CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

CAN'T REMOVE UNKNOWN FILE--CORPOLW.DLL

 
Post new topic   Reply to topic       All -> FavForums -> Unknown Files [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
bottlebrush

Cadet
Cadet


Joined: Dec 21, 2007
Posts: 8
Location: Australia

PostPosted: Fri Dec 21, 2007 11:28 am    Post subject: CAN'T REMOVE UNKNOWN FILE--CORPOLW.DLL
Reply with quote

Hello,
I have found these two suspicious files on my computer in C:\WINDOWS\System32
corpolw.dll
tb10hbzt.exe
Twisted Evil

I have searched the internet and can find 'nothing' about these two files.
I have tried various programs to 'unlock' and delete 'corpolw.dll' but cannot. Shocked
I have established 'explorer.exe' has control of 'corpolw.dll'
I have 'terminated' explorer.exe in 'safe mode' and tried to delete with 'killbox'--but no success.
I am not sure if they are causing the following problem:-
(I am using IE6--WinXP Pro SP1a,)
When I click on 'links' to web pages found in Google,-instead of opening up the web page--I get a blank page wi th the following address:-
http://89.149.227.101/click.php?c=972af1320460d67ad06f4004&r=3

It doesn't happen everytime.And when it does, I click on 'back' and then click on the web link again.I keep repeating this until the web page opens correctly.
The problem is only with IE6 and not with other browsers-'OPERA'

--please help- Sad

Back to top
View users profile Send private message
pykko

MIRT Hunter


Joined: Jan 18, 2007
Posts: 738

MIRT

PostPosted: Fri Dec 21, 2007 12:55 pm    Post subject: samples
Reply with quote

Please attach the two files here in a password-protected archive with password: infected
Thank you!


_________________
I want to know God's thoughts. The rest are details. - Albert Einstein
Back to top
View users profile Send private message
MysteryFCM

Sergeant
Sergeant


Joined: Feb 07, 2007
Posts: 125
Location: Tyneside, UK

PostPosted: Fri Dec 21, 2007 4:52 pm    Post subject:
Reply with quote

Might wanna de-linkify the OP's linky Wink


_________________
Regards

Steven Burn
Ur I.T. Mate Group / hpHosts
it-mate.co.uk / hosts-file.net
Back to top
View users profile Send private message Visit posters website
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5878

MIRT Premium

PostPosted: Sat Dec 22, 2007 3:48 am    Post subject:
Reply with quote

Have a look at http://wiki.castlecops.com/MRP

After you've followed the instructions, if you are still infected or worried that you may be please make a post in CastleCops Link/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html and someone will help you.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
bottlebrush

Cadet
Cadet


Joined: Dec 21, 2007
Posts: 8
Location: Australia

PostPosted: Sat Dec 22, 2007 4:50 am    Post subject: Re: samples
Reply with quote

pykko wrote:
Please attach the two files here in a password-protected archive with password: infected
Thank you!


Sorry for the delay---as I am new here--can you tell me how to add the zip file to my message/post please.

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5878

MIRT Premium

PostPosted: Sat Dec 22, 2007 1:37 pm    Post subject:
Reply with quote

Click on "post reply"

CastleCops Link/modules.php?name=Forums&file=posting&mode=reply&t=210994

Then under the main text box click on "browse", find the file, then click on "add attachment" and finally click on submit.

Back to top
View users profile Send private message
bottlebrush

Cadet
Cadet


Joined: Dec 21, 2007
Posts: 8
Location: Australia

PostPosted: Sat Dec 22, 2007 9:57 pm    Post subject: ZIP --PASSWORD PROTECTED SUBMITTED
Reply with quote

tetak wrote:
Click on "post reply"

CastleCops Link/modules.php?name=Forums&file=posting&mode=reply&t=210994

Then under the main text box click on "browse", find the file, then click on "add attachment" and finally click on submit.


OK---Here's the 'corpolw.dll'
The other file,'tb10hbzt.exe' has completely disappeared from my computer.

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5878

MIRT Premium

PostPosted: Sat Dec 22, 2007 11:47 pm    Post subject:
Reply with quote

corpolw.dll is malware known as Trojan.Win32.BHO.agz (Kaspersky)

Once you have removed all the malware I suggest you install Windows XP Service Pack 2. You can download it from Microsofts website for free.

Once you have installed Service Pack 2, visit Windows Update using IE6 and install all the updates.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
bottlebrush

Cadet
Cadet


Joined: Dec 21, 2007
Posts: 8
Location: Australia

PostPosted: Sun Dec 23, 2007 5:43 am    Post subject: CORPOLW.DLL WILL NOT DELETE
Reply with quote

tetak wrote:
corpolw.dll is malware known as Trojan.Win32.BHO.agz (Kaspersky)

Once you have removed all the malware I suggest you install Windows XP Service Pack 2. You can download it from Microsofts website for free.

Once you have installed Service Pack 2, visit Windows Update using IE6 and install all the updates.


I have tried everything to remove this file with no success. Embarassed
I followed the procedures in your article for 'Malware Removal'
---I ran 'CCleaner',ATF Cleaner,'Adaware',Spybot S&D,SuperantiSpyware,AVG Anti-spywareVundofix,VundoBegone,WinPfind,
SmitFraudfix.
SuperAntispyware was the only prog that found 'corpolw.dll' and some other registry entries--but could not delete them.
I ran progs in 'safe' mode---still no luck.
Ran 'KillBox','Unlocker',Emco Move on Boot','Emco Unlockit'---all unsuccessful!!!!---cannot unlock,read,move,replace with dummy or delete.
-looks like I might be doing a 'fresh' install Sad

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5878

MIRT Premium

PostPosted: Sun Dec 23, 2007 9:50 am    Post subject:
Reply with quote

If you know how to do a fresh install then that might be the best idea. Once you've installed XP make sure you install Service Pack 2 and update IE to IE7. You could also install Windows Defender as well as your existing AV program.

If you don't want to re-install Windows make a post here CastleCops Link/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
bottlebrush

Cadet
Cadet


Joined: Dec 21, 2007
Posts: 8
Location: Australia

PostPosted: Sun Dec 23, 2007 11:46 pm    Post subject:
Reply with quote

tetak wrote:
If you know how to do a fresh install then that might be the best idea. Once you've installed XP make sure you install Service Pack 2 and update IE to IE7. You could also install Windows Defender as well as your existing AV program.

If you don't want to re-install Windows make a post here CastleCops Link/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html


In this case--I'll go with the 'fresh install'

thanks for your help- Smile

Back to top
View users profile Send private message
bdragomir

Cadet
Cadet


Joined: Dec 28, 2007
Posts: 1
Location: USA

PostPosted: Fri Dec 28, 2007 6:48 am    Post subject: Re: CAN'T REMOVE UNKNOWN FILE--CORPOLW.DLL
Reply with quote

[quote="bottlebrush"]Hello,
I have found these two suspicious files on my computer in C:\WINDOWS\System32
corpolw.dll
tb10hbzt.exe
Twisted Evil

If you are sure that you know what you're doing you can reboot your machine using a linux live cd (e.g. knoppix) map your drive (if ntfs use ntfs -3g...) and delete the files that other might be locked by the Windows OS at bootup.
If you need any further help please let me know.

Regards,
Bogdan Dragomir

Back to top
View users profile Send private message
Cretem0nster

MIRT Hunter


Joined: Jul 02, 2005
Posts: 121
Location: USA
MIRT

PostPosted: Fri Dec 28, 2007 1:16 pm    Post subject:
Reply with quote

bottlebrush if you wish to remove this malware without doing a fresh install,send me a private message and ill help you sort it out as quickly as possible.

Back to top
View users profile Send private message
bottlebrush

Cadet
Cadet


Joined: Dec 21, 2007
Posts: 8
Location: Australia

PostPosted: Sat Dec 29, 2007 9:34 am    Post subject: fresh install
Reply with quote

Cretem0nster wrote:
bottlebrush if you wish to remove this malware without doing a fresh install,send me a private message and ill help you sort it out as quickly as possible.


Thanks for your offer, but I will be doing a fresh install (it's time I did it anyway, and a lot of cleaning up) Laughing

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Unknown Files All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer