Specialgoods.info infection

Reply

Join Date: May 2005
Posts: 1
Reputation: Bankarin is an unknown quantity at this point 
Solved Threads: 0
Bankarin's Avatar
Bankarin Bankarin is offline Offline
Newbie Poster

Specialgoods.info infection

 
0
  #1
May 7th, 2005
Hello all. My wife was browsing the web and a hijacking program downloaded itself and infected my laptop. After much searching of the web, several Spyware removal downloads and re-installing WebRoot Spysweeper, which the hijacking program managed to un-install BTW, and Norton, I finally stumbled on this site which helped greatly in removing the infection. The problem was almost exactly the same as the HotOffers infection only now I've lost almost all capability to access the Display properties. I can't change the theme, wallpaper (Through the display properties control panel that is), and the only tabs I have are the screen saver tab and the settings tab. I'm running WinXP SP1. SP2 and my laptop don't get along. She was using IE, which I've now removed all the shortcuts to and I'm getting her to use Firefox instead. I don't have an actual WinXP Home disc since the laptop just came with Restore discs and I don't want to re-install the entrie system just to fix this. And I won't be able to use my desktop till later or tomorrow. Anyone have any ideas as to what I need to do? Appreciate the help.
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 353
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: Specialgoods.info infection

 
0
  #2
May 7th, 2005
That alteration to your Display properties is usually the work of the "smitfraud" infection. See if this fixes the problem:


1. Download the following reg file by right-clicking on the link and choosing Save As. Save this file to your Desktop.

Smitfraud Fix Reg File

2. When it is finished downloading, double-click on the smitfraud.reg file on your Desktop. When it asks if you want to merge the information, allow it to do so.

3. Reboot. You should then be able to change your desktop properties back to the way you want to. If you have trouble with some settings, click on the Themes tab in the display settings and change the theme to Windows XP to use the default settings.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 2
Reputation: notryt is an unknown quantity at this point 
Solved Threads: 0
notryt notryt is offline Offline
Newbie Poster

Re: Specialgoods.info infection

 
0
  #3
May 10th, 2005
this works to bring the display back bnut does nothing to get rid of the spyware (specialgoods.info) this is a nasty bugger
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 1
Reputation: tavueni is an unknown quantity at this point 
Solved Threads: 0
tavueni tavueni is offline Offline
Newbie Poster

Re: Specialgoods.info infection

 
0
  #4
May 10th, 2005
Hey notryt ,

I had the same thing and I managed to get rid of it. Here's what I did (on Windows 98 SE):

* Install and Run Spyware Guard
* Navigate to C:\Windows\System32 (possibly C:\Windows\System if in Windows XP)
* I deleted any Programs that look like they "shouldn't" be there. They all had icons for the files and ones I had were labelled "Britney Spears", "Monster C*cks" and things to that affect. There must have been about 10 files in all.
* In the same directory, there was also a file called param.dll (or something to that effect - I deleted before noting down what it was but it was the only *.dll file in that directory). If you try and delete it in Windows, it won't let you saying that it is being used.
* I then went into "pure" DOS mode (if you're using a Windows XP, try a Windows 98 SE Boot Disk - You can get one from www.bootdisk.com)
* Once in DOS mode, I navigated to the directory in DOS and typed "attrib -r -a -s -h" to remove any file permissions and then deleted the file manually using "del param.dll" (if that was the file name)
* After this, I rebooted the machine, went to Internet Options and changed the default homepage (a note from Spyguard popped up asking me if I was sure and said "Keep Value".

...and I haven't had any problems since.

I hope that helps. If you not sure or you're having trouble, feel free to drop me a line and I'll see if I can walk you through it in more detail.

tav
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 2
Reputation: notryt is an unknown quantity at this point 
Solved Threads: 0
notryt notryt is offline Offline
Newbie Poster

Re: Specialgoods.info infection

 
0
  #5
May 10th, 2005
Originally Posted by tavueni
Hey notryt ,

I had the same thing and I managed to get rid of it. Here's what I did (on Windows 98 SE):

* Install and Run Spyware Guard
* Navigate to C:\Windows\System32 (possibly C:\Windows\System if in Windows XP)
* I deleted any Programs that look like they "shouldn't" be there. They all had icons for the files and ones I had were labelled "Britney Spears", "Monster C*cks" and things to that affect. There must have been about 10 files in all.
* In the same directory, there was also a file called param.dll (or something to that effect - I deleted before noting down what it was but it was the only *.dll file in that directory). If you try and delete it in Windows, it won't let you saying that it is being used.
*
...and I haven't had any problems since.

I hope that helps. If you not sure or you're having trouble, feel free to drop me a line and I'll see if I can walk you through it in more detail.

tav

Thanx.. anyone using xp the icons are in the system32 directory.. to del param32.dll in xp (Im assuming ntfs) reboot f8 .. safemode command prompt... once you get the prompt.. navigate yourself to the windows/system32 directory and type del param32.dll... reboot and alls good again
Reply With Quote Quick reply to this message  
Join Date: Jul 2004
Posts: 2,964
Reputation: dlh6213 is on a distinguished road 
Solved Threads: 209
Team Colleague
dlh6213 dlh6213 is offline Offline
Posting Maven

Re: Specialgoods.info infection

 
0
  #6
May 11th, 2005
Param.dll is indeed one of the bad files associated with this (smitfraud, HotOffers, and a couple of others), and you will most likely need to use the PocketKillbox to get rid of it. There are some other files that should be searched for, and deleted, as well. See post #41 in this thread for more info: http://www.daniweb.com/techtalkforum...hotoffers.html
Links to help you help yourself :

Protect Your PC & Avoid Infections -- http://www.daniweb.com/techtalkforums/thread27519.html

Cleanup Procedures & Tools -- http://www.daniweb.com/techtalkforums/thread27570.html

Infection Removal & HijackThis Use -- http://www.daniweb.com/techtalkforums/thread28196.html
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 1
Reputation: pioppo is an unknown quantity at this point 
Solved Threads: 0
pioppo pioppo is offline Offline
Newbie Poster

Re: Specialgoods.info infection

 
0
  #7
Jun 4th, 2005
[QUOTE=tavueni]Hey notryt ,

Thanks a lot , i have kill the maleficus page!!!
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 2
Reputation: angelus88 is an unknown quantity at this point 
Solved Threads: 0
angelus88 angelus88 is offline Offline
Newbie Poster

Re: Specialgoods.info infection

 
0
  #8
Jun 4th, 2005
hey basically i got that special goods virus and i
> cnt get rid. my screen display settings were able to
> be changed bak and i ve found the param.32 file in
> my systems32. but i cnt get rid of it. i have
> windows xp on my laptop, culd u tell me step by step
> how to get rid coz im preti dumb wiv computers.
> thanks very much
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 353
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: Specialgoods.info infection

 
0
  #9
Jun 4th, 2005
Hi angelus88,

First of all- welcome to TechTalk!

We ask that members not tag their questions on to a thread previously started by another member (regardless of how similar your problem might seem). Not only does it divert the focus of the thread away from the original poster's problem, but it also makes it less likely that you yourself will get the individual attention that you need.

Please start your own thread and post your question there. When you do, please try to give us as much specific info as possible regarding the problem (exact error messages, system specs, etc.).

For a full description of our posting guidelines and general rules of conduct, please see this page:

http://www.daniweb.com/techtalkforum..._faq#faq_rules


Thanks for understanding.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote Quick reply to this message  
Join Date: Jul 2005
Posts: 1
Reputation: BaLiNkEr is an unknown quantity at this point 
Solved Threads: 0
BaLiNkEr BaLiNkEr is offline Offline
Newbie Poster

Re: Specialgoods.info infection

 
0
  #10
Jul 8th, 2005
Thank you for the information tavueni, it helped me a lot!! Luckily, in my case, I am running a dual boot system so, deleting the file took nothing more than booting to a clean OS and deleting the file. Oddly, I opted for the FAT32 installation of xp and it paid off. I'm now off to figure out how to get linux, WinMe, and WinXP to boot off the same hard drive. Again, thank you tavueni, as I was ready to format my XP partition to get rid of this nasty bug.

BaLiNkEr
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC