Educause Security Discussion mailing list archives

Re: kraes.dll


From: Nathan Hall <hallnk () ONEONTA EDU>
Date: Thu, 22 Jul 2004 08:56:34 -0400

I believe this is a randomly named .dll. Try searching for it's effects:
resetting the homepage to res://???.dll/index.html. Searching for this
info I found the following information which may be helpful:
http://www.pchell.com/support/onlythebest.shtml,
http://www.pchell.com/support/lookfor.shtml. 


-----Original Message-----
From: The EDUCAUSE Security Discussion Group Listserv
[mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Edward Chase
Sent: Wednesday, July 21, 2004 3:33 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] kraes.dll

I'm looking for information on a file named:

c:\windows\kraes.dll

I've run across a machine that's got some internet weirdness going on.
It's
been virused checked, it been run through Ad-adware and Spybot.  It's
been
Windows updated and it's been firewalled.  All have been done AFTER the
weirdness started.

The machine keeps wanting to set it's homepage to
res://kraes.dll/index.html
(followed by ? and some number which I forget)

I did find the file above and manually deleted it, yet it somehow came
back.

The machine is Windows XP Home.

I can't find anything via Google.

Anybody heard of this?


-- 
Edward Chase
Providence College
Information Technology 

**********
Participation and subscription information for this EDUCAUSE Discussion
Group discussion list can be found at http://www.educause.edu/cg/.

**********
Participation and subscription information for this EDUCAUSE Discussion Group discussion list can be found at 
http://www.educause.edu/cg/.

Current thread: