PDA

View Full Version : Three malware programs Spybot should detect



SpySentinel
2007-02-05, 03:03
Bewlow are names and descriptions of three malware that Spybot should detect and remove. TeaTimer should also block them:

1) MyNabyoo

Type: Surveillance Tool
Level: Elevated
Description: MyNabyoo secretly monitors PC activity. It can run silently and completely hidden from the task bar, system tray, process list, start menu, and add/remove programs section. It creates logs of all websites visited and secretly takes high-quality screenshots.

File Traces
%DESKTOPDIRECTORY%\ nabsetup.exe
%SYSTEM%\ FLTMN.DLL
%SYSTEM%\ Msnbios\ mnFilter.exe
%SYSTEM%\ Msnbios\ mynabyoo.exe


2) Trojan.Desktop

Category: Trojan
Level: Severe
Alias: TrojanDownloader:Win32/Small

File Traces
desktop.exe


3) Trojan.Desktop Hijack

Category: Adware
Level: Elevated
Description: hijacks the Internet Explorer home page and search page, installs a toolbar, and hijacks the desktop to display deceptive ads for rogue security products.

File Traces
%system%\ 1.02.04.dll
%system%\ gunist.exe
%system%\ param32.dll
%system%\ pop_up.dll
%SYSTEM%\ popup_bl.dll
%SYSTEM%\ searchdll.dll
%system%\ wldr.dll
%windows%\ 20040818\ mt.exe
%windows%\ 20040818\ popup_bl.dll
%windows%\ 20040818\ serch_hook.dll
%windows%\ inetdata\ winlogon.exe
%windows%\ onma.exe
%windows%\ sys016.exe
%windows%\ sys08.exe
%windows%\ sys4133.exe
%windows%\ sys4149.exe
%windows%\ sys4228.exe
%windows%\ sys4230.exe
%windows%\ uninstiu.exe
%windows%\ wold.exe
%windows%\ wspld.exe
bsw.exe
c:\ r.exe
c:\ wp.exe
dd.exe
demo.exe
dropper.exe
loader187.exe
mssys.exe
popup_bl.dll
services.exe
sys4920.exe
winlogon.exe
wp.exe

tashi
2007-02-05, 16:58
Hello.

As far as I know, MyNabyoo is a commercial parental control, do you have evidence it stealth installs or have files our detectives can take a look at?

If Spybot-S&D does not detect an item, please send the zipped file to: detections(AT)spybot.info (Replace AT with @)

Thanks. :)

SpySentinel
2007-02-08, 00:32
The following minus the MyNabyoo were found on my pc by CounterSpy v2 (Newest version), so the files are gone. But I did provide the traces found.