General Spyware Notice: Heads up for Winsvcup and Mswinup

Performance, hardware, software, general buying and gaming discussion..
Post Reply
Message
Author
christopher_wolf
Special Member
Posts: 5741
Joined: Sat Oct 08, 2005 1:24 pm
Location: UC Berkeley, California
Contact:

General Spyware Notice: Heads up for Winsvcup and Mswinup

#1 Post by christopher_wolf » Thu Oct 05, 2006 10:00 pm

Whilst cleaning up someone's home laptop (Dell) that they brought into the lab; I found two pieces of Malware which I would opine are rather difficult to get rid of and are fairly stealthy;

Winsvcup.exe

and

Mswinup.exe

I managed to pick these up whilst the Dell was hooked up to the network firewall and I kept noticing that not only were these *.exes trying to contact some strange IPs (one a mailsite under the *.ru domain, a bad sign if ever there was one) and had to be cleared by the user to go through the client firewall each and every time. *No* windows program should have to do this once cleared by the user or system-launched. What was slightly disturbing is that it didn't show up on a system scan with Ad-Award Profesional or Spybot S&D and it had to be caught by the latest AVG definitions and the firewall; which should really be the last line of defense should things come to that. It took me quite awhile to discover why exactly it didn't flag the other lines of defense when running. It primarily uses the authority of the user to validate itself to the system.

I did a little sniffing and found that, while it does report token information on your system, it generall just changes registry values for other programs to take advantage of. On the system in question, however, this was mainly nullified by a weekly registry scan&fix operation as many of the keys it changes are mostly invalid if the malware it is changing it for doesn't exist on the system.

Cleaning it up with Prevx seems to get rid of it, as well as just deleting the executables and seeing whether or not they come back. Fairly easy, but sneaky at first. Thought I might put this information here just in case anybody wants to check.

Moral: *Always* watch whatever you clear to get past your firewall(s). :)
IBM ThinkPad T43 Model 2668-72U 14.1" SXGA+ 1GB |IBM 701c

~o/
I met someone who looks a lot like you.
She does the things you do.
But she is an IBM.
/~o ---ELO from "Yours Truly 2059"

dsigma6
Senior ThinkPadder
Senior ThinkPadder
Posts: 2299
Joined: Wed Apr 26, 2006 2:13 pm
Location: Philadelphia, PA
Contact:

#2 Post by dsigma6 » Fri Oct 06, 2006 7:38 am

I've never heard of Prevx- Is it just a virus/spyware removal tool, or does it actually scan the system and find malicious crap?
[Current] [Dell Latitude D630] : [Past] [T43] [T40] [T23] [T20] [R40] [X22] [600E] [570] [765D]

christopher_wolf
Special Member
Posts: 5741
Joined: Sat Oct 08, 2005 1:24 pm
Location: UC Berkeley, California
Contact:

#3 Post by christopher_wolf » Fri Oct 06, 2006 2:37 pm

dsigma6 wrote:I've never heard of Prevx- Is it just a virus/spyware removal tool, or does it actually scan the system and find malicious crap?
It does a....deep scan; the reason I hesitate is that I was up late last night clearing that laptop from the lab, in addition to various other fix ups I applied to it, and when they say deep scan, they really mean a *deep* scan. It is actually pretty good, if not a tad over-zealous, but it has a very clean and efficient system for it. More minimal than AVG for one and probably as simple as it could get without dropping features. It also picked up a hidden copy of one of thoese exes that had somehow managed to propagate to another folder elsewhere. It also seems to have a very comprehensive database on malware as well as adding what you flag as malware to the online database.

I am actually going to try it out on a few test systems over the weekend and, if it does as good as they claim, I might think about getting a site license/subscription for it. In any case, I will see...

:)
IBM ThinkPad T43 Model 2668-72U 14.1" SXGA+ 1GB |IBM 701c

~o/
I met someone who looks a lot like you.
She does the things you do.
But she is an IBM.
/~o ---ELO from "Yours Truly 2059"

dsigma6
Senior ThinkPadder
Senior ThinkPadder
Posts: 2299
Joined: Wed Apr 26, 2006 2:13 pm
Location: Philadelphia, PA
Contact:

#4 Post by dsigma6 » Fri Oct 06, 2006 3:05 pm

Thanks Chris. I'll give it a whirl later on. It should give my tpfancontrol settings a thorough test.
[Current] [Dell Latitude D630] : [Past] [T43] [T40] [T23] [T20] [R40] [X22] [600E] [570] [765D]

Post Reply
  • Similar Topics
    Replies
    Views
    Last post

Return to “Thinkpad - General HARDWARE/SOFTWARE questions”

Who is online

Users browsing this forum: No registered users and 5 guests