Trojan Horse Corruption of IE 6

G

Guest

I recently was attacked by a Trojan Horse called BackDoor BDD that has
affected my IE 6 installation. My anti-virus stopped the download before it
got too far, and I've not seen any other problems, but this thing really
screwed up my IE. When I initiate IE, it automatically goes to some bizarre
portal site, and opens a window saying that "you may have spyware". I've
tried:

1) Changing the "home" web address setting (multiple times - still goes back
to this EVERY time)

2) Using my Windows XP to uninstall and reinstall IE 6 (even REMOVED all the
IE subdirectories, cleaned all temp files, etc, and then reloaded IE 6 - and
STILL get the same thing!)

3) Uninstalling IE 6 and downloading IE 6 SP 2 (won't let me load it - says
I have a LATER version already installed?!?!?!)

Does ANYONE out there have a clue what I can do to reinstate IE? I'm using
Netscape 7 now (hate it); I'm a Web developer part-time, and I need IE to
test with . . .
 
J

Jan Il

Hi rahurd :)

Unlike previous versions of Windows, you CAN NOT uninstall IE from Windows
XP. You can only repair or reinstall. Thus, by uninstalling or deleting
any part of IE files or folders, etc. you may have completely trashed the
system. You may have no alternative but to completely reinstall the XP
program in order to restore the system. However, you might try the
following information and see if it will help. There are several methods of
properly repairing and reinstalling below you can review and find the one
that you prefer to try. But, you may also have additional scumware that is
not causing the problem. I will post the removal information as well.
Please follow all instructions very carefully.

First try:

Go to DOS: START - RUN - type COMMAND - press ENTER. (To exit type EXIT)

At the DOS C:\ prompt type the following, hitting enter after each line.

regsvr32 Shdocvw.dll
regsvr32 Shell32.dll
regsvr32 Oleaut32.dll
regsvr32 Actxprxy.dll
regsvr32 Mshtml.dll
regsvr32 Urlmon.dll

If that does not work, then continue:
**************************************************
NOTE: If you can not download these programs from the Internet, if your PC
has CD read capabilities, go to another computer with CD-ROM burning
capabilities. Create a folder on the hard drive of the other computer called
HOLD, download the programs to that folder, then burn that folder to a CD.
Copy the HOLD folder to your HD and then install the programs from there
and run them. After you have IE access again, update all scumware removal
programs where possible to get the latest definitions and run them again in
Safe Mode to be sure there are no lingering items on the system.
*************************************************

Be sure that your AV and firewall is disabled before starting:

How do I repair Internet Explorer in Windows® XP?
http://www.dougknox.com/xp/tips/xp_ie_reinstall.htm

How to Reinstall or Repair Internet Explorer and Outlook Express in Windows
XP
http://support.microsoft.com/kb/318378/EN-US/

The Internet Explorer Repair Tool
http://inetexplorer.mvps.org/answers_5.htm#repair_tool

also.........

You can reinstall IE in Windows XP by clicking Start, Run and entering the
following command:

rundll32.exe setupapi,InstallHinfSection DefaultInstall
132%windir%\Inf\ie.inf

*You will need to have your XP CD available*.

also.....

Method 2 in this article works on earlier versions of Windows.
How to Reinstall or Repair Internet Explorer and Outlook Express in
Windows XP
http://support.microsoft.com/?kbid=318378

Dealing with Unwanted Spyware and Parasites:
http://mvps.org/winhelp2002/unwanted.htm
Be sure to run CWShredder (newest version 2.1 here),
http://www.majorgeeks.com/download3019.html
AdAware and Spybot.
Download the newest version of HiJackThis here:
http://www.bleepingcomputer.com/files/hijackthis.php
(or Spybot - Search and Destroy DSO Exploit Fix 1.3.1 TX)
http://www.majorgeeks.com/download4392.html
Also be sure to use the HijackThis. Please DO NO post your log to this
newsgroup, but to one of the HiJackThis Support Forums below:
http://www.hijackthis.de/forum/forumdisplay.php?f=10&guestlanguageid=4
the Aumha HiJackThis forums
http://forum.aumha.org/viewforum.php?f=30
or Spyware Beware:
http://forums.maddoktor2.com/index.php?showforum=17
to allow the experts there to evaluate your log and advise you of the
necessary steps to clean your system.

Also this program searches for hidden .dlls that recreate the malware.
About Buster:
http://www.majorgeeks.com/download4289.html

CAUTION!!!!! Before you try to remove spyware using any of the programs
below, download a copy of LSPFIX from any of the following sites:
http://www.cexx.org/lspfix.htm
http://www.spychecker.com/program/winsockxpfix.html
(if your OS is Win2k or XP) The process of removing certain malware may kill
your internet connection. If this should occur, this program, LSPFIX, will
enable you to regain your connection.

Also, get a copy of WINSOCKXPFIX available at:
http://www.spychecker.com/program/winsockxpfix.html
and
WinsockXP Fix- WinXP
http://www.spychecker.com/program/winsockxpfix.html
Also, with instructions, at
http://www.iup.edu/house/resnet/winfix.shtm
also
From LavaSoft- all versions of Windows-
http://digital-solutions.co.uk/lavasoft/whndnfix.zip
also ....
(NOTE: It is reported that in XP SP2, the command netsh winsock reset
will fix this problem without the need for these programs.)

or ........

Winsock Fix Utility
http://www.dfwonline.net/files/WinsockFix.zip

Also.........

Courtesy of Jim Byrd -

Download Sysclean.com, from Trend Micro, here:
http://www.trendmicro.com/download/dcs.asp along with the latest pattern
file, here:
http://www.trendmicro.com/download/pattern.asp
Be sure to read the "How-to" info here:
http://www.trendmicro.com/ftp/products/tsc/readme.txt
You might also want to get Art's updater, SYS-UP.Zip, here for future
updating of these: http://home.epix.net/~artnpeg/.
(If you download and use the updater from the beginning, it will
automatically handle downloading the other files. Place them in a dedicated
folder after appropriate unzipping, and then run. This scan may take a long
time, as Sysclean is VERY extensive and thorough

If these steps do not resolve your problem, or you need help with the above,
please post back to this thread with the details and any error messages.

Hope this helps

Jan :)
Smiles are meant to be shared,
that's why they're so contagious.

Replies are posted only to the newsgroup for the benefit or other readers.
How to make a good newsgroup post:
http://www.dts-l.org/goodpost.htm
 
F

Frank Saunders, MS-MVP IE/OE

rahurd said:
I recently was attacked by a Trojan Horse called BackDoor BDD that has
affected my IE 6 installation. My anti-virus stopped the download
before it got too far, and I've not seen any other problems, but this
thing really screwed up my IE. When I initiate IE, it automatically
goes to some bizarre portal site, and opens a window saying that "you
may have spyware". I've tried:

1) Changing the "home" web address setting (multiple times - still
goes back to this EVERY time)

2) Using my Windows XP to uninstall and reinstall IE 6 (even REMOVED
all the IE subdirectories, cleaned all temp files, etc, and then
reloaded IE 6 - and STILL get the same thing!)

3) Uninstalling IE 6 and downloading IE 6 SP 2 (won't let me load it
- says I have a LATER version already installed?!?!?!)

Does ANYONE out there have a clue what I can do to reinstate IE? I'm
using Netscape 7 now (hate it); I'm a Web developer part-time, and I
need IE to test with . . .

How to remove Coolwebsearch and affiliates
http://mvps.org/winhelp2002/unwanted.htm#Coolwebsearch

--
Frank Saunders, MS-MVP, IE/OE
Please respond in Newsgroup only. Do not send email
http://www.fjsmjs.com
Protect your PC
http://www.microsoft.com/security/protect/
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top