Consolidated Security Thread (legacy)

Page 7 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

Doh!

Platinum Member
Jan 21, 2000
2,325
0
76
Just would like to comment that running PerfectDisk crashes windows if you're using Kerio FW 2.1.5 (documented by Raxco-PerfectDisk). More recent versions of Kerio FW are ok however.
 

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
Thanks Medea and John for all the new information that you gave me (in this thread and via PMs). It has been put into Revision 9, which is now live
 

0roo0roo

No Lifer
Sep 21, 2002
64,795
84
91
i'm sad i didn't run crap cleaner sooner so much space and less system bog. nice!
 

John

Moderator Emeritus<br>Elite Member
Oct 9, 1999
33,944
2
81
Originally posted by: SunnyD
Originally posted by: Medea
Originally posted by: SunnyD
Can someone post a working link for Kerio 2.1.5? And maybe some screenshots of the UI?


You can download it from here.

Cool thanks. Tried it out for a bit, doesn't seem as informational as 4.2 is, nor does it integrate with Windows Security very well. Very minimalist. It's a shame 4.2 isn't free anymore.

Schadenfroh, you might want to update the OP that neither Sygate or Kerio are free and/or exist anymore, other than maybe the legacy download of Kerio 2.1.5.

I've uploaded the popular free firewalls to my FTP.

Kerio 4.2.2 (last of the freebies)
Kerio 2.1.5
Sygate Personal Firewall Free 5.6.2808


 

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
The thread is not dead!

New applications have been added thanks to John, see the change log in the OP for other changes and additions.

With that folks, Rev .095 goes live, enjoy and do give feedback.
 

Pr0d1gy

Diamond Member
Jan 30, 2005
7,774
0
76
I bought & Dl'd Kaspersky IS 5.0 awhile back & absolutely love it. That said, for some reason it is no longernotifying me of network attacks despite me having it set to do just that. Any ideas? Keep in mind I do not regularly visit the the Kas website, so it could be something everyone knows about that I just missed.
 

Killrose

Diamond Member
Oct 26, 1999
6,230
8
81
Originally posted by: dAv
No one seems to have mentioned SpyCatcher (Tenebril)
Free express version picked up 4 baddies on deep scan. Keyloggers, backdoors, adware.
Had used Ad Aware, Spybot, SpywareBlaster and MS Defender, all had missed these.
Runs in background like Defender. Make sure you uninstall Defender first, they
don't play well together.

Thanks, using that cleaned a whole bunch of problem stuff that , AtiVir, Spybot Search and Destroy, Adware, Trend, Mcafee, A-square, ewido, and a Retail version of Spy Doctor, ect., did not catch. You do have to carefully go thru the items it catches to make sure they are not a valid app before removing them, but it does give you pretty good detailed info on each item. But My computer is no longer taken over by bogus pop ups and downloaders.

However, I still cant get into Safe Mode. I used to, but whatever hit me soon dissabled my ability to do so. That problem happened when I was using only the tools on the first page of this thread to repair a virus/worm/trojan or whatever I got into. It got by Ativir which I religiously kept updated everyday.

UPDATE: Thanks to a couple of runs with Spy Doctor and Spy Catcher, I was able to get into Safe Mode. I will have to give most the credit to Spy Catcher which compared to everything else I tried works super. Spy Bot SD is a joke, it never catches anything and WinDefender always said my comp was clean even at its worst state.

Spy Catcher for teh win :thumbsup:
 
May 31, 2001
15,326
2
0
Downloading the free version of SpyCatcher right now. I have been having a problem with some CasaleMedia spyware that my machine picked up somehow, and while SpyBot would find it and clean it, it would reappear after every reboot and the Google searches I did found nothing but sites I had to register for to read the solution to the problem. I will let you all know how it works out.

EDIT: Holy crap, SpyCatcher FTW! :shocked:
 

flexy

Diamond Member
Sep 28, 2001
8,464
155
106
i want to add some interesting notes:

First, thanks..i am always coming back to this thread because the listed tips/resources are priceless

() according to the latest av-comparatives

http://www.av-comparatives.org/

G-Data AVK has a slightly HIGHER detection rate than KAV !

But i need to mention that those (for the on-demand scanners) comparison on av-comparaitves is from February 06.
But still, there is no way around that AVK in this case beats KAV - even only a few percentage points.

The reason is that AVK uses both, the KAV and the BitDefender engine.

It is unknown to me what version KAV engine AVK uses, some say it uses an older KAV engine.

Also...i still am unsure about memory inprints. (I used to run NOD32 mainly because of good balance "memory inprint" <--> "detection rate"

()
http://www.virus.gr/english/fullxml/default.asp?id=69&mnu=69

Above did not even TEST G-Data's AVK because their policy is NOT to test a AV program if there is no free demo available.

This is on one hand understandable...but NOT professional and should be taken with a grain of salt, especially if you're out
looking for "the best AV checker" (with the best detection rate).

()
I was running NOD32 for the longest time and love it....but was bugged with recent infections which made me think twice about the sense/nonsense
of a AV program (NOD32) which was running all the time with all options on (Amon, Imon etc.)...and still i get (although rarely) BAD infections and have a hard time cleaning my system.
I did EXTENSIVE cleaning/scanning incl. Ewido 4.0, Trojan Hunter, Ad-Aware, NOD32, YOU NAME IT....from what i thought should REALLY get rid of certain infections i had.....but AT THE END i had to run hijackthis and manually delete entries which NO AV program above even complained about.

I had entries like a suspicios "winpsa32.dll" which turned out to be some trojan/virus as well as entries that "something" possibly redirected DNS lookups to unknown IP adressed...the result was that frequently some malware was downloaded from a certain website and executed in windows\temp. Only the fact that i blocked the webadress in my hosts file prevented it from downloading the actual program....still i saw the pop-up coming up all the time and trying to execute the malicious code.
(Again: With all the above scanners (Ewido, Trojan Hunter, NOD, Adaware checkers incl. runing them in safe-mode didnt clean/find ANYTHING suspicious while i got the pop-up every 15mins or so CLEARLY telling me something odd was going on

I am now (for testing purposes) switching to KAV6.

With ALL the resources and sites....it is STILL *not* easy to fine "the perfect" AV program/Trojan killer etc....especially if SOME sites are biased and basically only try to sell certain products....SOME sites just omit programs....and SOME sites use outdated programs for comparison purposes.

(AV comparatives still used KAV5 - but KAV6 is out)

I'd highly appreciate it if we could expand our thread and add some more independent links with comparisons of recent AV programs ?!


 

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
I'd highly appreciate it if we could expand our thread and add some more independent links with comparisons of recent AV programs ?!
If you find some, be sure to PM me or post them here and I will put it into the OP in the next revision with credit to you or whoever finds the information.
 

Googer

Lifer
Nov 11, 2004
12,576
7
81
Clamwin is a free open source GPL Antivirus Scanner that when it was tested beat out all the commercial scanners by a large margin and found twice as many viri.

It's still in development and needs a bit of maturing. But this program holds a lot of potential.

http://en.wikipedia.org/wiki/ClamWin
 

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
Thanks Supafly for bringing this to my attention,

The AOL AVS might not be the gift that we once thought. Some things have come up that worry me. The article linked below stated that the EULA contains things that can leave the door open for AOL spyware.
"If it actually does any of the things stated in the EULA, we would actually flag it as spyware," said Christina Olson
The EULA also keeps you from using adblocking software:
"If you have any ad-blocking software up, you're basically violating their EULA, which is ridiculous," she said.
In addition, AOL can send you spam email via your email address that you used to register it.
"We are reserving the right solely to send periodic marketing e-mails that users will have the choice to opt out of."

The biggest worry comes from the optional toolbar that one can install with the AOL AVS:
Adding to AOL's troubles is the fact Active Virus Shield's security toolbar is based on a product with a questionable reputation. An earlier version of this software, known as the Softomate toolbar, is flagged as adware by Kaspersky's own antivirus products.

"I don't understand how a legitimate company like AOL provides software that can be classified as rogue," said Aviv Raff, a security researcher based in Israel.

After examining AOL's toolbar, Raff discovered a flaw in the software that would allow hackers to change the toolbar's configuration options. While the flaw does not in itself present a security risk, it could be used in combination with other types of malicious software to do things like pop up bogus search results, he said.

Article

I would suggest that ANYONE using the AOL AVS register it with an email account that you dont mind getting spammed and that you DO NOT install the toolbar that comes with the AVS.

I have updated the OP to address these concerns and note the possible dangers of the AOL AVS.
 

UsandThem

Elite Member
May 4, 2000
16,068
7,383
146
Just to let others know before they try BitDefender's Internet Security 10 suite:

This recently released suite caught my attention because BitDefender detection rate is very good, and they have it where if you buy their new suite, you get two years of updates for around $69.00 through the end of the year.

Well, I downloaded it from their website and installed it. Windows kept giving me warnings that the software wasn't certified by Microsoft (no big deal I thought).

Well, it looks like it my be a good program at some point, however it must have been rushed for release. It disable Windows Update (wouldn't work even if Firewall/Antivirus was turned off).

Also, out of all the security suites I tested, it was the only one that I manually had to go in and uninstall because if left some stuff.

It also slowed my system down the most out of all the programs tested.

So, right now I am testing Kaspersky 6 and have been very impressed so far.
 

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
Thanks John for PMing me that virus.gr has updated their detection tests.

Anyone wishing to view the results can look at them here.

Kaspersky and AOL's freeware Active Virus Shield were at the very top and were identical in detection rate.

An amazing 99.62% pieces of malware detected from a "zoo" of 147184 unique malware samples, and this is after every antivirus product had their heuristics set to its highest setting.
 

Medea

Golden Member
Dec 5, 2000
1,606
0
0
Hi Schadenfroh -

I saw that post about the AV results. Glad I have Kaspersky.

Also, for those who haven't seen the post, AOL uses Kaspersky which accounts for the identical results...
 

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
After much work and reviewing, I have finished revision 10. I removed many parts that I thought were of little value, I fixed all broken links (dang, there were like 20 of them), I removed outdated applications or replaced them with more up-to-date ones, massive text fixes were done, all sections have been fully reviewed, revised, and updated. I hope that this one will last a while.

Revision 10 is now live, enjoy and do give feedback.
 

Medea

Golden Member
Dec 5, 2000
1,606
0
0
Originally posted by: Schadenfroh
After much work and reviewing, I have finished revision 10. I removed many parts that I thought were of little value, I fixed all broken links (dang, there were like 20 of them), I removed outdated applications or replaced them with more up-to-date ones, massive text fixes were done, all sections have been fully reviewed, revised, and updated. I hope that this one will last a while.

Revision 10 is now live, enjoy and do give feedback.

Clear, concise and informative. Well done! :thumbsup:

 

sonambulo

Diamond Member
Feb 22, 2004
4,777
1
0
Hi guys. Let me tell you a little story. I started a thread about this but it seems as though it was the wrong idea. I couldn't find the exact information I'm looking for in the OP or the thread so I'll go ahead and post this.

I got a call last night from my bank telling me that someone was trying to access my account to withdraw huge amounts of money. They were trying to buy plane tickets either from Miami to Peru or vice versa. Now, what strikes me as really odd is that there have been some 'acquaintances' in my house recently who hail from Peru using my computer.

Now it's my understanding that antivirus and adware programs don't detect keyloggers because they're supposedly good programs.

So it's a two-part question, really. 1. How can I detect if there are keyloggers installed in my computer? 2. Where can I learn more about Windows, especially Admin priveleges, in order to prevent this from happening again? Is there a good book or website I can start with?

Many thanks! Feel free to shout this down if it's in the wrong spot.
 

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
Originally posted by: sonambulo
1. How can I detect if there are keyloggers installed in my computer?
Kaspersky (try the AOL AVS in the freeware thread in my sig, which is the same thing) should detect the keyloggers.

2. Where can I learn more about Windows, especially Admin priveleges, in order to prevent this from happening again? Is there a good book or website I can start with?

See MechBGon's excellent guide
 

hans007

Lifer
Feb 1, 2000
20,212
18
81
i actually used to work in the symantec security response virus analysis lab. i suppose if any of you guys had any questions , maybe i could answer some of them.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |