PDA

View Full Version : 007 Spy Software is Stronger Than Spybot



dj.turkmaster
2008-06-30, 22:12
A few days ago my friend told me that his msn chats were being saved by someone. So i went to his house to see what was going on. Found two important threats. The first one was amvo.exe which is a very popular problem in turkey nowadays. A lot of people com to our hjt forums for help whatever i fixed it with combofix and the second threat was 007 spy software.
I couldnt open spybot in normal mode so i used it in safe mode. even it detected 007 spy software in safe mode when i clicked on the fix button the computer hanged. i tried fixing it on system startup the same thing computer hanged again. After searching on the internet i learned to open the spy software with ctrl+alt+f7 and after i opened the program's interface there was an option in the program to avoid running anti-spyware programs like ad-aware, spybot and the option was selected. Because of this i couldn't run spybot in normal mode and i couldn't clean the spyware in safe mode or on system startup. Well there was an uninstall option in the program and i uninstalled it :) But i was really shocked because the program really protected itself against spybot. Spybot was so weak against the spy. I was disappointed alot. Because i have been using spybot for nearly 4 years without any problems. Also in our security forum www.doctus.org my signature is spybot's banner. :bigthumb:
I think Spybot should be able to protect itself against this kind of malware. İ can shut teatimer from the task manager but kaspersky, and spyware terminator doesn't let this and they protect themselves.

PepiMK
2008-06-30, 22:24
Hmmmm... 2.0 will have a the real on-access scanner running as a system service. We've been hesitant because this means no 9x/ME support, but at some point supporting them just isn't an option any more if it hinders new stuff.

A few things:
The hang didn't maybe appear because you tried beta 2?
Did you try the random-name variant of SpybotSD.exe in the Spybot folder? They're there for purposes when Spybot-S&D gets blocked or deleted by anything.
If you have any samples, you should probably mail detections@spybot.info so that one of our detectives might review it under this aspect. Since it seemed to at least find it, there at least belongs some detailed information on further steps into the products documentation. I noticed the detection to be over a year old, maybe the version you encountered is newer than the detected one.