PDA

View Full Version : Spybot S&D won't clean 10 (or 36) problems



Avaava
2012-08-09, 16:46
It cleaned out a considerable number of detected problems ( I thought) but asked me to authorize cleaning the rest . No matter how many times I click on the button it says I haven't chosen any to clean. When I run a scan again almost ALL the original problems are still found .

I know I had an incomplete immunization issue for a while and Babylon toolbar that I couldn't get rid of ... but this seems MUCH WORSE ... please advise .

tashi
2012-08-09, 17:27
Hello Avaava,

Please open Spybot Search & Destroy > Help > About and let us know the version and the date of last definitions. :)

Also, please list:


The operating system.
Other security programs installed.
Any issues with the computer's performance.

Best regards.

Avaava
2012-08-10, 12:12
Thanks Tashi ! OS is Windows 7. working on the rest .

Avaava
2012-08-10, 12:58
Search results from Spybot - Search & Destroy

8/10/2012 6:41:20 AM
Scan took 00:26:18.

Babylon.Toolbar: [SBI $DEB52F26] Program directory (Directory, nothing done)
C:\ProgramData\Babylon\

Babylon.Toolbar: [SBI $554A5FF0] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bbylnApp.appCore

Babylon.Toolbar: [SBI $554A5FF0] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bbylnApp.appCore.1

Babylon.Toolbar: [SBI $554A5FF0] Class ID (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}

Babylon.Toolbar: [SBI $554A5FF0] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bbylnApp.appCore.1

Babylon.Toolbar: [SBI $554A5FF0] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bbylnApp.appCore

Babylon.Toolbar: [SBI $86348D5E] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Babylon.dskBnd

Babylon.Toolbar: [SBI $86348D5E] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Babylon.dskBnd.1

Babylon.Toolbar: [SBI $86348D5E] Class ID (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}

Babylon.Toolbar: [SBI $86348D5E] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Babylon.dskBnd.1

Babylon.Toolbar: [SBI $86348D5E] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Babylon.dskBnd

Babylon.Toolbar: [SBI $F75ED516] IE toolbar (Registry Value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{98889811-442D-49dd-99D7-DC866BE87DBC}

Babylon.Toolbar: [SBI $B04483F7] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr

Babylon.Toolbar: [SBI $B04483F7] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1

Babylon.Toolbar: [SBI $B04483F7] Class ID (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}

Babylon.Toolbar: [SBI $B04483F7] Browser helper object (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}

Babylon.Toolbar: [SBI $B04483F7] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1

Babylon.Toolbar: [SBI $B04483F7] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr

Babylon.Toolbar: [SBI $52C6ABB7] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.BabylonESrvc

Babylon.Toolbar: [SBI $52C6ABB7] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.BabylonESrvc.1

Babylon.Toolbar: [SBI $52C6ABB7] Class ID (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}

Babylon.Toolbar: [SBI $52C6ABB7] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.BabylonESrvc.1

Babylon.Toolbar: [SBI $52C6ABB7] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.BabylonESrvc

Babylon.Toolbar: [SBI $C2E2DFDF] Program directory (Directory, nothing done)
C:\Program Files (x86)\BabylonToolbar\

Babylon.Toolbar: [SBI $6FD65E4E] Program directory (Directory, nothing done)
C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\

Babylon.Toolbar: [SBI $BD2D2D7E] Program directory (Directory, nothing done)
C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\

Babylon.Toolbar: [SBI $7C2CF2C5] Program directory (Directory, nothing done)
C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\

Babylon.Toolbar: [SBI $82C5EBDA] Settings (Registry Value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}\AppName

Babylon.Toolbar: [SBI $07586C96] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\escort.escortIEPane

Babylon.Toolbar: [SBI $07586C96] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\escort.escortIEPane.1

Babylon.Toolbar: [SBI $07586C96] Class ID (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}

Babylon.Toolbar: [SBI $07586C96] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\escort.escortIEPane.1

Babylon.Toolbar: [SBI $07586C96] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\escort.escortIEPane

Babylon.Toolbar: [SBI $9BB50AEF] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\escort.escrtBtn.1

Babylon.Toolbar: [SBI $9BB50AEF] Class ID (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1}

Babylon.Toolbar: [SBI $9BB50AEF] Root class (Registry Key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\escort.escrtBtn.1

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\A\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\NVP9BSBA\s.ytimg.com\videostats.sol
Properties.size=275
Properties.md5=865FB293F34A77EA10752341C12D522D
Properties.filedate=1344519323
Properties.filedatetext=2012-08-09 09:35:23

Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Direct3D\MostRecentApplication\Name

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-2852634967-139479858-350855394-1000\Software\Microsoft\Direct3D\MostRecentApplication\Name

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Direct3D\MostRecentApplication\Name

MS DirectDraw: [SBI $EB49D5AF] Most recent application (Registry Change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name

MS DirectInput: [SBI $9A063C91] Most recent application (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-2852634967-139479858-350855394-1000\Software\Microsoft\DirectInput\MostRecentApplication\Name

MS DirectInput: [SBI $9A063C91] Most recent application (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-2852634967-139479858-350855394-1001\Software\Microsoft\DirectInput\MostRecentApplication\Name

MS DirectInput: [SBI $7B184199] Most recent application ID (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-2852634967-139479858-350855394-1000\Software\Microsoft\DirectInput\MostRecentApplication\Id

MS DirectInput: [SBI $7B184199] Most recent application ID (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-2852634967-139479858-350855394-1001\Software\Microsoft\DirectInput\MostRecentApplication\Id

Cookie: [SBI $49804B54] Browser: Cookie (1) (Browser: Cookie, nothing done)


Cache: [SBI $49804B54] Browser: Cache (16) (Browser: Cache, nothing done)


History: [SBI $49804B54] Browser: History (62) (Browser: History, nothing done)


Cookie: [SBI $49804B54] Browser: Cookie (14) (Browser: Cookie, nothing done)



--- Spybot - Search & Destroy version: 2.0.7.131 DLL (build: 20120207) ---

2012-02-07 blindman.exe (2.0.7.151)
2012-02-07 explorer.exe (2.0.7.170)
2003-04-18 ntrights.exe
2012-02-07 SDCleaner.exe (2.0.7.106)
2012-02-07 SDDelFile.exe (2.0.7.94)
2012-02-07 SDFiles.exe (2.0.7.128)
2012-02-07 SDFileScanHelper.exe (2.0.7.1)
2012-02-07 SDFSSvc.exe (2.0.7.198)
2012-02-07 SDImmunize.exe (2.0.7.125)
2012-02-07 SDLogReport.exe (2.0.7.104)
2012-02-07 SDPhoneScan.exe (2.0.7.27)
2012-02-07 SDPrepPos.exe (2.0.7.10)
2012-02-07 SDQuarantine.exe (2.0.7.102)
2012-02-07 SDRootAlyzer.exe (2.0.7.114)
2012-02-07 SDScan.exe (2.0.7.170)
2012-02-07 SDSettings.exe (2.0.7.114)
2012-02-07 SDShred.exe (2.0.7.104)
2012-02-07 SDSysRepair.exe (2.0.7.101)
2012-02-07 SDTools.exe (2.0.7.141)
2012-02-07 SDTray.exe (2.0.7.126)
2012-02-07 SDUpdate.exe (2.0.7.86)
2012-02-07 SDUpdSvc.exe (2.0.7.76)
2012-02-07 SDWelcome.exe (2.0.7.120)
2012-02-07 SDWSCSvc.exe (2.0.7.2)
2012-02-13 unins000.exe (51.52.0.0)
1999-12-02 xcacls.exe
2006-03-03 borlndmm.dll (10.0.2288.42451)
2010-09-06 DelZip190.dll (1.9.0.87)
2012-02-07 SDAdvancedCheckLibrary.dll (2.0.7.98)
2011-08-04 SDDialogs.dll (2.0.5.13)
2012-02-07 SDECon32.dll (2.0.7.113)
2012-02-07 SDEvents.dll (2.0.7.2)
2012-02-07 SDFileScanLibrary.dll (2.0.7.4)
2012-02-07 SDHelper.dll (2.0.7.88)
2012-02-07 SDImmunizeLibrary.dll (2.0.7.1)
2012-02-07 SDLists.dll (2.0.7.4)
2012-02-07 SDResources.dll (2.0.7.3)
2012-02-07 SDScanLibrary.dll (2.0.7.131)
2012-02-07 SDTasks.dll (2.0.7.15)
2012-02-07 SDWinLogon.dll (2.0.7.0)
2011-04-20 sqlite3.dll
2012-02-07 Tools.dll (2.0.7.36)
2012-02-07 UninsSrv.dll (1.0.0.0)
2011-03-18 Includes\Adware.sbi (*)
2012-08-07 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2010-12-14 Includes\Dialer.sbi (*)
2011-11-29 Includes\DialerC.sbi (*)
2011-02-24 Includes\HeavyDuty.sbi (*)
2012-06-19 Includes\Hijackers.sbi (*)
2012-07-31 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2010-12-14 Includes\Keyloggers.sbi (*)
2012-01-24 Includes\KeyloggersC.sbi (*)
2012-06-18 Includes\Malware.sbi (*)
2012-08-08 Includes\MalwareC.sbi (*)
2011-02-24 Includes\PUPS.sbi (*)
2012-07-10 Includes\PUPSC.sbi (*)
2012-06-19 Includes\Security.sbi (*)
2011-12-13 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2012-07-23 Includes\Spyware.sbi (*)
2012-07-31 Includes\SpywareC.sbi (*)
2011-06-07 Includes\Tracks.sbi (*)
2010-03-08 Includes\Tracks.uti (*)
2011-09-28 Includes\Trojans.sbi (*)
2012-08-07 Includes\TrojansC-02.sbi (*)
2012-08-06 Includes\TrojansC-03.sbi (*)
2012-07-31 Includes\TrojansC-04.sbi (*)
2012-08-07 Includes\TrojansC-05.sbi (*)
2012-08-06 Includes\TrojansC.sbi (*)

other than Microsoft updated Security package - no other firewalls besides Spybot . Norton Macafee firewall was bundled in original software but I didn't renew. Yesterday I cleaned out same 36 issues and was left with 9 ..also today .. yet 24 hours later all are back. Only performance problem I see is I am frequently asked to upgrade to administrator status AS an administrator and then denied permission to fix problems. The computer is slower though I think and also frequently freezes . :confused:

As far as updating Spybot definitions goes - last time I updated was 2 days ago. I was SO happy to finally see Babylon toolbar GO ... and then it came back GRRRR

spybotsandra
2012-08-10, 13:35
Hello,

You are running an old Beta version of Spybot-S&D (2.0.7) which was meant for testing only,
and no replacement for the stable version 1.6.2 of Sypbot-S&D which you can download here (http://www.spybotupdates.com/files/spybotsd162.exe).

About the admin rights:
Windows Vista/Windows 7 might tell you that you are not being allowed to operate at the administration level of your computer.
You can solve this problem as follows:
Right-click the Spybot - Search & Destroy entry in your start menu,
instead of just left-clicking to start it.
Then, choose Run as administrator/take ownership from the context menu.
You will find a screenshot of this problem in our FAQ:
How can I get administrator rights under Windows Vista or Windows 7 (www.safer-networking.org/faq/how-can-i-get-administrator-rights-under-windows-vista-or-windows-7/)

Best regards
Sandra
Team Spybot