On CNET: Start your tech shopping now
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 13 of 42:
Next »
« Previous
Tell them to stop installing and running Kazza
Or some other piece of scumware that kills or bypasses AV and firewall tasks in order to work. If they're getting re-infected like this it points to something that is disabling security, either the user themselves, some scumware, or a combination of the two. Finding out how this is happening is the key in order to prevent it from continuing to happen. I'd guess that they have one or more programs, such as a P2P program or 'browser helper' installed that aren't considered a virus by AV companies but leave them vulnerable to exploitation. Get rid of these programs (which can be a chore in some cases) and tell them if they want an infection free system to refrain from using them again.

Once you've done that, secure the system. The best thing they can do is switch to using Mozilla/Firefox. If they insist on or have to run IE and Outlook, get all of the security updates and then disable ActiveX (or run prompted) in the Internet Zone and disable all scripting in the Restricted Zone. Google for and install IESPYAD and Spyblocker to prevent installation of hijackers. Get the Sun Java VM and ditch the buggy and unsupported MS one. Set Outlook to view all mail as text and to restrict executable attachments and, as an extra precaution, make sure the security zone for Outlook is Restricted, not the old default of Internet zone (this simple change has prevented the auto-run in the preview window situation for at least 4 years now). Get a HOSTS file that will block access to scummy sites. Do this even if you go the Mozilla route since this will block aggressive adware. Then you might want to consider a personal firewall if they aren't being screened at the server side at all times as well as a registry and process protection (most AV and firewall programs don't do this).

These steps won't necessarily prevent them from being re-infected but they'll have to click "YES" on a lot of prompts telling them not to do it in order to pull it off.
Posted by: jfrankcarr   Posted on: 03/18/04 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Its about time!  Tammee | 03/17/04
Capability?  Update victim | 04/26/06
Yet another reason not to use Windows  ITGuy04 | 03/17/04
But Windows can be safe  Taz_z | 03/17/04
Re: But Windows can be safe  issthatso | 03/17/04
You are right for NSA level security,  Taz_z | 03/17/04
Quite simple  DragonBRockin | 03/17/04
I said "Given what I said in my previous post"  Taz_z | 03/18/04
Home users don't need C2 security  jfrankcarr | 03/17/04
Then why did I fix an infected machine on Monday?  ITGuy04 | 03/18/04
Read my post just a little more carefully  Taz_z | 03/18/04
auto update every week?????  PA-ITGuy | 03/18/04
Tell them to stop installing and running Kazza  jfrankcarr | 03/18/04
What do you mean...  vferrara | 03/17/04
start playing the B side!!  nite_w0lf | 03/17/04
It's not the system     | 03/18/04
Server Side Virus Scanning would help  jfp | 03/17/04
While I agree, in principle...  vferrara | 03/17/04
agreed  PA-ITGuy | 03/17/04
Funny no one suggested  Chad_z | 03/17/04
It's not that easy when setup right  jfrankcarr | 03/17/04
Busted users, NOT busted software. Try thinking next time.     | 03/18/04
It's not just the 'inbox attachments'  jfrankcarr | 03/18/04
Thank you Cable Modem ISPs  issthatso | 03/17/04
I totally AGREE  DragonBRockin | 03/17/04
AV Software  voska | 03/18/04
Stay away from BlackICE Defender  DragonBRockin | 03/19/04
ISP and virusmails  benopdezolder | 03/17/04
If you read above, pls read this  Sackaguano | 04/08/04
yes!  ryusen | 03/17/04
The Dirty Secret  jfrankcarr | 03/17/04
too secure  JWatson77 | 03/17/04
If my ISP...  BitTwiddler | 03/17/04
Trespassing!  bjbrock | 03/17/04
The only thing that will wise up users  nite_w0lf | 03/17/04
Finally, maybe this will get the public's attention  copperhead9901@... | 03/18/04
Windows can be secure  Louisiana oilman | 03/18/04
Re: Windows can be secure  bchesmer | 03/18/04
Help! anyone know where this one came from???  bchesmer | 03/18/04
Charge Microsoft Users Higher Rates  brenthawkinsmd | 03/18/04
Get Real!  DragonBRockin | 03/19/04
Fix the problem, not the symptom  ghastly | 04/27/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here
advertisement

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here