also @ TechSpot: Apple working with suppliers on 8-inch iPad, says WSJ
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.

Go Back   TechSpot OpenBoards > Tech Support > Virus and Malware Removal

Download Now:

I have Darksma virus, can anyone help?

Page 2 of 2 1 2
Thread Tools Search this Thread
  #21  
Old 09-25-2008
Newcomer, in training
 
Member since: Aug 2008, 17 posts
System specs
Hey,

I located the file "ebbddccceed.dll" in the System 32 folder, but every time I try to delete it, Windows says it is in use by another program, which I must first shut down to be able to delete it! Any idea what program it may be?

Ron
  #22  
Old 09-25-2008
Bobbye's Avatar
Helper on the Fringe
 
Location: Florida
Member since: Mar 2007, 15,043 posts
Ron, I could not identify ebbddccceed.dll. Try doing a right click on the file> Properties> see if you can get any information there. I didn't even get a suggested spelling correction from Google- only you post comes up with it.
  #23  
Old 09-27-2008
Newcomer, in training
 
Member since: Aug 2008, 17 posts
System specs
Quote:
Originally Posted by Bobbye View Post
This is back again:
O20 - Winlogon Notify: ebbddccceed - C:\WINDOWS\system32\ebbddccceed.dll
Try going into Safe Mode:
Right click on Start> Explore> Windows system 32> delete ebbddccceed.dll if it's there.
I am finding it difficult to get rid of this file. I've tried deleting it, both in safe mode, and normal Windows, and each time, it says it cannot be deleted, as it is currently in use by another program. I right-clicked the file in the Windows System 32 folder, and selected properties, I have attached screen grabs of what the results were.

Ron
Attached Images
File Type: jpg properties01.jpg (27.5 KB, 2 views)
File Type: jpg inuse01.jpg (45.1 KB, 2 views)
  #24  
Old 09-27-2008
Bobbye's Avatar
Helper on the Fringe
 
Location: Florida
Member since: Mar 2007, 15,043 posts
Well, wee need to find the application that this process is an 'extension' for. (Properties)

Best to search by date- see what was done on 'Created Date' of 27 June, 2007:
Search> Files & Folders> Scroll down to and check 'Specify dates'> change box to read 'Created date'> put 6/27/2007 in box date boxes> be sure search is set for Local Drive- usually C> Search.

Look on the right screen. Do you see anything installed on that date? Anything at all? IF you don't bring up anything helpful using the 'created date', start new Search and use 'modified date'> put 7/10/2008 in date box and search.

This reads as an application extension.I can't ID it it but if we can find the application itself, we may be able to handle this process by disabling that app.
  #25  
Old 10-19-2008
Newcomer, in training
 
Member since: Aug 2008, 17 posts
System specs
Quote:
Originally Posted by Bobbye View Post
Look on the right screen. Do you see anything installed on that date? Anything at all? IF you don't bring up anything helpful using the 'created date', start new Search and use 'modified date'> put 7/10/2008 in date box and search.
Hi,

sorry it's taken me w while to respond, been busy moving house. Anyway, I searched my hard drive for any programs installed on 27/06/07, and it seems that IE7 was installed on that day. I have attached a jpeg of the results...

Thanks,

Ron
Attached Images
File Type: jpg search_results.jpg (174.1 KB, 4 views)
  #26  
Old 10-19-2008
Ex-TechSpotter
 
Member since: Dec 2007, 18,354 posts
Download Unlocker: http://ccollomb.free.fr/unlocker/unlocker1.8.7.exe
Install the program
Browse to C:\WINDOWS\system32 folder
Locate: ebbddccceed.dll
Right Click on ebbddccceed.dll and select Unlocker
Then delete the file

Then restart
Confirm if ebbddccceed.dll is in fact gone
  #27  
Old 10-19-2008
Newcomer, in training
 
Member since: Aug 2008, 17 posts
System specs
Quote:
Originally Posted by kimsland View Post
Download Unlocker: http://ccollomb.free.fr/unlocker/unlocker1.8.7.exe
Install the program
Browse to C:\WINDOWS\system32 folder
Locate: ebbddccceed.dll
Right Click on ebbddccceed.dll and select Unlocker
Then delete the file

Then restart
Confirm if ebbddccceed.dll is in fact gone
Well! That was interesting!

I downloaded and installed Unlocker, located "ebbddccced.dll", right-clicked, and selected "Unlocker".

Then, all within a matter of two seconds, my Windows XP black theme reverted to Windows 98, and then in an instant, my computer switched off. I think perhaps this file would be best left alone, yeah?
  #28  
Old 10-19-2008
Ex-TechSpotter
 
Member since: Dec 2007, 18,354 posts
Quote:
I think perhaps this file would be best left alone, yeah?
No it's best removed

Now we can fix Windows, without any strange file lurking about

Sounds as though it was related to some display theme

What is the present status?
  #29  
Old 10-19-2008
Bobbye's Avatar
Helper on the Fringe
 
Location: Florida
Member since: Mar 2007, 15,043 posts
The search screen you attached also shows images and mp3 on this date, not just IE7. Check the 'Create date' and see if you find anything that will pin it down. IE7

I have no doubt that ebbddccceed.dll is some kind of malware. But what don't know is what files if may have changes. Removing it may have removed those files, but then the originals were missing.

Exactly what is the system status now? Will it boot? Into what OS? Have you reset the display settings?
Closed Thread
Page 2 of 2 1 2

Similar Topics
Topic Replies Forum
Darksma Virus 0 Virus and Malware Removal
Darksma virus Please Help 1 Windows OS
Darksma Virus. Please Help. 13 Virus and Malware Removal
Darksma Virus. Please Help 9 Virus and Malware Removal
Virus on computer-Darksma 5 Virus and Malware Removal

Thread Tools Search this Thread
Search this Thread:

Advanced Search
All times are GMT -4. The time now is 04:36 PM.