Sending out an SOS.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Blac_Slayer, Feb 2, 2005.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try this:

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\System32\boln.dll
    then click OK. If a dialog box confirming this action appears, click OK.

    Then fix the line in HJT. How does it look now? Did it go away? How about after a reboot?
     
  2. Blac_Slayer

    Blac_Slayer Private E-2

    Oh, yay me. After reboot with the cable plugged in, EVERYTHING came back. The temp folder, the isrvs folder, the boln.dll, EVERYTHING.

    *Sigh* ...I don't think we'll be able to find the cause of this. I'm getting thoughts of just going ahead and reformatting at this rate.

    Also, it seems as though my Avast! Resident Protections got diabled. I don't see them at the taskbar anymore. I didn't even disable them.
     
  3. cybermike

    cybermike Private E-2

    PestPatrol has a write-up - have a look here: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453090748 then read my trials.

    I fought the same battle for about 4 days! Exactly the same symptoms. I just kept plugging away at the command prompt and safe mode without network support. Finally after I found and removed the delprot items (now discussed at the web page above) along with its coherts, I rebooted to safe mode again. I killed spawned errant services, cleaned until the highjackthis reports were looking good, ran Trend AV, and let MS AntiSpyware reset IE settings. I then noticed several of the system ddl's and exe progams used by Windows XP did not appear to have the proper time/date stamps compared to the other Windows XP files (shell32.dll and explorer.exe among others). I quickly rebooted to a command prompt and did a DIR /OD (sort by date) on each of the WinXP primary system directories. Including \, \windows, \windows\system32, \windows\system among a few others. I then renamed executables, dll's, and subdirectories that were recent and had names that were not associated with Windows or the installed programs. They were rather obvious after all the time I had spent studying what was going on. I then booted to the WinXP SP2 CD and did an install/repair. This refreshed all of the Windows system files. The rest is history.

    Hope this helps...
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well much of what is at the Pest Patrol link is what we have been trying. But perhaps a combination of that plus what Cybermike found from first hand experience will also work for you Blac_Slayer. Take a look a the files in you folders sorted by date as he did and see what you find.
     
  5. Blac_Slayer

    Blac_Slayer Private E-2

    Well, I did as you asked, and it didn't come out pretty.

    I went on deleting things rather liberally, and ended up disabling my Word program and my Sygate Firewall, which I'm reinstalling right now. I also disable my Killbox, and I believe many more programs as well through this.

    I don't have a WinXP SP2 CD available.

    However, it did nothing. After going through the folders with a fine-toothed comb, the minute I was connected again, all the files stuck back on, and the dddd.exe file took a step inside my system32 folder instead of the usual documents and settings\owner folder.

    While looking in my add/remove programs in desperation, I found one selection which appeared to be my problem: "Best Search Engine!!!". That's what it was called. Upon trying to remove it that way, the uninstall stopped because it couldn't read from one file: boln.dll.

    So... I'd have to say this infestation has a name. Unless, of course, this has already been found out.

    Aslo, I recently just recleaned my computer of this thing, again, so if you want me to get re-infested to try something else out, just say the word. Its as easy as a simple reboot for me.

    EDIT: I take that back. My computer is re-re-infested without even a reboot. So, whats the next suggestion to pull?
     
  6. Blac_Slayer

    Blac_Slayer Private E-2

    Actually, I've been thinking (And after looking at Sygate Firewall some more)...

    Explorer.exe sends out a periodic send to admin2cash.biz. I think this is linked to the virus my explorer has on it, and since it can't be removed, the problem will continue to persist.

    By using Sygate, and blocking everything besides Mozilla, I've found the problem disappears. But if I do allow explorer.exe the ability to send messages agian, or reboot for that matter, when Sygate isn't up before explorer.exe can make its move, the problem comes back. Its just simple trial and error.

    ...I think the best way to fix this would be to re-format the hard-drive, unless there is a way to replace the explorer file.

    EDIT: Forgot to mention; After being infected once more, I tried removal through add/remove programs, but it did nothing, as I thought.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. QueenAngel

    QueenAngel Private E-2

    I had this very same thing. In searching for an answer this is the only thing I found on a google search so here I am.

    I read most of this thread- except the first few pages.....

    My AOL would not work- kept freezing. This started at the exact same time this virus appeared.
    Avast said my memory was infected.

    I had Avast force move the desktop.exe on start up since all of the problem files for me are write protected and I could do nothing with them.

    I also had a file called r.exe located at C:r.exe
    No matter what I did before nothing worked and this was one of the files that kept coming back.

    I overwrote that file in notepad, force moved the desktop.exe and all is well after a reboot. My AOL has even started working again and I was able to delete the entire isrvs folder with no problem.

    Now the only problem I have- I am missing a .dll file that I really need.
    msvcrt.dll how can I replace this? when I reboot I get a Windows explorer error and as soon as I click ok I will not be able to do anything until I replace this file.

    I do not have a windows disk or cd as windows came already installed in my computer. I am running Windows XP if that makes a difference.

    I am by no means a computer expert. And I can not guarantee that my problem is fixed. But it seems to be so far.

    Thank you guys for all the help- I have been trying to get rid of this bugger for a few days now.

    And I hope what I said can help someone else out.
     
  9. Blac_Slayer

    Blac_Slayer Private E-2

    Well, I know I need to replace my explorer file; Its just finding a replacement is whats difficult. I can't seem to find one.

    Got a suggestion as to where to find it?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you download the SP2 file to your PC? If you did and you have the network version, you may be able to extract it from there. We cannot give it to you here because that is illegal for us to do.

    Search you computer for other copies of explorer.exe and see if you can locate one that did not get infected. You original (before upgrade) may possible still exist in your c:\i386 folder. You can also get this from your original boot CD. But it will not be the SP2 version.
     
  11. questra25

    questra25 Private E-2

    Have you tried using a p2p like dc++ to retrieve files you might need....just a thought.
    I had something like that ...and I used avg to delete it ..nothing else would look at it..
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is illegal! Please do not discuss illegal things on MGs!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The proper solution is this and it can still be done even from the command prompt (assuming you delete all the current infected explorer.exe copies.


    Run c:\program files\internet explorer\iexplore.exe

    and go here to download the Network Version of SP2 from Microsoft:
    http://www.microsoft.com/downloads/details.aspx?FamilyID=049c9dbe-3b8e-4f30-8245-9e368d3cdb5a&DisplayLang=en

    Note: the above file is 272Mb in size, so I hope you have a fast connection.

    Now continue with the below while disconnected from the Internet.

    Then use WinZip, WinRar or similar to view the files in that executable. Extract explore.ex_ from the SP2 file. I would first extract it to a folder not related to Windows (create your own - like c:\myexpfix). It is compressed, so you will need to use Microsoft's expand progam to expand it. Here's how, assuming you did the above already.

    From the command prompt:
    cd c:\myexpfix
    expand explorer.ex_ explorer.exe

    Now assuming you have already gotten rid of the soft.exe trojan, from the command prompt:
    copy explorer.exe c:\windows
    cd c:\windows
    explorer

    That should start up the explorer shell with the new uninfected copy.
    Try rebooting and let's see what happens.

    Obviously it is important that you have already remove the infected versions and the soft.exe file that began this.
     
  14. Blac_Slayer

    Blac_Slayer Private E-2

    I followed everything you said, and I tried rebooting into normal mode with the cable in.

    ...It seems normal. I'm gonna go ahead and try rebooting a couple more times, and checking certain registry keys for any changes. I'll give you final results soon.
     
  15. Blac_Slayer

    Blac_Slayer Private E-2

    ...I'm going to hazard a guess... and say that... I'm finally fixed.

    I don't see any more adware popping up after replacement, and I gained control of my Windows Firewall once more (And its disabled now, thankfully), and I have Avast! and Sygate now, both under strict protection, along with Spybot, Ad-aware, and SpywareBlaster. My registry is unchanged, and no files are re-appearing in my system folder. In fact, nothing is coming back.

    Everything is back to normal!

    I can't give you enough thanks for all the help you've given me thus far. In fact, its six pages worth of help! I'm surprised you still kept trying to help me, despite how half-***ed I was toward you.

    This problem was very difficult to finish, and I'm just happy its finally over. If you can find a use for this thread, and make something out of it to help other people with the same problem as me, then that would be downright amazing.

    Thank you, Chaslang. Thank you!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome! I hope it remains clean! I would recommend posting a HJT log just to check things out.

    Did you find that soft.exe file and get it deleted? And all the other copies of explorer.exe that it infected too.
     
  17. Blac_Slayer

    Blac_Slayer Private E-2

    (Final!) HJT log posted.

    Yes, the soft.exe has been deleted, and everything is truly back to normal. I still can't thank you enough for how much you've helped me!
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! I'm glad to see we got this all fixed up. You had a combination of a bunch of nasties! And now your log is clean.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds