Friday, May 06, 2011

Ok, being mostly computer literate, except when I have a brain-fart (wait, can I say that on the blog-o-sphere?), I was perplexed by my computer's behavior.

Firefox (browser of choice, thank you Ad-Block): The close, maximize/restore, and minimize buttons were hidden by a weird half-covering. No extra toolbars (I checked), no weird extensions, etc.

Internet Exploder (I think I'm running 8.something): No real definite visible change.

However, every so often, I'd get a pop-up window, in whatever browser I had open. Strange. The first time, I wondered if I had clicked on a Google result that had been taken over. No, I went back, and it was fine.

Then, it happened enough times that I was getting annoyed. The pop-ups didn't happen so fast that I could barely close them. To me, this is actually pretty smart; if the computer is unusable, a non-techie just shuts it down, and gets someone to fix it. Spyware / malware / virus eliminated, no more income for the scumbag. However, for this one, if I were a non-techie, it didn't happen frequently enough that I would have thought too much about it.

So, I started doing some searches for this, and when I went to certain sites, I didn't get the actual site, but some advertisement. I could click on Google to get the preview window, but when I tried to bring up the site, it was an ad. Now, remember, these sites were all about different virus / spyware problems, so the spyware / malware / virus may actually be smart enough to detect this. I don't know, and I don't care at this point.

So, I run my anti-virus (which is always resident anyway, but I give it another chance). Nothing found. Grr.

Run Ad-Aware, always there for me, to find stuff like this ... Nothing. Double-grr.

Ok, Spybot Search and Destroy ... oops, it's not installed yet (did a full re-install several months ago, must have missed that one). Run the scan, and, "Ooooh, that's a BINGO!" (if you recognize the quote, give yourself 100 internets).

I don't know where I picked it up (I normally run anything that MIGHT be a problem in a VM, so if it infects something, it will only be around until it shutdown that VM, which I have setup to reset the VM back to the last snapshot). I guess I was lazy this time, or didn't realize the risk.

Bad me. But good Spybot S&D -- usually between it and Ad-Aware, they catch everything I've been tagged with.