trojan


 Powered by Max Banner Ads 

Virus Win32:Vitro is here. What is it?

Savemybutt.com Newsletter
May 11, 2009 – Issue: 1 – Number: 3
———————————————————— 

*** NEW VERSIONS ***

There is a new version of Ccleaner available. Version 2.19.901. You can download and install it from my website, http://savemybutt.com
————————————————————
*** NEW PROGRAM ***

I will be starting a new referral program in the next week or so. For every person you refer for Remote Computer Services, your account will be credited $5.00 towards your next service all.
I will let everyone know when it is available and how to sign up for it in the next week or two.
————————————————————
*** VIRUS ALERT *** VIRUS ALERT *** VIRUS ALERT ***

I am not one to use scare tactics when talking about a virus that is spreading, but this one is a doozie.

Name: Win32:Vitro
How Infected: By you click on a fake video codec installation link at free movie sites.
Spread: Medium, less than 10,000 computers infected.
Repairable: NO!

There is a new variation of the Virut Trojan, which began life in 2007, going around called Win32:Vitro. You obtain and install Vitro by visiting websites that ask you to install a video codec that is fake, before you can watch free movies online.

Vitro injects itself into ALL .exe files on your computer slowly and over time, making them unable to run. This includes Notepad, Paint, WordPad, Word, Excel, Outlook and Outlook Express, Quicken, Adobe products, and all of you browsers, and any software you have installed.

It also invites and installs fake clean up tools like Ant-Virus 360 and System Protector as well as others.

You will know you have it if you can not open a program that open just a minute ago or recently or if your anti-virus tells you that a needed .exe file is infected with Win32:Vitro.

The Vitro Trojan WILL, I repeat, WILL require you to back up your data, format your hard disk, then do a wipe of your drive, then reinstall Windows, all of the service packs and updates, all of your software, then restore your data. This IS the only way to get rid of it.

If you have any older software that you do not have the original installation disk to, say goodbye. There IS not way to repair them.

Also, if you use a USB drive, external, thumb, jump, or any other USB storage device that has .exe files on it, they WILL also become infected. That means the will HAVE to be deleted by formatting and wiping that drive as well.

You will not get this virus by visiting You Tube, Hulu, Netflix, Amazon, TV networks, or any other known big name site to watch video. If you frequent some porn sites, illegal movie sites, download illegal movies, or sites that you never heard of to watch video, your chances of getting this virus are huge.

If you are using a product like Acronis True Image to make full image backups onto an external drive, you are in better shape. However, if you backed up since you were infected with Vitro, your backup is now infected as well.

Avast, Norton, McAfee, and all of the good anti-virus programs detect Vitro. But, Vito cannot be removed or repaired. You MUST FORMAT and WIPE the drive to get rid of it.
If you can play movies from YouTube or Netflix you don’t need any video codecs. If they are offered for download and installation, get the heck off that site NOW! And, don’t click on anything on the site.

If you do click on something that says you need it to play video, shut your machine off NOW! Your computer will have to be taken into a reputable service center to try and clean it up before any damage is done. This cannot be cleaned up via remote control either. Make sure the service center backs up you data, photos, and music before they do anything.

Please be careful with visiting sites and clicking on anything that is not familiar. This is not cause by a security hole in Windows or any of your software. You get infected with this because you give it permission to install by clicking on malicious software installations offered to you on malicious or unknown websites.

Use common sense and read what pops up on the screen.
If you don’t know what it is or don’t understand what it is saying, leave that site immediately and call someone for assistance.

Conficker Worm Strikes Again

Photo of a virus Back in October, Microsoft released a patch, MS08-067 , that would block the Conficker.A worm in a special update.

Over the last couple of weeks, a new variant of this worm has been affecting customers. Microsoft detected it as Worm:Win32/Conficker.B. In addition to exploiting MS08-067 (the patch from October), this variant also uses other propagation methods; it tries to copy itself to network shares by guessing their passwords. If the password is weak, it may succeed. It also tries to spread via removable media like thumb or jump drives.

In the last few days, including January 15, 16, and 17. It has infected more than 3.5 million computers worldwide. And, it is spreading rapidly.

  • Shared computers with weak passwords may get infected by the worm
  • External hard disks and USB sticks may get infected by the worm
  • Computers without the latest patches and updates may get infected by the worm

It is important that you update all of the computers on your business or home network that are running the any version of the Windows operating system immediately, including Windows XP, Vista, and Server Operating systems. The update will block Conficker.B from infecting your computers if it has not already!

If you have been infected by Conficker, I have a link below that will allow you to download the Microsoft Malicious Software Removal Tool directly from Savemybutt to get rid of it.

However, because the warm blocks not only the Microsoft site, but also, most major security sites, including Norton, McAfee, Trend Micro, AVG, and Avast. You will have to download the removal tool from my site on the infected machine (because it is not blocked) or onto a clean machine that is not on your network, and then install it on all machines in your network. This MUST be run, and all computers on your network, because it spreads over your network to other machines.

Click here to download the Microsoft Malicious Software Removal Tool directly from this site.  Savemybutt is not be blocked  by the worm. Run it on EVERY computer on your network!

Also known as by different security companies:

TA08-297A (other)

CVE-2008-4250 (other)

VU827267 (other)

Win32/Conficker.A (Computer Associates)

Mal/Conficker-A (Sophos)

Trojan.Win32.Agent.bccs (Kaspersky)

W32.Downadup.B (Symantec)

List of word, character strings, websites, and domains that are blocked (that we know of).

virus
spyware
malware
rootkit
defender
microsoft
symantec
norton
mcafee
trendmicro
sophos
panda
etrust
networkassociates
computerassociates
f-secure
kaspersky
jotti
f-prot
nod32
eset
grisoft
drweb
centralcommand
ahnlab
esafe
avast
avira
quickheal
comodo
clamav
ewido
fortinet
gdata
hacksoft
hauri
ikarus
k7computing
norman
pctools
prevx
rising
securecomputing
sunbelt
emsisoft
arcabit
cpsecure
spamhaus
castlecops
threatexpert
wilderssecurity
windowsupdate