also @ TechSpot: Seven Intel P55 Motherboards Compared, Reviewed
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

I have Darksma virus, can anyone help?

Closed Thread
Page 2 of 2 1 2
Bookmark Thread Tools
  #21  
Old 09-25-2008
Newcomer, in training
 
Member since: Aug 2008, 17 posts
System specs
Hey,

I located the file "ebbddccceed.dll" in the System 32 folder, but every time I try to delete it, Windows says it is in use by another program, which I must first shut down to be able to delete it! Any idea what program it may be?

Ron
  #22  
Old 09-25-2008
Bobbye's Avatar
TechSpot Evangelist
 
Location: Clearwater, FL
Member since: Mar 2007, 5,878 posts
Ron, I could not identify ebbddccceed.dll. Try doing a right click on the file> Properties> see if you can get any information there. I didn't even get a suggested spelling correction from Google- only you post comes up with it.
To remove this ad, sign in. To register for a new account, click here.
  
  #23  
Old 09-27-2008
Newcomer, in training
 
Member since: Aug 2008, 17 posts
System specs
Quote:
Originally Posted by Bobbye View Post
This is back again:
O20 - Winlogon Notify: ebbddccceed - C:\WINDOWS\system32\ebbddccceed.dll
Try going into Safe Mode:
Right click on Start> Explore> Windows system 32> delete ebbddccceed.dll if it's there.
I am finding it difficult to get rid of this file. I've tried deleting it, both in safe mode, and normal Windows, and each time, it says it cannot be deleted, as it is currently in use by another program. I right-clicked the file in the Windows System 32 folder, and selected properties, I have attached screen grabs of what the results were.

Ron
Attached Images
File Type: jpg properties01.jpg (27.5 KB, 1 views)
File Type: jpg inuse01.jpg (45.1 KB, 1 views)
  #24  
Old 09-27-2008
Bobbye's Avatar
TechSpot Evangelist
 
Location: Clearwater, FL
Member since: Mar 2007, 5,878 posts
Well, wee need to find the application that this process is an 'extension' for. (Properties)

Best to search by date- see what was done on 'Created Date' of 27 June, 2007:
Search> Files & Folders> Scroll down to and check 'Specify dates'> change box to read 'Created date'> put 6/27/2007 in box date boxes> be sure search is set for Local Drive- usually C> Search.

Look on the right screen. Do you see anything installed on that date? Anything at all? IF you don't bring up anything helpful using the 'created date', start new Search and use 'modified date'> put 7/10/2008 in date box and search.

This reads as an application extension.I can't ID it it but if we can find the application itself, we may be able to handle this process by disabling that app.
  #25  
Old 10-19-2008
Newcomer, in training
 
Member since: Aug 2008, 17 posts
System specs
Quote:
Originally Posted by Bobbye View Post
Look on the right screen. Do you see anything installed on that date? Anything at all? IF you don't bring up anything helpful using the 'created date', start new Search and use 'modified date'> put 7/10/2008 in date box and search.
Hi,

sorry it's taken me w while to respond, been busy moving house. Anyway, I searched my hard drive for any programs installed on 27/06/07, and it seems that IE7 was installed on that day. I have attached a jpeg of the results...

Thanks,

Ron
Attached Images
File Type: jpg search_results.jpg (174.1 KB, 3 views)
  #26  
Old 10-19-2008
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,368 posts
Download Unlocker: http://ccollomb.free.fr/unlocker/unlocker1.8.7.exe
Install the program
Browse to C:\WINDOWS\system32 folder
Locate: ebbddccceed.dll
Right Click on ebbddccceed.dll and select Unlocker
Then delete the file

Then restart
Confirm if ebbddccceed.dll is in fact gone
  #27  
Old 10-19-2008
Newcomer, in training
 
Member since: Aug 2008, 17 posts
System specs
Quote:
Originally Posted by kimsland View Post
Download Unlocker: http://ccollomb.free.fr/unlocker/unlocker1.8.7.exe
Install the program
Browse to C:\WINDOWS\system32 folder
Locate: ebbddccceed.dll
Right Click on ebbddccceed.dll and select Unlocker
Then delete the file

Then restart
Confirm if ebbddccceed.dll is in fact gone
Well! That was interesting!

I downloaded and installed Unlocker, located "ebbddccced.dll", right-clicked, and selected "Unlocker".

Then, all within a matter of two seconds, my Windows XP black theme reverted to Windows 98, and then in an instant, my computer switched off. I think perhaps this file would be best left alone, yeah?
  #28  
Old 10-19-2008
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,368 posts
Quote:
I think perhaps this file would be best left alone, yeah?
No it's best removed

Now we can fix Windows, without any strange file lurking about

Sounds as though it was related to some display theme

What is the present status?
  #29  
Old 10-19-2008
Bobbye's Avatar
TechSpot Evangelist
 
Location: Clearwater, FL
Member since: Mar 2007, 5,878 posts
The search screen you attached also shows images and mp3 on this date, not just IE7. Check the 'Create date' and see if you find anything that will pin it down. IE7

I have no doubt that ebbddccceed.dll is some kind of malware. But what don't know is what files if may have changes. Removing it may have removed those files, but then the originals were missing.

Exactly what is the system status now? Will it boot? Into what OS? Have you reset the display settings?
To remove this ad, sign in. To register for a new account, click here.
  
Closed Thread
Page 2 of 2 1 2

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Tags
darksma
Thread Tools


Similar Topics
Topic Category Replies Last Post
Darksma Virus. Please Help Virus & Malware removal 9 07-07-2008 10:56 AM
Darksma help Virus & Malware removal 2 03-14-2008 01:23 PM
Virus on computer-Darksma Virus & Malware removal 5 01-05-2008 07:24 PM
Cant get rid of Darksma Virus & Malware removal 15 08-31-2007 08:02 PM
Darksma Virus & Malware removal 1 07-06-2007 01:30 PM


All times are GMT -4. The time now is 09:19 PM.