A Windows XP help forum. PCbanter

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Go Back   Home » PCbanter forum » Microsoft Windows XP » Security and Administration with Windows XP
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

wotuzapi.dll and Software Distribution Service 3.0



 
 
Thread Tools Display Modes
  #1  
Old December 3rd 09, 02:20 AM posted to microsoft.public.windowsxp.security_admin
usfinecats
external usenet poster
 
Posts: 1
Default wotuzapi.dll and Software Distribution Service 3.0

I noticed my computer behaving mighty odd today and yesterday. I discovered
in the HKLM\Software\Microsoft\WindowsNT\CurrentVersion\W indows
AppInit_Dlls that there were odd settings! (this setting is very bad
news, it causes dll's to get attached to everything!).

Also noticed in HKLM\Software\Microsoft\Windows\CurrentVersion\Run
more odd settings:

In both cases there were references to wotuzapi.dll, mokehohi.dll,
hewalots.dll,


Wotuzapi.dll is known maleware, I could not find references to the others.
When I tried to manually delete these values, they IMMEDIATELY were restored
, grr!

Fortunately, I had a "restore point" from just a few days prior and was able
to restore before they were installed. In the Restore Point tool it
indicated that a recent update was done by Software Distribution Service 3.0.


I don't know if Software Distribution Service 3.0 is the cause of this
wasted day, but restoring prior to it saved my bacon.
--
Gak -
Finecats
Ads
  #2  
Old December 3rd 09, 03:45 AM posted to microsoft.public.windowsxp.security_admin
David H. Lipman
external usenet poster
 
Posts: 4,185
Default wotuzapi.dll and Software Distribution Service 3.0

From: "usfinecats"

| I noticed my computer behaving mighty odd today and yesterday. I discovered
| in the HKLM\Software\Microsoft\WindowsNT\CurrentVersion\W indows
| AppInit_Dlls that there were odd settings! (this setting is very bad
| news, it causes dll's to get attached to everything!).

| Also noticed in HKLM\Software\Microsoft\Windows\CurrentVersion\Run
| more odd settings:

| In both cases there were references to wotuzapi.dll, mokehohi.dll,
| hewalots.dll,


| Wotuzapi.dll is known maleware, I could not find references to the others.
| When I tried to manually delete these values, they IMMEDIATELY were restored
| , grr!

| Fortunately, I had a "restore point" from just a few days prior and was able
| to restore before they were installed. In the Restore Point tool it
| indicated that a recent update was done by Software Distribution Service 3.0.


| I don't know if Software Distribution Service 3.0 is the cause of this
| wasted day, but restoring prior to it saved my bacon.
| --
| Gak -
| Finecats

You had "malware" and may still be infected !

I suggest you download, install and update Malwarebytes' Anti-Malware and perform a scan
of the platform.

http://www.malwarebytes.org/mbam/program/mbam-setup.exe

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


  #3  
Old December 3rd 09, 07:48 PM posted to microsoft.public.windowsxp.security_admin
MowGreen
external usenet poster
 
Posts: 534
Default wotuzapi.dll and Software Distribution Service 3.0

All updates create a restore point with the title " Software
Distribution Service 3.0 ". The update (s) did not infect the system.
Although it's apparent that the restore point you used did not contain
whatever infected the system, suggest you follow Mr. Lipman's advice to
ensure the system is still clean.
First, empty the %temp% subfolder *after* rebooting the system and then
empty Internet Explorer's Temporary Internet Files to decrease the
amount of MBAM's scan and to protect against those locations containing
any "undesired" files.

To empty your User Account's Temp folder click Start Run enter
%temp%
Click OK.
Delete IE's TIF by opening Internet Options in the Control Panel so that
IE is closed when you do that.

MowGreen
===============
*-343-* FDNY
Never Forgotten
===============

banthecheck.com
"Security updates should *never* have *non-security content* prechecked"





usfinecats wrote:

I noticed my computer behaving mighty odd today and yesterday. I discovered
in the HKLM\Software\Microsoft\WindowsNT\CurrentVersion\W indows
AppInit_Dlls that there were odd settings! (this setting is very bad
news, it causes dll's to get attached to everything!).

Also noticed in HKLM\Software\Microsoft\Windows\CurrentVersion\Run
more odd settings:

In both cases there were references to wotuzapi.dll, mokehohi.dll,
hewalots.dll,


Wotuzapi.dll is known maleware, I could not find references to the others.
When I tried to manually delete these values, they IMMEDIATELY were restored
, grr!

Fortunately, I had a "restore point" from just a few days prior and was able
to restore before they were installed. In the Restore Point tool it
indicated that a recent update was done by Software Distribution Service 3.0.


I don't know if Software Distribution Service 3.0 is the cause of this
wasted day, but restoring prior to it saved my bacon.

 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off






All times are GMT +1. The time now is 12:29 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright ©2004-2024 PCbanter.
The comments are property of their posters.