Stubborn spyware - process: 3188766420:726265665.exe
Posted on 2011-09-22
When I first saw this computer (win xp) it was in the state such that all the icons and files were hidden.
I ran rkill until I could run malwarebytes and removed a few things and then ran the unhide utility to restore the desktop, start menu and hard drive files. Everything seemed pretty normal at this time.
When I restarted everything seemed fine but after about 15 minutes something strange happens where programs are running and if a window is active you can work in it but the taskbar stops functioning, you can't restore a window and you can't do ctrl-alt-del.
I was surprised by this. I hought the issue had been resolved. After restarting I can see that there is a suspicious process 3188766420:726265665.exe which I cannot terminate by end process or end process tree.
I continued working on it, have run malwarebytes a few more times and it usually comes up clean or it found one thing when running in safe mode as administrator but that didn't remove this process after restart.
I searched through the registry for 3188766420 and found 3 instances and removed them. Now the registry search is clean but still this process returns after every restart. Except if I start into safe mode as the normal user or as administrator the process does not run.
I will wipe the computer next but other than this it is in perfect condition and it will be a bit of work to do it and get it set back up. I also thought about trying to create another user account. But I think that since it isn't running in safe mode I should be able to get rid of this.
I haven't found anything about this specific problem and it is unusual in the sense that it doesn't give any name to define it by except for that strange process.
The last time I ran malwarebytes in safe mode it found one trojan in a location related to java installation.
Anyway I am just putting it out here if anyone knows anything about this problem I will appreciate any insight.
Thanks and best regards,