Skip to content
View in the app

A better way to browse. Learn more.

MSFN

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

GDIhook.dll being reported as viral

Featured Replies

It was mentioned today in microsoft.public.win98.gen_discussion that Paolo Monti's "GDI32 / WMF Patch" (gdihook.dll) is being flagged with BackDoor.Hupigon4.ADUA trojan by 18 out of 36 AV packages at virus total.

Speculation is that it's likely a false positive, but also that it's a target for malware.

From the usenet post:

---------------

The package is delivered as a single install.exe file. When this file is scanned by Virustotal, Sophos identifies "Sus/Madcode-A" malware. All other antivirus products detect nothing.

I notice the following text strings in gdihook.dll:

====================================================================

forbiddenAPIsMutex madCodeHook warning...

You've tried to hook one of the following APIs:

These APIs are usually hooked in order to hide a process. Of course

madCodeHook can do that just fine. But I don't want virus/trojan

writers to misuse madCodeHook for illegal purposes. So I've decided to

not allow these APIs to be hooked. If you absolutely have to hook

these APIs, and if you have a commercial madCodeHook license, you may

contact me.

====================================================================

BTW, the subject patch is available here:

http://web.archive.org/web/20070203164123/.../wmfpatch11.zip

My research leads me to believe that MadCodeHook is a legitimate product that has occasionally been misused by malware writers. It is for this reason that I suspect the WMF patch is being falsely identified as infected.

---------------

Update:

AVG have replied as follows:

==========================================

Unfortunately, the current virus database version may detect the

mentioned file as infected. We can confirm that it is a false alarm.

We would like to inform you that the false positive will be removed

in the next Definitions update.

==========================================

Edited by 98Guy


Create an account or sign in to comment

Recently Browsing 0

  • No registered users viewing this page.

Account

Navigation

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.