About

Long, long ago in a blogosphere far, far away, we met in each other's comments. Who would have guessed that three years later we'd be married and blogging about our two daughters? Not us, but here we are!

Contact

jay -at- accidentalverbosity -dot- com
deb -at- accidentalverbosity -dot- com

Syndicate

Capitalism Makes The World Go Round

Carnival of the Capitalists

And Blogs Go Round The World


bfllogo.jpg


"...if it was up to me I'd show it every day..." --Darryl Worley


Search


Advanced Search

Categories

Monthly Archives

Man Does Not Click On Blogs Alone

IMDB
SFGate
Google
Reason
National Review Online
FOXNews
MSNBC
JunkScience
Technorati
Opinion Journal
Ain't It Cool News
RealClear Politics
Jurist - Legal News
Tech Central Station
Sci Tech Daily Review
Movie Reviews by Steve Rhodes
Michael Moore Hates America
MarketingProfs.com
Operation Give
Reading for the Future boston.com
WHDH weather
Weather.com
Todd Gross Weather Blog
BugMeNot
Fresno Bee
CNN
Yahoo
Pensacola News Journal
SouthofBoston.com
Center for Consumer Freedom
Project Linus
Fifty-Nine Deceits in Fahrenheit 9/11
Baen Free Library
spiked
Acme Mapper
National Hurricane Center
States Web Games
Trend Micro HouseCall
The Voluntary Trade Council
Expression Engine


Now relegated to Blogblivion...

Wednesday, July 28, 2004

Insidious Technical Crud

--Jay at 02:57 PM--

A while back I mentioned a laptop that will not respond to ctrl-alt-del at the login prompt screen for XP Pro.  I still haven’t solved that, or nuked it by wiping and reinstalling the machine, which is pending.

You hit ctrl-alt-del and the screen just sort of blinks at you.  In safe mode, it works.  Ditto for the login prompt in command prompt safe mode.  I was getting a funky RPC (remote procedure call) error at some point after logging in when in either safe mode I mentioned, but that seems to be gone after much futzing around, killing potential sources of trouble.  I never needed to use shutdown -a or whatever the command is to abort the RPC shutdown.

The problem began when the user, who is on DSL now and is insane to have AOL of any kind installed, apart from AIM, installed an AOL upgrade.

Quick!  Any thoughts before I whip out the magic fdisk WMD?

I have not been back to Google for the problem recently.  The things I found that seemed promising either turned out not to be applicable, or not to work at all.  I may check that again, in addition to booting from the XP CD and attempting a recovery.

On a slightly different note, I fought with malware on another laptop, this one borrowed by the same user.  The time I devoted would have been enough to fdisk and reinstall, and I ended up not being able to defeat the CoolWebSearch variant that afflicted it.

As it turns out, the guy who bravely and generously made cwshredder has given up on doing any further updates, so there exist CW variants that cannot be removed short of heroic, highly technical efforts, some of which I did not go so far as to try.  Or by fdisking.  Or, as one site described, replacing the registry with an old backup.

The fascinating thing was Ad-Aware kept finding it, in the form of one file and five registry entries, and removing it.  After rebooting, it would be back, despite all the ordinary means for something to return at startup being absent.  I tried removing the file in command prompt safe mode.  I tried replacing it with an innocuous file of the same name.  Going through info on the web regarding many variants of CW, I was finding nothing there to fit.  The one I did not end up pursuing before I had to go home was the winsock variant, which sounded nasty.

Another fascinating thing was what I found after Ad-Aware cleaned up.  You delve into these things enough and you can tell when there are files that don’t belong, that could have been placed there as part of malware, or spawned to create new instances and make it harder to kill.  Ad-Aware doesn’t necessarily see those, active or not.  I wiped out dozens of DLL, EXE and DAT files in the windows and system32 directories that were bogus.  What I look for is those extensions, with a recent file date, crazy file names, and multiple with the same date and size.  It’s a dead giveaway when you turn on the computer on, say, July 20, only for a little while to work on the malware problem.  Then on the 26th you see a bunch of files with names like uim6x9mt.dll, dated the 20th, with identical sizes.  No doubt a binary comparison would find them identical.  Purged many of those, to no avail.

Since it was not my place to reinstall the borrowed laptop (and I didn’t have any of the accompanying software), I returned it to the user and cautioned him to use Firefox, which I installed, instead of IE.  Doing so kind of defeats the purpose of CW, even if it remains on the system.  I left it for the owner of the machine to be made aware of the problem and act on it as he saw fit.

This stuff is really getting out of hand.



Powered by ExpressionEngine






Blog Empire

Solojent

Dispatches from Blogblivion

The Frugal Guy Cook

Geek Practitioners

Bizosphere

Neatly Tangled

RealityBucket

Divine Hamster

Carnival of the Capitalists

Tangent Mart

Retirees

Accidental Verbosity

Old Jay Solo

Jay Solo

Original Blogblivion


Blogs!

Acidman
Alphecca
American Digest
American Mind
America's North Shore Journal
And Then I Woke Up...
Attaboy
Aubrey Turner

Babalu Blog
Balloon Juice
Being Jennifer Garrett
Beth's Contradictory Brain
Big Red Giant
Blogblivion
Bogieblog
Bogus Gold
Brandon's Puppy
Bubba's Place
Business Pundit

Caerdroia
Distributed Republic
Chasing Grace
Claire Wolfe
Cootiehog
Cox & Forkum
Coyote Blog

Da Goddess
Dax Montana
Day by Day
Dean's World
Distributed Republic
Dizzy Girl
Dogs Don't Purr
Dog Snot Diaries
Drumwaster's Rants
Dustbury

Electric Venom
Enviropundit
Exgaucho

Farkleberries
Fire Ant Gazette
Freedom Lives
Future Pundit

Geek Practitioners Blog
Ghost of a Flea

Hell in a Handbasket
HE&OS
Heretical Ideas
Hit and Run
Hog On Ice
Hub Politics

IMAO
INCITE
Inoperable Terran
Instapundit
In The Pipeline
Irreverent Probity

Jaboobie's Journal
JawsBlog
Jay Manifold
Jay Reding
Jay Solo
Jeffrey Alan Miron
Jen Speaks
Julie Neidlinger: Web Log

KateSpot
Ken Jennings
Knowledge Problem

Laissez Faire Books Blog
Laughing Wolf
Laurence Simon
Lead and Gold
Les Jones
Let the Finder Beware
Libertarian Leanings
Libertyblog
Little Miss Attila
Lollygaggin
Low Earth Orbit

Marginal Revolution
MarsBlog
Martinis, Persistence and a Smile
McGehee Zone
Medrants
Mickey's Musings
Mike Campbell
The Moderate Voice
mountaineer musings
Mudville Gazette
My Button Box
My Life In Words

New England Republican
Ninjababe's Ramble
No Looking Backwards
NoodleFood
Not Exactly Rocket Science
No Treason!

O'DonnellWeb
One Fine Jay
One Sixteenth
The Online Lawyer
On the Third Hand
Outside The Beltway
Overactive Imagination
Overlawyered

Parkway Rest Stop
Pat Sajak
Peaktalk
Pearsonified
Planet Geek!
PoliBlog
Positive Liberty
Publicola
Practical Penumbra

The Queen of All Evil
Quibbles and Bits

Random Jottings
Random Nuclear Strikes
Regions of Mind
ResurrectionSong
Right Side of the Rainbow
Right Wing News
Ripples

SamaBlog
Samizdata
SCOTUS Blog
A Shareware Life
She Who Will Be Obeyed
Silflay Hraka
Smallest Minority
Somewhere On A1A
Suburban Blight
A Sweet, Familiar Dissonance

Tammi's World
Things You Should Do
Thinklings
Thought Mesh
Tiger
TigerHawk
Todd Sattersten
Transterrestrial Musings
Truth Laid Bear
Two-Four

Universal Hub

Velociman
Viking Pundit
Virginia Postrel
Virtualosophy
Vodka Pundit
Volokh Conspiracy

Walter in Denver
Weekend Pundit
The Window Manager
Winds of Change
Wizbang
Wizbang Bomb Squad
Wizbang Pop!
Wizbang Podcast
Wizbang Tech
Who knows what evil...
The World According To Wayne

XTremeBlog

Yet Another Weird SF Fan

ZenPundit

My Ecosystem Details

Who Links Here