Re: secure32.exe



check following registry keys on infected machine:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

is there any mention of your file ? (note registry value can have another
name, but path should include secure32).

Why can't you remove it from Task Manager ? Seems like module has it's
protection? Open this process in the Far and look at the list of modules it
uses.
Try to find "not-usual" dlls that are loaded it secure32.exe. More likely,
that secure32.exe extracts dll from it's resrouces and injects it somewhere,
after been injecting this dll may monitor system for occurences of
secure32.exe and if its absent(somebody terminated it) start it. If you will
find this "unusual dll" try to find it in all processes - if there are any
occurences in another processes, then most likely secure32 uses
SetWindowsHook to map it in all processes.
Try to find that dll (and remove) in
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify.

In addition to all that I wrote you may use ProcessExplorer from
www.sysinternals.com (it's free) to see what mutexes, events, threads
secure32.exe creates; and play with them. Most mailware creates protection
threads - a piece of code that monitors OS items to protect (registry,
processes, etc), so if you will terminate protection thread (if you will
find it) you will be able to remove it.

I usually perform these simple steps to remove mailware, and if I fail I
take debugger (SoftIce or OllyDbg, IDA pro) and begin debugging to make sure
how to remove that stuff from system.

--
Vladimir

"Michael Blanc" <mblanc@xxxxxxxx> wrote in message
news:fJydnb4gJ-MTgU3enZ2dnUVZ_sidnZ2d@xxxxxxxxxxxxxx
>I want *manual* instructions. Registry Keys, etc.
>
>
>
> David H. Lipman wrote in message ...
>>From: "Michael Blanc" <mblanc@xxxxxxxx>
>>
>>| I suspect that this binary is a parasite. I can't kill it in the Task
>>| Manager and don't know where to find it in the registry.
>>|
>>| I am having problems with the system - the computer keeps sending 100s
>>of
>>| Kbytes upon dial-up connection, and cannot even load a URL because of
> this
>>| degraded bandwidth.
>>|
>>| Am I right about this binary? If so, I will want to *manually* remove
>>it,
>>| hence need the instructions. (OS = Win2000, browser is IE5). Needless to
>>| say, I am using a different machine to post this.
>>|
>>| Thanks for any help!
>>|
>>| MB
>>|
>>
>>It is a Downloader Trojan so it may have associates that it has installed.
>>
>>Download MULTI_AV.EXE from the URL --
>>http://www.ik-cs.com/programs/virtools/Multi_AV.exe
>
> <snip>.....
>
>>
>>* * * Please report back your results * * *
>>
>>
>>
>>--
>>Dave
>>http://www.claymania.com/removal-trojan-adware.html
>>http://www.ik-cs.com/got-a-virus.htm
>>
>>
>
>


.



Relevant Pages

  • Problem with performance of IDE devices
    ... index 0, dll tcpstk.dll, context 0x3f8a5c9 ... 0x801abbe8: FSREG: Mounted ROM portion of boot registry ... 0x8014abcc: FSREG: Invalid HKEY 0x00000000 ...
    (microsoft.public.windowsce.platbuilder)
  • Re: HowTo: Unregister a DLL/Control when the File no longer Exists
    ... Tony Proctor wrote: ... recorded in the registry. ... However, matching them up without the original DLL ... The main project references one of the DLLs, ...
    (microsoft.public.vb.general.discussion)
  • Re: How do I load a third party driver in Windows CE 6.0
    ... I had a look at the link to the documentation you sent a link to and I ... I would get a dll to load. ... What do I have to do in the registry to get my dll to ... then myusbdevicedriver.dll will get loaded when I attach my USB device. ...
    (microsoft.public.windowsce.embedded)
  • Re: HowTo: Unregister a DLL/Control when the File no longer Exists
    ... projects, in the correct order, and deals with this exact situation Karl ... "registry bloat" by not cleaning the registry properly over a period ... The main project references one of the DLLs, ... another DLL. ...
    (microsoft.public.vb.general.discussion)
  • Re: VX2 - My Victory!
    ... I was having problem with an unknown VX2 spyware. ... it will call a DLL. ... >> I search the registry for these two files. ... I DID NOT RESTART THE COMPUTER. ...
    (microsoft.public.security.virus)