My wifes computer after being infected with Win32:Trojano-803, and bullseye, kept getting repeat infections.
After removal of “ncase package.exe” and bulls eye, her
computer kept going to rogue sites and Trojano etc returned.
I have think I have solved the problem manually, but thought I would share the information as it does not appear to be documented anywhere I searched on the net…
admilliserv Hijack info
Delete in Regedit this control {98264495-6376-443C-9340-2996038BD143}(VaCtrl Class) and these files:
C:\WINDOWS\Downloaded Program Files\AdmilliServX.dll
C:\WINDOWS\System32\acledit7.exe
C:\WINDOWS\System32\igmprn.exe
You also need to delete the folder & contents of “admilli Service” under program files (Use dos or safemode)
The files are admillikeep.exe and admilliserv.exe
--------------------------------------------------------------------------------------------
REMOVED FOLLOWING REGISTRY ENTRIES :-
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/CDTInc/ie/bridge-c18.cab
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}]
"SystemComponent"=dword:00000000
"Installer"="MSICD"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}\DownloadInformation]
"CODEBASE"="http://static.windupdates.com/cab/CDTInc/ie/bridge-c18.cab"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}\InstalledVersion]
@="0,0,0,1"
"LastModified"="Thu, 23 Dec 2004 17:34:46 GMT"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}\Contains]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}\Contains\Files]
"C:\\WINDOWS\\Downloaded Program Files\\AdmilliServX.dll"=""
[HKEY_CLASSES_ROOT\CLSID\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}]
[HKEY_CLASSES_ROOT\CLSID\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}\InprocServer32]
@="C:\\WINDOWS\\DOWNLOADED PROGRAM FILES\\ADMILLISERVX.DLL"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}\Implemented Categories]
[HKEY_CLASSES_ROOT\CLSID\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}]
[HKEY_CLASSES_ROOT\CLSID\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}]
ALSO CREATES THE FOLLOWING:-
R3 - Default URLSearchHook is missing
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: Search Relevancy - {1D7E3B41-23CE-469B-BE1B-A64B877923E1} - C:\PROGRA~1\SEARCH~1\SEARCH~3.DLL
O1 - Hosts: 65.125.226.85 www.al4a.com
O1 - Hosts: 65.125.226.82 www.altavista.com
O1 - Hosts: 65.125.226.85 www.amplandmovies.com
01 - Hosts: 65.125.226.85 www.book-mark.net
O1 - Hosts: 65.125.226.85 www.call-kelly.com
O1 - Hosts: 65.125.226.85 www.easypic.com
O1 - Hosts: 65.125.226.82 www.gg.com
O1 - Hosts: 65.125.226.82 www.gmail.com
O1 - Hosts: 65.125.226.82 www.google.com
O1 - Hosts: 65.125.226.82 www.hotmail.com
O1 - Hosts: 65.125.226.82 www.icq.com
O1 - Hosts: 65.125.226.82 www.infospace.com
O1 - Hosts: 65.125.226.82 www.lycos.com
O1 - Hosts: 65.125.226.82 www.mail.com
O1 - Hosts: 65.125.226.85 www.mature-post.com
O1 - Hosts: 65.125.226.82 www.microsoft.com
O1 - Hosts: 207.68.172.246 www.msn.com
O1 - Hosts: 65.125.226.82 www.norton.com
O1 - Hosts: 65.125.226.85 www.sleazydream.com
O1 - Hosts: 65.125.226.85 www.thehun.com
O1 - Hosts: 65.125.226.85 www.worldsex.com
O1 - Hosts: 65.125.226.85 al4a.com
O1 - Hosts: 65.125.226.82 altavista.com
O1 - Hosts: 65.125.226.85 amplandmovies.com
01 - Hosts: 65.125.226.85 book-mark.net
O1 - Hosts: 65.125.226.85 call-kelly.com
O1 - Hosts: 65.125.226.85 easypic.com
O1 - Hosts: 65.125.226.82 gg.com
O1 - Hosts: 65.125.226.82 gmail.com
O1 - Hosts: 65.125.226.82 google.com
O1 - Hosts: 65.125.226.82 hotmail.com
O1 - Hosts: 65.125.226.82 icq.com
O1 - Hosts: 65.125.226.82 infospace.com
O1 - Hosts: 65.125.226.82 lycos.com
O1 - Hosts: 65.125.226.82 mail.com
O1 - Hosts: 65.125.226.85 mature-post.com
O1 - Hosts: 65.125.226.82 microsoft.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 65.125.226.82 norton.com
O1 - Hosts: 65.125.226.85 sleazydream.com
O1 - Hosts: 65.125.226.85 thehun.com
O1 - Hosts: 65.125.226.85 worldsex.com
The above appear to act as DNS poisoning - so if you enter URL for Hotmail you end up at 65.125.226.82
I think the problem originated from an active X on a site she had visited possibly may be one of the IP address in the list above; but did not want to risk reinfecting computer.
Hope this helps someone else.