Saturday, September 20, 2008

Infected!

So the call comes in about an infected PC and I step up and go to work on it. This PC is so polluted with spyware, malware, downloaders, and other viruses it's not funny. To top it off, about every three seconds another pop-up warning manages to get in the way. I manage to get SuperAntiSpyware installed and start the scanning. Luckily it kills the easy stuff, but it leaves behind a couple of the downloaders which proceed to bring down more junk.
I end up installing PCTools Spyware Doctor, which has a free scanner, but you have to purchase it in order to actually clean the infections. It helps me find the rest of them so I can manually clean them off with SpyBot Search & Destroy. While I'm working I notice the normal virus software isn't even installed. So I make note to fix that later.
I worked on that PC for over seven hours to get it clean. During that time I begin chatting with the user:

GTG> When did you start noticing all these pop-ups and warnings?
User> Oh about three days ago.
GTG> Three days ago?
User> Yeah, I was doing some Googling to lookup some things and this warning came on about my machine being infected.
GTG> You didn't call us?
User> No, I just closed it, but it came up again about 10 minutes later.
GTG> You didn't call us?
User> No. There was no need. I wasn't feeling well so I went home sick.
GTG> But you didn't call us.
User> I wasn't here all day yesterday, so there was no point.

I don't think she understood that leaving her PC on allowed this thing to download more and more junk while she was out. I could have scanned and fixed the PC while she was out and when she returned she would not be sitting around twiddling her thumbs.

I was able to clean the machine and the next day the user calls me.
User> Hey, thanks again for fixing my machine. It's running great now.
GTG> No problem.
User> I was at this web page just now and another warning came up.
GTG> I'll check it out.

The warning is from the virus software blocking junk coming in from the website she is currently on. I let the user know that this is the normal software blocking it and to quit going to these infected pages.

No comments:

Here's your sign...