<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Giedrius Majauskas blog &#187; Security</title>
	<atom:link href="http://www.majauskas.com/category/security/feed" rel="self" type="application/rss+xml" />
	<link>http://www.majauskas.com</link>
	<description></description>
	<lastBuildDate>Thu, 29 Jul 2010 08:34:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Antivir Solution pro &#8211; new rogue mimicking legitimate antivirus</title>
		<link>http://www.majauskas.com/antivir-solution-pro-new-rogue-mimicking-legitimate-antivirus</link>
		<comments>http://www.majauskas.com/antivir-solution-pro-new-rogue-mimicking-legitimate-antivirus#comments</comments>
		<pubDate>Fri, 16 Jul 2010 15:53:28 +0000</pubDate>
		<dc:creator>Giedrius</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.majauskas.com/?p=357</guid>
		<description><![CDATA[Antivir Solution Pro is a remake of Antimalware Doctor and Antispyware soft. It is a fake antivirus, sharing the name with legitimate Antivir made by Avira. While Avira&#8217;s Antivir is one of the most widely recommended free antiviruses packages, the Antivir Solution Pro is dangerous for the PC. First of all, Antivir Solution Pro is [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.majauskas.com%2Fantivir-solution-pro-new-rogue-mimicking-legitimate-antivirus"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.majauskas.com%2Fantivir-solution-pro-new-rogue-mimicking-legitimate-antivirus&amp;source=giedrius&amp;style=normal&amp;service=bit.ly&amp;service_api=R_6b70a2205c1a0ba9dbc37392e42c745d" height="61" width="50" /><br />
			</a>
		</div>
<p><strong><a href="http://www.2-viruses.com/remove-antivir-solution-pro">Antivir Solution Pro</a></strong> is a remake of Antimalware Doctor and Antispyware soft. It is a fake antivirus, sharing the name with <a href="http://www.free-av.com/en/trialpay_download/1/avira_antivir_personal__free_antivirus.html">legitimate Antivir made by Avira</a>. While Avira&#8217;s Antivir is one of the most widely recommended free antiviruses packages, the Antivir Solution Pro is dangerous for the PC.</p>
<p><a href="http://www.2-viruses.com/remove-antivir-solution-pro"><img class="attachment-medium alignleft" title="Antivir Solution Pro" src="http://www.2-viruses.com/wp-content/uploads/2010/07/AntivirSolutionPro.jpg" alt="" width="300" height="227" /></a></p>
<p>First of all, Antivir Solution Pro is distributed by security vulnerabilities, like infected Adobe PDF files, Javascript ads on various websites. This is a first sign that a software can not be trusted. Secondly, it will start showing popups and alerts blocking normal processes and limiting access to legitimate websites to scare user into downloading and buying its full version. Thirdly, Antivir Solution Pro might reconfigure the PC to allow easier reinfection in the future, by changing proxy settings, modifying way DNS addresses are recognized and downloading other parasites to weaken the PC.</p>
<p>Antivir Solution Pro can be removed by rebooting into safe mode and scanning the PC with Spyware Doctor or Malwarebytes. Full scan is strongly recommended.  As the trojans might block the scan, it is highly recommended to disable the processes before the scan by killing all processes named with random letter strings (especially ending in tssd.exe). If such processes are successfully killed, One can run msconfig and remove startup entries referencing such processes. Still many of the infected files might be missed by manual removal, thus a single secure way is scanning with several automatic removal tools for Antivir Solution pro.<br />
Full removal guide is available here : <a href="http://www.2-viruses.com/remove-antivir-solution-pro">http://www.2-viruses.com/remove-antivir-solution-pro</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.majauskas.com/antivir-solution-pro-new-rogue-mimicking-legitimate-antivirus/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Global unlike: it does exit as MyWOT toolbar</title>
		<link>http://www.majauskas.com/global-unlike-it-does-exit-as-mywot-toolbar</link>
		<comments>http://www.majauskas.com/global-unlike-it-does-exit-as-mywot-toolbar#comments</comments>
		<pubDate>Thu, 01 Jul 2010 10:10:38 +0000</pubDate>
		<dc:creator>Giedrius</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[mywot]]></category>

		<guid isPermaLink="false">http://www.majauskas.com/?p=335</guid>
		<description><![CDATA[Most of my income is done in computer security market, and I have follow various tools and events to stay on the top. As with any other market, there are very interesting how the computer security is reflected in social media or how Social media is used in it. Security market got it all backwards [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.majauskas.com%2Fglobal-unlike-it-does-exit-as-mywot-toolbar"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.majauskas.com%2Fglobal-unlike-it-does-exit-as-mywot-toolbar&amp;source=giedrius&amp;style=normal&amp;service=bit.ly&amp;service_api=R_6b70a2205c1a0ba9dbc37392e42c745d" height="61" width="50" /><br />
			</a>
		</div>
<p>Most of my income is done in computer security market, and I have follow various tools and events to stay on the top. As with any other market, there are very interesting how the computer security is reflected in social media or how Social media is used in it.  Security market got it all backwards and released semi-global unlike button for its own market in terms of <a href="http://www.majauskas.com/mywot-part-2-the-results">MyWOT</a>.</p>
<p>I have reviewed MyWOT positively in the past, and the points are still valid. However, it is time to talk about several downsides of it (and why I see no real use for it in the future).</p>
<p>First, it works as global unlike button in security market. Lots of people know about it in this area and use it to manipulate listings.  Experts do not rate good sites in this area  &#8211; there are too many, and no one cares if they are not their own. For example, one negative review of one Rogue cleaner in my blog resulted at negative review in MyWOT of my site by him (with several accounts).  I know pretty much, that some of other ratings are voted by people advertising similar or same products:)</p>
<p>Second, the toolbar itself is made in the way that suggest  auto-confirming votes. It blocks all sites with negative ratings, and many of the negative ratings are reconfirmed by users which do not see the site itself. I had a looong discussion with MyWOT platinum member to remove his comment (and rating), which was made WITHOUT checking website.  The mailing forth and back lasted couple days, and I the last mail I got was that he removed the comment and will check the website once he has time.</p>
<p>Third, the sources of auto-rating. MyWOT uses 3 sources (maybe more) to confirm that site is valid : hphosts, delicious and digg. First one is negative, other ones have no bigger impact. All of them have no real basis. Everyone can submit to digg and delicious. Listing in hphosts is not purely black or white either: some of listings are irrelevant (&#8220;marketing strategies&#8221;) , some are out of control ( IPs history) , some are valid (distribution of malicious software).  However, I haven&#8217;t seen users evaluating these properly. Everyone would just vote all bards the same.</p>
<p>4th, the site banner issue. I do not think it is ok, but whatever. If people would like to pay for displaying how crowd things the site is secure, then it is great for mywot. All banners based on real testing are much more useful.</p>
<p>5th. Malware, response time and such. MyWOT will not rate sites at once. Thus malware sites will not be rated as dangerous on first vote.  Next, lots of malware is spread through sites with good reputation. Like facebook.  Thus it will not make web any safer.</p>
<p>To summarize, to protect from parasites I would advice to use Site Advisor Toolbar and not Mywot. However, MyWOT could become much better if adding some changes. For example, incorporating Site Advisors ratings (including possitive and negative sides), checking spent time on the site on rating, checking overall distribution of ratings, etc.</p>
<p>Somewhat funny note is that my site was rated badly by Site Advisor as well, as I have provided a link to Malwarebytes executable or download page (can&#8217;t remember). Later on I get my WOT ratings because I am one of the few people that does not advertise Malwarebytes as &#8220;the best single protection&#8221; or smth.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.majauskas.com/global-unlike-it-does-exit-as-mywot-toolbar/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Avoid AV Security Suite infection!</title>
		<link>http://www.majauskas.com/avoid-av-security-suite-infection</link>
		<comments>http://www.majauskas.com/avoid-av-security-suite-infection#comments</comments>
		<pubDate>Wed, 23 Jun 2010 12:03:21 +0000</pubDate>
		<dc:creator>Giedrius</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Antispyware Soft]]></category>

		<guid isPermaLink="false">http://www.majauskas.com/?p=333</guid>
		<description><![CDATA[Have you heard about AV Security Suite? For me this program appears to be a fake spyware remover which should be threatened by deleting all its files and also ignoring its scanners. It is clear that AVSecuritySuite comes from the same family as Antivirus Soft and Antispyware Soft malwares, because the same GUI has been [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.majauskas.com%2Favoid-av-security-suite-infection"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.majauskas.com%2Favoid-av-security-suite-infection&amp;source=giedrius&amp;style=normal&amp;service=bit.ly&amp;service_api=R_6b70a2205c1a0ba9dbc37392e42c745d" height="61" width="50" /><br />
			</a>
		</div>
<div id="_mcePaste">Have you heard about <a href="http://www.2-viruses.com/remove-av-security-suite">AV Security Suite</a>? For me this program appears to be a fake spyware remover which should be threatened by deleting all its files and also ignoring its scanners. It is clear that AVSecuritySuite comes from the same family as Antivirus Soft and Antispyware Soft malwares, because the same GUI has been simply applied just like for its earlier variants.</div>
<div></div>
<div id="_mcePaste">Trying to rip people off, scammers have also chosen for AVSecuritySuite the same misleading plan based on fake system scanners and alerts. First of all, malware typically gets installed through the use of trojans that come into potential host computer after security vulnerabilities are found. Just like its predecessors and other rogue anti-spywares, AV Security Suite then will try to mislead computer users that they have numerous viruses on their machines. AV Security Suite will popup on your desktop time to time and will also show system scanners and fake alerts announcing about serious computer problems. As a result, you are expected to install AV Security Suite commercial version if you want to “save” your PC. However, only more problems you will find on your computer after doing this. Save your money instead. The only thing which is recommended is to <a href="http://www.2-viruses.com/remove-av-security-suite">delete AV Security Suite</a>.</div>
<p>Additionally, recently it started using name &#8220;Green AV security Suite&#8221;. It looks like it is same parasite in general.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.majauskas.com/avoid-av-security-suite-infection/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Antispyware Soft and how to remove it</title>
		<link>http://www.majauskas.com/what-is-antispyware-soft-and-how-to-remove-it</link>
		<comments>http://www.majauskas.com/what-is-antispyware-soft-and-how-to-remove-it#comments</comments>
		<pubDate>Tue, 04 May 2010 12:42:39 +0000</pubDate>
		<dc:creator>Giedrius</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Antispyware Soft]]></category>

		<guid isPermaLink="false">http://www.majauskas.com/?p=309</guid>
		<description><![CDATA[Antispyware Soft is a malware application that secretly enters computer systems and pretends to be an antispyware program. The infiltration of the program is based on Trojan viruses. Antispyware Soft virus changes some entries of your Windows Registry and installs some components there in order to become the dominating program in the system. The program [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.majauskas.com%2Fwhat-is-antispyware-soft-and-how-to-remove-it"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.majauskas.com%2Fwhat-is-antispyware-soft-and-how-to-remove-it&amp;source=giedrius&amp;style=normal&amp;service=bit.ly&amp;service_api=R_6b70a2205c1a0ba9dbc37392e42c745d" height="61" width="50" /><br />
			</a>
		</div>
<div id="_mcePaste">Antispyware Soft is a malware application that secretly enters computer systems and pretends to be an antispyware program. The infiltration of the program is based on Trojan viruses.</div>
<div id="_mcePaste"><a href="http://www.2-viruses.com/remove-antispyware-soft">Antispyware Soft virus</a> changes some entries of your Windows Registry and installs some components there in order to become the dominating program in the system. The program disables most of your legitimate programs to make sure to stay in the system. When you try to run some program there’s a big chance to receive a warning stating that the program is infected.</div>
<div id="_mcePaste">Once inside, Antispyware Soft is able to use its scanner which is actually only imitates looking for infection. However, once the fabricated scan finishes, Antispyware Soft displays a bunch of infections and claims that removal of these infections is essential in order to clean your system. In addition to bogus scanner, Antispyware Soft generates fake security alerts reporting about spyware attacks. These warnings also suggest fixing the problems with a help of a full version of Antispyware Soft.Please consider <a href="http://www.2-viruses.com/remove-antispyware-soft">removal of Antispyware Soft</a>, if it happened to you to detect this virus on your computer. Do not doubt to do this immediately after its detection.</div>
<p>To remove Antispyware Soft, first you have to reenable internet connection first. To do so:</p>
<p>1. Reboot into safe mode with networking.</p>
<p>2. Launch your internet explorer and make sure your internet connection does not uses proxy server. Do so in other browsers as well</p>
<p>3. Download Spyware Doctor using <a href="http://downloads.2-viruses.com/IEXPLORE.exe">this link</a> (it should not be blocked by Antispyware Soft). Run and perform full scan.</p>
<p>If it fails, try blocking Antispyware Soft manually.</p>
<p>The best way to do so is start task manager (or, for example, process explorer) and stop all Antispyware Soft processes. The processes typically end in tssd.exe.</p>
<p>Afterwards, I would recommend doing full scan  with <a href="http://downloads.2-viruses.com/IEXPLORE.exe">Spyware Doctor </a>or <a href="https://store.malwarebytes.org/342/cookie?affiliate=7745&amp;redirectto=http%3a%2f%2fwww.malwarebytes.org%2fmbam.php">Malwarebytes anti-malware</a>.  It is critical to have a security suite that provides real time protection against such infections like this.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.majauskas.com/what-is-antispyware-soft-and-how-to-remove-it/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>How to remove Antivirus Soft rogue antivirus</title>
		<link>http://www.majauskas.com/how-to-remove-antivirus-soft-rogue-antivirus</link>
		<comments>http://www.majauskas.com/how-to-remove-antivirus-soft-rogue-antivirus#comments</comments>
		<pubDate>Mon, 01 Feb 2010 14:44:02 +0000</pubDate>
		<dc:creator>Giedrius</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.majauskas.com/?p=274</guid>
		<description><![CDATA[Antivirus Soft is a rename of rogue Antivirus live. The crooks had not bothered to change much, the most significant change is in name only. Antivirus soft uses same means to reproduce : fake websites, malicious ads in social networking sites or good old fake codecs and movies. After the download, your PC will stop [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.majauskas.com%2Fhow-to-remove-antivirus-soft-rogue-antivirus"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.majauskas.com%2Fhow-to-remove-antivirus-soft-rogue-antivirus&amp;source=giedrius&amp;style=normal&amp;service=bit.ly&amp;service_api=R_6b70a2205c1a0ba9dbc37392e42c745d" height="61" width="50" /><br />
			</a>
		</div>
<div class="wp-caption alignright" style="width: 310px"><img title="Antivirus Soft screenshot" src="http://www.2-viruses.com/wp-content/uploads/2010/02/AntivirusSoft-300x227.jpg" alt="" width="300" height="227" /><p class="wp-caption-text">Antivirus Soft </p></div>
<p><a href="http://www.2-viruses.com/remove-antivirus-soft">Antivirus Soft</a> is a rename of rogue Antivirus live. The crooks had not bothered to change much, the most significant change is in name only. Antivirus soft uses same means to reproduce : fake websites, malicious ads in social networking sites or good old fake codecs and movies.</p>
<p>After the download, your PC will stop executing other programs becouse they are &#8220;infected&#8221;. Usually, it is not true as single infection is Antivirus Soft  itself. They expect you to agree paying for it and funding these scammers.</p>
<p>The Antivirus Soft removal process is quite similar to antivirus live :</p>
<p>1. Reboot into safe mode</p>
<p>2. Remove proxy server from IE settings.</p>
<p>3. Search your user directory for file ending with sysguard.exe. Delete it. If you cant, press ctrl+shift+esc and stop process with same name and repeat deletion.</p>
<p>4. Reboot and scan with <a href="http://www.2-viruses.com/spdoc.exe">spyware doctor</a> to make sure you got everything out.</p>
<p>I recommend having an anti-malware with real time protection running all the time to avoid problems like this.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.majauskas.com/how-to-remove-antivirus-soft-rogue-antivirus/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SLOW PCfighter review- another registry cleaner</title>
		<link>http://www.majauskas.com/slow-pcfighter-review-another-registry-cleaner</link>
		<comments>http://www.majauskas.com/slow-pcfighter-review-another-registry-cleaner#comments</comments>
		<pubDate>Thu, 28 Jan 2010 13:49:41 +0000</pubDate>
		<dc:creator>Giedrius</dc:creator>
				<category><![CDATA[Reviews]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.majauskas.com/?p=272</guid>
		<description><![CDATA[Slow PC Fighter is a registry cleaner from same family as Spam Fighter or Virus Fighter. Registry cleaners allow fixing errors and inconsistencies in PC’s registry making PC boot and operate a bit faster. Many of them are made by security companies. Slow PC Fighter website claims that running Slow PCFighter will increase PC speed [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.majauskas.com%2Fslow-pcfighter-review-another-registry-cleaner"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.majauskas.com%2Fslow-pcfighter-review-another-registry-cleaner&amp;source=giedrius&amp;style=normal&amp;service=bit.ly&amp;service_api=R_6b70a2205c1a0ba9dbc37392e42c745d" height="61" width="50" /><br />
			</a>
		</div>
<p>Slow PC Fighter is a registry cleaner from same family as Spam Fighter or Virus Fighter. Registry cleaners allow fixing errors and inconsistencies in PC’s registry making PC boot and operate a bit faster. Many of them are made by security companies.</p>
<p>Slow PC Fighter website claims that running Slow PCFighter will increase PC speed up to 40%. That might be true on really badly supervised PC, but I would not expect such things on each PC.</p>
<p>Slow PCFighter free scanner installation was quite quick and easy. The download is around one megabyte. What impressed me, it recognized my Windows as 64 bit one and installed correct version of application itself.</p>
<p>The scan is was quite quick and found around 2000 errors, mostly missing files or empty registry keys. It had not shown any false positives, which is good.</p>
<p>The free version of SLOW PC Fighter removes 25 registry errors, which is quite little compared to errors it found.</p>
<p>Verdict: I would definitely give it a try to see if there are lots of errors in the PC. It might be useful and safe to have this product if you hate reinstalling windows like I do. The downside is that you would have to purchase full version as free scanner is not too useful except for trying the product out.</p>
<p>You can download <a rel="nofollow" href="https://www.cleverbridge.com/355/purl-2410-SLPC-LP">Slow PCFighter here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.majauskas.com/slow-pcfighter-review-another-registry-cleaner/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why you should be cautious about public security advice from contractor</title>
		<link>http://www.majauskas.com/why-you-should-be-cautious-about-public-security-advice-from-contractor</link>
		<comments>http://www.majauskas.com/why-you-should-be-cautious-about-public-security-advice-from-contractor#comments</comments>
		<pubDate>Sat, 23 Jan 2010 16:05:10 +0000</pubDate>
		<dc:creator>Giedrius</dc:creator>
				<category><![CDATA[SEM]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[affiliate]]></category>

		<guid isPermaLink="false">http://www.majauskas.com/?p=266</guid>
		<description><![CDATA[First, I must state here that I am affiliate of couple security products that have little to do with this post on itself. This rambling is about people motivation and truthfulness. Spending time in some forums and social boards I met couple types of people that give professional advice there: people that were in same [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.majauskas.com%2Fwhy-you-should-be-cautious-about-public-security-advice-from-contractor"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.majauskas.com%2Fwhy-you-should-be-cautious-about-public-security-advice-from-contractor&amp;source=giedrius&amp;style=normal&amp;service=bit.ly&amp;service_api=R_6b70a2205c1a0ba9dbc37392e42c745d" height="61" width="50" /><br />
			</a>
		</div>
<p>First, I must state here that I am affiliate of couple security products that have little to do with this post on itself. This rambling is about people motivation and truthfulness.</p>
<p>Spending time in some forums and social boards I met couple types of people that give professional advice there: people that were in same situation, contractors and affiliates or products. The most of people would argue that the last group is most annoying and they can not discern between contractor and other two groups. However, I would like to slightly disagree.</p>
<p>First, a security contractor is a person that is on payroll by specific security software or service company and gets static amount of money for his job and/or bonus on how well company is doing. An affiliate is a person that works for oneself and gets money from specific amount of product sales. Quite often affiliate has more than single products he offers. So, what is the practical difference? Here are some myths:</p>
<p><strong>Myth no 1</strong>. Contractor’s quality of advice is often better as many of them have better knowledge in the field.</p>
<p>Partly true, most of contractors work in the field. However, it is not true for hired marketers compared to security experts that refuse to work on contract bases and earn additional income from sale.</p>
<p><strong>Myth no 2</strong>. Contractors have stable income, so they do not need to force each sale</p>
<p>Not true. If contractor does lousy job, he will lose his income (contract) completely. Doing good job might yield a bonus. If an affiliate does lousy job, his profits will diminish. However, lot of affiliates try selling as much as possible because they seek profit.</p>
<p><strong>Myth no 3</strong>. A contractor does not need to use sneaky tactics at promoting product</p>
<p>Completely not true. Contractor has additional benefit at using sneaky tactics because they can pretend being former customers and there is hardly anything that would prove it otherwise. They do not need to use tracking codes, they do not need to disclose anything. They spamming techniques might reach borderline.</p>
<p><strong>Myth no  4</strong>. An affiliate will not promote best product because he is out for profit</p>
<p>That is again not true as you can’t promote BAD product for long.  Additionally, affiliate has a huge benefit of being able to choose what product to promote and what not. A truly good affiliate is not forced to promote a product using false comparison tables, spam or by accusing competitions business model.</p>
<p>Sure, there are all kinds of affiliates and contractors. However I would check such things as:</p>
<ol>
<li>Accusing other reputable products being bad because option x is paid one</li>
<li>Leaving user without a choice when choosing product</li>
<li>Calling other marketers spam because they promote different product than they do</li>
<li>Calling others a scam because they do same things and are paid by performance</li>
<li>Avoiding giving free information and pushing a product</li>
<li>Forcing user to pay for free things to boost sales of product without giving them to try it</li>
<li>Making a set of disclosure rules others (affiliates) have to follow to be legitimate but not following them themselves.</li>
</ol>
<p>I got a lot of examples of such behavior. And sadly it will remain that way in the market.</p>
<p>And there is one thing I have to disclose &#8211; I was a contractor of security company for a short while too (No, it was not Malwarebytes, but the experience would be the same I guess). I did not liked the experience, because my freedom to promote right product in each situation was reduced. Now I can give suggestions of any product I think is good for the customer. Even if I get 0 cents from it. That is freedom I have working for myself and not being a contractor.</p>
<p>And if you think it would be if I would work in different company, that promotes &#8220;best&#8221; &#8220;free&#8221; product? Well, think again. I will have less freedom and less choices.</p>
<p>Now I do not say that being contractor is evil. Being contractor and not disclosing it when suggesting a product is evil, though. Much more evil than being affiliate, which is easily seen in most cases. Calling other legitimate products malware is evil when you are paid by competitors. Calling others spammers when you do the same is evil.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.majauskas.com/why-you-should-be-cautious-about-public-security-advice-from-contractor/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Removing Antivirus Live in 3 simple steps</title>
		<link>http://www.majauskas.com/removing-antivirus-live-in-3-simple-steps</link>
		<comments>http://www.majauskas.com/removing-antivirus-live-in-3-simple-steps#comments</comments>
		<pubDate>Wed, 30 Dec 2009 13:45:27 +0000</pubDate>
		<dc:creator>Giedrius</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[antivirus live]]></category>

		<guid isPermaLink="false">http://www.majauskas.com/?p=256</guid>
		<description><![CDATA[Antivirus live is a rogue antispyware application on the same platform like cyber security and system security. It infects system by drive-by-downloads, shareware or infected websites. The difference is that Antivirus live uses a bit more complex way to protect its executables against removal and removal software. First of all, Antivirus live enables proxy server [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.majauskas.com%2Fremoving-antivirus-live-in-3-simple-steps"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.majauskas.com%2Fremoving-antivirus-live-in-3-simple-steps&amp;source=giedrius&amp;style=normal&amp;service=bit.ly&amp;service_api=R_6b70a2205c1a0ba9dbc37392e42c745d" height="61" width="50" /><br />
			</a>
		</div>
<p><strong>Antivirus live</strong> is a rogue antispyware application on the same platform like cyber security and system security. It infects system by drive-by-downloads, shareware or infected websites. The difference is that Antivirus live uses a bit more complex way to protect its executables against removal and removal software.</p>
<p>First of all, <a href="http://www.2-viruses.com/remove-antivirus-live">Antivirus live</a> enables proxy server in the common browsers. The server either goes through Trojan process on localhost or through infected websites. This allows manipulation of search results and inserting various popups into web pages. This hinders downloading of anti-spyware applications as well.</p>
<p>Second, Antivirus Live processes disable launching of other, non-white listed executables. Thus it is harder to get rid of antivirus live while process is active.</p>
<p>To <a href="http://www.2-viruses.com/remove-antivirus-live">get rid of Antivirus Live</a>, you have to disable its processes. There are couple ways to do so : First, start task manager right after logging in into windows (while Trojan has not launched). Keep pressing ctrl+shift+esc . Then stop all processes that end with sysguard or other processes that should not be there. Second way is using safe mode (press F8 on boot up). If it fails, download process explorer from Microsoft  (you might have to rename it to .pif ) and try using it.</p>
<p>Second step of Antivirus Live removal procedure is fixing your browser. For this simply disable proxy server and empty hosts file on your PC. Overall, it is good idea to disable add-ons of unknown companies as well.</p>
<p>The last step is removal of infected files. Although you can search for them on hard disk (files ending with sysguard.exe), the better approach is to download and install good Anti-spyware application. Personally, I recommend <a href="http://www.2-viruses.com/spdoc.exe">Spyware Doctor</a> for Antivirus Live removal and keeping your computer protected from similar parasites in the future. Other good choices include superantispyware and malwarebytes.</p>
<p><img class="attachment-medium" title="antivirus live" src="http://www.2-viruses.com/wp-content/uploads/2009/11/antiviruslive-300x191.jpg" alt="antivirus live rogue anti-spyware" width="300" height="191" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.majauskas.com/removing-antivirus-live-in-3-simple-steps/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to get rid of Security Tool</title>
		<link>http://www.majauskas.com/how-to-get-rid-of-security-tool</link>
		<comments>http://www.majauskas.com/how-to-get-rid-of-security-tool#comments</comments>
		<pubDate>Mon, 12 Oct 2009 11:16:03 +0000</pubDate>
		<dc:creator>Giedrius</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Tool]]></category>

		<guid isPermaLink="false">http://www.majauskas.com/?p=229</guid>
		<description><![CDATA[Security Tool is a rogue antivirus scam, using generic name for disguise. Together with Cyber Security, they are hitting computers hard and forcing users into buying their &#8220;full&#8221; versions to remove non-existing virus infections. Typically, Security tool states that one&#8217;s PC is infected with Spyware.IEMonster or similar parasites, however, the real infections are very different. [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.majauskas.com%2Fhow-to-get-rid-of-security-tool"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.majauskas.com%2Fhow-to-get-rid-of-security-tool&amp;source=giedrius&amp;style=normal&amp;service=bit.ly&amp;service_api=R_6b70a2205c1a0ba9dbc37392e42c745d" height="61" width="50" /><br />
			</a>
		</div>
<p>Security Tool is a rogue antivirus scam, using generic name for disguise. Together with <a href="http://www.2-viruses.com/remove-cyber-security">Cyber Security</a>, they are hitting computers hard and forcing users into buying their &#8220;full&#8221; versions to remove non-existing virus infections. Typically, Security tool states that one&#8217;s PC is infected with Spyware.IEMonster or similar parasites, however, the real infections are very different.</p>
<p>The main problem with Security tool and alike is that they prohibit most of downloads and render computer unusable. However, there is a way to remove it.</p>
<p><strong>Step 1.</strong></p>
<p>Check if you can access your Task Manager and Regedit. Task manager can be accessed by pressing ctrl+alt+del and choosing it from menu. regedit is accessed by simply running it.</p>
<p>If you can not access task manager, but you can access regedit, search for TaskMgr entry in registry (using regedit) and delete it. This should reenable task manager.</p>
<p>Alternatively, you can download <a href="http://download.sysinternals.com/Files/ProcessExplorer.zip">process explorer</a> (you might need to rename it to iexplorer.exe or iexplorer.bat for launching) . Also, you might need to download it to another PC and bring it using USB drive</p>
<p><strong>Step 2. </strong></p>
<p>If you can launch process explorer or task manager, do it. If not, go to Step 3.</p>
<p>Now you need to kill the processes blocking downloads. Typically, it is run under your username, and not under system user. Search for processes named with random numbers or unknown applications. And stop them. Note down the process names ( you will need these in step 4).</p>
<p><strong>Step 3. </strong></p>
<p>Now you need to check if there are additional blocks to visit other websites. This includes : disabling all proxy servers on your internet explorer or firefox browser, checking your hosts files ( it should be nearly empty, no known sites except localhost).</p>
<p><strong>Step 4. </strong></p>
<p>You have a choice : Search for Security Tool files in <a href="http://www.2-viruses.com/remove-security-tool">Security tool removal instructions </a>or download anti-spyware like <a href="http://www.2-viruses.com/spdoc.exe">spyware doctor</a>, and execute scan and removal.</p>
<p>If you choose manual removal, delete the files you have stopped in step 2 ( with random numbers in name). Also, modify registry and delete all keys mentioning these names.</p>
<p><strong>Step 5. </strong></p>
<p>Reboot and check if everything is ok. If not, repeat steps 2-4 And scan with antispyware you havent scanned. Superantispyware would be my choice nr2, but malwarebytes anti-malware will work too.</p>
<p>Thats it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.majauskas.com/how-to-get-rid-of-security-tool/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Malwarebytes best free protection for your PC? Yeah, right</title>
		<link>http://www.majauskas.com/malwarebytes-best-free-protection-for-your-pc-yeah-right</link>
		<comments>http://www.majauskas.com/malwarebytes-best-free-protection-for-your-pc-yeah-right#comments</comments>
		<pubDate>Thu, 10 Sep 2009 16:00:31 +0000</pubDate>
		<dc:creator>Giedrius</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.majauskas.com/?p=227</guid>
		<description><![CDATA[I have a very mixed feelings about one issue in anti-spyware community. That is how products are marketed as free. During the years as I work in the industry, there were a large amount of products marketed as free despite the fact that their important features are paid ones. Typically, this was the remover itself. [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.majauskas.com%2Fmalwarebytes-best-free-protection-for-your-pc-yeah-right"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.majauskas.com%2Fmalwarebytes-best-free-protection-for-your-pc-yeah-right&amp;source=giedrius&amp;style=normal&amp;service=bit.ly&amp;service_api=R_6b70a2205c1a0ba9dbc37392e42c745d" height="61" width="50" /><br />
			</a>
		</div>
<p>I have a very mixed feelings about one issue in anti-spyware community. That is how products are marketed as free. During the years as I work in the industry, there were a large amount of products marketed as free despite the fact that their important features are paid ones. Typically, this was the remover itself. However, some tools has changed the scene.</p>
<p>One of these tools is Malwarebytes anti-malware. It provides free detection and removal for parasites in database, and its paid feature is real-time protection module. So, what is the problem with it?</p>
<p>The problem is how this tool is positioned for end user. You are told that Malware bytes Antimalware provides the best free protection, however it is not so. Protection it is not same as removal. Protection from computer parasites depend on capabilities of real-time protection module. But few promoting this tool mentions this. Some of the experts can&#8217;t even see the difference in these statements.</p>
<p>However, Malwarebytes anti-malware is a free good program for SOLVING infections, and in most cases this is one of the first tools I install on infected PCs. It has quite good detection ratio, and quite often was enough to solve the problem. Then again, there are quite a few cases when I had to install spyware doctor or other program to finish off remains.</p>
<p>That brings me to another issue I do not like about Malwarebytes anti-malware: its naming conventions. Most of trojan parasites are hidden under simple name of Trojan.downloader so users can not find more information on what infected their PC at other anti-virus and anti-spyware vendors. Some might argue that this information is not important. I disagree, as other vendors might provide better, more in-depth information about particular parasite.</p>
<p>Thus I would stick to other anti-spywares like  super anti-spyware or Spyware doctor for reliable protection, and keep malwarebytes as a just in case tool only.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.majauskas.com/malwarebytes-best-free-protection-for-your-pc-yeah-right/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Beware of SaveDefense</title>
		<link>http://www.majauskas.com/beware-of-savedefense</link>
		<comments>http://www.majauskas.com/beware-of-savedefense#comments</comments>
		<pubDate>Fri, 28 Aug 2009 19:17:16 +0000</pubDate>
		<dc:creator>Giedrius</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.majauskas.com/?p=222</guid>
		<description><![CDATA[Savedefense is a skin of rogue parasite TrustNinja, whose family seems to use very strange names. It was released in the end of August and marks a start of new season of rogue parasites. Apparently, Personal Antivirus is no longer a trusted name, however the malware distribution method  used still works. The most likely place [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.majauskas.com%2Fbeware-of-savedefense"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.majauskas.com%2Fbeware-of-savedefense&amp;source=giedrius&amp;style=normal&amp;service=bit.ly&amp;service_api=R_6b70a2205c1a0ba9dbc37392e42c745d" height="61" width="50" /><br />
			</a>
		</div>
<p>Savedefense is a skin of rogue parasite <a href="http://www.2-viruses.com/remove-trustninja">TrustNinja</a>, whose family seems to use very strange names. It was released in the end of August and marks a start of new season of rogue parasites. Apparently, Personal Antivirus is no longer a trusted name, however the malware distribution method  used still works.</p>
<p>The most likely place for <a href="http://www.2-viruses.com/remove-safedefense">Savedefense</a> infection are fake &#8220;online antivirus scanners&#8221; and browser hijackers that pretend to scan your PC. You can not exit the site easily, as blocking alert is used to push a download at these clearly fake antispyware sites. After install, the Save Defense parasite will try to scan your PC again with even more parasites found, and then it will ask for registration key. Which has to be purchased at some rogue payment processor you have never heard about.</p>
<p>If you think the problems will end after paying for Savedefense or similar parasite, you are wrong. Firstly, Savedefense key will not like to work. Secondly, you will notice that your bank account is overcharged. So you should <a href="http://www.2-viruses.com/remove-safedefense">remove Safedefense</a> and not pay for this rogue and better invest in reputable anti-spyware software.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.majauskas.com/beware-of-savedefense/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>5 simple suggestions how to avoid site downtimes and minimize losses</title>
		<link>http://www.majauskas.com/5-simple-suggestions-how-to-avoid-site-downtimes-and-minimize-losses</link>
		<comments>http://www.majauskas.com/5-simple-suggestions-how-to-avoid-site-downtimes-and-minimize-losses#comments</comments>
		<pubDate>Thu, 20 Aug 2009 16:00:15 +0000</pubDate>
		<dc:creator>Giedrius</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.majauskas.com/?p=202</guid>
		<description><![CDATA[The biggest nightmare for me is having my websites inaccessible for public. This had happened in the past, and it will happen no matter how good your hosting or programmers are. There are many reasons: Bad code makes website database corrupt Database table went corrupt, or mysql is down Apache is down The whole server [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.majauskas.com%2F5-simple-suggestions-how-to-avoid-site-downtimes-and-minimize-losses"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.majauskas.com%2F5-simple-suggestions-how-to-avoid-site-downtimes-and-minimize-losses&amp;source=giedrius&amp;style=normal&amp;service=bit.ly&amp;service_api=R_6b70a2205c1a0ba9dbc37392e42c745d" height="61" width="50" /><br />
			</a>
		</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">The biggest nightmare for me is having my websites inaccessible for public. This had happened in the past, and it will happen no matter how good your hosting or programmers are. There are many reasons:</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Bad code makes website database corrupt</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Database table went corrupt, or mysql is down</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Apache is down</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">The whole server is down or compromised</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">You are in middle of DOS attack</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Your DNS servers are down or domain has expired</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">You forgot to pay for hosting or your hosting company has problems</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">And a lot of many other problems that you can’t imagine before seeing them happen.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Typically, these problems happen in middle of the night, on weekend and when you are not on PC. How to prepare for them?</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">1.<span style="white-space: pre;"> </span>Create a list of people that can bring your server up. That is you, your admins, maybe hosting company. It depends on your infrastructure. Also put down their phone numbers, contacts, working times.   Lots of time losses could be solved if the people working with websites would always know whom and how to contact. Make sure each of these people know how to solve common problems like restart the server or know whom to contact in cases they can’t do that.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">2.<span style="white-space: pre;"> </span>Use at least one monitoring service (like host-tracker.com, webmetrics, etc) or install 2 of monitoring softwares (like nagios) on your servers. If you got one server only, you have to rely on remote monitoring service. The problem is you have limited options on notifying someone from server that has high load or other heavy problems already. Your notification system should work if any of your servers is down. You can purchase a low-cost VDS server and run nagios from there if you got one server only. Check if your hosting company provides some monitoring, however you should implement some simple monitoring outside your hosting company  as well. Sometimes the hosting company goes down completely, although it is rare cases.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">3.<span style="white-space: pre;"> </span>SMS/pager notifications are the best way to be informed in my opinion and you should not rely too much on email notifications. There are some desktop applications as well.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">4.<span style="white-space: pre;"> </span>Consider hiring server administration from company rather than hiring single admin. Just make sure the company has couple admins and at any time during the day there is a person responsible that supervises servers. Hiring administrator is better when there are larger amount of servers and you can afford hiring more than one of them.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">5.<span style="white-space: pre;"> </span>Have a backup and worst case plan. What is worst case? Just imagine your hosting company went down. What would you do next? You should have backups in reliable place (like NAS) and alternatives for any companies you work with that are related to your hosting.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Anything else? Comment bellow.</div>
<p>The biggest nightmare for me is having my websites inaccessible for public. This had happened in the past, and it will happen no matter how good your hosting or programmers are. There are many reasons:</p>
<ul>
<li>Bad code makes website database corrupt</li>
<li>Database table went corrupt, or mysql is down</li>
<li>Apache is down</li>
<li>The whole server is down or compromised</li>
<li>You are in middle of DOS attack</li>
<li>Your DNS servers are down or domain has expired</li>
<li>You forgot to pay for hosting or your hosting company has problems</li>
<li>And a lot of many other problems that you can’t imagine before seeing them happen.</li>
</ul>
<p>Typically, these problems happen in middle of the night, on weekend and when you are not on PC. How to prepare for them?</p>
<ol>
<li>Create a list of people that can bring your server up. That is you, your admins, maybe hosting company. It depends on your infrastructure. Also put down their phone numbers, contacts, working times.   Lots of time losses could be solved if the people working with websites would always know whom and how to contact. Make sure each of these people know how to solve common problems like restart the server or know whom to contact in cases they can’t do that.</li>
<li>Use at least one monitoring service (like host-tracker.com, webmetrics, etc) or install 2 of monitoring softwares (like nagios) on your servers. If you got one server only, you have to rely on remote monitoring service. The problem is you have limited options on notifying someone from server that has high load or other heavy problems already. Your notification system should work if any of your servers is down. You can purchase a low-cost VDS server and run nagios from there if you got one server only. Check if your hosting company provides some monitoring, however you should implement some simple monitoring outside your hosting company  as well. Sometimes the hosting company goes down completely, although it is rare cases.</li>
<li>SMS/pager notifications are the best way to be informed in my opinion and you should not rely too much on email notifications. There are some desktop applications as well.</li>
<li>Consider hiring server administration from company rather than hiring single admin. Just make sure the company has couple admins and at any time during the day there is a person responsible that supervises servers. Hiring administrator is better when there are larger amount of servers and you can afford hiring more than one of them.</li>
<li>Have a backup and worst case plan. What is worst case? Just imagine your hosting company went down. What would you do next? You should have backups in reliable place (like NAS) and alternatives for any companies you work with that are related to your hosting.</li>
</ol>
<p>Anything else? Comment bellow.</p>
<div></div>
]]></content:encoded>
			<wfw:commentRss>http://www.majauskas.com/5-simple-suggestions-how-to-avoid-site-downtimes-and-minimize-losses/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AntivirusBEST &#8211; how to get it from your PC</title>
		<link>http://www.majauskas.com/antivirusbest-how-to-get-it-from-your-pc</link>
		<comments>http://www.majauskas.com/antivirusbest-how-to-get-it-from-your-pc#comments</comments>
		<pubDate>Mon, 29 Jun 2009 15:15:54 +0000</pubDate>
		<dc:creator>Giedrius</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.majauskas.com/?p=169</guid>
		<description><![CDATA[AntivirusBest is a scam &#8211; a parasite designated to capture your attention with multiple popups or fake security center alerts, and then convice you to pay for its full version. It is not different to other rogues from 2009 batch &#8211; that is it has no useful capabilities and only pretends to scan your PC [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.majauskas.com%2Fantivirusbest-how-to-get-it-from-your-pc"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.majauskas.com%2Fantivirusbest-how-to-get-it-from-your-pc&amp;source=giedrius&amp;style=normal&amp;service=bit.ly&amp;service_api=R_6b70a2205c1a0ba9dbc37392e42c745d" height="61" width="50" /><br />
			</a>
		</div>
<p><strong>AntivirusBest</strong> is a scam &#8211; a parasite designated to capture your attention with multiple popups or fake security center alerts, and then convice you to pay for its full version. It is not different to other rogues from 2009 batch &#8211; that is it has no useful capabilities and only pretends to scan your PC for infections. <a href="http://www.2-viruses.com/remove-antivirusbest"><img class="alignleft" title="AntivirusBEST Screenshot" src="http://www.2-viruses.com/wp-content/uploads/2009/06/antivirusbest-300x221.jpg" alt="" width="300" height="221" /></a></p>
<p>The main problem with <a href="http://www.2-viruses.com/remove-antivirusbest">AntivirusBest</a> is that you might get its popups without downloading anything intentionally. This is due to fact, that rogue parasites are spread with help of trojans or worms, that infect your PC or are hidden in some shareware, fake codecs or images. Removal of these parasites is tedious and most important fact, as they leave your computer exposed to more infections, like keyloggers, or other spyware. Thus seeing simple popups might be sign of bigger problems than simple AntivirusBEST rogue.</p>
<p>I recommend <a href="http://www.2-viruses.com/thank-you.html">spyware doctor</a> or malware bytes anti-malware for removing AntivirusBEST. These tools are reputable and will not damage your PC. Also, for more advanced users here are manual <a href="http://www.2-viruses.com/remove-antivirusbest">AntivirusBEST removal instructions</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.majauskas.com/antivirusbest-how-to-get-it-from-your-pc/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Contraviro &#8211; another rogue spyware parasite</title>
		<link>http://www.majauskas.com/contraviro-another-rogue-spyware-parasite</link>
		<comments>http://www.majauskas.com/contraviro-another-rogue-spyware-parasite#comments</comments>
		<pubDate>Fri, 26 Jun 2009 09:59:00 +0000</pubDate>
		<dc:creator>Giedrius</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[contraviro]]></category>

		<guid isPermaLink="false">http://www.majauskas.com/?p=162</guid>
		<description><![CDATA[Contraviro&#8230; does this name sounds familiar? Yeah, it is a slight variation of ContraVirus, a rogue active a year ago. It looks like Contra Viro method is timeless : push infections in fake video sites, or add a Trojan present to some crappy shareware. After that, wait push fake security alerts into the botnet of [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.majauskas.com%2Fcontraviro-another-rogue-spyware-parasite"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.majauskas.com%2Fcontraviro-another-rogue-spyware-parasite&amp;source=giedrius&amp;style=normal&amp;service=bit.ly&amp;service_api=R_6b70a2205c1a0ba9dbc37392e42c745d" height="61" width="50" /><br />
			</a>
		</div>
<p>Contraviro&#8230; does this name sounds familiar? Yeah, it is a slight variation of ContraVirus, a rogue active a year ago. It looks like <a href="http://www.2-spyware.com/remove-contraviro.html">Contra Viro</a> method is timeless : push infections in fake video sites, or add a Trojan present to some crappy shareware. After that, wait push fake security alerts into the botnet of infected PCs. Contraviro alerts will shows exaggerated reports of infections, or maybe some fake hacker attacks  that cannot be stoped unless you download and buy full version of  this scam.<img class="attachment-medium alignright" src="http://www.2-viruses.com/wp-content/uploads/2009/06/contraviro-300x239.jpg" alt="" width="300" height="239" /><br />
Funny enough, <a href="http://www.2-viruses.com/remove-contraviro">Contraviro</a> got &#8220;flexible&#8221; payment model as well. You may be charged for 50 or 100 dolars depending on the wish of these scam developers. Of cause, your credit card details will be sold further as well, so it is not so good idea to pay for this scamware. If you had, contact your bank and stop all charges for Rogue applications.</p>
<p>I recommend <a href="http://www.2-viruses.com/remove-contraviro">getting rid of Contraviro with these instructions</a> as soon as possible. Alerts promoting it shows that you already got an infection and that you should take care of your PC security. Failing to do so might lead to loss of sensitive information due to various spyware parasites that might be uploaded to your PC by creators of these parasites.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.majauskas.com/contraviro-another-rogue-spyware-parasite/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Privacy Center removal</title>
		<link>http://www.majauskas.com/privacy-center-removal</link>
		<comments>http://www.majauskas.com/privacy-center-removal#comments</comments>
		<pubDate>Wed, 22 Apr 2009 20:17:06 +0000</pubDate>
		<dc:creator>Giedrius</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[privacy center]]></category>
		<category><![CDATA[spyware]]></category>

		<guid isPermaLink="false">http://www.majauskas.com/?p=139</guid>
		<description><![CDATA[Privacy center is quite annoying piece of rogue anti-spyware programs because it uses multiple trojans for spreading around. The problem is, most of single removers fail to remove all versions of these Trojans now, as it is stated in comments of these Privacy Center removal tips.  Thus an infection might be a big problem.   [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.majauskas.com%2Fprivacy-center-removal"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.majauskas.com%2Fprivacy-center-removal&amp;source=giedrius&amp;style=normal&amp;service=bit.ly&amp;service_api=R_6b70a2205c1a0ba9dbc37392e42c745d" height="61" width="50" /><br />
			</a>
		</div>
<p>Privacy center is quite annoying piece of rogue anti-spyware programs because it uses multiple trojans for spreading around. The problem is, most of single removers fail to remove all versions of these Trojans now, as it is stated in comments of these <a href="http://www.2-viruses.com/remove-privacy-center">Privacy Center removal tips</a>.  Thus an infection might be a big problem.  <img class="alignright" style="-webkit-user-select: none;" src="http://www.2-viruses.com/wp-content/uploads/2009/03/privacycenter-300x216.jpg" alt="" width="300" height="216" /></p>
<p>So, how to deal with such infection like this one? I would use couple of tools to ensure one&#8217;s system is clean. First, I am recomending <a href="http://www.2-viruses.com/thank-you">Spyware Doctor</a> as primary spyware remover &#8211; it has quite big database and reliable detection scheme. Also, Spyware doctor should take care of parasites that block legitimate websites. However, it might miss some trojans, thus one needs alternative tool to detect left-overs. Leave Spyware Doctor real time protection running and download malwarebytes anti-malware ( <a href="http://www.malwarebytes.org/mbam.php">http://www.malwarebytes.org/mbam.php</a> ).  It allows free scan, though you would have to pay for real-time protection. This should take care of the rest.</p>
<p>Just remember, anti-spyware program alone can not provide 100% security of the system. You have to update windows and scan your PC with anti-spyware and anti-virus programs periodically. Also, a good firewall program like comodo firewall is strongly recommended to keep unwanted applications like Privacy Center out of your system.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.majauskas.com/privacy-center-removal/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New development in virus market &#8211; Conficker family</title>
		<link>http://www.majauskas.com/new-development-in-virus-market-conficker-family</link>
		<comments>http://www.majauskas.com/new-development-in-virus-market-conficker-family#comments</comments>
		<pubDate>Fri, 27 Mar 2009 12:17:39 +0000</pubDate>
		<dc:creator>Giedrius</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[conficker]]></category>

		<guid isPermaLink="false">http://www.majauskas.com/?p=115</guid>
		<description><![CDATA[Conficker (latest one is Conficker.C) is one of the few malwares nowdays that bring something new in the market that relies on new names and new skins only. The thing distinguishing it from crowd is unique registry modification scheme that makes its removal difficult for comon spyware removers. The trick used by Conficker.C is seting up [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.majauskas.com%2Fnew-development-in-virus-market-conficker-family"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.majauskas.com%2Fnew-development-in-virus-market-conficker-family&amp;source=giedrius&amp;style=normal&amp;service=bit.ly&amp;service_api=R_6b70a2205c1a0ba9dbc37392e42c745d" height="61" width="50" /><br />
			</a>
		</div>
<p>Conficker (latest one is Conficker.C) is one of the few malwares nowdays that bring something new in the market that relies on new names and new skins only. The thing distinguishing it from crowd is unique registry modification scheme that makes its removal difficult for comon spyware removers.</p>
<p>The trick used by Conficker.C is seting up registry permissions instead of inserting registry keys only. And you can not modify registry permission from the lowest leaf of affected tree &#8211; you need to traverse whole tree and start modifying it from top node. Thus removal instructions, just stating that you need removing single node  like</p>
<p>HKCUSoftwareMicrosoftWindowsCurrentVersionRun[Random String] = “rundll32.exe [Worm Executable], [Random String]”</p>
<p>are not fully correct. You need to check and fix the whole tree!.</p>
<p>There are couple dedicated tools that help you with removing Conficker and similar parasites. One of them is produced by <a href="http://www.enigmasoftware.com/a1/download/cfremover.exe">enigma software group &#8211; conficker remover</a>. Though I would suggest using complete spyware remover like <a href="http://www.majauskas.com/spdoc.exe">Spyware Doctor</a> or Malwarebytes Anti-Malware.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.majauskas.com/new-development-in-virus-market-conficker-family/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
