I have recently been infected by Trojan.Tofger with the file "cmid32.dll" I beleive this is causing me to be infected with Dialer.Silent over and over.
I can delete Dialer.Silent everytime I am infected with it but cannot delete cmid32.dll because it says "Cannot delete cmid32.dll: The specified file is being used by windows". Can someone please help me delete it?
and if possible explain where it came from and what is does?

Your help would be much apreciated Thank You - xDylanx

Dani AI

Generated

Good result: as suggested, booting to Safe Mode let remove the immediate cmid32.dll lock and stop the repeating Dialer.Silent symptom. That fixes the running handle in many cases, but true cleanup means removing whatever let the DLL persist and checking for leftovers that can reinfect later.

For locked DLLs, identify the owner before deleting. Run Process Explorer (Sysinternals) as Administrator and use Find (Ctrl+F) for cmid32.dll to see which process or service has it open. Close the handle or stop the process from within Process Explorer, then remove the file. If the process cannot be stopped while Windows is running, delete the file offline (boot from a Linux live CD or an antivirus rescue disk) to avoid file locks.

Remove persistence so the DLL cannot come back. Use Autoruns (Sysinternals) to remove any entries that reference cmid32.dll under Logon, Services, Scheduled Tasks, Explorer, and Winsock providers. Inspect common registry startup locations (export before editing): HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, and HKLM\SYSTEM\CurrentControlSet\Services. Also check Scheduled Tasks and any custom modem/dialer configuration entries if Dialer.Silent was present.

Finish with full, up-to-date scans using a main antivirus plus a second-opinion scanner, clear old System Restore points (turn System Restore off then on to remove infected snapshots), run netsh winsock reset and reboot, and change important account passwords. If uncertainty remains about hidden components or sensitive data was involved, a clean OS install is the most reliable way to ensure all persistence mechanisms are removed.

Recommended Answers

All 4 Replies

Try to delete in safe mode. Reboot into safe mode following the instructions

Hehe simple as that.. thanks heeps that Trojan has been bugging me for weeks. Cheers - Dylan

thanks again

Cool. No problems.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.