Microsoft Security Essentials 1.0.1611.0 License model : Free Limitations : Not available Operating systems : Windows Vista, Windows XP, Windows 7 Additional requirements : Not available Publisher's description The successor to Microsoft Live OneCare, Security Essentials (full review here) takes a different approach to securing your computer. The program is free with core security features intact, but abandons the additional heft of a firewall, performance tuning, and backup and restore options. Under a clean and uncluttered interface, Security Essentials wraps antivirus and antispyware engines, rootkit protection, and real-time detection courtesy of Microsoft SpyNet, the unfortunately named cloud-based service that compares file behavior across computers.
There are four tabs, each with a concise, understandable label: Home, Update, History, and Settings. From Home you can run a Quick Scan, Full Scan, or Custom Scan, and a link at the bottom of the pane lets you change the scheduled scan. In the Settings window you can schedule scans, toggle default actions, adjust real-time protection settings, and create whitelists. An Advanced option here is still fairly basic, allowing you to set Security Essentials to scan archives, removable drives, create a system restore point, or allow all users to view the History tab. Security Essentials uses labels imported from OneCare: green for all good, yellow for warning, and red for an at-risk situation.
Independent test numbers for Security Essentials weren't available at the time of writing, although OneCare scored high detection rates. On a real-world machine, the Quick Scan completed in less than 30 seconds. Benchmarking tests from CNET Labs reveal that Security Essentials actually makes starting up and shutting down faster, but the Full Scan is much slower than many competitors. RAM usage was not insignificant, with 85 to 90MB used during a full scan, but it felt lighter. Security Essentials is basically a good set-it-and-forget-it security program, but if you want more options, you should look elsewhere. With Microsoft Security Essentials Beta, you get high-quality protection against viruses and spyware, including Trojans, worms and other malicious software. And best of all, there are no costs or annoying subscriptions to keep track of.
Security Essentials is easy to install and easy to use. Updates and upgrades are automatic, so there's no need to worry about having the latest protection. It's easy to tell if you're protected - when the Security Essentials icon is green, your status is good. It's as simple as that.
When you're busy using your PC, you don't want to be bothered by needless alerts. Security Essentials runs quietly in the background, only alerting you if there's something you need to do. And it doesn't use a lot of system resources, so it won't get in the way of your work or fun.
By Michael Kassner Cybercriminals are putting forth every effort to make malware difficult to detect. Successfully, I might add. Ever optimistic, I thought I would have a go at providing information on how to make their job a little tougher.
Baselining is an important reference
Knowing exactly what is running on a computer is paramount to learning what shouldn't be. Creating a reference baseline is the best way I've found to accomplish this. Let's look at three applications that do just that.
Microsoft Process Explorer (formerly Sysinternals)
Process Explorer provides an excellent way to determine what processes are running on a computer. It also describes the function of each process. More important, you can use Process Explorer to create a baseline of the running processes used by the computer when it's operating correctly. If for some reason the computer starts behaving poorly, run Process Explorer again and compare the scans. Any differences will be good places to start looking for malware.
Trend Micro's HiJackThis
HiJackThis is Process Explorer on steroids, making the application somewhat daunting to those of us not completely familiar with operating systems. Still, running HiJackThis before having malware problems creates a great reference baseline, making it easy to spot changes. If it's too late to run a baseline scan, do not fear. Several Web sites offer online applications that will automatically analyze the log file from HiJackThis, pointing out possible conflicts. Two that I use are HiJackThis.de Security and NetworkTechs.com. If you would rather have trained experts help, I would recommend WindowSecurity.com's HiJackThis forum.
Kaspersky's GetSystemInfo
Kaspersky has an application similar to HiJackThis called GetSystemInfo. I like the fact that Kaspersky has an online parser. Just upload the log file and the parser will point out any disparities. GetSystemInfo, like the other scanners, is a good way to keep track of what's on the computer, and if need be, it can help find any malware that happens to sneak in. Be careful: As I alluded to earlier, removing processes suggested by the scanners is not for the faint of heart. It requires in-depth knowledge of operating systems or being able to compare before and after scans. Next, I'd like to discuss two vulnerability scanners.
It's simple: No vulnerabilities, no malware
Anti-malware includes any program that combats malware, whether it’s real-time protection or detection and removal of existing malware. Vulnerability scanners proactively detect vulnerabilities so that malware can't gain a foothold. I'd rather update applications than chase malware any day. Microsoft Baseline Security Analyzer
Microsoft Baseline Security Analyzer (MBSA) is a vulnerability scanner that detects insecure configuration settings and checks all installed Microsoft products for missing security updates. I recommend using MBSA when upper management needs convincing. Making a case for needing a vulnerability scanner is sometimes easier if the product is from the OEM.
Secunia inspection scanners
Secunia's scanners are similar to MBSA when it comes to Microsoft products. But unlike MBSA, Secunia products also scan hundreds of third-party applications, which gives Secunia a distinct advantage. All the Secunia scanners, online and client-side, have an intuitive way of determining what is wrong and how to rectify it. They usually offer a link to the application's Web page, where the update can be downloaded.
Not always simple
Remember when I said, "It's simple: No vulnerabilities, no malware"? Well, it's not exactly that easy. It would be, except for those nasty things called zero-day exploits and zero-day viruses. That's where antivirus applications come into play, especially if they use heuristics.
Antivirus programs
Lately, antivirus software is getting little respect. Like everyone, I get frustrated when my antivirus program misses malcode that other scanners mange to find. Still, I would not run a computer without antivirus. It's too risky. I subscribe to the layered approach when it comes to security. Choosing the correct antivirus application is personal. Comments come fast and furious when someone asks TechRepublic members which one is the best. A majority feel that any of the free versions are fine for nonbusiness use. I use Avira or Comodo on Windows machines.
Anti-malware enforcers
The next class of anti-malware is capable of both detecting and removing malware. I'm sure you are wondering why not just use these from the start. I wish it was that simple. Scanners use signature files and heuristics to detect malware. Malware developers know all about each and can morph their code, which then nullifies signature files and confuses heuristics. That's why malware scanners aren't the cure-all answer. Maybe someday. More caution: I want to emphasize that you need to be careful when picking malware scanners. The bad guys like to disguise malware (antivirus 2009) as a malware scanner, claiming it will solve all your problems. All four of the scanners I have chosen are recommended by experts.
Microsoft's Malicious Software Removal Tool Malicious Software Removal Tool (MSRT) is a good general malware removal tool, simply because Microsoft should know whether the scanned code is theirs or not. Three things I like about MSRT are: • The scan and removal process is automated. • Windows Update keeps the signature file database current automatically. • It has the advantage of being an OEM product, thus it's less intrusive and more likely to be accepted by management.
SUPERAntiSpyware
SUPERAntiSpyware is another general purpose scanner that does a good job of detecting and removing most malware. I have used it on several occasions and found it to be more than adequate. A number of TechRepublic members have mentioned to me that SUPERAntiSpyware was the only scanner they found capable of completely removing antivirus 2009 (malware).
Malwarebyte's Anti-Malware Malwarebytes Anti-Malware (MBAM) malware scanner was the most successful of the four I tested. I was first introduced to it by world-renowned malware expert Dr. Jose Nazario of Arbor Networks. For a detailed explanation of how MBAM works, refer to my post Malware scanners: MBAM is best of breed. Still, MBAM does not catch everything. As I pointed out in the MBAM article, it misses some of the more sophisticated malware, especially rootkits. When that happens, I turn to the next malware scanner.
GMER
In Rootkits: Is removing them even possible?, I explained why it's hard to find rootkit malware. Fortunately, GMER is one of the best when it comes to detecting and removing rootkits -- enough so that it's recommended by Dr. Nazario.
When you’re troubleshooting a problem in Windows 2000 or Windows XP, chances are that you may turn to Windows Task Manager for more information about the programs and processes that are running on a system. When you first launch Task Manager, it opens to the Applications tab, which shows you a list of all the applications that are currently running. However, when you switch to the Processes tab, you’ll see that there are many more processes running than there are applications.
As you know, many of the running processes are easy to identify—especially if they directly represent an application. For example, it’s easy to tell that the notepad.exe process corresponds to Notepad. However, not all processes are that easy to identify—especially if they represent services. In fact, as you look at the list of processes, chances are that you’ll find multiple processes listed as Svchost.exe, which is a generic host process name for services that run from dynamic-link libraries (DLLs). In addition, you may find other similarly named processes that actually represent services.
The Service Process Identifier script will locate those processes that are hosting services, identify them by their PID number, track down each service running inside the process, compile a list, sort it by PID, and then create a nicely formatted Excel spreadsheet, which can then be used in tandem with Windows Task Manager as a troubleshooting aid.
Requirements The Service Process Identifier is only designed to work with Windows 2000 or Windows XP. It requires Microsoft Excel and will work with versions 2000/2002/2003.
Readme.doc This file ServiceProcessID.vbs The main VBScript Application file
To install the Service Process Identifier, simply copy these two files to a folder of your choice.
Note: Because the Service Process Identifier is a VBScript, certain antivirus programs may flag it as a virus or a malicious script. If so, you’ll need to authorize, or allow the script to run. See your antivirus program documentation for information on how to do so.
Using the Service Process Identifier To launch the Service Process Identifier, just double-click the ServiceProcessID.vbs file. While the script is running, you’ll see a series of popup dialog boxes that will keep you informed of the program’s progress.
When the script finishes compiling its list of services, it will launch Excel and display the worksheet, which consists of two columns—one for the Process ID (PID) and the other for the Services. The PIDs will be listed in ascending order and appear in red. The Services will be listed by their full name and appear in blue. Right below the full name, you’ll find the command line, which will appear in black, used to launch the service.
When the spreadsheet appears, press [Ctrl][Shift][Esc] to access Task Manager. With Task Manager up and running, select the Processes tab. If you don’t see a column titled PID, pull down the View menu, choose the Select Columns command, select the PID (Process Identifier) check box, and then click OK. Now, click the PID column header to sort the list of processes by the PID number in ascending order. If you wish, you and click and drag the PID column to reposition it on the left-hand side of the Processes display.
At this point, you can scroll through the Processes display, locate the process you’re interested in and match its PID to the one in the Service Process Identifier worksheet.
Saving the spreadsheet While this spreadsheet is only meant for temporary use during a troubleshooting operation, you may want to save it for future reference. However, keep in mind that the original format of the data is a simple Comma Separated Value (CSV) file, so Excel will prompt you to make a decision as to formatting before it will allow you to save the file. In order to preserve the formatting and save the file in Excel format, follow the instructions displayed in the dialog box.
Malware: Is malicious software that’s specifically developed to infiltrate or cause damage to computer systems without the owners' knowledge or permission.
Malcode: Is malicious programming code that’s introduced during the development stage of a software application and is commonly referred to as the malware’s payload.
Anti-malware: Includes any program that combats malware, whether it’s real-time protection or detection and removal of existing malware. Antivirus and anti-spyware applications and malware scanners are examples of anti-malware.
It's important to remember that like its biological counterpart, malware's number one goal is reproduction. Damaging a computer system, destroying data, or stealing sensitive information are all secondary objectives.
Keeping the above definitions in mind, let’s take a look at 10 types of malware.
1: The infamous computer virus
A computer virus is malware that’s capable of infecting a computer but has to rely on some other means to propagate. A true virus can spread from the infected computer to a non-infected computer only by attaching to some form of executable code that’s passed between them. For example, a virus could be hidden in a PDF file attached to an e-mail message. Most viruses consist of the following three parts:
Replicator: When the host program is activated, so is the virus, and the viral malcode’s first priority is to propagate.
Concealer: The computer virus can employ one of several methods to hide from anti-malware.
Payload: The malcode payload of a virus can be purposed to do just about anything, from disabling computer functions to destroying data.
Some examples of computer viruses currently in the wild are W32.Sens.A, W32.Sality.AM, and W32.Dizan.F. Most quality antivirus software will remove a computer virus once the application has its signature file.
2: The ever-popular computer worm
Computer worms are more sophisticated than viruses, being able to replicate without user intervention. If the malware uses networks (Internet) to propagate, it’s a worm rather than a virus. The main components of a worm are:
Penetration tool: Malcode that leverages vulnerabilities on the victim computer to gain access.
Installer: The penetration tool gets the computer worm past the initial defense mechanism. At that point, the installer takes over and transfers the main body of malcode to the victim.
Discovery tool: Once settled in, the worm uses several methods to discover other computers on the network, including e-mail addresses, Host lists, and DNS queries.
Scanner: The worm uses a scanner to determine if any of the newly found target computers are vulnerable to the exploits available in its penetration tool.
Payload: Malcode that resides on each victim’s computer. This could be anything from a remote access application to a key logger used to capture user names and passwords.
This category of malware is unfortunately the most prolific, starting with the Morris worm in 1988 and continuing today with the Conficker worm. Most computer worms can be removed by using malware scanners, such as MBAM or GMER.
3: The unknown backdoor
Backdoors are similar to the remote access programs many of us use all the time. They’re considered malware when installed without permission, which is exactly what an attacker wants to do, by using the following methods:
One installation method is to exploit vulnerabilities on the target computer.
Another approach is to trick the user into installing the backdoor through social engineering.
Once installed, backdoors allow attackers complete remote control of the computer under attack. SubSeven, NetBus, Deep Throat, Back Orifice, and Bionet are backdoors that have gained notoriety. Malware scanners, like MBAM and GMER, are usually successful at removing backdoors.
4: The secretive Trojan horse
It’s difficult to come up with a better definition for Trojan horse malware than Ed Skoudis and Lenny Zelter did in their book Malware: Fighting Malicious Code:
“A trojan horse is a program that appears to have some useful or benign purpose, but really masks some hidden malicious functionality.”
Trojan horse malware cloaks the destructive payload during installation and program execution, preventing anti-malware from recognizing the malcode. Some of the concealment techniques include:
Renaming the malware to resemble files that are normally present.
Corrupting installed anti-malware to not respond when malware is located.
Using Polymorphic code to alter the malware’s signature faster than the defensive software can retrieve new signature files.
Vundo is a prime example; it creates popup advertising for rogue anti-spyware programs, degrades system performance, and interferes with Web browsing. Typically, a malware scanner installed on a LiveCD is required to detect and remove it.
5: Adware/spyware: more than an annoyance
Adware is software that creates popup advertisements without your permission. Adware usually gets installed by being a component of free software. Besides being irritating, adware can significantly decrease computer performance.
Spyware is software that collects information from your computer without your knowledge. Free software is notorious for having spyware as a payload, so reading the user agreement is important. The Sony BMG CD copy protection scandal is probably the most notable example of spyware.
Most quality anti-spyware programs will quickly find unwanted adware/spyware and remove it from the computer. It’s also not a bad idea to regularly remove temp files, cookies, and browsing history from the Web browser program as preventative maintenance.
Malware stew
Up until now, all the malware discussed has distinctive characteristics, making each type easy to define. Unfortunately, that’s not the case with the next categories. Malware developers have figured out how to combine the best features from different types of malware in an attempt to improve their success ratio.
Rootkits are an example of this, integrating a Trojan horse and a backdoor into one package. When they're used in this combination, an attacker can gain access to a computer remotely without raising any suspicion. Rootkits are one of the more important combined threats, so let’s take a deeper look at them.
Rootkits: Completely different
Rootkits are in a class all their own, choosing to modify the existing operating system instead of adding software at the application level, like most malware. That’s significant, because it makes detection by anti-malware much more difficult.
There are several types of rootkits, but three make up the vast majority of those seen in the wild: user-mode, kernel-mode, and firmware rootkits. Let's look at user-mode and kernel-mode first:
User-mode: Code has restricted access to software and hardware resources on the computer. Most of the code running on your computer will execute in user mode. Due to the restricted access, crashes in user-mode are recoverable.
Kernel-mode: Code has unrestricted access to all software and hardware resources on the computer. Kernel mode is generally reserved for the most trusted functions of the operating system. Crashes in kernel-mode aren’t recoverable.
6: User-mode rootkits
It’s now understood that user-mode rootkits run on a computer with the same privileges reserved for administrators. This means that:
User-mode rootkits can alter processes, files, system drivers, network ports, and even system services.
User-mode rootkits remain installed by copying required files to the computer’s hard drive, automatically launching with every system boot.
Hacker Defender is one example of a user-mode rootkit. Luckily Mark Russinovich’s well-known application Rootkit Revealer can detect it, as well as most other user-mode rootkits.
7: Kernel-mode rootkits
Since rootkits running in user-mode can be found and removed, rootkit designers changed their thinking and developed kernel-mode rootkits. Kernel-mode means the rootkit is installed at the same level as the operating system and rootkit detection software. This allows the rootkit to manipulate the operating system to a point where the operating system can no longer be trusted.
Instability is the one downfall of a kernel-mode rootkit, typically leading to unexplained crashes or blue screens. At that point, it might be a good idea to try GMER. It’s one of a few trusted rootkit removal tools that has a chance against kernel-mode rootkits, like Rustock.
8: Firmware rootkits
Firmware rootkits are the next step up in sophistication, with rootkit developers figuring out how to store rootkit malcode in firmware. The altered firmware could be anything from microprocessor code to PCI expansion card firmware. This means that:
When the computer is shut down, the rootkit writes the current malcode to the specified firmware.
Restart the computer and the rootkit reinstalls itself.
Even if a removal program finds and eliminates the firmware rootkit, the next time the computer starts, the firmware rootkit is right back in business.
9: Malicious mobile code
In relative anonymity, malicious mobile code is fast becoming the most effective way to get malware installed on a computer. Mobile code is software that’s:
Obtained from remote servers.
Transferred across a network.
Downloaded and executed on a local system.
Examples of mobile code include JavaScript, VBScript, ActiveX controls, and Flash animations. The primary idea behind mobile code is active content, which is easy to recognize. It’s the dynamic page content that makes Web browsing an interactive experience.
What makes mobile code malicious? Installing it without the owner’s permission or misleading the user as to what the software does. To make matters worse, it’s usually the first step of a combined attack, similar to the penetration tool used by Trojan horse malware. After that, the attacker can install additional malware.
The best way to combat malicious mobile code is to make sure that the operating system and all ancillary software are up to date.
10: Blended threat
Malware is considered a blended threat when it seeks to maximize damage and propagate efficiently by combining several pieces of single-intentioned malcode. Blended threats deserve special mention, as security experts grudgingly admit they’re the best at what they do. A blended threat typically can:
Exploit several known vulnerabilities or even create vulnerabilities.
Incorporate alternate methods for replicating.
Automate code execution, which eliminates user interaction.
Blended threat malware, for example, may send an HTML e-mail message containing an embedded Trojan horse along with a PDF attachment containing a different type of Trojan horse. Some of the more famous blended threats are Nimda, CodeRed, and Bugbear. Removing blended threat malware from a computer may take several pieces of anti-malware, as well as using malware scanners installed on a LiveCD.
Final thoughts
Is it even possible to reduce the harmful effect malware causes? Here are a few final thoughts on that subject:
Malware isn’t going away any time soon. Especially when it became evident that money, lots of money, can be made from its use.
Since all anti-malware applications are reactionary, they are destined to fail.
Developers who create operating system and application software need to show zero tolerance for software vulnerabilities.
Everyone who uses computers needs to take more ownership in learning how to react to the ever-changing malware environment.
It can't be stressed enough: Please be sure to keep operating system and application software up to date.
It’s always nice to read some exciting news from the people who develop our favorite apps, and the team over atMalwarebyteshad a bigannouncement in their forumsyesterday morning. In less than a year and a half, Anti-Malware has removed more than one billion infected items from users’ computers.
That’s an impressive figure, and a strong testimony to the quality of their software. Anti-malware has been an indispensable part of my technician’s toolkit since it was released and it keeps getting better. The app is so popular now that it’s hard to believe I considered it one of my “lesser-known malware apps” back in July of last year.
To use an Internet-connected computer is to be insecure and place your privacy in danger. Spyware, viruses, Trojans and assorted malware are everywhere on the Net, trying to hop onto your PC and cause damage. Snoopers want to get at your personal information for nefarious purposes, such as identity theft.
Operating systems of all kinds are under assault, but the prime target is Windows, because the vast majority of PCs worldwide use that operating system. If you use Windows, hackers have you in their cross hairs.
Luckily, there's plenty of free software for Windows that can help protect your privacy and security. I'm not talking about anemic, underpowered applications. I'm talking about industrial-strength tools that can do everything that expensive security software does.
With all the free stuff out there, which software should you choose? I've selected 10 of my favorite programs that can protect your privacy and security. Download and install them, and you'll be far safer against all the nastiness out there.
Some of the biggest security holes in your PC aren't directly related to Windows — instead, they're in the applications you run. As often as not, that's how hackers and crackers can get into your PC. For example, in the recent "Pwn to Own" hacker challenge, it was application vulnerabilities, notWindows Vistaitself, thatallowed hackers to crack Vista.
The best way to protect yourself from this problem is to keep your applications updated with vendor-issued patches. But you don't want to spend your life cruising the Web, looking for updates for every app you use.
Instead, get this freebie that does it for you. As a security vendor,Secuniakeeps track of software vulnerabilities and available patches. The company'sPersonal Software Inspector(PSI) scans your PC, downloads a current vulnerabilities file, and alerts you to any software on your machine that is missing security patches. It also warns you if any software is out of date and no longer supported by the vendor. Out-of-date software no longer gets security patches, and so may be more vulnerable to hackers.
When you get a list of insecure software, you can get more details about each piece of software, open the folder where the software resides, or download a patch. Click the + sign next to the software, and you'll get even more details about it, often including links to any tools for uninstalling the software. You also have the choice of having Secunia constantly monitor your software use and notify you when patches are available.
Secunia says that some programs require tedious or confusing patching procedures, so by default it starts in a mode that shows you only "easy-to-patch" programs. It's a much better bet to have Personal Software Inspector tell you about all applications that need patches, not just ones that are easy to patch. To make the change, select Settings and uncheck the box next to "Show only 'Easy-to-Patch' programs."
Note that Secunia PSI is free for home use, but requires payment for business use.
Microsoft Office documents often include data that can compromise your privacy or that you don't want others to see, such as hidden text or cells, document revision history, names of document authors and reviewers, and so on. When you send someone a document, they can easily see that information by viewing the version history and the document's properties, and in other ways.
It can be time-consuming and impractical to remember to review every document you send out via e-mail to make sure it doesn't contain privacy-compromising information. Instead, get Unedged Software'sSendShield.
Whenever you send PowerPoint, Excel or Word documents via Outlook, it examines them to see if they have any of private information. It then details what it finds and lets you remove the information with a single click. It deletes the information only from the copy of the file you send via e-mail, not the original on your hard disk.
You can also have the documents turned into PDFs and sent that way instead of as Office documents.
SendShield is in beta, and for now is free. However, when it gets out of beta, there is a chance that it will become for-pay software. (The company provided no details on timing or pricing.)
Many for-pay antivirus programs, such as Symantec's Norton AntiVirus, are system hogs, taking up far too much RAM and system resources, which slows down your PC unnecessarily. Not only that, but you have to pay an annual fee for using them.
There's a better way: Get theAvast Antivirussoftware from ALWIL Software. It's lightweight and takes up barely any RAM or system resources, it's simple to use, and it'll do everything you need by providing live, resident protection as well as scanning.
The software uses a shield metaphor for its multiple types of protection. There's an antivirus shield, one that protects against Web-based threats, another for e-mail protection and so on. You can customize the sensitivity of each shield.
Avast includes automated updates of virus definitions. The independent testing siteAV-comparatives.orgrates its effectiveness as Advanced+, the top level. I've been using the program for well over a year and a half, and it's caught every threat that's come my way.
Note that Avast is free for home use, but requires payment for business use.
Everybody should be using spyware-detection tools such asLavasoft Ad-AwareorSpybot Search & Destroy— preferably both. But some malware is so nasty that it escapes detection from any spyware scanners — and can't be removed by them, either.
So what can you do if your PC is acting strange and you suspect that you've been victimized by malware? Try downloading and using Trend Micro'sHijackThis, and with the help of experts, you may be able to track down the source of the problem and then fix it.
The program examines your settings and the Windows registry, particularly those sections that are most likely to be vulnerable, and then saves all those settings in a log file. Those settings are the key to finding out if you've been infected. Experts can analyze the log, and from what they find, determine whether there's a spyware infection.
Where do you find the experts? The program lets you upload your log file to the HijackThis Web site, where others will examine it, let you know if there are any likely infections and tell you how to rid yourself of them. There are plenty of other discussion areas on the Internet that will do the same; aGooglesearch will turn up plenty of them.
The software will also delete suspicious items, and it includes other useful tools, such as one that will generate a log of all programs that run on start-up. Keep in mind that if you're not an expert, you shouldn't try to use this program on your own. Think of it as a last resort when standard anti-malware tools fail.
Of course, the best way to protect yourself against spyware is to make sure that it doesn't install in the first place. That's whereSpywareBlasterfrom Javacool Software comes in. It stops the installation of ActiveX-based spyware, browser hijackers and other malware, and can also block spyware cookies.
It includes extras as well, such as disabling Flash running in Internet Explorer. And it also lets you create a system snapshot, so that if at some later point you get infected with spyware, you can always revert to a clean system.
Note that if you don't use Internet Explorer, there's no need to install this software, becauseFirefox, Opera and Safari don't use ActiveX.
Rootkits are the most nefarious of all malware, giving hackers access to your entire PC without your knowledge. They use special techniques to hide themselves from many antivirus and anti-malware programs, which makes detecting and killing them exceedingly difficult. Because of that, just using antivirus software isn't enough. Instead, you need a specialized rootkit detector and killer.
That's exactly whatF-Secure'sBlackLight Rootkit Eliminatordoes. It scans your PC for hidden processes, folders and files, then reports on what it finds. If your PC is clean, it will tell you so. If it finds anything hidden, it tells you that as well and lets you clean it up. Double-click any entry, and you'll get more information about it, such as the file location, a description and company information.
To kill a rootkit you've discovered, you have a choice of renaming or deleting the file using BlackLight's built-in tools. It's a good idea to first rename suspicious files, which gives them a .ren extension and prevents them from executing. Next, do a Google search for the file names to see whether they really are malware. Rootkits often hide legitimate files and processes, such as Explorer.exe, so make sure not to get rid of any legitimate ones. If you confirm that files are malware, then delete them.
Warning:Only very experienced users should attempt to clean their PC with this software, because if you rename or delete valid files, you can cause serious problems. If you're at all unsure about what you're doing, you might want to try a different free anti-rootkit tool calledRootAlyzer, from the same folks who bring you Spybot Search & Destroy. It checks your PC for rootkits but doesn't offer tools for deleting them. (Note that RootAlyzer is still in the preview stage.)
JavaScript, Java, plug-ins and other code found on Web pages can do serious damage to your PC. They can deliver interactivity and other useful features, but they can also be used to wreak a great deal of havoc. To keep yourself safe on unfamiliar Web sites, you'll want to turn them off, but doing so means that you'll lose some of the nifty features on some of your favorite Web sites.
The answer? A great Firefox extension calledNoScript, which not only blocks scripts, plug-ins and various types of code, but also protects againstcross-site scripting attacks. It lets you block scripts, plug-ins, and code on a site-by-site basis. You can control it to an exceptional degree, including whether to block scripts on sites on a one-time basis or permanently.
The firewall that ships with Windows XP or Vista simply isn't good enough to keep you safe — you need better protection. There are plenty of free firewalls out there, but my favorite isComodo Firewall Pro, which provides top-notch protection from both inbound and outbound threats. It offers other types of protection as well, including what it calls Defense+, which keeps you safe in several ways, including locking down certain files and folders so that they can't be altered.
Note that this firewall is more aggressive than many in asking whether you should allow connections. So when you first run it, expect to see a good many pop-ups asking whether you want to let through a particular application.
To help cut down on the pop-ups, run its Clean PC mode, which lets you scan your PC for applications and then register them as safe so that you're not inundated with quite so many pop-ups. In addition, there's an "install mode" that disables certain types of pop-ups for 15 minutes, allowing you to easily install new software.
Another very good free firewall isOnline Armor.Computerworldeditor in chief Scot Finnieprefers its paid versionto any other firewall. The free version is excellent as well, with one shortcoming: To install a new version, you first have to uninstall the old version, then install the new one.
The Web is filled with sites that harbor adware, spyware or worse. It can be almost impossible to know ahead of time whether you've visiting such a site. Making matters worse is that many of these sites also have legitimate information and software for download.
McAfee SiteAdvisoris a great way to make sure you steer away from those sites. When you do a search in Google or Yahoo, it places a small icon to the right of each search result, indicating whether the site is safe, questionable or known to be harmful. A red X indicates danger, a green check indicates the site is safe, and a yellow exclamation mark indicates that it's questionable. If McAfee hasn't assessed a particular site, it displays a question mark.
Move your mouse over the icon, and you'll get a pop-up with details about the dangers, including whether it has dangerous downloads, whether it links to other dangerous sites, and whether it will send spam if you register at the site.
Click More Info from the pop-up, and you'll get much more information, including a list of the dangerous downloads and malware or adware that infects it, what sites the site links to and more. It even tells you the site's "annoyances," such as what third-party cookies it installs.
The SiteAdvisor software works even when you don't do a search. As you browse the Web, a small icon sits at the bottom of the screen and tells you whether the site is dangerous or not. Click it to get more information.
CCleanerdoes double duty: Not only does it help protect your privacy, but it also keeps your system clean and running well. To protect your privacy, it removes traces of your Internet history, such as your temporary Internet files, browsing history, autocomplete form history, and cookies. In addition, it cleans Windows' Recent History list.
It's great at cleaning your system as well. CCleaner gets rid of many different kinds of unneeded files, such as temporary files, Windows log files, chkdsk file fragments and a lot more. It can also check your Registry and clean it of bad or broken entries and help you stop programs from running on start-up.
For anyone who wants to keep their browsing life private — and keep their system clean and running smoothly — this is a must-have download.