Software keeps reinstalling itself?

makken

Golden Member
Aug 28, 2004
1,476
0
76
We had relatives over for the holidays, and I let them use my laptop to check e-mail, etc (mainly so my little cousin could play his flash games). Didn't think much of it, and didn't keep taps on what people were doing.

Last night, when I booted up, the first thing that popped up was a program I never saw before, called 'SpyAxe'. It appeared to be an anti-spyware / adware program, and started a scan. I already had spybot installed, so.. no biggie, went to add / remove programs and uninstalled it.

Later that night, I rebooted, and to my suprise, found the program still installed. I uninstalled again and restarted. A few minutes after boot up, the program was back. Now believing it was adware, I ran spybot, updated and performed a full scan. It picked up Spyaxe and 3 or so other things. hit fix and restarted.

It came back again. A little worried now, I performed the uninstalled, verified that its directory under program files was gone, then did a modified date serach and found its setup files under Docs and settings \ Local settings \ Temp. deleted those, and restarted system.

within minutes, spyaxe had reinstalled itself. did a quick search again and found its install file back in the same place. Now, convinced i was dealing with a trojan, fired up AntiVir, updated and ran a full scan. It detected nothing. A little worried now, i downloaded NetLimiter to see if I can pick up anything. Nothing showed up there either.

Did a quick google search, and found the tool "SmitRem" downloaded and ran that, but besides reverting me to classic windows theme, it didn't do anything.

After that, It was nearly 2am, and I had work early this morning, so I couldn't deal with it anymore.

I did a little searching this morning at work, and found that it is indeed a trojan named 'Zlob.cy' but i'm lost as to why it wasn't detected by AntiVir. I'm planning to put back my old copy of Norton that came with the laptop and see if that's able to detect it.

Has anybody had this before? are there other steps I can try in case norton fails?
Thanks
 

CKent

Diamond Member
Aug 17, 2005
9,020
0
0
Lol you let someone - especially a kid - use your PC, unsupervised, on an admin account? Bad ATer! *raps OP with rolled up newspaper*

No virus / spyware scanner is complete, use at least two of each. Personally I go with avg free resident and occasionally a housecall scan at trendmicro.com for virus scanning. For spyware scanning, adaware & spybot. Google manual removal instructions for it, that's been helpful to me when cleaning friends'/relatives' borked-up PCs.
 

cubby1223

Lifer
May 24, 2004
13,518
42
86
I never trust the uninstallers put out by the companies themselves. They are purposely infecting machines, as I was cleaning up a computer a couple weeks ago with Spyaxe. I actually didn't finish up as I couldn't find enough information back then, and have had car troubles lately so I haven't gotten back.

It had a flashig icon in the system tray that is supposed to mimmick the MS virus & malicious software removal tool, and puts up a balloon tip saying your computer is infected, and any click anywhere in the balloon or the icon, and the system attempts to load SpyAxe, or if it's not found, goes out to a page on spyaxe.net to exploit a flaw in IE & reinstall the software. So don't believe that BS in the other thread about SpyAxe saying it's not their fault the software was illegally installed on the system.

I contained it with AVG & added entries in the hosts file for spyaxe.com & spyaxe.net, disabled balloon tips, & set that flashing icon to always hide in the tray. So a part of it is still there, but it's not the crap like before.

But yeah, I'll have to try those methods as well once I am able to again.
 

Markbnj

Elite Member <br>Moderator Emeritus
Moderator
Sep 16, 2005
15,682
14
81
www.markbetz.net
Yeah, the installers these scumbags include often do nothing at all, or they pop up a web page and ask you to click an "uninstall" button. I had a nasty one a few months back that started with a trojan that modded wininet.dll, and then initiated an outbound connection and started downloading packages of adware. Some of these turned on active desktop and modded the background, others popped up install boxes. It was a mess.

If it keeps coming back, then chances are it has installed a modified version of a file like wininet.dll, or it has inserted something into the startup folder or the registry run keys.
 

makken

Golden Member
Aug 28, 2004
1,476
0
76
yeah, I have that flashing icon on my system tray.
I've hidden balloon tips, but I would really like to get them back, as i use those as my main notifier of my wireless connection.

You said AVG caught the trojan that caused it? I may give that a go when I get home from work later today.

I'm gonna try to blacklist the spyaxe website on my router to prevent anyone else (some of my roommates don't exactly practice safe browsing) from getting it hopefully.

there's no way to get rid of that flashing icon? cause in addition to the balloon tip, it also has a 'pop' sound to it everytime, which still plays when tips are hidden.
 

Unkno

Golden Member
Jun 16, 2005
1,659
0
0
The safest way to remove a virus, trojan, and spyware/adware is to do a reformat or restore an image of your drive.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
I'll suggest you try the McAfee scanner described here since McAfee has made a point of adding SpyAxe detection (and refined it a couple times too). And make a Limited account, so your visitors aren't flyin' around with Administrator powers next time.
 

cubby1223

Lifer
May 24, 2004
13,518
42
86
Originally posted by: makken
there's no way to get rid of that flashing icon? cause in addition to the balloon tip, it also has a 'pop' sound to it everytime, which still plays when tips are hidden.

I was just looking at another computer today with SpyAxe, so I had a chance to try some of the solutions. For me, this worked:
http://www.webuser.co.uk/forums/showflat.php/Cat/0/Number/237336/Main/237244/

The second post has a link to a custom SmitRem.exe file that I ran in safe mode & it got rid of the flashing icon.
 

Looney

Lifer
Jun 13, 2000
21,938
5
0
You need to go into the registry and fix it. It's in there, and each time your computer reboots, it's reinstalling it.
 

makken

Golden Member
Aug 28, 2004
1,476
0
76
Thanks a lot for the replies guys

It looks like McAfee did the trick =)

I dunno why neither AntiVir nor Norton wouldn't pick it up though, even after the trojan was listed on the Norton webpage -.-'