This is default featured slide 1 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 2 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 4 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

Showing posts with label Spyware. Show all posts
Showing posts with label Spyware. Show all posts

Monday, April 20, 2009

Spyware The Peeping Toms of the Web

While the internet is a great tool for research, or for just keeping in touch with e-mail or looking for a perfect gift, there is an annoying problem that is becoming increasingly dangerous for your computer. While everyone understands what a computer virus does, many people are still relatively unaware of the problem that is Spyware.

Spyware is another word for Advertising Supported software (Adware). There are several large media companies that place banner ads and pop-ups on certain web pages in exchange for a portion of the revenue from banner sales. This is the front for the more harmful Spyware that almost always comes along with it behind the scenes. While the banner placement may be a great concept, the downside is that the advertising companies also install tracking software on your system, which is continuously "calling home" and using your Internet connection to report on everything on your computer and everywhere you go, and then reports this information back to the source program. While every site you may visit may have a privacy policy about not sharing information, the fact remains that someone put a program on your PC that is sending non-stop information about you and your surfing habits to someone else.

Although Spyware is something that because of its very nature seems like it should be illegal, it actually is not, though there are obviously major privacy issues. Spyware also has a tendency to open your computer up to receiving more computer viruses, which is another reason why someone should look at removing any Spyware from their computer. Spyware detection and removal software often comes with security software like Norton or MacAfee, but there are also plenty of programs out there that exist for the specific purpose of finding and removing Spyware. Any detailed research will help you find programs that you can download to your computer in order to take care of these problems.

There is also the type of Spyware that can be intentionally downloaded to a computer. This type is most often used by parents or guardians to get a monthly report to find out all the various web sites people in their household have visited over the past month. In some Christian circles, a particular type of Spyware has become popular, where a certain group of friends will receive a monthly list of every web site visited in the past month, as an “accountability” thing. Otherwise, most Spyware is best removed from a computer as soon as it is found.

Wednesday, April 1, 2009

The Home Computer User’s Guide to Spyware

As with the computer virus, spyware can be broken down into a number of different categories. Most users are familiar with the term “adware” which refers to software which serves annoying ads. There are however a number of other spyware variants you should be aware of.

To begin with it is important to have a clear definition of spyware. This will also help us understand why the term is commonly used to encompass a number of different variants. Spyware is a program, usually installed without your knowledge, which records what you do on your computer and then shares it with its creator.

The information which the spyware program collects can vary from the websites you visit to log-in and passwords for your online banking site. The sharing of your personal information with a third party is why spyware in its purest form is labelled as a malicious threat and clearly is a major privacy issue.

Adware is the second mostly commonly used term. Adware is designed to display adverts relevant you, commonly based on your surfing habits, to generate Pay-Per-Click advertising revenue or sales through affiliate links. Adware is commonly bundled with free software by developers instead of charging a price.

The malicious nature of adware can vary enormously. At one of the scale, adverts are displayed in a non-intrusive manner in a window within the free program you have downloaded. When the program is not running, ads are not displayed. At the other end of the scale, a user could find their desktop overwhelmed as the adware program spews out multiple pop up ads in a very aggressive manner. Whilst it may be possible to believe the former is not transmitting personal data to a third party, it is difficult to expect the later not to.

The adware issue is further complicated by marketing companies who do not like their software being labelled “spyware.” These marketing companies generate millions of dollars of income often via recognised brand name clients. So to avoid legal issue security companies refer to this software as PUPs (potentially unwanted programs).

Browser hijackers are another aggressive form of spyware. They attack important browser settings like your default homepage which your browser loads when you start the program. Hackers direct you to sites which generate revenue for them like the Russian website “Cool Web Search”. Browser hijackers can also insert sites into your bookmarks. They also can cause your browser to crash and stop working completely and are typically difficult to remove.

Key Loggers capture all your key strokes into a DLL file which the creator retrieves. Software key loggers are often bundled with a Trojan Virus which gives the creator access to your computer.

Here are some tips and strategies to fight the different types of spyware.
- Keep Windows XP and ALL your web browsers (including Internet Explorer and FireFox) up to date with the latest patches.
- Install a reputable anti-spyware program like Webroot Spy Sweeper or PC Tools Spyware Doctor. Run frequent scans and keep the definitions up to date.
- Install a reputable anti-virus program like Norton Anti-Virus or McAfee VirusScan. Run frequent scans and keep the definitions up to date.
- Install a firewall which manages both inbound and outbound connections. Top personal firewall software picks include Zone Labs’s Zone Alarm and Norton Personal Firewall. Alternatively purchase a router with a hardware firewall.
- Avoid downloading free software programs including screensavers and weather toolbars.
- Avoid know high spyware risk area on the internet including illegal music sharing sites, Peer-to-Peer programs, free game download sites and adult sites.

Wednesday, March 25, 2009

Where Spyware Lurks on the Internet

Spyware has to be the most talked about PC security threat of 2005. It has now surpassed the computer virus as the No. 1 menace to computer user both at home and in the enterprise. Despite efforts from Microsoft and independent security software companies, the spyware menace is set to continue through 2006 and beyond. The research firm Radicati Group expect worldwide anti-spyware revenue to surpass $1 billion by 2010.

There are numerous types of spyware with some more dangerous than others. At one end of the spectrum spyware pushes annoying ads to your computer as is usually referred as “Adware.” It is still spyware as the ads are generally pushed to you based on your surfing habits. A bad infection can also dramatically impact your computer’s performance as your desktop slowly gets overwhelmed with pop up adverts.

At the other end of the spectrum spyware programs can record what you do on your computer including individual key strokes. This information is then shared with a third party. This data is then sold to marketing companies or used to profit from. For example, the program may have captured your bank log-in details or credit card information.

Profit from these activities drives spyware development and deployment. According to anti-spyware vendor Webroot Inc advertising revenue generated from spyware is much more lucrative than trying to generate profit through Spam Email.

Here are the common ways spyware gets onto your computer:

• Bundled with free software like screensavers or P2P file sharing programs which you download. For example Kazaa, a P2P file-sharing application, installs adware onto a user’s computer even though it claims to contain “no spyware.” Waterfalls 3 from Screensaver.com installs spyware and Trojan horses. Examples are courtesy of a report from StopBadware.org’s website.
• Opening Spam email attachments.
• Being enticed into clicking on links in pop up adverts which then downloads spyware. These pop ups usually display messages to do with winning money or entering a special prize drawer.
• “Drive-by downloading” – this is when spyware is automatically downloaded onto your computer from the website you are surfing.

Earlier this year a report published by the University of Washington revealed categories of websites which are mostly like to host spyware or infect users through “drive-by downloads.” Their research revealed the following categories:

• Gaming sites
• Music download sites (I interpret this to mean “illegal” music sharing sites like dailymp3.com or where you can find P2P applications)
• Adult sites
• Celebrity sites
• Wallpaper / screensaver sites

Here are some tips and strategies to reduce the chance of spyware infection:

• Switch on your browser’s pop blocker.
• Install an anti-spyware tool with active protection which helps prevent infection in the first place.
• Keep Windows and other Microsoft applications like office up to date with the latest patches.
• Use SiteAdvisor (http://www.siteadvisor.com). This is a free plug-in for your browser which tells you whether a site is safe or not based on their testing. This is new software which is highly recommended.
• If you are a frequent visitor of the high risk categories please consider changing your surfing habits or at least making sure your system is fully protected.

Monday, March 23, 2009

My Spyware Nightmare, Your Lesson

Have you asked yourself any of these questions lately?

1. Why is my brand new computer slowing down to a crawl?
2. Why is it taking so long to load a basic word processor?
3. Why do I have so many popups? Where are they coming from?
4. Why do I keep being sent to places I did not ask to go?
5. Where are these embarassing popups coming from? I never visit sites like that!

I did. I was ignorant. I was slow and it cost me a brand new computer. Here is my story.

A couple of years ago, we bought a new eMachine for my wife. She had just enrolled in school and needed something better for her school work. Prior to that, we had an older HP machine. I believe it was a pentium II. It worked pretty well, though a little slow. I wanted us to get another HP, but she wanted an eMachine. Her cousin had one and she thought it was good. I did not like eMachines a lot and did not think highly of them. She was bent on having one so we bought one.

With the arrival of the new computer, the HP was quickly abandoned. I was pretty much the only one that used it. Not because of my disdain for eMachine, but becasue the HP was more in a central location. Our three boys loved the new machine and spent quite some time on it. I was eventually won over to the eMachine and I must confess, it turned out to perform excellently well. It was good on speed and the resolution was great.

Several months down the road, I noticed how the new computer was slowing down. I knew in my mind it was the eMachine. They were no good. And then I thought it was the dial up connection. But I soon realized that it was also slow when I was offline. It was taking long to open up applications and even longer to load webpages. I also noticed there were strange windows openning up at the most awkward times. Some of the pages were to sites I would not ordinarily visit. May be the boys are going to places that we don't know about. As a concerned parent, I asked them and they promptly denied. I was still not sure they did'nt. They were teenagers.

As time passed, it became more difficult to do anything on the eMachine. We gradually migrated back to the HP and there was no immediate need to find out what was wrong with it.

Finally, it was time to act. I was ready to find out what the problem was. I started asking questions and doing querries on google. I was encouraged to get a good popup blockers. I did and it did not do much. That computer was far gone and corrupted. I had waited too long. I was not sure what was going on and did not know where to ask. The warrantee on the computer had also expired.

One afternoon, I turned the computer on to take another look and was greeted by a blank screen. The monitor had also quit I said to myself. Now I knew almost for sure it was the eMachine. They were really no good. My wife disagreed. But to be sure, I hooked the monitor up to the HP and it came alive. So it was'nt eMachine after all. I was a little embarrassed.

I reconnected the monitor and rebooted and was again faced by a blank screen. The following week, I took the cpu to a repair and they told me the computer was dameged beyond repair. I retrived it and took it to a sencond repairman and it never came back.

You know, lightening they say does not strike the same spot twice. But spyware is different. It can strike the same spot many times. Early 2005, I bought another computer, having out grown the HP. Months latter, I noticed the same exact symptons that ruined the eMachine. The slow down, the multiple popups, redirects to undesirable websites, they were all there. This time I did not wait. That afternoon I was frantic. I began searching for a quick answer. It was not until late that night that I found a product that worked for me. And once I found the right solution, spyware was no longer an issue to me.

Spyware can make your online experience a nightmare if you are not forward thinking about internet security. The good news is that there are plenty of products out there that can cure that effectively.

Thursday, March 19, 2009

Phishing, Fraudulent and Malicious Websites

Whether we like it or not, we are all living in the Information Age. We have nothing left but adapt to rapidly developing information technology, no matter who we are and what we do for living.

The Internet, in particular, means for us boundless opportunities in life and business – but also lots of dangers unheard of just a decade ago. We should be aware of these dangers if we want to use the huge potential of the Internet and to avoid the hazards it brings us.

Warning: There are Websites You'd Better Not Visit

Phishing websites

Thanks to authors of numerous articles on this topic, "classic" phishing technique is relatively well known. This scam involves setting bogus websites and luring people to visit them, as a rule, by links in emails. Phishing website is disguised to look like a legitimate one -- of a bank or a credit card company, and users are invited to provide their identifying information. Sites of this kind are used solely to steal users' passwords, PIN numbers, SSNs and other confidential information.

At first phishing consisted only of a social engineering scam in which phishers spammed consumer e-mail accounts with letters ostensibly from banks. The more people got aware of the scam, the less spelling mistakes these messages contained, and the more these fraudulent websites resembled legitimate ones. Phishers are getting smarter. They eagerly learn; there is enough money involved here to turn criminals into earnest students.

Since about November 2004 there has been a lot of publications of a scheme which at first was seen as a new kind of phishing. This technique includes contaminating a PC with a Trojan horse program. The problem is that this Trojan contains a keylogger which lurks at the background until the user of the infected PC visits one of the specified websites. Then the keylogger comes to life to do what it was created for -- to steal information.

It seems that this technique is actually a separate scam aimed at stealing personal information and such attacks are on the rise. Security experts warn about commercialisation of malware -- cybercriminals prefer cash to fun, so various kinds of information-stealing software are used more actively.

Fraudulent websites are on the rise

Websense Security Labs -- a well-known authority in information security -- noticed a dramatic rise in the number of fraudulent websites as far back as in the second half of 2004. These sites pose as ones for e-commerce; they encourage users to apply for a reward or purchase something, of course never delivering the product or paying money. The most popular areas for such fraud are online pharmacies, lottery scams, and loan / mortgage sites. Experts predict there will be more fake merchants in future and their scams will become more sophisticated.

Malicious websites are especially dangerous. Cybercriminals create them exclusively to execute malicious code on the visitors' computers. Sometimes hackers infect legitimate sites with malicious code.

Bad news for blog readers: blogs can be contaminated, too. Since January, Websense Security Labs has discovered hundreds of these "toxic" blogs set by hackers.

When unsuspecting users visit malicious sites, various nasty applications are downloaded and executed on their computers. Unfortunately, more and more often these applications contain keyloggers--software programs for intercepting data.

Keyloggers, as it is clear from the name of the program, log keystrokes --but that's not all. They capture everything the user is doing -- keystrokes, mouse clicks, files opened and closed, sites visited. A little more sophisticated programs of this kind also capture text from windows and make screenshots (record everything displayed on the screen) – so the information is captured even if the user doesn't type anything, just opens the views the file.

In February and March 2005, Websense Security Labs researched and identified about 8-10 new keylogger variants and more than 100 malicious websites which are hosting these keyloggers EACH WEEK. From November of 2004 through December 2004 these figures were much smaller: 1-2 new keylogger variants and 10-15 new malicious websites per week. There is by all means a disturbing tendency--the number of brand-new keyloggers and malicious website is growing, and growing rapidly.

What a user can do to avoid these sites?

As for phishing, the best advice is not to click any links in any email, especially if it claims to be from a bank.

Opening an attachment of a spam message can also trigger the execution of malicious program, for example a keylogger-containing Trojan horse.

As for fraudulent websites, maybe buying goods only from trusted vendors will help -- even if it is a bit more expensive.

As for malicious websites… "Malicious websites that host adult entertainment and shopping content can exploit Internet Explorer vulnerabilities to run code remotely without user interaction."(a quote from Websense's report). What can a user do about it? Not much, but avoiding adult sites and buying only from known and trusted online stores will reduce the risk.

Hackers also attract traffic to malicious websites by sending a link through spam or spim (the analog of spam for instant messaging (IM). So a good advice never follow links in spam is worth remembering once more.

Detect Spyware and Adware and Remove It Without Spending a Dime

Adware and spyware have become a world-wide computer problem from using the World Wide Web. They have turned into malware because of their viral and extremely hostile behavior. Along with the hazards of identity theft and deceit at hand on the Internet, adware and spyware can be other than merely irritating. Here are some methods to detect spyware and adware and remove or merely avoid the adware and spyware and not outlay a dime on the most recent "anti-virus" software, such as Spyware Nuker.

1. USE Firefox. If you don't use the Internet very much, then maybe you don't understand a good deal concerning Firefox. All you need to comprehend is that it is a browser that performs VERY nicely and has excellent security protection.

2. DO NOT USE Microsoft Internet Explorer. Internet Explorer is similar to Swiss cheese. It seems to have an endless supply of security holes. Microsoft is ceaselessly sending out patches to fix all the flaws in the Internet Explorer 6.X and prior versions of the browser. Even though it can be "secured" by adding to thesecurity it may give away much of its functionality when set to highest security when specific exploitable features are turned off.

3. Use a software or hardware firewall (not only Windows XP Service Pack 2's firewall). This may be thought to be expensive and difficult to do but it is not. If you use a DSL or broadband cable connection your Internet Service Provider (ISP) may have issued you a DSL/Cable router that has a a firewall included with it. All you need to do is switch it on. This may force you to spend a few minutes to read the instructions.

If your ISP did not deliver you a DSL or Cable broadband router that includes a firewall you can shell out anywhere from $20 -$60 (or occasionally even cheaper when it includes a mail-in rebate) to get a router. If you use DSL you would require a DSL router. If you use Cable broadband ISP you would need a Cable Router. Brands such as Linksys have already built in firewalls and a feature known as NAT, Network Address Translation, which is extremely effective because it hides your actual IP address from the Internet. All routers are sold with directions on how to hook them up. If you desire to maintain you computer security free, merely use a free software firewall.

4. Detect Spyware and Adware using free Anti-spyware, anti-adware software. Lavasoft's Adaware and Spybot Search & Destroy are two superb methods of restoring your system for free. Majorgeeks.com is a favorite and trustworthy freeware website that has these and several additional outstanding spyware/adware cleaning and malware preventing software (including free downloadable firewalls).

The best approach is to use ALL of the options. Remaining proactive by surfing using a suitable browser and obtaining a firewall is critical, but it likewise helps to beware of other good anti-adware/spyware applications. If you get hit with a genuinely foul bit of malware that can not be cleaned using Adaware or Spybot, dig up yourself a geek. There are numerous big forums on the Internet committed to accomplishing nothing but to detect spyware and adware and remove them and other malware. In all likelihood if your computer is contaminated with it, hundreds of others prior to you have been contaminated and have previously figured out how to get rid of the malware.

Tuesday, March 17, 2009

The Ten Most Common Spyware Threats

You've heard the phrase "know thy enemy." Well, here are your most common spyware enemies (source:FaceTime Security Labs). Don't be fooled - spyware is not a game. It costs individuals and corporations millions of dollars each year. Spyware can be used to watch your surfing habits, steal credit card information, or just be a nuisance. In any case, it's a royal pain. Know they enemy.

1. Gator - Gator is installed by users as a password vault. That means that passwords can be recalled for you automatically when visiting sites. The trade-off for this service is that you have to endure pop-ups when visiting certain sites. Claria, the maker of Gator,has cleaned up its act a little by labeling the pop-up ads, but they're still annoying.

2. CoolWebSearch - This has got to be one of the most notorious browser hijackers out there. This is the name given to a program with many different variants that redirect users to coolwebsearch.com or datanotary.com. Uninstallation can be extremely complex. Users shouldn't try to manually remove this software.

3. 180SearchAssistant - This software either serves ads in pop-ups or pops up website windows based on your keyword searches. This software usually comes bundled with other "freebie" type software installs like emoticons or wallpaper. Newer versions of the software have an add/remove program uninstall item.

4. Huntbar - Now here's an annoying piece of software. Huntbar installs a toolbar onto internet explorer and windows explorer windows. It changes your home page and search page settings to point to their servers. If you use another search engine, Huntbar will redirect you to theirs. Great stuff. Oh, and it puts a 15% drain on memory resources.

5. Cydoor - This software usually comes with P2P software, ie. peer to peer. Again, it barrages you with a series of pop up advertisements. It also tracks usage information.

6. ISTbar - Yet another nice, unwanted piece of software. ISTbar does "drive-by" install via ActiveX and javascript. Basically, that means that you visit a site and it tries to install itself to your computer. Nice, huh. The Activex control installs a toolbar that pushes information to my-internet.info and blazefind.com.

7. WhenU-DesktopBar - Displays advertising content. Monitors internet traffic, collects search profiles, and can execute code from a remote server using its update feature only. Relevant searches may cause it to display a special offer, coupon, or other advertising content. The adware may also display advertisements.

8. New.Net - New.Net is a company that sells domain names for "nonstandard" top-level domains. It should be removed pronto.

9. IEPlugin - As the name implies, it installs a toolbar in Internet Explorer. It tracks web site usage, form items (like names, addresses, etc. - ie. yikes!), and local filenames that are browsed. It's invasive - remove it.

10. BargainBuddy - Bargain Buddy used to be everywhere. It is distributed by BullzEye Network. And it sets up a Browser Helper Object (BHO) and monitors your computer usage. It then, you guessed it, pushes advertisements your way based on that usage.

Thursday, March 5, 2009

Protecting your personal information

Avoiding the phishers


"The vandals are becoming fraudsters and electronic pickpockets."
Identity thieves are using more sophisticated methods to get consumers to divulge their personal and confidential information.

Bill Rosenkrantz, group product manager for internet security firm Symantec, says that in the last seven years, the internet has gone from an information source to an ATM: "Thirty-five to 40 per cent in the U.S. use the internet for financial transactions."

"Historically, hackers and virus writers would attack systems for ego's sake. But now it's financial," according to Rosenkrantz. "The vandals are becoming fraudsters and electronic pickpockets."

How to avoid getting "phished" in

  • Don't respond to e-mails requesting your personal information.

  • Don't click on links inside e-mails-

  • If you're uncertain about a website address that appears in an e-mail, go to your browser and enter the legitimate address manually.

  • Protect your computer -Use updated anti-virus software,.


  • Report suspicious e-mails

  • Notify the legitimate company if you receive any e-mails that you think might be fraudulent.

    More information at http://www.cbc.ca

    Tuesday, March 3, 2009

    "Koobface" Worm Resurfaces on Facebook, MySpace

    Security experts are warning users of Facebook, MySpace and other social networking communities to be on guard against a new strain of the "Koobface" worm, which spreads by tricking users into responding to a message apparently sent from one of their friends.

    The latest version of Koobface arrives as an invitation from a user's friend or contact, inviting the recipient to click on a link and view a video at a counterfeit YouTube site. Visitors are told they need need to install an Adobe Flash plug-in to view the video.

    The bogus plug-in instead installs a Trojan horse program that gives Koobface author(s) control over the infected user's computer, according to security firm Trend Micro, which documented the new strain on its blog...

    More information

    Tigger.A: Sophisticated trojan that likes stockbrokers

    Tigger.A: Sophisticated trojan that likes stockbrokers
    Customers and employees of firms that trade stocks and options beware, the Tigger.
    A trojan is targeting you. Tigger/Syzor is one of the most sophisticated pieces of malware that exists today.
    “The trojan uses a privilege escalation vulnerability (MS08-066), which is almost an exact replica of the public exploit on Milw0rm. It disables Windows Defender, Windows Firewall, Outpost, Avira, Kaspersky, AVG, and CA products in unique ways such as posting malformed messages to windows owned by the daemon processes, sending special byte codes over named pipes, and using the products’ own API.”

    “It installs a rootkit that runs in safe mode. The rootkit disables kernel debuggers, hooks FAT and NTFS file system drivers, and also prevents other processes from accessing the kernel driver’s memory so tools like GMER and IceSword can’t recover the .sys from RAM.

    Tigger of course also injects code into user-mode processes. This component takes screen shots, hooks COM for spying on browser events, and exports passwords (protected storage, network and dial-up, and at least 11 popular chat, email, and remote access applications). It also steals web cookies, steals certificates, and puts the NIC in promiscuous mode to sniff FTP and POP3 passwords.”


    More information on http://blogs.techrepublic.com.com/security/?p=960