1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Please Help: Malware dll and registry entries keep coming back after deletion

Discussion in 'Virus & Other Malware Removal' started by jcereced, Dec 31, 2008.

Thread Status:
Not open for further replies.
  1. jcereced

    jcereced Thread Starter

    Joined:
    Dec 31, 2008
    Messages:
    3
    I've been cleaning up my PC (Windows XP) for the last couple of days but no matter what I try the problem comes back.

    Here's the history and what i've tried so far:

    The PC was infected with Spyware Guard 2008 (tell you you have a virus and need their virus remover yada yada yada) and I was able to remove it and restore some normality using Malwarebytes Anti-Malware 1.31

    However when I was cleaning up the system there is a file that MAM finds but it cannot remove:

    c:\windows\system2\dxmhqx.dll

    It says that it will clean up during reboot but whe I reboot the file is still there.

    If I tried to delete the file manually I get a cannot delete access denied message so I downloaded Unlocker 1.8.7 so I could unlock the file (it was associated to svchost.exe and also other times to winlogon.exe). I was able to unlock the file and then delete

    Now I had to go to the registry to remove the entry in there but low and behold everytime I remove the entry it comes up again so this time I got Process Explorer so I could suspend all the instances of svchost.exe. Suspending the processes allows me to remove the entry from the registry and it doesn't come back.

    Then I ran MAM and Spybot and everything comes back clean but after I reboot dxmhqx dll and its registry entry come back.


    I have done this several times and i always end up on the same spot, one thing worth noting is that if I disconnect my internet connection cable and do the above steps I can clean the system and it stays clean but it gets infected again as soon as I plug the internet cable in (i've seen the dxmhqx.dll file appear as soon as I plug the cable in)

    One of the symptoms of the infection is that iexplore.exe runs constantly as one of my processes.

    For now I'm permanently disconnecting that PC from the internet and using a clean laptop to do everything else

    I don't know what else to try and willing to do anything at this point.

    I'm attachign the HJT log,

    Thanks a lot in advance and Happy New year!!

    Javi
     

    Attached Files:

  2. jcereced

    jcereced Thread Starter

    Joined:
    Dec 31, 2008
    Messages:
    3
    Hey guys,

    Just bumping to see if anyone has any ideas.

    Thanks
     
  3. jcereced

    jcereced Thread Starter

    Joined:
    Dec 31, 2008
    Messages:
    3
    Hello,

    Just wondering if this was seen my anyone. Still having the problem, bumping to see if anyone can help.

    Thanks.
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/785343

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice