Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, July 18, 2013

How to avoid PDF virus and protect your PC

PDF (Portable Document Format) files are used to store information and are transferred via different means.
Generally we think PDF files are safe from viruses. Are they Really safe from Virus??
Answer is "NO"
PDF Virus

Shocked !!!

So, How do PDF files become malicious?
- Programmers inject a small piece of Javascript code in the PDF file.
- When you open the PDF document, the script will be executed and it will call an external virus(mostly trojan) and it will infect your computer.

Now, you will ask too many questions :
How to avoid PDF virus and protect my PC ?
How to use PDF files without infecting my PC ?
What is the Solution to PDF virus ?

- Don't worry, follow these instructions and protect your PC :

Solution


Adobe Reader Users:

Open Adobe Reader
->Edit -> Preferences (or press ctrl + k)
In Categories ->Javascript.

Adobe reader preference

-> Uncheck Enable Acrobat JavaScript 
-> Ok

Foxit Reader users:

Open Foxit Reader
->File->Preferences

poxit reader preferences

-> Trust Manager -> in Javascript -> Uncheck Enable JavaScript Actions
-> OK

Now Open PDF files without worry !!
:) :)





Saturday, May 4, 2013

Secure Facebook account using Trusted Contacts

Secure Facebook
Hello Friends, All of you must be using Facebook, so do I. 
Recently, Facebook announced a new feature called "Trusted Contacts" to help you get back into your account when locked out.
Now you will ask:

Q. What are Trusted Contacts?
- Trusted contacts are people(your friends) you can reach out to if you ever need help getting into your Facebook account (ex: if you forget your Facebook password and can’t get into your email account to reset it).

So, Why did I named this article as 'Secure Facebook Account using Trusted Contacts' ?
- Yes, I named it right. As it is developed to prevent intruders from accessing your Facebook account easily using Facebook's loophole.


 Surprised!! Read On..

Facebook released this feature to Strengthen one of its feature which was more used by intruders to access Facebook accounts for wrong means rather than the actual purpose.

Warning: this article is meant to encourage security by showing loophole and its solution. Don't use it for wrong means, Author doesn't take responsibility if anyone uses 'part of this article' for wrong means.
 
Let's see what intruders do to access someone's Facebook account who is not using "Trusted Contacts" 


- in Facebook login page, click 'Forgot your password'
- next page, Identify your account, give Victim's full name or account information
- Next page, asks to reset password using email or phone, click 'No longer have access to these'
- it will ask a new email to reach you, give one
- now it asks 'Answer Your Security Question' - click - Recover your account with help from friends
- next page shows steps to recover your account- click continue
- Victim's Friends-list comes now, here intruder use two methods:
    a) they choose their own Fake FB accounts with which he/she has become friend with victim already
    b) they choose any 2 victim's friend with whom he can access codes 
(obviously, 3rd friend is intruder himself)
- provides code and access the victim's account


Solution


What can we do?
- Simple, As the heading suggests, use "Trusted Contacts"


How?


- Go to 'Security Settings' -> Trusted Contacts ->Choose Trusted Contacts


Security Settings

- click 'Choose Trusted Contacts'


- Type name of your 3 or 5 'Trusted Friends' -> select -> confirm


- Re-Enter your password ->Submit

- Done

Now, if intruder tries to access your account using this loophole, he gets this page:


Even if he/she  clicks 'Reveal My Trusted Contacts', it will show :


And it will reveal their names only when intruder knows 'Full name' of any one of your chosen friend.
Even if he/she guesses it right(less probable) he have to get codes from person you have chosen(very difficult) rather than those whom he wishes to choose!!

Remember, your account will be more secure if along-with you & your friends have secure accounts. So, spread this knowledge.

Happy Facebooking !!
:) :)



Wednesday, March 20, 2013

How to Prevent from virus - Learn safe habits

"Prevention is Better than cure"

PC with Virus
Imagining the world without Computer is impossible and so is 'A virus free world'!
If we have to live in the same world then why not Learn and Prepare ourselves so as to Prevent Virus infection as long as we can.

'Antivirus' is the word must be coming in your mind by now.
Okay.. Let me Divide this computer world in Three Categories: 

I.   Computers having No Antivirus
II.  Computers having Good Antivirus
III. Computers having Antivirus & Virus (living together happily)

You might be thinking Second Category must be virus free.

As per I see it,even a Mid-Low level Virus can enter and infect all the three Categories if the User handling them are unaware of Safe habits.

Safe System = Secure computer+(security)Informed user

Who is (security)Informed user ?
-User who Learn and practice safe habits to use computer.
-Keeps updating his knowledge time to time

Safe Habits - to prevent virus

- Have a Good Updated Antivirus installed
   Some Good Free Antiviruses:
          - 'Microsoft Security Essentials' if you have Genuine Windows else
          - 'AVG' or 'Avast' (free versions)
  
- Update your Window Regularly
- Keep Pop up Blocker ON
- Have a File catching Download Manager installed(idm, orbit downloader) and set it to catch all virus extensions
(unsafe websites download virus in your PC in back-end)  
- Prohibit going to illegal website (including keygen, torrent) even if you do, scan everything you get.
- scan everything you get from outside world before using whether you downloaded it, email attachment, from LAN network, External drives
- Using external drives(pendrive, memory card, external HDD) safely:
  - Always close the AutoPlay window which comes after inserting:
AutoPlay
  
  - Don't double click it from My computer also
  - Open it either from address bar or explore(my computer-right click drive-explore)
  - Always keep 'show hidden files' ON while using External drives.
  - Don't click anything suspicious, NEVER click shortcut or .exe extension you don't know about
  - In each of your drive(local, pendrive, MMC, HDD)
     - Make a New folder->name it as ' Autorun.inf ' 
     - Open command prompt-> go to your drive-> type this code:
       attrib +r +s +h Autorun.inf
    
  
I will try to keep updating you here, If you have any doubt or query regarding above, Feel free to ask.

Tell me how much you like it.
Any suggestion to improve is always welcome!!

Happy Safe Computing!!

:) :)             
  

Wednesday, March 13, 2013

Track stolen phone - Best Anti Theft Free Android App - TheftSpy

Screenshot
Smartphone is our best friend and worst enemy.
We store personal Documents, Pictures, videos, Bank details and many more things in it.

What if it gets stolen?

our phone will expose all our contacts, bank credentials, location, personal SMS/Pictures and so much more.
So we must prevent or minimize the risk of such things happening.

We have found out an App for Android Phone users which Registers your device rather than registering the SIM(any thief will first throw away the SIM). It is SS TheftSpy, which is strong enough App to help you in any such situations.

What should you do?
-first register an account on TheftSpy website and then install its android app on your android device. 

What is the System requirement?
-Requires Android 2.3 and higher. WiFi, Edge, or 3G network connection sometimes required.

 Features:
-can be used to control your device remotely and gather all information which is inside your stolen device.
-TheftSpy usually runs in background and is invisible in app drawer.
-user can remotely reset the device, switch off it, reboot it.
-collect pictures, videos, call logs, and other documents.
-Take Picture using Rear and front camera when Key-guard lock unlock attempt
-User can remotely get current GPS location of the device.
-Enable or disable key-lock
-can get screenshot also

-can record audio for 30 seconds remotely.
-Data Security such as wipe all data, gallery and Whatsapp content.


The fully loaded Android-App offers a bunch of Features which are 100% free and useable for everyone.

There are no restrictions or less features in the "Free-User"-Mode.

TheftSpy offers 3 days of Premium to try all functionality.

Special feature for paid users: The user after becoming premium user will get a chance of uploading 5GB data in TheftSpy account.


You cannot do much to get your stolen mobile back if the thief is a geek or Good techie. But its less likely that the thief is a very good techie. The best thing you can do is to install TheftSpy to your device so that at time you can remotely manage your device data remotely and minimize the effects and impact of theft.  So why to waste time thinking, start downloading TheftSpy and protect your mobile.

Links:
TheftSpy website

Play-store link

Friday, November 23, 2012

How to clean Virus infection from your computer safely

Clean Virus

You came to know that your PC or Laptop is infected with viruses.

Don't Panic! It is not the end of your system, it can be cleaned easily and Formatting is not necessary.

Just Follow our instructions... :)


If your computer is infected with a Malwares (like virus, trojan, worm etc) It is better to remove it as quickly as possible.
You might be thinking of downloading or purchasing an antivirus to remove 'the Parasites'. 

These were the old school methods, But Malware Programmers, or convenient to say, Virus Programmers have gone far ahead.
Now virus connects to their originators and download other malwares and make many changes in your system so as to make it difficult for you to remove them.

Some of those Changes are like :

-> Disable browsing security websites (ex- microsoft.com, symantec.com, etc )
-> Sometimes won't allow to connect to internet.
-> Disable windows tools like Task manager, Registry editor, cmd etc
-> Disable Folder options & thus won't let you see hidden files, extensions
-> Associate itself with system restore points (so that it can revoke itself after system restore)
-> Disable current antivirus program  & even won't allow you to install new antivirus !!
-> In some case, associate itself with the new antivirus being installed and remain untouched by it.

More Tensed!! :o
Don't worry, I am here to solve your problems. :)



Solution

Download some software which will be required further. If you are unable to go to the websites due to virus then download them from a clean computer and keep them in a clean Pen-drive. 

- Virus Process terminating tool : Rkill (download all versions keep them in a folder)
- Virus Removing Tools: Norman malware cleaner or Microsoft Safety Scanner 
- Antivirus: Microsoft security essentials, AVG Free / Avast ,  if you have any other personal choice

Before starting cleaning process,keep above files in infected PC and Disconnect it from Internet. Don't do anything else, Do only the steps asks you to do, in some cases, it can take longer time while scanning, Be Patient!!

First step: Stop Virus process

First it is better to stop processes of virus, so that difficulties in removing virus gets minimised. Please do not Restart your system after using 'Rkill', as Malwares are scheduled to start during start up. Immediately start cleaning as 'Rkill' finishes.  
->Run 'Rkill'
it will show in command prompt all the changes it is making.
When it Finishes, immediately proceed to Second step.

 Second step: Start cleaning 


A fast and safe way to check and clean for viruses is to use 'Virus removal tools' like 'Norman Malware Cleaner' , 'Microsoft Safety Scanner' and other tools provided by antivirus companies for Free(here I am providing those I use most).
These Tools are a free online service that helps you detect and remove viruses.

Procedure: Simple...
-> Run any of the above tools Downloaded
-> Accept
-> Do 'Full scan' and follow the instruction and remove Infected files and Threats
-> If it asks for a restart then Do it.


Third step: Make sure that no virus is left

-> Install MalwareBytes by double clicking it and follow normal steps of installing.

-> Turn off System restore (control panel> system > system restore )
This prevents malwares from coming back.
-> Reboot (as screens tuns off,keep tapping F8) with Advance Boot Option , choose 'Safe mode with networking'
Advance Boot Menu -Safe mode with networking

-> connect to internet, (if it doesn't connects, reboot in same fashion & try again. If still can't then reboot normally & connet with internet)
-> Right click the MalwareByte icon  'M' in taskbar, click Check for updates.
-> After finishing Update, Disconnect from internet (better unplug the LAN cable or whichever medium being used)
-> Open MalwareBytes, Do a 'Full scan'
-> Follow removal process as asked(check all detected->Remove selected)
-> Reboot Normally, again check for updates, again Do 'Full Scan' (to be double sure)
-> if it catches virus again, then clean them follow process mentioned in above line again

Now you can be sure of removal of viruses.
But still to be on safer side, Follow Step 3.

Fourth Step: Prohibiting attack

Now your system is cleaned from infection. But it needs Proactive monitoring so as to catch and prevent any future Virus attack. You may connect to internet now.

- Install a good Antivirus with Proactive Monitoring

Choosing Antivirus: I have chosen these two as per my experience and criteria, we can discuss it in further posts.
If your systems run Genuine Microsoft Windows version, then you must choose 'Microsoft security essentials' as it is the only Free complete version and very much effective Antivirus Program available. 
Else you may opt for  Free AVG/ Avast or any Good Antivirus (we will discuss about them in further posts)

- After installation, Update it
- Do a Full scan (to be on safer side)
- Remove infection as per instruction (if any)
- Restart if it asks to


This is Basic suggestion that can be given to any Infected Computer remotely for safely removal of Malwares (viruses in common language) .

It is Suggested to Learn and Practice Virus-safety Habits to prevent further virus attack. 





Feel free to ask any problem, i'll be happy trying to solve them.

Happy Computing and safe surfing :)

Tuesday, August 14, 2012

How to fix Registry editing has been disabled by Your administrator




You try to run regedit form start menu you are getting an error like this 'Registry editing has been disabled by administrator'


 Regedit is widely used to successfully remove Virus and their effects. This is also the reason why virus makers love to disable the Registry Editor so it makes solving the problem and removing the issue difficult.

Viruses are not always the reason for this issue sometimes administrators in IT departments place a restrictions on using the regedit command to keep employees from changes things on company computers.

 Let us look at the solution to fix it:

 Solution 1: Using the Group Policy Editor

  • Start -> Run -> gpedit.msc and press ENTER
  • Expand the '+' sign to go to the following location: User Configuration ->Administrative Templates -> System
  • Double-click 'Prevent access to registry editing tools' and set it to Not Configured
  • Exit the Group Policy Editor
    Note: 
    If the setting already reads Not Configured, set it to Enabled, and click Apply. Then revert it back to Not Configured. This ensures that the DisableRegistryTools registry value is removed successfully.


 


Solution 2: Using the REG.EXE console tool  

Start -> Run -> type this command:

REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f

Solution 3:
Symantec has developed a tool UnHookexec.inf which makes access to registry editing easy and sets their registry values to their default values. It is an inf file right click the tool and install . 

Solution 4:

Download this VB script file from doug Knox Website and run it .If you get any warning click ok to continue. After VB Script file enables registry editor ,restart your computer and access registry.


Solution 5:

Some viruses and other malware will load a regedit.com file that is many times a zero byte dummy file. Because .com files have preference over .exe files when executed if you type REGEDIT in the run line, it will run the regedit.com instead of the real regedit.exe file.

Delete the regedit.com file if its a zero byte file to restore access to REGEDIT. In some cases, such as the W32.Navidad worm, you'll need to rename the REGEDIT file to get it to work.

 Happy Troubleshooting ...

:)