FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister   ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 



first thing first

 
Post new topic   Reply to topic    [TweakNews.net Forum] Forum Index -> Spyware, Viruses & Security Discussion
View previous topic :: View next topic  
Author Message
gmoney
UberTweaker


Joined: 30 Oct 2003
Posts: 1674
Location: san jose, Ca.

PostPosted: Mon Jun 13, 2005 4:54 pm    Post subject: first thing first Reply with quote

alrite u guys.. brand new section brought to u by nate... thanks buddy... :-D !!

so basics... malware/spyware/trojans/virus' many different names... but all do one thing... mess ur rig up... not only will malware cause a nuicance to u through unexpected ie popups, its going to slow ur computer down... by often times running multiple instances of the same program or similar program...

for most instances many ppl around these forums will use programs such as:

spybot search and destroy http://www.safer-networking.org/en/mirrors/index.html

ad-aware se http://www.lavasoftusa.com/software/adaware/

avg anti virus http://www.grisoft.com/doc/10/lng/us/tpl/tpl01

trojan hunter http://www.trojanhunter.com/

these are all extremely popular.. and in all cases u are going to want to install, then update and then run the program.

as far as being aware of spyware/virus' ... if ur getting popups when ur not on the internet... or u are getting excessive popups while using the internet then u most likely have some sort of malware.

be aware of what u download.... that new screensaver mite seem really sweet or that new desktop calender is really convenient... however most of these will include in their .exe file some sort of software that u do not want.

also those pictures of that sooper 1337 chik mite seem awesome be befor u d/l that suckah.. make sure that teh prefix is what it should be.. meaning .. if its a movie make sure its not a .rar or .exe extension... etc many a time some 31337 |-\4x0r has tampered with such files just to mess with u.


and please ppl use software from a refutable name.. that ad-scan software mite advertise it as a nice product.. but a scan with a good company prog. will usually find that "ad-scan" to be itself spyware... WATCH OUT

watch out is all i can say... there is waaaaaay too much out there for u to jsut let it in.. so use a good browser like firefox ... my bestfriend :-D

http://www.mozilla.org/products/firefox/

peace out u guys and have fun with that wonderful world of the net[/url]
_________________
I finally got an award=OFFICIAL ROCKSTEADY AWARD and then one time... at tweaknews dene gave me a A+++++++....
and then...
i got a couple josh awards too
an' den one of those too -->... Ж award
Back to top
View user's profile Send private message Send e-mail AIM Address MSN Messenger
Google
Sponsor





PostPosted: Mon Jun 13, 2005 4:54 pm    Post subject: Advertisement

Back to top
fussnfeathers
Lord of the Tweak


Joined: 14 Dec 2004
Posts: 2763

PostPosted: Tue Jun 14, 2005 2:30 am    Post subject: Reply with quote

Aside from the horrendous spelling, I agree totally.

I've always said, from the beginning.........your best protection is your own common sense. While most of the good spyware/adware/virus scanner programs will help you prevent disaster, YOU are the most important factor to the equasion.

I look at it this way.......if you want to keep yourself free of a VD, you can do one of two things:

Use protection, and continue to visit the "houses of ill repute", OR you can pay attention to where you go, and if it seems too good to be true, too easy, or too cheap, it's probably not worth it.

Refuse any download you didn't request, regardless of the site (exception being trusted sites such as Symantec, MS Windows Download, or any software vendor who's product you own that has automatic updtates). DO NOT accept ActiveX controls from a site you don't know, DO NOT download any sort of plug-in that is "required" to visit the site.........for the most part, any time you see that, it's a scam, and you'll be hit with a crapload of spyware or adware.

Most importantly, MONITOR YOUR EMAIL. It kills me how many phishing emails I get, from banks that I've never had an account with, don't have in my area, and wouldn't deal with anyway. I tracked one down today to a hijacked server in Kuala Lampur, and notified the IP address owner of the problem. Granted, I have the skills and tools to do this, but it raises a good point...........if somebody sends you a LINK in an email to verify info, DO NOT USE IT. Contact your bank to verify they actually did send that mail (and I can guarantee you, they didn't, there isn't a single bank in the world that will ask for account maintenance, validation, verification, or whatever through e-mail).

I'll stress this again, the single most important part of any protection plan is YOU. If you don't configure right, ignore warnings, and don't update, you WILL get hit, and you might lose more than some data.

I don't care how good the program is, it ain't gonna protect you if you don't do the basics and maintain it.....which is what most people forget to do.

'Nuff said.
_________________
Big enough to scare you
Back to top
View user's profile Send private message
Silicon Skum
UberTweaker


Joined: 26 Jul 2004
Posts: 1156
Location: UK, Geordie land

PostPosted: Tue Jun 14, 2005 8:42 am    Post subject: Reply with quote

Here are a few little hints to help you solve that REALLY bad ad / spyware that you cannot remove while running windows, some software such as spybot or adaware will ask to run at the next startup of windows, but often the malware / ad / spyware has allready been loaded in to RAM before the scanning tool, so it's catch 22.

What to do in this case is to restart windows but use the "safe mode" by pressing the F8 key just as the operating system begins to load. This will give you a menu, select "safe mode" and windows will boot (slowly) into windows and will NOT load ANY drivers or files not required by windows to function at minimal level.
Now all you have to do is run your detection program(s) and they should now be able to detect and fully REMOVE the problems from your system.

Before you restart into "normal" windows you should spent a little amount of time looking through the "Program Files" folder and look for any installed programs that look suspicious or that you have *not* installed. in some rare cases you may find software such as dialers (dial a premium rate phone number and run up a F***ING HUGE bill, but ONLY work if you have a POTS (plain old telephone system) analogue modem connected to a phone outlet, so far these programs have not caused any problems with broad band connections!) or other types of spyware *could* be located in the root directory of you hard drive, in other words C:\ Mad
Another place to look for common malware / spyware is in the Windows or windows system folders, though spotining these by hand in probably NOT for the beginner as it is easy to find a file that *LOOKS* like a suspicious file, but is infact a file that is part of the operating system. Deleting such files can render windows inoperative. BE CAREFUL if you decide to or have no option but to try this. A simple method of detecting Microsoft or other software companies files is to right click on the file and select "properties" and look through the information in the "general", "version" and "summary" tags. You can look at a file’s name, location, modification date, file type, and version number. If the version lists the manufacturer as microsoft and all the other information seems correct, then it is probably safe to leave this file alone.

one last way to look for files which *may* but not always be malware or spyware, is to look at the file signatures, all windows file are signed. any unsigned file in the windows directory and subdirectories **COULD** be malware or spy ware but then equally could just be unsigned newer / updated files installed during the installation of new hardware drivers or new software. if you are unsure of the file's pupose, leave it be, you could trash windows easily and have to reinstall or repair the installation.
Microsoft has digitally signed Win2K / XP system files to ensure that the OS will run smoothly. A digital signature is Microsoft’s assurance that no other software installations have altered the files and that Microsoft has tested the files and approved them for use with Win2K. If someone accidentally or intentionally replaces a system file or a device driver, Windows File Protection automatically replaces the offending file or driver with Microsoft’s digitally signed file.

To start "File Signature Verification" in windows 2000 / XP, click Start, click Run, type sigverif, and then click OK.
Before you start the utility, you can configure advanced options by clicking the Advanced button and selecting options on the Search and Logging tabs.With the default search option, the system warns you about system files that Microsoft hasn't signed. You can select another option to search your system for other files that Microsoft hasn't digitally signed. The Logging tab lets you save the results of file signature verification to a log file (sigverif.txt). You can either append these results to an existing log file or overwrite it.
Once you have configured the advanced options, click Start to begin the signature file verification process. The process can take some time, depending on the number of files on your system. The modification dates and version numbers can come in handy when you're troubleshooting a problem.

one last thing, don't just belive that ONE spyware scanner can clean up your system, often there are parts of or even complete files and programs that are missed by certain scanning engines used in these programs. I always find that scanning with a combo of "Spybot search and destroy" and "Adaware SE" find 99% of the files associated with spyware and malware. There are a number of other good program, which can detect the remaing file and program that these programs missed. ALWAYS use a scanning tool recomended by other **users**, as stated in previous posts not all scanning tools are what they apear to be!

Happy hunting!

§
_________________
my sig disappeared from the image host (?)
But at least I have a Josh Award!
Back to top
View user's profile Send private message
2old2care
Lord of the Tweak


Joined: 09 Jul 2004
Posts: 2817
Location: Pssst....Over Here

PostPosted: Tue Jun 14, 2005 11:01 am    Post subject: Reply with quote

I'll re-post this guy's website...in our new section mainly because of how we sometimes get spyware and the people behind it.

http://www.benedelman.org/

Sometimes there is no avoiding it...they can sneek it in without your consent.
But...many times there will be a section in the EULA of software you get that explains what kind of stuff it may contain or potentially hook you up to.
So at least skim your agreements for that section.
_________________
.
Liquid-Cooled Q9450 and an EeePC
.
Back to top
View user's profile Send private message
Ham_fisT
Lord of the Tweak


Joined: 20 Jun 2004
Posts: 2244
Location: Gone Fishin'

PostPosted: Sat Jun 18, 2005 8:30 pm    Post subject: Reply with quote

Thast is an interesting site^^^

Very in-depth analasys of some popular installs, (that also install some very un-popular stuff)
_________________
Yeah....... ok
Back to top
View user's profile Send private message Send e-mail MSN Messenger
Dene~
Guest





PostPosted: Sun Jun 19, 2005 8:24 pm    Post subject: Reply with quote

Nice spelling G lol, good links bro
Back to top
fussnfeathers
Lord of the Tweak


Joined: 14 Dec 2004
Posts: 2763

PostPosted: Mon Jun 20, 2005 3:40 am    Post subject: Reply with quote

We don't criticise G on his spelling...........well, ok, we do, but I've learned to read it. Mostly. Causes some hiccups in post responses sometimes, but hey, we can't all be beautiful AND good spellers, can we?


_________________
Big enough to scare you
Back to top
View user's profile Send private message
gmoney
UberTweaker


Joined: 30 Oct 2003
Posts: 1674
Location: san jose, Ca.

PostPosted: Mon Jun 20, 2005 4:03 am    Post subject: Reply with quote

ahaha... i sppelz very good i tell u hhwat .... jerk
_________________
I finally got an award=OFFICIAL ROCKSTEADY AWARD and then one time... at tweaknews dene gave me a A+++++++....
and then...
i got a couple josh awards too
an' den one of those too -->... Ж award
Back to top
View user's profile Send private message Send e-mail AIM Address MSN Messenger
sickofsoyo
Tweakafile


Joined: 23 Apr 2005
Posts: 644
Location: NJ... yup

PostPosted: Wed Aug 17, 2005 10:20 am    Post subject: Reply with quote

STICKYYYYYY
Also another good program for detecting and removing adware spyware and others is microsofts version of antispyware found here...

http://www.microsoft.com/downloads/details.aspx?FamilyID=321cd7a2-6a57-4c57-a8bd-dbf62eda9671&displaylang=en
(WARNING!! MUST BE USING VALID COPY OF WINDOWS TO DOWNLOAD. YOUR WINDOWS WILL NEED TO BE VERIFIED BEFORE YOU CAN DOWNLOAD)

It is only the BETA version but it works well. It also runs in the background (if you want it to) and stops programs from altering you IE or installing adware or spyware. (it gives a HUGE popup notification and gives the details of the program and lets you decide what to do). As others have said, it is all common sense and it IS up to you to keep your computer free of this software.
_________________
P4 3.2ghz
lanparty pro875b
Enermax Liberty 500 Watt Modular PSU
Sony 52X CD-RW
Samsung 120gig SATA hdd
Maxtor 100gig SATA hdd
Powmax Demon case
ATI X800 XL AIW, 525 Core, 525 mem
Creative X-Fi Platinum
PDP systems Patriot Ram 2,3,2,5 timings
Back to top
View user's profile Send private message Send e-mail AIM Address
fussnfeathers
Lord of the Tweak


Joined: 14 Dec 2004
Posts: 2763

PostPosted: Wed Aug 17, 2005 10:36 pm    Post subject: Reply with quote

I use MS Antispyware, and really for one reason.............not for detecting spyware, but it IS very good at alerting you to registry changes or startup issues. Personally, from testing, MS AntiSpyware misses alot of stuff. It's still "new" though, and it does such a good job at alerting me to the more malicious stuff that it's worth having.

Just don't use is as your lone spyware program,
_________________
Big enough to scare you
Back to top
View user's profile Send private message
ToggleHead
TWEAKGURU


Joined: 03 Mar 2004
Posts: 4360
Location: Jersey

PostPosted: Thu Aug 18, 2005 10:26 am    Post subject: Reply with quote

i use spybots teatimer for that
_________________
Back to top
View user's profile Send private message Send e-mail AIM Address MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic    [TweakNews.net Forum] Forum Index -> Spyware, Viruses & Security Discussion All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB3 ©