On the subject of spyware...
Author
Discussion

jimbro1000

Original Poster:

1,619 posts

314 months

Monday 25th April 2005
quotequote all
To put it bluntly I *know* someone has been messing with my machine.

The fact that my AV keeps popping up 5 or 6 times a day to inform me that Downloader-ZM has reappeared on my harddrive coupled with the fact that a select few web pages (all microsoft) are no longer available (unknown server) suggests that things are not as they should be.

Annoyingly nothing I possess can find the fault (just been prompted to check my hosts file which for some reason I had completely forgotten to look at).

The problem is that I'm running out of ideas? Any suggestsions on where to look?

spivvy

1,535 posts

284 months

Monday 25th April 2005
quotequote all
check registry key for it

HKEY_LOCAL_MACHINE Software Microsoft Windows Current Version Run

also there will be a file in system32 which will be the one mentioned in the registry

delete this also ,if it won't let you delete start in DOs mode and delete this way

recheck registry and see if removed .also look in task manager to see what is running

Plotloss

67,280 posts

300 months

Monday 25th April 2005
quotequote all
I take it you have a firewall of some description?

jimbro1000

Original Poster:

1,619 posts

314 months

Monday 25th April 2005
quotequote all
Spivvy - I think you've misunderstood, something else is downloading the file. The infection by Downloader itself is being succesfully dealt with - it is the something else I am trying to remove, problem is that I cannot identify it.


Yes I am running a firewall - the router I use includes a passable firewall and I keep virtually all of the ports closed inbound so this is not a hack. The available ports don't map to my machine anyway...

On top of that I have the inevitable XPsp2 firewall on the machine but I have found it to be more problematic than useful.

Plotloss

67,280 posts

300 months

Monday 25th April 2005
quotequote all
So what have you used to remove it?

Adaware, Spybot?

jimbro1000

Original Poster:

1,619 posts

314 months

Monday 25th April 2005
quotequote all
Used adaware and the MS antispyware beta. Haven't tried spybot (yet).

Just arrived home and immediately checked the hosts file - I can now see why some pages are coming up as unavailable. The file has grown from 3 entries to over 1000. All redirected to localhost and in pairs (www.xxx.yyy and xxx.yyy) seeing as my localhost has nothing running on it I suspect this is something my security software has set up, there is no purpose in doing so otherwise - unless there is a hidden app now installed that I can't see. All very odd...

petros

2,441 posts

259 months

Monday 25th April 2005
quotequote all
[redacted]

jimbro1000

Original Poster:

1,619 posts

314 months

Monday 25th April 2005
quotequote all
petros said:
Are you running any Anti Spyware Progs? I'm using Giant Anti Spyware and it's very good. peter


That would be adaware and ms anti-spyware then...

The point is that nothing I've tried has found any spyware other than the occasional tracking cookie (and I then block those sites from storing cookies on my machine)

The story becomes stranger though. Occasionally I now see a pop-up that looks "exactly" like the microsoft search page when you get a 404 - the difference is that this one is hosted by a dodgy spam/porn pedler in the USA by the name of Jerry Ray (I love whois) assuming of course that it isn't a zombied site. The address is on the spam blacklists which doesnt come as a surprise. No trace of the offending IP address in my registry...so it must be hardcoded into some piece of malware on my pc somewhere...

spivvy

1,535 posts

284 months

Monday 25th April 2005
quotequote all
so have a self generating trojan ,these beast can disguise themselves as acceptable windows files ,
does it occur in safe mode ?
have you run msconfig and stop all auto load process
are you on a network ?
if so disable file and print sharing and run
spybot

if you are seeing a blank explorer window on loading IE this is dropping the trojan and reactivation

also set host file to Read only
search google or ie hijackers and tools to remove
this has piggy backed on from a web page ,

also try running

trend micro's online scanner as well ,although this is aV software it will detect Trojans as well




jimbro1000

Original Poster:

1,619 posts

314 months

Monday 25th April 2005
quotequote all
The trojan (downloader-zm) is retrieved over the internet by my little parasite. Look it up on the av databases and you'll find it is a favourite for this sort of infection.

Funnily enough the trojan seems to be related to PH - I've noticed this evening that it appears only just after connecting to the front page (not every time though).

Will give trend's online scanner a twirl but it didn't find anything yesterday...