Advertisement

04.16.2008 at 09:16AM PDT, ID: 23327820
[x]
Attachment Details

Help with AutoSpySpider infection. Single DLL remains.

Asked by rubiconx in Spyware / Ad Blockers, Networking Security Vulnerabilities, Windows XP Operating System

Tags: AntiSpySpider, Spyware, Trying to work out the DLL that Rundll32 is attached to...maybe

One of my clients has been infected with the AntiSpySpider Rogue software on an XP Pro PC.  Unfortunately, before I was called in they tried to remove it themselves. The end result is that all of the program has been removed bar one item.  I believe the item is a DLL.  I'm not (usually) stupid and I have tried running various scans and diagnostics, but I can't identify the file.  The only clue I have is that when I view the task manager there is a process running called RUNDLL32 (yes I know what this is for but it doesn't normally show up in the task manager).  When the computer is initially booted, after a few minutes the Rogue software kicks in and starts displaying the AntiSpySpider webpage.  As time goes by this page is displayed more and more frequently.  However, if I kill the RUNDLL32 task then the pages stop displaying until the next reboot.

Obviously, there is a DLL being run somewhere but I can't find it!

So, my questions are...
1) Does anyone know what this DLL is and where I am likely to find it? (No there are no references to AntiSpySpider anywhere on the PC now)
2) Is there a process or utility that allows me to see what DLL the RUNDLL32 process is tied to?

Thanks in advance...Start Free Trial
[+][-]04.16.2008 at 09:23AM PDT, ID: 21369489

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.16.2008 at 09:27AM PDT, ID: 21369531

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.16.2008 at 09:53AM PDT, ID: 21369784

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.16.2008 at 01:27PM PDT, ID: 21371666

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Spyware / Ad Blockers, Networking Security Vulnerabilities, Windows XP Operating System
Tags: AntiSpySpider, Spyware, Trying to work out the DLL that Rundll32 is attached to...maybe
Sign Up Now!
Solution Provided By: Jonvee
Participating Experts: 3
Solution Grade: A
 
 
[+][-]04.17.2008 at 12:07AM PDT, ID: 21374786

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628