Chief Delphi

Chief Delphi (http://www.chiefdelphi.com/forums/index.php)
-   Technical Discussion (http://www.chiefdelphi.com/forums/forumdisplay.php?f=22)
-   -   Malware, Adware and Spyware (http://www.chiefdelphi.com/forums/showthread.php?t=28539)

Bcahn836 12-05-2004 19:48

Re: Malware, Adware and Spyware
 
Pop ups- earthlink
Spy ware- Spy bot search and destroy
Virus- Norton
Spam-Norton
Adware- Spy Bot

MikeDubreuil 12-05-2004 20:47

Re: Malware, Adware and Spyware
 
Quote:

Originally Posted by Ashley Weed
Does a firewall on a router actually put up any substantial form of defense? I run and manage two seperate wireless networks, and I know that it claims "built in firewall", etc. but what is it actually doing inside of there? :confused:

What is implemented on most gateways is not technically a firewall, but provides firewall like bennifets.
A gateway is a device that connects multiple computers through 1 internet connection and out to the internet through a technology called Network Address Translation (NAT). I think gateway is what you meant by router.
By putting the gateway in front of your network it will stop people from being able to penetrate your network and attempt to port scan or enter your computer through traditional hacking techniques. As you may have noticed, most worms propogate by connecting to a port on a computer and abusing a service. The gateway stops people from initiating connections to your computers behind it.

This is all true unless you use routing. In which case packets destined for ports on your gateway get sent to a computer of your selection.

Chris Fultz 12-05-2004 22:23

Re: Malware, Adware and Spyware
 
norton anti-virus / always on

webroot spysweeper

pop up stopper campanion

opnickc 13-05-2004 08:16

Re: Malware, Adware and Spyware
 
Quote:

Originally Posted by sburro
Now I am scared. I only run a Mcafee virus scan/ firewall. I only have a dial up connecton :ahh: :ahh: Is there anything that I should be afraid of?


You should be ok, as long as Mcafee is kept updated. I only use Norton Antivirus and Mozilla, although I did use adaware to get some spyware off my parent's computer. I've just never let any on.

The best way to prevent spyware and such from getting on your computer is to read boxes that pop-up before clicking ok. Once you get one peice of spy/adware on your PC it can add five more almost instantly. This is what happened to my parents, the day after I reformatted their HD. I don't know how the first peice of software got downloaded (my parents are usually smart about that kind of thing), but as soon as it was on there were about 6 others. When you deleted them via "Add/remove programs", it was still there. When you deleted it's directory in "c:/program files/" it came back. So my brother reccomended ad-aware, and it worked great. But there's no need to get it until you have a problem.

Justin Stiltner 13-05-2004 08:40

Re: Malware, Adware and Spyware
 
From some searching and cleaning last night on a customers computer ive found this really neat page.
Task List
It lists most tasks that can appear in task manager (right click start bar choose task manager) It lets you look up all those cryptic names and see exactly what those programs are, all listed by the first letter, and most with instructions on how to rid yourself of them. They are trying to sell their software by this site too but I have no experience with it so cannot vouch for it. But the task list was great and answered an age old question for me.. what is this alg.exe and why was it running.

Bharat Nain 13-05-2004 15:11

Re: Malware, Adware and Spyware
 
Quote:

Originally Posted by Justin Stiltner
From some searching and cleaning last night on a customers computer ive found this really neat page.
Task List
It lists most tasks that can appear in task manager (right click start bar choose task manager) It lets you look up all those cryptic names and see exactly what those programs are, all listed by the first letter, and most with instructions on how to rid yourself of them. They are trying to sell their software by this site too but I have no experience with it so cannot vouch for it. But the task list was great and answered an age old question for me.. what is this alg.exe and why was it running.

Also, note that some spyware/adware is not going to show up your task manager instantly. It may launch when you launch another application. Sometimes you won't be able to even end the task in task manager. Sometimes, even when you end it, it comes back. These are the sort of problems you have to deal with. However, what Justin Stiltner suggested is an excellent way to check what adware/spyware you have one your computer... Good link Justin.

DanL 13-05-2004 20:50

Re: Malware, Adware and Spyware
 
As was said before by many people, using non-ie browsers help. Firefox is popular, but I use Opera. The main difference is Opera is a product you must pay for if you want to get rid of (in my opinion completely unintrusive) banner ads while Firefox is open-source (free). I say banner ads loosly because these ads aren't bad at all - I set Opera to display the google text ads... these ads are always relavent to the site I'm on (i.e. on chiefdelphi, its always sites for robotics kits ;) ) and every now and then I find them useful. Both Opera and Firefox offer improvements over IE such as customizable interfaces, putting bookmarks directly on the interface (kinda like the windows quicklaunch bar), tabbed windows (MUCH better than having 40 ie windows open in your taskbar), automatic pop-up stopping (I don't have any popups), and my favorite, mouse gestures. Mouse gestures in particular I find awesome because once you get the hang of them, you can move forward, move back, close windows, open windows, etc. by a single quick mouse motion. Last time I checked, Firefox didn't have these, but it may have changed. My biggest complaint about Opera is it doesn't seem to be able to stream video files - if you click on a link, it downloads the whole file first rather than opening it up immidiately in WMP and have WMP stream it. I'm sure there's a way to change that, but I haven't tried looking it up. Anyways, Opera is my preference - take that for whatever you want to take it.

The important part is most spyware gets onto your computer from security holes in IE. The biggest advantage of using Opera or Firefox is spyware is designed to infect your computer using IE. If you don't use IE, spyware simply doesn't get onto your system. I have Adaware and Spybot, and I run them every now and then... the worst thing they find is a buncha cookies.

On a similar topic, KEEP WINDOWS UPDATED! Again, Spyware finds its way onto your system through security holes - many of which have patches released shortly after they become a problem. Make sure you have Windows Automatic Updates turned on - this is the easiest way to make sure your system has the latest fixes. If you don't have XP, go to windows update atleast once a week. It'll save you both from spyware and viruses.

Another thing you can do to fight spyware is something called the windows HOSTS file. Using this file, you can essentially block any ad/spyware server. If you're interested in the technical details behind this, read this paragraph. Otherwise, skip to the next paragraph. There's this file hidden in windows (C:\Windows\System32\drivers\etc if you're on XP) - its essentially a DNS lookup table (computers only know how to get to servers by their numerical adress, or IP adress - something like 148.47.12.4. When you type something like www.google.com, your computer first contacts a known DNS server and asks, "what is the ip adress registered to www.google.com?" The DNS server responds with, "148.47.12.4" or whatever it is. Your computer then queries google using that ip address). The Windows TCP/IP protocol stack checks this file for a DNS entry before it queries its default DNS server. Someone discovered that if you put the domain names of ad/spyware servers into this file and have their associated ip be the local TCP/IP loopback ip of 127.0.0.1, then even if a popup is not blocked and a request is sent to say, ads.doubleclick.com, if there is an entry for ads.doubleclick.com in the HOSTS file, Windows automatically sends that request to 127.0.0.1. But since nothing exists at 127.0.0.1, that request doesn't get a response and presto! you're saved from seeing an ad. Doesn't matter if IE sent the request, Opera, Firefox, or a malicious program - since this blocking is a Windows hack, Windows makes sure that whatever program sent the request doesn't get a reply -- in essence, using the HOSTS file in this way causes Windows to not know where to find the malicious websites. Some people have collected long lists of popular ad servers and compiled HOSTS files that you can download.

In conclusion, I present
Dan's Abridged Guide to Keeping Spyware Off Your System
1. Scan for existing Spyware using spyware programs - the most popular being Adaware and Spybot: Search and Destroy. Read this thread for other programs people use and are happy with.

2. Don't use IE. Although its hard to let go (it was for me), other browsers offer better features than IE, including built-in pop-up stopping - the most popular ones being Opera and Firefox. In addition, because IE is so popular, spyware is designed to exploit IE-specific holes. If you use a non-IE browser, a lot of spyware doesn't even know how to attack your computer

3. KEEP YOUR SYSTEM UPDATED! The main reason viruses spread is because people don't install the latest patches. This is also true of spyware - windows updates sometimes fix the holes that spyware exploits to get onto your system. Windows XP has Automatic Updates - all you need to do is turn this on and forget about it... Windows will automatically check for updates and download them. If you don't have XP, check the windows update site atleast once a week.

4. The Windows HOSTS file offers a nice hack for your system to block ads and spyware. An example HOSTS file with a long list of blocked ad/spyware servers can be found here: http://everythingisnt.com/hosts.html. If you search, I'm sure you'll find others.

The most important thing is to be intelligent. Don't go to sites that give you lots of pop-ups. If something does pop-up asking you to install something that you didn't request, obviously hit No or Decline. Hope this helps, and happy surfing.

JAH 14-05-2004 16:45

Re: Malware, Adware and Spyware
 
I run McAfee Virus, Firewall, and Privacy Service. I also run AdAware about once a month. I use Opera 7, it took me a while to get used to it but now I can't stand anything else. It blocks the pop up ads and allows tabbing with a stylish look.

ahecht 14-05-2004 17:33

Re: Malware, Adware and Spyware
 
Quote:

Originally Posted by JakeGallagher
My advice is to just reformat...my friend had the same problem and no matter what he did, he couldn't get the popups and all that crap off his system.

I wouldn't do that if I were you. It sounds like you have a varient of CWS, or Cool Web Search, which is notorious for reinstalling itself from a hidden dll after you remove it. You can try using something like CWShredder from http://www.spywareinfo.com/~merijn/, or if that doesn't work, download HijackThis (from the same site), and post your logs to the SpywareInfo Forums.

If you read through the SI forums, you will see that they were able to fix some incredibly resilient malware problems.

D.J. Fluck 14-05-2004 17:37

Re: Malware, Adware and Spyware
 
McAfee Firewall
Adaware
Spyboy
Analog POW! to block popups....with POW! you train it to block certain items, and you can unblock certain items if you accidently block the wrong one...its a nice program especially since a lot of your popups are based off a handful of sites....i really havent had a popup problem since after I got POW!

Astronouth7303 14-05-2004 20:43

Re: Malware, Adware and Spyware
 
ZoneAlarm. I don't do pop up stuff (too many legit popups). And we have yet to find badware as it is. And in the last 44 minutes, I've gotten 48 access attempts. all blocked.

If you use a hardware router, I'd say put it on every computer. If the router is a computer, load it there.

And the best remedy: keep your computer off the web. ;)

Crash852 16-05-2004 22:51

Re: Malware, Adware and Spyware
 
Norton Antivirus
Adaware 6.0
Spybot
Zone Alarm
Default XP firewall
mozilla firefox
google toolbar if using IE


All times are GMT -5. The time now is 02:26.

Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2017, Jelsoft Enterprises Ltd.
Copyright © Chief Delphi