Spamremote.exe

Reply

Join Date: Mar 2004
Posts: 209
Reputation: i686-linux is on a distinguished road 
Solved Threads: 12
i686-linux's Avatar
i686-linux i686-linux is offline Offline
Posting Whiz in Training

Spamremote.exe

 
0
  #1
May 12th, 2004
Has anyone seen this? I can't find anything on google/groups, none of my co-workers have seen this and none of our usual recommended spy-ware tools from here are finding this! I boot into safe mode and remove the registry keys and exe file, but after a reboot it is somehow repropogated and back in the startup! It doesn't do any browser hijacking, just random popups. This thing is damned annoying, and until it gets removed from a client's computer, I get phone calls every time there is a popup! If anyone could help out that would be MUCH appreciated.

Thank you in advance!
PARANOIA:
A healthy understanding of the way the universe works.
Reply With Quote Quick reply to this message  
Join Date: Feb 2002
Posts: 626
Reputation: MAD_DOG is on a distinguished road 
Solved Threads: 13
MAD_DOG's Avatar
MAD_DOG MAD_DOG is offline Offline
Practically a Master Poster

Re: Spamremote.exe

 
0
  #2
May 13th, 2004
What steps have you ran all ready? Your saying in IE your getting ramdom pop-ups? Please be a little more clear on the question. Thanks buddy.
Jimmy
E-Mail - jimmy@fiberops.net
Chief Information Officer (CIO) of FiberOps
Reply With Quote Quick reply to this message  
Join Date: Mar 2004
Posts: 209
Reputation: i686-linux is on a distinguished road 
Solved Threads: 12
i686-linux's Avatar
i686-linux i686-linux is offline Offline
Posting Whiz in Training

Re: Spamremote.exe

 
0
  #3
May 26th, 2004
Originally Posted by MAD_DOG
What steps have you ran all ready? ...Please be a little more clear on the question.
Originally Posted by i686-linux
I can't find anything on google/groups, none of my co-workers have seen this and none of our usual recommended spy-ware tools from here are finding this! I boot into safe mode and remove the registry keys and exe file, but after a reboot it is somehow repropogated and back in the startup!
("our usual recommended spy-ware tools from here" means the same tools that we always tell people here at daniweb to use.)

In other words...

I ran AdAware, SpyBot, and Hijack-this with no results of anything pertaining to spamremote.exe (And yes all of these were up to date) There were a few things related to SahAgent, but those were removed by adaware, and have been gone for days.

After those programs found nothing I booted into safe mode to delete the spamremote.exe file on the HD as well as the registry keys that were causing it to startup, checked msconfig as well. No records of it in the startup. Cool? No... it repropogates itself somehow from a secondary binary elsewhere on the computer.

Other resources I have checked are google/groups.google and co-workers.

Originally Posted by MAD_DOG
Your saying in IE your getting ramdom pop-ups?
Originally Posted by i686-linux
It doesn't do any browser hijacking, just random popups.
I didn't mention IE. What I am saying is that it does random popups. Whether IE is loaded or not. Hence, random.
PARANOIA:
A healthy understanding of the way the universe works.
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC