Q. I am a subscriber to Norton AntiVirus and Norton SystemWorks and received a recent message that I need to renew. My Internet connection is through Comcast, and recently we were given free McAfee AntiVirus protection.
Is it good to have two antivirus programs, or should I just go with the free one from Comcast?
Fred [email protected]
A. Not only are two antivirus programs on the same machine not necessary, it is better to remove one of them to avoid potential conflicts as each attempts to do things like quarantine evil-looking stuff or make changes in the system registry.
Symantec Corp., maker of Norton, and McAfee Inc. are big players with staffs of experts who almost always find and fix most of the same viruses by letting users download updates of virus definitions. They also watch each other’s work in real time so if Symantec finds something, the McAfee makers will do their own finding and fixing of the same gremlin.
Further assuring that all makers of antivirus fixes are on the same page is an effort by Carnegie Mellon University called the Computer Emergency Response Team that runs a Web site describing new viruses as they are discovered by uncounted numbers of security watchers.
It’s become something of an underground of good guys and is well worth checking out at www.cert.org.
Q. If you go to Symantic.com instead of Symantec.com, you get something that appears similar but very different. At Symantic.com you get to a Web site called ErrorSafe.com. ErrorSafe offers to scan your computer for threats and viruses, provides a diagnosis and offers a program for $39.95.
Once I realized where I was, but after the free scan, I exited out of the Web site. I found the ErrorSafe program on my computer and uninstalled it. I launched Microsoft AntiSpyware and found two spyware programs associated with ErrorSafe–Winfixer and ABCScrabble. The Winfixer carried a high threat level, and ABCScrabble carried an elevated threat level. I deleted both.
What is the story with Symantic vs. Symantec?
Bill Barker @comcast.net
More Top Picks Best Tinted Glasses For Photophobia
A. You have encountered one of the nastier Web sites based on a strategy called phishing (pronounced “fishing”). Phishers prey on Web users by acquiring Web addresses that have names close to a major site. The scams range from Citibank to Lloyds of London, from America Online to Microsoft, and other Fortune 500 outfits.
Phishers count on people misspelling words in a Web address or hitting the wrong key while hurriedly typing in an address, as you probably did when you hit “i” instead of the “e” in the address of Symantec, the largest seller of antivirus software.
Another phishing tactic is to send waves of spam e-mails that include links to a phishing site that is made up to closely resemble the real thing.
Reader alert: Just going to Symantic.com can cause a blitz of sudden pop-ups, ads and numerous Web sites. The trick is to sell people what they think is virus-fighting software but includes a license to allow the phishers to add spyware to the user’s computer.
This stuff can be things like keyboard loggers that record every keystroke on a victim’s keyboard to ferret out personal information, or it can be schemes called scrapers in which the spyware grabs a picture of an entire screen and sends it along to disclose everything printed on that page.
This type of scheme is considered by some analysts to be the most dangerous of attacks on ordinary Web users, and it will surprise no one that the number of booby-trapped addresses continues to grow.
If you want to read more, there are documents on the Anti-Phishing Work Group site (www.antiphishing.org). The site offers essays describing various schemes of what is called crimeware or malware and is filled with bar charts and pie graphs showing numbers of schemers, numbers of victims, most affected countries and much other fascinating stuff.
But the main lesson here beyond watching your spelling is to never click on hotlinks in e-mail from strangers and to take precautions like double-checking the spelling of the address of any site where one does business that involves filling out forms or sending e-mail replies.
The address of the site you are on appears in the address bar at the top of all Web browsers and should be checked whenever doing business.
Q. Each time I turn on my computer, my screen shows a logo named Rundll and asks me to respond OK. How might I correct this?
The message: “Error loading C:
Program Files
wild tangent
apps
cda
cda engine 0400.D22. The specified module could not be found.”
I do not know how to delete this. Any suggestions?
Donald Brown @aol.com
A. Your note is quite calm compared with the waves of other victims of what appears to be poor programming by a Web-game-playing service called Wild Tangent Inc.
The company has responded to the howls of complaint by assuring callers that there is no spyware involved, just software glitches in something called a Web driver designed to facilitate online-game playing.
Adding to the displeasure is that the glitch you have can be fixed only by uninstalling the software, and that is nasty business because the necessary steps to fix it are terribly complicated. They involve making a large number of changes to the Windows registry and are posted at this address: http://support.wildgames.com/uninstall.html
———-
Contact Jim Coates via e-mail at [email protected] or via snail mail at the baiduhai, Room 400, 435 N. Michigan Ave., Chicago IL 60611. Questions can be answered only through this column. Add your point of view at chicagotribune.com/askjim.