Showing posts with label Computer Bugs. Show all posts
Showing posts with label Computer Bugs. Show all posts

Saturday, 12 April 2014

SOS Heartbleed Bug

We use https sites for financial transactions, or the website automatically go to it's secure version with the padlock sign visible when we sign in our user name and password. For years we've been confident in using this secure connections and believing the entries we make are hidden away from prying eye's because it has been encrypted. Then the discovery of the heartbleed bug changes everything.

What is the Heartbleed bug?


Heartbleed is a flaw in OpenSSL, the open-source encryption that makes sensitive data into unreadable or scrambled state that is used by most websites. Example is when your transaction involves going into your bank account and you type in your user name and password. You might have already noticed that the site will change into https and a padlock sing appears at the top or at the bottom of a page. It is not only financial sites that support https connection, even  email or chatting on IM.

During the secured connection, the website and the server communicates and they check each other if they are still connected by sending a small packet of data(heartbeat) that asks for a response. 

The flaw or programming error on the OpenSSL can let a well-disguised packet of data originating from a hacker that looked very similar to these heartbeats to trick the server into sending data stored in its memory and viceversa. These data include user name and passwords, even credit card numbers. But the worst that can happen is when the encryption key is handed over. This is like the master key of all the encoded messages and data stored in the server and sites .

With the encryption keys handed in the wrong hands, secure or encrypted data will be readily available to read and with the correct credentials, it is possible that any account will be compromised. Adding to the worry is the attack is untraceable. And if these affected websites and servers do not change the encryption keys, even future accounts will still be susceptible to such attacks.

How Do You Know If You're Affected


66% of websites use OpenSSL including major sites include Facebook, Instagram, Tumblr, Google search, Gmail, Yahoo and Yahoo Mail, Netflix, YouTube, Amazon web services, Dropbox, and LastPass. So if you have accounts to these sites then you might have been affected. Banks and other sites that make financial transactions are most likely targeted by hackers. The widespread presence of the flaw is enough to be alarmed. Patch for the flaw is already available and has been implemented by the affected sites and servers. You can check if a certain site is still vulnerable to the flaw by going into the site below.


How To Protect Your Account


Change Password

The best way to protect your account is to change your password. It is recommended that you will only do this when the website (where you user name and password might be compromised) has already implemented the patch.  You can check this by going into the site above.

Check Your Financial Statements

As store websites are connected to your bank account or credit card company, the best way to know that somebody has been spending your money without your knowledge is to keep a closer look to your invoices and bank statements. Report any suspected transaction however little the amount is. 

Saturday, 14 September 2013

How To Remove the Stubborn "Registry Helper" Scareware

If you have tried removing the Registry Helper with the usual programs and features uninstall utility and was not successful then read on the rest of this post. I had the same problem and accidentally stumbled upon a solution within one of the files of the the program itself.

I was surprised this morning that my laptop screen greeted me with a not so good news. A program called registry helper is splashing a bad news that it has detected threats (Pic. 1) in my device. I was surprised, not because of the "detected" threats but the presence of the said program. I know that it is just one of the scarewares out there that mimics legitimate scanners but always shows scary results and asks you at the end to download another software to remove the threats. But do not fall for it because your laptop is fine and the program it wants you to download will only makes matters worst. 

Pic 1

Can't Remove it the Usual Way


I tried to remove it through programs and features (control panel, program and features) by highlighting the program and clicking uninstall. I thought it is gone but when I restarted my computer, the scary message still pops up. I checked the startup items (start, type msconfig, start up), and the registry helper is still on the list. I unticked it and restarted my computer. The message is gone but I am sure that the program or other parts of the program are still installed in my laptop.

I turned to google and followed a link that gave me these steps but did not worked for me. 

1. Click “Ctrl+Alt+Del” to open Windows Task Manager, and then stop all registry helper processes. 

Which registry helper processes? I do not know! It doesn't show me which processes.

2. Click “Start” button and select “Run”. Type “regedit” into the box and click “OK”. Delete the following file:

“HKEY_LOCAL_MACHINE\Software\Registry Helper.” Right-click this registry key and select “Delete.”

I could not see this value myself inside Software folder.

3. Navigate to directory %PROGRAM_FILES%\Registry Helper\ and delete the infected files manually.

"If you don’t have sufficient expertise in dealing with computer files, this may cause damage to your computer. So please be prudent during the whole removal process. Otherwise, why not use a virus removal tool to help you remove virus and optimize computer system automatically."

Although the warning is scary, I tried to do this. But every time I try it says that it is being used by another program, so I could not delete it.

I was stuck for a while on thinking of how to remove it. The name of the program is no longer listed at programs and features, because of the first uninstall attempt. But it is still in my system as it is still showing at the start up. 

Whilst inspecting the elements of the program, I came across it's un installation process (computer, system C:, program files(x86), Registry Helper, Help folder) that came with the package. It is just a matter of double clicking ! 

Pic 2


But how can I do that when it is no longer showing in the list of programs?

This might sound crazy but in order for the program to be on the list again is to download and install  it the second time from http://registry-helper.software.informer.com/!

Uninstalling Registry Helper


After installing it, the program's name is back on the list. The software comes with two more additional programs, the computer updater and disk cleaner. I know that they come with it because the installation time of the three softwares are at the same time.

Pic 3


To uninstall, just double click it! A dialogue pops up saying to close the program (this dialogue did not showed up using programs and features to uninstall). 

Pic 4

Whilst uninstalling, a dialogue shows and asking if I want to keep the settings of registry helper. I did chose No.

Pic 5

Once uninstalled, I also uninstalled computer updater and disk cleaner!

Pic 6

The scary pop up stopped showing after the restart!



Related Post

How not to get infected with scarewares


Wednesday, 12 June 2013

Problem Solver Recorder


Do you have computer problems, especially with windows operating system, that you would like to share to others and see if they have solutions? Long before, I tell my friends to use remote access programs, particularly team viewer, to see what's going on, and that's the method I did to resolve  a friend's monitor showing a rotated image. This is good but this includes, conversation  over the phone and a program to download for the other party.  Another method is to tell them to take screen shots and label as necessary on what's happening before sending it as an email. Both are time consuming and can delay the help they needed.

One thing I did not know is that there is a program within windows that can record exactly what you are doing and makes a screen shot with every mouse activity. This makes error reporting very easy and mess free. You do not need to do anything, or download any program to make a professional looking error reporting. Here's how to access it.

Enabling Problem Solver Recorder


I am using a Fujitsu windows 7 with this tutorial. 

Click start (1), type cmd (2) at the search window, press enter.  At the command console, type psr (3), then press enter. The PSR tool bar will appear.



Using PSR


Start Recording

It is so easy to use, just press the record button and it will start taking screen shots with every mouse activity and automatically write a narrative of what is happening. If you do not want to record a particular mouse activity, just press pause record and when you are ready, press the record button again.

I would recommended to close all windows except the one you are working on or thinking of recording it to lessen the confusion.




Stop and Save Recording


Clicking the stop button (1) would save your recording usually at the desktop on a zip folder. You can name (2) the folder anything you want but the file name within has a default name and can't be renamed.


Inside the zip folder(1) is the file name of the MHTML document(2). You do not need to unzip it like other zip files. just click it and it opens instantly. It can be emailed to a friend or to an IT support as an attachment. Just be sure to review your recording as it can record sensitive information through the screen shots. You can also review your screen shots as slide shows when previewing.


You can email the zip folder to your contact and the recipient can easily open it without any additional tool.

Click link below to view sample of  the recording using PSR.


This recorder can be used not only to ask for help, but to explain a user's activity without any sweat!

Saturday, 14 July 2012

How To Bank Online Securely

The internet has brought us many convenience in life like free communication and the ability to express ourselves freely. It automates our tasks and doesn't necessarily transact physically especially in the financial world. We can do most or all of the time consuming process online saving us time, effort and money!

But like any other useful tools, it can be a source of frustration as well, like loss of money online.  The good news is, there is a way to avoid this problem, as this requires at least a user input, like phishing, where the author redirects your click to a similar looking bogus site.  Phishing writers are innovative, they are many steps ahead of the ordinary users.

How can we outsmart them?

The coders can change a legitimate URL link to a rogue site that has been infected. Try clicking the examples below(don't worry, they are not redirected to infected or phishing sites). The same legitimate URL address   www.yahoo.com   but of different landing pages.


So which one gives you the real yahoo page?

If fact, it is so easy to fool ordinary users and one weapon we must have to defend us from this is a little knowledge of URL's, we must know the landing page before we click it. How?

1. Hover your mouse over the link in querry or any suspicious link and you can see at the bottom of your browser, the destination URL. If the destination URL does not make sense, then do not proceed to click. Or take step two.

Clicking the first address link above will redirect you to gmail.


Example1

A phishing attempt email from "Natwest". The email sender has a user name "Natwest". The email address doesn't make sense as the domain name is clara.co.uk, instead of natwest.co.uk or natwest.com. The content is way out from the legitimate email formats from natwest, and the url destination is very obvious it is not going to the bank's website.


Example 2

The second email (Abbey National, part of Santander Group) I received seems like coming from a legitimate email address and the author also provided a secured https address, hoping I will fall into his trap. But by hovering the mouse over the address reveals the destination page.


2. Scan site's URL.

There are also URL's that can hide their destination page, and URL's with long codes and short links as well. These can be legitimate or a dodgy site and you will not know until you have clicked the link, and your computer became infected or you have just provided the hackers your banking details before you've realised. Before you are tempted to click, you can check this with an online tool  at www.virustotal.com . Just click scan URL (to enable URL search, the default is file scan) to start with before you copy and paste the URL into the search window. Scanned below is the URL of the second email from "Santander's Abbey National".






The tool uses many anti-virus popular engines to do the scans like AVG, Bitdefender, Comodo , Sophos, Websense, and many more.

From the email link that has been scanned above, here's the result.


The scanning tool can be added to browsers like internet explorer, firefox and chrome. How ? Go to the site www.virustotal.com and click documentation, at the Browser Extension click Virus Total browser extension, choose your browser and add the virustotal tool extension.

Below is VTextension for Chrome.



Once installed, an icon appears at the top right portion of the browser.


To use it, right click a questionable or suspicious link and scan with virustotal.








google.com, pub-9356159227116695, DIRECT, f08c47fec0942fa0

ShareThis

Popular Posts