Stupid Flap Dead: Trojan Horse Troubles

blip

Limp Gawd
Joined
Sep 29, 2003
Messages
346
hi,

Just got off the phone with one of my buddies. His computer was freaking out... Doing all sorts of crazy stuff. All sorts of software (looked like spyware mostly) was suddenly installing itself on his computer (a Viao laptop running Win98) without any input from him. Suddenly he was being bombarded by pop-up ads, icons were suddenly appearing on his desktop, and a ton of stuff had been added to his favorites list.

He ran ad-aware and spybot and both found and removed tons of software... but even after that the problems persisted. After that, he ran a Norton AV and failed to find anything.

So I had him disable a bunch of stuff that was starting up with windows. This seemed to help the problem (most of the things starting up on his computer he had never seen before!). After that I had him go through his program files directory and delete anything that looked suspicious (nothin' like the scortched earth approach, right?). That proceeded just fine until he came across this one directory entitled "Stupid Flap Dead". Whenever he deleted it, the directory would disappear for a moment and then (when he refreshed his folder view) would re-appear!

So now I'm stumped. I assume he has some trojan horse that Norton AV missed. But I can't find any information on a trojan horse with these specific symptoms. Anyone have any ideas? Or should I just call the exorcist and be done with it?
 
I'd try running a panda scan. Free from http://www.pandasoftware.com/activescan/com/activescan_principal.htm

In addition I would download the trial of TDS-3, manually update your system and run it as well. Make sure to turn on all the scan options under scan control before you do so.
http://tds.diamondcs.com.au/ Temember you have to manually download the update from the web page, only paid versions can auto update.

Also I would download hijack this and look for suspicouse entries in it's log. Don't change stuff unless you know what it is.
http://www.spywareinfo.com/~merijn/downloads.html

A firewall would be good to install as well, this way you could block all unneccessary things from accessing the net besides internet explorer, it may even tell you what program is infected if you do have a trojan and it's dialing out.
 
Thanks for the advice guys... I'll have him run some additional scans on his system. I forgot about viruses corrupting NAV... good catch!

Anyway, a few more details have emerged. Several of the programs were from somewhere called "spywarelabs" which purports to produce anti-spyware products but actually (from what I've read) is one of the big producers of spyware. The one that stands out in my mind is Virtual Bouncer which claims to be an anti-spyware program but actually installs itself through an IE exploit on some websites.
 
thats been happening quite a bit lately
been making the news

best to trust recommendations from
the major security boards only

Spybot
AdAware
CWShredder & HijackThis

and any time you think your security might be compromised
do an online scan (like at trendmicro or symantec)

as mentioned in that other thread a filecheck goes along way and is free
but Im going to be getting ProcessGuard
 
Back
Top