<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Rupa Bose&#039;s Blog &#187; Kaspersky</title>
	<atom:link href="http://rupabose.com/tag/kaspersky/feed/" rel="self" type="application/rss+xml" />
	<link>http://rupabose.com</link>
	<description>India, Asia, Business and Everything</description>
	<lastBuildDate>Wed, 08 Feb 2012 06:09:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='rupabose.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Rupa Bose&#039;s Blog &#187; Kaspersky</title>
		<link>http://rupabose.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://rupabose.com/osd.xml" title="Rupa Bose&#039;s Blog" />
	<atom:link rel='hub' href='http://rupabose.com/?pushpress=hub'/>
		<item>
		<title>Virus-Warriors in Chennai</title>
		<link>http://rupabose.com/2010/01/08/microsoft-virus-warriors-chennai/</link>
		<comments>http://rupabose.com/2010/01/08/microsoft-virus-warriors-chennai/#comments</comments>
		<pubDate>Fri, 08 Jan 2010 08:14:24 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Communications]]></category>
		<category><![CDATA[Doing Business in India]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Infrastructure]]></category>
		<category><![CDATA[computers]]></category>
		<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[offshoring]]></category>
		<category><![CDATA[outsourcing]]></category>

		<guid isPermaLink="false">http://www.rupabose.com/?p=632</guid>
		<description><![CDATA[Oftentimes, Americans talking about outsourcing offshoring have stories of  clueless youngsters with incomprehensible accents. I&#8217;ll admit that I&#8217;ve encountered inefficiencies and poor training; my experience as a consumer hasn&#8217;t been all good. One airline managed to give me four mutually &#8230; <a href="http://rupabose.com/2010/01/08/microsoft-virus-warriors-chennai/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rupabose.com&amp;blog=4975544&amp;post=632&amp;subd=rupabose&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Oftentimes, Americans talking about <span style="text-decoration:line-through;">outsourcing</span> offshoring have stories of  clueless youngsters with incomprehensible accents. I&#8217;ll admit that I&#8217;ve encountered inefficiencies and poor training; my experience as a consumer hasn&#8217;t been all good. One airline managed to give me four mutually exclusive answers to the same question&#8230;</p>
<p>But that&#8217;s not what I want to write about today. Today, it&#8217;s<strong> kudos to the Microsoft security people based in Chennai</strong>.</p>
<p><a href="http://rupabose.files.wordpress.com/2010/01/curses.png"><img class="size-thumbnail wp-image-637 alignleft" title="curses" src="http://rupabose.files.wordpress.com/2010/01/curses.png?w=150&#038;h=150" alt="" width="150" height="150" /></a>My computer had been colonized by the Alureon CT trojan, or actually<span style="text-decoration:underline;"> <a href="http://blogs.technet.com/mmpc/archive/2010/01/07/some-observations-on-rootkits.aspx">rootkit</a> </span>. <strong>I didn&#8217;t even know</strong>: Norton Internet Security, (which is what I had) doesn&#8217;t see it, let alone block it. Then one day, someone suggested downloading<span style="text-decoration:underline;"> <a href="http://www.microsoft.com/security_essentials/">Microsoft Security Essentials</a></span>. It found Alureon CT, cleaned the computer, and then suggested I restart the machine. I did. And <strong>within minutes, Alureon was back</strong>.  (Norton still showed nothing amiss.)</p>
<p>Rinse and repeat.</p>
<p>The infection explained some weird things that had been happening &#8211; like search hijackings, where clicking on a link took me someother-place.com. I&#8217;d attributed it to my computer aging and becoming incompatible with updated search engines. The thing is insidious; it keeps very quiet, but  it can steal passwords and make your computer part of a network outside your control.</p>
<p>I also found that getting rid of Alureon was Not Easy. Someone on<span style="text-decoration:underline;"> <a href="http://social.answers.microsoft.com/Forums/en-US/msescan/thread/beb58df0-388f-4c3f-9c13-3c426f2e46f6/">one forum</a></span> opined &#8220;<em>formatting and reinstallation of the operating system is the only sure way&#8230;</em>&#8220;</p>
<p>Someone else suggested <strong>opening a support file with Microsoft</strong>.  <em>&#8220;Start here &#8211; <span style="text-decoration:underline;"><a href="https://support.microsoftsecurityessentials.com/">https://support.microsoftsecurityessentials.com/</a></span> and select the link that says </em>I think my computer is infected<em> and then select the support option for phone (or email if phone is not offered for your region).&#8221;</em></p>
<p><span id="more-632"></span></p>
<p><a href="http://rupabose.files.wordpress.com/2010/01/person-left1.png"><img class="alignright size-thumbnail wp-image-655" title="person left" src="http://rupabose.files.wordpress.com/2010/01/person-left1.png?w=150&#038;h=150" alt="" width="150" height="150" /></a>So I did. <strong>Within minutes, I was in touch with their 24/7 phone help</strong>, given a case number and immediate assistance. &#8220;Nanda&#8221; shared my computer, performed a scan, emptied my temp files and cookies, and pronounced it cured.  But it wasn&#8217;t.</p>
<p>I e-mailed him (the engineer who&#8217;s been helping you provides an e-mail address) that it wasn&#8217;t working, and sent them a link to <span style="text-decoration:underline;"><a href="http://www.prevx.com/blog/139/Tdss-rootkit-silently-owns-the-net.html">a particularly dire article</a></span> on Alureon. I assumed the only <strong>solution was to go off and rebuild my computer </strong>with much cursing.</p>
<p>Well, Microsoft called back. The case isn&#8217;t closed until the problem is fixed. They wanted to give it a second try. This person had actually heard about rootkit infections. &#8220;I am going to run Kaspersky&#8217;s tdsskiller,&#8221; he said.</p>
<p>&#8220;I read that Norton, McAfee, Kaspersky, none of them work,&#8221; I argued, annoyed. This was going to be another afternoon of rote, by-the-book attempts. &#8220;I read that I have to rebuild.&#8221;</p>
<p>&#8220;Yes,&#8221; he said. &#8220;But sometimes the people on the forums are not aware of special programs like tdsskiller. I believe we can clean your computer without having to reinstall the operating system.&#8221;</p>
<p>I had nothing to lose, so I stood by while &#8220;Allan&#8221; took over my computer.</p>
<p>What do you know? It worked. I ran a full MSE scan, which took 2.5 hours. <strong>My computer was clean</strong>. Now, 36 hours later, it&#8217;s still clean.</p>
<p>I told my brother, who&#8217;s been active in the outsourcing space. <strong>&#8220;Those young people in Chennai,&#8221; he said. &#8220;They&#8217;re good.&#8221;</strong></p>
<p>Yes. They are.</p>
<p>Thanks, Nanda, Alan/ Arul, and all the folks on the forums.</p>
<p>&#8212;&#8212;&#8211;</p>
<p><em>[ETA: Some people still think it makes sense to reinstall the OS even after Alureon has been removed, because Alureon could have allowed undetected malware including keystroke loggers to lodge in the computer. As a precaution, I'm not using this machine for anything sensitive.]</em></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/rupabose.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/rupabose.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/rupabose.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/rupabose.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/rupabose.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/rupabose.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/rupabose.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/rupabose.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/rupabose.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/rupabose.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/rupabose.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/rupabose.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/rupabose.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/rupabose.wordpress.com/632/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rupabose.com&amp;blog=4975544&amp;post=632&amp;subd=rupabose&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://rupabose.com/2010/01/08/microsoft-virus-warriors-chennai/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ac0654f6274a01d9288dc044bd6a5823?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">webmaster</media:title>
		</media:content>

		<media:content url="http://rupabose.files.wordpress.com/2010/01/curses.png?w=150" medium="image">
			<media:title type="html">curses</media:title>
		</media:content>

		<media:content url="http://rupabose.files.wordpress.com/2010/01/person-left1.png?w=150" medium="image">
			<media:title type="html">person left</media:title>
		</media:content>
	</item>
	</channel>
</rss>
