Spyware dudes are sure getting more creative. Norma informed me last week that her computer had been infected when she got on twitter. She was getting some unwanted content on her computer and asked me to take a look at it.
When I got to her house, her pc and username was pretty messed up. Here are a few of the tricks the spyware guys had wreaked on her computer:
1. Access to task manager denied by administrator (cute)
2. Rundll32.exe hijacked (bad, bad news)
3. Tons of browser toolbars added.
4. Windows Security Center disabled.
5. Fake Windows Security Center alerts constantly popping up telling her she needed spyware protection (day late, dollar short).
6. This is my favorite, her google search and dns was being hijacked. Any request I made for SpyBot (my favorite spyware removal tool), AVG Free, or FireFox, was redirected to sites the spyware authors obviously wanted… they looked sorta like the real sites, but it just linked you to more spyware!
I got a clue to #6 when Norma originally claimed she probably got infected on Twitter, because Twitter had links to movies and stuff. I told her, “… Twitter doesn’t have movies.” They even redirected requests for Twitter to their bogus sites! So, her computer had obviously been infected before she even tried to find twitter.
Fixing it was no easy issue. I had to get spybot and avg without using the dns… in Safe Mode. I then cleaned up her computer, but it totally trashed her user account (rundll32.exe was so badly messed up it had to be removed). I set her up a new account, and that seemed to work ok.
The guys that write this garbage should be locked up. Then give them a key to the cell that looks exactly like the real key, that makes a sound like the door is unlocking when you turn it… that ultimately does nothing.

