![]() |
Show all 24 posts from this thread on one page |
VCDQuality Forums (http://www.vcdhq.com/forum/index.php)
- Computer and Audio/Video help (http://www.vcdhq.com/forum/forumdisplay.php?forumid=56)
-- Safe mode; possible virus. (http://www.vcdhq.com/forum/showthread.php?threadid=80384)
Safe mode; possible virus.
So my computer has been complete shit for a long while now..but at least it's now working...anyways...one day my computer stopped working so I put it away (i.e. stored it somewhere), decided to bring it back out and power it on. You know, for shits and giggles? To my surprise it turned it but would freeze before completely loading...so one day I decided to run it in safe mode and that resulted in it (the computer) staying on for 30-35 mins (40 if I was lucky!). So I did something and now it stays on for as long as I please but I fear I may have gotten a virus (having no protection because of safe-mode), but I have no way of fixing/ridding it..what can I do to rid this (potentional) virus, if anything?
__________________

I'm gay. <3 <3 <3
Why do you think you have a virus?
If you know you have and you can't clean with with an anti-virus product: just save all your important data to another drive, reformat and install a nice clean copy of your OS.
Re: Safe mode; possible virus.
quote:
Originally posted by LostInAHazeOfMyself
So my computer has been complete shit for a long while now..but at least it's now working...anyways...one day my computer stopped working so I put it away (i.e. stored it somewhere), decided to bring it back out and power it on. You know, for shits and giggles? To my surprise it turned it but would freeze before completely loading...so one day I decided to run it in safe mode and that resulted in it (the computer) staying on for 30-35 mins (40 if I was lucky!). So I did something and now it stays on for as long as I please but I fear I may have gotten a virus (having no protection because of safe-mode), but I have no way of fixing/ridding it..what can I do to rid this (potentional) virus, if anything?
__________________
Hold Da Motha Fuckin Salad.
Well I keep getting this error or something and a little 'X' keeps popping up on the bottom right corner of the screen..and oh, this...
2,000 TMP files, located in my Local Disk (C
, and I cannot delete. WTF?
And this is one of the errors:

__________________

I'm gay. <3 <3 <3
Re: Safe mode; possible virus.
quote:
Originally posted by LostInAHazeOfMyself
... so I put it away (i.e. stored it somewhere), decided to bring it back out and power it on....
I know...I know. At times I felt suicidal. Oh, what dark days. 
__________________

I'm gay. <3 <3 <3
After running HiJackThis, here is the log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:54:26 PM, on 3/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\Daemon Tools 3.47\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [Name of App] C:\Program Files\SAMSUNG\FW LiveUpdate\Liveupdate.exe
O4 - HKLM\..\Run: [CloneCDTray] "D:\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "E:\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [b818e8f6] rundll32.exe "C:\WINDOWS\system32\cbjoofhm.dll",b
O4 - HKLM\..\Run: [BMbb2bdb6a] Rundll32.exe "C:\WINDOWS\system32\ixlqtjet.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\RunOnce: [NeroHomeFirstStart] C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe
O4 - Startup: LimeWire On Startup.lnk = D:\LimeWire\LimeWire.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microso...b?1168256087746
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microso...b?1168256074727
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/active...free/asinst.cab
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Unknown owner - E:\iPod\bin\iPodService.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 6636 bytes
__________________

I'm gay. <3 <3 <3
wxyz.sys is a virus. Try giving this program a try, it seemed to have fixed other people who got this virus as well:
http://www.softpedia.com/get/Antivirus/VundoFix.shtml
Thank you for the link Candy, (un)fortunately it detected two files and then my computer froze. So I'm not sure what I will be doing to resolve this problem. Hmph.
__________________

I'm gay. <3 <3 <3
quote:
Originally posted by LostInAHazeOfMyself
Thank you for the link Candy, (un)fortunately it detected to files and then my computer froze. So I'm not sure what I will be doing to resolve this problem. Hmph.
My computer only runs in safe-mode I'm sure it was. Lol. It just won't finish the scan of my files without freezing...now instead of having 2,000 TMP files, it has created another 1,500. Man oh man. I may just be royally fucked.
__________________

I'm gay. <3 <3 <3
quote:Just fucking reformat you tool. Fuck it. install a virus scanner and run it before windows boots. Theres a couple suggestions.
Originally posted by LostInAHazeOfMyself
My computer only runs in safe-mode I'm sure it was. Lol. It just won't finish the scan of my files without freezing...now instead of having 2,000 TMP files, it has created another 1,500. Man oh man. I may just be royally fucked.
__________________
Hold Da Motha Fuckin Salad.
ha
you use IE, Nero, and AIM
After you reformat, feel free to bump this thread in three months with the same issue.
quote:
Originally posted by Fionn McCool
: just save all your important data to another drive, reformat and install a nice clean copy of your OS.
quote:
Delete any files under C:\ and My Documents called posxxx.tmp.Download VundoFix and ComboFix. Run VundoFix first, if there are still any files that it can't delete after rebooting then run ComboFix.
I do not see any file called 'posxxx.tmp'. I ran VundoFix, it found 2 problematic files but froze shortly thereafter. Having to run your computer in safe-mode sucks. I got my computer to stay on while running it normally but it was unbelievably slow. It took ages just to load my desktop.
__________________

I'm gay. <3 <3 <3
quote:
Originally posted by LostInAHazeOfMyself
I do not see any file called 'posxxx.tmp'.
Use some sort of LiveCD with av support, this way you'll won't have to worry about the virus freezing the pc up in windows.
Like any, this virus sucks! Now I am not able to delete ANY files. Can it get any worse?!?!? Ugh.
__________________

I'm gay. <3 <3 <3
quote:
Originally posted by lmao2k
Use some sort of LiveCD with av support, this way you'll won't have to worry about the virus freezing the pc up in windows.
quote:
Also what caused it to die in the firstplace and go into hiding?
__________________

I'm gay. <3 <3 <3
Odd that unplugging a fan would fix the issue. Can't really think why that would work. Do you have another PC to run, as you could just hook the drive up as a slave and grab all your porn.. err, I mean important info off it?
I do, or should I say my parents do. I'm just not good with that stuff.
__________________

I'm gay. <3 <3 <3
quote:
Originally posted by cobalt
Odd that unplugging a fan would fix the issue. Can't really think why that would work. Do you have another PC to run, as you could just hook the drive up as a slave and grab all your porn.. err, I mean important info off it?
| All times are GMT. The time now is 06:18 PM. | Show all 24 posts from this thread on one page |
Powered by: vBulletin Version 2.3.0
Copyright © Jelsoft Enterprises Limited 2000 - 2002.