Forum Home
Press F1
 
Thread ID: 78562 2007-04-20 08:07:00 Weird unknown files in program files Mike.H (145) Press F1
Post ID Timestamp Content User
542617 2007-04-20 08:07:00 Ok these are these random files I got, don't know how. They all have the phrase "deleteme" in them, thought this was a little sketchy so I thought i's ask you professionals out there. any help will be greatly appreciated. The link is a picture of my problem, hosted by imageshack.

img206.imageshack.us
Mike.H (145)
542618 2007-04-20 09:39:00 I'm not an expert, so can't help you myself, but I'd be suspicious...

I notice the BAK file has tomorrow's date, which is rather weird.
Your link also downloaded a poker website on my machine..

I suggest you look at Speedy Gonzalez' signature for info & download HijackThis for starters. He'll help you with it later.

Other members may have other suggestions....
Laura (43)
542619 2007-04-20 09:56:00 Yup, whatever those files are, or doing they dont look legit.

Altho it looks like it may have something to do with Vista.

Is Vista installed?

Hijackthis is in my sig below.
Speedy Gonzales (78)
542620 2007-04-20 10:38:00 Ya I have Vista Premium. Btw sorry Laura for the link, I was just in such a rush to sort this out. Mike.H (145)
542621 2007-04-21 00:59:00 bump! Mike.H (145)
542622 2007-04-21 01:09:00 I dont have Vista so dunno if theyre legit or what.

Someone, who's using Vista, will have to check their system, to see if theyve got the same files.
Speedy Gonzales (78)
542623 2007-04-21 01:20:00 I talked to me son (M$-guy) and he says the one dated tomorrow MIGHT be a time bomb..payload deliverable on that calendar date. I didn't get to ask about the others....so don't know...

Be ye careful!
SurferJoe46 (51)
542624 2007-04-21 02:31:00 Should I delete them then because i've never had them on the last install of Vista. :( Mike.H (145)
542625 2007-04-21 02:42:00 Is $$DeleteMe.crypt32.dll the full filename? (as I noticed that there is "..." afterwards indicating a longer filename) Same with the others. Sherman (9181)
542626 2007-04-21 04:06:00 Is $$DeleteMe.crypt32.dll the full filename? (as I noticed that there is "..." afterwards indicating a longer filename) Same with the others.

These are the full filenames:
$$DeleteMe.crypt32.dll.01c78310593b5b24.0001
$$DeleteMe.csrsrv.dll.01c78310599cf384.0003
$$DeleteMe.user32.dll.01c7831058f19084.0000
$$DeleteMe.winsrv.dll.01c78310599cf384
BOOTSECT.BAK

Hope this can help
Mike.H (145)
1 2 3