L
Lars-Erik Østerud
Clean a friends system, but there are something left I can't get rid
of. Both Ad-Aware and Spybit S&D finds it. It is in the "Startup"
list, but when they try to remove it it just reinstalls itself. Even
tried removing the entries in the registry. But they keep coming back.
Microsoft Anto Spyware and Malisious Software removal doesn't find it.
Neither does the anti-virus programs. But when installed it launches
IE with a window with commercials (stopped that by blocking "Winlogon"
in the firwall
So somthing is very very wrong. But what do I do?
Details:
In "startup" (actuall it suncribes to "Lgon" and "logoff" events, but
it show as "system.ini" in Spybot S&D" under the "Startup items")
there are two DLLs that are launched:
"tdcyw.dll" always has the same name, the other DLL changes name (and
description) all the time: dnp0018me.dll, r0p8la7u1d.dll,
mv6ul9j91.dll are only some of the names..
Tried to delete those DLLs, but of course they are in use. But I can't
see any processes that should not be there...
I forgot to note the names on the spyware "Ad-Aware" found :-(
But it finds 12 entries each time (even after I delete them).
Thought I could boot to "command prompt only" but that is not in the
boot meny (it's XP home), the obly choice with "command prompt" boots
XP first (to GUI) then launches a "cmd" (and then the spyware has
allready reinstalled itself and run). Is there a way to get a "cmd"
windows without launching XP first with XP home (works on XP Pro)?
of. Both Ad-Aware and Spybit S&D finds it. It is in the "Startup"
list, but when they try to remove it it just reinstalls itself. Even
tried removing the entries in the registry. But they keep coming back.
Microsoft Anto Spyware and Malisious Software removal doesn't find it.
Neither does the anti-virus programs. But when installed it launches
IE with a window with commercials (stopped that by blocking "Winlogon"
in the firwall

Details:
In "startup" (actuall it suncribes to "Lgon" and "logoff" events, but
it show as "system.ini" in Spybot S&D" under the "Startup items")
there are two DLLs that are launched:
"tdcyw.dll" always has the same name, the other DLL changes name (and
description) all the time: dnp0018me.dll, r0p8la7u1d.dll,
mv6ul9j91.dll are only some of the names..
Tried to delete those DLLs, but of course they are in use. But I can't
see any processes that should not be there...
I forgot to note the names on the spyware "Ad-Aware" found :-(
But it finds 12 entries each time (even after I delete them).
Thought I could boot to "command prompt only" but that is not in the
boot meny (it's XP home), the obly choice with "command prompt" boots
XP first (to GUI) then launches a "cmd" (and then the spyware has
allready reinstalled itself and run). Is there a way to get a "cmd"
windows without launching XP first with XP home (works on XP Pro)?