Computing.Net > Forums > Security and Virus > Pos.tmp files, have Hijackthis log

Pos.tmp files, have Hijackthis log

Reply to Message Icon

Original Message
Name: Nitronium
Date: March 7, 2008 at 12:14:32 Pacific
Subject: Pos.tmp files, have Hijackthis log
OS: Windows XP Home Edition S
CPU/Ram: Pentium(R) 4 CPU / 512 MB
Model/Manufacturer: HP Pavilion a475c
Comment:

My C: and My Documents have a ton of pos.tmp files. Also, my desktop has icons for "windows updates" and "help and support center" that cannot be deleted and are tied to internet explorer.

I believe that budwimcj.dll in my c:windows/system32 is/has an infection, as Spyware Doctor shows it trying to access internet explorer and blocking it.

Also, when I start up, I get two error messages that say the same thing:
"Important- potential errors found at startup. During a scan of files at system startup, potential errors in the system registry were found.
p-07-0100 irql: 1f SYSVER 0xff00024
NT_Kernel error 1256
KMODE_EXCEPTION_NOT_HANDLED"

Other symptoms include not being able to open anything but programs (I can't open My Computer, folders, etc.) after having been on the computer for a while.

I receive errors from SysFader: IEXPLORE.EXE.

I have downloaded Hijackthis and ComboFix as I saw a thread with someone having the same problem as me.


Report Offensive Message For Removal


Response Number 1
Name: jabuck
Date: March 8, 2008 at 18:01:27 Pacific
Subject: Pos.tmp files, have Hijackthis log
Reply: (edit)

Please run the following scans and post their logs please.

Go to the this link:

Disable Realtime Protection

Follow their directions to disable any realtime protection that you have as it will interfere with the fix by reinstalling the corrupt files.

Please download Atribune's VundoFix.exe from the following site to your desktop:

Vundofix.exe

Double-click VundoFix.exe to run it.

Click the Scan for Vundo button.

Once it's done scanning, click the Remove Vundo button.

You will receive a prompt asking if you want to remove the files,
click "yes".

Once you click yes, your desktop will go blank as it starts removing
Vundo.

When completed, it will prompt that it will reboot your computer,
click "ok".

Please download and install the latest version of HijackThis v2.0.2:


Download the "HijackThis" Installer from this link:
Hijack This


1. Save " HJTInstall.exe" to your desktop.
2. Double click on HJTInstall.exe to run the program.
3. By default it will install to C:\Program Files\Trend Micro\HijackThis.
4. Accept the license agreement by clicking the "I Accept" button.
5.Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
6. Click "Save log" to save the log file and then the log will open in Notepad.
7. Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
8. Paste the log in your next reply.
9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.

Please download ComboFix to the desktop from one of the following links:

Link1

Link 2

Link 3

Double-click combofix.exe
Follow the prompts.
(Don't click on the window while the program is running, it may cause your system to hang.)
Please post the log it produces.


Report Offensive Follow Up For Removal







Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: Pos.tmp files, have Hijackthis log

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software




How often do you use Computing.Net?

Every Day
Once a Week
Once a Month
This Is My First Time!


View Results

Poll Finishes In 3 Days.
Discuss in The Lounge