From: "liu" <spamfreeliu@yahoo.com>
| What is this tuttut.dll + tuttut.ini inside Windows folder? It runs
| while starting up. From regedit, it has an entry BootService with data
| "urndll32.exe "c:\windows\tuttut.dll",realset" under HKEY_LOCAL_MACHINE
| \SOFTWARE\Microsoft\Windows\Run\ .
| It's probably from one of the file sharing sites like depositfiles.com
| I visited a few days ago.
Please submit a sample of "tuttut.dll" to Virus Total --
http://www.virustotal.com/flash/index_en.html
The submission will then be tested against many different AV vendor's scanners.
That will give you an idea what it is and who recognizes it. In addition, unless told
otherwise, Virus Total will provide the sample to all participating vendors.
You can also submit a suspect, one at a time, via the following email URL...
mailto:scan@virustotal.com?subject=SCAN
When you get the report, please post back the exact results.
--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Reply With Quote