Showing posts with label McAfee. Show all posts
Showing posts with label McAfee. Show all posts

Monday, January 17, 2011

Anti-virus hoax

The Antivirus hoax is one that I think infects all layers of antiviral software, both legitimate and non.

Hello folks, sorry I havn't posted in a while. Seems tonight is an insomnia night so I thought I'd update you all based on some observations in the past few days.

It's no secret that I work with the public, on their computers, and often when they become infected with malware/virii. The customers I've dealt with have had just about every antivirus program under the sun. Everything from McAfee, to Norton, to AVG (the paid version)... the list goes on and on. At work, our systems use Nod32, so everything is in the mix. I still have yet to see anything that would remotely constitute a "good" antivirus.

Internet Explorer's best-known trait is that it's vulnerable. A program can install itself by ActiveX almost always without the user's knowledge or permission. A lot of my customers use IE. I use IE at work because some of our software only works correctly in IE. An interesting thing happened today, but first, some background.

Many of the recent virus programs (or malware if you insist), are part of a new trend called "rogue antivirus". We've seen a few of these, including Security Tool 2011, Thinkpoint, and Palladium, to name a few. All pose as Antiviral software, proporting to be internationally renowned as excellent software (usually "worlds leading antivirus" or something like that), all of which ask for a payment for services (usually around $80), to fix the supposed issues on your system. Fact is, the issues don't exist, the program is a fraud, and paying for it won't change a thing...

These Rogues get onto your computer by very crafty webpages that utilize a large amount of Javascript to animate, what looks to be, a Windows Explorer, showing several infections in shared folders, local disks, etc. with very convincing progress bars and the sort. To the untrained eye, a prompt like this represents a huge problem, and any attempts to close it are met by a prompt asking if you're sure you want to 'navigate away' from the page, and often, the page will re-open itself when closed. To the trained eye, this is an obvious fraud, and should be destroyed with great Prejudice.

Well, while googling something for a customer early this morning (now yesterday morning), I came across one of these pages, hosted from an IP, and "impossible" to close. My first instinct was to destroy it, however, if I killed IE, half the pages I needed to perform my job would go away too, so I opted to block the site... with the URL clearly visible, I opened Internet Options and added the IP to the list of restricted sites... after a short bout of trying to refresh the page, it returned with a blank page (all scripts were blocked, so no content was showing)... interesting, I can now painlessly close the page and return to work.

I decide to check something, so I remove the restriction, and refresh the page. I select to download whatever software they're pimping out, and save the file to the desktop. I ask Nod32 to scan it... 2 files scanned, 0 viruses.

Interesting.

I'm certain the situation would be the same for Norton, McAfee, AVG, Trend... the list goes on.

I renamed the file to "THIS IS A VIRUS.exe" and left it on my desktop, now in my roaming profile. I'll see how long it will be until the file get's picked up. My guess is at least 3-4 weeks, if ever.

All antivirus software is like this. The majority of the time people just keep eliminating the virus and the SOURCE of the virus just moves on and stops hosting the old virus... so it goes away... this is more likely to happen than a definition being put out that will actually stop the software from infecting your computer.

I havn't used an Antivirus in many years on any of my main PCs, in my humble opinion, they're useless. Knowing when to close a browser window and knowing when to deny a UAC prompt is about a million times more useful than any antivirus.

User education over user protection. Unfortunately, not many users want to learn, they just want their farmville.

Wednesday, December 15, 2010

Let's install McAfee

I file this one under "woes of an IT Professional serving the public"...

it's more PEBKAC than anything else.

So, as some of you may know, I work on the phones, doing remote support for an ISP in the eastern united states. Yesterday, I got a call from a customer who was having some issues getting, and staying, connected.

It was a strange issue, since the customer had no issues getting to most webpages, but couldn't load either of the two he needed to connect his computer to me, even in safe mode (with networking).... I decided, after about 45 minutes, to ask him to uninstall his Antivirus (McAfee). I also inquired about having something installed prior, and he mentioned he had McAfee before, but 'removed' it for the new version. Well, uninstalling worked, long story short, his 'removal' of his previous version wasn't complete, it failed or crashed or didn't complete for some reason, and he still had some of the firewalls from the old version.

I EXPLAINED THIS TO HIM.

We have a tool... the filename is MCPR.exe and it's the McAfee removal tool (there's a similar one for AVG and another for Norton). This tool removes any and all McAfee software from your computer. I was going to use it to uninstall the broken version, but first, wanted to download the installer to get the current version re-added to the system when I'm done. I asked the customer to log into the website where we download it, and he did, and when clicking on the download link, it came up with "error 31", which is something we see sometimes. "We" have a support department that can specifically handle error 31 with a significant amount of ease, and presuming the customer can get in touch with them in a timely fashion, we can have the error resolve in a matter of minutes.

So I send him off, and finish up some of the other work I had to do on his system, and take another call, and I'm working on other peoples computers... by the time I get back to his screen, HES INSTALLING MCAFEE AGAIN.

Yes, let's reinstall a problematic software, so we can run the removal for another piece of software that will just so happen to completely wipe out exactly what you're doing.

and he was all happy about it too, he typed into our support chat "only 7 minutes left!"
I was like.... no, we can't do this, I havn't run the removal. I asked you to resolve the error 31, not reinstall the application.

I immediately cancelled the install, shut it down and started the removal tool.
After that, reboot, got him to re-login to the download page, and re-downloaded and re-re-installed the application.

The system now works as intended... however, there seems to be an issue somewhere on Layer 8.