http://www.m~tech.com/

http://www.hospitalityupgrade.com/redirect/ethostream_banner.asp

http://www.hitec.org

Magazine



 


 
A Look At | Technology

Notes: From an IT Service Shop - The Latest Virus Threats: Antivirus Soft, Internet Security 2010

3/1/2010
Geoff Griswold  geoff@atlantaomnigroup.com
Bert McDonold  apex_micro@yahoo.com

© 2011 Hospitality Upgrade. No reproduction without written permission.

The New Year kicked off with an old virus also raising its ugly head.  Internet Security 2010 and a variant, Antivirus Soft, began appearing on user machines at the beginning of 2010.

While similar to older versions called Spyware Protect 2009 and Windows Antivirus Pro, these new versions are much more annoying and virtually take control of the system.  These are examples of a more generalized group of rogue antivirus programs called Scareware. While the symptoms vary from mildly annoying to absolutely crippling (denying you access to task manager, Window Explorer or other programs), the end result is much the same. They are in the business of getting in your wallet. They will say whatever is required to get you to enter your credit card information. It’s all about the money.

Even the best antivirus programs available seem unable to slow this newest threat. One of the first things that the malware does once in control of your computer is to disable the resident antivirus program.

How does the virus infect a computer?  The most common way is to trick users into thinking they are visiting a news site to be updated on a current event.  When the user clicks on a link, the virus is loaded onto their system.  Another way is just by visiting a rouge site, the infection can be downloaded.

The symptoms of the infection are obvious.  A fake virus alert appears on the right hand side of the system tray.  Then a fake virus scan appears detailing all sorts of bogus system infections.  Next, an activation window appears asking for a code.  Then, a purchase window appears requesting credit card information.

Each variation of the virus may appear differently, but the end result is the same, the rogue has almost complete control of the system. 

While some might be tempted to give their credit card information just to get rid of the thing, this is not advisable.  First, this is a totally bogus program that has no value whatsoever other than to extort money from users and possibly steal confidential information off the system.  Do not enter any information into these boxes.

A common remedy to rid systems of this pest was to use system restore to roll back the system to an earlier time, before the virus struck.  This was a simple, effective way of removal and required no other antivirus or removal product.  However, these newer versions block system restore with a file is infected message and does not permit the restore, as well as many other Windows features, such as using the control panel.

How Can This Threat Be Removed?
Antivirus 2010, while blocking many Windows functions, still allows the use of Windows Explorer, so a malware removal tool, such as Malwarebytes (www.malwarebytes.org) can be installed from a USB disk (not the Internet, because the virus blocks Internet access). Malwarebytes offers a free download that includes a program that kills or disables the virus so that it can be removed.
Antivirus Soft disables Windows Explorer so the hard drive has to be removed from the computer and scanned as an external drive.  In addition to Malwarebytes, PC Tools Spyware Doctor (which is not free) is also effective in removing this threat.  There are several other tools, including one from Microsoft (www.microsoft.com) that may be helpful in dealing with these threats.

The other alternative is to completely reload Windows (after backing up all data) and associated programs.  This alternative can be attractive for older systems because it will clean up many of the items that may be causing the system to function poorly.  Careful planning should be used before performing a reload, such as locating all program disks, or the names of the Web sites that will be used in re-installing the programs.  Be sure that the data backup is complete and has been tested before beginning the reload.

What can be done to prevent being infected? Don’t follow links unless you trust the source. If there are pop ups on your screen – even if they look legitimate, don’t click anywhere inside the box (don’t click yes/no/cancel/anything), just close the box. If suspicious, just turn off your computer rather than click inside the box. Keep your antivirus up to date. Do not open any e-mail attachment unless it is from a trusted source.

What if, after removal of the malware, Internet Explorer still does not function properly?  There is a trick, call us and we will tell you.
 

Geoff Griswold is a field engineer and general manager of the Omni Group, an IT services company specializing in the hospitality industry.  He can be reached at (678) 464-2427 or geoff@atlantaomnigroup.com.

Bert McDonold is a network specialist in the Atlanta area supporting small law firms and hotels with network setup, security and tuning, along with setting up proper backup systems and procedures. He can be reached at (770) 330-4373 or apex_micro@yahoo.com.  

 

Related Articles:
  • An IT Checklist for the Start of a New Year - Making the best of your IT budget
  • Benchmarking Menu Analysis Algorithms
  • But I Like Technology
  • E-Marketing Responsibly - How to Avoid the Spammer Label
  • Happy Anniversary, Mythical Man
  • In Praise of Geeks
  • IT MANAGERS ARE ATTACKED FROM ALL SIDES - JUST ANOTHER DAY IN IT
  • It’s All in the Package
  • Notes: From an IT Service Shop - The Latest Virus Threats: Antivirus Soft, Internet Security 2010
  • Securing Your IT Assets – The Time Is Now
  • The 411 On The 411
  •  

    Articles By The Same Author:
  • 3-Dimensional Television: The Wave of the Future or 8-Track Déjà Vu?
  • Alternative Energy Sources - What Does It Mean for Hotels?
  • An IT Checklist for the Start of a New Year - Making the best of your IT budget
  • Bad Power can be a Big Problem
  • Complimentary Telephone and Internet - Is This the Beginning of a Trend?
  • Computer BackUp - Is it being overlooked at your property?
  • Energy Savings - Why These Tips Work
  • High Priority: Keeping Your Investments Updated and Maintained
  • High Tech Items in a Hotel that Can Be Overlooked--Until They Break Down
  • High-speed Internet Access
  • High-Speed Internet Access:New Phases Are Coming
  • Hotel Telecommunications in the 21st Century
  • Keeping Out the Bugs!
  • Managing Energy in a Volatile Environment
  • Minor Disasters Can Be Very Disruptive
  • Notes From an I.T. Service Shop: Streaming Media Players (connected TV players)
  • Notes From an IT Service Shop: Every Hotel Computer Should Have at Least Two Internet Browsers
  • Notes: From an IT Service Shop - The Latest Virus Threats: Antivirus Soft, Internet Security 2010
  • Notes: from an IT Service Shop - Windows 7: Microsoft Got It Right
  • Part 2: Quality Management Systems - Providing valuable information to single and multiple properties
  • PCI Compliance: What Every Hotelier Should Know and Do
  • POS Wireless Handheld Terminals...Great in the Right Places
  • Preventive Maintenance & Rapid Response Systems - Key Components of Quality Management Applications
  • Security: Something No Hotel Can Ignore
  • Systems: Notes From an IT Service Shop - New High-speed Internet Standards
  • The Need for Speed - What Hotels Can Do to Increase Network Performance
  • Windowsâ„¢ Version Alternatives - Choices
  •