Self replicating program with name variants...
Posted: Wed May 05, 2004 4:35 pm
Couldn't really think of a better title
Anywho, this is the problem. My sister has been noticing that when she uses IE (Yes, I know, she still uses it though), something else keeps stealing the focus away from it. Nothing pops-up or anything but all of a sudden the IE window becomes a background window even though nothing comes up infront of it.
I decided to run through different things to see what could potentially be causing this problem and the first thing that came to my mind was spyware or a virus. I opened her task manager up to look at the processes (WinXP Home btw) and we went through each process and came across several that I didn't recognize.
So, we did some research and google didn't return anything on the ones I was the most concerned about. I had her update Ad-Aware and run it, found some stuff but it didn't remove this problem. Had her update Spybot, ran it, found some stuff, didn't remove the problem. Updated Norton A/V and Norton turned up nothing as well.
This is where it gets interesting though. I told her to open her registry and go to HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
and inside there was an entry called "4M@ZD#F5KNNFGP" which of course didn't turn anything up in google. This is where the only instance of this item is found in the registry. This entry though leads to 3 executables in the Windows\System32 folder called Msyi62.exe, izi6.exe, & jifyvw.exe, not all at the same time though.
When you delete the string and reboot it replaces itself with one of these .exe files and cycles through each one if you repeat the process. It doesn't show up in HKEY_CURRENT_USER though. Same happens when you use msconfig to disable it from starting up, it creates another instance of itself and it is checked off again.
In the task manager there is gispf.exe, jze2.exe, tmot.exe, fysq8.exe & bcka1zS9.exe. Usually there is two instances of these running in her task manager at the same time in any order. If you try to end any one of the processes it starts a new process using one of the names I've listed here and it continues to cycle through these names if you repeat this process. All of these programs indicate being used in the system32 folder on her User account but like I said before, it doesn't show up as being run from the current user in the registry.
Also if you search for any one of these .exe files other then the 3 I mentioned before being used by startup in the registry it doesn't find anything. Even though I think all of this stuff is related.
Doing a search of all of her files & folders through Windows turns up nothing on any of the .exe files either.
We have no clue what this could be. It kind of acts like a virus, but again, Norton didn't find anything. I was hoping that some of you out there might have an idea as to what this could be and how to deal with it because to me this seems like it could potentially be a larger problem then just taking focus away from IE.
Anywho, this is the problem. My sister has been noticing that when she uses IE (Yes, I know, she still uses it though), something else keeps stealing the focus away from it. Nothing pops-up or anything but all of a sudden the IE window becomes a background window even though nothing comes up infront of it.
I decided to run through different things to see what could potentially be causing this problem and the first thing that came to my mind was spyware or a virus. I opened her task manager up to look at the processes (WinXP Home btw) and we went through each process and came across several that I didn't recognize.
So, we did some research and google didn't return anything on the ones I was the most concerned about. I had her update Ad-Aware and run it, found some stuff but it didn't remove this problem. Had her update Spybot, ran it, found some stuff, didn't remove the problem. Updated Norton A/V and Norton turned up nothing as well.
This is where it gets interesting though. I told her to open her registry and go to HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
and inside there was an entry called "4M@ZD#F5KNNFGP" which of course didn't turn anything up in google. This is where the only instance of this item is found in the registry. This entry though leads to 3 executables in the Windows\System32 folder called Msyi62.exe, izi6.exe, & jifyvw.exe, not all at the same time though.
When you delete the string and reboot it replaces itself with one of these .exe files and cycles through each one if you repeat the process. It doesn't show up in HKEY_CURRENT_USER though. Same happens when you use msconfig to disable it from starting up, it creates another instance of itself and it is checked off again.
In the task manager there is gispf.exe, jze2.exe, tmot.exe, fysq8.exe & bcka1zS9.exe. Usually there is two instances of these running in her task manager at the same time in any order. If you try to end any one of the processes it starts a new process using one of the names I've listed here and it continues to cycle through these names if you repeat this process. All of these programs indicate being used in the system32 folder on her User account but like I said before, it doesn't show up as being run from the current user in the registry.
Also if you search for any one of these .exe files other then the 3 I mentioned before being used by startup in the registry it doesn't find anything. Even though I think all of this stuff is related.
Doing a search of all of her files & folders through Windows turns up nothing on any of the .exe files either.
We have no clue what this could be. It kind of acts like a virus, but again, Norton didn't find anything. I was hoping that some of you out there might have an idea as to what this could be and how to deal with it because to me this seems like it could potentially be a larger problem then just taking focus away from IE.