Computer Application, Maintenance and Supplies
Showing posts with label Antivirus. Show all posts
Showing posts with label Antivirus. Show all posts

Wednesday, July 04, 2012

Internet Doomsday 2012

Internet Doomsday 2012

Sebuah peringatan penting dipublikasikan oleh Federal Bureau Investigation (FBI) melalui situs resminya, agar para pengguna komputer untuk selalu berhati-hati dengan serangan DNSChanger Malware. Terlebih lagi pada tanggal 9 Juli 2012 mendatang (5 hari lagi) sebagai puncak Internet Doomsday 2012 atau Kiamat Internet 2012. Malware ini mampu mencegah instalasi software Antivirus dan update Operation System
pada komputer yang terinfeksi. Bahkan komputer tidak dapat mendeteksi ataupun menghentikan serangan Malware sekaligus membuka peluang atas serangan virus lainnya. Malware tersebut diam-diam mengubah pengaturan pada komputer yang terinfeksi dan mengarahkannya ke situs tertentu dengan sejuta iklan. Redirect link pada link tertentu memungkinkan Netter melihat dan/atau menge-Klik situs atau iklan tersebut yang memberi keuntungan tersendiri terhadap pelaku kejahatan Cyber ini berupa aliran dana ke rekeningnya.

Ketika pengguna komputer yang terinfeksi mengklik link tertentu berdasarkan hasil pencarian yang ditampilkan oleh mesin pencari, Malware mengarahkan komputer tersebut ke situs yang berbeda. Hal ini dituturkan JANICE K. FEDARCYK (FBI Assistant Director in Charge), mengingat bahwa artikel ini disadur sepenuhnya dari situs resmi FBI. Meski demikian, belum bisa dipastikan bahwa Internet Doomsday BENAR ADANYA akan terjadi 5 hari ke depan. Dimana, Internet akan mati total akibat serangan DNSChanger Malware.

Berdasarkan data FBI, saat ini komputer yang terserang malware ini telah mencapai 4 juta unit yang tersebar di 100 negara, termasuk setengah juta komputer di Amerika Serikat. Olehnya, patutlah Ambae.exe dan sobat Netter sekalian berhati-hati. Tanpa kehadiran malware ganas ini sekalipun, selayaknyalah kita semua waspada dengan segala ancaman dunia maya dibalik kehebatan dan kecanggihan yang dipertontonkannya.

Lalu apa langkah-langkah yang harus diambil untuk menghadapi dan mengantisipasinya...? Pihak FBI menganjurkan agar Netter mengunjungi DNS Changer Working Group (DCWG) lalu cek disini

Penting untuk dipahami, mengingat di dunia nyata beberapa waktu ini berkembang cerita bahwa pada tanggal 9 Juli 2012, semua perangkat komputer (baik yang terkoneksi dengan internet maupun yang Offline sekalipun) akan terserang malware tersebut. Ada pula cerita yang berkembang bahwa semua perangkat yang bisa Online, pada tanggal tersebut tidak akan mampu melakukan koneksi. Perlu diluruskan agar tidak menimbulkan ketakutan yang mencekam.

Sejak saat ini, DNSChanger Malware menyerang komputer yang telah terhubung melalui internet. Komputer yang telah terinfeksi, saat ini masih bisa terhubung ke internet melalui DNS palsu yang diciptakan Perusahaan Rogue. Tanggal 9 Juli 2012 nanti, sesuai mandat dari Manhattan Federal Court, FBI akan mematikan Rogue DNS Servers. Sehingga pada saatnya itu, tiap komputer yang telah terinfeksi DNSChanger Malware tidak dapat melakukan koneksi ke internet karena DNS palsu yang digunakannya selama ini akan dinonaktifkan. Wah...jadi bingung!!! Kalau ada yang kurang, harap ditambahkan dan diperbaiki ya sobat Blogger!!!

Bilamana komputer Anda terlanjur terdeteksi serangan tersebut, lakukan langkah-langkah berikut :
  • Segera laporkan status komputer Anda pada FBI sebagai korban serangan.
  • Perbaiki dan bersihkan komputer disini.
  • Gunakan Antivirus/Tools yang mumpuni dan up to date
Berikut Tools yang direkomendasikan DCWG :
Harapan kita semua, semoga dunia maya tetap tidak menakutkan bagi siapapun.

Tuesday, February 09, 2010

Clean and Scan Computer without Antivirus

Menjadi kebiasaan buruk jika tidak mengutamakan kebersihan. Kebersihan tidak mutlak bagi yang nampak saja secara kasat mata. Bagian terdalam dari sebuah benda pun harus diperhatikan kebersihannya. Kenapa tidak mencoba hidup bersih sebagai cikal bakal kesehatan. Dimulai dari diri sendiri, hingga semua yang ada di sekitar kita. Jangan menjadikannya berlarut-larut, mengingat hal ini akan memperburuk kondisi yang tadinya normal. Namun, karena kelalaian dan sikap acuh tak acuh, suatu waktu bakal terasa akibatnya.


Yang kita bicarakan kali ini adalah proses Cleaning yang akan dilakukan terhadap komputer kesayangan. Layaknya memelihara kebersihan kuku, maka yang akan dilakukan pertama kali yakni membuka terlebih dahulu sepatu yang dikenakan.

Bicara soal komputer, yang lazim dilakukan berupa Antivirus untuk membersihkan virus yang menguasai system. Untuk itu, akan diuraikan bagaimana membersihkan komputer tanpa memanggil bantuan Antivirus. Langkah demi langkah yang patut diikuti yakni :

Sebelumnya siapkan Bahan, berupa :
1. Obeng
2. Kuas/Sikat
3. Lap Kering
4. Kipas Angin
5. Djarum Black
6. Cemilan
7. Kopi Hangat
8. Djarum Black Menthol (ini milik sobat-ku)
9. Tempat Sampah
10. Mini Vacuum Cleaner

Proses
1. Buka Casing Komputer dengan bantuan obeng
2. Scanning kondisi komputer
3. Lepas Memori Komputer
4. Lepas Processor
5. Lepas Fan CPU dari pendinginnya
6. Lepas VGA Card
7. Lepas Audio Card
8. Lepas komponen lainnya yang mungkin mengganggu proses Cleaning
9. Cleaning dengan menggunakan kuas/sikat biar segala debu dan kotoran lainnya yang melekat pada komponen dalam Casing
10. Penggunaan kuas dimaksudkan untuk meminimalkan kerusakan pada komponen yang ada khususnya pada bagian terkecil dari benda-benda yang melekat pada PCB, misalnya resistor dan sebagainya
11. Setelah kotoran bergeser dari posisinya alias tidak melekat lagi, nyalakan Kipas Angin dan Kipas ke dalam Casing agar debu dapat dikeluarkan dengan cepat
12. Gunakan Mini Vacuum Cleaner untuk menyedot kotoran yang membandel
13. Gunakan Lap Kering untuk membersihkan sisa debu yang telah dihilangkan sebelumnya
14. Kotoran dipindahkan ke tempat sampah yang telah disediakan agar area kerja pun ikut bersih dan kinclong
15. Setelah selesai pembersihan, pasang kembali tiap komponen yang tadinya dilepas dari tempat melekatnya
16. Pasang kembali tutup Casing Komputer
17. Pindahkan CPU kembali ke asalnya
18. Bila sudah benar-benar yakin bahwa Komputer bersih kini, sekarang saatnya beristirahat
19. Cicipi cemilan dan kopi hangat sambil menikmati Djarum Black dan Djarum Black Menthol bersama rekan-rekan yang tadinya menjadi penonton setia

It's simply tutorial to Clean your computer, try again a regular.

Thursday, February 04, 2010

New McAfee in 2010

For years McAfee, has offered seamless continuous updates to their antivirus and security suite products. Updated program code slides into place automatically without bothering the user. It's so smooth, the user might not notice any change, especially since the product's appearance hardly changes. When McAfee AntiVirus Plus 2010 ($39.99/year, Direct; $59.99 for 3 licenses) hits the desktop, though, users will do a double-take. Not only has the name changed (from McAfee VirusScan Plus), the user interface has been completely refreshed to make the product more effective and easier to use. Because this is such a total makeover, the update comes with links to online help and explanatory videos.


The new interface is designed to present the user with exactly the information needed, as clearly as possible. It's brighter and cheerier than the old black, grey, and beige interface. There's still a "green for safe" status indicator, but based on focus groups and user interviews McAfee has added the reassurance "(no action required)" to this indicator. The status panel at the top offers quick access to information about scanning, updates, firewall, and subscription. Yes, I said firewall—while not a full suite, this antivirus comes with firewall protection. The status panel also presents a rotating set of statistics, among them the number of McAfee-protected PCs on the network and number of viruses detected during the last scan, with a link to a full security report.

All features are just a click or two away, and many can be reached via multiple routes. For example, the user can trigger an on-demand scan from the top panel or by clicking the Virus and Spyware Protection ribbon in the features area below. The "Navigation Center" offers yet another route to a full scan, along with access to less-used features.

Malware Interferes with Installation

Installing McAfee is a lengthy process, because the tiny installer always downloads the latest program code and virus signature data. For an average user, this is no big deal—especially for those who got McAfee pre-installed—but the necessary download did slow the installation process my twelve malware-infested test systems. On the plus side, the product was immediately ready on completion of the installation, with no need for an additional lengthy initial update. And the new UI appears instantly when invoked—that's a big change.

However, McAfee successfully installed and ran on just six of those twelve systems. On the other six, one problem or another prevented installation or blocked the installed program from doing its job. Fortunately, McAfee has a substantial set of tools to help in this situation. Unfortunately, getting all six problem systems fixed required every tool in the box.

The first step toward clearing up any problem is McAfee's Virtual Technician. This simple tool checks for problems with the product or, if no McAfee product is present, for problems that could interfere with installation. Virtual Technician cured one of the six problem systems.

McAfee offers a small anti-malware tool called Stinger that wipes out certain common threats without requiring a lengthy install process. Stinger found and removed threats on several of the remaining systems. After running it, I managed to install the product on two more systems, though it still wouldn't run on one of those two. McAfee's pre-scan preparation tool and online FreeScan solved a few more problems, but I still wound up with two stinkers. On one the product simply would not install; on the other it installed but would not run.

The starting-level technician crewing McAfee's online chat-based help system didn't manage to fix the last two, so I got escalated to McAfee's full-scale virus removal service. It took hours, but eventually the virus experts remote-controlling my sick systems managed to get McAfee installed and ready to scan.

If you're buying an antivirus to clean up a computer that you suspect (or know) is infested with malware, McAfee may not be the best choice to perform the initial cleanup. On the other hand, the wealth of ancillary repair tools, along with personal support, did deal with all the problems I encountered.

Good Test Scores

The big independent test labs have hordes of researchers and rooms full of test computers, all working to evaluate the efficacy of security software. McAfee did well in the latest tests, though it didn't take top honors.

AV-Test.org recently ran a real-world parallel test of a dozen security products over 60 days. Each product was confronted with the exact same very current malware samples daily and challenged to protect the test system. McAfee's scores were right in the middle for both detection and removal; Norton Internet Security 2010, Kaspersky Internet Security 2010 and PC Tools Internet Security 2010 were the most effective.

AV Comparatives ran a new test this year evaluating the performance impact of sixteen antivirus products. Over half the subjects, including McAfee, Norton and Kaspersky scored ADVANCED+ (the top rating), though McAfee did so with the lowest numeric score.

In the latest test of on-demand malware cleanup by AV-Comparatives, McAfee scored ADVANCED, and in their proactive test of non-signature-based detection it scored STANDARD, the lowest passing score. On the plus side, ICSA Labs and West Coast Labs both certified McAfee's technology for virus detection and removal, and West Coast Labs added several other checkmark certifications. McAfee has also received the VB 100% award from Virus Bulletin in all but one of their last ten Windows-based testing cycles.

Speedy Malware Scanner

Much of McAfee's malware detection abilities live "in the cloud." Called Active Protection, this online system gets a billion queries per day, so it has to be fast. A full scan of my standard clean system took 40 minutes, a little longer than the average of 30 minutes. However, due to McAfee's "smart scan" technology, a repeat scan took less than 10 minutes. Note that the product automatically configures a weekly scan, so even if you never manually launch a scan, the app will still clean up your system.

As noted, getting the product installed on all of my malware-infested test systems was a challenge. Even after that success, one system continued to cause trouble. McAfee's real-time protection detected a Trojan and requested a reboot to complete its removal. After reboot it did the exact same thing, again and again for as long as I could stand it. I finally ignored the prompt and let the full scan run to completion. That's annoying—a user would have to make a leap of faith that the app will eventually get the Trojan, and the average user isn't qualified to know whether that's a reasonable assumption.

The scanner removes Trojans, viruses, and other serious threats immediately on detecting them. For lower-risk items, termed "potentially unwanted programs," it asks what to do at the end of the scan. I always chose "Quarantine all." The scan occasionally requested a reboot to finish cleanup.

When the dust settled, I tallied up the results. McAfee scored 7.0 in the malware removal test, the same as Microsoft Security Essentials 1.0. That's just a bit above the average on this test. PC Tools holds the record with 8.3 points; Norton took 7.5.

In a separate test of removing commercial keyloggers McAfee scored 4.7 points. Norton did the best with 7.5 points and Double Anti-Spy Professional 1.4 scored 7.4. Not to worry; I don't consider this result nearly as important as the malware removal test.

Looking at rootkits, whether from the malware or keylogger collection, McAfee scored 6.0 points. It detected all of the samples, but it left some of them actively running. Norton scored highest against rootkits with 7.9 points; PC Tools came in second with 7.7. I also broke out a separate score defining McAfee's ability to remove scareware (rogue security software). With 5.8 points in this test it came in a fraction below average. Top scareware-remover was Ad-Aware Pro 8.1 8.8 points.

Overall, McAfee did a good job of malware removal, but other products have scored significantly better.

Powerful Real-time Protection

McAfee's protection for a clean system starts with SiteAdvisor, which warns when the site you're visiting has been identified as dangerous. This is just the free SiteAdvisor anybody can download; it doesn't include the ability to actually block access to dangerous sites the way SiteAdvisor Plus does. That means you must pay attention to its warnings and actively avoid sites it flags as dangerous.

When I tried to re-download my current collection of malware samples, SiteAdvisor warned about well over half of them, including those from many URLs that are no longer valid. What's the virtue of that? Well, it will certainly make you think twice about the e-mail or Web page from which you obtained the now-defunct bad link!

SiteAdvisor now interacts with Active Protection online, which makes it much more responsive. In the past, its ratings were global to a domain and got updated only when the service's Web-crawlers re-examined that domain. Now it can get updated immediately when Active Protection detects malware coming from a site, and can also fine-tune ratings to specific URLs, not just entire domains. I can see the difference–it wasn't nearly as effective last year.

McAfee also checks every download and pops up a big warning the moment it identifies the download as malicious. Every malware sample whose URL wasn't blocked by SiteAdvisor got caught as a dangerous download. Sometimes the warning came the moment the download began, other times at the end of the process, but it always came. The only samples that got past McAfee were a couple of the commercial keyloggers.

Next, I opened a folder containing already-downloaded samples. A single click on a sample was enough to trigger McAfee's real-time scan. It identified and removed over 90 percent of the samples, asking for permission to remove those classified as "potentially unwanted programs." None of the remaining samples installed successfully, though a couple managed to place executable files on the system. A repeat test using hand-modified copies of each file got exactly the same results.

I did note one odd occurrence. Several times McAfee popped up a box announcing that it could not remove "this program" and suggesting that I use Add/Remove programs. This could make sense if the program in question was installed and running, but all of these samples were static files. And why didn't it say which program it meant?

McAfee used to include a feature called SystemGuards which asked the user whether to allow certain sensitive system changes made by any program, good or bad. With its current Active Protection and other layers of technology in place McAfee felt free to jettison the annoying SystemGuards—hooray!

McAfee scored very well in the malware blocking test, with 9.5 of 10 possible points, though others squeaked out even better scores. Panda Cloud Antivirus Free Edition 1.0 and PC Tools both got 9.7, while Norton scored 9.6.

I also tested McAfee's ability to block installation of keyloggers. Its score of 7.4 points is well above average but it doesn't approach the 9.0 points scored by Double Anti-Spy and Panda Cloud AntiVirus. And of course, good or bad the keylogger score isn't nearly as important as the full-scale malware score.

At 7.9 points, McAfee scored above average at blocking rootkits, but it was handily beaten by Panda Cloud Antivirus, with 10.0 points. Along with eight other products McAfee blocked every single scareware sample, for a perfect 10.

McAfee AntiVirus Plus is definitely better at keeping malware out of a clean system than at cleaning up an entrenched malware infestation, especially considering the problems it had even installing on a system where malware was already dug in. If you can get your system clean, McAfee will keep it that way.

Significant Bonus Features

As always, you can link directly from McAfee to online resources that include the company's interactive virus map, anti-hacker community, and virus information library. But there's more, much more, to merit the "Plus" in this product's name.

To start, it includes a fully functional firewall, one that passed all my standard firewall tests handily. A network map feature easily identifies other McAfee-equipped computers on your network and can even be configured to fix any security problems remotely. McAfee's venerable QuickClean system tune-up utility is also included, as is a "shredder" to securely delete sensitive documents.

The firewall and other bonus features would normally be found in a suite, not a standalone antivirus, so their presence adds significant value. I'll go into full detail about these features in my coming review of McAfee Total Protection 2010.

For those with McAfee VirusScan Plus already installed, the upgrade to McAfee AntiVirus Plus 2010 will bring even better protection against malware attacks along with an attractive, streamlined user interface. Those looking to install this product on a hitherto-unprotected system may have some challenges, though McAfee offers many tools to overcome these. It's a very good antivirus with some surprising bonus features.

Tuesday, January 19, 2010

Bredolab dan Zbot siap meruntuhkan harapan FACEBOOKer


Perusahaan antivirus Vaksincom mencermati, saat ini setidaknya ada dua virus yang mengancam pengguna Facebook. Virus itu bukan menyebar di Facebook, tapi memanfaatkan jejaring sosial popular itu untuk menjaring korban dan bertujuan mendapatkan akun FB.

“Menurut hemat kami, di tahun ini serangan virus dengan modus operandi mengeksploitasi FB akan makin marak seiring makin populernya FB,” kata CEO Vaksincom Alfons Tanuwijaya, di Jakarta.


Ia menambahkan di dunia virus berlaku hukum pembuat virus akan mengincar sistem operasi atau aplikasi yang paling popular. Hal itu karena korban potensialnya lebih besar.

Oleh karena itu komputer dengan sistem operasi Microsoft Windows lebih menarik dibuat virusnya dibandingkan Mac OS Leopard atau Linux, karena penggunannya paling banyak. Sementara sistem operasi Windows Mobile atau BlackBerry lebih sedikit mendapat serangan, karena secara de facto market ponsel masih dikuasai oleh sistem operasi Symbian.

“Saat ini dua virus yang cukup berbahaya dalam mengeksploitasi FB adalah Bredolab dan Zbot,” kata Alfons.

Bredolab merupakan virus lama yang menyebarkan diri sebagai lampiran e-mail. Sebelumnya, virus ini seolah-olah datang dari DHL. Jika dijalankan, maka virus akan menyebabkan komputer terinfeksi.

Memanfaatkan Facebook yang popular, pembuat virus mengubah e-mail seakan-akan dari administrator Facebook. Pembuat virus meminta password reset Facebook dan menjalankan satu aplikasi yang isinya program berbahaya.

“Jika aplikasi itu dijalankan, maka korbannya akan dibuat pusing tujuh keliling. Selain menginfeksi komputer korbannya, virus juga akan meng-download spyware, scareware berupa antivirus palsu, dan menginfeksi lagi komputer korbannya,” kata Alfons.

Tidak cukup melakukan hal ini, Bredolab juga akan melakukan spam dari komputer korbannya. Akibatnya IP address komputer korban bisa diblok oleh perusahaan blacklist, karena mengirimkan spam dan mengganggu pengiriman e-mail.

Sedangkan cara penginfeksian virus Zbot lebih canggih. Virus ini tidak mengirimkan diri sebagai lampiran e-mail seperti Bredolab, yang bisa diblok oleh mailserver.

Virus itu menyebar melalui email phishing, seakan-akan pesan resmi dari Facebook untuk mengubah password. Jika link tersebut diklik, maka ia akan menampilkan situs palsu Facebook yang meminta korbannya memasukkan username dan password.

Jika dituruti maka username dan password pengguna Facebook akan diketahui oleh pembuat virus. Tidak cukup mencuri password Facebook korbannya, virus ini juga akan memberikan link ke file untuk diunduh yang dikatakan sebagai file update dari Facebook. Jika dijalankan, maka virus akan menginfeksi komputer korbannya dan mengakibatkan komputer itu mengirimkan spam.

Lalu bahaya terbesar apa yang bisa dialami user?

Alfons mengatakan tingkat bahaya tergantung dari korbannya. Korban bisa kehilangan akun Facebook dan jika ada nilai ekonomis di akun itu, misalnya data rahasia rekening perbankan maka akan bisa berpindah tangan.

“Selain itu yang perlu dikhawatirkan adalah bahaya jaringan komputer kantor yang menjadi korban virus ini. Jika komputer mengirimkan spam, maka IP kantor akan di-blacklist sehingga tidak akan bisa mengirimkan email dengan baik, dan seluruh email kantor tersebut akan masuk ke dalam kategori spam. Potensi kerugian ekonominya sangat besar,” ujar Alfons.

Untuk menghindari virus di Facebook, Alfons mengatakan pengguna komputer harus menggunakan program antivirus yang ter-update. Selain itu ia menyarankan pengguna komputer selalu waspada terhadap pemalsuan situs atau webforging.

“Jangan mudah percaya link yang diberikan. Khususnya pada saat memasukkan data penting seperti username dan password, sebaikn, ya perhatikan situs yang dikunjungi dengan seksama,” timpalnya.

Source : Inilahcom & Vkasincom