| View previous topic :: View next topic |
| Author |
Message |
quietman7
1st Responder Mentor 1st Responder Mentor
 Joined: Sep 30, 2004 Posts: 3564 Location: Virginia, USA
|
Posted: Wed Apr 20, 2005 7:47 pm Post subject: Bolger.dll & Aurora.exe |
|
|
Bolger.dll & Aurora.exe
This new transponder variant includes a replacement to their buddy.exe called Bolger.dll. I have read in several security forums that they are foisting this variant being bundled by isearch and using CWS exploits sites to install in stealth.
Files installed with this variant include: Poller.exe, uacupg.exe, Nail.exe, thnall1ac.html, DrPMon.dll, svcproc.exe. The svcproc.exe does not like to be stopped without a court order. This deviant seems to be showing up everywhere in HijackThis logs around the security forum community.
As such I thought our members here might want to read up on this.
Read here: http://www.webhelper4u.com/index.html
DickT - Just the Facts
"THE BAD GUYS DON'T NEED A SEARCH WARRANT. ARE YOU PROTECTED?"
|
|
| Back to top |
|
 |
eXCeLeNCe
Sergeant

Joined: Apr 04, 2005 Posts: 108 Location: USA
|
Posted: Thu Apr 21, 2005 2:48 am Post subject: |
|
|
Hi,
From the research I have done here is what I found out:
Bolger.dll
This is a file that increases pop-ups on your computer. It seems as though it can be delete by Ad-Aware SE Personal, Spyware Blaster, or possibly Spybot Search and Destroy v1.3. Therefor I would suggest trying to run those files and see if it gets rid of them. If it does not, please post back and I can show you a way to do it manually.
Aurora.exe
This seems to be a legit file. This file was downloaded by someone using your computer. It does something with screensavers. I am thinking maybe it is a screen saver package that gives you additional screen savers. I went to the main site, and for the descripion of the file it said "Geometrical colour effects inspired by the northern lights." This led me to the fact that it is a single screen saver someone downloaded. But it seems legit.
Regards,
eXCeLeNCe _________________ Regards,
|
|
| Back to top |
|
 |
Oldfrog
Special Response Team
 Joined: Jun 27, 2004 Posts: 8575 Location: Deep in the Heart of Texas
|
Posted: Thu Apr 21, 2005 3:01 am Post subject: |
|
|
1) Spyware Blaster Will not remove anything as it is oot a scanning program.
2) Did you visit the link and see what Webhelper had to say about aurora.exe? If not,
| Quote: | Aurora.exe - This is their replacement to their buddy.exe that was created by the ceres.dll and speer.dll files.
CRC-32: 1BD15F16
MD5: F5CABEC2B069077EF90370E0EB92D13E |
_________________
MS MVP Security 2006-2008
|
|
| Back to top |
|
 |
Webhelper
Security Expert
 Joined: Apr 17, 2005 Posts: 729
|
Posted: Fri Apr 29, 2005 12:57 pm Post subject: |
|
|
| eXCeLeNCe wrote: | Hi,
From the research I have done here is what I found out:
Bolger.dll
This is a file that increases pop-ups on your computer. It seems as though it can be delete by Ad-Aware SE Personal, Spyware Blaster, or possibly Spybot Search and Destroy v1.3. Therefor I would suggest trying to run those files and see if it gets rid of them. If it does not, please post back and I can show you a way to do it manually.
Aurora.exe
This seems to be a legit file. This file was downloaded by someone using your computer. It does something with screensavers. I am thinking maybe it is a screen saver package that gives you additional screen savers. I went to the main site, and for the descripion of the file it said "Geometrical colour effects inspired by the northern lights." This led me to the fact that it is a single screen saver someone downloaded. But it seems legit.
Regards,
eXCeLeNCe |
The Aurora that is installed with the bolger.dll transponder BHO variant is a transponder file. Their methods is to use file names that are well known and in that way users will not know if it is good or bad.
The following are all the files that are used in the bolger.dll infestation
download.abetterinternet.com/download/UAC/Poller.exe
download.abetterinternet.com/download/UAC/uacupg.exe
download.abetterinternet.com/download/UAC/Nail.exe
download.abetterinternet.com/download/UAC/thnall1ac.html
download.abetterinternet.com/download/UAC/DrPMon.dll
download.abetterinternet.com/download/UAC/aurora.exe
download.abetterinternet.com/download/UAC/svcproc.exe
download.abetterinternet.com/download/UAC/thnall1a.html
aurora.exe is 212kb at this moment
MD5: 1F5CB7887DE415347034735CC05480BE
Properties of the file will show nothing.
The Nail.exe is the main reinfestational agent which also creates a random named exe file in the %indow% %system&% folder that is 74kb in size and the name in the properties will show: TODO. _________________ Wächter der Geschichten:
http://www.webhelper4u.com/thewatcher.html
|
|
| Back to top |
|
 |
quietman7
1st Responder Mentor 1st Responder Mentor
 Joined: Sep 30, 2004 Posts: 3564 Location: Virginia, USA
|
Posted: Fri Apr 29, 2005 1:45 pm Post subject: |
|
|
eXCeLeNCe said: | Quote: | | I would suggest trying to run those files and see if it gets rid of them. If it does not, please post back and I can show you a way to do it manually. |
I have not been infected by this. I was posting for informational purposes to others since the infection was spreading in various HJT forums.
|
|
| Back to top |
|
 |
XWAGON21
Cadet

 Joined: Apr 30, 2005 Posts: 3 Location: USA
|
Posted: Sat Apr 30, 2005 12:45 pm Post subject: Need help |
|
|
I'm not as computer sophisticated as other posters, but I am currently plagued by bolger.dll and aurora and don't know how to get rid of them (or if they are connected).
My virus scanner, avast, finds the bolger.dll virus every time I open a web browser. I "move to chest" each time, but it continually comes back. The result of the bolger.dll, I think, is that I am constantly getting pop-up windows with "Aurora" as the source.
Can anyone explain what I need to do to make this problem go away? Delete certain files? Anything???
Thanks.
One other simple question that probably everyone on this site can answer. When I do a virus scan, there are tens of thousands of temporary internet files that are scanned. When I go into My Computer to find those files and delete them, I can't see them. When I go to Internet Options and delete temporary files, that doesn't work either. I have 100,000 files on my computer - and it seems 60,000 are temporary internet files. How do I get rid of them - I certainly don't need them.
Thanks very much.
|
|
| Back to top |
|
 |
quietman7
1st Responder Mentor 1st Responder Mentor
 Joined: Sep 30, 2004 Posts: 3564 Location: Virginia, USA
|
|
| Back to top |
|
 |
XWAGON21
Cadet

 Joined: Apr 30, 2005 Posts: 3 Location: USA
|
Posted: Sun May 01, 2005 4:32 am Post subject: |
|
|
Thanks very much. I will do as you instruct.
|
|
| Back to top |
|
 |
|
|