This is intended for anyone who has been plagued by the practically impossible-to-remove d8t.biz spyware. If your browser homepage and searchpage have been hijacked by the address “http://s1di.d8t.biz/index.php?aid=20038 or any other address containing 'd8t.biz' then this is for you. This spyware is highly malicious- even if it is detected by various virus and spyware checkers, it repeatedly regenerates and the problem persists. I’ve had this on my computer for nearly 2 weeks now and only just got rid of it today. Here we go...
1. Download Hijack This from “http://www.spywareinfo.com/~merijn/files/hijackthis.zip
Run it, and get it to fix all references ending in sp.html; this is achieved by ticking the boxes alongside the appropriate lines and then clicking ‘fix checked’.
Also fix the following line…
O2 - BHO: (no name) - {random code} - C:\WINDOWS\System32\[suspicious].dll
N.B. The [suspicious].dll represents the .dll file name that will differ every time. It is the last entry that begins with O2, i.e. the next entry is usually O3…msdxm.ocx
2. Download and install “FINDnFIX.exe from
[http://downloads.subratam.org/FINDnFIX.exe]
Run the "!LOG!.bat" file. This creates a file called “log.txt – do not close this yet.
Scroll down the log- near the top of the page should be the following…
C:\WINDOWS\System32\[suspicious].DLL +++ File read error
C:\WINDOWS\System32\[suspicious].DLL +++ File read error
This .dll is the malicious spyware file that needs to be removed.
3. Open notepad.exe from the Start Menu> Accessories menu
Open the file "MOVEit.bat" which is located in the C:\FINDnFIX\Keys1 Subfolder
The file will open as text file.
Delete the instruction line which begins “REM…
Copy and paste the following line in its place (without the “)…
move %WinDir%\System32\[suspicious].DLL %SystemDrive%\junkxxx\[suspicious].DLL
Replace [suspicious] with the .dll file name discovered in log.txt
Save the file and close notepad.
4. Get ready to restart your computer.
In the same folder, run "FIX.bat"
You will be prompted by popup alert box that your computer will restart in 15 seconds.
5. Once the computer has restarted, open the C:\FINDnFIX\ main folder.
Run the "RESTORE.bat" file. This creates a new file called “log1.txt
There should now be no mention of the suspicious .dll file that was discovered in log.txt
6. Open the FINDnFIX\Files2 subfolder.
Run "ZIPZAP.bat"
This will clean the rest of the bad files and make copies in the same folder as “junkxxx.zip
Your email client will open, along with an email instruction but ignore this and close it.
7. When this is finished, restart your computer.
Delete the entire 'FINDnFIX' folder from C:\
Make sure the C:\junkxxx folder was deleted (it will have been by the clean-up process, but just check anyway)
8. Your computer should now be totally free of the annoying spware!
9. To prevent other such infections, read the following article “Why did I get infected:
http://www.wilderssecurity.com/showthread.php?t=27971
I recommend installing SpywareBlaster & SpywareGuard; both links are on this page. In addition, it is well worth installing a firewall: I recommend ZoneAlarm which is available here: http://www.zonelabs.com/store/content/catalog/products/sku_list_za.jsp