Welcome, Guest. Please login or register.

Author Topic: Malware that renames itself on reboot  (Read 3450 times)

Description:

0 Members and 1 Guest are viewing this topic.

Offline jjansTopic starter

  • Full Member
  • ***
  • Join Date: Aug 2003
  • Posts: 241
    • Show all replies
Malware that renames itself on reboot
« on: November 24, 2004, 03:44:06 AM »
I am trying to get rid of some vicious spyware on a buddy's PC, running Windows ME, that was infected with over 300 Viruses that I removed with AVG (Grisoft), and with over 400 malware/spyware, detected by both SpyBot and AddAware. The kids love to download from all the freeware, play online Java Games, and download music, and naturally, there was no firewall, virus, or antispy protection installed.

AddAware chokes during the attempted deletion of detected critical objects, and Spybot's Resident IE monitoring gives constant warning prompts ( 1 per minute on average) to re-direction/browser web page changes to constantly changing addresses: ie http:// www .nuwprnbyqrybznfdkaarbuwpx. net/.(spaces added to address to disable hyperlink).

I was able to track one of the little buggers to WINDOWS\TEMP\ and found a 240 KB executable called oozwexsb.exe, and a lib called ladHide.dll(16KB). Both of these little buggers could not be deleted due to "the specified file is being used by Windows" message.

So I rebooted to Safe-Mode, and was able to successfully delete the file and the dll.

However, on each reboot, the exe and dll, are recopied from somewhere(??),  back to the WINDOWS\TEMP folder, and the exe renames itself.

Anyone else encountered these little riggin's?

The interesting question, is how do I get rid of them, (aside from a flame thrower...).

I do have the OS restore CD (if needbe), but am not yet able to declare defeat by re-formatting the drive.
\\"Most Xenonites fly imports. Unfortunately yours is a domestic model. Don\\\'t be surprised if the gears work in reverse\\" - Volhaul\\\'s Revenge: Close Encounters of the Sludge Kind.

GVP A530, VXL 30/32, Supra 500XP, A590, A1000.
 

Offline jjansTopic starter

  • Full Member
  • ***
  • Join Date: Aug 2003
  • Posts: 241
    • Show all replies
Re: Malware that renames itself on reboot
« Reply #1 on: November 24, 2004, 05:35:48 AM »
@Ilwrath: Thanks for the tip. I'll give it a go.

BTW ยท   Research of ladHide.dll(16KB) pointed to BackWeb (an Auto Update program bundled with HP) as a possible variant of spyware, Program not needed due to Windows Update already  on MSN, and articles critical of resource usage, and privacy concerns. (see: http://www.pestpatrol.com/PestInfo/B/Backweb.asp
      http://forums.techguy.org/archive/index.php/t-183700.html).

Not sure what the other one is yet...
\\"Most Xenonites fly imports. Unfortunately yours is a domestic model. Don\\\'t be surprised if the gears work in reverse\\" - Volhaul\\\'s Revenge: Close Encounters of the Sludge Kind.

GVP A530, VXL 30/32, Supra 500XP, A590, A1000.
 

Offline jjansTopic starter

  • Full Member
  • ***
  • Join Date: Aug 2003
  • Posts: 241
    • Show all replies
Re: Malware that renames itself on reboot
« Reply #2 on: November 25, 2004, 02:47:33 AM »
Great input guys-Thanks! I'll give all suggestions a go.

By the way, how current are Amiga viruses these days? I'm talking OS 3.5 and less on the classics, not OS 4. I haven't heard of anyu since the days of VirusZ.
\\"Most Xenonites fly imports. Unfortunately yours is a domestic model. Don\\\'t be surprised if the gears work in reverse\\" - Volhaul\\\'s Revenge: Close Encounters of the Sludge Kind.

GVP A530, VXL 30/32, Supra 500XP, A590, A1000.