CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer

Bolger.dll & Aurora.exe

 
Post new topic   Reply to topic       All -> FavForums -> Security [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
quietman7

1st Responder Mentor
1st Responder Mentor

Joined: Sep 30, 2004
Posts: 3564
Location: Virginia, USA
1st Responder Mentors 1st Responders MVP Premium Rootkit Experts Security Experts

PostPosted: Wed Apr 20, 2005 7:47 pm    Post subject: Bolger.dll & Aurora.exe
Reply with quote

Bolger.dll & Aurora.exe

This new transponder variant includes a replacement to their buddy.exe called Bolger.dll. I have read in several security forums that they are foisting this variant being bundled by isearch and using CWS exploits sites to install in stealth.

Files installed with this variant include: Poller.exe, uacupg.exe, Nail.exe, thnall1ac.html, DrPMon.dll, svcproc.exe. The svcproc.exe does not like to be stopped without a court order. This deviant seems to be showing up everywhere in HijackThis logs around the security forum community.

As such I thought our members here might want to read up on this.

Read here: http://www.webhelper4u.com/index.html

DickT - Just the Facts

"THE BAD GUYS DON'T NEED A SEARCH WARRANT. ARE YOU PROTECTED?"

Back to top
View users profile Send private message
eXCeLeNCe

Sergeant
Sergeant


Joined: Apr 04, 2005
Posts: 108
Location: USA
Team F@H

PostPosted: Thu Apr 21, 2005 2:48 am    Post subject:
Reply with quote

Hi,

From the research I have done here is what I found out:

Bolger.dll
This is a file that increases pop-ups on your computer. It seems as though it can be delete by Ad-Aware SE Personal, Spyware Blaster, or possibly Spybot Search and Destroy v1.3. Therefor I would suggest trying to run those files and see if it gets rid of them. If it does not, please post back and I can show you a way to do it manually.

Aurora.exe
This seems to be a legit file. This file was downloaded by someone using your computer. It does something with screensavers. I am thinking maybe it is a screen saver package that gives you additional screen savers. I went to the main site, and for the descripion of the file it said "Geometrical colour effects inspired by the northern lights." This led me to the fact that it is a single screen saver someone downloaded. But it seems legit.

Regards,
eXCeLeNCe


_________________
Regards,
image
Back to top
View users profile Send private message Send email AIM Address Yahoo Messenger MSN Messenger
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8575
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Thu Apr 21, 2005 3:01 am    Post subject:
Reply with quote

1) Spyware Blaster Will not remove anything as it is oot a scanning program.

2) Did you visit the link and see what Webhelper had to say about aurora.exe? If not,

Quote:
Aurora.exe - This is their replacement to their buddy.exe that was created by the ceres.dll and speer.dll files.

CRC-32: 1BD15F16
MD5: F5CABEC2B069077EF90370E0EB92D13E


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
Webhelper

Security Expert


Joined: Apr 17, 2005
Posts: 729

MVP Security Experts

PostPosted: Fri Apr 29, 2005 12:57 pm    Post subject:
Reply with quote

eXCeLeNCe wrote:
Hi,

From the research I have done here is what I found out:

Bolger.dll
This is a file that increases pop-ups on your computer. It seems as though it can be delete by Ad-Aware SE Personal, Spyware Blaster, or possibly Spybot Search and Destroy v1.3. Therefor I would suggest trying to run those files and see if it gets rid of them. If it does not, please post back and I can show you a way to do it manually.

Aurora.exe
This seems to be a legit file. This file was downloaded by someone using your computer. It does something with screensavers. I am thinking maybe it is a screen saver package that gives you additional screen savers. I went to the main site, and for the descripion of the file it said "Geometrical colour effects inspired by the northern lights." This led me to the fact that it is a single screen saver someone downloaded. But it seems legit.

Regards,
eXCeLeNCe


The Aurora that is installed with the bolger.dll transponder BHO variant is a transponder file. Their methods is to use file names that are well known and in that way users will not know if it is good or bad.

The following are all the files that are used in the bolger.dll infestation

download.abetterinternet.com/download/UAC/Poller.exe
download.abetterinternet.com/download/UAC/uacupg.exe
download.abetterinternet.com/download/UAC/Nail.exe
download.abetterinternet.com/download/UAC/thnall1ac.html
download.abetterinternet.com/download/UAC/DrPMon.dll
download.abetterinternet.com/download/UAC/aurora.exe
download.abetterinternet.com/download/UAC/svcproc.exe
download.abetterinternet.com/download/UAC/thnall1a.html

aurora.exe is 212kb at this moment
MD5: 1F5CB7887DE415347034735CC05480BE
Properties of the file will show nothing.

The Nail.exe is the main reinfestational agent which also creates a random named exe file in the %indow% %system&% folder that is 74kb in size and the name in the properties will show: TODO.


_________________
Wächter der Geschichten:
http://www.webhelper4u.com/thewatcher.html
Back to top
View users profile Send private message Visit posters website
quietman7

1st Responder Mentor
1st Responder Mentor

Joined: Sep 30, 2004
Posts: 3564
Location: Virginia, USA
1st Responder Mentors 1st Responders MVP Premium Rootkit Experts Security Experts

PostPosted: Fri Apr 29, 2005 1:45 pm    Post subject:
Reply with quote

eXCeLeNCe said:

Quote:
I would suggest trying to run those files and see if it gets rid of them. If it does not, please post back and I can show you a way to do it manually.

I have not been infected by this. I was posting for informational purposes to others since the infection was spreading in various HJT forums.

Back to top
View users profile Send private message
XWAGON21

Cadet
Cadet


Joined: Apr 30, 2005
Posts: 3
Location: USA

PostPosted: Sat Apr 30, 2005 12:45 pm    Post subject: Need help
Reply with quote

I'm not as computer sophisticated as other posters, but I am currently plagued by bolger.dll and aurora and don't know how to get rid of them (or if they are connected).

My virus scanner, avast, finds the bolger.dll virus every time I open a web browser. I "move to chest" each time, but it continually comes back. The result of the bolger.dll, I think, is that I am constantly getting pop-up windows with "Aurora" as the source.

Can anyone explain what I need to do to make this problem go away? Delete certain files? Anything???

Thanks.

One other simple question that probably everyone on this site can answer. When I do a virus scan, there are tens of thousands of temporary internet files that are scanned. When I go into My Computer to find those files and delete them, I can't see them. When I go to Internet Options and delete temporary files, that doesn't work either. I have 100,000 files on my computer - and it seems 60,000 are temporary internet files. How do I get rid of them - I certainly don't need them.

Thanks very much.

Back to top
View users profile Send private message
quietman7

1st Responder Mentor
1st Responder Mentor

Joined: Sep 30, 2004
Posts: 3564
Location: Virginia, USA
1st Responder Mentors 1st Responders MVP Premium Rootkit Experts Security Experts

PostPosted: Sat Apr 30, 2005 8:33 pm    Post subject:
Reply with quote

You cannot just delete these files. This infection is a bad one to fix even for the experts. Post a log in the Hijackthis Forum located here:
CastleCops Link/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html

Prior to posting that log, please read "Hijackthis Guidelines Read Before Posting" and follow all instructions. The link is here:
CastleCops Link/t102301-Hijackthis_Guidelines_Read_Before_Posting.html

As for your temp files, run Disk Cleanup and make sure all the boxes are checked first. Go to Start > Run and type: "cleanmgr" [without the quotes]. Let it scan your system for files to remove.

I also recommend that you download and install CCleaner from here: http://www.ccleaner.com/

1. Run CCleaner using it's default setting's.
2. A pop up box will appear advising this process will permanently delete files from your system.
3. Click OK and it will scan and clean your system.

DickT - Just the Facts

"THE BAD GUYS DON'T NEED A SEARCH WARRANT. ARE YOU PROTECTED?"

Back to top
View users profile Send private message
XWAGON21

Cadet
Cadet


Joined: Apr 30, 2005
Posts: 3
Location: USA

PostPosted: Sun May 01, 2005 4:32 am    Post subject:
Reply with quote

Thanks very much. I will do as you instruct.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Security All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer