CIEPl Object- Newest Variant- adds an infected 020 AppInit_DLLs HJT entry
Example 1
O2 - BHO: CIEPl Object - {F85E86D8-F796-4C97-AAA2-26664A98A42C} - C:\WINDOWS\system32\service.dll
O20 - AppInit_DLLs: C:\WINDOWS\System32\jfwofybc.dll
O20 - Winlogon Notify: service - C:\WINDOWS\SYSTEM32\service.dll
Example 2
O2 - BHO: CIEPl Object - {F85E86D8-F796-4C97-AAA2-26664A98A42C} - C:\WINDOWS\System32\msvmon.dll
O20 - AppInit_DLLs: C:\WINDOWS\System32\gllrlgyd.dll
O20 - Winlogon Notify: msvmon - C:\WINDOWS\SYSTEM32\msvmon.dll
Note: Only variant with randomly named file in the AppInit_DLLs value and a constant 02 BHO CLSID = F85E86D8-F796-4C97-AAA2-26664A98A42C
http://wiki.castlecops.com/index.php?title=Malware_Removal:_Virtumundo&redirect=no
Malware Removal: Virtumundo
From CastleCopsWiki
This procedure is to remove Adware-Virtumundo (Vundo).Winfixer /WinAntiSpyware / WinAntiVirus and Adware-Virtumundo are not one and the same.
http://wiki.castlecops.com/index.php?title=Malware_Removal:_Virtumundo&redirect=no
2007-12-14 13:23:21
·
answer #1
·
answered by Anonymous
·
0⤊
0⤋
First I will say I not know.
Castle cops mentioned above has help me fix other problems, and may be your Best Answer.
Sometimes, I copy and save the DLL file and then delete when I not sure. If, I run a program and it say DLL not found it will give the name of the Deleted File. So, I can copy back.
But, somethings, could, re-install the DLL on their own!!!
I searched and this may not be good. But, it your call and as I say, Castle Cops been a good help (Which I also say the above be Best Answer if this work). Just copy what you not sure of and write down where it was!!!! If a program stop working, put it back or Delete/Reinstall that program!
2007-12-14 21:34:38
·
answer #2
·
answered by Snaglefritz 7
·
0⤊
0⤋
simple! when you do the scan click on the button that says analize this within hijacks program ,,,,problem sorted!!
2007-12-14 21:24:20
·
answer #3
·
answered by mark_only37 2
·
0⤊
0⤋
Go to this site to analyze your log.
http://www.hijackthis.de/#anl
2007-12-14 21:24:26
·
answer #4
·
answered by christie 3
·
0⤊
0⤋
I think it is VIRUS OR SPYWARE...
2007-12-14 21:22:48
·
answer #5
·
answered by Madz Blitz 1
·
0⤊
0⤋