Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

winlogon.exe and explorer.exe infected


  • This topic is locked This topic is locked
18 replies to this topic

#1 Rick - MSCS

Rick - MSCS

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:06:52 PM

Posted 12 February 2011 - 09:37 PM

Hi,

I am new here and obviosuly looking for a little help. I have a PC (not mine) that was given to me because it has a virus on it. It's from a small school computer lab so I am not too concerned about loosing what it on it because I can always just clone another machine but I would rather give a shot at fixing this. It had Microsoft Security Essentials on it AND the Avast Free edition. I removed the Microsoft SE, updated Avast and ran the 'scan on boot', it found 8 things that were under a temp java folder and deleted them. Not knowing this was wrong until now I ran combofix off of Hiren's Boot CD, it said winlogon.exe and explorer.exe were infected. I then ran Kaspersky Rescue disk, it did find a few things, I don't remember what they were right now but on the second scan it came back clean. I then ran combofix again, still says that winlogon.exe and explorer.exe were infected. So I ran the free avast again and it came back clean.

Knowing that combofix still says that winlogon.exe and explorer.exe are infected but all the other scans come back clean I am not sure what to do next. Any help or suggestions would be appreciated.

Thanks!
Rick

BC AdBot (Login to Remove)

 


#2 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:06:52 PM

Posted 12 February 2011 - 09:48 PM

Hi Rick,

Posted Image

Your computer has a Bamital infection. Let's fix it. :thumbup2:

I'd rather you had this version of ComboFix, please.

This tool is not a toy. If used the wrong way you could trash your computer. Please use only under direction of a Helper. If you decide to do so anyway, please do not blame me or ComboFix.

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

1. Download this file - combofix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

2. Double click combofix.exe & follow the prompts.
3. When finished, it will produce a log for you. Post that log in your next reply please.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall.

If you have trouble running it the first time, then rename ComboFix.exe to rick.exe and try again.

Thanks,
tea

Edited by teacup61, 12 February 2011 - 09:49 PM.

Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#3 Rick - MSCS

Rick - MSCS
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:06:52 PM

Posted 12 February 2011 - 10:02 PM

Thanks for helping!


ComboFix 11-02-12.01 - Administrator 02/12/2011 21:57:53.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1791.1398 [GMT -5:00]
Running from: F:\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\winlogon.exe . . . is infected!!

c:\windows\explorer.exe . . . is infected!!

.
((((((((((((((((((((((((( Files Created from 2011-01-13 to 2011-02-13 )))))))))))))))))))))))))))))))
.

2011-02-13 02:53 . 2011-02-13 02:53 -------- d-----w- c:\program files\ESET
2011-02-13 02:49 . 2010-12-20 23:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-13 02:49 . 2010-12-20 23:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-12 16:33 . 2011-02-12 16:33 -------- d-----w- c:\documents and settings\Administrator\DoctorWeb
2011-01-26 18:39 . 2011-01-13 08:37 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-01-26 18:39 . 2011-01-13 08:41 294608 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-01-26 18:39 . 2011-01-13 08:40 47440 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-01-26 18:39 . 2011-01-13 08:37 23632 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-01-26 18:39 . 2011-01-13 08:40 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-01-26 18:39 . 2011-01-13 08:39 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-01-26 18:39 . 2011-01-13 08:37 29392 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-01-26 18:38 . 2011-01-13 08:47 38848 ----a-w- c:\windows\avastSS.scr
2011-01-26 18:38 . 2011-01-13 08:47 188216 ----a-w- c:\windows\system32\aswBoot.exe
2011-01-26 18:38 . 2011-01-26 18:38 -------- d-----w- c:\program files\Alwil Software
2011-01-26 18:38 . 2011-01-26 18:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2011-01-26 18:15 . 2011-01-26 18:15 -------- d-----w- c:\windows\system32\wbem\Repository
2011-01-19 19:09 . 2011-01-19 19:09 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-01-15 19:29 . 2011-01-15 19:29 -------- d-----w- c:\documents and settings\Administrator\Application Data\InterVideo
2011-01-15 19:28 . 2011-01-15 19:28 8 --sh--r- c:\documents and settings\All Users\Application Data\9BBD7302AC.sys
2011-01-15 19:28 . 2011-01-15 19:28 2516 --sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2011-01-15 19:28 . 2011-01-15 19:28 -------- d-----w- c:\documents and settings\Administrator\Application Data\Corel
2011-01-15 15:30 . 2011-01-15 15:30 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
2011-01-15 15:11 . 2008-04-14 10:41 21504 ----a-w- c:\windows\system32\hidserv.dll
2011-01-15 15:11 . 2008-04-14 10:41 21504 ----a-w- c:\windows\system32\dllcache\hidserv.dll
2011-01-15 15:11 . 2001-08-17 18:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2011-01-15 15:11 . 2001-08-17 18:48 12160 ----a-w- c:\windows\system32\dllcache\mouhid.sys
2011-01-15 15:11 . 2008-04-14 05:09 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2011-01-15 15:11 . 2008-04-14 05:09 14592 ----a-w- c:\windows\system32\dllcache\kbdhid.sys
2011-01-15 15:11 . 2008-04-14 05:15 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2011-01-15 15:11 . 2008-04-14 05:15 10368 ----a-w- c:\windows\system32\dllcache\hidusb.sys
2011-01-15 15:11 . 2008-04-14 05:15 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2011-01-15 15:11 . 2008-04-14 05:15 32128 ----a-w- c:\windows\system32\dllcache\usbccgp.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.

------- Sigcheck -------

[-] 2010-11-05 . 3127006A8E2D6CFEACBAB38D2ADD2449 . 507904 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe

[-] 2010-11-05 . B4F4369FD47354807F2F83CA54D6F335 . 1033728 . . [6.00.2900.5512] . . c:\windows\explorer.exe
.
((((((((((((((((((((((((((((( SnapShot@2011-02-12_17.16.33 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-02-13 02:49 . 2011-02-13 02:49 16384 c:\windows\Temp\Perflib_Perfdata_56c.dat
+ 2009-04-06 14:51 . 2011-02-13 00:30 67516 c:\windows\system32\perfc009.dat
- 2009-04-06 14:51 . 2011-02-07 12:46 67516 c:\windows\system32\perfc009.dat
+ 2009-04-06 14:51 . 2011-02-13 00:30 432686 c:\windows\system32\perfh009.dat
- 2009-04-06 14:51 . 2011-02-07 12:46 432686 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2009-07-08 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-07-08 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-08 13762560]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"RTHDCPL"="RTHDCPL.EXE" [2009-10-16 18782720]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2009-06-18 563736]
"SetRefresh"="c:\program files\Compaq\SetRefresh\SetRefresh.exe" [2003-11-21 525824]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-01-13 3396624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone Network Version 3\\support\\bin\\win\\RosettaStoneLtdServices.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone Network Version 3\\RosettaStoneNetworkVersion3.exe"=

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [1/26/2011 1:39 PM 294608]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [1/26/2011 1:39 PM 17744]
R2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [6/16/2010 2:42 PM 635416]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [4/17/2007 10:09 PM 11032]
S1 dytbfhyu;dytbfhyu;\??\c:\windows\system32\drivers\dytbfhyu.sys --> c:\windows\system32\drivers\dytbfhyu.sys [?]
S1 jzcnrysn;jzcnrysn;\??\c:\windows\system32\drivers\jzcnrysn.sys --> c:\windows\system32\drivers\jzcnrysn.sys [?]
S1 ljjhawgk;ljjhawgk;\??\c:\windows\system32\drivers\ljjhawgk.sys --> c:\windows\system32\drivers\ljjhawgk.sys [?]
S1 mhexmbof;mhexmbof;\??\c:\windows\system32\drivers\mhexmbof.sys --> c:\windows\system32\drivers\mhexmbof.sys [?]
S1 MpKsl8b806c1b;MpKsl8b806c1b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{429E7D65-C3DA-4DF7-A90D-747C3F4B1060}\MpKsl8b806c1b.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{429E7D65-C3DA-4DF7-A90D-747C3F4B1060}\MpKsl8b806c1b.sys [?]
S1 nynlsdsp;nynlsdsp;\??\c:\windows\system32\drivers\nynlsdsp.sys --> c:\windows\system32\drivers\nynlsdsp.sys [?]
S1 tmykdzye;tmykdzye;\??\c:\windows\system32\drivers\tmykdzye.sys --> c:\windows\system32\drivers\tmykdzye.sys [?]
S2 0287011282831559mcinstcleanup;McAfee Application Installer Cleanup (0287011282831559);c:\docume~1\ADMINI~1\LOCALS~1\Temp\028701~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\docume~1\ADMINI~1\LOCALS~1\Temp\028701~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/8/2010 2:31 PM 136176]
.
Contents of the 'Scheduled Tasks' folder

2011-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-08 19:31]

2011-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-08 19:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://yearbookavenue.jostens.com/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //FWEvent.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-12 22:00
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2860435963-2152744713-940506227-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3a,93,92,af,b8,76,e3,40,bd,63,2d,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3a,93,92,af,b8,76,e3,40,bd,63,2d,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2011-02-12 22:01:03
ComboFix-quarantined-files.txt 2011-02-13 03:01
ComboFix2.txt 2011-02-13 02:09
ComboFix3.txt 2011-02-13 01:37
ComboFix4.txt 2011-02-13 00:31
ComboFix5.txt 2011-02-13 02:57

Pre-Run: 126,388,244,480 bytes free
Post-Run: 126,367,334,400 bytes free

- - End Of File - - DD633BF5EDD5E5A793AAA4EB915B9756

#4 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:06:52 PM

Posted 12 February 2011 - 10:27 PM

Hi there,

You're welcome. :)

This machine had to have come with SP3 already installed, which is why ComboFix couldn't fix the infection. What I need for you to do is do an over the top installation of SP3 from here: http://www.microsoft.com/downloads/en/details.aspx?FamilyID=5b33b5a8-5e76-401f-be08-1e1555d4f3d4&displaylang=en

When you're done, please run ComboFix again and post the report. Please also let me know how it's running now. :)

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#5 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,430 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:07:52 PM

Posted 12 February 2011 - 10:34 PM

Hello, just letting you know I moved this topic to Here in the Virus, Trojan, Spyware, and Malware Removal Logss forum where it will stay.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#6 Rick - MSCS

Rick - MSCS
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:06:52 PM

Posted 12 February 2011 - 10:41 PM

Ok, will do. I will run it over night and finish up in the morning. :)

#7 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:06:52 PM

Posted 12 February 2011 - 10:47 PM

Thanks boopme. :)

Post when you're ready, Rick. :thumbup2:

tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#8 Rick - MSCS

Rick - MSCS
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:06:52 PM

Posted 13 February 2011 - 10:24 AM

SP3 has been running for about 2 hours. I thought it was hung earlier but it jumped up some. For the last half hour or so it's been finishing installation and the progress bar is not quite at the halfway mark. Hopefully is ok.

#9 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:06:52 PM

Posted 13 February 2011 - 10:31 AM

It is okay...it's just BIG. :thumbup2:
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#10 Rick - MSCS

Rick - MSCS
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:06:52 PM

Posted 13 February 2011 - 01:07 PM

It's been another 2.5 hours and hasn't moved any. :(

#11 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:06:52 PM

Posted 13 February 2011 - 01:18 PM

Hi Rick....when you downloaded it, where did you download it to? Can you get to it to look inside? All I'm really interested in are those two files so we can replace them with clean copies.
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#12 Rick - MSCS

Rick - MSCS
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:06:52 PM

Posted 13 February 2011 - 01:32 PM

It's just saved to the desktop.

#13 Rick - MSCS

Rick - MSCS
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:06:52 PM

Posted 13 February 2011 - 01:40 PM

Ok I have the i386 directory extracted.

#14 Rick - MSCS

Rick - MSCS
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:06:52 PM

Posted 13 February 2011 - 01:42 PM

Should I cancel the sp3 update? The option to cancel is greyed out.

#15 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:06:52 PM

Posted 13 February 2011 - 01:51 PM

If you can, then yes. Can you replace those files? If not, I'll give directions, but you seem pretty savvy about things like that. :)
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users