Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Networking Forum > Security and Firewalls
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

Security and Firewalls Protecting you against unwanted people and programs

Reply
 
Thread Tools
Old 03-26-2008, 04:45 AM   #1 (permalink)
Registered User
 
Join Date: Aug 2007
Posts: 27
OS: XP Home SP2


Unauthorized DLL Modifications...

I've recently noticed web pages on my computer do not load properly, they tend to half load and stick in certain places (like searches for example) although you can still see the information in the bottom left corner saying "Transferring data from... etc". I'm using firefox, but this happens in Internet Explorer too (both latest versions). I don't know if this is connected to the problem but it seems likely. Yesterday I got a series of about 5 or 6 "Registry Modificatio Detected" windows from Lavasoft Ad-watch, asking mne whether to allow or block the modification of the "Rundlll32" file, I cant remember exactly what it said but then after that it had something about "pxaxurky.dll" and "oaitufvh.dll". Stupidly, I allowed the first three of these windows, but blocked the rest. I had no installers running or anything that i would expect to provoke these modifications. Today, my system has been quite cranky, the mouse movements are jerky at times, the web page problems are still there, and I also got an online poker game tab come up in firefox. There's also been a few windows from Norton Antivirus claiming "A recent attack on your computer has been blocked", or something along those lines. I've just looked in my Norton Antivirus log from yesterday and found this: "Attempted Intrusion "HTTP Trojan Vundo Activity" from your machine against tamotua.com(82.98.235.152) was detected and blocked." I've also looked under the startup tab in the system config window and found these two dll's again:

pxaxurky rundll32.exe "C:\WINDOWS\system32\pxaxurky.dll",b
oaitufvh Rundll32.exe "C:\WINDOWS\system32\oaitufvh.dll",s

I'm not entirely sure whats going on, I've tried putting those dll's into google and found nothing. They seem as though theyre foreign to the windows system32 folder. I've also tried searching for other instances of rundll32.exe on my computer and found nothing except the other one in the service pack folder. Help!
ezsteve is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 03-26-2008, 07:04 AM   #2 (permalink)
Manager, Networking Forums
 
johnwill's Avatar
 
Join Date: Sep 2002
Location: S.E. Pennsylvania, US
Posts: 31,467
OS: XP-Pro, Vista, Linux


Blog Entries: 1
Re: Unauthorized DLL Modifications...

Well, that alone should raise red flags.

Please follow the instructions here (5 pages) and then post all the requested logs in a new thread here for the security analysts to look at. If you have any trouble running any of the scans, leave them and move onto the next.

The security forum is always busy, so please be patient and you will receive a reply as soon as possible. If you go to Thread Tools > Subscribe at the top of your new thread you will receive an email as soon as a reply is posted.
__________________
If TSF has helped you, Tell us about it! or Donate to help keep the site up!

Microsoft MVP - Windows Desktop Experience
johnwill is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 03-26-2008, 08:31 AM   #3 (permalink)
Registered User
 
Join Date: Aug 2007
Posts: 27
OS: XP Home SP2


Re: Unauthorized DLL Modifications...

Thanks, my browser is still playing up at the moment so I'll have to try and do the scan again later.
ezsteve is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -7. The time now is 12:53 PM.



Copyright 2001 - 2008, Tech Support Forum

Search Engine Friendly URLs by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82