CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Does this look like a spybot?

 
Post new topic   Reply to topic       All -> FavForums -> Privacy [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
MrBill

Lieutenant
Lieutenant
Premium Member

Joined: Apr 05, 2003
Posts: 218
Location: USA
Premium

PostPosted: Sun Nov 12, 2006 12:59 am    Post subject: Does this look like a spybot?
Reply with quote

I have a question about identification of spyware. Specifically, I see a pattern of behavior on my PC that seems odd, and I want to know if anyone is aware of a malware item that acts this way. More specifically:

I observe a "hidden" instance of iexplore. I can see it in Task Manager, but it doesn't display a window. However, it appears to have a "window title", sometimes "AutoSuggest Drop-Down" and sometimes "SysFader". I can kill it with Task Manager, but it comes back within a few minutes. Fow a while, it seems innocuous, but then it starts interacting with Kaspersky antivirus on-access scanning, such that between the two of them 100% CPU is consumed. If I kill the iexplore process, intantly the CPU drops to normal levels.

Does this ring a bell? Where else should I post this, if this isn't the right place?


_________________
--
Bill
Back to top
View users profile Send private message
mrsugg

Special Response Team
Premium Member

Joined: Aug 15, 2006
Posts: 2758
Location: Somewhere, over the rainbow...
Premium SRT Team F@H

PostPosted: Sun Nov 12, 2006 1:12 am    Post subject:
Reply with quote

Hi Mr. Bill,
Where is it running from? It should be ../Program Files/Internet Explorer/iexplore. If it isn't then it is likely malware and I suggest that you work through the Malware Removal and Prevention

procedure. This procedure has been designed to enable you to partially or even fully

rid your computer of viruses, trojans, adware, and spyware. Be sure to carefully

follow the directions in order to achieve the best results. If you have any questions

about any of the steps, then please post a new topic in the appropriate forum.

There are links to them along the way. If you still need help when you finish,

please read these directions for posting a topic in the HijackThis forum

and a trained 1st responder or security expert will assist you.


_________________
"We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness." -- Thomas Jefferson
Back to top
View users profile Send private message
MrBill

Lieutenant
Lieutenant
Premium Member

Joined: Apr 05, 2003
Posts: 218
Location: USA
Premium

PostPosted: Sun Nov 12, 2006 1:22 am    Post subject: yes...
Reply with quote

It appears to be running from the proper place. I attempted to disable iexplore by renaming it, but Windows is just too smart for me - it replaced it with a new copy. Even though it is probably a real iexplore, I suspect it's being remote controlled somehow. I didn't want to start the malware removal process unless it really was, though - and hoped someone would recognize the fingerprint.


_________________
--
Bill
Back to top
View users profile Send private message
mrsugg

Special Response Team
Premium Member

Joined: Aug 15, 2006
Posts: 2758
Location: Somewhere, over the rainbow...
Premium SRT Team F@H

PostPosted: Sun Nov 12, 2006 1:34 am    Post subject:
Reply with quote

What is your OS configuration? What software?
Also could you look in your system event and application event logs and see if there are any red X events?


_________________
"We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness." -- Thomas Jefferson
Back to top
View users profile Send private message
Wynne-R

Major
Major


Joined: Jul 30, 2005
Posts: 1411
Location: Texas

PostPosted: Sun Nov 12, 2006 1:35 am    Post subject:
Reply with quote

If you close the browser, is it still there? Have you tried it with Firefox or Opera?

It sounds normal to me, except for Kaspersky fighting with IE. It could be a BHO or activex associated with IE, which could still be malware.

— Wynn

Back to top
View users profile Send private message
mrsugg

Special Response Team
Premium Member

Joined: Aug 15, 2006
Posts: 2758
Location: Somewhere, over the rainbow...
Premium SRT Team F@H

PostPosted: Sun Nov 12, 2006 1:50 am    Post subject:
Reply with quote

I found this information for you.

sysfader.exe is a process belonging to the NVidia Graphics device range and is bundled alongside these products. This is a non-critical system process although it should not be terminated unless suspected of causing problems.

Do you have something called "Auto Suggest" on your computer? If so, then the drop-down is part of that program.

Hope this is helpful.


_________________
"We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness." -- Thomas Jefferson
Back to top
View users profile Send private message
mrsugg

Special Response Team
Premium Member

Joined: Aug 15, 2006
Posts: 2758
Location: Somewhere, over the rainbow...
Premium SRT Team F@H

PostPosted: Sun Nov 12, 2006 1:57 am    Post subject:
Reply with quote

MrBill,
I have consulted with my references and "iexplore" should not be hidden. Please start on the MRP as suggested above and post back if you have any questions.

Let us know how things go.


_________________
"We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness." -- Thomas Jefferson
Back to top
View users profile Send private message
MrBill

Lieutenant
Lieutenant
Premium Member

Joined: Apr 05, 2003
Posts: 218
Location: USA
Premium

PostPosted: Sun Nov 12, 2006 6:22 am    Post subject:
Reply with quote

Quote:
If you close the browser, is it still there?


This is with no (visible) browser running. I just changed to Firefox as my default browser to see if that made a difference, but it didn't. I kill the iexplore process, and it comes right back a couple of minutes later.


_________________
--
Bill
Back to top
View users profile Send private message
MrBill

Lieutenant
Lieutenant
Premium Member

Joined: Apr 05, 2003
Posts: 218
Location: USA
Premium

PostPosted: Sun Nov 12, 2006 6:28 am    Post subject:
Reply with quote

SysFader is disabled on my PC, and I don't have anything called "AutoSuggest" (that I know of). I think these are bogus titles designed to mislead. I will be going through the cleaning process over the next couple of days.

Really disappointing - I run multiple layers of protection, including four different spyware scanners, hardware and software firewalls, etc. Getting an infection like this is an embarassment.


_________________
--
Bill
Back to top
View users profile Send private message
Wynne-R

Major
Major


Joined: Jul 30, 2005
Posts: 1411
Location: Texas

PostPosted: Sun Nov 12, 2006 6:34 am    Post subject:
Reply with quote

Ohh! Scary.

Just to clarify - You said you changed the default. Is Internet Explorer closed when you see this process?

— Wynn

Back to top
View users profile Send private message
MrBill

Lieutenant
Lieutenant
Premium Member

Joined: Apr 05, 2003
Posts: 218
Location: USA
Premium

PostPosted: Sun Nov 12, 2006 5:27 pm    Post subject:
Reply with quote

Right. No visible Internet Explorer window.


_________________
--
Bill
Back to top
View users profile Send private message
mrsugg

Special Response Team
Premium Member

Joined: Aug 15, 2006
Posts: 2758
Location: Somewhere, over the rainbow...
Premium SRT Team F@H

PostPosted: Sun Nov 12, 2006 5:47 pm    Post subject:
Reply with quote

Nothing to be embarrassed about MrBill. Those scumbags that write the programming for these malware are very talented. There is no such thing as a 100% secure computer.

Let us know how the MRP goes and if you have any quesitons.


_________________
"We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness." -- Thomas Jefferson
Back to top
View users profile Send private message
YounGun

1st Responder
Site Moderator

Joined: Dec 11, 2004
Posts: 4369

1st Responders Moderators MVP Rootkit Responders SRT Team F@H

PostPosted: Tue Nov 14, 2006 9:51 pm    Post subject:
Reply with quote

There are several threats that use iexplore.exe or iexplorer.exe as filename.

The MRP and the hijackthis log will certainly tell the tale..


_________________
IT Stuff
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Privacy All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer