Techzonez    

Go Back   Techzonez > Software Support > Adware & Spyware

Adware & Spyware Think you may have an Adware or Spyware problem? Discuss it here.

Reply Post New Thread
 
Thread Tools Display Modes
Old March 14th, 2005, 19:57 PM   #1
Curio
Triple Platinum Member
 
Curio's Avatar
 
Join Date: Nov 2004
Location: London
Posts: 907
About Blank se.dll variant

I did my first se.dll computer today and it is a bit of a git.
se.dll is loaded by a combination of files that pretend to be something else - the information here is from my own experience then later looking around techy forums for other similar views (it's pointless beforehand because so many ppl post guesses or rubbish).

2 loaders
c:\windows\system\xxxx.dll (xs are random letters in my case 0mab.dll) This shows up as text and an html filter in HJT.
c:\recycled\qxxxxxx.exe (didn't write it down random letters - looked like it could be a MS update except it shouldn't be in there) some ppl report it as c:\qxxxxxxx.exe

1 resource file
c:\windows\temp\se.dll (temp folder depends on OS - this was in Win98)

Se.dll is held open as a sub-process of rundll32.exe - you should terminate this first using Process Explorer or Task Manager.

Use hijackthis to identify the res file and the loaders then use killbox to delete on reboot using the replace with dummy option (just in case) for all three files. Once rebooted run HJT again and delete the registry run key.
Easy when u know how but the loaders re-install the res file and each other so you can't get at it normally.

Telltale sign is in add/remove programs - entry 'Search Assistant' don't try using the uninstall feature it actually re-installs it - I tried that.

I hope this helps someone out there in the interweb world.
__________________
I'm using Windows 7 - you got a problem with that?

Last edited by Curio; March 15th, 2005 at 07:55 AM. Reason: left a bit out
Curio is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 03:17 AM.



Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright © Techzonez 2002-2009