PDA

View Full Version : win xp virus trouble


DuttyFoot
07-30-2006, 02:15 AM
i bought spy doctor because i had spyware problems. i also used system suite 6 to take off any viruses and other spyware that spware doctor didn't detect and remove. system suite did a scan for viruses and spyware . when i run my pc it gives me a virus error. i was thinking of deleting the infected file, but i am not sure what it is. it is located in the windows system 32 directory. the file is called stub86. i tried to figure out what the file was but kept running into alot of german sites. any idea what this file does.

there is another affected file called EYQJC.DLL

lots
07-31-2006, 02:58 AM
Try out spybot search and destroy, its free, and among the best.

Also try out any one of the free antivirus softwares out there, they're pretty good as well. AVG, Avast!, Kapersky (spelling?), etc...

Most of these should handle whatever comes your way.

Draconic
07-31-2006, 06:06 AM
Yeah those all those apps work great. But if you already know wich files are infect try removing them, those are essential for windows xp. Make sure to back up your system reg. Before doing anything. :) I use nod32,spybot search destroy,Spysweeper,Adware-SE,and about 13 other scanners on rare days that I am bored. All those except nod are freeware.

RiKToR
08-01-2006, 11:59 AM
Nod32 is one of the best and up coming virus scanners, its also cheap and light on system resources you should probably get it. Doing a search I found alot of german as well though it clearly seems to be a virus. ie Prob mit Windows-Virus W32/Nsag.B (http://board.protecus.de/t21138.htm) translates to problem with Windows - Virus w32/Nasag.b

I recommend downloading Nod32 trial and running it it should clear the viruses or at least quarantine them. BTW if it was a standard file doing a string search on google would give you its legitimate purpose, if it doesnt then its probably not since not many apps put stuff in you win32 folder, though some do such as drivers and codecs and stuff.

Draconic
08-04-2006, 04:56 AM
After alot of of thought on this subject I figured I might as well share what I do when I get a nasty bug, that just wont go away... Reformat....reformat....reformat... Install my hdd iso back up. :) Sorry I forgot to mention that the other day.

Rambiert
08-04-2006, 02:32 PM
Can you list here your report or better send me infected file. I'm collecting some ... "words"

DuttyFoot
08-05-2006, 05:28 AM
sorry i took so long to respond. my own pc was going through hell, so i am emailing from my dads house.

i had some serious spyware problems with my pc and had to do a reformat of my whole hdd. then i tried reinstalling xp and started getting alot of stop errors. then my powersupply died. i think something must be wrong with some of my memory sticks because i took two of em out and was able to install the suse linux that i had laying around. i will try that with xp and see if that works. maybe that will solve the stop errors.

i feel like a fish out of water without being able to use my pc

the initial question i asked was about my dads pc anyway. i will run spyware doctor and get that list for you. he currently bought systemsuite pro 6. but those two files are a pain. one that keeps popping up when explorer opens up the home page is called about blank. no matter how many times you change the home page it goes back to that aboutblank page. i tried following some examples to get it off and they didnt work at all.

i will check that nod32 out.

DuttyFoot
08-05-2006, 06:30 AM
just run a virus check on my dads pc, and this one thing just dosen't go away. no matter what.

Found potential threat

In File: C:\WINDOWS\system32\urlyn.dll

Name: HTML_STARTPAG.ZE

Requested action: Remove potential threat.

Results: Potential threat removal attempt failed. File quarantined.

Draconic
08-05-2006, 03:16 PM
C:\WINDOWS\system32\urlyn.dll
Try going to the dll right click it check read only option reboot, then go to it and delete the dll. Its how I manually remove spyware that keeps hanging around. Works 80% of the time... Its a browser force spyware, my brother is constantally getting those...but we just wont mention why. Shame on him. :)

Anyway bar that manual delete working these apps work great and are free, spybot search destroy, adware, and there are others but those 2 are top notch man. Sorry to hear about you system going poof. Thats ruff as all heck. Not much I can tell you to try without seeing it myself. Keep up the hope though seems like your on the path to pc resurection. :)

DuttyFoot
08-05-2006, 04:31 PM
thanks for the help so far fellas. i figured out my main cause of my blue screen and stop errors. i had two bad sticks of ram. so now i am back down to 1gig of ram. i installed xp on one drive, and then i installed suse 9.2 on the other drive. now i have to go and re install all my software all over again.


as far as the spyware stuff on my dads pc, i will try to delete the two files that the spyware has attached itself to and see what happens.

ngrava
08-05-2006, 05:49 PM
just run a virus check on my dads pc, and this one thing just dosen't go away. no matter what.

Found potential threat

In File: C:\WINDOWS\system32\urlyn.dll

Name: HTML_STARTPAG.ZE

Requested action: Remove potential threat.

Results: Potential threat removal attempt failed. File quarantined.


This usually happens because the file in question is running in memory and the system isn't giving you access to it. There are two ways to get rid of it, one is to open the task manager and switch to the processes tab. somewhere in there you should see "urlyn.dll". Right click on it and choose "End Process". Now go back to the system32 folder and manually delete it. If that doesn't work you may need to make a boot disk, boot from it, enter the command line and manually delete the file that way. If the file is not in the processes tab then it's probably used to launch another file that does the actual nasty stuff. do a search of the registry (using "regedit") for the file. Sometimes you will see something like "urlyn.dll -l -v" in there. Obviously, you'll need to delete that from the registry and any other entries that look dubious.

ngrava
08-05-2006, 05:53 PM
All this talk of virus problems seriously makes me want to get a Mac. The one issue I have is that I use Max and XSI. I guess I could use Cinema 4D... There is no way I'm going back to Maya. I hate that program.

Draconic
08-06-2006, 04:48 AM
Naw just got for a custom linux.. So far I have not had any issues with spyware or virus's "knock on wood" then again I have multiple os boots... linux,windows xp pro. Just a thought.

Yeah macs are probably great and all, but they render slower than all heck, so I have been told. Amongst other issues. Not sure its all hearsay as I haven't owned one. :)

Anyway back to the studing.. wish me luck.

DuttyFoot
08-06-2006, 05:19 AM
i will try that out also engrava. thanks for the tip.

hey draconic im about to install maya on my linux drive. i have a dual boot too with xp and suse linux.

the mac book pro looks like a cool laptop, i am actually thinking of getting one this year. from what i have heard engrava it runs max on the xp installation without any problems. one problem i have with the mac is that nvidia dosen't have a card for em.

CGTalk Moderation
08-06-2006, 05:19 AM
This thread has been automatically closed as it remained inactive for 12 months. If you wish to continue the discussion, please create a new thread in the appropriate forum.