gfkernel.dll

Page 1 of 2 12 LastLast

  1. Posts : 6,618
    W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCE
       #1

    gfkernel.dll


    Since I don't find that any of the malware scanner are 100% reliable, I usually run more than one. It occurred to me that I hadn't run SpyBot S&D for a while, so after updating it, I did so. The result was that it listed the file virtumonde.sdn at C:\\Windows\System32\gfbaksm.dat. after a quick Google, I decided to let Spybot remove it.

    However, there is another file called gfkernel.dll, that SpyBot didn't mark or remove, that appears to be related to the former. What I have Googled seems to indicate that it should be removed also, but since SpyBot didn't complain about it, I wanted to double check by posting here and see if anyone knows anything about it?
      My Computer


  2. Posts : 13,354
    Windows 7 Professional x64
       #2

    It does look dangerous. Try running Malwarebytes or some other program, and see if it picks it up.

    You can also try creating a backup the file, and deleting it.
      My Computer


  3. Posts : 2,303
    Windows 7 & Windows Vista Ultimate
       #3

    Good call, Jon. It is indeed nasty. See Prevx-GFKERNEL.DLL.html

    With Virtumonde identified, I suggest taking a close look at Add/Remove programs and uninstalling all versions of Java prior to SE6u20. This includes any item listing J2SE or Java Runtime Environment in the name. It would also be a good idea to run JavaRa.

      My Computer


  4. Posts : 6,618
    W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCE
    Thread Starter
       #4

    Corrine said:
    Good call, Jon. It is indeed nasty. See Prevx-GFKERNEL.DLL.html

    With Virtumonde identified, I suggest taking a close look at Add/Remove programs and uninstalling all versions of Java prior to SE6u20. This includes any item listing J2SE or Java Runtime Environment in the name. It would also be a good idea to run JavaRa.

    I had already uninstalled all older versions of Java several days ago. Is this the most common source of these files? The one thing that I wish MS would change is that there would be an easy and simple means of tracking the source of all files installed.

    What is JavaRa?

    Just as a footnote, I just finished a full scan with Malwarebytes, and it didn't squawk about the file either, but considering the remarks given, I'm deleting it.
      My Computer


  5. Posts : 11,990
    Windows 7 Ultimate 32 bit
       #5

    JavaRa is a Java uninstaller. It gets everything related to Java
      My Computer


  6. Posts : 6,618
    W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCE
    Thread Starter
       #6

    Thanks, but since I just installed update 20 and uninstalled everything prior to that, just a few days ago, I will leave JavaRa until the next update.

    EDIT: Of course, assuming that update 20 did not install these files, I guess that the uninstaller in Programs And Features doesn't do too good of a job.
      My Computer


  7. Posts : 11,990
    Windows 7 Ultimate 32 bit
       #7

    JavaRa itself gets updated and will only remove Java up to certain version. Right now it seems to be two or more versions behind. At any rate, it does does not remove the current version.
      My Computer


  8. Posts : 2,303
    Windows 7 & Windows Vista Ultimate
       #8

    JavaRa cleans up the left-overs missed in the uninstall process.
      My Computer


  9. Posts : 11,990
    Windows 7 Ultimate 32 bit
       #9

    Thanks, Corrine.
      My Computer


  10. Posts : 5,056
    Windows 7 x64 pro/ Windows 7 x86 Pro/ XP SP3 x86
       #10

    According to the security forums, A-squared is able to detect these 2 files. If seekermeister hasnt deleted them yet, perhaps he can check.
      My Computer


 
Page 1 of 2 12 LastLast

Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 18:51.
Find Us