help! rogue program running on boot

N

Nick

On boot I checked Task Manager to see one instance of IExplorer.exe
but nothing was in the Task Bar. I rebooted the computer to then see
two Internet Explorer's in the Task Manager Applications tab. Both
eventually displayed errors next to them -- 404 and server cannot be
found. I checked the Registry in HKLM and HKCU in
software\microsoft\windows\currentversion\run, but there was nothing
out of the ordinary. I searched for files modified over the last few
days and found c:\windows\system32\Kabapl32.exe and
c:\windows\system32\Gcamkaaj.dll both modifed at the same minute a few
days ago. The next minute there is a prefetch file to Windows Media
Player and then one for ctfmon.exe. There are no more files with close
modified times. I searched for kabapl32 and Gcamkaaj on google but
found nothing. I tried to delete both of them, but I get Access is
Denied. I updated and ran Ad-Aware and Spybot, but neither found
anything. I then ran my anti-virus Nod32 but that didn't find anything
either. After ending the Iexplorer.exe processes, I don't see anything
out of the ordinary in Task Manager Processes tab. Nothing in the
Start->Programs->Startup either. Any idea what it is? Any idea why I
couldn't see the Internet Explorer's in the Task Bar like every other
program? I am the only user on the machine (Admin).
 
N

Nick

Maybe some kind of spyware? It didn't set off ZoneAlarm as it is going
through IE but the only thing that I can see that it has done was to
lose the ability to search in the Address bar. I used to be able to
search using Google, now if I type in "test" and hit enter, after a
few seconds I just get "http:///? test". I went through Internet
Explorer's search customize again, but it didn't seem to help. Trend
Micro's online anti-virus program didn't find anything either.
 
N

Nick

Thanks Kelly.

I tried them all, to no avail. I did find Security Task Manager, which
showed that kabapl32.exe was running. I then logged on as another user
and was able to zip up the exe and dll and then delete the original
files. Booting back I seem to have no problems after using HiJackThis
to determine the URLSearchHook was missing.

I was starting to think it was a virus as it tried to connect to web
sites using hidden Internet Explorer windows when booting but neither
anti-virus program has yet to say that there is an infection.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top