C:\WINDOWS\secure32.html

C:\WINDOWS\secure32.html

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
C:\WINDOWS\secure32.html fsw 10-16-2005
Posted by fsw on October 16, 2005, 6:05 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,
the other night my son downloaded "something" that caused a few
problems.....
Since then I`ve run AVG, Ad aware and Spybot R & D - to clean up most
things, however one thing remains...

The Internet explorer home page has been set to C:\WINDOWS\secure32.html.
which seemed to prevent the browser from doing anything - except going to
where the page wanted you to go to - so I deleted it and this allows us to
go to other websites normally, however no matter how I try I cannot reset
the Home page away from C:\WINDOWS\secure32.html.

Looking in the Windows directory around the time of the above software
download I notice these suspicious files:-
dodrrr.exe
tool4.exe

Any advice on how to get my home page setup again and does anyone know what
these files are?

Thanks
F



Posted by David H. Lipman on October 16, 2005, 8:55 am
If you were  Registered and logged in, you could reply and use other advanced thread options

| Hello,
| the other night my son downloaded "something" that caused a few
| problems.....
| Since then I`ve run AVG, Ad aware and Spybot R & D - to clean up most
| things, however one thing remains...
|
| The Internet explorer home page has been set to C:\WINDOWS\secure32.html.
| which seemed to prevent the browser from doing anything - except going to
| where the page wanted you to go to - so I deleted it and this allows us to
| go to other websites normally, however no matter how I try I cannot reset
| the Home page away from C:\WINDOWS\secure32.html.
|
| Looking in the Windows directory around the time of the above software
| download I notice these suspicious files:-
| dodrrr.exe
| tool4.exe
|
| Any advice on how to get my home page setup again and does anyone know what
| these files are?
|
| Thanks
| F
|



I hope that was Ad-aware SE v1.06 and SpyBot S&D v1.4 !

I suggest downloading, installing and updating BHODemon for any Browser Helper
Objects
that may be on the PC.

BHODemon
http://www.definitivesolutions.com/bhodemon.htm

Please submit dodrrr.exe & tool4.exe to Virus Total --
http://www.virustotal.com/flash/index_en.html
The submissions will then be tested against many different AV vendor's scanners.
That will give you an idea what it is and who recognizes it. In addition,
unless told
otherwise, Virus Total will provide the sample to all participating vendors.

When you get the report, please post back the exact results.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Nick Skrepetos \(SuperAdBlocke on October 16, 2005, 4:32 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,

If you would like to .ZIP and e-mail me those files, I would be happy
analyze them and their contents for free and report the findings back to the
group.

You may also wish to try the free scan/view of what's running on your PC
here it may reveal what those are if we have previously identified the files
(most likley by MD5/FingerPrint as they appear randomly named):
http://www.fileresearchcenter.com

You may also wish to try Super Ad Blocker with SUPERAntiSpyware:
http://www.superadblocker.com

If that does not find the spware/adware on your machine, you can submit a
diagnositc and I will diagnose your machine for free and post the results
back to the group and update our rules with anything found:
http://www.superadblocker.com/diagnostic.html?id=nicks

Nick Skrepetos
SuperAdBlocker.com - SUPERAntiSpyware
http://www.superadblocker.com


> Hello,
> the other night my son downloaded "something" that caused a few
> problems.....
> Since then I`ve run AVG, Ad aware and Spybot R & D - to clean up most
> things, however one thing remains...
>
> The Internet explorer home page has been set to C:\WINDOWS\secure32.html.
> which seemed to prevent the browser from doing anything - except going to
> where the page wanted you to go to - so I deleted it and this allows us to
> go to other websites normally, however no matter how I try I cannot reset
> the Home page away from C:\WINDOWS\secure32.html.
>
> Looking in the Windows directory around the time of the above software
> download I notice these suspicious files:-
> dodrrr.exe
> tool4.exe
>
> Any advice on how to get my home page setup again and does anyone know
what
> these files are?
>
> Thanks
> F
>
>



Posted by FSW on October 19, 2005, 3:02 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,
thanks for your offers of help - Unfortunately I deleted the files so cannot
send them for analysis.

I'm using another machine to post this as the problem machine ---- has
problems that make it unusable, here is a list of my observations - which
hopefully help idnetify what has happened:-
- I downloaded the BHO demon software, but found that this would not work
properly and failed.
- no matter what application I start it consumes 100% of the CPU for a long
time - without the application actually doing anything
- I notice this even when I run the command window and do a "Ping".
- the ping process consume 100% CPU for about 5 - 10 minutes, then does the
ping and repoprts back good Round trip responses to a few test web
addresses.
- I noticed that around the time of the software download , the Windows
firewall stopped and dumped a log.
- The Windows Firewall no longer works
- I downloaded Zone Alarm and find it doesn't respond - againg CPU shows
100% loading for the Zone Alarm application process.

AS said in earlier post
I ran AVG, Ad Aware and Spybot R & D whis spotted and immunized quite a few
things but I'm left with this/these problems

Appreciate any suggestions to get the machine back working again.

Thanks
Frase

> Hello,
>
> If you would like to .ZIP and e-mail me those files, I would be happy
> analyze them and their contents for free and report the findings back to
> the
> group.
>
> You may also wish to try the free scan/view of what's running on your PC
> here it may reveal what those are if we have previously identified the
> files
> (most likley by MD5/FingerPrint as they appear randomly named):
> http://www.fileresearchcenter.com
>
> You may also wish to try Super Ad Blocker with SUPERAntiSpyware:
> http://www.superadblocker.com
>
> If that does not find the spware/adware on your machine, you can submit a
> diagnositc and I will diagnose your machine for free and post the results
> back to the group and update our rules with anything found:
> http://www.superadblocker.com/diagnostic.html?id=nicks
>
> Nick Skrepetos
> SuperAdBlocker.com - SUPERAntiSpyware
> http://www.superadblocker.com
>
>
>> Hello,
>> the other night my son downloaded "something" that caused a few
>> problems.....
>> Since then I`ve run AVG, Ad aware and Spybot R & D - to clean up most
>> things, however one thing remains...
>>
>> The Internet explorer home page has been set to C:\WINDOWS\secure32.html.
>> which seemed to prevent the browser from doing anything - except going to
>> where the page wanted you to go to - so I deleted it and this allows us
>> to
>> go to other websites normally, however no matter how I try I cannot reset
>> the Home page away from C:\WINDOWS\secure32.html.
>>
>> Looking in the Windows directory around the time of the above software
>> download I notice these suspicious files:-
>> dodrrr.exe
>> tool4.exe
>>
>> Any advice on how to get my home page setup again and does anyone know
> what
>> these files are?
>>
>> Thanks
>> F
>>
>>
>
>



Similar ThreadsPosted
HTML.ObjectDataHTA January 4, 2006, 2:35 am
Trojan-Spy.HTML.Fraud.gen May 14, 2008, 2:02 pm
Trojan-Spy.HTML.Fraud.gen August 8, 2008, 12:55 pm
HTML/scripted.gen virus August 16, 2008, 8:31 pm
IE home pg stuck as msblank.html October 17, 2005, 8:46 pm
Pagefile.sys infected by HTML.PHishing.Pay-131 August 31, 2006, 9:12 am
Lost HTML for Running Active Desktop July 31, 2005, 7:20 pm
Exploit.HTML.IFrame reported as virus in email December 29, 2005, 12:55 pm

The site map in XML format XML site map

Contact Us | Privacy Policy