An encounter with something nasty
07-03-2005, 23:40
|
#1
|
|
 
Join Date: Nov 2003
Location: Leeds - the dog house
Age: 31
Services: Email me for a current price list
Posts: 8,241
|
An encounter with something nasty
Had customer today with a spyware problem. Customer had run Spybot but no joy - spyware kept coming back. The problem was lots of pop-ups just appearing, and IE exception errors. I managed to find a few dodgy dlls, including one called "sd.dll" lurking in the Windows temp folder. They were also listed as BHOs in IE. The home page had been hijacked. I immunized the system and downloaded SpywareBlaster but it would not run - installation is damaged or something. I think the spyware was blocking it from running. Try as I might, everytime I killed the dodgy run32dll process that was using the dlls, deleted the files, and remove the startup entry, the damn thing would reappear again on reboot  Spent an hour on it before giving up and advising the customer to speak to their Health Authority - see if an engineer could be sent out.
Any useful URLs or listed of spyware out there? No point searching Google - never know what you might catch
__________________
Consistency is the last refuge of the unimaginative [Wilde]
|
|
|
08-03-2005, 00:17
|
#2
|
|
Cable Forum Team
Join Date: Feb 2004
Location: /root/
Age: 31
Services: netstat -tula > /home/raistlin/netstat.txt
Posts: 8,179
|
Re: An encounter with something nasty
This is quite a good site with a fairly comprehensive listing of running processes.
Not sure if it helps you here though.....
http://www.answersthatwork.com/Taskl...s/tasklist.htm
__________________
Formerly known as 'Raistlin'
Pausing Live TV and Eating Wotsits
|
|
|
08-03-2005, 00:22
|
#3
|
|
lifeless
Join Date: Aug 2003
Location: nowhere
Posts: 718
|
Re: An encounter with something nasty
The dll or service is still running so despite what you do it recreates itself on startup. I had a similar experience not so long ago where I had identified the spyware, removed all traces of it in the registry and files but it still kept coming back and the virus checker kept reporting a file that did not exist, even a search in explorer could not find it. I was going to give up after about 1.5 hours until I remembered back to my DOS days and ran an attrib command to find the file and once I had done that I had it clean in under 10 minutes
I can't remember what one it was but I did a search in Google and all the so called solutions were as much help as used toilet roll. As long as you have removed all traces of the files from the hard disk and the registry, then a boot into safe mode and a check of the files using attrib can be very helpful because alot of spyware programs add the hidden attributes to the files so even a search in explorer won't, pick them up.
|
|
|
09-03-2005, 17:56
|
#4
|
|
cf.mega poster
Join Date: Nov 2004
Posts: 7,737
|
Re: An encounter with something nasty
If it is so badly infected and he removes such files, could there not be a chance some of the core Windows files could be corrupted?? would a format and total reinstallation of software with spyblaster/spybot/adaware se 1.05 be wise with a good av/firewall??
Start with a fresh slate and learn from the mistake?
|
|
|
09-03-2005, 17:57
|
#5
|
|
vista home premium user
Join Date: Jul 2004
Location: chavy Nottingham
Age: 24
Services: Freeview, Sky+ on big TV, 2 Mb/s NTL BB, mega PC, PSP, PDA, N95
Posts: 6,366
|
Re: An encounter with something nasty
Quote:
|
Originally Posted by Raistlin
|
Crikey that's a link and a half. Rep time!
__________________
PC: X2 4200+, 2GB RAM, X1650, 940GB HDDs, Audigy2ZS Platinum, HVR1100, Vista Home Premium Laptop: Advent 7203 (T5300, 2GB RAM, 80GB HDD, VHP) Server: WHS (XP 2800+, 1GB RAM, 820GB HDD)
 10111 pts
|
|
|
09-03-2005, 20:54
|
#6
|
|
Cable Forum Team
Join Date: Jun 2003
Location: between Portsmouth and Southampton.
Age: 56
Services: VM DTV,VM 2MB,VM Phone
Posts: 19,620
|
Re: An encounter with something nasty
Quote:
|
Originally Posted by nffc
Crikey that's a link and a half. Rep time!
|
Worth a mention in the Helpful Post Thread for this month perhaps?
__________________
Prejudice is opinion without judgement...Voltaire.
Is still Incognitas at heart.
If it's bold it is a moderation technique.If it's soft it's Coggy speaking.
|
|
|
09-03-2005, 21:08
|
#7
|
|
vista home premium user
Join Date: Jul 2004
Location: chavy Nottingham
Age: 24
Services: Freeview, Sky+ on big TV, 2 Mb/s NTL BB, mega PC, PSP, PDA, N95
Posts: 6,366
|
Re: An encounter with something nasty
Quote:
|
Originally Posted by Incognitas
Quote:
|
Originally Posted by nffc
Crikey that's a link and a half. Rep time!
|
Worth a mention in the Helpful Post Thread for this month perhaps? 
|
Bribery. Yes OK then...
__________________
PC: X2 4200+, 2GB RAM, X1650, 940GB HDDs, Audigy2ZS Platinum, HVR1100, Vista Home Premium Laptop: Advent 7203 (T5300, 2GB RAM, 80GB HDD, VHP) Server: WHS (XP 2800+, 1GB RAM, 820GB HDD)
 10111 pts
|
|
|
09-03-2005, 21:26
|
#8
|
|
Android
Join Date: Nov 2003
Location: Madchester
Age: 42
Services: SKY+
& NTL 2mb
Posts: 512
|
Re: An encounter with something nasty
Quote:
CWS is a robust infection that exhibits robust intelligence, technical prowess and a determination to survive removal attempts. CWS wants to live.
The difficulty of removing CWS from a user's system is significant. In the early variants, CWS was slightly tricky to remove, but it could be done, carefully, by a knowledgeable Windows user.
However, CWS has stepped up the battle and recent variants are virtually impossible to remove manually. Some CWS variants even use methods of hiding and running themselves that had never been used before in any other spyware strains.
The chronological order in which the CWS variants appeared is detailed here, along with the approximate dates when they appeared online.
|
http://www.softpedia.com/get/Interne...Shredder.shtml
|
|
|
09-03-2005, 22:40
|
#9
|
|
cf.mega poster
Join Date: Oct 2003
Location: Portsmouth
Age: 30
Posts: 1,684
|
Re: An encounter with something nasty
I recently had a very similar situation, it eventually comes down to the amount of time its going to take to clean the infections and stabilise the system, to how long it would take to build the machine from the ground up, as AndrewJames mentiond.. I find sometimes this is the cheapest route for my customers. and it can be quite helpfull in the long run as you can set the machine up properly from the get go. rather than constantly trying to firefight.
|
|
|
09-03-2005, 23:03
|
#10
|
|
cf.geek
Join Date: Aug 2003
Location: Asleep down in the server room
Age: 44
Posts: 516
|
Re: An encounter with something nasty
wipe and reload, only sensible way forward.
__________________
www.f2s.com They used to be good b4 Pipex got 'em
now on BT who are em.........pretty good...sorry
|
|
|
09-03-2005, 23:08
|
#11
|
|
cf.mega poster
Join Date: Jun 2003
Location: Huthwaite, Nottinghamshire
Services: VM 2Mb, VM phone 5p plan, 2xSky+ boxes (Family pack, sports & movies)
Posts: 4,520
|
Re: An encounter with something nasty
Quote:
|
Originally Posted by tkiely
wipe and reload, only sensible way forward.
|
Having first checked with the customer to see that there was nothing of vital importance that he wanted saving.
__________________
Please put brain in gear before posting.
There is no such thing as the average man (or woman).
DigiGuide - the best by far source for planning your TV viewing http://getdigiguide.com/?p=1&r=11440
|
|
|
09-03-2005, 23:32
|
#12
|
|
cf.mega poster
Join Date: Nov 2004
Posts: 7,737
|
Re: An encounter with something nasty
Agreed, curious thought does your customer have system restore enabled?? if so could it be that this program is using a restore point to come back again and again..
I am sure I have heard of a malware program doing such a thing.
|
|
|
09-03-2005, 23:36
|
#13
|
|
 
Join Date: Nov 2003
Location: Leeds - the dog house
Age: 31
Services: Email me for a current price list
Posts: 8,241
|
Re: An encounter with something nasty
Ta for the input all. Rep fairy has visited, though she got carried away with the ctrl+v key and may have pasted half a comment here and there
I've got rid of this sort of thing before, but it's not something you can easily remove remotely and without Internet access to do research or download tools. It's the first time I've encountered something so stubborn and nasty though. My own system has various security measures so there's no chance of me getting anything nasty  Shame that others are so complacent. Would an AV scanner pick up spyware? I know f-prot for DOS will flag up and clean keystroke loggers.
I have accidentally deleted user files before now, so I've learnt to exercise caution
edit:
The OS is good old Windows 98 SE, no doubt unpatched, so options are limited.
__________________
Consistency is the last refuge of the unimaginative [Wilde]
|
|
|
09-03-2005, 23:40
|
#14
|
|
Cable Forum Team
Join Date: Feb 2004
Location: /root/
Age: 31
Services: netstat -tula > /home/raistlin/netstat.txt
Posts: 8,179
|
Re: An encounter with something nasty
I know that this is probably a silly question but did you try deleting it (or running your spyware prog's) through Safe Mode?
In Safe Mode (in theory at least) it shouldn't be running so you should be able to get shot of it easil enough. Also worth (as already suggested) deleting the restore points (turn system restore off and then back on) just in case.
Glad you liked the link BTW, it's in constant use I can assure you.
Oh, and you think you have problems. Imagine the look on the face of the guy who's computer I have just rebuilt when I told him:
"Sorry, this is gonna take longer than expected. The 789 Virus Infected Files ( thank you Avast) and 389 Malicious Programs ( thank you Ad-Aware) that were on your machine have corrupted the Windows install to such a degree that I'm going to have to rebuild it from scratch!" 
__________________
Ah, just read the OS bit, ignore the system restore comments.
Safe Mode still stands, but if you're doing things remotely that could be.....tricky.....
__________________
Formerly known as 'Raistlin'
Pausing Live TV and Eating Wotsits
|
|
|
09-03-2005, 23:44
|
#15
|
|
 
Join Date: Nov 2003
Location: Leeds - the dog house
Age: 31
Services: Email me for a current price list
Posts: 8,241
|
Re: An encounter with something nasty
Quote:
|
Originally Posted by Raistlin
"Sorry, this is gonna take longer than expected. The 789 Virus Infected Files ( thank you Avast) and 389 Malicious Programs ( thank you Ad-Aware) that were on your machine have corrupted the Windows install to such a degree that I'm going to have to rebuild it from scratch!" 
|
You should have been on today's customer care course  Communicating the problem to the user so that they understand that you're working with them to resolve the problem
Quote:
|
Originally Posted by Raistlin
Ah, just read the OS bit, ignore the system restore comments.
Safe Mode still stands, but if you're doing things remotely that could be.....tricky.....
|
F8. No F - F for foxtrot - at the top of the keyboard. Yes - that's it. Now hit that key repeatedly as soon as the computer starts - you've got to be quick. No - you've missed it. Let's try again but this time, hit the key much faster - like a woodpecker. HP restore utils? I think you've hit the F8 too soon. Let's try that again...
__________________
Consistency is the last refuge of the unimaginative [Wilde]
|
|
|
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +1. The time now is 23:51.
|