Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label AVG. Show all posts
Showing posts with label AVG. Show all posts

Thursday, April 1, 2010

Security and Forensics Roundup: Heavy Version #7

Posted on 4:05 PM by Unknown

Oh my.  I may have bit off more than I can chew with this load of links.  I’m having a challenging time breaking them all down into meaningful chunks!

Incident Response

  • The Tiger and the Ghost – Nice and reflective thoughts on the changing landscape of incident preparedness from Hogfly over at the Forensic Incident Response blog.

  • Verizon Incident Metrics Framework Released – Verizon has published a framework for categorizing incidents and elements that comprise them.  One of many out there, nevertheless, it might provide some additional ideals for conceptualizing incident events and help guide you as you form narratives that analyze and summarize them for your audiences. Spotted via the TaoSecurity blog.

  • DarkReading Evil Bytes bloggist John Sawyer has posted a trilogy of articles on incident response as well as drive-imaging thoughts and techniques in that response; Adding Forensic Imaging To Your Standard IR Process, Using Hard-Drive Imaging In Forensics, and Drive Imaging Using Software Write Blocking provide an updated refresher on these topics. Good for a quick review particularly for the unfamiliar.

  • Responding to Incidents – Windows Incident Response blog.  Coming in at the anchor position is a great post by Harlan covering all the major points and issues on why establishment and execution of an organizational incident response plan for the IT shop is critical. If you don’t have one, it’s long past time to start building and implementing one.  Failure to do so comes with great peril.

Timeline Merry-go-Round

Having some time ago been faced with the challenge of preparing a digestible incident timeline of a Windows system, I am now paying even closer attention to timeline issues.  Like many, I had reams of data, much of it all valuable. However, the real challenge wasn’t so much the capture and spin-out of the information, it was presenting the findings in an objective manner that successfully and accurately told a story to management and non-IT consultants.  What was of value to me understanding the sequence of events was less valuable to those who wanted the big-picture and major-plot-points.  It end up being as much the art-of-communication as well as art-of-examination.

  • Timeline Creation and Analysis and Even More Thoughts on Timelines – Windows Incident Response blog.  Start here to let Harlan give us our bearings on timeline issues.

  • Timeline Analysis Part I : Creating a Timeline of a Live Windows System – The Digital Standard blog. cepogue starts us on a nice incident walkthrough from a timeline perspective

  • Timeline Analysis Part 2 : The Registry – The Digital Standard blog.

  • Timeline Analysis Part 3 : Log2timeline – The Digital Standard blog.

  • Timeline Analysis Part 4 : Timescanner – The Digital Standard blog.

  • Digital Forensic SIFTing: SUPER Timeline Analysis and Creation - SANS Computer Forensic Investigations and Incident Response Blog.  Very valuable guided tour on how to make a SUPER timeline using the SANS Investigative Forensice Toolkit (SIFT) Workstation 2.0.

  • Shadow Timelines And Other ShadowVolumeCopy Digital Forensics Techniques with the Sleuthkit on Windows  - SANS Computer Forensic Investigations and Incident Response Blog. Because timelines are not just for the main Windows volumes…you’ve got clues in the Shadow Volumes as well.

  • NFIlabs – Aftertime – Java tool to create timelines.  Pretty cool.

It’s all about Analysis

  • Malware case: Day 1 and Malware Case : Concluded – Eye on Forensics blog.

  • Memory Analysis on Windows 2003 64-bit and What’s Next – Mandiant M-unition blog.

  • Analyzing RAM Dumps, RAM Analysis Part 2,and Memory Analysis Part 3 – The Digital Standard blog.

  • Flock shepherds in a Life of Grime – Forensics from the Sausage Factory blog.  In which in this installment, we find DC1743 encountering the Flock browser, which is just a fancified version of Firefox geared to the social media experience.

Tools and Toys

  • Streamarmor - RootkitAnalytics.com new freeware tool to discover ADS elements and remove them from a system.
  • Internet History Examination Tools - you generally get what you pay for  – Forensics from the Sausage Factory blog.  In which DC1743 weighs the pros and cons of various utilities used to examine browser history.

  • EnCase Portable device – Review - Computer Forensics, Malware Analysis & Digital Investigations blog.

  • AVG Rescue CD: Free toolset for repair of infected machines – PSA announcement on HelpNet Security about a bootable LiveCD to review/clean an infected Windows system. Might be worth considering adding it to your stable.

  • QCC Information Security - Free Forensic Tools – including CaseNotes, VideoTriage, and FragView.

  • P2 eXplorer v2.0 – Free tool from Paraben Forensics to allow mounting of forensic images. Comes with support for reams of image formats.  Neat!

Miscellanea: Don’t count out the value of small things…

  • Tidbits, Links, and even more Links – Windows Incident Response blog.  Think of these post links as Easter-eggs.  Each one nice and simple holding wonderful treats just under the shell!

  • Digital Forensics Case Leads: Tools and Lists, Bugs, and Web 2.0 for Packet Ninjas - SANS Computer Forensic Investigations and Incident Response Blog.

  • Digital Forensics Case Leads: New Gear, New PDFs Abuse, and Defeating TrueCrypt - SANS Computer Forensic Investigations and Incident Response Blog.

  • The Chain of Custody for 2010-03-21 – Weekly Tweets - SANS Computer Forensic Investigations and Incident Response Blog.

  • What is this field called anyway? – Forensic Focus Blog…a rose. By any other name, would smell as…well, you know.

Cheers.

--Claus V.

Read More
Posted in anti-virus software, AVG, boot-cd's, browsers, Firefox, forensics, Link Fest, security, utilities | No comments

Saturday, March 20, 2010

Dealing with the Dell … 2010 Edition

Posted on 7:31 PM by Unknown

For the longest time, the Dealing with the Dell... post I did back in 2006 was a perennial top post ranker here at the GSD tech ranch.

Most of that I have to credit to Tech Blog’ist Dwight Silverman and Ed Bott who both linked to the post.

  • Time to a usable PC: 4.5 hours – TechBlog | Chron.com - Houston Chronicle.
  • Why do new PCs come with so much junkware? – Ed Bott’s Windows Expertise.

So this past week, I stopped by a senior friend’s house after work and set up his new Dell Inspiron 580 Desktop.

My o my. How far we have come.

Back in 2006, setting up that new factory-fresh Dell system took 4.5 hours.  In 2010? Just under two hours.

Sure my experience has grown since then, systems are faster, and this user’s needs were more simple than before, but it was a very refreshing experience.

The User

This wonderful mentor of mine would fall squarely in the “senior” category.  Long since retired but still very active.  He continues to grow PC savvy and I usually function as the premiere pc support source he relies upon.

He has had two laptops as well as a previous Dell desktop system.  All running Windows XP.

He surfs the web, does financial management, is getting into digital photography (after many years as a film-based hobbyist) and prints/scans stuff.

His XP system continued to experience crashes and while adequate, was showing its age.

A few weeks earlier he asked for advice on what to look for in a desktop system and I gave him my basic spiel.

Then he called me to come set it up and swing his data over onto the new system.

The System

The Dell system he purchased came with a quad-core, 6 GB of system RAM, a 500 GB SATA drive, and a new wide-screen LCD monitor.

It was loaded with Windows 7 Home Premium running as x64 bit flavor.

He had gone ahead and purchased the MS Office 2007 Student Teacher edition which was pre-loaded.

It also came with a trial McAfee Security Center.

The Setup

I didn’t have much work to do on his current XP system.  It had BSOD and (knowing I was busy with a work project) had elected to have a local PC shop work on it.  They “solved” his problem by saving his My Documents folder and a few others, overlaying XP as a fresh install, then porting his “My Documents” folder back into the fresh profile.

Great.

Gone were the Outlook Express data stores that were kept in a non-My Documents location along with a lot of other data.

Fortunately all of the key stuff was still present and he had religiously been backing up Quicken data to a USB stick and CD media.

Lessons learned…call me.  Really.  If I’m so busy I can’t look at it I can give you advice.  Anyway…

Shut down the old system.  Pulled all the cords/cables, etc and strung the new ones out of the box.

Cordless mouse and keyboard now.  Sweet.

In about ten minutes it was unboxed, cabled up, and powered on.

I quickly set up the single user account on the system and rebooted.

It was wicked-fast.

I checked the add/remove programs list and it was refreshingly clear of any and all crapware and third-party software add-on bloat.  Both the x32 and x64 bit Java versions had been loaded and were current.

No need for deployment of the awesomely helpful PC Decrapifier (recently updated to version 2.2.1).

Quick and deeper system reviews using Process Explorer and Autoruns found everything ship-shape.

Flash and Shockwave got installed and updated.

I uninstalled the McAfee trialware package.

I made sure the Windows 7 Microsoft Firewall was on and set correctly before plugging it into the DSL modem. (for some easy Win7 alternative firewalls see this The Best Free Firewalls for Windows 7: Top Firewall Options Compatible with Windows 7 Including Software from Comodo, Sunbelt, and Outpost) post.  More on why I stuck with this one later..

Windows Updates took quite while to download over DSL. (Cable broadband has spoiled me silly.)  I think there were about 32 Microsoft updates as well as maybe three hardware driver updates.

Microsoft Security Essentials also got installed and configured for daily scans about this time.

I had to enter the MS Office key and activate it.  No problems.

I installed the ACDSee Photo Software trial so our budding digital photographer could try this semi-pro application out, having learned that he wanted something a bit more sophisticated than the FastStone Image Viewer could provide, particularly in regards to photo image management.

I also tucked away downloads of ShowMyPC as well as TeamViewer Portable so we would have remote support options in place prior to any future calls for assistance to me.

We quickly loaded the latest version of Quicken which he had purchased.

Then came the HP Printer Driver update.  Windows 7 did pick up automatically the base drivers for the device, but I had to download the full x64 bit software package to realize the scanning and other advanced features his HP printer offered.

All done with no issues and in no time flat.

Using my Rosewill RCW-608 USB2.0 Adapter I finally yanked the IDE hard-drive from the XP system, connected it up to the new system, and in just over five minutes had copied over almost 20 GB of user documents, photos, music and tucked them away in their proper Windows 7 library locations.

After a quick review with the x64 bit version of Recuva as well as DiskDigger I was hopeful I could recover additional files that had been nuked, in case they were needed.  I advised my mentor to keep the drive in a safe place, out of the old system. If he found something very important later we could arrange for a data recovery at the sector level.  Othewise if all ended up being good, we could arrange for a secure wipe of the drive before he donates or tosses the old system.

Then came the Mail Client

As mentioned, he had been using Outlook Express.  I had done my homework and was all set to root out the .dbx files buried in the C:\Documents and Settings\your user name\Local Settings\Application Data\Identities\{your Windows user identity number}\Microsoft\Outlook Express location.

  • Migrate/Import Outlook Express (.dbx) files into Windows Mail in Vista – Windows Reference.
  • Migrate Your Outlook Express Inbox – PCWorld.

Unfortunately, the “crack” local PC support shop tech had only focused on the “My Documents” folder and not bothered to save the entire user-profile folder with all it’s hidden system and application files and folders.  Oh bother.

Outlook Express doesn’t come available for Windows 7.  I could have gone with Thunderbird or another email client, but to keep things simple as possible for this user I just set up Windows Live Mail (which turns out was pre-installed on his system with most of the other Windows Live items as well).

Turns out Windows Live mail is very slick and has a very simple interface.  He felt quite at home in it and it reminded me of a minimalist version of the full Outlook application.

I was all set with my Verizon email settings to manually configure it.

  • Verizon POP3 Incoming SMTP Outgoing Mail Servers News Server.
  • Verizon | High Speed Internet - What are my email settings?.
  • Verizon | High Speed Internet - Your Attention Needed: Re-configure Your Email Settings to Send Email.

But I was amazingly surprised that after we had put in his Verizon email address and proceeded, Windows Live Mail had automagically pre-configured all the settings correctly!  Sweet!

Fortunately for us both, we had never set his former Outlook Express client to delete messages off the server once downloaded, so all 9500+ of his emails were still living.  Down they came (and continued long after I left).  So we were lucky that though the Outlook Express files had been nuked, they were “recoverable”.  I showed him how Windows Live mail offers to “add contact” up at the top by each email sender’s name so he can quickly rebuild his contact lists.  We reviewed the junk mail settings/folder, the calendar and how to change views and add items. Easy peasy.

Wrap up and Final Thoughts

I have to confess we have come a long way since the last time I had to set up a factory Dell system for a home user.

The process was faster, the setup was simpler, and Windows 7 alone makes a large improvement.

Because of the precipitous XP system failure/reload, I didn’t get a chance to use any of the various user/system migration tools/utilities I had brought along to the setup party.  That was good for me but clearly not a representative experience for most users moving from one physical XP/Vista system to another Windows 7 system.  Being a sysadmin I did feel very comfortable with the manual user-data transfer process and having a drive adapter made it rocket-fast.

You will have noticed also that I stuck with many Microsoft products for the security protection and web-work.  No I didn’t load Firefox.  We stuck with IE 8.  I went with MS Security Essentials and not VIPRE or AVG Free or avast! Free Antivirus or even Comodo Free Anti Virus. I didn’t even use a more robust third-party firewall with anal-retentive outbound traffic monitoring/blocking.

Why all this stock Microsoft stuff?  Clearly there are “better” browser, email, and security options out there.  I know because I use them all on my own systems at home and work. 

The answer is complex and easy at the same time:

This was not my system. 

I knew my friend and how he had used his PC over many years.  I needed to keep it simple, consistent, and easy for him to use.  That in turn will result in less need for troubleshooting and support.  The fewer deviations and more transparent the systems and software applications, the easier it would be for him to enjoy it and still remain acceptably secure.  Too much security was a bad thing as the block/allow notices from the previous firewall under XP often led to many safe and necessary things getting blocked by accident and causing support calls to me when software “just wouldn’t work right” anymore.

Sometimes hardened security options leads to more problems and frustrations.  That ends up with it being turned off.  Even worse.

Dell seems to have successfully come a long way, at least based on this system, on removing all the crapware and bloatware that used to bog down their systems.  Alas this isn’t the norm with all factory systems, but in my experience, those purchased direct from the OEM’s seem to have way fewer bloatware/crapware than those picked up at BigBox outlets and office supply stores.  And even then, in many cases even these systems seem more dialed back now with that nuisance stuff than in years past.

Yes…and given the options when setting up a new factory-fresh system and porting the old data over, on an after-work worknight, I’ll take this brave new 2010 PC world over that of 2006 anytime!

And I have to chuckle.  This still-youthful senior friend is ripping away now on a quad-core, 6 Gig RAM, 500 GB SATA drive running a x64 bit OS that is so fast we both might need to go to confession after using it.  It seems sinfully fast and robust for a simple middle-of-the-road home desktop system.

Yes indeed. How far we have come.

Cheers.

--Claus V.

Read More
Posted in anti-virus software, AVG, Internet Explorer, Microsoft, Remote Support, software, utilities, Windows 7, XP | No comments

Saturday, December 13, 2008

Mid-December Linkfest: Snowflake version

Posted on 12:07 PM by Unknown

This past Wednesday night we Texas Gulf-Coast residents were treated with a very rare sight:

Snow.

It started coming down while we were at our church-house and on the drive back it was full flurries.  Visibility driving was something else.  Alvis had been soaked by antics while I was wrapping up some training (for me) on the software used to build and project displays during the Sunday services.

It was late when I got out and it was cold and I wanted to get home and cook dinner for the girls.  So instead of playing for a moment, we jumped in and got home quick.

The next morning (Thursday) most of the East-side Houston freeways and overpasses were shut down due to ice.  Our cars were covered with at least 4 inches of powder-grade snow as were all horizontal and some vertical surfaces.

I made a really horrible mistake that I have been chastising myself for the rest of the week.

See I should have paused being a responsible adult and taken  the moment (or hour) to have a snowball fight and do other stupid things with Alvis and Lavie.

Instead I diligently worked to scrape down the cars so they would be safe to drive, pre-warm them by running the engines, and fuss at Alvis to stay back because of the mud, water, and the rush to get her off to school.

Big FAIL.

Once all was contained and all were in their designated places of action, reality hit me Dad-style for missing a rare opportunity to play in thick and deep snow with the girls.

I mean how many chances do we have to do that?  Apparently only after a major hurricane hits us.  That seems to be the pattern at least (Rita-snow/Ike-snow).

Lesson learned and not to be forgotten.

Take a moment to play in the snow…then move on with life.

It will still be there waiting.

Linkage

Here are some miscellaneous links for you to play in today.  No mess no fuss.

  • AVG’s NOPslide – SecuriTeam Blog – More consideration and commentary on AVG.  Just one of a growing chorus of voices questioning AVG’s position and model as a recommended AV solution.
  • Why does it take so long to create a fixed size virtual hard disk? - Virtual PC Guy’s WebLog -  Quick answer? It’s a security thing and involves zeroing out the “drive”.
  • No SWAP Partition, Journaling Filesystems, … on a SSD? -Robert Penz Blog – Technical discussion on configuration options for Solid State drives.
  • How to cancel a print job that hangs under Windows Vista and XP – 4sysops blog – Great procedure for dealing with those really-stubborn hung jobs that sysadmins come across from time to time
  • The Case of the Mysteriously Large Spooler.xml File - Ask the Performance Team – More Windows printing (spooler) troubleshooting and background since we were briefly on the subject.
  • TweakVista.com - The many looks of the Windows 7 Taskbar – TweakVista.com – Whew! I’m glad I’ve got options! The Areo Peek thing wasn’t doing it for me.
  • 7 Better Alternatives To Common Windows Apps - MakeUseOf.com – Nice picks and no complaints from this app-list roundup.
  • Security’s Dirty Dozen - PC Magazine – Great in-depth reviews of many popular AV products.  Seems pretty fair and balanced.  I like reading these to keep abreast of products I use often and have heard of but haven’t tried.  Always learning something new from a different perspective.
  • AVID - Antivirus is Dead!  - Hackers Center Blogs – OK, maybe not yet, but the existing models are a bit broken in places and there is definitely some room for improvement  Good examination of some of those concerns.
  • The Home Computer Freeware List: Updated 09/05/08 - Confessions of a freeware junkie – A very good roundup of freeware software choices broken down into various categories.  Well worth perusing.  You will certainly find some oldies-but-goodies as well as some new tools and utilities worth considering.

--Claus V.

Read More
Posted in anti-virus software, AVG, Link Fest, malware tools, utilities | No comments

Saturday, November 15, 2008

Security Simmerings…chunky style goodness

Posted on 3:40 PM by Unknown

image

Lean Snake-meat

I’m trial-testing a new (to me) anti-virus/anti-malware product on our Vista system.  It’s Sunbelt Software’s VIPRE Antivirus + Antispyware program.

It’s a bit of a different product for me as I usually stick with “free for personal use” versions such as AVG Free.  This one is good for just 15 days.  On the plus-side, Sunbelt offers a $49.95 deal to register its use on all the computers in your home for a year.  That does seem like a good value.

I uninstalled AVG Free 8 then after a reboot loaded this one up.  A full scan with VIPRE took 128 minutes and as the image above shows scanned a bunch-load of items.  In all it found five cookies as well as two possible trojans and one potentially unwanted program.  I was a bit shocked at first, but found that one was Abel (of Cain and Abel), one was a utility in NetTools, and the last (PUP) was a tool that allows you to run an application under a different date. So all were in fact, known and approved by me to be on my system.

I must say my first impressions are very positive.  The interface is very logical and easy to navigate. Each time I wanted to do something or find something, I was quickly able to find it, even without having read the Help files.

My only “gripe” at this point is that I was not able to select any of the items found in the middle of a scan to view the details on them.  This led to some mixed concern on my point until the scan completed and I was able to see the details. I’d like to ask the Sunbelt team to allow viewing of detected threat details in the process of the scan, or allow additional columns to be added to the default view that would at least show the location (path) and filename of the threats so some information can be reviewed mid-scan.

I’m not intending this to be a “review” but more of a first impressions.  However, if after the fifteen days are up I’m still happy, I’m pretty sure I’ll be signing up for a subscription and composing a longer review.  In the past I used their Sunbelt Firewall product for a very long time, abandoning it only when it took so long for them to deliver a Vista compatible version…(now available). I was very pleased with the product and company from that experience.

On top of that, CEO Alex Eckelberry’s SunbeltBLOG is a long-time RSS feed of mine and I really enjoy the posts found there. Alex is very responsive and frequently drops into forums and blogs and leaves his comments.  I’m always impressed with his attitude and willingness to engage in constructive discussions on both his company’s product as well as the anti-malware industry in general.

AVG Foul and Alternative Poultry Choices for the Pot

Goodness knows, I’ve been a long-time apologist for AVG Free here on this blog.  It was one of the very first “free” anti-virus products I switched to after leaving a paid-subscription service.  It’s had its ups and downs but overall I still remain pretty pleased with AVG and continue to recommend it for most home-users looking for a free security product.

My complaints remain, however; a very busy interface, difficulty finding and using the “advanced” settings and configurations tools, periodic false-positives, the fact I’ve never been able to get the “upload to AVG” feature for sending sample files to AVG to work, and the fact that it continues to hammer away on a number of my utilities as “Potentially Unwanted Programs” despite the fact I tell it not to.

AVG again has made the tech-circles with reports of nailing false-positives for some critical (or important) system files. Although I personally haven’t experienced any of these recent behavioral problems, they could be a bit disconcerting for AVG noobies not yet accustomed to the frequent AVG false-positives the signatures are know for.

TechBlog: Ooops: AVG thinks key Windows file is a Trojan

TechBlog: Yet another AVG false alarm: Time for an alternative?

AVG virus scanner removes critical Windows file - Security and the Net

This led to me re-evaluating my selection with AVG Free 8 again and giving VIPRE a try.

In my previous AVG Free v8 versus the Competition (Speed to Scan only) post, I came to the conclusion that AVG Free v8 had the fastest performance overall of any free anti-virus product that I had tested.

The runner up was Avira AntiVir Personal.  I said that I would likely choose this as my second choice were I to leave AVG Free 8.  The only drawbacks I find with AntiVir is the fact that the free product did have a few more limitations in this product compared to other free solutions. On the plus-side, Avira consistently leads the pack of SRI’s Most Effective Antivirus Tools Against New Malware Binaries detection list.  See also AV-Comparatives.

Curiously, I did not see Sunbelt Software’s VIPRE listed in either location. So I really have no way to see how they would stack up in these tests by comparison.

If I did go with AntiVir I would probably also use it in tandem with either (or both) Malwarebytes' Anti-Malware (free but $ for full-feature version) and ThreatFire (freeware).  I had always relied on ThreatFire’s HIPS type protection before, but it seemed to conflict with COMODO’s firewall and kept locking up my XP system’s hard-drive so I just uninstalled it from everything for now.

Then there is COMODO’s Internet Security suite which remains a free security product that bundles both it’s awesomely hardened firewall along with some interesting anti-virus/anti-malware products.  Certainly worth looking at as well as an integrated anti-malware/anti-virus solution if you are tempted to walk away from AVG Free 8.

Finally, I found this security software review site that uses YouTube videos to highlight its findings: Remove Malware.

Pure Angus Meatiness

Microsoft® Malware Protection Center : Malware and Signed Code – Yep, it’s a brief discussion on code signing and how it is beneficial to preventing malware.

Microsoft® Malware Protection Center : Win32/FakeSecSen - A Nasty Piece of Work – MMPC staff take some of the fake security programs to task. I frequently see evidence of these at work where users were surfing, got a pop-up and the program/presentation looked quite legitimate and tricked the user into installing the app on the system.  Then our Symantec program alerts on them, (but can’t remove them) and off we go to pull them off the system.  It’s probably even worse for many home users. It’s a great roundup and discussion.

Wi-Fi Networking News: WPA Not Cracked, But Still Vulnerable and Security experts reveal details of WPA hack - News - heise Security UK – The weakness of the WPA chain is finally fully out.  It is a flaw, but probably nothing for the average home user to be deeply concerned about…at least not quite yet.  If you are really concerned and your Wi-Fi router supports it, consider switching to WPA2.

Windows Incident Response: More Deleted Keys Goodness! – Harlan shows just how valuable the ability to find (and recover) deleted registry keys can be. Neat stuff.

Windows Incident Response: New Code Posted – Harlan also kindly offers up a plug-in to his RegRipper tool that will help recover deleted registry key information for investigators and SysAdmins.

SynJunkie: The Story of a Hack - Part 2. Breaking In – SynJunkie is continuing his class on how a penetration attack occurs.  So far it has been quite educational and nicely documented.

Shoulder Surfing a Malicious PDF Author « Didier Stevens – This was really cool.  Didier was able to obtain a malicious PDF file that actually retained the incremental changes the malware writer used to try to get the PDF bomb ticking.  He provides a great analysis and I wonder what applications this technique could play for forensic examiners as well who could find some good clues and data as well.  If nothing else it is good information to be familiar with.

--Claus

Read More
Posted in anti-virus software, AVG, malware tools, security | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Network Capture Tools and Utilities
    At a conference this week, we had quite a section regarding network captures. The instructor was going on about how you can try to sort ou...
  • It just has to be bigger on the inside…
      Last Christmas, Lavie gifted me with a cute little Jawbone JAMBOX unit. I thought it was pretty cool. It uses a Bluetooth connection t...
  • Mostly Minor Network Notes
    Here are some minor tweaks and features, mostly of a network nature. Manual Uninstall of the Cisco VPN Client « Mobile Expertise -- becaus...
  • Windows Live Mail error 0x80041161
    Dad is working with his father-in-law who has an issue with his Suddenlink web-mail-based “forwarding” handling of messages. Seems that (an...
  • FireCAT 1.5 “Plus” Add-On Collection
    In yesterday’s GSD post I noted the following: Both of these tools brought be back to the excellent FireCAT 1.5 collection of Firefox...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ▼  2013 (83)
    • ▼  November (8)
      • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA uti...
      • ForSec Linkfest - 2013 DST Fallback Edition
      • CryptoLocker Ransomware Info & Free Prevention Sol...
      • Linkfest for the SysAdmins
      • Microsoft Security Essentials/Defender & PowerShell
      • Miscellaneous TrueCrypt linkage
      • PowerShell 4.0 and a tiny “gotcha”
      • New Software Updates + VMware Tools Update fix
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ►  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile