Hey guys! im in deep trouble b'coz of trojan horse startpage.19.j se.dll. It did the following to my laptop:
IE's home page was set to a search engine
Many IE's started opening by themselves...around 20-30 browsers at the same time creating a big havoc.I couldnt even get to open task manager at that time, had to either log off or reboot.
I downloaded AVG 7.0 pro, ran a scan to find out the trojan horse, clicked on heal...it said healed but in the virus vault the files still exists saying they are infected & is a backup copy. path is c:\document and settings\administrator\local settings\temp\se.dll
Then, I looked up on the net & found this out. Followed the solution and downloaded
http://www.derbilk.de/SpSeHjfix112.zip & did the steps as mentioned.
however now when i have rebooted from safe to normal mode, in this now I'am unable to open internet explorer itself. Ths is my broadband brower, thru which im writing. the log after disinfection from safe mode was:
(6/5/05 3:59:54 AM) SPSeHjFix started v1.1.2
(6/5/05 3:59:54 AM) OS: Win2000 Service Pack 4 (5.0.2195)
(6/5/05 3:59:54 AM) Language: english
(6/5/05 3:59:54 AM) Win-Path: C:\WINNT
(6/5/05 3:59:54 AM) System-Path: C:\WINNT\system32
(6/5/05 3:59:54 AM) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
(6/5/05 4:04:39 AM) SPSeHjFix started v1.1.2
(6/5/05 4:04:39 AM) OS: Win2000 Service Pack 4 (5.0.2195)
(6/5/05 4:04:39 AM) Language: english
(6/5/05 4:04:39 AM) Win-Path: C:\WINNT
(6/5/05 4:04:39 AM) System-Path: C:\WINNT\system32
(6/5/05 4:04:39 AM) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
(6/5/05 4:04:40 AM) Disinfection started
(6/5/05 4:04:40 AM) Bad-Dll(IEP): c:\docume~1\admini~1\locals~1\temp\se.dll
(6/5/05 4:04:40 AM) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINNT\system32\jplb.dll
(6/5/05 4:04:40 AM) Searchassistant Uninstaller - Keys Deleted
(6/5/05 4:04:40 AM) UBF: 6 - UBB: 5 - UBR: 23
(6/5/05 4:04:40 AM) FilterKey: HKCR\text/html (deleted)
(6/5/05 4:04:40 AM) FilterKey: HKCR\CLSID\{E7044E28-66DA-41E2-B434-CEFC481717CA} (deleted)
(6/5/05 4:04:40 AM) FilterKey: HKLM\SOFTWARE\Classes\text/html (error while deleting)
(6/5/05 4:04:40 AM) FilterKey: HKCR\text/plain (deleted)
(6/5/05 4:04:40 AM) FilterKey: HKCR\CLSID\{E7044E28-66DA-41E2-B434-CEFC481717CA} (error while deleting)
(6/5/05 4:04:40 AM) FilterKey: HKLM\SOFTWARE\Classes\text/plain (error while deleting)
(6/5/05 4:04:40 AM) BHO-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F42D829A-2AE6-415B-9A36-B0753740C9D5} (deleted)
(6/5/05 4:04:40 AM) BHO-Key: HKCR\CLSID\{F42D829A-2AE6-415B-9A36-B0753740C9D5} (deleted)
(6/5/05 4:04:40 AM) Run-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\sp=rundll32 C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll,DllInstall (deleted)
(6/5/05 4:04:40 AM) UBF: 4 - UBB: 4 - UBR: 22
(6/5/05 4:04:40 AM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\admini~1\locals~1\temp\se.dll/spage.html
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\admini~1\locals~1\temp\se.dll/spage.html
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(6/5/05 4:04:40 AM) Stealth-String not found
(6/5/05 4:04:40 AM) File added to delete: c:\winnt\system32\jplb.dll
(6/5/05 4:04:40 AM) File added to delete: c:\docume~1\admini~1\locals~1\temp\se.dll
(6/5/05 4:04:40 AM) Reboot
(6/5/05 4:15:39 AM) SPSeHjFix started v1.1.2
(6/5/05 4:15:39 AM) OS: Win2000 Service Pack 4 (5.0.2195)
(6/5/05 4:15:39 AM) Language: english
(6/5/05 4:15:39 AM) Win-Path: C:\WINNT
(6/5/05 4:15:39 AM) System-Path: C:\WINNT\system32
(6/5/05 4:15:39 AM) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
(6/5/05 4:15:44 AM) Disinfection started
(6/5/05 4:15:44 AM) Bad-Dll(IEP): (not found)
(6/5/05 4:15:44 AM) Bad-Dll(IEP) in BHO: (not found)
(6/5/05 4:15:44 AM) UBF: 4 - UBB: 4 - UBR: 23
(6/5/05 4:15:44 AM) UBF: 4 - UBB: 4 - UBR: 23
(6/5/05 4:15:44 AM) Bad IE-pages: (none)
(6/5/05 4:15:44 AM) Stealth-String not found
(6/5/05 4:15:44 AM) Not infected->END
after which, as i said now, my IE doesnt open anymore.
plz anyone help me out..i've windows 2000 pro on HP Laptop. dunoo wot to do????plz help
thx a ton:
Gia