I am currently dealing with this on my daughters laptop. I have run MBAM a few times and while it appears to find and remove all the dodgy files the problem remains.

I did notice an icon in the tray (shield with yellow black lines) and discovered it was linked to a programme called 1275054603.exe. I tried a websearch for this file with no results. Suspicious!
A process with this name was seen running in Task Manager which I stopped.
I disabled this process in STARTUP with msconfig, restarted and it was removed from the tray.
I also found this file was Allowed through my Firewall which I set to Deny.
The spyware did not appear after another restart.

The full address is c:\Documents and Settings\All Users\Application Data\961565551\1275054603.exe . When I go looking in that address, nothing. So I did a search and found it in c:\windows\Prefetch as . I deleted this file and restarted the pc. Again no problem. No spyware launch.

I then re-ticked the entry in STARTUP and the spyware reappeared. Stupid or what but I wanted to know for sure.
My plan is to stop the process, run MBAB, remove files, stop process in Startup and hope it stays that way.

Any ideas for getting rid of it permanently?

Dani AI

Generated

Good troubleshooting by — removing visible artifacts is a solid first step. If the item comes back after undoing cleanup, assume it used a persistence mechanism beyond the obvious. The next steps are about verification and thorough removal rather than repeating the same edits.

Use a dedicated autorun/inspection tool to enumerate less obvious startup locations and drivers, and a process/handle viewer to see which files are actually locked by running code. Autoruns and Process Explorer from Sysinternals make this practical: check image paths, publisher signatures, and any unknown DLLs or shell hooks. For any unknown binary, submit its hash or sample to VirusTotal before trusting it.

If the item resists removal or you suspect a rootkit, run an offline/boot-time scan from trusted media. Microsoft provides both an offline rescue option and an on-demand scanner: and Microsoft Safety Scanner. Also consider a reputable online scanner such as ESET Online Scanner. Bootable rescue ISOs are the safest way to find components that hide while Windows runs.

After cleaning, verify system integrity and lock things down: run sfc /scannow, update OS and apps, change important passwords from a known-clean device, check router DNS and admin credentials, and make a full backup or system image. If persistence components (unsigned drivers, unknown services, modified boot files) remain, a clean reinstall from known-good media is the most reliable way to be certain. Always back up data and registry keys before making further changes.

OK I think it's gone.
In the end I did a search for "1275054603" in the registry files using regedit and deleted any entry with this file name including one encrypted Count Key. There was also a folder with this name in the registry which I deleted.
It no longer appears in the Startup list.
MBAM runs clear.
No tray icons and no pop-ups.

Time for bed as it's 4am here.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.