altivo: Wet Altivo (wet altivo)
[personal profile] altivo
Well, of course. It was Wednesday again.

The good happened in the morning, before work. I got that limited palette exercise finished and actually it looks pretty decent for what it is, a color sketch on a 9 x 6 sheet of watercolor paper. For details and a link to the picture over on DA, check [personal profile] argos' journal.

Work went downhill though. Around 5:30, when everyone left but the director and myself, we discovered that someone had let a disgusting trojan into one of the circulation desk PCs. This thing masquerades as an antivirus program called "Antivirus XP" (and of course I know perfectly well we have nothing of the sort installed) and claims that your machine is loaded with viruses and spyware and is being "attacked" from various network ports "RIGHT NOW" to try to get you to agree to a "free scan." The supposedly free scan either does nothing or else it installs more crap that will need to be removed. It disables any genuine antivirus software and turns off the Windows Firewall. Fortunately we have a good external hardware firewall, so I knew the claims about being attacked through various ports that are blocked by that device were phony. That in turn proved that the entire thing was a scam. Apparently it builds up to convince you to pay for a "full professional" version of their software, which doesn't really exist. Removing it is no doubt a nasty job too.

I shut the thing down and marked it "out of order." Some one is going to get their ears burned tomorrow, though. Probably it will take my entire work shift to clean this mess up. I suspect I'm going to have to hide Internet Explorer on those machines, and make them use Firefox with popups blocked and AdBlock Plus active, since they just can't learn not to click on these stupid spyware things. I'd filter them down to a list of approved sites if I could get away with it, but I don't think the director will go along with that. Actually, I'd take Windows away and give them Linux, but so far I haven't been able to sell that either, despite the fact that other public service machines that the same staff have been using for three years now have only Linux on them. Most of them are blissfully unaware of the difference.

Weather was nice, sky was really clear. When I got home, Gary had left a note asking me to close the barn doors that he'd left open due to the nice weather. I went out to do it and saw the best star-studded sky I've seen in probably a couple of years. The moon is just a young sliver, so no light pollution from it, and the air was so clear that even the filthy commercial and subdivision lights from towns to the east of us was minimized. Orion and Canis major were blazing high in the sky like I haven't seen them in what seems like forever. If only so many neighbors weren't afraid of the dark, we'd probably even have our view of the Milky Way back tonight, it's that clear.

Date: 2010-03-18 07:08 am (UTC)
From: [identity profile] calydor.livejournal.com
Don't bother trying to clean up after Antivirus XP. Unless you for some reason have no installation disks for the stuff on it, or it has a bunch of settings that will be impossible to recreate, it's faster, simpler and more effective to simply nuke and pave the machine.

Antivirus XP is a textbook example of malware done right - it is resilient to being removed, will recreate itself Brainiac-style from even the tiniest of remains, and fights with a vengeance against any kind of cleaning tool.

Take off and nuke it from orbit, it's the only way to be sure.

(Yes, this was me - feel free to delete the anonymous post)

Date: 2010-03-18 10:42 pm (UTC)
From: [identity profile] calydor.livejournal.com
You can't really blame them for where they were anymore. There have been numerous reports of sites like nytimes.com being duped into having a malicious ad banner running which would install, you guessed it, Antivirus XP.

The trick is simple: Send in a normal-looking set of ads, let them run quite normally for a couple of weeks, then Friday night you patch in the evilness.

'Hilarity' ensues.

Date: 2010-03-18 09:34 am (UTC)
From: [identity profile] avon-deer.livejournal.com
I was going to suggest some sort of USB port blocker, but it seems this came on through the web rather than an infected USB stick. The writers of these programs really annoy me. They are getting seemingly more ruthless as time goes on as well.

Date: 2010-03-18 10:22 am (UTC)
farthing: Farthing coin, 1948 (Default)
From: [personal profile] farthing
Yep, Calydor got it, if it's the same variant I struggled with, it's sneaky. And it downloads more stuff if it is let to stay on the internet. And it seems to notice a removal attempt, and then it gets even worse.

Oh, and it spreads over local area network too, somehow. :-P

Date: 2010-03-18 10:33 am (UTC)
moonhare: (Default)
From: [personal profile] moonhare
One hour after receiving a note from Technical Services about that particular worm I got a call from the Children's Librarian that her machine might be infected. This is our second 'at work' instance, and the fifth I've had to deal with. Yesterday I just ghosted it all away.

I was able to stall it the first time it hit here. Taskbar showed the process and I eliminated the file. Spybot removed a lot of it, but there was one element it missed, a .dll called iehelper_old.dll, and it came back with a vengence. It wouldn't let me delete itself, so I renamed the bugger and everything ran okay again.

I flattened it a day later, as everyone above tells you to do, because once it gets in it leaves little bits of itself all over the registry. Think of that "Earwig" episode of Night Gallery with Vincent Price.

Oh, and if the staff person was doing their job then they really aren't to blame. This thing comes in in PDF and IE holes. If they were playing on the web outside of their duties, then sure, they violated your policies.

Date: 2010-03-18 02:07 pm (UTC)
moonhare: (Default)
From: [personal profile] moonhare
Okay, just ignore my last comment, since deleted. I forgot that this is a browser hijacker. :o(

However, Symantec is worthless for this. Spybot was blocked in one instance, and I loaded it via flash drive in another. My son's machine wouldn't start in safe mode, and staff did, but, well, blah blah blah... you know what you're doing. Good luck!

November 2024

S M T W T F S
     12
345678 9
10111213141516
17181920212223
24252627282930

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Apr. 12th, 2026 05:27 pm
Powered by Dreamwidth Studios