virus, cant get rid of...

Discussion in 'Malware Help (A Specialist Will Reply)' started by worthy22, Jul 23, 2005.

  1. worthy22

    worthy22 Private E-2

    Hey guys

    K, the situation is i have (according to Norton) a bloodhound.w32.ep virus in c:/windows/system/wininet.dll.
    My desktop has also become a big flashing advertisement to click on some link to get rid of spyware and adware, main symptom so far.

    Norton cannot get rid, I've run everything recommended in the sticky thread (adaware, spybot, spyware-blaster, ccleaner, online scans etc etc)

    Nothing has got rid of the problem so far. I have run a HiJack This scan and have the log if you need it.

    cheers
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. worthy22

    worthy22 Private E-2

    There is no dllcache folder in my system folder.
    I ran a file search and there is only one Wininet.dll on the computer.

    would downloading a replacement wininet.dll file work? I heard the virus would just return on the new one.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What OS do you have? Sounds like a Win9x or Me system. And yes wininet.dll can become reinfected.

    You can get a copy from your original CD but it is more than like compressed into a CAB file.
     
  5. worthy22

    worthy22 Private E-2

    I'm on win98.

    Following some advice from another site (Killbox and smitRem) there are no actual symptoms remaining of the virus, the active desktop has gone. And my HJT log is apparently now clean

    But Norton antivirus still spots the bloodhound.w32.ep in c:/windows/system/wininet.dll

    cheers
    Josh
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can get a copy of wininet.dll from your Win98 CD. Look in the Win98 folder and then in the WIN98_44.CAB file (you will need WinZip or similar to work look and extract files from the CAB). This CAB file should have a copy of wininet.dll. You could exract it to your c:\ folder and then you can reboot to an MSDOS command prompt and rename the infected file to something like wininet.ddd . Then you can copy the clean one from c:\wininet.dll to your c:\windows\system folder.


    Do you know how to do what I'm saying above or do you need more detail instructions?

    Get WinZip if you need it and install it.
     
  7. worthy22

    worthy22 Private E-2

    I dont have the Windows cd...yeah I know i should.

    Would downloading it to te c:/ folder than doing the same as you said work?

    If so, could you explain this a bit more...
    "reboot to an MSDOS command prompt and rename the infected file to something like wininet.ddd"

    cheers
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you do not have the CD, where are you going to get the file from? You must have the version for your OS. Do you have the CAB files on your PC already? Look in C:\windows\options\cabs
     
  9. worthy22

    worthy22 Private E-2

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! That is why I said you need the version for your OS. That is the version for current Windows XP SP2.

    Perhaps your CAB files are in a differen folder. Search for *.cab and see if you get any matches.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds