Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Sunday, October 18, 2009

AVG 9 ( Free Edition ) now available for download

For PC users who are looking for an alternative free anti-virus software, and for those who are current users of AVG 8.5, the most current version of the popular free anti-virus is now available for download.

I just wished the "Game mode" feature was also a part of the free version, but I guess AVG still needs to keep features that will give users a reason to upgrade to the "Full" version.

Links

  1. AVG homepage
  2. AVG 9 features and comparison table
  3. AVG 9 download page

Sunday, April 26, 2009

Conficker Removal Toolbox

I recently needed to remove Conficker on some Windows XP machines, and downloaded some of the removal tools available from Anti-Virus companies and Microsoft. I also used a Portable copy of ClamWin, which was useful as Conficker would not allow the installed AV to run updates. I've zipped and uploaded the following tools to Mediafire, to serve as an emergency copy and for others to use if they are not able to download from the different AV vendor sites ( a Conficker infected machine will have difficulty downloading from AV sites ).

You can use the Conficker Eye Chart to check if you are infected by Conficker.

If you want to try and download removal tools directly from their sources ( or if you are in a different machine that is not infected ), you can use this list provided by the Conficker Working Group. You can also check their Home page as well as their FAQ to read more about Conficker.

If you want to download the removal tools that I've collected as the Conficker Removal Toolbox, you can follow this link. The list of things that you'll find in the zip file are:

  1. Symantec Downadup Removal Tool
  2. BDTools from BitDefender
  3. Microsoft Windows Malicious Software Removal Tool
  4. ClamWin Portable ( extracted and updated on April 26, 2009 )

Resources:

  1. Conficker in Wikipedia
  2. Conficker Working Group
  3. Conficker Eye Chart
  4. List of Removal Tools
  5. Download link for zipped collection of removal tools with ClamWin AV
  6. Download link for zipped collection of removal tools without ClamWin AV

Thursday, June 26, 2008

Portable and Free eXpress CheckSum Calculator

I've been recently downloading Linux distros, through bittorrent and direct iso downloads, and one of the tools that I found very helpful in checking the validity of the files that I download is the eXpress CheckSum Calculator. You can match the values calculated by XCSC against the given and previously generated checksum values for files that you download online. The tool supports CRC32, MD5 and SHA-1. If you need to find the checksum for a group of files, you can also use another program from the same developer, the eXpress CheckSum Verifier (which is also portable and free).

Details :

Developer : Irnis Haliullin Cost : Free Supported OS : Windows 95/98/ME/NT4/2000/XP/Vista Supported algorithms : CRC32 (Cyclic Redundancy Code), MD5 (Message Digest number 5) and SHA-1 (Secure Hash Algorithm). Download Size : 263Kb ( Self-extracted EXE file )

Resources and Links

  1. Download eXpress CheckSum Calculator (XCSC) here
  2. Download eXpress CheckSum Verifier (XCSV) here
  3. CRC
  4. MD5
  5. SHA hash functions

Thursday, March 30, 2006

createTextRange vulnerability in IE: Disable Active scripting or use another browser

The flaw is caused by how Internet Explorer handles createTextRange tags, and could let malicious software run and install itself. Microsoft has not yet offered a patch, though it should be on the April 11 updates. Numerous websites have been identified that exploit the vulnerability. In a recent article from CNet it is reported that e-mail spams containing excerpts of BBC stories are being sent out, and readers are redirected to forged BBC webpages. Once the infected site is visited, a keylogger is pushed into the system, and user information like usernames and passwords are captured and collected.

Until the patch is released, users of Internet Explorer could do the following:

Disable active scripting:

  1. On the IE browser, click on Tools and select Internet Options
  2. .
  3. Click on the Security tab, click on Internet and then select Custom Level
  4. On the Security settings look for Scripting. Set Active Scripting to either Disable or Prompt. Click OK.
  5. Now back to the Internet Options, Click Local intranet, and then Custom Level. Repeat step no. 3.

Download and Use another browser :

Use Firefox or Opera as your browser.

Update:

Microsoft has released a cumulative patch for IE, which is found in the Microsoft Security Bulletin. Together with the April 11 IE updates are patches for MDAC, Outlook Express and Frontpage.

Wednesday, March 08, 2006

Brontok e-mail worm

I recently had an encounter with an infected Windows XP Pro with SP2 machine which annoyingly restarted whenever a download was initiated and opened on the default browser the link about Brontok.A. The page that was appearing had the following text:

BRONTOK.A [ By: H[REMOVED]Community ]
-- Hentikan kebobrokan di negeri ini --
1. Adili Koruptor, Penyelundup, Tukang Suap, Penjudi, & Bandar NARKOBA
( Send to "NUSAKAMBANGAN")
2. Stop Free Sex, Absorsi, & Prostitusi
3. Stop (pencemaran laut & sungai), pembakaran hutan & perburuan liar.
4. SAY NO TO DRUGS !!!
-- KIAMAT SUDAH DEKAT --

This was my clue, so I searched for the brontok.a reference, and came up with the following aliases for the e-mail worm that had infected the system when the user opened a certain e-mail attachment.

A.K.A. : Email-Worm.Win32.Brontok.a (Kaspersky Lab) is also known as: W32/Rontokbro.gen@MM (McAfee), W32.Rontokbro@mm (Symantec), BackDoor.Generic.1138 (Doctor Web), W32/Korbo-B (Sophos), Worm/Brontok.a (H+BEDV), Win32.Brontok.A@mm (SOFTWIN), Worm.Mytob.GH (ClamAV), W32/Brontok.C.worm (Panda), Win32/Brontok.E (Eset)

An Anti-virus was present on the system, but was not updated (lesson no. 1 !!!), and scanning the system did not find anything. Apparently, upon infection the virus creates registry keys that enable it to run at startup, and edits and sets registry entries that disable the use of regedit, msconfig, folder options, etc. (More info from Sophos.)

On the Sophos website, there is an available removal tool, but running it did not remove the worm variant. Badly enough, there was no anti-spyware software on the system, and downloading was not an option as the system would restart at every attempt to download one. The Anti-virus software was also unable to do auto-update. I downloaded Spybot from a different machine, and was able to install it on the infected one. It found and reverted changes made to the registry by the virus. Now this allowed the Anti-virus software to update itself and on restart was able to clean the machine after scan.