It was not a good night last night.
Eleanor wound up going to bed very early, clearly upset about a couple of things that I did not cause but I share her feelings of rottenness about anyway. Not before turning her laptop over to me and mentioning that her antivirus was suddenly acting up.
Only it wasn't her antivirus. It was an anti-antivirus which had slipped through the cracks and was causing major mayhem on her desktop:

Wow. If these Russians could speak English as well as they wrote malicious code, they would've won the damn Cold War.
Pesky little bugger, this one. It managed to disable the real antivirus program, kept starting itself up as "proof" of how infected her computer was, and continued to offer to sell itself to her as blackmail to make the Binary Blue Screen of Death go away.
I got it into safe mode and started Spybot and got the real antivirus scan under way. Knowing these would take awhile, I fell asleep myself. Then the wakies came a bit before 2 in the morning. I rebooted, and the bitch was back. Dayum.
Then it occurred to me to take the picture above and put the annoying Pidgin into Google on my still-unviolated computer. This identified the beast- a naughty little piece of rogue spyware called SpyBurner- and, more importantly, the remedy. A good witch of a proggie called Malwarebytes was the ticket to kill the thing.
But how to get it to the patient when I could only run in safe mode, which disables the internet connection?
Her computer already had it installed. Vinny, the best damn computer guru on the planet, installed it for her last time I brought it in. An hour later, I'd killed it. Dead dead dead.
Now to compose a delicate email to the computer-illiterate "forward this cute attachment to 20 of your friends or Jesus will be sad" friend who sent her the payload last night. (And to download Malwarebytes onto this computer, where of course I don't have it because, after all, I never get viruses or nuth
i
n
Eleanor wound up going to bed very early, clearly upset about a couple of things that I did not cause but I share her feelings of rottenness about anyway. Not before turning her laptop over to me and mentioning that her antivirus was suddenly acting up.
Only it wasn't her antivirus. It was an anti-antivirus which had slipped through the cracks and was causing major mayhem on her desktop:
Wow. If these Russians could speak English as well as they wrote malicious code, they would've won the damn Cold War.
Pesky little bugger, this one. It managed to disable the real antivirus program, kept starting itself up as "proof" of how infected her computer was, and continued to offer to sell itself to her as blackmail to make the Binary Blue Screen of Death go away.
I got it into safe mode and started Spybot and got the real antivirus scan under way. Knowing these would take awhile, I fell asleep myself. Then the wakies came a bit before 2 in the morning. I rebooted, and the bitch was back. Dayum.
Then it occurred to me to take the picture above and put the annoying Pidgin into Google on my still-unviolated computer. This identified the beast- a naughty little piece of rogue spyware called SpyBurner- and, more importantly, the remedy. A good witch of a proggie called Malwarebytes was the ticket to kill the thing.
But how to get it to the patient when I could only run in safe mode, which disables the internet connection?
Her computer already had it installed. Vinny, the best damn computer guru on the planet, installed it for her last time I brought it in. An hour later, I'd killed it. Dead dead dead.
Now to compose a delicate email to the computer-illiterate "forward this cute attachment to 20 of your friends or Jesus will be sad" friend who sent her the payload last night. (And to download Malwarebytes onto this computer, where of course I don't have it because, after all, I never get viruses or nuth
i
n
no subject
Date: 2009-08-04 08:33 pm (UTC)no subject
Date: 2009-08-05 12:18 am (UTC)http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe
which hasn't blowed me up yet
no subject
Date: 2009-08-05 03:46 am (UTC)