Computing.Net > Forums > Windows XP > trojan horse startpage .19.j se.dll

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

trojan horse startpage .19.j se.dll

Reply to Message Icon

Original Message
Name: sjbmaldon
Date: May 15, 2005 at 12:54:13 Pacific
Subject: trojan horse startpage .19.j se.dll
OS: windows xp pro sp1
CPU/Ram: p 4 1.7ghz
Comment:

hi there have picked this trojan horse up somewhere but cant seem to get rid of it . have looked for file (se.dll) but it dosent seem to exist and or it denies me access. have run avg and spybot no luck. if i launch internet explorer i get the avg message of a virus clik heal then a rundll message "access is denied" in other words i havent deleted the file .. can anybody help.. i am on another computer at the mo.


Report Offensive Message For Removal


Response Number 1
Name: Abnormal
Date: May 15, 2005 at 13:52:57 Pacific
Reply: (edit)

Download
http://www.derbilk.de/SpSeHjfix112.zip
to the desktop and then right-click a blank part of desktop & select new folder, call it spfix and unzip the file into that folder.

Disconnect from the net and close all open programs.
Go to safe mode.

Run 'SpSeHjfix'. and click on "Start Disinfection".
When it's finished it will reboot your machine to finish the cleaning process.

Good luck


Report Offensive Follow Up For Removal

Response Number 2
Name: Rich Mentzel
Date: May 15, 2005 at 13:56:41 Pacific
Reply: (edit)

Try Hijack this:
http://www.majorgeeks.com/download3155.html
if thast doesn't do it go to free online virus checker from Trend Micro:
housecall.trendmicro.com


Report Offensive Follow Up For Removal

Response Number 3
Name: traceyrich
Date: May 16, 2005 at 05:42:26 Pacific
Reply: (edit)

i had this problem. this is what i did, first i launched task manager and found the suspect file in processes, i then stop this running and then i was able to go and delete it without it saying access denied. no more problems since


Report Offensive Follow Up For Removal

Response Number 4
Name: Gia
Date: June 4, 2005 at 16:36:56 Pacific
Reply: (edit)

Hey guys! im in deep trouble b'coz of trojan horse startpage.19.j se.dll. It did the following to my laptop:
IE's home page was set to a search engine
Many IE's started opening by themselves...around 20-30 browsers at the same time creating a big havoc.I couldnt even get to open task manager at that time, had to either log off or reboot.

I downloaded AVG 7.0 pro, ran a scan to find out the trojan horse, clicked on heal...it said healed but in the virus vault the files still exists saying they are infected & is a backup copy. path is c:\document and settings\administrator\local settings\temp\se.dll

Then, I looked up on the net & found this out. Followed the solution and downloaded
http://www.derbilk.de/SpSeHjfix112.zip & did the steps as mentioned.

however now when i have rebooted from safe to normal mode, in this now I'am unable to open internet explorer itself. Ths is my broadband brower, thru which im writing. the log after disinfection from safe mode was:


(6/5/05 3:59:54 AM) SPSeHjFix started v1.1.2
(6/5/05 3:59:54 AM) OS: Win2000 Service Pack 4 (5.0.2195)
(6/5/05 3:59:54 AM) Language: english
(6/5/05 3:59:54 AM) Win-Path: C:\WINNT
(6/5/05 3:59:54 AM) System-Path: C:\WINNT\system32
(6/5/05 3:59:54 AM) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\


(6/5/05 4:04:39 AM) SPSeHjFix started v1.1.2
(6/5/05 4:04:39 AM) OS: Win2000 Service Pack 4 (5.0.2195)
(6/5/05 4:04:39 AM) Language: english
(6/5/05 4:04:39 AM) Win-Path: C:\WINNT
(6/5/05 4:04:39 AM) System-Path: C:\WINNT\system32
(6/5/05 4:04:39 AM) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
(6/5/05 4:04:40 AM) Disinfection started
(6/5/05 4:04:40 AM) Bad-Dll(IEP): c:\docume~1\admini~1\locals~1\temp\se.dll
(6/5/05 4:04:40 AM) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINNT\system32\jplb.dll
(6/5/05 4:04:40 AM) Searchassistant Uninstaller - Keys Deleted
(6/5/05 4:04:40 AM) UBF: 6 - UBB: 5 - UBR: 23
(6/5/05 4:04:40 AM) FilterKey: HKCR\text/html (deleted)
(6/5/05 4:04:40 AM) FilterKey: HKCR\CLSID\{E7044E28-66DA-41E2-B434-CEFC481717CA} (deleted)
(6/5/05 4:04:40 AM) FilterKey: HKLM\SOFTWARE\Classes\text/html (error while deleting)
(6/5/05 4:04:40 AM) FilterKey: HKCR\text/plain (deleted)
(6/5/05 4:04:40 AM) FilterKey: HKCR\CLSID\{E7044E28-66DA-41E2-B434-CEFC481717CA} (error while deleting)
(6/5/05 4:04:40 AM) FilterKey: HKLM\SOFTWARE\Classes\text/plain (error while deleting)
(6/5/05 4:04:40 AM) BHO-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F42D829A-2AE6-415B-9A36-B0753740C9D5} (deleted)
(6/5/05 4:04:40 AM) BHO-Key: HKCR\CLSID\{F42D829A-2AE6-415B-9A36-B0753740C9D5} (deleted)
(6/5/05 4:04:40 AM) Run-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\sp=rundll32 C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll,DllInstall (deleted)
(6/5/05 4:04:40 AM) UBF: 4 - UBB: 4 - UBR: 22
(6/5/05 4:04:40 AM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\admini~1\locals~1\temp\se.dll/spage.html
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\admini~1\locals~1\temp\se.dll/spage.html
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(6/5/05 4:04:40 AM) Stealth-String not found
(6/5/05 4:04:40 AM) File added to delete: c:\winnt\system32\jplb.dll
(6/5/05 4:04:40 AM) File added to delete: c:\docume~1\admini~1\locals~1\temp\se.dll
(6/5/05 4:04:40 AM) Reboot


(6/5/05 4:15:39 AM) SPSeHjFix started v1.1.2
(6/5/05 4:15:39 AM) OS: Win2000 Service Pack 4 (5.0.2195)
(6/5/05 4:15:39 AM) Language: english
(6/5/05 4:15:39 AM) Win-Path: C:\WINNT
(6/5/05 4:15:39 AM) System-Path: C:\WINNT\system32
(6/5/05 4:15:39 AM) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
(6/5/05 4:15:44 AM) Disinfection started
(6/5/05 4:15:44 AM) Bad-Dll(IEP): (not found)
(6/5/05 4:15:44 AM) Bad-Dll(IEP) in BHO: (not found)
(6/5/05 4:15:44 AM) UBF: 4 - UBB: 4 - UBR: 23
(6/5/05 4:15:44 AM) UBF: 4 - UBB: 4 - UBR: 23
(6/5/05 4:15:44 AM) Bad IE-pages: (none)
(6/5/05 4:15:44 AM) Stealth-String not found
(6/5/05 4:15:44 AM) Not infected->END

after which, as i said now, my IE doesnt open anymore.

plz anyone help me out..i've windows 2000 pro on HP Laptop. dunoo wot to do????plz help

thx a ton:
Gia


Report Offensive Follow Up For Removal

Response Number 5
Name: Abnormal
Date: June 7, 2005 at 19:11:36 Pacific
Reply: (edit)

Hi Gia, sorry for the late answer.

On a few occasions it has been reported that after using the SPSEHjfix you cannot open Internet Explorer.
To fix this, go into Control Panel >Internet Options >Programs & press reset web settings, then you can set your home page to what you want on the general tab.


Report Offensive Follow Up For Removal


Response Number 6
Name: AMBLY
Date: June 21, 2005 at 04:49:42 Pacific
Reply: (edit)

Just want to say "Thanx". I had the startpage.19.jse.dll trojan, identified by my AVG Virus checker, and used the advice here to disinfect my PC (after trying Adware) - I used "Abnormal's SPSEHjfix. Can't believe how quick to set up & then how fast it did the job!
Thanx again :-))


Report Offensive Follow Up For Removal






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows XP Forum Home








Do you own an iPhone?

Yes
No, but soon
No


View Results

Poll Finishes In 7 Days.
Discuss in The Lounge
Poll History




Data Recovery Software