Ad

Simple ways to keep your computer safe and secure

It is a fact; the Internet is just not a safe place to connect your computer to. There are worms constantly scanning for vulnerable computers to infect, trojans disguised as helpful programs but actually install malicious ones, spyware that reports your activities back to their makers, and hijackers that take control of your web browser and browsing experience. For those people who have been the victim of one of these mentioned infections, removing them and getting your computer back in your control can be a daunting and frustrating experience. The purpose of this article is to teach you how to setup your computer in such a way that you minimize as much as possible the risks of contracting one of these infections. Each step is very easy to do and regardless of your computer experience you will have no trouble following along. It is also important to note that there is not one step listed below that is more important than the other. They are all equally important to keeping your computer safe and secure.

1. Educate yourself and be smart about where you visit and what you click on - Understanding how you can get infected and what to avoid when using the Internet will be the most important step in keeping your computer clean and secure. The majority of people who have infections on their machines were infected due to lack of knowledge and clicking on things that they should not. I will provide a list of actions under this step that you should not do:

1. Do not open attachments from users that you do not know. This is one of the most effective ways for viruses to infect you. If you do not know the user, then simply do not open the email and delete it.

2. Never open an attachment that is a .exe, .pif, .com, or .bat unless you specifically know the file is clean. The majority of these are always bad!

3. If you visit a site and a popup appears saying that your computer is unsafe, ignore it! These are gimicks that are used to make you click on the ad which then can potentially install unwanted malware. To make your browsing experience safe and secure, we recommend you to use Trend Micro’s free Utility called TrendProtect™.
There is an excellent list that contains a list of antispyware apps that should be avoided and a list of ones that are recommended can be found here:
Rogue
/Suspect Anti-Spyware Products & Web Sites

4. When you go to a site and a popup occurs, many times they will make them look like a normal Windows message box in order to trick you into clicking on them. Instead just close them by clicking on the X.

5. Do not visit porn sites! I know some of you may not be happy about this, but the reality is that the majority of spyware and browser hijackers are put on your computer through porn sites.

6. Do not visit warez sites! Not only is pirated software illegal, but it is a breeding ground for malware.

7. Do not visit crack sites! Many of the cracks include malware in them!

8. If you use P2P software, make sure you are careful about what you open. Malware is all over the P2P networks.

9. Read the license agreement for any software that you install. Many free downloads are offered with spyware and other programs that you DO NOT want on your computer. Reading the agreement may help you to spot them.

2. Use an AntiVirus Software - It is very important that your computer has an antivirus software running on your machine. By having an program running, files and emails will be scanned as you use them, download them, or open them. If a virus is found in one of the items you are about to use, the antivirus program will stop you from being able to run that program and therefore infect yourself.

3. Update your AntiVirus Software - There is no point running an antivirus program if you do not make sure it has all the latest updates available to it. If you do not update the software, it will not know about any new viruses, trojans, worms, etc that have been released into the wild since you installed the program. Then if a new infection appears in your computer, the antivirus program will not know that it is bad, and not alert you when you run it and become infected. Therefore it is imperative that you update your Antivirus software at least once a week (Even more if you wish) so that you are protected from all the latest threats.

Install an Anti-Spyware Program - Just as you installed and use an antivirus program, it is essential these days to use a Spyware protection and removal program. These programs can be used to scan your computer for spyware, dialers, browser hijackers, and other programs that are malicious in nature. Although nowadays almost all reputed Antivirus Softwares are bundled with anti spyware.

4. Occasionally Run Online Virus Scans - Unfortunately not all antivirus programs are created equal. Each program may find infections that other antivirus programs do not and vice-versa. It is therefore recommended that you occasionally run some free online antivirus scanners to make sure that you are not infected with items that your particular antivirus program does not know how to find. Two online scanners that we recommend are:

Kaspersky Web scanner

Trend Micro Housecall


Every once in a while, maybe once every 2 weeks, run one or both of these scanners to see if they find anything that may have been missed by your locally installed antivirus software.

5. Visit Microsoft's Windows Update Site Frequently - If you are a Windows users you must visit http://www.windowsupdate.com regularly. This site is a Microsoft site that will scan your computer for any patches or updates that are missing from your computer. It will then provide a list of items that it can download and install for you. When visiting the site, if it asks if you would like to install the Windows Update software, allow it to do so and it should only ask you to do this once. When the site is loaded you should then allow it to check for new updates and download any that it finds. If it has you reboot your computer, reboot and when your back at the desktop visit the site again and check for new updates. Repeat this process until there are zero critical updates available. This will ensure your computer has all of the latest security updates available installed on your computer and is secure from any known security holes.

  1. Visit the Apple Security Updates Site Frequently - If you are an Apple user then you frequently check the Apple Security Site for any new updates and download them if they are available. Information on finding and downloading the latest updates can be found at the Apple security site that we linked to earlier in this step.
  2. Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. You may say "Why do I need a firewall?" I have all the latest updates for my programs and operating system, so nobody should be able to hack into my computer". Unfortunately that reasoning is not valid. Many times hackers discover new security holes in a software or operating system long before the software company does and therefore many people get hacked before a security patch is released. By using a firewall the majority of these security holes will not be accessible as the firewall will block the attempt.

8. Update your security programs regularly - As always if you do not update your programs, your programs will not be able to find the newest infections that may be racing around the Internet. It is therefore important that you upgrade the software and spyware/virus definitions for a particular program so that they are running the most effectively.

9. Switch to another browser, like Firefox, or make your Internet Explorer more secure - The latest version of Internet Explorer 8 is now shipped with much more secure settings. On the other hand, if you use Internet Explorer 6 there are settings that need to be changed. With that said you have two choices; either make Internet Explorer 6 more secure or switch to another browser like Mozilla Firefox. It's an excellent browser and is secure right after installing it. You can find more info on switching from Internet Explorer to Firefox here

Switching from Internet Explorer to Firefox



If you decide you would rather continue to use Internet Explorer, then follow these steps to make it more secure:

1. From within Internet Explorer click on the tools menu and then click on Options.

2. Click once on the Security tab

3. Click once on the Internet icon so it becomes highlighted.

4. Click once on the Custom Level button.

1. Change the Download signed ActiveX controls to Prompt

2. Change the Download unsigned ActiveX controls to Disable

3. Change the Initialize and script ActiveX controls not marked as safe to Disable

4. Change the Installation of desktop items to Prompt

5. Change the Launching programs and files in an IFRAME to Prompt

6. Change the Navigate sub-frames across different domains to Prompt

7. When all these settings have been made, click on the OK button.

8. If it prompts you as to whether or not you want to save the settings, press the Yes button.

5. Next press the Apply button and then the OK to exit the Internet Properties page.

By following all these steps you are sure to keep your computer at minimal risk to future infections or hack attempts. This is unfortunately not a fool proof method of securing your computer as new risks are released almost every day, but your susceptibility to these attacks will be diminished greatly.

Data Leaks, Mobile Trends, and Risky Small Business–Key Findings


Threat Landscape

Data Leaks, Mobile Workers, and Risky Small Business—Key Findings of Annual User Study

Each year, Trend Micro polls 1600 corporate end users in the U.S., U.K., Germany, and Japan to better understand their perceptions of and experiences with Web threats as they relate to the workplace. Respondents are grouped according to company size, with a small company defined as less than 500 employees in the U.S., U.K., and Germany and less than 250 employees for Japan. A total of 800 computer users from small companies across the U.S., U.K., Germany and Japan were surveyed. The results were then compared to previous studies conducted in 2006 and 2007 to monitor trends. The following article highlights several key findings from 2008 survey results.Data Leaks—A Growing ConcernFor the first time in the Corporate End User Study, Trend Micro surveyed computer users about the prevalence of data leaks within their business environments. Data leaks occur when employees leak sensitive information about customers, finances or intellectual property in violation of security policies or even regulatory requirements. Surprisingly, authorized personnel cause most corporate data breaches—probably because employees have easy access to valuable corporate data. Despite the fact that corporate enterprises have deployed protective measures such as virtual private networks (VPNs), firewalls, and network monitoring to prevent unauthorized external access to proprietary information, these solutions fail to adequately address the rising threat from internal users. Leaks can occur either through deliberate policy breaches, such as stealing data for financial gain, or by accident, such as an employee misplacing a thumb drive or losing a laptop containing customers' account numbers.The explosion of messaging systems, wireless networking, and USB storage devices has also made protecting critical corporate information increasingly difficult. And growing numbers of telecommuting and traveling employees have increased mobile device use and the tendency to transmit sensitive information via email. This creates a challenge for today's companies to protect against the loss or theft of corporate data assets—either by employees or contractors.Because data leaks are becoming an increasing concern, Trend Micro polled end users to determine if users understand which information within their organization is considered confidential and therefore worthy of protection. According to the survey, U.S. end users are more likely than end users in the U.K. or Japan to identify confidential company data. Perhaps this is because U.S. companies adopted the Internet within the workplace early on and therefore developed more policies and regulations to govern the use of proprietary and confidential data.The survey also indicates that end users in large companies in Japan better understand what constitutes confidential company data, compared to smaller organizations. This may be due to the greater likelihood that large companies conduct compliance training compared to smaller organizations, increasing the probability that users would better understand which information is considered confidential. The survey also noted that laptop users in the U.S. and U.K. are more likely to fully understand which information is confidential than desktop or workstation users in those countries.Perhaps most alarming was the percentage of users who reported leaking data. Overall, in all countries surveyed, six percent of end users admitted to leaking confidential information outside the company. This is especially disconcerting because the survey was based on self reporting, which would indicate that actual numbers are probably much higher since most people would not admit leaking confidential information.Also, while six percent of end users admitted to having leaked company information, 16 percent believe other employees caused data leaks. Interestingly, end users in the U.S., U.K., and Germany are more likely to admit to leaking company data, either intentionally or accidentally, than end users in Japan.According to the survey, in all countries, it is more common for large organizations to have established preventative policies than small companies. However, the survey also indicates that employee data leaks are believed to be more common in large organizations. This might indicate that data leaks occur, regardless of whether companies have set policies.The survey also asked end users about the amount of training they received to prevent data leaks. According to survey results, one in seven U.S. end users has been trained on their company's data leak policy and significantly more users in the U.S. have been trained, compared to the U.K. In all countries, a majority of trained end users think they would score highly if tested on their company's data leak policy.The survey results indicate that companies, particularly small businesses, can be more proactive in preventing data leaks. The increasing challenge to effectively manage data breaches is becoming a serious security concern to companies forced to comply with strict government regulations regarding data handling, such as the Gramm-Leach-Bliley Act, the European Union Directive on Data Protection, Sarbanes-Oxley, and the Health Insurance Portability and Accountability Act (HIPAA). Failing to comply can trigger fines and litigation, not to mention brand damage and negative press.Laptop Users' Activities Differ by CountryAccording to the survey, in the U.S., laptop end users are not any more likely to use the Internet for personal reasons while off the company network compared to when they are on the network. UK laptop end users, however, are more likely to check personal email and browse Web sites while connected through their company's network. German and Japanese laptop end users are more likely to download executable files while connected through their company's network—perhaps indicating that users in both countries have faster Internet connections at work. Interestingly, Japanese laptop users are less likely than laptop users elsewhere to connect to the Internet outside the company network, and U.S. users are more likely to connect at airports.In the U.K., Germany, and Japan, mobile users are more likely than desktop users to send confidential information via Instant Messaging or Webmail.Risky BusinessAccording to the survey, in the U.K., Germany, and particularly in Japan, employees of small companies take more online risks while on the company network compared to their counterparts in larger organizations. The study found that certain risky activities such as browsing Web sites unrelated to work, shopping online, visiting social networking sites, downloading executable files, and checking personal Webmail are more likely to occur amongst small businesses.For example, 32 percent of U.K. small business employees admitted to downloading executable files that can potentially lead to Trojan or virus attacks and, ultimately, identity and data theft. Checking personal email is the most popular non-work related online activity for German workers, especially at smaller companies—70 percent of small-business employees check personal email at work, compared to 59 percent in large companies. In Japan, the study revealed that most personal Internet activities that occurred were more likely to happen in small businesses.Despite a higher level of risky online behavior occurring, only about 50 percent or fewer end users within small companies had an IT department, which may explain why spam, phishing, and spyware were more commonly reported within these companies compared to larger organizations.In all countries surveyed, small organizations are less likely to have established preventative policies than large companies. This probably explains why the survey found that small company end users in Japan are less aware of confidential data concerns compared to end users in larger organizations. Only 33 percent of small business end users said they understood what constitutes confidential company data compared to 46 percent from large companies. This held true for users in both the U.S. and the U.K. as well, but the disparity was less.

Brazil: Orkut Phishing Mail Leads to Data-Stealing Malware



Trend people recently captured a spam email that appeared to be from Orkut. It is written in Portuguese, and translates to the following (via GoogleTranslate):

Problems with your account.

Dear User,

We received some complaints against your profile saying you are "using copyrighted material," and before Orkut disables your account unfairly, asks for you to contact us stating the problem.

Some information from the complaint:

Your Profile: {malicious link to phishing page}
Report: {directly download malware}

* Please do not reply to this email, follow the instructions in the report of the complaint.

Warning: Your period for justification is 48h.

Regards,
{name}
Administration Orkut.com

Note: *We are taking measures in accordance with the laws in your country. (Brazil)
* Please meet the requirements of the report within the stipulated period.

Figure 1 shows the Portuguese Orkut spam (click to view larger version). Users who click on the first link on the email are led to a phishing page (see Figure 2). At this point users may be led to key in their credentials at this fake site, compromising access to their Orkut accounts. When the browser opens to the phishing page, the browser also automatically downloads a certain file which, should the user accept the download, when saved and run, introduces a BANKER variant (TROJ_BANKER.GAT) to the system.

Click for larger view
Click for larger view


BANKER variants and their components are notorious malware that together sit silently in victims’ PCs waiting until users browse online banking sites. These then either change the online banking site from the real site to a fake one or directly steal keyed in information such as user names and passwords.

Online banking is a commonly accepted method of transaction and managing funds in Latin America because of the sites’ ease of use and offer of convenience. This compounds the risk of this targeted attack netting in more users than usual. Furthermore, the Orkut spam is written in Portuguese, which unknowing users may take to mean that the mail is valid.

Users are always advised to enter sites requiring logins using their clean bookmarks or by typing in the correct URL at the browser address bar. Also, ignore email (and the links therein) that come from doubtful or unknown sources. Smart Protection Network protects Trend Micro users from this attack by identifying the phishing mail as malicious, by blocking access to the phishing page, by preventing the download of the malicious file, and by detecting the downloaded file (and related malware) as malicious.

How to Avoid Spam:Tips to Avoid Spam




Listed below are a number of suggestions that can help prevent your email address from becoming a target to spammers.

  • Do not post your e-mail address in an unobfuscated form on the Internet. If you need to post your e-mail address, obfuscate it so it cannot be easily harvested such as “name –at- hotmail – dot- com,” Or if you need to include your e-mail address in your signature, include a small graphic image containing your e-mail address.
  • Check to see if your e-mail address is visible to spammers by typing it into a Web search engine such aswww.google.com. If your e-mail address is posted to any Web sites or newsgroups, remove it if possible to help reduce how much spam you receive.
  • Lots of ISPs provide free e-mail addresses. Set up two e-mail addresses, one for personal e-mail to friends and colleagues, and use the other for subscribing to newsletters or posting on forums and other public locations. If you have a more complex e-mail address, it is less likely to receive spam than one that could be easily dictionary-attacked.
  • Many ISPs also offer free spam filtering. If this is available, enable it. Report missed spam to your ISP, as it helps reduce how much spam you and other members of the same ISP receive. If your ISP does not offer spam filtering, use anti-spam software to reduce the amount of spam delivered to your inbox.
  • When replying to newsgroup postings, do not include your e-mail address.
  • When filling in Web forms, check the site's privacy policy to ensure it will not be sold or passed on to other companies. There may be a checkbox to opt out of third party mailings. Consider opting out to receive less opt-in e-mail.
  • Never respond to spam. If you reply, even to request removing your e-mail address from the mailing list, you are confirming that your e-mail address is valid and the spam has been successfully delivered to your inbox, not filtered by a spam filter, that you opened the message, read the contents, and responded to the spammer. Lists of confirmed e-mail addresses are more valuable to spammers than unconfirmed lists, and they are frequently bought and sold by spammers.
  • Do not open spam messages wherever possible. Frequently spam messages include "Web beacons" enabling the spammer to determine how many, or which e-mail addresses have received and opened the message. Or use an e-mail client that does not automatically load remote graphic images, such as the most recent versions of Microsoft® Outlook® and Mozilla Thunderbird.
  • Do not click on the links in spam messages, including unsubscribe links. These frequently contain a code that identifies the e-mail address of the recipient, and can confirm the spam has been delivered and that you responded.
  • Never buy any goods from spammers. The spammers rely on very small percentages of people responding to spam and buying goods. If spamming becomes unprofitable and takes lots of effort for little return, spammers have less incentive to continue spamming. Would you risk giving your credit card details to an unknown, unreputable source?
  • If you have an e-mail address that receives a very large amount of spam, consider replacing it with a new address and informing your contacts of the new address. Once you are on lots of spammers' mailing lists, it is likely that the address will receive more and more spam.
  • Make sure that your anti-virus software is up to date. Many viruses and Trojans scan the hard disk for e-mail addresses to send spam and viruses. Avoid spamming your colleagues by keeping your anti-virus software up to date.
  • Use the firewall included with your operating system, or use a firewall from a reputable company, to avoid your computer being hacked or infected with a worm and used as a spam-sending zombie.
  • Do not respond to e-mail requests to validate or confirm any of your account details. Your bank, credit card company, eBay, Paypal, etc., already have your account details, so would not need you to validate them. If you are unsure if a request for personal information from a company is legitimate, contact the company directly or type the Web site URL directly into your browser. Do not click on the links in the e-mail, as they may be fake links to phishing Web sites.
  • Do not click on unusual links. Confirm the sender did send the e-mail if it looks suspicious.
  • Never give out your login details to anyone.
  • IT departments should train their users not to give out sensitive information.

Top Ten Tips for Protecting Corporate End Users

Based on results from the 2008 Corporate End User Study, Trend Micro advises both end users and businesses to observe the following precautions to avoid Web threats and address the increasing problem of data leaks to ensure a safer computing experience.

Following are some basic safety measures you and your children can implement together today particularly if your children are just beginning to explore the Internet:

1. To prevent data leaks and to combat increasing levels of Web threats, install a multi-layered strategy approach that locates security in the cloud before data reaches the gateway. Also protect data at the Internet gateway where the Internet connects to a corporate or Internet Service Provider network. Additionally, locate protections at the endpoint so data is analyzed on the user's PC or at the server.
2. Deploy vulnerability scanning software on the network and ensure all operating systems and other software applications are up-to-date and patched with the most recent security patches. Enable the "Automatic Update" feature in all users' operating systems, Web browsers, and applications.
3. Issue security policies and Internet usage guidelines on PC and laptop usage and mobile devices to control the information accessed.
4. Advise employees not to disclose sensitive information when receiving an email or telephone call. Banks and other institutions never call and request account information or Social Security numbers over the telephone or by email.
5. Develop corporate guidelines that advise against opening attachments or clicking on links contained in email messages from unknown senders. Also, train users to avoid installing files from unknown companies or organizations.
6. Educate end users about emerging threats and their consequences, emphasizing business-specific outcome such as a damaged reputation, lost customers, or regulatory fines.
7. Advise employees where they may or may not surf online. Many employees are unaware that Trojans and other malware can appear as blog comments and other code embedded on Web pages.
8. Prevent unnecessary protocols from entering the corporate network, such as P2P communication protocols and IRC.
9. Restrict user privileges for all network users. For example, kernel-level rootkits are implemented as device drivers; therefore, denying users the right to "load and unload device drivers" will largely block them.
10. To help protect mobile users on laptops, consistently update all systems and choose security products with in-the-cloud updates.

How to Protect against IM Threats

The messaging environment continues to evolve at an incredibly alarming rate. When Samuel Morse typed the message, "What hath God wrought!" on 24 May 1844, the world of message delivery changed forever. But never has it changed more than in the past 5-to-10 years with the explosion of email and Instant Messaging (IM). Once limited to desktops, IM is now available via handheld devices and cell phones, allowing users to chat from virtually anywhere, even becoming a staple mode of communication in business environments. With recent developments making IM protocols interoperable, users from one network are now about to communicate with users on another network.

However, IM is accompanied by its own share of security risks. Because IM is generally unprotected and unmonitored, it's vulnerable to attacks and can easily expose all users in an IM contact list to the same attacks via IM sent from that machine, creating the potential for rapid proliferation. In such a scenario, it's likely that any malicious code that propagates through one of the protocols will also propagate through the other, potentially impacting more users with minimal effort.

The most prevalent threats to IM include:
* Worms and Trojan Horses

Similar to threats sent by email, worms and Trojan horses via IM can compromise the integrity of IT systems. Too many IT departments focus on solely on email threats because they are not aware of the number of people using IM in their businesses. This is because individual users can load IM programs directly onto local computers, and IM traffic is often undetectable at the network level. According to the IMlogic Threat Center, "90% of IM-related security attacks included worm propagation; 9% delivered viruses; 1% exploited known client vulnerabilities or exploits." Via an IM program, it's possible for a Trojan horse to configure the client to give access to all files on a computer via peer-to-peer file sharing. Ultimately this opens up the entire computer system to attackers.

* Password Stealing and Impersonation

Hackers can use Trojan horses to gain access to an IM password if it's stored on the computer. Using this method, hackers can have access to the user's screen name and the user's entire list of IM contacts. Impersonation is not only harmful to the victim whose password has been stolen, but to anyone who interacts with the hacker and divulges personal information, or executes any files sent by the hacker under the guise of the user.

* Theft of Log Files

Similar to other forms of information theft, IM log files, which may be stored on a user's computer, are vulnerable to hackers. In many cases, these files may contain sensitive or private data from a past IM conversation the user has long since forgotten about. This information is readily available via IM logs, however, and can be devastating to businesses if exposed, causing tainted reputations, legal problems, and in some cases, loss of the business.

*Denial-of-Service (DoS) Attacks

A DOS attack via IM happens when a hacker sends a flood of messages for the purpose of overloading the resources of a computer or network. By the time the victim tries to add the hacker's screen name to the list of parties that the IM program should ignore, the computer may freeze or crash. Though DoS attacks tend to be more of a hassle and less of a threat than other types of hacks, they can be harmful when hackers combine DoS attacks with other security breaches such as shutting out users from their accounts to hijack systems.

* Privacy Intrusion

Outside parties can capture information to use in malicious ways, and employees may not be aware of the ramifications of their IM conversations. Businesses could be legally or financially at risk if employees send confidential information that's subsequently gathered by outside parties. Many IM programs don't offer encryption, making it easy for a third-party to eavesdrop on IM conversations using different types of programs such as packet sniffers. Businesses can deal with these risks by enforcing an IM policy that restricts the type of information that can be exchanged via IM and setting up a system to encrypt IM conversations.

TO BE CONTINUED ON PAGE 2

How to Protect against IM Threats 2

* SPIM

Similar to spam, spim is unsolicited messages sent via IM. Spim can be used to lure unsuspecting users to websites designed to collect private information. Web bots deployed by advertisers and spammers often collect screen names from public directories where individuals can list their IM screen names. To reduce spim, businesses should advise employees against listing screen names on any public directories or websites, and also to configure their IM clients to accept messages only from an approved list of contacts.

While many of these threats have the potential to wreak havoc on any business, there are a few steps businesses can take to mitigate IM threats so they can fully enjoy the benefits of IM:

* Install IM Security Tools

IM security tools span a variety of functions from capturing data sent over IM, to monitoring and tracking unusual IM behavior which may indicate misuse or virus-related security breaches. By installing IM security tools, businesses will have a more comprehensive, centralized solution to help manage IM usage within the company.

* Educate Employees and Create Corporate Policies

Employee education on any exchange service is paramount in securing the IT infrastructure, but especially on IM usage because of the potential for rapid proliferation throughout the network. Businesses should make it a priority to learn about the best safety and security practices and incorporate them into company policies. To protect businesses and employees, businesses should define appropriate uses of IM in the workplace and encourage precautionary measures such as not storing IM passwords on the computer.

*Secure IM Logs

Because IM programs automatically create and store logs of all conversations on a user's computer, hackers can obtain valuable information on a business, including specific statements made during a conversation as well as business secrets discussed via IM. One way to secure IM logs is to store them behind a corporate firewall or even delete the logs. These options are available in the preferences section of the program.

* Use Vulnerability Management Tools for Compliance

Businesses can install and use vulnerability management tools to gain an overview of IM software installed on employee machines. Using these tools, they can monitor whether employees have made any changes to their IM programs that violate business policies, and make sure that desktop firewall and antivirus programs are being used properly.

* Install Desktop Antivirus and Firewall Programs
Since spam sent over IM typically requires users to download and open an attachment. Security at the desktop and firewall level can guard against threats by blocking an attachment or cleaning an infected file. Installing desktop firewalls help protect individual machines from attacks from within an organization or through a LAN. Desktop firewalls are also good for those in a remote office or who handle sensitive data. Businesses should also install desktop antivirus programs to provide a final line of defense against viruses, worms, and Trojan horses.

* Install and Update IM Patches

The major public IM networks frequently deploy IM patches in response to newly discovered vulnerabilities in their programs. Businesses can reduce the risk of attacks to their computers via IM by installing and updating IM patches regularly.

There are many advantages to using IM in a business setting. If businesses choose to use this communication tool, they need to understand the security threats to IM and how to protect their business. By educating employees, enforcing policies, installing protective technologies, and, where possible, encrypting IM conversations, organizations can continue to enjoy the benefits of using IM as a business tool while also managing its risks.

Get Rs.500 Just for FREE signup. Get paid for Online Surveys.

Hi Friends,

I have found an interesting website for earning money in Internet. You can Earn Rs.2000 Jobs is simple doing surveys in the internet. It take only 2-5 min to complete the work. On an average you can Earn. Rs.1000 per day. Click this
http://www.surveyspaysu.com?id=193579 . and register today.

Earlier I was also thinking this thing as fake, but no tried and tasted and wonders...It actually works, because it's totally run and organise by India and this is for Indian Surveys ONLY.

Go get started and earn now, there's only risk of your 2 minutes signing up timing else you are losing anything, but if you don't join you might lose lost of extra money.


Get Rs.500 Just for FREE signup. Get paid for Online Surveys.

Convert Your Spare Time into Money. Just Register Free By clicking this Link http://www.surveyspaysu.com?id=193579 . Make Money By Filling simple online surveys. Its All FREE.

Worldwide Online Survey Jobs. Signup now and get Rs.500 Free.

Wanted Online Internet job workers. Spend 30 Minutes a Day. Complete online survey form daily and earn Rs.20000 to 30000 per month. Click http://www.surveyspaysu.com?id=193579 .and Register FREE


Dear friend, Online Survey Jobs for Indians. Get Rs.500 just for FREE signup

I have Earned Rs.500 within 10 min and still i can earn more by just doing simple online survey jobs. I spend only 30 min a day. You can also do this job. just click http://www.surveyspaysu.com?id=193579 . and Register FREE


Paid Survey Jobs available all over world. No investment required.

Get paid for your opinion. It is easy, just spend 30mts daily. Earn Rs.20000 to Rs.30000 per month. Get surveys into your email daily and earn daily. Please visit http://www.surveyspaysu.com?id=193579

Regards,
Kandarp Devashrayee

What Is Virus, Malware, Trojan or Worm?

Virus Primer

What is Malware?
A malware is a program that performs unexpected or unauthorized, but always malicious, actions. It is a general term used to refer to viruses, Trojans,
and worms. Malware, depending on their type, may or may not include replicating and non-replicating malicious code. Due to the many facets of malicious
code or a malicious program, referring to it as malware helps to avoid confusion. For example, a virus that also has Trojan-like capabilities may be called
malware.


What is a virus?
A computer virus is a program – a piece of executable code – that has the unique ability to replicate. Like biological viruses, computer viruses can spread
quickly and are often difficult to eradicate. They can attach themselves to just about any type of executable file and are spread as files that are copied
and sent from individual to individual.In addition to replication, some computer viruses share another commonality: a damage routine that delivers the virus
payload. While payloads may only display messages or images, they can also destroy files, reformat your hard drive, or cause other damage. If the virus does
not contain a damage routine, it can cause trouble by consuming storage space and memory, and degrading the overall performance of your computer.


What is a Trojan?
A Trojan is a malware that performs a malicious action, but has no replication abilities. Coined from Greek mythology's Trojan horse, a Trojan may arrive as
a seemingly harmless file or application, but actually has some hidden malicious intent within its code.Trojan malware usually have a payload. When a Trojan
is executed, you may experience unwanted system problems in operation, and sometimes loss of valuable data.


What is a worm?
A computer worm is a self-contained program (or set of programs) that is able to spread functional copies of itself or its segments to other computer systems.
The propagation usually takes place via network connections or email attachments. More recent worms have also discovered ways to propagate using Instant
Messengers, via file sharing applications, and by collaborating with other malware such as Trojans or other worm variants. WORM_BAGLE.BE, for example, forms
a vicious worm-Trojan cycle with TROJ_BAGLE.BE, in which the worm mass-mails copies of the Trojan, and the Trojan downloads copies of the worm. Additionally,
the FATSO family is a family of worms that propagate via an
instant messaging application and a popular peer-to-peer file sharing application. Some worms may have an additional payload, such as preventing a user from
accessing antivirus Web sites, or stealing the licenses of installed games and applications.


Life Cycle of a Malware
The life cycle of a malware begins when it is created and ends when it is completely eradicated. The following outline describes each stage:

Creation
Until recently, creating a malware required knowledge of a computer programming language. Today anyone with basic programming knowledge, and Internet access,
can create a malware. Whole Web sites exist whose only intent is to spread malicious code, and to encourage individuals to develop their own harmful version
of already existing, and tried-and-tested malicious programs.

Replication and Propagation
Malware propagate in a number of ways. Worms may spread via email, instant messengers, or network shares. Viruses replicate within a system, while some
viruses also have automatic propagation techniques similar to worms. Trojans. while not having any automatic form of replication and propagation, are
nevertheless available all over the Internet, and the links to download them from may be included in email messages, or other Web sites.For more information
on the propagation techniques of today's malware types, read more here.


Activation
Most malware perform their malicious activities upon execution. Some have certain payloads that are activated only at a certain trigger date, or with the
onset of a specific trigger condition.

Discovery
This phase does not always follow activation, but typically does. When a malware is detected and isolated, it is sent to the ICSA in Washington, D.C., to
be documented and distributed to antivirus software developers. However, with the rapid development of technology, and the ease by which malware authors
create their programs, most malware are released to unsuspecting users even before they are discovered by the "authorities". This is all the more reason
to protect your system from the threats that surround the computing world today.To read more about what you can do to prevent your system from becoming
infected, read more here.


Assimilation
At this point, antivirus software developers modify their software so that it can detect the new malware. This can take anywhere from one day to six months,
depending on the developer and the malware type.

Eradication
If enough users install up-to-date virus protection software, any malware can be wiped out. So far no malware have disappeared completely, but some have
long ceased to be a major threat.

What can you do to Protect against Malware?
There are many things you can do to protect against malware. At the top of the list is using a powerful antivirus product, and keeping it up-to-date with
the latest pattern files. You may also visit the ICSA lab's Web site for further suggestions.