Temp\se.dll/sp.html - BJ & chaslang discussion

Discussion in 'Malware Help (A Specialist Will Reply)' started by bjgarrick, Feb 24, 2005.

Thread Status:
Not open for further replies.
  1. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Re: Could someone pls look at my hijackthis log?

    You still have the about:blank hijacker. Please go thru this sticky thread again.

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    Be sure you run About:Buster & HSRemove.

    After you have completed this, then post a new log.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Could someone pls look at my hijackthis log?

    BJ,

    Tyrus already stated that the READ ME was run.

    About:Buster & Hsremove while useful for somethings, will not fix the problems in this log.
     
  3. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Re: Could someone pls look at my hijackthis log?

    Just starting at the beginning and taking things one at a time, like I was requested to. Sorry! Just thought he may have skipped something or didnt do something complete as most do. Thought doing it twice would help.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Could someone pls look at my hijackthis log?

    That's okay but but Tyrus said he did the steps. Also HSremove does not address about blank issues accept for when it is an HSA related about:blank hijack which this is not. Also About:Buster does not work on this type either.
     
  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Re: Could someone pls look at my hijackthis log?

    Thanks for the info:)

    Also, May I ask how can you tell?

    I thought the se.dll/sp.html was about:blank symptoms?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Could someone pls look at my hijackthis log?

    It is a type of about blank but not the type About:Buster works on. You have to read info on about:buster to know this. It only works on certain types. The ones that look more like a typcial HSA hijack. It does not hurt to run AB! There could be other stuff hidden in there too that you just cannot see yet. You cannot always see everything. I even tried using AB embedded in some other steps on some of these se.dll infections lately. I did it just to see if the new AB database improved anything. Mutliple runs with AB found absolutely nothing.

    The below lines are also not typical of an HSA style hijack. Notice the DLLinstall too and it is loaded with rundll32.

    O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\KENNETH\LOCALS~1\Temp\se.dll,DllInstall
    O18 - Filter: text/html - {A9B1F227-239D-41D9-B9FD-1B0F3F7DA47C} - C:\WINDOWS\system32\nhccca.dll
    O18 - Filter: text/plain - {A9B1F227-239D-41D9-B9FD-1B0F3F7DA47C} - C:\WINDOWS\system32\nhccca.dll

    You may find that when trying to fix this, it will keep coming back after reboot and a connect to the internet. You may also find things get worse (more problems appear).

    This may be a case for Kapersky AV and possibly a run of the updated MS Antispyware. Symantec AV finds se.dll but does nothing to help fix the problem. I have a feeling that explorer.exe is infected (that's where Kapersky comes in).
     
  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Re: Could someone pls look at my hijackthis log?

    Ah! This will be very helpful in the future.
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Re: Could someone pls look at my hijackthis log?

    Would you like to remove all our post and make one post with instructions so that this user wont get confused? :p
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Could someone pls look at my hijackthis log?

    I'll remove down to message #3 . I would like you to work thru this thread. Good experience. Some of these are easier than others. I don't know why but that is typical of these infections. Sometimes they are easier when they are found early before they spread themselves out too much.

    So after you read and respond to this I'll delete our exchange. I could also move them to another thread if you want to keep it around for any reference.
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Re: Could someone pls look at my hijackthis log?

    If my instructions in post 2 wont help then on this particular variant, then they can be removed :confused:

    Where do you think or want me to start at, HJT and removing the files?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Could someone pls look at my hijackthis log?

    Tyrus is already back! Look at the HJT log in the first post and pick it up from there.
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Re: Could someone pls look at my hijackthis log?

    Ok, ill start the post, you can go ahead and remove these!
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds