Sponsored by: CodeLock Web Asset Management for Small Businesses

Mirror of Joe Stewart dot org Conficker Eye Chart

 

How to interpret:

If you see this above:It probably means this:
All images displayed= Normal/Not Infected by Conficker (or using proxy)
Security/AV logos not displayed= Possibly Infected by Conficker (C variant or greater)
Some security/AV logos not displayed= Possibly Infected by Conficker A/B variant
No images displayed= Image loading turned off in browser?
Any other combination= Poor Internet connection?

 

Explanation:

Conficker (aka Downadup, Kido) is known to block access to over 100 anti-virus and security websites.

If you are blocked from loading the remote images in the first row of the top table above (AV/security sites) but not blocked from loading the remote images in the second row (well-known search engines) then your Windows PC may be infected by Conficker (or some other malicious software).

If you can see all six images in both rows of the top table, you are either not infected by Conficker, or you may be using a proxy server, in which case you will not be able to use this test to make an accurate determination, since Conficker will be unable to block you from viewing the AV/security sites.

2 minute guide to securing your computer


Sponsored by: CodeLock Web Asset Management for Small Businesses

Secure411.org 2 minute Guide

2 Minute Guide to Securing Your Computer

(Computer already deathly ill? Click here to skip to Triage)
  1. Install recommended free protection software: MalwareBytes, ClamWin, WinPatrol.
  2. Uninstall expired, over-priced software that is slowing things down: (Start, Control Panel, Add/Remove)
  3. If you want the extra layer of Active protection, we recommend VIPRE. Here's why.

    Take a deep breath.

  4. Switch to Firefox and Thunderbird, encrypt your chats, password transmissions, confidential emails, and offsite backups.
  5. Turn off auto-connect on laptops, fix your bad password habits, and check your home router for default names & passwords, remote admin loophole.
  6. Get a really rugged, high quality USB memory stick and put File Scavenger on it. Here's why.

THAT'S IT - THANKS FOR TAKING TWO MINUTES TO LEARN TODAY

We'll send you our free CD with all the above free software we recommend and the easy install menu pictured above, if you decide to buy the VIPRE program and install it right now - helping to clean up and protect your little corner of the Internet.

I trust it, because I know the guys who wrote it and maintain it. If you are going to spend money on malware protection or anti-virus, this is the one I recommend. If not, please do install the free programs and don't visit shady websites or open any email attachments.


Successful enough to justify having your own
personal super-geek watching out for you full-time?

We'll take care of all the details described above for you, keep you up-to-date and learn your needs and preferences. Call 888-894-3896 and press 1.

If you don't reach a real person immediately, a real person will call you back. Her name is Janice :). (Unbelievable, I know... but that's why we only serve the top tiny fraction of discerning people like yourself.)

Quality, not quantity is our motto: Join the select few enjoying our limited edition gold club level service. You can also reach us by sending email to help (at) fullscalecommerce.com


Triage for Sick Computers

Already infected with a computer virus?

  • Cut the criminal's access to your computer off immediately by physically removing the network wire or shutting off wireless if it is a laptop

  • Do NOT make any PURCHASES of ANYTHING from the infected computer! Your credit card details could be stolen by the virus makers who infected your computer.

  • Use a second computer that isn't infected to work on the sick one.

Ideally, use your clean computer to download, burn and then boot your sick one from the Trinity Rescue Kit cd.

If you prefer something easy / fast to try first: Get the free MalwareBytes and run it, and also get the free 15 day trial of VIPRE and run it.


Prepare NOW for easy recovery of deleted files or failed hard drives later

TIP:
Amazon Prime
is the bomb

If you have deleted an important file, or your hard drive is failing, the first thing you need is data recovery software on a USB memory stick aka thumb drive. Create that USB stick with File Scavenger on it NOW - and you can be a data recovery hero for yourself or others when the need arises.

For those who don't prepare ahead of time: Stop using the computer with the data loss immediately. The space where deleted files are still intact - can be overwritten by any drive activity. For example, downloading or installing data recovery software may make it impossible for you to ever get your lost data back.

Unplug the problem computer from the Internet and use a different computer to create the USB stick with data recovery software on it. Run the software "from the USB stick" - do not install to the hard drive of the sick computer.

File Scavenger will be free to prove what files of yours can be recovered. It will do a scan for free and show you all the file names you could recover. If you see that you will get what you need, then use a separate computer to make the purchase and put the license file onto the USB stick. Use the USB stick as the destination to restore your files to. This again will prevent unrecovered files from being destroyed by the act of writing recovered files over them.

You can also get back deleted photos from camera memory cards using File Scavenger.

Our Gold level customers can ship laptops, hard drives and memory cards to us for data recovery and analysis. Call 888-894-3896 ext 1 to apply - limited slots available as we only serve 1000 special business people worldwide and very rarely have a customer leave us.


Stop Criminals from Getting Your Passwords

DON'TS: You are easy pickin' for criminals if you use:

  • Same password for email and shopping logins

  • Pattern passwords like amazon1951, chase1951, myspace1951

  • Password is made only of words found in the dictionary

Is your password on a list of "easy first tries" for hackers?

Single concept passwords, color names, kids or pet names, etc see list here and here

Sarah Palin-ed: Are the answers needed to reset your password public knowledge, guessable, or something you pass to strangers in casual conversation? If so, you can use faked answers to these questions that only you would know. For example, make up a different name for your "favorite childhood pet" instead of using the real one.

DO'S: Fix your current password mess

  1. Go change your email password now

  2. Don't use your email password for anything else

  3. In creating your password, combine more than one un-related concept

  4. Combine numbers and letters - and where allowed, combine upper and lowercase and punctuation

  5. Where allowed, make your passwords 12 or more characters

  6. Your cheat sheet of password hints need not spell them out directly and should not be typed or stored on a computer

Read on to find out the ways criminals can obtain even strong passwords - if they are transmitted insecurely.


Is your password visible to criminals?

Dirty POP & SMTP Email Secrets

Only a tiny fraction of people have a POP3 email server with Secure Socket Layers (SSL.) Most of you are sending your email password in plain text every time you check for new mail. Potentially anyone on a network you plug into to get on the internet - wired or wireless - can "sniff" or snoop the plain text packets you send. They can pick out interesting bits of what you receive, such as passwords and financial info.

The same is true when sending mail. Your ISP may provide "SMTP Auth" which is a good policy for them - but if it doesn't also include SSL, your authentication password is visible to criminals. So are the texts of your emails and any attachments.

HOW TO: Test if your email passwords are transmitted securely

POP3 (Email checking & receiving) Port Numbers

Port 995 is the default port for secure POP3 connections. Port 110 is the non-secure port.

Thunderbird settings
You can check the port in Thunderbird from pull down menu Tools, Account Settings, Server Settings.

Outlook Express settings
You can check the port in Outlook Express from pull town menu Tools, Accounts. Now click on the name of the account you want to check. Click Properties button on the right, then click the Advanced tab on the far right.

Do not change the port numbers you find - the only way a secure connection on port 995 will work is if your ISP supports it. So changing that setting when your ISP does not support it will just result in your email not working at all.

SMTP (Email Sending) Port Numbers
Port 465 is the default port for secure SMTP connections. Port 25 and 587 are the common non-secure ports.

Thunderbird
To check the SMTP port for outgoing mail, pull down menu Tools, Account Settings. Now scroll the menu on the left of that window all the way to the bottom and click on Outgoing SMTP Server.

Webmail Passwords
To check if your webmail passwords are transmitted securely or insecurely, look for the S after http in the web address. For example, https://www.google.com/. If there's no S, or if other indicators on your browser show that a secure SSL connection is not present when you go to log into your webmail account, your password is being transmitted in plain text and can be observed by criminals who have access to the network you are plugged into - wired or wireless.

Do you own a website?
The most common way your website files get put in place and modified is using "FTP." Most FTP software still transmits the password the protects your website files in plain text. If a criminal gets hold of your website maintenance password, he can destroy your website, and put anything he wants in place of it. This often means illegal sites that pretend to be bank or government websites defrauding people of financial information, or advertising illegal or embarrasing products.

If you have hired someone else to maintain your website, it is still vitally important that you check that s/he is using SFTP (Secure FTP) not plain old FTP to access your website. If you are able to switch from FTP to SFTP, the old password must be changed to insure that no one else has it.

The default port for non-secure FTP is 21; the default port for secure SFTP is 22.

WHAT TO DO IF: you find insecure password transmissions or are not sure

You can contact tech support at your ISP and ask for the "secure POP3" and "secure SMTP" settings, if they offer them. Be prepared that they may give you wrong information and in some cases will spend hours on the phone with you doing nothing other than making you type again all the same insecure settings you already have.

If you already own your own domain name, you can switch the hosting of email for it to a host that does offer true secure POP3 and secure SMTP.

Another option is to switch to a webmail provider that secures password transmission. But be aware that the vast majority drop the security level as soon as you are logged in. Therefore the text of all emails you receive and send is visible to criminals who have access to your local network - wired or wireless.

We test & configure secure POP3 / SMTP / SFTP / Webmail for our Gold level customers. Call 888-894-3896 ext 1 to apply - limited slots available as we only serve 1000 special business people worldwide and very rarely have a customer leave us.


Turn Off Automatic Wireless Connections

Why?
Criminals can set up a "wifi hotspot" with a name you have set your laptop to automatically connect to. For example, "linksys" or perhaps the SSIDs of common wireless hotspot brand names or hotels.

When you enter their service area, without warning your laptop will connect to the criminal's network and potentially give him access to your files and private information. Potentially he could install code that would activate later to give him a backdoor into your computer, a malware infection, or keylogging of your user names and passwords.

How?
The following step-by-step is for Vista. The steps for other operating systems will be similar.

Click the Start button, then Control Panel,Manage Wireless Networks.

After you've done some travelling, your wireless network list may look something like this, including many hotel, hotspot and perhaps your office and home network SSIDs.

If any have "Automatically Connect" next to them, you need to turn that off. Right click the wireless network name and choose "Properties" with a left click.

Here in the Properties you will see a checkbox for Connect Automatically. UNCHECK the box and click OK.

Repeat for each network that shows "Automatically Connect."

In the future when you connect to a new network, be sure to use Advanced settings to set it to Manually Connect instead of Automatically Connect.  

 


 

Advanced info that won't apply to everyone
Some laptop software also allows you to prevent connections between your laptop and any access point other than ones matching the MAC address you specify, which could be your home or office, etc. This could still be broken by a criminal but likely only if you personally are being targeted and surveilled by the criminal.

Here's an example of the Intel software settings for a Lenovo Idea Pad computer if "Enable Intel Connection Settings" is checked on the "Properties" window, and then the "Configure" button is clicked:


Securing Your Router

TIP:
Amazon Prime
is the bomb

A "router" for your home or small business network can keep a lot of criminal activity out plus makes it easy for you to share Internet access with multiple computers.

The danger is that most routers are left "open to the world" - to be accidentally attached to by your neighbor's laptop, or intentionally hacked by war drivers. In fact if you leave remote administration settings turned on in your router - and the default password - any criminal in the world can enter your network and wreak havoc.

Here's how to check your home router for default names & passwords, and disable remote admin.


Active Protection

The big name anti-virus program that probably came pre-installed on your computer provided "active" protection. It is "always on" and always watching to try to stop malware and viruses - until it expires. Also you should know that no anti-virus brand stops all viruses. Absolutely none of them will stop every malware, spyware, trojan or virus. That is why you still need to careful about the software you use and where you go on the internet. Plus most people use multiple brands, free and paid, for protection.

The downside to most active protection is twofold: it dramatically slows down your computer by sucking up system resources, and it may block you from your own network or the Internet. Tongue in cheek, we privately call some of these big name programs "Anti-Internet" instead of Anti-Virus.

We like VIPRE for a couple of important reasons:

  • Primary design goal is NOT to slow your computer down

  • Fair pricing that is far lower and stays low compared to big name products

  • Effective against existing infections and at preventing new ones, in our experience

Also we know and trust the people behind the company and find them ethical and responsive.

 

 

 

 

 

 

 

 

 

 

 

 


Copyright 2008 All Rights Reserved FullScaleCommerce.com (888) 894-3986 ext 1