StewartBondi Posted December 18, 2009 Posted December 18, 2009 Recently we have noticed that in the Root of students and staff "My Documents" redirected to drive u: there is a file bho.dll of varying size and date stamps. A Google search suggests that it usually is used as spyware/adware. After deleting it the next day it is regenerated. I assume it may be the activity of one of our network applications but no idea which. Does anyone know anything about this?
Dos_Box Posted December 18, 2009 Posted December 18, 2009 bho.dll - bho.dll - DLL Information bho.dll - What is bho.dll? Uh oh! Looks like you've some work to do!
StewartBondi Posted December 18, 2009 Author Posted December 18, 2009 Thanks for links, which I had previously read in my Google searches, but what I am hoping to find out is what activity/activities are occuring that causes the creation of this file. It appears in student, teacher, parent and our tech accounts which is why I was wondering if it was a network apps action. I would like to identify the source of its creation and know if I can ignore it or what action I may need to take to stop it occuring in the future. Thanks
synaesthesia Posted December 18, 2009 Posted December 18, 2009 Found a lot of these recently relating to varying installations of stuff like MyWebSearch toolbars - not in My Documents though, that's a new one on me. Keep us posted though please.
Sylv3r Posted December 18, 2009 Posted December 18, 2009 I would guess after deleting the file and then re-logging on to an infected workstation the file would reappear. I take it you have tried a full virus scan / adaware scan on a test PC to try this?
Michael Posted December 18, 2009 Posted December 18, 2009 What you could do is run MalwareBytes on your server to get rid of all the BHO.DLL files which are appearing in user redirected documents. Unfortunately it's then a case of some detective work; either scan a handful of machines (again with Malwarebytes) or start re-imaging workstations you suspect may be the source of the problem. In the circumstances I'd be more inclined to re-image machines. It's probably quicker and you're guaranteed if anything's there it should get deleted in the process.
saundersmatt Posted December 18, 2009 Posted December 18, 2009 Are you running Impero on your workstations?
StewartBondi Posted January 13, 2010 Author Posted January 13, 2010 (edited) Thanks for the last suggestion about Impero. This was initially denied by Impero to be the cause, but removing the client removed the generation of the dll file, re-installing the client caused the dll file to be re-generated. I sent off clear logs and Impero accept the info, but in fairness they had prepared a unique build for us to fix a problem and the beta process of placing a dll file was still within the code. I am now not worried about this file, but waiting on a client update so I can remove it across all users home directories. Thank you to everyone for your feedback. Sorry it took so long to update. Stewart Edited January 13, 2010 by StewartBondi
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now