Saturday, November 15, 2008

Fake Spyware message in Windows




Fixing a PC with a stupid Spyware bubble message.




"Windows has detected spyware infection!" is the alarming message popping up from your Windows toolbar. Windows XP in this case but likely to occur on other versions in a similar way.

Its not Windows doing the detection. The Windows operating system does not do detection. Spyware products do.

The other clues about this being a fake message is that the spelling is atrocious. 'pervent' instead of 'prevent' and 'recomended' instead of 'recommended'.

The message is malware. In longer words, the message is from a piece of software that is malicously designed and sent to your computer via an email or from a website. Once it is in the computer it's main aim is to get you to click on the bubble message and download their product which you then need to pay for.

Having spent a number of hours booting and rebooting, trying various AV techniques and looking into the registry I located more than a handful of issues including a rootkit. At that point I decided to grab what data I could save and reimage the system. Painful, but less so than manually trying to recover and still ending up with a compromised system.

No comments: