Hey notryt ,

I had the same thing and I managed to get rid of it. Here's what I did (on Windows 98 SE):

* Install and Run Spyware Guard
* Navigate to C:\Windows\System32 (possibly C:\Windows\System if in Windows XP)
* I deleted any Programs that look like they "shouldn't" be there. They all had icons for the files and ones I had were labelled "Britney Spears", "Monster C*cks" and things to that affect. There must have been about 10 files in all.
* In the same directory, there was also a file called param.dll (or something to that effect - I deleted before noting down what it was but it was the only *.dll file in that directory). If you try and delete it in Windows, it won't let you saying that it is being used.
* I then went into "pure" DOS mode (if you're using a Windows XP, try a Windows 98 SE Boot Disk - You can get one from www.bootdisk.com)
* Once in DOS mode, I navigated to the directory in DOS and typed "attrib -r -a -s -h" to remove any file permissions and then deleted the file manually using "del param.dll" (if that was the file name)
* After this, I rebooted the machine, went to Internet Options and changed the default homepage (a note from Spyguard popped up asking me if I was sure and said "Keep Value".

...and I haven't had any problems since.

I hope that helps. If you not sure or you're having trouble, feel free to drop me a line and I'll see if I can walk you through it in more detail.

tav

hey yer basically i got this special goods info virus on my computer , ive found the param file but as u say u cnt delete from system folder , im not a computer whizz atall so i dnt actually no how to navigate in DOS. i have windows xp and i downloaded a boot disk from the website. could please send a message back talking me throught the process literally step by step , thank u very much
angelus

Dani AI

Generated

This thread already has useful hands‑on notes from and troubleshooting pointers from . The following complements those replies with safe, non‑destructive steps and prevention advice that apply years later when older Windows systems are still in use.

Before deleting anything, copy personal data (documents, photos, mail) to external media and keep the PC offline. Prefer scanning from a clean environment: either run a modern on‑demand scanner from a different machine or boot the infected disk with rescue media so the malware cannot block removal. Trusted scanners with current signatures can find related components that manual file deletion misses; for a start, consider a reputable on‑demand scanner such as Malwarebytes or the Microsoft Safety Scanner.

To locate persistent items without randomly deleting files, use startup and process inspection tools to disable suspicious autoruns and services first; this is reversible and safer than blind file removal. The Sysinternals Autoruns and Process Explorer utilities are designed for that purpose: Autoruns. Also inspect the hosts file and browser settings (homepage, extensions), clear caches, and reset the browser if it remains hijacked. After cleanup, change passwords for accounts used on the machine.

If the system remains unstable or you cannot fully remove the infection, restore from a known clean image or reinstall the OS. Remember that Windows XP is unsupported and lacks current security updates, so migrate to a supported platform when possible. As recommended, capture and post a saved plaintext startup/log report (do not post personal files) so helpers can review what remains and advise targeted next steps.

Hi angelus88, welcome to DaniWeb :D

I've split your post into a new thread to prevent confusion with the other one.

Get the Pocket Killbox from here:
http://bleepingcomputer.com/files/spyware/KillBox.zip

Unzip the file to your desktop.

Go offline until this is completed (you may wish to print these instructions).

Boot into Safe Mode and do a search for these files and delete any instances found:

param32.dll
guninst.exe
popup_bl.dll
systr.dll
svrhost.exe

If any could not be deleted, (most likely param32.dll), run Pocket Killbox and paste the full file path of file in the box and click on Delete on Reboot. Click on the button with the red circle and an X in the middle; you will get a message saying File will be deleted on next reboot, Process and Reboot now?, Click Yes to reboot (normal reboot, not Safe Mode). Note: the 'file path' will be something like C:\WINDOWS\System32\param32.dll

Delete any unwanted icons from your desktop (icons you didn't put there).

Empty your Recycle Bin.

Get the self-extracting version of HijackThis from here (in line 2):
http://www.malwareremoval.com/downloads.html

Close any open browser windows, 'Scan and Save Log' with hijackthis, copy the log, and paste it here in this thread. (See this thread before posting the log -- http://www.daniweb.com/techtalkforums/thread24085.html)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.