| View previous topic :: View next topic |
| Author |
Message |
bottlebrush
Cadet

 Joined: Dec 21, 2007 Posts: 8 Location: Australia
|
|
| Back to top |
|
 |
pykko
MIRT Hunter
 Joined: Jan 18, 2007 Posts: 736
|
Posted: Fri Dec 21, 2007 12:55 pm Post subject: samples |
|
|
Please attach the two files here in a password-protected archive with password: infected
Thank you! _________________ I want to know God's thoughts. The rest are details. - Albert Einstein
|
|
| Back to top |
|
 |
MysteryFCM
Sergeant

 Joined: Feb 07, 2007 Posts: 125 Location: Tyneside, UK
|
Posted: Fri Dec 21, 2007 4:52 pm Post subject: |
|
|
Might wanna de-linkify the OP's linky  _________________ Regards
Steven Burn
Ur I.T. Mate Group / hpHosts
it-mate.co.uk / hosts-file.net
|
|
| Back to top |
|
 |
tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5864
|
|
| Back to top |
|
 |
bottlebrush
Cadet

 Joined: Dec 21, 2007 Posts: 8 Location: Australia
|
Posted: Sat Dec 22, 2007 4:50 am Post subject: Re: samples |
|
|
| pykko wrote: | Please attach the two files here in a password-protected archive with password: infected
Thank you! |
Sorry for the delay---as I am new here--can you tell me how to add the zip file to my message/post please.
|
|
| Back to top |
|
 |
tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5864
|
|
| Back to top |
|
 |
bottlebrush
Cadet

 Joined: Dec 21, 2007 Posts: 8 Location: Australia
|
Posted: Sat Dec 22, 2007 9:57 pm Post subject: ZIP --PASSWORD PROTECTED SUBMITTED |
|
|
OK---Here's the 'corpolw.dll'
The other file,'tb10hbzt.exe' has completely disappeared from my computer.
|
|
| Back to top |
|
 |
tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5864
|
Posted: Sat Dec 22, 2007 11:47 pm Post subject: |
|
|
corpolw.dll is malware known as Trojan.Win32.BHO.agz (Kaspersky)
Once you have removed all the malware I suggest you install Windows XP Service Pack 2. You can download it from Microsofts website for free.
Once you have installed Service Pack 2, visit Windows Update using IE6 and install all the updates. _________________ Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.
Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
|
|
| Back to top |
|
 |
bottlebrush
Cadet

 Joined: Dec 21, 2007 Posts: 8 Location: Australia
|
Posted: Sun Dec 23, 2007 5:43 am Post subject: CORPOLW.DLL WILL NOT DELETE |
|
|
| tetak wrote: | corpolw.dll is malware known as Trojan.Win32.BHO.agz (Kaspersky)
Once you have removed all the malware I suggest you install Windows XP Service Pack 2. You can download it from Microsofts website for free.
Once you have installed Service Pack 2, visit Windows Update using IE6 and install all the updates. |
I have tried everything to remove this file with no success.
I followed the procedures in your article for 'Malware Removal'
---I ran 'CCleaner',ATF Cleaner,'Adaware',Spybot S&D,SuperantiSpyware,AVG Anti-spywareVundofix,VundoBegone,WinPfind,
SmitFraudfix.
SuperAntispyware was the only prog that found 'corpolw.dll' and some other registry entries--but could not delete them.
I ran progs in 'safe' mode---still no luck.
Ran 'KillBox','Unlocker',Emco Move on Boot','Emco Unlockit'---all unsuccessful!!!!---cannot unlock,read,move,replace with dummy or delete.
-looks like I might be doing a 'fresh' install
|
|
| Back to top |
|
 |
tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5864
|
|
| Back to top |
|
 |
bottlebrush
Cadet

 Joined: Dec 21, 2007 Posts: 8 Location: Australia
|
|
| Back to top |
|
 |
bdragomir
Cadet

 Joined: Dec 28, 2007 Posts: 1 Location: USA
|
Posted: Fri Dec 28, 2007 6:48 am Post subject: Re: CAN'T REMOVE UNKNOWN FILE--CORPOLW.DLL |
|
|
[quote="bottlebrush"]Hello,
I have found these two suspicious files on my computer in C:\WINDOWS\System32
corpolw.dll
tb10hbzt.exe
If you are sure that you know what you're doing you can reboot your machine using a linux live cd (e.g. knoppix) map your drive (if ntfs use ntfs -3g...) and delete the files that other might be locked by the Windows OS at bootup.
If you need any further help please let me know.
Regards,
Bogdan Dragomir
|
|
| Back to top |
|
 |
Cretem0nster
MIRT Hunter
 Joined: Jul 02, 2005 Posts: 121 Location: USA
|
Posted: Fri Dec 28, 2007 1:16 pm Post subject: |
|
|
bottlebrush if you wish to remove this malware without doing a fresh install,send me a private message and ill help you sort it out as quickly as possible.
|
|
| Back to top |
|
 |
bottlebrush
Cadet

 Joined: Dec 21, 2007 Posts: 8 Location: Australia
|
Posted: Sat Dec 29, 2007 9:34 am Post subject: fresh install |
|
|
| Cretem0nster wrote: | | bottlebrush if you wish to remove this malware without doing a fresh install,send me a private message and ill help you sort it out as quickly as possible. |
Thanks for your offer, but I will be doing a fresh install (it's time I did it anyway, and a lot of cleaning up)
|
|
| Back to top |
|
 |
|
|