seventhe: (Squall: What now?)
unfortunate hobo ([personal profile] seventhe) wrote2008-04-06 07:29 pm

(no subject)

So the desktop downstairs has apparently been infected with some sort of spyware, and may be completely ruined. I have a bad feeling it's completely trashed. Whatever it is changed the background of the computer to a "Your computer has been infected with spyware! Please run the latest antivirus software to remove" thing, it has completely blocked me from both Control Panel and the Task Manager (Ctrl-Alt-Del), and has apparently already removed the copy of Norton that was on there to begin with.

The strangest part is that it keeps continually giving me popups - both regular ones and from the lower-right-hand-corner system tray - saying "Click here to download Windows' latest virus software" or something like that, and I know it's not a Windows message. It keeps trying to run/install something, and I keep telling it no, but the pop-ups continue to show up.

It just happened in the middle of a basic search for tabs. As soon as we realized what was happening, I unplugged both my external hard drive and the internet. Once disconnected from the internet, whatever was trying to run kept prompting me to reconnect, so I'm wondering whether it was an information-fishing type of virus. I'm hoping I saved the hard drive soon enough that it's not ruined -- I'm afraid to plug it in to any of my other computers, and I'll probably be taking it to one of those Geek Stores to have someone who knows what they're doing take a look at it.

Once it was disconnected from the actual Internet I could get to my desktop, and could possibly run things, although I didn't really try to - I was too busy trying to find my Norton and to get the virus popups to go away. I'm afraid to try to pull anything off of it, though - I don't want to ruin a USB drive and/or another computer when I try to connect it. >.>

The part I just don't understand is where it came from. We hadn't downloaded or installed anything new, we weren't looking at strange websites (it was a guitar tab website when it happened, by the way, that we've gone to tons of times), and so I have no idea how this thing got on my computer in the first place. Any ideas? Anyone know more about this kind of thing than I do?

Basically, what I'm planning on doing is phoning the local Professional Computer Nerd place (I actually think that's what they're called, there's one down in the Valley) and seeing what they recommend. I'm wondering if I bought a new version of Norton/other anti-spyware software whether I would be able to install it and wipe the computer clean. I'm hoping the computer place can advise me on what to do, or if maybe I can just take the computer in to them and have them get the spyware off for me.

I don't really care about the desktop - it needed a reformat anyway, although I'd obviously rather be able to collect things off of it before reformatting. If it's going to cost like $200-$300 to fix the computer, I'll probably just say 'fuck it' and buy a new one (I was planning on doing it this summer; it'll just accelerate things a little). What I'm most concerned with is the external hard drive, because that's where all my music and photos are. I don't want to plug it into the laptop in case it somehow got infected too, because then both my computers are Royally Fucked.

Does anyone have any ideas/advice on how to get this really annoying spyware off of my desktop? Anyone else been hit with this kind of thing? I have no idea what to do with it (other than call a professional) so help would be most appreciated.

Fucking hell. Fucking shitfuck virus.

EDIT - I've left this unlocked in case anybody has geeky friends they'd like to send my way to help me out. If there are any questions, leave it in a comment, and I'll get back to you ASAP. Seriously, people, I am stumped!

[identity profile] hilldo.livejournal.com 2008-04-07 12:59 pm (UTC)(link)
First download Adaware (as another one of your commenters mentioned) and spybot on the flash drive and put them on your other computer.
If that doesn't work, as well as all the other good suggestions the other commenters left (especially the ones that have had this happen before), let one of your geeky friends (*cough*) look at it before you pay anyone.

[identity profile] first-seventhe.livejournal.com 2008-04-07 01:10 pm (UTC)(link)
This is probably a stupid question, but if I download them on my USB drive and then plug the USB drive into the infected computer, do I risk infecting/ruining my USB drive?

And do you want to come over some time this week and help me? I have beer.

[identity profile] hilldo.livejournal.com 2008-04-07 02:03 pm (UTC)(link)
Not sure. I'd be careful with your hard drive though, as there is actually stuff you want on it. I thought you had one of those keydrives or whatever they are called you could use? If not, I'll just burn a cd with them on it instead.

Tonight is the most free I'm going to be, so if you're free lets just get it over with (hopefully). It'll give the 3 of us discussion time for another subject as well...

[identity profile] first-seventhe.livejournal.com 2008-04-07 02:10 pm (UTC)(link)
That's what I meant, my little keychain USB drive. I just don't want to ruin it, it's actually a really good one (as opposed to my last one which worked for crap).

I actually don't think we're free tonight, we may be playing with one of the guys from work... any other night would work, though, for computer fixing and Certain Person Discussion.

[identity profile] hilldo.livejournal.com 2008-04-07 02:12 pm (UTC)(link)
What? Are you cheating on me? :P

[identity profile] first-seventhe.livejournal.com 2008-04-07 02:58 pm (UTC)(link)
I DIDNT KNOW WE WERE IN AN EXCLUSIVE RELATIONSHIP

Are any other nights OK for you?

[identity profile] hilldo.livejournal.com 2008-04-07 04:04 pm (UTC)(link)
What's the bitches name! HMM? haha

I guess wednesday would be ok.

[identity profile] first-seventhe.livejournal.com 2008-04-07 05:04 pm (UTC)(link)
YOURE NOT ALLOWED TO BEAT HER UP! IT DOESNT MEAN ANYTHING I SWEAR BABY, I SWEAR

Cool. If I haven't figured it out (or totally ruined it) by then, that is.

[identity profile] hilldo.livejournal.com 2008-04-07 05:54 pm (UTC)(link)
I just love how you work in the land of 1000 musicians though, I know like 2 people here that play anything!

Yeah, just burn a cd with those programs on it and try to run them. Hopefully if it's just stupid malware of some form they'll fix it.

[identity profile] first-seventhe.livejournal.com 2008-04-07 06:08 pm (UTC)(link)
There are a lot of musicians here, it IS kind of weird. At the same time, too many of them are like A Certain Person Who Shall Not Be Named But Maybe Should Be Discussed Over Email.

[identity profile] hilldo.livejournal.com 2008-04-07 06:38 pm (UTC)(link)
MAYBE.
ext_3328: Rosencrantz & Guildenstern are Dead (Default)

[identity profile] rosencrantz.livejournal.com 2008-04-07 02:46 pm (UTC)(link)
quick answer is: yes (you risk infecting your USB drive)