Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93104 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

XCVWER.dll


  • This topic is locked This topic is locked
No replies to this topic

#1 wallacetech

wallacetech

    New Member

  • New Member
  • Pip
  • 1 posts

Posted 19 December 2007 - 12:47 PM

I found that once this dll was loaded after restart. A connection was made to a web site in Russia. I used Spybot 1.5 with the Teatimer loaded to help with this. I deleted the registry entry for this DLL , renamed the DLL, and denied the recreation of the new dll registry entry. Rebooted the PC and then used Hijackthis to remove the registry entry once and for all. Then deleted the renamed file. Norton, Smitfraud, Spybot 1.5, Adaware did not find this file as a threat. But the file properties pointed to Russia. Hope this helps.

    Advertisements

Register to Remove

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users