My mostly computer illiterate mother got sucked in by Windows Advanced Security Center. (http://malwaretips.com/blogs/windows-advanced-security-center/) She used to call me every time windows firewall warned about outgoing connections, and they were always safe, so on her new computer, she figured she could just click OK every time it popped up.
So, I devised a plan:
1) have her download SuperAntiSpyware portable version to a flash drive
2) boot into safe mode and use part 1 to remove the malware.
my problems:
1) I'm across the country, and have to talk her through it on the phone. She's doing okay with my instructions. Her weak English isn't helping, as she slowly reads every word in every window from top to bottom, but that's what I get to deal with.
2) This malware is superbly designed. The window is splash across her desktop and start menu so that it covers almost everything. And when a new window is opened, the malware screen covers things up. I've tried to use different methods to get to safe mode, but the system doesn't work. Sometimes her clicks generate a "click in an invalid area" chime, sometimes a "torrent detected, download anonymizer now" window pops up instead of the desired window.
I tried to troubleshoot with her for a couple hours yesterday, then gave up and had dinner and tried to regroup.
Anyone have any hints? It's a cheapy Gateway that's mostly used for youtube viewing.
My planned approach for tonight:
1) try to get the system to boot off the stored Windows installer partition that's typically invisible within windows. I don't know if this computer has it. She has never made the restore CDs. Using this method, I hope to get her to safe mode.
2) That's all I have for today so far. If it fails, I'll let it stew until tomorrow before I get her to use the NUCULAR option.
My nuclear option for tomorrow:
1) factory reset via bios/alt boot. This is not an ideal outcome, as I don't know if the pictures saved on the computer will be erased. (not a huge deal as there are backups, but I won't be able to restore them for her until I visit home later this year)
tl;dr
1) I need help getting into safe mode
So, I devised a plan:
1) have her download SuperAntiSpyware portable version to a flash drive
2) boot into safe mode and use part 1 to remove the malware.
my problems:
1) I'm across the country, and have to talk her through it on the phone. She's doing okay with my instructions. Her weak English isn't helping, as she slowly reads every word in every window from top to bottom, but that's what I get to deal with.
2) This malware is superbly designed. The window is splash across her desktop and start menu so that it covers almost everything. And when a new window is opened, the malware screen covers things up. I've tried to use different methods to get to safe mode, but the system doesn't work. Sometimes her clicks generate a "click in an invalid area" chime, sometimes a "torrent detected, download anonymizer now" window pops up instead of the desired window.
I tried to troubleshoot with her for a couple hours yesterday, then gave up and had dinner and tried to regroup.
Anyone have any hints? It's a cheapy Gateway that's mostly used for youtube viewing.
My planned approach for tonight:
1) try to get the system to boot off the stored Windows installer partition that's typically invisible within windows. I don't know if this computer has it. She has never made the restore CDs. Using this method, I hope to get her to safe mode.
2) That's all I have for today so far. If it fails, I'll let it stew until tomorrow before I get her to use the NUCULAR option.
My nuclear option for tomorrow:
1) factory reset via bios/alt boot. This is not an ideal outcome, as I don't know if the pictures saved on the computer will be erased. (not a huge deal as there are backups, but I won't be able to restore them for her until I visit home later this year)
tl;dr
1) I need help getting into safe mode
