HellzLittleSpy and Spybot 1.5.2
I have a client who has been be-deviled with HellzLittleSpy (pun intended :devil

. I've spent several hours reading posts in this and other fora...after re-building her registry twice :banghead: (remove hard drive, put it into another system, then remotely edit Software hive to restore userinit.exe setting in Winlogon (see previous posts)).
The commonest explanation for how the Winlogon loop happens is that something has crept into recent definition updates that has caused Spybot version 1.3 to find a false positive, then to do a bad thing to the registry :hair:. But despite there being multiple reports of this also happening with version 1.5.2, various bot-team members insist it shouldn't happen with that version.
So I may have an answer for this apparent problem. Here's what's taken place on my client's system: Originally, she had version 1.3 installed. Then, she updated to version 1.5.2
without first uninstalling 1.3. How do I know this?
Ran Spybot. Clicked on Help, About. Spybot dutifully reported that it was version 1.3. :crazy: Checked with client. "But I updated," she said. And, Add and Remove Programs agrees with her! Version 1.5.2 is what is listed in its record. Told A/RP to remove 1.5.2. It says it did, but it did it suspiciously quickly.
Started hunting. And, sure'nuff, there, in front of Ghod and everybody, sitting in the Start/Programs list, is Spybot Search and Destroy, together with its own uninstaller. Ran that and, taking longer this time, it removed SS&D
again. Kept hunting. Checked her hard drive — guess what? There's a big Spybot Search and Destroy folder with tons of sub-folders. Manually deleted them :cleaning:.
Checked her Registry. Finally, all mention of Spybot gone.
Next, installed 1.6 ('cause I'm still a believer


. Told it to download new files while installing, then checked Update once the install was finished to discover (you've no doubt been there) that there are still more files to download

:thud:. Re-immunized. Running 'bot-check even as we speak.........
And, lo the results are in...
Drumroll, please :band:............ :wav:
76 new problems found (the client found only 2 before frying her system again) and none of them is HellzLittleSpy. More importantly, none of the entries found by Spybot refers to the Winlogon section of HKEYLocalMachine/software...
So, it would appear that 1.6 is clean - still some wrinkles, but clean.
But I also think it's time to go through the various posts to clean 'em up. We know what causes the problem. We know how to fix it. Preventing users from using newer definitions, etc. for old SS&D versions is a start, but cleaning up the long list of posts and flames and turning this into a FAQ would also be kinda helpful. Maybe? You think?