I spent most of last night and tonight cleaning my mom's laptop of viruses, spyware, malware, and all other manner of nasty crap.
There was one particularly nasty piece of malware called PestTrap that installs itself via an IE security hole (simply by visiting a web site) and then pretends to be an anti-spyware package. It proceeds to throw popup warning every hour or so about how your computer is infected and displays alert flags every 2-3 minutes claiming the same. In reality, they just want to annoy you until you pay to “register” the software, and steal your credit card info in the process.
Removing it turned into an ordeal of rebooting in safe mode, running some custom batch files, followed by two different malware removal programs, then an antivirus scan to finally get rid of it. Anything less and it would simply reinstall itself on the next boot. Ugly.
So she now has a copy of the free version of AVG AntiVirus along with instructions to run it weekly and scan every program they download. Also copies of both Ad-Aware and Spybot Search & Destroy with instructions to run them every other week. Finally, a copy of Mozilla Firefox installed and set as the default browser, with the IE View extension to make it easy to switch over to IE for the rare site that requires it. Oh yeah, and Windows Update set to automatically keep everything up-to-date.
All this because she canceled her AOL account, which at least offered some protection from this kind of crap, and switched to DSL (without telling me she did so.) Let's see… a Windows system that hadn't even been updated to SP2 (let alone any other security updates) connected directly to a DSL line, no firewall, no antivirus, nothing. Gee, I wonder how it got so fucked up?