![]() |
|
#1
|
|||
|
|||
|
My parents dont`s use their pc very much, only visit a few websites a day. Nevertheless the regularly have rootkits on their pc. They only visit websites such as newspapers and a known dutch trade site.
Is it possible that someone sends them these rootkits as they have a fixed ip? What can I do to prevent it? The pc is protected with a known free av and firewall. They are up to date and I asked them to use Firefox . Thank you. |
|
#2
|
|||
|
|||
|
Perhaps after their system has been cleaned try something like Sandboxie? http://www.sandboxie.com/
|
|
#3
|
|||
|
|||
|
If they are running as administrator, create a limited account for them to use instead for their surfing and other online use. How are these "regular" rootkits being removed? BTW, Securing you PC and Data... is an excellent read.
|
|
#4
|
||||
|
||||
|
Perhaps they're playing Sony CDs
![]() |
|
#5
|
||||
|
||||
|
Quote:
LOL Sony BMG TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14 VIP Member Of ASAP - (Alliance of Security Analysis Professionals™) Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.147 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's. |
|
#6
|
||||
|
||||
|
Why Admin? Try to give them LUA with SRP implemented. I am sure they'll get 99.9% protection from getting infected. Try to tell your dad that they should run LUA all the time unless and until they want to install anything.
__________________
∆√♪ηάکђ ℓєтک υηcσммpℓιcαтє http://www.adminus.net http://technonxt.wordpress.com |
|
#7
|
||||
|
||||
|
Quote:
May be the news paper website is infected one...Yesterday i saw an Indian Newspaper website infected with Rootkit.Win32.Agent.ey. This Rootkit have Stealth-mode characteristics which is common to Rootkits. And i wonder that their IT Admins are very much unaware of the same. What a shame on them !!!
__________________
∆√♪ηάکђ ℓєтک υηcσммpℓιcαтє http://www.adminus.net http://technonxt.wordpress.com |
|
#8
|
|||
|
|||
|
Thanks for all your answers, I will study the solutions.
At first I thought about that the ads of the newspaper or fleemarket/trade site might be infected. I scanned it (with a freeware rootkit scanner) and there was nothing today, deleted most items from a local settings/temp folder. Hope this helps too. |
|
#9
|
|||
|
|||
|
I found one today, it was a swf file so maybe from a flash ad. But if its from an ad many people would have this rootkit.
Maybe its better to use linux ![]() |
|
#10
|
|||
|
|||
|
Quote:
Uninstall Flash and Java? Or: uninstall Java (too insecure) and use the mvps HOSTS file ? That will cut down on the ads. If it's too slow, disable the Windows DNS client. Maybe Returnil ? |
|
#11
|
|||
|
|||
|
Quote:
Bingo! |
|
#12
|
||||
|
||||
|
Install MBRGuard to protect MBR from Rootkits.
http://www.blueridgenetworks.com/sup...rd/mbguard.php Limited User Account. Dont install JAVA.
__________________
Win7PRO64bit | SUA | SRP | UAC | EMET | SpywareBlaster | MVPSHOST | OpenDNS | SandboxIE | Privoxy | Windows Image Backup . built-in security + sandboxing fag. |
|
#13
|
||||
|
||||
|
Quote:
I can't live without Flash lol. If you want Flash, go install Chrome and run it with the command: -incognito --safer-plugins so the Flash plugin are locked in a sandboxed. or you could just use sandboxie to run your browser.
__________________
Win7PRO64bit | SUA | SRP | UAC | EMET | SpywareBlaster | MVPSHOST | OpenDNS | SandboxIE | Privoxy | Windows Image Backup . built-in security + sandboxing fag. |
|
#14
|
||||
|
||||
|
You don't mention email. Could that be a means of infections too?
I also recommend Sandboxie. I just recently started using it and it's pretty simple to use. The only change I made to the defaults was to delete the sandbox when the last program in it ends. I think it would make a big improvement for them. |
|
#15
|
||||
|
||||
|
Quote:
Is windows up to date would be a good first question :-) |
|
#16
|
||||
|
||||
|
Quote:
__________________
DefenseWall HIPS/Personal Firewall Emsisoft Anti-Malware 7.0 VoodooShield Look 'n' Stop Firewall (Phant0m Ruleset) Last edited by JRViejo : May 3rd, 2010 at 01:15 AM. Reason: De-linked YouTube URL - JRViejo |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|