Click to See Complete Forum and Search --> : Special.goods
jstut
May 18th, 2005, 08:58 AM
Has anyone run into this?
Got a buddy who has been bitten. Ran Adaware. SpyBot AVG, Ran a hijackthis scan and cleaned up any suspicious stuff, checked startup.
Looks liek he's hijacked, Jenna Jameson comes up as his "Home Page".
Personally, I told him not to bother fixing, but for some reason, (think it's wifw) he wants it fixed. Also put a lot of desktop icons out there all with ....special.goods... in target.
Appreciate any help you can offer.
shamus
May 18th, 2005, 09:25 AM
Have you run the apps (AVG, AdAware and Spybot) in safe mode?
jstut
May 18th, 2005, 09:38 AM
Think so....I'll retry though!
jstut
May 19th, 2005, 04:49 PM
reran in safe mode. SpyBot S&D picked up Alexa, and DSO EXPLOIT.
Wouldn't remove!
jstut
May 19th, 2005, 05:44 PM
Got the DSO exploit.....still can't kill specialgoods.
Got a small x in load, but can't find source.
jstut
May 19th, 2005, 06:17 PM
I am deleting through hijackthis, but the next scan brings back ...specialgoods... as home page. Where do I kill this thing?
shamus
May 19th, 2005, 07:02 PM
If this is an XP machine make sure you've turned of System Restore. If it's on it will replace everything you get rid of...
jstut
May 22nd, 2005, 08:22 AM
I'll give that a shot .......Thanks.
Ferrit
May 22nd, 2005, 10:22 AM
Get Counterspy and install and run it
JeffO93
May 23rd, 2005, 02:09 PM
Whether a virus or spyware, I think McAfee will remove it, but you may have to boot off a CD to clean it.
If McAfee can't remove it, it should at least name names. Once you get a name, you can Google it and get manual-removal instructions.
You might also try Norton, but keep in mind that different antivirus companies may have differing names for the same virus, so you'd have to search the translated names.
http://www.trendmicro.com/en/home/us/enterprise.htm
http://www.mcafee.com/us/default.asp
http://www.symantec.com/index.htm
http://www.pestpatrol.com/pestinfo/hijacker.asp
If you buy a new antivirus CD to get the latest definitions, unfortunately the producers don't keep the CD's on store racks up-to-date when manufactured. The CD's are never continuously updated.
Some people know how to download the latest definitions and burn a new CD so that they can boot off the McAfee, Norton, or other CD and do a scan with the latest def's.
Also, I think everyone should own a bootable multi-purpose CD for these situations (and learn how to use it). 700MB CD image download:
http://www.knopper.net/knoppix/index-en.html
geoscomp
May 23rd, 2005, 02:21 PM
Or just download the Nyquil Kids compilation Antivirus/antispyware (http://nyquil-kid.dyndns.org/) bootable cd with all the fix tools and spyware tools you need in one place..updated frequently
jstut
May 23rd, 2005, 05:29 PM
Ran in safe mode....appears to be a dialer, or spyware. Loading an Icon in the start tray I can't kill.....Restore off, MULTIPLE pop-ups and crap. Multiple Icons on Desk top.
jstut
May 24th, 2005, 08:00 AM
Also found 2 entries in registry. When I delete...ekeps coming back.
shamus
May 24th, 2005, 08:23 AM
What's it finding? If you can give us the name of the dialer or what spyware it is it would be easier to help you find a fix.
Zonie
May 24th, 2005, 09:01 AM
Try downloading this 14 day free trial and see if this takes care of the problem. I have seen a problem with a nail.exe in systems and this is the only program that gets rid of it. http://downloads-zdnet.com.com/Ewido-Security-Suite/3000-8022_2-10326287.html
jstut
May 24th, 2005, 04:25 PM
The only reocurring theme is specialgoods. It even has its own little icon in the startup tray. Seems to por up about every minute- 90 seconds. Fighting it now!
shamus
May 24th, 2005, 05:48 PM
edit:
check the posts from this forum
http://www.wilderssecurity.com/showthread.php?t=79379
good luck.
Zonie
May 24th, 2005, 07:25 PM
Check my thread, this removes all sorts of malware and should work in your case.
jstut
May 25th, 2005, 01:13 PM
That looks like it did the trick! Thanks.
I also cleaned registry up.......Unfortunately Jenna is gone!