Jump to content

drog

Members
  • Posts

    9
  • Joined

  • Last visited

Posts posted by drog

  1. On the debug folder there is also a item.dat which is open in rundll32.exe and a sub folder called WIA with a text document called wiatrace inside.


    **************** Started trace for Module: [sti_ci.dll] in Executable [devsetup.exe] ProcessID: [7028] at 2016/09/25 02:27:37:919 ****************
    WIA: 7028.4852 0 0 0 [sti_ci.dll] ERROR: GetDwordFromRegistry, RegQueryValueEx() failed. Err=0x4.
    WIA: 7028.4852 0 0 0 [sti_ci.dll] ERROR: GetDwordFromRegistry, RegQueryValueEx() failed. Err=0x4.
    WIA: 7028.4852 0 0 0 [sti_ci.dll] ERROR: GetDwordFromRegistry, RegQueryValueEx() failed. Err=0x4.
     

    this is what is in it

  2. So I've been having this problem for the last few days, my PC was pretty slow so I ran malwarebytes and it found a lot of stuff, then got rid of it but they came back with every reboot so I started looking into solutions online, I guess I've managed to get rid of a few of them by running a lot of different cleaning tools but "conhost.exe" always comes back after reboot. There was also some exes called lsmose and mysa1 mysa2 and mysa3 which I found out online that are bitcoin miners. I can stop the conhost manually by stopping some processes but it comes back after every reboot so I would really appreciate some help. I already ran FRST and attached the files, also not sure if this changes anything but these are the cleaning tools I used: malwarebytes, hitmanpro, roguekiller, mbamantirootkit and combofix

    FRST.txt

    Addition.txt

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.