New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 24)
· Marcia's (CO8)
· Bill G's (CO12)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 1155
Comments: 21
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

Security Task Manager v Module32.exe

 
Post new topic   Reply to topic       Computer Cops Forum Index -> Spyware Tools
View previous topic :: View next topic  
Author Message
muckto

Cadet
Cadet



Joined: May 29, 2004
Posts: 2
Location: USA

PostPosted: Mon May 31, 2004 2:40 am    Post subject: Security Task Manager v Module32.exe
Reply with quote

Hi all,

I had until yesterday a Trojan/Malware called module32.exe, not sure how I got that but it was there. It took me a while to locate so I wanted to document this for all users out there.

First, it would set my homepage to about:blank, then it would prevent me from copying and pasting into IE 6.0 SP1 - note other browsers eg Mozilla would work fine.

Thats how I guessed I was infected somehow eventhough I run firewall and real time anti virus.

I tried various software namely Spybot and a2 but nothing apart from harmless malware. Then I read about HijackThis but here again nothing too bad except for my start page set to about:blank.

Since my firewall and task manager would crash everytime I was starting my PC, I thought that I had to get to the bottom of the problem because not using IE anymore was not enough, there was something serious going on.

I discovered Security Task Manager, and I have to say that in 5 minutes, module32.exe was located on my HD and quarantined, easy! Its a payware, but I have to say that I will probably buy it because it is above the rest of the anti-spywares you can find on the web!

So if you boys and girls get these symptoms, here is the url for your fix:
http://www.neuber.com/taskmanager/

Good luck,
Jack Muckto
Back to top
View users profile Send private message
Mariner

Site Moderator
Site Moderator
Premium Member
Premium Member


Joined: Aug 25, 2003
Posts: 1904

PostPosted: Mon May 31, 2004 3:46 pm    Post subject:
Reply with quote

muckto,

I think you'll find that module32.exe is a keylogger and l don't see that resetting your homepage to A_B. A program such as SpyCop would detect a keylogger but not an A_B infection.

If you have a true About_Blank problem, no commercially available program on earth will remove that for you. That will require you to submit a HijackThis log and have an expert look at it for you.

muckto wrote:

I tried various software namely Spybot and a2 but nothing apart from harmless malware. Then I read about HijackThis but here again nothing too bad except for my start page set to about:blank.


If you would like expert opinion/attention re your A_B problem, please, feel free to submit your HJT log for our perusal. Your call.

To all others reading this, please, if you have an About_Blank problem, read the instructions in the Spyware - HijackThis Forum and then submit your log or, seek further advice re same from us here at CC. Thanks


Last edited by Mariner on Mon May 31, 2004 3:51 pm, edited 1 time in total
Back to top
View users profile Send private message
claire

Site Moderator
Site Moderator
Premium Member
Premium Member


Joined: Apr 21, 2002
Posts: 4857
Location: Belgium

PostPosted: Mon May 31, 2004 3:49 pm    Post subject:
Reply with quote

Hi,
I absolutely second Mariner on this issue

_________________
Carpe Diem
Back to top
View users profile Send private message
mbauer

Cadet
Cadet



Joined: Jun 24, 2004
Posts: 1
Location: Switzerland

PostPosted: Thu Jun 24, 2004 4:50 am    Post subject:
Reply with quote

Mariner wrote:
If you have a true About_Blank problem, no commercially available program on earth will remove that for you.


But the Security Task Manager solved muckto's problem. I tried Security Task Manager too and I'm very happy with it. If you have a dogged About_Blank problem, STM can help to find the cause.

PS: STM comes with a tool called SpyProtector that warns against browser hijacking activities.

Michael
Back to top
View users profile Send private message
Mariner

Site Moderator
Site Moderator
Premium Member
Premium Member


Joined: Aug 25, 2003
Posts: 1904

PostPosted: Fri Jun 25, 2004 9:15 am    Post subject:
Reply with quote

CRAP!!


muckto's problem solved (alledgedly) was a keylogger issue, not an A_B pproblem. An A_B problem will require specialised attention.

There is one hidden dll file, which is isolated by running other special utilities*, not a log. There is a visible dll file which you can see in the HJT log and this is also part of A_B. It was probably put there as a diversionary tactic. But this one is no problem to remove. The hidden one which is invisible, is hard to detect and even harder to remove. It is not visible in the HJT log, and has hidden, read-only attributes.

There is not one single version of this thing; there being different strains, all requiring one-on-one working by an expert.

*Note. "other special utilities" you simply will not find these contained within this program. And, they must be run in a special sequence as dictated by the variant and the advice of the expert working the case.

Say again, If you have a true About_Blank problem, no commercially available program on earth will remove that and that alone for you.

Course, you should not confuse an A_B problem with that of you having set your home page to "Blank" by yourself.

If this wonderous cure-all 'Security Task Manager'; did all that has been claimed by yourself and muckto, this and every other site would be out of business within the week, there being no more problems to solve and help to dish out, etc. We are still here, along with all the others........


Once more...To all others reading this, please, if you have an About_Blank problem, read the instructions in the Hijackthis - Spyware, Viruses, Worms, Trojans Oh My! Forum and then submit your log or, seek further advice re same from us here at CC. Thanks
Back to top
View users profile Send private message
negster22

1st Responder
1st Responder
Premium Member
Premium Member


Joined: Mar 10, 2004
Posts: 519
Location: USA

PostPosted: Fri Jun 25, 2004 9:40 pm    Post subject:
Reply with quote

Mariner and claire are correct. Mucko is mislead or confused. module32.exe bears not relationship to an About:blank infection. Removal and detection of this pest is at best semi-automated and at worst completely manual. To further complicate the issue, each individual case can be unique. Maybe mucko is just not aware of the intracacies involved in about:blank removal, but to suggest that Security Task Manager is a panacea for the real about:blank infection is highly suspect. I, for one do not believe it. No way, no how.
Back to top
View users profile Send private message Send email
negster22

1st Responder
1st Responder
Premium Member
Premium Member


Joined: Mar 10, 2004
Posts: 519
Location: USA

PostPosted: Sat Jun 26, 2004 10:43 am    Post subject:
Reply with quote

Quote:
But the Security Task Manager solved muckto's problem. I tried Security Task Manager too and I'm very happy with it. If you have a dogged About_Blank problem, STM can help to find the cause.


Problem with this statement is that muckto did not have a dogged About_Blank problem. He had an infected module32.exe. So his statement does nothing to glorify virtues of the of Security Task Mgr. in regard to that issue. It is based on erroneous information.

Quote:
STM comes with a tool called SpyProtector that warns against browser hijacking activities.


So does SpyGuard...and it's FREE!!
www.javacoolsoftware.com/sgdownload.html

Case closed.
Back to top
View users profile Send private message Send email
negster22

1st Responder
1st Responder
Premium Member
Premium Member


Joined: Mar 10, 2004
Posts: 519
Location: USA

PostPosted: Sat Jun 26, 2004 10:52 am    Post subject:
Reply with quote

Minor correction: SpywareGuard is the real-time browser protection program.
www.javacoolsoftware.com/sgdownload.html

Spyguard is a program that actually spies on people. Wouldn't want to recommmend that! Laughing

But the link is correct, all the same.
Back to top
View users profile Send private message Send email
Display posts from previous:   
Post new topic   Reply to topic       Computer Cops Forum Index -> Spyware Tools All times are GMT - 5 Hours
Page 1 of 1

 
 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops