PDA

View Full Version : Ati2evxx.dll acts as malware



caprafan
2009-01-07, 20:18
Hoping this is the right place to post this, as we've had problems caused by this and I noticed many people also have this in their logs.
We do have an ATI graphics card, but are not sure whether our copy of Ati2evxx.dll is real or a trojan. Either way, it slowed our machine to a virtual standstill, and I found it running two instances in the process log. Its official purpose is to manage some highly sophisticated hot keys (such as displaying on multiple monitors) that hardly anyone needs, but it's definitely a system hog, and won't allow itself to be deleted even with MSCONFIG. My workaround for the moment has been to rename it, which has worked to isolate other malware.

drragostea
2009-01-08, 00:32
If you can't be sure if the file is a malware, you can always locate it and upload it to VirusTotal to see if it is flagged.

For me, I don't seem to have a .dll file in my Startup, but I do have the service (which I disabled, because I didn't not need it, and like you said most users do not need the hotkeys).

I also located the file using a Search scan which it happened to be lying around the System32 folder.