Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label malware tools. Show all posts
Showing posts with label malware tools. Show all posts

Saturday, November 2, 2013

CryptoLocker Ransomware Info & Free Prevention Solutions

Posted on 1:08 PM by Unknown

I work hard to keep our home systems malware-free and safe.

That typically involves talking about good Windows end-user behavior with Alvis and Lavie, letting them know about various breaking threats, running a AV/AM product, installing advanced protection afforded by Microsoft's EMET v 4.0 on our home systems, making sure all Windows and third party browser plugins are kept updated, run backups, etc.

So generally, I don’t worry too much about viruses and malware…but this new CryptoLocker threat does have my nerves extra-edgy.

First, we don’t have 10 bitcoins sitting around to pony up for a decryption. Most home\SOHO Windows users probably don’t either. Note this price has gone up from the previous 2 bitcoin expense.

  • CryptoLocker developers charge 10 bitcoins to use new Decryption Service - Bleeping Computer News

Secondly, it seems to work primarily on social-engineering and spear-fishing techniques (for now) to trick a user into opening a payload delivered by email. While I can have pretty good confidence in software defense-in-depth security practices, I never can trust the end-user (myself included) to be 100% dependable in catching this attack. I am my own weakest link.

Lastly, although CryptoLocker primarily targets local drives, it will encrypt any targeted files on a network share if the shared folder is mapped as a drive letter rather than a UNC share. So if one person on a network gets infected, and has mapped drives via drive lettering, that could hose everyone! That’s scary bad.

So the first important step you can take is to educate yourself about the threat itself:

  • How To Avoid CryptoLocker Ransomware — Krebs on Security
  • CryptoLocker Ransomware Information Guide and FAQ - Bleeping Computer - Probably the current de-facto resource for all technical details on this threat. Updated frequently.
  • CryptoLocker Is The Nastiest Malware Ever - Here's What You Can Do - MakeUseOf blog
  • Cryptolocker Ransomware: What You Need To Know - Malwarebytes Unpacked
  • You’re infected—if you want to see your data again, pay us $300 in Bitcoins - Ars Technica

At home, my immediate response was to deploy a special package maintained by Foolish IT LLC on ALL our personal Windows systems (including my Windows VM’s) that protects against this threat. 

CryptoPrevent - free for personal and commercial deployment - Foolish IT LLC - current version at time of posting is 3.1 but that is certain to change. In both “portable” and installable versions.

Like any AV/AM vs. Security battle, it is a constant arms race of updates so if you go this method, check back frequently for new versions or pay the $ for the auto-updating version.

Just to illustrate the challenge, take a look at these posts from the developer to see how the tool has mutated to keep pace with the threat and customer’s needs.

  • CryptoPrevent v2.0 just released with whitelisting capabilities!
  • CryptoPrevent v2.1 - I just can't seem to win!
  • CryptoPrevent v2.4 just released with internal update feature - please update!
  • CryptoPrevent v2.5 - with a powerful new layer of protection introduced!
  • CryptoPrevent v2.6 released - my life is consumed by this madness!
  • CryptoPrevent v3.0 - Recycle Bin protection and a new optional AUTOMATIC UPDATE service!

For corporate locations, I learned about another solution via Brian Kreb’s post noted above. From that post:

A team of coders and administrators from enterprise consulting firm thirdtier.net have released the CryptoLocker Prevention Kit – a comprehensive set of group policies that can be used to block CryptoLocker infections across a  domain. The set of instructions that accompanies this free toolkit is comprehensive and well documented, and the group policies appear to be quite effective.

Cryptolocker Prevention Kit (updated) - Spiceworks

Get protected now if you are a Windows user. Period. 

It’s not worth dilly-dallying about.

Cheers,

Claus V.

Read More
Posted in anti-virus software, malware tools, Microsoft, security, viruses | No comments

Sunday, October 20, 2013

Security Tidbits

Posted on 7:39 PM by Unknown

And here are some security related links that caught my fancy this week.

Vulnerabilities Discovered in Global Vessel Tracking Systems - Trend Micro’s Security Intelligence Blog - Super study that sent chills down my spine reading. We take so many critical infrastructure systems for granted. I hear the next block-buster action novel waiting to pounce on this for the storyline.

Cryptolocker Prevention - Foolish IT LLC bloc - information on a new freeware tool to lock down any Windows OS (preventively) to block infection from the Cryptolocker malware/ransomeware. When infection occurs it encrypts personal files then offers to decrypt them for a paid ransom. More details on the utility here: CryptoPrevent. And the attack details courtesy of Ars Technica: You’re infected—if you want to see your data again, pay us $300 in Bitcoins.

Tools for reviewing infected websites - ISC Diary. They listed four and there are some more suggestions in the comment thread. Back in January 2012 I posted this fairly extensive roundup: Interesting Malware in Email Attempt - URL Scanner Links. I’ve not checked recently but hopefully more than a few of these are still active.

Learn By Example - The Hacker Factor Blog - Dr. Neal Krawetz has some wise words and poor examples of a generation that doesn’t seem to see the concern with publically posting tweeted photos of their debit/credit cards online. I’m clueless how someone can be so ill-informed. This is just one example. I see the commercials showing banking apps for smartphones that let people take a photo of a check and deposit it in their account. I also wonder if this is common as well…or even health-coverage ID/Info cards perhaps?  I suspect this is just the tip of the iceberg.

40 inappropriate actions to take against an unlocked PC - Troy Hunt’s blog - As a sysadmin, all I can say is that it is probably a violation of several computer usage agreements in the workplace to walk away from your computing device without first locking the screen to prevent unauthorized access. At the same time, it is probably a violation of additional computer usage agreements in the workplace to tamper with someone else’s computer -- even if they were a bonehead in the first place and left it unlocked. Instead what you need to do is take a photo of their unlocked screen and tweet it to everyone in the workplace. No wait…I just learned by example in the previous post that probably isn’t wise to do either. Never mind. Help us all out and just pull the power-cord out slightly to kill power to the system and make them call the sysadmins when it won’t power back on. No don’t do that either after further consideration. That might kill the system/drive and lead to a charge of wonton destruction of corporate resources; or at the very least prevent someone's unsaved labor of love on the critical TPS reports for the day. That would be bad too. OK…I give up.

Contrary to public claims, Apple can read your iMessages - Ars Technica

Experian Sold Consumer Data to ID Theft Service - Krebs on Security - Seriously, if you can’t trust the data broker companies who hold all your credit and personal financial data history records (and who they sell that data to) then who can you trust with it? Time go start digging out that backyard bunker again. Go read the article. Then get mad.

New effort to fully audit TrueCrypt raises $16,000+ in a few short weeks - Ars Technica

For your security, please email your credit card and driver’s license (and what PCI has to say about that) - Troy Hunt’s blog. See, it’s only a crazy idiotic thing to tweet your CC information if you don’t have a really important reason to do it. If you do it is stupidly insecure. However, if you are a big corporate entity (or govermint agency/official) then you can have something call “a policy” to require your customers to photocopy items critical to establishing and proving your identify and they can do whatever they want…oh, and by the way…please dent them to us via unencrypted email communications because like, nobody can sniff that traffic while it winds it’s way from your laptop to our desks. Sheesh. Needless to say, Troy goes to town on this one and why it is a Bad Thing™.

Please be wise, be patient, and be proactively safe.

Claus Valca

Read More
Posted in anti-virus software, Link Fest, malware tools, security, troubleshooting, utilities, viruses | No comments

Saturday, October 19, 2013

Back to MS-Security Essentials for now…

Posted on 8:29 PM by Unknown

In the last GSD post, I made note that I had made the change from Microsoft Security Essentials to Bitdefender Antivirus Free._2013-10-04_19-24-14

The installation process went smoothly. Once on my Win 7 x64 bit system seemed a bit “peppier” after reboots.  For the first week or two I really didn’t notice any issues at all.

Then about two-three weeks in to using it I noticed a little notification that I had 15 files quarantined.

Goodness!

A quick review of the log found that I hadn’t succumbed to an onslaught of malware and viruses due to sloppy computing habits.

No. Bitdefender finally got around to scanning my collection of Windows utilities and found it ripe with all kinds of potentially unwanted software applications. Bad stuff.  Things from NirSoft that let me recover passwords and other things from beloved family members’ systems when they forget their system and email and other account passwords -- among other things. Oh my!

Bitdefender Antivirus Free Edition - Logs_2013-10-04_19-25-21

Here is what a Bitdefender quarantined file looks like.

asterisk logger - FreeCommander XE_2013-10-04_19-27-37

Well, we can’t have that!  So I went though the process of un-quarantining them.

Bitdefender Antivirus Free Edition - Logs_2013-10-04_19-26-00

And quickly I was done.

gc423pge.jby

Yea!

asterisk logger - FreeCommander XE_2013-10-04_19-28-07

Only when I went to use one of them, the executable file refused to run!  Blocked!

Nothing I could do could get it running. It was showing “Excluded” but I just couldn’t run it.

To complicate matters, after a reboot (troubleshooting) Bitdefender appeared to be trying to do a pre-Windows clean and file removal too. Hmm. Turns out that while I was working on that issue, it also found a USB stick I carry these tools on as well and had gone to town on the same file sets on it as well. I had removed the USB stick before reboot so it couldn’t find the files it was looking for. Fortunately the system came up no worse for wear despite some fairly scary language, but my attempts to later un-quarantine the files on the USB drive failed horribly and it refused to find/see them when I tried to exclude them.  Right-clicking the quarantined files and trying to restore them wasn’t successful on the USB drive either.

So I figured I would just re-download the handful of them from Nir Sofer’s website, delete my original files on my C: and USB drives, and put them back in.

Except I was met with a very frightening and ugly warning message in my browser that Bitdefender had identified the NirSoft website as a dodgy and dangerous location and didn’t really want me going there. In fairness, on the Bitdefender Free website, if you dig down on the page it does clearly say that the product does the following:

HTTP Scanning - Protects you from scams such as credit card phishing attempts, Bitdefender Antivirus Free Edition scans all the links you access from your browser and blocks them when they prove to be unsafe.

Unfortunately for me, that was the final straw.

So I uninstalled Bitdefender and reinstalled Microsoft Security Essentials.

Then I had to delete the still not really working “excluded/quarantined” files shown above off both my local hard drive and my USB drive. Luckily I could do that once Bitdefender had been removed and the system rebooted.

Then I downloaded all the “lost” files again from their sources. MSSE caught a few of the Nir Soft downloads but they alerted immediately and I was able to restore/exclude them with no fuss and about 30 minutes later had everything put back together again.

qjiw0nr5.qab

So, I must really be unhappy with Bitdefender right?

Well, it was an inconvenience to say the least, but I’m really not bummed out. If Bitdefender were to make some minor changes to their product, it might still win me back. I really, really, really liked the fast speed and light resources it displayed; particularly in that it made my post-boot and Windows login experience must faster and responsive that when using MSSE.

What I would like to see is a better set of options for controlling and enabling/disabling/fine-tuning features in Bitdefender free.  Unless they are there and I’m totally overlooking them…

  • I want to be able to disable the HTTP scanning.
  • When I restore/exclude a file, I want it to return to full functionality and remain whitelisted for future downloads and execution.
  • I want to exclude portable/external drives from scans when I feel like it.
  • I would like to know when Bitdefender finds something with a real-time pop-up alert and ask me what I want to do then and there…not let me find out about it later.
  • I really would like Bitdefender to warn me at a system shutdown if it has any “pending actions” that it plans to take on the reboot…and let me decide to follow-through with those actions or postpone or cancel that activity.

I guess I just want somewhat more advanced technical control over the operations and fewer headaches putting things back to normal.

Even “basic” MSSE allows me to…

  • Disable scanning of removable drives,
  • Exclude specific running processes from scans,
  • Exclude specific file-types from a scan,
  • Exclude specific files and locations from a scan, and,
  • not fiddle with monitoring and intercepting HTTP traffic to and from my web browser.

Hopefully future versions of Bitdefender Free can incorporate these items.  If so then I’m game and open to give it another shot.

Until then, I’m sticking with MSSE and continuing to recommend it to my own family and IT-support provided friends…unless they are horribly poor with their computing activity and I have to clean their systems more than a few times in a row…only then will I recommend they go to a more powerful (and less flexible) AV/AM solution, and that would be Bitdefender Free over most of the other free AV/AM offerings for Windows systems.

At least for now….

Possibly related:

  • Goodbye Microsoft Security Essentials: Microsoft Now Recommends You Use a Third-Party Antivirus - How To Geek website
  • Microsoft (allegedly) Now Recommends You Use a Third-Party Antivirus - BleepingComputer news forum.
  • Sensationalist Press Got it WRONG! Microsoft Does Not Recommend Two Antivirus Programs! - Security Garden
  • Our commitment to Microsoft antimalware - Microsoft Malware Protection Center Blog

Cheers,

--Claus Valca

Read More
Posted in anti-virus software, malware tools, security, troubleshooting, utilities, viruses | No comments

Sunday, September 29, 2013

Links of the Week

Posted on 2:04 PM by Unknown

Here is a hodge-podge of links that stood out this week.

Tr3Secure Data Collection Script Reloaded - Journey Into Incident Response blog - Corey Harrell has new news and updated on the Tr3Secure Volatile Data Collection Script he developed some time ago.

Tr3Secure Data Collection Script Reloaded - Journey Into Incident Response blog - Corey then follows up with a “real-world” walkthough of the Tr3Secure Volatile Data Collection Script after purposefully a lab pc for the sake of the discussion. It’s one thing to read about what a tool and process can do, it is a real treat to have the author lead a guided walkthough of the tool in action. As always, don’t forget to follow up with a comments reading as well.

plaso - super timeline - from the website “Plaso (plaso langar að safna öllu) is the Python based back-end engine used by tools such as log2timeline for automatic creation of a super timelines. The goal of log2timeline (and thus plaso) is to provide a single tool that can parse various log files and forensic artifacts from computers and related systems, such as network equipment to produce a single correlated timeline. This timeline can then be easily analysed by forensic investigators/analysts, speeding up investigations by correlating the vast amount of information found on an average computer system.”  Spotted via this CDF at Champlain post.

Microsoft Security Essentials: Aiming low? - ZDNet - Larry Seltzer offers some thoughts on Microsoft’s free AV solution. He really doesn’t thrash MSE but does point out that there are many other free alternatives that tend to perform higher. It seems like a pretty reasonable perspective.  FYI, I have been debating making a change from Microsoft Security Essentials to Bitdefender Antivirus Free. Yesterday I uninstalled MSE and replaced it with BAF. The changeover went very smooth. The deciding factor for me was the ongoing poor post-boot performance of my system.  While I don’t have a SSD drive in my laptop, I is running an Intel i7 CPU with 8 GB RAM. After boot, MSE scans on the post boot environment seem to be leading to slower post-boot launch of a number of my applications for a while as processes and files get scanned. Now that I am on BAF, I don’t see those post-boot application hangs. That said, I will continue to primarily recommend MSE to family and friends unless repeated infections indicate a need for the advance protection BAF may provide.

Before moving on from Microsoft Secuirty Essentials and Windows Defender (for Win 8), I thought this post Windows Defender and context menu for file check? (GTranslated) at Borns IT and Windows Blog was very insightful.  Some time ago I posted a number of Windows Defender tweaking tips Advanced Tips for Windows Defender with Windows 8, one of which was how to add a scan with Windows Defender to the context menu list in Win 8.  Born’s acknowledges that is a popular request and go though how it is accomplished. However, as he points out, the way Windows Defender operates, when a file is accessed via the (File) Explorer, Windows Defender already scans it before allowing access. If it is infected then you don’t get to fiddle with it.  Same thing with downloaded files; again pre-scanned by Windows Defender.  So, you can manually scan them again if you want, but know that if you do use Windows Defender in Win 8, it has already scanned the file.

Message Analyzer has Released – A New Beginning and Message Analyzer: Why so different from Network Monitor? - MessageAnalyzer Blog - Final release now public for Microsoft’s network capture analysis tool. I’m not sure it will replace Wireshark, but the approach is a step up from their older Network Monitor capture tool and is at the very minimum a great supplemental network capture tool for packet analysis.

Plugin Activation in Firefox - Mozilla Add-ons Blog - basically in a future version of Firefox, all plugins (except Flash) will become “click-to-activate”. This may or may not be a great thing depending on your security versus convenience perspective.

Wendel's Small Hacking Tricks - Killing Processes from the Microsoft Windows Command Line interface - SpiderLabs Anterior - I’m always looking to find a way to do something without a third-party tool so this is handy information to be familiar with.

Universal USB Installer (also YUMI) USB Flash drive does not boot on EeePC - RMPrepUSB, Easy2Boot and USB booting... blog - This is a pretty esoteric technical post for most folks, however if you are into USB-based system booting, it is interesting.

When setting up Windows 8.1, Microsoft appears to do all it can to shove you to create/use an on-line Microsoft account rather than a local one.  For some folks that might be fine but others (particularly the old-school crowd) will find this process similar to a cattle chute. If you are a thinking cow, it probably isn’t a very pleasant experience. Fortunately, there seem to be a number of outs if you know the game ahead of time.

  • How To Install Windows 8.1 Without Microsoft Account - Into Windows
  • Use Windows 8.1 with a local account instead of a Microsoft account - 4sysops
  • How to setup local account in Windows 8.1 - DeDoimedo.com
  • Windows 8.1 How To Convert Windows Live Account To Local Account - Next of Windows

Group Policy Search Engine Gets Updated - Group Policy Central blog - From that post by Alan Burchill:

“The Group Policy Search Engine is a great web site that has all the different version of Microsoft Group Policy ADMX files that allows you to easily and quickly search for the policy setting. This site is one I use very frequently especially and is a must have bookmark for any Group Policy Administrator.

“Well, Stephanus from Microsoft who maintains the web site has just loaded the Windows 8.1 and Windows Server 2012 R2 policy setting meaning you can now look up all the new policy setting in the latest version of Windows. “

Group Policy Search - site homepage.

Google Static Map Maker: Static Maps on Steroids - noupe - Nice tool to create linkable custom static Google maps rather than using a screen-shot image or a embedded and modifiable one.

Google Static Map Maker - site homepage by Katy Decorah.

Cheers!

--Claus Valca

Read More
Posted in Active Directory, browsers, Firefox, forensics, Google, Internet Explorer, Link Fest, malware tools, Microsoft, networking, security, Windows 8 | No comments

Saturday, September 14, 2013

GSD Saturday Linkfest: IT Crowd and ForSec Folks welcome

Posted on 4:31 PM by Unknown

News and Links For the ForSec Crowd

Kali Linux 1.0.5 and Software Defined Radio - Kali Linux - new build released with updates and some bells-and-whistles to boot!

Windows 8 / Server 2012 Memory Forensics - Forensic Methods

Inside Windows Rootkits - Forensic Methods

Links - Windows Incident Response blog - Lots of great fresh material here!

Forensic Perspective - Windows Incident Response blog

Tools to Grab Locked Files - Journey Into Incident Response blog - Cory Harrell has a simply amazing post full of tremendous resources worth taking a look into for using to grab locked files.

DOWNLOAD: Microsoft Security Intelligence Report, Volume 14 Windows Application & PDF - Kurt Shintaku's Blog - This is too good to pass up! From Kurt’s post.

The Microsoft Security Intelligence Report Windows application analyzes the threat landscape of exploits, vulnerabilities, and malware using the latest data from hundreds of millions of systems around the world and some of the Internet’s busiest online services.

Readers will find the data, insights, and guidance provided in this report useful in helping them protect their organizations, software, and users.  

Key features of the application include:

  • All content, in one convenient place – includes all 800+ pages of content from Volume 14 of our latest report and is fully searchable.
  • High fidelity charts – Many customers have asked us if they can obtain high resolution versions of the charts. We’ve delivered that in the application and have even included the “save as” functionality so that customers may use them in other applications, such as PowerPoint.
  • Reader friendly – We’ve designed the application with you, the reader in mind. One example of this is the integration of our glossary into the body of a page which appear as mouse-over tool-tips.

Security Intelligence Report (SIR) vol.14 (Windows Application) - Microsoft.com - The installable application has 800+ pages of content while the PDF version checks in at 120 pages. Pick you medicine and pucker up.

Other useful Microsoft security and threat response links:

  • Microsoft Malware Protection Center
  • Microsoft Security Response Center
  • Computer Security Tools & Downloads – TechNet Security
  • Microsoft Security Intelligence Report

Microsoft Security Essentials Prerelease - Microsoft Download Center - new pre-release version 4.4.207.0 for interested users of MSSE. Released on 09.09.13 so it is very fresh.

(IN)SECURE Magazine issue 39 released - HelpNet Security - Download directly here (PDF link).

News and Links For the IT Crowd

I enjoy the technical and scientific articles I get in my RSS feeds over from the IEEE Spectrum website. It has great material and is terribly technical. Some sadly interesting IT news I’ve seen over there recently tag state IT departments.

  • IT Hiccups of the Week: A Bad Week for U.S. State Government IT - IEEE Spectrum
  • Is There a U.S. IT Worker Shortage? - IEEE Spectrum
  • IT Hiccups of the Week: U.S. State Government IT System Meltdowns Galore - IEEE Spectrum

A new find this week has been the Microsoft Office Configuration Analyzer Tool

The Microsoft Office Configuration Analyzer Tool (OffCAT) is a program that provides a detailed report of your installed Office programs. This report includes many parameters about your Office program configuration and highlights known problems found when OffCAT scans your computer. For any problems that are listed in the report, you are provided with a link to a public-facing article (usually a Microsoft Knowledge Base article) on the issue so you can read about possible fixes for the problem. If you are a Help Desk professional, you can also save the report to file so that the report can be viewed in the Office Configuration Analyzer Tool on another client where the tool is installed. The Office Configuration Analyzer Tool 1.1 also includes a command-line version that can be used to collect an OffCAT scan without user intervention.

I’ve been playing with it for a while and am amazed at the depth of information and assistance it provides, particularly for many very obscure items.

Spotted over at this 4sysops post FREE: Microsoft OffCAT – Office Configuration Analyzer Tool 1.1

MBSA 2.3 Preview Release Available - Anything about IT - News about a new preview release version of Microsoft Baseline Security Analyzer (note link is to public version 2.2) that supports MS OS’s between XP and Windows 8.1

Windows 8.1 Command Prompt or PowerShell - Anything about IT

PowerShell 4.0 – A first look - 4sysops

How to Know When an Object Was Created and Changed in Active Directory - WindowsNetworking.com

When was the Last Password Changed for a User Account in Active Directory - WindowsNetworking.com

Office 365 for Nonprofits Organizations - Microsoft.com - Microsoft recently announced that they are offering Office 365 for non-profits (including eligible churches). This could be a big deal for many, learn more here.

SysInternals Tools, Windows 8 Training - Microsoft Virtual Academy - Seven video training modules and supporting materials to assist with learning the latest in core SysInternals tools. Check it out! Hat tip to Kurt Shintaku.

Kyle Beckman has posted a great series about Folder Redirection over at 4sysops that I (re)discovered. Lots of good information and tips here.

  • Folder Redirection – Part 1: Introduction - 4sysops
  • Folder Redirection – Part 2: Setting up your file server
  • Folder Redirection – Part 3: Explanation of folder permissions
  • Folder Redirection – Part 4: Group Policy configuration
  • Folder Redirection – Part 5: Best practices
  • How to disable Folder Redirection

Create a new Windows Service

Moon Point Support Weblog had a helpful post: Creating a Service for a Windows System

It caught my eye as we are working with a system down in the coal-mines that requires running the core features as applications rather than services which makes security and log-in/account management more than a little bit challenging. Alas, this won’t solve those headaches but it is worth bookmarking and knowing.

How To Create a User-Defined Service - Microsoft Support

How to create a Windows service by using Sc.exe - Microsoft Support

NSSM - the Non-Sucking Service Manager

Virtualization Software Updates

Download VMware Player 6.0 - VMware

VMware woos power users and IT pros with Fusion and Workstation upgrades - Ars Technica

VMware Player 6 Released with Full Windows 8.1 Support - Next of Windows

Oracle VM VirtualBox - Version 4.2.18 released - Oracle

General Application and Utility Updates of Note

UltraVNC VNC - version release 1.1.93 now out.

PeStudio - version release 7.45 now out.

Speccy v1.23 - Piriform - new release.

HWiNFO Portable - version 4.24-2000 - PortableApps.com - in what begs another GSD LinkList post, HWiNFO is yet another system hardware info-gathering resource I’ve been playing with. I’ve got more than a few I call up from the bullpen and this one has been added to the pitching stable.

IOBit Driver Booster Free - I confess I was very skeptical when I saw this new application appear. I have a few trusted driver apps to catalog and/or back up existing drivers on a system, and some vendor-specific driver update scanning applications used to update my systems. However, I have generally distained apps that claim to scan for driver updates on Windows systems and tell me what I need. Driver updating can be a dangerous and system-harmful thing if the wrong one is applied. So when I tried with trepidation this application, I found the UI was super clean and easy to navigate, the scan was immediate and dead-on fast, it seemed very accurate (finding only one out of date driver), provides a detailed and comprehensive list of drivers checked and their status, and creates a Restore point before every driver update is installed. It’s so easy I’d recommend it to my non-techy friends and family who I support. Great job IOBit! I’ll be running this one weekly!

SoftPerfect Network Scanner - updated to version 5.5. See Changelog for details.

Wireshark - updated to Stable version 1.10.2 and Old Stable version 1.8.10.

  • Wireshark 1.10.2 - Release notes
  • Wireshark 1.8.10 - Release notes

For you crazy WinPE building fans who use WinBuilder, a new version has been released that is much different from the previous version you may be familiar with. At the time of this blog-posting, the Winbuilder.net site seems to be temporarily down, but here were the applicable links you need to check out. I suspect fans of WinBuilder will fall one one side of the fence or the other; love it or hate it. Particularly with the Java building components.

  • WinBuilder - Development - reboot.pro
  • WinBuilder - reboot.pro
  • without imbedded Java RTEs - download version.

lessmsi (aka Less Msiérables) · ActiveScott at GitHub - now at version 1.1.3 The download link is a bit hard to find on the page if you aren’t used to GitHub. Look for “1 release" at the top bar just above the purple band and click it to find the compiled binaries in lessmsi-v1.1.3.zip.

d7 v10 Just Released! - Computer Technician - Foolish IT LLC.the updated change list is too expansive for me to try to list here. Check it out.

SoundVolumeView - new NirSoft utility - View/change sound levels & save/load sound level profiles on Windows Vista/7/8/2008 - More details in this NirSoft blog post.

Whew!  That post tired me out…or maybe it was the A&M/Alabama game live-streaming on my second monitor.

--Claus Valca

Read More
Posted in Active Directory, anti-virus software, boot-cd's, forensics, Link Fest, Linux, malware tools, Microsoft, networking, PowerShell, security, software, tutorials, utilities, virtualization, viruses | No comments

Saturday, September 7, 2013

Microrant: Microsoft Security Essentials & File Restore

Posted on 8:07 AM by Unknown

I’ve been a long time fan of the anti-virus/anti-malware application Microsoft Security Essentials for non-technical family and friends for the following reasons.

  1. It’s free.
  2. The GUI is not “scary” or threatening to civilians.
  3. It plays very well with all Windows OS’s (XP-Win7).
  4. It automatically updates the engine and DAT files as part of the Windows Updates settings.

Since I have been running it on my own personal systems for quite a while, it is super-easy to walk folks through solving most any problems they have without needing to get a remote session to their PC.

Granted, while it has rated low in recent AV-TEST results my confidence it it has remained high enough to continue to use and recommend it to others.  (MSSE rebuttal to those results here.)

However the UI frustrated me today and I am strongly considering switching over to Bitdefender Antivirus Free.

I’ve been running Bitdefender Free on my Win 8 virtual machines for some time and absolutely love it.  The interface is a bit more “geeky” and technical than MSSE and you need to provide/register it with a valid email address. However that also gets you access to a “cloud-based” console to manage and view history on all your Bitdefender free systems that you have registered. That’s kinda handy and useful for geeks like me who use a similar approach at work.

Bitdefender products also get rated high in recent AV-TEST results.

(See also Virus Bulletin summary results.)

Anyway, the rant today is because of the current MSSE handling of potential threats; or to be more accurate, the behavior encountered in the UI when trying to recover from MSSE’s handling of potential threats.

This morning I had downloaded an updated version of Nir Sofer’s IE PassView.  I use this great utility when I am responding to a user’s system where they have forgotten passwords (and didn’t write them down or put them in a digital password manager app). Often they saved the password to “auto-enter” in IE when the browse to the page (yuck but what are you gonna do?). So I can use this tool with their permission to look for and recover the password for them. If I don’t find it there, I try many of the other password tools Nir Sofer has on his site. Usually I get lucky and can recover it.

Only today, when I downloaded the ZIP file package for the application, MSSE kept intercepting the downloaded file and quarantining it as a threat.

No biggie. I’d expect as much since it could be used by others for nefarious purposes.

So I just opened up MSSE, clicked on the “History'” tab, and found it present under the Quarantined items list.

So I did what seemed natural and ticked the checkbox next to the line item, and hit the “Restore” button.

It disappeared out of the list.

I checked back to my download location.  File not there.

Hmmm.

So I downloaded the file again from NirSoft.  Again it was intercepted and quarantined. Again I restored it.

Again it disappeared to the netherworlds.

I didn’t see an UAC prompts even though the “Restore” button has a little shield like it should be prompting me for confirmation action.

Hmmm.

Clearly “Restore” didn’t restore anything. Nor did it whitelist the file for future downloads.

It wasn’t listed in my “Allowed items” list in MSSE either.

Ok.

So, non-intuitively, I selected the “All detected items” radio button.

In the list was the file listed several times for all the repeated download attempts.

5j3qw4s4.prl

I clicked on one of those and selected “Allow item”.

A UAC prompt appeared and I said “OK”.

I checked my download location and there was the restored file now.

The item still wasn’t added and listed in the “Allowed items” list.

Hmmm.

So (as of today) it appears that in some cases with MSSE, when a file is intercepted and quarantined, and you want to free it from quarantine and restore it;

  1. don’t select it from the quarantine list and “Restore” from there.
  2. select it from the “all detected items” list and “Allow item” from there.

Running iepv.exe didn’t generate any MSSE alerts or warning bells.

Subsequent retries shows that MSSE no longer quarantines downloads of the ZIP file.

So MSSE seems to have been quite good at intercepting the ZIP file for IE Pass View during download, and quite good at making it challenging to “restore” the download file after it had been quarantined. However it also was quite poor about easily allowing me to “whitelist” it. Nor did it complain or protect me (not that I really wanted I to…just saying) from the actual execution and presence of the iepv.exe binary.

Hmmm.

This alone isn’t enough reason to jump away from MSSE, however it is one more data-point in my considerations of moving to a different solution on my personal system.

Posting in case anyone else searches the Googles for this particular issue.

--Claus V.

Read More
Posted in anti-virus software, malware tools, Microsoft, security, troubleshooting | No comments

Sunday, August 11, 2013

Utility updates and stuff - Quickpost

Posted on 6:35 PM by Unknown

Updated recently.

  • Autoruns v11.70, Bginfo v4.20, Disk2vhd v1.64, Process Explorer v15.40 - Sysinternals Site Discussion
  • Download PeStudio 7.35 - updated - Winitor.com
  • PhotoRec - Digital Picture and File Recovery - now released at stable version 6.14.
  • TestDisk - CGSecurity- now released at stable version 6.14.
  • FreeFixer: Free Tool To Remove Potentially Unwanted Software - The Windows Club - Use with caution!
  • Spybot promises better performance, smoother installation - Betanews
  • Spybot - Search & Destroy from Safer-Networking Ltd.
  • EventLogSourcesView - NirSoft - new utility release to view all event log sources install on your system. Interesting.
  • dUninstaller | Computer Technician - PC Repair Software |Foolish IT LLC - Neat uninstaller tool for technicians. Not for the common man or woman. Definitely not for children and unattended noobies.

Other uninstallers worth considering (for the common folk)

  • MyUninstaller - NirSoft - Alternative uninstaller to the standard Windows Add / Remove module - This is my “go-to” uninstaller, especially for Windows XP systems.
  • GeekUninstaller - This one is really growing on my fast, especially for Win7/8 systems. My # 2 favorite, may be my new favorite after a few more dates.
  • IObit Uninstaller Portable - PortableApps.com
  • Revo Uninstaller Portable - PortableApps.com
  • ZSoft Uninstaller Portable - PortableApps.com
  • Wise Program Uninstaller Portable - PortableApps.com
  • Uninstall Tool - Portablefreeware.com - I used to love, love, love this tool back when I was first getting started in my “technicians” career. A much modernized version (no longer freeware) is now available but if you want v1.6.6 (the last freeware version), you will have to grab it from here.
  • Free Uninstaller 1.1 - Freeware replacement for the system applet - Jacek Pazera. Like Uninstall Tool above, I still carry this one on my USB stick but I never use it. Hasn’t been updated for a very long time but hey, it works on all systems from NT to Vista, so if you need an uninstaller tool for your NT/Win2K/Me/98 box, this might be the girl you are looking to dance with!

Cheers.

Claus V.

Read More
Posted in anti-virus software, malware tools, software, utilities | No comments

Sunday, July 28, 2013

ForSec “Value Package” Linkfest - No coupons required!

Posted on 5:00 PM by Unknown

One last Linkfest from a now exhausted GSD blogger this weekend.

Cleaning out the “to-be-blogged” hopper is always rewarding, but I tend to get very behind on the weekend chores. My saving grace this weekend has been frequent scattered showers and an equally tired Lavie who hasn’t been interested in going out for shopping, groceries, or dining out. The kitchen has been cleaned. The laundry has been done for the week.

Next stop, a few hours of rest, post-blogging, then a wind-down with Endeavour on PBS Masterpiece.

Too Funny Not To Miss

Bloody galah scammers still not getting the message - Troy Hunt’s blog. Security guru Troy Hunt has had his fair share of “this is (not) Microsoft cold calling you…your PC is infected…let me remote control it” scams and has picked them all apart to the bone.

This time he takes a new angle…in a way that only an Aussie could pull off!  This is a classic! Troy, please offer us some of those sound files or link to where we can get them!  I need to put together a Texan sound-effect package for similar fun with unwanted callers. Brilliant!

Microsoft Security News

Microsoft Releases New Mitigation Guidance for Active Directory - Microsoft Security Blog

Overview of Microsoft`s "Best Practices for Securing Active Directory" - SANS Computer Forensics and Incident Response blog’s Mike Pilkington does a great summary and takeaway of the new AD mitigation guidance.

Security Awareness Training: Your First Line of Defense (Part 4) - WindowSecurity.com’s Deb Shinder discusses evaluating training effectiveness short and long-term.

See also these previous series posts:

  • Security Awareness Training: Your First Line of Defense (Part 1)
  • Security Awareness Training: Your First Line of Defense (Part 2)
  • Security Awareness Training: Your First Line of Defense (Part 3)

Network Security, News and Techniques

Wireshark 1.8.9 and 1.10.1 Security Update - ISC Diary

  • Wireshark 1.10.1 - Release Notes
  • Wireshark 1.8.9 - Release Notes
  • Wireshark - Downloads

Next up are some great and detailed video presentations from Sharkfest 2013

  • Sharkfest 2013 - Wireshark Network Forensics (by Laura Chappell)
  • Sharkfest 2013 - Trace File Sanitization NG (by Jasper Bongertz)
  • Sharkfest 2013 - Attack Trends and Techniques (by Steve Riley)
  • Sharkfest 2013 - Capture Limit of a Laptop, When does it Drop Packets? (by Chris Greer)

Recent Forensically Focused Posts

  • HowTos - Windows Incident Response blog
  • HowTo: Malware Detection, pt I - Windows Incident Response blog
  • HowTo: Data Exfiltration - Windows Incident Response blog
  • HowTo: Add Intelligence to Analysis Processes - Windows Incident Response blog
  • HowTo: Determine/Detect the use of Anti-Forensics Techniques - Windows Incident Response blog
  • HowTo: Investigate an Online Banking Fraud Incident - Windows Incident Response blog
  • Finding an Injected iframe - Journey Into Incident Response blog
  • MS Excel and BIFF Metadata: Last Opened By - Digital Forensics Stream blog

Physical (In)Security?

Duplicate house keys online - Keys Duplicated - This is either freaking amazing or super-scary. I just can’t decide! According to their Security page, precautions are taken.

The Keys Duplicated Blog - A couple really cool and technical posts on the behind the scenes things that make their keys pretty good.

…as spotted on Lifehacker’s post: Shloosl Copies Your House Keys Using a Smartphone Photograph

When 'Smart Homes' Get Hacked: I Haunted A Complete Stranger's House Via The Internet - Forbes

ForSec LiveCD Distro News

  • More on WinFE and Autopsy - Windows Forensic Environment blog
  • DEFT Linux 8 stable with DART 2 is out! - DEFT Linux - Computer Forensics live cd
  • Kali Linux Summer Update Release 1.0.4 - Kali Linux
  • Pass the Hash toolkit, Winexe - Kali Linux
  • Downloads - Kali Linux

AV/AM Bits

Microsoft Security Essentials quietly released version 4.3.216.0 engine update for their free antivirus scanning program. If you use MSSE, you should get it via the automatic updates…if you have them turned on…you do have them turned on right?

Download Microsoft Security Essentials - Microsoft Download Center - Like most things MSSE, trying to figure out just what got updated is next to impossible so let’s just say for now that this one must be better than the previous version and move on.

I’m still using MSSE around the Valca home on all our home systems. I also continue to recommend it to friends and family (generally everyone non-work-related) who I provide friendly IT support to. I find it is pretty non-threatening to the non-technical users I know and though it loves to alert on many of my security programs (potentially unwanted programs) since they can also be used for 3vil, it seems to do a more than adequate job security the systems.

For my Windows 8 systems, I’m instead relying on Bitdefender Antivirus Free. In some ways it’s a bit different model in that you need to sign up with an email address to set up your account. Then you can download the client to the system. What is nice is that if you manage multiple systems in your home, you can log into your account at their site and then get a console feedback on the status of those systems. That’s something that I do at work with another vendor’s enterprise AV client health/status management console. That’s super cool for a free product. I’m seriously leaning to expanding it’s coverage to my main Windows 7 laptop at home. Performance has been outstanding on my Windows 8 systems.

Kaspersky tops real world protection test - BetaNews - this post does point out that Bitdefender tied Kaspersky with a 99.9 % protection level in AV-Comparatives Independent Tests of Anti-Virus Software for July 2013. While Microsoft Security Essentials rated a 92.5 % protection level. There are some additional disclaimers so read the short BetaNews article carefully. Then head over to AV-Comparatives to dig deeper and see the full findings.

  • AV-Comparatives Real-World Protection Test March-June 2013 - AV-Comparatives
  • AV-Comparatives Real-World Protection Tests - AV-Comparatives

Finally, we wrap up this segment with this interesting discussion:

The evolution of Ronvix: Private TCP/IP stacks - Microsoft Malware Protection Center

It’s a bootkit infection that has its own private TCP/IP stack. By doing so it can be extra stealthy and bypass personal firewall hooks and can lurk unseen in standard tools and utilities (such as nbtstat). Doing so, depending on packet/network monitor off the infected machine may be ineffective. However, it still must talk ON the network, so an independent network monitoring and forensics analysis approach using a network monitoring appliance or span port capture may detect the traffic. This may be why comparing outside network traffic captures from a system on the network to network traffic captured on the system may be a useful exercise for incident response and monitoring purposes.

Legally Focused

I’ve been reading a wider range of subjects, and a small part of those touch on our legal system. Mainly they apply to digital law and crime but some are more general. I’m just tossing them out there for the interested or curious. Generally they tend to analysis of current events or provide a more detailed lawyer’s review than the talking/shouting legal heads we encounter on mass-media “news-like” entertainment outlets these days.

  • CYB3RCRIM3 - Susan Brenner’s blog on cybercrime and cyberconflicts in technology and law.
  • Popehat - group blog with a mostly legal focus (though topics can range far afield!)
  • Le·gal In·sur·rec·tion - group blog with mostly legal and law-in-today’s-culture focus. Pretty vibrant opinions. Alignments may vary.
  • Lowering the Bar - Sometimes lighthearted (though always serious at the core) look at some of the nonsense the legal system contains, or foists on others from time to time. Great site.
  • Massad Ayoob - legal, cultural, and educational postings primarily dealing with legal private firearm ownership issues. Also analysis of public media trends and news stories.

Have a great week!

--Claus Valca

Read More
Posted in Active Directory, anti-virus software, boot-cd's, cheat sheets, firewalls, forensics, humor, Link Fest, malware tools, Microsoft, networking, NFAT, security, troubleshooting, tutorials, utilities, video, viruses, Win FE | No comments

SysAdmin Linkfest - Chock'-o’-Videos Edition (G-rated version)

Posted on 3:41 PM by Unknown

This is a super-heavy linkpost filled to the rim with video presentation linkages. Make sure you have some extra time and bandwidth set aside for all these.

Seriously. You think I’m joking, but all it takes is one sysadm running around careless with streaming video file links and then “bam” someone ends up loosing their bandwidth.

As tempting as it is, I’m just providing the links to the video rather than embeds of the video in a player itself. Not that Mark and the Defrag Tool guys aren’t handsome or anything, its more because I just hate seeing the Flash SWP pre-load in everyone’s web-browser when I then get behind in posting and you fans are hit with it when you land on a GSD blog page with embedded video and you aren’t using a Flash-blocking plugin, or have it disabled for my blog.

w1fil0k5.j3p

(the evidence as seen in Process Explorer as happened back from April 2013 - late June 2013 )

General philosophy: wipe the baby and keep it, toss the diapers

Why wiping decommissioned IT assets should be a must - Help Net Security - Duh.

The cost of cleaning up - ISC Diary

GrandStreamDreams blog has written heavily regarding securely wiping hard drives. It should be a no-brainer in today’s digital age…and coupled with some whole disk encryption (to boot). Likewise I just can’t grasp how it is cheaper to trash 170 PC’s because they were infected rather than having a secure-wipe/standard-image reload process. Don’t skip the ISC Diary article’s Comments section.

Sysinternals/Pass the Hash TechEd North America talks

Sysinternals - and Pass the Hash - at TechEd next week- Aaron Margosis' "Non-Admin" and App-Compat WebLog - These were five keynote talks back from June. In case you couldn’t stop by New Orleans last month, you got some serious catching up to do now!

  • License to Kill: Malware Hunting with the Sysinternals Tools - Channel 9 - Mark Russinovich presenting
  • Case of the Unexplained 2013: Windows Troubleshooting with Mark Russinovich - Channel 9 - Mark Russinovich presenting
  • Sysinternals Primer: TechEd 2013 Edition - Channel 9 - Aaron Margosis presenting
  • Pass the Hash and Other Credential Theft and Reuse: Preventing Lateral Movement and Privilege Escalation - Channel 9 - Aaron Margosis, Mark Simos presenting
  • Defrag Tools: Live - TechEd USA 2013 - Channel 9 - Andrew Richards presenting

The Case of…

Case of the Slow Logon – Anti-Virus vs 3rd Party Application - chentiangemalc

Case of the Windows 8 Explorer Hang – Part 1 - chentiangemalc

Defrag Tools takes on Windows Performance Toolkit

You may recall the GSD blog post Case of the Unexplained Donut of Death where I started out using Windows 7 Xperf tool to do some performance troubleshooting. I then jumped from it to the new WPT set in Windows 8 SDK and outlined just how amazing the level of logging detail and analysis was.

Windows Perfmance Analyzer SDK 8

As the time there was not a considerable amount of documentation out for us mere mortals on how leverage the true power the tools contained.

No more. The team at Channel 9 has hit the ground hard with a series of videos going into the details on the tool and its features. I suspect more will come. Now I can really start figuring out what all those indicators shown above really mean!

  • Defrag Tools: #39 - Windows Performance Toolkit
  • Defrag Tools: #40 - WPT - WPR & WPA
  • Defrag Tools: #41 - WPT - Command Line
  • Defrag Tools: #42 - WPT - CPU Analysis
  • Defrag Tools: #43 - WPT - Wait Analysis
  • Defrag Tools: #44 - WPT - DiskIO Analysis
  • Defrag Tools: #45 - WPT - File & Registry Analysis
  • Defrag Tools: #46 - WPT - Driver Analysis
  • Defrag Tools: #47 - WPT - MiniFilter Analysis
  • Defrag Tools: #48 - WPT - Memory Analysis - Pool

Offline Windows Updating

WSUS Offline Update - I have been a longtime fan of this tool, updated a few days ago to version 8.5. I never leave my cubicle to respond to a system or re-image/deployment without it on my USB stick. It is the #1 tool I know of to help conserve bandwidth and minimize impact at a site where we are doing a deployment. It remains highly Valca recommended! If you are a Windows PC deployment tech or analyst and you don’t have this tool, you either have some super-big circuits, an internal WSUS server, or you can swagger like Beckham and just don’t care.

Portable Update - This “bravo-ware” tool is new to me. Like WSUS Offline Updater, once built you can use it to redeploy Windows/MS patches to a target system. The process seems considerably different that USUS-OU but it may work better for your needs. I’m hoping to test it soon and have a better side-by-side experience to compare them against. For more information on the tool check out the application’s How to use page as well as this AddictiveTips post: Apply Windows Update To Multiple PCs From A USB Drive While Offline.

SysAdmin Tips

Run any app under the NT Authority\Local System account - TinyApps.org - Comparison between ETS (Elevate To System) tool (it has an optional GUI) and psexec.exe from Sysinternals.

FREE: Get Local Admins GUI – Find users with administrator rights - 4sysops

How To Make UEFI Bootable USB Flash Drive to Install Windows 8 - Next of Windows

Making a better, somewhat prettier, but definitely more functional Windows Command Line - Scott Hanselman’s ComputerZen blog

How To Quickly Unlock Local Administrator Account in Windows 8 - Next of Windows

Finally a Windows Task Manager Performance tab blog! - Ask the Performance Team

SysAdmin Utility & Software Leads

Updates: Mark's TechEd Sessions, Autoruns v11.61, Strings v2.52, ZoomIt v4.5 - Sysinternals Site Discussion

Updates: Autoruns v11.6, Procexp v15.31, Procmon v3.05, Sigcheck v1.92 - Sysinternals Site Discussion

Update: Autoruns v11.62 - Sysinternals Site Discussion

Free Windows virtual machines for Mac, Linux, or Windows - TinyApps.org blog - Official developer virtual machine files for XP, Vista, WIn7 and Win 8. These are really for Internet Explorer developers but are great for other software testing purposes. Even more details here: Making Internet Explorer Testing Easier with new IE VMs - Rey Bango.  Main VM’s download link here.

CopyToFlash - Foolish IT - This could be really dangerous. REALLY dangerous. Like most stuff over at Foolish IT. However it could just be dead-helpful for the right audience and application. Basically it just starts a drive monitoring process and then (with a few configuration actions) will copy the contents of a monitored source folder location to any USB flash drive that attaches to the system. Yeah. Dangerous but helpful if you are responsible for updating new content to tons of USB sticks. Oh, did you know it uses RoboCopy? Yep.

Office 2010 Service Pack 2 Released…(mostly)

Just in time after a major Office 2010 rollout at our coal-mine. Nice timing guys…

Microsoft delivers Office 2010 Service Pack 2 - ZDNet - Mary Jo Foley

Office 2010 and SharePoint 2010 Service Pack 2 Availability - Office Sustained Engineering Blog

Description of Office 2010 SP2 - Microsoft Support

How to obtain and install the service pack

Method 1: Microsoft Update (recommended)

Note In addition to the products in the Office 2010 suite, the service pack 2687455 also updates Microsoft Project 2010, Microsoft Visio 2010, and Microsoft SharePoint Designer 2010.

To download the service pack from Microsoft Update, go to the following Microsoft website:

Microsoft Update

You can opt in a computer to the Microsoft Update service, and then register that service with the Automatic updates to receive the SP2 update. Microsoft Update will detect which products that you have installed, and then apply all updates to the products.

Method 2: Download the SP2 package from Microsoft Download Center

The following files are available for download from the Microsoft Download Center:

  • Download the Microsoft Office 2010 Service Pack 2 32-bit package now.
  • Download the Microsoft Office 2010 Service Pack 2 64-bit package now.

For more information about how to download Microsoft support files, click the following article number to view the article in the Microsoft Knowledge Base:

119591 How to obtain Microsoft support files from online services

Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help prevent any unauthorized changes to the file.

For more information about a complete list of all released SP2 desktop packages, click the following article number to view the article in the Microsoft Knowledge Base:

2687521 List of all Office 2010 SP2 packages

Cheers,

Claus Valca

Read More
Posted in Active Directory, Internet Explorer, Learning, Link Fest, malware tools, Microsoft, security, troubleshooting, tutorials, utilities, video, Virtual PC, virtualization | No comments

New Apps and Utility Updates

Posted on 1:30 PM by Unknown

Submitted here for your frustration is a jumble of new and updated software applications I’ve collected over the past couple of weeks.

Think of it like the “pot-luck” box where everything is free for the taking after the week-long garage sale has concluded.

Only you might really want something in this mix.

MetroTextual 1.5 - SingularLabs - slick notepad replacement has some new improvements in this edition. Including Transformers (Plugins).

SpeedyFox - CRYSTALIDEA Software - Some time back got bumped to version 2.0.4. I run this regularly to clean up my Firefox/Chrome/Thunderbird databases. It really helps with launch speed. See also SpeedyFox Portable - PortableApps.com

CPU Meter Pro - Microsys - The GUI is very nice though the level of detail might be a bit less than some sysadmins might prefer.

DLL UnInjector - NoVirusThanks - unload DLLs within a selected process. More at this Unload loaded DLLs with DLL UnInjector post.

Download Backup Thunderbird - free tool to back up Thunderbird email clients spotted in this AddictiveTips post Easily Backup & Restore Your Mozilla Thunderbird Accounts & Their Data. I personally have always relied on MozBackup.

NetworkLatencyView - Nirsoft - New tool that calculates the network latency. Some details in this NirBlog post: New utility that calculates the network latency of every TCP connection. Looks pretty cool for you network troubleshooting and monitoring geeks.

TightVNC version 2.7.10. - What's New in TightVNC

LibreOffice 4.1 is here! - LibreOffice.org

LibreOffice - Home

LibreOffice Productivity Suite Download - LibreOffice

LibreOffice 4.1.0 Portable - PortableApps.com

Opera Next 16 hints at new features - BetaNews. I don’t really follow Opera web-browser development very closely any longer. Most of my time is focusing on Firefox/Chrome/Chromium/Internet Explorer. Hover there are some detail here that might be worth noting.

Network monitor debuts in latest Firefox beta - Mozilla Links. I really, REALLY like this addition…browser-bloat or not.

SMF v 5.0 – Search my Files - funk.eu - I’ve got more than many Windows file finders, searchers, and file indexing apps that I can summon at will. However funk’s SMF and NirSoft’s SearchMyFiles tools are my go-to file finders without peer. They both have been recently updated with loads new features and rather than see them as competitors, I see them as complimentary utilities depending on the search need at hand.

Intel® Driver Update Utility - Back while I was working on my “What is this “PC-Doctor Module” you speak of?” post, I noted Lavie’s system had the Dell Support Center software installed and how it can help with keeping OEM drivers updated. I checked my own system and the software wasn’t there. Maybe I uninstalled it? Anyway, this Java based application from Intel will do a scan of your system and report if any Intel-based hardware components are present and if a newer driver is available. Sometimes the OEM-branded driver will be preferred, however in most all cases, I have found the Intel driver is much, much fresher and more improved than the OEM version. Yesterday it told me my IntelProNic/WiFi network driver was way old so I updated it to the latest Intel driver version. No issues.

View DELL Service Tag and Express Service Code From Linux and Windows - The Geek Stuff.  Because sometimes it’s a hassle to flip your Dell laptop/desktop around to look for the codes:

1. Get DELL Service Tag on remote Windows system

Login to the Windows remote-host using VNC or remote desktop connection. Use WMIC on Windows to get service tag as shown below.

C:\>wmic bios get serialnumber
SerialNumber
ABCDEF1

Following WMIC command will give make and model number along with service tag.

C:\>wmic csproduct get vendor,name,identifyingnumber
IdentifyingNumber Name Vendor
ABCDEF1 PowerEdge 2950 Dell Inc.

If VNC or remote desktop connection to the remote-host is not available,  execute the following from the local-host to get the service tag of the remote-host.

C:\>wmic /user:administrator /node:remote-host bios get serialnumber
SerialNumber
ABCDEF1
[Note: Replace remote-host with the machine name of your remote-host.]

PeStudio 7.26 - winitor - (updated) - “PeStudio is a free tool to perform static analysis and investigation of any Windows executable file. A file being analyzed with PeStudio is never launched. Therefore, you can evaluate unknown executable files and even malware with no risk. PeStudio runs on any Windows platform and is fully portable, no installation is required. PeStudio does not change the system or leave anything behind.”


SoftPerfect Network Scanner - version 5.4.12 - a free network scanner, tweaked and updated. It’s one of my all-time favs.


Get the Start menu back in Windows 8 and 8.1 with Classic Shell - BetaNews - Tip from Mike WIlliams that Classic Shell 3.9 beta has improved their flagship tool for reclaiming the ground lost by users everywhere in the ongoing battle for Win8 Start Menu hill against Microsoft. I really like the way this looks. Pop over to Classic Shell directly to download the beta bits if you are interested. I find that I still (for now) prefer IObit Start Menu 8 Free for my Windows 8 tweaking. One of these days I’ll get caught up and empty out my lethargic Windows 8 post-launch pile-o-links that has more than a few additional alternatives. My little brother recommends Stardock’s $ Start8 application for what it’s worth.


Cheers.


--Claus Valca

Read More
Posted in browsers, Firefox, Internet Explorer, Link Fest, malware tools, Microsoft, networking, Opera, security, utilities | No comments

Sunday, July 14, 2013

ForSec briefs - Low Post Consumer Waste version

Posted on 5:17 PM by Unknown

Forensic LiveCD News

  • DEFT Linux 8 public beta & DART 2 stable ready for download DEFT Linux - Computer Forensics live cd
  • Running Autopsy 3 Digital Forensics Platform on WinFE Lite for Triage Forensics -Windows Forensic Environment blog

EMET 4.0 Related

  • toolsmith: EMET 4.0 - These Aren’t the Exploits You’re Looking For - HolisticInfoSec blog
  • Windows Security 101: EMET 4.0 — Krebs on Security
  • Threat Mitigation with EMET 4.0 - Microsoft Security TechCenter
  • Microsoft's EMET v 4.0 Released … in case you missed it - GrandStreamDreams blog

Fundamentals are Everything

Windows Incident Response Blog’s Harlan Carvey is running a great series of “How To” posts

  • HowTo: Determine Users on the System
  • HowTo: Correlate Files To An Application
  • HowTo: Determine Program Execution
  • HowTo: Determine User Access To Files
  • HowTo: Track Lateral Movement
  • HowTo: Correlate an Attached Device to a User
  • Finding Malware Like Iron Man Slide Decks - Corey Harrell - Journey Into Incident Response

Updates! Get Yer Updates!

  • Second batch of Windows 8.1 updates improve application compatibility - BetaNews
  • Adobe, Microsoft Release Critical Updates — Krebs on Security

Cheers.

--Claus V.

Read More
Posted in anti-virus software, boot-cd's, forensics, Link Fest, Linux, malware tools, Microsoft, software, Win FE | No comments

Sunday, June 30, 2013

Microsoft’s EMET v 4.0 Released … in case you missed it

Posted on 3:01 PM by Unknown

Microsoft’s Enhanced Mitigation Experience Toolkit 4.0 - EMET - just got released about two weeks ago.

It really hasn’t made that big a splash in the security news pond; maybe getting lost in all the waves from coverage on our domestic network digital data gathering, leaks in the SS Minnow, and that whole Facebook Shadow Profile data collection fiasco.

Oh, then there is that whole breaking story in the food world that has everyone shocked and a-twitter--How Cronuts Are Driving New York City Crazy.

So it’s not surprising that news of the release of a Windows-specific security tool to prevent advanced malware attacks got little notice.

So here you go.  Little rock toss into a big pond.

a0n12tap.xsg

I’ve got it running on all our home systems as well as all my Windows virtual machines. I’ve seen no performance issues at all and it is super-quiet; no chatter at all. Accordingly, I would recommend it to all my friends/family-members, especially those who insist on using Internet Explorer and do a lot of work in MS Office applications and documents. It is not a solution to replace any existing anti-virus/anti-malware security software you have, but rather it works to supplement and harden it.  I’m running it aside Microsoft Security Essentials (Win 7 systems), Windows Defender (Win 8 systems), and Bitdefender Antivirus Free (Win 8 systems). It works great.

  • Nuclear Scientists, Pandas and EMET Keeping Me Honest - SANS ISC Diary - great post from Johannes Ullrich detailing just how deployment and use of EMET (v3.5) could have prevented a recent “watering-hole” attack. It’s a great introduction on how the EMET software works. Version 4.0 is better.
  • EMET 4.0 is now available for download - SANS ISC Diary notice/followup.
  • EMET 4.0 now available for download - Microsoft Security Research & Defense blog. Great overview of the tool and all the new features and capabilities. Read this next before considering deployment
  • Enhanced Mitigation Experience Toolkit 4.0 - Official Microsoft Download Center source. It runs on everything from XP SP3 to Windows 8 platforms, as well as all related Server OS’s as well.
  • Enhanced Mitigation Experience Toolkit 4.0 - bink.nu - quick recap summary scraped from the product details of the official download site.
  • Microsoft’s EMET 4 adds even more malware-blocking power - Betanews overview of the tool.
  • Microsoft releases Enhanced Mitigation Experience Toolkit 4.0 - Help Net Security announcement of the tool.
  • Enhanced Mitigation Experience Toolkit 4.0 final is out - Ghacks.net - Nice review and overview of the EMET 4.0 features.

Not impressed enough yet to download?

Well, did I mention it has “skins” so you can change the theme to some pretty snazzy color schemes?

Seriously, if you spend any time on the Web (particularly in IE) and run a Windows system, then you really should consider deployment of this tool. Just take the default configuration settings to get started, then you can tweak away and add additional protection coverage after you read the manual.

Cheers!

Claus Valca.

Read More
Posted in anti-virus software, browsers, Internet Explorer, malware tools, Microsoft, networking, security, viruses, Windows 7, Windows 8, XP | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Network Capture Tools and Utilities
    At a conference this week, we had quite a section regarding network captures. The instructor was going on about how you can try to sort ou...
  • It just has to be bigger on the inside…
      Last Christmas, Lavie gifted me with a cute little Jawbone JAMBOX unit. I thought it was pretty cool. It uses a Bluetooth connection t...
  • Mostly Minor Network Notes
    Here are some minor tweaks and features, mostly of a network nature. Manual Uninstall of the Cisco VPN Client « Mobile Expertise -- becaus...
  • Windows Live Mail error 0x80041161
    Dad is working with his father-in-law who has an issue with his Suddenlink web-mail-based “forwarding” handling of messages. Seems that (an...
  • FireCAT 1.5 “Plus” Add-On Collection
    In yesterday’s GSD post I noted the following: Both of these tools brought be back to the excellent FireCAT 1.5 collection of Firefox...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ▼  2013 (83)
    • ▼  November (8)
      • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA uti...
      • ForSec Linkfest - 2013 DST Fallback Edition
      • CryptoLocker Ransomware Info & Free Prevention Sol...
      • Linkfest for the SysAdmins
      • Microsoft Security Essentials/Defender & PowerShell
      • Miscellaneous TrueCrypt linkage
      • PowerShell 4.0 and a tiny “gotcha”
      • New Software Updates + VMware Tools Update fix
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ►  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile