Unknown startup entries

BadBusta

New member
Local time
3:39 PM
Messages
2
Location
Draper Utah
I wanted to see if anyone could tell me what the following two startup entries might be. I have searched google and neither come up with anything at all about them. I have tried to disable them in ccleaner startup and when I reboot it shows them enabled again. I found them in HiJackThis, but I don't want to delete them without a better understanding of what they might be.

I am running Windows 7 Professional

Here they are:

Yes HKCU:Run Kvopig rundll32.exe "C:\Users\Randy\AppData\Local\opid870.dll",Startup

Yes HKCU:Run Iquzepiguyorukem rundll32.exe "C:\Users\Randy\AppData\Local\inaxisetacoku.dll",Startup

Thank You
Randy Smith
 

My Computer

Computer Manufacturer/Model Number
Dell Studio 1537
OS
Windows 7
CPU
Intel Core 2 Duo P8400 2.26 GHz
Memory
4 GB
Graphics Card(s)
ATI Mobility Radeon HD 3400 Series
Screen Resolution
1920x1200
Hard Drives
Hitachi HTS543232L9A300 ATA Device 300GB
Case
Laptop
Internet Speed
20 mb Qwest Fiber

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell XPS 420
OS
Windows 10, Home Clean Install
CPU
Intel Core2 processsor Q8200(2.33Ghz 1333FSB) Quad Core Tech
Motherboard
Dell
Memory
6 gb
Graphics Card(s)
ATI Radeon 256MB HD3650
Sound Card
Intergrated 7.1 Channel Audio
Monitor(s) Displays
Dell SP2009W 20"
Hard Drives
640 GB Serial ATA Hard drive
Cooling
Fan
Keyboard
Dell USB Keyboard
Mouse
Dell Premium Optical USB
Internet Speed
DSL 2.85
Hi BadBusta,

I would remove these files as they aren't necessary system files, and I doubt they are critical components of any other applications. There's a chance that they're malicious.

  • Go to Jotti.
  • Click Upload.
  • Copy and paste the exact file name in bold:
  • C:\Users\Randy\AppData\Local\opid870.dll
  • C:\Users\Randy\AppData\Local\inaxisetacoku.dll
  • Click Submit.
  • Copy and paste back the results once Jotti has finished scanning the file.
Do the above steps if you want to be sure.

Also, 'HKCU' only means they're located within the Current User hive in the System Registry - it, by no means, automatically means it's an infection.

Thanks,
Harvey Meale
 

My Computer

Computer Manufacturer/Model Number
Dell Inspiron 1545
OS
Windows 7 Home Premium 32-bit, BackTrack 4, Ubuntu
Thank Yo for the quick response. Jotti is an excellent tool. I will be able to delete them from my system. They both showed multiple entries for trojans.

Thank You
Randy Smith
 

My Computer

Computer Manufacturer/Model Number
Dell Studio 1537
OS
Windows 7
CPU
Intel Core 2 Duo P8400 2.26 GHz
Memory
4 GB
Graphics Card(s)
ATI Mobility Radeon HD 3400 Series
Screen Resolution
1920x1200
Hard Drives
Hitachi HTS543232L9A300 ATA Device 300GB
Case
Laptop
Internet Speed
20 mb Qwest Fiber
There you go. Glad I could help.
 

My Computer

Computer Manufacturer/Model Number
Dell Inspiron 1545
OS
Windows 7 Home Premium 32-bit, BackTrack 4, Ubuntu
Back
Top