Thread Starter
Jul 27, 2003
Hi there, yo guys have been helping me out last time. Many thanks for that. I was able to remove some trash by myself because of your nice tips. But somehow, I encountered a nasty one. It directs to a search engine called Sometimes, it just pops up. I can't remove it with CW shredder or Hijack this (it comes back all the time). Hopefully you guys can help me. Many thanks in advance!!

Logfile of HijackThis v1.97.7
Scan saved at 1:29:13, on 7-4-2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\Program Files\ICQLite\ICQLite.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\mockp.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\mockp.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\mockp.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\mockp.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\mockp.dll/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\mockp.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {50642A3F-8DEE-4FBB-BC50-F87573F6FBAC} - C:\WINDOWS\System32\mockp.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\downloaded program files\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\downloaded program files\googletoolbar1.dll
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LiveNote] livenote.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [brcxhdc] "C:\WINDOWS\System32\brcxhdc.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [rundl.exe] C:\WINDOWS\System32\rundl.exe
O4 - HKLM\..\RunServices: [rundl.exe] C:\WINDOWS\System32\rundl.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\RunServices: [rundl.exe] C:\WINDOWS\System32\rundl.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\windows\downloaded program files\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\windows\downloaded program files\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\windows\downloaded program files\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Ontvang alles met FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Ontvang met FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: Si&milar Pages - res://c:\windows\downloaded program files\GoogleToolbar1.dll/cmsimilar.html
O9 - Extra button: ICQ Lite (HKLM)
O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
O9 - Extra button: FlashGet (HKLM)
O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} -
O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{B2228053-328D-4BDF-8316-98BEBD6189DC}: NameServer =
Jul 26, 2002
CWShredder should remove this. First make sure you have the latest version. Open CWShredder and make sure you have version 1.55.0. If that is not the version you have click on the "Check for update" button and download the updated version and run it.


Thread Starter
Jul 27, 2003
Thanks for the fast reply. I have the lastest version (15.5 as you said). That's the strange thing, it can detect it, there are 6 internet pages restored and fixed (should be the first 6 things in my hijackthis log). But whenever I open a new IE Browser, it pops up again. Should reset me PC or something?
Jul 26, 2002
You have to restart your computer after running CWShredder. If you didn't do that you need to run CWShredder again and restart your computer. After you've done that if they're still there we will remove it manually.


Thread Starter
Jul 27, 2003
Okay, I did what you said. Closed all my browsers and ran it again. Then restarted my PC. It's still here! Can you tell me how to remove it manually? Thanks in advance. It's quite late now, if you can tell me the instructions to remove it, I will post the results later this day. Tnx a lot again!
Jul 26, 2002
First please do this:

Navigate to the C:\WINDOWS\system32 folder and locate the mockp.dll file. Right click it and choose "Send to compressed (zipped) folder". The zipped folder will appear there in the System32 folder. Now do the same with the C:\WINDOWS\System32\rundl.exe file. Attach copies of those zipped folders and send them to me here. Please include a link to this thread so I'll remember where they came from.

These files may be hidden so click on My Computer. Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and "Hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"

Run Hijack This again and put a check by these. Close all windows except HijackThis and click "Fix checked"

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\mockp.dll/sp.html (obfuscated)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\mockp.dll/sp.html (obfuscated)

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\mockp.dll/sp.html (obfuscated)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\mockp.dll/sp.html (obfuscated)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\mockp.dll/sp.html (obfuscated)

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\mockp.dll/sp.html (obfuscated)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank

O2 - BHO: (no name) - {50642A3F-8DEE-4FBB-BC50-F87573F6FBAC} - C:\WINDOWS\System32\mockp.dll

O4 - HKLM\..\Run: [brcxhdc] "C:\WINDOWS\System32\brcxhdc.exe"

O4 - HKLM\..\Run: [rundl.exe] C:\WINDOWS\System32\rundl.exe

O4 - HKLM\..\RunServices: [rundl.exe] C:\WINDOWS\System32\rundl.exe

O4 - HKCU\..\RunServices: [rundl.exe] C:\WINDOWS\System32\rundl.exe

O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) -

Restart to safe mode.

How to start your computer in safe mode

Now find and delete:

The C:\WINDOWS\System32\rundl.exe file
The C:\WINDOWS\System32\brcxhdc.exe file
The C:\WINDOWS\System32\mockp.dll file

IMPORTANT!: To help prevent this from happening again, I strongly recommend you install the patches for the vulnerabilities that this hijacker exploits.

The simplest way to make sure you have all the security patches is to go to Windows update and install all "Critical Updates and Service Packs"


Thread Starter
Jul 27, 2003
Hi hi there. I think everything worked, coz it doesn't pop up anymore. For now it's solved! Many thanks for that. Currently, I am installing the windows update packs. Tnx for the advice!
Jul 26, 2002
My pleasure! :)

Thanks for sending the files.

Check this out for info on how to tighten your security settings and some good free tools to help prevent this from happening again.

I'm closing this thread. If you need it reopened please PM me or one of the other mods.

Anyone else with a similar problem please start a "New Thread".
Jul 26, 2002
I reopened your thread since you posted in the other one and I believe you insinuated that CWS had returned.

There was another new version of CWShredder that was released this afternoon. Let's see if it will remove this. Open CWShredder and click on the "Check for update" button. Download and run the new version.


Thread Starter
Jul 27, 2003
Hi there flrman. As Khaom I tried everything. I downloaded PV, like you said in post #52, I have the log. Can you please tell me with files I should edit with killswitch? Thanks a lot.

Jul 26, 2002
I reopened this thread for you several days ago when I got your PM so you could continue this here. I have split your post off from khaom's thread and moved it here with your original thread. Please continue this here.
Jul 26, 2002
If you do not already have it Click here to download CWShredder. UnZip the file, but do not run it yet.

Now download TheKillbox from here:

Unzip the files to the folder of your choice.

Now go offline and Do Not go back online until these procedures are completed.

Double-click on Killbox.exe to run it. In the "Paste Full Path of File to Delete" box, copy and paste the following:


Don't click any of the buttons though, instead please click on the Action menu and choose "Delete on Reboot". On the next screen, click on the File menu and choose "Add File". The c:\windows\system32\resblkc.dll listing should show up in the window. If that's successful, choose the Action menu and select "Process and Reboot". You'll be prompted to restart, go ahead and restart.

Finally run CWShredder. Just click on the cwshredder.exe and then click "Fix" (Not "Scan only") and let it do it's thing.

When it is finished restart your computer.

When you're back in windows, check to see if there's any change in the search problem and report back. Please also post a new Hijack This log. along with a new runme.bat log.
