Wednesday, March 11, 2009

Bad Symantec update leads to trouble for users

Hackers took advantage of a Symantec issue today to flood search engines with more troublesome redirection to rouge anti-virus sites. Apparently Symantec periodically sends its users PIFTS known as Product Information Framework Troubleshooter which is a diagnostic program that anonymously collects information such as the operating system and version number of the product being used in order to get a snapshot of its user base. This time however the file wasn't digitally signed cauing many firewalls to flag it, including Symantec's own firewall.

So my advice for the time being. Don't install PIFTS.exe. If you visit a website and are advised your computer is infected, CTRL, ALT, DEL and end task on your browser process. Then run a good anti-virus software and anti-spyware program like Avast and Malwarebytes.



Monday, March 2, 2009

Update Win32.Vitro

It appears this nasty peice of work is causing many issues. As I have mentioned in my previous post, at this time it cannot be removed and a format is necessary.
From my research The transmition of this virus seems to come from an infected movie type file. This file informs you you'll need a codec to view it, when you agree it infects your system.

When installed it injects code into running processes than hooks the following functions in ntdll.dll which transfers control to the virus every time any of these function calls are made.

* NtCreateFile
* NtCreateProcess
* NtCreateProcessEx
* NtOpenFile
* NtQueryInformationProcess

This vitro virus then infects every program you open. While good firewall and security software is essential to your online safety, they alone are not enough. Use caution when asked to download codecs or add-on's.

If you do get infected with this virus. DO NOT use previous backups. Perform a full clean install of Windows and your programs.

Friday, February 27, 2009

DCS Tech Corner

DCS Computer Services has launched a tech support forum called DCS Tech Corner. You can get help with Microsoft Windows, computer hardware, computer software, networking, virus & spyware removal, and much more. Contributors are welcome to join and share their knowledge. Hope to see you there.
DCS Tech Corner

Thursday, February 19, 2009

New Virus Warning W32.Vitro

I recently got a machine in the shop which failed to boot after what appeared to be a Microsoft Update. Apparently this was NOT a legit Windows Update Icon and when installed infected all called exe files on reboot.

This Virus is known as W32.Vitro. It is a polymorphic virus. Polymorphic viruses were first seen in 1990. A polymorphic virus is one that replicates itself every time a legitimate program on your computer is run. The file names on your computer will appear to be normal when in fact they are now part of the virus. Each and every program opened by Windows will become infected.

At this time Nortons, Macafee, AVG and others do not detect it. Avast was able to detect it but became infected as well. At this writing there is no way to remove this virus successfully.
A format alone may not be enough. Deletion of the partition, recreation of the partition, a hard format, and complete Windows installation will be necessary.

Back up of files is NOT recommended. The virus infects any external media you may use, burning programs, cdr's flash drives.

This new outbreak seems to have been discovered just this week. There is little information about its transmission as yet.

I will keep you posted as more information becomes available.

Tuesday, February 10, 2009

Malware Software Reviews

I am impressed with the new Malware scanner by Malwarebytes. This scanner does an exceptional job of identifying and removing malicious software from your computer.
There is a freeware scanner that can be updated and run manually or a very reasonably priced resident scanner. This tool is a must have for any Internet user.

You can download the free scanner here:
Malwarebyes Anti-Malware

Don't Be Duped by Rouge Anti-Virus Software

The newest trend in security issues seems to be Rogue Anti-Virus Software. While not a threat exactly it's a major annoyance. The bogus company or web site throws up a alert window informing you that your computer is infected. The truth is it's probably not. Unfortunately selecting cancel does not solve the issue If you encounter this situation, using CTRL, ALT, DEL and ending task on your browser process can often prevent this.

Are you infected with Rogue Anti-Virus Software?
Were You able to remove it?
Sound off and let us know.