Spyware from hell
Results 1 to 13 of 13

Thread: Spyware from hell

  1. #1
    Registered User
    Join Date
    Aug 2002
    Posts
    30

    Spyware from hell

    Hello
    At the shop it seems for the past two weeks (or I may have missed it to begin with) there has been spyware that has inserted garbage letters in the Startup items under Task Manager. This and a few others are not easily eliminated by Ad Aware despite updates. I find it difficult for some reason to believe that this nonsense requires a format /reload (or exhaustive registry editing).

    Is this an epidemic or am I seeing things?
    Ken

  2. #2
    Driver Terrier NooNoo's Avatar
    Join Date
    Dec 2000
    Location
    UK
    Posts
    31,824
    you are missing something
    Morze5.exe causes this.

    There is a sticky thread in antivirus/security which details various approaches to avoid formatting.

    As for exhaustive registry editing, define exhaustive please.

  3. #3
    Registered User 3FS's Avatar
    Join Date
    Jul 2003
    Location
    PA
    Posts
    94
    Quote Originally Posted by katurner
    Hello
    At the shop it seems for the past two weeks (or I may have missed it to begin with) there has been spyware that has inserted garbage letters in the Startup items under Task Manager. This and a few others are not easily eliminated by Ad Aware despite updates. I find it difficult for some reason to believe that this nonsense requires a format /reload (or exhaustive registry editing).

    Is this an epidemic or am I seeing things?
    Ken
    Did you try Spybot?

  4. #4
    Registered User craigmodius's Avatar
    Join Date
    Sep 2001
    Location
    Hellmira, NY, USA
    Posts
    1,572
    Quote Originally Posted by katurner
    Hello
    At the shop it seems for the past two weeks (or I may have missed it to begin with) there has been spyware that has inserted garbage letters in the Startup items under Task Manager. This and a few others are not easily eliminated by Ad Aware despite updates. I find it difficult for some reason to believe that this nonsense requires a format /reload (or exhaustive registry editing).

    Is this an epidemic or am I seeing things?
    Ken
    I saw this on a friends computer, where there's a bunch randomly named .exe's running in task manager.

    I ran spybot adaware and spywareblaster all on latest definitions, after which it cleaned alotta crap, but the exe's were all still there.

    Ended up just having to delete the .exe's shortcuts from the startup folder, and the All Users startup folder.

    kinda like you have to play cleanup hitter for spybot and adaware.

  5. #5
    Registered User fugg_hugh's Avatar
    Join Date
    Nov 2002
    Posts
    3
    I had delt with a version of ABetterInternet that bound a .dll file to explorer.exe. This forced the spyware to load on startup and there was no way to disable it. I tried stopping explorer.exe and the unregistering the .dll to explorer.exe and it would not let me. The only way I was able to remove it was to remove the hard drive from the system, put it in another computer, and then delete it.

    What a pain.

  6. #6
    Registered User
    Join Date
    Mar 2004
    Posts
    3
    Quote Originally Posted by katurner
    Hello
    At the shop it seems for the past two weeks (or I may have missed it to begin with) there has been spyware that has inserted garbage letters in the Startup items under Task Manager. This and a few others are not easily eliminated by Ad Aware despite updates. I find it difficult for some reason to believe that this nonsense requires a format /reload (or exhaustive registry editing).

    Is this an epidemic or am I seeing things?
    Ken
    looks like Wowex32 &/or Kern32 could be part of your troubles, they keep generating random "garbage" named .exe files and put them into your startup routine. here is a discussion with details and links to solve and remove the Wowex32 & Kern32 problems, (also called peper trojan)
    http://www.computercops.biz/postt10611.html

  7. #7
    Registered User Bigtimbre's Avatar
    Join Date
    Apr 2001
    Location
    Anchorage, AK
    Posts
    134
    Quote Originally Posted by craigmodius
    I saw this on a friends computer, where there's a bunch randomly named .exe's running in task manager.

    I ran spybot adaware and spywareblaster all on latest definitions, after which it cleaned alotta crap, but the exe's were all still there.

    Ended up just having to delete the .exe's shortcuts from the startup folder, and the All Users startup folder.

    kinda like you have to play cleanup hitter for spybot and adaware.
    I've never seen that associated with Spyware, the random names. There are a number of viruses that create executables with random names. I would do a virus check.

  8. #8
    Registered User inferno_gn's Avatar
    Join Date
    Mar 2003
    Location
    Montreal, Quebec
    Posts
    698
    Hi there,

    The best is still format and reinstall. That's what I usually do, even takes alot of time, but less headache.

    Ju Leon...

  9. #9
    Registered User Carpel's Avatar
    Join Date
    May 2003
    Location
    NJ
    Posts
    36
    If you do go the format/reinstall route, consider setting aside a small partition and imaging the hd after you've installed all os/drivers/updates etc. This way next time you have to do a total reinstall, you can be back to a base install in minutes.

    hmm, that's good advice, someday I'll even be smart enough to do it myself.

    Carpel

  10. #10
    Registered User craigmodius's Avatar
    Join Date
    Sep 2001
    Location
    Hellmira, NY, USA
    Posts
    1,572
    Quote Originally Posted by Bigtimbre
    I've never seen that associated with Spyware, the random names. There are a number of viruses that create executables with random names. I would do a virus check.
    Yeah, I ran everything against that system. Scans with AVG anti-virus on the latest definitions turned up nothing. But Adaware and Spybot found plenty of stuff. I don't remember the names of stuff it found.

    Alotta times splitting hairs on Spyware/Malware vs. Virus/Worms isn't easy. They are both very similar in the way they get on a system and the harm they cause.

  11. #11
    Registered User Sunshine's Avatar
    Join Date
    Apr 2001
    Location
    Winnipeg
    Posts
    491
    I just had this same problem about 2 days ago. The spyware that seems to be causing the problem for me is Ezula. If you find one of the stupid .exe files in the task manager, don't just try to end the task. All that does is create a new exe and it starts up again. You have to end the entire process tree for it. Once you've done that, run spybot and Adaware again. There are wickedly long registry hacks to get rid of this, but stopping the process and running the antispyware software seems to work ok, at least for the past couple of days.

    Good luck with that!
    Life is short - Eat dessert first! mmmm... cake

  12. #12
    Registered User Sckott's Avatar
    Join Date
    Aug 1999
    Location
    Hyannis MA
    Posts
    47
    The ammount of Spyware activity that I've seen in the past week make the Klez virus look like a walk in the park. This stuff is really evil. I've been in IT for >10 years and the ammount of time I need to "rake" through these problems gets to the point I just have to stop at 1hr and recommend format and reinstall the OS, or else go mad. You can spend hours on spyware every time and not really find every nook and cranny. Spyware just goes "Splat" everywhere in Windows, System32 and even the c:\ as well as all over the registry. It's like trying to clean up a murder with Windex and a paper towel. All the removal tools in the world, and nothing is 100% perfect. It takes time. Sometimes it's 10 minutes, sometimes it's 3 days and it's still not "GONE".

    If I see BTIEIN in the registry again, I'll scream.

    For those who are really racking their brains with it, don't try and be a hero and solve things. Sometimes it's better to backup and reload.

    This situation of Spyware is also very difficult to describe to customers and clients. They just look at you like a dog that's been shown a card trick. Frustrating stuff.

  13. #13
    Driver Terrier NooNoo's Avatar
    Join Date
    Dec 2000
    Location
    UK
    Posts
    31,824
    I found a nice little one on my sisters machine... netpal games. Neither spybot or adaware picked up on it.

    It was in the favourites, had a registry key.. didn't pay much attention to it since she has realgames etc.

    Anywhoooo, I removed it because she was having issues, and on the 3rd reboot the machine "restored" the registry. Guess what came back? Netpal...
    So I did it again, again on the 3rd reboot it restored the registry. Once more to check, yup same pattern.

    Look for installerupdater.exe in the c:\ and check the java applets in the internet cache - remove them all, empty the recycle bin. Run hijack this, fix the no name bho and the netpal entry.

    Reboot 3 times. If you got it all, it will not restore the registry in 3 reboots time.
    Never, ever approach a computer saying or even thinking "I will just do this quickly."

Similar Threads

  1. SpyWare Forum
    By Nakedboy in forum Comments and Suggestions
    Replies: 19
    Last Post: May 13th, 2005, 08:44 AM
  2. How to fix popups, spyware, malware and nuisance programs
    By NooNoo in forum Spyware & Antivirus - Security
    Replies: 15
    Last Post: June 3rd, 2004, 02:46 AM
  3. Why is XP spyware?
    By JungleMan1 in forum Tech Lounge & Tales
    Replies: 6
    Last Post: July 30th, 2001, 10:36 PM
  4. [RESOLVED] Is it spyware or not?
    By MacGyver in forum Tech Tips
    Replies: 35
    Last Post: April 22nd, 2001, 12:05 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •