In which I do some maintenance. For the good of the household.

spyware1.JPGWhen I got on the laptop today, there was a new icon in the systray and every few minutes it would launch a popup to tell me that the machine is infested with spyware. I think it came bundled with a codec I downloaded when I got online, which makes me feel like an asshole – even though the codec appeared to be from a reliable source, and I even scanned with AVG it before I opened it.

Ah crap.

I force-quit out of everything I didn’t recognize, went through Add/Remove Programs, disabled the IE toolbar it had installed, and then manually cleaned up the Programs Folder.

Then I rebooted. And the pop-up is still running. I have no idea what it’s called, so I can’t figure out how to kill it! Which pisses me right the hell off.

So I go to the web site the damn pop-up wants me to go to, and there are no removal instructions for their piece of shit little adware. I began surfing for info: is it known adware, did it come with the codec or not, how do I remove it, etc.

An hour later and I’ve settled on an ad-, mal-, and spyware remover and am running it now. At 13% complete, it’s already found 56 instances of malicious software on the machine. This freaks me out because spyware, as you know, often contains keystroke loggers, which is how people lose their passwords. I am feeling the itch to change all of my passwords, even though I no longer have any sensitive or financial information on the web.

The scanner hasn’t even gotten to my pr0n folder yet. *bangs head on desk*

Update: 119 instances were removed. Gah. (I’m so ashamed. I know better.) But the problem is still there… turns out it’s a little beaut called Spydawn or maybe Spylocked, and removing it doth sux0r mightily.

Update: All clean. SmitfraudFix rocks.

In other news, the wire in my iPod headphones broke last night, so now I can only listen to the right channel.

 

16 Responses to Malware

  1. naomi says:

    i’m astounded that you don’t have an array of mal- and spyware removal programs. i run adaware, spy bog, a windows malware program and avg antispyware program. i also go into my temp files and delete everything there.

  2. keef says:

    I run old, crappy, non-targeted, long-stable OS’s like windows 2000. That way I don’t have to care about these things.

  3. Jayrob says:

    My roommate got this too. It took me awhile to get rid of it. Here’s what I did:

    http://www.pchell.com/support/spylocked.shtml

    Hijack this is a fantastic program. Get it now.

    http://www.spywareinfo.com/~merijn/programs.php

  4. Jayrob says:

    Looks like I cant post links, your bot rejector seems to be working great.

    I WAS going to post the link to the steps to remove that mother fucker. And the link to hijackthis. But I can’t.

  5. Mush says:

    Naomi: This isn’t my machine. (I don’t have a machine of my own these days.) I should keep it fairly locked up since I’m the resident geek, but I don’t own it so everyone’s got admin privs. It’s running SpybotSD now, but that didn’t fix Spylocked, just the other doodads that weren’t bothering any of us.

    Keef: I’ve seen Win2k boxen utterly hosed with malware. You’re confusing Windows with OSX, apparently. Now there’s an opsys with very little targeted at it! *snort*

    Jayrob: I found your comment and enabled it. Sorry! (Any comment with more than one link gets eaten.) I had no trouble finding removal instructions once I figured out what the fuck the ‘ware was called. Then I used SmitfraudFix. It kicked arse!

  6. Jim@HiTek says:

    Ha! I got rid of the same damn malware yesterday on one of the volunteers computers and then the office computer today. That thing is malicious as hell isn’t it?

    Yeah, it was certainly annoying!

    And the fix (free) is Smitfraudfix for sure. Worked both times. Of course I’m so cool, I didn’t get it on my computer even though I set up a network with the infected computer…

    Well, you probably weren’t trying to view illicit material over the Intarwebz. đŸ˜‰ -m

  7. Brad says:

    I’ve been dealing with one computer problem or another lately. (The latest one being my beloved laptop is no longer functional. Long story short, I think one of the cats peed on it…)

    I like SpybotS&D. I’ve been using it for a year or so.

    And finally, your dad is just way too damned smart.

    Smooches!

    Aw, sorry to hear about your laptop! Let it dry, take out the battery and take it apart. You may be able to clean it – an eraser works well on circuit boards, and a lint-free cloth for everything else – and have it work again. -m

  8. Buzz says:

    I had “SpySheriff” on my Win2k laptop once that absolutely refused to be removed. I had to wipe and reinstall to get it taken care of. On another note, girls have pr0n folders? Or only very *cool* girls?

    I have one! It’s got weird shit in it, of course, like, yaoi manga and crap only I like, and it’s even labeled “pr0n,” for clarity. *snort* -m

  9. Jim@HiTek says:

    Spybot S&D is considered to be a spy by itself. Go here: http://housecall.trendmicro.com/

    and run the free spy remover just after running S&D and you’ll see how many it missed. Most consultants think that S&D is protecting a certain few and will delete the rest.

    Pee on keyboard? Remove the keyboard assembly, put it on the top rack of a dishwasher, a little soap, run it through to ‘dry’, open the door and let the moisture out fast, let it sit there for a couple hours, wipe it down with a terry towel, then move it to a sunny window sill for a couple days. Also you can use a small fan to blow on it. Don’t let it get too hot in the sun or it will melt.

    Good luck.

  10. naomi says:

    thanks to you and jayrob, i am now equipped with 2X the number of get-rid-of-crap-and-nasties than i had before. đŸ™‚

    w00t! -m

  11. Jayrob says:

    i’m sorry but i have to say something. DAD! i would NOT suggest tearing your laptop apart and placing any of it’s components in the dishwasher. if it is non functional, let me know what model it is via jp2012@gmail.com and I can send you detailed instructions on how to repair it.

    naomi, glad to be of some help. tell you the truth, you shouldn’t need all the apps here installed all the time. i mean, how often do you get a crap-nasty? however, i cannot stress how badass hijackthis is. it is suberb while running in safe mode.

    in other news, take a look at this: http://www.ubcd4win.com/

    you can have total controll of your windows environment without even starting windows! bootable cd my friends!

  12. Jim@HiTek says:

    Jayrob! I don’t have a laptop, I was talking to Brad. He mentioned his might have cat pee on it. Pay attention kid.

    And I’ve washed at least 50 keyboards in dishwashers, and if done right there isn’t a problem. It works 10 times better then doing it by hand.

    Laptop keyboards come as one assembly. It’s easy to just unplug from the mainboard (after removing the case) and isn’t any big deal to wash them. Laptop cases can be a bear to take apart but the keyboard is easy to access once the case is open.

  13. Mush says:

    It’s so cool that my dad and my brother argue geek crap in the comments. I freakin’ lurve it. đŸ™‚

  14. Jayrob says:

    It’s my job to argue with dad. There’s just no way he’s ever right! It’s why I exist. đŸ˜‰

    *snort!* -m

  15. Jim@HiTek says:

    Jayrob is a butt head…no doubt about it.

    I think you just broke about ninety parenting rules with that sentence. -m

  16. dharma says:

    I am way tired, but the opening part was over my head even not exhausted. Well maybe not really. Glad you fixed it.

    Go to sleep! *smooch* -m