Thursday, October 1, 2009

Secret to Fighting Cybercrime

I was shocked to learn how fast the threat of cybercrime is growing. I couldn't believe a report from the Department of Treasury that the profits of Cybercrime are greater than the profits of the sale of illegal drugs. When President Obama informed us that cybercriminals have stolen $8 billion dollars from Americans in the past two years and the cost of repairing computers has risen to $11 billion a year. Cybercrime is not about vandalism. It is about our economy.

Beware of free or store bought security software installed on your computer that claims to protect you from cybercriminals. Your chance of becoming a victim is 7 out of 10. Companies like McAfee, Symantec (Norton), and Trend Micro, Inc. spend a lot of money advertising how good their products are, but Computer World Security writes that they "confirmed vulnerabilities in their security software that could let hackers hijack systems.

The security software and suites that these companies sell do not prevent cybercrime. They mainly focus on worms, Trojans horses, and spyware that allow hackers to infect your computer. It takes many hours for the security companies to capture and analyze the problem, write a new solution, and get it to you. Therefore, hackers are always one step ahead of the security companies. This explains why 172,000 computers are hacked each day.

Security companies do not focus on vulnerabilities, e.g. weak passwords, software bugs, a computer virus or other malware that allow hackers to install malware on your computer, take your sensitive data, convince you to open an email message with attached malware, or copy a hardened, encrypted program onto a thumb drive and crack it at home. Not focusing on these vulnerabilities can bring the 'blue screen of death ' and make your operating system unusable.

When your computer is hijacked, it becomes a zombie computer. The cybercriminal now has full control of all your personal information and can use it for criminal activities. You don't know that this has happened. Your computer slows down and you go to the tech to get it fixed. It costs a lot of money and happens a few times a year. You wish there was a better way to manage your computer, but nobody tells you how.

I know exactly how you feel as I once had 7,500 malware on my computer and it was slowing down. I then enrolled in a managed internet security program where a team of techs remotely cleaned it up. They then installed professional grade software and a bi-directional firewall on my computer, scanned it daily and I was notified immediately if malicious malware had been placed on my computer. I then deleted it. I just love my Managed Internet Security Service.

Check this list to help decide to consider a new concept in Computer Protection, Managed Internet Security, and to learn about the latest technologies that can protect you, your family and your business from cybercrime and cybercriminals.

1. When you first sign up, you will have a tech team who will spend hours to remotely remove viruses, spyware, Trojans, and malicious codes from your computer that the security software you have on it did not remove.
2. You will get professional grade software that bypasses the Windows Operating System, directly scans locations of the hard drive, and removes the infections that are found.
3. You will have a clean and fast computer.
4. Notification pop-ups and warnings will be at a minimum.
5. You are immediately warned of any major security outbreaks.
6. Your emails and attachments will be protected from malware.
7. You can have all of the above for just a small monthly fee.

I am Miriam Bobroff, President and CEO of Bubby's Business, Inc. an international marketing and distribution company that offers information and education about Cybercrime and Identity Theft. A Managed Internet Security Service iis offered that prevents these crimes but should the inevitable happen, trained professionals help solve the problem.Everyone can now fight the war on Cybercrime and be safe and secure from Cybercriminals.

Reinventing SIEM

Security Information and Event Management (SIEM) perimeter scope has widened as the business and strategic IT requirement goes beyond just security and compliance. Today SIEM are used for meeting many IT and business requirements because of the kind of data it collects, monitors, correlates and reporting from the heterogeneous set of devices (firewall, routers, switches, UTMs, Vulnerability scanners, VPNs, Content filters, IP enabled devices etc), applications (MS Exchange , Anti virus, etc), databases (Oracle, SQL) and systems (Windows, Linux, UNIX, Mac etc).

SIEM is effectively used by organizations in the following areas.

  • Log Mangement
  • Detecting and responding to security events
  • Protecting confidential and private data (fraud detection)
  • Vulnerability Analytics
  • Security and forensic analysis
  • Automating security operations
  • Monitoring internal & external threats
  • Tracking user activity - end user behavior
  • Monitoring IT staff/administrator behavior
  • Meeting corporate governance initiatives
  • Complying with government and industry regulations
  • Risk Analysis
  • Network operations, Performance monitors & optimization
  • Asset Management, Capacity or resource planning
  • Configuration Change Audit
  • Optimizing traffic , bandwidth monitoring
  • Network behavior anomaly (NBA) detection
  • Troubleshooting IT problems
  • Service level/performance management
  • Business Analysis
  • Centralized Management Analytics
  • Compliance Automation
  • Audit Gap Analysis

Today's next generation SIEM delivers services to the NOC, SOC, Risk and the Audit teams. Its rich reporting capability lets enterprises to have an upper hand in the market and full visibility at the macro and micro levels. Business managers want to see how security controls map to individual lines of business which help in strategic business and IT decisions. Enterprises know what's happening and what is expected to happen in their strategic IT environment which give them the confidence and winning edge over the competitors.

Wiith the emergence of cloud computing which reduces the cost of IT investment and maximizes the ROI, organizations are opting for Software as a Service (SaaS) for SIEM solutions. Most organizations already have invested in many point solutions to meet their IT requirements. But they have gaps and they need to fill those gaps. The SaaS delivery model of SIEM solution fills the gaps. Organizations only need to pay for what they want and that too as a subscription model. They also have all the advantage of cloud computing too. The complexities & expenses involved in managing the infrastructure and resources for point solutions is diluted.

In UAE, Zener Electrical & Electronics - IT Division delivers SIEM through cloud computing (SaaS Model). Organizations can opt for 'Zener Cloud SIEM' and the RIO is justified (lower TCO) whether it's for filling the gaps to meet their requirements or a fully fledged SIEM solution.

Clean Your Secret Data

It is well known to most of people that the browsers, Internet Explorer and Fire Fox, record the track of surfing the Internet. But it is not well known to people that Windows keep the track of your operations. These records are stored in your disk, such as Windows document history, Windows temporary folder, Windows run history etc. On the other hand, the instant message tools also keep your chat track. For example, Yahoo recent profiles, Yahoo cache files and Yahoo pager statistics etc. You are not aware of these things when you leave computer. It most likely leaks your secret, if you share the account and the computer with your friends and colleagues.

So I always use the options of Internet Explorer and Fire Fox to clean my Internet track. But it always can not do it thoroughly. I remove the files in Windows temporary folder every week. But it always can only remove little files. It is a boring thing to delete so many files in different places manually. Fortunately, I find that a tool can do this for me absolutely and thoroughly. The only thing I can do is to click simple button. I just need to check the report that tells me how many tracks in my disk vanish.

Now I keep a habit to clean all tracks in disk every week in my home. In office, I clean tracks every day, including Windows general records, Internet history records, chat history records and common software records. I am satisfied with keeping my secret from others.

Information is Like Water

Is information really like water?

Not long ago, I heard someone say that information is like water; I agree. It always looks for a way to flow, and it's hard to control, it leaks, rains, evaporates, etc. This is an extremely great analogy. In fact, in almost every single challenge that we face with our information, the water analogy holds tight.

Consider if you will, that there have been many people who have sued other folks over water rights. One neighbor might steal water, or someone puts a well on their property in take water from their neighbor's underground resources and reservoir. What's the difference between that and identity theft? Not much.

Ask anyone in the CIA and they will tell you that "loose lips sink ships," that information leaks out, and that's why we have a spy agency in the first place to capture some of the information it leaks, or even help it leak. What is top-secret today, may be on the front pages of the magazines within a month, do you see the point?

Information can also evaporate can't it, after all, the devices we use to store information often fail. And we lose information this way. Perhaps, our hard drive might crash, we might lose a disk of information, or be unable to read it later.

Information is extremely hard to control, information is also valuable like water, and sometimes it seems to have a mind of its own. Information also gets manipulated, transposed, and turned into other things. Just like water can take on additives, and become a fruit drink, a can of beer, or a soda pop in a two-liter bottle. Please consider all this.

Lance Winslow is a retired Founder of a Nationwide Franchise Chain, and now runs the Online Think Tank. Lance Winslow believes if you have diabetes, there are things you need to know; diabetes types

Note: All of Lance Winslow's articles are written by him, not by Automated Software, any Computer Program, or Artificially Intelligent Software. None of his articles are outsourced, PLR Content or written by ghost writers. Lance Winslow believes those who use these strategies lack integrity and mislead the reader. Indeed, those who use such cheating tools, crutches, and tricks of the trade may even be breaking the law by misleading the consumer and misrepresenting themselves in online marketing, which he finds completely unacceptable.

Rundll32-exe Features

What is Rundll32.exe?

Now, let's learn more information about the file Rundll32.exe. The role of Rundll32.exe is to execute the internal function of DLL files, so that in the processes there is only Rundll32.exe, instead of the DLL backdoor, which allows the DLL files to be hidden. If you find that there are several Rundll32.exe in the system, please don not worry, as this just shows how many DLL files have been initiated. Of course, as for what the DLL files executed by Rundll32.exe are, we can find them where the system automatically loads.

Is Rundll32.exe infected?

If your computer has the disguised Rundll32.exe file, the system may have contained several files produced by viruses. Generally, these files survive by attaching to other processes, and they download or upload information in the background of the system, doing relatively great harm to the system. The following is the sum-up of some features of infected Rundll32, which may be good alerts to computer users while using their computers.

Feature One:
As long as opening a website, the computer becomes extremely slow; in the processes of the Task Manager, Rundll32.exe occupies CPU 99%. Meanwhile, there are other processes with strange names which will appear again after being closed. And, the antivirus/anti-spyware software does not seem to work to these processes.

Feature Two:
Download a free Process Viewer tool to see the file path of the process Rundll32.exe. If the file path is not C:windowssystem32, it is usually the case that the virus disguises itself and stores in another file directory. Then, there are always many Rundll32.exe appearing in the system process, while it usually exists as hidden file.

Feature Three:
Check the Registry. If the following keys are added, then your system has been infected.
[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
"TaskMan"="C:WINNTFontsrundll32.exe"
"Explorer"="C:WINNTFontsexplorer.exe"
"messnger"="C:WINNTsystem32Dvldr32.exe"

Feature Four:
Access the computer system; click Run on Start menu; type cmd, and type netstat -an in the opened command window. If a large number of TCP connections to the external port 6667, or TCP port 5800 and 5900 are in monitoring, then your system may have been infected, as follows:
C:>netstat.exe -n
Active Connections
Proto Local Address Foreign Address State
TCP x.x.x.x:1043 149.156.91.2:6667 CLOSE_WAIT
TCP x.x.x.x:1045 198.65.147.245:6667 CLOSE_WAIT
...
TCP x.x.x.x:4811 198.65.147.245:6667 CLOSE_WAIT
TCP x.x.x.x:4887 149.156.91.2:6667 CLOSE_WAIT

Feature Five:
Often disguise itself with different process names, such as rundll132.exe, rundl132.exe, etc. All these need to be carefully viewed with a Process Viewer tool.

Solutions to fix Rundll32.exe

1. Rundll32.exe is a Windows executable file which can be disabled by many viruses. However, there is a virus named "Happy Times" which has the same name and size as Rundll32.exe and it keeps reproducing itself under the root directory of each folder you open. If a large number of this file appears in your computer, then your computer is undoubtedly infected, and usually most antivirus software can not solve this problem. The general solution is, manually bulk deleting all the files with the name Rundll32.exe, and then retrieve from the Windows source program the useful file Rundll32.exe. The way to retrieve it is, taking Windows XP as an example, typing "cmd" in the Run box and pressing Enter; typing:
expand CD-ROM i386rundll32.ex_%Systemroot%rundll32.exe
CD-ROM is the location of the operating system source code, not necessarily the drive.

2. The original file of Rundll32.exe has backup in C:windowssystem32dllcache, where you can make a copy.

3. Download the same file from website and cover it to the directory C:windowssystem32.

4. If you have two computers at home, it is also available by copying and recovering the file from one computer to another.

Please notice that only Rundll32.exe in the same version of system can be recovered, or the system will show an error. Before recovering the process manager should be used first to end the process Rundll32.exe.