https://invisiblesecurity.blogspot.com/ https://knowledgeanitivirus.blogspot.com/ https://easydatasolutionshere.blogspot.com/ https://anitvirusecurity.blogspot.com/ Tech-Talk

Types of Computer Virus Attacks & Solutions by Antivirus

 

Types of Computer Virus Attacks & Solutions by Antivirus

 


Below you will find a list of the most common attacks that we face daily on the Internet, ordered by types:

Scan (Search):

Scanning, as a method of discovering potentially exploitable communication channels, has been in use for a long time. The idea is to scan as many listening ports as possible, and save information on those that are receptive or useful for each particular need.
There are different types of Scanning according to the techniques, ports and protocols exploited:

 

·         TCP connect scanning - Basic way to scan TCP ports to find open ports to enter.

·         TCP SYN scanning: simulates a client-server connection in which a SYN packet is sent, if it receives a response, communication is cut and that port is registered as open. 

·     TCP FIN Scanning- Stealth Port Scanning: similar to the previous one but more clandestine.

·    Fragmentation scanning: modification of the previous ones, but fragmenting the packages.

·  Eavesdropping-packet sniffing: intercepts packets from the network without modifying them to, for example, find out passwords.

·   Snooping downloading: same as above, but also intercepts files that can be downloaded.

 

Authentication attacks:

This type of attack aims to deceive the victim's system to enter it, for this the attacker makes identity theft. Generally, this deception is carried out by taking the sessions already established by the victim or by obtaining their username and password.

·      Spoofing-Looping: consists of impersonating someone else and then taking actions on their behalf. There are several types such as IP spoofing, DNS, WEB etc.

·      Web Spoofing (Phishing): the attacker creates a fake website similar to the original, allowing to find out from the victim's data to bank codes.

·     IP Splicing-Hijacking: consists of impersonating an authorized user when he identifies himself.

·         Using Back Doors: allows you to bypass normal authentication methods.

·     Use of Exploits: they take advantage of hardware or software failures to enter the system.

·     Obtaining Passwords: obtaining passwords by trial and error or through programs that use dictionaries with millions of keys that they try to find the correct key.

 

Denial of service (DOS):

The current protocols were designed to be used in an open community and with a relationship of mutual trust. Reality indicates that it is easier to disorganize the functioning of a system than to access it; Thus, Denial of Service attacks aim to saturate the victim's resources in such a way that the services provided by the victim are disabled.

·         Jamming or Flooding: disable or saturate system resources, such as memory, disk, etc.

·       Syn Flood: A "half-way" connection is established, so that the computer is awaiting a response from the hostile computer, thus slowing down the system.

·         Connection Flood: causes the connection limits to be exceeded, leaving the Internet server hanging.

·         Net Flood: saturates the line with malicious traffic, preventing useful network traffic.

·      Land Attack: consists of sending a packet with the source address and port the same as the destination one, causing the system to crash.

·     Super nuke or Win nuke: sending manipulated packets to port range 137-139 that causes the computer to hang.

·         Teardrop I and II-Newtear-Bonk-Boink: prevents the fragments that form a package from being correctly assembled, causing the system to saturate.

·      E-Mail Bombing-Spamming: the first consists of saturating an email account by mass sending the same message, and what spamming does is a mass sending of an email to thousands of users without their consent.

 

Mod-Damage Attacks:

·         Tampering or Data Diddling: unauthorized modification of the data or software installed on the victim system, including deletion of files.

·         Fingerprint Removal: consists of eliminating all the tasks that the intruder performed on the system to prevent it from being located.

·    Attacks Using Java Applets: Take advantage of security flaws in ?? java virtual machines ?? to launch attacks.

·      Attacks through JavaScript and VBscript: used to, for example, send emails without the user's knowledge, read directories, files, view the history of visited pages, etc.

·      Attacks Using ActiveX: manipulate the code of certain browsers, so that it does not ask the user for confirmation when downloading another active control from the Internet, thus they can introduce malicious code.

·      Vulnerability Attacks in Browsers: allows access to the computer's buffer and run programs such as format.com.

 

Exploitation of design, implementation and operation errors:

Many systems are exposed to security "holes" that are exploited to access files, passwords, or gain privileges. These vulnerabilities are caused by programming flaws in operating systems, software applications, network protocols, Internet browsers, email, etc.

Recommendations to avoid the spread of viruses and spyware


1) Always have an
antivirus and antispyware program active; It is advisable not to trust just one, but using more than one does not mean that we must have them all installed, we simply run those antivirus and antispyware in their scanning option, on the folder that contains the files to review.

2) Just as important as having the antivirus installed is having it fully updated. Currently, updates are daily in most programs, or at least weekly, so if the antivirus we have is not updated with a maximum frequency of one week, it would be best to change to another that had daily updates or several weekly. The same happens with an antispyware program, we must keep it as up-to-date as possible, since this way security holes are corrected that can put our security at risk. Many worms nowadays are successful due to the laziness of users to update their programs, so an awareness of continuous renewal of the programs on our computers, especially those more delicate such as browsers, operating systems, P2P clients and others, is basic to be sure.

3) Do not open any message or file received via email from unknown or very little known sources. In the case of familiar persons, the corresponding precautions must also be taken. Make sure with that person of the shipment, and never execute them before passing the updated antivirus to these files. When in doubt, simply choose to delete the message and the attached files.

4) Do not download anything from websites that you do not have serious references to, or that are not fairly well known. And if files are downloaded, we must do as with the attached files; examine them with the antivirus before executing or downloading them.

5) Test several
antivirus, firewalls, antispyware, etc., downloading its trial version (trial version) that usually lasts between 15 and 30 days, with which we can try several before deciding to buy the one that best suits our needs. Tell us about its ease of use and configuration, after-sales support, features, and performance. Find users of those programs who provide us with their opinion about this or other similar programs. The best we can do is navigated in a forum dedicated to security or in those of the program's company, where we can read important details of the operation of the people who use it. They will even answer the questions we ask them, and we will see the advantages and disadvantages of the users themselves.

Whom to Choose among Endpoint & Antivirus Software

Whom to Choose among Endpoint & Antivirus Software?


If there is one thing that does not change over the years in IT, it is viruses and computer attacks. According to a survey by the non-profit association ISACA, 46% of companies experienced an increase in attacks in 2018. The top attacks that organizations faced were phishing (44% of respondents), malware (31% of respondents), and social engineering (27% of respondents).

According to reports from the security companies, in the first half of 2019 the Ransomware detected by its systems exceeded 110 million attack attempts and threats from encrypted traffic (TLS / SSL) are growing in a new trend,  exceeding 2.5 million detections. To prevent these attacks, companies have different technologies at their disposal. The most used are antivirus and Endpoint protection systems.

What is an ANTIVIRUS?

An antivirus is software that is responsible for detecting and suppressing computer viruses. In recent years it has incorporated other advanced functions such as blocking viruses, disinfecting files and preventing them from being infected.

These programs, nowadays, also recognize other types of malware, although with many limitations, such as spyware, Trojans, pseudoviruses, worms or rootkits, among others.

However, user mobility has reduced the effectiveness of this protection method. To solve this, new technologies have emerged such as Endpoint security.

What is Endpoint Security?

It is a new approach to IT security that is responsible for monitoring terminals (computers and mobile devices connected to the Internet) in search of insecure activities.

Advanced technologies such as Artificial Intelligence (AI) and Machine learning intervene in these security systems , which can detect anomalous activities and counteract it immediately. They specialize in advanced threats such as Ransomware or Phishing , in addition to being effective against malware and viruses in general with much higher effectiveness than antivirus.

They are security systems that have the ability to detect anything from malicious URLs to web attack codes. Solutions that bring many benefits to companies.

Lately cybercriminals are focusing on PDF and Office files to try to circumvent security measures, a good endpoint must be able to analyze this file and detect any suspicious behavior and stop its execution, in addition to informing and updating the database from the manufacturer to avoid future threats with the same signature.

Endpoint protection benefits

These specific treatments of computer security are the most complete and secure solution for companies because it provides the following advantages:

·         Maximum efficiency
Endpoint protection systems are very effective. If the main Antivirus Software are 50% effective, an endpoint solution, capable of stopping malware even before it is executed, is around 90% effective. In our case, with Capture Client of SonicWall, efficiency is about 99.79% and both we and our customers can attest first hand.

·         Reduces end user downtime
Malware prevention facilitated by these protection systems means that the end user is very little down time (or always on), since these systems can act even before the attack is carried out without altering the development of user activity. Or even perform Rollback actions returning the computer to its initial situation , as in the case of Capture Client.

·         It offers global protection for all devices
Thanks to the implementation of a security system of these characteristics; a company is able to guarantee the security of physical PCs, virtual desktops and servers.

·         Better computer performance
Unlike antivirus, Endpoint protection systems use little CPU and memory, which allows a significant improvement in system performance.

·         Increased IT productivity
The application of AI and mathematical models to prevent attacks on endpoints increases IT productivity thanks to its complete management in the cloud and the creation and application of guidelines in real time.

Endpoint security, the best solution to protect your company

Organizations are increasingly exposed to threats and need innovative solutions to improve their protection, even when users are on the move.

They need more effective security systems that increase user productivity, protect all devices in the organization without compromising their performance, and free IT staff from tedious unproductive tasks.

In addition to offering advice based on 20 years of experience, invites anyone interested in an Endpoint Antivirus Software to try all the features, the most advanced endpoint on the market, for free.

End Point Security protects more than 99.7% effective against threats such as ransomware or phishing and is capable of detecting and preventing the activation of zero day threats. In addition, it has a Rollback system to restore files in case of an infection, with the important saving of time and peace of mind .

  

Let us Differentiate- Antivirus vs. Antimalware

 

Let us Differentiate-

Antivirus vs. Antimalware

Security is undoubtedly a very important factor on the Internet. There are many threats that are present on the network. Fortunately, there are also many tools that we can use to protect ourselves. Today we are going to talk about it, differentiating two that are widely used. We are going to explain what are the differences between ANTIVIRUS and antimalware. We are going to talk about how each option protects us and under what circumstances we have to use them.

Differences between Antivirus and antimalware

When we choose to protect our systems we can make use of different tools. Two clear examples are antivirus and antimalware. This is something that must be applied regardless of the type of operating system we are using or the device we have.

Now, we must bear in mind that not just any tool will always protect us for what we need. We can basically compare it with medicines. All medicines serve to heal us, just as vaccines prevent diseases. But of course, does any medicine cure us of everything? There is the question. The same happens with antivirus and antimalware and you have to know how to differentiate them.

To understand the differences, we first have to know what is a virus and what is malware. This way we will know what each tool really works for. These are two terms that sometimes confuse users. On the one hand we have viruses, which are programs created to make a system not work properly. They can multiply, change their characteristics, hide ... On the other hand we have malware, which is all malicious software. It can have much more functionality than viruses. For example, it can steal passwords, distribute Spam, be programmed to steal information, etc.

How an Antivirus and antimalware works

If we start with antivirus we can say that their main function is to prevent the entry of viruses. What it does is make it difficult for these threats to enter. It's like giving our team a vaccine to prevent it from getting infected.

On the other hand, antimalware software acts more specifically with the malware that is already inside. Scans for malicious files and software that shouldn't be there. If it detects something, it sends it to a quarantine area where it cannot infect other functions, and then deletes it. Keep in mind that today we have security solutions that act in a hybrid way. In other words, they can act as an antivirus preventing the entry of these types of threats, but also as antimalware.

In short, an antivirus has the main function of detecting viruses and preventing their entry. In principle we can have tools of this type without the ability to eliminate them. On the other hand, antimalware's main objective is to eliminate these threats.

Therefore, these differences must be taken into account when we want to correctly protect our system. There are many types of threats on the network but we also have many solutions to protect ourselves. There are both free and paid antivirus and antimalware. It is a matter of choosing the one that best suits what interests us and always keeping it updated.

Antivirus or anti-malware software: main differences

The mission of antivirus software is to prevent. It is used to prevent files containing viruses from being downloaded to your computer. It also tries to prevent viruses from being activated if they are somehow downloaded onto your computer and placed in memory or some file-like location. If the virus file does not download, there will be no problem. And if the file is downloaded but the antivirus software marks it as malware and prevents it from activating, it will not cause damage to your computer. Although it is still necessary to locate and delete the infected file.

 

When Are Malware Removers Needed

Suppose an infected file is downloaded and then run, causing the virus to become active. Typically, this situation occurs by mistake, such as when a malicious link is clicked or a virus-infected email attachment is opened. Some antivirus software has rudimentary tools to remove active viruses, but today's malware is sophisticated at hiding itself on computers by choosing locations where it can be restarted later, so these basic tools may not completely eliminate infections.

A malware remover provides tools that are specifically used to remove malware from an infected computer in the event that viruses pass the verification process by antivirus software. Malware includes active viruses, neutralized viruses, and inactive malware that may be hidden and lurking on the infected computer.

 

Antivirus and anti-malware software: smart security

Anti-malware tools are necessary because anti-malware can hide, reappear, spread, and infect, even if the anti-virus program flags an identified virus and removes it.

Malware can take various forms, such as a file, a hidden file, or a partially corrupted file; you can hide the mechanisms that start the virus, such as a startup service or a registry item. In the worst case, the malware works for a third party whose objective is to steal valuable information, such as bank account numbers or personal data, without making themselves known. In the case of today's malware, it is usually not enough to delete a single virus file. Rather, multiple checks and scans are required at various locations to completely remove the malware package.

There are a number of Free Antivirus and malware scanner offerings that can provide a valuable starting point if you are introducing computer security at home. Some tools can tell you if your computer is infected and give you a full report of their results. However, they may not remove found virus infections, so ultimately it will be wise for you to purchase both antivirus software and a malware remover to properly preserve your investment in a computer.

 

How to Check If Antivirus Software Is Working

 

How to Check If

Antivirus Software Is Working

Next, we are going to see how to check if my antivirus is running correctly. It is very important to protect the PC with an Antivirus, Firewall, Anti Spyware and Anti Spam that is responsible for protecting us when browsing the internet.

When it comes to browsing different websites, downloading files, watching videos, etc. We are exposing ourselves to all kinds of malware. For this reason, it is essential to have a good antivirus to protect us at all times from this class of malicious programs.

Although it is very likely that you have an antivirus installed. But are you sure it works correctly? Luckily, there are reliable companies that allow us to carry out different tests to check if our antivirus is protecting us efficiently.

How to know if my antivirus is working

What we can do to check if our antivirus is working correctly is to download a fake virus. Amtso takes care of providing us with fake virus download links that are blacklisted by antivirus.

It will act as if it were a malware that endangers our computer. However, we could say that this is “performance” since it will not actually endanger the PC since, as we mentioned earlier, it is a fake virus to check if your antivirus works properly.

The list of fake viruses provided by AMTSO is as follows:

Detects drive-by downloads of malware: in this case it measures the level of effectiveness of the antivirus against downloads that we have not made intentionally.

Detects manually downloaded malware: what it does is help us to check if the antivirus is capable of detecting any kind of virus that we ourselves download from the internet.

Detects potentially Unwanted Applications (PUAs): it tests the antivirus in every way to see if it is capable of blocking malicious programs.

Is connected to a cloud-based lookup system: verifies that the antivirus we use is capable of using the cloud to improve the level of malware detection.

Detect compressed malware: what it does is download a virus which is compressed in order to see how the antivirus behaves and in how long it detects it.

Detects phishing pages: there are many web pages that are phishing, what it does is load sites known for this to see how long the antivirus takes to block them.

Something that we must make quite clear, again. This is a test, which means that none of these tests endanger our computer. These are safe tests to verify the operation of our antimalware.

How to check if my antivirus works correctly

Another thing you can do is try the test to verify the ports that we have opened. It is extremely useful to verify how we have the configuration of the Windows firewall and the router. We also have another very useful tool that tests our antivirus program against ransomware quite effectively.

To finish this long article we must clarify that it is not recommended to have two antiviruses on the same PC. Since you will not be able to improve the security of your computer, quite the opposite. By having two antiviruses on the same PC, the only thing you get is more vulnerabilities than you could imagine, it is very counterproductive. The reason?

The consumption of resources is one, evidently having two programs running in the background the consumption of resources of the computer is doubled, which means that it will work much slower in every way, making it necessary to clean, optimize and accelerate the PC .

They also block each other, this is normal. When one of the Antiviruses tries to scan another file or the two try each other. They will not be able to do it, which will cause said file not to be analyzed, putting your computer at risk

 

9 Tips to Choose Best Antivirus Software

 

9 Tips to Choose Best

Antivirus Software


Are you looking for the best Antivirus Software or the best Total Security Solution for the IT maintenance of your SME? There are so many options on the market that you may not know what to choose. Surely you have heard thousands of times how important it is to have an antivirus, but you may not know what criteria it has to meet to achieve the best security for your company. On some occasion we have talked about the importance of making backup copies as the safest method to protect your company's information. Today we are going to guide you in the most important aspects that you

Today we are going to guide you in the most important aspects that you have to take into account to choose the best antivirus option for your SME.  

With more than a quarter of a million new malicious programs being detected every day, is clear that everyone needs the protection of a good antivirus product. Having it will not guarantee us to be free from threats, but we will make it more difficult.

It doesn't matter if you work on Windows, Android or macOS: there is malware that makes its way to your computer. But what kind of antivirus software should you get? Will you have to pay for it, or is the free antivirus good enough? Is anti-malware software the same as anti-virus software? Why are there so many different types of antivirus software, even from just one brand? And does the use of antivirus software pose a risk to computer equipment?

The answers to all these questions are complicated, but we are going to try to give you some basic advice while you decide on the best protection for your SME's IT.

1.    Free antivirus that offer good protection, but pay offers more features

Some free antivirus products will protect your computer systems extremely well from malware. But paid products tend to have a lot more extra features, especially on Windows. You just have to keep in mind that in most cases you will have to spend an annual subscription. Most people tend to choose less expensive products, and while this is a good general approach, it is not always the best.For security products, that means looking for the cheapest product that meets your needs and offers the protection you need. That product might not be the least expensive on the market. On the other hand, imagine how much it will cost you if you buy a bargain security product that cannot protect your personal files against ransomware threats.

2.    Look for a light system load

It is true that any Antivirus Software will use up some of our computer's resources, but a good antivirus program should keep your system free of malware without significantly slowing down your system's performance. In testing, the best antivirus software is hardly a performance drag.

3.    A near perfect detection rate

Since the role of antivirus software is to detect threats, it should do so flawlessly. Seek certification from a respected third-party testing organization.

You will need to ensure that your antivirus software stops more than 95% of malware, whether it is common malware or new malware. But make sure that the detection rate is not accompanied by a high rate of false positives, which are benign files mistakenly identified as malware.

4.    An intuitive interface

Because antivirus software can be customized, it is important that the interface guides users through the various settings.

5.    Daily updates

Provide up-to-date protection. An Antivirus Software that uses old and outdated malware definitions is a weak product. Viruses continually evolve, they never stop, so antivirus must do that too. A good antivirus is a product that is constantly updated, several times a day.

6.    Consider reputation

This may sound a bit conservative, but in the IT security market, reputation matters. Buying and using a security product from a reputable company is usually a safer bet than jumping in with a security product from an unknown company. Good security solutions tend to stay good as time goes on.

7.    Antivirus alone or security suite?

Antivirus software comes as a standalone program, but you can also purchase it as part of a comprehensive security suite. Security suites, covered in our separate report on Internet security software, are more expensive, but include a range of protections, with antivirus, antispyware and antispam programs, identity theft protection, firewalls, and parental controls. 

8.    Check the system requirements

Make sure the antivirus program you choose works with your Windows or Mac operating system. If you have an older computer, a large antivirus software program can consume a large percentage of your computing power and may have compatibility problems.

9.    Avoid conflicts

Antivirus software rarely works very well with similar products from different vendors. Before installing third-party software, completely uninstall any pre-existing security software.

Despite all the information we've collected, choosing the best antivirus software in 2019 is easier said than done. From free products to sophisticated feature-laden security software, there are so many options on today's market that it can be difficult to know which Antivirus Software is right for your business.