Options

Help Required - 2 unremoveable Trojans?

Hi all - I have got two issues I need some help with.

Firstly, my internet explorer home page has been hi jacked with a dll I cannot access or remove (res://C:\WINDOWS\system32\shdocsv.dll/API32.htm#ID=347;065D) - it displays an advert for spyware. (Evidence Eliminator)

Secondly, my desktop has also been hi-jacked by another spyware system(http://www.antivirus-gold.com/?wm=&swm=), which has loaded a screen.html document into my C:\Windows.

I have tried using Hi-Jacksoftware (as presented in these threads) but tono avail. Can anybody help?

Comments

  • NLichtmanNLichtman Spring Valley, CA
    edited July 2005
    I think that you may be able to fix this problem by disabling the programs. I'm not sure of the names of the programs but if you could find out where they are located on your computer or even a general direction. I could help you from there.
  • edited July 2005
  • NLichtmanNLichtman Spring Valley, CA
    edited July 2005
    Can you access your control panel?
  • edited July 2005
    Yes - like I say I have fixed the desktop issue - although I have an exe file called gdbj.exe that caused the problem left in my Temp file - and I cannot delete it.

    The issue remaining is the home page for IE - I have since downloaded firefox as a temporary solution - but obviously not perfect.
  • NLichtmanNLichtman Spring Valley, CA
    edited July 2005
    I use Firefox. Firefox is the perfect solution. Rants on...lol

    Anyway...
    Do you use Adaware? I think that Adaware may let you delete it.

    The IE problem.. is a little tougher... Do you know the name of the program that causes this problem? Do you know where it is located on you computer?

    EDIT: I hope that I don't get into trouble for this...

    EDIT AGAIN: I wonder why Buckeye-Sam hasn't posted here yet... :scratch:
  • edited July 2005
    Hi yes - the problem is caused by an 'invisible dll' located in C:\Windows.

    It is also calling an API called API32.htm. But is cannot locate this (ive performed a search, and found one in the Temp directory, deleted it, but the problem was still there.)

    I can locate the dll through the command line, but it is read only. I have started the computer in safe mode, but it is still in read only mode there aswell.

    Im confused!
  • Buckeye_SamBuckeye_Sam Columbus, Ohio
    edited July 2005
    We need to get a look at what's running on your computer in order to help you. Please follow the directions at this link to download a tool called Hijackthis and post a log.

    http://www.short-media.com/forum/showpost.php?p=172584&postcount=2
Sign In or Register to comment.