ZeroPaid.com

  (#1) Old
JoeRocks Offline
Zeropaid Regular
JoeRocks Reputation is 0
 
Posts: 6
Join Date: Aug 2004
Reputation Power: 0
IadHide4.dll - August 14th, 2004, 03:43 PM

This jerk is stuck in my temp folder- it is incredibly stubborn to remove. I know a lot of people have picked this hijacker from File sharing. It is one of the more malicious ones out there.
I've run AdAware, SpyBot and HijackThis- but I can't identify it on Hijack's list. I've rebboted in Safe Mode to uninstall- no avail. I think HijackThis is my best bet-does anyone know how to identify it? The list is long, I dont want to remove the wrong item.
Anyone been here before?
Thanks for any help/suggestions.
   
Reply With Quote
  (#2) Old
CCSDUDE Offline
Proud Girl Lover
CCSDUDE Reputation is 2000CCSDUDE Reputation is 2000CCSDUDE Reputation is 2000CCSDUDE Reputation is 2000CCSDUDE Reputation is 2000CCSDUDE Reputation is 2000CCSDUDE Reputation is 2000CCSDUDE Reputation is 2000CCSDUDE Reputation is 2000CCSDUDE Reputation is 2000CCSDUDE Reputation is 2000
 
CCSDUDE's Avatar
 
Posts: 3,924
Join Date: Sep 2002
Location: Tomoyos Little Black Box
Reputation Power: 353
August 14th, 2004, 03:55 PM

Find a process monitor (hopefully with a terminate feature) or use WinXP Manager or SuperUtilites to find the exact dll and kill the son of a bitch off...ban it from loading up then delete it...


The only power tyrants have is the power relinquished to them by their victims. —Étienne de la Boétie
www.dakota-fanning.org
www.elle-fanning.net
   
Reply With Quote
  (#3) Old
Mels_Smileys45 Offline
SCHMOHAWK
Mels_Smileys45 Reputation is 2000Mels_Smileys45 Reputation is 2000Mels_Smileys45 Reputation is 2000Mels_Smileys45 Reputation is 2000Mels_Smileys45 Reputation is 2000Mels_Smileys45 Reputation is 2000Mels_Smileys45 Reputation is 2000Mels_Smileys45 Reputation is 2000Mels_Smileys45 Reputation is 2000Mels_Smileys45 Reputation is 2000Mels_Smileys45 Reputation is 2000
 
Mels_Smileys45's Avatar
 
Posts: 15,178
Join Date: Dec 2003
Location: Forman's Basement
Age: 87
Reputation Power: 1538
August 14th, 2004, 03:57 PM

This looks very similar to what caused me to lose everything on my hard drive a few weeks back. I was un installing it and eventually it took over everything. I checked always start in safe mode under system start up and it stopped windows from loading. Dont do this! I do not know how to get rid as it seems to attach to windows in a manner thats hard to identify. In your program logs is there a program called wasup or coolcash running? All I can say is be very careful and sorry I can't be of more help. If its the same hijacker its really very amazing.
   
Reply With Quote
  (#4) Old
MikeHunt Offline
Zeropaid Regular
MikeHunt Reputation 350MikeHunt Reputation 350MikeHunt Reputation 350MikeHunt Reputation 350MikeHunt Reputation 350
 
MikeHunt's Avatar
 
Posts: 835
Join Date: Apr 2002
Location: So. California
Reputation Power: 138
August 14th, 2004, 04:02 PM

a site with some tools to help... http://subratam.org/?page=removal


vx2finder is especially good.


warmest personal regards

Mike


Uncensored discussion board, post anything you like.
You can post anonymous (dot) .
No registration required!
BEST emoticons ever!
http://www.whofailedtoday.com/newbbs/viewforum.php?id=1
.
   
Reply With Quote
  (#5) Old
crackerjacker Offline
Banned
crackerjacker Reputation 450crackerjacker Reputation 450crackerjacker Reputation 450crackerjacker Reputation 450crackerjacker Reputation 450
 
Posts: 6,488
Join Date: Jan 2003
Location: p2pconsortium.com i live
Age: 75
Reputation Power: 0
August 14th, 2004, 04:12 PM

hmm read the information on pest patrols website, this may be the reason you are having problems. Read the information and then in the bottom it will tell you how to move it. hmm you might even wanna download a trial version of pest patrol to see if it can remove it. Either way read this site its good information. hmm
http://www.pestpatrol.com/PestInfo/B/Backweb.asp
 Send a message via ICQ to crackerjacker Send a message via AIM to crackerjacker Send a message via Yahoo to crackerjacker  
Reply With Quote
  (#6) Old
crackerjacker Offline
Banned
crackerjacker Reputation 450crackerjacker Reputation 450crackerjacker Reputation 450crackerjacker Reputation 450crackerjacker Reputation 450
 
Posts: 6,488
Join Date: Jan 2003
Location: p2pconsortium.com i live
Age: 75
Reputation Power: 0
August 14th, 2004, 04:15 PM

Quote:
Originally Posted by MikeHunt
a site with some tools to help... http://subratam.org/?page=removal


vx2finder is especially good.


warmest personal regards

Mike
hey mike that site looks good too.
 Send a message via ICQ to crackerjacker Send a message via AIM to crackerjacker Send a message via Yahoo to crackerjacker  
Reply With Quote
  (#7) Old
Mels_Smileys45 Offline
SCHMOHAWK
Mels_Smileys45 Reputation is 2000Mels_Smileys45 Reputation is 2000Mels_Smileys45 Reputation is 2000Mels_Smileys45 Reputation is 2000Mels_Smileys45 Reputation is 2000Mels_Smileys45 Reputation is 2000Mels_Smileys45 Reputation is 2000Mels_Smileys45 Reputation is 2000Mels_Smileys45 Reputation is 2000Mels_Smileys45 Reputation is 2000Mels_Smileys45 Reputation is 2000
 
Mels_Smileys45's Avatar
 
Posts: 15,178
Join Date: Dec 2003
Location: Forman's Basement
Age: 87
Reputation Power: 1538
August 14th, 2004, 04:29 PM

After reading up on this hijacker its nothing like what I came across.
   
Reply With Quote
  (#8) Old
JoeRocks Offline
Zeropaid Regular
JoeRocks Reputation is 0
 
Posts: 6
Join Date: Aug 2004
Reputation Power: 0
August 14th, 2004, 04:49 PM

THANK YOU, THANK YOU, I got my soul back! All help was useful and appreciated, but ... http://subratam.org/?page=removal did the trick.
I restarted and saw an AMAZING difference in my system, almost like new.....
   
Reply With Quote
  (#9) Old
crackerjacker Offline
Banned
crackerjacker Reputation 450crackerjacker Reputation 450crackerjacker Reputation 450crackerjacker Reputation 450crackerjacker Reputation 450
 
Posts: 6,488
Join Date: Jan 2003
Location: p2pconsortium.com i live
Age: 75
Reputation Power: 0
Red face August 14th, 2004, 05:10 PM

Quote:
Originally Posted by JoeRocks
THANK YOU, THANK YOU, I got my soul back! All help was useful and appreciated, but ... http://subratam.org/?page=removal did the trick.
I restarted and saw an AMAZING difference in my system, almost like new.....
Which removal tool did you use btw to resolve the problem that way we know for future ?
 Send a message via ICQ to crackerjacker Send a message via AIM to crackerjacker Send a message via Yahoo to crackerjacker  
Reply With Quote
  (#10) Old
JoeRocks Offline
Zeropaid Regular
JoeRocks Reputation is 0
 
Posts: 6
Join Date: Aug 2004
Reputation Power: 0
August 15th, 2004, 05:27 AM

Hijack This......ever other method removed it but it would show up again after a reboot
   
Reply With Quote
  (#11) Old
tm2livnlern Offline
Registered User
tm2livnlern Reputation is 0
 
Posts: 1
Join Date: Nov 2004
Reputation Power: 0
Remove Iadhide.dll - November 11th, 2004, 08:43 AM

This file is part of HP/Compaq's Backweb connection service. Kill this process: BACKWE~1.EXE then delete Iadhide.dll

If you open this file using notepad you can see it's origins written in plain english.
   
Reply With Quote
  (#12) Old
Michael O'Donnell Offline
Registered User
Michael O'Donnell Reputation is 0
 
Posts: 1
Join Date: Dec 2004
Reputation Power: 0
Cool IadHide4.dll - December 9th, 2004, 10:42 AM

Problem: IadHide4.dll
Name: BackWeb
Category: Downloader
Found By: Yahoo! Anti-Spy

Location:
C:\Documents and Settings\Administrator\Local Settings\Temp\IadHide4.dll

Process:
backWeb-8876480 [or similar process!]

Installed By:
Logitech Desktop Messenger [or other program!]

Description:
backWeb-8876480.exe [or similar process] is a process that comes with Logitech [and other corporations] products software.
It manages the automatic update check and provides the latest offers and products from Logitech [and other corporations].
This is a non-essential process; disabling or enabling it is a user preference.

Files:
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\6.1.4.68-8876480L\Program\backweb.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\6.1.4.68-8876480L\Program\backweb.tlb
C:\Program Files\Logitech\Desktop Messenger\8876480\6.1.4.68-8876480L\Program\IAdHide.dll

Solution:
Search For: backweb*.*, iadhide*.* [if necessary to locate other program!]
Uninstall: Logitech Desktop Messenger [or other program!]
Delete: IadHide4.dll

Comment: :santa
Harmless process widely used among corporations like Hewlett-Packard, Kodak, Logitech, etc.

More Info:
http://www.iamnotageek.com/a/iadhide4.dll.php . . . Scan page to "Removal Instructions:" & click "here" . . .

Be Aware: :cross
iamnotageek.com site is loaded with advertisements!

Last edited by Michael O'Donnell; December 13th, 2004 at 05:00 AM. Reason: Aesthetics
   
Reply With Quote
  (#13) Old
RACKnRAIL Offline
Gemacht Sie schauen
RACKnRAIL Reputation is 2000RACKnRAIL Reputation is 2000RACKnRAIL Reputation is 2000RACKnRAIL Reputation is 2000RACKnRAIL Reputation is 2000RACKnRAIL Reputation is 2000RACKnRAIL Reputation is 2000RACKnRAIL Reputation is 2000RACKnRAIL Reputation is 2000RACKnRAIL Reputation is 2000RACKnRAIL Reputation is 2000
 
RACKnRAIL's Avatar
 
Posts: 5,200
Join Date: Apr 2003
Location: an island in the pacific
Reputation Power: 855
December 9th, 2004, 11:23 AM

i didn't read all of the posts, but if no one mentioned, move on boot, it is also good for stubborn hard to remove folders, files, and so on. It was someone from here, ZP, that turned me onto this app. I haven't had a need for it in a long time, but it does work very well, for future reference. http://www.snapfiles.com/get/moveonboot.html


-----------®N®----------



Today's subliminal thought is:
   
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off




vBulletin Skin developed by: vBStyles.com