adware that is using a dll that renames itself

  • Thread starter Thread starter wr
  • Start date Start date
W

wr

There is a dll that resides in windows\system32 that is
rename itself after boot up which I suspect is causing
popups but the antipspyware is not catching it

Anyone seen this threat?
 
Hi WR, Happy holiday

Please submit a suspected spyware report to spynet. (tools-
submit suspected spyware report).

Feel free to say what you've got in place and have tried,
and that it didn't work.

Once that has completed, please reboot into safe mode
logged in as administrator
and run a full AntiSpyware scan.
(open Microsoft AntiSpyware, on the scan page choose Scan
options > Full System Scan (check the boxes below) >
click "Run Scan Now" ) scan with the latest signatures to
see if that helps.
It is also important to do a full virusscan with an
updated antivirusprogram in Safe Mode
Apply the same principles with the following AntiSpyware
solutions in safe
mode:
Spy Sweeper - www.webroot.com
Spybot - http://www.safer-networking.org/
CWShredder -
http://www.intermute.com/products/cwshredder.html
Ad-Aware - www.lavasoftusa.com

Microsoft reads the posts here, and encourages users to
post feedback, positive and negative.

Good luck

Engel
 
Hi W,

Do a search of your Windows directory and see if you have a file in there
titled "nail.exe."
If so, come back and search out the help for ABI, nail or Aurora.

Ron Chamberlin
MS-MVP
 
Back
Top