troubleshooting Question

surfsidekick AppInit_DLLs

Avatar of dave4dl
dave4dl asked on
Windows XP
7 Comments1 Solution1355 ViewsLast Modified:
In the registry location
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
there is a key called
AppInit_DLLs
with a value of
"repairs303169590.dll"
that i picked up from somewhere as part of the surfsidekick virus

When i change or delete this registry value it immediately changes back to "repairs303169590.dll"

I have tried to delete this file with Unlocker, killbox, deleteReboot, and hijackthis (via the delete on reboot) with no success.  Unlocker fails because the "F:\WINDOWS\system32\repairs303169590.dll" file is locked by the [System Process] process (as well as every other process).  Delete on reboot fails because "AppInit_DLLs" loads before the other boot commands are run.

I have tried writing a dos batch file that continuously loops and merges an empty string to the AppInit_DLLs value and while running it (or several instances of it) cold rebooting or regular rebooting.  None of these things have worked.

Does anyone know how to delete a file like this (or have any ideas about it)?
ASKER CERTIFIED SOLUTION
Join our community to see this answer!
Unlock 1 Answer and 7 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 7 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros