• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

Commercially available worm program

  • Thread starter Thread starter KF
  • Start date Start date

KF

Golden Member
BlazingTools Keylogger

Now you too can have the pleasure of infecting your friends' computers with malware, and you don't have to find some obscure site on a hacked server to find out how, or hang out on IRC.

"Our keylogger has unique remote installation feature. You can attach keylogger to any other program and send it by e-mail to install on the remote PC in the stealth mode. Then it will send keystrokes, screenshots and websites visited to you by e-mail or FTP. You don't have to worry about the firewall alerts - now our keylogger can be invisible for the firewall program. Our keylogger supports remote installation, update and removal - no physical access required!"

Only $34.95. 🙂

But seriously folks...

I got rid of some file (I guess) that one of those spy/adware remover programs found and now I get an error box every time my main XP installation boots. The box title is: "BlazingTools Perfect Keylogger" and the error is:

"Error loading hook DLL". (no dot between hook and DLL.)

Sure, this is just annoying, but it could just as easily be destructive.

Searching the registry turns up no reference to BlazingTools. And the only references to "hook" are to seemingly legitimate sofware (like Microsoft C++). So where the heck is this dialog box coming from? How the heck do I get rid of it, or track it down? How can XP be loading up garbage on the computer, or attempting to, and there be no way to track it down? It is like somebody walking around your house leaving notes, and there is no trace of the person.

I am the only one that ever uses this computer and I have no reason to spy on myself, so I am mystified how this POS is (or was) on my computer. I did just recently get a worm attack, though, when I reinstalled XP and lost all my security updates. A couple of programs verify that I am now virus free.

My Internet search about this immediately turned up this BlazingTools company. What tha...???

Looks like BlazingTools also has a spy remover program. Hmm... you can understand I am just a little leery about trying it.


 
Somewhere there is a command to load this software. It's probably in the registry, but may not be, did you check win.ini, system.ini, autoexec.bat, config.sys, etc? It may be loading through another alias, so you may not find a reference to hook.dll in the registry. Also, hook is a generic term, I suspect the actual .dll referenced is named something else, you're just seeing an error message that deletes the actual name. This would explain the lack of a dot. (sneaky)

 
First find out which of your friends did this and kill them.

You might try some virus scanners, many will pick up trojans for you
 
Somewhere there is a command to load this software.

Well, maybe so, but it may be an internal dependency, and so what is happening is that the file that is hooked to cannot be found.

I think this is a case of "DLL hell." See if you can find a utility that scans your DLL's for problems.

 
Originally posted by: KF
BlazingTools Keylogger
[...]"Error loading hook DLL".

Keyloggers and such would run as services, normally... Did you check your service list? (services.msc) (edit🙂You may also try figuring out the "sc" command, since some services may be invisible to the GUI AFAIK.
 
there is a chance the program is being ran on boot via a registery entry, as you may (or may not know) most programs that run on boot are executed either via shortcut (*.lnk) located in one of your "Startup" folders (normally accessible via your start menu) or in the registery although i am unsure of the exact location. you could try to download and install magic tweak (www.magictweak.com) it has a function that allows you to disable/enable or delete entries set for programs to auto run on boot...maybe it is in one of the two locations. might help you find the traces of the progam or atleast what is being loaded so you can delete it or such
 
Check for a value under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows called AppInit_DLLs. Is anything listed there?
Bill
 
Thanks for all the replies. It might have been easy, except I already thought the obvious had been eliminated.

>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows called AppInit_DLLs
This didn't have anything there.

I did a file search looking for a file containing "Blazing", which didn't find anything.

I used the BlazingTools spy remover program, which they tout as being great because they know the ins-and-outs of spyware. It turned up a long list of what they called possibilities, all of which seemed legitimate. I didn't know what to do about that. I tried installing their spy program, and then uninstalling it. I thought it might remove the registry crap that caused this nuisance, but it didn't. Sometimes that method does undo screwy registry problems.

I got the tweaker suggested, and just turned off some of the programs in the RUN key, which are run when XP boots. As I mentioned, none of these seemed like they were the BlazingTools keylogger. But turning off mdll2.exe did the trick. It was located in the 'Program Files\Internet Explorer."

I see how this BlazingTools error notice started. The spyware scanners pointed out two other files in that directory (with similar looking names) as being spyware, so I deleted them. They must have been the "hooks."

Really, turning off the things in the Run key should have been one of the first things I did. Sometimes you need other people to get you back on track. Thanks again.

I only wish I knew what some of the other crap in the Run key is, and if I could get rid of it.
 
Back
Top