Thursday, August 23, 2007

Sneaky Pete

Work yesterday and the day before went well with the exception of the open case that will not ever seem to close. It is an intermittent problem that involves a "bolt on" application to SAP. No one has been able to resolve it yet and we have an open ticket with the vendor for resolution. We shall see.

I stopped by the house of a family who goes to our church. They asked me to look at their PC and do what was needed to get it back into good shape, up to and including re-rolling it. They stated they had backed up their data so a re-roll was okay with them.

I got it home and ran the usual virus and spyware checks. I found one virus file and four spyware/trojan/malware programs running...two which worried me. One turned off the Windows firewall and the other was a DNS redirect program. Well, I now know where the pr0n pop-ups were coming from!

After cleaning those I next removed a lot of demo/shareware programs and then cleaned out all the temp/useless files. I got about a gigabyte of junk cleared out when that was done.

I was told by the mother that one of her sons had been downloading stuff and causing all the PC issues. The had locked down all the accounts, but he still found a way to wreck havoc. What he did after mom locked out his account was hack into his dad's account (who never hardly used that PC...he had one of his own) and do his pr0n surfing from there. Once that was discovered, he started using the guest account (which had full admin access) to do his dirty deeds. That was discovered very quickly and all access to the PC was turned off to him except a very minimal amount.

After realizing this, I looked into pr0n boy and his father's profile. Both were 1.5 GIGS in size. To give you an idea of how big that is, my work PCs main profile, the PC I use 8-10 every day, is only 450 megs. Since I was given the okay to wipe the HD, I just killed those two profiles. I cleared out three gigs more of space.

After that fun job, I ran 3 different reg tools and cleared about eight megs of registry data and compacted it. I rebooted after each step and by this time the machine was easily five times faster than it was when I got it. The last two steps will be handled today. The first is a final virus/malware/trojan/spyware scan with Trend Micro's online tool. once that is done and rebooted, I will run a full defrag. That could take the rest of the night :-) .

I want to clear all this up before this weekend since we have the men's retreat then. I plan on having a good time.

No comments: