Bienvenido! - Willkommen! - Welcome!

Bitácora Técnica de Tux&Cía., Santa Cruz de la Sierra, BO
Bitácora Central: Tux&Cía.
Bitácora de Información Avanzada: Tux&Cía.-Información
May the source be with you!

Tuesday, September 13, 2011

NDIS driver or malware?


Source
From HiJackThis
Unknown file in Winstock LSP: C:/windows/system32/nlaapi.dll
Unknown file in Winstock LSP: C:/windows/system32/napinsp.dll
Unknown file in Winstock LSP: C:/program files/bonjour/mdnsnsp.dll
From RegCleaner 4.3
(Unknown) RegisteredApplications
(Unknown) Set8187
(Unknown) Set8187B
----------------------------------------
DO NOT DELETE THOSE FILES. they are microsoft files.
nlaapi.dll should not be disabled, required for essential applications to work properly
napinsp.dll is a system file created by Microsoft Corporation. napinsp.dll is part of Windows Operating System
---------------------
If you remove the wrong LSP without restoring the correct system settings, you will loose all networking on your system.
---------------------
Do a scan with Spybot S&D from http://www.safer-networking.org
It should find LSP anomalies and report them. Sometimes it is unable to fix those problems, but it will pop-up a message with a link to a site that has a "fixer" tool for LSP problems. Download that tool first, then you can remove LSP entries to your hearts content, and run the fixer tool to repair your network after the fact.
 
Source
The following is a preview of SETUP.TXT in Archive ec28209e:
+============================+

| REALTEK RTL8187 USB Wireless LAN Driver Setup Utility |
| for Windows ME/2000/XP NDIS Driver | | Release Note | +=========================================+
How to use this Set8187 Utility 
 For Windows 2000/XP:
1. If the Operating System's Found New Hardware Wizard prompts you that "New Hardware Found" for the "Ethernet Controller", you should click "Next" until "Finish" is clicked and without specifying location of the driver. You will see the "Ethernet Controller" in the Device Manager. 
2. Then you can install or upgrade the NDIS driver with "setup" or "setup -s" command: 
a) setup: The InstallShield will prompt you the steps to install or upgrade the driver. 
b) setup -s:  The InstallShield will complete the installation or upgrade without prompting you any instruction.
3. You can remove Set8187 utility from Add/Remove Program Palette in Control Panel
The InstallShield will prompt you the steps to remove the driver. After remove the driver, please restart the system inmediately if you want your networking to be re-installed.

No comments: