<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>Technovice.net - Security</title>
    <link>http://www.technovice.net/</link>
    <description>A Simple Blog For Totally Tech Beginners</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.1 - http://www.s9y.org/</generator>
    <pubDate>Mon, 29 Jan 2007 22:39:16 GMT</pubDate>

    <image>
        <url>http://www.technovice.net/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: Technovice.net - Security - A Simple Blog For Totally Tech Beginners</title>
        <link>http://www.technovice.net/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>Free Firewall From PC Tools</title>
    <link>http://www.technovice.net/archives/312-Free-Firewall-From-PC-Tools.html</link>
            <category>Security</category>
    
    <comments>http://www.technovice.net/archives/312-Free-Firewall-From-PC-Tools.html#comments</comments>
    <wfw:comment>http://www.technovice.net/wfwcomment.php?cid=312</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.technovice.net/rss.php?version=2.0&amp;type=comments&amp;cid=312</wfw:commentRss>
    

    <author>nospam@example.com (jumanjisama)</author>
    <content:encoded>
    &lt;!-- s9ymdb:32 --&gt;&lt;img width=&quot;77&quot; height=&quot;120&quot; style=&quot;float: left; border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://www.technovice.net/uploads/boxshot.gif&quot; alt=&quot;&quot;  /&gt;PC Tools is a brand well known for it&#039;s spyware product called Spyware Doctor, which has won may awards from various magazine and websites. And previous to the release of this free firewall software, they have also released a free anti virus,which i have also covered in an &lt;a href=&quot;http://www.technovice.net/archives/186-Recommended-Free-Anti-Viruses.html&quot; &gt;earlier article&lt;/a&gt;. Although their anti-virus software was free but it was quite competent and offers quite a number of features. Gladly, they had also repeat the same thing when they release their free firewall software.

As soon as i got to know about this free firewall, i immediately went to the website, download it, installed the firewall, restarted my PC and start testing the firewall capability. As a starters, you can bet that PC Tools Firewall is far much better than the default Windows firewall, in respect of protecting your PC. 

 So, in this article i am just going to share some of my experience using PC Tools Firewall. First of all,upon installation, you would probably see some warning like: This driver has not passed the Windows Logo Test ; just ignore it and continue with the installation.

Next, just as other firewalls out there, free or commercial, PC Tools Firewall also give out warning dialogs, just like in the image below:

&lt;!-- s9ymdb:31 --&gt;&lt;img width=&quot;231&quot; height=&quot;271&quot; style=&quot;border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://www.technovice.net/uploads/PcToolsFirewall-Warning.jpg&quot; alt=&quot;&quot;  /&gt;

When you first start using PC Tools Firewall, you should expect a lot of this dialogs. But this is good, at least you know that the firewall is working :)

There are a couple of test that has been done by other users and myself to see how good PC Tools Firewall actually is, it was just some basic leak test, but surprisingly, PC Tools Firewall passed them all with flying colors. Though it was just a basic leak test, but be surprise that there are some commercial firewalls that didn&#039;t passed it (you don&#039;t have to ask about the Windows firewall, everybody know that it is there only for show). 

But with great protection, comes a great penalty, well, not much of a penalty, but still it is a pain in the ass. This is only for P2P users or similar (Kazaa,Limewire,Mirc et cetera) - you need to include a few filtering rules (depending on how many P2P application you have) in order for the P2P application to run properly. For example, if you didn&#039;t add additional rules to allow your BitTorrent client to connect to the net, PC Tools Firewall will certainly block it from downloading and uploading any files. Not good! But actually, it is the same in all firewall system (the good ones), you need to add the filtering rules for certain type of application to function.

&lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://www.technovice.net/uploads/PCToolsFirewall-large.jpg&#039;&gt;&lt;!-- s9ymdb:30 --&gt;&lt;img width=&quot;300&quot; height=&quot;199&quot; style=&quot;border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://www.technovice.net/uploads/PCToolsFirewall-small.jpg&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;

As a conclusion, i would say that this free firewall from PC Tools is definitely a recommendation, especially if you are still using Windows Firewall. Not only it is produced by a reliable company but also the firewall itself is functional as expected. If you are already using some other firewall system, then it is totally unnecessary to change, unless you want to give it a try. But again, if you are currently using Windows Firewall, then it is best that you get yourself a solid firewall system, if not this one, maybe some others :)

To download the PC Tools Firewall, please click on this link to go to the download page: &lt;a href=&quot;http://www.pctools.com/firewall/&quot; target=&quot;_blank&quot;&gt;Get PC Tools Firewall&lt;/a&gt; 
    </content:encoded>

    <pubDate>Tue, 30 Jan 2007 06:39:16 +0800</pubDate>
    <guid isPermaLink="false">http://www.technovice.net/archives/312-guid.html</guid>
    
</item>
<item>
    <title>ATM Scams - How They Get Your Password and Card Info</title>
    <link>http://www.technovice.net/archives/201-ATM-Scams-How-They-Get-Your-Password-and-Card-Info.html</link>
            <category>Security</category>
    
    <comments>http://www.technovice.net/archives/201-ATM-Scams-How-They-Get-Your-Password-and-Card-Info.html#comments</comments>
    <wfw:comment>http://www.technovice.net/wfwcomment.php?cid=201</wfw:comment>

    <slash:comments>2</slash:comments>
    <wfw:commentRss>http://www.technovice.net/rss.php?version=2.0&amp;type=comments&amp;cid=201</wfw:commentRss>
    

    <author>nospam@example.com (jumanjisama)</author>
    <content:encoded>
    I found this site which explains (aided by images) how ATM scammers can get hold of your PIN number and ATM card information. I really didn&#039;t know that such things can be done. Honestly, i have to give some credit to these fellas, they are really creative when it comes to achieve their objective. 

If you have never heard about ATM scams techniques before, then i really suggest that you visit this page: &lt;a href=&quot;http://www.snopes.com/fraud/atm/atm.asp#atmcamera&quot; &gt;ATM Scams&lt;/a&gt;. It explains the three techniques which are known to be used by ATM scammers to steal your hard earned money.

I am really glad that there are such kind of website is available on the net. Yes, it does makes you feel insecure reading all about the ATM scam techniques, but it also undoubtedly makes you more prepared to face such threats, since now you are more informed about it. Hopefully, none of us need to encounter such scams ever.   
    </content:encoded>

    <pubDate>Mon, 08 Jan 2007 10:46:03 +0800</pubDate>
    <guid isPermaLink="false">http://www.technovice.net/archives/201-guid.html</guid>
    
</item>
<item>
    <title>Recommended Free Anti Viruses</title>
    <link>http://www.technovice.net/archives/186-Recommended-Free-Anti-Viruses.html</link>
            <category>Security</category>
    
    <comments>http://www.technovice.net/archives/186-Recommended-Free-Anti-Viruses.html#comments</comments>
    <wfw:comment>http://www.technovice.net/wfwcomment.php?cid=186</wfw:comment>

    <slash:comments>2</slash:comments>
    <wfw:commentRss>http://www.technovice.net/rss.php?version=2.0&amp;type=comments&amp;cid=186</wfw:commentRss>
    

    <author>nospam@example.com (jumanjisama)</author>
    <content:encoded>
    &lt;a href=&quot;http://technovice.net/archives/30-Recommended-Free-Defences-For-Normal-PC-Users.html&quot; &gt;In a previous article &lt;/a&gt;, i have recommended a couple of free anti viruses. But after a few months and reviews later, i have decided to revamp my recommendation. So, in today&#039;s article, i will recommend three anti viruses which, in my point of view, are the most competent, hi tech and reliable. Two of them are already known for quite sometime for being among the best free anti virus available, and one is a new comer in the free anti virus arena :) (the more the better)

 &lt;img style=&quot;border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://www.technovice.net/uploads/Free_Defence.jpg&quot; alt=&quot;&quot;  /&gt;

&lt;strong&gt;AVG&lt;/strong&gt;

Yeah, the good old AVG, been recommended by many security experts as one of the best free anti virus out there and it has been around for quite a long time now (relatively) and with the new release of AVG 7.5 , Grisoft is (not literally) telling the world that AVG ain&#039;t going anywhere anytime soon.

Things that make AVG cool:

# It auto updates it&#039;s virus signature

# Other than having an On Demand virus capability, AVG also offers virus protection for your emails - you need to know that not all free anti viruses offer both On Demand and Email virus protection, so any free anti virus which does offer this, it can be considered as a very generous gift :-)

# It has a very good reputation for being a really reliable free anti virus application 

If you are interested to know more about AVG, please click on this link: &lt;a href=&quot;http://free.grisoft.com/doc/avg-anti-virus-free/lng/us/tpl/v5&quot; target=&quot;_blank&quot;&gt;Read More&lt;/a&gt;

To download the latest version of free AVG, go here: &lt;a href=&quot;http://free.grisoft.com/doc/5390/lng/us/tpl/v5#avg-anti-virus-free&quot; target=&quot;_blank&quot;&gt;Get Free AVG&lt;/a&gt;


&lt;img width=&quot;200&quot; height=&quot;200&quot; style=&quot;border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://www.technovice.net/uploads/Avast.gif&quot; alt=&quot;&quot;  /&gt;

&lt;strong&gt;Avast! Home Edition&lt;/strong&gt;

Avast can be considered AVG&#039;s most haunting rival, most security experts will either recommend AVG or Avast or both as the best free anti virus. Personally, i can&#039;t tell which one is better in respect of detecting more viruses and protecting your PC better, but Avast can really boast about it&#039;s list of features and cool design. 

Avast is cool because:

# Just like AVG, Avast offers both On Demand virus scan and Email protection

# Unlike AVG, Avast has P2P (bticomet,kazaa,limewire and etc) and Instant Messaging (IM) protection - this feature gets a lot of extra points from me :-P

# Auto Updates

# Has Web Shield - a protection system against attacks from websites ( don&#039;t be surprise, there are websites made today which has a sole purpose - to make your life miserable)

# Protection from network attack - totally cool for people who are connected to a network such in a University&#039;s Network


As i said, Avast has a long list of features compared to AVG, so if you are keen to know every tiny miny detail about Avast, head here: &lt;a href=&quot;http://www.avast.com/eng/avast_4_home.html&quot; target=&quot;_blank&quot;&gt;Read More&lt;/a&gt;

Then, if you are interested to get your own copy of Avast, click on this link: &lt;a href=&quot;http://www.avast.com/eng/download-avast-home.html&quot; target=&quot;_blank&quot;&gt;Get Avast&lt;/a&gt;


&lt;img width=&quot;77&quot; height=&quot;120&quot; style=&quot;border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://www.technovice.net/uploads/PcToolsAV.gif&quot; alt=&quot;&quot;  /&gt;

&lt;strong&gt;PC Tools Anti Virus
&lt;/strong&gt;
This AV is the new kid in the block (again, relatively speaking dude!) but sure got under the spot light really fast. PC Tools AntiVirus is developed by the same company that made the famous Spyware Doctor. Though this cannot be a prove that PC Tools AntiVirus is a good free anti virus, but it has to mean something right (the made-by-the-same-company thing) - just like cars, news models from BMW or Toyota is considered good, cause both of the car manufacturers has made many really good models before (a bit off topic :-) )

Anyway, PC Tools Anti Virus is considered cool by me (that is why i recommend it :-) ) because:

# It has Smart Updates function - just another funky name for auto update

# It has community support - this feature, though may seem unnecessary, but it is really totally useful when you encounter any problems with the application (hopefully there are no problems in the first place)

# Just like the two above,  PC Tools Anti Virus has both On Demand scanning capability and Email protection

# It has Internet Guard - again, this is just another funky name for protection against treats from websites

to learn more about PC Tools Anti Virus, go to this link: &lt;a href=&quot;http://www.pctools.com/free-antivirus/&quot; target=&quot;_blank&quot;&gt;Read More&lt;/a&gt;

to download PC Tools Anti Virus, please click on this link: &lt;a href=&quot;http://www.pctools.com/free-antivirus/download/&quot; target=&quot;_blank&quot;&gt;Get PC Tools Anti Virus&lt;/a&gt;


Lastly, just as a reminder, no one AV can give you a full protection against any attacks, not even the commercial ones can, so please don&#039;t expect much from the free ones. Practice save internet activities and probably you won&#039;t have to worry about your PC getting infected by viruses :-) 
    </content:encoded>

    <pubDate>Sun, 31 Dec 2006 08:26:45 +0800</pubDate>
    <guid isPermaLink="false">http://www.technovice.net/archives/186-guid.html</guid>
    
</item>
<item>
    <title>Secure Your Instant Messenger</title>
    <link>http://www.technovice.net/archives/172-Secure-Your-Instant-Messenger.html</link>
            <category>Security</category>
    
    <comments>http://www.technovice.net/archives/172-Secure-Your-Instant-Messenger.html#comments</comments>
    <wfw:comment>http://www.technovice.net/wfwcomment.php?cid=172</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.technovice.net/rss.php?version=2.0&amp;type=comments&amp;cid=172</wfw:commentRss>
    

    <author>nospam@example.com (jumanjisama)</author>
    <content:encoded>
    &lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://technovice.net/archives/172-Secure-Your-Instant-Messenger.html&#039;&gt;&lt;img width=&quot;132&quot; height=&quot;48&quot; style=&quot;float: left; border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://www.technovice.net/uploads/ims_logo.gif&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;I found this cool free security software for your instant messenger while wasting my precious time surfing the net :) . Anyway, this application is called IM Secure from Zonelabs, the same company that created the famous Zone Alarm Firewall. Zonelabs offers home users the light version of the IM Secure, good enough for me, as long as it is free :)

 Some of the offered features are as below:

&lt;strong&gt;#Universal, Transparent Protection&lt;/strong&gt;

Works with the IM you already use—AOL Instant Messenger, ICQ, MSN Messenger, Yahoo!, ICQ, and even universal clients like Trillian. Once IMsecure Pro is installed, it protects your IM silently, without interaction.
 
&lt;strong&gt;#Inbound and Outbound Threat Protection&lt;/strong&gt;

Guards your PC by blocking dangerous inbound and outbound IM traffic, including: invalid messages, buffer overflow attacks, and more. Defends your computer and your files from hackers, thieves, vandals, and predators.

&lt;strong&gt;#Spam Blocker&lt;/strong&gt;

Saves time by blocking unwanted messages from strangers, and protects you from dangerous and inappropriate content.
 
&lt;strong&gt;#ID Lock&lt;/strong&gt;

Blocks a user-defined list of confidential terms from being sent via IM by anyone else sharing your computer.


to learn more about the requirements and stuffs, click on this link: &lt;a href=&quot;http://www.zonelabs.com/store/content/catalog/products/sku_list_ims.jsp?dc=12bms&amp;amp;ctry=US&amp;amp;lang=en&amp;amp;lid=nav_fim&quot; target=&quot;_blank&quot;&gt;More About IM Secure&lt;/a&gt;


&lt;strong&gt;Personal Opinion&lt;/strong&gt;

This is a great application, especially for people who have had experienced their IM being hijacked before. IM Secure may not able to completely secure your IM (well, nothing can) , but at least it can help you to avoid most of the attacks. One drawback of IM Secure is that, it is not compatible with a few security application such as NOD32 (i was unsuccessful in finding a reliable source to give me the list of application that IM Secure ain&#039;t compatible with)

Anyway, it is a great free application from Zonelabs and i really do encourage you to download it, will surely be a valuable addition to you computer&#039;s defense system.

 
    </content:encoded>

    <pubDate>Thu, 21 Dec 2006 06:11:32 +0800</pubDate>
    <guid isPermaLink="false">http://www.technovice.net/archives/172-guid.html</guid>
    
</item>
<item>
    <title>Encrypted Messages For IMs</title>
    <link>http://www.technovice.net/archives/127-Encrypted-Messages-For-IMs.html</link>
            <category>Security</category>
    
    <comments>http://www.technovice.net/archives/127-Encrypted-Messages-For-IMs.html#comments</comments>
    <wfw:comment>http://www.technovice.net/wfwcomment.php?cid=127</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.technovice.net/rss.php?version=2.0&amp;type=comments&amp;cid=127</wfw:commentRss>
    

    <author>nospam@example.com (jumanjisama)</author>
    <content:encoded>
    Did you know that there exists softwares that you could use to spy on people who are using Instant Messengers (IM)? Spy in this context means that you could read all of their conversation. OK, now that you know, don&#039;t start to be excited yet because this article ain&#039;t gonna disclose to you on how to do just that, but instead, how to avoid from your private messages to be misused. One way of doing that is to encrypt all out going messages, so that even if they are intercepted, it would be totally useless :)

 &lt;strong&gt;Why Encrypted ?&lt;/strong&gt;

Sometimes, you pass some private information to your friends or family using IMs. Other times you are having a secret conversation with your girlfriend or boyfriend or both through IMs. Either way, you wouldn&#039;t like if the conversation was leaked to a third party. You don&#039;t need to encrypt your messages every time you wanna chat, but you should encrypt your messages that you think are very valuable and there are probably rivals or enemies that are tagging your messages. But, i can only show you the door, it is you who needs decide whether to open it or not (i think that was the line Morpheus said to Neo when visiting the Oracle)


&lt;strong&gt;SimpLite&lt;/strong&gt;

There are a few softwares that you could use to encrypt your messages,the first is a software from &lt;a href=&quot;http://www.secway.fr/us/&quot; target=&quot;_blank&quot;&gt;Secway&lt;/a&gt;, called Simp. There are two versions of the software, commercial and free. The commercial version is called SimpPro while the free version is called SimpLite. Both are just as good, but for the free version, you may only use the encryption software for one IM at a time. Plus, you need to download a specific encrypter for a specific IM. Below are the download links for the four IMs that the SimpLite supports:

1. &lt;a href=&quot;http://www.secway.fr/us/products/simplite_msn/getsimp.php&quot; target=&quot;_blank&quot;&gt;SimpLite For MSN Messenger&lt;/a&gt;

2. &lt;a href=&quot;http://www.secway.fr/us/products/simplite_yahoo/getsimp.php&quot; target=&quot;_blank&quot;&gt;SimpLite for Yahoo Messenger&lt;/a&gt;

3. &lt;a href=&quot;http://www.secway.fr/us/products/simplite_jabber/getsimp.php&quot; target=&quot;_blank&quot;&gt;SimpLite for Google Talk/Jabber&lt;/a&gt;

4. &lt;a href=&quot;http://www.secway.fr/us/products/simplite_icq_aim/getsimp.php&quot; target=&quot;_blank&quot;&gt;SimpLite for ICQ/AIM&lt;/a&gt;

But take note that, in order to fully utilize this tool, both you and your chatting partner need to have SimpLite installed, and it must be the same version, or else, your messages won&#039;t be encrypted. 


&lt;strong&gt;Miranda and GAIM&lt;/strong&gt;

These two aren&#039;t actually encrypting softwares, but are Universal Messengers (UM). The great thing about these two is, they support message encryption, both of the UMs have plugins that are capable of encrypting all incoming and outgoing messages. But just as SimpLite, both parties need to use the same IM client. For example, if you are using Miranda, your chatting partner also need to use Miranda with the same encryption plugin in order for everything to work, this also applies to GAIM.

I have written a short intro to both of these UMs in separate articles, you may read them by clicking the link below:

1. &lt;a href=&quot;http://technovice.net/archives/111-Miranda,-Universal-IM-for-Windows.html&quot; &gt;Miranda&lt;/a&gt;

2. &lt;a href=&quot;http://technovice.net/archives/56-Universal-Instant-Messenger.html&quot; &gt;GAIM&lt;/a&gt;


As i have mentioned above, it is not required for you to encrypt all of your messages. But if you think that you are being spied on by your spouse,boss,rival,enemy or etc, encrypting your message can be a really good idea :) 
    </content:encoded>

    <pubDate>Tue, 14 Nov 2006 06:00:23 +0800</pubDate>
    <guid isPermaLink="false">http://www.technovice.net/archives/127-guid.html</guid>
    
</item>
<item>
    <title>HijackThis - A Great Malware Detecting Tool</title>
    <link>http://www.technovice.net/archives/115-HijackThis-A-Great-Malware-Detecting-Tool.html</link>
            <category>Security</category>
    
    <comments>http://www.technovice.net/archives/115-HijackThis-A-Great-Malware-Detecting-Tool.html#comments</comments>
    <wfw:comment>http://www.technovice.net/wfwcomment.php?cid=115</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.technovice.net/rss.php?version=2.0&amp;type=comments&amp;cid=115</wfw:commentRss>
    

    <author>nospam@example.com (jumanjisama)</author>
    <content:encoded>
    &lt;a href=&quot;http://www.tomcoyote.org/hjt/#introduction&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://www.technovice.net/uploads/hijackthis_big.gif&quot; border=&quot;0&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;&lt;a href=&quot;http://www.tomcoyote.org/hjt/&quot; target=&quot;_blank&quot;&gt;HijackThis&lt;/a&gt; have been around for quite some time already, and it is a very popular tool to diagnose your system for malware infections. There are a few reasons to why &lt;a href=&quot;http://www.tomcoyote.org/hjt/#introduction&quot; target=&quot;_blank&quot;&gt;HijackThis&lt;/a&gt; is a popular malware detecting and removing tool, such as:

1. It is free
2. It has a great support
3. It doesn&#039;t require installation, thus making it portable
4. It is really good at what it does, detecting and removing malwares

 &lt;a href=&quot;http://www.tomcoyote.org/hjt/#introduction&quot; target=&quot;_blank&quot;&gt;HijackThis&lt;/a&gt; has a unique approach to counter malware infections. Being different from other normal malware detector and remover, upon scanning your system,&lt;a href=&quot;http://www.tomcoyote.org/hjt/#introduction&quot; target=&quot;_blank&quot;&gt;HijackThis&lt;/a&gt; will not give any warning of malware infections or suspicious application (in case it detects any). Instead, it will produce a report, which is the most essential product of the system scanning. Using this report, you may ask for expert&#039;s opinions and help from various forums and sites, which i think is the best feature of &lt;a href=&quot;http://www.tomcoyote.org/hjt/#introduction&quot; target=&quot;_blank&quot;&gt;HijackThis&lt;/a&gt;. 


&lt;strong&gt;Start&lt;/strong&gt;

To download &lt;a href=&quot;http://www.tomcoyote.org/hjt/#introduction&quot; target=&quot;_blank&quot;&gt;HijackThis&lt;/a&gt;, pleas go to this link: &lt;a href=&quot;http://www.download.com/HijackThis/3000-8022_4-10379544.html&quot; target=&quot;_blank&quot;&gt;Get HijackThis&lt;/a&gt;

To make a quickstart using &lt;a href=&quot;http://www.tomcoyote.org/hjt/#introduction&quot; target=&quot;_blank&quot;&gt;HijackThis&lt;/a&gt;, you may visit this link, which will explain to you in short on how to use &lt;a href=&quot;http://www.tomcoyote.org/hjt/#introduction&quot; target=&quot;_blank&quot;&gt;HijackThis&lt;/a&gt;: &lt;a href=&quot;http://www.tomcoyote.org/hjt/#quick&quot; target=&quot;_blank&quot;&gt;HijackThis Quickstart
&lt;/a&gt;


&lt;strong&gt;Support Sites/Forums&lt;/strong&gt;

This link will show most, if not all, available support sites, which you could join and get advice and also help: &lt;a href=&quot;http://www.merijn.org/forums.php&quot; target=&quot;_blank&quot;&gt;Support Sites/Forum&lt;/a&gt;. But remember, in order to get any help from the experts, you will need to have the system&#039;s scan report of your system. You may ask questions,advice,suggestion and also help at all of those support sites.Anyway, for the sake of reminding, please be polite when you are asking for advice at these sites, they are helping you for free, respect that :)


&lt;strong&gt;Web Service&lt;/strong&gt;

Other than asking for expert&#039;s advice, you may also submit your scan report to a web service at: &lt;a href=&quot;http://www.hijackthis.de/#anl&quot; target=&quot;_blank&quot;&gt;Fast Report Submission&lt;/a&gt;. This web service will generate a simple analysis of your scan report and will warn you for any suspicious or known malware infection in your system. Using this web service, you could get a faster result of your scan, but still, it lacks the human touch :)

As a summary, &lt;a href=&quot;http://www.tomcoyote.org/hjt/#introduction&quot; target=&quot;_blank&quot;&gt;HijackThis&lt;/a&gt; is a really reliable tool to scan your system and make sure it is free from malware infections. It has been used by many and has proven itself to be a really great tool. Again,to download &lt;a href=&quot;http://www.tomcoyote.org/hjt/#introduction&quot; target=&quot;_blank&quot;&gt;HijackThis&lt;/a&gt;, please go to this link: &lt;a href=&quot;http://www.download.com/HijackThis/3000-8022_4-10379544.html&quot; target=&quot;_blank&quot;&gt;Get HijackThis&lt;/a&gt; 
    </content:encoded>

    <pubDate>Sat, 11 Nov 2006 10:37:29 +0800</pubDate>
    <guid isPermaLink="false">http://www.technovice.net/archives/115-guid.html</guid>
    
</item>
<item>
    <title>GMER, An Anti-Rootkit For Beginners</title>
    <link>http://www.technovice.net/archives/287-GMER,-An-Anti-Rootkit-For-Beginners.html</link>
            <category>Security</category>
    
    <comments>http://www.technovice.net/archives/287-GMER,-An-Anti-Rootkit-For-Beginners.html#comments</comments>
    <wfw:comment>http://www.technovice.net/wfwcomment.php?cid=287</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.technovice.net/rss.php?version=2.0&amp;type=comments&amp;cid=287</wfw:commentRss>
    

    <author>nospam@example.com (jumanjisama)</author>
    <content:encoded>
    Previously, i have written a short article about rootkits and the threats that they appose : &lt;a href=&quot;http://technovice.net/archives/100-Danger-!!!-Intro-to-Rootkits.html&quot; &gt;Intro To Rootkits&lt;/a&gt;. In this article, i wanna introduce you guys to an anti-rootkit which is suitable for beginners. It is really tech-novice friendly, as it doesn&#039;t require you to have any knowledge identifying a rootkit and it is practically really easy to use and has some really useful features when it comes to detecting and removing the rootkits.

 The anti-rootkits that i am talking about is called &lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt;, some of the features that it has are as below:

# hidden processes
# hidden threads
# hidden modules
# hidden services
# hidden files
# hidden Alternate Data Streams
# hidden registry keys
# drivers hooking SSDT
# drivers hooking IDT
# drivers hooking IRP calls
# inline hooks

Don&#039;t worry if you don&#039;t know anything about this features and what it means, you are not alone :-). Most important thing that you need to know is that &lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt; allows you to lookout for any hidden or suspicious running applications. 


&lt;strong&gt;Start&lt;/strong&gt;

&lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt; is a lightweight application, it&#039;s size is only under 500kb (version 1.0.12). But despite the small size, it has some amazing functions under its hood. Other than being small in size, it is also free to download and use, which adds more awesomeness to it. You may download it at it&#039;s official web : &lt;a href=&quot;http://www.gmer.net/files.php&quot; &gt;Get GMER&lt;/a&gt;. You will see a list of files at the page,  to download &lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt;; choose the one on top of the list. The other files are video files, examples of &lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt; in action.


&lt;strong&gt;Processes&lt;/strong&gt;

&lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt; has a really informative process viewing feature. For a beginner, you may not understand all the information &lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt; may provide about all the running processes in your PC, but there are still a few types of information that may be useful ,such as, you could see where the running process is located (the executable file), how long it has been running and how much memory is it consuming. 

Other than being informative, it could also kill any running process that you would like to shutdown. This is a very useful feature, as you could kill a running rootkit and scan for the malware that it is hiding using your anti malware application. Click on this link to learn more on how to kill all processes and scan for the hidden malware: &lt;a href=&quot;http://www.gmer.net/antivirus.php&quot; &gt;Learn More&lt;/a&gt;. Some example images that the author has provided are in Polish, but you should have no problem understanding it :)

&lt;strong&gt;Scanning Rootkits
&lt;/strong&gt;
&lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt; doesn&#039;t provide a real time protection, well not directly. What i mean by that is, if for example a rootkit has been downloaded into your system and starts running, &lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt; won&#039;t give out some warning or automatically remove the rootkit or something. To do so, you need to do it manually. &lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt; could be set to log all running processes or set to prompt you if any unauthorized action was made, but this requires you to identify the level of danger of the unauthorized action.

But even so, &lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt; still has a really solid rootkit scanning capability. At the &#039;files&#039; section at the official &lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt; website, there is a video showing &lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt; kicking kaspersky&#039;s ass, when &lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt; could detect a rootkit which kaspersky fail to. You may download the video here: &lt;a href=&quot;http://www.gmer.net/kav6.wmv&quot; &gt;Get Video&lt;/a&gt;. 

Scanning for rootkits is really simple, and after the scan has been completed, &lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt; will show a full report of the scan, which is really important. With this report, since rootkits can be a bit complicated,you may ask rootkit&#039;s experts to analyse the report and help you to identify if there are any rootkits that &lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt; has overlooked or if &lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt; has mistakenly identified an innocent process to be a rootkit. Even the author of &lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt; offers you this service, helping you to analyse your &lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&#039;s&lt;/a&gt; scan report. Just fill in this contact form: &lt;a href=&quot;http://www.gmer.net/contact.php&quot; &gt;Contact GMER&#039;s author&lt;/a&gt;, include the scan report with it, and submit.


Overall, i really like &lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt; and i really suggest it for you to use. I like it&#039;s simplicity but yet so powerful. Though it may not be the ultimate anti rootkit available, but there are a few rootkits experts out there that rate &lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt; to be at the same level as the best anti rootkits.  Download &lt;a href=&quot;http://www.gmer.net/index.php&quot; target=_blank&quot;&gt;GMER&lt;/a&gt; right away : &lt;a href=&quot;http://www.gmer.net/files.php&quot; &gt;Get GMER&lt;/a&gt; 
    </content:encoded>

    <pubDate>Mon, 06 Nov 2006 05:58:07 +0800</pubDate>
    <guid isPermaLink="false">http://www.technovice.net/archives/287-guid.html</guid>
    
</item>
<item>
    <title>Danger !!! - Intro to Rootkits</title>
    <link>http://www.technovice.net/archives/100-Danger-!!!-Intro-to-Rootkits.html</link>
            <category>Security</category>
    
    <comments>http://www.technovice.net/archives/100-Danger-!!!-Intro-to-Rootkits.html#comments</comments>
    <wfw:comment>http://www.technovice.net/wfwcomment.php?cid=100</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.technovice.net/rss.php?version=2.0&amp;type=comments&amp;cid=100</wfw:commentRss>
    

    <author>nospam@example.com (jumanjisama)</author>
    <content:encoded>
    I am sure that you know what a computer worm,virus or a trojan is. Lately, the most popular annoying malware are spywares. In this article, i just wanna write a short intro about another less known malware, called rootkits. Unlike the other trouble making malwares, rootkits are a bit unique.

 &lt;strong&gt;What A Rootkit Does?&lt;/strong&gt;

The main nature of worms,viruses,trojans and spywares are to make damages. But rootkits are different, they don&#039;t do damages, instead, their main purpose is to conceal the existence of the malware that comes with it. Quoted from wikipedia:

&lt;blockquote&gt;A rootkit is a set of software tools intended to conceal running processes, files or system data, thereby helping an intruder to maintain access to a system whilst avoiding detection.&lt;/blockquote&gt;

This is a very important characteristic of rootkits that users should be aware of, rootkits are really hard to be detected, especially the hardcore ones. Even the antivirus makers are having a lot of trouble to make sure that their software could detect as much rootkits as possible. Quoted from Mikael Albrecht, product manager for F-Secure:

&lt;blockquote&gt;Rootkit detection is a cat-and-mouse game. Sometimes the rootkit authors are ahead, sometimes the antirootkit authors.&lt;/blockquote&gt;


&lt;strong&gt;Rootkits Are Troublesome&lt;/strong&gt;

Not enough with it&#039;s ability to conceal itself and the malwares it carries, it is also can be quite troublesome to remove it. Unlike other malwares (i am not sure if rootkits can be classified as malwares, as it doesn&#039;t directly do any damages) which you could simply use the anti malware software to remove it,removing a rootkit has a probability to cause damages to your Operating System (OS). Quoting from wikipedia again:

&lt;blockquote&gt;Rootkits often modify parts of the operating system or install themselves as drivers or kernel modules.&lt;/blockquote&gt;

This statement tells us that rootkits attach itself deeply into the core of the OS, which means, removing it, can cause instability to your system. 

Though it is undeniable that most commercial anti virus companies has made their software capable of detecting and sometimes removing rootkits, but this is only limited to basic rootkits and the number of rootkits sample that they have. Rootkits writers are making more and more complex rootkits as time goes by. 


&lt;strong&gt;The End?&lt;/strong&gt;

What about anti rootkits? Don&#039;t they exist? Well, they exist all right, and the good news is, the best anti rootkits around is free. The bad news is, since rootkits are a bit more troublesome than other malwares, most of the best anti rootkits available are mostly for expert and advance users.  But, there are a few that are also suitable for beginners. Since this article is already too long to tolerate, i will post about my review of the anti rootkit, the one that is suitable for beginners, in my upcoming article :)


References:

&lt;a href=&quot;http://en.wikipedia.org/wiki/Rootkits&quot; target=&quot;_blank&quot;&gt;Wikipedia is my friend&lt;/a&gt;
&lt;a href=&quot;http://itmanagement.earthweb.com/columns/executive_tech/article.php/3512621&quot; target=&quot;_blank&quot;&gt;Interview With Developer Of Icesword&lt;/a&gt;

p/s: yeah2, i know, this article is boring, but i need you to know about rootkit before i write about detecting and removing it !!! Stop complaining and start reading :-P

 
    </content:encoded>

    <pubDate>Fri, 03 Nov 2006 07:04:18 +0800</pubDate>
    <guid isPermaLink="false">http://www.technovice.net/archives/100-guid.html</guid>
    
</item>
<item>
    <title>A Trojan Stealing Your Precious Infos</title>
    <link>http://www.technovice.net/archives/62-A-Trojan-Stealing-Your-Precious-Infos.html</link>
            <category>Security</category>
    
    <comments>http://www.technovice.net/archives/62-A-Trojan-Stealing-Your-Precious-Infos.html#comments</comments>
    <wfw:comment>http://www.technovice.net/wfwcomment.php?cid=62</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.technovice.net/rss.php?version=2.0&amp;type=comments&amp;cid=62</wfw:commentRss>
    

    <author>nospam@example.com (jumanjisama)</author>
    <content:encoded>
    There is a trojan circulating in the internet, detected by Panda Antivirus, which steals your personal informations (that&#039;s not new, i know). But what makes it worst, it is protected by a rootkit. Now, what in the world is a rootkit? In simple words, it is a application used to hide malwares from being detected by anti malware softwares. It is really a bad combination, once you are infected, it is really hard to detect and remove it.

 The malicious code writer(s) is sending this Trojan variant by attaching it to spam mails, quoted from Luis Corrons, director of PandaLabs:

[quote]it seems that the author or authors of these malicious codes are mass-mailing these Trojans as attachments to spam messages. For this reason, it is recommendable to delete any suspicious or unwanted email messages.......[/quote]

The Trojan steals infos such as (quoted from Panda):

[quote]...designed to steal passwords for popular Internet services, such as eBay, ICQ, Pay Pal or Web Money, and for many email clients, including Outlook Express or The Bat!...[/quote]


&lt;strong&gt;Just Reminding&lt;/strong&gt;

I am posting this entry not to make you guys scared or something, but just wanna remind you to be cautious while surfing. Since this troublesome Trojan is protected by rootkit(s), normal antivirus can&#039;t detect it (especially the free ones). You really don&#039;t want your PC to be infected by this Trojan, so takes precautions steps as suggested by Luis Corrons - don&#039;t ever, never ever, big never ever read or open attachments from spam mails, even better, just delete them of. No matter how appealing the subject of the spam mail can be, it is not worth the risk of losing your personal infos to some crazy maniac who would, no doubt bout it, make your life miserable as long as s/he can.

Lastly, i got this active scan from Panda, so you could scan your PC online, just to make sure you are clean of this damn stupid Trojan, to use it, unfortunately you need to have IE 5 or IE 6 - Firefox and IE 7 ain&#039;t supported. Go to this link to scan your PC for free: &lt;a href=&quot;http://www.pandasoftware.com/products/activescan.htm&quot; target&quot;_blank&quot;&gt;Panda Active Scan&lt;/a&gt;


Read Original Report : &lt;a href=&quot;http://www.pandasoftware.com/about/press/viewNews.htm?noticia=7863&amp;amp;ver=21&amp;amp;pagina=&amp;amp;numprod=&amp;amp;entorno=&amp;amp;sitepanda=empresas&quot; target=&quot;_blank&quot;&gt;Panda News&lt;/a&gt;

Extra Reading: &lt;a href=&quot;http://en.wikipedia.org/wiki/Rootkit&quot; target=&quot;_blank&quot;&gt;What Is A Rootkit?&lt;/a&gt; 
    </content:encoded>

    <pubDate>Fri, 20 Oct 2006 20:14:00 +0800</pubDate>
    <guid isPermaLink="false">http://www.technovice.net/archives/62-guid.html</guid>
    
</item>
<item>
    <title>Link Scanner - Scans For Malicious Links</title>
    <link>http://www.technovice.net/archives/55-Link-Scanner-Scans-For-Malicious-Links.html</link>
            <category>Security</category>
    
    <comments>http://www.technovice.net/archives/55-Link-Scanner-Scans-For-Malicious-Links.html#comments</comments>
    <wfw:comment>http://www.technovice.net/wfwcomment.php?cid=55</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.technovice.net/rss.php?version=2.0&amp;type=comments&amp;cid=55</wfw:commentRss>
    

    <author>nospam@example.com (jumanjisama)</author>
    <content:encoded>
    &lt;img src=&quot;http://www.technovice.net/uploads/LinkScanner_logo.gif&quot; class=&quot;image_test&quot; alt=&quot;&quot;  /&gt;There is a webtool on the net that allows you to scan links for hidden exploits. Well, i am not saying that you need to scan all the links that you wanna visit, before you visit them. I just merely wanna share this cool webtool with you guys, in case anyone of you suspects a link to be malicious and but you don&#039;t know how to make sure of it. Then probably this webtool that i am recommending is the one you are looking for. 

 Just click on this link below and visit the web that host this webtool (don&#039;t worry, i am not spreading some malicious link here :)):

&lt;a href=&quot;http://linkscanner.explabs.com/linkscanner/&quot; target=&quot;_blank&quot;&gt;LinkScanner
&lt;/a&gt;
All you need to do is insert the URL of the link into the space provided then click on &#039;Scan&#039;, that&#039;s all. Soon after that, the web will post a report of the scan. So if you have a link that you feel suspicious about it&#039;s safety, then use this webtool, and be suspicious no more :) 
    </content:encoded>

    <pubDate>Mon, 16 Oct 2006 11:37:13 +0800</pubDate>
    <guid isPermaLink="false">http://www.technovice.net/archives/55-guid.html</guid>
    
</item>
<item>
    <title>Extra Defence For P2P Users - For Free</title>
    <link>http://www.technovice.net/archives/54-Extra-Defence-For-P2P-Users-For-Free.html</link>
            <category>Security</category>
    
    <comments>http://www.technovice.net/archives/54-Extra-Defence-For-P2P-Users-For-Free.html#comments</comments>
    <wfw:comment>http://www.technovice.net/wfwcomment.php?cid=54</wfw:comment>

    <slash:comments>2</slash:comments>
    <wfw:commentRss>http://www.technovice.net/rss.php?version=2.0&amp;type=comments&amp;cid=54</wfw:commentRss>
    

    <author>nospam@example.com (jumanjisama)</author>
    <content:encoded>
    &lt;img src=&quot;http://www.technovice.net/uploads/PeerGuardian.jpg&quot; class=&quot;image_test&quot; alt=&quot;&quot;  /&gt;P2P (peer to peer) Users are users which uses applications such as bittorent clients (bitcomet,azureus,utorrent etc), Limewire,eMule and Kazaa. I think you got the idea already. P2P network is by itself very insecure, as soon as you log in into the network, you make your PC vulnerable to attacks. I prefer not to go all technical about how a p2p network works, but you should at least have a rough idea about it. In layman words, in a p2p network, you send and receive chunks of file to and from different PC&#039;s which has different &lt;a href=&quot;http://en.wikipedia.org/wiki/IP_address&quot; target=&quot;_blank&quot;&gt;IPs&lt;/a&gt;. And there are known &lt;a href=&quot;http://en.wikipedia.org/wiki/IP_address&quot; target=&quot;_blank&quot;&gt;IPs&lt;/a&gt; that sends bad stuffs to people. Most of p2p clients can&#039;t protect you from this evil &lt;a href=&quot;http://en.wikipedia.org/wiki/IP_address&quot; target=&quot;_blank&quot;&gt;IPs&lt;/a&gt;, even if they can, it is very limited.

  Luckily for us, the download junkies, there exist an application called &lt;a href=&quot;http://phoenixlabs.org/pg2/&quot; target=&quot;_blank&quot;&gt;PeerGuardian&lt;/a&gt;, from &lt;a href=&quot;http://phoenixlabs.org/&quot; target=&quot;_blank&quot;&gt;Phoenix Labs&lt;/a&gt;. It is a very optimized application for blocking these evil &lt;a href=&quot;http://en.wikipedia.org/wiki/IP_address&quot; target=&quot;_blank&quot;&gt;IPs&lt;/a&gt; that i mentioned above. Blocking is what all what it does, nothing else. It has a frequently updated list of &lt;a href=&quot;http://en.wikipedia.org/wiki/IP_address&quot; target=&quot;_blank&quot;&gt;IPs&lt;/a&gt; which distributes spyware,trojan, virus, just name it, it has the list. 

Before i go on, i want to make it clear, this is not a firewall application, though it&#039;s function is almost the same. So it wouldn&#039;t conflict with your current firewall (and please don&#039;t go on and removing your firewall after you have installed this, totally not recommended)

&lt;strong&gt;Get It&lt;/strong&gt; 

You can get your own free &lt;a href=&quot;http://phoenixlabs.org/pg2/&quot; target=&quot;_blank&quot;&gt;PeerGuardian&lt;/a&gt; here: &lt;a href=&quot;http://phoenixlabs.org/pg2/&quot; target=&quot;_blank&quot;&gt;Download PeerGuardian&lt;/a&gt; . It&#039;s current build is &lt;a href=&quot;http://phoenixlabs.org/pg2/&quot; target=&quot;_blank&quot;&gt;Peer Guardian 2 (PG2)&lt;/a&gt;, which is also the same one that i am using right now. There is also a really, i mean , really complete documentation of &lt;a href=&quot;http://phoenixlabs.org/pg2/&quot; target=&quot;_blank&quot;&gt;PG2&lt;/a&gt; available. It touches all of the important topics such as how it works, how to install it, and how to use it. It even includes images to aid the learning process, nice !!.


&lt;strong&gt;Disadvantage&lt;/strong&gt;

When you use &lt;a href=&quot;http://phoenixlabs.org/pg2/&quot; target=&quot;_blank&quot;&gt;PG2&lt;/a&gt;, you will probably notice a decrease in connection speed, this is due the nature of the p2p network and how &lt;a href=&quot;http://phoenixlabs.org/pg2/&quot; target=&quot;_blank&quot;&gt;PG2&lt;/a&gt; functions. But from the &lt;a href=&quot;http://phoenixlabs.org/pg2/&quot; target=&quot;_blank&quot;&gt;PG2&lt;/a&gt; developers, this disadvantage may be overcome by &lt;a href=&quot;http://www.technovice.net/archives/12-Increase-Your-Half-Open-Connection-For-Better-Download-Speed.html&quot; &gt;increasing your half open connections (HOC)&lt;/a&gt;, for Windows users only.  For Bitcomet 0.73 users, there is a build in feature that allows you to edit the amount of HOC that you have, read it here: &lt;a href=&quot;http://www.technovice.net/archives/50-Insight-Of-Bitcomet-Version-0.73-Features.html&quot; &gt;Edit HOC With Bitcomet 0.73&lt;/a&gt;.

Personally, i don&#039;t think you should trade your PC&#039;s safety for anything, especially when you have other options to overcome the advantages that comes with security. As the writter of this article, i forbid you !! :).  So, wait no more p2p junkies, strengthen your defence arsenal right now, download &lt;a href=&quot;http://phoenixlabs.org/pg2/&quot; target=&quot;_blank&quot;&gt;PG2&lt;/a&gt; : &lt;a href=&quot;http://phoenixlabs.org/pg2/&quot; target=&quot;_blank&quot;&gt;Download Peer Guardian&lt;/a&gt;

p/s: there is also a &lt;a href=&quot;http://phoenixlabs.org/pgosx/&quot; target=&quot;_blank&quot;&gt;PG2 version for OS X available&lt;/a&gt; but for Linux users, the developers of PG2 recommends &lt;a href=&quot;http://moblock.berlios.de/&quot; target=&quot;_blank&quot;&gt;MoBlock&lt;/a&gt;

 
    </content:encoded>

    <pubDate>Sun, 15 Oct 2006 11:36:09 +0800</pubDate>
    <guid isPermaLink="false">http://www.technovice.net/archives/54-guid.html</guid>
    
</item>
<item>
    <title>Worm Attack - From Internet Explorer to Yahoo Messenger</title>
    <link>http://www.technovice.net/archives/48-Worm-Attack-From-Internet-Explorer-to-Yahoo-Messenger.html</link>
            <category>Security</category>
    
    <comments>http://www.technovice.net/archives/48-Worm-Attack-From-Internet-Explorer-to-Yahoo-Messenger.html#comments</comments>
    <wfw:comment>http://www.technovice.net/wfwcomment.php?cid=48</wfw:comment>

    <slash:comments>6</slash:comments>
    <wfw:commentRss>http://www.technovice.net/rss.php?version=2.0&amp;type=comments&amp;cid=48</wfw:commentRss>
    

    <author>nospam@example.com (jumanjisama)</author>
    <content:encoded>
    There is a recent worm breakout for Yahoo Messenger (YM) users.  As usual, the worm exploits the link usage in YM. If infected, the worm will send links to your buddy network, other than that, it also takes advantage of the status mode in YM, making a really innocent looking linked status for your friends to click. The interesting part is, the link will direct you to a webpage filled with high value Google Ads, so practically, the hackers (i assuming there are more than one) is trying to make a living out of worms. Another point of interest is that, you can get infected by this worm by visiting certain web build by the hackers, with Internet Explorer, no surprise there :)

 Tips to avoid getting infected by worm, for this particular situation, are as below:

&lt;strong&gt;Use Firefox&lt;/strong&gt;

Though there are some recently stir about the security vulnerabilities of Firefox, Mozilla made a patch for that in lightning Internet speed. Even better, the updates were sent to the browser when it is activated. I can go on and on telling you all the better security features of Firefox compared to IE (IE 7 is an exception). But you get the idea, don&#039;t compromise the safety of your PC, use Firefox. If you don&#039;t already have one, get it here : &lt;a href=&quot;http://www.mozilla.com/firefox/&quot; target=&quot;_blank&quot;&gt;Get Firefox&lt;/a&gt;. If you already have and are using Firefox, then hooray for you 8-)

Below are tips quoted from my previous entry titled : &lt;a href=&quot;http://technovice.net/archives/35-Worm-Spreading-Using-MSN-Messenger.html&quot; &gt;Worm Spreading Using MSN Messenger&lt;/a&gt;


&lt;strong&gt;Use IM in a Virtual Environment&lt;/strong&gt;

This is at the moment, my best suggestion. It may require a little extra effort for you to activate the IM in a virtual environment, but i really believe it is better to be safe than sorry.  Using IM within a virtual environment decreases your percentage of getting worms like this one into your system ,down to nothing. Any worms that tries to infect your PC will be stuck in the virtual folder. If you would like to learn more about Virtualization, read this : &lt;a href=&quot;http://technovice.net/archives/29-Sandboxie-Working-In-A-Virtual-Environment.html&quot; target=&quot;_blank&quot;&gt;Read Virtualization Article&lt;/a&gt;.


&lt;strong&gt;Ask&lt;/strong&gt;

Ask your friend whether the link is legitimate, just make sure it was a human that sent you the link, not a bot. Sounds a bit silly for some people to do this, but there is not harm from asking, there is a lot of harm that follows a worm though, if it infects your PC :-)

You may read the full report of the worm attack here : &lt;a href=&quot;http://blog.spywareguide.com/2006/10/ie_used_to_launch_instant_mess.html&quot; target=&quot;_blank&quot;&gt;Read Full Report&lt;/a&gt; 
    </content:encoded>

    <pubDate>Sat, 07 Oct 2006 20:40:05 +0800</pubDate>
    <guid isPermaLink="false">http://www.technovice.net/archives/48-guid.html</guid>
    
</item>
<item>
    <title>Worm Spreading Using MSN Messenger</title>
    <link>http://www.technovice.net/archives/35-Worm-Spreading-Using-MSN-Messenger.html</link>
            <category>Security</category>
    
    <comments>http://www.technovice.net/archives/35-Worm-Spreading-Using-MSN-Messenger.html#comments</comments>
    <wfw:comment>http://www.technovice.net/wfwcomment.php?cid=35</wfw:comment>

    <slash:comments>4</slash:comments>
    <wfw:commentRss>http://www.technovice.net/rss.php?version=2.0&amp;type=comments&amp;cid=35</wfw:commentRss>
    

    <author>nospam@example.com (jumanjisama)</author>
    <content:encoded>
    &lt;!-- google_ad_section_start --&gt;&lt;p&gt;&lt;img src=&quot;http://www.technovice.net/uploads/msnmessenger.jpg&quot; class=&quot;image_test&quot; alt=&quot;&quot;  /&gt;&lt;/p&gt;Another threat to Msn Messenger users, this time, according to Kaspersky, the worm is sent using a link, an innocent looking link, with a .PIF extension. What&#039;s worst is that, people will receive this links from their IM friends, which they trust and have almost no reason to doubt the link. Well, now you need to think again before you click on the links that you get.  The extension of the file comes in a few variation, but all are the same, still worms.&lt;!-- google_ad_section_end --&gt;

 &lt;!-- google_ad_section_start --&gt;Though Microsoft has filtered the .pif extension, but it is case sensitive, so the worm writers got smart and toyed with this flaw, using .PIF or .Pif or other variation instead, from Kaspersky:

&lt;blockquote&gt;So the criminals used capital letters, &quot;.PIF&quot; and the network filters let the message flow right through. Other variations like .Pif, .pIf, and so on also work.&lt;/blockquote&gt;

If your IM friend is already infected,  there is very little that you can do to stop the link from being sent to you, but there are a few precaution steps that i would suggest to prevent the worm from getting into your system.


&lt;strong&gt;Use IM in a Virtual Environment&lt;/strong&gt;

This is at the moment, my best suggestion. It may require a little extra effort for you to activate the IM in a virtual environment, but i really believe it is better to be safe than sorry.  Using IM within a virtual environment decreases your percentage of getting worms like this one into your system ,down to nothing. Any worms that tries to infect your PC will be stuck in the virtual folder. If you would like to learn more about Virtualization, read this : &lt;a href=&quot;http://technovice.net/archives/29-Sandboxie-Working-In-A-Virtual-Environment.html&quot; target=&quot;_blank&quot;&gt;Read Virtualization Article&lt;/a&gt;.


&lt;strong&gt;Ask&lt;/strong&gt;

Ask your friend whether the link is legitimate, just make sure it was a human that sent you the link, not a bot. Sounds a bit silly for some people to do this, but there is not harm from asking, there is a lot of harm that follows a worm though, if it infects your PC :-)


&lt;strong&gt;Skip the .pif file and it&#039;s variations&lt;/strong&gt;

Well, this is just common sense, but i still wanna point it out. Microsoft must have good reasons for filtering out this extension, it is best if you follow them. Just in case one of your friend is trying to prank you because you didn&#039;t invite him/her to share pizzas with you the other night.


By following the three suggestions of mine, hopefully none of you will get infected from this notorious worm (i am hoping i won&#039;t get infected again this way, once is more that enough :-))

Read the original article from Kaspersky : &lt;a href=&quot;http://www.viruslist.com/en/weblog?weblogid=199354341&quot; target=&quot;_blank&quot;&gt;Read Original Article&lt;/a&gt;&lt;!-- google_ad_section_end --&gt; 
    </content:encoded>

    <pubDate>Tue, 26 Sep 2006 21:47:21 +0800</pubDate>
    <guid isPermaLink="false">http://www.technovice.net/archives/35-guid.html</guid>
    
</item>
<item>
    <title>Recommended Free Defences For Normal PC Users</title>
    <link>http://www.technovice.net/archives/30-Recommended-Free-Defences-For-Normal-PC-Users.html</link>
            <category>Security</category>
    
    <comments>http://www.technovice.net/archives/30-Recommended-Free-Defences-For-Normal-PC-Users.html#comments</comments>
    <wfw:comment>http://www.technovice.net/wfwcomment.php?cid=30</wfw:comment>

    <slash:comments>2</slash:comments>
    <wfw:commentRss>http://www.technovice.net/rss.php?version=2.0&amp;type=comments&amp;cid=30</wfw:commentRss>
    

    <author>nospam@example.com (jumanjisama)</author>
    <content:encoded>
    &lt;p&gt;&lt;img src=&quot;http://www.technovice.net/uploads/Free_Defence.jpg&quot; class=&quot;image_test&quot; alt=&quot;&quot;  /&gt;&lt;/p&gt;&lt;!-- google_ad_section_start --&gt;OK, let me first define normal PC users. This species of people just use their PC to do their work or surf the Internet to check emails, to send email, to read news, simply put, they just browse the net, no more. Chatting using Yahoo Messenger or Windows Messenger may be also added to the list, though this actually increases the channel of threats the user is vulnerable to. If you are classified as normal PC users and aren&#039;t using any security applications to protect your PC, then you may want to read this article.&lt;!-- google_ad_section_end --&gt;
 &lt;!-- google_ad_section_start --&gt;If i may class the users, i will say it would be something like this:

1st level, threat vulnerability = low

-Check e-mails, and
-Send e-mails, and/or
-Only browse the web, and/or

2nd level, threat vulnerability = medium

-Same as above, and
-Chatting using Instant messengers, such as Yahoo Messenger

Users categorized in the first level are the one most suitable to use free security applications, but users in the 2nd level may need to be more cautious if they also choose to use free security software.


&lt;strong&gt;Free Anti-virus &lt;/strong&gt;

Free AV from Grisoft or AVG is my first recommendation. I have experiences using it before, it had served well defending my PC from infections. You may get your own copy of AVG by clicking on this link : &lt;a href=&quot;http://free.grisoft.com/doc/2/lng/us/tpl/v5&quot; target=&quot;_blank&quot;&gt;Get Free AVG&lt;/a&gt; . Installation and usage of the program is quite simple and well organized. You should have no problem using this piece of software. It supports email scanning and on demand scanning. 

My second recommendation is Bitdefender free edition. But since Bitdefender only supports on demand virus scanning,  i wouldn&#039;t suggest for frequent Internet and instant messenger users, even the provider seems to think it that way.
&lt;blockquote&gt;
BitDefender 8 Free Edition is an on-demand virus scanner, which is best used in a system recovery or forensics role. If you are on an &quot;always-on&quot; Internet connection, we strongly advise you to consider using a more complex antivirus solution.&lt;/blockquote&gt;

You can download the free copy of Bitdefender at : &lt;a href=&quot;http://www.bitdefender.com/PRODUCT-14-en--BitDefender-8-Free-Edition.htm&quot; target=&quot;_blank&quot;&gt;Get Free Bitdefender&lt;/a&gt; 

&lt;strong&gt;
Free Spyware Scanner/Remover&lt;/strong&gt;

Again recommending another free security application from Grisoft,  Ewido. Evaluating Ewido for all the time it had protected my PC from spywares, it must say, it is an awesome free software. Updates are frequent and it can even detect unknown threats, which is a plus to the product. Try it for yourself : &lt;a href=&quot;http://free.grisoft.com/doc/20/lng/us/tpl/v5&quot;  target=&quot;_blank&quot;&gt;Get Free Ewido&lt;/a&gt;

Another spyware scanner and remover that i would like to promote is the AdAware from Larasoft. It is popular free software, most probably you have already heard about it. AdAware boast about it&#039;s Code Sequence Identification (CSI) technology, which allows the software to detect unknown malware infection. Other than that, Larasoft also offers addon&#039;s for Adware at it&#039;s website. Just choose which addons that you like, download and install it. Like Ewido, AdAware hasn&#039;t yet failed me when it comes to detect irritating spywares in my PC. Dont take my word for it, download and test it : &lt;a href=&quot;http://www.lavasoftusa.com/software/adaware/&quot; target=&quot;_blank&quot;&gt;Get Free AdAware&lt;/a&gt;

That are the four main free defence software that i highly recommend. Just keep in mind, i wouldn&#039;t recommend them if i haven&#039;t personally tested and used them in a period of time. But just a reminder from me, no one security software can protect you from all the threats out there in the Internet, my suggestion is,  use a couple of software to give your PC more protection. In this case, unfortunately for the Anti virus, you may just choose one, but for the spyware protection, you may use both. Like the old saying goes, two heads are better than one :)&lt;!-- google_ad_section_end --&gt;
 
    </content:encoded>

    <pubDate>Mon, 25 Sep 2006 10:10:41 +0800</pubDate>
    <guid isPermaLink="false">http://www.technovice.net/archives/30-guid.html</guid>
    
</item>
<item>
    <title>Sandboxie - Working In A Virtual Environment</title>
    <link>http://www.technovice.net/archives/29-Sandboxie-Working-In-A-Virtual-Environment.html</link>
            <category>Security</category>
    
    <comments>http://www.technovice.net/archives/29-Sandboxie-Working-In-A-Virtual-Environment.html#comments</comments>
    <wfw:comment>http://www.technovice.net/wfwcomment.php?cid=29</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.technovice.net/rss.php?version=2.0&amp;type=comments&amp;cid=29</wfw:commentRss>
    

    <author>nospam@example.com (jumanjisama)</author>
    <content:encoded>
    &lt;div class=&quot;image_front_large&quot;&gt;&lt;img src=&quot;http://www.technovice.net/uploads/sandboxie.jpg&quot; alt=&quot;&quot;  /&gt;&lt;/div&gt;I spent the whole day testing and playing with the Sandboxie. Despite it&#039;s simplicity, i found that there are a few adjustment and things that i need to get use to, if i want to continue using this application. If you don&#039;t know what Sandboxie is, please read my &lt;a href=&quot;http://technovice.net/archives/28-Surf-The-Web-Securely-In-A-Virtual-Environment.html&quot; target=&quot;_blank&quot;&gt;previous entry&lt;/a&gt;, it may clear things up a bit for you. But in case you already know, you may just continue reading this post, as i share with you what i have gain, in the hope that it may help you to use the Sandboxie easier.

 In case you are also interested in testing this piece of free virtualization software, you may go to the Sandboxie dedicated website to get you own copy of Sandboxie version 2.60: &lt;a href=&quot;http://www.sandboxie.com/index.php?DownloadSandboxie&quot; target=&quot;_blank&quot;&gt;Download Sandboxie&lt;/a&gt;, but this isn&#039;t the latest release, there is another newer version, &lt;a href=&quot;http://sandboxie.com/phpbb/viewtopic.php?t=562&quot; target=&quot;_blank&quot;&gt;Sandboxie 2.62&lt;/a&gt;, for some unknown reason, the author has decided not to publish this release on the official download page. Personally, i would recommend version 2.62, as it has improved security measures implemented. 

Anyway, Sandboxie is relatively a small sized software, only around 250kb, so downloading it shouldn&#039;t take very long, even for dial-up users. After you have downloaded the application, you can install it right away. The installation is pretty simple and straight forward, nothing a beginner can&#039;t handle.

When Sandboxie has been successfully installed to your machine, you may start using it right away. Double clicking the Sandboxie shortcut in your Desktop or Start Menu will bring a yellow 4 angle image to your tray icon.Right clicking on the yellow icon will bring out the option pane of Sandboxie.

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie1.jpg&quot; alt=&quot;&quot;  /&gt;


&lt;strong&gt;Run,View and Delete Sanboxed Programs&lt;/strong&gt;

To start using Sandboxie to browse the Internet, you just need to right click on the yellow icon and choose  Run Sanboxed-&gt;Default Browser  or, if there are more than one web browser installed in you PC other than Internet Explorer and you want to sandbox Internet Explorer instead, just click Run Sandboxed-&gt;Internet Explorer. Your web browser should appear with &#039;[#]&#039; symbol at both ends of it&#039;s name, for example:

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie19.jpg&quot; alt=&quot;&quot;  /&gt;

Examples using sandboxed Internet Explorer, Opera and Thunderbird

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie20.jpg&quot; alt=&quot;&quot;  /&gt;

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie21.jpg&quot; alt=&quot;&quot;  /&gt;

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie18.jpg&quot; alt=&quot;&quot;  /&gt;

Other than that, you will also notice that the yellow icon have red dots in it now, it is a sign that Sandboxie is active and currently running application in a virtual environment.

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie3.jpg&quot; alt=&quot;&quot;  /&gt;

Other than browsing the net with the protection of Sandboxie, you may also do other things. If you want to install a software but not sure it is infected or not, you may sandbox it, just right click the yellow icon again and  choose Run Sandboxed-&gt;Any Program:

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie5.jpg&quot; alt=&quot;&quot;  /&gt;

Then a small vertical window will appear, click on browse and go to the place, where the software you want to test, is located:

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie6.jpg&quot; alt=&quot;&quot;  /&gt;

Again, a [#] symbol will wrap the name of the application&#039;s name, just like the example i showed above. Other than testing an installation, you may also follow the same steps (Run Sandboxed-&gt;Any Program) or choose Run Sandboxed-&gt;From Start Menu,to run any program on your PC, such as p2p application.

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie7.jpg&quot; alt=&quot;&quot;  /&gt;

You can download files using p2p such as Limewire or Bitcomet with very little or no risk at all if you run them within the virtual environment provided Sandboxie. All you need to do is right click on the yellow icon, choose Run Sandboxed-&gt;Any Program or From Start Menu, and select any p2p or program of your liking. 

Any infection or threat that may come from downloading a file using p2p will stay in the virtual environment and will not disturb your main system. But just as a reminder, if you were downloading using a sandboxed p2p application and wish to continue the download later, you will need to continue the download with a sandboxed p2p application too, otherwise, your may not continue the download from where you have stopped.

In another situation, you have downloaded an executable file from the Internet and the file is situated in the virtual environment, you need to right click the yellow icon, choose Run Sandboxed-&gt;Windows Installer Service, in order to enable the executable file to installed right from the virtual environment.

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie4.jpg&quot; alt=&quot;&quot;  /&gt;

There is also option to run sandboxed email reader, right click the yellow icon, choose Run Sandboxed-&gt;Email Reader, this way, any malicious attack from your emails won&#039;t interfere with your system.

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie8.jpg&quot; alt=&quot;&quot;  /&gt;

To check what programs are running sandboxed, you just need to double click on the yellow icon, and a window will appear showing all sandboxed application, almost similar to this one below:

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie9.jpg&quot; alt=&quot;&quot;  /&gt;

If you want to terminate all sandboxed processes, just right click the yellow icon, Terminate Sandboxed Processes-&gt;in Current Sandbox or In All Sandbox, if you have more that one sandboxie running.

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie10.jpg&quot; alt=&quot;&quot;  /&gt;

&lt;!--nextpage--&gt;
&lt;strong&gt;Within The Virtual Folders&lt;/strong&gt;

To view files that is contained in the virtual environment, for example, you have downloaded a file from the net while using a sandboxed Firefox, the file will be located in this folders, just right click the yellow icon again, choose Content Of Sandbox-&gt;Explore Contents, the start browsing trough the folder.

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie11.jpg&quot; alt=&quot;&quot;  /&gt;

In case there are files in the virtual folders that you want to retrieve or bring it outside of the virtual folders, just choose Content Of Sandbox-&gt;Recover Files 

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie12.jpg&quot; alt=&quot;&quot;  /&gt;

A window will pop-up listing all the possible files to be recovered,then,you may choose to place the file to the same folder it should have been if it was downloaded outside the virtual environment (downloaded the way you use too) , by clicking Recover to Same Folder on the window. 

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie13.jpg&quot; alt=&quot;&quot;  /&gt;

But if you decided to place it somewhere else, the just click Recover to Any Folder. Another window will appear,you just need to browse to the location where you want the file to be.

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie14.jpg&quot; alt=&quot;&quot;  /&gt;

If you want to delete all the files within the virtual folders, just choose Content of Sandbox-&gt;Delete Contents.

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie15.jpg&quot; alt=&quot;&quot;  /&gt;

In case there are still files that can be recovered within the virtual folder, you will be prompted if you want recover the files or just delete them.

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie16.jpg&quot; alt=&quot;&quot;  /&gt;

After you have decided what are you going to do with the recoverable file, you will be asked whether you want to continue all files within the virtual folders. One thing you need to remember, if you have made any changes in your browser, such as bookmark a new site, while the browser is sandboxed, the bookmark will be lost if you didn&#039;t save it using extensions like Foxmark or using social bookmarks like del.icio.us.

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie17.jpg&quot; alt=&quot;&quot;  /&gt;


&lt;strong&gt;Changing the Virtual Directory&lt;/strong&gt;

Sandboxie default path for it&#039;s virtual folders are under the drive C: , and this can be a bit if problem for some of you if you made C: your Windows partition, which usually has small harddisk space, aroun 10GB only. If this is the case, then you need to reconfigure the Sandboxie.ini file, which is located in the Windows directory, or you can just double click the yellow icon, go to Configuration-&gt;Edit Configuration.

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie22.jpg&quot; alt=&quot;&quot;  /&gt;

Upon clicking on Edit Configuration, a text editor will pop-up, and what you are seeing is the content of the Sandboxie.ini file. What you need to find in this file are lines almost like this one:

[GlobalSettings]
ConfigLevel=1
BoxRootFolder=%apps%

At the BoxRootFolder line, in the %apps% area, you may enter the path that you want your virtual directory to be, lets say in drive X: and in folder Virtual, the path will be 

X:\Virtual\

Remember one thing, the configuration is case sensitif, if you put  

x:\Virtual\ 

or 

X:\virtual\

it will not work. Other than editting the SandboxINI file,you can change the folder path by going to the Sandbox Control, click Configuration-&gt;Global Settings-&gt;Set Sandbox Top Level Folder, and set your desired path there. Then, after you have edited the path, you need to reload the configuration, just double click the yellow icon again and go to Configuration-&gt;Reload Configuration, and you are done, but your setting will only affect applications running after the configuration is editted.

&lt;img src=&quot;http://www.technovice.net/uploads/Sandboxie23.jpg&quot; alt=&quot;&quot;  /&gt;

Thats all from me, i think i have covered all the basics. If you want to know more about configuring the sandboxie.ini file,  please click : &lt;a href=&quot;http://www.sandboxie.com/index.php?SandboxieIni&quot; target=&quot;_blank&quot;&gt;More Sandboxie.ini&lt;/a&gt; . Good luck and hopefully you guys aren&#039;t furious about my extra long entry. :D
 
    </content:encoded>

    <pubDate>Sun, 24 Sep 2006 08:32:08 +0800</pubDate>
    <guid isPermaLink="false">http://www.technovice.net/archives/29-guid.html</guid>
    
</item>

</channel>
</rss>