Infected Website protection...know of any?

Discussion in 'Software' started by LauraR, Jun 24, 2009.

  1. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    So here is my question...

    After two spammer infections just from clicking on a website link (one from a spammer here at MGs that I didn't know was spamrolleyes and the other a couple of days ago doing a search on google for a type of flower), I want to know if anyone knows of anything that would act as an additional barrier to all the other protection I have specifically while doing searches.

    Just to make it clear, I have all the MG recommended protection before someone who doesn't know me suggests the 'How to protect yourself' link. LOL (I have Comodo Firewall, Avira AV, Spysweeper Anti Malware (realtime), and Spybot and SAS for scanning)


    Obviously, ideally, you only want to go to websites you know, but if you are researching something that isn't always possible.

    I have no idea why my apps have failed me, but they have.

    I want something that maybe does a quick check of a website before you are allowed to click over to it....does some recon for you, I guess. I thought maybe there would be a FF addon that would do something like that, but didn't see anything.

    Any ideas?

    Or, maybe I need to switch from Spysweeper (which never failed me) to SAS full time. :(
     
  2. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member


    Nice...the AVG is just what I'm looking for (hopefully). I saw WOT on FF and wasn't too sure after reading some of the comments. I'm going to try AVG and see how it works.
     
  3. stevestrib

    stevestrib Private E-2

    AVG is pretty good. I've used it for years and never had any problem.
     
  4. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    Maybe I'll give that a try too.

    So they are ok together?

    Also, I downloaded the AVG toolbar in addition to linkscanner...was that really necessary or should I uninstall that part. I'm not a fan of toolbars and stay away from them generally.
     
  5. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    Thanks. What the heck, I'll live a little and give all three a try. :-D

    I'll report back on any probs if I have any. Thanks again DomLuc.
     
  6. dlb

    dlb MajorGeek

    I too have been hit by infected web sites (I call 'em "drive by's"). It only happened one time, but I was Googling for info about a certain video format and when I clicked the web site link, I was infected in under 3 seconds. Luckily, I recognized what was going on and I immediately shut down the PC, unplugged by ethernet cable, and restarted and was able to remove the infection. It was the infamous TDSSServ rootkit, and was a freakin nightmare, but I killed it. This was about a year ago, or more, and I've been looking for protection from this type of infection ever since. AVGs Link Scanner has rec'd bad press for slowing down one's surfing and for generating huge amounts of unneeded web traffic, and WOT has rec'd some bad reviews too, but, then again, everything will have its fans and detractors... I'll be watching this to see how the various options work out for Laura.... Good luck! :-D
     
  7. hrlow2

    hrlow2 MajorGeek

    Theres always the McAfee Site Advisor.
     
  8. greasemonkey

    greasemonkey Private First Class

    How about the idea of visualization?
    Sandboxie, geswall and the like?
    May not stop the malware from being downloaded, but, will prevent anything from actually infecting the rest of your machine.
    http://majorgeeks.com/Sandboxie_d4993.html
    http://www.gentlesecurity.com/

    Or even 'drop my rights' which lets you run your web browsers etc with limited user privileges thus malware can't install in the drive by fashion
    some good background on this here:
    http://cybercoyote.org/security/drop.shtml

    I know these are not quite what was being asked for in the first place, its just a different sort of approach to this 'drive by' style of infection...
     
  9. mimon

    mimon Private E-2

    I ran into one of those "drive by's "myself about a week ago from trying out a different proxy site than the one that i normally use,on account of the web site being down temporarily,(I use it to troll on a local forum that displays your ISP location)the page came up OK,pasted my link to they're URL tab,took me to the page,when all of a sudden this collage of loud blaring music started playing!!!,.. the Avast popped up and reported that the page was viral (i cant recall the name of it,it was an http something)and prompted me to abort the connection,which i did,the page disappeared but the music was still blaring, so then i tried to exit the browser(FF)and it didn't close ,so then i got to the task Mgr,which finally closed the page after a a couple of frantic attempts ,after which immediately i scheduled a boot scan that came back clean,I still wasn't sure about it, so i performed a real time full scan that showed no infections, but the point is that spyblaster & spybot really let me down ,I just installed the link scanner that Dom suggested to Laura,but without the toolbar,although it says that I'm protected,..so i think that it still runs without the toolbar,the only thing that i have to do manually is to paste a link on the interface to pre'check it if i want to before i link to it .
    Thanks for the tip Domluc

    mimon
     
  10. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    Well, unless it tends to slow down with time, so far, initially, I'm not seeing any lag. We'll see, I guess. The toolbar, as far as I can see, is through Yahoo and basically only displays 'safe sites' in your search. Not sure how much I'll use that. I"m a creature of habit and I prefer google. Besides, I'm not sure how thorough a 'safe search' is.

    The sandboxie idea isn't horrible, gm, but one that is a bit more cumbersome. If I have anymore problems, I may go that route though. Thanks for the ideas.
     
    Last edited: Jun 24, 2009
  11. greasemonkey

    greasemonkey Private First Class

    I don't think much of Sandboxie myself, but, was pleasantly surprised with Geswall's usability...

    Drop my rights is probably the most lightweight idea as a means of protection, but not without its quirks either.

    Or...
    Have you thought of No-script as a browser addon?
    where you only allow scripts to run from trusted sites.

    http://noscript.net/
     
  12. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    Drop my rights and no script (which I saw earlier over at FF) would be last resorts for me. I'm looking for the least amount of involvement on my part. :-D I'm really not a high risk internet user (I"m pretty boring actually :-D) so I'm hoping these will be enough.

    I have to say though, after I read dlb's response about getting hit while doing a search on a type of file, that rung a bell. I thought it was my search I was doing on a type of flower (see??? so dangerous LOL) but I think I was looking up a type of file a friend had asked about when I got hit.
     
  13. augiedoggie

    augiedoggie The Canadian Loon - LocoAugie (R.I.P. 2012)

    Good thread. I'll have to read up on the links provided but from what I understand, any legit site can be affected by these 'drive-by's, correct?

    @mimon Totally off topic, that is a great album! Happened to listen to it today.:)
     
  14. greasemonkey

    greasemonkey Private First Class

    My understanding is yes, any site can be hacked & or compromised, but, I guess a lot depends on how tight their security is.
    Smaller sites aren't as likely to have as many security measures in place and thus easier targets
     
  15. Buck_nekid

    Buck_nekid Specialist

    The only problem I can see with all the link scanners, WOT, spyware blaster, spybot immunization is that 'bad guys' can stay a step ahead at any given second. It doesn't take much to register a domain and start it all over again. With spybot it takes until Wendsday to get protected, WOT relies on the people using it (I think) etc, etc I think you get my drift.
     
  16. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    Which brings up the question of how these apps work that I installed. Are they going by how trusted a website is or are they actually prescanning the site? Even if it's the former, it adds value, but the latter would be preferable.


    Nothing is perfect. I'm aware that ultimately it's what I click on. I just want something that is a bit more than what I have.
     
  17. greasemonkey

    greasemonkey Private First Class

    Very true, hence the suggestions I put out there;)

    Check out geswall, its better than you may think
     
  18. studiot

    studiot MajorGeek

  19. augiedoggie

    augiedoggie The Canadian Loon - LocoAugie (R.I.P. 2012)

    Ya OK, but one needs ample CPU and RAM for that. I'm running VMWare now though with Ubuntu on there. Let's call it a dual CPU and 2 gigs, many don't have that option but you do make sense as everything's isolated.
     
  20. studiot

    studiot MajorGeek

    I thought Laura had a posh new PC.

    Sorry If I'm wrong.

    I think Windows 7 will have this anyway.

    ?Halo?
     
  21. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    lol...Laura Wants a posh new pc. :-D That won't be happening until Windows 7.

    Right now I"m running XP.


     
  22. studiot

    studiot MajorGeek

    Microsoft has promised Christmas will come early this year (October).

    roflmao
     
  23. hrlow2

    hrlow2 MajorGeek

    to studiot
    In regards to your post #24 regarding a virtual machine, I think #13 could cover that.
     
  24. greasemonkey

    greasemonkey Private First Class

    Ha, but I called it visualization... any friendly mods want to correct that for me? :-o
    I did mean virtualization... really, honest... :innocent
     
  25. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    Well, here's my follow up reply....


    after using both WOT and AVG safe search, I have not noticed any significant slow down. It's nice have the symbols on the search links as to whether the site is deemed safe. Sometimes they do differ.

    I haven't had any infections, but I really don't perform questionable searches.

    All in all it's seemed to work out.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds