Massassi Forums Logo

This is the static archive of the Massassi Forums. The forums are closed indefinitely. Thanks for all the memories!

You can also download Super Old Archived Message Boards from when Massassi first started.

"View" counts are as of the day the forums were archived, and will no longer increase.

ForumsDiscussion Forum → Continuing adventures in spyware (large picture)
Continuing adventures in spyware (large picture)
2008-02-01, 4:31 PM #1
So I still haven't been able to clean the spyware/adware/virus/whatever off of my roommate's computer. It kind of doesn't matter anymore because he's decided to just format the hard disk, but today he turned on the computer to see this:
Attachment: 18417/spy.JPG (61,982 bytes)
COUCHMAN IS BACK BABY
2008-02-01, 4:34 PM #2
Well, it seems he has spyware problems. It says so right on the screen.
SnailIracing:n(500tpostshpereline)pants
-----------------------------@%
2008-02-01, 4:37 PM #3
that's the smitfraud virus. this is how to remove it.

first run smitfraudfix in safe mode.

then run combofix in normal mode.

then load spybot s&d and it will clean up the remnants

it sometimes creates system polices that prevent you from doing things like task manager or changing the background. they are in hkey_current_user -> software -> microsoft -> windows -> polices

they will be named things like norun and notaskmgr. delete them, log in, log out, you will be fine.


also, pretty sure i told you it was smitfraud in the previous thread here. i run a computer shop, do this every day, so i can call them pretty easily. i'm in the chat if you have questions, i can walk you through cleaning it up.
gbk is 50 probably

MB IS FAT
2008-02-01, 4:52 PM #4
Oh, thanks NoEsc. I really just wanted to share a funny picture, but I'll check that out.
COUCHMAN IS BACK BABY
2008-02-01, 5:18 PM #5
There's a really fun policy which blocks registry editor from running. :eng101: Would be surprised if this thing DIDN'T set it.

I'm sure there're tools to remove just that registry entry so you can use regedit again to clean up other stuff like it.

2008-02-01, 5:22 PM #6
Originally posted by The Mega-ZZTer:
There's a really fun policy which blocks registry editor from running. :eng101: Would be surprised if this thing DIDN'T set it.

I'm sure there're tools to remove just that registry entry so you can use regedit again to clean up other stuff like it.

That's probably why you have to remove it in safe mode. I've seen many similar cases of this. (not on my machines)
Naked Feet are Happy Feet
:omgkroko:
2008-02-01, 6:20 PM #7
yeah, you can do it in safe mode. the policy is set on the current user, so you can go into safe mode using the built in admin account and reset it for the other user.
gbk is 50 probably

MB IS FAT

↑ Up to the top!