M 
		
								
				
				
			
		Menno Hershberger
I've been working on a computer that was sent to me from a mortgage
broker. They were getting popups faster than they could close them. Every
time one of the popups advertised spyware removers, they'd install them
and of course that made it worse. I mirrored the drive off to another
drive and went to work on it. Between MSAS, Pest Patrol, Sybot S&D, and
AdAware, I finally got it fairly clean. I couldn't install anything in
the exisiting account because it always wanted to install it on a network
drive. So I made a new account and have been doing it all from that
account. I FINALLY was able to set Service Pack 2 and all the updates
installed. Twice now when I thought I about had it, then it stopped
booting into Normal mode. So I copied the mirrored drive back and started
over again. It has now locked up in Normal Mode again and I'm damned if
I'm going through all that again. The last time I went into Safe Mode,
just to make a final run with MSAS to make sure I had everything, I got
red popups from MSAS that the crap was trying to install itself again...
in SAFE MODE. I use Hijack this to keep "fixing" all the random file
names, boot into Safe Mode with Command Prompt and delete all the freshly
formed DLL and exe files. Everything that's exactly 408 KB (there's
always about 5 or 6 new DLL's... 440 Kb). Nail.exe was in there way back,
but now I'm getting others that searches don't turn up. towl.exe is the
latest that keeps coming back. I keep getting more or less the same list.
Virtual Bouncer
Navidad.worm
eXact.BargainBuddy
eXact.NaviSearch
eXact.CashBack
eXact.Downloader
eXact.Bullseye Network
eXact.SearchBar
SurfSideKicker
Transponder.ABetterInternet.DrPMon
Transponder.ABetterInternet.Aurora
Transponder.ABetterInternet.Adware
ShopAtHome
Same filenames that keep reappearing are skkgsd.exe, and various other
skk*.dll files, towl.exe, ttrs.exe, exp.exe, svcproc.exe, hnerbe.exe,
iddk.exe, bargains.exe, mscd.dll (CashBack). Also a bunch of PerfString
folders and files.
Somewhere along the line when I could hold the popups down long enough, I
was able to run TrendMicro's HouseCall on it. It found a few items and
fixed them. He hadn't had anything but problems with Panda, so I got it
out and installed NAV 2005. A full scan with it in Safe Mode found some
adware stuff and deleted it. I get rid of everything that shows up in
HiJack This but it just keeps coming back.
How does stuff get itself running in Safe Mode? Like random file names.
You can end task on them and another will pop up to take its place. Where
else in the registry besides the Run Keys can stuff hide and get started?
If it were anyone else's computer, I would have wiped it a long time ago
and started over. But this guy has some kind of network setup, with
servers all configured on each machine. The outfit that set it up has
flown the coop and I don't know anything about it.
Does ANYONE see any kind of pattern here?
I'm posting this in alt.privacy.spyware seperately.
				
			broker. They were getting popups faster than they could close them. Every
time one of the popups advertised spyware removers, they'd install them
and of course that made it worse. I mirrored the drive off to another
drive and went to work on it. Between MSAS, Pest Patrol, Sybot S&D, and
AdAware, I finally got it fairly clean. I couldn't install anything in
the exisiting account because it always wanted to install it on a network
drive. So I made a new account and have been doing it all from that
account. I FINALLY was able to set Service Pack 2 and all the updates
installed. Twice now when I thought I about had it, then it stopped
booting into Normal mode. So I copied the mirrored drive back and started
over again. It has now locked up in Normal Mode again and I'm damned if
I'm going through all that again. The last time I went into Safe Mode,
just to make a final run with MSAS to make sure I had everything, I got
red popups from MSAS that the crap was trying to install itself again...
in SAFE MODE. I use Hijack this to keep "fixing" all the random file
names, boot into Safe Mode with Command Prompt and delete all the freshly
formed DLL and exe files. Everything that's exactly 408 KB (there's
always about 5 or 6 new DLL's... 440 Kb). Nail.exe was in there way back,
but now I'm getting others that searches don't turn up. towl.exe is the
latest that keeps coming back. I keep getting more or less the same list.
Virtual Bouncer
Navidad.worm
eXact.BargainBuddy
eXact.NaviSearch
eXact.CashBack
eXact.Downloader
eXact.Bullseye Network
eXact.SearchBar
SurfSideKicker
Transponder.ABetterInternet.DrPMon
Transponder.ABetterInternet.Aurora
Transponder.ABetterInternet.Adware
ShopAtHome
Same filenames that keep reappearing are skkgsd.exe, and various other
skk*.dll files, towl.exe, ttrs.exe, exp.exe, svcproc.exe, hnerbe.exe,
iddk.exe, bargains.exe, mscd.dll (CashBack). Also a bunch of PerfString
folders and files.
Somewhere along the line when I could hold the popups down long enough, I
was able to run TrendMicro's HouseCall on it. It found a few items and
fixed them. He hadn't had anything but problems with Panda, so I got it
out and installed NAV 2005. A full scan with it in Safe Mode found some
adware stuff and deleted it. I get rid of everything that shows up in
HiJack This but it just keeps coming back.
How does stuff get itself running in Safe Mode? Like random file names.
You can end task on them and another will pop up to take its place. Where
else in the registry besides the Run Keys can stuff hide and get started?
If it were anyone else's computer, I would have wiped it a long time ago
and started over. But this guy has some kind of network setup, with
servers all configured on each machine. The outfit that set it up has
flown the coop and I don't know anything about it.
Does ANYONE see any kind of pattern here?
I'm posting this in alt.privacy.spyware seperately.
 
	

 .  Then I copy the cloned drive back and start all over
.  Then I copy the cloned drive back and start all over