beware of " UnSpyPC " !!!

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • UncasMS
    Super Moderator
    • Nov 2001
    • 9047

    beware of " UnSpyPC " !!!

    take care of a software called "UnSpyPC"

    this software pretends to be a spyware removal tool


    you may find something like this on your pc:

    File names:
    UnSpyPC.exe
    UnSpyPCUpdate.exe

    When UnSpyPC is executed, it performs the following actions:

    1. Creates the following files:

    * %ProgramFiles%\UnSpyPC\UnSpyPC.exe
    * %ProgramFiles%\UnSpyPC\UnSpyPCUpdate.exe
    * %ProgramFiles%\UnSpyPC\uninstall.exe
    * %ProgramFiles%\UnSpyPC\uns.ico
    * %ProgramFiles%\UnSpyPC\warez.dat
    * %ProgramFiles%\UnSpyPC\wover.dat
    * %Desktop%\UnSpyPC Scanner & Monitor.lnk

    Note:
    * %ProgramFiles% is a variable that refers to the program files folder. By default, this is C:\Program Files.
    * %Desktop% is a variable that refers to the Windows Desktop folder. By default, this is C:\Documents and Settings\Administrator\Desktop (Windows 95/98/Me) or C:\Documents and Settings\Administrator\Desktop (Windows NT/2000/XP).

    2. Creates the following registry subkeys:

    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\
    {BF69DF00-4734-477F-8257-27CD04F88779}
    HKEY_CURRENT_USER\Software\UnSpyPC
    HKEY_LOCAL_MACHINE\Software\UnSpyPC
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Uninstall\UnSpyPC

    3. Adds the values:

    "UnSpyPC" = "%ProgramFiles%\UnSpyPC\UnSpyPC.exe"
    "[RANDOM STRING 1]" = "[RANDOM STRING 2].exe"

    to the registry subkey:

    HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run

    so that the risk runs every time Windows starts.

    The variables [RANDOM STRING 1] and [RANDOM STRING 2] represent randomly chosen strings.

    4. May add random registry entries. The added entries may look similar to the following registry entries:

    HKCR\CLSID\{94A0E512-EFBE-18DE-9964-820E962F7FAD}\InprocServer32\
    "(Default)" = "34763.dll"

    HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\
    "{94A0E512-EFBE-18DE-9964-820E962F7FAD}" = "DCC_send"
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run \"SysSupport" = "sysconf16.exe"
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run \"newbreed" = "backorif.exe"
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run \"utsgmon" = "driver64.exe"
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run \"MON76234" = "NopeZ.exe"
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run \"cmon14" = "borlandg.exe"
    source: symantec




    Removal Instructions:

    Delete the following directories
    %programfilesdir%\UnSpyPC

    Delete the following files
    UnSpyPC.exe
    UnSpyPCUpdate.exe
    uninstall.exe
    uns.ico
    %programfilesdir%\UnSpyPC\warez.dat
    %programfilesdir%\UnSpyPC\wover.dat
    %desktopdir%\UnSpyPC Scanner & Monitor.lnk

    Delete the following cookies
    UnSpyPC does not create any cookies

    Delete the following registry keys
    UnSpyPC
    UnSpyPC
    {BF69DF00-4734-477F-8257-27CD04F88779}
    {BF69DF00-4734-477F-8257-27CD04F88779}
    UnSpyPC

    Delete the following registry values
    UnSpyPC
    {BF69DF00-4734-477F-8257-27CD04F88779}
  • Zero G
    Next to Arch Stanton
    • Jan 2006
    • 545

    #2
    Thanks for the tip! Any idea on what is installing it?
    "Wanted in 14 counties of this state. The condemned is found guilty of the crimes of murder, armed robbery of citizens, state banks and post offices, the theft of sacred objects, arson in a state prison, purgery, bigamy, deserting his wife and children, inciting prostitution, kidnapping, extortion, receiving stolen goods, selling stolen goods, passing counterfeit money, and contrary to the laws of this state, the condemned is guilty of using marked cards...therefore according to the powers vested in us, we sentence the accused here before us Tuco Benedicto Pacifico Juan Ramirez also known as the Rat and any other aliases he may have to hang by the neck until dead."

    Comment

    • UncasMS
      Super Moderator
      • Nov 2001
      • 9047

      #3
      Originally Posted by Zero G
      Thanks for the tip! Any idea on what is installing it?
      incautious users (like so often) trusting evil adverts like this:


      [don't download let alone install the crap please!!!]

      Comment

      • Zero G
        Next to Arch Stanton
        • Jan 2006
        • 545

        #4
        I never download anything I don't already know about. Way too many people trust everything they read and download all kinds of crap.
        "Wanted in 14 counties of this state. The condemned is found guilty of the crimes of murder, armed robbery of citizens, state banks and post offices, the theft of sacred objects, arson in a state prison, purgery, bigamy, deserting his wife and children, inciting prostitution, kidnapping, extortion, receiving stolen goods, selling stolen goods, passing counterfeit money, and contrary to the laws of this state, the condemned is guilty of using marked cards...therefore according to the powers vested in us, we sentence the accused here before us Tuco Benedicto Pacifico Juan Ramirez also known as the Rat and any other aliases he may have to hang by the neck until dead."

        Comment

        • soup
          Just Trying To Help
          • Nov 2005
          • 7524

          #5
          Thanks for the heads up, will check.

          Comment

          • Dan
            Digital Video Master
            Digital Video Master
            • Dec 2005
            • 1029

            #6
            Thank you for the heads up! Especially with the web site and all, that could fool people easily.

            Comment

            • LT. Columbo
              Demigod of Digital Video
              • Nov 2004
              • 10671

              #7
              yes ty for the notice. people behind spyware are the same breed as serial killers in my book. i already have spyware i can't remove with the software i have currently....
              "One day men will look back and say I gave birth to the 20th Century". Jack The Ripper - 1888
              Columbo moments...
              "Double Shock" "The Greenhouse Jungle" "Swan Song" FORUM RULES
              "You try to contrive a perfect alibi, and it's your perfect alibi that's gonna hang ya."
              (An Exercise In Fatality, 1974)


              Comment

              • mill
                Im Off To See The Wizard
                • Oct 2005
                • 1105

                #8

                Have you tryed this tool from microsoft Lt.?
                Keep Plugin away

                Comment

                • LT. Columbo
                  Demigod of Digital Video
                  • Nov 2004
                  • 10671

                  #9
                  no, and i bookmarked it. this shiite has been on my pc for about a year. it causes no problemos but must removed. when i have time between cases i shall delve into it

                  ty
                  "One day men will look back and say I gave birth to the 20th Century". Jack The Ripper - 1888
                  Columbo moments...
                  "Double Shock" "The Greenhouse Jungle" "Swan Song" FORUM RULES
                  "You try to contrive a perfect alibi, and it's your perfect alibi that's gonna hang ya."
                  (An Exercise In Fatality, 1974)


                  Comment

                  • a2j3
                    If it aint broke, don't fix it
                    • Feb 2006
                    • 546

                    #10
                    Hello UncasMS

                    thank you 4 the info. how do u feel about the program Ad-adware personal se?
                    sigpic

                    Comment

                    • LT. Columbo
                      Demigod of Digital Video
                      • Nov 2004
                      • 10671

                      #11
                      i know you're asking UncasMS, but having used it for 2 years, it won't catch everything (like most progs). someone needs to invent an uber spyware prog that detects everything under the sun.
                      "One day men will look back and say I gave birth to the 20th Century". Jack The Ripper - 1888
                      Columbo moments...
                      "Double Shock" "The Greenhouse Jungle" "Swan Song" FORUM RULES
                      "You try to contrive a perfect alibi, and it's your perfect alibi that's gonna hang ya."
                      (An Exercise In Fatality, 1974)


                      Comment

                      • soup
                        Just Trying To Help
                        • Nov 2005
                        • 7524

                        #12
                        I don't know Ad-Aware tickled a trojan for me today & Avast grabbed it. You are right though LT even with what I have to prevent that it still got through.
                        Last edited by soup; 14 Apr 2006, 01:01 PM.

                        Comment

                        • Gary D
                          Lord of Digital Video
                          Lord of Digital Video
                          • Dec 2005
                          • 2266

                          #13
                          someone needs to invent an uber spyware prog that detects everything under the sun.
                          or use multiple (and different) scan programs (one at a time and only one running)

                          I also use rootkit revealer as well as Nortons Internet Suckurity

                          I think there is like three or more spyware programs out there free.
                          Gary D

                          Comment

                          • UncasMS
                            Super Moderator
                            • Nov 2001
                            • 9047

                            #14
                            how do u feel about the program Ad-adware personal se
                            i personally dont use it (having ruined two systems with previous versions of this tool yrs ago) but many people do and it cant be that bad

                            i, too, do suggest to use more than one tool in order to scan for virii/spyware



                            if need be, try one of these:

                            - stinger from mcafee

                            - a² / a-squared (needs free registration but is worth it!)

                            - ewido

                            - spybot search & destroy

                            - ad-aware

                            Comment

                            • a2j3
                              If it aint broke, don't fix it
                              • Feb 2006
                              • 546

                              #15
                              Hello LT. Columbo

                              i very much agree with u. one tool 2 do it all would be nice. i used to run norton on my system and was still having comp, probs,, so i downloaded ad-aware and avg, in less than 1 hour after restart comp. ran as good as new. got rid of norton and added cox security suite and avg no more unresolved problems.
                              sigpic

                              Comment

                              Working...