If any of the above tools won't run, then re-download them and rename the file before saving to your desktop. Or use another pc to download the file and rename it before transfering it to the infected pc.
Main Topics
Browse All TopicsHi,
I really don't know much about fixing viruses but I have tried to eliminate the Trojan I am encountering using the the detection name link. I was obviously unsuccessful. I am also encountering an intetner explorer script error. When trying to clean it I encountered this site. Please help me if you can. The two errors I am finding are as follows:
Pc-cillin notification
Notification
Real-time Virus Protection
Real-time Virus Protection has detected a virus or other security risk, and performed the action specified.
Action taken: The Quarantine action was unsuccessful. Manually delete the file if you are sure that it is not needed.
.
Incident name: C:\Windows\system32\msqpdx
Detection name: TROJ_ARPOISON.B
User name: abletobecain
Note: If Search for and clean Trojans is turned on and executed after scanning, click Next to view the final action taken.
And this is the explorer script error
An error has occured in the script on this page.
Line: 31
Char: 3
Error: LIbrary not registered.
Code: 0
URL file:///C:/Program%20Files
Do you want to continue running scripts on this page?
Yes No
Im not sure what these two errors are doing besides that I notice once in a while I'll click on a link and It'll send me to a different site. I would like to remove these nasties from my computer but I haven't been able to do so. Please help.
Thanks,
~Jhanek
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Hi again,
I downloaded both items successfully. However I have attempted to run a scan with Malwarebytes three times now and each time I get the blue screen of death after scanning approximately 28,000 items. I was attempting to run a full scan on all drives each time it happened. When my computer restarted the first two times I got the following error messages;
Problem signature:
Problem Event Name: BlueScreen
OS Version: 6.0.6001.2.1.0.768.3
Locale ID: 1033
Additional information about the problem:
BCCode: 1000008e
BCP1: C0000005
BCP2: 91046B8A
BCP3: C8518754
BCP4: 00000000
OS Version: 6_0_6001
Service Pack: 1_0
Product: 768_1
Files that help describe the problem:
C:\Windows\Minidump\Mini01
C:\Users\abletobecain\AppD
C:\Users\abletobecain\AppD
Read our privacy statement:
http://go.microsoft.com/fw
Problem signature:
Problem Event Name: BlueScreen
OS Version: 6.0.6001.2.1.0.768.3
Locale ID: 1033
Additional information about the problem:
BCCode: 1000008e
BCP1: C0000005
BCP2: 9100DB8A
BCP3: C699A754
BCP4: 00000000
OS Version: 6_0_6001
Service Pack: 1_0
Product: 768_1
Files that help describe the problem:
C:\Windows\Minidump\Mini01
C:\Users\abletobecain\AppD
C:\Users\abletobecain\AppD
Read our privacy statement:
http://go.microsoft.com/fw
After the third restart I did not get an error message. Am I doing something wrong?
Thanks,
~Jhanek
This is a rootkit. combofix should take care of it but since this is Vista Combofix might also have problems running.
You can try running it in Safe Mode and show us the resulting log.
You could also try SUPERAntispyware and see if that helps.
http://www.superanti
We can also try and use Gmer later(I'll post the instructions later)if nothing helps.
I thought MBAM would not finished its run? even if you redownload and rename it?
So I thought try SUPERAntispyware instead and see if that will run successfully.
Then if problem persists, you can run Combofix in Safe Mode, Combofix only supports 2000/XP but it will run on vista as well. Some Vista system are able to run combofix in normal mode but I always go for safe mode when it's Vista to minimize possible running problems.(use at your own risk)
Or if SUPERAntispyware doesn't help, instead of running Combofix we can use Gmer. These are just options for you to choose.
I quarintined everything that superantispyware found and it was good for a while (no trojan message). However, when I started my computer up tonight it popped up again everytime I opened a new web page. I ran superantispyware again and it seems to have worked again but will it pop up again later? Also the second error (library not registered) still pops when I turn on my computer. Should I try combofix now?
Thanks,
~Jhanek
I ran Combofix in Safe Mode and I disabled Pc-cillin and Windows Defender but I did this before I went into safe mode. Was that correct?
When I ran it I got a couple of errors.
First was a windows box that said;
Windows cannot find '32788R22FWJFW\nircmd.com'
The next error was from Combofix and it said;
Combofix has detected the presence of rootkit activity and needs to reboot the machine. Kindly note down on paper, the name of each file. We may need it later.
C:\Windows\system32\driver
C:\Windows\system32\msqpdx
Also when I clicked ok after the message it didn't reboot and I had to do it myself.
Lastly I just wanted to note what was in the blue screen of Combofix itself. In the top left corner was -C.bat. Here's what it said;
The system cannot find message text for mesage number 0X8 in the message file for system.
Scanning for infected files...
This typically doesn't take more than 10 minutes. However scan times for badly infected times may easily double.
Access Denied. Administrator permissions are needed to use the selected options.
Use an administrator command prompt to complete these tasks.
The system cannot find message text for mesage number 0X8 in the message file for system.
Also when I restarted my computer my clock had changed to military time. What should I do?
Thanks,
~Jhanek
To fix the military time,
Go to start > run and type:
intl.cpl
Enter and when the window opens,
In the "Regional Options" tab, > standards and formats,
from the dropdown list, select your region and click "Customize" click the "Time" tab
h:mm:ss tt
which h = 12 hour.
Did combofix produced a log file? can you please attach the Combofix log.
It should be in the C:\combofix.txt
Thanks, I got out of military time no problem. I guess I was unclear with my prior post. I posted everything that combofix gave me. It was just a couple of error boxes. It seems that I can't dissable Pc-cillin in safe mode. I think if you could coach me how to dissable it combofix would work. Also, I looked for C:\combofix.txt but I can't find it anywhere. AAAHHHHHH!!
Thanks for your patience.
Business Accounts
Answer for Membership
by: rpggamergirlPosted on 2009-01-24 at 15:08:18ID: 23458619
Use either MalwareBytes or Combofix, you need to also show us the logfiles specially combofix to make sure all bad entries have been removed.
Download Malwarebytes' Anti-Malware to your desktop, check for the tool's Updates before running a scan.
http://www.malwarebyt
If you can't access the above link then use this link:
http://www.download.c
Please download ComboFix by sUBs: ingcompute r.com/sUBs /ComboFix. exe
http://download.bleep
You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.