ask matt cpa we are free agents nation …

A Little Spyware War – My Version of the Film “The Departed”

10.19.2009 · Posted in Personal Skills, Productivity


It is funny when I was reading something about time management, I sudden got a spyware outburst on my hand.  Time management went out of window immediately.  I was then totally absorbed by a time waster, trapping in a non-productive cycle.  Seen the move The Departed?  That is how it was like – a game of infiltration and false identities.

This is a terrible spyware of its kind.  It is a spyware fix tool.  Huh?  Yes it is actually a software to remove spyware, but it sneaks in your PC by the very spyware tactic.  Then it plays a scary show to trick you into paying for this low quality or even a scam software.  It is a very very very bad selling technique or total scam.  There are a few things in common for this kind of rogue software:

Trojan Horse

Spyware comes in disguise when you download those little freeware or shareware, posting as legit utility software.  It finds home in many strategic locations of your system such as registry key or the startup run, and carries on its secret mission.

Mind Game

Often it uses terrible images to replace your own cozy desktop wallpaper, sounding sirens  with flashing red lights – very effective way to get you into a panic mode and do whatever handy to put off fire.  It is strange if you don’t fall off your chair in surprise by that.  The famous one for this kind is “Zlob”.  It camouflages as video player.

Sometimes, you will not see such a dramatic show.  As in “SecurityTools”, another rogue software.  It comes with a very decent professional look.  But it scares you by showing an ever increasing log of viruses found.

White Knight Game

Now you are surrounded by a doom-is-coming feeling, you will see many popup windows to alarm you, crying virus attach, and shows a running list of newly discovered viruses.   You may be terrified and overwhelmed.  Then it advices you to activate a rescuing software, but credit card number please….

Very Well Fortified

It is difficult to fight this kind of scare ware. It understands where we will try to fight it.  It turns off your security setting,  stops your task manager where you can end the process, disables the Run so you can not fix key registry, and even worse, you can not go to the safe mode in some case.

Best Advice

Two things this kind of software count on to get you:  1. Free.  This is the spirit of internet age.  Somehow we get the feeling of entitlement.  However, when it comes to computer security, free stuff always is the start of trouble.   2. Fear.  Panicking makes you take ridiculous action.  Remember, it is not as bad as it looks.

I was panic when I first got this.  I rushed to find a software from the web.  Ironically, I found another rogue software and installed it myself this time.  Guess what, it is a free one too!  :-) Shame on me.  This one is called SmitFraudFixTool, dubbed it name after the good guy, named SmithFraundFix, which is a legit tool.

Finale

Finally, I downloaded a commercial software Spyware Doctor.  Yes, I was so paranoid now, and checked it out in Wiki first to make sure its authenticity.  The software did the job removing it.  However, the bad guy keeped coming back again and again.  I finally found tips online, that I have to block a website because it turned out once this one gets in, it can invite itself back even after removal.  I also have to manually detect the location and remove the EXE file manually.

Resources:

Some tips here.  You should try to read other or more updated tips

Work with key registry – Be very careful with this.  You should not touch it unless you know what you are doing.

How to get into safe mode of Windows – This is a big help because in safe mode, you won’t see those the annoying effect of the rogue software and can concentrate on the fix.

How to change screen resolution in safe mode – In safe mode, your screen could be hard to work with because of the resolution.  A techie provides his simple hack here.

Leave a Reply