Unsolved

This post is more than 5 years old

8436

October 25th, 2004 22:00

Can't delete unwanted .dll files

I constantly clean out my files by going to my computer/local disk drive/program files I only delete files that I know are useless. If i don't know what it is I wont touch it. Well I've found two .dll files called "web specials" and "my way search bar" . I know they came from internet downloads such as the p2p search sites b/c that was the last program i downloaded from the internet and then those files appeared. I've tried to change the .dll to .old (b/c that was suggested), but that didn't work. I've already tried the Ad Aware program and that didn't work . In another forum they recommended I use "who locked me out" which I did and it helped me to remove "my way search bar," but I still Can't delete "web specials." Every time I try to delete the .dll file it says:  
                                  Can not delete webspec.dll: Access denied.
                                  Make sure the disk is not full or write-protected
                                  and that the file is not currently in use.
When i try to uninstall the program from within the file it says to use the add/remove program, so i went there and it is not listed as being installed. At this point i don't know what to do and I'm not really computer literate, so i need someone who can help me delete these files and explain it in elementary terms. Please help! Thanks

4.8K Posts

October 26th, 2004 04:00

Felisha,

Download and run HiJackThis; v 1.98.2.  Then move it to it's own folder, out of the temporary downloads folder; "C:\HJT". Run it, then click "Scan", then "Save log". Copy/paste the text that comes up, and post it back. Don't 'fix' anything just yet, alot of what it reports is 'good', then close the HiJackThis window.

We'll use this to 'see' what's starting on your computer, so we can decide how best to approach a solution.

Mike.

November 2nd, 2004 00:00

Logfile of HijackThis v1.98.2
Scan saved at 9:27:07 PM, on 11/1/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\msswchx.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\ogvwgke.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Danielle\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://websearch.drsnsrch.com/sidesearch.cgi?id =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.findwhatevernow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://websearch.drsnsrch.com/sidesearch.cgi?id =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://websearch.drsnsrch.com/sidesearch.cgi?id =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINDOWS\localNRD.dll
O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: jimmyhelp.CBrowserHelper - {29A5EE7F-7129-4AA9-91F8-D0CAD06E0B8A} - C:\WINDOWS\birjj.dll
O2 - BHO: jimmyhelp.CBrowserHelper - {A06E9338-BC61-4206-A302-0AD7280D8378} - C:\WINDOWS\rnflyexoe.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [WebSpecials] rundll32 "C:\Program Files\WebSpecials\webspec.dll",run
O4 - HKLM\..\Run: [ovnpriyn] C:\WINDOWS\system32\ogvwgke.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Clock] C:\WINDOWS\mmc.exe
O4 - HKCU\..\Run: [WebSpecials] rundll32 "C:\Program Files\WebSpecials\webspec.dll",run
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,73/mcinsctl.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install2.5/Installer.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://utu.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} - http://cabs.media-motor.net/cabs/mmed.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/ym/yiebio5_1_6_0.cab
 
 
This is my log. I have not deleted anything. The objects that are in bold are what I suspect to be corrupting my computer. The Findwhatever website forces itself to become my home start up page. Even when I change it back to my default ( www.dellnet.com) some how the find whatever comes back. The object in red is what I think is changing my home page. The "web search" is in a folder found in c:\programfiles\webspecials folder. which is the .dll file that I cant delete. thank you for all the help that you have already given me.

4.8K Posts

November 2nd, 2004 02:00

felishagreen,

There's a few problems in there. But before we use HiJackThis, or any other program to remove them, let's see if we can remove some stuff using "Add/Remove programs".

Post back any entry(s) that have the words: search, bargain, rebates or web in the title, along with any entry(s) that you don't immediately recognize.

Mike.

 

4.8K Posts

November 2nd, 2004 02:00

felishagreen,

I've got your log next on the list to check. I should get to it sometime tommorrow afternoon.

For now, you might want to go ahead and download, and install CWShredder (just in case), AdAware SE Pesonal (version 1.05) and Spybot S&D (version 1.3). Be sure to check for and download any signature/ program updates before we begin tommorrow.

Mike.

 

November 2nd, 2004 02:00

I have tried the add/remove program. There are no programs to remove. All the programs that the computer lists are programs that I recognize. The only place I could find these files were in the c:programfiles\webspecials, and i've already tried deleting it there. what next?

4.8K Posts

November 2nd, 2004 20:00

felishagreen,
 
Thanks for the assistance with the marked entries, it's much appreciated.
 

 
Before we begin, let's first create a manual restore point and backup the registry.
 

 
Next, you need to place HiJackThis in it's own folder and out of the temporary downloads folder. HiJackThis will create backups for each entry we 'fix', and we might need to restore them at a later point, if need be.
 

Use " Add/Remove programs" to remove the following:
 
WebSpecials
 

 
Ok, first let's download, and run the VX2 cleaner for AdAware SE Personal. Follow the instructions on this page.
 

 
Open a command line, then unregister (" regsvr32 /u") the following dll(s):
 
systb.dll
birjj.dll
rnflyexoe.dll
 
For example: regsvr32 /u systb.dll
 
If they're not found, try prefixing them with : C:\WINDOWS\
 

 
Run HiJackThis, click " Scan", then check(tick) the following entry(s), if present:
 

C:\WINDOWS\system32\ogvwgke.exe
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://websearch.drsnsrch.com/sidesearch.cgi?id =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.findwhatevernow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://websearch.drsnsrch.com/sidesearch.cgi?id =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://websearch.drsnsrch.com/sidesearch.cgi?id =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
 
O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll
O2 - BHO: jimmyhelp.CBrowserHelper - {29A5EE7F-7129-4AA9-91F8-D0CAD06E0B8A} - C:\WINDOWS\birjj.dll
O2 - BHO: jimmyhelp.CBrowserHelper - {A06E9338-BC61-4206-A302-0AD7280D8378} - C:\WINDOWS\rnflyexoe.dll
 
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
 
O4 - HKLM\..\Run: [WebSpecials] rundll32 "C:\Program Files\WebSpecials\webspec.dll",run
O4 - HKLM\..\Run: [ovnpriyn] C:\WINDOWS\system32\ogvwgke.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKCU\..\Run: [WebSpecials] rundll32 "C:\Program Files\WebSpecials\webspec.dll",run
 
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
 

Now, with all windows closed except HiJackThis, click " Fix checked".
 

 
Locate and delete the following item(s),if present. Make sure your able to view system and hidden files.
 
[file]      C:\WINDOWS\system32\ogvwgke.exe
[file]      C:\WINDOWS\system32\wupdt.exe
[file]      C:\WINDOWS\systb.dll
[file]      C:\WINDOWS\birjj.dll
[file]      C:\WINDOWS\rnflyexoe.dll
 
[folder] C:\Program Files\WebSpecials
 
Reboot your computer.
 

 
Post back a new log.
 
Mike.

November 4th, 2004 01:00

Logfile of HijackThis v1.98.2
Scan saved at 10:26:10 PM, on 11/3/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\csrss.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Danielle\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: jimmyhelp.CBrowserHelper - {29A5EE7F-7129-4AA9-91F8-D0CAD06E0B8A} - C:\WINDOWS\birjj.dll
O2 - BHO: jimmyhelp.CBrowserHelper - {A06E9338-BC61-4206-A302-0AD7280D8378} - C:\WINDOWS\rnflyexoe.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [WebSpecials] rundll32 "C:\Program Files\WebSpecials\webspec.dll",run
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Clock] C:\WINDOWS\w32tm.exe
O4 - HKCU\..\Run: [WebSpecials] rundll32 "C:\Program Files\WebSpecials\webspec.dll",run
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,73/mcinsctl.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install2.5/Installer.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://utu.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/ym/yiebio5_1_6_0.cab
 
 
This is my new log. I do not know how to open a command line to unregister the
systb.dll
birjj.dll
rnflyexoe.dll
 
I downloaded the AdAware SE Personal and VX2. It removed many of the problems. The only file left is C:\program files\webspecials. The things that you told me to delete using hijackthis i successfully deleted except for the line that is high lighted in red. I've tried three times to delete it and it wont go away. The web specials is the original file that I wanted to delete. I don't know what to do next.
        When I went into C:\windows\system32\         I found these files:
p2p.dll
p2pgasvc.dll
p2pgraph.dll
p2pnetsh.dll
p2psvc.dll
Are these harmful in any way?
 
Once again I would like to thank you for all of your advice and help!!!!!!:smileyhappy:

4.8K Posts

November 4th, 2004 08:00

felishagreen,
 
Wow! That's looking alot better! Let's see if we can figure out how to get the rest of those problems off your system.
 

 
When I went into C:\windows\system32\         I found these files:
p2p.dll
p2pgasvc.dll
p2pgraph.dll
p2pnetsh.dll
p2psvc.dll
Are these harmful in any way?
 
For these files, see this article from Microsoft.
 

 
To unregister a dll, do the following:
 
  • Click "Start", then "Run..."
  • Type cmd, then press [enter].
  • Type regsvr32 /u [dll to unregister]

Use that and try to unregister webspec.dll.

If the dll files from the previous post were successfully deleted, however, you won't need to unregister them. I usually recommend doing that to prevent a 'file cannot be deleted, in use' message, if it's currently being used by some other application.


It looks like you might have at least one trojan sitting on your pc, so let's try the following to flush it out and remove it:

First, download, install and run "A squared 2". Next, check for any new trojan signatures, then begin scanning:

  • Update A2 online.
  • Scan your computer for Malware infections.

Next, go to www.trendmicro.com, then click "Free Online Scan". It will take a few minutes to download and install. When it's done, select all available drives, then click "Scan".

See this article when you done. This is the program that is suspect in locking out WebSpecials, and other '.exe' files from being removed/ fixed: C:\WINDOWS\csrss.exe . The 'csrss.exe' file should be located in the system32 folder on XP systems.


Now, for the WebSpecials problem, let's try this next:

Run HiJackThis, click "Config", then "Misc Tools", then "Delete file on reboot...". Next, browse to and select "C:\Program Files\WebSpecials\webspec.dll", then click "Yes" to reboot your computer.


Next, run HiJackThis, click "Scan", then check(tick) the following entry(s), if present:

O4 - HKLM\..\Run: [WebSpecials] rundll32 "C:\Program Files\WebSpecials\webspec.dll",run
O4 - HKCU\..\Run: [WebSpecials] rundll32 "C:\Program Files\WebSpecials\webspec.dll",run
(There are two entries)

Now, with all windows closed except HiJackThis, click "Fix checked".

Reboot your computer normally.


Post back a new log.

Mike.

 

November 4th, 2004 16:00

Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.
 
C:\Documents and Settings\Danielle>regsvr32/u[webspec.dll
 
C:\Documents and Settings\Danielle>regsvr32[/u[:cmdline]]webspec.dll
'regsvr32[' is not recognized as an internal or external command,
operable program or batch file.
 
C:\Documents and Settings\Danielle>regsvr32[/u[cmdline]]webspec.dll
'regsvr32[' is not recognized as an internal or external command,
operable program or batch file.
 
C:\Documents and Settings\Danielle>regsvr32/u[/u[:cmdline]]webspec.dll
 
C:\Documents and Settings\Danielle>regsvr32[/u[:cmdline]]webspec.dll
'regsvr32[' is not recognized as an internal or external command,
operable program or batch file.
 
C:\Documents and Settings\Danielle>regsvr32/u
 
C:\Documents and Settings\Danielle>
 
This is what happened when I tried to use the command line to unregister the webspec.dll.  OR it would give a message saying:
 
Usage:   regsvr32[/i[:cmdline]] dllname
/u-       Unregister server
/s-        Silent; display no message box
/i-        Call DllInstall passing it an optional [cmdline]; when used with /u calls dll unistall
/n-      do not call DllRegisterServer; this option must be used with /i
 
What does this all mean? Because i don't think im doing it correctly. I have not yet gotten to the trojan or the second Hijackthis scan, I wanted to get this step first. thank you

4.4K Posts

November 4th, 2004 17:00

felishagreene,

It looks like a stray character crept into the "regsvr32" command line.

This is how is should look:

regsvr32 /u webspec.dll


Jim

November 12th, 2004 00:00

Logfile of HijackThis v1.98.2
Scan saved at 9:40:06 PM, on 11/11/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINDOWS\dsndup.exe
C:\Program Files\a2\a2guard.exe
C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Danielle\LOCALS~1\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe
C:\WINDOWS\system32\cidaemon.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: jimmyhelp.CBrowserHelper - {29A5EE7F-7129-4AA9-91F8-D0CAD06E0B8A} - C:\WINDOWS\birjj.dll
O2 - BHO: jimmyhelp.CBrowserHelper - {A06E9338-BC61-4206-A302-0AD7280D8378} - C:\WINDOWS\rnflyexoe.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Clock] C:\WINDOWS\spoolsv.exe
O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a2\a2guard.exe"
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,73/mcinsctl.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install2.5/Installer.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://utu.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/ym/yiebio5_1_6_0.cab
 
 
Sorry I've been MIA. Can you please take a look at my new log from Hijack this scan. I think all of the bad things are gone (ie webspecials). The only objects that I am wondering about are highlighted in red. Are they bad? Thank you for suggesting the AdAware Se, it has been working great. Once again, thank you, I really appreciate all the time you have taken out of your schedule to help, felishagreene 

4.8K Posts

November 12th, 2004 01:00

felisha,
 
Your more than welcome...
 
I'd venture to guess the following randomly named items are indeed 'baddies'. If you GOOGLE the CLSID, you'll see the same id for another randomly named file; it has been removed.
 
Let's get started...
 

 
From a command line, enter each of the following:
 
regsvr32 /u birjj.dll
regsvr32 /u rnflyexoe.dll
 

 
Run HiJackThis, click " Config...", then " MiscTools", then " Open process manager". Next look for the following entry:
 
C:\WINDOWS\spoolsv.exe
 
Click " Kill process".
Click " Refresh" - make sure it's gone.
 
The spoolsv.exe is a valid file when it's located in the C:\Windows\System32 folder. This is a problem file that seems to mutate by changing names; it might be a different name on each reboot. Just look for the text in the 04 - [Clock] entry. Be careful, it may have the same name of a legitimate running process, so make sure you 'kill' the right one; it's known by the path it keeps. Plus [Clock] and " print spooler" don't exactly go hand-in-hand ... :)
 
Click " Back" ( the one in the lower right hand corner).
 

 
Click " Scan", then check(tick) the following entry(s), if present:
 
 
O2 - BHO: jimmyhelp.CBrowserHelper - {29A5EE7F-7129-4AA9-91F8-D0CAD06E0B8A} - C:\WINDOWS\birjj.dll
O2 - BHO: jimmyhelp.CBrowserHelper - {A06E9338-BC61-4206-A302-0AD7280D8378} - C:\WINDOWS\rnflyexoe.dll
 
O4 - HKCU\..\Run: [Clock] C:\WINDOWS\spoolsv.exe
(or whatever name it's currently using.)
 
 
Now, with all windows closed except HiJackThis, click " Fix checked".
 

 
Locate and delete the following item(s), if present. Make sure your able to view hidden files/ folders.
 
C:\WINDOWS\spoolsv.exe
(or whatever name it's currently using.)
 
C:\WINDOWS\birjj.dll
C:\WINDOWS\rnflyexoe.dll
 
Reboot your computer normally.
 

 
Post back a new log.
 
Mike.
 
No Events found!

Top