New member -se.dll - help with hijackthis log

Discussion in 'Malware Help (A Specialist Will Reply)' started by mvckti, Mar 11, 2005.

  1. mvckti

    mvckti Private E-2

    I have ran adaware, spybot, norton av but each time I open a browser page the Norton realtime picks up virus and windows pops up error message cant find se.dll as it has been quarantined. I have emptied all temp folders and recycle bin. Also spybot seems to pick up the same 5 DSO each time I restart it. I can get onto other websites but each time I go to the windows update site it redirects me to about blank... the hijacked hompage. Please help with the hijackthis log below. Thankyou!!

    Logfile of HijackThis v1.99.1
    Scan saved at 18:02:29, on 10/03/2005
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Edit by chaslang: Unrequested inline log removed
     
    Last edited by a moderator: Mar 11, 2005
  2. TheOldThug

    TheOldThug First Sergeant

    Welcome :)

    We ask that you please follow our procedure here. A HJT log is not the first step. Please follow the TUTORIAL listed below. When asked to post a HJT log it must not be inline but rather a .log or .txt file. Also make sure that HJT is placed in it's own folder and not run from a zipped file. Read the HJT Tutorial before submitting or running it.

    This site has alot of good tools for cleaning up your computer. It's very important that the first thing you do is the following:

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal.
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    Try this... you may find it's all you need. If not post your results and I am sure one of the PROS can help you. These guys are quite busy, as you can see by the number of posts, so hang in there. Good Luck!! :)

    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99.1 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, INCLUDING YOUR WEB BROWSER, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder for example C:\Program Files\HJT
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Doing what TheOldThug requested will help get you started. If you follow the steps there completely, it will resolve the DSO Exploits you are seeing from Spybot.

    You should also look in Add/Remove programs for uninstalls to the below and uninstall if found:
    QuickSearch or QuickSearchBar

    Is the next R1 line setting below required? Do you use a proxy server?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.253.44:8080

    Also do you know why the below is configured?
    O1 - Hosts: 200.1.10.6 HLSERVER

    That IP address is for:
    200.1.10.6 = [ ]

    inetnum: 200.1.8/21
    status: assigned
    owner: Electricidad de Caracas
    ownerid: VE-ELCA-LACNIC
    responsible: Yelitza Zambrano
    address: San Bernardino Avd. Vollmer Edif. EDC Caracas 99999 99
    address: 1010 - Caracsas - DF
    country: VE
    phone: 0058 0212 5021047 [1047]
    owner-c: YEZ
    tech-c: YEZ
    created: 19930907
    changed: 19981009
    nic-hdl: YEZ
    person: Yelitza Zambrano
    e-mail: yelitza.zambrano@AES.COM


    Then please do the following:
    1) go here and download Registrar lite and install it: http://www.majorgeeks.com/download469.html
    2) Run it, copy and paste this line to reglite's address bar:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
    3) Click the "go" tab
    4) Find: "AppInit_Dlls" value on the right side panel.
    5) DoubleClick on AppInit_Dlls and tell me exactly what you see in the Value field:
     
    Last edited: Mar 11, 2005

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds