PDA

View Full Version : spyware disabling spybot and no-internet installation



CreatureOfLegend
2008-07-31, 20:27
Hey guys!

I'va had spybot working on my machene for a while and like it a lot. Yesterday a friend of mine called me and asked me to take a look at her machene. Her husband was downloading something from a file-sharing application, when the command prompt came up by itself, then his web browser (IE) navigated itself to a page w/ a bio-hazard symbol. After this, when she restarted her computer, she got a blue-screen-of-death afther she logged in. Not when the computer was started in safe-mode, though.

So I took Anti-Vir virus scanner and spybot over to her place. I installed and ran the anti-vir in safe mode, scanned the computer and that took care of the BSD. When I started the computer in the normal mode, however, it was insanely slow, the Internet Explorer wouldn't really let me browse anywhere. Various popups were comming up no matter what page I tried to go to saying stuff ranging from "Your computer may be infected, click here to download the solution", to pages for some sort of university search. One particularly disturbing thing was that the destop wallpaper disappeared and was replaced by something that said it was "Windows Acrive Desktop error" also w/ a button to go somewhere to download something.

So I tried to install the spybot search and destroy... I downloaded the file that very day (Spybot - Search & Destroy 1.6.0 ). Whenever I doulbe-clicked on it both in normal and safe mode, it wouldn't start the installation. The task manager showed the program being loaded then closed right away. Then I decided to re-name the file. I renamed the install file w/ a nonsense name like "aldfjlasjf.exe", and when I doulbe-clicked on it the installation started.

Problem: I think the installer tries to connect to the internet during the installation. This fails both in safe mode and in normal mode. An error message pops up at the point in the installation where I've went through all of the screens that configure the instsallation (directory, etc) and the two progress bars one underneath the other pop up.

My first question is: is there an install file that can be run without the computer being connected to the internet? I'd really like to install and run the program in safe mode.

The second question is: Does any of these simptoms sound familiar to you guys and if yes, what is the workaround? I'm concerned that even if I manage to install the spybot, the spyware/addware will prevent it from running effectively just like it's preventing it from being installed.

Thanks!
Creature

tashi
2008-07-31, 21:00
Hello CreatureOfLegend,

It may be best to approach this in a different way.

Can you produce a HJT log as shown in the topic here: "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)


Note:

If you have lost your Internet connection on the infected computer, or otherwise cannot post from that machine; you can download HJT to a clean PC if one is available.

Upload to infected machine
Place HJT into own folder
Run HJT on the infected PC and post the log you produce using the clean PC.

If so, please copy paste the HJT log into a new topic you would start here: Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22)

Please let us know if you can do that.

Also as an FYI to your file sharing friend:
File Sharing, otherwise known as Peer To Peer. (P2P (http://forums.spybot.info/showthread.php?t=282)) (http://forums.spybot.info/showthread.php?t=282)


Best regards.

CreatureOfLegend
2008-08-05, 04:11
I sure can :)

Thank you very much!

I've posted the log here: http://forums.spybot.info/showthread.php?p=219841

tashi
2008-08-05, 06:05
:bigthumb:

A helper will assist you as soon as available, it's a busy forum so just in case:

Post here if still waiting for help in the Malware Forum, (AFTER) FOUR days (http://forums.spybot.info/forumdisplay.php?f=37)

Cheers.