got two warnings from WinDefend. how to solve the problem?

G

Guest

i have problem with two files. Can body can help me? thanks

When i log on windowx xp professional version using my account, i got two
error messsage, something like this:
RUNDLL

can not open C:\WINDOWS\system32\DRIVERS\vojljh24.sys because it is used by
another program.

can not open C:\WINDOWS\system32\DRIVERS\ihpned47.sys because it is used by
another program.

Furthermore, Windows Defender give me two warnings regarding these two
files. i dont know how to solve this problem. hope any person can help me.
thanks.

--------------------
Event Type: Warning
Event Source: WinDefend
Event Category: None
Event ID: 3004
Date: 11/9/2006
Time: 11:05:53 PM
User: N/A
Computer: YUANDONG
Description:
Windows Defender Real-Time Protection agent has detected spyware or other
potentially unwanted software.
For more information please see the following:
http://www.microsoft.com
Scan ID: {DD1F7199-F747-4FFF-B6DD-3FF3920F3F1D}
User: YUANDONG\Yuandong
Name: Unknown
ID:
Severity ID:
Category ID:
Path Found: driver:ihpned47;file:C:\WINDOWS\system32\DRIVERS\ihpned47.sys
Alert Type: Unknown
Detection Type:


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.





Event Type: Warning
Event Source: WinDefend
Event Category: None
Event ID: 3004
Date: 11/19/2006
Time: 1:15:29 AM
User: N/A
Computer: YUANDONG
Description:
Windows Defender Real-Time Protection agent has detected spyware or other
potentially unwanted software.
For more information please see the following:
http://www.microsoft.com
Scan ID: {D96D7928-4813-4B30-AF80-A58B6DE65C8F}
User: YUANDONG\Yuandong
Name: Unknown
ID:
Severity ID:
Category ID:
Path Found: driver:vojljh24;file:C:\WINDOWS\system32\DRIVERS\vojljh24.sys
Alert Type: Unknown
Detection Type:


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
 
G

Guest

I suspect the RunDLL messages were there before you ever installed Windows
Defender. The issue is whether these drivers belong on your system. I would
use Explorer and go to the drivers folder and hover the mouse over
vojljh24.sys and ihpned47.sys. Maybe you will get lucky and see the vendor
name. I could not find any drivers with the above names with a Google
search. Under WD, you can look at Tools->Software Explorer->Startup
Programs. If none of this helps, create a restore point and then use WD
Software Explorer to disable the run keys with the drivers. Reboot the
system and see if any devices don't work under Device Manager. Otherwise I
don't have a clue as to their function.
 
G

Guest

Also, you might want to use Regedit (registry editor) and use find on the 2
......sys entries.
 
G

Guest

The WD messages were from the real time agents. What happened when you ran a
"full" scan?
 
D

Dave M

Hi Yuandong;
Another idea is to send those files to virustotal and or another
multiscanner to have them independently checked. In order to do that, you
might have to run from Safe mode with networking or something similar (like
the unlocker program) to get around the lock on the file before you can
ship it off. Many pieces of malware are given random names so that's
really not much help knowing what it's name on your harddrive is:

http://virusscan.jotti.org/
http://scanner.virus.org/
http://www.virustotal.com/en/indexf.html
 
M

Melvin \(math\) Klassen

When i log on windowx xp professional version using my account, i got two
error messsage, something like this:
RUNDLL

can not open C:\WINDOWS\system32\DRIVERS\vojljh24.sys because it is used by
another program.

can not open C:\WINDOWS\system32\DRIVERS\ihpned47.sys because it is used by
another program.

Furthermore, Windows Defender give me two warnings regarding these two
files.

1. Use REGEDIT to make a backup of your Windows Registry.
2. Use REGEDIT to 'find' every occurrence of 'vojljh24' and delete the key.
3. Use REGEDIT to 'find' every occurrence of 'ihpned47' and delete the key.
4. Reboot.
5. Scan again with Windows Defender.
6. If Windows Defender does not delete the two files, manually delete the
two files from the DRIVERS folder.
7. Reboot.

If the two messages reappear, you're in serious trouble.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top