Showing posts with label Emsisoft. Show all posts
Showing posts with label Emsisoft. Show all posts

Wednesday, 31 October 2012

Free Personal Firewall: The Door To Your Computer

What is Firewall

Firewall is either a software or hardware gate to the computer or computer network. So it is very easy to compare the Firewall to the gate that limits access to the personal property in terms of estate: house, garage and any other building within the area that is your personal property. To be more precise, the Firewall is like a gate and its guard in one: it restricts the access to the computer or computer network by examining the incoming and outgoing data traffic from other network which, on most cases, is the Internet. In order to be capable of doing what it is supposed to do, Firewall needs to have rules set. For both, Windows and Linux Firewalls, you would have some basic rules set by default.
Now, on the network there may be peripheral devices that can be accessed from trusted computers on the network, and this is where we are figuratively talking a property that consists of few different buildings. The topic of this post however is not the Network Firewall where it usually works together with Network Intrusion Detection and Prevention System to keep the network of computers as safe and protected as possible. Such a topic doesn't apply to basic Computer Security essentials, and is a discipline of IT Professionals. We will take a look at free Personal Firewall, and some tests that can be run to ensure that your personal computer meets good security standards.


How Does Firewall Work?

Digital Communication

Every Computer Network, including the biggest one in The World, The mighty Internet, is essentially a network of communications. Nothing more than that... and nothing less. Computers communicate with each other by sending and receiving data packets. That is their way of communicating. Today's world basically has a parallel, digital dimension that consists of the traffic of millions of data packets. In order for computers to understand each other, there are various Communication protocols in place. This is the reason why you would need, for example, a Skype application instead of MSN Messenger installed and running on a Windows machine in order to communicate with someone who is using Skype on their computer. So where does Firewall come into play?

Data Packet

In this post I refer to the unit that is sent from one computer to another as the 'data packet'. It contains essential communication information such as destination IP address, communication protocol in use and few other things. One of the main Firewall's tasks is to analyze contents of these data packets: whether the right protocol is being used for a specific communication port, whether the IP address, the packet is supposed to be received by, has actually anything to share with the sender of that packet, and what type of software application is involved in exchange of these data packets. For years this has been a point where basically the common things between Firewall software of Windows OS and that of Linux OS's end. While Linux has got Firewalls based on IP Table filtering, Windows OS has had different requirements regarding its security because of the differences in how each of these Operating Systems have been designed and developed.


Further in this post we will deal exclusively with Windows Security by taking a look at typical Firewall features on Windows machine. The product I have chosen as an example is Online Armor by Emsisoft. Not only it's an outstanding paid solution for those who would like to take full advantage of its additional security features, it's also one of the best free Win Firewalls out there.

Online Armor: Free Cutting Edge Firewall

This Firewall software does not lack a single thing any other free Firewall worth its name would be able to provide. Besides, Emsisoft have been working hard for years to provide Windows computer users and administrators with additional free and effective computer security tools, and the fact that one of them, Anti-Malware, the name that speaks for itself, is among the means of keeping your Windows machine protected, adds to the strength of Online Armor's effectiveness.



Firewall. The section where you manage communication ports on your Win computer, and networks your computer gets connected to. You can easily allow or block access rights for programs to access the Internet here. You can see all the associated program files that have the right for Internet access: protocols and ports they use.
Domains. This section is very much like a Windows Hosts file that allows you to list domains that you'd rather not want to be connected to. Editing the actual Hosts file is not a recommended practice for someone who's not an advanced computer user therefore the opportunity to simply save an unwanted domain name here makes things very convenient and simple.
Programs. Allow, Block or Run Safer any installed program on your computer. The Firewall is also able to detect Hidden running processes on your computer. For a full list of Program Options please see the Screenshot:


Autoruns. The list of all the System and Program Files that are allowed to start automatically (like scheduled Java Update, for instance). Block or Delete them easily here.
Anti-Keylogger. Online Armor automatically detects files and programs that might have keystroke recording capability (your usernames, password, web addresses, email addresses, phone numbers given to others, bank security details?). Those programs and files, if any, will be listed here.
Hosts File. Monitors and keeps a record of the changes made to the Windows Hosts File, if any.
History. List of alerts made by Online Armor, and the response action taken by you.
Options. Firewall Software general configuration settings.


Why Firewall is mandatory for every PC regardless of Operating System?

There is no Data and Computer Security expert who wouldn't advise on having a Firewall installed on your computer unless they would want you to see what happens in about week's time after you've been connecting to the Internet without a Firewall on your machine. The list of Online Armor features provided earlier basically contains answers to the question: why would I need a Firewall on my computer? After all, Firewall is just another software application using my computer's resources, and asks annoying and repetitive questions every time I install new software on my computer. Well, just as it is in the real world, there are people in the Digital one who wouldn't want to miss the opportunity to take advantage of someone else. For whatever reasons. And then there are people who just love challenges and games, and for them hacking techniques might be simply an interesting game. Regardless of anyone's personal motives, here are few ways modern Personal Firewall makes life more difficult for online criminals:
  • It reduces to a minimum the possibility for malicious software to be installed and run without your consent;
  • It doesn't allow scanning for available communication ports on your computer;
  • It reduces unwanted connections to a minimum.
So we can certainly say that Firewall is a tool that lets you be in control. However, it's not a guarantee for your machine to be invincible. Why? Read more in my other post about how computers get infected.

Test your computer's visibility from hacker's view online

There are quite a few excellent options for testing your computer's Firewall, visibility, state of your ISP's DNS and your computer's communication ports, all to be found at Gibson Research Corporation Website. Look for Services / Shields Up! if you want to see if matters related to your network connections are in Stealth Mode (i.e. in a good condition). Look for some other no less brilliant free things on their website including secure password generators and DNS spoofability Test.

Tuesday, 28 February 2012

Anti Malware for Windows Server 2003 and 2008


This product from Emsisoft can be a real treat for IT administrators and a solution, worth considering in business environment. Particularly at large organizations that depend on multiple interconnected computer networks that have to be secured for safe and optimal functioning. As is the case with all the Emsisoft products, this one too comes with 30 day money back guarantee and can be obtained with considerable discounts ranging from 25 to 75 percent, depending on the number of machines it is obtained for. There is also a free trial version of the software available for download so that you can test the product before deciding on purchase.
Anti Malware for Server comes with:
  • dual scan engine consisting of: E1/A2 Emsisoft Anti-Malware engine, and E2/IK Ikarus Anti-Virus engine: a combination that works as 2 in 1;
  • File Guard that works as a real-time shield and compares every file downloaded to known malware patterns. As soon as infected file is detected and quarantined/deleted, a notification email is sent to administrator;
  • HiJack Free, an integrated software designed for professionals to monitor autorun and running processes, services, port configuration, installed ActiveX objects (can be submitted for online analysis), LSP Protocols;
  • Command-line scanner which is the same anti malware scanner without GUI.
This product can be run alongside other Anti Virus software and Firewall causing no conflicts or system failures. In case a technical problem arises the publisher's support team is always available to assist in solving it quickly and professionally.

To download the trial version click here. If you'd like to order the product electronically or by postal mail click here.

You might also want to consider these products:
Internet Security Pack: AntiVirus+Firewall
Online Armor Premium Firewall

Thursday, 16 February 2012

Bot, Spybot and free malware removal

What are bots and Botnets?

By definition bot is a software application running automated tasks over the Internet like, for example, those best friends of SEO specialists: Google and Bing robot spiders/crawlers that index webpages. We however will be talking the removing of those bots that by About.com's definition are
type of malware which allows an attacker to gain complete control over the affected computer. Computers that are infected with a 'bot' are generally referred to as 'zombies'.
Description of botnets by Securelist.com website pretty much sums up the answer to questions like, what is a purpose of developing botnets and why would anyone want to create trojan bots:
Special Trojans – ‘bots’ (from “robot”) are created for this kind of networks, centrally managed by the remote “master”. The Trojan intrudes into thousands, tens of thousands or even millions of computers. This enables the master of the “zombie network” (or “bot-network”) to access resources of all infected computers and use them to own benefits. Sometimes such networks of “zombie-machines” come into the black Internet-market where they are acquired by spammers or rented.
The following video by rynesandbergfan23 explains what malicious bots are capable of, what to look out for and how to secure your machine so that its chances of getting infected are greatly reduced. (Note: if you haven't got a software to monitor your network connections similar to one shown in the video, you can use Command Prompt (Start-->Run-->cmd) instead. For the list of network connections and associated software applications maintaining them, type netstat -b in the Command Prompt and hit Enter):

Spybot

Last year my machine, despite the full ZoneAlarm's protection it had, got infected with what was known as Google Redirector malware. That's how I got familiar with a freeware called Spybot S&D (or Spybot Search&Destroy), a software project that financially depends on PayPal donations. This freeware is able to identify more than 820,000 pests (including Win32/Zbot (also known as ZeuS), SpyEye and TDSS trojans) by basically doing what it calls a bot-check. The following video will show you what features Spybot has got as well as how to scan and clean your machine:


Now, from my experience, Spybot is very useful to get rid of spyware, adware and all kinds of sneaky pests but it cannot serve as a replacement for an anti-virus software. Handling of malicious Windows Registry entries is one thing Spybot is really good at. The picture that follows is a screenshot of Spybot's scan results:


If you click on it and take a closer look, you can see that (apart from 2 DoubleClick tracking cookies) there are only 3 objects expanded that are not Registry entries.

Malware and spyware removal method

Let's get back to the video at this point. The author of the video comes up with what I see as a generally good idea as to how a Windows machine has to be cleaned: if one malware detection software comes up with detected objects after the scan, it is recommended that after deleting those objects, a system scan is run again, this time by using the same type of software by different vendor. In the video the free Malwarebytes Anti-Malware (appears to be most trusted free malware detector for Windows environment) scanner is used to compare scan results however, unlike that of the video author, our point here is not to demonstrate a comparison because no software is absolutely perfect. The point is using what Hitman Pro (also used in the video) developers call a 'second opinion'. Now, lets see what I've got after following this sequence: free Emsisoft Anti-Malware (Scan settings: Scan type: Deep Scan Objects: Rootkits, Memory, Traces, C:\ Scan archives: On ADS Scan: On) -->Spybot scan --> free Malwarebytes Anti-Malware (Deep Scan) --> Hitman Pro (Default scan):
  • Emsisoft Anti-Malware detects 387 objects each related to one of the following: mywebsearch toolbar, zwinky toolbar, funwebproducts, Trojan.Win32.AddUser and Trojan-Downloader.Agent.  (No screenshot provided because of the amount of objects found yet the scan Report can be viewed by clicking here.)
  • Spybot detects some MyWebSearch and FunWebProducts Windows Registry entries as seen in the screenshot above (the scan takes up to several hours)
  • Malwarebytes Anti-malware still detects some MyWebSearch entries in Windows Registry and a Start Menu Hijack:
  • Hitman Pro detects one remnant of malware in Windows Registry:

  • Now the machine can be considered free of both, malware and spyware. Remember, before you start cleaning your machine, make sure you have:
    • downloaded all the latest updates for the software you are going to use. If this doesn't work, the best thing to do is to obtain anti-malware software installation using other computer. Spybot for instance can be installed and run without the connection to Internet: latest updates is an optional step during the installation;
    • disconnected the machine from the network either by removing cable or disabling/removing your wireless adapter. This is actually the first thing you want to do if you suspect your computer has been infected and you seem to have no control over running processes.
But speaking of Google Redirector... The only free tool that got rid of it was HitMan Pro (Google redirection infection is known as TDL3/TDL4 rootkit).  Mind you, that was back in May 2011, and as we know, things constantly change.

Internet Security Pack: AntiVirus+Firewall
Online Armor Premium Firewall