Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Please Help, I am infected with BloodHound


  • This topic is locked This topic is locked

#1
khurramsh22

khurramsh22

    New Member

  • Member
  • Pip
  • 6 posts
Hi

Hope you will be helping me.

I have Windows98. I am infected with BloodHound. Please help me in this matter. somehow I figure out that one of the culprits is Intel32.exe i have deleted it (I don't know whether it is deleted completely, window's message of deletion said yes it is deleted). But it has infected my system file "wininet.dll". my norton antivirus has quarantine this file. So I am having troubles now.

First I saw icon on my task bar, saying my computer is infectedwith virus. Then something happened and I have to restart.

When I restarted computer's wallpaper was overridden by a message that your system is still volunerable to trojons/spys... click here to save your computer (something like). But I didn't click (wisely I think), and somehow manage to change it to my original wallpaper.

Now I could not find Wininet.dll any where to copy it. I am having troubles with internet. Many application are not starting like Jet Audiio, Windows Media Player, MSN Messenger, Yahoo Messenger, etc. The desktop properties showing only three tabs (ScreenSaver, Effects, DisplaySetting). Also the properties of internet explorer shows some infections. There use to be an option in IE properties where we can set the size of "Temporary Internet Files" folder, it doesn't allow me to enter any value other that 0 to 1 (allow me enter nothing). And also the fear of lossing data from PC.

I was thinking of copying Wininet.dll from some other PC with windows 98 and paste it in my pc in the folder c:\windows\system. Will it work please tell?

Please suggest me how to get rid of it completely.

anxiously waiting for reply
regards
Khurram
  • 0

Advertisements


#2
Retired Tech

Retired Tech

    Retired Staff

  • Retired Staff
  • 20,563 posts
Please go here:

http://www.geekstogo..._Log-t2852.html

Run all the programmes as advised then post a current Hijack This Log to the Malware Team
  • 0

#3
khurramsh22

khurramsh22

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hi,
Thanks for your help. I think I have done everything that has to be done before sending this logfile of HijackThis.

After I restarted I found my computer is working much better. Thanks for that. Just a little problem (thats what I think). i.e. whenever I open a folder (my computer) or starts msn or yahoo messengers, there comes a msg on windows msg box that access denied for the file "c:\windows\temp\se.dll". i think it is tried to be started. Actually it is not present in this folder temp. But then after this msg box, a msg box appears from avg antivirus that a virus found and an infected file is "se.dll". When I asked the antivirus to heal this file, it did it successfully. Screen captures of both messages are attached. Please help me.

Following is the log file details after dashed line.
----------------------------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 1:42:02 AM, on 8/5/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2479.0006)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\A4TECH\MOUSE\AMOUMAIN.EXE
C:\PROGRAM FILES\TROJANHUNTER 4.2\THGUARD.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\OPERA7\OPERA.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/space.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/space.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
F1 - win.ini: run=hpfsched
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\ACROBAT\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {A42DD1E1-03D3-11DA-9FE6-009033CB1AE7} - C:\WINDOWS\SYSTEM\BABJ.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [WheelMouse] C:\PROGRA~1\A4TECH\MOUSE\AMOUMAIN.EXE
O4 - HKLM\..\Run: [DU Meter] C:\PROGRAM FILES\DU METER\DUMETER.EXE
O4 - HKLM\..\Run: [ICSMGR] ICSMGR.EXE
O4 - HKLM\..\Run: [THGuard] "C:\PROGRAM FILES\TROJANHUNTER 4.2\THGUARD.EXE"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRAM FILES\YAHOO!\MESSENGER\ypager.exe" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER 7\MSNMSGR.EXE" /background
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.5.0\bin\npjpi150.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O12 - Plugin for .spop: C:\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .mov: C:\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mp4: C:\INTERN~1\PLUGINS\npqtplugin4.dll
O18 - Filter: text/html - {25C6C5C0-052A-11DA-9FE6-00903C337947} - C:\WINDOWS\SYSTEM\BABJ.DLL
O18 - Filter: text/plain - {25C6C5C0-052A-11DA-9FE6-00903C337947} - C:\WINDOWS\SYSTEM\BABJ.DLL

Attached Files


  • 0

#4
Retired Tech

Retired Tech

    Retired Staff

  • Retired Staff
  • 20,563 posts
Post the log to the malware forum, they will advise you
  • 0

#5
khurramsh22

khurramsh22

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hi again,

Please help me. I have posted my HiJackThis Log for very long, but no one has replied me. Please reply me. I am waiting for anxiously. I am having troubles with my PC. I don't want to format my hard disk to remove the viruses. So please ask someone to reply me.

Regards
Khurram
  • 0

#6
Retired Tech

Retired Tech

    Retired Staff

  • Retired Staff
  • 20,563 posts
Run these while you are waiting

http://www.pandasoft...n_principal.htm

http://housecall60.t.../start_corp.asp

The Malware Team will get back to you as soon as
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP