SoftwareTipsandTricks Forum

Go Back   SoftwareTipsandTricks Forum > Software > Software Problems and Useful Utilities
User Name
Password


Help deleting spyware

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes

  #1  
Old 11-18-2008, 11:37 PM
zodiax24 Offline
Registered User
 
Join Date: Nov 2008
Posts: 3
Help deleting spyware

I ran the hijackthis scan and it shows a few DLL's that I know are spyware... however I cannot delete them because they do not show in explorer when I go to the directory they are in...

here's the log from hijackthis.. I have highlighted the spyware DLLs in bold..;

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:26:54 PM, on 11/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\dllhost.exe
c:\opt\MBCASE\pm\bin\mcp.exe
C:\WINDOWS\System32\locator.exe
C:\WINDOWS\system32\cmd.exe
C:\opt\MBCASE\pm\bin\cmserver.exe
C:\WINDOWS\system32\cmd.exe
C:\opt\MBCASE\pm\bin\lic_srv.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\regedit.exe
C:\WINDOWS\system32\logon.scr
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

O2 - BHO: (no name) - {242f8ecd-dd59-4026-aade-025da5825e51} - C:\WINDOWS\system32\guyugadu.dll (file missing)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [rohohitije] Rundll32.exe "C:\WINDOWS\system32\filawuzo.dll",s
O4 - HKLM\..\Run: [CPM3741721d] Rundll32.exe "c:\windows\system32\yibabofi.dll",a
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-48.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://atv.disney.go.com/global/down.../OTOYAX29b.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.28.9/ttinst.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/download...ameManager.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\guzazuwo.dll c:\windows\system32\yibabofi.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\yibabofi.dll (file missing)
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\yibabofi.dll (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: konfig - Unknown owner - c:\opt\MBCASE\pm\bin\mcp (file missing)
O23 - Service: license - Unknown owner - c:\opt\MBCASE\pm\bin\mcp (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: mcp - Unknown owner - c:\opt\MBCASE\pm\bin\mcp (file missing)
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O24 - Desktop Component 0: (no name) - file:///C:/Documents%20and%20Settings/mike/Desktop/&quot;http://pics.ebaystatic.com/aw/pics/spacer.gif&quot;width=1&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/FORM&gt;&lt;/TABLE&gt;<br
O24 - Desktop Component 1: (no name) - https://www5.recruitingcenter.net/cl...mages/logo.png

--
End of file - 5845 bytes
Reply With Quote

  #2  
Old 11-19-2008, 05:46 AM
pip22's Avatar
pip22 Offline
Registered User
 
Join Date: Jun 2004
Location: United Kingdom
Posts: 1,355
For those where it says "file missing" that's why you can't see them, they don't exist anymore, but the entry to load them is still in the Registry hence it comes up in the HJT log. Do a search for each alpha-numeric string shown in bold, and delete that key.

For the two entries which don't say "file missing", search in the Registry for the filename and delete all instances of it. Then close regedit.

In Control Panel->Folder Options, make sure "Show Hidden Files & Folders"
is enabled. Look for the offending files again in C:\windows\system32

Delete them.
Reply With Quote

  #3  
Old 11-19-2008, 10:50 AM
zodiax24 Offline
Registered User
 
Join Date: Nov 2008
Posts: 3
I tried deleting the registry entries / filenames in regedit but they come back...

this happens with all of them...

what do I do?
Reply With Quote

  #4  
Old 11-24-2008, 10:51 AM
zodiax24 Offline
Registered User
 
Join Date: Nov 2008
Posts: 3
Any help? still have not fixed the problem...
Reply With Quote

  #5  
Old 11-24-2008, 03:38 PM
Monty007's Avatar
Monty007 Offline
Registered User
 
Join Date: Jan 2007
Location: Australia
Posts: 1,992
Hi, first back up all of your important docs and files, also deleate all temp files, you can use a program like ccleaner http://www.ccleaner.com/download once you have downloaded ccleaner untick advanced , start menu and desktop. Run ccleaner and reg ccleaner but make a backup of your reg items.
Now go here http://www.doddpc.com and download Malwarebytes and update. Now boot your PC into safe mode with no networking and run a full scan.
Now go back to doddpc.com and run a scan with nod32 online.
__________________
http://www.doddpc.com
MCP
MCDST
Reply With Quote
Reply




Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Spyware and Virus Issues, Hijack this Logfile contained Please Help the man Windows XP 3 10-29-2007 04:20 AM
Internet explorer has encountered a problem and needs to close HELP simon1mufc13 Windows XP 11 01-14-2007 05:20 PM
Spyware Detected homersillo Windows XP 7 02-13-2006 06:39 PM
deleting spyware Caspi Software Problems and Useful Utilities 2 10-02-2004 11:28 PM
svchost.exe inbound from Beijing? Obfuscated Windows NT/2000/2003 2 07-09-2003 08:16 AM



All times are GMT -5. The time now is 06:22 PM.


Designed by eXtremepixels. Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.