Showing posts with label computer security. Show all posts
Showing posts with label computer security. Show all posts

Anti-virus Products Mostly Ignore Windows Security Features

I recently highlighted a study which showed that most of the top software applications failed to take advantage of two major lines defense built into Microsoft Windows that can help block attacks from hackers and viruses. As it turns out, a majority of anti-virus and security products made for Windows users also forgo these useful security protections.

As I wrote last month:

Attackers usually craft software exploits so that they write data or programs to very specific, static sections in the operating system’s memory. To counter this, Microsoft introduced with Windows Vista (and Windows 7) a feature called address space layout randomization or ASLR, which constantly moves these memory points to different positions. Another defensive feature called data execution prevention (DEP) — first introduced with Windows XP Service Pack 2 back in 2004 — attempts to make it so that even if an attacker succeeds in guessing the location of the memory point they’re seeking, the code placed there will not execute or run.

These protections are available to any applications built to run on top of the operating system, and they’re designed to make it difficult for attackers to develop reliable exploits for vulnerabilities in Windows applications. As we saw last month, few top apps invoke the protections, but many readers may be surprised to learn that few anti-virus products have adopted these technologies.

I installed the trial versions of a dozen top anti-virus and security suites on a virtual machine running Windows Vista, and then checked each product’s executable files using Microsoft’s excellent process Explorer tool, which provides a mass of information about processes running on your Windows system, including whether or not those processes invoke DEP and/or ASLR.

Among the anti-virus products that used neither ASLR nor DEP were AVAST Home Edition, AVG Internet Security 9.0, BitDefender Internet Security 2010, ESET Smart Security, F-Secure Internet Security, Norton Internet Security 2010, Panda Internet Security 2010 and Trend Micro Internet Security 2010.

Microsoft Security Essentials was the only product that used both ASLR and DEP consistently on Windows Vista (although interestingly it does not invoke DEP on Windows XP). Other anti-virus suites I tested used either ASLR or DEP (or both), but only in some applications that make up the suite. For example, McAfee Internet Security’s “mcagent.exe” program runs both ASLR and DEP, while four other executable processes spawned by the program ran DEP but not ASLR (since these tests were run, McAfee has changed the trial version of MIS available on its site, and the company sent me a screen shot that shows DEP and ASLR on all running processes in that version).

Similarly, I found that the anti-virus suite from Avira ran its main avguard.exe program in ASLR mode but did not use DEP. The rest of the program files that ship with this product run neither ASLR nor DEP. Kaspersky Internet Security had DEP enabled on just one process (the browser plug-in), and did not invoke ASLR with any program components.

To be sure, DEP and ASLR are not panaceas: Security researchers have come up with a number of clever ways to bypass these protection mechanisms. Still, it’s interesting to note the lack of these features in anti-virus products for two reasons: First, even researchers who have developed exploits to work around these protections say the two technologies raise the bar significantly for malicious coders. Second, anti-virus products are not immune to a number of clever ways to bypass these protection mechanisms

I sought comment from all of the anti-virus vendors whose products I examined (except for Microsoft) and received a few responses. Most either downplayed the usefulness of the two technologies in combating today’s threats, or said that they planned to implement the protections in upcoming releases.

Mikko Hypponen from F-Secure said that “adding support for DEP and ASLR in our products is on our roadmap, but has not been implemented yet. This is because we’ve focused our development efforts lately to focus on performance. Once we have this feature ready, it will be available to all of our customers through our update channel.”

Pedro Bustamante, a senior research adviser at Panda Security, said Panda decided not to use either ASLR or DEP in favor of their own technology “to provide protection not only for the single AV processes but also for other types of operations. For example our products include a Shield component which already takes care of the protection as offered by ASLR and DEP, in addition to other types of self-protections such as preventing a process from injecting a thread into a separate process, preventing certain applications from executing dangerous operations on the system (such as Adobe Acrobat dropping an executable in the system and running it), protection of the AV files in the installation directories, etc.”

Bustamante continued: “These Microsoft technologies might be a good solution for certain types of more basic applications, but from our point of view are insufficient for an anti-malware product trying to get a more defense-in-depth approach to securing the whole OS and third party applications.”

Bitdefender said it plans to incorporate DEP and ASLR in its 2011 suite of products.

Symantec’s director of product management, Dan Nadir, said Norton Internet Security 2010 does in fact include support for DEP (although my experiments with Process Explorer showed it was not enabled) and that the company is “evaluating possible support of ASLR in future versions of our products.”

The research team from ESET responded: “Based upon the types of attacks we see against security software, and the likely attack scenarios, ASLR and DEP do not provide any significant defense. [While] enabling ASLR and DEP is quite trivial, the complexity come in assuring the proper test matrix has been implemented. Without proper testing ASLR can be weaponized…We will consider adding the features in the future, but not without extremely rigorous testing.”

Source:-krebsonsecurity.com

How to Remove Trojan without Installation of any Antivirus Software?

virus scan
Trojan is basically a software program that can perform enviable functions on your computer. In addition to this, it offers the facility to intruders to easily access your system. Trojans can get entry into your system from many methods, such as e-mail attachments, software downloads, etc.
Once any Trojan gets entry into your system, it allows remote access of your system to hacker. After getting access to your system, hacker can perform various tasks like, stealing your confidential information, installation of software, deletion or modification of files, keystroke logging, etc.
You can scan your system with Windows Live OneCare safety scanner in order to get information about malicious programs installed on your system. This scanner consists of various scan types and you can select any scan for your system. Its protection scan will check your system for Trojans viruses and other malicious software.
In addition to this, it will check for the open ports of your computer, which can make your system more vulnerable to online threats. After scanning, it will produce a report, which contains the number of files scanned, the number of infected files found, the type of infection and virus name, the number of common open ports, etc.
Another scan type of Windows Live OneCare safety scanner is clean up scan, which will find out the redundant temporary files of your system. Tune up scan will provide you the information about your hard disk drive. After scanning your system with Windows Live OneCare safety scanner, you can remove Trojans with Microsoft Windows Malicious Software Removal Tool.
This tool can check the systems running Windows 2000, Windows Server 2003, Windows XP, Windows Vista, and Windows 7 for infections and can also remove these infections. When its detection and removal process gets complete, it will display a report, which will contain information about all the malicious software detected and removed.

Install Anti-virus

Anti-virus

With the increasing pace of Internet usage worldwide, the rate at which the Computer Security systems are being infected is also increasing. Not only the users connected to Internet are infected, but the non-Internet users are also being attacked at the same rate with the use of infected portable storage devices like floppies, CD/DVD, USB flash drives and other for transferring files, data, and other documents among different computer systems.

There has been a tremendous growth in the number of malicious codes developed and spread on Internet. There has been a growth in the virus, spywares, Trojan horse, worms, adware, key loggers and other similar threats. To tackle with this increasing growth of virus and other malicious code on Internet, anti-virus software are simultaneously developed and updated.

In today’s scenario the anti-virus software comes bundled with several additional programs such as firewalls, and spyware removal tools so as to provide a higher level of security to the computer users.

The first line of defense to protect your PC is to install some good anti-virus software carrying the feature of automatic update. The reason behind installing anti-virus software with the automatic update feature is to get the latest protection against the newly released viruses and other malicious codes. The next step is to update the anti-virus with the latest virus definitions.

The install anti-virus software compares the binary code of the content stored on the computer hard disk against the database of virus definitions. When the anti-virus software detects the similar binary code of the virus on the hard disk then it report it as the presence of virus. So, if the virus definition database is updated with the latest virus definitions then your computer system will remain protected against the latest virus attacks.



BEWARE OF VIRUSES & PARASITES

By now, most computer users know that they have to protect against viruses. You need a good antivirus support program running on your computer in real time, monitoring and checking as files are accessed, as well as running periodic scans of all files. You need to use an up-to-date virus definition file with this AV program (sometimes these are updated almost every day, so automated updating is preferable). The virus protection on your computer should be so solid that there is rarely any doubt that you are virus-free — the only room for doubt being whether a new virus snuck in before your antivirus software’s manufacturer had a definition file that would catch it. If suspicious, run your AV program to check the system as part of zeroing in on a problem that suddenly develops on your computer. You can also try one or more of the free online virus scanners listed on my Parasites & Other Computer Security Issues page.

But there are also nonviral invaders that have become as big a problem as viruses. In fact (perhaps because people are less aware of these and less mindful of protecting themselves), these parasites may be an even greater risk to your computer’s proper running. Adware, spyware, browser hijackers, automatic diallers, and other forms of nonviral malware — some intentionally if misguidedly installed by the user, some foisted on you without your awareness — are, at least in a few cases, as destructive.

And, since they often are badly written, they commonly announce themselves unintentionally by breaking some functionality on the computer. Therefore, checking for these is an important early step in troubleshooting computer problems, especially if the problems appear suddenly. If there is a serious browser or Windows Explorer/My Computer problem not related to a bad or damaged browser install, failing hardware, or user error, 90% of the time the problem will be the result of one of these parasites. Because Internet Explorer is integrated into the kernel of all Windows versions after Win95, these “browser problems” can manifest as general performance degradation or error conditions in the Windows shell. If you’ve ruled out the obvious in troubleshooting browser failures, the eruption of many error messages, inability to launch programs, or sudden (in contrast to gradual) serious slowing of your computer, checking for parasites should probably be your next diagnostic step.

For an onderly seven-step approach for identifying and removing these parasitic invaders, see Quick Fix Protocol page.

Several of these parasites are intentionally added to the computer by the user because the program looks like a cool toy. For example, Hotbar is a popular browser add-on that causes big problems on most computers. Many people install Gator (now renamed Claria) to manage online passwords. People install the insidious and pernicious IEPlugin to get “faster, smarter web browsing,” and live to regret it. And so forth. Other parasites are snuck onto your computer often without your knowledge. An important early step in all troubleshooting of Windows problems, therefore, is the isolation and removal of such parasites.

 
©2009 Antivirus Support | by TNB