<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>hijackthis &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://wordpress.com/tag/hijackthis/</link>
	<description>Feed of posts on WordPress.com tagged "hijackthis"</description>
	<pubDate>Wed, 08 Oct 2008 03:18:18 +0000</pubDate>

	<generator>http://wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[How to Make Your Computer Fast and Clean, for Free]]></title>
<link>http://feedontech.wordpress.com/?p=23</link>
<pubDate>Mon, 29 Sep 2008 08:10:22 +0000</pubDate>
<dc:creator>Ai</dc:creator>
<guid>http://feedontech.it.wordpress.com/2008/09/29/how-to-keep-your-computer-fast-and-clean-for-free/</guid>
<description><![CDATA[Yeah, I know. Everyone at home has been bugging me about the  same old thing: how to make computer t]]></description>
<content:encoded><![CDATA[<p>Yeah, I know. Everyone at home has been bugging me about the  same old thing: how to make computer to run fast just like it did when it was  just bought. As time grows, so does your computer. And as we all know,  everything has an end and that includes your computer. So, it’s time to throw  it off. L</p>
<p>Just kidding! If your computer is slow, chances are that  there are tones of programs that are hogging up your limited resources: unnecessary  programs that were frequently accessed in the past but no longer in use today.  And since this guide is for those who want to make their computer fast for  free, buying up more RAM is not really a solution (but of course, I highly  recommend this to everyone who has the money!).</p>
<p>So, now I’m going to reveal my way of quicken things up.  First thing to say, the solutions produced here are not exhaustive, meaning to  say, there may be other ways or solutions that perform better than mine.  However, I assure you that mine do really work, based on my real experience. J</p>
<p>I’m just going to list out all tricks in my sleeve so brace  yourselves.</p>
<p><strong>All the  tech-tricks in my pocket:</strong></p>
<ol>
<li><strong>Update  your anti-virus frequently</strong>
<ol>
<li>As cliché as it can be, this is the fundamental  move that you should do first. Viruses, Trojans, spywares and other evil beings  can be really a pain in the neck when it comes to detecting and eliminating  them.</li>
<li>By having the latest protection, you will  protect your beloved computer from these culprits who often will hog up your resources  without you knowing.</li>
<li>As for me, I use <strong><a title="Free Edition" href="http://free.avg.com/" target="_blank">AVG Anti-Virus: Free Edition</a>. </strong>So far it works and most importantly  it’s <strong>free</strong>. :P</li>
</ol>
</li>
<li><strong>Install  Firewall to Safeguard Your Computer from Unwanted Programs on the Web</strong>
<ol>
<li>Firewall supplied by Microsoft is enough as long  as you turn it on.</li>
<li>But to be in the safe side, you should try to  install other brands of firewall, since they perform better than Microsoft  (logically, they specialize in building firewall, as opposed to Microsoft who  has multitude of other things to do)</li>
<li>As for me, I have used <strong>Sygate Personal Firewall (SPF)</strong> in the past and now have reverted to  the old <strong>Windows Firewall</strong>. From my  experience SPF is really simple but not as user-friendly to those who are not  much of technical person. I have used it countless of times before and it works  in blocking things that you don’t know about (it will ask you).  There are also other famous brands like <strong>ZoneAlarm Personal, </strong>but I detest them  since it’s too autonomous. Maybe it fits you. Who knows? Give it a try.:P</li>
</ol>
</li>
<li><strong>Spybot  Search &#38; Destroy (SSD)</strong>
<ol>
<li>This is one of the must-have weapons in your  combating inventory. SSD is very famous and its database is always up-to-date  to include all the spywares out there (be it small or big).</li>
<li>So, whenever you feel that something is wrong  with your system, this is your first step: Scan with the <strong>Spybot Search &#38; Destroy</strong> (with latest update of course J). Chances are that you’ll  bump onto a lot of unknown spyware that have been breathing up on your  resources.</li>
<li>Another thing to do in SSD, is the <strong>Immunisation</strong> process. It works just  like how it works on human body. Update regularly and immunize your system  frequently.</li>
<li>As for me, whenever I get a new system, I will  do install this application first before moving on with other things.</li>
</ol>
<p>[caption id="attachment_33" align="aligncenter" width="300" caption="Spybot Search &#38; Destroy"]<a href="http://feedontech.files.wordpress.com/2008/09/spybot.jpg"><img class="size-medium wp-image-33" title="spybot" src="http://feedontech.wordpress.com/files/2008/09/spybot.jpg?w=300" alt="Spybot Search &#38; Destroy" width="300" height="205" /></a>[/caption]</li>
<li><strong>Msconfig  – Makes your computer to boot up fast</strong>
<ol>
<li><strong>Msconfig</strong> is not a software, rather it is a utility provided by Microsoft to those who  want to customize their startup programs (programs which are launched  automatically when you log on into windows)</li>
<li>Here is how to launch <strong>Msconfig</strong>: Go to Start &#62; Run &#62; Type “msconfig” &#62; Click OK</li>
<li>Then, a new window will be launched. Click on  the <em>Startup</em> tab. In there, you will  see a list of programs along with a tick box for each program.</li>
<li>You can browse the list and select programs that  you think are unnecessary to be loaded near the startup time.</li>
<li> In fact  you can uncheck all the boxes if you want. Why? What happen if you uncheck an important  application that must be loaded during the startup? The answer is, that  application will be loaded regardless whether you uncheck it or not. So don’t  worry.:P</li>
</ol>
<p>[caption id="attachment_28" align="aligncenter" width="300" caption="Msconfig windows"]<a href="http://feedontech.files.wordpress.com/2008/09/msconfig.jpg"><img class="size-medium wp-image-28" title="msconfig" src="http://feedontech.wordpress.com/files/2008/09/msconfig.jpg?w=300" alt="Msconfig windows" width="300" height="197" /></a>[/caption]</li>
<li><strong>Install  Procexp – Display and describe all the running processes in your computer</strong>
<ol>
<li><strong>Procexp or Process Explorer</strong> is just amazing. This application helps you to identify all the running  processes in the background. There is a description given for every process  that is currently running.</li>
<li>So whenever you want to do spot-check, fire up  this application and go through the list of running processes. If you suspect a  malicious process is running, google up the name of the process to confirm your  suspicion. If it’s true, time to <em>spybotting</em> (using <strong>Spybot Search and Destroy</strong> (no.3) and kill the process. In fact this is better, since you can save time  from having to scan your computer all the time (in other words, you can only choose  to scan when there is a problem).</li>
</ol>
<p>[caption id="attachment_29" align="aligncenter" width="300" caption="Process Explorer windows"]<a href="http://feedontech.files.wordpress.com/2008/09/procexp.jpg"><img class="size-medium wp-image-29" title="procexp" src="http://feedontech.wordpress.com/files/2008/09/procexp.jpg?w=300" alt="Process Explorer windows" width="300" height="249" /></a>[/caption]</li>
<li><strong>Uninstall  unused programs</strong>
<ol>
<li>This is pretty much self explanatory.</li>
<li>Why? Some of these unused programs will  automatically launch their services/processes when you log on into the  computer. And since you have no need of them, we indeed have no need of their  background processes too!</li>
<li>So, dig up your Program Files folder and try to  find any software that you feel unfamiliar with. Chances are you don’t need  that software anymore!</li>
</ol>
</li>
<li><strong>Clean  your computer with CCleaner</strong>
<ol>
<li>Another great application that I would like to  share is <strong>CCleaner</strong>.</li>
<li>You can do lots with <strong>CCleaner</strong>:
<ol>
<li>Cleaning up temporary internet files
<ol>
<li>When you browse or surf the internet some files  will be downloaded into your computer without you knowing it explicitly.</li>
<li>Most of them are not dangerous and are only used  to aid your surfing experience.</li>
<li>However, as time passes by, the files will grow  in number and soon all of your space will be eaten up.</li>
<li>Hence, it’s advisable for you to at least  cleaning up your temporary file folder monthly or once for two months or so on.</li>
</ol>
<p>[caption id="attachment_31" align="aligncenter" width="300" caption="CCleaner windows - Cleaning up temporary files"]<a href="http://feedontech.files.wordpress.com/2008/09/ccleaner_clean.jpg"><img class="size-medium wp-image-31" title="ccleaner_clean" src="http://feedontech.wordpress.com/files/2008/09/ccleaner_clean.jpg?w=300" alt="CCleaner windows - Cleaning up temporary files" width="300" height="131" /></a>[/caption]</li>
<li>Fixing up any existing issue
<ol>
<li>This feature will fix up any broken links in  your laptop.</li>
<li>For example if you have a broken Shortcut, this  feature will eliminate it, hence leaving your system all clean and sorted out.</li>
</ol>
<p>[caption id="attachment_30" align="aligncenter" width="300" caption="CCleaner windows - Fixing up issues"]<a href="http://feedontech.wordpress.com/files/2008/09/ccleaner_fix.jpg"><img class="size-medium wp-image-30" title="ccleaner_fix" src="http://feedontech.wordpress.com/files/2008/09/ccleaner_fix.jpg?w=300" alt="CCleaner windows - Fixing up issues" width="300" height="131" /></a>[/caption]</li>
</ol>
</li>
</ol>
</li>
<li>[OPTIONAL] <strong>Get Hijackthis – This is an ultimate  double sided weapon</strong>
<ol>
<li>Hijackthis is very powerful that it can backfire  to the user. It’s a program much like to Procexp but has very deep results  shown up to the users.</li>
<li>So deep that if the user accidentally delete an  important application, the whole system can be corrupted.</li>
<li>Usually, I turn to this for the last result. It  is very technical and requires you to know every single process shown without  any description given.</li>
<li>However, don’t worry since there are experts out  there that will help you using Hijackthis. Usually they will ask you to paste  the result into the website for diagnosis. From then on, they will advise you on  which program/process to delete and which to leave untouched.</li>
<li>A simple google on Hijackthis will yield  hundreds of website that offer free diagnose on one’s Hijackthis result.</li>
</ol>
<p>[caption id="attachment_32" align="aligncenter" width="300" caption="Hijackthis windows"]<a href="http://feedontech.files.wordpress.com/2008/09/hijackthis.jpg"><img class="size-medium wp-image-32" title="hijackthis" src="http://feedontech.wordpress.com/files/2008/09/hijackthis.jpg?w=300" alt="Hijackthis windows" width="300" height="265" /></a>[/caption]</li>
</ol>
<p>That is it folks. However, I sincerely believe that prevention  is better than cure. It’s cost-effective, fast, better and saves you a lot of  time. All the above methods do indeed work for me. So far, nothing worse has  happened to my beloved lappy. If you are really worried, I would suggest that  you make a restoration point so that if anything bad happens, you can roll back  to your previous state. I’m not going to be responsible if your computer blows  out or something, but I will try to help you as much as I can! J</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Free HijackThis - A Powerful Anti-Malware Tool]]></title>
<link>http://billmullins.wordpress.com/?p=1363</link>
<pubDate>Wed, 10 Sep 2008 16:26:14 +0000</pubDate>
<dc:creator>billmullins</dc:creator>
<guid>http://billmullins.it.wordpress.com/2008/09/10/free-hijackthis-a-powerful-anti-malware-tool/</guid>
<description><![CDATA[ Given the extreme state of the Internet today, and all of it’s accompanying dangers, computer use]]></description>
<content:encoded><![CDATA[<p><a href="http://billmullins.files.wordpress.com/2008/09/windowslivewriterfreehijackthisapowerfulantimalwaretool-ac97hijack-this-opener3.gif"><img class="alignleft" style="margin:0 30px 0 0;" src="http://billmullins.files.wordpress.com/2008/09/windowslivewriterfreehijackthisapowerfulantimalwaretool-ac97hijack-this-opener-thumb1.gif" alt="" width="128" height="128" /></a> Given the extreme state of the Internet today, and all of it’s accompanying dangers, computer users’ need all the help we can get to keep our machines free of spyware/Trojans/viruses/hijackers ……. Just fill in the blanks.</p>
<p>HijackThis is a free utility by <a href="http://store.trendmicro.com/ca/tis/en/20?gclid=CP7A9ei_0ZUCFSWlQAodNHnHhw" target="_blank">Trend Micro</a> which <a href="http://www.thefreedictionary.com/heuristic" target="_blank">heuristically</a> scans your computer to find settings that may have been changed by homepage hijackers, spyware, other malware, or even unwanted programs.</p>
<p>This application has a well deserved reputation for being aggressive in tracking down unauthorized changes that have been made to your system/applications.</p>
<p><a href="http://billmullins.files.wordpress.com/2008/09/windowslivewriterfreehijackthisapowerfulantimalwaretool-ac97hijackthis3.jpg"><img style="border-width:0;" src="http://billmullins.files.wordpress.com/2008/09/windowslivewriterfreehijackthisapowerfulantimalwaretool-ac97hijackthis-thumb1.jpg" alt="" width="497" height="439" /></a></p>
<p>The program doesn’t target specific programs, but instead it analyses registry and file settings, and then targets the methods used by cyber-crooks. After you scan your computer, HijackThis creates a report, or log file, with the results of the scan.</p>
<p>Because of the heuristic methods used by HijackThis, the results of the scan can be confusing/intimidating, to those who are not advanced users. On the other hand, the strength of this program lies in the large community of users who participate in online forums, where experts (voluntarily and for free), will interpret HijackThis scan results for you, and then provide you with the information you need to clean any infection.</p>
<p><a href="http://billmullins.files.wordpress.com/2008/09/windowslivewriterfreehijackthisapowerfulantimalwaretool-ac97hijackthis3.png"><img style="border-width:0;" src="http://billmullins.files.wordpress.com/2008/09/windowslivewriterfreehijackthisapowerfulantimalwaretool-ac97hijackthis-thumb1.png" alt="" width="501" height="445" /></a></p>
<p>The latest version (2.0.2), adds potent tools to the Configuration window including, a process manager and hosts file editor to help you remove dangerous infections, and an ADS Spy tool which scans <a href="http://www.antispywarecoalition.org/documents/glossary.htm" target="_blank">alternate data streams</a>, that browser hijackers can, and will use, to evade antispyware applications.</p>
<p>Despite the fact that you may only need this small application infrequently, it deserves a place in your anti-malware toolbox.</p>
<p>To get a real feel for how powerful this small application is, checkout the great tutorial on using HijackThis, at <a href="http://www.bleepingcomputer.com/tutorials/tutorial42.html" target="_blank">BleepingComputer.com</a>.</p>
<p><strong>System requirements:</strong> Windows Vista, XP, 2000, Me, 98</p>
<p><strong>Software requirements:</strong> Internet Explorer, FireFox</p>
<p><strong>Download at:</strong> <a href="http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html" target="_blank">Download.com</a></p>
<p>To read a great article on the current state of other free security tools hop on over to <strong>Techwalker</strong>, and checkout my friend Mark's article on<br />
 <a href="http://mark-techwalker.blogspot.com/2008/09/online-security-tools-revisited.html" target="_blank"><strong><span style="font-size:12pt;font-family:&#34;">Online Security Tools Revisited</span></strong></a>.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Some improvements on Smokey's Security Forums]]></title>
<link>http://smokeys.wordpress.com/?p=192</link>
<pubDate>Fri, 29 Aug 2008 23:22:35 +0000</pubDate>
<dc:creator>Smokey</dc:creator>
<guid>http://smokeys.it.wordpress.com/2008/08/30/some-improvements-on-smokeys-security-forums/</guid>
<description><![CDATA[My security board, Smokey&#8217;s Security Forums, is in a continuous process of evolution and impro]]></description>
<content:encoded><![CDATA[<p>My security board, <a href="http://www.smokey-services.eu/forum/index.php">Smokey's Security Forums,</a> is in a continuous process of evolution and improvements, this with the aim to serve the user in the best possible way with support, help and advice concerning all security and malware related issues.</p>
<p>This is the reason I have added several new services to the board:</p>
<p>- a new forum called <strong>"Is this an infection?"</strong>: <a href="http://www.smokey-services.eu/forum/viewforum.php?f=139">http://www.smokey-services.eu/forum/viewforum.php?f=139</a><br />
This forum is part of the <strong>HijackThis Logs / Malware Removal Forums,</strong> here can you post if you think that the problems you are experiencing are due to malware. My HJT Staff help decide what your problems are and, if necessary, will take suitable action to solve your problems.<br />
Of course our <a href="http://www.smokey-services.eu/forum/viewforum.php?f=5">HijackThis Log Analyzing and Malware Removal &#38; Cleaning Forum</a> remain unaltered, like in the past you can post here your HJT logs.</p>
<p>- the up to date <strong>Internet Storm Center Infocon Status:</strong> <a href="http://www.smokey-services.eu/forum/viewtopic.php?f=64&#38;t=19805">http://www.smokey-services.eu/forum/viewtopic.php?f=64&#38;t=19805</a><br />
The <strong>'Infocon'</strong> is a service provided by <strong><a href="http://www.sans.org/">SANS,</a></strong> the largest source for information security training, certification &#38; research in the world. The intent of the 'Infocon' is to reflect changes in malicious traffic and the possibility of disrupted connectivity. In particular important is the concept of "Change". Every host connected to the Internet is subject to some amount of traffic caused by worms and viruses. However, once a worm has been identified and the number of infected machines is no longer increasing, this traffic is not likely to cause any disruptions.<br />
The 'Infocon' is intended to apply to the condition of the Internet infrastructure. SANS do not monitor particular nations or companies.</p>
<p>- up to date Security Alerts, Advisories and access to a Threat Database: <a href="http://www.smokey-services.eu/forum/viewtopic.php?f=64&#38;t=19802">http://www.smokey-services.eu/forum/viewtopic.php?f=64&#38;t=19802</a> All these services are provided by Symantec. These Symantec services are an addition to our existing Alerts and Advisories.</p>
<p>We hope you will appreciate our efforts :)</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[HijackThis 2.0.2]]></title>
<link>http://ucretsizprogramlar.wordpress.com/?p=27</link>
<pubDate>Sun, 17 Aug 2008 06:03:20 +0000</pubDate>
<dc:creator>admin</dc:creator>
<guid>http://ucretsizprogramlar.it.wordpress.com/2008/08/17/hijackthis-202/</guid>
<description><![CDATA[İnternette başınıza gelebilecek kötü şeylerden sizi korur.Program bilgisayarınızda tarama y]]></description>
<content:encoded><![CDATA[<p><a href="http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe"><img class="alignnone" src="http://www.trendsecure.com/portal/en-US/_images/tools/hjt_logo.gif" alt="" width="128" height="128" /></a>İnternette başınıza gelebilecek kötü şeylerden sizi korur.Program bilgisayarınızda tarama yapar ve çıkan sonuçlardan neyi sileceğinize siz karar verirsiniz.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Anti-Malware Toolkit]]></title>
<link>http://techtronic.wordpress.com/2008/08/14/software-anti-malware-toolkit/</link>
<pubDate>Thu, 14 Aug 2008 22:13:45 +0000</pubDate>
<dc:creator>Casey Andrews</dc:creator>
<guid>http://techtronic.it.wordpress.com/2008/08/14/software-anti-malware-toolkit/</guid>
<description><![CDATA[
Get Anti-Malware Toolkit here!
It is a never ending battle to protect yourself from the ever increa]]></description>
<content:encoded><![CDATA[<p align="center"><img src="http://www.blogsmithmedia.com/www.downloadsquad.com/media/2008/08/antimalware.png" alt="" width="440" height="213" /></p>
<p align="center"><a href="http://www.lunarsoft.net/downloads/doc_download/30-anti-malware-toolkit" target="_blank">Get Anti-Malware Toolkit here!</a></p>
<p align="justify">It is a never ending battle to protect yourself from the ever increasing threat of ad-ware, malware, spyware, and viruses. Everyday new variants are unleashed in to the internet making our chances of infection greater than ever. The most protective measures we can take is to arm ourselves with protection software. While some are good for protection purposes, some are well served to help remove problems from our systems.</p>
<p><strong>Anti-Malware Toolkit</strong> is a tool to download protective software. While it does not protect or clean, it does download the tools and utilities to do so. AMT downloads the latest versions of Super Antispyware, Malwarebytes Anti-Malware, HijackThis, Spybot, Autoruns, CCleaner, LSP Fix, and several applications to keep us safer (Firefox, Thunderbird).</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[HijackThis]]></title>
<link>http://xovirus.wordpress.com/?p=141</link>
<pubDate>Wed, 13 Aug 2008 18:39:34 +0000</pubDate>
<dc:creator>antoniozigg</dc:creator>
<guid>http://xovirus.it.wordpress.com/2008/08/13/hijackthis/</guid>
<description><![CDATA[
Atualmente está difícil navegar na Internet sem contrair os famosos Hijacks, controles de ActiveX]]></description>
<content:encoded><![CDATA[<p><a href="http://xovirus.files.wordpress.com/2008/08/0000001.jpg"><img class="alignright size-medium wp-image-142" src="http://xovirus.wordpress.com/files/2008/08/0000001.jpg?w=100" alt="" width="100" height="65" /></a></p>
<p>Atualmente está difícil navegar na Internet sem contrair os famosos Hijacks, controles de ActiveX e componentes que infestam seu navegador de barras, botões, ficam abrindo janelas(na maioria das vezes de produtos ou pornografia) e fazem alterações de dar medo. Muitas vezes você pode adquirir essas pragas instalando programas que aparentemente são inofensivos, mas trazem patrocinadores e malwares.</p>
<p>O <strong>HijackThis </strong>é capaz de achar entradas de registro, detectar e remover estas ameaças que tanto causam dores de cabeça, o programa é atualizado quase sempre, oferecendo defesa as novas pragas.</p>
<p>Download: <a href="http://baixaki.ig.com.br/download/HijackThis.htm">HijackThis</a></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Antivirus xp 2008 (How to remove Antivirus XP 2008)]]></title>
<link>http://bmuthini.wordpress.com/?p=71</link>
<pubDate>Tue, 12 Aug 2008 12:43:39 +0000</pubDate>
<dc:creator>bmuthini</dc:creator>
<guid>http://bmanmedia.com/2008/08/12/antivirus-xp-2008-how-to-remove-antivirus-xp-2008/</guid>
<description><![CDATA[Remember my previous article: your computer is infected! Well after doing more research and having m]]></description>
<content:encoded><![CDATA[<p>Remember my previous article: <a href="http://bmanmedia.com/2008/07/24/your-computer-is-infected/">your computer is infected</a>! Well after doing more research and having my computer screwed up for a couple of days, I figured out what was causing it: a rouge/ trojon going by the name: Antivirus xp 2008: The good news is that I have a cure for it.</p>
<p>How to get rid of Antivirus XP 2008.</p>
<p>QUICK NOTE: It is different than the XP Antivirus 2008 most sites refer to.. please see the pictures:</p>
<p><strong>STEP 1</strong>. (<em><strong>OPTIONAL:</strong></em> FOR TECHIES: ALL OTHERS CAN SKIP THIS STEP:<br />
1. Got to the Start menu and click Run<br />
Type Regedit</p>
<p>Browse to<br />
a. Hkey_Local_MAchine/Software/rhc5m5j0ev0p<br />
b. Hkey_Local_MAchine/Software/lphc35dj0e1an<br />
and remove the above 2 entries.</p>
<p><strong>STEP 2.</strong> (You can <strong>Start here</strong> and get the same results)</p>
<p>1. Stop the program from loading on startup. How you ask?</p>
<p><strong>Click </strong>&#62; Start,</p>
<p>Go on to &#62;Run and click Run</p>
<p>2. Type <strong>msconfig </strong><img class="alignnone size-medium wp-image-76" src="http://bmuthini.wordpress.com/files/2008/08/msconfig.gif?w=300" alt="" width="300" height="160" /></p>
<p>3. select the <strong>Startup</strong> tab</p>
<p>Look for the following programs checked to run on start up:</p>
<p>a. Uncheck: lphc35dj0e1an<br />
b. Uncheck: rhc75dj0e1an</p>
<p>Click apply, and then click ok</p>
<p>4. <strong>Restart</strong> computer</p>
<p>5. <strong>Delete</strong> the main files(Folders) the program uses. Delete the following file:</p>
<p>a. C:\windows\system32\lphc35dj0e1an.exe (where "C:" is the letter for your        harddrive)</p>
<p>Then delete the following folder and all files in it:</p>
<p>b. C:\program files\rhc75dj0e1an</p>
<p>Although this will remove the program from your system you still have a warning message displayed as your wallpaper in Windows--the reason is that the virus removed the ability to change the wallpaper or your desktop settings. We are almost done, hand in there....</p>
<p>To restore ability to change your desktop settings and select a different wallpaper follow the instructions below.</p>
<p><strong>STEP 3.</strong></p>
<p>1. Go to &#62;Start &#62; Run</p>
<p>type: Gpedit.msc</p>
<p>Navigate to User configuration&#62; Administrative Templates&#62; Control Panel&#62; Display</p>
<p>2. Right click on Remove Display in Control Panel<br />
3. Click on Properties and select Disabled</p>
<p>4. Do the same steps to change the following attributes to disabled:</p>
<p>a. Hide Desktop Tab<br />
b. Prevent changing wallpaper<br />
c. Hide Appearance and Themes tab<br />
d. Hide Settings tab<br />
e. Hide Screen Saver tab</p>
<p>You should now be able to use your computer normally and change the wallpaper to something other than the warning message Antivirus XP 2008 set it to.....Hahaha DONE! You did it, you are the mannnn or woman no I got to be politically correct! Mmmmmmmmmmhhhhhhhh...you get the picture.</p>
<p>Once you are done, you can <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">click here</a> to download a scanning tool: Recommended: This tool will scan and clean up your system:<br />
<strong> Tools Needed for this fix:</strong><br />
<a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe"> Malwarebytes' Anti-Malware: Click here </a>to download the tool: Do a full system scan:Delete all the entires that appear on the list<br />
The <a href="http://www.microsoft.com/downloads/details.aspx?familyid=435bfce7-da2b-4a6a-afa4-f7f14e605a0d&#38;displaylang=en">Download windows system defender</a> and as well scan the entire system: Remove all the system entires that appear on the list as well</p>
<p><img class="alignnone size-medium wp-image-77" src="http://bmuthini.wordpress.com/files/2008/08/avxp8.png?w=300" alt="" width="300" height="231" /><a href="http://bmanmedia.com/2008/07/24/your-computer-is-infected/"><img class="alignnone size-medium wp-image-78" src="http://bmuthini.wordpress.com/files/2008/08/background.jpg?w=300" alt="" width="300" height="131" /></a></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Freeware for Secured Computer]]></title>
<link>http://reyadel.wordpress.com/?p=39</link>
<pubDate>Mon, 30 Jun 2008 13:54:46 +0000</pubDate>
<dc:creator>reyadel</dc:creator>
<guid>http://reyadel.it.wordpress.com/2008/06/30/freeware-for-secured-computer/</guid>
<description><![CDATA[There are freewares available to secure a computer, the following are recommended:
ClamWin, issued u]]></description>
<content:encoded><![CDATA[<p>There are freewares available to secure a computer, the following are recommended:</p>
<p><a href="http://sourceforge.net/projects/clamwin/"><img class="alignleft size-full wp-image-40" src="http://reyadel.wordpress.com/files/2008/06/clamwin.png" alt="ClamWin" width="170" height="161" /></a><strong>ClamWin</strong>, issued under a GNU General Public License, is a graphical front-end to the ClamAV anti-virus software that runs on Microsoft Windows. Features include: Scheduler - set up scans to run at a defined time. Automatic virus database updates via the Internet, Automatic notifications of new ClamWin releases, Standalone virus scanner, Scanning of programs that are loaded in memory, Context menu integration to Microsoft Windows Explorer - right click on a file to scan it, Microsoft Outlook add-in to scan incoming and outgoing e-mails. ClamWin Antivirus does not include an on-access real-time scanner, that is, it is necessary to manually scan files in order to detect a virus. The Microsoft Outlook add-in, however, will delete a virus-infected attachment automatically, without any intervention from the user.<sup>[<a href="#14">14</a>]</sup> Without the on-access real-time scanner, it gives a user option to deploy one other proprietary [commercial] antivirus software: McAfee, Grisoft AVG, Norton, Symantec, etc. The newest release is ClamWin <del datetime="00">0.91.2</del> 0.93.1, a <del datetime="00">6.32MB</del> 21.432 installer without the <del datetime="00">10.5MB</del> 14.845MB main and 1.260MB daily virus databases protecting against <del datetime="00">287,326</del> 332028 viruses.</p>
<p><a href="http://www.spybot.com/en/download/index.html"><img class="alignright size-full wp-image-41" src="http://reyadel.wordpress.com/files/2008/06/sb.png" alt="Spybot - Search and Destroy" width="354" height="77" /></a><br />
<strong>Spybot - Search &#38; Destroy</strong><sup>[<a href="#15">15</a>]</sup> by Safer Networking Ltd. detects and removes spyware of different kinds from your computer. If there are new toolbars in the user’s Internet browser that one did not intentionally install, if the browser crashes, or the browser start page has changed without one’s knowledge, it most probably hosts some spyware. Spybot – S&#38;D comes under the Dedication Public License, and runs on Microsoft Windows 95, 98, ME, NT, 2000 or XP (32 and 64 bit), 2003, Vista. Spybot-S&#38;D can also clean usage tracks. Spybot – S&#38;D offers multiple tools for computer system monitoring, such as Resident Tea Timer, which perpetually monitors the processes called/initiated and immediately detects known malicious processes wanting to start and terminates them; tools to list installed ActiveX, BHOs, Browser Pages, Hosts file, current running processes, programs at Windows startup, registered uninstallers, and network drivers (Winsock LSP). It allows fixing some registry inconsistencies through a bundled system internals tool which searches missing help files and shared DLLs; non-existent application paths; wrong uninstall information and broken desktop links. The current version <del datetime="00">15.1.15</del> 15.2, a <del datetime="00">7.12MB</del> 9.495MB installer plus a <del datetime="00">1.83MB</del> 2.585MB included files, offers protection against 70,036 malware from Trojans to PUPs. The freeware SpyBot – S&#38;D tackles what other stand-alone proprietary registry checkers, such as CCleaner, RegMechanic, PC Tools, etc. cannot do.</p>
<p><a href="http://www.javacoolsoftware.com/spywareblaster.html"><img class="alignright size-full wp-image-42" src="http://reyadel.wordpress.com/files/2008/06/swb.png" alt="SpywareBlaster" width="318" height="58" /></a><br />
<strong>SpywareBlaster</strong><sup>[<a href="#16">16</a>]</sup>, published by Javacool Software in 2002, pioneered the effective use of prevention techniques to reduce or greatly eliminate spyware-related problems, as well as problems related to other potentially unwanted software such as dialers, browser hijackers, and adware. The current release of SpywareBlaster, version <del datetime="00">3.5.1.0</del> 4.1 is a <del datetime="00">2.44MB</del> 2.803MB installer, which also provides unique utilities like the exclusive "System Snapshot", and various useful tools such as Restricted Sites Protection, Internet Explorer and Mozilla/Firefox Protection. Current SpywareBlaster offer protection against 8543 installed ActiveX dialers, cookies, adbots, hijackers, and potential unwanted sites, e.g., CoolWebSearch or XXXToolBar.</p>
<p><a href="http://www.pcworld.com/downloads/file_download/fid,71309/download.html"><img class="alignright size-medium wp-image-43" src="http://reyadel.wordpress.com/files/2008/06/aa.png?w=300" alt="Ad-Aware" width="300" height="54" /></a><br />
<strong>Ad-Aware</strong>, issued by <a href="http://www.lavasoft.com/">Lavasoft AB</a> and designed for Windows 98, 98SE, Win ME, Win NT 4, Win 2000, and Win XP Home/Professional running at least P166hz, can comprehensively scan memory, registry, hard, removable and optical drives for known data-mining, aggressive advertising, parasites, scumware, selected keyloggers, selected traditional Trojans, dialers, malware, browser hijackers, and tracking components. The SE v. 1.06r1 installer is a 6.41MB file plus the current 1.58MB definitions files, detecting 153,120 signatures.</p>
<p><strong>HijackThis</strong>, issued by Soeperman Enterprises Ltd., now presently bundled as <a href="http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html">TrendMicro’s</a> beta version <del datetime="00">2.0.0.0</del> 2.02, a <del datetime="00">1.24MB</del> 793KB utility, is the first general browser hijacker detector and remover. It scans the PC and generates a log file of the registry and file settings commonly manipulated by malware and legitimate software.</p>
<hr />
<blockquote><p><strong>Notes:</strong><br />
<sup>[<a name="14" href="http://sourceforge.net/projects/clamwin/">14</a>]</sup> Phillips, Russel, (2007), Clamwin Manual &#38; Help © 2004 – 2007.</p>
<p><sup>[<a name="15" href="http://www.spybot.com/en/download/index.html">15</a>]</sup> Safer Networking Ltd. (2007), Spybot – Search &#38; Destroy Help file.</p>
<p><sup>[<a name="16" href="http://www.javacoolsoftware.com/spywareblaster.html">16</a>]</sup> Javacool Software LLC (2005), SpywareBlaster Help file.</p></blockquote>
<h6>This blog is based on another paper: <a href="http://reyadel.files.wordpress.com/2008/06/network_security.pdf">A Secured Network Using Freeware: A Proposal</a>. Although the latter is applied to a corporate network, the ideas could also be applied to home computers or stand-alone computers.</h6>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Varun at MUO: Get Geeky with your computer with HijackThis]]></title>
<link>http://varunkashyap.wordpress.com/?p=143</link>
<pubDate>Thu, 26 Jun 2008 17:13:13 +0000</pubDate>
<dc:creator>Varun Kashyap</dc:creator>
<guid>http://varunkashyap.it.wordpress.com/2008/06/26/varun-at-muo-get-geeky-with-your-computer-with-hijack-this/</guid>
<description><![CDATA[Head over to MakeUseOf for my latest article on HijackThis. HijackThis is an awesome tool for those ]]></description>
<content:encoded><![CDATA[<div align="justify"><img src="http://varunkashyap.wordpress.com/files/2008/06/muo.png" alt="" width="300" height="66" class="alignleft size-full wp-image-134" />Head over to <a href="http://www.makeuseof.com/tag/get-geeky-with-hijackthis/">MakeUseOf</a> for my latest article on HijackThis. <a href="http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis">HijackThis</a> is an awesome tool for those situations when you have a misbehaving computer you need to get help on forums or your antivirus doesn't do the trick for you. It can give you a log or dump or critical areas of your computer and help you get the computer under you control once again.</p>
<p>For more read the article <a href="http://www.makeuseof.com/tag/get-geeky-with-hijackthis/">here</a></div>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Hijack it Back! - Get HijackThis! - Free]]></title>
<link>http://billmullins.wordpress.com/?p=538</link>
<pubDate>Wed, 25 Jun 2008 17:06:39 +0000</pubDate>
<dc:creator>billmullins</dc:creator>
<guid>http://billmullins.it.wordpress.com/2008/06/25/hijack-it-back-get-hijackthis-free/</guid>
<description><![CDATA[ Your home page has been hijacked and despite the fact you’ve run every anti-malware program in yo]]></description>
<content:encoded><![CDATA[<p><a href="http://billmullins.files.wordpress.com/2008/06/windowslivewriterhijackitbackwithhijackthisfree-b676hijackthis2.jpg"><img style="border-width:0;margin:0 20px 0 0;" src="http://billmullins.files.wordpress.com/2008/06/windowslivewriterhijackitbackwithhijackthisfree-b676hijackthis-thumb.jpg" alt="" width="240" height="212" align="left" /></a> Your home page has been hijacked and despite the fact you’ve run every anti-malware program in your arsenal, you can’t get it back. Don't give up; there’s hope yet!</p>
<p>HijackThis is a free utility by <a href="http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis" target="_blank">Trend Micro</a> which heuristically scans your computer to find settings that may have been changed by homepage hijackers, spyware, and other malware or unwanted programs.</p>
<p>This application has a well deserved reputation for being aggressive in tracking down unauthorized changes that have been made to your system/applications.</p>
<p>The program doesn’t target specific programs, but instead it analyses registry and file settings and targets the methods used by hijackers to redirect your browser. After the scan HijackThis creates a report, or log file, with the results of the scan.</p>
<p>Because of the heuristic methods used by HijackThis, the results of the scan can be confusing to those who are not advanced users. However, the strength of this program lies in the large community of users who participate in online forums, where experts will interpret HijackThis scan results for you, and provide you with the information you need to clean any infection.</p>
<p>There is a great tutorial on using HijackThis at <a href="http://www.bleepingcomputer.com/tutorials/tutorial42.html" target="_blank">BleepingComputer</a></p>
<p>The latest version (2.0.2), adds powerful tools to the Configuration window including, a process manager and hosts file editor to help you excise virulent infections, and the ADS Spy tool which scans alternate data streams, that browser hijackers can use to evade spyware removers.</p>
<p>Despite the fact that you may only need this small application infrequently, it deserves a place in your anti-malware toolbox.</p>
<p><strong>System requirements:</strong> Windows Vista, XP, 2000, Me, 98</p>
<p><strong>Software requirements:</strong> Internet Explorer, FireFox</p>
<p><strong>Download at:</strong> <a href="http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html" target="_blank">Download.com</a></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Essential Free Downloads For A New PC (Or An Existing PC)]]></title>
<link>http://nyctech.wordpress.com/?p=38</link>
<pubDate>Wed, 11 Jun 2008 13:47:36 +0000</pubDate>
<dc:creator>ninjatechnyc</dc:creator>
<guid>http://nyctechtips.com/2008/06/11/essential-freeware-for-a-new-pc-or-an-existing-pc/</guid>
<description><![CDATA[If you just bought a new desktop or laptop, no doubt it came with 30-Day trials of typical well know]]></description>
<content:encoded><![CDATA[<p style="text-align:justify;">If you just bought a new desktop or laptop, no doubt it came with 30-Day trials of typical well known AntiVirus, AntiSpyware applications along with a host of other applications whose licenses expires within 30 to 60 days. The good news is, you can let them expire. The reason being, there are plenty of just as good, if not better, freeware applications out there, that can take their place. In this post, I'll outline a list of freeware applications that I think are essential and should be installed on any desktop or laptop running Windows XP and Vista. Full disclosure, I don't get paid to recommend these applications. I just use them myself and have found them to be very reliable, without any spyware, adware, or virus attached to them. Now without further ado:</p>
<h2 style="text-align:justify;">Twelve Essential Freeware Applications:</h2>
<ol style="text-align:justify;">
<li><strong>AntiVirus Software<span style="text-decoration:underline;">:</span></strong> <a href="http://free.grisoft.com/ww.download?prd=afe" target="_blank">AVG </a>or <a href="http://www.avast.com/eng/download-avast-home.html" target="_self">avast!</a> - With it's realtime protection, automatic updates, avast! is an excellent alternative to commercial antivirus products. A highly configurable application, avast! guards against viruses by scanning downloaded files or email attachments. Similarly, another quality antivirus application is AVG. The latest incarnation of AVG (8.0) is slightly more bloated than the previous version (7.5), which will be dearly missed, however, it's still a good antivirus program. It too has realtime protection and automatic updates, and just like avast!, you basically install it and let it do it's thing. And unlike avast!, you can do scheduled scans - which I think is an important feature. For example, I have AVG scan my entire system starting at 1 AM every Saturday morning. Both AVG and avast! have fully featured editions which cost money, but the free home/personal editions are perfect for the average home user.</li>
<li><strong>AntiSpyware Software</strong>: <a title="Anti - AdWare" href="http://www.lavasoftusa.com/products/ad_aware_free.php" target="_blank">Lavasoft's AdAware 2008 Free</a> and <a href="http://www.superantispyware.com/" target="_blank">SuperAntiSpyware</a> - AdAware can scan and eliminate tracking programs, cookies, keyloggers, spyware, hijackers, and trojans. A good program, it unfortunately does not provide realtime protection. SuperAntiSpyware, despite having a name that sounds like a bogus AntiSpyware program, it actually works.  My first experience with the software was when I used it to remove a varient of the Vundo trojan off a friend's computer.  The only drawback is that updates are manual and there is no realtime protection. Install both and run them manually biweekly.</li>
<li><strong>Browser Hijacks</strong>: <a href="http://www.hijackthis.de/en" target="_blank">HijackThis</a> along with the <a href="http://www.hijackthis.de/en" target="_blank">Log Analyzer</a> - An application that actually falls under the AntiSpyware category, HijackThis scans your machine for settings that may have been changed by spyware programs. For example, if you have alot of popups or if your google/yahoo searches lead you to shopping websites, your browser may have been hijacked. HijackThis will scan your machine and create a log file. You take the log file to the Log Analyzer page to get an interpretation of the results, giving you an idea of what's good and what's bad. Just like AdAware, you usually don't need this program unless you unwittingly installed some "search assistant" or "shopping assistant" program or some third party wallpaper/screensaver that came with some "extra goodies", that you really weren't aware of.</li>
<li><strong>Firewall:</strong> <a href="http://www.personalfirewall.comodo.com/download_firewall.html" target="_blank">Comodo Firewall Pro 2.4</a> and <a href="http://www.zonealarm.com/store/content/catalog/products/sku_list_za.jsp" target="_blank">Zone Alarm</a>- If you have a router at home (if you don't you should!!), that will protect you from incoming attacks. The router typically has firewall functionality built in, that will make your internal PC invisible to the outside world. A software firewall, on the other hand, installed on your PC, will protect you against malicious outgoing traffic. It will allow you to control which software programs on your computer has access to the internet. By using a software firewall, you can see which programs are trying to get out to the internet, either to access info (such as program updates, antivirus updates) or send info (such as your personal searching habits). Zone Alarm works well in giving you this type of protection, displaying alerts when applications try to connect out. It is good for the novice user who wants a general software firewall without the need to fine tune. Comodo allows a user to fine tune the firewall, with the ability to specify TCP ports, traffic direction (incoming, outgoing, or both). In other words, it's for the user who wants to get down to the nitty gritty. The new 3.0 version seems a little bloated. It crashed my machine several times, causing BSODs. So I would stick to the 2.4 version, which is still available, unless you're adventurous. They are constantly updating the software, so the latest version may be ok, but try at your own risk. If you choose to use Zone Alarm or Comodo, you should disable the Windows Firewall so that they don't create any conflicts. On a side note, <a href="http://www.symantec.com/press/2005/n051010c.html" target="_blank">Sygate Personal Firewall</a> was fantastic until Symantec bought them out and canned it (R.I.P.).</li>
<li><strong>Privacy</strong>: <a title="CCleaner" href="http://www.ccleaner.com/" target="_blank">CCleaner</a> - If you surf the Internet, whether using Internet Explorer or Firefox, of any other browser, you're bound to have a load of cookies and temporary files. CCleaner will help clean up those unnecessary files in addition to, Windows Temporary Files, URL History, Recycle Bin, Clipboard, Windows Log Files, Recent Documents from the Start Menu, among other temporary files. A good, easy to use cleaner. You can set it to run automatically after the computer boots up, and set it for secure deletion (from 1 to 35 passes). I usually run it after I'm done browsing or going to websites where I need to enter a username and password. The "C" in CCleaner supposedly stands for Crap. <span style="color:#ff0000;">NOTE: When you install CCleaner, make sure you uncheck the "<span style="text-decoration:underline;">Add CCleaner Yahoo! Toolbar and use CCleaner from your browser</span>" option.</span> It otherwise installs the Yahoo toolbar which is not something I recommend.</li>
<li><strong>Popup Blockers</strong>: <a href="http://toolbar.google.com/T4/index_pack_xp.html" target="_blank">Google Toolbar</a>: Windows Internet Explorer has it's own popup blocker which works ok, but the Google toolbar provides an extra layer of protection against popups. Plus you get the Google search bar. A nice toolbar that doesn't seem to weigh down the browser providing extra buttons for gMail and gCalendar (both recommended but non-essential), it also simplifies your search. Just make sure to go into the Settings--&#62; Feature tab and uncheck any unnecessary add-ons (usually all of them).</li>
<li><strong>Archiving</strong>: <a href="http://www.7-zip.org/" target="_blank">7Zip</a> - A fast archiving program which packs/unpacks files and directories in 7z format as well as the ZIP, GZIP, BZIP2 and TAR formats. It unpacks only in the RAR, CAB, ISO, ARJ, LZH, CHM, MSI, WIM, Z, CPIO, RPM, DEB and NSIS formats. It integrates well with the Windows shell, and works better than the Windows unpacking utility since you don't have to deal with the Windows Extraction Wizard which makes something that should take one step, into four steps.</li>
<li><strong>CD/DVD Burner</strong>: <a href="http://canneverbe.com/" target="_blank">CDBurnerXP</a> - A CD/DVD Burner program which allows you to burn a data or audio disc, burn an ISO image, copy or erase a disc. Replace your trial version of Nero or Roxio with this free program.</li>
<li><strong>Encryption</strong>: <a href="http://www.truecrypt.org/" target="_blank">TrueCrypt </a>- When you need to encrypt your USB flash drive or create an encrypted "container" or partition on your hard drive, TrueCrypt is the way to go. TrueCrypt provides for "on-the-fly", transparent encryption allowing you to securely store your files without much hassle. Essential when you store personal information on your computer, such as your tax files, password lists, etc.</li>
<li><strong>PDF Reader</strong>: <a href="http://www.foxitsoftware.com/pdf/reader_2/down_reader.htm" target="_blank">Foxit Reader </a>- A small, fast alternative to Adobe Acrobat Reader (2.55M versus 20M) with no annoying splash window. Required for when you need to download/read user manuals or other documents which only come in PDF format.</li>
<li><strong>PDF Writer</strong>: <a href="http://www.download.com/PrimoPDF/3000-10743_4-10264577.html?tag=lst-0-1" target="_blank">PrimoPDF </a>- Great for when you need to print something (like an online shopping receipt) but don't have a printer handy, print to a PDF printer. Basically, acts like a printer, but simply "prints" to a pdf file, which you can save and print later, or save and open using your favorite PDF reader.</li>
<li><strong>Image Resizer</strong>: <a href="http://www.microsoft.com/windowsxp/using/digitalphotography/learnmore/tips/eschelman2.mspx" target="_blank">Microsoft Image Resizer PowerToy</a> - Nice simple tool to resize pictures that you've taken with your digital camera. You simply right-click on the photo (or selection of photos), and select "Resize Pictures" from the menu. Easier than starting another program (such as Photoshop or Elements) to resize pictures.</li>
</ol>
<p>That's it!. Of course, if you're not the type to install "free" wallpapers, screensavers, toolbars, shopping assistant applications, then you probably don't need any of the above :)</p>
<p>Hope this list helps.  Comments are certainly welcome!</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Interesting Information Security Bits for June 9th, 2008]]></title>
<link>http://infosecramblings.wordpress.com/2008/06/09/interesting-information-security-bits-for-june-9th-2008/</link>
<pubDate>Mon, 09 Jun 2008 18:03:50 +0000</pubDate>
<dc:creator>Kevin Riggins</dc:creator>
<guid>http://infosecramblings.it.wordpress.com/2008/06/09/interesting-information-security-bits-for-june-9th-2008/</guid>
<description><![CDATA[Good afternoon everyone or at least those who share my timezone.  We have a good bunch of interestin]]></description>
<content:encoded><![CDATA[<p>Good afternoon everyone or at least those who share my timezone.  We have a good bunch of interesting things to look at that were posted over the weekend.  So here we go!</p>
<p><a href="http://securityincite.com" target="_blank">Mike Rothman</a> posted some thoughts on the <a href="http://securityincite.com/blog/mike-rothman/thoughts-on-mss" target="_blank">rapidly evolving Manage Security Services space</a>.  He likens it to the process banking went through.  It's an interesting read.</p>
<p><a href="http://securityuncorked.squarespace.com" target="_blank">Jennifer Jabbusch</a> shares a really good analogy with us regarding <a href="http://securityuncorked.squarespace.com/security-uncorked/2008/6/6/logging-correlation-and-it-search-an-analogy.html" target="_blank">Logging, Correlation and IT Search</a>.  Very helpful for those times when you are trying to get across an inherently technical topic to a group of non-technical people.</p>
<p>Via Xavier at <a href="http://blog.rootshell.be/2008/06/07/shit-happens-3/" target="_blank">/dev/random</a> a free and nifty looking tool.</p>
<blockquote><p><a href="http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis" target="_blank"><strong>HijackThis™</strong></a> is a free utility which quickly scans your Windows computer to find settings that may have been changed by spyware, malware or other unwanted programs. HijackThis creates a report, or log file, with the results of the scan.</p></blockquote>
<p><a href="http://security4all.blogspot.com" target="_blank">Security4all</a> points us towards a video that gives us a <a href="http://security4all.blogspot.com/2008/06/video-introduction-into-xss-using.html" target="_blank">introduction to XSS using Webgoat</a>.  The video is hosted at <a href="http://securitydistro.com/video-tutorials/54/Introduction-to-XSS-using-WebGoat.php" target="_blank">securitydistro.com</a>.</p>
<p>By way of <a href="http://www.johnmwillis.com/other/20-great-windows-open-source-projects/" target="_blank">John M Willis</a>, a pointer to an article on Network World, <a href="http://www.networkworld.com/community/20-open-source-windows-tools?page=0%2C0" target="_blank">20 great Windows open source projects you should get to know</a>.</p>
<p><a href="http://taosecurity.blogspot.com/" target="_blank">Richard Bejtlich</a> <a href="http://taosecurity.blogspot.com/2008/06/best-single-day-class-ever.html" target="_blank">shares</a> his experience attending a <a href="http://www.tufte.com/" target="_blank">Edward Tufte</a> class on <a href="http://www.edwardtufte.com/tufte/courses" target="_blank">Presenting Data and Information</a>.  I have not read Edward's stuff, but it is on my list to check out.</p>
<p><a href="http://www.bloginfosec.com/author/jlowder/" target="_blank">Jeff Lowder</a> has an article up on <a href="http://www.bloginfosec.com" target="_blank">BlogInfoSec.com</a> about <a href="http://www.bloginfosec.com/2008/06/09/agility-and-risk-compensation-exploring-the-connection/" target="_blank">Agility and Risk Compensation</a>.  He has some interesting points about perceived risk and the actions that people take in light of their understanding of risk as it pertains to agility in business.  He also points to a good article on wikipedia about <a href="http://en.wikipedia.org/wiki/Risk_compensation" target="_blank">Risk Compensation Theory</a>.  Both are worth a gander.</p>
<p>Well that's it for now.</p>
<p>Have a good day.</p>
<p>Kevin</p>
<p>Technorati Tags: <a class="performancingtags" rel="tag" href="http://technorati.com/tag/mss">mss</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/logging">logging</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/correlation">correlation</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/search">search</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/hijackthis">hijackthis</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/xss">xss</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/webgoat">webgoat</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/open%20source">open source</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/powerpoint">powerpoint</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/presentation">presentation</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/risk%20compensation">risk compensation</a></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Bewerk het register met HijackThis.]]></title>
<link>http://handigzeg.wordpress.com/?p=224</link>
<pubDate>Thu, 01 May 2008 20:37:10 +0000</pubDate>
<dc:creator>Alexander Thijssen</dc:creator>
<guid>http://handigzeg.it.wordpress.com/2008/05/01/bewerk-het-register-met-hijackthis/</guid>
<description><![CDATA[HijackThis is een stukje gereedschap dat een lijst laat zien van bepaalde configuraties die op je pc]]></description>
<content:encoded><![CDATA[<p>HijackThis is een stukje gereedschap dat een lijst laat zien van bepaalde configuraties die op je pc gevonden zijn. HijackThis scant je register en andere bestanden op ingangen die door Spyware of Hijackers achtergelaten kunnen worden. Het interpreteren van deze resultaten kan moeilijk zijn omdat er veel legitieme programma’s zijn die geïnstalleerd worden op dezelfde manier als de Hijackers. Daarom moet je extreem voorzichtig zijn als HijackThis gebruikt wordt om de problemen te herstellen.</p>
<p><a href="http://download.bleepingcomputer.com/hijackthis/HiJackThis.exe">Download HijackThis 2.02</a> [392 kb] [1 mei 2008]</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Virus.Suriv.Visur.Sivur.Rusiv. Tingkat Tinggi (2)]]></title>
<link>http://esetiawan.wordpress.com/?p=65</link>
<pubDate>Mon, 17 Mar 2008 05:01:26 +0000</pubDate>
<dc:creator>esetiawan</dc:creator>
<guid>http://esetiawan.it.wordpress.com/2008/03/17/virussurivvisursivurrusiv-tingkat-tinggi-2/</guid>
<description><![CDATA[Howdy&#8230;.Sekarang kita coba melumpuhkan virus yang sudah terlanjur menginfeksi komputer.
Pada ba]]></description>
<content:encoded><![CDATA[<p>Howdy....Sekarang kita coba melumpuhkan virus yang sudah terlanjur menginfeksi komputer.</p>
<p>Pada bagian satu sudah kita bahas mengenai penggunaan <a title="Bikinan Mark Russinovich" href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx" target="_blank">ProceXP</a>, sebuah utiliti kecil pengganti Task Manager bawaan Windows. Dibandingkan dengan Task Manager Windows, ProceXP memiliki fitur-fitur tambahan yang memungkinkan kita untuk melihat lebih dalam service-service atau file yang sedang berjalan di sistem komputer kita.</p>
<p>Nah, kali ini pertanyaannya adalah bagaimana jika registri windows sudah di-blok oleh virus sehingga kita tidak dapat mengakses registri lagi, dan dengan demikian file atau service bawaan virus tidak dapat dihentikan ?</p>
<p>Tentu saja tugas pertama kita adalah membuka proteksi registri dulu, sehingga kita dapat dengan mudah meng-aksesnya.</p>
<p>Copy teks dibawah ini lalu buka di notepad dan simpan dengan nama bebas dengan ekstension .inf (misalkan unhook.inf), maka file  teks tadi akan berubah menjadi file inf (Installation File) :</p>
<pre style="border:1px inset;overflow:auto;width:95%;height:258px;text-align:left;margin:0;padding:4px;">[Version]
Signature="$Chicago$"
Provider=Symantec

[DefaultInstall]
AddReg=UnhookRegKey

[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""
HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableRegistryTools,0x00000020,0</pre>
<p>Seperti biasa masuk Windows dalam modus <em>Safe Mode</em> dulu.</p>
<p>Setelah itu klik kanan file tersebut lalu klik Install.  Action ini akan menyebabkan entri registri yang sudah dibuat di file .inf diatas akan dimasukkan ke registri sistem. Tidak ada window apapun yang muncul pada proses instalasi unhook.inf ini. Restart komputer dan masuk kembali dalam <em>safe mode</em></p>
<p>Kembali ke ProceXP dan lanjutkan mencari service atau file yang dicurigai sebagai virus.</p>
<p><strong>HIJACKTHIS</strong></p>
<p>Ada satu lagi utiliti yang bernama <a title="Merijn" href="http://www.merijn.org/files/HiJackThis_v2.exe" target="_blank">HijackThis</a> . Utiliti ini mirip seperti MSCONFIG di Windows, yaitu bertugas menampilkan entri-entri startup secara lebih mendalam. Bahkan entri tersembunyi pada startup dapat ditampilkan juga.</p>
<p><a title="Tampilan Utama HijackThis" href="http://esetiawan.wordpress.com/files/2008/03/hijackthis.jpg"><img src="http://esetiawan.wordpress.com/files/2008/03/hijackthis.jpg" alt="Tampilan Utama HijackThis" /></a></p>
<p>Klik tombol Do a System Scan Only untuk memulai penelusuran entri startup. Setelah itu akan muncul hasil penelusuran seperti contoh dibawah :</p>
<p><a title="Komputer Saya setelah Scan" href="http://esetiawan.wordpress.com/files/2008/03/hijackthis-scan.jpg"><img src="http://esetiawan.wordpress.com/files/2008/03/hijackthis-scan.jpg" alt="Komputer Saya setelah Scan" /></a><br />
Proses selanjutnya adalah ceklist entri yang anda curigai sebagai entri virus. Proses ini harus dilakukan dengan sangat hati-hati, karena salah-salah anda malah menghapus entri yang "tidak bersalah".</p>
<p>Setelah itu anda tinggal klik Fix Checked untuk menghapus entri yang nakal tersebut.</p>
<p><strong>KESIMPULAN</strong></p>
<p>Jadi kesimpulannya adalah untuk melumpuhkan virus anda perlu mengikuti urutan seperti dibawah :</p>
<p>1. Boot dalam <em>safe mode</em></p>
<p>2. Matikan entri startup yang anda curigai menggunakan MSCONFIG atau Hijackthis</p>
<p>3. Restart dan masuk kembali dalam <em>safe mode</em></p>
<p>4. Matikan entri virus yang masih ada di sistem menggunakan ProceXP</p>
<p>5. Full Scan sistem anda dengan anti virus. Saya menyarankan menggunakan <a title="Lokal tapi bandel" href="http://www.ansav.com" target="_blank">Ansav</a> karena sifatnya yang <em>portable</em>.</p>
<p>6. Perbaiki registri (jika perlu) dengan utiliti perbaikan registri. Coba cari di <a title="Gratisan ada disini !" href="http://www.snapfiles.com/freeware/" target="_blank">SnapFiles/Freeware</a></p>
<p>Ditunggu komentar anda.....</p>
]]></content:encoded>
</item>

</channel>
</rss>
