PDA

View Full Version : Manual Removal Guide for SpyArsenal.Watcher



Friday
2008-11-30, 00:02
The following instructions have been created to help you to get rid of "SpyArsenal.Watcher" manually.
Use this guide at your own risk; software should usually be better suited to remove malware, since it is able to look deeper.

If this guide was helpful to you, please consider donating towards this site (http://www.safer-networking.org/index.php?page=donate).

Threat Details:

Categories:
spyware

Description:
This software records pictures taken by the users webcam without his knowledge or consent.
Removal Instructions:

Installed Software List:

You can try to uninstall products with the names listed below; for items identified by other properties or to avoid malware getting active again on uninstallation, use Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) or RunAlyzer (http://www.safer-networking.org/index.php?page=runalyzer) to locate and get rid of these entries.

Products that have a key or property named "Digi-Watcher.com".

Files:

Please use Windows Explorer or another file manager of your choice to locate and delete these files.

The file at "<$PROGRAMS>\Digi-Watcher.com\Watcher 2.31\DGW to AVI converter.lnk".
The file at "<$PROGRAMS>\Digi-Watcher.com\Watcher 2.31\help documents.lnk".
The file at "<$PROGRAMS>\Digi-Watcher.com\Watcher 2.31\Run as NT Service.lnk".
The file at "<$PROGRAMS>\Digi-Watcher.com\Watcher 2.31\Uninstall Watcher.lnk".
The file at "<$PROGRAMS>\Digi-Watcher.com\Watcher 2.31\Watcher scheduler.lnk".
The file at "<$PROGRAMS>\Digi-Watcher.com\Watcher 2.31\Watcher.lnk".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\ASYCFILT.DLL".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Dgw2Avi.exe".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\index.html".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\keyhook.dll".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\LOG.INI".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\LogList.html".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\mask.ini".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Order.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Scheduler.exe".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\videolog.ini".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Watcher.exe".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\WatcherNTService.exe".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\WatcherService.exe".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Broadcasting\broadcast.html".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Broadcasting\broadcast.jpg".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Broadcasting\broadcast_origin.html".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\cap_disabled.jpg".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\cap_disabled_big.JPG".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\cap_main.jpg".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\cap_main_big.jpg".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\cap_over.jpg".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\cap_over_big.JPG".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\cap_selected.jpg".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\cap_selected_big.JPG".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\CAP_SKIN.INI".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\CAP_SKIN_BIG.INI".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\log_disabled.jpg".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\log_disabled_big.jpg".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\log_main.jpg".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\log_main_big.jpg".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\log_over.jpg".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\log_over_big.jpg".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\log_selected.jpg".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\log_selected_big.jpg".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\LOG_SKIN.INI".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\LOG_SKIN_big.INI".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\Mask.bmp".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo\Mask_big.bmp".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\avi.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\capture.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\faq.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\intro.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\log.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\multi_inst.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\multi-cam.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\quickstart-rv.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\quickstart-w.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\register.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\remoteview.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\schedule.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\settings_broadcast.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\settings_general.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\settings_listen.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\settings_manual.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\settings_monitor.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\settings_video.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\troubleshoot.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\Watcher.htm".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\advancedvideo.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\audio_setting.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\auto_start.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\aviconverter.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\broadcast_html.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\broadcast_local.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\broadcast_remote.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\broadcast_remote_ftp.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\capture_functions.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\creategroup.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\email_alert.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\ftp_alert.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\hidden_mode.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\listen_setting.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\log.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\log_options.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\motion_sensitivity.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\multi-install.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\order_watcher.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\other_alerts.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\play_fast_btn.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\register_location.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\rem_con_setting.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\remote_pwd.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\rvsave.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\schedule.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\scheduler.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\selectfolder.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\stop_logging.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\tips.h1.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\tips.h2.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\troubl2.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\video_frame_size.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\video_source.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\video_source_tn.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\video_src_fmt.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\videum4100.jpg".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image\web_server.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\images\blend.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\images\order_watcher.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\images\rule.gif".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\images\watcher_banner1.jpg".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\log\20020406224050.dgw".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\log\alert1.jpg".
The file at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\recorded\readme.txt".
The file at "<$DESKTOP>\Watcher.lnk".
Make sure you set your file manager to display hidden and system files. If SpyArsenal.Watcher uses rootkit technologies, use our RootAlyzer (http://forums.spybot.info/downloads.php?id=8) or our Total Commander anti-rootkit plugins (http://forums.spybot.info/downloads.php?id=3).
You will have to use a global search for files without a name specified. Be extra careful, because just the name might not be enough to identify files!

Important: There are more files that cannot be safely described in simple words. Please use Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) to remove them.

Folders:

Please use Windows Explorer or another file manager of your choice to locate and delete these folders.

The directory at "<$PROGRAMS>\Digi-Watcher.com".
The directory at "<$PROGRAMS>\Digi-Watcher.com\Watcher 2.31".
The directory at "<$PROGRAMFILES>\Digi-Watcher.com".
The directory at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31".
The directory at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Broadcasting".
The directory at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\Demo".
The directory at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help".
The directory at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\help\image".
The directory at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\images".
The directory at "<$PROGRAMFILES>\Digi-Watcher.com\Watcher 2.31\log".
Make sure you set your file manager to display hidden and system files. If SpyArsenal.Watcher uses rootkit technologies, use our RootAlyzer (http://forums.spybot.info/downloads.php?id=8) or our Total Commander anti-rootkit plugins (http://forums.spybot.info/downloads.php?id=3).
You will have to use a global search for files without a name specified. Be extra careful, because just the name might not be enough to identify folders!

Registry:

You can use regedit.exe (included in Windows) to locate and delete these registry entries.

Delete the registry key "Audiert" at "HKEY_USERS\.DEFAULT\Software\".
Delete the registry key "Audiert" at "HKEY_CURRENT_USER\Software\".
If SpyArsenal.Watcher uses rootkit technologies, use our RegAlyzer (http://www.safer-networking.org/index.php?page=regalyzer), RootAlyzer (http://forums.spybot.info/downloads.php?id=8) or our Total Commander anti-rootkit plugins (http://forums.spybot.info/downloads.php?id=3).

Final Words:

If neither Spybot-S&D nor self help did resolve the issue or you would prefer one on one help,
Please read these instructions (http://forums.spybot.info/showthread.php?t=288) before requesting assistance,
Then start your own thread in the Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22) where a volunteer analyst will advise you as soon as available.