L
Lynx
Hi Guys,
I was exploring System Explorers and noticed 3 new ActiveX programs appeared
in the list. It was easy to find because for a long time I did have only 4
entries there (MS Office 2003, 2 Sun Javas and Shockwave Flash).
They are marked as "unknown ActiveX":
{17492023-C23A-453E-A040-C7C580BBF700}
{8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}
I tried to block them. They will resurrect after restart. The same after
deleting with SpyBot.
I don't want to annoy anybody so I put some info and the extract from reg.
extract just for {..700} at the end.
Are those GWFSPidGen.DLL & LegitCheckControl.DLL part of the "Genuine
Advantage.." stuff?
If so what is "unknown" about it from Microsoft's point of view?
If those are nasties it would be nice to know how get rid if them?
Thanks in advance
1)
[HKEY_CURRENT_USER\Software\GIANTCompany\AntiSpyware\SpyNet]
"{17492023-C23A-453E-A040-C7C580BBF700}"="sent"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution
Units\{17492023-C23A-453E-A040-C7C580BBF700}\Contains\Files]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution
Units\{17492023-C23A-453E-A040-C7C580BBF700}\DownloadInformation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution
Units\{17492023-C23A-453E-A040-C7C580BBF700}\InstalledVersion]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/GWFSPidGen.DLL]
".Owner"="{17492023-C23A-453E-A040-C7C580BBF700}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/GWFSPidGen.DLL]
"{17492023-C23A-453E-A040-C7C580BBF700}"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/LegitCheckControl.DLL]
"{17492023-C23A-453E-A040-C7C580BBF700}"=""
2) File Analyzer sais:
Microsoft PidGen
GWFSPidGen.DLL
Description: PidGen
Original file name: PidGen.dll
Publisher: Microsoft
Path: C:\WINDOWS\system32\GWFSPidGen.DLL
Version: 1.5.0.42
Size: 23304 bytes
MD5: 76cfe0b49089af874d3d135efc38bf3a
I was exploring System Explorers and noticed 3 new ActiveX programs appeared
in the list. It was easy to find because for a long time I did have only 4
entries there (MS Office 2003, 2 Sun Javas and Shockwave Flash).
They are marked as "unknown ActiveX":
{17492023-C23A-453E-A040-C7C580BBF700}
{8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}
I tried to block them. They will resurrect after restart. The same after
deleting with SpyBot.
I don't want to annoy anybody so I put some info and the extract from reg.
extract just for {..700} at the end.
Are those GWFSPidGen.DLL & LegitCheckControl.DLL part of the "Genuine
Advantage.." stuff?
If so what is "unknown" about it from Microsoft's point of view?
If those are nasties it would be nice to know how get rid if them?
Thanks in advance
1)
[HKEY_CURRENT_USER\Software\GIANTCompany\AntiSpyware\SpyNet]
"{17492023-C23A-453E-A040-C7C580BBF700}"="sent"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution
Units\{17492023-C23A-453E-A040-C7C580BBF700}\Contains\Files]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution
Units\{17492023-C23A-453E-A040-C7C580BBF700}\DownloadInformation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution
Units\{17492023-C23A-453E-A040-C7C580BBF700}\InstalledVersion]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/GWFSPidGen.DLL]
".Owner"="{17492023-C23A-453E-A040-C7C580BBF700}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/GWFSPidGen.DLL]
"{17492023-C23A-453E-A040-C7C580BBF700}"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/LegitCheckControl.DLL]
"{17492023-C23A-453E-A040-C7C580BBF700}"=""
2) File Analyzer sais:
Microsoft PidGen
GWFSPidGen.DLL
Description: PidGen
Original file name: PidGen.dll
Publisher: Microsoft
Path: C:\WINDOWS\system32\GWFSPidGen.DLL
Version: 1.5.0.42
Size: 23304 bytes
MD5: 76cfe0b49089af874d3d135efc38bf3a