Hi, one of the lines from HijackThis log is:
04 - HKLM\..\Run: [Esoxopegogajeku] rundll32.exe "C:\WINDOWS\eqilusef.dll",Startup
and I couldn't find any info online about it - can I check and "fix checked" it in HijackThis?
Page 1 of 1
eqilusef.dll - is it malware?
#2
Posted 12 April 2011 - 05:43 PM
Yes, that's malware.
Lawrence Abrams
Circle BleepingComputer on Google+!
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
How to detect vulnerable programs using Secunia Personal Software Inspector <- Everyone should do this!
Circle BleepingComputer on Google+!
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
How to detect vulnerable programs using Secunia Personal Software Inspector <- Everyone should do this!
#4
Posted 13 April 2011 - 11:39 AM
I checked that one item in HijackThis and "fix checked" - report successful; however it returned again on startup.
Same thing deleting that value from registry and it returned on startup. I found eqilusef.dll in the windows directory but could not delete - "Access denied" (probably b/c it was in use).
Startup safe mode and removed the value again from registry and then was able to delete eqilusef.dll from windows dir.
No more value on startup - to date.
This all started b/c of redirect virus.
Thanks again!
Same thing deleting that value from registry and it returned on startup. I found eqilusef.dll in the windows directory but could not delete - "Access denied" (probably b/c it was in use).
Startup safe mode and removed the value again from registry and then was able to delete eqilusef.dll from windows dir.
No more value on startup - to date.
This all started b/c of redirect virus.
Thanks again!
#5
Posted 13 April 2011 - 01:57 PM
If you had the google redirects, be sure to use this guide as well:
http://www.bleepingcomputer.com/virus-removal/remove-tdss-tdl3-alureon-rootkit-using-tdsskiller
http://www.bleepingcomputer.com/virus-removal/remove-tdss-tdl3-alureon-rootkit-using-tdsskiller
Lawrence Abrams
Circle BleepingComputer on Google+!
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
How to detect vulnerable programs using Secunia Personal Software Inspector <- Everyone should do this!
Circle BleepingComputer on Google+!
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
How to detect vulnerable programs using Secunia Personal Software Inspector <- Everyone should do this!
#6
Posted 13 April 2011 - 04:23 PM
Yes, I followed a clean/removal pattern I was seeing on the other forum topics and looking through my logs:
TDSSKiller - Clear Java Cache - TFC - MBAM - HijackThis... and that's where that file turned up.
Worked great (so far) - thanks guys!
TDSSKiller - Clear Java Cache - TFC - MBAM - HijackThis... and that's where that file turned up.
Worked great (so far) - thanks guys!
Share this topic:
Page 1 of 1

Help

Back to top









