J
Jim Bunton
Guest
Windows media centre service pack 3
iexplorer v 7
Windows update will not run
Run services.msc
Check Background Intelligent Transfer Service running - OK
Check Event Log running - ok
Check Automatic Updates NOT running
Automatic Updates is disabled and it's start button is greyed out
Setting the combo to Automatic (or manual) it reverts to disabled
-----------
RECENT EVENTS - seems like some sort of malware
IeExplorer Home page began to default to MyWebHunt
When reset to normal home page on reboot reverted to MyWebHunt
---------------
Googled mywebhunt
--------
found:
http://www.threatexpert.com/report.aspx?uid=dd190d12-5574-4797-8d70-24b662a299ea
The following Registry Value was modified:. [HKEY_CURRENT_USER\Software\
Microsoft\Internet Explorer\Main]. Start Page = "http://www.mywebhunt.com"
....
reports the folowing registry modifications
a.. The following Registry Key was created:
a.. HKEY_LOCAL_MACHINE\SOFTWARE\GodLib
a.. The newly created Registry Values are:
a.. [HKEY_LOCAL_MACHINE\SOFTWARE\GodLib]
a.. FR = "1"
b.. BootDays = "23"
b.. [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
a.. NotifyDownloadComplete = "yes"
c.. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
a.. [filename of the sample #1 without extension] =
"%Windir%\[filename of the sample #1]"
so that [filename of the sample #1] runs every time Windows starts
a.. The following Registry Value was modified:
a.. [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
a.. Start Page = http://www.mywebhunt.com
---------
I HAVE DELETED
HKEY_LOCAL_MACHINE\SOFTWARE\GodLib
HKEY_LOCAL_MACHINE\SOFTWARE\GodLib]
a.. FR = "1"
b.. BootDays = "23"
in the entry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
a.. [filename of the sample #1 without extension] = "%Windir%\[filename of
the sample #1]"
I found a program named molocha.exe
AND a copy of it
in C:\Windows & Documents and Settings .. . \Temp
CREATED DATE today !!
Deleted the registry entry
"[filename of the sample #1 without extension] =
"%Windir%\[filename of the sample #1]" " for this file
AND, after reboot, renamed the C:\windows instance to Xmolocha.exe
AND deleted it from Documents and Settings\ . . \Temp
----------
This has stopped the hijack of the web browser to MyWebHunt
BUT Internet explorer is occassionally opening new instances with seemingly
random websites.
--- HELP! ---
iexplorer v 7
Windows update will not run
Run services.msc
Check Background Intelligent Transfer Service running - OK
Check Event Log running - ok
Check Automatic Updates NOT running
Automatic Updates is disabled and it's start button is greyed out
Setting the combo to Automatic (or manual) it reverts to disabled
-----------
RECENT EVENTS - seems like some sort of malware
IeExplorer Home page began to default to MyWebHunt
When reset to normal home page on reboot reverted to MyWebHunt
---------------
Googled mywebhunt
--------
found:
http://www.threatexpert.com/report.aspx?uid=dd190d12-5574-4797-8d70-24b662a299ea
The following Registry Value was modified:. [HKEY_CURRENT_USER\Software\
Microsoft\Internet Explorer\Main]. Start Page = "http://www.mywebhunt.com"
....
reports the folowing registry modifications
a.. The following Registry Key was created:
a.. HKEY_LOCAL_MACHINE\SOFTWARE\GodLib
a.. The newly created Registry Values are:
a.. [HKEY_LOCAL_MACHINE\SOFTWARE\GodLib]
a.. FR = "1"
b.. BootDays = "23"
b.. [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
a.. NotifyDownloadComplete = "yes"
c.. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
a.. [filename of the sample #1 without extension] =
"%Windir%\[filename of the sample #1]"
so that [filename of the sample #1] runs every time Windows starts
a.. The following Registry Value was modified:
a.. [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
a.. Start Page = http://www.mywebhunt.com
---------
I HAVE DELETED
HKEY_LOCAL_MACHINE\SOFTWARE\GodLib
HKEY_LOCAL_MACHINE\SOFTWARE\GodLib]
a.. FR = "1"
b.. BootDays = "23"
in the entry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
a.. [filename of the sample #1 without extension] = "%Windir%\[filename of
the sample #1]"
I found a program named molocha.exe
AND a copy of it
in C:\Windows & Documents and Settings .. . \Temp
CREATED DATE today !!
Deleted the registry entry
"[filename of the sample #1 without extension] =
"%Windir%\[filename of the sample #1]" " for this file
AND, after reboot, renamed the C:\windows instance to Xmolocha.exe
AND deleted it from Documents and Settings\ . . \Temp
----------
This has stopped the hijack of the web browser to MyWebHunt
BUT Internet explorer is occassionally opening new instances with seemingly
random websites.
--- HELP! ---