Sunday, August 30, 2015

Profiles in PC Poisoning, Part 5

If you are new to file recovery (as I was), I encourage you to go through the set of brief articles thereon written by PCSupport.About.com's Tim Fisher, specifically
(1) "How To Recover Deleted Files",
(2) "Will a Data Recovery Program Undelete Anything Ever Deleted?",
(3) "How Long is Too Long Before a File is Unrecoverable?", and
(4) "Why Are Some Deleted Files Not 100% Recoverable?".
Once you've read these guys, check out Tim's "19 Free Data Recovery Software Tools" survey.

Interestingly, CTB-Locker does not encrypt the original target files but rather copies thereof.
It’s important to know that CTB Locker creates copies of your files and encrypts them. In the meanwhile, the original files get deleted. There are applications out there that can restore the removed data. ... The newest version of the ransomware under consideration tends to apply secure deletion with several overwrites, but in any case this method is worth a try.
- "CTB Locker removal: how to decrypt files encrypted by CTB Locker virus"
Consequently, a number of the ctb-locker decrypt search pages suggest that a file recovery tool may be able to recover the original target files. The "Some ideas to restore files encrypted by CTB Locker" article from which I quoted last time recommends the Recuva program in this regard. Recuva has both a free version and a "professional" version for $24.95, and the former has pride of place in the aforecited "19 Free Data Recovery Software Tools" survey. Sounds good, let's do this, shall we? So, I go to this download page and download the rcsetup152.exe installer executable and then run the installer to install Recuva.

Recuva comes to us courtesy of Piriform, the same folks who make the CCleaner unnecessary file remover. Piriform maintains help documentation for Recuva here; it's not necessary to read this material to use Recuva, although doing so will give you a more complete (but not completely complete) view of the program.

Recuva run

Recuva has two modes of operation: a "wizard mode" and an "advanced mode". With respect to searching a computer for deleted files, I find that the advanced mode does not in practice do anything that can't be done with the wizard mode, although the former does provide an interface via which search results can be parsed in a value-added way, as we'll see below. When first launched, Recuva starts in the wizard mode.



We can go straight to the advanced mode by clicking the window's button, but let's stay in the wizard mode for the time being. Clicking the button takes us to a second window with a menu of files types that we may want to recover.



The menu's All Files radio button is checked by default; I'd stick with this option as its search results can be easily 'filtered' for specific file types in the advanced mode. Clicking the window's button takes us to a third window with a menu of locations where the files of interest may have been prior to their deletion.



We will target the Recovery (D:) volume in our quest to recover the .wps, .jpg, and .pdf My Documents\ data. Accordingly, we check the menu's In a specific location radio button and enter D:\ into the text input below the radio button label by either
(a) clicking the button and navigating to the Recovery (D:) location in the Browse For Folder window that pops up



and then clicking the button or just
(b) manually typing D:\ in the input.

The D:\ volume gives us a much better shot at recovering our data than does the Local Disk (C:) volume because cleaning up the computer entailed some 'write-heavy activity' - specifically, several software installs - in the latter, and there's a pretty good likelihood that some of the data has been overwritten by that activity: see the Stop using your computer! subsection of the aforecited "How To Recover Deleted Files" article.

Clicking the File location window's button takes us to a Thank you, Recuva is now ready to search for your files window in which we can elect to carry out a "deep scan".



Let's stick with a non-deep scan for now. Clicking the button starts a 3-stage scanning process.
Stage 1 of 3: Scanning drive for deleted files
Stage 2 of 3: Analyzing damage
Stage 3 of 3: Analyzing file contents
When Stage 3 has finished, Recuva displays a window with a list of files that may or may not be recoverable.



Each file name is preceded by a solid circle whose color indicates the likelihood of recovery, which is "excellent" for a circle, "acceptable" for a circle, or "unlikely" for a circle.

Now, a humongous list of >6000 files is not exactly a user-friendly data set; we can directorily organize the list and shed parts of it we don't want in the advanced mode, so let's switch to the advanced mode by clicking the button, which gives the window below:



Shaking the tree

By default, Recuva outputs a list view display for its search results; you can switch the display to a volume- and directory-organized tree view by clicking the button and then selecting the Tree View option in the View mode menu on the General tab of the Options window that pops up:



Clicking the button gives a display window with a single
D:\
result, whose expansion returns:



My menu is like a sieve

Between the button-menu and the button, the advanced-mode display window features a text input-menu via which the search results can be filtered by file type.



The Pictures, Music, Documents, Video, Compressed, and Emails file categories are defined for the wizard mode here; I'm pretty sure (but not 100% sure) that these definitions also apply to an advanced-mode non-deep scan.

Moreover, we can enter an *.ext1|*.ext2... expression into the input to zero in on files with specific extensions: à la the syntax of regular expressions, * matches zero or more file name characters and | serves as a boolean OR operator; for example, we can isolate the results' .wps, .jpg, and .pdf files by typing *.wps|*.jpg|*.pdf in the input.

Hmmm, ten screenshots, that's enough for one post, wouldn't you say? We'll continue our Recuva conversation in the following entry.

Monday, August 17, 2015

Profiles in PC Poisoning, Part 4

Before we get rolling, I have an addition to make to the Undamaged section of the previous post: somewhat surprisingly, CTB-Locker didn't encrypt any of the 1,850 .gif images on my father's computer - my guess is they weren't targeted because most (>95%) of them lie outside the C:\Documents and Settings\ directory.

So, what are we going to do about those .jkffbil.xyz, .bqtuzhl.xyz, and .xyz files? Is there any chance of recovering the original .wps, .jpg, and .pdf data in the My Documents\ folder?

A ctb-locker decrypt Google search brings up a number of pages that dole out advice for dealing with the aftermath of a CTB-Locker infection, and there is general agreement that restoring files from an external backup is the optimal response thereto. In the words of the Kaspersky guys themselves:
The best line of defense against this and other threats is to have backed up your machine yesterday (and to back it up again next week).
However, my father has never copied his My Documents\ data to an external medium of any type even though blank CD-Rs are cheap - you can buy a 50-disk spindle of 'em at Walmart for $10 - and copying stuff to a CD with his system is as easy as one, two, ... twelve.

Burnin' for you

A copy files to a cd windows xp Google search returns about a page's worth of pages with instructions for burning files and folders to a CD on a Windows XP machine. Because none of these pages quite describes what I do and what happens when I burn a CD on my father's computer, I thought I would give you my own little procedure in this regard.

(1) I begin by inserting a blank CD into the slot-loading CD-RW (F:) drive, which is the lower of the two optical drives held by the PC tower. (Above the F: drive is an E: drive for DVDs.)

(2) Up pops a CD Drive (F:) window that contains a menu of Windows actions for the CD.



The copy files to a cd windows xp search pages say that you should click on the Open writable CD folder using Windows Explorer option although I find that the Take no action option is also serviceable. I don't know anything about the Nero Express and Nero StartSmart programs: whatever they are, they're not necessary.

(3) Via the My Computer icon or the My Documents icon on the desktop, I navigate to the file or folder that I want to write to the CD and select it (click on it once). Holding down the Shift key allows me to select a range of consecutive items in the same directory; holding down the Ctrl key allows me to select nonconsecutive items in the same directory.

(4) I go to the Edit menu and choose the Copy To Folder... command.



(5) A Copy Items window containing a menu of places to copy the item(s) pops up.



I select the CD Drive (F:) option and then click the button at the bottom of the window.

(6) Depending on how much stuff I am copying, I may at this point see a Copying... window that displays an animation of the to-be-copied item(s) moving from folder to folder along a parabolic path.

(7) A tooltip-like speech balloon pops up in the lower-right-hand corner of the screen. The balloon points to a little CD icon in the taskbar and bears a message that reads:

You have files waiting to be written to the CD.
To see the files now, click this balloon.



(8) Clicking the balloon (vs. the icon it's pointing to) displays another CD Drive (F:) window.



Below the window's Standard Buttons toolbar
(a) a Files Ready to Be Written to the CD right pane lists the item(s) to be copied and
(b) a Write these files to CD command appears in a CD Writing Tasks menu in the left pane.

(9) Selecting the right-pane item(s) and clicking the Write these files to CD command launches the Windows CD Writing Wizard.



(10) By default, the CD name is set to the current date in a 3-letter-month-abbr DD YYYY format: you may fill in a different name if this is not to your liking.

(11) Clicking the button starts the burning process.



(12) When the burning is finished, the CD is ejected and a separate window announcing You have successfully written your files to the CD pops up.



Click the button and that's all she wrote.

One more point about screenshots

By default, Paint saves a screenshot as a (24-bit) .bmp image, which is uncompressed and therefore has a much larger memory footprint than, say, a .png image: you can and should save a screenshot as the latter via the Save as type: menu at the bottom of the Save As window.



Dark shadows

In the absence of an external backup, the ctb-locker decrypt search pages suggest two other courses of action for retrieving files encrypted by CTB-Locker:

(1) See if Windows' Volume Shadow Copy Service (VSS) has saved previous versions of the files.
Solution 3: Use the Volume Shadow Copy​
In case you didn't know, the operating system creates so-called volume shadow copies of each file if the Windows System Restore is enabled on the computer. In this way the restore points are created at specified intervals, with snapshots of the files as they appear at the moment that are generated at the same time. This method does not guarantee the recovery of the latest versions of the files but is certainly appropriate to carry out a test anyway.
- "Some ideas to restore files encrypted by CTB Locker"
The Volume Shadow Copy Service was first implemented in Windows XP but the volume snapshots it creates with Windows XP are only temporary; persistent snapshots began with the Vista version of Windows. Undeterred - and seeing a vssvc.exe executable in the C:\WINDOWS\system32\ directory - I launched the Windows Command Prompt (Start → Programs → Accessories → Command Prompt) and ran vssadmin list shadows on the command line: No shadow copies present in the system. So much for that idea.

(2) See if the original files can be recovered via a file recovery tool -
we'll get into this next time.

Monday, July 27, 2015

Profiles in PC Poisoning, Part 3

In the previous post, I detailed the removal of the CTB-Locker Trojan from my father's computer with Malwarebytes Anti-Malware. Up to this point I haven't been very specific about the damage that CTB-Locker left in its wake - I'll get into that today.

Encryption prototype

CTB-Locker encrypted hundreds of files on my father's computer. For example, CTB-Locker converted a Byron.wps file to a Byron.wps.xyz file.

The Byron.wps document was created by the word processor module of Microsoft Works, which was discontinued by Microsoft several years ago. Besides Microsoft Works, both Microsoft Word and Notepad can open a .wps file; in the latter case most of the file will be unintelligible but the original .wps content will be present therein and can be extracted if desired.

Now, what about the Byron.wps.xyz file? As it happens, there is a recognized .xyz file format, but it has nothing to do with word processing. An attempt to open Byron.wps.xyz with Microsoft Works throws the following error:
Works cannot open "C:\Documents and Settings\Owner\Desktop\Byron.wps.xyz". The file may be in use by another application, the file format may not be supported by any of the installed converters, or the file may be corrupt.
The file can be opened with Microsoft Word or Notepad but the content is complete gobbledygook in both cases. (BTW, subtracting the .xyz extension from the file name does not give a readable file, in case you were wondering.)

C: damage

In the computer's Local Disk (C:) volume, CTB-Locker mainly targeted two folders:
(1) C:\Documents and Settings\Owner\My Documents\
Most of the affected files in the My Documents\ folder were in fact doubly encrypted, as detailed below.
(2) C:\Program Files\

My Documents\

• 170 .wps documents were converted to 153 .wps.jkffbil.xyz files, 10 .wps.bqtuzhl.xyz files, and 7 .wps.xyz files. Also, a .docx document was converted to a .docx.xyz file and 4 .txt documents were converted to 2 .txt.jkffbil.xyz files and 2 .txt.bqtuzhl.xyz files.

.jkffbil? .bqtuzhl? What seems to have happened is the computer was initially hit with two different CTB-Locker infections and then after applying that video procedure to the computer a remnant of one or both infections (or maybe even a third, separate infection) later reared its ugly head and .xyz-ed (1) the .jkffbil-ed and .bqtuzhl-ed files and (2) whatever was missed the first time around - at least these are the conclusions I draw from inspecting the Created:/Modified:/Accessed: fields on the General tab of the Properties pane for a variety of encrypted and unencrypted files.

• 100 .jpg images, including all those in the My Pictures\ subfolder, were converted to 88 .jpg.jkffbil.xyz files, 7 .jpg.bqtuzhl.xyz files, and 5 .jpg.xyz files.

• 25 .pdf files were converted to .pdf.jkffbil.xyz files.

• 4 .zip packages were converted to 2 .zip.jkffbil.xyz files and 2 .zip.bqtuzhl.xyz files.

• In the My Music\ subfolder, 2 .itl iTunes libraries were converted to .itl.xyz files and 2 .itdb iTunes databases were converted to .itdb.xyz files.

• In the My Videos\ subfolder, a .flv video was converted to a .flv.xyz file.

• Lastly and least, there are 338 .png.xyz files and 4 .css.xyz files in RegCure Pro\ and SpeedyPC\ subfolders that really shouldn't be on my father's computer in the first place.

Program Files\

• 384 files were converted to 272 .jkffbil files and 112 .bqtuzhl files; all of these files are singly encrypted. Affected file formats: .cer, .doc, .eps, .jpg, .js, .mdf, .pdf, .ppt, .rtf, .txt, .xls, and .zip.

Etc.

• There are 9 encrypted files in the C:\Documents and Settings\Owner\Desktop\ folder and 20 encrypted files in the hidden C:\Documents and Settings\Owner\Application Data\ and C:\Documents and Settings\Owner\Templates\ folders. Affected file formats: .air, .dbf, .doc, .docx, .jpg, .js, .pdf, .ppt, .rtf, .txt, .wb2, .wps, .xls, .xlsx, and .zip.

• Outside of the C:\Documents and Settings\Owner\ folder, 2 .wma audio clips were converted to .wma.xyz files and 4 .jpg images were converted to 2 .jpg.jkffbil.xyz files and 2 .jpg.bqtuzhl.xyz files in the C:\Documents and Settings\All Users\Shared Documents\ folder.

D: damage

Twice in the past - about five months ago and in 2012 - the Address Book\, Desktop\, Favorites\, and My Documents\ subfolders of the C:\Documents and Settings\Owner\ folder were copied to the computer's Recovery (D:) volume. Without exception, all of the encrypted C:\Documents and Settings\Owner\Desktop\ and C:\Documents and Settings\Owner\My Documents\ files were also encrypted in the D: volume although not necessarily in the same way, e.g., some of the .jkffbil.xyz files appear as .bqtuzhl.xyz files and vice versa.

Undamaged

• The following file types were left alone: .bak backups, .bmp images, .dat data files, .db databases, .dll libraries, .exe executables, .htm and .html and .xml Web documents, .mp3 audio files, .wav audio files, and .xlr Microsoft Works spreadsheets (not a complete list).

• Gratifyingly, the C:\WINDOWS\ folder was left untouched.

In search of a key

I found a "How to remove CTB Locker Virus" article whose Stage 3 : Unlocking files that were encrypted by CTB Locker section suggests that a Panda Ransomware Decrypt program might be able to decrypt CTB-Locker-encrypted files and provides a link thereto. My attempts to decrypt a small group of encrypted files with Panda Ransomware Decrypt are not worth discussing to any extent: suffice it to say that they didn't work.

To my understanding, file decryption tools are target-specific, i.e., a program that unlocks files encrypted by a specific type of ransomware will generally be useless for files encrypted by other types of ransomware. As of this writing and as far as I am aware, no one has written a program that can decrypt files encrypted by CTB-Locker.

Subsequently, I decided to see if I could re-obtain the affected data on my father's computer via a file recovery approach, which did prove somewhat successful, and I'll tell you about it in the following entry.

Saturday, July 11, 2015

Profiles in PC Poisoning, Part 2

Let's get back now to our ongoing discussion of my father's computer and its CTB-Locker ransomware infection. As noted in the previous post, the protocol provided by this "REMOVE CTB-Locker" YouTube video didn't pan out very well. What next?

Go to the root

It occurs to me that I may be able to return the computer to a pre-infection state via Windows' System Restore feature. I go to the System Configuration Utility and click the button on the General tab (see the first screenshot in the next section). An alert( ) message pops up:
System Restore has been turned off by group policy. To turn on System Restore, contact your domain Administrator.
When it rains, it pours, huh? I go to my iMac to research the message, and come across a helpful Microsoft Community page on which "A. User" states:
Unless you disabled [System Restore] on purpose, the chances are good that your system has a malicious software infection. ... You need to fix the immediate problem of [System Restore] not working [vis-à-vis running System Restore itself], then scan your system for malicious software when you are done.
A. User goes on to recommend Malwarebytes and SUPERAntiSpyware programs for the removal of malicious software.

We'll get back to System Restore later in the post, but for now let's see where this gets us, shall we?

Under the knife

I download installers for CCleaner (go here to download the ccsetup*.exe executable on a Macintosh) and Malwarebytes Anti-Malware and write them to a CD on my computer. My attempts to copy the installers to my father's computer either generate a fusillade of errors or cause the system to hang, depending on the computer's boot state.

On my father's computer and in Selective Startup mode per the settings shown below - the
Load Startup Items
checkbox is unchecked because all of those items have been disabled via the Startup tab -



a second attempt to download the CCleaner installer is successful (I'm pretty sure that first download attempt was in Normal Startup mode, but I can't remember); installing and running CCleaner subsequently proceed without incident.

An attempt to download the Malwarebytes Anti-Malware installer from Malwarebytes itself in Selective Startup mode throws a "Secure Connection Failed" error; fortunately, I am able to download the installer from c|net. I am unable to install Malwarebytes Anti-Malware in Selective Startup mode; a malwarebytes anti-malware won't install Google search leads me to a "Cleanup Malware Using Malwarebytes" .pdf whose What To Do If Malwarebytes Won’t Install Or Won’t Run section instructs the user to install Malwarebytes Anti-Malware in SAFE MODE (not SAFE MODE WITH NETWORKING), i.e.:



I boot the computer into its /SAFEBOOT-MINIMAL mode. Installation of Malwarebytes Anti-Malware is successful and I scan the computer with it: 6 threats are detected, and I remove them. I boot the computer into its /SAFEBOOT-NETWORK* mode and then update the program's database(s) and run a custom scan per the Running Malwarebytes section of the .pdf: this time 62 threats are found and I get rid of them too. Gratifyingly, the latter scan serves to return the computer to operational normalcy, the encrypted files notwithstanding.

*The What To Do If Malwarebytes Won’t Install Or Won’t Run section says that after the /SAFEBOOT-MINIMAL scan you can go directly to Normal Startup mode and should then do a second, custom scan; I strongly recommend that the second scan be carried out in /SAFEBOOT-NETWORK mode in order to keep any remnants of your infection(s) at bay while you are cleaning up your computer. Upon subsequently returning your computer to Normal Startup mode or a Selective Startup variant thereof, however, you should indeed scan it again to make sure everything's OK. If I recall correctly, a third, Selective Startup scan of my father's computer did detect one last threat.

A word on screenshots

The screenshots in this post were taken via the procedure outlined on this page, with one important detour: on my father's computer I launched the Paint program by opening mspaint.exe with the Run command as the computer's Start → Programs → Accessories menu does not have a Paint selection.

System Restore, revisited

Once the computer is clean, I re-enable System Restore via the Registry Editor-based "Method 2" detailed on this page ("Method 1" is not applicable because, contra a note near the bottom of the page, the Home Edition of Windows XP does not have a Group Policy Editor).

I go to Start → Programs → Accessories → System Tools → System Restore and am hit with a confirm( ) box whose message reads, System Restore has been turned off. Do you want to turn on System Restore now? I click the box's button and am taken to the System Restore tab of the System Properties tool:



I uncheck the
Turn off System Restore on all drives
checkbox: this enables the button, which I click, and then I click . I return to System Restore and am greeted by a "Welcome to System Restore" window; I click the button at the bottom of the window in order to
Restore my computer to an earlier time.
System Restore then displays a "Select a Restore Point" window showing a single restore point that is a year into the future and a related July 2016 calendar that cannot be moved forward or backward.



As it happens, turning System Restore off deletes its restore points, so System Restore wouldn't have been able to help me in the first place. Was this disabling action part of the CTB-Locker 'payload'? I don't know.

Now, what about those encrypted files? We'll take stock of what we've got in the following entry.

Friday, July 3, 2015

Profiles in PC Poisoning, Part 1

About a month and a half ago, my father walked into my room and asked me to take a look at his computer: "I can't do anything with it." Sure enough, something was slowing his computer down to the point that it took several minutes to process a mouse click - if it responded at all (i.e., if the system didn't hang). With some major-league perseverance I have been able to largely nurse his computer back to health: believe me when I tell you that this is the most exasperating thing I have had to deal with in my entire life.

My father's computer has a 1.39-GHz processor and 736 MB of RAM, which is not so different than the 2.4-GHz processor and 1 GB of RAM that my own computer has. But that's where the similarities end. I have an Intel iMac that runs OS X 10.6.8 whereas he has a Compaq 5017m that runs Windows XP Home Edition Service Pack 3. At this point you are thinking, "Windows XP? Dude, just get a new computer already." Yeah, yeah, we'll get to that: I am acutely aware that Microsoft pulled the plug on its XP support a little over a year ago. Be that as it may, a Compaq running XP is what I had to work with; moreover, there was an 'archival' aspect to its cleanup that appealed to me.

Low-hanging fruit

So, I trudge over to Google, run a windows xp troubleshooting slow search, and decide to try some of the things recommended by a "How to Speed Up a Windows XP Computer" wikiHow article.

I go to the computer's Add or Remove Programs Control Panel and throw out all of the Apple stuff - iTunes, QuickTime, a Bonjour program I am unfamiliar with, a Software Update application - and then get rid of RealPlayer. I reason, "If he wants to listen to music or watch a movie, he can do that with the Windows Media Player that is built into XP." I access the Add or Remove Programs panel via the My Computer pointer in the upper-left-hand corner of the desktop - this is a lot easier than getting to it via the Start menu.

I use the Disk Cleanup utility to
(a) delete temporary files,
(b) empty the Recycle Bin, and
(c) compress what can be compressed
for the C: volume. The Disk Cleanup utility can be launched by opening cleanmgr.exe with the Run command, which I access via a &Run... pointer on the desktop.

I defragment the C: and D: volumes via the Disk Defragmenter utility, which can be launched by opening dfrg.msc with the Run command.

I disable all of the system's Startup Items via the Startup pane of the System Configuration Utility, which can be launched by opening msconfig with the Run command.

None of this has any noticeable effect on the computer's performance.

Hitting the iceberg

The wikiHow article recommends
(1) a CCleaner program for the removal of unnecessary files and
(2-4) Spyware Blaster, AVG, and Avira programs for the removal of spyware and/or viruses.
An initial attempt to download CCleaner causes the browser (Firefox) to crash. AVG 2015 is installed already on the computer: a "Scan now" operation turns up nothing.

I wonder, "If worse comes to worse, can I copy programs onto the hard disk via a CD?" In the course of trying to mount one of my old CDs via the F: drive I am suddenly confronted with a screen very similar to the one shown in the image below:



Uh-oh. My father's computer is infected with a ransomware program - specifically, a trojan named CTB-Locker - that has encrypted various files on the computer and will leave them encrypted unless a ransom payment is tendered within 96 hours. Clicking the button does display a list of encrypted files, most of which are in the computer's My Documents folder(s). I do not proceed to the 'payment page': whatever the payment is, I'm not going to pay it.

What doesn't work (for me at least)

I go to my iMac to research CTB-Locker on the Web, and come across a "How do I REMOVE CTB-Locker ransomware (Free removal guide!)" YouTube video. The video gives the following procedure for getting rid of CTB-Locker:
(1) Reboot the computer into its safe mode.
(2) Go to the Temp folder, show its hidden files, and then delete everything in it.
(3) Go to the My Documents folder and delete the "Decrypt All Files" .bmp image that should be residing there.

• I put my father's computer into its safe mode by launching the System Configuration Utility, checking the
/SAFEBOOT
checkbox in the Boot Option menu on the BOOT.INI tab, clicking , clicking , and restarting the computer.

• In this case, the Temp folder refers to the C:\Documents and Settings\Owner\Local Settings\Temp\ folder (vis-à-vis the C:\WINDOWS\Temp\ folder), which can be opened by opening %temp% with the Run command.

I clear out the Temp folder. There are two "Decrypt All Files" .bmp images in the My Documents folder and I delete both of them. I go back to the System Configuration Utility, check the
Normal Startup - load all device drivers and services
radio button in the Startup Selection menu on the General tab, and restart the computer. After the boot the ransom screen is gone but the computer still runs excruciatingly slowly. Without getting into the details another ransom screen emerges with a vengeance a few hours later - if I recall correctly, this is triggered by an attempt to surf the Web.

It would seem that the video procedure cures symptoms of the CTB-Locker infection and not the infection itself, but I don't know for sure; in any case, stronger medicine is clearly required. So, what do I use to clean up my father's computer, and how exactly do I do it? All will be revealed in our next episode.

Monday, June 8, 2015

Sods and Odds

More English to come

That AP English post had been rolling around in my head for the better part of a year and I finally took the time out to bring it to life - better late than never, eh? In due course I will write about the English classes I took in the 11th and 10th grades and perhaps even the 9th grade (that'll be as far back as I go, I promise) - maybe I can roll it all into a single post - but not today.

I've long held that English composition is the most important school subject, even more so than basic arithmetic. If you can write well, the world steps back and says, "Here is a person to be reckoned with." If you can't write well, the world sneers and asks, "Who is this illiterate hack?" You can quote me on this.

Check it out

I am at long last the proud carrier of a San Diego County Library Card! Armed with my passport and a Chase bank statement, I walked over to and into Vista's library and approached the librarian at the front desk and said, "I'd like to apply for a library card"; within a few minutes she had manufactured a card for me, on the spot - there was no waiting therefor to speak of - and now I am wired for checkout.

Vista's library has a decent music CD collection - I know that Alice Cooper's Love It to Death, David Bowie's Aladdin Sane, and The Stooges' Fun House are sitting there in the stacks, for example - and I'm really looking forward to getting into it. I've checked out my first CD, for Christina Aguilera's Lotus: look for a mini-review thereof in a subsequent entry.

Perambulatorily yours

Speaking of walking, I've been doing a lot of that lately. In late March my 88-year-old father dropped a bombshell-of-sorts on me: "I can't drive you to the store any longer." As I don't have a driver's license, I now hike to and from Walmart and to a lesser extent Vons several times a week to keep myself fed - several times because there's a limit to how much stuff I can carry home on a given trip. Lugging heavy bags of groceries around is somewhat hard on me physically, and the situation is exacerbated by Vista's hilly terrain - New Orleans was completely flat in comparison. Maybe it's time for me to get my act together and finally become a motorist, huh?

FYI: Vons has a local grocery delivery service but Walmart doesn't as far as I know.

Blog spam

As of this writing, Google has completely choked off the flow of spam to both of my Blogger blogs. I am thankful for this, although I do find it a bit strange that nothing at all is getting through. It couldn't be that no one is sending me spam anymore, could it?

I've thrown out most of my old blog spam but not all of it as some of those comments hold a certain 'historical resonance' for me and some of them amuse me, for example:
This is truly very good... Your website is incredible, but I simply have to declare, if your web site was a human being; I would go with you by saying That you simply so incredibly hot that you denature my protein. Thanks a lot plus sustain the great work! Here is my page - selfinger.com
I've always wanted to denature someone's protein, haven't you?

Careering

At the end of "Have It Our Way", the last Reptile7 Metablog post prior to my departure from New Orleans, I concluded with:
Moving on, I'll tell you about the free résumé critique that the aforementioned QuintCareers.com did for me in our next episode.
I never followed through on this, shame on me! In any case, look for me to bring my 'employment story' to the front burner in the not-too-distant future. BTW, although I'm currently not getting any blog spam, I do get a daily stream of employment-related email spam stemming from the submission of my résumé to QuintCareers.com - that's a separate post right there.

Grooveshark

I said I wasn't going to talk about Grooveshark anymore but let me quickly note that http://grooveshark.li/ has been shut down.

The Greater Dog sleeps for the summer

My own marker for the end of spring is not the Memorial Day weekend but rather the disappearance of Sirius in the southwestern sky, which has come to pass. In August you can see the Hunter begin to rise if you're willing to get up just before dawn...

Sunday, May 31, 2015

For the Record: AP English, 1979-1980

In the summer of 2013, in the run-up to my departure from New Orleans, I discarded a thick binder of items from the Advanced Placement (AP) English course that I took as a senior in high school during the 1979-1980 academic year. I now very much regret having done this: in my defense, let me say that the prospect of having to move sometimes causes one to do irrational things.

There are actually two AP English courses:
(1) Language and Composition
(2) Literature and Composition ("Composition and Literature" back then)
The latter was the only AP course offered by my high school and that's the one I took.

AP English was far and away the most rigorous course I took in high school - it was decidedly tougher than analytic geometry/introductory calculus, if I do say so myself. The course was run by one Patricia K. Prather, a take-no-prisoners instructor who did a good job of whipping us all into shape (at least she whipped me into shape). The primary course text was Laurence Perrine's Literature: Structure, Sound, and Sense (2nd edition, published in 1974, buy it here from Amazon); there were one or two supplementary texts whose title(s) I don't remember.

Course content

The course began with what you might call a writing workshop warmup period: if memory serves, I and my fellow classmates were during this time put through writing assignments on point of view, tone, setting, that sort of thing. Subsequently, the course veered into units on the short story, the novel, poetry, and drama; some milestones thereof are detailed below:

The short story

• We all wrote five-paragraph essays on "Tears, Idle Tears" by Elizabeth Bowen, "Youth" by Joseph Conrad, "Two Little Soldiers" by Guy de Maupassant, and "The Drunkard" by Frank O'Connor. I had no recollection at all of writing these essays upon throwing them out.

• We also wrote a literary analysis paper discussing "The Infant Prodigy" by Thomas Mann and "A Hunger Artist" by Franz Kafka.

The novel/la

• Over the course of the year, everyone wrote eight five-paragraph book reports: my first five book reports were on Nineteen Eighty-Four by George Orwell, Roßhalde by Hermann Hesse, We by Yevgeny Zamyatin, One Day in the Life of Ivan Denisovich by Aleksandr Solzhenitsyn, and The Metamorphosis by Franz Kafka.

• In the middle of the year (November 1979 through February 1980), we read the following class novels: The Mayor of Casterbridge by Thomas Hardy, Heart of Darkness by Joseph Conrad, The Plague by Albert Camus, and A Portrait of the Artist as a Young Man by James Joyce.

Poetry

• By far the strangest thing I threw out was a detailed prosodic analysis of "Heaven—Haven: A Nun Takes the Veil" by Gerard Manley Hopkins. Trochee, spondee, anapest, what is this stuff? Get it away from me!

• Everyone wrote a literary analysis paper discussing "The Changeling" by Charlotte Mew and "The Love Song of J. Alfred Prufrock" by T. S. Eliot.

Drama

• My last three book reports were on Oedipus the King by Sophocles, A Streetcar Named Desire by Tennessee Williams, and Oedipus at Colonus by Sophocles.

• In class we read out loud parts of An Enemy of the People by Henrik Ibsen and The Tragedy of Othello, the Moor of Venice by William Shakespeare.

• Everyone wrote a literary analysis paper discussing The Wild Duck by Henrik Ibsen and The Cherry Orchard by Anton Chekhov.

Over and above the aforenoted essays/book reports/papers, I chucked a large volume of instructional material for these units that Mrs. Prather had given us throughout the year. Again, I wish I had held onto this stuff, but I didn't.

The course culminated in the AP English Composition and Literature Exam on Monday, 12 May 1980. The exam fee back then was $34; today it's $91 - still a good value if you do well and are then able to get out of taking a semester of X at college. All told it was an intense experience that generated a great deal of camaraderie in the class and great relief when it was all over.

A final comment

I did save one item from my AP English materials, that being my A Streetcar Named Desire book report. I didn't do a very good job on that report and Mrs. Prather accordingly raked me over the coals for it; that said, I would like to take the opportunity to briefly respond to the following part of her critique:
Williams sets the delicate, romantic, obsolete Blanche against the brutal, realistic, vital Stanley to play out one of his themes about the South and its people. They are declining in strength because they cannot adapt to a world in which soft lights, bed baths, mint juleps, and gallantry/hypocrisy are obsolete.
Obsolete? Nah. Blanche was simply a flake who was not up to the task of bettering her situation. Just because Blanche couldn't get her act together doesn't mean that there weren't other Southerners on the scene who could supplant her and enjoy those soft lights, bed baths, and mint juleps. Moreover, societal hypocrisy is as entrenched today as it ever was (in case you haven't noticed).

There, I feel better now.

Reading assignment

Almost all of the works mentioned in this post can be found on the Web. (Indeed, Elizabeth Bowen's "Tears, Idle Tears" and Hermann Hesse's Roßhalde were the only ones I couldn't find! And that doesn't mean they're not out there somewhere.) I offer no guarantee that the following links point to resources that are complete and not in violation of copyright.

Short stories
"Youth"
"Two Little Soldiers"
"The Drunkard"
"The Infant Prodigy"
"A Hunger Artist"

Novels and novellas
Nineteen Eighty-Four
We
One Day in the Life of Ivan Denisovich
The Metamorphosis
The Mayor of Casterbridge
Heart of Darkness
The Plague
A Portrait of the Artist as a Young Man

Poems
"Heaven—Haven: A Nun Takes the Veil"
"The Changeling"
"The Love Song of J. Alfred Prufrock"

Plays
Oedipus the King
A Streetcar Named Desire
Oedipus at Colonus
An Enemy of the People
The Tragedy of Othello, the Moor of Venice
The Wild Duck
The Cherry Orchard