Hi-Jacked by Sywsvcs.exe

Discussion in 'Malware Help (A Specialist Will Reply)' started by pace, Dec 1, 2005.

  1. pace

    pace Private First Class

    I have been hi-jacked. I have ran the latest version of Adaware and it found 58 Criticals the first time and it was clean the second time I ran it. I cant really go through the rest of the Tutorial with my PC (On my laptop now) since it wont let me onto Major Geeks to download everything else, also the Internet connection is kicking out and I am getting the following error message when it does:
    (Sywsvcs.exe-mta-v3.level3.mail.vip.mud.yahoo.com.25)

    Also there is an icon that appears by the clock that keeps changing its name, it is in the form of a mail notice and the name changes to xmxpita.com, smsa.org etc. etc. etc.
    I can find a file in the SYSTEM 32 folder created on 12/1/05 named Sywsvcs but I cannot delete it, the message says the file is either full or in use.

    Any help would be appreciated. I can try to download HiJack this onto a disc, load it on my PC, run it, save the results to a disc and post on here if it would help.

    Thanks.
     
  2. pace

    pace Private First Class

    Update I went into Safe mode and deleted the Sywsvcs.exe file. I also ran Adaware in Safe Mode and it came up clean. I rebooted and I can now browse the Internet without getting redirected. I ran the Tutorial (all except Spybot, it doesn't want to download for me for some reason). After running the tutorial AdAware found 17 items, 6 critical (Tracking cookies), Microsoft Anti Spyware found 1 critical called Backdoor.galapop.a (backdoor) , ran CCleaner and it found a bunch of stuff to delete. The computer seems to be working normal, Can I get a Hijack this file read or is it necessary. Anything else I should do?

    Thanks.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you still having a problem even just downloading the Spybot program? But other files could be downloaded?

    Download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Now make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .
     
  4. pace

    pace Private First Class

    Still havent got Spybot to download, when I click on the link from this site only part of the page loads and it doesn't provide any links to download the product. I did run a HJT log, I have attached it to this post.
    Thanks.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which download link did you try? They seem to work fine. Try one of the other ones.

    Perhaps you are blocking something with your settings.

    Were you able to download other tools from Majorgeeks?
    Can you download this: WinPatrol You don't need to run it. I just want to know if you can download it.

    I see no evidence that you ran the online scanners from the READ ME. Why did you skip them?

    Try clicking the below and let me know if this gets you to a Spybot download:

    Spybot

    At anyrate your log is clean!
     
  6. pace

    pace Private First Class

    That link for Spybot worked perfectly. I downloaded it and ran the program, said the system was clean. I had ran the other scanners earlier and they found issues, cleaned them and when I ran them again they said they were clean. Thanks for your help, do I need to post another HJT log for any reason?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds