PDA

View Full Version : Removal of zitajalu.dll from C:\WINDOWS\system32 folder



american2022
2009-12-28, 20:23
I recently was having an issue with my computer, and after performing a virus scan with my Windows Live OneCare software, to which I subscribe, as well as Panda's excellent free online 2.0 scan, I identified a w32/mytob.rt.worm, virtumonde spyware, a number of cookies, and .dll files in the C:\WINDOWS\system32 directory that were recommended for removal.

After disabling system restore and deleting the worm, the virtumonde and all of is registry and back up components, all of the cookies, and most of the .dll's, ONLY ONE FILE REMAINS that I cannot rid my system of - and that is zitajalu.dll. When right clicked and selecting delete form the system32 folder, it gives the message that Access is Denied. I had a program that was called Remove on Reboot, and when right clicked and set for delete on reboot the file is still there after reboot.

I have researched and read and attempted to delete using cmd promts "del zitajalu.dll to which I receive "Access Denied" and also another command that I can no longer find where I wrote it down, but to the same degree of success.

I should add that all of my actions were performed in Safe Mode with Networking (sometimes having issues connecting to the Internet through Internet Explorer even though Network Connections shows "Connected" to my network).

I don't know where else to turn. It is my hope that one of the knowledgable administrators here at this site may have some advice for me, and it will be greatly appreciated.

american2022
2009-12-28, 20:29
Two more details I would like to add: Something is disabling Microsoft Automatic Updates as well as the Microsoft Live OneCare software from remaining open and active. Upon manually reactivating each, after just a short matter of time I look and they are once again inactive.

I was not experiencing this problem before a few days ago when I found something to be wrong and found zitajalu.dll in my scan, so it is my hope that by finding a way to successfully remove it, I will in doing so resolve the above issues I believe it to be causing.

tashi
2009-12-28, 20:40
Hello american2022 :welcome:

Please see this FAQ, "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Then start a new thread and copy paste the HJT log into it.

If HJT won't run please start a new topic anyway, make note of the situation and a volunteer analyst will advise you when available.

Best regards.

-------------------
http://forums.spybot.info/showthread.php?t=54427