Sometimes free work pays off

Although, truthfully I did get paid in Guinness and made from scratch cookies, but all the work I did on that laptop paid off in an unexpected way today.

I was sitting at the helpdesk early this morning, when our network admin came by with a laptop. It had been one of our pool laptops for a remote office before it got completely hosed by trojans and spyware. He had been working at cleaning it up off and on for a few weeks and had gotten to the point where there was just one trojan left on it, and he was having a hard time getting it cleaned, because the .dll that McAfee was identifying was attached to winlogon.exe. I agreed to take a look at it using some of the tools I still had on my thumb drive.

When I booted the laptop, and McAfee told me I was dealing with Adware.Virtumonde, the same exact bit of crap that I had struggled with on that other laptop, I knew I was only going to need one of those tools. The VundoFix tool. I ran it, let it do it’s thing, rebooted and voila, no more trojan warnings from McAfee.

Took me 15 minutes to do something our network admin had been struggling for weeks with. Tell me that doesn’t make me look good? 😉

Technorati tags: VundoFix, Spyware

Similar Posts

  • Happy St. Patrick’s

    I’ll have a more thorough essay on the meaning of St. Patrick’s Day and what not over at the other blog at some point later today. I’ve got a bunch of thoughts ruminating in my head about being Irish and what it means in today’s world. I’ve no time to get them down right now,…

  • News

    Just a few notes on some things that may, or may not, interest you: Movable Type version 2.6 has been released. You can download the Upgrade version or the full version here. This is where you can find the info on the Mac OS 10.2.4 Update. (link thanks to nfo.) Cafepress is running a coupon…

  • Thanks!

    Thanks go out to Shannon who had the answer to my IE title bar question. As soon as I read the solution I thought to myself, “Group Policy Editor! I knew there was a simple place to set that!” Thanks Shannon! Follow these topics: Uncategorized

  • Security is Happiness

    No seriously, I attended an Internet Security Systems demo/seminar this morning and they gave away t-shirts with big smiley faces and “Security is Happiness” printed under them. They’re pretty silly looking, I’ll try and webcam it tonight so you can see what I’m talking about. The seminar was decent, it’s always humorous when you setup…

4 Comments

  1. Does it even make sense to try and “clean-up” an infected PC in a business environment? How can you be sure you got all the viruses/spyware? Ghost it and move on.

  2. In this case, because the laptop came in from a remote office and didn’t start with us, there was no Ghost image, the only option was to wipe it clean and start over, but, naturally, we have no idea where the install CD’s are, and again, we don’t necessarily have the serial numbers to install everything all over again either because this remote office is somewhat lacking in keeping track of these things (Hence the reason this thing got infected in the first place!). That being said, we’re also NOT using it in anything closely related to production on the network. It will have a very insignificant role being used outside of the office from time to time by members of the IS team only, so that we can keep an eye out for problems.

  3. oh. seems like a fair amount of time was spent on an insignificant machine. but that’s how it works sometimes.

  4. Yeah, I totally agree with your point, but hey, one, it wasn’t much of my time, and two, it really wasn’t my call on how to handle it. I’m just a helpdesk jockey, ya know? 🙂

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)