AppInit_DLL

edited November 2004 in Spyware & Virus Removal
Seems I have an AppInit_DLL's infection. The pesky CWS again. Anybody got any ideas on clearing it?

Comments

  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    edited November 2004
    Read this, and then post a log using HJT.
  • CrunchieCrunchie Mandurah. Western Australia. Member
    edited November 2004
    Download Registrar Lite from here:
    http://www.resplendence.com/download/reglite.exe

    Put it in its own folder. You may want to keep this program. It is an excellent free, registry editor.


    Run reglite and open this key:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
    DoubleClick and identify the file listed in AppInit_DLLs.

    Create new folder for backups somewhere: (e.g. My Documents\Backups)
    Hilite the Windows key marked in purple, and use reglite's file menu>export, save in the following formats:
    Name them as--
    1.) Winkey.reg (Selected by defaults) (Save as type: regedit4 .reg type)
    2.) Winkey.hiv (in Save as type: Scroll to select-regetd32/WinAPI *hiv *dat files)

    When both files/backups are successfully saved, Rename the Windows key to Windows1
    , Clear the data in the AppInit value., Rename back to original , restart
    Preferably in Safe mode, find and delete the file.

    --When done:
    1.) Navigate to backups location, And DoubleClick on the winkey.reg file.
    Answer yes to the prompt.
    2.) Run reglite, open the same windows key:
    While it's being selected/marked in purple, Use reglite's file menu>Import
    Browse to and select the "winkey.hiv" saved.
    Hit 'open' , merge and 'ok' it.
    Repeat the cleanup steps outlined before in the AppInit value (clearing the data)
    ====================================================

    *If the file is found but can't be deleted!
    Create Dummy folder (e.g. C:\junk) Move it there, first:
    1.)
    -RightClick on it: properties
    /Advanced/Security/permissions \
    and take ownership giving yourself 'Full control'.
    2.)-Right click the 'Container' (junk) folder itself. hit properties.
    -Go to the security tab and click the advanced button.
    -check the box to reset permissions on all child objects.
    Hit apply. ok
    Delete file+folder.
  • edited November 2004
    I will do. Its called com.dll I had to click it twice to get it to appear.
  • edited November 2004
    I dont understand certain parts. Dont wanna screw something up.

    Where is the windows key that u mention thats marked in purple?
  • CrunchieCrunchie Mandurah. Western Australia. Member
    edited November 2004
    When you go to that key, the folder in the left window will be the colour purple.
    So, when you navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows the windows folder will be seen in purple.
Sign In or Register to comment.