Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy problems
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 25th, 2010, 11:21 AM
RTKNM RTKNM is offline
Infrequent Poster
 
Join Date: Apr 2010
Posts: 3
Default How to prevent rootkits.

My parents dont`s use their pc very much, only visit a few websites a day. Nevertheless the regularly have rootkits on their pc. They only visit websites such as newspapers and a known dutch trade site.
Is it possible that someone sends them these rootkits as they have a fixed ip?
What can I do to prevent it?
The pc is protected with a known free av and firewall. They are up to date and I asked them to use Firefox .
Thank you.
  #2  
Old April 25th, 2010, 12:36 PM
ploder ploder is offline
Infrequent Poster
 
Join Date: Apr 2009
Posts: 36
Default Re: How to prevent rootkits.

Perhaps after their system has been cleaned try something like Sandboxie? http://www.sandboxie.com/
  #3  
Old April 25th, 2010, 05:43 PM
wat0114
 
Posts: n/a
Default Re: How to prevent rootkits.

If they are running as administrator, create a limited account for them to use instead for their surfing and other online use. How are these "regular" rootkits being removed? BTW, Securing you PC and Data... is an excellent read.
  #4  
Old April 25th, 2010, 09:22 PM
hierophant's Avatar
hierophant hierophant is offline
Frequent Poster
 
Join Date: Dec 2009
Posts: 854
Default Re: How to prevent rootkits.

Perhaps they're playing Sony CDs
  #5  
Old April 25th, 2010, 11:15 PM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,614
Default Re: How to prevent rootkits.

Quote:
Originally Posted by hierophant
Perhaps they're playing Sony CDs

LOL Sony BMG

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.147 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #6  
Old April 26th, 2010, 12:09 AM
AvinashR's Avatar
AvinashR AvinashR is offline
Very Frequent Poster
 
Join Date: Dec 2009
Location: New Delhi Metallo β-Lactamase 1
Posts: 2,060
Default Re: How to prevent rootkits.

Why Admin? Try to give them LUA with SRP implemented. I am sure they'll get 99.9% protection from getting infected. Try to tell your dad that they should run LUA all the time unless and until they want to install anything.
__________________
∆√♪ηάکђ
ℓєтک υηcσммpℓιcαтє
http://www.adminus.net
http://technonxt.wordpress.com
  #7  
Old April 26th, 2010, 12:15 AM
AvinashR's Avatar
AvinashR AvinashR is offline
Very Frequent Poster
 
Join Date: Dec 2009
Location: New Delhi Metallo β-Lactamase 1
Posts: 2,060
Default Re: How to prevent rootkits.

Quote:
Originally Posted by Triple Helix
LOL Sony BMG

TH

May be the news paper website is infected one...Yesterday i saw an Indian Newspaper website infected with Rootkit.Win32.Agent.ey. This Rootkit have Stealth-mode characteristics which is common to Rootkits. And i wonder that their IT Admins are very much unaware of the same. What a shame on them !!!
__________________
∆√♪ηάکђ
ℓєтک υηcσммpℓιcαтє
http://www.adminus.net
http://technonxt.wordpress.com
  #8  
Old April 26th, 2010, 03:27 PM
RTKNM RTKNM is offline
Infrequent Poster
 
Join Date: Apr 2010
Posts: 3
Default Re: How to prevent rootkits.

Thanks for all your answers, I will study the solutions.
At first I thought about that the ads of the newspaper or fleemarket/trade site might be infected.
I scanned it (with a freeware rootkit scanner) and there was nothing today, deleted most items from a local settings/temp folder. Hope this helps too.
  #9  
Old April 30th, 2010, 11:47 AM
RTKNM RTKNM is offline
Infrequent Poster
 
Join Date: Apr 2010
Posts: 3
Default Re: How to prevent rootkits.

I found one today, it was a swf file so maybe from a flash ad. But if its from an ad many people would have this rootkit.

Maybe its better to use linux
  #10  
Old May 1st, 2010, 04:49 AM
Fly Fly is offline
Very Frequent Poster
 
Join Date: Nov 2007
Posts: 1,865
Default Re: How to prevent rootkits.

Quote:
Originally Posted by RTKNM
I found one today, it was a swf file so maybe from a flash ad. But if its from an ad many people would have this rootkit.

Maybe its better to use linux

Uninstall Flash and Java?

Or: uninstall Java (too insecure) and use the mvps HOSTS file ?
That will cut down on the ads.
If it's too slow, disable the Windows DNS client.

Maybe Returnil ?
  #11  
Old May 1st, 2010, 01:01 PM
LockBox LockBox is offline
Very Frequent Poster
 
Join Date: Nov 2004
Posts: 2,081
Default Re: How to prevent rootkits.

Quote:
Originally Posted by Fly
Uninstall Flash and Java?

Or: uninstall Java (too insecure) and use the mvps HOSTS file ?
That will cut down on the ads.
If it's too slow, disable the Windows DNS client.

Maybe Returnil ?

Bingo!
  #12  
Old May 1st, 2010, 03:07 PM
Konata Izumi's Avatar
Konata Izumi Konata Izumi is offline
Very Frequent Poster
 
Join Date: Nov 2008
Posts: 1,512
Default Re: How to prevent rootkits.

Install MBRGuard to protect MBR from Rootkits.
http://www.blueridgenetworks.com/sup...rd/mbguard.php

Limited User Account.
Dont install JAVA.
__________________
Win7PRO64bit | SUA | SRP | UAC | EMET | SpywareBlaster | MVPSHOST | OpenDNS | SandboxIE | Privoxy | Windows Image Backup .
built-in security + sandboxing fag.
  #13  
Old May 1st, 2010, 05:21 PM
Konata Izumi's Avatar
Konata Izumi Konata Izumi is offline
Very Frequent Poster
 
Join Date: Nov 2008
Posts: 1,512
Default Re: How to prevent rootkits.

Quote:
Originally Posted by snowdrift
Also don't install Flash and use Privoxy to filter ads, MVPS HOSTS, Spyware Blaster, and Firefox with AdBlocker.

I can't live without Flash lol.
If you want Flash, go install Chrome and run it with the command:
-incognito --safer-plugins

so the Flash plugin are locked in a sandboxed.

or you could just use sandboxie to run your browser.
__________________
Win7PRO64bit | SUA | SRP | UAC | EMET | SpywareBlaster | MVPSHOST | OpenDNS | SandboxIE | Privoxy | Windows Image Backup .
built-in security + sandboxing fag.
  #14  
Old May 2nd, 2010, 08:59 AM
HAN's Avatar
HAN HAN is offline
Very Frequent Poster
 
Join Date: Feb 2005
Location: USA
Posts: 1,719
Default Re: How to prevent rootkits.

You don't mention email. Could that be a means of infections too?

I also recommend Sandboxie. I just recently started using it and it's pretty simple to use. The only change I made to the defaults was to delete the sandbox when the last program in it ends. I think it would make a big improvement for them.
  #15  
Old May 2nd, 2010, 01:10 PM
Baz_kasp's Avatar
Baz_kasp Baz_kasp is offline
Frequent Poster
 
Join Date: May 2008
Location: London
Posts: 593
Default Re: How to prevent rootkits.

Quote:
Originally Posted by RTKNM
My parents dont`s use their pc very much, only visit a few websites a day. Nevertheless the regularly have rootkits on their pc. They only visit websites such as newspapers and a known dutch trade site.
Is it possible that someone sends them these rootkits as they have a fixed ip?
What can I do to prevent it?
The pc is protected with a known free av and firewall. They are up to date and I asked them to use Firefox .
Thank you.

Is windows up to date would be a good first question :-)
  #16  
Old May 3rd, 2010, 01:01 AM
G1111's Avatar
G1111 G1111 is offline
Very Frequent Poster
 
Join Date: May 2005
Location: USA
Posts: 1,723
Default Re: How to prevent rootkits.

Quote:
Originally Posted by RTKNM
My parents dont`s use their pc very much, only visit a few websites a day. Nevertheless the regularly have rootkits on their pc. They only visit websites such as newspapers and a known dutch trade site.
Is it possible that someone sends them these rootkits as they have a fixed ip?
What can I do to prevent it?
The pc is protected with a known free av and firewall. They are up to date and I asked them to use Firefox .
Thank you.
First is to make sure all the rootkits, etc. are gone. -http://www.youtube.com/user/mrizos#p/u/144/nWfWJmB2kJc- for ideas. You may have to run from a bootable CD with A-Squared or Dr. Web Cureit. Worse case scenario is to reformat hard drive. Next run Secunia inspector: http://secunia.com/vulnerability_scanning/online/ to make sure everything is update, not only Windows but also Adobe Reader, Apple Quicktime, etc. Once computer is clean in addition to an Anti-Virus and firewall I would install either DefenseWall HIPS, Shadow Defender or Sandboxie (if they want something that is more configurable).

Last edited by JRViejo : May 3rd, 2010 at 01:15 AM. Reason: De-linked YouTube URL - JRViejo
 

Wilders Security Forums > Privacy Related Topics > privacy problems « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:25 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums