges.
  • Never use an Administrator-level login account as your normal one. Always login as a lower level account and then "Runas" or login as the Administrator level only as needed. Vista security is a big advance in making this type security easier. Yes, you get pop-ups to login as Administrator, but that's much better than manually running a "runas" command and you don't need to know the runas command line syntax.
  • Disable Auto-play
  • Turn off "File Sharing"
  • Turn off and remove unnecessary system services
  • Always keep your programs patched (You can use the free Secunia PSI to monitor patch status)
  • Don't open email attachments unless you were expecting them. Contact the sender separately (not by a "Reply") and see if they really did send you that email and attachment.
  • Turn off Bluetooth via Windows Control Panel if you are not using it.
  • If you really need to use Bluetooth, make sure every Bluetooth device's visibility is set to "Hidden".

Wednesday, July 04, 2007

Microsoft Malware Protection Center

Microsoft offers a security portal page called "Microsoft Malware Protection Center". It lists and links to the top 10 most active malicious software families, most active family variants, most active email threats, and spyware/adware removed from PCs.

The site officially launches in "early July", but the links to threat information are already active.