PDA

View Full Version : New user needs help!



simonat
2005-10-31, 22:09
Hi,

I have downloaded Spybot to deal with Spyware on my PC, and also have MS Antispyware, & Ad-aware.

All problems are immunised but how do I remove them permanently from my pc?

Whan I perform a search using S&D, 'Running Spybot s&d (XXXXXX)' displays in the lower left corner of the screen and appears to show various items of spyware, but I am unsure how to permanently remove them. They have not been picked up by other spyware software? At the end of the search no problems are reported although I get an error message 'Xuron55(' etc?

I would be grateful for any advise more experienced users can give me!

Thanks

Simon

md usa spybot fan
2005-10-31, 22:35
The status bar shows what is being checked not what is being found. In the display "Running bot-check(xxxxx/yyyyy:zzzzzz)" the zzzzzz is the malware that is being scan for.

What is found will be displayed under problems when the scan completes.

simonat
2005-10-31, 23:06
Thanks for advice, that makes me feel a whole lot better!

Any ideas on the reported problems?:

Error during check!: Xuron55 (Datei C:\WINDOWS\win.ini kann nicht geöffnet werden. The process cannot access the file because it is being used by another process) ()


RealDownloadExpress: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{FDF5CDE5-17A6-40B3-A544-A8527AE8B243}

RealDownloadExpress: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{56336BCB-3D8A-11d6-A00B-0050DA18DE71}

RealDownloadExpress: Root class (Registry key, nothing done)
HKEY_CLASSES_ROOT\RealDownloadExpress.IE.1

RealDownloadExpress: Root class (Registry key, nothing done)
HKEY_CLASSES_ROOT\RealDownloadExpress.IE

Windows Security Center.AntiVirusDisableNotify: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify!=dword:0

Windows Security Center.FirewallDisableNotify: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify!=dword:0


--- Spybot - Search && Destroy version: 1.3 ---
2005-10-21 Includes\Cookies.sbi
2005-10-21 Includes\Dialer.sbi
2005-10-21 Includes\Hijackers.sbi
2005-10-21 Includes\Keyloggers.sbi
2004-11-29 Includes\LSP.sbi
2005-10-21 Includes\Malware.sbi
2005-10-21 Includes\PUPS.sbi
2005-10-21 Includes\Revision.sbi
2005-10-21 Includes\Security.sbi
2005-10-21 Includes\Spybots.sbi
2005-02-17 Includes\Tracks.uti
2005-10-21 Includes\Trojans.sbi

Thanks

Simon

md usa spybot fan
2005-10-31, 23:20
The error:


Error during check!: Xuron55 (Datei C:\WINDOWS\win.ini kann nicht geöffnet werden. The process cannot access the file because it is being used by another process) ()
Is terminating your scan!!!

Unless you are running on a Windows 95 system, upgrade to Spybot 1.4. Downloads are here:
Download Spybot-S&D
http://www.safer-networking.org/en/mirrors/index.html

After upgrading post another report and we can discuss it.

simonat
2005-11-02, 21:21
Hi,

Upgraded as suggested, new report follows:

--- Report generated: 2005-11-01 20:26 ---

RealDownloadExpress: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\RealDownloadExpress.IE

RealDownloadExpress: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\RealDownloadExpress.IE.1

RealDownloadExpress: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{56336BCB-3D8A-11d6-A00B-0050DA18DE71}

RealDownloadExpress: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{FDF5CDE5-17A6-40B3-A544-A8527AE8B243}

Windows Security Center.FirewallDisableNotify: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify!=dword:0

Windows Security Center.AntiVirusDisableNotify: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify!=dword:0


--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2005-11-01 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2005-05-31 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2005-05-31 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2005-10-28 Includes\Cookies.sbi (*)
2005-10-28 Includes\Dialer.sbi (*)
2005-10-28 Includes\Hijackers.sbi (*)
2005-10-28 Includes\Keyloggers.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2005-10-28 Includes\Malware.sbi (*)
2005-10-28 Includes\PUPS.sbi (*)
2005-10-28 Includes\Revision.sbi (*)
2005-10-28 Includes\Security.sbi (*)
2005-10-28 Includes\Spybots.sbi (*)
2005-02-17 Includes\Tracks.uti
2005-10-28 Includes\Trojans.sbi (*)

Would be very grateful for your thoughts!

Thanks



Simon

md usa spybot fan
2005-11-03, 06:50
RealDownload Express is a download manager that comes packaged with RealOne Player. It contains spyware and should be removed.

For safe download managers see:
Review of download managers
http://www.safer-networking.org/en/articles/download-managers.html


These detections:


Windows Security Center.FirewallDisableNotify: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify!=dword:0

Windows Security Center.AntiVirusDisableNotify: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify!=dword:0
Indicate two of the setting within Windows Security Center have been turned off. Go into Start > Control Panel > Security Center > Resources (on the left hand side of the window – expand if necessary) > click "Change the way Security Center alerts me". This brings up an "Alert Setting" window. There are three possible alerts:
Firewall
Alert me if my computer might be at risk because of my firewall settings
Automatic Updates
Alert me if my computer might be at risk because of my Automatic Updates settings
Virus Protection
Alert me if my computer might be at risk because of my virus protection software settings
I believe that you will find that the first and third alerts are turned off. For more of an explanation please see this post:
http://forums.spybot.info/showpost.php?p=216&postcount=2

simonat
2005-11-03, 20:05
Hi,

Just to say thanks very much for your help, I would have been lost without it!

Regards


Simon:)

minhas
2005-11-23, 05:34
i was having the same problem of the alerts being disabled ....went thru so many sites .....but ur answer was precise and perfect ...........good work ..thanks to u i'll know now where to come if i face some problem

[/FONT]ot fan]RealDownload Express is a download manager that comes packaged with RealOne Player. It contains spyware and should be removed.

For safe download managers see:
Review of download managers
http://www.safer-networking.org/en/articles/download-managers.html


These detections:


Windows Security Center.FirewallDisableNotify: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify!=dword:0

Windows Security Center.AntiVirusDisableNotify: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify!=dword:0
Indicate two of the setting within Windows Security Center have been turned off. Go into Start > Control Panel > Security Center > Resources (on the left hand side of the window – expand if necessary) > click "Change the way Security Center alerts me". This brings up an "Alert Setting" window. There are three possible alerts:
Firewall
Alert me if my computer might be at risk because of my firewall settings
Automatic Updates
Alert me if my computer might be at risk because of my Automatic Updates settings
Virus Protection
Alert me if my computer might be at risk because of my virus protection software settings
I believe that you will find that the first and third alerts are turned off. For more of an explanation please see this post:
http://forums.spybot.info/showpost.php?p=216&postcount=2