<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Cultivated Web Blog &#187; trojan</title>
	<atom:link href="http://www.cultivatedweb.com/blog/tag/trojan/feed" rel="self" type="application/rss+xml" />
	<link>http://www.cultivatedweb.com/blog</link>
	<description>Getting the most out of web and graphic design</description>
	<lastBuildDate>Sat, 05 Mar 2011 16:55:48 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Computer Security More Important Than Ever</title>
		<link>http://www.cultivatedweb.com/blog/online-security/computer-security-more-important-than-ever.html</link>
		<comments>http://www.cultivatedweb.com/blog/online-security/computer-security-more-important-than-ever.html#comments</comments>
		<pubDate>Fri, 27 Mar 2009 02:49:36 +0000</pubDate>
		<dc:creator>Mitch Cohen</dc:creator>
				<category><![CDATA[Online Security]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.cultivatedweb.com/blog/?p=120</guid>
		<description><![CDATA[This evening a friend called me after she watched a news report about the ZeuS virus/bot. Here is the text I sent her and though I would share it here.

You'll find this article on the USA Today website very interesting and educational. <a href="http://www.cultivatedweb.com/blog/online-security/computer-security-more-important-than-ever.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>This evening a friend called me after she watched a news report about the ZeuS virus/bot. Here is the text I sent her and though I would share it here.</p>
<p>You&#8217;ll find this article on the USA Today website very interesting and educational.</p>
<p><a href="http://tinyurl.com/5olver">http://tinyurl.com/5olver<br />
</a><br />
Then take a look at the blog post I wrote back in November.<br />
<a href="http://www.cultivatedweb.com/blog/category/online-security">http://www.cultivatedweb.com/blog/category/online-security</a></p>
<p>It&#8217;s about rootkits and provides links to some of the preventive measures and tools you can use. Here&#8217;s what I&#8217;m using on my PC now.</p>
<p>Signature Based AntiVirus: <strong>BitDefender</strong><br />
<a href="http://www.bitdefender.com/PRODUCT-2216-en--BitDefender-Antivirus-2009.html">http://www.bitdefender.com/PRODUCT-2216-en&#8211;BitDefender-Antivirus-2009.html</a></p>
<p>Behavior Based AntiVirus: <strong>Threatfire</strong><br />
<a href="http://www.threatfire.com/">http://www.threatfire.com/</a></p>
<p><strong>COMODO Firewall</strong><br />
This is a great firewall. It monitors inbound and outbound network traffic, unlike the firewall in Windows that I&#8217;ve read only blocks inbound traffic. Think about it. If you get a virus that tries to phone home, the Windows firewall may not stop it or notify you of it. Firewalls must monitor outbound traffic too. But COMODO is almost too good. it also monitors program behavior. I get a lot of warnings about legitimate programs creating files, trying to launch another program, or accessing memory. Maybe I just have not configured it adequately yet. I suggest you may want to consider a less technically demanding firewall. Take a look at the firewalls reviewed at <a href="http://personal-firewall-software-review.toptenreviews.com/">Top Ten Reviews</a> and see what&#8217;s available for free at <a href="http://tinyurl.com/c5dnko">Download.com</a>.<br />
<a href="http://personalfirewall.comodo.com/download_firewall.html">http://personalfirewall.comodo.com/download_firewall.html</a></p>
<p>As I mentioned, keeping ALL your software updated is an important step to thwart malicious software. I use Secunia <strong>Personal Software Inspector</strong>.<br />
<a href="http://secunia.com/vulnerability_scanning/personal/">http://secunia.com/vulnerability_scanning/personal/</a></p>
<p>I&#8217;m also running a program from TrendMicro to detect bots like the Conficker virus that&#8217;s been in the news. It&#8217;s called <strong>RUBotted.  Still in beta</strong> and free but has not caused problems. Although, it does seem to be giving me a false positive on the 404 error pages (the page that you see when a page doesn&#8217;t exist) from sites hosted with IX Web Hosting. I&#8217;m working through the problem with IX and TrendMicro.<br />
<a href="http://www.trendsecure.com/portal/en-US/tools/security_tools/rubotted">http://www.trendsecure.com/portal/en-US/tools/security_tools/rubotted</a></p>
<p>Read a review here:<br />
<a href="http://blogs.zdnet.com/security/?p=802">http://blogs.zdnet.com/security/?p=802</a></p>
<p>Finally, read this series of pages on &#8220;Ten free security utilities you should already be using&#8221;.<br />
<a href="http://content.zdnet.com/2346-12691_22-95490.html">http://content.zdnet.com/2346-12691_22-95490.html</a></p>
<p>This is a ton if info so take your time to work through it and be a responsible internet computer user. The fact that I&#8217;m still using these programs after about 6 months and don&#8217;t have any problems (as far as I know) is my testimonial and recommendation.</p>
<p>Mitch</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cultivatedweb.com/blog/online-security/computer-security-more-important-than-ever.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Does Your Computer Have the Worst Virus?</title>
		<link>http://www.cultivatedweb.com/blog/online-security/does-your-computer-have-the-worst-virus.html</link>
		<comments>http://www.cultivatedweb.com/blog/online-security/does-your-computer-have-the-worst-virus.html#comments</comments>
		<pubDate>Thu, 27 Nov 2008 18:40:56 +0000</pubDate>
		<dc:creator>Mitch Cohen</dc:creator>
				<category><![CDATA[Online Security]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.cultivatedweb.com/blog/?p=9</guid>
		<description><![CDATA[The Culprits If you&#8217;ve never heard of rootkits let alone what they are, now is the time to learn. I&#8217;ve heard of them before but never really knew how bad they can be. Not only can they hide from many &#8230; <a href="http://www.cultivatedweb.com/blog/online-security/does-your-computer-have-the-worst-virus.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<h3>The Culprits</h3>
<p>If you&#8217;ve never heard of <a href="http://en.wikipedia.org/wiki/Rootkit">rootkits</a> let alone what they are, now is the time to learn. I&#8217;ve heard of them before but never really knew how bad they can be. Not only can they hide from many of the most widely used antivirus programs, they can actually start running on your computer before your operating system even starts.</p>
<p>What&#8217;s worse is how they get into our computers. Many of the most frequently and widely used programs are the most likely targets of the criminals who spread viruses, spyware, and whatever other kind of program we don&#8217;t want, especially the programs that make use of the internet and the web. But why? Why do people make viruses? Do I really need to tell you? <strong>They do it for money.</strong> And usually their stealing it from our bank accounts and our credit cards. That&#8217;s why the bad guys find ways to take advantage of the programs we all use to inject their malware into our computers. And that&#8217;s why the responsible software companies figure out how to fix the problems and patch, or update, the software on our PCs. Some of the most common targets are:</p>
<ul>
<li><strong>web browsers</strong> such as Internet Explorer, Firefox, and Opera, among others</li>
<li><strong>office software</strong> such as Word, Excel, Thunderbird, and many more</li>
<li><strong>media programs</strong> such as Flash, Acrobat, Quicktime, and yes, other.</li>
</ul>
<p>On top of that, the <strong>software that runs on the web servers</strong> that deliver the web pages we all love is also at risk of being compromised. Hackers find ways to use parts of the server operating systems (Windows and Linux), blogging software, content management systems, forums, you name it.</p>
<h3>What To Do About It</h3>
<p>So let me tell you about what &#8220;inspired&#8221; this post. I recently learned about the Sinowal (also known as Mebroot) trojan rootkit in a couple of articles written by Woody Leonhard on the <a href="http://windowssecrets.com/">Windows Secrets website</a>. The first article, <a href="http://www.windowssecrets.com/2008/11/20/03-Dont-be-a-victim-of-Sinowal-the-super-Trojan">&#8220;Don&#8217;t be a victim of Sinowal, the super-Trojan&#8221;</a>, was posted November 20, 2008 and gives a good description of this bugger and how it spreads, infects, and steals your private information, like your bank or credit card account user name and password. Woody&#8217;s second article gets down to the business of detecting Sinowal/Mebroot, removing it, and what you can do to minimize your risk of infection.</p>
<p>There are two tools Woody recommends for us to use, F-Secure Backlight and <a href="http://secunia.com/vulnerability_scanning/personal/">Secunia Personal Software Scanner</a>. Use <a href="http://www.f-secure.com/blacklight">Backlight</a> to scan your computer to find Sinowal/Mebroot <strong>and remove it</strong>. Backlight does not need to be installed like many programs. It&#8217;s completely self-contained.  To run it in XP, just double click it. But in Vista, you need to run Backlight as the Administrator. To do this, righ-click the Backlight icon, and select &#8220;Run as Administrator&#8221; from the pop-up menu.</p>
<p>Once Backlight is done, use Secunia PSI to inspect the software on your computer to see if it is the most current and secure version available. The advantage of using PSI is that once it finds programs that are vulnurable, you can download and install the updated and secure version with just a few clicks. Without PSI you would have to open every program installed on your computer, check the version, then go to the publisher&#8217;s website to see if there&#8217;s a more recent version to download and install it. I&#8217;ve tried both these programs on my HP Pavilion dv9000 laptop running Windows Vista and was pleased with way they worked. I also ran them on my Windows XP desktop. XP users are the most at risk. Fortunately, Vista seems to be immune for the time being. Backlight and PSI ran just fine on the XP desktop and I was relieved that Backlight did not find any rootkits.</p>
<p>I urge you to <a href="http://www.windowssecrets.com/2008/11/20/03-Dont-be-a-victim-of-Sinowal-the-super-Trojan">read Woody Leonhard&#8217;s first article</a> about the Sinowal/Mebroot rootkit for a basic understanding and then <a href="http://www.windowssecrets.com/2008/11/26/03-Antivirus-tools-try-to-remove-Sinowal-Mebroot">look at the second article</a> to better understand how the tools work and how to use them.</p>
<p>Have you ever encountered this kind of problem? If you have, how about leaving a comment to share your experience? Everyone be safer.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.cultivatedweb.com%2Fblog%2Fonline-security%2Fdoes-your-computer-have-the-worst-virus.html&amp;title=Does%20Your%20Computer%20Have%20the%20Worst%20Virus%3F" id="wpa2a_2"><img src="http://www.cultivatedweb.com/blog/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.cultivatedweb.com/blog/online-security/does-your-computer-have-the-worst-virus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

