»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 09-01-2003, 12:50 AM   #1 (permalink)
Registered User
 
bhath19's Avatar
 
Join Date: Apr 2003
Posts: 144
bhath19 is on a distinguished road

I just noticed this file running in the background in XP. For the description of the file it says "hole". I already ran a scan on the computer to make sure it didn't have a virus and it didn't. Does anyone know what this file is and does?

bhath19 is offline   Reply With Quote
Old 09-01-2003, 01:19 AM   #2 (permalink)
Guest
Guest
 
Posts: n/a
Quote:
iedll.exe



With MUCH thanks to Rick from "The MacKinzie Family" (who sent me a copy of iedll.exe for examination) and Galen (aka KGIII and GotRoot etc) who took pity on me, decompiled the file and told me what it does........



Its a BHO ("browser helper object"), affecting Internet Explorer, that tries to write to the registry "..looks like a fragmented version of SearchBar.."



The problem: error message when starting Windows - " C:\windows\IEDLL.EXE\ file appears to be corrupt. Reinstall the file and try again."



Search engine/option hijackings:



global-finder.com (in the registry as out.true-counter.com/.../?344012)

searchalot.com

coolwebsearch (appearing in the registry as approvedlinks.com/hp.htm) (coolwebsearch is also mentioned HERE)


The cleanup: Use Task Manager (ctrl, alt, del) to make sure iedll.exe is not running. If it is, shut it down. Rename iedll.exe to iedll.old.



Export then delete the following registry keys:



HKCU\Software\Microsoft\Internet Explorer\SearchURL
HKCU\Software\Microsoft\Internet Explorer\Main\Search Bar
HKCU\Software\Microsoft\Internet Explorer\Main\Search Page
HKCU\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
HKCU\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
HKCU\Software\Microsoft\Internet Explorer\Search\SearchAssistant
HKCU\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
HKLM\Software\Microsoft\Internet Explorer\Main\Search Bar
HKCU\Software\Microsoft\Internet Explorer\Main\HomeOldSP
HKCU\Software\Microsoft\Internet Connection Wizard\Shellnext
HKLM\Software\Microsoft\Internet Connection Wizard\Shellnext



HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run [iedll] C:\WINDOWS\iedll.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run [loader] C:\WINDOWS\LOADER.EXE



NOTE: Loader.exe can be a legitimate Windows file. Do NOT delete or rename the file - just delete the entry above from the registry!!
From here
  Reply With Quote
Old 09-06-2003, 12:39 PM   #3 (permalink)
Registered User
 
Join Date: Sep 2003
Posts: 1
Kevin W is on a distinguished road
Thank you. Took me a while to figure out the directions (English Degree), but it seems to have taken care of the problem.
Kevin W is offline   Reply With Quote
Old 09-21-2003, 03:40 AM   #4 (permalink)
Registered User
 
Join Date: Sep 2003
Posts: 1
wuorange is on a distinguished road
Systems error window at boot up ... -- loader.exe

error window at boot up ...

can i do the same as with iedll.exe (this file also is started) ?!

or is there any other way to get rid of it?!
wuorange is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 3 (2 members and 1 guests)
hmoscikyvtm, huynwccnnup
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 09:40 PM.