AlanKG
February 16th, 2004, 04:18 AM
I was cleaning up a machine with this rather nasty spyware on it.
Although Blaster S&D identified and removed a lot of associated stuff it didn't actually catch everything and the machine was subject to immediate reinfection after a reboot.
The key omission (I think) was the failure to remove the registry entry HKLM\Software\Microsoft\Internet\Run: [SystemSearch] C:/WINDOWS/REGEDIT.EXE -s C:/WINDOWS/system.reg.
Once this key (and the associated file) were deleted the spyware stopped reinserting itself.
See these links for more information:
http://forums.techguy.org/t194850/s1bfe82e7e83cb5452cd5bcfd2524a41d.html
http://amazingtechs.com/index.php?showtopic=9999
I did also manually clear a key:
HKCU\Software\Microsoft\Internet Explorer\Main, Search
Alan
Although Blaster S&D identified and removed a lot of associated stuff it didn't actually catch everything and the machine was subject to immediate reinfection after a reboot.
The key omission (I think) was the failure to remove the registry entry HKLM\Software\Microsoft\Internet\Run: [SystemSearch] C:/WINDOWS/REGEDIT.EXE -s C:/WINDOWS/system.reg.
Once this key (and the associated file) were deleted the spyware stopped reinserting itself.
See these links for more information:
http://forums.techguy.org/t194850/s1bfe82e7e83cb5452cd5bcfd2524a41d.html
http://amazingtechs.com/index.php?showtopic=9999
I did also manually clear a key:
HKCU\Software\Microsoft\Internet Explorer\Main, Search
Alan