About

Long, long ago in a blogosphere far, far away, we met in each other's comments. Who would have guessed that three years later we'd be married and blogging about our two daughters? Not us, but here we are!

Contact

jay -at- accidentalverbosity -dot- com
deb -at- accidentalverbosity -dot- com

Syndicate

Capitalism Makes The World Go Round

Carnival of the Capitalists

And Blogs Go Round The World


bfllogo.jpg


"...if it was up to me I'd show it every day..." --Darryl Worley


Search


Advanced Search

Categories

Monthly Archives

Man Does Not Click On Blogs Alone

IMDB
SFGate
Google
Reason
National Review Online
FOXNews
MSNBC
JunkScience
Technorati
Opinion Journal
Ain't It Cool News
RealClear Politics
Jurist - Legal News
Tech Central Station
Sci Tech Daily Review
Movie Reviews by Steve Rhodes
Michael Moore Hates America
MarketingProfs.com
Operation Give
Reading for the Future boston.com
WHDH weather
Weather.com
Todd Gross Weather Blog
BugMeNot
Fresno Bee
CNN
Yahoo
Pensacola News Journal
SouthofBoston.com
Center for Consumer Freedom
Project Linus
Fifty-Nine Deceits in Fahrenheit 9/11
Baen Free Library
spiked
Acme Mapper
National Hurricane Center
States Web Games
Trend Micro HouseCall
The Voluntary Trade Council
Expression Engine


Sadie Good, Briz Bad

I took Sadie with me yesterday, to get her desire to “go” out of her system.  I needed to look at a computer with an apparent malware affliction, pick up a check, mess with servers a little, and I wanted to do a trial install of Outlook 2003 on one workstation that could be messed up without mattering.

It turned out the malware affliction was a variant of this lovely thing.  I had a certain amount of fun, because I located the files that contained the user’s recent web browser keystrokes, including his webmail URL, name and password, and all the most recent actions, including what I had done in the registry and such since sitting down.  I’d heard of viruses or spyware designed to log keystrokes and transmit the info, but I’d never encountered one or seen direct evidence that’s what it was.

When I hit the registry, the most recently modified key was now blank “run once” under HKCU (hkey_current_user), so obviously something had been planted there and had a chance to deploy and clear on reboot.  The run key under HKLM (hkey_local_machine) had five items, only one of them legit.  One of them was winlogin.  It and one other put themselves back as soon as they were cleared.

The file I recognized as not right in processes was ieredir.exe, which I was able to get rid of.  Searching on it later told me this was Briz-F or a variant and allowed me to learn more.

The symptoms he was having were that Firefox would not run at all.  Double-click and it goes away instantly.  Internet Explorer would run but not work.  Other things started hanging and not working, including eventually Word.

Fishing through files on the system, I found it was apparently spoofing explorer.exe with its own version, which would explain a lot.  Ugly.

He went home.  I left it for today, filled with joy at having that much extra to do this weekend.  A cleanup of that sort could take hours.  Afterward I looked at proxy server logs and found since about 10:00 AM the machine had periodically talked to a suspicious sounding .info URL and a URL ending in .org that otherwise sounded like it could be a credit union site.  The latter appears to make you think that it is doing a windows update.

So, remember I had Sadie with me?  She is so good!  It’s as if she has a built-in sense of decorum.  The whole time I worked on that computer, she hung out in that office quietly, chewing on a big pretzel the lawyer gave her and waiting patiently for me.  Periodically one of her admiring public would come to the door to say hi to her.

Then we went over to the server room, which is more of a closet.  She sits in there with me and touches nothing she shouldn’t.  This in a place where she could easily reach out and rip the spaghetti of little phone wires from their contacts.  There’s a toolbox she uses as a chair, and someone left a doorknob kit on the floor next to the door, so she plays with the pieces of that.

Then she got a big purple lollipop from the receptionist on our way down to my office, and for the little while we were there she ate the lollipop and played with her computer and a couple of small toys that live there.

She was sooooo good!  I know she is generally, but it still amazes me.  I still couldn’t take her for a whole day of intense work in the client’s offices, but it’s nice that I can take her for a couple hours or more and not have to worry much.

Posted by on 09/09 at 10:44 AM
Commenting is not available in this weblog entry.

<< Back to main

Powered by ExpressionEngine


Blog Empire

Solojent

Dispatches from Blogblivion

The Frugal Guy Cook

Geek Practitioners

Bizosphere

Neatly Tangled

RealityBucket

Divine Hamster

Carnival of the Capitalists

Tangent Mart

Retirees

Accidental Verbosity

Old Jay Solo

Jay Solo

Original Blogblivion


Blogs!

Acidman
Alphecca
American Digest
American Mind
America's North Shore Journal
And Then I Woke Up...
Attaboy
Aubrey Turner

Babalu Blog
Balloon Juice
Being Jennifer Garrett
Beth's Contradictory Brain
Big Red Giant
Blogblivion
Bogieblog
Bogus Gold
Brandon's Puppy
Bubba's Place
Business Pundit

Caerdroia
Distributed Republic
Chasing Grace
Claire Wolfe
Cootiehog
Cox & Forkum
Coyote Blog

Da Goddess
Dax Montana
Day by Day
Dean's World
Distributed Republic
Dizzy Girl
Dogs Don't Purr
Dog Snot Diaries
Drumwaster's Rants
Dustbury

Electric Venom
Enviropundit
Exgaucho

Farkleberries
Fire Ant Gazette
Freedom Lives
Future Pundit

Geek Practitioners Blog
Ghost of a Flea

Hell in a Handbasket
HE&OS
Heretical Ideas
Hit and Run
Hog On Ice
Hub Politics

IMAO
INCITE
Inoperable Terran
Instapundit
In The Pipeline
Irreverent Probity

Jaboobie's Journal
JawsBlog
Jay Manifold
Jay Reding
Jay Solo
Jeffrey Alan Miron
Jen Speaks
Julie Neidlinger: Web Log

KateSpot
Ken Jennings
Knowledge Problem

Laissez Faire Books Blog
Laughing Wolf
Laurence Simon
Lead and Gold
Les Jones
Let the Finder Beware
Libertarian Leanings
Libertyblog
Little Miss Attila
Lollygaggin
Low Earth Orbit

Marginal Revolution
MarsBlog
Martinis, Persistence and a Smile
McGehee Zone
Medrants
Mickey's Musings
Mike Campbell
The Moderate Voice
mountaineer musings
Mudville Gazette
My Button Box
My Life In Words

New England Republican
Ninjababe's Ramble
No Looking Backwards
NoodleFood
Not Exactly Rocket Science
No Treason!

O'DonnellWeb
One Fine Jay
One Sixteenth
The Online Lawyer
On the Third Hand
Outside The Beltway
Overactive Imagination
Overlawyered

Parkway Rest Stop
Pat Sajak
Peaktalk
Pearsonified
Planet Geek!
PoliBlog
Positive Liberty
Publicola
Practical Penumbra

The Queen of All Evil
Quibbles and Bits

Random Jottings
Random Nuclear Strikes
Regions of Mind
ResurrectionSong
Right Side of the Rainbow
Right Wing News
Ripples

SamaBlog
Samizdata
SCOTUS Blog
A Shareware Life
She Who Will Be Obeyed
Silflay Hraka
Smallest Minority
Somewhere On A1A
Suburban Blight
A Sweet, Familiar Dissonance

Tammi's World
Things You Should Do
Thinklings
Thought Mesh
Tiger
TigerHawk
Todd Sattersten
Transterrestrial Musings
Truth Laid Bear
Two-Four

Universal Hub

Velociman
Viking Pundit
Virginia Postrel
Virtualosophy
Vodka Pundit
Volokh Conspiracy

Walter in Denver
Weekend Pundit
The Window Manager
Winds of Change
Wizbang
Wizbang Bomb Squad
Wizbang Pop!
Wizbang Podcast
Wizbang Tech
Who knows what evil...
The World According To Wayne

XTremeBlog

Yet Another Weird SF Fan

ZenPundit

Who Links Here