PDA

View Full Version : Spyware invasion


PCNOOB
05-09-2007, 11:51 AM
Woke up this morning, booted up, and BSOD.:eek: No I didn't write down the error code, as I always fail to do when I'm in panic mode. After awhile I managed to boot up, and stay running long enough to identify some features of the invader.

Not only does windows repeatedly notify me of spyware, but malware keeps popping up trying to run, and I have about 6 new icons on my desktop. Again in my paniced rush to try and fix this and get to work ontime I failed to write down details, but from the numerous titles of programs attempting to run, and from the icon titles, it looks like it's trying to appear to be anti-spyware, drivers, and internet search tools.

I even managed to run Spybot, and Adaware. They removed some stuff, but there were many objects about which it said something like "...cannot remove now, but will do at reboot...". Does it really remove these at reboot? What's up with it identifying things but not removing? Any tips. I also went into control panel and tried to uninstall any wierd looking things, but some of them took me to an uninstall program, which means they're either bogus, or not spyware, so I abandoned that.

But I think my major question is that of my attempt to boot into Safe Mode. I have never done this on this system, so I went ahead pressed the usual F8 at boot-up and went into the boot menu, but there was no "Safe Mode" option listed explicitely as such. Just a list of the usual boot up devices: HDD, DVD, and Floppy. Am I missing something? Is F8 the proper path to Safe Mode on an Asus? I went ahead and selected the HDD, it booted up and everything, but the way in which it booted didn't look that "safe". The Spyware was running, windows was still freaking out trying to tell me something was wrong. Is there something that needs to be enabled in the BIOS before it will boot into Safe Mode? Or something like that. Or maybe this was "Safe Mode", and I'm just stupid? I don't remember safe mode looking like this. Anyway. Some recommendations would be great.

Sorry about the long post :o

mairving
05-09-2007, 12:01 PM
Sounds like this one (http://www.pcmech.com/forum/showthread.php?t=180387).

PCNOOB
05-09-2007, 01:03 PM
OK. So just go to that site and run it? I haven't seen "smit-fraud" anywhere though. I remove stuff that says "smit-fraud" using my spyware cleaners all the time, but I don't think I saw smitfraud anywhere on this thing. hmmmmmmm.

Looks like I have some work cut out for me after work. Hopefully I can get a handle on things before Lost.

PCNOOB
05-10-2007, 02:11 AM
OK so I booted into "Safe Mode" and ran the recommended scanners along with all of my other scanners, multiple times. It looked like they were gradually removing things, a little more each scan, but I booted up in normal mode and no dice. Actually, since I got home this afternoon I've been getting an immediate BSOD right as my desktop attempts to load. I can't even get into windows.

So I booted up into "Last Known Good Configuration", and presto. Adaware and Spybot even ran like they said they would, at boot, in an attempt to remove what they could not in Safe Mode, but of course, the only object that could not be removed is "Smitfraud C". That's all it says. No Toolbar 888; FYI. But I'm not too familiar with the details of these different boot options. For instance, do changes I make in safe mode apply globally to all users? And what exactly does "Last Known Good Configuration" give me?

The only thing I haven't done is post HJT logs.

If I could get some more suggestions that would be great.

Thanks again. Back to battle.

PCNOOB
05-10-2007, 02:11 AM
double post