IWETHEY v. 0.3.0 | TODO
1,095 registered users | 0 active users | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New So you can be helpful after all
That's what I was looking for, some good advice

I don't why you say I was asking a group of people who couldn't possibly know

Certainly I am not the only person to encounter spyware

btw, I googled tick~th.exe the program that ran IE but found nothing
so I thought I'd ask here

A
Play I Some Music w/ Papa Andy
Saturday 8 PM - 11 PM ET
All Night Rewind 11 PM - 5 PM
Reggae, African and Caribbean Music
[link|http://westcottradio.org|Tune In]
New The reason you fond nothing on that .exe....
is that they randomize the name on install.

Also, the random name also keeps track of the other random names it installs and runs.

2-6 exes typically run to be watchdogs so they can be "kept running".

Assuming 6 versions running hidden...

1 watches to make sure 2,3,4,5,6 are running.
2 watches to make sure 1,3,4,5,6 are running.
3 watches to make sure 1,2,4,5,6 are running.
4 watches to make sure 1,2,3,5,6 are running.
5 watches to make sure 1,2,3,4,6 are running.
6 watches to make sure 1,2,3,4,5 are running.

You have to kill all of them at once.

Good luck. I'll bet there are some latent ones that will start up at a later date. Lobbed in on some CLSID.
--
[link|mailto:greg@gregfolkert.net|greg],
[link|http://www.iwethey.org/ed_curry|REMEMBER ED CURRY!] @ iwethey
PGP key: 1024D/B524687C 2003-08-05
Fingerprint: E1D3 E3D7 5850 957E FED0  2B3A ED66 6971 B524 687C
Alternate Fingerprint: 09F9 1102 9D74  E35B D841 56C5 6356 88C0
     Spyware running IE - (andread) - (18)
         Re: Spyware running IE - (pwhysall)
         Creating dummy accounts on message boards and spamming. -NT - (inthane-chan)
         perhaps a click thru trojan to generate ad revenue -NT - (boxley)
         Hehehe - (crazy) - (9)
             Wrong - (andread) - (8)
                 Watch it as it runs - (crazy) - (7)
                     tcpdump is your friend, works under winders -NT - (boxley)
                     remind me of that the next time you get root kitted :-) -NT - (boxley) - (3)
                         There's NOTHING that can be done once root kitted - (crazy) - (2)
                             Don't agree -NT - (andread) - (1)
                                 You're wrong. - (pwhysall)
                     So you can be helpful after all - (andread) - (1)
                         The reason you fond nothing on that .exe.... - (folkert)
         Do you know the actual spyware? - (static) - (3)
             Re: Do you know the actual spyware? - (andread) - (2)
                 I like their eula - (boxley)
                 WinZix is clearly the problem. - (static)
         another link to your issue - (boxley)

Learn to love the Questions.
--Rilke, Rainer Maria
51 ms