| | |
Specialgoods.info infection
![]() |
•
•
Join Date: May 2005
Posts: 2
Reputation:
Solved Threads: 0
•
•
•
•
Originally Posted by tavueni
Hey notryt ,
I had the same thing and I managed to get rid of it. Here's what I did (on Windows 98 SE):
* Install and Run Spyware Guard
* Navigate to C:\Windows\System32 (possibly C:\Windows\System if in Windows XP)
* I deleted any Programs that look like they "shouldn't" be there. They all had icons for the files and ones I had were labelled "Britney Spears", "Monster C*cks" and things to that affect. There must have been about 10 files in all.
* In the same directory, there was also a file called param.dll (or something to that effect - I deleted before noting down what it was but it was the only *.dll file in that directory). If you try and delete it in Windows, it won't let you saying that it is being used.
* I then went into "pure" DOS mode (if you're using a Windows XP, try a Windows 98 SE Boot Disk - You can get one from www.bootdisk.com)
* Once in DOS mode, I navigated to the directory in DOS and typed "attrib -r -a -s -h" to remove any file permissions and then deleted the file manually using "del param.dll" (if that was the file name)
* After this, I rebooted the machine, went to Internet Options and changed the default homepage (a note from Spyguard popped up asking me if I was sure and said "Keep Value".
...and I haven't had any problems since.
I hope that helps. If you not sure or you're having trouble, feel free to drop me a line and I'll see if I can walk you through it in more detail.
tav
angelus
•
•
Join Date: Jul 2004
Posts: 2,964
Reputation:
Solved Threads: 209
Hi angelus88, welcome to DaniWeb 
I've split your post into a new thread to prevent confusion with the other one.
Get the Pocket Killbox from here:
http://bleepingcomputer.com/files/spyware/KillBox.zip
Unzip the file to your desktop.
Go offline until this is completed (you may wish to print these instructions).
Boot into Safe Mode and do a search for these files and delete any instances found:
param32.dll
guninst.exe
popup_bl.dll
systr.dll
svrhost.exe
If any could not be deleted, (most likely param32.dll), run Pocket Killbox and paste the full file path of file in the box and click on Delete on Reboot. Click on the button with the red circle and an X in the middle; you will get a message saying File will be deleted on next reboot, Process and Reboot now?, Click Yes to reboot (normal reboot, not Safe Mode). Note: the 'file path' will be something like C:\WINDOWS\System32\param32.dll
Delete any unwanted icons from your desktop (icons you didn't put there).
Empty your Recycle Bin.
Get the self-extracting version of HijackThis from here (in line 2):
http://www.malwareremoval.com/downloads.html
Close any open browser windows, 'Scan and Save Log' with hijackthis, copy the log, and paste it here in this thread. (See this thread before posting the log -- http://www.daniweb.com/techtalkforums/thread24085.html)

I've split your post into a new thread to prevent confusion with the other one.
Get the Pocket Killbox from here:
http://bleepingcomputer.com/files/spyware/KillBox.zip
Unzip the file to your desktop.
Go offline until this is completed (you may wish to print these instructions).
Boot into Safe Mode and do a search for these files and delete any instances found:
param32.dll
guninst.exe
popup_bl.dll
systr.dll
svrhost.exe
If any could not be deleted, (most likely param32.dll), run Pocket Killbox and paste the full file path of file in the box and click on Delete on Reboot. Click on the button with the red circle and an X in the middle; you will get a message saying File will be deleted on next reboot, Process and Reboot now?, Click Yes to reboot (normal reboot, not Safe Mode). Note: the 'file path' will be something like C:\WINDOWS\System32\param32.dll
Delete any unwanted icons from your desktop (icons you didn't put there).
Empty your Recycle Bin.
Get the self-extracting version of HijackThis from here (in line 2):
http://www.malwareremoval.com/downloads.html
Close any open browser windows, 'Scan and Save Log' with hijackthis, copy the log, and paste it here in this thread. (See this thread before posting the log -- http://www.daniweb.com/techtalkforums/thread24085.html)
Links to help you help yourself :
Protect Your PC & Avoid Infections -- http://www.daniweb.com/techtalkforums/thread27519.html
Cleanup Procedures & Tools -- http://www.daniweb.com/techtalkforums/thread27570.html
Infection Removal & HijackThis Use -- http://www.daniweb.com/techtalkforums/thread28196.html
Protect Your PC & Avoid Infections -- http://www.daniweb.com/techtalkforums/thread27519.html
Cleanup Procedures & Tools -- http://www.daniweb.com/techtalkforums/thread27570.html
Infection Removal & HijackThis Use -- http://www.daniweb.com/techtalkforums/thread28196.html
![]() |
Similar Threads
- Specialgoods.info infection (Viruses, Spyware and other Nasties)
- specialgoods.info infection (Viruses, Spyware and other Nasties)
Other Threads in the Viruses, Spyware and other Nasties Forum
- Previous Thread: I need guidance on HSA/SE/SW (Who doesnt?)
- Next Thread: NEW Hijackthis log and worries
| Thread Tools | Search this Thread |
adware anti-malware anti-virussitesaccessissue antivirus apple attack audio avg backtoschoolspeech bar blackhat botnet botnets censorship china commercial commercials conficker connect control crosssitescripting cyber cybercrime cyberwarfare ddos domains e-mafia education email europe exam exploit facebook fake fancheckvirus gaming gumblar halloween hijack hosting internet iphone kaspersky legal logfiles mail malware mcafee mega-d messagelabs microsoft mobile msn nazi news obama onlinethreats panel parents patch phishing police policeprovirusmba-mblockedinternetaccess president privacy pro problem redirect redirecting reliability report research risk rogueantivirus sans scareware school search security seopoisoning software spam spyware spywareexternalwindows7adminstratortrojans sqlinjection symantec system teen trojan unabletoaccessanti-virussites unwanted update usa virus viruses vista warning windows worm yahoo






