Results 1 to 7 of 7

Thread: Start Up DLLs

  1. #1
    Junior Member
    Join Date
    Jan 2008
    Posts
    4

    Unhappy Start Up DLLs

    Recenty my system was affected with Rootkit & i had formatted by C drive. My other drives cant be opened in the normal way. I have to use Explorer/ type the drive name in command promt..

    When i was checking for my startup entries tho S&D i found that the DLLs
    1) WINotify.dll
    2) crypt32.dll
    3) cryptnet.dll
    4) cscdll.dll
    5) wlnotify ( 4entires where there -
    one value is "Schedule"
    another "ScCertProp"
    another "wlballoon"
    another "termsrv"

    KEY - VALUE - COMMAND LINE
    WinLogon - crypt32chain - crypt32.dll
    WinLogon - cryptnet - cryptnet.dll
    WinLogon - cscdll - cscdll.dll
    WinLogon - ScCertProp - wInotify.dll
    WinLogon - Schedule - wInotify.dll
    WinLogon - sclgntfy - sclgntfy.dll
    WinLogon - SensLogn - WINotify.dll
    WinLogon - termsrv - wInotify.dll
    WinLogon - wlballoon - wInotify.dll

    this link http://www.softwaretipsandtricks.com...NOTIFYDLL.html
    Says entry is a dangerous spy ware . Is it TRUE plz help.. .

  2. #2
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    vivekphlp:

    Is the entry in the startup wlnotify.dll or winotify.dll (l or i as the second letter)?

    Also, please see the following thread:

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz IntelŪ PentiumŪ 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

  3. #3
    Junior Member
    Join Date
    Jan 2008
    Posts
    4

    Default

    Iam attaching my report...

  4. #4
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    Quote Originally Posted by vivekphlp View Post
    ...

    WinLogon - wlballoon - wInotify.dll

    this link http://www.softwaretipsandtricks.com...NOTIFYDLL.html
    Says entry is a dangerous spy ware . Is it TRUE plz help.. .
    Your report shows WlNotify.dll (in caps WLNOTIFY.DLL) which is a legitimate Microsoft dll file.

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz IntelŪ PentiumŪ 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

  5. #5
    Junior Member
    Join Date
    Jan 2008
    Posts
    4

    Default

    ok . .. Thanks.. . I am confused with some other sites but i do believe in "S&D". . .
    http://www.computing.net/security/ww...rum/22249.html
    They say it can be a Trojan ... .
    bit confused..
    Can you give me a solution for the problem with oppening my drives. . . When i click my drives it pops up an "open with page" .. .
    plz help... .

  6. #6
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    There difference between the dll that is in your startup entry and what you are looking up and keep providing references for.

    Your startup entry is WlNotify.dll (with a lower case "L" as the second letter). You keep looking up WINotify.dll (with an upper case "I" as the second letter).

    WLNOTIFY.DLL is a legitimate Microsoft dll file.
    _______________

    I really don't know what is causing the problems with your disk. Did you go into Disk Management and assign a drive letter to the disk?

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz IntelŪ PentiumŪ 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

  7. #7
    Junior Member
    Join Date
    Jan 2008
    Posts
    4

    Default

    Thanks
    By the by the problem with oppening my drives started after the attack of "Hackit.Rootkit"... whenever i try to open the drive it displays "open with" dialog... I have to use
    RUN -> "drive name"

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •