Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy problems
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 8th, 2007, 07:49 AM
Sayin's Avatar
Sayin Sayin is offline
Infrequent Poster
 
Join Date: Jul 2007
Location: Lithonia, GA
Posts: 3
Exclamation RE: what is ?POOLSV.EXE

Quoting an old topic I found while looming around looking for an answer to the same question, I decided to report my findings here.

Topic

Now... poolsv.exe Does infact exist. (NOT spoolsv.exe, I've done the check on the two files, they are quite different from one, another.) The file itself has many registry keys hidden away in the registry, and runs whenever a user accesses the internet. From what I can tell, it is spam, as it hosts a self-installing spyware program called "WinAntiSpyware 2007" which is, although similar to the basic spamming and tracking spyware, quite an annoyance because it attempts to mask it's own files under the names, or almost-matching names of key system files. This program is also carried along with another program, which I don't currently have the name of. I will get it as soon as possible, though.

Name:  Info.jpg
Views: 1416
Size:  20.1 KB
There is two of it's 6+ keys.
so far, I have found keys in these folders (I will update the list as I find more);
\\HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache

\\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\poolsv

\\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\
(mainly the key-folder "NI.UWAS7_0001_N91M2703", but you may want to search through every folder and key directory in there for various names like WinAntiSpyware 2007 FreeInstall, or something of the sort.)

\\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Explorer\ShellExecuteHooks\
(Found a key for the program it hosts, here.)

\\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Uninstall\WAS7_is1
(Found another key for the program it hosts)

\\HKEY_LOCAL_MACHINE\SOFTWARE\WinAntiSpyware 2007\
(Another key for the hosted program)

\\HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\fopn\log\
(Another key for the hosted program)
---------

If anyone else finds information on this spyware program, please share it.
~Sayin

Last edited by Sayin : July 8th, 2007 at 08:13 AM.
  #2  
Old July 8th, 2007, 08:51 AM
eniqmah's Avatar
eniqmah eniqmah is offline
Frequent Poster
 
Join Date: Jul 2006
Posts: 391
Default Re: what is ?POOLSV.EXE

Spyware.

It's not a part of Windows. And it certain doesn't look like it belongs in your Windows folder. upload to Virus total and scan. Check your ports.
__________________
TravelMate 8204WLMi
Intel Core Duo T2500, 2.0GHz|2 GB DDR2 667 RAM|ATI Mobility Radeon X1600 256MB|120 GB 5400 RPM SATA|
_____________
C2D E6600@3.7Ghz,|3GB DDR2|ATI Radeon X1950Pro|160GB+500GB x 4 SataII|
  #3  
Old July 8th, 2007, 09:10 AM
LoneWolf's Avatar
LoneWolf LoneWolf is offline
Massive Poster
 
Join Date: Jan 2006
Posts: 3,130
Default Re: what is ?POOLSV.EXE

You can try and remove this rouge app with the free version of Rouge Remover
I have removed some old entries of Error Nuker in the past with this.
Their forum is here.http://www.malwarebytes.org/forums/

A little info here.http://www.castlecops.com/o23list-1837.html
And here.http://fileinfo.prevx.com/spyware/qq...OOLSV.EXE.html
Attached Images
 
__________________
May you fly straight to heaven - but if you go to Hades - may Lethe run with Guinness

Last edited by LoneWolf : July 8th, 2007 at 12:27 PM.
  #4  
Old July 8th, 2007, 09:49 AM
GlobalForce's Avatar
GlobalForce GlobalForce is offline
Regular Poster
 
Join Date: Jun 2004
Location: Garden State, USA
Posts: 3,581
Default Re: what is ?POOLSV.EXE

Welcome Sayin,

Take a look at this 2yr old, EXAMPLE ONLY thread - http://www.geekstogo.com/forum/lofiv...hp/t60652.html

Further investigation reveal's a possible PurityScan infection. Prevx has it flagged, CCop's listing as the 'Microsoft SCC Host Protocol' (maybe running hidden). Hard to tell what's what these day's with the different variant's in circulation. If you're serious about both removing it and learning a thing or two in the process I'd suggest taking your concern's to a *dedicated* removal forum.

BFC Computer Help is one such site - http://bfccomputerhelp.com/index.php?showtopic=323

Should you have any question's prior to post, I'm sure someone there would be happy to field them for you.


Steve
__________________
"No matter what, no matter where ~ it's always home when love is there!"

Last edited by GlobalForce : July 8th, 2007 at 10:46 AM. Reason: update
  #5  
Old July 11th, 2007, 11:28 AM
Shaba's Avatar
Shaba Shaba is offline
Spyware Fighter
 
Join Date: Jul 2007
Location: Finland
Posts: 10
Default Re: what is ?POOLSV.EXE

Flagged as Trojan.Smitfraud Variant here

Comes often as a part of WinAntiSpyware/Vundo/Virtumonde infection bundle.
  #6  
Old July 14th, 2007, 07:33 AM
Sayin's Avatar
Sayin Sayin is offline
Infrequent Poster
 
Join Date: Jul 2007
Location: Lithonia, GA
Posts: 3
Default Re: what is ?POOLSV.EXE

I thank you guys alot for such informative replies. Personally, neither I, nor my software had any information on the file, or the package itself. Any advise on what program I should use to, possibly clean the entire trojan off of my computer without having to wipe my HDD?
  #7  
Old July 14th, 2007, 08:36 AM
GlobalForce's Avatar
GlobalForce GlobalForce is offline
Regular Poster
 
Join Date: Jun 2004
Location: Garden State, USA
Posts: 3,581
Default Re: what is ?POOLSV.EXE

That you were compelled to ask I'd suggest visiting malware expert Shaba at my previous link, BFC Computer.

BTW Shaba, "Wishing you a warm and healthy welcome to our Wilder's community!"


Steve
__________________
"No matter what, no matter where ~ it's always home when love is there!"
  #8  
Old July 16th, 2007, 01:30 PM
Shaba's Avatar
Shaba Shaba is offline
Spyware Fighter
 
Join Date: Jul 2007
Location: Finland
Posts: 10
Default Re: what is ?POOLSV.EXE

Thank you for your kind words, GlobalForce
  #9  
Old July 17th, 2007, 12:02 AM
Sayin's Avatar
Sayin Sayin is offline
Infrequent Poster
 
Join Date: Jul 2007
Location: Lithonia, GA
Posts: 3
Default Re: what is ?POOLSV.EXE

Oo... Interesting...
 

Wilders Security Forums > Privacy Related Topics > privacy problems « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:52 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums