B3D Killer - remove BDE/B3D scumware...

Discussion in 'SpywareBlaster & Other Forum' started by javacool, Apr 4, 2002.

Thread Status:
Not open for further replies.
  1. Tester

    Tester Guest

    I think you need the Visual Basic run-time. Search http://www.micrososft.com for the VB 6 SP5 run-time installer.
     
  2. Tester

    Tester Guest

    Oops - misspelled that above link.

    But here's the direct link: http://www.microsoft.com/downloads/release.asp?ReleaseID=28337&LangID=20&LangDIR=en-us&OpSysID=9801&Search=Keywords&Value=Visual+Basic&Show=Alpha&Start=&Page=0
     
  3. Rxdoxx

    Rxdoxx Registered Member

    Joined:
    Feb 11, 2002
    Posts:
    9
    Thank you!!!!!
    Ran the program, KaZaa still works.

    Did a search and found a number of files remaining, mostly .gag files Deleted them also.

    I have my system backed up on a second HD.  Didn't see it clean the registry that was still there. Copied it to the D drive and tried running it from there also, so looks like your great program hits the active registry.

    Final thing I am looking for is a list of files. I'm hesitant to delete everything with BDE in it. Still finding msxbde40.dll , mspbde40.dll , KBDE.KBD , and NETCBDEC.INF .
    NETCBDEC.INF was a hidden file. I unhid and went looking just in case they had tried to sneak something in that way.

    (Javacool, if you remember me, you'll remember I tend to go overboard with these things), still some questions in my mind, but I am very happy and grateful for the program. Thank you again.
     
  4. javacool

    javacool BrightFort Moderator

    Joined:
    Feb 10, 2002
    Posts:
    4,099
    Glad the program worked well for you.

    That is correct, the program only affects the active registry.

    You shouldn't have to delete any other files if you ran my program - it gets rid of all the Brilliant Digital files installed - including those installed with the newest KaZaA (which has a newer version of Brilliant Digital).

    WARNING: I generally wouldn't go around deleting everything with BDE in it - many are IMPORTANT system files. If you ran my program, you should be fine.
    (This also applies to registry entries - there are many that include the string "BDE" that are important for windows, and then there are some that don't contain the string that are Brilliant Digital entries - my program should get rid of ALL the Brilliant registry entries too, so you won't have to manually search for any more.)

    Note: if you really do want to check those files out to make sure they are legit, you can right click on the file, and select properties - that should tell you what company/software that file is from.

    I don't forget that easily.  ;)

    No problem with answering the questions, and you're quite welcome for the program.

    If you have any other questions, don't hesitate to ask.  :)
     
  5. spy1

    spy1 Registered Member

    Joined:
    Dec 29, 2002
    Posts:
    3,139
    Location:
    Clover, SC
    javacool - I'd like to thank you for the program, too (yes, I came up clean everywhere).

    You, Robin Keir ( http://keir.net/bde.html ) and AdAware are all to be highly commended for leaping all over that thing and beating it to death - for free! Pete
     
  6. GhostWerm

    GhostWerm Registered Member

    Joined:
    Apr 8, 2002
    Posts:
    2
    Nice work javacool. Ive made a post on elitehackers.com: http://www.elitehackerz.com/ubb/ultimatebb.php?ubb=get_topic;f=8;t=000681 and mirrored your download as well as given a link to your download page. Keep finding those files and keys and updating the program...very cool indeed!
     
  7. Mr.Blaze

    Mr.Blaze The Newbie Welcome Wagon

    Joined:
    Feb 3, 2003
    Posts:
    2,842
    Location:
    on the sofa
    bandwith problem
    set up mass acounts at tripod with difrent e-maill adress

    copy page at free servers upload to several tripods.


    just paste the several urls of mirrors from tripods to free servers

    but keep the tripods non asochiated wite freeservers

    keep handy all your tripod acounts and pass words

    never log in with rember me from now on.

    mask ip

    and always use internet sweeper to wipe out cookies ect after each visit to tripod and on to the next one.

    im just guessing this is how its done=)

    hey its for a good cause security =)why every one looking at me funny=)
     
  8. snowman

    snowman Guest

          Javacool


          I am extending "thank you" from eight familes.

          today using your great lil program I cleaned their computers of <brilliant>.......the program worked wonderfully.........several of these computers were win95.......

         hip hip hooray....job well done....get-em Javacool!!
     
  9. GhostWerm

    GhostWerm Registered Member

    Joined:
    Apr 8, 2002
    Posts:
    2
    [/Re: B3D Killer - remove BDE/B3D s... I can do to hook you up. Again, good job  8)
     
  10. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    Not sure which version i ran, as downloading 1.1.2 where it said "the newest version" it asked for username/password, so guess i had the 1.1 from ??
    Coming up so clean, that i wondered if the program was even working :D. A little message would be helpfull i guess.
    Never used Kazaa, could have been in another software... so good to be clean!  
     
  11. weh

    weh Registered Member

    Joined:
    Apr 11, 2002
    Posts:
    1
    Nice work!

    Perhaps you can answer a couple of questions...
    In your study of this software were you able to determine how Brilliant software downloads and updates? Specifically, is the update function provided by KaZaa, or once Brilliant's software is present on a system does it function and update on its own?  (Does KaZaa have to be running for Brilliant to do its stuff?)

    I am particularly interested in what you know about the ability of the software to re-infect a PC.

    On an infected machine I was not able to detect any additional processes running in the task list -  so if KaZaa is not running can Brilliant still manipulate the machine?
     
  12. spy1

    spy1 Registered Member

    Joined:
    Dec 29, 2002
    Posts:
    3,139
    Location:
    Clover, SC
    Anyone who has been affected by 'Brilliant' should also check for (and delete if there) C:\WINDOWS\SYSTEM\bde3d_refk7.dll (or at the very least, un-register it). Pete
     
  13. javacool

    javacool BrightFort Moderator

    Joined:
    Feb 10, 2002
    Posts:
    4,099
    Actually, I do have a couple answers for those questions.

    1) As far as I can tell, the updating only goes through the Zupdate program. It seems as though this program must run itself BEFORE most other things load (pretty suspicious) - which I believe is an attempt to circumvent outbound protecting software.

    2) Kazaa does NOT have to be running for the Brilliant Digital software to function. Side note: Reports have indicated that the Kazaa software pings a strange outside IP address, and that this pinging stops once Brilliant is uninstalled...

    3) As for your other question - the only components known as of yet are the B3D player and associated download components. The download components are, of course, the most dangerous, as they will allow the download of the "distributed computing" application part at a later date. As of now, no reports have come in of this new part being pushed out or activated, but supposedly, it soon will.

    Hope this was somewhat useful to you, and I will post more later if I get a chance.
     
  14. Hey as for bandw I have a few dedicated servers on my hands I can mir the file for you.

    It can be on
    www.visualdysfunction.com
    www.obtainroot.com
    www.gladewater.net
    www.fekt.org
    www.fektnetworks.com
    etc..

    and yes it is great thank you for helping us all with that great program :)
     
  15. spy1

    spy1 Registered Member

    Joined:
    Dec 29, 2002
    Posts:
    3,139
    Location:
    Clover, SC
  16. Mike_Healan

    Mike_Healan Registered Member

    Joined:
    Mar 6, 2002
    Posts:
    302
    Location:
    USA
    It looks like BDE is planning to update it's crap every week now. I believe Urizen intends to match them with a new reflist each time.
     
  17. javacool

    javacool BrightFort Moderator

    Joined:
    Feb 10, 2002
    Posts:
    4,099
    As soon as I obtain more information on this new version (and to make sure its not a version my program already covers) I will update B3D Killer's detection database. I have not yet found a new version of BDE online, however - but I will download the BDE Player from Brilliant Digital's website again today, and the same with Kazaa, to make sure it doesn't install anything new. (If I can confirm it does, you can be sure an update will be put out.)  :)
     
  18. javacool

    javacool BrightFort Moderator

    Joined:
    Feb 10, 2002
    Posts:
    4,099
    As I will, as soon as I can get my hands on the newest version of their "scum"...
     
  19. Paul Wilders

    Paul Wilders Administrator

    Joined:
    Jul 1, 2001
    Posts:
    12,475
    Location:
    The Netherlands
    Nice going, javacool!


    Seems like you will have to update on a weekly basis as well...

    regards.

    paul
     
  20. javacool

    javacool BrightFort Moderator

    Joined:
    Feb 10, 2002
    Posts:
    4,099
    That seems to be the case.

    In my investigation, which I just completed, I have found traces of a new version of BDE in the KaZaA 1.6 download (which, although the version number of KaZaA has not changed, installs different and/or more files/folders/registry keys).

    A B3D Killer update is on its way...
     
  21. javacool

    javacool BrightFort Moderator

    Joined:
    Feb 10, 2002
    Posts:
    4,099
  22. Checkout

    Checkout Security Rhinoceros

    Joined:
    Feb 11, 2002
    Posts:
    1,226
    Just an aside - my ZA logs show an attack from a service called "KAZAA" this morning.  Coincidence?
     
  23. Hi! I have used bde-killer 1.1.2 on my PC and then installed kazaa lite a few days ago (I´m running Windows XP professional... maybe u want know it). Now i´ve found: in Wininit.ini "/system32/bdeinstal2" -it´s a link to a non existing file- and, in system32, this files from Brilliant: bde3d_ref2.dll, bdeinsta25.dll, bdeload.dll, BDESac10.dll and BDERastDx6_30002.dll. My lastest version of kazaa was 1.5.1. Hope this will be helpfull for you. Any question e-mail me el_tercer_hombre@hotmail.com. Sorry for my bad english. Bye.
     
  24. securetype

    securetype Guest

    Hi,

    Didn't completely remove all traces.  The folder "C:\WINDOWS\BDE" and it's subdirectories "b3dlogo", "Cache", "movies", "mskin", & "Update" cannot be removed on this Win XP (NTFS) machine.  They are "access denied" and considered to be "critical system files".

    Already tried to remove via "Add/Remove Programs" prior to B3D Killer.  Ad-Aware can't remove these directories, either.  Booting into safe mode doesn't work.

    What do you think?

    David
     
  25. javacool

    javacool BrightFort Moderator

    Joined:
    Feb 10, 2002
    Posts:
    4,099
    This is VERY strange...

    It could be a new version/variant of BDE - or just something weird with how it installed itself on your system.

    I'll have to look into this - if more people are having this occurance, and I can replicate it...Brilliant Digital has DEFINITELY made its software a trojan (if it can't be removed by simple deletion or uninstall - you can delete even WINDOWS folders/files, so this could be VERY malicious behavior).

    -javacool
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.