[DeTomaso] Fwd: NPC--UNWANTED SPYWARE

Biancoj at aol.com Biancoj at aol.com
Sun Oct 8 11:30:27 EDT 2006


Hi everyone, I thought I would pass this around.  Last week a warning 
appearred on my computor indicating I had spyware and viruses, etc.  Usually with 
this type of spyware you can go to the site and that usually will remove it from 
your opening screen, however this one did not and had no way to email the 
company trying to sell the spyware protection program (Total-pc-protection.com).  
At the website the only choices are Download or Buy with no email address or 
way to contact them.  I did go to the buy site and found a link for emailing if 
you were having problems with the credit card purchase.  I sent them a nasty 
gram explaining that they were equally responsible as they accepted payment 
for a company that hijacks computors.  I also cc a copy to the SC govenor as 
well as ebay and paypal and this is the response I got.



In a message dated 10/8/2006 1:08:33 AM Eastern Daylight Time, 
tech404 at Safe-mail.net writes:

> Subj: Re: UNWANTED SPYWARE 
>  Date: 10/8/2006 1:08:33 AM Eastern Daylight Time
>  From: tech404 at Safe-mail.net
>  To: Biancoj at aol.com
>  Sent from the Internet 
> 
> 
> 
> Greetings!
> 
> First of all I want to apologize for the unfair actions of some of our 
> webmasters that cause the problems with your PC. Our company is developing 
> security software that protects from any kind of spyware and viruses. 
> 
> 
> 
>  
> 
> 
> 
> We work on affiliate terms with many webmasters that sell our software. 
> Unfortunately, while selling our products some webmasters prefer to cheat our 
> potential customers using illegal ways of distribution such as placing various 
> scripts on websites so user can download it on computer. Once discovered, 
> those webmasters are permanently banned just right away and they never get paid 
> for their actions. Webmasters who use such way to advertise our software break 
> our rules.
> 
>  
> 
>  
> 
> 
> 
> Please be assured that at no time your personal information was in any 
> unauthorized access danger. 
> 
> 
> 
>  
> 
> 
> 
> Enclosed please see simple removal instructions to permanently delete 
> infections.
> 
>  Ill gladly help if you have any other questions.
> 
> -------------------------------------------------------
> 
>  Removal Instructions
> 
>  
> 
>  
> 
> 
> 
> 1. Restart your system in Safe Mode:  
> 
> - Reboot your computer.  
> 
> - When the black-and-white progress Starting Windows bar will appear, press 
> the F8 key repeatedly.  
> 
> - From the appeared Advanced Options Menu select the Safe Mode.   
> 
> - Press enter. Windows will start in Safe Mode.  
> 
>  
> 
> 2. Once in Safe Mode, delete the following files (if present):  
> 
>  
> 
> C:\Windows\system32\sumsw32.exe  
> 
>  
> 
> 3. Restart your PC. 
> 
> ----------------------------------------------------------
> 
>  If this will not work please use alternative method:
> 
>  
> 
>  
> 
> 
> 
> 1. Print out these instructions as we will need to close every window that 
> is open later in the fix.
> 
>  
> 
>  
> 
> 
> 
> 2. Download SmitfraudFix.zip from here: 
> http://siri.urz.free.fr/Fix/SmitfraudFix.zip
> 
>  
> 
>  
> 
> 
> 
> 3. Extract all of the files to your desktop.
> 
>  
> 
>  
> 
> 
> 
> 4. Next, please reboot your computer into Safe Mode by doing the following:
> 
>  
> 
>  
> 
> 
> 
> 4.1. Restart your computer
> 
>  4.2. After hearing your computer beep once during startup, but before the 
> Windows icon appears, press F8.
> 
>  
> 
>  
> 
> 
> 
> 4.3. Instead of Windows loading as normal, a menu should appear
> 
>  4.4. Select the first option, to run Windows in Safe Mode.
> 
>   4.5. When you are at the logon prompt, log in as the user your normally 
> log in as.
> 
>  
> 
>  
> 
> 
> 
> 5. When your computer has started in safe mode and you see the desktop.
> 
>  
> 
>  
> 
> 
> 
> 6. Close all open Windows.
> 
>  
> 
>  
> 
> 
> 
> 7. Open the Smitfraudfix folder on your desktop. Double-click on the 
> SmitfraudFix.cmd file, as shown in the image above, to start the removal process.
> 
>  
> 
>  
> 
> 
> 
> 8. When the tool first starts you will see a credits screen. Simply press 
> any key on your keyboard to get to the next screen.
> 
>  
> 
>  
> 
> 
> 
> 9. You will now see a menu. Press the number 2 on your keyboard and the 
> press the enter key to choose the option Clean (safe mode recommended).
> 
>  10. The program will start cleaning your computer and go through a series 
> of cleanup processes. When it is done, it will automatically start the Disk 
> Cleanup program.
> 
>  
> 
>  
> 
> 
> 
> This program will remove all Temp, Temporary Internet Files, and other files 
> that may be leftover files from this infection. This process can take up to 
> a
> 
>  few hours depending on your computer, so please be patient. When it is 
> complete, it will close automatically and you should continue with step 11.
> 
>  
> 
>  
> 
> 
> 
> 11. When Disk Cleanup is finished, you will be presented with an option 
> asking Do you want to clean the registry ? (y/n). At this screen you should press 
> the Y button on your keyboard and then press the enter key.
> 
>  
> 
>  
> 
> 
> 
> 12. When this last routine is finished, you will be presented with a red 
> screen stating Computer will reboot now. Close all applications. You should now 
> press the spacebar on your computer. A counter will appear stating that the 
> computer will reboot in 15 seconds. Do not cancel this countdown and allow 
> your computer to reboot.
> 
>  13. Once the computer has rebooted, you will be presented with a Notepad 
> screen containing a log of all the files removed from your computer. Examine 
> this log, and when you are done, close the Notepad screen.
> 
>  
> 
>  
> 
> 
> 
> Your computer should now be free of the infection!
> 
>  
> 
>  
> 
> 
> 
> 
> 
> -------- Original Message --------
> From: Biancoj at aol.com
> Subject: UNWANTED SPYWARE
> Date: Sun, 8 Oct 2006 00:56:46 EDT
> 
> 
> 



More information about the DeTomaso mailing list