Possible infection with kll32.dll and

From: Sharon (torgo7_at_comcast.net)
Date: 07/07/04


Date: 7 Jul 2004 07:35:38 -0700

I have decided to put these 2 problems in one message, since they are
related.

On Microsoft.com, I followed the link to check for kk32.dll and
surf.dat Although I consistently check my PC daily for
malware/spyware/adware/ a search did turn up kk32.dll and shows surf
and describes it as a DAT file. What is scary is that when I open the
kk32.dll, it contains info, including my VISA card info, that I used
when I purchased merchandise from an online store. The surf dat shows
so many entries it is impossible to begin to list them, but also
include some online stores as well.

Problem: When I open the update patch page with IE, it freezes and
can only be removed through the End Task option. In other words, it
won't let me download the patch. However:

We are also running AOL. There appears to be no problem with the
patch download page, although I have not as yet tried the actual
download process.

I was wondering if some malware is preventing the download on I.E.

Also, I found this today which seems to indicate that the source for
kk32 has been found (in Russia, not a surprise) and the server
disabled. (dated 6/25/04)

"The attack, which had turned some Web sites into points of digital
infection, was nipped in the bud Friday, when Internet engineers
managed to shut down a Russian server that had been the source of
malicious code. Compromised Web sites are still attempting to infect
Web surfers' PCs by referring them to the server in Russia, but that
computer can no longer be reached."
SMD @ 3:40 PM | Receptors (0) | Trackback (0)

My Questions: Why does the Microsoft Patch page freeze on I.E. but
appears OK on AOL?

I am running Spybot, X-Cleaner, AVAST and Norton Anti-virus (both
programs picked up on viruses the other did not).

My system: Windows 98 Second Edition
            I.E. 6.0

As I realize this could be a very serious issue, I would appreciate
any comments/suggestions. I sincerely hope it is true about kk32,
which means that threat is nullified, though almost certainly similar
ones will (and probably do) exist.

Hope I made myself clear. My communication skills are not the best due
to a physical problem.
A good day to all...



Relevant Pages

  • Re: Is MSIE dead as a browser - if Microsoft does not patch it then it is as far as I am concerned!
    ... > infected web sites, and altered the web server configuration to append the ... > files served by the web server. ... > method used to compromise the servers. ... > it - and does not even bother to patch it when the flaw is discovered! ...
    (microsoft.public.security.virus)
  • Re: EXCHANGE2000-KB928225x86-ENU.exe Re: Exchange 2000 DST 2007 CDO patch options
    ... I think we are going to skip the patch. ... so other like you & me can download in ... I hesitate to install this patch on our production server. ... I downloaded the Exchange 2000 hotfix for Exchange 2000 DST ...
    (microsoft.public.exchange2000.admin)
  • Re: uninstall
    ... download the patch with out 1st downloading the service pack. ... You can download and install it from The Major Geeks. ... > I would suggest searching for ' SQL Server version number' as your search ...
    (microsoft.public.windowsxp.general)
  • RE: MS Connector for POP3
    ... >>I have about 10 accounts set up to download via the pop ... >>server is a lesser version, ... >replace the file manually if the patch is not overwriting ...
    (microsoft.public.windows.server.sbs)
  • RE: MS Connector for POP3
    ... >server is a lesser version, ... >Event Source: POP3 Connector ... >Event Category: Download ... You can run the patch with a -x switch to extract the files and then ...
    (microsoft.public.windows.server.sbs)