Two Plus Two Publishing LLC Two Plus Two Publishing LLC
 

Go Back   Two Plus Two Poker Forums > Other Topics > Computer Technical Help

Notices

Computer Technical Help Post your questions about computer hardware and software and configuring same here.

Reply
 
Thread Tools Display Modes
Old 03-23-2011, 11:59 AM   #1
BSOD and racetrack Ninja
 
wellju's Avatar
 
Join Date: Feb 2010
Location: ALL OF THEM
Posts: 5,129
How to prevent your pc from 90% of all malware in 30 seconds

In this thread I'll clear up some urban myths about computer security then give you a step-by-step guide to improving your computer's security in less than a minute.

If you don't care about what, why and who, just skip to the spoiler for the instructions.

First off, this guide doesn't apply solely to Windows 7 with SP1 installed, but it's highly recommended. Using XP/Vista or having an outdated OS (Operating System) will get in the way of security.

1. "There are convenient software solutions that protect you."

Let's get this straight. Having a secure system is neither effortless nor achieved by a single security program. Not even if they market it as a "suite."

2. "I use MacOS/Linux because of its security."

http://news.cnet.com/8301-13846_3-20011403-62.html

The 2 reasons why MacOS/Linux are supposed to be more secure than windows systems are:
a) Unlike windows, user accounts don't have admin rights by default.
b) Currently, there are far too few clients using these OSs for them to be a viable target for widely spread attacks.

For that reason, I contacted a friend and specialist at Symantec research labs and got a very informative heads up on the current technical state of malware. As a sidenote, the hacked user doesn't care if it's called a virus, trojan, malware, spyware or badware, and in reality, every attack is a combination of all of these, so we just stick to "malware". He has access to basically every kind of exploit that ever has been recorded.

I specifically asked if there was any malware that meets the following criteria:
  1. Can spread via networks without user interaction, i.e. clicking a link or opening email attachments.
  2. Can't be detected by current AV (Anti-Virus programs)
  3. Has the ability to gather and identify personal and crucial data such as account names, passwords, credit card information, etc ...
  4. Can use your network to send this data to the creator of the malware
  5. Does not need admin-rights to be executed.
The simple answer, there are none. This statement is valid as of March 18, 2011.

However, this picture changes drastically when you alter #1 and #5 of the criteria.

The single most important factor in your system's security is still your online behavior.

If you open email attachments that you didn't ask for, or click on links to collect the million dollar cash prize you just won in a lottery you didn't enter, no one on this planet can help you.

Also, if you're running your OS with administrator-privileges, malware can mess you up even if you don't click bad links, especially if your router (aka hardware firewall) is not set up properly.

They key factor is admin-rights. Malware can't spread, gather information or send it to someone else without admin-rights. You don't need them for everyday computer work - just for installing, removing and configuring applications and system settings.

According to Secunia, the average user installs 2 new programs every year. That means that, if you don't use a user account with admin-rights, you'd have to enter your admin-password twice a year. Or whenever you're going to modify system files. I hope that wouldn't be too much of an inconvenience for you.

Spoiler:


These measures only prevent you against common attacks, but at least nearly against all of them.

Also, funkyworms' CTH security sticky is basically mandatory to further secure your system, it just misses the "remove admin rights from your everyday user account".




Quote:
Ninety percent of critical Microsoft Windows 7 vulnerabilities can be mitigated by configuring the operating system for standard user rather than administrator,
http://news.cnet.com/8301-27080_3-20001359-245.html

Quote:
Key findings from this report show that removing administrator rights will better protect companies against the exploitation of:

90-percent of critical Windows 7 vulnerabilities reported to date
100-percent of Microsoft Office vulnerabilities reported in 2009
94-percent of Internet Explorer and 100 percent of Internet Explorer 8 vulnerabilities reported in 2009
64-percent of all Microsoft vulnerabilities reported in 2009
http://www.tomshardware.com/news/win...are,10054.html


Quote:
Configuring users as standard users enables parents to more securely share family computers with their children.
http://arstechnica.com/microsoft/new...min-rights.ars
wellju is offline   Reply With Quote
Old 03-23-2011, 11:59 AM   #2
BSOD and racetrack Ninja
 
wellju's Avatar
 
Join Date: Feb 2010
Location: ALL OF THEM
Posts: 5,129
Re: How to prevent your pc from 90% of all malware in 30 seconds

.
wellju is offline   Reply With Quote
Old 03-23-2011, 12:02 PM   #3
BSOD and racetrack Ninja
 
wellju's Avatar
 
Join Date: Feb 2010
Location: ALL OF THEM
Posts: 5,129
Re: How to prevent your pc from 90% of all malware in 30 seconds

Also, if all of this is completely new to you and my instructions are too complicated, please let me know.
It's no problem to do screenshots or a video of it, but it's only 15 mouseclicks, so chances are this might be way easier to do than you might think after the first look.


I hope there will be a further discussion about UAC, the hidden admin account, possible problems with ownership of system files and general security statements specific to Windows7.

Ask away!

Last edited by wellju; 03-23-2011 at 12:07 PM. Reason: Ty ToTheInternet for correcting my Eurenglish.
wellju is offline   Reply With Quote
Old 03-24-2011, 12:26 AM   #4
indisposed
 
Gonzirra's Avatar
 
Join Date: Apr 2006
Posts: 17,009
Re: How to prevent your pc from 90% of all malware in 30 seconds

Quote:
Originally Posted by wellju View Post
Also, if you're running your OS with administrator-privileges, malware can mess you up even if you don't click bad links, especially if your router (aka hardware firewall) is not set up properly.
Running in admin mode is something lots of people do by default and its just a huge mistake. It's just operating in a very vulnerable state for no reason. Not that I'm a high-risk user based on my habits but when I stopped running as an admin 24/7 problems dropped dramatically.
Gonzirra is offline   Reply With Quote
Old 03-24-2011, 02:25 AM   #5
band
 
LirvA's Avatar
 
Join Date: Sep 2007
Posts: 40,192
Re: How to prevent your pc from 90% of all malware in 30 seconds

wellju
LirvA is offline   Reply With Quote
Old 03-24-2011, 04:55 AM   #6
banned
 
ashes of eight's Avatar
 
Join Date: Jul 2008
Location: - )
Posts: 8,087
Re: How to prevent your pc from 90% of all malware in 30 seconds

this is so simple but great advice .. cant believe ive been running in admin for so long ..
ashes of eight is offline   Reply With Quote
Old 03-24-2011, 03:15 PM   #7
adept
 
MNOWAX's Avatar
 
Join Date: Jun 2010
Location: Phelps, NY
Posts: 1,004
Re: How to prevent your pc from 90% of all malware in 30 seconds

this is great advice! If only people would actually do this!
MNOWAX is offline   Reply With Quote
Old 03-24-2011, 07:19 PM   #8
centurion
 
akaAlso's Avatar
 
Join Date: Mar 2009
Location: UK
Posts: 189
Re: How to prevent your pc from 90% of all malware in 30 seconds

Thank you, been meaning to do this for ages and never quite got around to it.
Top advice as per usual
akaAlso is offline   Reply With Quote
Old 03-25-2011, 11:39 AM   #9
banned
 
fishpielemonsole's Avatar
 
Join Date: Aug 2006
Location: Brighton & Hove
Posts: 205
Re: How to prevent your pc from 90% of all malware in 30 seconds

.

Last edited by fishpielemonsole; 03-25-2011 at 11:45 AM. Reason: fixed
fishpielemonsole is offline   Reply With Quote
Old 03-26-2011, 04:38 PM   #10
adept
 
freedom18's Avatar
 
Join Date: Apr 2006
Location: Tokyo
Posts: 1,141
Re: How to prevent your pc from 90% of all malware in 30 seconds

waaay too easy NOT to do. Makes a lot of sense, admin has access to everything whereas standard user will have more restrictions for system overtaking o.ov
freedom18 is offline   Reply With Quote
Old 03-26-2011, 04:45 PM   #11
Pooh-Bah
 
funkyworms's Avatar
 
Join Date: Jun 2004
Location: computer helpin'
Posts: 4,249
Re: How to prevent your pc from 90% of all malware in 30 seconds

Completely agree with wellju on this. The only reason I didn't mention limited user accounts in my videos is because it's virtually impossible to run as a limited user in XP.
funkyworms is offline   Reply With Quote
Old 03-27-2011, 10:05 AM   #12
old hand
 
lau808's Avatar
 
Join Date: Jul 2010
Posts: 1,220
Re: How to prevent your pc from 90% of all malware in 30 seconds

ive dont this but now i have a problem... i can run hem from admin but not my non admin acct.... says path to "c/program filesx86/rvg software/hem/config/statranges.xml" is blocked. tried running as admin from my acct, didnt work... any ideas? thx
lau808 is offline   Reply With Quote
Old 03-27-2011, 07:59 PM   #13
centurion
 
akaAlso's Avatar
 
Join Date: Mar 2009
Location: UK
Posts: 189
Re: How to prevent your pc from 90% of all malware in 30 seconds

Quote:
Originally Posted by lau808 View Post
ive dont this but now i have a problem... i can run hem from admin but not my non admin acct.... says path to "c/program filesx86/rvg software/hem/config/statranges.xml" is blocked. tried running as admin from my acct, didnt work... any ideas? thx

Have you followed this guidance?

http://forums.holdemmanager.com/mana...m-manager.html

I have to enter my admin password every time I run HM now, but thats no great issue to me.

If this does't work - cross post here
http://forumserver.twoplustwo.com/16...-tracker-1535/
and Fozzy will likely respond more quickly than here. It wouldn't hurt to link back to this thread as well.
akaAlso is offline   Reply With Quote
Old 03-28-2011, 04:34 AM   #14
old hand
 
lau808's Avatar
 
Join Date: Jul 2010
Posts: 1,220
Re: How to prevent your pc from 90% of all malware in 30 seconds

will try this 2morrow, thx
lau808 is offline   Reply With Quote
Old 03-28-2011, 09:23 AM   #15
old hand
 
Join Date: Oct 2004
Posts: 1,301
Re: How to prevent your pc from 90% of all malware in 30 seconds

Pokertracker doesn't work without admin rights
Stormwolf is offline   Reply With Quote

Reply
      

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -4. The time now is 01:05 PM.


Powered by vBulletin®
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0 ©2011, Crawlability, Inc.
Copyright © 2008-2010, Two Plus Two Interactive