Unknown problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by kneeland24, Feb 8, 2005.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! I'm familiar with WinVNC.

    You have a real bad as in there that has been very tuff to remove. The dddd.exe is what I'm referring to. Maybe we will get lucky.


    f you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = C:\WINDOWS\blank.htm
    O2 - BHO: (no name) - {B75F75B8-93F3-429D-FF34-660B206D897A} - C:\WINDOWS\system32\boln.dll
    O4 - HKLM\..\Run: [Windows Service] C:\WINDOWS\system32\dddd.exe

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\blank.htm
    C:\WINDOWS\system32\boln.dll
    C:\WINDOWS\system32\dddd.exe
    C:\WINDOWS\system32\soft.exe <--- just incase it is still around

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Tell me if you cannot find any of these or if you cannot delete them.


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  2. kneeland24

    kneeland24 Private E-2

    Hey I ran HJT fixed the things you told me to in normal mode, restarted in safe mode and then deleted the files you instructed to delete(C:\WINDOWS\system32\dddd.exe C:\WINDOWS\system32\soft.exe were not there) and restarted windows in normal mode. When it booted up it popped up an error that "boln.dll was not found" or something like that. Does that mean that there is still a key on my machine that instructs that file to run at startup?
     
  3. kneeland24

    kneeland24 Private E-2

    Also when running Adaware it always comes back with about 4 coolwebsearch files. For some reason I cannot turn on my automatic updates in the security center. Here's my new HJT log. The computer is running great I cannot thank you enough for the both of your help!
    Greg
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Your log is clean! Hope it stays like that.

    Do you get the message about "boln.dll was not found" everytime you boot?

    If so try this:

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\system32\boln.dll
    then click OK. If a dialog box confirming this action appears, click OK.
     
  5. TheOldThug

    TheOldThug First Sergeant


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds