Documente Academic
Documente Profesional
Documente Cultură
Antiviruses
Module 3
Simplifying Security.
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
3March2011,Thursday
MarketforAntivirusBecomingAggressiveinNorthITMarket
Theneedforprotectingvaluabledatapushingthedemandforantivirusproductsin
Northernregion.
Withexplosionintheuseofnetworksandalsoincreaseduseofinternethasdefinitelycreatedanew
conduitforcomputervirusestospreadatarapidrate.Earliervirusesusedexecutablefilesandwould
typicallybenomorethananannoyancebydisplayingharmlessphrases.Thelatestvirusesaremuch
moresophisticatedandabletocauseextensiveandirreparabledamagetofiles.Somevirusesare
abletospreadthemselvestoothercomputersontheInternetornetworkcausingwidespread
damagetomanysystems.Thustocounterattack
theseproblemsandtokeepupwiththe
accompanyingriseofmaliciouswebactivitya
numberofvendorsarebusyrollingoutlayers
ofupdatesofAntivirus.WeatITPV,contemplatedintheNorthernregionabouthowtheAntivirus
vendorsaredoing,whatisthedemand,whichsegmentisboomingandwhatsthefutureofthis
technology.
http://www.itvarnews.net
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Module Objectives
TheMostDangerousComputer
VirusesofAllTime
HowtoTestifAntivirusis
Working?
IntroductiontoAntivirusSoftware
ChoosingtheBestAntivirus
Software
HowDoesAntivirusSoftware
Work?
ConfiguringMcAfeeAntivirus
AntivirusSoftware2011
ConfiguringKasperskyPURE
StepstoInstallAntivirusonYour
Computer
AntivirusSecurityChecklist
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Module Flow
Introduction
toAntivirus
Software
HowDoes
Antivirus
SoftwareWork?
Stepsto
Install
Antivirus
Choosingthe
BestAntivirus
Software
Configuring
McAfee
Antivirus
Configuring
Kaspersky
PURE
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Blaster(2003)
EstimatedDamage:20to80milliondollarsworldwide,
countlessamountsofPCdatadestroyed.Unleashed
fromTaiwaninJuneof1998
EstimatedDamage:2to10billiondollars,hundredsof
thousandsofinfectedPCs
Melissa(1999)
EstimatedDamage:5to10billiondollars,over1million
PCsinfected
Sobig.F(2003)
EstimatedDamage:300to600milliondollars
ILOVEYOU(2000)
Bagle(2004)
EstimatedDamage:10to15billiondollars
CodeRed(2001)
EstimatedDamage:Tensofmillionsofdollarsand
counting
EstimatedDamage:2billionand600milliondollars
(2.6B$)
MyDoom(2004)
EstimatedDamage:Atitspeak,slowedglobalInternet
performanceby10percentandWebloadtimesbyupto
50percent
SQLSlammer(2003)
EstimatedDamage:BecauseSQLSlammereruptedona
Saturday,thedamagewaslowindollarsandcents.
However,ithit500,000serversworldwideandactually
shutdownSouthKoreasonlinecapacityfor12hours
Sasser(2004)
EstimatedDamage:Tensofmillionsofdollars
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
WhenaPCisconnectedtotheInternet,the
PChastocombatdifferentmaliciousprograms
suchasviruses,worms,Trojans,spyware,
adware
Cybercriminalssuchasattackersandhackersuse
thesemaliciousprogramsastoolstosteal
importantinformationsuchaspersonaldata
storedonthecomputer
Theseprogramsposeaseverethreattothe
computerandmaydestroyitsfunctionalityin
differentways
MaliciousprogramspavetheirwayintoonesPC
throughemailattachmentsandspamemail,
throughUSBdrives,visitingafraudulentwebsite,
etc.
Duetotheinvasionofmaliciousprograms
incyberspace,antivirusprogramshave
becomenecessaryforcomputers
Ifyourcomputerhasagoodantivirusprograminstalled,thenthePCisprotectedandcombatall
typesofmaliciousprograms
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Module Flow
Introduction
toAntivirus
Software
HowDoes
Antivirus
SoftwareWork?
Choosingthe
BestAntivirus
Software
Stepsto
Install
Antivirus
Configuring
McAfee
Antivirus
Configuring
Kaspersky
PURE
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Virus Dictionary
Approach
Suspicious Behavior
Approach
Whileexaminingthefilesthe
antivirussoftwarerefersto
thedictionaryofknown
virusesidentifiedbythe
authorofantivirussoftware
Theantivirussoftware
monitorsthebehaviorofall
theprogramsinsteadof
identifyingtheknownviruses
Ifabitofcodeinthefile
matcheswiththatofany
virusinthedictionary,then
theantivirussoftwarecan
eitherdeletethefile,repair
thefilebyremovingthevirus,
orquarantineit
Wheneveraprogramwith
suspiciousbehaviorisfound
thesoftwarealertstheuser
andaskswhattodo
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
http://www.mcafee.com
http://free.avg.com
http://www.symantec.com
http://www.avast.com
http://www.kaspersky.com
http://www.vipreantivirus.com
http://www.comodo.com
http://www.bitdefender.com
http://www.pctools.com
http://www.eccouncil.org
10
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Module Flow
Introduction
toAntivirus
Software
HowDoes
Antivirus
SoftwareWork?
Choosingthe
BestAntivirus
Software
Stepsto
Install
Antivirus
Configuring
McAfee
Antivirus
Configuring
Kaspersky
PURE
11
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
ScanningSpeed
Checkwhethertheantivirussoftwarecanperformthe
taskquicklyandefficiently
ResourceUtilization
Ensurethattheantivirussoftwareusesminimal
systemresourcesanddoesnotaffectsystem
performancewhenperformingascan
12
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
BidirectionalFirewall
AutomaticUpdates
Checkwhethertheantivirussoftwareisequipped
withasoftwarefirewallornottoscantheboth
incomingandoutgoingtraffic
Thisfeaturekeepstheuserabreast
ofthelatestonlinethreatswithout
theuserhavingtovisitthevendors
websitetostayuptodate
TechnicalSupport
Lookforgoodtechnicalsupportso
thatissuesaresolvedeasily
SpywareDetection&
Prevention
ParentalControls
Checkforantispyware
componentstokeepspywareat
bay
Checkfortheparentalcontrolfeaturein
theantivirusprogramthathelpschildren
browsetheInternetsafely
EmailScanning
EasyInstallation(andEasytoUse)
EmailProtectioncanmonitorPOP
andSMTPportsandensuresthat
yourcomputerdoesn'tcontaina
threattoyourcomputer
Theantivirussoftwareshouldbeuserfriendly
andeasytouse
OnDemandandScheduledScanning
Thisoptionsletsyouscheduleascanaccordingtouser
specifiedtime.Userschedulethescandaily,weeklyor
monthly
13
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Module Flow
Introduction
toAntivirus
Software
HowDoes
Antivirus
SoftwareWork?
Choosingthe
BestAntivirus
Software
Stepsto
Install
Antivirus
Configuring
McAfee
Antivirus
Configuring
Kaspersky
PURE
14
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Mostoftheantivirusesfollowawizarddriveninstallationprocess
andnecessarycomponentsareinstalledinthesystembydefault
Downloadtheantivirusandlaunchtheinstallationof
antivirusbydoubleclickingthesetupfile
Agreetothelegalagreementthatmightappear,click"Iagree",and
thenclick"Next"tocontinue
Reviewallthesettingsandclicknextuntilinstallationisfinished
Oncetheinstallationprocessisfinished,restartyourcomputer
15
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Openanotepadandcopythefollowingcodeontoit,andsavethenotepad.
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICARSTANDARDANTIVIRUSTESTFILE!$H+H*
2.
RenamethefilefromNewTextDocument.TXTtomyfile.com
3.
Runtheantivirusscanonthismyfile.com file
4.
Iftheantivirusisfunctioningproperly,itgeneratesawarningandimmediatelydeletesthefile
Note:Mostantiviruswilldisplayawarningmessageinstep1
16
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Module Flow
Introduction
toAntivirus
Software
HowDoes
Antivirus
SoftwareWork?
Choosingthe
BestAntivirus
Software
Stepsto
Install
Antivirus
Configuring
McAfee
Antivirus
Configuring
Kaspersky
PURE
17
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
OntheMainSecurityCenterConsole click
RealtimeScanning select ScanyourPC
18
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
AfterselectingtheScheduleScanSettingsoption
RealtimeScanningSettings selectthefiletypes,
attachments,andlocationsthatyouwanttheantivirus
toautomaticallyscanandprotectthecomputerfrom
threats clickApply
19
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Module Flow
Introduction
toAntivirus
Software
HowDoes
Antivirus
SoftwareWork?
Choosingthe
BestAntivirus
Software
Stepsto
Install
Antivirus
Configuring
McAfee
Antivirus
Configuring
Kaspersky
PURE
20
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Youcan:
ActivateCommercialLicense withthepurchasedactivation
code
ActivateTrialVersion forthetrialperiodof 30 daysandget
acquaintedwiththepossibilitiesoftheprogram
ActivateLater, ifyouselect activatelater,thestage
of KasperskyPURE activationwillbeskipped.Theapplication
willbeinstalledonyourcomputer,butyouwillbeableto
updatetheapplicationonlyonceafteritsinstallation.
Tocontinuetheactivationprocess,clickNext
Afterthelicenseisactivated,clickNext toproceedwiththe
configuration
21
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Step2: Systemanalysis
The InstallationWizard analyzesthe
systeminformationandcreatesrules
fortrustedapplicationsthatare
includedintheWindowsoperating
system.Waituntiltheprocessis
completed.
22
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
23
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
24
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
25
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
26
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
27
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
28
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
29
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
30
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Module Summary
Anantivirusprogramprotectsacomputeragainstviruses,worms,spywares,andTrojans
AcomputerconnectedtotheInternetisalwaysathighriskanditisrecommendedtohave
antivirussoftwareinstalledonthesystem
Mostofthecommercialantivirussoftwareusestwotechniques:
Usesvirusdictionarytolookforknownviruseswhileexaminingfiles
Detectssuspiciousbehaviorfromanycomputerprogram
Inthevirusdictionaryapproach,whileexaminingthefiles,theantivirussoftwarerefersto
thedictionaryofknownvirusesidentifiedbythesoftwareauthor
Wheneveraprogramwithsuspiciousbehaviorisfound,theantivirussoftwarealertsthe
userandaskswhattodo
31
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.
Alwaysschedulescanning
32
CopyrightbyEC-Council
AllRightsReserved.ReproductionisStrictlyProhibited.