• Navigation
Results 1 to 16 of 16
  1. #1
    Salvage Bans
    Join Date
    Jul 2007
    Posts
    832
    BG Level
    5

    Problem opening HDD after a fresh install

    I just reinstalled a fresh copy of windows XP Pro on my computer. I have a HDD ~300 GB so I divided them into 2 HDD: 80GB & 220GB. The 220GB is to store files and such while 80GB is just programs. I installed XP on the 80GB. When I tried to access both drive from "My Computer" I get an Error Message:

    "Windows cannot find
    RECYCLER\S-2-9-65-100024093-100001027-100001089-9560.com.Make sure you typed the name correctly, then try again. To search for a file, click Start button, and then click Search."

    Does anyone know what is this and how to fix this? I installed the same copy on my parents computer and it works fine. This is the first time something like this pop up.

  2. #2
    Pandemonium
    Join Date
    Jul 2008
    Posts
    4,875
    BG Level
    7
    FFXI Server
    Bismarck

    Try running this program:

    Autorun Eater - Free software downloads and reviews - CNET Download.com

    Does it detect anything suspicious?

  3. #3
    Salvage Bans
    Join Date
    Jul 2007
    Posts
    832
    BG Level
    5

    Hi Kohan!

    Thank you~
    Yea it detects something suspicious. Here's the screenshot.


    It detects in both of the HDD. Do you know what is it? Should I do a spyware/virus scan?

  4. #4
    Pandemonium
    Join Date
    Jul 2008
    Posts
    4,875
    BG Level
    7
    FFXI Server
    Bismarck

    Try removing that on both HDDs, then see what happens.

    You may not necessarily have a virus infection or anything like that. However, it won't hurt to follow up the bad autorun.inf deletion with a MalwareBytes and/or Avast! Anti-Virus scan.

  5. #5
    Salvage Bans
    Join Date
    Jul 2007
    Posts
    832
    BG Level
    5

    I removed them and was able to access my HDDs! Works like a charm! Thank you very much!!

    However MalwareBytes detects an infection call "iamfamous.dll" I tried to remove it but I don't think it's gone completely because I plugged in my USB and shortly after I got the same Error Message that I got with the HDDs, and lost my account on RS as well.

  6. #6
    Pandemonium
    Join Date
    Jul 2008
    Posts
    4,875
    BG Level
    7
    FFXI Server
    Bismarck

    All right. This is going to scare you, and I apologize, but iamfamous.dll is a part of an extremely dangerous rootkit that has caused people to lose very essential information, including their bank account data. Though I'm only a random face over the internet, I implore you to trust me on this, as I'm not going to bullshit someone over something so serious.

    If you do any internet banking or have credit card information stored on your computer, I advise that you call your banks and inform them that your information could have been compromised. If you do not use internet banking then you obviously don't need to worry about this.

    Your USB drive (as I'm assuming that's what caused this to happen, since you said you "plugged in your USB") must be infected by something that's running and replacing itself. Viruses that are severe will rapidly infect any running applications and other forms of executable files they can launch themselves from, so that is probably what happened here -- you contracted the virus from the internet and now it's all over the place.

    Here is a forum discussion that's quite thorough about the virus:

    Iamfamous.dll - The Elder Geek on Windows XP

    If you need to ask more questions, first follow the instructions there, then post things (like a HijackThis log) here.

  7. #7
    Salvage Bans
    Join Date
    Jul 2007
    Posts
    832
    BG Level
    5

    Thanks for your help and informative warning!

    I followed the steps and all the scans are giving me no threats found! Thank you very much!

  8. #8
    Pandemonium
    Join Date
    Jul 2008
    Posts
    4,875
    BG Level
    7
    FFXI Server
    Bismarck

    Congrats on getting rid of it, and glad to help.

    If you don't already, you should have Avast! Anti-Virus installed on your machine (or another good anti-virus) and running, and a spyware blocker -- like Spybot Search & Destroy -- would be good, too.

  9. #9
    Salvage Bans
    Join Date
    Jul 2007
    Posts
    832
    BG Level
    5

    Yea I have them installed on the comp already! I use Kaspersky for Antivirus. Thanks for the tips!

    I have one more question. I went to work last night and probably my sister used the computer while I was gone, when I came back and check I saw 2 strange things on the Start up list.

    1.uvuzofuqoqiwogij.dll
    2.blepilitaciwiwa.dll

    Do you know what they are? I've never heard of anything like this. Below is a screenshot I took.



    HIJackthis Log
    Spoiler: show
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:51:36 AM, on 2/19/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16762)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\Internet Download Manager\IDMan.exe
    C:\Program Files\Internet Download Manager\IEMonitor.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {348FE907-249E-4C65-A838-F34A193FE1D1} - (no file)
    O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [EOUApp] "C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe"
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
    O4 - HKLM\..\Run: [Vvaroceloz] rundll32.exe "C:\WINDOWS\Blepilitaciwima.dll",e
    O4 - HKLM\..\Run: [Vdazukic] rundll32.exe "C:\WINDOWS\uvuzofuqoqiwogij.dll",e
    O4 - Global Startup: OSCust.lnk = C:\WINDOWS\system32\OEM\OSCust.exe
    O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
    O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
    O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
    O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1234045790533
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...18/mcfscan.cab
    O20 - AppInit_DLLs: wbsys.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll ,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROG RA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KAS PER~1\KASPER~1\kloehk.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

    --
    End of file - 6790 bytes

  10. #10
    Pandemonium
    Join Date
    Jul 2008
    Posts
    4,875
    BG Level
    7
    FFXI Server
    Bismarck

    If you're getting these viruses despite using a powerful program like Kapersky, my guess is that someone is either turning it off or deliberately ignoring warnings, as they're installing things that do contain viruses. Those are both rubbish files caused by an infection.

    There is an actual authentic Rundll32, but those aren't it, that's for sure. There are a few possibilities as to what this one could be:

    W32.Miroot.Worm | Symantec
    Backdoor.Lastdoor | Symantec
    Trojan.StartPage | Symantec

    Do any of those help you? It might be something else, but those are among the viruses that disguise themselves this way. These are the kind of viruses that root themselves in the depths of your system and keep reinstalling themselves (which is why Google won't show you anything if you put in those DLL names -- they're randomly generated).

  11. #11
    Salvage Bans
    Join Date
    Jul 2007
    Posts
    832
    BG Level
    5

    Ah I see... Nowonder I couldn't find any information on it through Google. I tried to remove it with HiJackthis but it still comes up after a re-scan. Do you think it'd be best to have a fresh install again?

  12. #12
    Smells like Onions
    Join Date
    Feb 2009
    Posts
    2
    BG Level
    0
    FFXI Server
    Sylph

    Hello,

    Before you reinstall windows, Download Process Explorer It will give you more info on what is running on your system.

    It sounds like there is a service running on your system or a process remaking the dll files.

  13. #13
    Sea Torques
    Join Date
    Dec 2005
    Posts
    668
    BG Level
    5
    FFXI Server
    Valefor

    ComboFix, then you'll scan clean. Those random garbage letters.dll and stuff are always a pain, but CF will get it clean in 20mins or so.

    MalwareBytes rocks, but for rootkits it misses many pieces or doesn't remove them completely. ComboFix fills that gap for the other 99% of rootkits. So far, I've only ever had one instance where I needed more than MB and CF.

    Edit:That's a cute program for autorun.inf, thanks for posting it

  14. #14
    Salvage Bans
    Join Date
    Jul 2007
    Posts
    832
    BG Level
    5

    All done and done! the comp is 100% clean! Thank you everyone for the help! =]

  15. #15
    Pandemonium
    Join Date
    Jul 2008
    Posts
    4,875
    BG Level
    7
    FFXI Server
    Bismarck

    You're welcome. Now make sure nobody messes with your virus scanner!

  16. #16
    Salvage Bans
    Join Date
    Jul 2007
    Posts
    832
    BG Level
    5

    Haha will do!

Similar Threads

  1. Problems opening up FFXIV.
    By Draylo in forum Tech
    Replies: 14
    Last Post: 2010-11-12, 00:29
  2. Windows 7 Ultimate Fresh Install
    By Oreth in forum Tech
    Replies: 10
    Last Post: 2010-07-25, 13:14
  3. Problem opening POL/FFXI with vista
    By ryanjh in forum Tech
    Replies: 10
    Last Post: 2008-05-11, 20:13
  4. odd problem cpu/hdd?
    By justbaem in forum Tech
    Replies: 5
    Last Post: 2007-11-20, 18:19
  5. Problem installing XP
    By Calina in forum Tech
    Replies: 8
    Last Post: 2007-05-07, 16:15
  6. Annoying problem when opening files.
    By Epical in forum Tech
    Replies: 16
    Last Post: 2007-02-23, 12:54
  7. PS2 HDD swapping / Installation Question
    By Charitwo in forum Tech
    Replies: 1
    Last Post: 2007-02-17, 00:42