Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > General Computer Security
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


General Computer Security Get Help With System Security - This forum is not for malware removal assistance. For malware removal assistance, read the sticky topic at the top of the Virus/Trojan/Spyware Help forum, or the "First Steps" link at the top right of each page.

Reply
 
LinkBack Thread Tools
Old 04-12-2007, 07:04 PM   #1 (permalink)
Pog
Registered User
 
Join Date: Mar 2007
Posts: 10
OS: XP


Comodo/AVG Anti-Spyware, rootkits, and Avast

I have three questions:

1. In both the Comodo firewall and AVG Anti-Spyware among lists like ActiveX controls, startup items, and running processes they have these other lists like Network Monitor with all of these TCP/UDP etc. listings. The first three lists of course I'm familiar with and have tweaked when necessary, but since there is another list involving several other connections I'm assuming it's important enough to have to be tweaked, if necessary of course, and checked to see if things are the way they should be. How would I know if something is wrong in that list, like a connection that shouldn't be there? Is there anything that is to be checked and/or done in the network monitor or component manager to make sure their isn't any connection going to someone else's computer or if there are connections there that are vulnerable and unneeded?

2. Another involves rootkits. I'm very thorough when it comes to computer and internet security and since none of the major anti-virus or spyware programs have anything for rootkit detection, from what I could tell, I am wondering what is the best way to detect them? I have RootkitDetector but I really don't know at all how to tell what-is-what with the results. Is there any good guide out there about the detection and removal of rootkits?

3. I recently replaced AVG Free with Avast(at the suggestion of one of the HijackThis people) and I started running the scan but it was slow as molasses. Every other scanner I use whether on computer or internet is either half-way finished, close to finished, or entirely finished by the time it(Avast) is up to the 15,000'th file.
NOTE: I'm not saying I run them all at the same time, I'm just comparing how slow it is compared to others I've run.
Pog is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 04-17-2007, 09:51 AM   #2 (permalink)
Roaming To Help
 
Join Date: Nov 2006
Posts: 5,642
OS: Many


Quote:
Originally Posted by Pog View Post
How would I know if something is wrong in that list, like a connection that shouldn't be there? Is there anything that is to be checked and/or done in the network monitor or component manager to make sure their isn't any connection going to someone else's computer or if there are connections there that are vulnerable and unneeded?
Yes there is. They are the ports used for network access mainly;
TCP/IP enables two hosts to establish a connection and exchange streams of data and UDP/IP is a direct way to send and receive datagrams over an IP network - to/fro your computer. Here's a list of them and what is usually assigned to a port: http://en.wikipedia.org/wiki/List_of...P_port_numbers

TCP Port 80 is the typical WWW aka Internet connection port.

You can check TCP/UDP ports and their various accesses and uses by good/bad processes and services here: http://www.securitystats.com/tools/portsearch.php

Use TCPView (free), a simple small program used to enumerate all port process activities, connections and their states on your system. Very simple really and most of it is explained well on there. It captures real-time activity so you know what is going on by what and where.
Quote:
2. Another involves rootkits. I'm very thorough when it comes to computer and internet security and since none of the major anti-virus or spyware programs have anything for rootkit detection, from what I could tell, I am wondering what is the best way to detect them?

I have RootkitDetector but I really don't know at all how to tell what-is-what with the results. Is there any good guide out there about the detection and removal of rootkits?
Rootkits can be a little more complex than the other threats, especially given as the whole system can be under someone else's control. There are however many ways to find out, as Rootkits are a famous ever growing and complex threat; one of the main forms used by hackers to exploit systems nowadays.

If you want to take a shot at it yourself, the simplest I know:

First comes..
PC Safety and Security--What Do I Need?
How to prevent Rootkits

Then..
How to detect Rootkits
http://www.techsupportforum.com/secu...val-guide.html
How to deal with Rootkits
Recovering from Rootkits
Quote:
3. I recently replaced AVG Free with Avast(at the suggestion of one of the HijackThis people) and I started running the scan but it was slow as molasses. Every other scanner I use whether on computer or internet is either half-way finished, close to finished, or entirely finished by the time it(Avast) is up to the 15,000'th file.
NOTE: I'm not saying I run them all at the same time, I'm just comparing how slow it is compared to others I've run.
Depends what setting is chosen. If you have scanning of all drives, large folders/files, system restore, archives, media, compressed and encrypted files then it will take its time, be sure of that. The more data you have the longer the time taken. Drive and processor speed obviously makes a difference too, as well as what else you're running in the background.

Best practice is to boot into Safe Mode, disable network connections, close all the security software/processes that are not needed and run ONE security software at a time, like Avast!. Leave that running and go to bed.

Let it take its time, 6 hours isn't unusual at all.

I've used Avast! on my personal setups ever since I heard of it and was recommended it by the ASAP community veterans. Its been the best I've witnessed out there in terms of "all round" stability and efficiency. Even AVG and McAfee posed so many problems and hassles, though they are equally as effective. To each his own.
Kalim is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 05:22 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85