Wednesday, June 15, 2016

Use System Restore to Fix Your Windows Computer

Use System Restore to Fix Your Windows Computer

There are plenty of glitches that can plague our Windows computers, malware being just one. Programs break, drivers break, we users make unhelpful changes, etc. 

System Restore - the magic undo
The good news? There is a magic “undo” feature in Microsoft Windows – it’s called System Restore. It’s bailed me and my clients out of difficulties many times. And when you've been hit by malware you can use this to repair your computer before removing the infections with a security scanner. 

If you’ve used System Restore, you may recall your delight when it did its magic. If it’s new to you, let me explain.

A simple approach
Of course there are more detailed ways of diagnosing and remedying hardware and software problems, including malware infections. But if things were fine one day, and the next they’re not - and you don’t recall changing anything - System Restore is a handy tool.

To use it, locate the Run box after clicking your Start button (Windows 7), or type Run in the Windows search box (Windows 8 or 10). Then in the Run box type rstrui.exe, then click OK.

No change to data - but back up anyway
System Restore will launch. Click Next, then locate a recent restore point prior to the day you started having issues. Note: any programs or updates you installed after that date will be removed, but none of your data will be changed. (Nonetheless, it’s best to back up important data before running System Restore.)

Before running System Restore, close all open programs and save all work. Allow anywhere from 5-15 minutes for the Restore process.  

The computer will reboot and present your Windows login screen, and report whether System Restore succeeded or failed.

Creating a Restore Point
A proactive approach to take with System Restore is to set a Restore Point when things are working well. Open the Control Panel, then type Restore in the Search box. Then select Create a restore point. Choose your Windows drive (usually C). Then click Create and name the Restore Point.

Once this Point is created, you can roll back to this in the future should your computer be throwing a fit. (If it’s throwing a big fit, you may have to run System Restore from the command prompt in Safe Mode, but that’s another story.)

Deeper malware removal
If you're running System Restore to aid in malware removal, after Restore is done, go to your Programs in the Control Panel and remove any suspicious characters, sorting by date - a clue being programs you didn't intend to install. 

Then run malware removal scans by using programs like Malwarebytes. 

Restore doesn’t fix all problems, but it’s an easy “go-to” when you want a quick return to smoothing sailing after rough waters.   

Thanks for reading.
Sam

---
If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send. 



Sunday, May 15, 2016

Where's Your Data Stored?

Where's Your Data stored?

I'd like to pose a question we should be asking ourselves often in this modern digital world: Where's my data?

Where is your data?
These days a person may own a computer, a smartphone, a tablet, and other Internet-connecting gadgets like a smartwatch. Each of these devices collects data we put into them, and data they gather about us. Here I'll focus on one set of important data we input: Personally Identifying Information (PII).

What is Personally Identifying Information (PII)?
PII can include your name, social security number (SSN), date and place of birth, mother's maiden name, etc. It can also relate to your unique medical, educational, financial, or employment information. PII can be exploited for identity theft and other crimes.

Know where your PII is stored. For example, do you keep your SSN, or those of family members, on your phone in the Contacts or in a notes app? This may be convenient, but it's risky. If someone steals your phone, or hacks it, the PII is exploitable.

So after answering the "Where's my data?" question, the follow up should be: "Is it safe there?"

Is your data safe there?
In the example of a smartphone, is yours password protected? Is it encrypted? If the answer is no, no, then do not store PII on the phone. If you are using an app like Lastpass on your phone to store PII, this app's vault encrypts the data. This is good protection, but still password-protect and encrypt your phone. Nothing is 100% secure.   

What if… your phone is lost or stolen?
The third data risk question to ask is: "What if?" For example, ask yourself, "What if my phone is lost or stolen?" Have a protocol you can follow quickly to minimize the potential for information theft, the first step being locating the phone and trying a remote wipe. 

If that isn't effective, then consider all apps and accounts you save on the phone that are password-linked and change those passwords on the website for those apps and accounts immediately! (If you haven’t done so already, make complex and unique passwords for each of those accounts.)

Don't keep any PII on a portable device
To err on the side of paranoia, don't keep any PII on a portable device, or for that matter any info that you don't want going public. Take measures to protect what’s most precious. 

Thanks for reading.
Sam

---
If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send. 


Friday, April 15, 2016

3 Steps to Reduce Computer Crisis Stress

3 Steps to Reduce Computer Crisis Stress

There are 3 steps you can take to reduce stress related to a computer crisis. 

By computer crisis I mean a situation where the computer is running very poorly, or may be infected by malware (annoying popups), or may have a hardware part failing (odd noises), or worse yet has crashed and won't restart. 

Be proactive! 

Do these 3 things to reduce your stress when the inevitable happens... 

  • Make regular backups of critical data - locally and offsite. For local backup you can use a USB drive. For offsite, I recommend Mozy.com. Worst case, if your computer fails or is hit by damaging malware (such as ransomware), at least you will have your data available to restore when the crisis is resolved. Note: You will need an offsite backup solution to recover from a ransomware attack because this kind of attack can encrypt even your local backup. 
  • Deal with the problem promptly. When the computer starts to act up, if you can't fix it, get help asap. Putting it off usually only makes things worse. It's the same as was when you hear an odd noise coming from your car's engine compartment. Better not ignore that one!
  • Do regular maintenance. This means installing important updates for all software, and doing tune-ups and clean-ups. Also run security software scans regularly. For businesses, I recommend scheduling maintenance at least quarterly, or having someone in-house be tasked to do it. For home users, do maintenance at least 2x/year. 
As the old adage goes, an ounce of prevention is worth a pound of cure. 

It's also a risk tolerance issue: ask yourself how comfortable you are risking a computer failure that could ruin your day. 

Thanks for reading.
Sam

---
If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send. 

Monday, March 14, 2016

Do Not Run Your Computer as Administrator

Do Not Run Your Computer as Administrator

I came across a recent study that reinforced why I recommend to my clients that they not use their computer logged in with administrator privileges. 

The study revealed that of the 251 vulnerabilities in Microsoft's Patch
Tuesday security bulletins in 2015 with a critical rating, 85% were concluded to be mitigated by removing administrator privileges.

The primary benefit of running in Standard user-level privilege instead is that programs which try to install without your permission/involvement cannot do so unless you provide the administrator password. This includes malware. 

This approach is also beneficial if you're sharing a home computer with kids - the last thing you want is them installing programs without your supervision. (And it's best to have parental controls running on their accounts too.)

The administrator account does not need to be named Administrator. It can be named whatever you like: Master, Admin, Big Kahuna, Sky Lord, whatever. But it needs to be the only account on the computer with administrator privileges. 

When setting this account up, choose a password that only you or another trusted person knows. 

After creating the new administrator-level account, log off the computer and try to log in with that account. Verify in Settings or the Control Panel that the account in fact has administrator privileges. This is very important! 

It's critical because in the next step you will demote any other administrator-level accounts. Once you do so, they will no longer have administrator control. If you didn't give the new account administrator privileges, you won't be able to "administrate" your computer. Not good!

The next step is to demote all other users to Standard user level. I've provided links at the bottom for Widows 7, 8, and 10. Select a desired user and change to Standard. Then log off the computer and log in again as that user, just to test the user can still log in.

You will notice a change on the computer after doing this: If you try to install software or make system-wide changes as a Standard user, you'll be prompted for the administrator password. 

Again, this is a best practice for computer security. It applies to Windows computers, Apple computers, and Linux (in Linux, administrator is called root.)

Thanks for reading.
Sam

---
If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send. 

Thanks for reading.
Sam

---

Links for changing account types

Windows 7
http://www.sevenforums.com/tutorials/103538-user-account-type-change.html

Windows 8
http://www.eightforums.com/tutorials/5518-user-account-type-change-windows-8-a.html

Windows 10
http://www.tenforums.com/tutorials/6917-account-type-change-windows-10-a.html

Friday, March 11, 2016

GWX means Get Windows 10 - And Yes, You Still Have A Choice - Resistance Is Not Futile

GWX means Get Windows 10 - And Yes, You Still Have A Choice
Resistance Is Not Futile

Way back in June of last year I posted a piece titled "Windows 10 - Upgrade Optional, Can Wait And See." You can see it here

The clock starts ticking
My post was written in midst of the buzz around Microsoft trumpeting the official release of their latest operating system - Windows 10 - and how they were graciously offering it as a free download to existing customers, beginning July 29, 2015. (You could upgrade as long as you were running Windows 7 or 8.1, that is.)

Many early adopters jumped on the bandwagon. Some had problems, some didn't. Some were impressed, some weren't. Most organizations wisely didn't bite the hook - they played the wait and see game. (This is mainly because they have much more to lose if new software doesn't play nice on their systems.)

Pushing the product
Microsoft has been pushing the Windows 10 upgrade pretty aggressively ever since that hallowed day last July. One of their main tactics to influence users is to run a little icon in the system tray at lower right, tempting one to install the upgrade. 

Fiasco
One of my clients felt so pestered by this icon that she did the install. Sadly, it didn't go well. I had to spend hours afterwards making things right, including calling Microsoft tech support to get the upgrade to recognize her previous Windows license, which it should do seamlessly. What a fiasco! And it cost her money, i.e., my time. 

On the other hand, after due consideration to hardware and software versions, and to appease the desires of certain clients, I've installed the Windows 10 upgrade on several computers, upgrading from Windows 7 or 8.1, and haven't had any issues. This I've done on my home systems too - my version of beta testing.

Businesses, be careful
But again, for organizations, especially those which may have legacy (older) programs or equipment, the last thing they need is the headache of dealing with a post-Windows 10 upgrade snafu. 

Blocking the upgrade
If you want to play it safe and prevent the pernicious little GWX (Get Windows 10) agent from harassing you, you can do this: Install a free program named GWX Control Panel. I've been successfully doing this for many of my business clients. (After all, we want do the upgrade on our terms, not because Microsoft is bugging us.) You can get this program here

Privacy concerns
If, however, you do take the leap and upgrade to Windows 10, and you are satisfied with the upgrade (you can always roll back if not, at least for short period of time), I suggest you check out the default privacy settings. These are disconcerting to me, because they give too much information and control Microsoft and its bevy of installed apps. I suggest you turn off all the privacy slider bars that concern you.

To see the privacy settings in Windows 10, click the Start button, then PC Settings, then Privacy. You can go item by item and turn off whatever you don't feel comfortable giving Windows access too. If you turn off anything that disables another program, such as Skype, you can always turn it back on. I have turned off everything with no ill effect.  

Upgrade deadline
A last word: The latest news is that Microsoft is providing the Windows 10 upgrade for free until July, 29, 2016. If you want to upgrade after then, you may have purchase Windows 10 from the Windows Store, likely for over $100. 

My suspicion is that Microsoft will somehow extend the free offer. They really want the entire Milky Way Galaxy to migrate to Windows 10 so they can better monitor people's computers and "provide what consumers want" from the "mother ship" in Redmond. Those privacy settings mentioned above have a lot to do with revenue streams collected from being in "close" (i.e. creepy) partnership with you as long as you are online.

---
If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send. 

Thanks for reading.
Sam

Wednesday, February 24, 2016

Ransomware Attacks Are On The Rise

Ransomware attacks are on the rise


One of the latest ploys cybercrooks are using is to lock up your computer, or the files on it, and demand payment to re-enable access.
Via links in emails or website scams, the crooks trick computer users to install software that encrypts all or parts of a computer's files. The only way to decrypt is to pay a ransom demanded by the perpetrators.  
This is happening not only on home computers but also on government and business systems. Recently Hollywood Presbyterian Medical Center was subjected to this scheme. The hospital said it paid a $17,000 ransom in bitcoin to the hacker who seized control of the hospital's computer systems. Apparently it was worth it to regain access to the data asap instead of struggling to restore it.
The most important defensive tactic against ransomware attacks is to be very, very careful which emails you open, links you click, sites you visit. Even so, we are not perfect.  
So the next best thing is to use an online data backup service, like Mozy.com. Online backup enables you to restore files if you are hacked by ransomware. Worst case, after an attack, you can have a computer tech erase your computer’s hard drive and reload software, then restore the backed up files. Or you can buy a new computer.
Either approach can be cheaper than the ransom requested. And you avoid dealing with the ransomware jerks at all, effectively not supporting their vile business model. That’s cold comfort, but any comfort counts when we’re victimized by criminals.
If you'd like to read more about this, here's a story in the LA Times:

And here's another story about two more hospital ransomware victims, these in Germany:

http://www.scmagazine.com/ransomware-holds-data-hostage-in-two-german-hospitals/article/479835/

If you like to beta test software, click here to install an anti-ransomware software program I'm trying out. It's made by Malwarebytes, whose anti-malware program, Malwarebytes Anti-Malware, I recommend.

A REMINDER...
If you ever suspect your computer is infected by ANY malicious software, unplug if from the Internet immediately and request trusted tech support. The longer the exploit goes on, the more damage the hackers can cause.
Please feel free to forward this tip to friends, family, colleagues, and others.  

If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send.


Thanks for reading, 
Sam

Monday, February 15, 2016

Update or Remove Java - the Only Safe Options

Update or Remove Java - the Only Safe Options 

Oracle has released security updates to address vulnerability in Java SE versions 6, 7, and 8 for Windows. 


Exploitation of this vulnerability may allow a remote attacker to take control of an affected system.


Before worrying about an update, however, consider this: If you don't need Java, you can uninstall it. Usually you would only need it for a gaming program or online database that requires Java. 


If you determine you don't need it, open the Control Panel, then Programs and Features, then locate all versions of Java on the list; uninstall each. Then close all open programs and reboot your computer. 


If you do need Java, you should only need the most current version, unless otherwise indicated by your specific software program that requires it. You can remove all unneeded versions as explained above. 


To check if Java is up to date on your system, visit the site below with Internet Explorer or Firefox, and then click the button: Verify Java version. Follow whatever prompts you receive. (The 32-bit Windows online version is fine for most applications. I recommend to not concurrently install third-party applications offered like Yahoo, McAfee etc.)


http://java.com/en/download/installed8.jsp


If you're curious to learn about Java, check this link:


http://java.com/en/download/faq/whatis_java.xml


This may all seem a bit of a hassle, but if you want to keep your computer as secure as possible, either remove Java or keep it updated. This pretty much applies to every program on your computer, whether Windows or Mac, smartphones, tablets, etc.


A good rule of thumb proposed by Brian Krebs, author of the book Spam Nation, is this: 1)If you didn’t go looking for it [software available online for download], don’t install it; 2)if you do want it, keep it updated; 3)if you no longer want it, remove it.

Please feel free to forward this tip to friends, family, colleagues, and others.  


If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send.



Thanks for reading, 

Sam