While each virus or worm appears to pose an individual threat to Lab computers, the real threat is the Internet itself, Computer Protection Program Manager Jim Rothfuss told members of the Computing and Communications Services Advisory Committee (CSAC) at their September meeting.
“The fundamental problem is that the Internet is the threat – the emergency is continuous,” Rothfuss said. “As a result, our protection must be continuous, not just as a response to the crisis of the week.”
As each new worm or virus appears, some of the earlier ones fall off the screen, he said. Such viruses as Code Red, Code Red 2, Nimda, Slammer and others may not be in the news, but they are still out there, scanning for vulnerabilities and attacking whenever the opportunity presents itself.
The recent spread of the SoBig.F worm was the fastest ever, infecting more than a million computers around the world in just a few days. Because of the Lab’s vigilance in maintaining its Virus Wall, only two infections were reported here – out of the 250,000 SoBig.F-infected messages aimed at LBNL.
Once a computer becomes infected, it needs to be taken off the network, have the virus removed, antivirus software updated and the security patches applied. However, because such worms and viruses spread so quickly, if the user attempts to reconnect to a network to download the patches, the machine can get infected again before the patch can be downloaded. To prevent this, the Computer Protection Program has established a procedure called “DHCP Jail,” where vulnerable computers are put in solitary confinement (in other words, cut off from the network), until the vulnerability is fixed. The owner may need to call the Help Desk (x4357) and pay for the Mac/PC Support Group to install patches or have a friend download the patches onto a CD for them.
Such measures are necessary because of the damage an unprotected computer can inflict on other LBNL systems. In the case of the Blaster worm, an infected computer was attached to the Lab network and 76 computers were infected. Subnetworks had to be blocked within the Lab to stop the spread. Cleaning up the cybermess afterward was one of the most costly computer security incidents the Lab has ever had, Rothfuss said.
Enable Automatic Updates: In Windows XP, right-click My Computer, choose Properties, Automatic Updates, and make sure that Keep my computer up to date is checked. (See this months Internet Tips for more on Automatic Updates.) Once a month (preferably just after Microsoft announces its latest security fixes), visit windowsupdate.microsoft.com, let the site scan your system, and then download anything labeled Critical. Every month, no exceptions–got it?
Turn off scripting behaviors in Internet Explorer: Many worms and viruses spread through Web page scripts (commands in the page that push the worm out to anyone who opens it in IE). Other browsers dont have this problem, but if you cant or simply wont change to Opera, Mozilla, or another browser, you must alter IEs scripting settings to block the threat.
In IE, click Tools, Internet Options, Security. Choose the Earth icon under Select a Web content zone, and click Custom Level. The settings in the dialog have three options: Disable, Enable, and Prompt. Enabling everything is asking for trouble, but being prompted every time a script or ActiveX control wants to run will drive you batty. In any event, disable Download unsigned ActiveX controls, Initialize and script ActiveX controls not marked as safe, Active scripting, and Scripting of Java applets (see FIGURE 1 ). Set Java permissions to High Safety.
With scripts disabled, many of your favorite Web sites may not open. Also, your company intranet or Web mail service may require scripting. If so, add the URLs for these sites and services to IEs Trusted Sites list. Open IE and click Tools, Internet Options, Security. Select the Trusted Sites icon, click Sites, and then enter the URLs one at a time. Uncheck Require server verification (https:) for all sites in this zone, and click OK (see FIGURE 2 ).
Control what starts up with Windows: Many worms place a reference to themselves in a portion of the Windows Registry that defines what programs start up with Windows. The TeaTimer applet that comes bundled with Spybot Search & Destroy 1.3 and with WinPatrol can control what gets added to this list. TeaTimer asks you to verify any program that seeks to be added to that list. Spybot and WinPatrol are free, so why not use both?
Use a software and a hardware firewall: If you have broadband Internet service–even if you have Zone Labs free ZoneAlarm or some other software firewall active on your PC–you cant be too safe. Belkin, D-Link, Linksys, and other vendors sell inexpensive broadband gateways that bounce back worm attacks that otherwise would reach your computer.
Proactive Malware Prevention With Qwik-Fix
In early tests, PivXs Qwik-Fix Pro was successful in preventing malicious scripted Web pages from forcing Internet Explorer to load worms or spyware. The tool provides stopgap protection so that your system doesnt get infected while youre trying to download patches. Qwik-Fix Pro is free for noncommercial use, and businesses should be able to buy the corporate version by the time you read this.
Andrew Brandt is a senior associate editor for PC World and the author of the monthly Privacy Watch column.
Related posts:
- kaspersky internet security 2009Kaspersky Internet Security 2009 * Protects from viruses, Trojans, worms, spyware, adware * Scans files, email, and Internet traffic * Protects instant messengers * Protects from unknown threats * Analyzes and closes Internet Explorer vulnerabilities * Disables links to malware sites / phishing sites * Global Threat Monitoring (Kaspersky Security Network) * Blocks all types [...]...
- Remove Virus from USB Drives -autorun Viruses removal killerOne of the ways by which a virus can infect your PC is through USB/Pen drives. Common viruses such as ’Ravmon’ , ‘New Folder.exe’, ‘Orkut is banned’ etc are spreading through USB drives. Most anti virus programs are unable to detect them and even if they do, in most cases they are unable to delete [...]...
- تحميل كاسبر سكاي 2010 الجديد مجانا kaspersky internet security 2010تحميل كاسبر سكاي 2010 الجديد مجانا kaspersky internet security 2010 كاسبر سكاي 2010 للتحميل Kaspersky انتي فايروس مجاني كامل صدقني لن ترضى _ بديل لهذا البرنامج وهذا بعد تجربة جميع المكافحات .. _ والتجربة خير برهان !! أفضل ما انتجته شركة كاسبر وهو الوحش الروسي...
- Protected USB Drives – Target for Virus InfectionsBecause thumb drives are so popular and generally get used to move data between multiple systems frequently, especially in the IT world, they are also a prime target for attackers as means to get infections spread around with you doing most of the work for them. Although a lot of work places ban the use [...]...
- WinPC Antivirus download – WinPC DefenderWinPC Antivirus is a rogue program from the same family as WinPC Defender. This program is advertised through the use of malware that displays fake security alerts and pop-ups on your computer. These alerts state that your computer is infected and that you should download and install WinPC Antivirus in order to clean your computer. [...]...
- download Rising Antivirus 2009 Free Edition exe msi setupPublishers description of Rising Antivirus 2009 Free Edition RISING Antivirus Free Edition protects your computers against all types of viruses, Trojans, Worms, Rootkits and other malicious programs. Easy to use, Active Defense technology, Patented Unknown Virus Scan and Clean technology and Patented Smartupdate technology make RISING Antivirus install and forget product and entitles you to [...]...
- McAfee VirusScan 2008McAfee is an industry leader in computer protection and VirusScan is their #1 defense against viruses. This software comes with a ScriptStopper to prevent viruses from propagating from one computer to another via email, and WormStopper.Some downsides to the program are that it doesnt provide instant message protection, P2P/file sharing protection or registry startup protection. [...]...
- remove a Trojan, Virus, Worm, or other MalwareAdware - A program that generates popups on your computer or displays advertisements. It is important to note that not all adware programs are necessarily considered malware. There are many legitimate programs that are given for free that display ads in their programs in order to generate revenue. As long as this information is provided up front then they are generally not considered malware...
- Avira AntiVir Personal – Free Antivirus downloadAntivirus is a comprehensive, easy to use antivirus program, designed to offer reliable free of charge virus protection to home-users only. Avira offers: Extensive Malware Recognition of viruses, Trojans, backdoor programs, worms, etc. Automatic incremental updates of antivirus signatures, engine and entire software. Permanent virus protection, with Virus Guard real time monitoring. Install and configuration [...]...
- Norton AntiVirus 2008 download free + reviewsBeing VB100%, W.C.L 1 and 2, as well as ICSA certified means that Norton Antivirus 2008 is equipped to handle all of your virus scanning needs. The scanner has proven to 3 independent labs that it has the ability to detect and remove viruses and variants of all viruses that the Norton virus engine was tested against. The antispyware capabilities of Norton Antivirus 2008 were less effective than the virus scanner. It missed all of our tests while finding only a single tracking cookie on our whole test system....
- avira antivir personal en 2010Antivirus is a comprehensive, easy to use antivirus program, designed to offer reliable free of charge virus protection to home-users only. Avira offers: Extensive Malware Recognition of viruses, Trojans, backdoor programs, worms, etc. Automatic incremental updates of antivirus signatures, engine and entire software. Permanent virus protection, with Virus Guard real time monitoring. Install and configuration in just a couple of steps. Virus protection against known and unknown threats, using an advanced heuristic system. Scheduler where you can set the scanner to make automatic virus scans or updates on your system. Forum and phone support, Knowledge Base with virus descriptions available on web site. Vista Support. Rootkit Detection and Removal. Version 8 adds an enhanced interface, a modularized AV-search engine for improved scan performance, an integrated failsafe security system, and SMTP support for AntiVir MailGuard....
- كاسبر سكاي 2010 للتحميل Kaspersky انتي فايروس مجاني كاملكاسبر سكاي 2010 للتحميل Kaspersky انتي فايروس مجاني كامل يعد واحدة من اشهر وافضل برامج مكافحة الفيروسات ,حيث يقوم بتحديث البرنامج على فترات متتالية ويكتشف ويحذف احدث الفيروسات اوخطرها مما جعله يحتل المناصب الاولى فى مجال حماية الحواسيب برنامج كاسبر سكاى للتحميل كاسبر سكاي key كاسبر سكاي انتي فايروس مفاتيح كاسبر سكاي...
- AVG Anti-Virus Free Edition downloadAVG Free Edition is the well-known antivirus protection tool. AVG Free is available free of charge to home users for the life of the product. Rapid virus database updates are available for the lifetime of the product, thereby providing the high level of detection capability that millions of users around the world trust to protect their computers. AVG Free is easy to use and will not slow your system down (low system resource requirements. Highlights include automatic update functionality, the AVG Resident Shield, which provides real-time protection as files are opened and programs are run, free Virus Database Updates for the lifetime of the product, and AVG Virus Vault for safe handling of infected files.Version 8.0.1 adds integrated spyware protection and a new LinkScanner feature that gives users safety rankings for their Google, Yahoo, and MSN searches...
- برنامج التحميل من الإنترنت Internet Download ManagerDont let the dull name fool you: Internet Download Manager is a full-featured package that handles downloading tasks with aplomb. It conveniently integrates into your browser, even if you use Mozilla or Opera. برنامج التحميل من الإنترنت Internet Download Manager...
- Removing Happy99.exe (ska) virusThis Happy99.exe (ska) virus or worm as it is better described, This worm is attached to newsgroup and e-mail messages as an attachment called Happy99.exe. You cannot get infected with this virus just by reading a newsgroup or e-mail message. You have to execute the attachment by opening it. Generally, the person who sent it [...]...