My IE got infected with some strange file.. its changed the default page to C:\WINDOWS\system32\shdocpl.dll this isnt the normal dll file that comes when the page doesnt exist, but some crapass spyware version of it.
I opened it in notepad and rewrote it only to find that i couldn’t save it because it was a hidden, read only file.
How do i remove these tags?
Even i click on view even hidden files it doesnt show up.
I also went to DOS and tried -h c:\WINDOWS\system32\shdocpl.dll which will normally change the hidden attribute to off. Even that didn’t work.
How can i delete or unhide or un-readonly this file?
Logfile of HijackThis v1.99.1
Scan saved at 11:42:53 AM, on 4/3/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
(have to go out hence answering in short)
These 3 entries definitely need to be fixed.
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://C:\WINDOWS\system32\shdocpl.dll/security.htm#subID=MPV;401
O4 - HKLM..\Run: [FastStart] C:\WINDOWS\system32\svcnut.exe home
most probably this svcnut.exe is the culprit.
for removal instructions use google. (u will have to disable this first from the task manager first before attempting its removal else it will return i guess.)
right.. i took out svcnut. (shift+del) following google instructions.but the crap is still there.
how do i remove the other entries?
should i run hijack this to see if svcnut is still there somehow?
You can download it from here mate,note that you need to have a genuine check before you can download it,by that i mean you have to have an original copy of Windows.
Try it,if it doesnt help just post here and we will help you further.
@ice , i had already suggested that. see the 2nd post in this thread.
@ alchemist,
Kindly post what you have done till now w.r.t to removing the svcnut.exe
Give a complete and comprehensive steps you took to remove it. if you give short, 2 sentence replies you should expect 2 words solutions. please remember this.
sorry.
after you told me to google svcnut.exe i came across advice that said end the process and then delete. it didn’t work. also, those popups that started coming. ive posted a scrn shot a few posts before.
then, on urs and icefusion’s advice i dled and ran antipyware. it deleted a few more registry items etc. but it still persisted.
i then followed the steps to correct ie hijack which said that it had succesfully worked but on running ie, same problem.
as this file is hidden, is it possible that all these apps are not scanning it?
deejay, now ill follow the suggestion of urs to reboot in safe mode and delete the items you posted in red.
SUCCESS!!
deejay, i did what you told me to without restarting though. and ie now starts with about:blank.
now i’ll just reboot and see if the fix is permanent.. thanks all of you guys.. thanks a lot
Alchemist, that’s (pic attached) messenger service (do not confuse with windows messenger) poping up. It’s a spam message. It simply means u hve not installed sp2, messenger service by default is running (or enabled by some spyware), u hve no firewall and the above service is used to deliver spam messages.
pls disable the messenger service as followed
type “services.msc”, without quotes in the “start menu”–> run box, hit enter.
Now, look for a service named “messenger” with description as follows “Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this service is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start.”
Double click on it and stop the service by hitting the stop b utton.
then, from “startup type” chose “manual” (or disable) and hit "apply’, “ok”.
That’s it. that type of messages will stop popping up.
This is a common microsoft vulnerability exploited by spammers.
Now, we continue with ur other problems, but it is highly suggested that after clearing all problems, pls install a good firewall too or atleast enable the default xp firewall.
PS: Do u hve a antivirus, as it too seems highly unlikely. U seem to hve a new pc or a fresh install of xp, which is not upto date. Pls do not browse web w/o a firewall, antivirus and anyone anti-spyware application (like microsoft anti-spyware or spybot with realtime monitoring).