PolyMorphic Win32:Vitro Most Viraulent Virus
This seems to be an virus that is getting some people hit hard. I wanted to blog about this because of the nature of Virus and Trojans. I have read reports that this might be from Online Movies, and I have to say this is one reason why you must stay away from certain online movies. I am going to take a guess that this virus requires a special CODEC, and you downloaded it and installed it. It Could also be the update the Adobe Flash player idea to but still results in getting the Virus.
As I said before you take a risk when you go to sites you don’t trust or know anything about. You also should know that if you need a “SPECIAL” codec, you should just go on to another site. These sites that claim they need this special codec means only one thing they want to install something without your Knowledge.
So what is this Virus:
The Virut family of viruses uses polymorphism to hide from all anti-virus protection, it infects executable files. File infection makes it very hard to repair a system that has been infected. W32/Vitro injects code in running processes and hooks the following functions in ntdll.dll which transfers control to the virus every time any of these function calls are made.
Microsoft Keynote CES 2009
Comments Off
Some Key topics talk about in this Keynotes are:
Windows 7 — Lighter, Faster, and Reliability. Windows 7 Should boot quicker and faster, and enables cool new interface touch.
Windows 7 — Beta will be available Worldwide on January 9, 2009 and will be available for download on MSDN and Technet. Also it will be available at : http://www.microsoft.com/windows/windows-7 For those who want to download it from Microsoft directly.
Windows Live Essentials — Windows live Messenger, Mail, and Photo Gallery works with Windows XP, VISTA, and Windows 7. It is available for download worldwide. Dell will also be putting this on their consumer and small business computers.
Windows Mobile — 11 Different Mobile phones.
Verizon Mobile – Windows Live Search will be available through Verizon and it’s a partnership with Microsoft.
Demo of Windows 7, Live, and Mobile:
Windows 7 will have Windows touch and be able to use net books with Windows 7.
Windows 7 has been designed with the Touch DNA in mind.
Windows Mobile demo with an Panoramic display.
Windows Live Demo – Various things they discuss here including Photo’s and Silver light.
Windows XBOX:
Disaster preparation 101 — Data backup
Comments OffIn this one I will talk about Disaster, it happens to all of us from time to time. A fire, a earthquake, a stolen laptop or any number of ways. So what happens to your data, is it stored on the laptop? Is it important very sensitive data? Could you get fired if you lost that data?
Uncovering a Virus/Trojan
Comments OffGetting done with the first part really got my juices flowing. I was shopping looking and thinking about this next article. I came up to only one option turning this into a 3-5 length post due to all the content that I will have. So where did we leave off? Oh that is right figuring out if you have a virus/Trojan. The instant I made a post about this 12 hours later someone make a comment and here is what he said:
I can’t wait to read part two of this article. I always wondered how you’d know you’re infected if a virus don’t want to be detected and no virus definitions are yet available, because the virus is so new.
Now the truth is anytime a Virus does something it usually leaves a footprint somewhere and somehow. Even the hardest working hacker can’t plan for all possibilities and that is where we begin. I have been helping people for a while with viruses and know that no matter how hard the virus tries to hide you can usually find it relatively quickly and easily do to virus check here are the ways I’ve done to figure out if they may or may not have a virus/Trojan.
Fix Shutdown Problems in Vista!
Comments Off
In the Patch Tuesday update, Microsoft quietly released the patch to fix Windows Vista machine shut problems. This patch should of came sooner.
Update for Windows Server 2008 and Windows Vista
Install this update to resolve a set of known application compatibility issues with Windows Server 2008. After you install this item, you may have to restart your computer.
This was not a critical update and it seems to resolve so many issues with compatibility. One thing it seemed to fix on my system has been the shutdown time. It is now quite fast, it would normally take me 2 to 3 mins to shutdown, now it does it in less than a Minute. So if you’ve not installed this update please install it soon. I would like to know if people are seeing the same thing I am. I’ve found a great resource on fixing it if you are still having problem, it talks about how to check your system performance. Although this is been doing it lately with these programs not loaded or even running, they still seem to cause problems so now I get the feeling it has to do with legacy programs. This should fix most of the problem with older programs.
Rumor is that Itunes will Remove DRM!
Comments Off
A report from last week brought to AppleInsider’s attention by French technology site ElectronLibre asserts that it’s now “clear” Apple will spark new interest in its music store by removing DRM from tracks published by Sony, Universal and Warner on December 9th.[Via Apple Insider]
Although, this is somewhat unlikely I’ve got my own theories on this. You see If Apple did this tomorrow that would be a BIG deal, due to the fact that Microsoft will be releasing there patches on the same day. I find it would be a momentous occasion.
trojan.zlob removal tricks!!
Comments OffAliases:
Trojan-Downloader.Win32.Zlob.qyl (Kaspersky)
Trojan-Downloader.Win32.Zlob.qzs (Kaspersky)
Trojan-Downloader.Win32.Zlob.qzn (Kaspersky)
Trojan.Zlob.CPP (BitDefender)
Puper (McAfee)
SystemDefender (Symantec)Trojan:Win32/Zlob.G is a component of Win32/Zlob that downloads rogue security programs, adware, and additional Win32/Zlob components.
[Via Windows Live OneCare]
Are you patched, Secunia Says NO
Comments Off
Think you’ve got nothing to worry about, according to Secunia 98% of computers are not fully patched and are vulnerable to some kinda of attack.
If you have a system that is off of the Net you could use the Clone of Autopatcher Program to do it for you. You also need to update all your secondary programs such as Audacity, Open Office, and other programs that you use weekly.
Vista To release Service Pack 2 in April 2009

Some program Vulnebilities Detected!!
Comments OffJust got done looking at some of my security sites and according to SecuriTeam there are are several programs that have vulnerabilities. here are the Ones that I’ve found:
Google chrome is vulnerable to URI Obfuscation vulnerability.
An attacker can easily perform malicious redirection by manipulating the browser functionality. The link can not be traversed properly in status address bar.This could facilitate the impersonation of legitimate web sites in order to steal sensitive information from unsuspecting users. The URI specified with @ character with or without NULL character causes the vulnerability.iPhone Configuration Web Utility for Windows Directory Traversal
iPhone Configuration Web Utility lets “you easily create, sign and distribute configuration profiles using a web browser”. A vulnerability in iPhone Configuration Web Utility allows remote attackers to access files that reside outside the bounding root directory of the program’s files folder.Streamripper Multiple Buffer Overflows
Streamripper “records Shoutcast and Live365 MP3 streams to a hard disk, creating separate files for each track. Runs under Unix and Windows.” Secunia Research has discovered some vulnerabilities in Streamripper, which can be exploited by malicious people to compromise a user’s system.
Microsoft kills a fake antivirus tool from 994,061 computers!
Comments Off
According to Arstechnica and I’ll quote:Win32/FakeSecSen has gone by various names, including Micro Antivirus 2009, MS Antivirus, Spyware Preventer, Vista Antivirus 2008, Advanced Antivirus, System Antivirus 2008, Ultimate Antivirus 2008, Windows Antivirus, XPert Antivirus, Power Antivirus, and Ultra Antivirus 2009. Furthermore, it is skinnable, so each of these variants has a different GUI, although the basic functionality is the same: bother users with warnings of malware until they pay up.The Microsoft Malware Protection Center recently released some data on how the removal tool performed this month: FakeSecSen was removed from 994,061 machines. That number isn’t the highest Microsoft has recorded before, and the number of removals depends on which malware Microsoft adds each month and how widespread it is.
[via Arstechnica]
This seemed to of happened this month with the usual Windows update. If you haven’t updated your system just yet you should. This troublesome fake virus seems to have been killed from several systems. This could effectively make it harder for these guys who ever designed this program to make money. I hope microsoft does even more virus removals in next month. If you still want to try to get rid of these viruses don’t forget to check out my tips on Virus removal.
How to disable autorun the easy way!!!
Comments OffI read a report from Cnet about USB devices spreading Virus and I will quote:
The bad guys are intentionally developing new flavors of malware designed to propagate through USB devices,” said Gunter Ollmann, chief security strategist for IBM’s ISS security division. “They are today’s floppy drives.”
An infected computer can spread a virus to a clean USB thumb drive that is inserted. That USB drive will then be spreading the virus onto other computers if the operating system on those machines has an AutoRun-type feature enabled. The AutoRun function in Windows launches installers and other programs automatically when a flash drive or CD is inserted. The Mac has an equivalent function, according to Ollmann.[Via Cnet]
In order to disable “autorun“, which in Vista is called Autoplay. In order to disable Autoplay from starting when you insert media into your computer here is how you do it:
You will need to be Logged in as Administrator before this can be done:
Next click start and type “Autoplay” without quotes. It will bring up a screen but all you have to worry about is this:
Vista has a new Vulnebility!
Comments OffAccording to Techworld.com, Vista has a new Vulnerability that could let a hacker infect a Vista machine with a rootkit. The talk from them is quite intriguing. I will quote it to better let you know what the Vulnerability is:
The vulnerability could allow a hacker to install a rootkit, a small piece of malicious software that is very difficult to detect and remove from a computer, Unterleitner said.
Phion notified Microsoft about the problem on 22 October. Microsoft indicated to Phion that it would issue a patch with Vista’s next service pack. Microsoft released a beta version of Vista’s second service pack to testers last month. Vista’s Service Pack 2 is due for release by June 2009.
[via Techworld.com]
The way they could do this is through the Device IO Control which in turn could corrupt the Kernel of Windows Vista. Now we all know that Microsoft will release a patch quicker than 6 months away. According to this article, people are already looking for the exploit and want to know more about it. I would be willing to bet they will have a patch out sooner than later. Probably January or Febuary, which will be a big deal because no one will expect it. I would also imagine hackers will start trying to figure out how they could install software as quick as possible before Microsoft pushes out the patch. So what can you do to protect yourself, Get a firewall, a Antivirus and learn how to protect yourself to prevent yourself from getting a computer virus.
Is Vista just Windows 7?
Comments OffNow I know Vista isn’t what people expected and that it had high expectations when they first released it. I think that is due to the fact Microsoft tried so hard to make Vista seem more than it actually was. Now According to Ina Fried from CNET her post was about Windows 7: A better Vista?. In her post she talked about the features of Windows 7, and how Windows 7 is almost like Vista. I tend to agree because of the look from screenshots I’ve seen to make me think it will be Version 2 of Vista. I don’t think it is anything that will change from Vista to Windows 7. It will however be more ready to boot up and shutdown that is according to what Microsoft said to Ina.
Windows update is getting a revision!
Comments Off“Over the next couple of months, we’ll be rolling out another infrastructure update to the Windows Update agent (client code),” said an unidentified Microsoft employee on the Windows Update team’s official blog. “This update makes it possible for users to install more than 80 updates at the same time.”
[via Computer World]
Now if your like me and have several computers who need to be updated at a given schedule, you sometimes worry about these updates that come along that might just break your system. I have been using a program call Offline Updater, which does what Autopatcher does really nicely. So why is Microsoft sending out this patch? Two reasons, one they want you to be able to update your operating System without hurting your system integrity.
Now lets talk about the integrity of having to reboot your system. You see, every time you reboot the system, it causes the system hardware some strain. It is something like having starting up a car, sooner or later you will have the starter go out, because of to much start up.
Time to Change your clocks.
Time to change those clocks of ours
Beginning in 2007, Daylight Saving Time is extended one month and the schedule for the states of the United States that adopt daylight saving time will be:
2 a.m. on the Second Sunday in March
to
2 a.m. on the First Sunday of November.
So that saying goes it “Fall back, Spring Forward“ So now here are some great programs to better help you get your computer clock up to snuff:
Worldtimeclock Atomic Clock Sync Program – It is a free program for you to use with your Windows. Although you have to make sure your selected the right timezone once it is installed all you will need in an internet connection to sync your windows time with the atomic clock.
Some bloggers are Hyping Windows 7 operating System.
After looking around the blogosphere, I’ve come to the realization that people are starting to get hyped up over Windows 7. In one blog post from it.toolbox.com:
Windows 7 is due to hit beta and release in 2009, and odds are likely that if the pundits, all of us on the blogosphere and other places like PC World, Cnet, and others all agree that this works the way a computer was supposed to work will help drive sales. What is also interesting is that Microsoft is really pushing to get this puppy out. Along with the bloat are gone the five years of development.
[Via It.Toolbox.com]
I totally agree with what he is saying on the possibility to have an operating system actually do what it is told. Some things people have been looking for in there Searches in regards to Windows Vista are:
Windows 7 Milestone 1 Leaked!
Comments Off
Many people have been wanting a copy of this so called elusive copy from PDC to test out and see where Microsoft is going. Most developers are wanting to start to get into the stage of figuring out how they can get a step ahead of everyone else. That being said, people have started to leak the Windows 7 on the Torrent sites.
We must assume Microsoft expected this and kinda wanted this to happen because when they gave this out they didn’t make it have any major copy protection. Although we must not forget that there will be fakes out there and people are downloading this at a tramendous rate. Most people will download it in under a day if you let it go!! I have not downloaded it because I am trying to get into the beta team for Windows 7 and don’t want to be to critical on the system.









