ws2help32.dll - Dangerous

ws2help32.dll

Manual removal instructions:

Antivirus Report of ws2help32.dll:
ws2help32.dll Malware
ws2help32.dllDangerous
ws2help32.dllHigh Risk
ws2help32.dll
We suggest you to remove ws2help32.dll from your computer as soon as possible.
Ws2help32.dll is Trojan/Backdoor.
Kill the file ws2help32.dll and remove ws2help32.dll from Windows startup.

File: gm.exe

Classification:
Antivirus Version Last Update Result
Avast 4.8.1335.0 2009.07.01 Win32:Trojan-gen {Other}
AVG 8.5.0.386 2009.07.02 -
BitDefender 7.2 2009.07.02 -
Comodo 1538 2009.07.02 -
DrWeb 5.0.0.12182 2009.07.02 -
F-Secure 8.0.14470.0 2009.07.02 Suspicious:W32/Malware!Gemini
Kaspersky 7.0.0.125 2009.07.02 -
Microsoft 1.4803 2009.07.02 -
NOD32 4209 2009.07.02 -
Symantec 1.4.4.12 2009.07.02 -

Additional information
File size: 43008 bytes
MD5 : 5b489cd58da06309297c1e084aa01a17
SHA1 : 1224334408369187b7f9c7a05b8d96e557301fd9

Installation
When the program is executed, it creates the following registry subkeys and values:

----------------------------------
Keys added:2
----------------------------------
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000

----------------------------------
Values added:7
----------------------------------
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000\Service: "AppMgmt"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000\Legacy: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000\ConfigFlags: 0x00000000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000\Class: "LegacyDriver"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000\ClassGUID: "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000\DeviceDesc: "Application Management"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\NextInstance: 0x00000001

----------------------------------
Values modified:6
----------------------------------
HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Start: 0x00000003
HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Start: 0x00000002
HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Type: 0x00000020
HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Type: 0x00000120
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Start: 0x00000002
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Start: 0x00000004

----------------------------------
Files added:3
----------------------------------
C:\Documents and Settings\Administrator\Local Settings\Temp\sfc_ox.dll
C:\WINDOWS\system32\dllcache\appmgmts.dll
C:\WINDOWS\system32\ws2help32.dll

----------------------------------
Files deleted:1
----------------------------------
C:\sand-box\gm.exe

----------------------------------
Files [attributes?] modified:1
----------------------------------
C:\WINDOWS\system32\appmgmts.dll

----------------------------------
Folders added:0
----------------------------------

----------------------------------
Folders deleted:0
----------------------------------

----------------------------------
Total changes:20
----------------------------------

-------------------------------------------------------------------------------------
Detected by RegRun Reanimator:

Item Name: APPMGMTS.DLL
Author: Unknown
Related File: C:\WINDOWS\SYSTEM32\APPMGMTS.DLL
Type: Infected System Files

Removal Results: Success
Number of reboot: 1
-------------------------------------------------------------------------------------

Recommended software:
UnHackMe anti-rootkit and anti-malware
http://www.unhackme.com
RegRun Security Suite (Good choice for removal and protection)

Remove ws2help32.dll now!

Dmitry Sokolov:

I created UnHackMe in 2006 to fix the problem that antivioruses did not fix: detecting rootkits.

Since that time I work every day to fix the issues that antiviruses cannot.

If your antivirus have not helped you solve the problem, you should try UnHackMe.

We are a small company and you can ask me directly, if you have any questions.

Testimonials

You can read UnHackMe testimonials here.