What is sol630.txt
Recently a friend brought me a very badly infected computer to repair. The computer after various tests was found infected by multiple pieces of malware. The very strange thing of the whole scenario was the presence of a file called "sol630.txt" in windows/system32 folder. This file was a masqueraded dll file that:
- Could not be deleted (you could delete it but it kept being recreated)
- Was called everytime an application was launched (found the registry key:[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]"AppInit_DLLs"="C:\\WINDOWS\\system32\\sol630.txt" which also kept being recreated when deleted)
- And the most strange thing is that we could not find any info about this file in the web! We found info about a similar file called sol629.txt.
Avira’s antivir detected the presence of a trojan and various other malware, but could not remove everything even in safe mode.
The solution to repair the system was sadly the complete removal of the old windows installation and the installation of Windows from scratch.