<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tech DC &#187; anti-virus</title>
	<atom:link href="http://www.techdc.com/tag/anti-virus/feed" rel="self" type="application/rss+xml" />
	<link>http://www.techdc.com</link>
	<description>home and office computer support for Virginia, D.C. &#38; Maryland</description>
	<lastBuildDate>Wed, 01 Sep 2010 03:06:41 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Microsoft Security Essentials 2.0 Beta</title>
		<link>http://www.techdc.com/microsoft-security-essentials-2_-beta</link>
		<comments>http://www.techdc.com/microsoft-security-essentials-2_-beta#comments</comments>
		<pubDate>Tue, 20 Jul 2010 18:22:38 +0000</pubDate>
		<dc:creator>Rick</dc:creator>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[anti-spyware]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.techdc.com/?p=2974</guid>
		<description><![CDATA[My favorite free security software for Windows is Microsoft Security Essentials from Microsoft, the folks who should be protecting their operating system.
Microsoft just came out with a beta of their next version, Microsoft Security Essentials 2.0 featuring:

Windows Firewall integration– allows you to turn on or off the Windows Firewall during setup.
Enhanced protection from web-based threats [...]]]></description>
			<content:encoded><![CDATA[<p>My favorite free security software for Windows is <a href="http://www.microsoft.com/security_essentials/" target="_blank">Microsoft Security Essentials</a> from Microsoft, the folks who should be protecting their operating system.</p>
<p>Microsoft just came out with a beta of their next version, Microsoft Security Essentials 2.0 featuring:</p>
<ul>
<li>Windows Firewall integration– allows you to turn on or off the Windows Firewall during setup.</li>
<li>Enhanced protection from web-based threats – integrates with Internet Explorer to provide improved protection against web-based attacks.</li>
<li>New protection engine – offers enhanced detection and cleanup capabilities with better performance.</li>
<li>Network inspection system – protects against network-based exploits.</li>
</ul>
<p>To get the new version, go to the <a href="http://go.microsoft.com/fwlink/?LinkId=197385" target="_blank">Microsoft Connect</a> site and fill out the beta registration information.  Then you’ll see instructions for downloading and installing the beta.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.techdc.com/microsoft-security-essentials-2_-beta/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker Arrives</title>
		<link>http://www.techdc.com/conficker-arrives</link>
		<comments>http://www.techdc.com/conficker-arrives#comments</comments>
		<pubDate>Mon, 30 Mar 2009 10:47:09 +0000</pubDate>
		<dc:creator>Rick</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[down & up]]></category>
		<category><![CDATA[down and up]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.techdc.com/?p=1743</guid>
		<description><![CDATA[Is it time to buy those boxes of ammo and head for the hills? We&#8217;ll see.
This Wednesday, April 1st the Conficker worm will do something. No one knows what. But it has security experts up late. It is believed that at one point Conficker was on 6% of the world&#8217;s PCs. This has been reduced [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.techdc.com/wp-content/uploads38454/2009/03/armageddon.jpg"><img class="alignright size-medium wp-image-1744" title="Armageddon" src="http://www.techdc.com/wp-content/uploads38454/2009/03/armageddon-300x225.jpg" alt="Armageddon" width="270" height="203" /></a>Is it time to buy those boxes of ammo and head for the hills? We&#8217;ll see.</p>
<p>This Wednesday, April 1st the <a href="http://www.techdc.com/down-up-worm-worst-ever" target="_blank">Conficker worm</a> will do something. No one knows what. But it has security experts up late. It is believed that at one point Conficker was on 6% of the world&#8217;s PCs. This has been reduced dramatically by the work of Microsoft in issuing special patches for the worm. But hundreds of thousands of PCs are still estimated to be infected.</p>
<p>Early this month, Symantec&#8217;s security researchers began noticing that the worm was changing in order to avoid steps to interrupt the worm&#8217;s links with its hacker controllers. The first versions of the worm generated a list of 250 possible domains each day that could be used to route instructions from hackers. The new edition uses a list of 50,000 URLs in order to overwhelm security researchers.</p>
<p>Typically hackers use large botnets of computers to commit distributed denial of service (DDOS) attacks against websites. The hackers will demand that large websites pay them in order to be spared.</p>
<p>If you are worried about your computers or those of people you love, you can read <a href="http://support.microsoft.com/kb/962007" target="_blank">Microsoft&#8217;s alert</a> and my <a href="http://www.techdc.com/down-up-worm-worst-ever" target="_blank">earlier post</a> on how to prevent and remove the virus.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.techdc.com/conficker-arrives/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Antivirus XP 2008 Is Bogus</title>
		<link>http://www.techdc.com/antivirus-xp-2008-is-bogus</link>
		<comments>http://www.techdc.com/antivirus-xp-2008-is-bogus#comments</comments>
		<pubDate>Fri, 24 Oct 2008 19:08:50 +0000</pubDate>
		<dc:creator>Rick</dc:creator>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[help]]></category>
		<category><![CDATA[infection]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[remove]]></category>
		<category><![CDATA[spyware]]></category>

		<guid isPermaLink="false">http://www.techdc.com/?p=964</guid>
		<description><![CDATA[A recent Sterling, Virginia customer got hit by a fake warning that her computer had been infected by a virus. But it was just a pop-up browser window that, when clicked, actually installed malware on her computer. To add insult to injury, the malware installed is called Antivirus XP 2008. So you think it&#8217;s there [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-967" title="Antivirus XP 2008 Icon" src="http://www.techdc.com/wp-content/uploads/2008/10/antivirus_xp_2008_icon.gif" alt="" width="83" height="68" />A recent Sterling, Virginia customer got hit by a fake warning that her computer had been infected by a virus. But it was just a pop-up browser window that, when clicked, actually installed malware on her computer. To add insult to injury, the malware installed is called Antivirus XP 2008. So you think it&#8217;s there to help you when in fact it IS the infection.</p>
<p><a href="http://www.techdc.com/wp-content/uploads/2008/10/antivirus_xp_2008.jpg"><img class="alignright size-medium wp-image-965" title="Antivirus XP 2008" src="http://www.techdc.com/wp-content/uploads/2008/10/antivirus_xp_2008-300x230.jpg" alt="" width="300" height="230" /></a>Antivirus XP 2008 shows a list of files that it claims are infected on your computer. See that the icons used are the same as those used by Windows. If you register the &#8220;anti-virus&#8221; software in an attempt to fix your computer, the bad guys will have your credit card information.</p>
<p>On other computers, I have seen Antivirus XP 2008 installed on the Windows Desktop background so that your wallpaper background always gave you a warning.</p>
<p>This has become a common computer problem. It is an easy scam to fall for because it looks very close to a real Windows warning.</p>
<p>This is an effective social engineering scam because people are scared of viruses and have grown accustomed to following any computer-generated prompts to remove them.</p>
<p><a href="http://www.techdc.com/wp-content/uploads/2008/10/malwarebyte.gif"><img class="alignleft size-medium wp-image-966" title="Malwarebyte Anti-Malware Software" src="http://www.techdc.com/wp-content/uploads/2008/10/malwarebyte-300x230.gif" alt="" width="270" height="207" /></a>For this particular computer, I booted into Windows Safe mode and ran <a href="http://www.malwarebytes.org" target="_blank">Malwarebyte&#8217;s Anti-malware program</a> which is free for a couple of weeks use. Luckily the infection could be removed. In some cases, the malware can actually take over all administrator rights to the computer and rewrite the operating system to the extent that the only real alternative is to save your personal files and reinstall Windows.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.techdc.com/antivirus-xp-2008-is-bogus/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Russian Gang Hijacking PCs</title>
		<link>http://www.techdc.com/russian-gang-hijacking-pcs</link>
		<comments>http://www.techdc.com/russian-gang-hijacking-pcs#comments</comments>
		<pubDate>Fri, 08 Aug 2008 13:48:30 +0000</pubDate>
		<dc:creator>Rick</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[russian gang]]></category>

		<guid isPermaLink="false">http://www.techdc.com/?p=176</guid>
		<description><![CDATA[This NY Times article talks about how a gang in a Russian town is using Microsoft administrative tools to infect private and government computers. A few excerpts:
The gang was identified publicly in May by Joe Stewart, director of malware research at SecureWorks, a computer security firm in Atlanta. Mr. Stewart, who has determined that the [...]]]></description>
			<content:encoded><![CDATA[<p>This <a href="http://www.nytimes.com/2008/08/06/technology/06hack.html" target="_blank">NY Times article</a> talks about how a gang in a Russian town is using Microsoft administrative tools to infect private and government computers. A few excerpts:</p>
<blockquote><p>The gang was identified publicly in May by Joe Stewart, director of malware research at SecureWorks, a computer security firm in Atlanta. Mr. Stewart, who has determined that the gang is based in Russia, was able to locate a central program controlling as many as 100,000 infected computers across the Internet.</p>
<p>The system infects PCs with a program known as Coreflood that records keystrokes and steals other information.</p>
<p><a href="http://www.nytimes.com/2008/08/06/technology/06hack.html"><img class="alignright size-full wp-image-177" title="Joe Stewart via NY Times" src="http://www.techdc.com/wp-content/uploads/2008/08/stewart.jpg" alt="" width="190" height="135" /></a>“The great thing about this system is that from one computer it is possible to push out updates to all machines in a corporate network at once,” Mr. Stewart said. “This is a useful tool that Microsoft has provided. However, the bad guys said, ‘We’ll just use it to roll out our Trojan to every machine in the network.’ ”</p></blockquote>
<p>The gang then uses the passwords to access your bank account and transfer out money. Scary stuff.</p>
<p>This only affects Microsoft operating systems, so Macs are safe. In order to protect PCs, I suggest using:</p>
<ul>
<li>hardware firewall (included in routers)</li>
<li>Windows Vista or XP with Service Pack 3 (latest)</li>
<li>Anti-virus software such as <a href="http://www.techdc.com/?p=82" target="_blank">AVG Free</a> or <a href="http://www.avast.com/eng/download-avast-home.html" target="_blank">Avast</a>.</li>
</ul>
<p>If you get infected by something like this Coreflood virus, you should do a <a href="http://www.techdc.com/?p=118" target="_blank">complete re-install</a> of your system.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.techdc.com/russian-gang-hijacking-pcs/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Operating System re-installs installs for virus ridden computers</title>
		<link>http://www.techdc.com/operating-system-re-installs-installs-for-virus-ridden-computers</link>
		<comments>http://www.techdc.com/operating-system-re-installs-installs-for-virus-ridden-computers#comments</comments>
		<pubDate>Mon, 04 Aug 2008 14:55:12 +0000</pubDate>
		<dc:creator>Rick</dc:creator>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[operating system]]></category>
		<category><![CDATA[os]]></category>
		<category><![CDATA[reinstall os]]></category>

		<guid isPermaLink="false">http://www.techdc.com/?p=118</guid>
		<description><![CDATA[Infections Beyond Repair

Most people say that once a machine is infected with a virus, there is no practical way to know for sure if it is ever truly safe. You could take out the drive, attach it to a Linux machine for scans, and run all the latest tools. But this doesn&#8217;t guarantee success.
Think of [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Infections Beyond Repair<br />
</strong></p>
<p><img class="alignright size-thumbnail wp-image-124" title="biohazard" src="http://www.techdc.com/wp-content/uploads/2008/08/biohazard-150x150.jpg" alt="" width="150" height="150" />Most people say that once a machine is infected with a virus, there is no practical way to know for sure if it is ever truly safe. You could take out the drive, attach it to a Linux machine for scans, and run all the latest tools. But this doesn&#8217;t guarantee success.</p>
<p>Think of it as an arms race between the virus writers and the anti-virus writers. Many viruses re-write parts of the Windows operating system. They are written specifically to sneak past popular anti-virus software, namely Norton and McAfee.</p>
<p>The solution, especially for machines with nasty viruses, is a clean install of the operating system. This can&#8217;t be done from within Windows. The important data should be backed up and the drive should be formatted and a clean install should be performed.</p>
<p>Before the old data is put back on the computer, it too should be scanned. Even documents can contain little programs (Macros) that could contain viruses.</p>
<p><strong>Client Story</strong></p>
<p>A recent client in Virginia had a computer that was badly infected. After the computer booted up, supposed anti-virus software popped up indicating that there were viruses. This was certainly true, but the anti-virus software was bogus. It just asked for his credit card info to fix the problems. If he had provided his credit card, I am sure that the virus would not have been removed. He would have probably just gotten many unauthorized charges.</p>
<p>His computer was no longer his. He had no administrator privileges. He had no &#8220;My Computer&#8221;, no CD drive, and no task manager. His system tray in the bottom right corner only had the words &#8220;VIRUS ALERT!&#8221;.</p>
<p>Without much hope, I initially tried <a href="http://www.avast.com/eng/download-avast-home.html" target="_blank">Windows is Avast! 4 Home Edition</a>.  One feature that Avast has over the previously mentioned <a href="http://www.techdc.com/?p=82">AVG</a> is the ability to scan Windows before booting into Windows machines.</p>
<p>Unfortunately, much of the operating system had been modified, so Avast could not fix it. I removed the drive, placed it in a Linux machine, backed up and scanned the important files, and then ran <a href="http://www.dban.org/" target="_blank">Darik&#8217;s Boot and Nuke</a> to wipe the drive.</p>
<p>The desktop was an HP that did not come with a restore disk, so we had to purchase another copy of Windows to install.</p>
<p>I told the customer how many viruses use social engineering to work. Messages appear in an email or browser pop-up window and they appear legitimate so users click on them. He asked me how to tell the real pop-ups for the fake ones. Without computer experience, it is very difficult to know.</p>
<p>Windows Vista has made this worse. By constantly asking people to approve even small tasks, it conditions people to just click &#8220;Okay&#8221; for everything.</p>
<p>His computer now is up and running again. It is behind a router with a firewall and has the Firefox web browser and Avast anti-virus.  Hopefully that will keep him safe from viruses and malware. At least he can rest assured that his machine is not currently hi-jacked after a clean operating system install.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.techdc.com/operating-system-re-installs-installs-for-virus-ridden-computers/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Anti-virus Software</title>
		<link>http://www.techdc.com/anti-virus-software</link>
		<comments>http://www.techdc.com/anti-virus-software#comments</comments>
		<pubDate>Sun, 27 Jul 2008 01:51:25 +0000</pubDate>
		<dc:creator>Rick</dc:creator>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[mcafee]]></category>
		<category><![CDATA[norton]]></category>

		<guid isPermaLink="false">http://www.techdc.com/?p=82</guid>
		<description><![CDATA[If you are running Windows, you should have anti-virus software. One of the best is free for personal use. It is:
AVG Anti-virus Free Edition
It includes free anti-virus updates and does a great job of finding and stopping viruses.
The only downside to AVG is that every year or so AVG comes out with an update that [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.techdc.com/wp-content/uploads/2008/07/avg-free-edition-71361_1.jpg"><img class="alignright size-thumbnail wp-image-83" title="AVG Free Edition" src="http://www.techdc.com/wp-content/uploads/2008/07/avg-free-edition-71361_1-150x150.jpg" alt="" width="150" height="150" /></a>If you are running Windows, you should have anti-virus software. One of the best is free for personal use. It is:<br />
<a href="http://free.avg.com/" target="_blank">AVG Anti-virus Free Edition</a></p>
<p>It includes free anti-virus updates and does a great job of finding and stopping viruses.</p>
<p>The only downside to AVG is that every year or so AVG comes out with an update that requires a fresh install of the new version. And on the website, you need to look for the free version. AVG does push their paid version.</p>
<p>When installing, you don&#8217;t need to install their browser plug-in which can needlessly slow things down. Instead, for safety, you should use <a href="http://www.mozilla.com/en-US/firefox/" target="_blank">Firefox</a> when browsing the Internet.</p>
<p>Compared to standard anti-virus software from Norton and McAfee, AVG does both a better job finding viruses and is less resource hungry in my opinion. Often I will find a system that is completely bogged down, not by viruses but by Norton&#8217;s rediculously large Internet Security Suite of software.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.techdc.com/anti-virus-software/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
