My weekend spyware odyssey

Mon Nov 10, 2008 2:42PM EST

See Comments (15)

I'd been away to a friend's house for several hours. Had barely even used the computer on Sunday. But when I came home I saw that it had rebooted in my absence and was now awaiting my login. That's nothing unusual: I figured Windows had installed one of its incessant updates and helpfully rebooted itself while I was gone.

When I got to the desktop, though, I could see that was not the case: Somehow I'd gotten a spyware infection and now it had taken root.

The manifestation was simple yet obvious: In the system tray I had a new icon with an oversized pop-up: AntiVirus 2009, it called itself, and the pop-up said I needed to immediately run the software to "pervent (sic) data loss."

AntiVirus 2009 promptly proved itself to be awfully insidious: Right-clicking the icon for it began installing additional spyware (which I immediately canceled), and there was nothing to be found in the add/remove programs control panel. I didn't get any overwhelming pop-ups, at least, so the computer was still usable... but Trojans like this tend to install more and more malware until the PC is dead, so I knew I needed to act fast.

Now I follow my own advice on how to remove spyware, so I started through the usual routine. Avira was installed on the machine already, so I ran a full scan. Avira found a few items, which I deleted immediately, hoping for the best. I also installed AdAware and ran it, and it came up blank. Finally I ran HijackThis, used an automated log reader to find the malware entries (brastk.exe was the culprit), and manually deleted them.

Rebooting, the spyware was still there, so I moved on to more specialized tools. Downloading them was tricky, though, as AntiVirus 2009 had hijacked a number of browser pages: Typing in security website URLs instead took me to broken 404 pages or ad-riddled spam websites, even in safe mode. The malware also blocked web updates from working on all the antivirus software I did have. Using another computer I was able to download the oft-recommended Malwarebytes, but after a lengthy two-hour scan, it came up with very little.

I cleared what it found and rebooted, hoping for the best. The system tray icon and pop-ups were finally gone, but the browser hijacks remained. I figured I'd give System Restore a try to roll things back to a pre-infection state -- why not? -- only to discover that the malware had also stopped it from working right. It was still on and running, but when I tried to restore to an earlier time, the "Next" button just wouldn't work. Click click click... nothing. Clever, yet frustrating.

I wasn't ready to give up yet and reinstall Windows. More research finally led me to a tool called ComboFix. I nabbed it from another PC -- though not before finding that some of the links to download it were fake, yet another annoying malware tactic -- and ran it normally. ComboFix found a rootkit, rebooted my PC, and did a quick five-minute scan. After another reboot, everything was finally back to normal, no pop-ups, and no browser redirects.

Total time my computer was unusable: About four hours, including two hours of hands-on work searching and scrubbing.

I write this post to remind you, the reader, that spyware happens to everyone, and yet I still have no idea what infected email or hacked website I visited that opened the door for this evil app in the first place.

One major security takeaway I hope to leave you with: If standard removal tools don't work (a problem that's becoming increasingly large) spend some time searching the web from a clean PC to see if specialized tools exist that can help. I finally found one in ComboFix, though I'd never heard of it before yesterday. My system is now running Norton Internet Security 2009 instead of Avira, and scans with it, AdAware, and HijackThis are all coming up clean. Fingers crossed...

Comments on My weekend spyware odyssey

Post a Comment

Join in the discussion. Here you'll see the comments in the order they were posted.

  • 6 Posted by jedimaster_gary on Thu Sep 3, 2009 4:31PM EDT Report Abuse

    I run Avast and havent had any problems on either of my computers

  • 7 Posted by jedilord007 on Thu Sep 3, 2009 4:31PM EDT Report Abuse

    ComboFix is a great little tool for a large majority of those fake Antivirus apps. I work on a lot of infected machines and use a whole host of apps for cleanup. Including SUPERAntiSpyware, SpyBot, Malwarebytes Anti-Malware and ComboFix usually in that order unless it is one of those rouge antivirus apps then I start with ComboFix.

  • 8 Posted by starcatcher_wh on Thu Sep 3, 2009 9:39PM EDT Report Abuse

    Just yesterday there was something on my computer from Antivirus 2009. It hadn't installed anything (the one time when I've been thankful for Vista's constant asking for permission to do anything), so it was quick and painless to delete it. I wasn't too surprised--my other computer's Norton Antivirus had expired a while back, without my knowledge, so it was bombarded by viruses and crap. Re-installing Norton fixed it, though, and it's back and running as it should (well, as a nearly 5-year-old, low-end computer should, that is, slowly).

  • 9 Posted by tacoramajon on Thu Sep 3, 2009 9:54PM EDT Report Abuse

    3 better solutions exist than wasting all of that time and risk installing additional malware pretending to help: reformat/install regardless, use linux or surf within a virtual computer (its like playing in a sandbox)

  • 10 Posted by agustin2489 on Thu Sep 3, 2009 2:47PM EDT Report Abuse

    Comodo firewall is pretty useful since you can filter out what files are safe and unsafe. It's noisy because of that but I find safety a good tradeoff for noisiness.

  • 11 Posted by sniperkill546 on Thu Sep 3, 2009 9:30PM EDT Report Abuse

    The extensive research I've done on this virus shows me that infected video codecs are the most common way of infection. Also an un-updated version of Java seems to let this thing in. Keep Java updated and Windows updated in general to help prevent this. I have installed Malwarebytes program in safe mode and scanned and I have never had a problem removing with that program.

  • 12 Posted by alkinzer on Thu Sep 3, 2009 2:50PM EDT Report Abuse

    My wife and I had this same problem. We did a McAfee, Ad-Aware, HijackThis, VundoFix and Spybot Search scans and came up with several fixes but never did find the Root problem. Not until I downloaded avast!Antivirus, Malwarbytes Anti-Malware, OTScanIT2 and received help from avast! via avast! forums did I get the Root rooted out!

  • 13 Posted by chellofs on Thu Sep 3, 2009 3:22PM EDT Report Abuse

    Spysweeper from Webroot has always been a good utility for me but to truly prevent spyware infections, create a full ghost image of your hard drive (and update it regularly) or use Deep Freeze by Faronics to freeze your hard drive. Keep in mind though that no changes to the hard drive will remain once the system is rebooted so keep your data files on a non-frozen USB flash or external hard drive....

  • 14 Posted by rudster_99 on Thu Sep 3, 2009 8:55PM EDT Report Abuse

    I had this same virus and I was using Norton Antivirus at the time. You might want to change to McAfee? I eventually had to buy and use Spyhunter to remove the Antivirus 2009 bug, it worked great. Afterward I switched to Firefox and have had no more isseus.

  • 15 Posted by saxonmor503 on Thu Sep 3, 2009 9:06PM EDT Report Abuse

    I encounter a lot of people who bash Norton. I don't know if they don't update enough, if I'm just lucky or what, but Norton has been good to me and my computers year after year after year. I have no plans to switch.

More Posts: First Prev 1 2 Next Last

Post a Comment


My Tech

Please enable your browser's cookies to activate the My Tech column.

Also on Yahoo! Tech

Computers Home Office Wi-Fi & Networking Phones & PDAs Cameras & Camcorders TV & Home Theater Portable Audio
 

Question and Answer content at Yahoo! Tech is written by Yahoo! users at Yahoo! Answers. Yahoo! does not evaluate or guarantee the accuracy of any Yahoo! Answers content. For more information, read the Full Disclaimer.

Opinions expressed by the Advisors are their own and do not necessarily reflect the views of Yahoo! Inc. Yahoo! receives no compensation from any manufacturer or distributor nor does it compensate any Advisor for the coverage of any product or service in any Advisor's content.