5 ms·
It's not that I don't care about being uninfected, I just don't know where to find out about things like DNS Changer and Conficker. I answer all the requests my
by feefie 15y ago
It's not that I don't care about being uninfected, I just don't know where to find out about things like DNS Changer and Conficker. I answer all the requests my system tray makes of me keeping the following up-to-date: Windows Updates, AVG Anti-Virus Free Edition 2012, Adobe Flash, and Java. I use Chrome and Firefox that update themselves. Is something else I should be doing? Is there a web page that has a check list of things I should do regularly, like 1. run windows update, 2. go to http://dns-ok.us/ http://dns-ok.us/, etc. How do I know if I'm infected by Conficker? I assumed Windows or my AVG Anti-Virus would have told me.
- gravitronic 15y agoA few years ago my wife would frequent asian streaming sites to get the latest episodes of some of her shows. Despite having a mostly-patched system and AVG, she got infected with a few viruses/worms. Generally I'd say that you'll know you're infected rather quick. Some evidence: - advertising disconnected from the websites you're visiting. Random pop-up ads for example. - most malware have ability to download and install MORE malware, which AVG will catch some of. So you'll start to randomly get AVG hits for files you did not download because the malware downloaded and attempted to install them. - some malware will succeed in installing and end up trying to scam you out of $40. In her case she was infected with an extremely lethal (and interesting) piece of malware called TDL3: http://www.securelist.com/en/analysis/204792180/TDL4_Top_Bot http://www.securelist.com/en/analysis/204792180/TDL4_Top_Bot It hides really well by creating an encrypted partition at the end of the disk, and its primary goal is to just download and execute other malware which the authors charge a per-install fee to the other authors. It is nearly impossible to get rid of. She would randomly get infected with other more obvious viruses all the time due to this infection vector.
- freehunter 15y agoThere are many ways to get infected with a virus on Windows. Sometimes it's just as simple as viewing a webpage (fairly rare, only when there's an unpatched exploit). More often, it's in malicious PDFs or EXEs. Running an up-to-date anti-virus still isn't going to give you 100% protection. A customer of mine recently was infected by a virus while running an up-to-date McAfee, because the virus was released before the virus definitions were updated to catch it. In the two days before McAfee updated their definitions, my customer got the virus. There's not much reason to check if you're infected unless you suspect you are. With Conficker and DNS Changer, for example, there are symptoms of the virus. DNS Changer would reroute your search results to their own search page. The best thing to do is keep a running AV up to date, do some research on any exe you're about to run (is the distributor reputable?) and watch for sudden signs of slowness, instability, or any modifications to how your system normally behaves. If you notice changes, there are forums where people can tell you how to clean the infection. HijackThis! is a popular analytical tool (but don't change anything using it without posting it on the forums first). http://hjt-data.trendmicro.com/hjt/analyzethis/index.php http://hjt-data.trendmicro.com/hjt/analyzethis/index.php
- trotsky 15y agoSecunia Personal Software Inspector is very helpful. It detects all the software you have installed and runs a scan once a week to determine if any of it is out of date and gives you easy links to the updated versions. You sound like you're doing quite well, though I would add Quicktime (comes wirh iTunes) to the flash and java list, but even if you're doing a great job Secunia PSI can be a nice reminder and/or provides a visible confirmation that you're all patched up. https://secunia.com/vulnerability_scanning/personal/ https://secunia.com/vulnerability_scanning/personal/
- j_s 15y agoYou did not specifically mention your UAC configuration and user type... you should leave UAC enabled, create a second Administrator user with at least a simple password, and downgrade your normal account to a regular user. (This is all for a home version of Windows, the business versions offer more configuration options.) Any unexpected popup requiring the administrative user's password is usually enough to know something bad is about to happen... and if software doesn't require Administrative rights to install it is usually either easy to remove or exploiting Windows in a way that's unavoidable once it's hit the machine.
- nikcub 15y agoStop running Flash and Java, they are the source of most browser vulnerabilities, which are the source of most malware Go to chrome://plugins and kill everything When you need one of the two, run them in a separate (updated) browser in a separate guest account (fast user switching ftw).
- naner 15y agoWhen you need one of the two, run them in a separate (updated) browser in a separate guest account (fast user switching ftw). Yeah, nobody is going to do that. Chrome has an option to have 3rd party plugins blocked by default (click to activate) and Firefox has Flashblock. That's about as much as you can expect users to do.
- nikcub 15y ago> Yeah, nobody is going to do that. I do. Once you force yourself to do it once or twice it is actually pretty quick (2 keystrokes), but you rarely need Flash today anyway. There are far too many web rootkits going around for it to be worth running flash and java (OSX and windows) see: http://krebsonsecurity.com/2010/10/java-a-gift-to-exploit-pack-makers/ http://krebsonsecurity.com/2010/10/java-a-gift-to-exploit-pa... If you spend any amount of time on the web there is a chance that you have visited a page running an exploit pack. Their penetration rates are 10-20%. There is even a chance that you have been exploited right now and don't even know it. Any extension that claims to block in Chrome doesn't actually block, since the extension API doesn't allow that - it is only hiding using CSS or some other Javascript trick that still leaves the plugins vulnerable. Flashblock for Firefox also doesn't prevent exploits of vulnerable browser plugins. All those plugins create a false sense of security
- Dylan16807 15y agoThe plugin click to enable in chrome is built-in. And what do you mean flashblock in Firefox doesn't help? If you don't intentionally activate the plugin it can't hurt you.