<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Rupa Bose&#039;s Blog &#187; computers</title>
	<atom:link href="http://rupabose.com/tag/computers/feed/" rel="self" type="application/rss+xml" />
	<link>http://rupabose.com</link>
	<description>India, Asia, Business and Everything</description>
	<lastBuildDate>Wed, 08 Feb 2012 06:09:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='rupabose.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Rupa Bose&#039;s Blog &#187; computers</title>
		<link>http://rupabose.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://rupabose.com/osd.xml" title="Rupa Bose&#039;s Blog" />
	<atom:link rel='hub' href='http://rupabose.com/?pushpress=hub'/>
		<item>
		<title>The Virus Warriors Ride Again</title>
		<link>http://rupabose.com/2011/04/04/the-virus-warriors-ride-again/</link>
		<comments>http://rupabose.com/2011/04/04/the-virus-warriors-ride-again/#comments</comments>
		<pubDate>Mon, 04 Apr 2011 08:11:28 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Communications]]></category>
		<category><![CDATA[Doing Business in India]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Infrastructure]]></category>
		<category><![CDATA[computers]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[offshoring]]></category>

		<guid isPermaLink="false">http://rupabose.com/?p=1410</guid>
		<description><![CDATA[Back in January 2010, I wrote about the virus-warriors of Chennai &#8211; Microsoft&#8217;s Consumer Security Support team. Yesterday, I had occasion to call them again. They&#8217;re still awesome, though the phone access isn&#8217;t as good as last year. (And they&#8217;re &#8230; <a href="http://rupabose.com/2011/04/04/the-virus-warriors-ride-again/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rupabose.com&amp;blog=4975544&amp;post=1410&amp;subd=rupabose&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Back in January 2010, I wrote about <a href="http://rupabose.com/2010/01/08/microsoft-virus-warriors-chennai/">the virus-warriors of Chennai </a>&#8211; Microsoft&#8217;s Consumer Security Support team. Yesterday, I had occasion to call them again. <strong>They&#8217;re still awesome, </strong>though the phone access isn&#8217;t as good as last year.</p>
<p>(And they&#8217;re a refreshing counterpoint to the irritating <a href="http://rupabose.com/2010/05/14/guess-who-called-me-dish-network/">call-center interruptions from Dish Network</a>&#8230;)</p>
<p><a href="http://rupabose.files.wordpress.com/2011/04/troubled-computer.png"><img class="alignright size-thumbnail wp-image-1414" title="troubled computer" src="http://rupabose.files.wordpress.com/2011/04/troubled-computer.png?w=150&#038;h=119" alt="" width="150" height="119" /></a>I knew <strong>something was wrong </strong>when I went into my Yahoo email account a couple of days ago. The list of emails in my inbox looked fine, but when I clicked on one entitled  &#8221;Meeting next week?&#8221; instead of the expected note from my friend, it was spam. I presumed it was a Yahoo glitch, and carried on.</p>
<p>But when I went to Google, it was clear this wasn&#8217;t just any little glitch. The same thing was happening with my Google searches. They were getting hijacked to evil sites like &#8220;Ta*zinga&#8221; and &#8220;add*edsuccess&#8221; (The asterisks are mine. Just to be safe.)</p>
<p>So I ran a full scan with Microsoft Security Essentials. A couple of hours later it came up with the culprit: a Trojan called Tracur.Gen!B &#8212; which it said it had removed.</p>
<p><strong>It hadn&#8217;t.</strong> My Searches were still being hijacked, and another full scan gave me the exact same result: Trojan:JS/Tracur.Gen!B</p>
<p><strong>TIME TO CALL MICROSOFT</strong></p>
<p>This time, I knew to go directly to Microsoft&#8217;s Security people for help. (I couldn&#8217;t get to the forums in any case, with all my searches being redirected.) They&#8217;d been winners the last time, the young people in Chennai. I emailed, got my support case number and the phone number to call. The last time, I&#8217;d gotten through almost instantly. Not now. Instead, I got <strong>put on endless hold </strong>of music and commercial messages. I gave up. Night- time would be better.</p>
<p>Around 10 p.m. I got through much faster, to &#8220;Jason&#8221;  who was possibly Jaisingh or Janak, I don&#8217;t know. (Or may even actually be  Jason. ) I explained the problem, then told him that the last time, it had been Kaspersky&#8217;s tdsskiller that fixed the problem.</p>
<p>&#8220;<strong>This is more powerful than Kaspersky</strong>,&#8221; Jason told me. I visualized a videogame screen, Tracur and Kaspersky battling it out in armor with swords. My best bet, he thought, would be to run MRT (Microsoft&#8217;s Malware Removal Tool) and then call them back. It would take several hours, he said. So I ran it, and it took several hours, at the end of which it showed&#8230; <em>nothing</em>. But my searches were still being hijacked.</p>
<p><strong>RAHUL TO THE RESCUE</strong></p>
<p>I called them back, and this time Rahul answered the phone and took my case number. He cut to the chase, sharing my computer, running some searches for and with Bing (I have Google as my home page), and noting how those got redirected. Then he ran Kaspersky. It showed&#8230; nothing, again nothing. But searches were still being hijacked. <em>So Jason was right</em>. I pictured Tracur standing with a victorious foot on fallen Kaspersky&#8217;s chest.</p>
<p>&#8220;How come Microsoft Security Essentials didn&#8217;t block this?&#8221; I asked, annoyed.  If this problem didn&#8217;t get fixed, this machine was doomed to spend its remaining days as an isolated super-typewriter with no internet access.</p>
<p>At this point, Rahul (who still controlled my computer) removed my existing Internet Explorer. &#8220;You&#8217;ll lose all your cookies and saved passwords and settings,&#8221; he said apologetically before he started.</p>
<p>&#8220;Go for it,&#8221; I said. Who cared about cookies when the searches were being stolen? &#8220;Is it a browser problem? I just got rid of Firefox because it seemed to be lodged there, but that didn&#8217;t fix it.&#8221;</p>
<p>&#8220;Sometimes,&#8221; he said, a bit doubtfully. Then he downloaded the latest version of Explorer.</p>
<p><a href="http://rupabose.files.wordpress.com/2011/04/computer-fixed-2.png"><img class="size-thumbnail wp-image-1420 alignleft" title="computer, relieved..." src="http://rupabose.files.wordpress.com/2011/04/computer-fixed-2.png?w=150&#038;h=120" alt="" width="150" height="120" /></a>And wondrously, <strong>the searches were back to normal</strong>. It was now maybe 3 a.m., and worth every minute of the time it took.</p>
<p>Thanks, guys! Great job.</p>
<p>(Later, I ran another full scan with Microsoft Security Essentials. This time, it also showed nothing. I have my fingers crossed the machine stays clean.)</p>
<p style="text-align:center;">###</p>
<p style="text-align:left;">And yes, my tech-expert friends, I know I should be running Linux. I just find the learning curve a bit too steep&#8230;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/rupabose.wordpress.com/1410/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/rupabose.wordpress.com/1410/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/rupabose.wordpress.com/1410/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/rupabose.wordpress.com/1410/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/rupabose.wordpress.com/1410/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/rupabose.wordpress.com/1410/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/rupabose.wordpress.com/1410/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/rupabose.wordpress.com/1410/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/rupabose.wordpress.com/1410/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/rupabose.wordpress.com/1410/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/rupabose.wordpress.com/1410/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/rupabose.wordpress.com/1410/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/rupabose.wordpress.com/1410/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/rupabose.wordpress.com/1410/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rupabose.com&amp;blog=4975544&amp;post=1410&amp;subd=rupabose&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://rupabose.com/2011/04/04/the-virus-warriors-ride-again/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ac0654f6274a01d9288dc044bd6a5823?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">webmaster</media:title>
		</media:content>

		<media:content url="http://rupabose.files.wordpress.com/2011/04/troubled-computer.png?w=150" medium="image">
			<media:title type="html">troubled computer</media:title>
		</media:content>

		<media:content url="http://rupabose.files.wordpress.com/2011/04/computer-fixed-2.png?w=150" medium="image">
			<media:title type="html">computer, relieved...</media:title>
		</media:content>
	</item>
		<item>
		<title>Virus-Warriors in Chennai</title>
		<link>http://rupabose.com/2010/01/08/microsoft-virus-warriors-chennai/</link>
		<comments>http://rupabose.com/2010/01/08/microsoft-virus-warriors-chennai/#comments</comments>
		<pubDate>Fri, 08 Jan 2010 08:14:24 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Communications]]></category>
		<category><![CDATA[Doing Business in India]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Infrastructure]]></category>
		<category><![CDATA[computers]]></category>
		<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[offshoring]]></category>
		<category><![CDATA[outsourcing]]></category>

		<guid isPermaLink="false">http://www.rupabose.com/?p=632</guid>
		<description><![CDATA[Oftentimes, Americans talking about outsourcing offshoring have stories of  clueless youngsters with incomprehensible accents. I&#8217;ll admit that I&#8217;ve encountered inefficiencies and poor training; my experience as a consumer hasn&#8217;t been all good. One airline managed to give me four mutually &#8230; <a href="http://rupabose.com/2010/01/08/microsoft-virus-warriors-chennai/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rupabose.com&amp;blog=4975544&amp;post=632&amp;subd=rupabose&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Oftentimes, Americans talking about <span style="text-decoration:line-through;">outsourcing</span> offshoring have stories of  clueless youngsters with incomprehensible accents. I&#8217;ll admit that I&#8217;ve encountered inefficiencies and poor training; my experience as a consumer hasn&#8217;t been all good. One airline managed to give me four mutually exclusive answers to the same question&#8230;</p>
<p>But that&#8217;s not what I want to write about today. Today, it&#8217;s<strong> kudos to the Microsoft security people based in Chennai</strong>.</p>
<p><a href="http://rupabose.files.wordpress.com/2010/01/curses.png"><img class="size-thumbnail wp-image-637 alignleft" title="curses" src="http://rupabose.files.wordpress.com/2010/01/curses.png?w=150&#038;h=150" alt="" width="150" height="150" /></a>My computer had been colonized by the Alureon CT trojan, or actually<span style="text-decoration:underline;"> <a href="http://blogs.technet.com/mmpc/archive/2010/01/07/some-observations-on-rootkits.aspx">rootkit</a> </span>. <strong>I didn&#8217;t even know</strong>: Norton Internet Security, (which is what I had) doesn&#8217;t see it, let alone block it. Then one day, someone suggested downloading<span style="text-decoration:underline;"> <a href="http://www.microsoft.com/security_essentials/">Microsoft Security Essentials</a></span>. It found Alureon CT, cleaned the computer, and then suggested I restart the machine. I did. And <strong>within minutes, Alureon was back</strong>.  (Norton still showed nothing amiss.)</p>
<p>Rinse and repeat.</p>
<p>The infection explained some weird things that had been happening &#8211; like search hijackings, where clicking on a link took me someother-place.com. I&#8217;d attributed it to my computer aging and becoming incompatible with updated search engines. The thing is insidious; it keeps very quiet, but  it can steal passwords and make your computer part of a network outside your control.</p>
<p>I also found that getting rid of Alureon was Not Easy. Someone on<span style="text-decoration:underline;"> <a href="http://social.answers.microsoft.com/Forums/en-US/msescan/thread/beb58df0-388f-4c3f-9c13-3c426f2e46f6/">one forum</a></span> opined &#8220;<em>formatting and reinstallation of the operating system is the only sure way&#8230;</em>&#8220;</p>
<p>Someone else suggested <strong>opening a support file with Microsoft</strong>.  <em>&#8220;Start here &#8211; <span style="text-decoration:underline;"><a href="https://support.microsoftsecurityessentials.com/">https://support.microsoftsecurityessentials.com/</a></span> and select the link that says </em>I think my computer is infected<em> and then select the support option for phone (or email if phone is not offered for your region).&#8221;</em></p>
<p><span id="more-632"></span></p>
<p><a href="http://rupabose.files.wordpress.com/2010/01/person-left1.png"><img class="alignright size-thumbnail wp-image-655" title="person left" src="http://rupabose.files.wordpress.com/2010/01/person-left1.png?w=150&#038;h=150" alt="" width="150" height="150" /></a>So I did. <strong>Within minutes, I was in touch with their 24/7 phone help</strong>, given a case number and immediate assistance. &#8220;Nanda&#8221; shared my computer, performed a scan, emptied my temp files and cookies, and pronounced it cured.  But it wasn&#8217;t.</p>
<p>I e-mailed him (the engineer who&#8217;s been helping you provides an e-mail address) that it wasn&#8217;t working, and sent them a link to <span style="text-decoration:underline;"><a href="http://www.prevx.com/blog/139/Tdss-rootkit-silently-owns-the-net.html">a particularly dire article</a></span> on Alureon. I assumed the only <strong>solution was to go off and rebuild my computer </strong>with much cursing.</p>
<p>Well, Microsoft called back. The case isn&#8217;t closed until the problem is fixed. They wanted to give it a second try. This person had actually heard about rootkit infections. &#8220;I am going to run Kaspersky&#8217;s tdsskiller,&#8221; he said.</p>
<p>&#8220;I read that Norton, McAfee, Kaspersky, none of them work,&#8221; I argued, annoyed. This was going to be another afternoon of rote, by-the-book attempts. &#8220;I read that I have to rebuild.&#8221;</p>
<p>&#8220;Yes,&#8221; he said. &#8220;But sometimes the people on the forums are not aware of special programs like tdsskiller. I believe we can clean your computer without having to reinstall the operating system.&#8221;</p>
<p>I had nothing to lose, so I stood by while &#8220;Allan&#8221; took over my computer.</p>
<p>What do you know? It worked. I ran a full MSE scan, which took 2.5 hours. <strong>My computer was clean</strong>. Now, 36 hours later, it&#8217;s still clean.</p>
<p>I told my brother, who&#8217;s been active in the outsourcing space. <strong>&#8220;Those young people in Chennai,&#8221; he said. &#8220;They&#8217;re good.&#8221;</strong></p>
<p>Yes. They are.</p>
<p>Thanks, Nanda, Alan/ Arul, and all the folks on the forums.</p>
<p>&#8212;&#8212;&#8211;</p>
<p><em>[ETA: Some people still think it makes sense to reinstall the OS even after Alureon has been removed, because Alureon could have allowed undetected malware including keystroke loggers to lodge in the computer. As a precaution, I'm not using this machine for anything sensitive.]</em></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/rupabose.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/rupabose.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/rupabose.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/rupabose.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/rupabose.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/rupabose.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/rupabose.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/rupabose.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/rupabose.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/rupabose.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/rupabose.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/rupabose.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/rupabose.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/rupabose.wordpress.com/632/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rupabose.com&amp;blog=4975544&amp;post=632&amp;subd=rupabose&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://rupabose.com/2010/01/08/microsoft-virus-warriors-chennai/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ac0654f6274a01d9288dc044bd6a5823?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">webmaster</media:title>
		</media:content>

		<media:content url="http://rupabose.files.wordpress.com/2010/01/curses.png?w=150" medium="image">
			<media:title type="html">curses</media:title>
		</media:content>

		<media:content url="http://rupabose.files.wordpress.com/2010/01/person-left1.png?w=150" medium="image">
			<media:title type="html">person left</media:title>
		</media:content>
	</item>
	</channel>
</rss>
