<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7085617280006501022</id><updated>2012-01-22T23:29:17.660+05:30</updated><category term='Windows XP'/><category term='Mcafee antivirus'/><category term='Windows Vista'/><category term='tweak dsl'/><category term='runalyzer'/><category term='firewalls'/><category term='Secure deletion'/><category term='Win32 Sality.aa'/><category term='virus removal'/><category term='Kamsoft virus removal'/><category term='disable usb storage'/><category term='regalyzer'/><category term='Browser hijacking'/><category term='hide ip'/><category term='chat encryption'/><category term='Data Encryption softwares'/><category term='XP security settings'/><category term='Disable Autorun feature'/><category term='security softwares'/><category term='rootkit removal tools'/><category term='Secunia Patches'/><category term='windows 7 security center fix'/><category term='Windows 7'/><title type='text'>Windows virus removal and information security blog</title><subtitle type='html'>Network security and virus removal</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>29</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-6388360565026333282</id><published>2011-07-30T15:31:00.003+05:30</published><updated>2011-07-30T16:26:20.459+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus removal'/><category scheme='http://www.blogger.com/atom/ns#' term='windows 7 security center fix'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows 7'/><title type='text'>Miscellaneous fixes for Windows 7 after cleaning a malware or virus infection</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;This post contains various fixes to restore default functionality of the services and other programs in Windows 7 after removal of infections &lt;br /&gt;&lt;br /&gt;Sometimes after removal of malware or virus infection, the security center service might get disabled. If we try to start the service it gives an error "Error 1058: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.". This usually happens because of two reasons&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-H_BI47uqueY/TjOlLoX1HxI/AAAAAAAAAJo/OvVQ0mK79tk/s1600/Action+center.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="146" src="http://4.bp.blogspot.com/-H_BI47uqueY/TjOlLoX1HxI/AAAAAAAAAJo/OvVQ0mK79tk/s320/Action+center.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;1. The Service is Disabled.&lt;br /&gt;2. The Service has a corrupted or incorrect registry setting.&lt;br /&gt;&lt;br /&gt;We can resolve this in three ways&lt;br /&gt;&lt;br /&gt;1. Check the necessary service through Services.msc by typing this through the "Start Search Option" and selecting it. Look for the Service needed to be Started. In your case this should be Security Center. The Status should be "&lt;b&gt;Started&lt;/b&gt;" and &lt;b&gt;Startup Type&lt;/b&gt; should be "&lt;b&gt;Automatic (Delayed Start)&lt;/b&gt;".&lt;br /&gt;&lt;br /&gt;2. Go to &lt;b&gt;Start-&amp;gt; type cmd in Search&lt;/b&gt;&lt;b&gt;-&amp;gt;&lt;/b&gt;&lt;b&gt; right click on cmd&lt;/b&gt;&lt;b&gt;-&amp;gt;&lt;/b&gt;&lt;b&gt; select run as administrator&lt;/b&gt;&lt;b&gt;-&amp;gt;&lt;/b&gt;&lt;b&gt;we will have command prompt running under administrator privileges&lt;/b&gt;&lt;b&gt;-&amp;gt;&lt;/b&gt;&lt;b&gt; Type sfc /scannow at the prompt and press enter.&lt;/b&gt;Wait for it to finish then restart.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;3. Download and apply this &lt;b&gt;REG&lt;/b&gt; fix which reinstates the missing Security Center service:&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="http://www.mediafire.com/?8kj92804xdk1jt1"&gt;Windows 7 32 bit fix&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.mediafire.com/?s9budr1vcbks23b"&gt;Windows 7 64 bit fix&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt;&amp;nbsp; If&amp;nbsp; Remote Procedure Call (RPC) service is not starting or missing from services tab please use these fixes&lt;br /&gt;&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="http://www.mediafire.com/?0vw78hx77pv34z4"&gt;Windows 7 32 bit fix&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.mediafire.com/?6bozmbradmj322u"&gt;Windows 7 64 bit fix&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt;&amp;nbsp;If&amp;nbsp; Windows installer service is missing please use this fix&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt; &lt;a href="http://www.mediafire.com/?zf2fh52u5br6ujc"&gt;Windows 7 installer fix&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&amp;nbsp;If we get &lt;b&gt;Error 1719 Windows Installer Service Could Not be Accessed&lt;/b&gt;, when installing applications. Please use this fix&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&amp;nbsp;&lt;a href="http://www.mediafire.com/?6edrczcrn942d6b"&gt;Windows 7 installer fix&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;For Windows 7 file association fixes visit this &lt;a href="http://www.winhelponline.com/blog/file-asso-fixes-for-windows-7/"&gt;link&lt;/a&gt;&lt;br /&gt;For Vista file association fixes visit this &lt;a href="http://www.winhelponline.com/articles/105/1/File-association-fixes-for-Windows-Vista.html"&gt;link&lt;/a&gt;&lt;a href="http://www.winhelponline.com/articles/105/1/File-association-fixes-for-Windows-Vista.html"&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;If we accidentally falsely associate .lnk files or shortcuts with some other application in Vista or windows 7 Use this utility to unassociate the filetypes&lt;br /&gt;&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="http://www.winhelponline.com/downloadattachment.php?aId=c060d239de9af876a20a6374973bb60a&amp;amp;articleId=231"&gt;Author's site&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.mediafire.com/?hglo24l9f3scnap"&gt;Mediafire mirror&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&amp;nbsp;If a virus or malware hides all files and folders in vista or windows 7 use this command to unhide the files and folders&lt;br /&gt;&lt;br /&gt;Open command prompt as administrator and type this command &lt;b&gt;attrib - s -h -r /s /d&lt;/b&gt; after this is done (please hide the system files back if it is root drive).&lt;br /&gt;&lt;br /&gt;Sometimes after malware infection the start menu program shortcuts are deleted to user's temporary folder hence before deleting the temporary folder contents, please search for *.lnk in temporary folder and restore the .lnk files back to start menu programs folder.&lt;br /&gt;&lt;br /&gt;Internet explorer DLL registration batch file scripts for&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;open in new tab/window not working&lt;/li&gt;&lt;li&gt;Find on this page "empty"&lt;/li&gt;&lt;li&gt;tabs on Favorites pane missing&lt;/li&gt;&lt;li&gt;about screen and other dialogs "empty"&lt;/li&gt;&lt;li&gt;IE8 closes immediately (not if caused by an add-on!)&lt;/li&gt;&lt;li&gt;can't print (interface not registered)&lt;/li&gt;&lt;/ul&gt;Please visit:&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="http://iefaq.info/index.php?action=artikel&amp;amp;cat=48&amp;amp;id=133&amp;amp;artlang=en"&gt;Author's site&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.mediafire.com/?idqyonz8dslde"&gt;Mirror&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-6388360565026333282?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/6388360565026333282/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=6388360565026333282' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/6388360565026333282'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/6388360565026333282'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2011/07/miscellaneous-fixes-for-windows-7-after.html' title='Miscellaneous fixes for Windows 7 after cleaning a malware or virus infection'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-H_BI47uqueY/TjOlLoX1HxI/AAAAAAAAAJo/OvVQ0mK79tk/s72-c/Action+center.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-8028912868035296333</id><published>2010-04-17T04:06:00.002+05:30</published><updated>2010-05-06T01:10:29.552+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows 7'/><title type='text'>Windows update gives an error 80072EFD in Windows Vista and error 8024402C in Windows 7</title><content type='html'>You may sometimes receive an  error "Windows could not search for new updates" with an error code &lt;b&gt;80072EFD&lt;/b&gt; in Windows vista or error code &lt;b&gt;8024402C&lt;/b&gt; in Windows 7 while checking for windows updates. &lt;br /&gt;&lt;br /&gt;You may experience temporary internet connection loss when you try to use windows update on an office laptop over a direct internet connection at home. This might be due to configuration of proxy in internet explorer or if internet connection is working in internet explorer but you still receive error &lt;b&gt;80072EFD&lt;/b&gt; in Windows vista and &lt;b&gt;8024402C&lt;/b&gt; in Windows 7. This might be caused due to an independent proxy configured for windows update in Vista and Windows 7 which is not dependent on internet explorer proxy.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_LM6_hkmgEAk/S8jcNQ8X-UI/AAAAAAAAAHU/D0pKl8bFfts/s1600/Untitled.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="225" src="http://3.bp.blogspot.com/_LM6_hkmgEAk/S8jcNQ8X-UI/AAAAAAAAAHU/D0pKl8bFfts/s320/Untitled.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="" style="clear: both; text-align: left;"&gt;To fix the error &lt;b&gt;80072EFD&lt;/b&gt;, we need to disable the proxy for windows update using command prompt.&lt;/div&gt;&lt;div class="" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_LM6_hkmgEAk/S8jevMnp_bI/AAAAAAAAAHk/MPNivpMICaI/s1600/Untitled.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="201" src="http://4.bp.blogspot.com/_LM6_hkmgEAk/S8jevMnp_bI/AAAAAAAAAHk/MPNivpMICaI/s400/Untitled.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_LM6_hkmgEAk/S8jdG5i5hqI/AAAAAAAAAHc/9hekd1L9hxc/s1600/Untitled.jpg"&gt;&lt;/a&gt;Click on start and type &lt;b&gt;cmd&lt;/b&gt;. Right click on &lt;b&gt;cmd&lt;/b&gt; and click on &lt;b&gt;Run as administrator&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;Type &lt;b&gt;netsh winhttp show proxy&lt;/b&gt;.&lt;br /&gt;if there is a proxy configured type&lt;b&gt; netsh winhttp reset proxy&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;It will say direct access&lt;no proxy="" server=""&gt;, now you have direct access for windows update without a proxy.&lt;/no&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Also there is a KB article from Microsoft for windows update proxy issue.&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/836941"&gt;http://support.microsoft.com/kb/836941&lt;br /&gt;&lt;/a&gt;&lt;a href="http://support.microsoft.com/kb/836941"&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-8028912868035296333?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/8028912868035296333/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=8028912868035296333' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/8028912868035296333'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/8028912868035296333'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2010/04/windows-update-gives-error-80072efd-in.html' title='Windows update gives an error 80072EFD in Windows Vista and error 8024402C in Windows 7'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_LM6_hkmgEAk/S8jcNQ8X-UI/AAAAAAAAAHU/D0pKl8bFfts/s72-c/Untitled.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-9048314962576122374</id><published>2010-01-28T20:55:00.003+05:30</published><updated>2010-01-28T21:01:32.645+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus removal'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows XP'/><title type='text'>Double click on drive in My Computer opens Search or shows Open With in Windows XP</title><content type='html'>Sometimes double clicking on drive shows "open with" window as shown in the image&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_LM6_hkmgEAk/S2GkQnZRxXI/AAAAAAAAAGk/_LRwQnDcMr8/s1600-h/my+comp.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_LM6_hkmgEAk/S2GkQnZRxXI/AAAAAAAAAGk/_LRwQnDcMr8/s320/my+comp.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;&amp;nbsp;To fix this issue:&lt;/b&gt; &lt;br /&gt;&lt;br /&gt;&lt;b&gt;Go to Start menu | Run&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Type Regedit&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Navigate to &lt;b&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2&lt;/b&gt; as shown in the image&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_LM6_hkmgEAk/S2GlEc9QysI/AAAAAAAAAGs/uYJGO263FKM/s1600-h/regedit.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="249" src="http://1.bp.blogspot.com/_LM6_hkmgEAk/S2GlEc9QysI/AAAAAAAAAGs/uYJGO263FKM/s320/regedit.JPG" width="320" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{30bd6510-e969-11de-a5e9-806d6172696f}&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Delete&lt;/b&gt;&amp;nbsp; &lt;b&gt;{30bd6510-e969-11de-a5e9-806d6172696f} in the above key.&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Delete all keys that start with &lt;b&gt;{.........}&lt;/b&gt; with + sign beside them (CLSID values) under &lt;b&gt;Mountpoints2.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Search Window opens when you double click on a drive&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_LM6_hkmgEAk/S2Gm9c29YdI/AAAAAAAAAG8/zJQZEzB-4p0/s1600-h/search.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_LM6_hkmgEAk/S2Gm9c29YdI/AAAAAAAAAG8/zJQZEzB-4p0/s320/search.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Sometimes double clicking on a drive in My Computer opens "Search" Window as shown in the image&lt;br /&gt;&lt;br /&gt;&lt;b&gt;To resolve this&lt;/b&gt;:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_LM6_hkmgEAk/S2GmqYF0PUI/AAAAAAAAAG0/lv5yQlh7jX0/s1600-h/searchreg.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_LM6_hkmgEAk/S2GmqYF0PUI/AAAAAAAAAG0/lv5yQlh7jX0/s320/searchreg.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;To fix this:&lt;/b&gt; &lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;Go to Start | Run Type regedit&lt;/b&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt; &lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Navigate to &lt;b&gt;HKEY_CLASSES_ROOT\Drive\shell &lt;/b&gt;as shown in the image&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;In the right window pane locate the value &lt;b&gt;Default&amp;nbsp; REG_SZ&amp;nbsp; find&lt;/b&gt;&lt;br /&gt;Double click on the value and change it to &lt;b&gt;none&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-9048314962576122374?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/9048314962576122374/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=9048314962576122374' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/9048314962576122374'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/9048314962576122374'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2010/01/double-click-on-drive-in-my-computer.html' title='Double click on drive in My Computer opens Search or shows Open With in Windows XP'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_LM6_hkmgEAk/S2GkQnZRxXI/AAAAAAAAAGk/_LRwQnDcMr8/s72-c/my+comp.JPG' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-8140781068637854748</id><published>2010-01-26T12:49:00.004+05:30</published><updated>2010-01-28T21:01:32.646+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus removal'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows XP'/><title type='text'>Enabling registry, task manager, folder options without the help of third party softwares</title><content type='html'>Some times registry and task manager are disabled by virus or malware programs, if you do not have a third party tools to enable it, use the &lt;b&gt;reg&lt;/b&gt; command to enable them.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;For Windows XP Home&lt;/b&gt; &lt;br /&gt;&lt;br /&gt;Copy and paste the below command in&lt;b&gt; Start -&amp;gt; Run&lt;/b&gt; for task manager&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Copy and paste the following command in &lt;b&gt;Start-&amp;gt; Run&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Copy and paste the following commands in &lt;b&gt;Start-&amp;gt; Run&lt;/b&gt; for enabling folder options&lt;br /&gt;&lt;br /&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoFolderOptions /t REG_DWORD /d 0 /f&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;REG add HKLM\Software\Microsoft\Windows\CurrentVersion\Policies&lt;span style="font-size: small;"&gt;\Explorer /v NoFolderOptions /t REG_DWORD /d 0 /f&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;For Windows XP Professional (Using the Group Policy Editor)&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;For Enabling registry&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Click Start, Run and type gpedit.msc and press ENTER&lt;br /&gt;&lt;br /&gt;Go to the following location:&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;User Configuration-&amp;gt;Administrative Templates -&amp;gt; System &lt;br /&gt;&lt;br /&gt;(Only to reverse virus effects)&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Double-click Disable registry editing tools and set it to Disabled then Enabled and then Not configured.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;For Task Manager&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Click Start, Run, type &lt;b&gt;gpedit.msc&lt;/b&gt; and click OK.&lt;br /&gt;&lt;br /&gt;Go to the following location:  &lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;User Configuration -&amp;gt;Administrative Templates -&amp;gt; System -&amp;gt; Ctrl+Alt+Delete Options- &amp;gt;Remove Task Manager&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&lt;b&gt;Double-click Disable registry editing tools and set it to Disabled then Enabled and then Not configured.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;For Folder options &lt;br /&gt;&lt;/b&gt;&lt;br /&gt;Start-&amp;gt;Run-&amp;gt;&lt;b&gt;gpedit.msc&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt; Navigate to User Configuration -&amp;gt; Administrative Templates-&amp;gt; Windows Components-&amp;gt;Windows Explorer.&lt;br /&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Remove the Folder Options menu item from the Tools Menu&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Double-click Disable registry editing tools and set it to Disabled then Enabled and then Not configured.&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-8140781068637854748?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/8140781068637854748/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=8140781068637854748' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/8140781068637854748'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/8140781068637854748'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2010/01/enabling-registry-task-manager-folder.html' title='Enabling registry, task manager, folder options without the help of third party softwares'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-4935279187792876130</id><published>2009-12-12T13:41:00.002+05:30</published><updated>2009-12-12T13:49:14.836+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='Secunia Patches'/><title type='text'>Secunia PSI detected PowerPoint viewer 2007 as an insecure program on a fully patched Microsoft Windows system</title><content type='html'>Secunia PSI detected C:\Program Files\Microsoft Office\Office12\PPTVIEW.EXE was insecure on a fully patched Windows operating system. I have Office 2007 Enterprise SP2 fully patched on my system. I was not able to get the update from Windows update site either. I downloaded and tried installing "Security Update for PowerPoint Viewer 2007 (KB970059)" but it said &lt;b&gt;"There are no products affected by this package installed on this system".&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_LM6_hkmgEAk/SyNFzpitGlI/AAAAAAAAAFc/Ppk9nBsr-EM/s1600-h/untitled.bmp"&gt;&lt;img src="http://1.bp.blogspot.com/_LM6_hkmgEAk/SyNFzpitGlI/AAAAAAAAAFc/Ppk9nBsr-EM/s320/untitled.bmp" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So I visited Secunia forums and searched for solution. In one of the threads there was a solution mentioned which worked for me.&lt;br /&gt;&lt;br /&gt;First rename the present version of &lt;b&gt;PPTVIEW.EXE &lt;/b&gt;to&lt;b&gt; PPTVIEW.EXE_OLD in "C:\Program Files\Microsoft Office\Office12\"&lt;/b&gt; then download 7-zip from &lt;a href="http://www.filehippo.com/download_7-zip"&gt;http://www.filehippo.com/download_7-zip&lt;/a&gt; and install it. Now download &lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=141b8338-5c52-4326-a9e4-d2f2d8940d9c&amp;amp;displaylang=en"&gt;&lt;b&gt;Security Update for PowerPoint Viewer 2007 (KB970059)&lt;/b&gt;&lt;/a&gt; . Right click on the downloaded file on the desktop -&amp;gt; scroll down to 7Zip and select &lt;b&gt;Extract to as &lt;/b&gt;shown in the image&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_LM6_hkmgEAk/SyNNILCLKDI/AAAAAAAAAF0/RtuBtIvCeYs/s1600-h/New+Picture.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_LM6_hkmgEAk/SyNK6rjHRsI/AAAAAAAAAFk/wdaZlo-2rAQ/s1600-h/untitled.bmp" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_LM6_hkmgEAk/SyNK6rjHRsI/AAAAAAAAAFk/wdaZlo-2rAQ/s320/untitled.bmp" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_LM6_hkmgEAk/SyNL2a9F5II/AAAAAAAAAFs/RwZIVbZ5iI4/s1600-h/untitled.bmp" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_LM6_hkmgEAk/SyNL2a9F5II/AAAAAAAAAFs/RwZIVbZ5iI4/s320/untitled.bmp" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_LM6_hkmgEAk/SyNK6rjHRsI/AAAAAAAAAFk/wdaZlo-2rAQ/s1600-h/untitled.bmp" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_LM6_hkmgEAk/SyNNILCLKDI/AAAAAAAAAF0/RtuBtIvCeYs/s1600-h/New+Picture.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_LM6_hkmgEAk/SyNNILCLKDI/AAAAAAAAAF0/RtuBtIvCeYs/s320/New+Picture.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Then find &lt;b&gt;PPTVIEW.EXE_0001&lt;/b&gt;in the extracted files and rename it to&lt;b&gt; PPTVIEW.EXE&lt;/b&gt;.&lt;br /&gt;Copy and paste it in the following location &lt;b&gt;C:\Program Files\Microsoft Office\Office12\&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;Now rescan entire system with Secunia PSI it should show powerpoint viewer 2007 in the patched programs list. Visit &lt;a href="http://secunia.com/community/forum/thread/show/2624/insecure_but_can_t_get_the_update"&gt;http://secunia.com/community/forum/thread/show/2624/insecure_but_can_t_get_the_update&lt;/a&gt; for more information on this patch.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_LM6_hkmgEAk/SyNL2a9F5II/AAAAAAAAAFs/RwZIVbZ5iI4/s1600-h/untitled.bmp" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_LM6_hkmgEAk/SyNL2a9F5II/AAAAAAAAAFs/RwZIVbZ5iI4/s1600-h/untitled.bmp" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_LM6_hkmgEAk/SyNK6rjHRsI/AAAAAAAAAFk/wdaZlo-2rAQ/s1600-h/untitled.bmp" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-4935279187792876130?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/4935279187792876130/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=4935279187792876130' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/4935279187792876130'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/4935279187792876130'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2009/12/secunia-psi-detected-powerpoint-viewer.html' title='Secunia PSI detected PowerPoint viewer 2007 as an insecure program on a fully patched Microsoft Windows system'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_LM6_hkmgEAk/SyNFzpitGlI/AAAAAAAAAFc/Ppk9nBsr-EM/s72-c/untitled.bmp' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-2707845508504787615</id><published>2009-11-08T17:46:00.001+05:30</published><updated>2009-11-08T18:56:03.426+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='Mcafee antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='security softwares'/><title type='text'>Free 3 user mcafee virus scan plus 2010 trial license for one year</title><content type='html'>Mcafee is offering a free 12 month trial of its product 3 user Mcafee Virus scan plus 2010 This promotional offer has been started by vmware. To get Mcafee trial visit this link &lt;a href="http://us.mcafee.com/en-us/affiliates/vmware/landingpages/16288.asp?cid=48523"&gt;http://us.mcafee.com/en-us/affiliates/vmware/landingpages/16288.asp?cid=48523&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_LM6_hkmgEAk/SvazDZU7j7I/AAAAAAAAAFE/sx40bUOcXJA/s1600-h/New+Picture.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_LM6_hkmgEAk/SvazDZU7j7I/AAAAAAAAAFE/sx40bUOcXJA/s320/New+Picture.bmp" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Click on the &lt;b&gt;Download trial&lt;/b&gt; button&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_LM6_hkmgEAk/Sva0BOJXA_I/AAAAAAAAAFM/UPNbteK2UVU/s1600-h/New+Picture+%282%29.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_LM6_hkmgEAk/Sva0BOJXA_I/AAAAAAAAAFM/UPNbteK2UVU/s320/New+Picture+%282%29.bmp" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Create an account by filling in details and click &lt;b&gt;I agree&lt;/b&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt; &lt;a href="http://4.bp.blogspot.com/_LM6_hkmgEAk/Sva1fbzSkTI/AAAAAAAAAFU/0qW7ZRf67P8/s1600-h/New+Picture+%283%29.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_LM6_hkmgEAk/Sva1fbzSkTI/AAAAAAAAAFU/0qW7ZRf67P8/s320/New+Picture+%283%29.bmp" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Click on &lt;b&gt;Download&lt;/b&gt; button and again click on &lt;b&gt;Download&lt;/b&gt; button your mcafee product installation will start automatically in internet explorer if it is firefox you have to double click on &lt;b&gt;dmsetup.exe &lt;/b&gt;file which will start installation of Mcafee.&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-2707845508504787615?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/2707845508504787615/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=2707845508504787615' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/2707845508504787615'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/2707845508504787615'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2009/11/free-3-user-mcafee-virus-scan-plus-2010.html' title='Free 3 user mcafee virus scan plus 2010 trial license for one year'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_LM6_hkmgEAk/SvazDZU7j7I/AAAAAAAAAFE/sx40bUOcXJA/s72-c/New+Picture.bmp' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-6740862259955485171</id><published>2009-10-09T13:10:00.007+05:30</published><updated>2009-10-09T14:31:35.544+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='Browser hijacking'/><title type='text'>Preventing browser hijacks</title><content type='html'>&lt;b&gt;Browser hijacking&lt;/b&gt; is one of the methods of taking control of internet browser by installing unknown addons without any approval. This technique can be used to install malicious software that monitors your browsing habits or to send some sensitive personal information to hackers or to redirect your search to a malicious website which in turn will&amp;nbsp; lead to installation of malware onto the computer.&lt;br /&gt;&lt;br /&gt;Home page change, URL redirection, hyperlink redirection, Changes in the hosts file, lots of pop ups which may include obscene pop ups are symptoms of a browser hijack.You may not be able to browse security related websites and&amp;nbsp;it may also lead to DNS Hijack. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Browser hijacking software&amp;nbsp;may install&amp;nbsp;itself as a legitimate program and take complete control of your system. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;Prevention tips: &lt;/b&gt;&lt;br /&gt;&lt;br /&gt;To prevent browser hijacking you need to be little cautious while installing freeware or shareware programs as these programs are bundled with unwanted toolbars and addons. &lt;br /&gt;&lt;ul&gt;&lt;li&gt;Enable automatic update and keep your computer up to date.&lt;/li&gt;&lt;li&gt;Install Antivirus or Antispyware programs like Ad-aware or Spybot if you have windows defender make sure it is up to date.&lt;/li&gt;&lt;li&gt;Most of the browsers now come with internal phishing filters which will enable you to identify a fake website from legitimate ones, so make sure phishing filter is enabled in your browser.&lt;/li&gt;&lt;li&gt;Use a good anti-virus which has features like on demand scan, real time protection,  real time scanner, anti phishing, web browser protection.Make sure your antivirus is up to date.&lt;/li&gt;&lt;li&gt;Make sure Internet explorer is running in protected mode.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;if your browser is already hijacked you can use these tools to reset the registry entries:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Autoruns&lt;/b&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Hijack this&lt;/b&gt;&lt;/li&gt;&lt;/ul&gt;For more information on these tools please visit &lt;a href="http://infosecurityhub.blogspot.com/2009/08/utilities-for-tracking-malware-hiding.html"&gt;http://infosecurityhub.blogspot.com/2009/08/utilities-for-tracking-malware-hiding.html&lt;/a&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;b&gt; &lt;br /&gt;&lt;/b&gt;&lt;br /&gt;Also you can refer to this link for more tools:&amp;nbsp;&lt;a href="http://aumha.org/a/parasite.htm"&gt;http://aumha.org/a/parasite.htm&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://infosecurityhub.blogspot.com/2009/08/utilities-for-tracking-malware-hiding.html"&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-6740862259955485171?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/6740862259955485171/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=6740862259955485171' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/6740862259955485171'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/6740862259955485171'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2009/10/preventing-browser-hijacks.html' title='Preventing browser hijacks'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-8004993414197006552</id><published>2009-10-06T12:34:00.003+05:30</published><updated>2009-10-06T12:46:20.488+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='security softwares'/><title type='text'>Free anti-malware tool from Microsoft</title><content type='html'>Microsoft security Essentials is a free anti-malware from Microsoft. It provides real time protection for your PC against malware, spyware, viruses and other malicious software free. It has features like&lt;br /&gt;&lt;b&gt;Scheduled scan&lt;br /&gt;Quick, full and custom scan&lt;br /&gt;Automatic updates without user interaction&lt;br /&gt;Real-time protection&lt;br /&gt;File exclusions&lt;br /&gt;Microsoft SpyNet&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;It has four tabs:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Home&lt;/b&gt; tab which contains  scan options like Quick Scan, Full scan and Custom scan. Quick scan scans critical areas of system like registry, start up etc. Full Scan scans the entire system and Custom scan is for scanning specific areas of system.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Update&lt;/b&gt; tab allows you to run a manual update of malware signatures.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;History &lt;/b&gt;tab contains  Quarantined items, detected items and items that are allowed to run.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Settings&lt;/b&gt; tab contains various settings of security essentials including Microsoft spynet membership settings.&lt;br /&gt;&lt;br /&gt;Microsoft spynet is the online community&lt;span id="intelliTxt"&gt; that helps you choose how to respond to potential threats in case you don't know what to do. It is also responsible for preventing threats from spreading around.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_LM6_hkmgEAk/SsrktwLURYI/AAAAAAAAAE0/0NQOITq4qfA/s1600-h/security+essentials1.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_LM6_hkmgEAk/SsrktwLURYI/AAAAAAAAAE0/0NQOITq4qfA/s320/security+essentials1.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;span id="intelliTxt"&gt;&lt;b&gt;System requirements:&lt;/b&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt; Genuine Windows XP, with a CPU clock speed of 500 MHz or higher, and 1 GB RAM or higher.&lt;/li&gt;&lt;li&gt;Windows Vista and Windows 7 with a CPU clock speed of 1.0 GHz or higher, and 1 GB RAM or higher.&lt;/li&gt;&lt;li&gt;VGA display with a resolution of 800 × 600 or higher.&lt;/li&gt;&lt;li&gt;140 MB of available hard disk space.&lt;/li&gt;&lt;li&gt;An Internet connection is required for installation and to download the latest virus and spyware definitions for Microsoft Security Essentials.&lt;/li&gt;&lt;li&gt;Internet browser( IE or Firefox)&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;Download Microsoft security Essentials: &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.microsoft.com/security_essentials/" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_LM6_hkmgEAk/SsrtQnDHmRI/AAAAAAAAAE8/TXqokbtI-so/s320/images.jpeg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-8004993414197006552?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/8004993414197006552/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=8004993414197006552' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/8004993414197006552'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/8004993414197006552'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2009/10/free-anti-malware-tool-from-microsoft.html' title='Free anti-malware tool from Microsoft'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_LM6_hkmgEAk/SsrktwLURYI/AAAAAAAAAE0/0NQOITq4qfA/s72-c/security+essentials1.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-8882897278586761752</id><published>2009-08-29T11:16:00.018+05:30</published><updated>2009-09-01T17:15:16.302+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus removal'/><category scheme='http://www.blogger.com/atom/ns#' term='runalyzer'/><category scheme='http://www.blogger.com/atom/ns#' term='security softwares'/><category scheme='http://www.blogger.com/atom/ns#' term='regalyzer'/><title type='text'>Utilities for tracking Malware hiding in windows autostart entries</title><content type='html'>When Malware infects a computer it automatically creates some autostart entries in windows autostart locations like&lt;br /&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon&lt;br /&gt;&lt;br /&gt;etc.&lt;br /&gt;&lt;br /&gt;As Malware executes sometimes it will disable registry editor and task manager and msconfig so these utilities will help you to recover your system from malware.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Autoruns&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This utility from &lt;span style="font-weight: bold;"&gt;sysinternals&lt;/span&gt; shows the programs that are configured to run automatically at windows startup.&lt;br /&gt;These locations include startup folder, Run, RunOnce, and other Registry keys. You can configure &lt;em&gt;Autoruns&lt;/em&gt; to show other locations, including Explorer shell extensions, toolbars, browser helper objects, Winlogon notifications, auto-start services, and much more. &lt;em&gt;&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_LM6_hkmgEAk/SpjG4tFpokI/AAAAAAAAAEE/csk2iSDACTE/s1600-h/bb963902.Autoruns%28en-us,MSDN.10%29.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 212px;" src="http://2.bp.blogspot.com/_LM6_hkmgEAk/SpjG4tFpokI/AAAAAAAAAEE/csk2iSDACTE/s320/bb963902.Autoruns%28en-us,MSDN.10%29.jpg" alt="" id="BLOGGER_PHOTO_ID_5375264832744956482" border="0" /&gt;&lt;/a&gt;It displays logon entries, Explorer add-ons, Internet Explorer add-ons including Browser Helper Objects (BHOs), Appinit DLLs, image hijacks, boot execute images, Winlogon notification DLLs, Windows Services and Winsock Layered Service Providers.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx"&gt;http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;RunAlyzer&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;RunAlyzer is a utility from safer-networking.org. It is  a combination of a standard configuration manager and an advanced tool to locate and remove places where hijackers, spyware and other malware hide.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_LM6_hkmgEAk/SpjROa-5sYI/AAAAAAAAAEc/TRxwpMnjsNs/s1600-h/runalyzer-main-1.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 250px;" src="http://1.bp.blogspot.com/_LM6_hkmgEAk/SpjROa-5sYI/AAAAAAAAAEc/TRxwpMnjsNs/s320/runalyzer-main-1.png" alt="" id="BLOGGER_PHOTO_ID_5375276200958210434" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;For more information on this tool and to download it visit &lt;a href="http://www.safer-networking.org/en/runalyzer/index.html"&gt;http://www.safer-networking.org/en/runalyzer/index.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;RegAlyzer&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;RegAlyzer&lt;/i&gt; is a tool to browse and change the registry. It has improved search and Jump to key by command line parameter, jump to key by typing/copying it into dialog (instead of browsing)&lt;br /&gt;,display of .reg file contents without importing it.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_LM6_hkmgEAk/SpjQ5KgEZiI/AAAAAAAAAEU/9WCl4WslCEg/s1600-h/regalyzer-main-1.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 162px;" src="http://3.bp.blogspot.com/_LM6_hkmgEAk/SpjQ5KgEZiI/AAAAAAAAAEU/9WCl4WslCEg/s320/regalyzer-main-1.png" alt="" id="BLOGGER_PHOTO_ID_5375275835756668450" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;For more information on this tool and to download it please visit&lt;a href="http://www.safer-networking.org/en/regalyzer/index.html"&gt; http://www.safer-networking.org/en/regalyzer/index.html&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Process Explorer&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Process Explorer is a better replacement for task manager it has many features which a normal task manager does not contain.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_LM6_hkmgEAk/SpjTcrSg38I/AAAAAAAAAEk/FCAuEa948x0/s1600-h/bb896653.ProcessExplorer1%28en-us,MSDN.10%29.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 238px;" src="http://1.bp.blogspot.com/_LM6_hkmgEAk/SpjTcrSg38I/AAAAAAAAAEk/FCAuEa948x0/s320/bb896653.ProcessExplorer1%28en-us,MSDN.10%29.jpg" alt="" id="BLOGGER_PHOTO_ID_5375278644876861378" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;It shows a list of the currently active processes, including the names of their owning accounts,  if it is in handle mode you'll see the handles that the process selected in the top window has opened; if Process Explorer is in DLL mode you'll see the DLLs and memory-mapped files that the process has loaded. It also has a powerful search which quickly shows you which processes have particular handles opened or DLLs loaded. It is useful for tracking down DLL-version problems or handle leaks it is useful for application behavior analysis.&lt;br /&gt;&lt;br /&gt;For more information on this tool and to download it please visit &lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx"&gt;http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Hijackthis&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This tool is useful in tracking internet explorer browser hijackers and it also gives insight into key areas of registry like startup locations and gives a list of processes running in your system which can be saved as a log which can be posted to forums for troubleshooting.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_LM6_hkmgEAk/SpjV7eNzN6I/AAAAAAAAAEs/ue-PuM6imEQ/s1600-h/48313_large.jpeg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 240px;" src="http://3.bp.blogspot.com/_LM6_hkmgEAk/SpjV7eNzN6I/AAAAAAAAAEs/ue-PuM6imEQ/s320/48313_large.jpeg" alt="" id="BLOGGER_PHOTO_ID_5375281372966631330" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;ADS Spy tool scans for alternate data streams, which some browser hijackers use to hide from spyware removers.&lt;br /&gt;&lt;br /&gt;Download Hijackthis from here:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://download.cnet.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html"&gt;Download link1&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.filehippo.com/download_hijackthis/"&gt;&lt;br /&gt;Download link2&lt;/a&gt;&lt;br /&gt;&lt;a href="http://majorgeeks.com/Trend_Micro_HijackThis_d5554.html"&gt;&lt;br /&gt;Download link3&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-8882897278586761752?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/8882897278586761752/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=8882897278586761752' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/8882897278586761752'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/8882897278586761752'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2009/08/utilities-for-tracking-malware-hiding.html' title='Utilities for tracking Malware hiding in windows autostart entries'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_LM6_hkmgEAk/SpjG4tFpokI/AAAAAAAAAEE/csk2iSDACTE/s72-c/bb963902.Autoruns%28en-us,MSDN.10%29.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-3104731875717181388</id><published>2009-07-27T14:00:00.018+05:30</published><updated>2009-08-01T15:32:44.545+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='security softwares'/><category scheme='http://www.blogger.com/atom/ns#' term='Secure deletion'/><title type='text'>Deleting Confidential information beyond recovery</title><content type='html'>&lt;div&gt;&lt;/div&gt; Any file system stores data on a storage device using an index table which links or maps to original data. When we delete a file, the operating system marks that memory or portion of the index table for reuse. So the actual information contained in the file is not deleted.&lt;br /&gt;&lt;br /&gt;File header or index table contains&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Filename, type&lt;br /&gt;&lt;/li&gt;&lt;li&gt;File attributes&lt;/li&gt;&lt;li&gt;Time and date of creation, modification&lt;/li&gt;&lt;li&gt;Starting cluster in the file allocation table&lt;/li&gt;&lt;li&gt;File size&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Even if a file has been deleted it can be recovered by reconstructing the file header or index of that file, until the portion has been used or overwritten by some other information. This can be done using data recovery softwares like stellar data recovery or pc inspector file recovery etc. So if you want to delete a confidential or sensitive information beyond recovery use softwares like file shredder, Wipe disk or Eraser.&lt;br /&gt;&lt;br /&gt;With file shredder you can remove files from your hard drive beyond recovery. In File Shredder you can choose between 5 different shredding algorithms, each one gradually stronger than the previous one. It also has integrated Disk Wiper which uses shredding algorithm to wipe unused disk space. It is a freeware&lt;br /&gt;&lt;br /&gt;Eraser is an advanced security tool for Windows which allows you to completely remove sensitive data from your hard drive by overwriting it several times with carefully selected patterns. Works with Windows 98, ME, NT, 2000, XP, Vista, Windows Server 2003 and Server 2008. It is a freeware.&lt;br /&gt;&lt;br /&gt;Download &lt;a href="http://www.fileshredder.org/"&gt;file shredder &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Download &lt;a href="http://eraser.heidi.ie/index.php#download"&gt;Eraser&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-3104731875717181388?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/3104731875717181388/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=3104731875717181388' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/3104731875717181388'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/3104731875717181388'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2009/07/deleting-confidential-information.html' title='Deleting Confidential information beyond recovery'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-1768064910125789768</id><published>2009-07-20T19:59:00.009+05:30</published><updated>2009-07-21T10:24:37.426+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='Data Encryption softwares'/><category scheme='http://www.blogger.com/atom/ns#' term='security softwares'/><title type='text'>Encrypt data on storage devices to secure confidential information</title><content type='html'>If you have confidential information on your computer and you want to protect it, use disk encryption software like TrueCrypt. TrueCrypt is a free open-source disk encryption software it works on Windows Vista/XP, Mac OS X, and Linux.&lt;br /&gt;&lt;br /&gt;It has On-the-fly encryption feature which encrypts or decrypts data automatically right before it is loaded or saved, without any user intervention. No data stored on an encrypted volume can be read (decrypted) without using the correct password/keyfile(s) or correct encryption keys. Entire file system is encrypted (e.g., file names, folder names, contents of every file, free space, meta data, etc).&lt;br /&gt;&lt;br /&gt;Main Features of TrueCrypt:&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;Creates a virtual encrypted disk within a file and mounts            it as a real disk. &lt;/li&gt;&lt;li&gt;Encrypts an entire partition or storage device such as USB flash drive or hard drive.&lt;/li&gt;&lt;li&gt;Encrypts a partition or drive where Windows is installed (pre-boot authentication).&lt;/li&gt;&lt;li&gt;Encryption is automatic, real-time (on-the-fly) and transparent.&lt;/li&gt;&lt;li&gt;Parallelization and pipelining allow data to be read and written as fast as if the drive was not encrypted.&lt;/li&gt;&lt;li&gt;Provides plausible deniability, in case an adversary            forces you to reveal the password:&lt;/li&gt;&lt;li&gt;Hidden volume (steganography) and hidden operating system.&lt;/li&gt;&lt;li&gt;Encryption algorithms: AES-256, Serpent, and Twofish.           Mode of operation: XTS.           &lt;/li&gt;&lt;/ul&gt;                                                                                                                    Download TrueCrypt from &lt;a href="http://www.truecrypt.org/downloads"&gt;here&lt;/a&gt;. For more information on this software visit this &lt;a href="http://www.truecrypt.org/docs/"&gt;link&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-1768064910125789768?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/1768064910125789768/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=1768064910125789768' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/1768064910125789768'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/1768064910125789768'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2009/07/encrypt-data-on-storage-devices-to.html' title='Encrypt data on storage devices to secure confidential information'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-3057410713915341380</id><published>2009-06-26T10:04:00.004+05:30</published><updated>2009-07-27T15:26:12.469+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='Win32 Sality.aa'/><category scheme='http://www.blogger.com/atom/ns#' term='virus removal'/><title type='text'>Manual removal of Win32 Sality.aa</title><content type='html'>This is a polymorphic virus it loads in the startup as a driver&lt;br /&gt;&lt;br /&gt;Creates following files and registry entries:&lt;br /&gt;&lt;p&gt;&lt;em&gt;&lt;/em&gt;&lt;/p&gt;%System%\drivers\.sys it is&lt;random filename=""&gt;  &lt;/random&gt;&lt;span style="font-weight: bold;"&gt;"infuo.sys"&lt;/span&gt;&lt;random filename=""&gt; &lt;/random&gt;in my case(but this file is hidden) in system32\drivers loads as a driver so it has capability to block antivirus sites.&lt;random filename=""&gt;&lt;br /&gt;&lt;br /&gt;&lt;/random&gt;HKCU\Software\"username"914&lt;random filename=""&gt;&lt;br /&gt;&lt;/random&gt;&lt;random filename=""&gt;&lt;br /&gt;&lt;/random&gt;For example:&lt;br /&gt;HKCU\Software\Administrator498&lt;random filename=""&gt;&lt;computer name=""&gt;&lt;p&gt;&lt;em&gt;&lt;/em&gt;&lt;/p&gt;&lt;/computer&gt;&lt;/random&gt;HKCU\Software\Administrator914&lt;random filename=""&gt;&lt;computer name=""&gt;&lt;br /&gt;&lt;br /&gt;&lt;/computer&gt;&lt;/random&gt;It adds the following text to the "system.ini" file located in the %Windows% directory:&lt;br /&gt;[MCIDRV_VER]&lt;br /&gt;DEVICEMB=random number&lt;random filename=""&gt;&lt;computer name=""&gt;&lt;random number=""&gt;&lt;br /&gt;&lt;br /&gt;&lt;/random&gt;&lt;/computer&gt;&lt;/random&gt;it disables windows firewall by executing the following command&lt;br /&gt;&lt;br /&gt;"netsh firewall set opmode disable"&lt;br /&gt;&lt;random filename=""&gt;&lt;computer name=""&gt;&lt;random number=""&gt;&lt;br /&gt;&lt;/random&gt;&lt;/computer&gt;&lt;/random&gt;it adds following entry to firewall through registry:&lt;br /&gt;&lt;br /&gt;HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"&lt;infected&gt;" = "&lt;infected&gt;:*:Enabled:ipsec"&lt;br /&gt;&lt;random filename=""&gt;&lt;computer name=""&gt;&lt;random number=""&gt;&lt;br /&gt;&lt;/random&gt;&lt;/computer&gt;&lt;/random&gt;It deletes and modifies the following registry entries:&lt;br /&gt;&lt;br /&gt;HKCU\System\CurrentControlSet\Control\SafeBoot&lt;br /&gt;HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot&lt;br /&gt;HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList&lt;br /&gt;HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\Stats&lt;br /&gt;HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats&lt;br /&gt;HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects&lt;br /&gt;&lt;br /&gt;It also modifies Hidden files entry in the registry&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\SHOWALL&lt;br /&gt;&lt;br /&gt;Modifies the dword "Checked value" from 1 to 0&lt;br /&gt;&lt;br /&gt;It also disables Registry Editor and Task Manager by adding these registry entries:&lt;br /&gt;&lt;br /&gt;HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\system\DisableTaskMgr = dword:00000001&lt;br /&gt;HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\system\DisableRegistryTools = dword:00000001&lt;br /&gt;&lt;br /&gt;Terminates major antivirus software services&lt;br /&gt;&lt;br /&gt;Prevents access to security related sites and antivirus sites&lt;br /&gt;&lt;br /&gt;Also disable settings related to system security. It does this by adding the following registry entries:&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Security Center\AntiVirusOverride = dword:00000001&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify = dword:00000001&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify = dword:00000001&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Security Center\FirewallOverride = dword:00000001&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify = dword:00000001&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Security Center\UacDisableNotify = dword:00000001&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Security Center\Svc\AntiVirusOverride = dword:00000001&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Security Center\Svc\AntiVirusDisableNotify= dword:00000001&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Security Center\Svc\FirewallDisableNotify = dword:00000001&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Security Center\Svc\FirewallOverride = dword:00000001&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Security Center\Svc\UpdatesDisableNotify = dword:00000001&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Security Center\Svc\UacDisableNotify = dword:00000001&lt;br /&gt;&lt;br /&gt;For more information on this virus please visit this&lt;random filename=""&gt;&lt;computer name=""&gt;&lt;random number=""&gt; &lt;a href="http://www.ca.com/us/securityadvisor/virusinfo/virus.aspx?id=74007"&gt;link&lt;/a&gt;&lt;br /&gt;&lt;/random&gt;&lt;/computer&gt;&lt;/random&gt;&lt;random filename=""&gt;&lt;computer name=""&gt;&lt;random number=""&gt;&lt;br /&gt;&lt;/random&gt;&lt;/computer&gt;&lt;/random&gt;&lt;span style="font-weight: bold;"&gt;Manual Virus removal instructions for an infected system:&lt;/span&gt;&lt;random filename=""&gt;&lt;computer name=""&gt;&lt;random number=""&gt;&lt;br /&gt;&lt;br /&gt;&lt;/random&gt;&lt;/computer&gt;&lt;/random&gt;1.Download this rarfile from this&lt;random filename=""&gt;&lt;computer name=""&gt;&lt;random number=""&gt; &lt;a href="http://www.mediafire.com/download.php?m2qjhz41wnk"&gt;link &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/random&gt;&lt;/computer&gt;&lt;/random&gt;2.Extract the contents to desktop, open cmd and type "netsh winsock reset" without quotes&lt;random filename=""&gt;&lt;computer name=""&gt;&lt;random number=""&gt;&lt;br /&gt;&lt;br /&gt;&lt;/random&gt;&lt;/computer&gt;&lt;/random&gt;3.Execute the file regtools.vbs by doubleclicking it&lt;random filename=""&gt;&lt;computer name=""&gt;&lt;random number=""&gt;&lt;br /&gt;&lt;br /&gt;&lt;/random&gt;&lt;/computer&gt;&lt;/random&gt;4.Now Execute the XP_reg.reg file by doubleclicking it click yes in the dialogbox that appears.&lt;random filename=""&gt;&lt;computer name=""&gt;&lt;random number=""&gt;&lt;br /&gt;&lt;br /&gt;&lt;/random&gt;&lt;/computer&gt;&lt;/random&gt;5.Execute the file regtools.vbs by doubleclicking it again.&lt;random filename=""&gt;&lt;computer name=""&gt;&lt;random number=""&gt;&lt;br /&gt;&lt;br /&gt;&lt;/random&gt;&lt;/computer&gt;&lt;/random&gt;6.Now execute the assoc.reg file by doubleclicking it click yes in registry prompt.&lt;random filename=""&gt;&lt;computer name=""&gt;&lt;random number=""&gt;&lt;br /&gt;&lt;br /&gt;&lt;/random&gt;&lt;/computer&gt;&lt;/random&gt;7.Execute the file regtools.vbs by doubleclicking it again.&lt;random filename=""&gt;&lt;computer name=""&gt;&lt;random number=""&gt;&lt;br /&gt;&lt;br /&gt;&lt;/random&gt;&lt;/computer&gt;&lt;/random&gt;8.Now open registry editor Go to start-&gt;Run-&gt;type "regedit" without quotes press enter&lt;br /&gt;sometimes you need execute the script again and again to open regedit after opening registry editor do not close it.&lt;random filename=""&gt;&lt;computer name=""&gt;&lt;random number=""&gt;&lt;br /&gt;&lt;br /&gt;&lt;/random&gt;&lt;/computer&gt;&lt;/random&gt;9.Now in registry editor navigate to HKCU\software and delete the entry that contains your "username"&lt;br /&gt;&lt;random filename=""&gt;&lt;computer name=""&gt;&lt;random number=""&gt;&lt;random number=""&gt;&lt;br /&gt;&lt;/random&gt;&lt;/random&gt;&lt;/computer&gt;&lt;/random&gt;10.Now navigate to HKCU\Software\Microsoft\Windows\CurrentVersion\Run and delete all values in right window pane&lt;br /&gt;&lt;br /&gt;11.Now navigate to HKLM\Software\Microsoft\Windows\CurrentVersion\Run and delete all values in right window pane&lt;br /&gt;&lt;br /&gt;12.Now navigate to HKCU\Software\Microsoft\Windows\CurrentVersion\Policies and delete Disabletaskmgr value. If task manager is not working use process explorer&lt;br /&gt;&lt;br /&gt;13.Now qiuckly press Crtl+Shift+Esc it opens task manager.&lt;br /&gt;&lt;br /&gt;14.Now quickly figureout processes that are running without your interaction like &lt;span style="font-weight: bold;"&gt;notepad.exe&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;or Winmine.exe&lt;/span&gt; ( these are files which I did not open but were running in task manager in my system.&lt;br /&gt;&lt;br /&gt;15. Now after figuring out any exe files running without your interaction (even if they are legitimate microsoft files they are affected by virus) delete those files from system32 and by using Unlocker. get &lt;a href="http://ccollomb.free.fr/unlocker/unlocker1.8.7.exe"&gt;unlocker&lt;/a&gt; here.&lt;br /&gt;&lt;br /&gt;16.Now Go to Run type CMD press enter, now type sfc /scanow and insert XP cd to restore system files that are modified.&lt;br /&gt;&lt;br /&gt;17.Now download &lt;a href="http://download.sysinternals.com/Files/Autoruns.zip"&gt;autoruns.zip   &lt;/a&gt;extract the contents open autoruns.exe click on drivers tab in autoruns and delete abp470n5 value from drivers section.&lt;br /&gt;&lt;br /&gt;18.Now open Run-&gt;type sysedit-&gt;goto system.ini and delete&lt;br /&gt;[MCIDRV_VER]&lt;br /&gt;DEVICEMB=random number&lt;br /&gt;&lt;br /&gt;19. Now navigate to HKCU\Software\Microsoft\Windows\CurrentVersion\Policies and delete all values in right pane. Also delete all startup items present in "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" and "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" because all executables are infected even antivirus entries should be deleted. Also clean all temporary files and clean prefetch in windows&lt;br /&gt;&lt;br /&gt;20. Now also doubleclick the safeboot registry entries for restoring safeboot&lt;br /&gt;&lt;br /&gt;21.Download &lt;a href="http://www.malwarebytes.org/"&gt;malwarebytes&lt;/a&gt; and run it&lt;br /&gt;&lt;br /&gt;21.Now restart the system and install kaspersky trial version or use the tool given below and scan all files.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Win32/Sality.aa removal tools:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Run this tool on an infected system to remove the infection&lt;br /&gt;&lt;br /&gt;download tool from kaspersky:&lt;br /&gt;&lt;a href="http://www.mediafire.com/?tyfjqgnjmzy"&gt;&lt;br /&gt;Link1&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://support.kaspersky.com/downloads/utils/sality_off.rar"&gt;Link2&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;em&gt;&lt;/em&gt;&lt;/p&gt;&lt;random filename=""&gt;&lt;computer name=""&gt;&lt;random number=""&gt;&lt;random number=""&gt;&lt;/random&gt;&lt;/random&gt;&lt;/computer&gt;&lt;/random&gt;&lt;/infected&gt;&lt;/infected&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-3057410713915341380?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/3057410713915341380/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=3057410713915341380' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/3057410713915341380'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/3057410713915341380'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2009/06/manual-removal-of-win32-salityaa.html' title='Manual removal of Win32 Sality.aa'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-4929503673206566495</id><published>2009-06-10T17:25:00.007+05:30</published><updated>2010-02-09T11:29:24.355+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='XP security settings'/><category scheme='http://www.blogger.com/atom/ns#' term='disable usb storage'/><title type='text'>Disabling Usb storage devices in windows</title><content type='html'>&lt;span style="font-weight: bold;"&gt;To prevent data theft from computers disabling USB storage is important.&lt;br /&gt;&lt;br /&gt;Follow these instructions to disable USB storage device&lt;/span&gt;&lt;br /&gt;&lt;h4 id="tocHeadRef" style="font-weight: bold;"&gt;If a USB storage device is not already installed on the computer&lt;/h4&gt;&lt;script type="text/javascript"&gt;             loadTOCNode(3, 'resolution'); &lt;/script&gt;If USB storage device is not installed Apply &lt;b class="uiterm"&gt;Deny&lt;/b&gt; permissions to the following files:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;%SystemRoot%\Inf\Usbstor.pnf&lt;/b&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;%SystemRoot%\Inf\Usbstor.inf &lt;/b&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;%SystemRoot%\system32\drivers\usbstor.sys&lt;/b&gt;&lt;/li&gt;&lt;/ul&gt;If you deny permissions to above files users will not be able to install a USB storage device on the computer.&lt;br /&gt;&lt;br /&gt;To assign a user or group Deny permissions to the Usbstor.pnf,&amp;nbsp;Usbstor.inf&amp;nbsp;and Usbstor.sys files&amp;nbsp;follow these steps:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Click on &lt;b&gt;Start&lt;/b&gt; -&amp;gt;&lt;b&gt; Run&lt;/b&gt; type &lt;b&gt;%SystemRoot%\Inf&lt;/b&gt;.&lt;/li&gt;&lt;li&gt;Find Usbstor.pnf. Right-click the &lt;b class="uiterm"&gt;Usbstor.pnf&lt;/b&gt; file, and then click &lt;b class="uiterm"&gt;Properties&lt;/b&gt;.&lt;/li&gt;&lt;li&gt;Click the &lt;b class="uiterm"&gt;Security&lt;/b&gt; tab.&lt;/li&gt;&lt;li&gt;In the &lt;b class="uiterm"&gt;Group or user names&lt;/b&gt; list, click the user or group that you want to set Deny permissions for.&lt;/li&gt;&lt;li&gt;In the &lt;b class="uiterm"&gt;Permissions for &lt;var&gt;UserName or GroupName&lt;/var&gt;&lt;/b&gt; list, click to select the &lt;b class="uiterm"&gt;Deny&lt;/b&gt; check box next to &lt;b class="uiterm"&gt;Full Control&lt;/b&gt;, and then click &lt;b class="uiterm"&gt;OK&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Note&lt;/b&gt; Also add the &lt;span style="font-weight: bold;"&gt;System&lt;/span&gt; account to the &lt;b class="uiterm"&gt;Deny&lt;/b&gt; list.&lt;/li&gt;&lt;li&gt;Right-click the &lt;b class="uiterm"&gt;Usbstor.inf&lt;/b&gt; file, and then click &lt;b class="uiterm"&gt;Properties&lt;/b&gt;.&lt;/li&gt;&lt;li&gt;Click the &lt;b class="uiterm"&gt;Security&lt;/b&gt; tab.&lt;/li&gt;&lt;li&gt;In the &lt;b class="uiterm"&gt;Group or user names&lt;/b&gt; list, click the user or group that you want to set Deny permissions for.&lt;/li&gt;&lt;li&gt;In the &lt;b class="uiterm"&gt;Permissions for &lt;var&gt;UserName or GroupName&lt;/var&gt;&lt;/b&gt; list, click to select the &lt;b class="uiterm"&gt;Deny&lt;/b&gt; check box next to &lt;b class="uiterm"&gt;Full Control&lt;/b&gt;, and then click &lt;b class="uiterm"&gt;OK&lt;/b&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Click on &lt;b&gt;Start&lt;/b&gt; -&amp;gt; &lt;b&gt;Run&lt;/b&gt; type &lt;b&gt;%SystemRoot%\system32\drivers&lt;/b&gt;&lt;/li&gt;&lt;li&gt;Find &lt;b&gt;Usbstor.sys&lt;/b&gt;. Right-click the &lt;b&gt;Usbstor.sys&lt;/b&gt; file, and then click Properties.&lt;/li&gt;&lt;li&gt;Click the Security tab.&lt;/li&gt;&lt;li&gt;In the Group or user names list, click the user or group that you want to set Deny permissions for.&lt;/li&gt;&lt;li&gt;In the Permissions for UserName or GroupName list, click to select the Deny check box next to Full Control, and then click OK.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;/ul&gt;The above steps will prevent users from installing USB storage device.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;If USB storage is already installed then follow these steps&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Click &lt;b class="uiterm"&gt;Start&lt;/b&gt;, and then click &lt;b class="uiterm"&gt;Run&lt;/b&gt;.&lt;/li&gt;&lt;li&gt;In the &lt;b class="uiterm"&gt;Open&lt;/b&gt; box, type &lt;span class="userInput"&gt;regedit&lt;/span&gt;, and then click &lt;b class="uiterm"&gt;OK&lt;/b&gt;.&lt;/li&gt;&lt;li&gt;Locate and then click the following registry key: &lt;br /&gt;&lt;br /&gt;&lt;div class="indent"&gt;&lt;b class="uiterm"&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UsbStor&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;&lt;li&gt;In the details pane, double-click &lt;b class="uiterm"&gt;Start&lt;/b&gt;.&lt;/li&gt;&lt;li&gt;In the &lt;b class="uiterm"&gt;Value data&lt;/b&gt; box, type &lt;span class="userInput"&gt;4&lt;/span&gt;, click &lt;b class="uiterm"&gt;Hexadecimal&lt;/b&gt; (if it is not already selected), and then click &lt;b class="uiterm"&gt;OK&lt;/b&gt;.&lt;/li&gt;&lt;li&gt;Exit Registry Editor.&lt;/li&gt;&lt;li&gt;USB storage device will be disabled&lt;/li&gt;&lt;/ul&gt;Connect a usb flash drive (pen drive) and check it is not detected&lt;br /&gt;&lt;br /&gt;Even after following above steps if it is not disabled then follow the these steps:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Click &lt;b class="uiterm"&gt;Start&lt;/b&gt;, and then click &lt;b class="uiterm"&gt;Run&lt;/b&gt;.&lt;/li&gt;&lt;li&gt;In the &lt;b class="uiterm"&gt;Open&lt;/b&gt; box, type &lt;span class="userInput"&gt;regedit&lt;/span&gt;, and then click &lt;b class="uiterm"&gt;OK&lt;/b&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Locate and then click the following registry key:&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet1\Services\UsbStor&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;In the details pane, double-click &lt;b class="uiterm"&gt;Start&lt;/b&gt;.&lt;/li&gt;&lt;li&gt;In the &lt;b class="uiterm"&gt;Value data&lt;/b&gt; box, type &lt;span class="userInput"&gt;4&lt;/span&gt;, click &lt;b class="uiterm"&gt;Hexadecimal&lt;/b&gt; (if it is not already selected), and then click &lt;b class="uiterm"&gt;OK&lt;/b&gt;.&lt;/li&gt;&lt;li&gt;Now Navigate to &lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet2\Services\UsbStor&lt;/span&gt;&lt;/li&gt;&lt;li&gt;In the details pane, double-click &lt;b class="uiterm"&gt;Start&lt;/b&gt;.&lt;/li&gt;&lt;li&gt;In the &lt;b class="uiterm"&gt;Value data&lt;/b&gt; box, type &lt;span class="userInput"&gt;4&lt;/span&gt;, click &lt;b class="uiterm"&gt;Hexadecimal&lt;/b&gt; (if it is not already selected), and then click &lt;b class="uiterm"&gt;OK&lt;/b&gt;.&lt;/li&gt;&lt;li&gt;Exit Registry Editor.&lt;/li&gt;&lt;/ul&gt;Now connect USB flash drive it will not be detected.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Note:Disabling USB storage device does not effect connecting USB keyboard or USB mouse to your computer. It will only disable USB storage device.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-4929503673206566495?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/4929503673206566495/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=4929503673206566495' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/4929503673206566495'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/4929503673206566495'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2009/06/disabling-usb-storage-devices.html' title='Disabling Usb storage devices in windows'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-4708308787739902435</id><published>2009-06-08T16:48:00.003+05:30</published><updated>2009-08-01T12:36:51.746+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='tweak dsl'/><title type='text'>Increase internet speed using Tcp optimizer and Half-Open</title><content type='html'>You can increase your internet speed using &lt;span style="font-weight: bold;"&gt;tcp optimizer&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_LM6_hkmgEAk/Si2HKyKUZYI/AAAAAAAAAD4/LscYNwKULUA/s1600-h/Capture1.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 316px; height: 265px;" src="http://3.bp.blogspot.com/_LM6_hkmgEAk/Si2HKyKUZYI/AAAAAAAAAD4/LscYNwKULUA/s320/Capture1.JPG" alt="" id="BLOGGER_PHOTO_ID_5345076952092140930" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The program can aid both the novice and the advanced user in tweaking related TCP/IP parameters in the Windows Registry, making it easy to tune your system to the type of Internet connection used. The tool uses advanced algorithms, and the bandwidth*delay product to find the best TCP Window for your specific connection speed. It provides for easy tuning of all related TCP/IP parameters, such as MTU, RWIN, and even advanced ones like QoS and ToS / Diffserv prioritization. The program works with all current versions of Windows, and includes additional tools, such as testing average latency over multiple hosts, and finding the largest possible packet size (MTU).&lt;br /&gt;&lt;br /&gt;Open tcp optimizer in the tcp optimizer window select &lt;span style="font-weight: bold;"&gt;optimal settings&lt;/span&gt; radio button Click on apply changes and click on &lt;span style="font-weight: bold;"&gt;OK&lt;/span&gt; and Click on &lt;span style="font-weight: bold;"&gt;No &lt;/span&gt;when it asks  for reboot&lt;br /&gt;&lt;br /&gt;get the tcp optimizer &lt;a href="http://www.speedguide.net/files/TCPOptimizer.exe"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;After tweaking MTU you can use half-open to change the tcp ip connection limit &lt;span style="font-weight: bold;"&gt;Half-open limit fix&lt;/span&gt; is a program designed to change the maximum number of concurrent half-open outbound TCP connections (connection attempts) in the Windows system file tcpip.sys. Microsoft first introduced this limit in Windows XP SP2 (Service Pack 2) and is present in all later versions of Windows. This was done to try to slow the spreading of viruses and malware from system to system and also to reduce the impact of infected systems participating in DoS (Denial of Service) attacks. This limit makes it impossible for Windows systems to have more than 10 concurrent half-open outbound connections. After 10, new connection attempts are put in a queue and forced to wait. Therefore, the speed of connection to other computers is actually limited. P2P (peer-to-peer) programs (µTorrent, BitComet, eMule, P2P TV etc.) are generally the most affected programs. As they use up all 10 of the half-open connections, other Internet activity, especially the loading of web pages, can be extremely slow. The delay before the beginning of opening can make some tens seconds. This happens regardless of the speed of your Internet connection. Half-open limit fix takes care of this problem by increasing the maximum limit of half-open connections. For the overwhelming majority of Internet users, changing the limit to 100 will be more than sufficient.&lt;br /&gt;&lt;br /&gt;get half-open &lt;a href="http://half-open.com/Half-open_limit_fix_3.9.exe"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_LM6_hkmgEAk/Sge18gLKtFI/AAAAAAAAACk/aBqKQiKdvpE/s1600-h/Half-open_limit_fix_en.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 304px;" src="http://2.bp.blogspot.com/_LM6_hkmgEAk/Sge18gLKtFI/AAAAAAAAACk/aBqKQiKdvpE/s320/Half-open_limit_fix_en.png" alt="" id="BLOGGER_PHOTO_ID_5334432334677193810" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;now open half limit and select the language as English and click on &lt;span style="font-weight: bold;"&gt;add to tcpip.sys&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;This will improve the internet performance on your DSL and cable internet lines. If you want you can restore the settings also by clicking on &lt;span style="font-weight: bold;"&gt;restore original file&lt;/span&gt; because sometimes your ISP router may have a limit on no of tcp ip connections.&lt;br /&gt;&lt;br /&gt;If you have firefox you can install &lt;span style="font-weight: bold;"&gt;tweak network addon &lt;/span&gt;to improve the speed in firefox&lt;br /&gt;&lt;br /&gt;after installing tweak network restart firefox and open &lt;span style="font-weight: bold;"&gt;tools menu&lt;/span&gt;-&gt; tweak network click on &lt;span style="font-weight: bold;"&gt;OK &lt;/span&gt;now click on &lt;span style="font-weight: bold;"&gt;power&lt;/span&gt; and click on &lt;span style="font-weight: bold;"&gt;OK&lt;/span&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-4708308787739902435?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/4708308787739902435/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=4708308787739902435' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/4708308787739902435'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/4708308787739902435'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2009/06/increase-internet-speed-using-tcp.html' title='Increase internet speed using Tcp optimizer and Half-Open'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_LM6_hkmgEAk/Si2HKyKUZYI/AAAAAAAAAD4/LscYNwKULUA/s72-c/Capture1.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-2923024666583077082</id><published>2009-06-08T16:34:00.004+05:30</published><updated>2009-08-01T12:37:26.586+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='hide ip'/><title type='text'>Hide your IP address and surf internet anonymously</title><content type='html'>&lt;strong&gt;UltraSurf&lt;/strong&gt; is a proxy server that beats the rest of the proxy servers on the net by offering features that others do not including login, flash files, java script, orkut, youtube, and file downloads, file uploads. Along with this you will not have any annoying ads or annoying pop ups and you will travel at faster speeds than you can imagine.&lt;br /&gt;&lt;br /&gt;you will be able to &lt;strong&gt;bypass the firewalls&lt;/strong&gt; that are put there to ensure you do not visit websites your company or school do not want you to view. You may not realize this, but many companies and universities block access to various social websites, thus stopping your freedom. With the &lt;strong&gt;UltraSurf&lt;/strong&gt;, you will be able to browse all the social websites such as &lt;strong&gt;Facebook&lt;/strong&gt;, &lt;strong&gt;Youtube&lt;/strong&gt;, &lt;strong&gt;Myspace&lt;/strong&gt;, &lt;strong&gt;Orkut&lt;/strong&gt;, &lt;strong&gt;Hi5&lt;/strong&gt;, and &lt;strong&gt;Linkedin&lt;/strong&gt; to name a few of the most popular.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_LM6_hkmgEAk/Sg3pET0607I/AAAAAAAAADY/h-PZmc8lx_E/s1600-h/ultrasurf.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 229px;" src="http://3.bp.blogspot.com/_LM6_hkmgEAk/Sg3pET0607I/AAAAAAAAADY/h-PZmc8lx_E/s320/ultrasurf.gif" alt="" id="BLOGGER_PHOTO_ID_5336177393754887090" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Note:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;It works only with &lt;strong&gt;Internet Explorer&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;The proxies &lt;a href="http://www.how-to-hide-ip.info/webproxy" style="" target="_blank" rel="nofollow"&gt;&lt;span&gt;&lt;/span&gt;&lt;/a&gt; are from &lt;strong&gt;US only&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;You can not choose the proxy to use&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Note:&lt;/span&gt; To use ultrasurf  with firefox download this addon&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.ultrareach.com/downloads/ultrasurf/wjbutton_en.zip"&gt;Download firefox addon&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Download it and open it with firefox to install it now enable it by clicking &lt;span style="font-weight: bold;"&gt;wjbutton&lt;/span&gt; at the bottom right corner of firefox window. Now open ultrasurf and browse internet.&lt;br /&gt;http://www.ultrareach.com/downloads/ultrasurf/wjbutton_en.zip&lt;br /&gt;&lt;br /&gt;Download it from here:&lt;br /&gt;&lt;a href="http://www.ultrareach.net/downloads/ultrasurf/u94.zip"&gt;&lt;br /&gt;http://www.ultrareach.net/downloads/ultrasurf/u94.zip&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;or use&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;GPass&lt;/span&gt; is a highly advanced software that can encrypt your online data, hide your IP address, and sidestep content filtering and monitoring using a number of secure channels to connect to the Internet and break through the Internet blockade. GPass supports the online applications that you use the most, including Web browsers (e.g. Firefox), multimedia players, email, instant messengers, download managers, and so on.&lt;br /&gt;&lt;br /&gt;The software is free for personal use within selected countries where unjust Internet censorship is prevalent.&lt;br /&gt;&lt;br /&gt;Supported applications include:&lt;br /&gt;Web browsers such as&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Internet Explorer or Firefox&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Multimedia players such as Windows Media Player or Real Player&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Email clients such as Outlook or Thunderbird&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Instant messengers such as MSN, Skype, and Yahoo messengers   Download managers such as wget and FlashGet&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;For more information visit:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://gpass1.com/gpass/"&gt;http://gpass1.com/gpass/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Download gpass from here:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://gpass1.com/gpass/download-en"&gt;http://gpass1.com/gpass/download-en&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:Arial;font-size:85%;"  &gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-2923024666583077082?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/2923024666583077082/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=2923024666583077082' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/2923024666583077082'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/2923024666583077082'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2009/06/ultrasurf-is-proxy-server-that-beats.html' title='Hide your IP address and surf internet anonymously'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_LM6_hkmgEAk/Sg3pET0607I/AAAAAAAAADY/h-PZmc8lx_E/s72-c/ultrasurf.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-5094343046406122635</id><published>2008-09-29T01:07:00.007+05:30</published><updated>2009-06-26T10:07:39.034+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='Kamsoft virus removal'/><category scheme='http://www.blogger.com/atom/ns#' term='virus removal'/><title type='text'>Kamsoft CKVO.exe malware manual removal instructions</title><content type='html'>Description: Troj/Gamania-BW&lt;br /&gt;&lt;br /&gt;Name: Kamsoft&lt;br /&gt;&lt;br /&gt;Command: C:\windows\system32\ckvo.exe&lt;br /&gt;&lt;br /&gt;This malware creates following entries in registry so that it executes whenever windows starts&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"Kamsoft"=C:\windows\system32\ckvo.exe&lt;br /&gt;&lt;br /&gt;Attacks all drives and modifies mount points key in registry so that when you double click on drives they open in new window instead of opening in same window&lt;br /&gt;&lt;br /&gt;Example:&lt;br /&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{05ef6149-5e60-11dd-8a88-0003254ecf1b}\shell\Autoplay\DropTarget&lt;br /&gt;&lt;br /&gt;Resets the hidden files attributes.&lt;br /&gt;&lt;br /&gt;Files associated with this malware that are hidden as system files in all partitions including C:\&lt;br /&gt;&lt;br /&gt;39lpji.com&lt;br /&gt;ktnquo.exe&lt;br /&gt;vxl.exe&lt;br /&gt;oq.cmd&lt;br /&gt;fe.bat&lt;br /&gt;kk3.bat&lt;br /&gt;rs.cmd&lt;br /&gt;autorun.inf&lt;br /&gt;&lt;br /&gt;Files found in C:\windows\system32&lt;br /&gt;&lt;br /&gt;ckvo.exe&lt;br /&gt;ckvo0.dll&lt;br /&gt;ckvo1.dll&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Removal instructions:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Start the computer in &lt;span style="font-weight: bold;"&gt;safe mode &lt;/span&gt;by pressing F8 during booting&lt;br /&gt;&lt;br /&gt;Open Registry Editor&lt;br /&gt;&lt;br /&gt;Delete the value  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"Kamsoft"=C:\windows\system32\ckvo.exe&lt;br /&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\&lt;br /&gt;&lt;br /&gt;delete all the keys starting with {........}&lt;br /&gt;&lt;br /&gt;Example:&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{05ef6149-5e60-11dd-8a88-0003254ecf1b}&lt;br /&gt;&lt;br /&gt;In the above key delete {05ef6149-5e60-11dd-8a88-0003254ecf1b}&lt;br /&gt;&lt;br /&gt;Open the command prompt&lt;br /&gt;&lt;br /&gt;go to C:\&gt;&lt;br /&gt;&lt;br /&gt;type attrib so you can see the hidden files in root drive&lt;br /&gt;&lt;br /&gt;To clear the attributes of malware files type&lt;br /&gt;&lt;br /&gt;attrib -s -h -r filename&lt;br /&gt;&lt;br /&gt;Example: C:\&gt;attrib -s -h -r autorun.inf&lt;br /&gt;                                D:\&gt;attrib -s -h -r autorun.inf&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;repeat the above command for all files of malware&lt;br /&gt;&lt;br /&gt;To delete the virus files type&lt;br /&gt;&lt;br /&gt;del filename&lt;br /&gt;&lt;br /&gt;Example: C:\&gt; del autorun.inf&lt;br /&gt;                                D:\&gt; del autorun.inf&lt;br /&gt;&lt;br /&gt;repeat the above command for all files of malware&lt;br /&gt;&lt;br /&gt;look for the files of malware in all other partitions and delete them.&lt;br /&gt;&lt;br /&gt;go to c:\windows\system32&gt;&lt;br /&gt;&lt;br /&gt;type attrib -s -h -r ckvo.exe&lt;br /&gt;     attrib -s -h -r ckvo.dll&lt;br /&gt;     attrib -s -h -r ckvo0.dll&lt;br /&gt;     attrib -s -h -r ckvo1.dll&lt;br /&gt;     del ckvo.exe&lt;br /&gt;     del ckvo0.dll&lt;br /&gt;     del ckvo1.dll&lt;br /&gt;&lt;br /&gt;Some files in system32 may not delete then you should logoff once and logon to delete any files associated with this malware&lt;br /&gt;&lt;br /&gt;Now open Registry editor go to&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\SHOWALL&lt;br /&gt;&lt;br /&gt;Change the DWORD value of Checked Value from 0 to 1.&lt;br /&gt;&lt;br /&gt;Now go to folder options and change the hidden file attributes and show system files options. You should be able to see all hidden files.&lt;br /&gt;&lt;br /&gt;Finally turnoff the system restore and turn it on again so the previous restore points will be deleted&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;/span&gt;&lt;h1 style="margin-left: 2px;"&gt;&lt;/h1&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-5094343046406122635?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/5094343046406122635/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=5094343046406122635' title='9 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/5094343046406122635'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/5094343046406122635'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2008/09/kamsoft-ckvoexe-malware-manual-removal.html' title='Kamsoft CKVO.exe malware manual removal instructions'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>9</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-3438030232934110652</id><published>2008-09-12T12:14:00.002+05:30</published><updated>2009-06-08T17:05:52.892+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='firewalls'/><category scheme='http://www.blogger.com/atom/ns#' term='security softwares'/><title type='text'>Free personal firewalls</title><content type='html'>&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;A firewall can offer complete protection from inbound and outbound communications occuring from a system. It allows and denies communication based on a set of rules. It can help in saving internet bandwidth and also protects from hackers with intrusion prevention. It helps in preventing identity theft.&lt;br /&gt;&lt;br /&gt;Below is list of free personal firewalls for windows&lt;br /&gt;&lt;br /&gt;Comodo Firewall Pro 3.0.22.349 &lt;a style="color: rgb(255, 0, 0);" href="http://www.personalfirewall.comodo.com/download_firewall.html"&gt;&lt;span style="font-size:85%;"&gt;Get it&lt;/span&gt; &lt;span style="font-size:85%;"&gt;now&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Online Armor Personal Firewall 2.1.0.131 Free  &lt;a style="color: rgb(255, 0, 0);" href="http://www.tallemu.com/downloads.html"&gt;&lt;span style="font-size:85%;"&gt;Get it&lt;/span&gt; &lt;span style="font-size:85%;"&gt;now&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;PC Tools Firewall Plus 4.0.0.45  &lt;a style="color: rgb(255, 0, 0);" href="http://www.pctools.com/consumer/products/?ref=cj"&gt;&lt;span style="font-size:85%;"&gt;Get it&lt;/span&gt; &lt;span style="font-size:85%;"&gt;now&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;ZoneAlarm free firewall &lt;a style="color: rgb(255, 0, 0);" href="http://www.zonealarm.com/store/content/company/products/znalm/freeDownload.jsp"&gt;&lt;span style="font-size:85%;"&gt;Get it&lt;/span&gt; &lt;span style="font-size:85%;"&gt;now&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;h1 class="product_h1"&gt;&lt;br /&gt;&lt;/h1&gt;&lt;br /&gt;&lt;a style="color: rgb(255, 0, 0);" href="http://www.zonealarm.com/store/content/company/products/znalm/freeDownload.jsp"&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-3438030232934110652?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/3438030232934110652/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=3438030232934110652' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/3438030232934110652'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/3438030232934110652'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2008/09/free-personal-firewalls.html' title='Free personal firewalls'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-3250681824145160497</id><published>2008-09-09T13:09:00.000+05:30</published><updated>2009-07-20T20:29:01.691+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='security softwares'/><category scheme='http://www.blogger.com/atom/ns#' term='rootkit removal tools'/><title type='text'>Rootkit Removal tools</title><content type='html'>A rootkit is a program or a set of programs used to take control of a computer in future. This rootkit is installed by an attacker once he gains access to compromised system. A rootkit may alter the normal execution flow of an application by a process called "hooking". It can also hide itself by hiding the processes and registry keys belonging to it. A rootkit can be used by attacker in future to access the compromised computer at his will.&lt;br /&gt;&lt;br /&gt;Below are the free rootkit removal tools&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;DarkSpy&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;DarkSpy Anti-Rookit is a multiway-based detection tool for rootkit detection. It internally combines many effective detection techniques, including DarkSpy's own handlers and also methods used by other famous tools.&lt;br /&gt;&lt;br /&gt;Get it &lt;a href="http://www.fyyre.net/%7Ecardmagic/download/darkspy105_en.rar"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Rootkit Revealer&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This rookit revealer freeware from sysinternals detects persistent rootkits on windows 4.0 and higher.&lt;br /&gt;&lt;br /&gt;Get it &lt;a href="http://www.sysinternals.com/Utilities/RootkitRevealer.html"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Sophos Anti-Rootkit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;It finds and removes any rootkit that is hidden on your computer using advanced rootkit detection technology.&lt;br /&gt;&lt;br /&gt;Get it &lt;a href="http://www.sophos.com/products/free-tools/sophos-anti-rootkit/download/"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;VPanda AntiRootkit 1.07&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Deactivates any unknown rootkits found on your system. Various improvements have also been made to the disinfection of unknown rootkits, some false positives reported by some of you, and more deactivation routines.&lt;br /&gt;&lt;br /&gt;Get it &lt;a href="http://research.pandasecurity.com/blogs/images/AntiRootkit.zip"&gt;here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-3250681824145160497?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/3250681824145160497/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=3250681824145160497' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/3250681824145160497'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/3250681824145160497'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2008/09/rootkits-and-removal-tools.html' title='Rootkit Removal tools'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-8965082439782707864</id><published>2008-09-09T12:25:00.000+05:30</published><updated>2009-06-13T01:30:21.827+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='security softwares'/><title type='text'>Free antivirus softwares</title><content type='html'>&lt;span style="font-weight: bold;"&gt;BitDefender&lt;br /&gt;&lt;/span&gt;BitDefender Free Edition is an on-demand virus scanner which incorporates BitDefender scanning engines. This is one of the top rated antivirus in reviews&lt;br /&gt;&lt;br /&gt;Click &lt;a href="http://fs5.filehippo.com/4149/72d0a351362646de93996e555b4efd3f/bitdefender_free_v10.exe"&gt;here&lt;/a&gt; to get it.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;" class="fullpost"&gt;Avast Home Edition&lt;/span&gt;&lt;br /&gt;It is available free for home use. It provides continuous protection against all forms of malicious software (malware).&lt;br /&gt;&lt;br /&gt;Click &lt;a href="http://software-files.download.com/sd/c7czsrCR_3GK_SIwca4Z4ndGRNSOCcKJ54q_iQKaEse-v5w4ZAAWPO94hORHyEnPACiUwdoTKk5Dflmi84IX2IqRJ09tZjEf/software/10879477/10019223/3/setupeng.exe?lop=&amp;amp;ptype=1901&amp;amp;ontid=2239&amp;amp;siteId=4&amp;amp;edId=3&amp;amp;spi=1c26bbd947011098864a97ecaf478dfd&amp;amp;pid=10879477&amp;amp;psid=10019223"&gt;here&lt;/a&gt; to get it&lt;br /&gt;&lt;br /&gt;Download links of other free antivirus softwares are listed below:&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;a href="http://free.grisoft.com/"&gt;AVG Antivirus&lt;/a&gt;&lt;a href="http://www.free-av.com/antivirus/allinonen.html"&gt;&lt;br /&gt;Avira Antivirus&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pctools.com/free-antivirus/"&gt;PC Tools Antivirus&lt;/a&gt;&lt;br /&gt;&lt;a href="http://safety.aol.com/isc/BasicSecurity/"&gt;Mcafee&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.threatfire.com/download/"&gt;PC Tools Threatfire&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-8965082439782707864?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/8965082439782707864/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=8965082439782707864' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/8965082439782707864'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/8965082439782707864'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2008/09/free-antivirus-softwares.html' title='Free antivirus softwares'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-8073953381187089627</id><published>2008-08-27T11:07:00.001+05:30</published><updated>2009-06-13T01:29:37.159+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='XP security settings'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows XP'/><title type='text'>Services that need your attention in windows xp</title><content type='html'>&lt;span style="font-weight: bold;"&gt;For securing standalone or workgroup computers of windows xp professional /home&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Services which can be set to manual state are:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Recommended Setting: Manual&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Application Layer Gateway Service&lt;br /&gt;&lt;br /&gt;Application Management Service&lt;br /&gt;&lt;br /&gt;Background Intelligent Transfer Service&lt;br /&gt;&lt;br /&gt;COM+ Event System Service&lt;br /&gt;&lt;br /&gt;COM+ System Application Service&lt;br /&gt;&lt;br /&gt;Distributed Transaction Coordinator Service&lt;br /&gt;&lt;br /&gt;Fast User Switching Compatibility Service&lt;br /&gt;&lt;br /&gt;HID Input Service&lt;br /&gt;&lt;br /&gt;HTTP SSL&lt;br /&gt;&lt;br /&gt;IMAPI CD-Burning COM Service&lt;br /&gt;&lt;br /&gt;Indexing Service&lt;br /&gt;&lt;br /&gt;IPSEC Services Service&lt;br /&gt;&lt;br /&gt;Logical Disk Manager Administrative Service&lt;br /&gt;&lt;br /&gt;Machine Debug Manager Service&lt;br /&gt;&lt;br /&gt;Network Connections Service&lt;br /&gt;&lt;br /&gt;Network Location Awareness (NLA) Service&lt;br /&gt;&lt;br /&gt;Network Provisioning Service&lt;br /&gt;&lt;br /&gt;NT LM Security Support Provider&lt;br /&gt;&lt;br /&gt;Performance Logs and Alerts Service&lt;br /&gt;&lt;br /&gt;Portable Media Serial Number Service&lt;br /&gt;&lt;br /&gt;Remote Access Auto Connection Manager Service&lt;br /&gt;&lt;br /&gt;Remote Access Connection Manager Service&lt;br /&gt;&lt;br /&gt;Remote Procedure Call (RPC) Locator Service&lt;br /&gt;&lt;br /&gt;Removable Storage Service&lt;br /&gt;&lt;br /&gt;TCP/IP NetBIOS Helper Service&lt;br /&gt;&lt;br /&gt;Telephony Service&lt;br /&gt;&lt;br /&gt;Terminal Services Service&lt;br /&gt;&lt;br /&gt;Universal Plug and Play Device Host Service&lt;br /&gt;&lt;br /&gt;Web Client Service&lt;br /&gt;&lt;br /&gt;Windows Image Acquisition (WIA) Service&lt;br /&gt;&lt;br /&gt;Windows Installer Service&lt;br /&gt;&lt;br /&gt;Windows Management Instrumentation Driver Ext&lt;br /&gt;&lt;br /&gt;WMI Performance Adapter Service&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Services which can be disabled are:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Recommended setting: Disabled&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Alerter Service&lt;br /&gt;&lt;br /&gt;Clip Book Service&lt;br /&gt;&lt;br /&gt;Indexing Service&lt;br /&gt;&lt;br /&gt;Internet Connection Firewall (ICF)/Sharing (ICS)&lt;br /&gt;&lt;br /&gt;Messenger Service&lt;br /&gt;&lt;br /&gt;MS Software Shadow Copy Provider Service&lt;br /&gt;&lt;br /&gt;Net Logon Service&lt;br /&gt;&lt;br /&gt;NetMeeting Remote Desktop Sharing Service&lt;br /&gt;&lt;br /&gt;Network DDE Service&lt;br /&gt;&lt;br /&gt;Network DDE DSDM Service&lt;br /&gt;&lt;br /&gt;QoS RSVP Service&lt;br /&gt;&lt;br /&gt;Remote Desktop Help Session Manager Service&lt;br /&gt;&lt;br /&gt;Remote Registry Service&lt;br /&gt;&lt;br /&gt;Routing and Remote Access Service&lt;br /&gt;&lt;br /&gt;Smart Card Service&lt;br /&gt;&lt;br /&gt;Smart Card Helper Service&lt;br /&gt;&lt;br /&gt;SSDP Discovery Service&lt;br /&gt;&lt;br /&gt;Telnet Service&lt;br /&gt;&lt;br /&gt;Uninterruptible Power Supply Service&lt;br /&gt;&lt;br /&gt;Upload Manager Service&lt;br /&gt;&lt;br /&gt;Volume Shadow Copy Service&lt;br /&gt;&lt;br /&gt;Windows Firewall/Internet Connection Sharing (ICS)&lt;br /&gt;&lt;br /&gt;Windows Time Service&lt;br /&gt;&lt;br /&gt;Wireless Zero Configuration Service&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;This section presents an overview of the above mentioned services and why they need to be disabled.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Alerter&lt;/span&gt;&lt;br /&gt;Notifies selected users and computers of administrative alerts. If the service is stopped, programs that use administrative alerts will not receive them. If this service is disabled, any services that explicitly depend on it will fail to start.&lt;br /&gt;&lt;br /&gt;You can use the alerter service to have Performance Monitor send you a network pop-up message or run a program when one of the counters exceeds a preset threshold. It is of no use for standalone system.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Application Layer Gateway Service&lt;/span&gt;&lt;br /&gt;Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Internet Connection Firewall&lt;br /&gt;&lt;br /&gt;Instead of sharing an internet connection through single system as gateway you can purchase a router and a switch to share an internet connection. A router has a built-in port filtering mechanism.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Automatic Updates&lt;/span&gt;&lt;br /&gt;Enables the download and installation of critical Windows updates. If the service is disabled, the operating system can be manually updated.&lt;br /&gt;&lt;br /&gt;You can disable automatic updates if you are updating windows manually&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Background Intelligent Transfer Service&lt;/span&gt;&lt;br /&gt;Uses idle network bandwidth to transfer data.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ClipBook Viewer&lt;/span&gt;&lt;br /&gt;Enables ClipBook Viewer to store information and share it with remote computers. If the service is stopped, ClipBook Viewer will not be able to share information with remote computers. If this service is disabled, any services that explicitly depend on it will fail to start.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Distributed Transaction Coordinator Service&lt;/span&gt;&lt;br /&gt;This service is used to share information that is copied on to ClipBook to be shared on remote computers.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;COM+ Event System Service&lt;/span&gt;&lt;br /&gt;Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;COM+ System Application Service&lt;/span&gt;&lt;br /&gt;Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.&lt;br /&gt;&lt;br /&gt;If you disable this service COM+/OLE registration will not work&lt;br /&gt;At every boot a warning will be in the Event Log&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Distributed Transaction Coordinator Service&lt;/span&gt;&lt;br /&gt;Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will not occur. If this service is disabled, any services that explicitly depend on it will fail to start.&lt;br /&gt;&lt;br /&gt;MSDTC performs the transaction coordination role for components, usually with COM and .NET architectures. In MSDTC terminology, the director is called the transaction manager.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Fast User Switching Compatibility Service&lt;/span&gt;&lt;br /&gt;Windows XP's new Fast User Switching feature allows one user to quickly access a computer without forcing another to log off or quit applications.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HID Input Service&lt;/span&gt;&lt;br /&gt;Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HTTP SSL&lt;/span&gt;&lt;br /&gt;This service implements the secure hypertext transfer protocol (HTTPS) for the HTTP service, using the Secure Socket Layer (SSL). If this service is disabled, any services that explicitly depend on it will fail to start.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;IMAPI CD-Burning COM Service&lt;/span&gt;&lt;br /&gt;Manages CD recording using Image Mastering Applications Programming Interface (IMAPI). If this service is stopped, this computer will be unable to record CDs. If this service is disabled, any services that explicitly depend on it will fail to start.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Indexing Service&lt;/span&gt;&lt;br /&gt;Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language.&lt;br /&gt;&lt;br /&gt;This service is used to extract content from files and construct an indexed catalog to facilitate efficient and rapid searching.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Internet Connection Firewall (ICF)/Sharing (ICS)&lt;/span&gt;&lt;br /&gt;Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.&lt;br /&gt;&lt;br /&gt;Disable Internet Connection Sharing (ICS) and Firewall services use third party firewalls&lt;br /&gt;or an Internet security suite securing your computer&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;IPSEC Services Service&lt;/span&gt;&lt;br /&gt;Manages IP security policy and start the ISAKMP/Oakley (IKE) and the IP security driver&lt;br /&gt;&lt;br /&gt;If connecting over an IPSEC secured connection you have to have this service Enabled.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Logical Disk Manager Administrative Service&lt;/span&gt;&lt;br /&gt;Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start.&lt;br /&gt;&lt;br /&gt;This service is important as it monitors hard disk drives and works in conjunction with disk management.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Machine Debug Manager Service&lt;/span&gt;&lt;br /&gt;Manages local and remote debugging for Visual Studio debuggers&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Messenger Service&lt;/span&gt;&lt;br /&gt;Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this service is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;MS Software Shadow Copy Provider Service&lt;/span&gt;&lt;br /&gt;Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed.&lt;br /&gt;&lt;br /&gt;Works along with Volume Shadow Copy Windows ntbackup utility. it is useful service for cloning of disks&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Net Logon Service&lt;/span&gt;&lt;br /&gt;Supports pass-through authentication of account logon events for computers in a domain&lt;br /&gt;&lt;br /&gt;This service is useful for authenticating users for domain logon&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;NetMeeting Remote Desktop Sharing Service&lt;/span&gt;&lt;br /&gt;Enables an authorized user to access this computer remotely by using NetMeeting over a corporate intranet. If this service is stopped, remote desktop sharing will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Network Connections Service&lt;/span&gt;&lt;br /&gt;Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Network DDE Service&lt;/span&gt;&lt;br /&gt;Provides network transport and security for Dynamic Data Exchange&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Network DDE DSDM&lt;/span&gt;&lt;br /&gt;Manage shared DDE communications from shares like \\computername\ndde$&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Network Location Awareness (NLA) Service&lt;/span&gt;&lt;br /&gt;Collects and stores network configuration and location information, and notifies applications when this information changes&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Network Provisioning Service&lt;/span&gt;&lt;br /&gt;Manages XML configuration files on a domain basis for automatic network provisioning&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;NT LM Security Support Provider Service&lt;/span&gt;&lt;br /&gt;Provides security to remote procedure call (RPC) programs that use transports other than named pipes&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Performance Logs and Alerts Service&lt;/span&gt;&lt;br /&gt;Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Portable Media Serial Number Service&lt;/span&gt;&lt;br /&gt;Retrieves the serial number of any portable media player connected to this computer. If this service is stopped, protected content might not be down loaded to the device&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;QoS RSVP Service&lt;/span&gt;&lt;br /&gt;Provides network signaling and local traffic control setup functionality for QoS-aware programs and control applets&lt;br /&gt;&lt;br /&gt;QoS functions as a load balancer between applications by shifting bandwidth for the applications when needed&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Remote Access Auto Connection Manager Service&lt;/span&gt;&lt;br /&gt;Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Remote Access Connection Manager Service&lt;/span&gt;&lt;br /&gt;Creates a network connection&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Remote Desktop Help Session Manager Service&lt;/span&gt;&lt;br /&gt;Manages and controls Remote Assistance. If this service is stopped, Remote Assistance will be unavailable. Before stopping this service, see the Dependencies tab of the Properties dialog box&lt;br /&gt;&lt;br /&gt;For remote desktop the Remote Desktop Help Session Manager Service should be enabled&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Remote Procedure Call (RPC) Locator Service&lt;/span&gt;&lt;br /&gt;Manages the RPC name service database&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Remote Registry Service&lt;/span&gt;&lt;br /&gt;Enables remote users to modify registry settings on this computer&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Removable Storage Service&lt;/span&gt;&lt;br /&gt;Removable Storage works together with your data-management applications. It makes possible for multiple applications to share the same storage media resources&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Routing and Remote Access Service&lt;/span&gt;&lt;br /&gt;Offers routing services to businesses in local area and wide area network environments&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Smart Card Service&lt;/span&gt;&lt;br /&gt;Manages access to smart cards read by this computer&lt;br /&gt;&lt;br /&gt;If you use a smart card for authentication (logging into computer) enable this service&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Smart Card Helper Service&lt;/span&gt;&lt;br /&gt;Enables support for legacy non-plug and play smart-card readers used by this computer&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;SSDP Discovery Service&lt;/span&gt;&lt;br /&gt;Enables discovery of UPnP devices on your home network&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;TCP/IP NetBIOS Helper Service&lt;/span&gt;&lt;br /&gt;Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Telephony Service&lt;/span&gt;&lt;br /&gt;Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Telnet Service&lt;/span&gt;&lt;br /&gt;Enables a remote user to log on to this computer and run programs, and supports various TCP/IP Telnet clients, including UNIX-based and Windows-based computers&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Terminal Services Service&lt;/span&gt;&lt;br /&gt;Allows multiple users to be connected interactively to a machine as well as the display of desktops and applications to remote computers&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Uninterruptible Power Supply Service&lt;/span&gt;&lt;br /&gt;Manages an uninterruptible power supply (UPS) connected to the computer&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Universal Plug and Play Device Host Service&lt;/span&gt;&lt;br /&gt;Provides support to host Universal Plug and Play devices&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Upload Manager Service&lt;/span&gt;&lt;br /&gt;Manages synchronous and asynchronous file transfers between clients and servers on the network&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Volume Shadow Copy Service&lt;/span&gt;&lt;br /&gt;Manages and implements Volume Shadow Copies used for backup and other purposes&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Web Client Service&lt;/span&gt;&lt;br /&gt;Enables Windows-based programs to create, access, and modify Internet-based files.&lt;br /&gt;&lt;br /&gt;This allows users to connect directly to online storage service such as Apple Idisk by using WebDAV protocol&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Web-based Distributed Authoring and Versioning or WebDAV&lt;/span&gt;, is a protocol which allows users to collaboratively edit and manage files on remote World Wide Web servers&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Windows Image Acquisition (WIA) Service&lt;/span&gt;&lt;br /&gt;Provides image acquisition services for scanners and cameras&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Windows Installer Service&lt;/span&gt;&lt;br /&gt;Adds, modifies, and removes applications provided as a Windows Installer (*.msi) package&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Windows Management Instrumentation Driver Extensions&lt;/span&gt;&lt;br /&gt;Provides systems management information to and from drivers&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Windows Time Service&lt;/span&gt;&lt;br /&gt;Maintains date and time synchronization on all clients and servers in the network&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Wireless Zero Configuration Service&lt;/span&gt;&lt;br /&gt;Provides automatic configuration for the 802.11 adapters&lt;br /&gt;&lt;br /&gt;If you disable wireless zero configurations you have to configure wireless networking manually&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;WMI Performance Adapter Service&lt;/span&gt;&lt;br /&gt;Provides performance library information from Windows Management Instrumentation (WMI) providers to clients on the network&lt;br /&gt;&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;Also see &lt;a href="http://infosecurityhub.blogspot.com/2008/08/security-options-configuration-for.html"&gt;Security options Configuration&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-8073953381187089627?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/8073953381187089627/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=8073953381187089627' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/8073953381187089627'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/8073953381187089627'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2008/08/services-that-need-your-attention-in.html' title='Services that need your attention in windows xp'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-8313327515022529772</id><published>2008-08-21T12:35:00.000+05:30</published><updated>2009-06-13T01:29:37.160+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='XP security settings'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows XP'/><title type='text'>Least privilege policy for windows XP</title><content type='html'>We should never leave the administrator account with a blank password. Users should have the least rights that are needed to perform there tasks. It is recommended to disable the guest account and always browse internet with the least privilege principle applied. For this you need to create a user account with limited rights. You can do this by using computer management.&lt;br /&gt;&lt;br /&gt;Right click on &lt;span style="font-weight: bold;"&gt;My Computer&lt;/span&gt;, go to &lt;span style="font-weight: bold;"&gt;Manage&lt;/span&gt;, &lt;span style="font-weight: bold;"&gt;Local users and Groups&lt;/span&gt;.&lt;br /&gt;Right click in the right window pane select &lt;span style="font-weight: bold;"&gt;new user&lt;/span&gt; and specify the &lt;span style="font-weight: bold;"&gt;username&lt;/span&gt; and &lt;span style="font-weight: bold;"&gt;password&lt;/span&gt;.&lt;br /&gt;Uncheck &lt;span style="font-weight: bold;"&gt;user must change password on next log on&lt;/span&gt; and create the user. This user by default will not have admin rights.&lt;br /&gt;&lt;br /&gt;Also enforce the password complexity rule in account policies snap in in group policy, Also specify account lock out duration and no of invalid attempts for locking the account. If you enable this policy by default the account will unlock after the time you specified in account lock out duration.&lt;br /&gt;&lt;br /&gt;follow the steps mentioned below for password policy configuration:&lt;br /&gt;&lt;br /&gt;Go to &lt;span style="font-weight: bold;"&gt;Start&lt;/span&gt;, &lt;span style="font-weight: bold;"&gt;Run&lt;/span&gt;, type &lt;span style="font-weight: bold;"&gt;gpedit.msc&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In the Group Policy Editor and under Computer Configuration, expand Windows Settings, expand &lt;span style="font-weight: bold;"&gt;Security Settings&lt;/span&gt;, expand &lt;span style="font-weight: bold;"&gt;Account Policies&lt;/span&gt;, and then click &lt;span style="font-weight: bold;"&gt;Password Policies&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Double-click Enforce password history, set the value of Keep password history to 24, and then click OK.&lt;br /&gt;&lt;br /&gt;Double-click &lt;span style="font-weight: bold;"&gt;Maximum password age&lt;/span&gt;, set the value of &lt;span style="font-weight: bold;"&gt;Password will expire&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;in&lt;/span&gt; to &lt;span style="font-weight: bold;"&gt;42&lt;/span&gt;, click &lt;span style="font-weight: bold;"&gt;OK&lt;/span&gt;, and then click &lt;span style="font-weight: bold;"&gt;OK&lt;/span&gt; to accept a suggested value change for the Minimum password age.&lt;br /&gt;&lt;br /&gt;Set the &lt;span style="font-weight: bold;"&gt;minimum password age&lt;/span&gt; to 1 or 2&lt;br /&gt;&lt;br /&gt;Double-click &lt;span style="font-weight: bold;"&gt;Minimum password length&lt;/span&gt;, set the value &lt;span style="font-weight: bold;"&gt;&lt;/span&gt;to &lt;span style="font-weight: bold;"&gt;8&lt;/span&gt;, and then click OK.&lt;br /&gt;&lt;br /&gt;Double-click Password must meet complexity requirements, select Enabled, and then click OK.&lt;br /&gt;&lt;br /&gt;Double-click &lt;span style="font-weight: bold;"&gt;Store passwords using reversible encryption&lt;/span&gt;, select &lt;span style="font-weight: bold;"&gt;Disabled (default)&lt;/span&gt;, and then click &lt;span style="font-weight: bold;"&gt;OK&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;password-secure your screen saver&lt;br /&gt;&lt;br /&gt;In &lt;span style="font-weight: bold;"&gt;Group Policy Editor&lt;/span&gt;, go to &lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;User Configuration&lt;/span&gt;, expand &lt;span style="font-weight: bold;"&gt;Administrative Templates&lt;/span&gt;, expand &lt;span style="font-weight: bold;"&gt;Control Pane&lt;/span&gt;l, and then click &lt;span style="font-weight: bold;"&gt;Display&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;In the details pane, double-click &lt;span style="font-weight: bold;"&gt;Password protect the screen saver&lt;/span&gt;, select &lt;span style="font-weight: bold;"&gt;Enabled&lt;br /&gt;&lt;br /&gt;Also see &lt;a href="http://infosecurityhub.blogspot.com/2008/08/security-tab-in-ntfs-partitions.html"&gt;Other security settings&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-8313327515022529772?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/8313327515022529772/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=8313327515022529772' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/8313327515022529772'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/8313327515022529772'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2008/08/least-privilege-policy-for-windows-xp.html' title='Least privilege policy for windows XP'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-6467380784431245673</id><published>2008-08-21T12:08:00.000+05:30</published><updated>2008-09-03T14:24:52.323+05:30</updated><title type='text'>firewall and antivirus are mandatory</title><content type='html'>Firewall is a device or software which  permit, deny, encrypt, or proxy all the information passing through it based on rules configured in to it.&lt;br /&gt;&lt;br /&gt;Firewalls are systems designed to prevent unauthorized access to or from a private network. Firewalls can be implemented in both Hardware and Software, or a combination of both.There are so many firewalls which offer stateful packet inspection, deep packet inspection, applicaton layer firewalls,proxy firewalls.&lt;br /&gt;&lt;br /&gt;Windows has a built firewall for xp but it offers only inbound protection. A firewall should be able to stop the internal processes from outbound communication also so that if a virus attack happens any outbound intenet communication is denied by default.&lt;br /&gt;&lt;br /&gt;Topmost personal firewalls include Zone Alarm, Kaspersky Internet Security Suite which offers complete protection with web antivirus,firewall,file antivirus etc. Comodo firewall also offers a good protection on outbound communication. Even if you have a firewall if you did not configure it properly it will result in poor security.&lt;br /&gt;&lt;br /&gt;You should configure in such a way that only necessary programs should be able to communicate  and deny all other programs. Comodo offers a parental control feature to control the alerts that you will recieve from the firewall if you put a password there is an option to suppress the firewall alerts and defense alerts. if you use comodo you should install a antivirus solution also.&lt;br /&gt;&lt;br /&gt;Bitdefender is also an internet security suite offering the same protection as kaspersky and also tops the 2008 antivirus reviews.&lt;br /&gt;&lt;br /&gt;In kaspersky you should configure the firewall in high security mode so it will not show any alerts and denies the outbound communication if that program is not configured to use internet by default.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Also see &lt;a href="http://infosecurityhub.blogspot.com/2008/08/scan-your-system-for-missing-patches.html"&gt;scan for missing patches&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-6467380784431245673?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/6467380784431245673/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=6467380784431245673' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/6467380784431245673'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/6467380784431245673'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2008/08/firewall-and-antivirus-are-mandatory.html' title='firewall and antivirus are mandatory'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-1138746843351073460</id><published>2008-08-21T11:51:00.000+05:30</published><updated>2009-07-24T14:32:16.443+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='chat encryption'/><title type='text'>Use Simplite for messenger encryption</title><content type='html'>Simplite is a messenger encyption software it encrypts messages before they leave your computer to the Internet, SimpLite prevents eavesdroppers from  reading your Messenger  conversations. if you are using yahoo messenger use simplite for yahoo and for msn use simplite for msn messenger. Simplite is a free messenger encyption software.&lt;br /&gt;&lt;br /&gt;Get this software &lt;a href="http://www.secway.fr/us/products/simplite_yahoo/"&gt;here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-1138746843351073460?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/1138746843351073460/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=1138746843351073460' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/1138746843351073460'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/1138746843351073460'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2008/08/use-simplite-for-messenger-encryption.html' title='Use Simplite for messenger encryption'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-5865575715009359848</id><published>2008-08-21T11:11:00.000+05:30</published><updated>2009-06-13T01:29:37.160+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='XP security settings'/><category scheme='http://www.blogger.com/atom/ns#' term='Disable Autorun feature'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows XP'/><title type='text'>Few more security settings for enhanced security</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold; font-style: italic;font-family:times new roman;" &gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Security tab:&lt;/span&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-family:times new roman;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Enable the security tab that appears in the folder properties tab by disabling the simple file sharing that is enabled by default in windows XP. This setting applies only for NTFS partitions. FAT32 partitioned drives are not as secure as NTFS. This security tab can be used to specify restrictions on an file or a folder for a purticular user whether he can access it or not.&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;font-family:times new roman;" &gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Disable Autorun Feature:&lt;/span&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-family:times new roman;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Some malicious software uses Autorun feature that makes any program run automatically when you insert a flash drive or a CD. You can disable autorun feature for all drives or for specific drives.&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;To disable autorun:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;For XP Pro:&lt;/span&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-family:times new roman;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;"&gt;&lt;/span&gt;&lt;/span&gt;Open &lt;span style="font-weight: bold;"&gt;Run&lt;/span&gt; from start menu&lt;br /&gt;&lt;br /&gt;Type &lt;span style="font-weight: bold;"&gt;gpedit.msc&lt;/span&gt; and click &lt;span style="font-weight: bold;"&gt;OK&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The Group Policy snap in will open.&lt;br /&gt;&lt;br /&gt;Go to &lt;span style="font-weight: bold;"&gt;Computer configuration, Administrative Templates&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In the right pane, double-click System&lt;br /&gt;&lt;br /&gt;Scroll down the list and double-click &lt;span style="font-weight: bold;"&gt;Turn Off Autoplay&lt;/span&gt;, in the Turn Off Autoplay Properties window, select Enabled.&lt;br /&gt;&lt;br /&gt;From the dropdown next to Turn Off Autoplay on, select All drives and Click Ok.&lt;br /&gt;&lt;br /&gt;Go to &lt;span style="font-weight: bold;"&gt;User Configuration&lt;/span&gt;, &lt;span style="font-weight: bold;"&gt;Administrative templates&lt;/span&gt; follow the above proceedure for this also.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;For XP home users:&lt;br /&gt;Go to Start, &lt;span style="font-weight: bold;"&gt;Run&lt;/span&gt; type &lt;span style="font-weight: bold;"&gt;regedit&lt;/span&gt; and press enter&lt;br /&gt;&lt;br /&gt;Navigate to the following key&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer.  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Select the key Explorer and in the right-pane right click the value &lt;span style="font-weight: bold;"&gt;NoDriveTypeAutoRun&lt;/span&gt;&lt;br /&gt;select &lt;span style="font-weight: bold;"&gt;Modify&lt;/span&gt; select Hexadecimal.Type 95 and click OK.Exit the registry editor.&lt;br /&gt;&lt;br /&gt;If it is no present create a &lt;span style="font-weight: bold;"&gt;DWORD&lt;/span&gt; value &lt;span style="font-weight: bold;"&gt;NoDriveTypeAutorun&lt;/span&gt; an then assign the hex value&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Also see &lt;a href="http://infosecurityhub.blogspot.com/2008/08/firewall-and-antivirus-are-mandatory.html"&gt;&lt;span style="text-decoration: underline;"&gt;firewalls and antivirus&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-5865575715009359848?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/5865575715009359848/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=5865575715009359848' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/5865575715009359848'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/5865575715009359848'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2008/08/security-tab-in-ntfs-partitions.html' title='Few more security settings for enhanced security'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-3227082010042423940</id><published>2008-08-21T10:46:00.000+05:30</published><updated>2009-06-13T01:29:37.161+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='XP security settings'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows XP'/><title type='text'>Scan your system for missing patches</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;Use tools like  Secunia PSI from Secunia to scan for missing updates and applications that vulnerable and download the appropriate application or patch and apply it so that your system remains hard on any kind of attack or expliotation. Also remove the outdated applications for which the support ended so that your system remains less vulnerable or prone to attacks. For more visit&lt;span style="font-size:130%;"&gt;&lt;span style="font-family:times new roman;"&gt; &lt;a href="https://psi.secunia.com/"&gt;www.secunia.com&lt;/a&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-family:times new roman;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;Get Secunia PSI from&lt;span style="font-size:130%;"&gt; &lt;a href="https://psi.secunia.com/PSISetup.exe"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Also see &lt;a href="http://infosecurityhub.blogspot.com/2008/08/use-simplite-for-messenger-encryption.html"&gt;Simplite messenger encryption&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-3227082010042423940?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/3227082010042423940/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=3227082010042423940' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/3227082010042423940'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/3227082010042423940'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2008/08/scan-your-system-for-missing-patches.html' title='Scan your system for missing patches'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-8508452534895550467</id><published>2008-08-21T10:01:00.000+05:30</published><updated>2009-06-13T01:29:37.161+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='XP security settings'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows XP'/><title type='text'>Security Options Configuration for securing XP Professional</title><content type='html'>The security options snap in contains options that can also be modified through registry. But its better to use this snap in instead of registry.&lt;br /&gt;&lt;br /&gt;The security options that need a change to secure your system are listed below&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Limit local account use of blank passwords to console logon only&lt;/span&gt;.&lt;span style="font-weight: bold;"&gt;Enable&lt;/span&gt; this setting local accounts with blank passwords cannot be used to connect to the machine from across the network.&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Rename the default administrator account with a different name&lt;/span&gt;.Rename the guest account and also disable guest account for more security&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Allow undock without having to log on&lt;/span&gt;&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;. &lt;/span&gt;&lt;/span&gt;Disable this setting.&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Restrict CD-ROM access to locally logged-on user only&lt;/span&gt;&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;. &lt;/span&gt;&lt;/span&gt;Enable this setting.&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Restrict floppy access to locally logged-on user only&lt;/span&gt;&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;. &lt;/span&gt;Enable this setting.&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Domain member: Disable machine account password changes.&lt;/span&gt; &lt;/span&gt;Disable this setting.&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Do not require CTRL+ALT+DEL &lt;/span&gt;disable this setting if you require to have CTRL+ALT+DEL key combination enabled at the time of logon. This setting is enabled by default in domain controllers. Also yo need to disable welcome screen to enable this setting.&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Number of previous logons to cache (in case domain controller is not available&lt;/span&gt;&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;.Set this to 0.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Smart card removal behavior&lt;/span&gt;&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;span style="font-weight: bold; font-style: italic;"&gt; &lt;/span&gt;&lt;/span&gt;set this to lock workstation.&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Send unencrypted password to third-party SMB servers&lt;/span&gt;&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;span style="font-style: italic;"&gt;&lt;span style="font-weight: bold;"&gt;. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Disable this setting&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Allow anonymous SID/Name translation.&lt;/span&gt;&lt;span style=";font-family:times new roman;font-size:130%;"  &gt; &lt;/span&gt;Disable this setting&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Do not allow anonymous enumeration of SAM accounts.&lt;/span&gt;&lt;span style=";font-family:times new roman;font-size:130%;"  &gt; &lt;/span&gt;Enable this setting.&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Do not allow anonymous enumeration of SAM accounts and shares.&lt;/span&gt;&lt;span style=";font-family:times new roman;font-size:130%;"  &gt; &lt;/span&gt;Enable this setting.&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Do not allow storage of credentials or .NET Passports&lt;/span&gt;. Enable this setting.&lt;br /&gt;&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Let Everyone permissions apply to anonymous users&lt;/span&gt;. Disable this setting.&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Remotely accessible registry paths.&lt;/span&gt;&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt; &lt;/span&gt;Delete all settings.&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Shares that can be accessed anonymously.&lt;/span&gt;&lt;span style=";font-family:times new roman;font-size:130%;"  &gt; &lt;/span&gt;Delete all settings.&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Sharing and security model for local accounts. &lt;/span&gt;Set this to classic users authenticate themselves.&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Do not store LAN Manager hash value on next password change&lt;/span&gt;&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;. &lt;/span&gt;Set this to enabled&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Allow system to be shut down without having to log on&lt;/span&gt;&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;. &lt;/span&gt;Set this to disabled.&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Clear virtual memory pagefile&lt;/span&gt;&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;. &lt;/span&gt;Set this to enabled.&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Strengthen default permissions of internal system objects (e.g. Symbolic Links)&lt;/span&gt;&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;. &lt;/span&gt;Set this to enabled.&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;Also see &lt;a href="http://infosecurityhub.blogspot.com/2008/08/user-rights-assignment.html"&gt;User rights assignment&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-8508452534895550467?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/8508452534895550467/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=8508452534895550467' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/8508452534895550467'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/8508452534895550467'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2008/08/security-options-configuration-for.html' title='Security Options Configuration for securing XP Professional'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-5382417003373467269</id><published>2008-08-21T09:33:00.001+05:30</published><updated>2009-06-24T06:15:18.989+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='XP security settings'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows XP'/><title type='text'>User Rights Assignment</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-family:times new roman;"&gt;&lt;/span&gt;&lt;/span&gt;User rights assignment snap in determines what actions the user will be able to perform. settings which require a change are explained below&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;"&gt;&lt;/span&gt;&lt;/span&gt;To modify the user rights settings:&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;"&gt;&lt;/span&gt;&lt;/span&gt;Local Policies → User Rights Assignment&lt;br /&gt;Double-click on the desired Attribute in the right frame.&lt;br /&gt;To add a user or group, Add User or Group → Enter user or group →&lt;br /&gt;Add → OK → OK&lt;br /&gt;To remove a user or group, select user or group → Remove → OK&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;Remove the&lt;span style="font-size:130%;"&gt;&lt;span style="font-family:times new roman;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;power users&lt;/span&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-family:times new roman;"&gt; &lt;/span&gt;&lt;/span&gt;group from all user rights.&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-family:times new roman;font-size:130%;"  &gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Backup files and directories&lt;/span&gt; remove the backup operators&lt;span style="font-size:130%;"&gt;&lt;span style="font-family:times new roman;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;If  you require backup operators for your network you can keep it however administrators are granted this right.&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-family:times new roman;font-size:130%;"  &gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Bypass traverse checking&lt;/span&gt; give permission to users and remove all other groups&lt;span style="font-size:130%;"&gt;&lt;span style="font-family:times new roman;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-family:times new roman;font-size:130%;"  &gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Debug programs&lt;/span&gt; is a right required for a developer otherwise remove all the users from this setting&lt;span style="font-size:130%;"&gt;&lt;span style="font-family:times new roman;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-family:times new roman;font-size:130%;"  &gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Force shutdown from a remote system&lt;/span&gt; remove all groups except administrators&lt;span style="font-size:130%;"&gt;&lt;span style="font-family:times new roman;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-family:times new roman;font-size:130%;"  &gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;logon locally&lt;/span&gt; give this right to &lt;span style="font-weight: bold;"&gt;administrators&lt;/span&gt; and &lt;span style="font-weight: bold;"&gt;users&lt;/span&gt; group and also for backup operators if required.&lt;span style="font-size:130%;"&gt;&lt;span style="font-family:times new roman;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Restore files and directories&lt;/span&gt; if you require &lt;span style="font-weight: bold;"&gt;backup operators&lt;/span&gt; assign the right for them or else you can remove all the groups except the &lt;span style="font-weight: bold;"&gt;administrators&lt;br /&gt;&lt;br /&gt;Also see &lt;a href="http://infosecurityhub.blogspot.com/2008/08/least-privilege-policy-for-windows-xp.html"&gt;Least privilege policy&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-5382417003373467269?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/5382417003373467269/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=5382417003373467269' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/5382417003373467269'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/5382417003373467269'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2008/08/user-rights-assignment.html' title='User Rights Assignment'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-3810914801818613428</id><published>2008-08-19T18:13:00.000+05:30</published><updated>2009-06-13T01:29:37.162+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='XP security settings'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows XP'/><title type='text'>Security guide for windows xp</title><content type='html'>Microsoft is providing a security configuratuion guide for configuring system security policies.This guide is intended for security specialists. This guide explains in detial about the user rights assignment group policy and services configuration.If you want this guide you can download it from this&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:times new roman;"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-family:times new roman;"&gt; &lt;/span&gt;&lt;a style="font-family: times new roman;" href="http://download.microsoft.com/download/e/4/9/e49db890-f683-404d-990d-7a9842145450/Windows_XP_Security_Guide_v2.2.zip"&gt;link&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-3810914801818613428?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/3810914801818613428/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=3810914801818613428' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/3810914801818613428'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/3810914801818613428'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2008/08/security-guide-for-windows-xp.html' title='Security guide for windows xp'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7085617280006501022.post-8878419862351251426</id><published>2008-08-19T16:59:00.000+05:30</published><updated>2008-08-27T11:07:03.072+05:30</updated><title type='text'>Factors that influence Information Security</title><content type='html'>Information security for home users comprises of&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Confidentiality:&lt;/span&gt;&lt;span style=";font-family:times new roman;font-size:130%;"  &gt; &lt;/span&gt;Information should be available only for the users who are authorized to access it.&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Integrity:&lt;/span&gt;&lt;span style=";font-family:times new roman;font-size:130%;"  &gt; &lt;/span&gt;Information should be modified only by persons who has right to modify it.&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Availability: &lt;/span&gt;Information should be available for authorized users when there is a need to access it.&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Information or data is disclosed to unauthorized persons by below mentioned methods:&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;1. &lt;/span&gt;Malware&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;2. &lt;/span&gt;Spyware&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;3. &lt;/span&gt;Buffer overflow attacks&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;4. &lt;/span&gt;DOS and DDOS&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;5. &lt;/span&gt;Unprotected file sharing&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;6. &lt;/span&gt;Cross-site scripting&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;7. &lt;/span&gt;Email spoofing&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;8. &lt;/span&gt;Email viruses&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;9. &lt;/span&gt;Active x controls, JavaScript&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;10. &lt;/span&gt;Internet Relay Chat clients&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Malware&lt;/span&gt;&lt;span style=";font-family:times new roman;font-size:130%;"  &gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;&lt;/span&gt;(Malicious software in short) is a program which is designed to cause damage or to gain access to a remote system without relying on vulnerabilities.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Spyware&lt;/span&gt; is software that is installed on a remote system on accessing a compromised website or an insecure system which is used to capture screenshots or keystrokes (key loggers) of a user.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Buffer overflow&lt;/span&gt; is a condition which occurs due to insufficient bounds checking of a program. It is a kind of software vulnerability. This occurs when a malicious user tries to insert data beyond the boundaries of fixed length buffer.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;DoS or DDoS&lt;/span&gt; attack is an attack where the aim of the attacker is to make the resource unavailable for legitimate users. This is achieved by sending large number of external communication requests which results in consumption of available bandwidth.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Unprotected file sharing&lt;/span&gt; using a weak password over network results in compromise of the file sharing mechanism in windows which can be utilized by viruses and worms to spread over the entire network. Disable the file sharing if not required or use a strong password mechanism to prevent unauthorized access.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Cross-site scripting&lt;/span&gt; is a condition where a compromised or malicious website or a web application allows code injection by malicious users which results in site phishing attacks or browser exploitation to gain control over the attacked computer.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Email spoofing&lt;/span&gt; is a technique where a user receives a mail that looks as if it came from a legitimate source but was actually sent from another source.&lt;br /&gt;&lt;br /&gt;Example: Emails claiming credit card numbers, passwords etc.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Email viruses&lt;/span&gt; come from attached files when a user clicks on the attachment that is not from a legitimate source.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Active x controls, JavaScript&lt;/span&gt; may contain scripts or controls that may harm your computer and compromise it.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Internet Relay Chat&lt;/span&gt; clients are mainly designed for discussions over forums and channels which also allows private communication. IRC communication can also result in DoS attacks.&lt;br /&gt;&lt;br /&gt;To reduce the risk of the above mentioned attacks we need to harden our operating systems accordingly&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7085617280006501022-8878419862351251426?l=infosecurityhub.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecurityhub.blogspot.com/feeds/8878419862351251426/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7085617280006501022&amp;postID=8878419862351251426' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/8878419862351251426'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7085617280006501022/posts/default/8878419862351251426'/><link rel='alternate' type='text/html' href='http://infosecurityhub.blogspot.com/2008/08/information-security-for-home-users.html' title='Factors that influence Information Security'/><author><name>Madhava Rao Arimilli</name><uri>http://www.blogger.com/profile/16354903592118879936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
