English Deutsch Français Italiano Español Português 繁體中文 Bahasa Indonesia Tiếng Việt ภาษาไทย
All categories

020 - AppInit_DLLs: Is that normal or is it spyware?

2007-12-14 13:16:11 · 5 answers · asked by Anonymous in Computers & Internet Security

5 answers

CIEPl Object- Newest Variant- adds an infected 020 AppInit_DLLs HJT entry
Example 1

O2 - BHO: CIEPl Object - {F85E86D8-F796-4C97-AAA2-26664A98A42C} - C:\WINDOWS\system32\service.dll
O20 - AppInit_DLLs: C:\WINDOWS\System32\jfwofybc.dll
O20 - Winlogon Notify: service - C:\WINDOWS\SYSTEM32\service.dll

Example 2

O2 - BHO: CIEPl Object - {F85E86D8-F796-4C97-AAA2-26664A98A42C} - C:\WINDOWS\System32\msvmon.dll
O20 - AppInit_DLLs: C:\WINDOWS\System32\gllrlgyd.dll
O20 - Winlogon Notify: msvmon - C:\WINDOWS\SYSTEM32\msvmon.dll
Note: Only variant with randomly named file in the AppInit_DLLs value and a constant 02 BHO CLSID = F85E86D8-F796-4C97-AAA2-26664A98A42C
http://wiki.castlecops.com/index.php?title=Malware_Removal:_Virtumundo&redirect=no

Malware Removal: Virtumundo
From CastleCopsWiki

This procedure is to remove Adware-Virtumundo (Vundo).Winfixer /WinAntiSpyware / WinAntiVirus and Adware-Virtumundo are not one and the same.
http://wiki.castlecops.com/index.php?title=Malware_Removal:_Virtumundo&redirect=no

2007-12-14 13:23:21 · answer #1 · answered by Anonymous · 0 0

First I will say I not know.
Castle cops mentioned above has help me fix other problems, and may be your Best Answer.
Sometimes, I copy and save the DLL file and then delete when I not sure. If, I run a program and it say DLL not found it will give the name of the Deleted File. So, I can copy back.
But, somethings, could, re-install the DLL on their own!!!
I searched and this may not be good. But, it your call and as I say, Castle Cops been a good help (Which I also say the above be Best Answer if this work). Just copy what you not sure of and write down where it was!!!! If a program stop working, put it back or Delete/Reinstall that program!

2007-12-14 21:34:38 · answer #2 · answered by Snaglefritz 7 · 0 0

simple! when you do the scan click on the button that says analize this within hijacks program ,,,,problem sorted!!

2007-12-14 21:24:20 · answer #3 · answered by mark_only37 2 · 0 0

Go to this site to analyze your log.

http://www.hijackthis.de/#anl

2007-12-14 21:24:26 · answer #4 · answered by christie 3 · 0 0

I think it is VIRUS OR SPYWARE...

2007-12-14 21:22:48 · answer #5 · answered by Madz Blitz 1 · 0 0

fedest.com, questions and answers