ws2help32.dll - Dangerous
ws2help32.dll
Manual removal instructions:
Antivirus Report of ws2help32.dll:
ws2help32.dll
We suggest you to remove ws2help32.dll from your computer as soon as possible.
Ws2help32.dll is Trojan/Backdoor.
Kill the file ws2help32.dll and remove ws2help32.dll from Windows startup.
File: gm.exe
Classification:
Antivirus Version Last Update Result
Avast 4.8.1335.0 2009.07.01 Win32:Trojan-gen {Other}
AVG 8.5.0.386 2009.07.02 -
BitDefender 7.2 2009.07.02 -
Comodo 1538 2009.07.02 -
DrWeb 5.0.0.12182 2009.07.02 -
F-Secure 8.0.14470.0 2009.07.02 Suspicious:W32/Malware!Gemini
Kaspersky 7.0.0.125 2009.07.02 -
Microsoft 1.4803 2009.07.02 -
NOD32 4209 2009.07.02 -
Symantec 1.4.4.12 2009.07.02 -
Additional information
File size: 43008 bytes
MD5 : 5b489cd58da06309297c1e084aa01a17
SHA1 : 1224334408369187b7f9c7a05b8d96e557301fd9
Installation
When the program is executed, it creates the following registry subkeys and values:
----------------------------------
Keys added:2
----------------------------------
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000
----------------------------------
Values added:7
----------------------------------
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000\Service: "AppMgmt"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000\Legacy: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000\ConfigFlags: 0x00000000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000\Class: "LegacyDriver"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000\ClassGUID: "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000\DeviceDesc: "Application Management"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\NextInstance: 0x00000001
----------------------------------
Values modified:6
----------------------------------
HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Start: 0x00000003
HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Start: 0x00000002
HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Type: 0x00000020
HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Type: 0x00000120
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Start: 0x00000002
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Start: 0x00000004
----------------------------------
Files added:3
----------------------------------
C:\Documents and Settings\Administrator\Local Settings\Temp\sfc_ox.dll
C:\WINDOWS\system32\dllcache\appmgmts.dll
C:\WINDOWS\system32\ws2help32.dll
----------------------------------
Files deleted:1
----------------------------------
C:\sand-box\gm.exe
----------------------------------
Files [attributes?] modified:1
----------------------------------
C:\WINDOWS\system32\appmgmts.dll
----------------------------------
Folders added:0
----------------------------------
----------------------------------
Folders deleted:0
----------------------------------
----------------------------------
Total changes:20
----------------------------------
-------------------------------------------------------------------------------------
Detected by RegRun Reanimator:
Item Name: APPMGMTS.DLL
Author: Unknown
Related File: C:\WINDOWS\SYSTEM32\APPMGMTS.DLL
Type: Infected System Files
Removal Results: Success
Number of reboot: 1
-------------------------------------------------------------------------------------
Recommended software:
UnHackMe anti-rootkit and anti-malware
http://www.unhackme.com
RegRun Security Suite (Good choice for removal and protection)
ws2help32.dll | Malware |
ws2help32.dll | Dangerous |
ws2help32.dll | High Risk |
Ws2help32.dll is Trojan/Backdoor.
Kill the file ws2help32.dll and remove ws2help32.dll from Windows startup.
File: gm.exe
Classification:
Antivirus Version Last Update Result
Avast 4.8.1335.0 2009.07.01 Win32:Trojan-gen {Other}
AVG 8.5.0.386 2009.07.02 -
BitDefender 7.2 2009.07.02 -
Comodo 1538 2009.07.02 -
DrWeb 5.0.0.12182 2009.07.02 -
F-Secure 8.0.14470.0 2009.07.02 Suspicious:W32/Malware!Gemini
Kaspersky 7.0.0.125 2009.07.02 -
Microsoft 1.4803 2009.07.02 -
NOD32 4209 2009.07.02 -
Symantec 1.4.4.12 2009.07.02 -
Additional information
File size: 43008 bytes
MD5 : 5b489cd58da06309297c1e084aa01a17
SHA1 : 1224334408369187b7f9c7a05b8d96e557301fd9
Installation
When the program is executed, it creates the following registry subkeys and values:
----------------------------------
Keys added:2
----------------------------------
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000
----------------------------------
Values added:7
----------------------------------
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000\Service: "AppMgmt"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000\Legacy: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000\ConfigFlags: 0x00000000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000\Class: "LegacyDriver"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000\ClassGUID: "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000\DeviceDesc: "Application Management"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\NextInstance: 0x00000001
----------------------------------
Values modified:6
----------------------------------
HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Start: 0x00000003
HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Start: 0x00000002
HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Type: 0x00000020
HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Type: 0x00000120
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Start: 0x00000002
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Start: 0x00000004
----------------------------------
Files added:3
----------------------------------
C:\Documents and Settings\Administrator\Local Settings\Temp\sfc_ox.dll
C:\WINDOWS\system32\dllcache\appmgmts.dll
C:\WINDOWS\system32\ws2help32.dll
----------------------------------
Files deleted:1
----------------------------------
C:\sand-box\gm.exe
----------------------------------
Files [attributes?] modified:1
----------------------------------
C:\WINDOWS\system32\appmgmts.dll
----------------------------------
Folders added:0
----------------------------------
----------------------------------
Folders deleted:0
----------------------------------
----------------------------------
Total changes:20
----------------------------------
-------------------------------------------------------------------------------------
Detected by RegRun Reanimator:
Item Name: APPMGMTS.DLL
Author: Unknown
Related File: C:\WINDOWS\SYSTEM32\APPMGMTS.DLL
Type: Infected System Files
Removal Results: Success
Number of reboot: 1
-------------------------------------------------------------------------------------
Recommended software:
UnHackMe anti-rootkit and anti-malware
http://www.unhackme.com
RegRun Security Suite (Good choice for removal and protection)
Dmitry Sokolov:
I created UnHackMe in 2006 to fix the problem that antivioruses did not fix: detecting rootkits.
Since that time I work every day to fix the issues that antiviruses cannot.
If your antivirus have not helped you solve the problem, you should try UnHackMe.
We are a small company and you can ask me directly, if you have any questions.