From JJ@21:1/5 to Jan K. on Mon Jan 22 01:25:46 2024
XPost: alt.comp.freeware
On Sat, 20 Jan 2024 23:15:24 +0100, Jan K. wrote:
The KC Softwares freeware "Startup Sentinel" usually reports new things after I
install poorly behaved software but this time it reported something different. https://www.kcsoftwares.com/?sus
This is what Startup Sentinel reported after a Windows update.
HKLM:RunOnce wextract_cleanup0 rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Windows\TEMP\IXP000.TMP\"
ADVPACK.DLL is a legit Windows own DLL as long as its in the Windows system directory (oterwise it'd be suspicious). It's been around since Windows 95,
and it was based on Windows 3.x's ADVINS16.DLL.