PDA

View Full Version : Spybot is unable to remove most maleware dectected



skb52
2013-10-22, 05:46
I have tried to run spybot and remove malware that I believe is causing a number of problems. The main problem is a pop-up window telling me that I need to update Firefox, but when I look at the URL in the address bar, it doesn't look anything like a mozilla address. So after I run spybot, it tells me that some of the items couldn't be removed, it may help to run Spybot again as an administrator. Well..... my logon has full administrative access so I don't know what more I can do. I did reboot and tried running the program as soon as the system came up - but to no avail. I'm hoping someone here can help. Thank you in advance. Here is the scan report:

--- Report generated: 2013-10-21 21:57 ---

CouponBar: [SBI $7A5ACBCB] Interface (Registry key, fixing failed)
HKEY_CLASSES_ROOT\Interface\{6E780F0B-BCD6-40CB-B2DB-7AF47AB4D4A4}

CouponBar: [SBI $7B15781E] Interface (Registry key, fixing failed)
HKEY_CLASSES_ROOT\Interface\{A138BE8B-F051-4802-9A3F-A750A6D862D4}

IWinGames: [SBI $C7B64946] Settings (Registry key, fixing failed)
HKEY_CLASSES_ROOT\AppID\ForseRemove

IWinGames: [SBI $C7B64946] Settings (Registry key, fixing failed)
HKEY_CLASSES_ROOT\AppID\ForseRemove

IWinGames: [SBI $8D161E83] Interface (Registry key, fixing failed)
HKEY_CLASSES_ROOT\Interface\{E3ED53C5-7AD5-4DF5-9734-AFB6E7E5D9DB}

IWinGames: [SBI $8D161E83] Interface (Registry key, fixing failed)
HKEY_CLASSES_ROOT\Interface\{E3ED53C5-7AD5-4DF5-9734-AFB6E7E5D9DB}

IWinGames: [SBI $FF593BF7] Type library (Registry key, fixing failed)
HKEY_CLASSES_ROOT\TypeLib\{495874FE-4A82-4AD1-9476-0B957E0B95EB}

IWinGames: [SBI $FF593BF7] Type library (Registry key, fixing failed)
HKEY_CLASSES_ROOT\TypeLib\{495874FE-4A82-4AD1-9476-0B957E0B95EB}

IWinGames: [SBI $E8B83F64] Settings (Registry key, fixing failed)
HKEY_USERS\.DEFAULT\Software\iWinArcade

IWinGames: [SBI $E8B83F64] Settings (Registry key, fixing failed)
HKEY_USERS\S-1-5-18\Software\iWinArcade

IWinGames: [SBI $3B64B144] Settings (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\iWinArcade

IWinGames: [SBI $23600E87] Uninstall settings (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iWinArcade

Ask.MyGlobalSearch: [SBI $9FA3D6C1] User settings (Registry key, fixing failed)
HKEY_USERS\.DEFAULT\Software\AskToolbar

Ask.MyGlobalSearch: [SBI $9FA3D6C1] User settings (Registry key, fixing failed)
HKEY_USERS\S-1-5-18\Software\AskToolbar

SelectionLinks: [SBI $DF9517D8] Program directory (Directory, fixing failed)
C:\Program Files (x86)\OApps\

SelectionLinks: [SBI $8243D7E4] Executable (File, fixed)
C:\Program Files (x86)\OApps\dler.exe
Properties.size=432781
Properties.md5=5DAC8BF922D2510C3D8F734F52F257B3
Properties.filedate=1346113268
Properties.filedatetext=2012-08-27 20:21:08

SelectionLinks: [SBI $5640C838] Text file (File, fixed)
C:\Program Files (x86)\OApps\status.txt
Properties.size=27
Properties.md5=517F583389416378274514E44F1EC92E
Properties.filedate=1350166616
Properties.filedatetext=2012-10-13 18:16:55

SelectionLinks: [SBI $A1AB844B] Settings (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\kincjchfokkeneeofpeefomkikfkiedl

SelectionLinks: [SBI $45DAC639] Settings (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{517E0D3E-17A4-4592-926E-A082DB43B7D3}

SelectionLinks: [SBI $104BBC3D] Settings (Registry value, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{517E0D3E-17A4-4592-926E-A082DB43B7D3}\AppName

SelectionLinks: [SBI $69C2736C] Settings (Registry value, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{517E0D3E-17A4-4592-926E-A082DB43B7D3}\AppPath

SelectionLinks: [SBI $F0E20AA6] Settings (Registry value, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{517E0D3E-17A4-4592-926E-A082DB43B7D3}\Policy

SelectionLinks: [SBI $BBF632A0] Settings (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Object\SelectionLinks

SelectionLinks: [SBI $3ACA7D36] Settings (Registry value, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Object\SelectionLinks\bhoguid

SelectionLinks: [SBI $E26DA595] Settings (Registry value, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Object\SelectionLinks\installdate

SelectionLinks: [SBI $2D84FEFF] Settings (Registry value, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Object\SelectionLinks\installid

SelectionLinks: [SBI $9B5E6E89] Settings (Registry value, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Object\SelectionLinks\partner

SelectionLinks: [SBI $C70F65B7] Settings (Registry value, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Object\SelectionLinks\product

SelectionLinks: [SBI $6D697F3F] Settings (Registry value, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Object\SelectionLinks\version

SelectionLinks: [SBI $C0787B77] Settings (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\kincjchfokkeneeofpeefomkikfkiedl

SelectionLinks: [SBI $C0787B77] Settings (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\kincjchfokkeneeofpeefomkikfkiedl

SelectionLinks: [SBI $ACF5AEDC] Settings (Registry key, fixing failed)
HKEY_CLASSES_ROOT\Interface\{3AE26843-9171-4F23-A8E5-5421701276A4}

SelectionLinks: [SBI $ACF5AEDC] Settings (Registry key, fixing failed)
HKEY_CLASSES_ROOT\Interface\{3AE26843-9171-4F23-A8E5-5421701276A4}

SelectionLinks: [SBI $8F3BAA82] Settings (Registry key, fixing failed)
HKEY_CLASSES_ROOT\TypeLib\{B00FE392-639D-4688-976E-A1BFF368CB96}

SelectionLinks: [SBI $8F3BAA82] Settings (Registry key, fixing failed)
HKEY_CLASSES_ROOT\TypeLib\{B00FE392-639D-4688-976E-A1BFF368CB96}

Banker: [SBI $EBFB4022] Browser helper object (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8CA5ED52-F3FB-4414-A105-2E3491156990}

Banker: [SBI $7F6039C1] Class ID (Registry key, fixing failed)
HKEY_CLASSES_ROOT\CLSID\{8CA5ED52-F3FB-4414-A105-2E3491156990}


--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2012-03-18 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2013-04-11 Includes\Adware.sbi (*)
2013-10-01 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2012-11-14 Includes\Dialer.sbi (*)
2013-04-11 Includes\DialerC.sbi (*)
2013-04-11 Includes\HeavyDuty.sbi (*)
2012-11-14 Includes\Hijackers.sbi (*)
2013-04-11 Includes\HijackersC.sbi (*)
2013-09-10 Includes\iPhone.sbi (*)
2013-06-25 Includes\Keyloggers.sbi (*)
2013-04-11 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2013-05-29 Includes\Malware.sbi (*)
2013-10-01 Includes\MalwareC.sbi (*)
2012-11-14 Includes\PUPS.sbi (*)
2013-10-02 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2012-11-14 Includes\Security.sbi (*)
2013-04-11 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2013-05-22 Includes\Spyware.sbi (*)
2013-08-06 Includes\SpywareC.sbi (*)
2012-11-19 Includes\Tracks.uti
2013-01-16 Includes\Trojans.sbi (*)
2013-08-13 Includes\TrojansC-02.sbi (*)
2013-10-01 Includes\TrojansC-03.sbi (*)
2013-09-24 Includes\TrojansC-04.sbi (*)
2012-03-05 Includes\TrojansC-05.sbi (*)
2012-03-09 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll

tashi
2013-10-22, 06:23
Hello skb52,


So after I run spybot, it tells me that some of the items couldn't be removed, it may help to run Spybot again as an administrator. Well..... my logon has full administrative access so I don't know what more I can do. l

Did you elevate Administrator permissions within Spybot? :) How can I get administrator rights under Windows Vista / Windows 7 / Windows 8? (http://forums.spybot.info/showthread.php?t=55946)

Kind regards.

skb52
2013-10-23, 02:45
Hello skb52,



Did you elevate Administrator permissions within Spybot? :) How can I get administrator rights under Windows Vista / Windows 7 / Windows 8? (http://forums.spybot.info/showthread.php?t=55946)

Kind regards.

Thank you - I had no idea, I thought it was telling me I needed to have Win 7 administrative access.... glad I asked for help.

Best regards,
Sharon