Specialgoods.info infection

Reply

Join Date: May 2005
Posts: 2
Reputation: angelus88 is an unknown quantity at this point 
Solved Threads: 0
angelus88 angelus88 is offline Offline
Newbie Poster

Re: Specialgoods.info infection

 
0
  #1
May 26th, 2005
Originally Posted by tavueni
Hey notryt ,

I had the same thing and I managed to get rid of it. Here's what I did (on Windows 98 SE):

* Install and Run Spyware Guard
* Navigate to C:\Windows\System32 (possibly C:\Windows\System if in Windows XP)
* I deleted any Programs that look like they "shouldn't" be there. They all had icons for the files and ones I had were labelled "Britney Spears", "Monster C*cks" and things to that affect. There must have been about 10 files in all.
* In the same directory, there was also a file called param.dll (or something to that effect - I deleted before noting down what it was but it was the only *.dll file in that directory). If you try and delete it in Windows, it won't let you saying that it is being used.
* I then went into "pure" DOS mode (if you're using a Windows XP, try a Windows 98 SE Boot Disk - You can get one from www.bootdisk.com)
* Once in DOS mode, I navigated to the directory in DOS and typed "attrib -r -a -s -h" to remove any file permissions and then deleted the file manually using "del param.dll" (if that was the file name)
* After this, I rebooted the machine, went to Internet Options and changed the default homepage (a note from Spyguard popped up asking me if I was sure and said "Keep Value".

...and I haven't had any problems since.

I hope that helps. If you not sure or you're having trouble, feel free to drop me a line and I'll see if I can walk you through it in more detail.

tav
hey yer basically i got this special goods info virus on my computer , ive found the param file but as u say u cnt delete from system folder , im not a computer whizz atall so i dnt actually no how to navigate in DOS. i have windows xp and i downloaded a boot disk from the website. could please send a message back talking me throught the process literally step by step , thank u very much
angelus
Reply With Quote Quick reply to this message  
Join Date: Jul 2004
Posts: 2,964
Reputation: dlh6213 is on a distinguished road 
Solved Threads: 209
Team Colleague
dlh6213 dlh6213 is offline Offline
Posting Maven

Re: Specialgoods.info infection

 
0
  #2
May 26th, 2005
Hi angelus88, welcome to DaniWeb

I've split your post into a new thread to prevent confusion with the other one.

Get the Pocket Killbox from here:
http://bleepingcomputer.com/files/spyware/KillBox.zip

Unzip the file to your desktop.

Go offline until this is completed (you may wish to print these instructions).

Boot into Safe Mode and do a search for these files and delete any instances found:

param32.dll
guninst.exe
popup_bl.dll
systr.dll
svrhost.exe


If any could not be deleted, (most likely param32.dll), run Pocket Killbox and paste the full file path of file in the box and click on Delete on Reboot. Click on the button with the red circle and an X in the middle; you will get a message saying File will be deleted on next reboot, Process and Reboot now?, Click Yes to reboot (normal reboot, not Safe Mode). Note: the 'file path' will be something like C:\WINDOWS\System32\param32.dll

Delete any unwanted icons from your desktop (icons you didn't put there).

Empty your Recycle Bin.

Get the self-extracting version of HijackThis from here (in line 2):
http://www.malwareremoval.com/downloads.html

Close any open browser windows, 'Scan and Save Log' with hijackthis, copy the log, and paste it here in this thread. (See this thread before posting the log -- http://www.daniweb.com/techtalkforums/thread24085.html)
Links to help you help yourself :

Protect Your PC & Avoid Infections -- http://www.daniweb.com/techtalkforums/thread27519.html

Cleanup Procedures & Tools -- http://www.daniweb.com/techtalkforums/thread27570.html

Infection Removal & HijackThis Use -- http://www.daniweb.com/techtalkforums/thread28196.html
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC