Computing.Net > Forums > Security and Virus > What is devmgrn.dll?

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

What is devmgrn.dll?

Reply to Message Icon

Original Message
Name: jclfc
Date: September 11, 2007 at 16:59:24 Pacific
Subject: What is devmgrn.dll?
OS: Win XP SP2
CPU/Ram: NA
Model/Manufacturer: NA
Comment:

Hi,

For the last few days every time I attempt to open a browser window, be it IE or My Computer/Documents etc., my AVG free edition pops up with the following message...

Threat Detected!
While opening file: C:\Windows\SYSTEM32\devmgrn.dll
Trojan horse BHO.AXY

I have tried using heal and move to vault but they prompt me to restart and the problem is still there after rebooting. I've even tried in Safe Mode.

I've used HijackThis, AVG free, Avast free, KillBox, BHODemon and AdAware to remove it but nothing has.

I'm also having a problem with Google search pages being redirected to some IP address and then onto Search-Daily.com.

Please help!



Report Offensive Message For Removal


Response Number 1
Name: Johnw
Date: September 12, 2007 at 01:04:24 Pacific
Reply: (edit)

Open Hijackthis, Click Open the Misc tools section Then click the Open Uninstall Manager... button.
The Add/Remove Programs Manager panel should appear.
In this panel click the Save list button.
Save the uninstall_list.txt file to your desktop and copy and paste the contents here.


Report Offensive Follow Up For Removal

Response Number 2
Name: jclfc
Date: September 12, 2007 at 13:04:06 Pacific
Reply: (edit)

Here you go:

3ivx MPEG-4 5.0.1 (remove only)
7-Zip 4.42
Ad-Aware 2007
Adobe Flash Player ActiveX
Adobe Reader 8.1.0
Apple Software Update
Avance AC'97 Audio
avast! Antivirus
AVG 7.5
AVS Cover Editor 1.3.1.79 (AVSMedia)
AVS DVD Copy version 1.4
BHODemon 2.0.0.23
BitTorrent 5.0.7
BlindWrite 6
BT Broadband Desktop Help
BT Home Hub
BT Home Hub USB Installer
BT Softphone 1.5.3.6
BT Wireless Connection Manager
BT Yahoo! Applications
ConvertXtoDVD 2.2.3.258
DivX Codec
DivX Converter
DivX Player
DivxToDVD 0.5.2b
Elecard MPEG-2 Decoder&Streaming Pack
ffdshow [rev 1405] [2007-08-04]
FM Modifier 2.12
Football Manager 2007
Formula V3 v2.28
HijackThis 2.0.0
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB918997)
Hotfix for Windows XP (KB926239)
iTunes
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office FrontPage 2003
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (2.0)
MP3 To Ringtone Gold 5.23
MP3 Wav Editor 3.00
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 6.0 Parser (KB933579)
Nero 7 Essentials
PowerISO
QuickTime
Real Alternative 1.52 Lite
SAMSUNG CDMA Modem Driver Set
SAMSUNG Mobile Composite Device Software
Samsung Mobile phone USB driver Software
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
Samsung PC Studio 3
Samsung PC Studio 3 USB Driver Installer
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938829)
Spybot - Search & Destroy 1.4
System Requirements Lab
Thoosje Sidebar 2.2
Trojan Remover 6.6.1
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
VAIOXP
VCDEasy
Vista Visual Pack 7.0
VSO CopyToDVD 4
VSO Inspector 1.3.1.82
WDN4OAK+
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows Sidebar
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
WinRAR archiver
WinZip 11.1
Xvid 1.1.2 final uninstall



Report Offensive Follow Up For Removal

Response Number 3
Name: Johnw
Date: September 12, 2007 at 14:34:25 Pacific
Reply: (edit)

Is devmgrn correct? Copy & paste to stop typo's.

Have you turned off system restore?
How to turn off or turn on Windows XP System Restore
http://service1.symantec.com/SUPPOR...

Now run AVG.

Download >
ATF Cleaner
http://www.atribune.org/content/vie...
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browser
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
If you use Opera browser
Click Opera at the top and choose: Select All
Click the Empty Selected button.

Reboot.

Turn System Restore back on.

How is it now?


Report Offensive Follow Up For Removal

Response Number 4
Name: jclfc
Date: September 12, 2007 at 15:24:48 Pacific
Reply: (edit)

Hi,

I've followed your instructions but the problem is still there.

The file is called devmgrn.dll. It is mentioned twice in a HijackThis log -

O2 - BHO: (no name) - {421B7566-ABB1-437F-AEA2-8291B7F564F1} - c:\windows\system32\devmgrn.dll

O20 - Winlogon Notify: dreacrya - C:\WINDOWS\SYSTEM32\devmgrn.dll

Hope you don't mind me posting that by the way!


Report Offensive Follow Up For Removal

Response Number 5
Name: Johnw
Date: September 12, 2007 at 15:46:25 Pacific
Reply: (edit)

"Hope you don't mind me posting that by the way!"

No, that's Ok, I'm a private user, nothing to do with the forum management.

Have you ticked those items & clicked > Fix checked in HiJackThis?

Have you run AVG in Safe Mode?


Report Offensive Follow Up For Removal


Response Number 6
Name: Johnw
Date: September 12, 2007 at 15:51:25 Pacific
Reply: (edit)

Opp's, see you did try Safe Mode, worth a try again.

Google dos'nt show anything for that dll, plenty here on Search-Daily.com

http://www.google.com.au/search?hl=...


Report Offensive Follow Up For Removal

Response Number 7
Name: jclfc
Date: September 13, 2007 at 07:53:36 Pacific
Reply: (edit)

I've tried running all the programs in safe mode. Is there anyway to force a delete of the dll?


Report Offensive Follow Up For Removal

Response Number 8
Name: Johnw
Date: September 13, 2007 at 16:30:16 Pacific
Reply: (edit)

You have Killbox, have you tried it in Safe mode?

Here is more if needed.

You cannot delete a file or a folder on an NTFS file system volume
http://support.microsoft.com/defaul...

Delete - Can't Delete Files or Folders
http://www.kellys-korner-xp.com/xp_...
http://theeldergeek.com/delete_unde...
Permission Denied - When Trying to Delete Folders/Files
http://www.kellys-korner-xp.com/xp_...

Windows Explorer/Tools/Folder Options/View/Unmark "Use Simple File Sharing". Right click the folder/file in question/Properties/Security/Advanced/Owner/Set Permissions.

HOW TO: Set, View, Change or Remove File and Folder Permissions
http://www.kellys-korner-xp.com/xp_...
http://support.microsoft.com/suppor...

Scandisk is called Chkdsk in XP
http://www.freepctech.com/pc/xp/xp0...
http://kb.ultratech-llc.com/?File=S...
http://labmice.techtarget.com/windo...
Information about the chkdsk command
http://www.computerhope.com/chkdskh...
How to perform disk error checking in Windows XP
http://support.microsoft.com/?KBID=...
Chkdsk (Chkdsk.exe) is a command-line tool that checks volumes for problems. The tool then tries to repair any that it finds. For example, Chkdsk can repair problems related to bad sectors, lost clusters, cross-linked files, and directory errors. To use Chkdsk, you must log on as an administrator or as a member of the Administrators group.
You can also run Chkdsk from My Computer or from Windows Explorer.


Report Offensive Follow Up For Removal

Response Number 9
Name: jclfc
Date: September 17, 2007 at 16:44:20 Pacific
Reply: (edit)

Still can't remove it. Please, someone out there must know what is going on?


Report Offensive Follow Up For Removal

Response Number 10
Name: Johnw
Date: September 17, 2007 at 18:06:59 Pacific
Reply: (edit)

I would do HiJackThis again.

If possible run HJT in Normal mode ( not Safe ) with all your normal startup's working.
HijackThis Tutorial - How to Analyse your own log.
http://spywarewarrior.com/viewtopic...
http://hometown.aol.co.uk/jrmc137/h...
http://www.bleepingcomputer.com/tut...
http://www.malwarehelp.org/understa...
HijackThis log file analysis ( online )
http://hijackthis.de/index.php?lang...

Malware Prevention: Prevent Re-infection
http://wiki.castlecops.com/Malware_...


Report Offensive Follow Up For Removal






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge
Poll History




Data Recovery Software