Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Bho Helper That I Wanted To Share


  • Please log in to reply
2 replies to this topic

#1 Mussels

Mussels

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:11:43 PM

Posted 29 May 2008 - 10:47 AM

My system was infected with a BHO spyware that none of the main virus/spyware detectors could find. The infection only occurred when using the combination of Internet explorer and Google.

If i went to http://www.google.com, any keyword i submitted would come back with only advertisements, the page would mask itself to look like google, but would say either ctcfinder or pqsearch.org in the browser. It was designed so that all of the links to google still worked and as soon as i selected the next page option it would bring me to the real search results.

I used adaware, cwshredder, norton, kaspersky, spydoctor and fixwareout and none detected it or fixed it. I found out about hijack this and discovered the below information when the program ran.

O2 - BHO: BHelper Objects - {0BD8D6AE-A0BE-4CD2-9A7D-E440E33C3227} - C:\WINDOWS\system32\winndlc.dll

After removing it, i have had no other issues.

I just wanted to share in case anyone else was experiencing something similar. I am definitely not an expert and would recommend still posting so that some of the more experienced Bleepingcomputer users could help.

Take care

BC AdBot (Login to Remove)

 


#2 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 52,087 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:43 AM

Posted 29 May 2008 - 11:45 AM

Welcome to BC Mussels.

Thank you for sharing your experience with us.

Your advice for others to post for assistance from more experienced BC members is sound especially if using specialized tools to remove malware.

HijackThis is an advanced enumerator (similar in some respects to a registry editor) that is used to display certain areas of the Windows registry where the majority of malware reside. HijackThis will scan these areas of your system and then create a log to help diagnose the presence of undetected malware in known hiding places. Most of the log entries are required to run a computer and removing essential ones can potentially cause serious damage such as loss of Internet connectivity or problems with your operating system which could preventing it from starting. Using HijackThis requires advanced knowledge about the Windows Operating System and relies on trained experts to interpret the log entries in order to determine what needs to be fixed.

If you have future issues please don't hesitate to start a new topic in this forum and ask for assistance.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#3 DaChew

DaChew

    Visiting Alien


  • Members
  • 10,317 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:millenium falcon and rockytop
  • Local time:01:43 AM

Posted 29 May 2008 - 12:33 PM

http://www.castlecops.com/modules.php?name...ery=winndlc.dll

I really do like avira as a resident anti-virus program

Malwarebytes anti-malware and superantispyware might have picked it up, it seems awfully new tho

Wed, 28 May 2008

http://www.avira.com/en/threats/section/vd....00.04.107.html

I would not assume that that one entry in HJT was the only component tho
Chewy

No. Try not. Do... or do not. There is no try.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users