• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
TheWayoftheWeb

TheWayoftheWeb

Content and Digital Marketing Specialists

  • Blog
  • The Cipher
  • About Us
    • Useful Resources For Businesses In Peterborough, UK
  • Contact Us
  • Show Search
Hide Search

malware

Backup. Restore. Protect

April 4, 2012 By Dan Thornton

It may have been April Fools Day on Sunday, but it was actually Saturday March 31 that held all the ironic humour for me this year. That’s because it was ‘World BackUp Day’ (unfortunately the site appears to be down right now!), designed to promote safe and secure second copies of all of your data, and I was spending it reinstalling my operating system due to a malware infection.

 

Malware can get you, even when you’re careful:

I tend to be reasonably careful, particularly on the laptop I primarily use for my business. I have antivirus software installed (McAfee for the record), I run some browser add-ons for extra safety and I try not to visit any websites which I know or suspect could be dangerous.

Security

I also don’t click on links in emails offering Nigerian lottery winnings or direct messages on Twitter which suggest there’s a ‘really bad picture of me’ with a link obscured with a shortened link.

And yet on Friday afternoon I was hit by a spoof version of a legitimate program which not only then covered my desktop in pop-up windows, but also proved a complete pain to remove as it edited the computer’s registry and made sure it reappeared every time I thought I’d successfully eradicated it.

The one good thing is that there are now plenty of websites giving detailed instructions on curing more problems as soon as they appear – unfortunately it took a couple of attempts to find one to deal with the current version of the malware, but it’s worth having a look around to find trusted and reliable sites before you need to Google them in a hurry.

And incidentally, a new piece of research just published shows how easy it is to fall foul of a widespread problem – on average 2 of the top 25,000 websites in the world (ranked via Alexa) serve malware to visitors each day on average. Or problems can occur installing apps – even from ‘official’ sources such as the Chrome Web Store. This doesn’t mean you need to be paranoid, but does mean doing some research and thinking before clicking on links, installing apps, and putting some effort into protecting yourself and your data, including if the worst happens.

 

The importance of backups:

The good news is that I finally managed to remove it successfully, using a couple of anti-spyware programs I hadn’t tried before. Having finally killed the process and restarted my machine to ensure it wouldn’t reappear, I was left with one further problem – the malware had also been created to remove all desktop icons, links and to stop anyone searching from programs which would interfere with it.

So a Restore/Re-Install was needed. But trying the automatic Windows Restore didn’t work – it was only the proprietary manufacturer backup which worked, sending my laptop back in time to the first day of 2011.

I always ensure I have two copies of all data relating to work – one copy is stored on a removable hard drive which is kept in a different part of the house to the laptop when not in use, and the other is stored ‘in the cloud’ on an online storage system which automatically saves any changes made to any files.

Pictures are always backed up on the hard drive, and also uploaded to Flickr on a weekly basis, as are most videos. But I did lose all my (legally) downloaded music as unfortunately I’d cleared all the albums from my hard drive backup whilst I sorted through them and put them into some sort of order.

Aaaaaaaaaargh.

And even worse, I have a nagging feeling that some images and videos of my son appear to be missing, and it was pre-upload/backup, which means they’re gone forever.

Going back so far also means I’ve spent about a week receiving updates every time I fire up my laptop, which then install on Shutdown and leave me stood around for ages when everyone else is going home.

 

Re-install, Rebuild, Update,Protect:

So what have I done since? Well, seeing as I’m fully paid up for McAfee for a while longer I’ve made sure it’s completely up-to-date and double-checked the set-up. I’ve also started testing one of the new programs which seems to have killed the malware on this occasion, and one other anti-virus solution which is available for free download. No single program is lightly to always cover everything 100%, but having 2 or 3 available means I should be able to cover most options.

I primarily use Firefox as a browser, so I’ve added ‘AdBlocker’ and ‘No Script’ to cut down on the risks. There’s a moral issue with using AdBlocker, in that it deprives ad-funded sites of revenue by stopping any advertising from appearing, but you can quickly and easily whitelist sites you trust, as you can with No Script, which stops a lot of sites working initially as it blocks all Javascript. That’s great for preventing malicious attacks, but it’s not a solution that will be 100% effective – for many sites to work, you have to start allowing various processes to run, and as mentioned earlier, even trusted sites can sometimes end up unknowingly spreading malicious software.

But on balance I think I’ve done a reasonable amount, as well as double and triple-checking all backups are running correctly both for the laptop OS and Software, and for the Files and Data. I’ve reinstalled the programs I use on a regular basis, and set them all back up to work properly, and I’m working at full speed again.  You can never be 100% safe, but with the right processes in place the occasional problem isn’t as much of a hassle, and a clean install can be quite a refreshing spring clean of all the old junk you’ve got on your PC which isn’t actually used.

It’s also reminded me to audit my accounts and passwords on my sites, remove unused WordPress plugins, and update everything on social networks etc.

Antivirus security is more essential than ever

October 13, 2010 By Dan Thornton

This post is supported by Bullguard, who supply free internet security and antivirus software.

The rise of social networks, cloud computing and mobile applications means that having a decent level of security for your business or home has never been more important – and when was the last time you checked your antivirus software was up-to-date or ran a full system scan? There’s not a lot of excuse with the amount of free internet security options around (Either as trials or full products).

It’s something many people writing about the digital world forget to mention – or even neglect to do themselves, but if you consider the rise of digital networking (e.g. 500 million people connected on Facebook), then consider how the viral effect applies to malware and malevolent programmes as much as the latest marketing campaign.

It may seem blindingly obvious considering the fact they’re called viruses, but considering I’ve seen infections transferred via USB sticks swapped between digital marketing experts, for example, it’s always good to have a timely reminder.

A report from Microsoft today revealed that the U.S, for example, leads the figures for hijacked home computers, with over 2.2. million botnets currently out there, which are then controlled by whoever has taken them over – often invisibly to the owner of the computer unless they realise that’s the reason their PC is going a little slower than normal.

And social media could even be making things more dangerous. When search was the primary way to discover websites, there was a clear hierarchy of results, which meant most common terms would have some level of filtering – indeed search engines do employ warnings for know malware sites, although this obviously doesn’t cover many of them.

But when a social networking friend recommends a link, often obscured by a url shortener, how many of us honestly check before clicking on it, or even repeating it to our own network?

And there’s also the illusion that applications, particularly for mobiles, mean that everything is safe – it assumes that every application store and every 3rd party site has examined every single line of code for every application.

If that isn’t enough, there appears to be a rise in hackers actively targeting routers, rather than PCs, meaning they’re reaching anything connecting via that hub – your mobile phone, all your computers, and anything else running software which could be compromised.

Earlier this year, my websites were all disrupted by malware which infected website hosts. The disruption was bad enough, but the thought of anyone getting an infected computer due to one of my sites has been enough for me to educate myself a lot more to minimise the chance of it happening in the future.

Many of us are issued computers by our employers, and quite often we’ll assume that the often over-worked IT department have got everything covered – but a lot of the time they’re maintaining rather than having the time to pro-actively go after the latest major threats.

But there’s no need to panic:

I’m not suggesting you should run away from the internet. It’s actually surprisingly simple to start taking control and responsibility for your own data and safety. You can start by making sure you have decent antivirus software up and running, and updated. Make sure it’s updated regularly and you’re running scans either manually or automatically on a regular basis. And most vendors allow you to try their software for free for a limited time, so there’s really no excuse for not trying it.

Change your router username and password from the default – if you’re still logging in with ‘admin’ and ‘password’ you’re liable for anyone using your wifi to access any website, as well as vulnerable to malicious software.

Store sensitive passwords away from the computers and change them regularly – especially any banking passwords. I use a variety of ways to secure my passwords for most things, but I never store any financial passwords on any computer, or write them and store them anywhere near any of the computers I use. The social element of hacking is best summed up by someone writing their password on a Post-It note stuck to their monitor, and it also applies to someone having an illicit wander through the files on your computer.

And lastly, don’t be afraid to read up, ask stupid questions, and find out about securing your computers. I’m definitely not an expert, and there are plenty of great resources available online to find out what you should do to prevent problems – and to help after they’ve happened. It’s all about taking responsibility for all of the equipment in your care, and all of the things which are precious to you, and at the end of the day, it should become as much a part of your routine as locking the door when you leave the house, and not walking around with a bag of cash sticking out of your pockets… You’ve never be completely safe, but by taking the essential steps you’ll have made your computer and mobile less attractive then the one next to it!

Stocktwits gets funding, Bit.ly get’s safer, Cli.gs gets bought

December 2, 2009 By Dan Thornton

The Twitter ecosystem is busy as always, so rather than try to write 20 posts to cover everything purely for SEO benefit, I thought I’d round up three things which stood out:

Stocktwits has gained $3 million in another round of financing for the social and microblogging network for the stock market. It’s interesting that the service has spun out of Twitter, building its own platform and Adobe Air desktop application which came into life in September. In addition Stocktwit.tv seems to be taking off.

Rather than building your own social network from scratch, perhaps a more realistic plan is to build community on the main Twitter site, before spinning off as Stocktwits have done – a technique that would work on any social network…

URL shortener Bit.ly (as set as the default shortener on Twitter, and heavily used by yours truly) has announced a partnership with security firms including Websense, Sophos and VeriSign to help address the problems of spam and malware-spreading shortened links which are otherwise difficult to spot (Bit.ly already offers a plugin to expand links before you click on them). That adds onto Twitter’s malware detection, and Bit.ly’s spam filtering.

For reference, Bit.ly shortens 35-40 million links a day, and apparently spam links make up less than 0.5% of that number…

And finally, fellow url shortener Cli.gs has been bought by social bookmarking site Mr Wong. That’s good news for users, and also for the White House, which uses Cli.gs. The reason for the sale is given as the time and effort needed on behalf of the founder – something which makes sense in the context of Bit.ly’s 40 million links a day!

Twitter starts filtering links to malware

August 3, 2009 By Dan Thornton

As more and more people use Twitter, so the number of spam/porn messages has increased – partly due to users succumbing to the numbers game and blindly following and re-tweeting anything they see.

So it’s a good move for Twitter to start blocking malware, as spotted by the F-Secure blog earlier today – making the service a little safer for the less-savvy.

It seems that the filtering itself comes via Bit.ly, checking against spam filters SURBL and Google Safe Browsing, and then adding a warning, as shown in the screen below from F-Secure (Obviously I don’t know any dodgy sites!):

Twitter being used to distribute Malware and DoS attacks

June 22, 2009 By Dan Thornton

Sadly it’s no surprise that the ‘Trending Topics’ ranking on Twitter is being used by both spammers and distributors of Malware. Or for instigating DoS attacks:

Malware:

Malware is the catch-all term for software referred to in the mainstream press as ‘virusus’ – technically a virus is a type of Malware.

Luckily the methods being used aren’t particularly sophisticated yet – the scammers are creating fake Twitter accounts to post with #hashtags for trending topics and links to sites which contain the malicious software or scams.

Mashable reports that the most common links at the moment are “Twitterbest (dot) mp” and “Zasaden (dot) mp”. An added sign is that in this case, the url also tends to contain a pornographic term.

The alert from Mashable came via Panda Security who explain that the fake accounts link to a page that prompts you to ‘upgrade your Flash player’ or similar. If you agree to download software, it installs itself, and you’ll get error messages warning you of a virus and that you need to pay $89 for fake software called “Fast Anti-Virus 2009”.

The best tip is to avoid links that look suspicious, or are posted by people you don’t know. And if you do think you need to download a software update, go to the site of the company concerned, rather than installing via a random 3rd party site.

DoS:

The New York Times is reporting that Twitter is being used to instigate Denial of Service attacks against key government officials in Iran;

‘But a still developing and less benign use of Twitter in Iran has been its application in denial-of-service attacks against key government officials, including those affiliated with President Mahmoud Ahmedinejad.

… Tweets have begun circulating that allow users to target a Web site that will eventually be overcome by simply clicking on the embedded URL in the message. As soon as a user hits the page, as many as 24 frames open up simultaneously and refresh continuously, causing a DoS attack against the 24 separate Web sites.’

  • Page 1
  • Page 2
  • Go to Next Page »

Primary Sidebar

Join us…

  • Facebook
  • Instagram
  • LinkedIn
  • RSS
  • Twitter

We only exist to deliver results for your business. So you get fresh Content, expert SEO, engaging Social Media, or a new Website which is right for you – and your customers.

We help you build your brand, reach more customers and increase your revenue

Search

Categories

Creative Commons License
This work by TheWayoftheWeb is provided under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.

Start growing your business today Contact Us

TheWayoftheWeb

Copyright © 2026· TheWayoftheWeb Ltd. Company Number 08038527. ICO registration: ZB397650