AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
December 02, 2008, 09:07:49 AM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 4756 Members
Latest Member: Uobeley
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Spyware Alerts  |  Topic: Spyware.InlookExpress 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: Spyware.InlookExpress  (Read 765 times)
Brad
SysAdmin
Tech Team
Hero Member
********
Offline Offline

Posts: 391



View Profile
Spyware.InlookExpress
« on: June 13, 2005, 12:55:58 AM »

Behavior
Spyware.InlookExpress logs keystrokes and captures screenshots.

Symptoms
Your Symantec program detects Spyware.InlookExpress.

Transmission
Spyware.InlookExpress must be manually installed.

technical details
File names:
inlookexpresssetup.exe
svchost.exe
final.exe
IEControl2.exe

When Spyware.InlookExpress is installed, it performs the following actions:

   1. Creates the following files:

          * %Windir%\inlook.exe
          * %Windir%\is-QV2PM.exe
          * %Windir%\is-QV2PM.lst
          * %Windir%\sds20.oca
          * C:\sds20\final.exe ( viral )
          * C:\sds20\IEControl2.exe ( viral )
          * C:\sds20\ijl11.dll
          * C:\sds20\remie20.exe
          * C:\sds20\settings.dat
          * C:\sds20\svchost.exe ( viral )
          * C:\sds20\svchost32.exe
          * C:\sds20\TheHook.dll

            Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP) or C:\Winnt (Windows NT/2000).

   2. Creates the following registry key:

          * HKEY_LOCAL_MACHINE\SOFTWARE\sds

   3. Adds the value:

      "sds20" = "C:\sds20\svchost.exe"

      to the registry subkey:

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

      so that the risk runs every time Windows starts.

   4. Logs keystrokes and captures screenshots.

REMOVAL INSTRUCTIONS
See: http://securityresponse.symantec.com/avcenter/venc/data/spyware.inlookexpress.html

To delete the value from the registry
   1. Click Start > Run.
   2. Type regedit

      Then click OK.

      Note: If the registry editor fails to open the risk may have modified the registry to prevent access to the registry editor. Security Response has developed a tool to resolve this problem. Download and run this tool, and then continue with the removal.

   3. Navigate to the subkey:

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

   4. In the right pane, delete the value:

      "sds20" = "C:\sds20\svchost.exe"

   5. Navigate to and delete the registry subkey:

      HKEY_LOCAL_MACHINE\SOFTWARE\sds

   6. Exit the Registry Editor.
Logged

Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Spyware Alerts  |  Topic: Spyware.InlookExpress « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!