avwapi32.dll

Psych

Senior member
Feb 3, 2004
324
0
0
I'm not sure how this got onto my computer since I am usually careful, but I noticed a significant slowdown in my computer and numerous security pop-ups from Norton, so I checked it out. Apparently a file named "avwapi32.dll" was copied into my \Windows\system32 folder, edow.exe into \Windows, VBounce into \Program Files, and a startup entry.

Winlogon.exe was constantly trying to contact sites like www.888.com and www.look2me.com, but nothing was done to it. I removed everything except avwapi32.dll because it was being used by a process. I tried in Safe Mode, but the same thing happened.

I think Winlogon is being tricked into using avwapi32.dll as an application extension, and since Winlogon can't be turned off, I can't delete avwapi32.dll! Is there any way to do this?

If your answer is to use a DOS boot disk with an NTFS reader and modifier, could you give some instructions or a link to a good way of doing that?
 

dclive

Elite Member
Oct 23, 2003
5,626
2
81
Originally posted by: Psych
I'm not sure how this got onto my computer since I am usually careful, but I noticed a significant slowdown in my computer and numerous security pop-ups from Norton, so I checked it out. Apparently a file named "avwapi32.dll" was copied into my \Windows\system32 folder, edow.exe into \Windows, VBounce into \Program Files, and a startup entry.

Winlogon.exe was constantly trying to contact sites like www.888.com and www.look2me.com, but nothing was done to it. I removed everything except avwapi32.dll because it was being used by a process. I tried in Safe Mode, but the same thing happened.

I think Winlogon is being tricked into using avwapi32.dll as an application extension, and since Winlogon can't be turned off, I can't delete avwapi32.dll! Is there any way to do this?

If your answer is to use a DOS boot disk with an NTFS reader and modifier, could you give some instructions or a link to a good way of doing that?

Boot to Recovery Console from your XP CD.
Log in, and copy userinit.exe to avwapi32.dll (both are in c:\windows\system32)

Or you could simply go into regedit, search for that data in winlogon, and modify the winlogin key so it only points to userinit.exe and not avwapi32.dll, then reboot.
 

Psych

Senior member
Feb 3, 2004
324
0
0
Thanks. Just curious, what tells Winlogon to load other DLLs and use them?
 

Psych

Senior member
Feb 3, 2004
324
0
0
Which one, in specific? Is there some interface to enable and diable extensions for these processes?
 

dclive

Elite Member
Oct 23, 2003
5,626
2
81
Originally posted by: Psych
Which one, in specific? Is there some interface to enable and diable extensions for these processes?

Or you could simply go into regedit, search for that data in winlogon, and modify the winlogin key so it only points to userinit.exe and not avwapi32.dll, then reboot.

(in other words, search for avwapi32.dll in RegEdt32, and when you get to the Winlogon key, you'll see something like "c:\windows\system32\userinit.exe, c:\windows\system32\avwapi32.dll," --- everything after that first comma (ie the entire avwapi32.dll part) is bad.)

This is an educated guess based on another post I read on this subject. I suggest opening up regedit and looking for that value in the winlogon key, and seeing if it is present.

...or just go into recovery console, rename avwapi32.dll to avwapi32.old, and see what happens. Worst case you'd just need to go back into RC to rename the file...
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |