Showing posts with label pc. Show all posts
Showing posts with label pc. Show all posts

Wednesday, 31 October 2012

Free Personal Firewall: The Door To Your Computer

What is Firewall

Firewall is either a software or hardware gate to the computer or computer network. So it is very easy to compare the Firewall to the gate that limits access to the personal property in terms of estate: house, garage and any other building within the area that is your personal property. To be more precise, the Firewall is like a gate and its guard in one: it restricts the access to the computer or computer network by examining the incoming and outgoing data traffic from other network which, on most cases, is the Internet. In order to be capable of doing what it is supposed to do, Firewall needs to have rules set. For both, Windows and Linux Firewalls, you would have some basic rules set by default.
Now, on the network there may be peripheral devices that can be accessed from trusted computers on the network, and this is where we are figuratively talking a property that consists of few different buildings. The topic of this post however is not the Network Firewall where it usually works together with Network Intrusion Detection and Prevention System to keep the network of computers as safe and protected as possible. Such a topic doesn't apply to basic Computer Security essentials, and is a discipline of IT Professionals. We will take a look at free Personal Firewall, and some tests that can be run to ensure that your personal computer meets good security standards.


How Does Firewall Work?

Digital Communication

Every Computer Network, including the biggest one in The World, The mighty Internet, is essentially a network of communications. Nothing more than that... and nothing less. Computers communicate with each other by sending and receiving data packets. That is their way of communicating. Today's world basically has a parallel, digital dimension that consists of the traffic of millions of data packets. In order for computers to understand each other, there are various Communication protocols in place. This is the reason why you would need, for example, a Skype application instead of MSN Messenger installed and running on a Windows machine in order to communicate with someone who is using Skype on their computer. So where does Firewall come into play?

Data Packet

In this post I refer to the unit that is sent from one computer to another as the 'data packet'. It contains essential communication information such as destination IP address, communication protocol in use and few other things. One of the main Firewall's tasks is to analyze contents of these data packets: whether the right protocol is being used for a specific communication port, whether the IP address, the packet is supposed to be received by, has actually anything to share with the sender of that packet, and what type of software application is involved in exchange of these data packets. For years this has been a point where basically the common things between Firewall software of Windows OS and that of Linux OS's end. While Linux has got Firewalls based on IP Table filtering, Windows OS has had different requirements regarding its security because of the differences in how each of these Operating Systems have been designed and developed.


Further in this post we will deal exclusively with Windows Security by taking a look at typical Firewall features on Windows machine. The product I have chosen as an example is Online Armor by Emsisoft. Not only it's an outstanding paid solution for those who would like to take full advantage of its additional security features, it's also one of the best free Win Firewalls out there.

Online Armor: Free Cutting Edge Firewall

This Firewall software does not lack a single thing any other free Firewall worth its name would be able to provide. Besides, Emsisoft have been working hard for years to provide Windows computer users and administrators with additional free and effective computer security tools, and the fact that one of them, Anti-Malware, the name that speaks for itself, is among the means of keeping your Windows machine protected, adds to the strength of Online Armor's effectiveness.



Firewall. The section where you manage communication ports on your Win computer, and networks your computer gets connected to. You can easily allow or block access rights for programs to access the Internet here. You can see all the associated program files that have the right for Internet access: protocols and ports they use.
Domains. This section is very much like a Windows Hosts file that allows you to list domains that you'd rather not want to be connected to. Editing the actual Hosts file is not a recommended practice for someone who's not an advanced computer user therefore the opportunity to simply save an unwanted domain name here makes things very convenient and simple.
Programs. Allow, Block or Run Safer any installed program on your computer. The Firewall is also able to detect Hidden running processes on your computer. For a full list of Program Options please see the Screenshot:


Autoruns. The list of all the System and Program Files that are allowed to start automatically (like scheduled Java Update, for instance). Block or Delete them easily here.
Anti-Keylogger. Online Armor automatically detects files and programs that might have keystroke recording capability (your usernames, password, web addresses, email addresses, phone numbers given to others, bank security details?). Those programs and files, if any, will be listed here.
Hosts File. Monitors and keeps a record of the changes made to the Windows Hosts File, if any.
History. List of alerts made by Online Armor, and the response action taken by you.
Options. Firewall Software general configuration settings.


Why Firewall is mandatory for every PC regardless of Operating System?

There is no Data and Computer Security expert who wouldn't advise on having a Firewall installed on your computer unless they would want you to see what happens in about week's time after you've been connecting to the Internet without a Firewall on your machine. The list of Online Armor features provided earlier basically contains answers to the question: why would I need a Firewall on my computer? After all, Firewall is just another software application using my computer's resources, and asks annoying and repetitive questions every time I install new software on my computer. Well, just as it is in the real world, there are people in the Digital one who wouldn't want to miss the opportunity to take advantage of someone else. For whatever reasons. And then there are people who just love challenges and games, and for them hacking techniques might be simply an interesting game. Regardless of anyone's personal motives, here are few ways modern Personal Firewall makes life more difficult for online criminals:
  • It reduces to a minimum the possibility for malicious software to be installed and run without your consent;
  • It doesn't allow scanning for available communication ports on your computer;
  • It reduces unwanted connections to a minimum.
So we can certainly say that Firewall is a tool that lets you be in control. However, it's not a guarantee for your machine to be invincible. Why? Read more in my other post about how computers get infected.

Test your computer's visibility from hacker's view online

There are quite a few excellent options for testing your computer's Firewall, visibility, state of your ISP's DNS and your computer's communication ports, all to be found at Gibson Research Corporation Website. Look for Services / Shields Up! if you want to see if matters related to your network connections are in Stealth Mode (i.e. in a good condition). Look for some other no less brilliant free things on their website including secure password generators and DNS spoofability Test.

Tuesday, 24 April 2012

Zero Day: an upcoming documentary on cyber crime

Journalist Brian Krebs and few other reporters are to be featured in an upcoming documentary co-financed by BBC Storyville where viewer will be able to witness hands-on forensics that uncover the perpetrators and follow film makers as they film cases and investigations in real time. However, this project will only be funded if at least $20 000 is pledged by Saturday, June 2, 2012. For more information and to support the project please click here.

Wednesday, 4 April 2012

How do you email? Starter's guide

Creating an email (electronic mail) message by using the software such as Outlook or Apple Mail doesn't differ much from creating email using webmail servers (like Gmail or Hotmail for instance), and there are quite a few features similar to ones in word processors (like Microsoft Word) for text formatting purposes. If you want to send a fancy looking email message, you would most likely want to change fonts, insert pictures, add links, and more. While this post is rather about creating and sending than designing the email message, I will provide couple of links that deal with designing nice looking email messages.
Designing of an advertisement-like HTML email is explained in video here. Yet, bear in mind that lot of people prefer to receive plain text email messages, and their email clients are set to show HTML code as a text rather than process it, therefore all the fancy design created can result in the opposite to the expected.
The following video by ISTrainer shows how to use MS Outlook for creating and sending Email messages:

Basic fields to fill in before sending an email message

To:

is the field for e-mail address of the recipient (e.g., johndo@freecomputer.com). If you like you can add the name before address, and it should look like this:

"John Doe" johndo@freecomputer.com

Note that this is the only correct syntax for sending an email. Adding a name before the actual address is optional. You can add quite a few recipients in To: field, but bear in mind, after each email address a comma must be inserted, and it should look like this:

"John Doe" johndo@freecomputer.com, "Mary Poppins" marypoppins@freecookies.com,

and so on.

Subject:

is a field for writing in what the message you are sending, is all about. Keep it short and simple, otherwise the recipient won't be able to see the whole text in the list of all incoming emails.

Bcc:

While every recipient from To: list can see all the other recipients that all have received the same message, every email address that is entered in this field, won't show up to anyone else who receives the message. The syntax for this field is the same as described before. Remember, in order to be able to send the message, you should enter at least one email address in To: field.

Body (or Content)

is where the actual text and links go. (Or images, videos and other fancy things if you are going to send an HTML email message.)

Attach (or Attachments)

is for attaching files to your email message. You can attach any file from the computer to your message but keep in mind that large files (videos for instance) are usually sent using file sharing online servers. Email is suitable for sending documents (like doc or pdf files), compressed/archived documents, small audio files.

Other things to know before sending an email

Every recipient will see who has sent the message to them. Whom they will see as a sender depends on what you have saved in your email settings as your name and last name. Usually that is a From setting that can be accessed in order to change the sender's name.
In email settings there is always an option to set a signature. That is a static text or image that appears at the bottom of each and every message you send. It is a nice way to send some cheerful text or image, or advertise your favourite website.

What else can be seen by recipient

This is more to the point in the context of this website's purpose. Recipient can always see Headers which means that it is possible to see who sent the message, what time it was sent, what email address it has been sent from, what IP address it has been sent from and more. Detailed info on how to read Email Headers can be found here.

A SpamCop.net website explains how to access the headers in all popular email and webmail clients.

How to access your email account using computer's email client

The email client on your computer needs to have correct settings for receiving and sending email to/from your email account. In order to receive messages, software email clients use POP3 protocol, in order to send messages - SMTP protocol. There are two ways to find out correct settings for receiving/sending email using your computer's email client:
  • Using Google to find POP3/SMTP settings for accessing your email account
  • Calling your ISP for the advice on setting up your email client
Here is instructional page for setting up Email client for accessing the Gmail account. This illustrates the common procedure for accessing Email account by using computer's Email software client.

Download and test these products for free for 30 days:
Internet Security Pack: AntiVirus+Firewall
Online Armor Premium Firewall

Saturday, 31 March 2012

How Windows pc and Mac systems get infected

Why Windows malware is not posing a threat to Linux system

In this post I will make an attempt to create a synopsis of usual ways malware makes its way into Windows or Mac system. I am referring specifically to Win/Mac because the vast majority of viruses and other malware is created for these two aforementioned Operating Systems, MS Windows being particular favourite of malware writers due to its large share of OS market (that is, if we are not talking mobile phones at this point).
Malware that has been created for Windows pc, is designed for Registry based OS, and neither Linux or Unix is one, therefore, cannot become affected by it (that is one of the few reasons why I absolutely love Linux). Even though malware can affect only OS it has been designed for, there are couple of things often shared by all three most popular computer Operating Systems (as well as those found in majority of mobile smartphones): Adobe Flash and Sun Java. (In case of Linux the use of Adobe product is less common though.) Even though HTML5+DOM coding in website development is expected to eventually make the use of Flash obsolete, currently that is not the case.

Top weaknesses that can cause infection

1. Unpatched security holes.

Operating system, software and its components are always a subject to exploitation because nothing is ever 100% perfect. If latest updates are not installed, the coding and design vulnerabilities in software applications and operating system are posing a risk of being abused by malware writers. Internet browsers, Adobe products, Sun Java, Windows Media Player, Apple Quicktime all have to be updated on regular basis.
Adobe products. Adobe Reader is usually installed with Speed launcher. This feature is loaded during Windows start-up thus prolonging the OS loading and storing the associated .exe file in Applications' folder where it may simply be another useless file which may be exploited during malware attack on the system. By reading this short article you can decide whether you really need this feature. More on Adobe Acrobat Reader related security issues here.
Adobe Flash is another subject to exploitation if not kept updated. Hackers are known to exploit Flash vulnerabilities which can lead to malware infection. When visiting a website that hosts a HTML page which requires a Flash script, users may encounter a malicious Flash redirector, or malicious script written to exploit vulnerability in the Flash Interpreter which causes it to execute automatically in order to infect the computer. Flash vulnerabilities are directly related to Web application and casual online gaming security. More extensive overview on this subject can be found here.
Java, if not kept updated, is the most common way of infecting computer with trojans while browser is rendering a HTML code at some dodgy adult or software cracking tools' website. It must be noted that most exploited vulnerability on such an occasion is previous Java version that has not been uninstalled after the new, updated one has been downloaded and installed. You can check whether you have two Java versions in your Windows pc by going to Control Panel and opening Add/Remove Programs. If you do have two Java updates listed, it is recommended that you uninstall the older one. You can check your system's Java status here.

2. Javascript enabled for all sites.

Regardless of the Web browser you are using, a Javascript can make your system less secure if enabled to run on all sites. The safe way of using Javascript is to enable it exclusively for trusted sites. Javascript is often the cause of malicious redirects to a site with either a malicious content or an intent to boost the incoming traffic.

3. Online game servers.

Because of the design of the online game architecture, firewalls and anti-malware software sometimes can't detect intrusions. That provides an opportunity for hackers to abuse the victim's machine by using online bots and rootkit-like techniques. More info on data and computer security threats related to online gaming can be found here.

4. Torrent, P2P (Peer-to-Peer) networks, File Sharing programs.

Connection to these networks is making the system susceptible to remote attacks and probability of downloading infected, malicious files. That in turn can lead to identity thefts. Malicious worms, backdoor Trojans, IRCBots and rootkits spread across P2P file sharing networks, gaming, dodgy adult and underground sites.

5. Infected files on USB and other storage media.

An Autorun.inf file can cause much trouble. More about this threat and how to avoid it you can read here.

6. Clicking unsolicited links in e-mail and Instant Messenger chats.

For more info as to why such links are being sent and what consequences such actions can have please see my previous posts here and here.

7. Rogue antivirus / antimalware software.

This includes clicking on pop-ups or banners that claim your computer is infected. All about rogues you can read in one of my previous posts here.

8. Backing up infected files.

A logical cause of re-infection.

9. Assuming that antivirus and/or firewall are not needed, or that they are providing 100% protection.

Two extreme assumptions that both can result in computer not being protected against cyber threats. On the first occasion, it is most likely that such a computer's owner won't even get that far as to visit this website to read this article, therefore, I am going to address the second assumption by saying that even protected machines get infected. Otherwise malware writers wouldn't waste their time on doing what they do. Here is an excerpt from Ivizsecurity.com blog:
Security products like anti-virus, firewalls, IDS/IPS and VPN have become of paramount importance to provide highest degree of confidentiality, availability and Integrity (CIA) to individuals and organizations. However, it is foolish to assume that security products are free from any vulnerability (security flaws). Security Products can also be of target of attacks from the attackers.
  By assuming that Anti-virus and Firewall will do the trick of fully protecting the machine, we risk to return to the beginning of this list, e.g. unpatched security holes.

Download and test these products for free for 30 days:
Internet Security Pack: AntiVirus+Firewall
Online Armor Premium Firewall

Tuesday, 28 February 2012

Free anti malware tools from Emsisoft

There is a variety of malicious software removal tools available from Emsisoft for both, regular and advanced users.
Emsisoft Anti-Malware
For regular users the Anti-Malware software would be most suitable. It is available for download as a full free trial version for 30 days. After that time period in case the license is not renewed it switches to freeware version. Here is the list of features available in full version of Emsisoft Anti-Malware 6.0:
  • File Guard that works as a real-time shield and compares every file downloaded to known malware patterns;
  • dual scan engine consisting of: E1/A2 Emsisoft Anti-Malware engine, and E2/IK Ikarus Anti-Virus engine: a combination that works as 2 in 1. Available also in freeware mode.
  • Behaviour Blocker: constantly monitors the behavior of all active programs and raises an alarm as soon as something suspicious happens. Works without the need for malware signatures as it is designed to be a part of so called zero-day protection capable of recognizing malicious actions performed by hijackers, trojans, keyloggers, spyware, adware, viruses, rootkits and worms by detecting their malicious behaviour in system;
  • Updates can be set to be downloaded as often as 5 times a day;
  • HiJack Free, an integrated system analysis tool designed for professionals to monitor autorun and running processes, services, port configuration, installed ActiveX objects (can be submitted for online analysis), LS Protocols. Advanced user's feature, available also in freeware mode;
  • Commandline scanner. Also an advanced user's feature. A scanner without GUI.
If you want to perform just a quick check on your system, there are two available options that allow you to do just that: Web Malware scanner and MalAware, cloud and signature based light-weight freeware online scanner. Click here and proceed to Freeware section to perform a quick scan on your machine.

Emsisoft Emergency Kit is also available from the Freeware section at publisher's website. It is a very convenient tool to be kept on your USB stick in case your system fails to load the OS because of a virus or other malware. This is really more of an advanced user / admin type of software as it contains Commandline scanner which is supposed to be run from the command prompt; a HiJackFree tool (see the description for Anti-Malware above); and BlitzBlank, a tool that requires more advanced knowledge of Windows Operating System as it lets you delete malicious objects at boot time by using scripts. It is useful for removing locked files, destroying Windows Registry entries, disabling Windows drivers.

Download and test these products for free for 30 days:

Internet Security Pack: AntiVirus+Firewall
Online Armor Premium Firewall

Thursday, 16 February 2012

Bot, Spybot and free malware removal

What are bots and Botnets?

By definition bot is a software application running automated tasks over the Internet like, for example, those best friends of SEO specialists: Google and Bing robot spiders/crawlers that index webpages. We however will be talking the removing of those bots that by About.com's definition are
type of malware which allows an attacker to gain complete control over the affected computer. Computers that are infected with a 'bot' are generally referred to as 'zombies'.
Description of botnets by Securelist.com website pretty much sums up the answer to questions like, what is a purpose of developing botnets and why would anyone want to create trojan bots:
Special Trojans – ‘bots’ (from “robot”) are created for this kind of networks, centrally managed by the remote “master”. The Trojan intrudes into thousands, tens of thousands or even millions of computers. This enables the master of the “zombie network” (or “bot-network”) to access resources of all infected computers and use them to own benefits. Sometimes such networks of “zombie-machines” come into the black Internet-market where they are acquired by spammers or rented.
The following video by rynesandbergfan23 explains what malicious bots are capable of, what to look out for and how to secure your machine so that its chances of getting infected are greatly reduced. (Note: if you haven't got a software to monitor your network connections similar to one shown in the video, you can use Command Prompt (Start-->Run-->cmd) instead. For the list of network connections and associated software applications maintaining them, type netstat -b in the Command Prompt and hit Enter):

Spybot

Last year my machine, despite the full ZoneAlarm's protection it had, got infected with what was known as Google Redirector malware. That's how I got familiar with a freeware called Spybot S&D (or Spybot Search&Destroy), a software project that financially depends on PayPal donations. This freeware is able to identify more than 820,000 pests (including Win32/Zbot (also known as ZeuS), SpyEye and TDSS trojans) by basically doing what it calls a bot-check. The following video will show you what features Spybot has got as well as how to scan and clean your machine:


Now, from my experience, Spybot is very useful to get rid of spyware, adware and all kinds of sneaky pests but it cannot serve as a replacement for an anti-virus software. Handling of malicious Windows Registry entries is one thing Spybot is really good at. The picture that follows is a screenshot of Spybot's scan results:


If you click on it and take a closer look, you can see that (apart from 2 DoubleClick tracking cookies) there are only 3 objects expanded that are not Registry entries.

Malware and spyware removal method

Let's get back to the video at this point. The author of the video comes up with what I see as a generally good idea as to how a Windows machine has to be cleaned: if one malware detection software comes up with detected objects after the scan, it is recommended that after deleting those objects, a system scan is run again, this time by using the same type of software by different vendor. In the video the free Malwarebytes Anti-Malware (appears to be most trusted free malware detector for Windows environment) scanner is used to compare scan results however, unlike that of the video author, our point here is not to demonstrate a comparison because no software is absolutely perfect. The point is using what Hitman Pro (also used in the video) developers call a 'second opinion'. Now, lets see what I've got after following this sequence: free Emsisoft Anti-Malware (Scan settings: Scan type: Deep Scan Objects: Rootkits, Memory, Traces, C:\ Scan archives: On ADS Scan: On) -->Spybot scan --> free Malwarebytes Anti-Malware (Deep Scan) --> Hitman Pro (Default scan):
  • Emsisoft Anti-Malware detects 387 objects each related to one of the following: mywebsearch toolbar, zwinky toolbar, funwebproducts, Trojan.Win32.AddUser and Trojan-Downloader.Agent.  (No screenshot provided because of the amount of objects found yet the scan Report can be viewed by clicking here.)
  • Spybot detects some MyWebSearch and FunWebProducts Windows Registry entries as seen in the screenshot above (the scan takes up to several hours)
  • Malwarebytes Anti-malware still detects some MyWebSearch entries in Windows Registry and a Start Menu Hijack:
  • Hitman Pro detects one remnant of malware in Windows Registry:

  • Now the machine can be considered free of both, malware and spyware. Remember, before you start cleaning your machine, make sure you have:
    • downloaded all the latest updates for the software you are going to use. If this doesn't work, the best thing to do is to obtain anti-malware software installation using other computer. Spybot for instance can be installed and run without the connection to Internet: latest updates is an optional step during the installation;
    • disconnected the machine from the network either by removing cable or disabling/removing your wireless adapter. This is actually the first thing you want to do if you suspect your computer has been infected and you seem to have no control over running processes.
But speaking of Google Redirector... The only free tool that got rid of it was HitMan Pro (Google redirection infection is known as TDL3/TDL4 rootkit).  Mind you, that was back in May 2011, and as we know, things constantly change.

Internet Security Pack: AntiVirus+Firewall
Online Armor Premium Firewall

Friday, 10 February 2012

How a banking trojan can steal your data and money

A quick look at Zbot

There are many ways hackers can try to steal personal data from computers. We will take a look at what is known as Zeus to give you the idea of how your banking information can be stolen, so that you know what to be aware of, and how to avoid of becoming a victim.

There is an in-depth analysis of ZeuS Banking trojan to be found at SecureWorks website by authors Kevin Stevens and Don Jackson, Security Researchers from SecureWorks Counter Threat Unit SM (CTU). While it is suggested that you read the whole article, I will post some excerpts here:
ZeuS is a well-known banking Trojan horse program, also known as crimeware. This trojan steals data from infected computers via web browsers and protected storage. Once infected, the computer sends the stolen data to a bot command and control (C&C) server, where the data is stored. ZeuS has evolved over time and includes a full arsenal of information stealing capabilities:
  • Steals data submitted in HTTP forms
  • Steals account credentials stored in the Windows Protected Storage
  • Steals client-side X.509 public key infrastructure (PKI) certificates
  • Steals FTP and POP account credentials
  • Steals/deletes HTTP and Flash cookies
  • Modifies the HTML pages of target websites for information stealing purposes
  • Redirects victims from target web pages to attacker controlled ones
  • Takes screenshots and scrapes HTML from target sites
  • Searches for and uploads files from the infected computer
  • Modifies the local hosts file (%systemroot%\system32\drivers\etc\hosts)
  • Downloads and executes arbitrary programs
  • Deletes crucial registry keys, rendering the computer unable to boot into Windows
  •  
How to detect the ZeuS Banking Trojan on your computer
Computers infected with this version of ZeuS will have the following files and folders installed. The location depends on whether the victim has Administrator rights. The files will most likely have the HIDDEN attribute set to hide them from casual inspection.
With Administrator rights: 
%systemroot%\system32\sdra64.exe (malware)%systemroot%\system32\lowsec%systemroot%\system32\lowsec\user.ds (encrypted stolen data file) %systemroot%\system32\lowsec\user.ds.lll (temporary file for stolen data) %systemroot%\system32\lowsec\local.ds (encrypted configuration file)
Without Administrator rights: 
%appdata%\sdra64.exe%appdata%\lowsec%appdata%\lowsec\user.ds%appdata%\lowsec\user.ds.lll%appdata%\lowsec\local.ds 
ZeuS also makes registry changes to ensure that it starts up with Administrator privileges:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinlogonFrom:"Userinit" = "C:\WINDOWS\system32\userinit.exe"To:"Userinit" = "C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe"
Without Administrator rights:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunAdd:"Userinit" = "C:\Documents and Settings\<user>\Application Data\sdra64.exe" 
The sdra64.exe program uses process injection to hide its presence in the list of running processes. Upon startup, it will inject code into winlogon.exe (if Administrator rights available) or explorer.exe (for non-Administrators) and exit. The injected code infects other processes to perform its data theft capabilities.

How your system can get infected

There is a list of ways your system can get infected to be found in one of my other posts here. Things you really should watch out for, and avoid, are emails supposedly sent from your bank where you are asked to follow a certain link in order to update your security details, or to download a file attached to the e-mail message. Here are few samples of such e-mail messages:

Dear Customer,
We detected irregular activity on your
Internet banking account.
For your protection, you must verify this
activity before you can continue using your
account.
Please download the document attached to this
email to review your account activity.
We will review the activity on your account
with you and upon verification, we will remove any restrictions placed on
your account.
If you choose to ignore our request, you leave us no choice
but to temporary suspend your account.
We ask that you allow at least 72 hours for the case to be
investigated and we strongly recommend to verify your
account in that time.
© Copyright Barclays Bank Holdings plc 2012 - All rights reserved


and

Dear Valued Customer,
Your account is suspended due to the number of incorrect login attempts.
For your protection, we've suspended your account .
To reactivate your account please download the document attached to this
e-mail and review your account activity.
If not completed until February 09, we will be forced to close your account .
Note: If you received these e-mail in your BULK/SPAM section please
add to your address book [e-mail address withdrawn]

Thank you,

Customer Support Service.

Copyright © NatWest Bank Plc. Limited. All rights reserved.


On both occasions senders obviously have made an opportunistic attempt to get me into downloading their malicious HTML files attached to messages without knowing that I'm not a customer of either of aforementioned banks.
So, what would have happened if I'd downloaded the attached file? I would most likely have infected my machine with a trojan bot spyware that would be capable of sending data from my computer to a remote server on the Internet, controlled by a cyber criminal, and basically making my machine a part of a botnet.
Or, if there would have been a link to follow, then, by clicking it, I would most likely have ended up on some bogus website designed by a cyber criminal for malicious purposes such as pharming (URL redirections with purpose of information stealing) or spreading malware infections. Example of a phishing message:

Dear Valued Customer,
our security filter noticed a malicious activity in your online account.
We were able to trace it to an unknown link thereby, placing
your online banking on suspension till this is resolved.
We implore you to go over your account details so
as to continue with your online transactions.
Click here to resolve the problem.
[Link withdrawn]

Thank you for helping us to render you a maximum protection.

Security Department.

Alliance-leicester online banking.


Things to keep in mind

Regardless of the content of the message, remember: banks will not ask you for any security details or security updates via e-mail. Don't just click on links in emails you receive from someone. Make sure the sender is trusted and genuine, and the link does not look dodgy. (The same applies to Instant Messenger chats.) If you receive a suspicious email supposedly sent from your bank, and you are asked to proceed with giving away any of your personal or financial details, or to download an attachment, don't. Instead, forward the email message to the bank. Almost on all occasions you can find e-mail address for forwarding phishing emails to at the bank's official website. For more detailed information on types of scams related to Online banking, and to get a genuine advice, please visit Bank Safe Online, a website developed by UK Payments Administration Ltd.

Internet Security Pack: AntiVirus+Firewall
Online Armor Premium Firewall

Thursday, 9 February 2012

Free anti spyware tools by Trend Micro

  • HouseCall. A free Web-based tool designed to scan your PC for a wide range of Internet security threats including viruses, worms, Trojans, and spyware. You can download HouseCall directly from the TrendMicro's website, download takes a short time as the file is not too big, just double-click the file after it has finished downloading and there you go. 
  • RUBotted. Real-time monitoring of your network (Internet) connection for potential infection and suspicious activities associated with bots. During its installation RUBotted installs additional third-party freeware called WinPcap for capturing the incoming/outgoing data packets. Upon discovering a potential infection, RUBotted will identify and clean them with HouseCall. So if you are concerned about someone from the outside using and abusing your machine, TrendMicro's RUBotted is the way to go. 
  • Trend Smart Surfing. Designed for iPhone and iPod touch devices. It is the first secure browser to protect you from Web pages with malicious intent. If you attempt to access a bad or malicious URL, Smart Surfing is designed to block access to the URL and a notification will appear in the browser. 
  • Trend Micro HijackThis is a free utility that generates an in-depth report of registry and file settings from your computer. HijackThis makes no separation between safe and unsafe settings in its scan results giving you the ability to selectively remove items from your machine. In addition to this scan and remove capability HijackThis comes with several tools useful in manually removing malware from a computer. This is a very handy tool if you are an administrator/advanced user and know what you are doing. By using HijackThis you can see if you still have some useless or strange browser objects, processes that are not supposed to maintain data streams and to be connected to the Internet, and so on.
Here is a YouTube video showing how to use HijackThis. Watch this before you attempt to do anything in HijackThis:


Stay safe!

Wednesday, 8 February 2012

Speed up and secure your Web Browser

One excellent way to make your Windows (or Mac or Linux) computer more safe for the Internet browsing is to manage what is called the Hosts file. That does not mean that you would have to understand programming or anything like that. It's actually pretty simple: on your computer you just go to where your Windows Hosts file is, and either, copy+paste new content into it, or replace the file with a new one. It is easy to do yet also requires careful attention while performing the process of changing the file: Hosts file is not something you want carelessly play around with.

Before we proceed to actual way of dealing with Hosts file, I will explain what is the point of changing it, so you can figure out yourself if you actually want to do that.
You most definitely want to update your Hosts file if you:
  • don't like dozens of advertisements displayed on pages you are browsing. If that is the case then updating your Hosts file the way I am about to advise will let you get rid of majority of annoying ads on Internet pages by simply not loading those ads.
  • want to keep the number of malicious websites (those containing malware and browser hijackers) you risk to open to a minimum.
  • don't want to be secretly tracked by some Internet ad providers who try to follow visitors' actions and see what other sites they are visiting.
Changing your Hosts file will block your computer's connection to any of the sites that are correctly listed in this file.
For instructions and more details visit this site: http://winhelp2002.mvps.org/hosts.htm The procedure is harmless and doesn't require any additional software. Speaking in terms of TV adverts: Ever since I have discovered this method, my computers' (both, Windows and Linux) Hosts file is always up to date with the content provided by Winhelp2002 website. No more forever loading ads, no more strange, slow loading pages, no more strange behaviour by my Web Browsers.

Download and test these products for free for 30 days:

Internet Security Pack: AntiVirus+Firewall
Online Armor Premium Firewall