OK. I rarely get stymied or attacked by these things but somehow I ended up with a nasty little piece of spyware called Winhound.
It claims to be a spyware scanner but if it is then why: 1. Did it install without my permission? 2. Does it reinstall itself every time I get online?
3. Not allow me to delete it’s registry keys?
Here’s the situation. It apparently has some sort of process that waits until a user logs on. We have 5 different user profiles on the machine (Win XP). It doesn’t matter who it is. As soon as they connect (DSL) it installs. Thereafter it will run at startup.
Here’s what I’ve done so far. I’ve deleted everything on the PC in every user’s profile regarding Winhound. It seems to store itself in a variety of locations, …\Local Settings\Application Data, \Local Settings\Temp etc.
I’ve cleared out the registry of all winhound related things EXCEPT…there’s one regkey I can’t get rid of. It’s called winhound.com and it has two subkeys. The bottommost child is the problem. I can’t view it, can’t change permissions on it, can’t delete it. I’m convinced that’s the source of the problem.
I’m assuming there’s a process running on startup causing the install but I can’t figure out which one it would be and I can’t find the keys in the registry for startup. Also, it doesn’t show up when I run msconfig unless it’s been installed. That is, after I get rid of it, it doesn’t show up in msconfig so I can’t find what process it’s starting. Also I’ve started in safe mode but still can’t delete the regkey.
Any help in being able to delete naughty regkeys would be appreciated.
Also, Adaware and Window Washer don’t get rid of it either.
Google searches haven’t helped a bit.
Hey,
I don’t know anything about winhound but I have a method (somewhat dangerous) for deleting stubborn reg entries. It is dangerous in that it gives you totally unfettered access to delete anything ( so no mis-clicking) and also sometimes deleting reg entries can have unintended effects ( like the early fix for the Sony-BMG malware disabling your cd drive altogether.)
Download this .iso and burn to a cd (bootable)
http://sourceforge.net/project/showfiles.php?group_id=99853
INSERT is a german forensics and security Live linux distribution. Live Linux distros run only using your cd drive and ram so they can run a full linux os without disturbing your windows. Boot from the cd. when you are done reboot without cd.
Boot from the cd. INSERT should find all of your hardware (monitor, mouse, etc) starts up to a simple looking xwindows environment. On the lower right shoud be a representation of the drives on your machine. you scroll through them with L and R arrows. find your windows drive (C?) and click on it to mount (connect to/access) it. Right click on the screen and look through the menus that apear for the file manager app. there should be two versions, one runs as root (all permissions)
Familiarize yourself with the operation of the file manager (I can’t remeber the keystrokes right now) find those pesky undeletable files and delete them ( don’t mess up!) close file manager click on drive again to unmount. right click use shut down. remove cd reboot computer. Voila!
Might come back anyway though as realy isidious(sp) stuff usually hides even more deeply than that (unrelated file names, embedded in other apps, etc)
Total Disclaimer - Not Responsible fro fried machine or corupted OS - Replace winbloze with a nice simple Linux (Fedora Core 4 is nice) distro. It is better for multi-user systems anyway and has no spyware/virus issues - surf with impunity!
Hope this helps, Good Luck!
Don
Last I checked, Linux was unable to write to Windows XP partitions
(though it can mount and read them). Is this still the case? If so, you
wouldn’t be able to write the new registery or delete files…
INSERT uses a small app called Captive to read and write to NTFS patitions. It works. Linux can read and write to NTFS fairly reliably, especially for something as simple as deleting or writing a single file. The problem for Linux developers as I understand it is that NTFS support is probably not up to snuff for fast and complex read/write operations ( integrated databases, etc) so it remains a "beta’ part of the os. But of course Beta is Betta!
Don
Huh. Cool.
I think it’s clever that they use a bootable CD linux distro for Forensics…
Thanks. I’ll try the bootable Linux.
It’s apparently a new one and only within the last couple days have threads started to appear on various web sites. I’m going to either try the Linux fix or use a combo of a couple other tools I’ve found.
I’ll keep you posted.
Oh, I learned the hard way: Backup your VMM32.vxd before removing spyware. Oy.
You probably can’t delete the reg key because a process has it open. Linux won’t help here unless you have a linux-based registry editor. But the reg key isn’t what is starting the app (though a different reg key might be doing it). This utility may give you a clue as to which process is running and what starts it. This one will find stuff hidden from view using rootkit techniques.
As far as I know Linux doesn’t even now what a registry is.Just a bunch of text files ready for deleting. The live cd operates without booting any part of windows so no processes will be running from the windows registry.
Linux live cds are super cool and fun anyway. INSERT is a super lightweight (ugly) and limited cd for limited purposes. For fun try Knoppix, it is a full linux distro with all of the graphics, bells and whistles, etc. Good for getting a tast of Linux before making the (inevitable) jump. It will work on most modern pc’s with little or no setup, just boot the computer with the cd in your drive.
And remember, in a world without walls and fences, who needs windows and gates.
Don
Those look like great tools. Especially the RootkitRevealer. Awesome. I’m going to have fun tonight with those.
Is this one of your hobbies? Getting infected with spyware? 
Why yes. Yes. Is that the kind of hobby you might be interested in sharing with a loving companion?