| |||||||
| Soft- and Hardware PC not booting anymore? Other problems? Or if you just want to show off your setup! |
![]() |
| | Thread Tools | Display Modes |
| | #1 (permalink) |
| Genuine Failure ![]() Join Date: Mar 2007 Location: Earth ->Malaysia->Sabah
Posts: 5,070
Rep Power: 180 ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
A message pops up and then a countdown to shutdown was there . . I cant do anything this happened more frequently latelythe msg was : The instruction at "0x77f5324e" referenced memory at "0x909006ef". The memory could not be "written" Click on OK to terminate the program. and there was only 1 OK button,nothing else.
__________________ Lucky Star Desktop Buddies!!! http://www.megaupload.com/?d=G7286Z46 MY BIOs Spoiler ![]() Whoever made this have my respect: Uncolored version http://www.youtube.com/watch?v=hjE4fi0E0DU Colored version http://www.youtube.com/watch?v=2N1e-nRZfjo Dancing XD Spoiler Click here to feed me a Rare Candyhttp://www.youtube.com/watch?v=l3Q9oR2M20Y http://www.youtube.com/watch?v=9d-tMet-un4 |
| |
| | #3 (permalink) |
| Genuine Failure ![]() Join Date: Mar 2007 Location: Earth ->Malaysia->Sabah
Posts: 5,070
Rep Power: 180 ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
it FORCES me to shutdown, and because there's this countdown thing before it shutdowns.
__________________ Lucky Star Desktop Buddies!!! http://www.megaupload.com/?d=G7286Z46 MY BIOs Spoiler ![]() Whoever made this have my respect: Uncolored version http://www.youtube.com/watch?v=hjE4fi0E0DU Colored version http://www.youtube.com/watch?v=2N1e-nRZfjo Dancing XD Spoiler Click here to feed me a Rare Candyhttp://www.youtube.com/watch?v=l3Q9oR2M20Y http://www.youtube.com/watch?v=9d-tMet-un4 |
| |
| | #4 (permalink) |
| BANNED ![]() Join Date: Apr 2007 Location: 404 - Not Found
Posts: 2,869
Rep Power: 0 ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
I googled Issas.exe and it's not looking good. Lssas.exe(lsass.exe) is a windows process but Issas.exe(the one you have) seems to be a trojan.Are you sure it's Issas.exe, and not lssas.exe? Let's assume it's the former. Even if it's not Issas.exe, you might learn a thing or two about basic Windows-security. Press ctrl + alt + delete(if options shows up, press "Task Manager"). Under the tab "Processes" find issas.exe and press "End Process". When you've done that, press Start and goto All Programs -> Startup and see if Issas.exe is there. If it is, right-click on it and delete it. Be sure to empty the trash. If you can't find it there then press "Start" and go to "This Computer" -> C:\ -> Documents and Settings. Now it should look like this(but with diffrent names on the folders): ![]() Now you'll go into each of the folders and you will find a folder named "start menu". Open it and go to "programs" -> startup(picture beneath) and look there. If you find Issas.exe, delete it. ![]() Let's see if that helps. If it don't, then I have a few other tricks up my sleeve. I also reommend you to install a decent antivirus software and firewall. What are you currently using? Here you can perform a free anti-virus scan of your computer: http://housecall.trendmicro.com/us/index.html Here is a 30-day free trial of the worlds best Anti-virus software(nod32): http://www.eset.com/download/free_tr...wnload_int.php AND REMEMBER! Before you install nod32, you must uninstall your existing anti-virus software. I also recommend you to install some anti-spyware software. Use the one below please: http://www.download.com/Ad-Aware-200...dlPid=10844457 When it comes to a good firewall that's free, then I recommend Zonealarm. Download it below: http://download.zonealarm.com/bin/fr...zaSetup_en.exe I also recommend you to update Windows. It's essential for you to update Windows on a regular basis if you want a secure system. Finally I read somewhere that you should install this fix from Microsoft. "Multiple security issues have been identified that could allow an attacker to compromise a computer running Windows and gain complete control over it. You can help protect your computer by installing this update from Microsoft.": http://www.microsoft.com/downloads/d...displaylang=en Last edited by Anon-sama; 09-05-2008 at 02:08 AM. |
| |
| | #5 (permalink) | |
| Head Tech Guru ![]() ![]() ![]() Join Date: Apr 2007
Posts: 1,849
Rep Power: 679 ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Quote:
http://www.download.com/Trend-Micro-...-10227353.html I don't recommend to delete anything yet! Let's see what we are working with before we delete anything.
__________________ ![]() Sig created by blitzbullet ![]() AnimeA's *Official* Tech Guru ![]() Read my web security review of the latest security programs! http://www.animea.net/forums/f20/bla...-review-16114/ | |
| |
| | #6 (permalink) |
| Mateus |
If it was me i would just format and start allover again. But that just me.
__________________ Join my Fan club. The Old School Anime Lovers Fanclub http://www.animea.net/forums/f37/old...fanclub-29359/ ![]() ![]() |
| |
| | #7 (permalink) | |
| Genuine Failure ![]() Join Date: Mar 2007 Location: Earth ->Malaysia->Sabah
Posts: 5,070
Rep Power: 180 ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Quote:
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:44:53 PM, on 9/6/2008 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\hard63.exe C:\WINDOWS\System32\kdjfdssdl.com C:\WINDOWS\System32\igfxtray.exe C:\WINDOWS\System32\hkcmd.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\AGRSMMSG.exe C:\Program Files\Apoint2K\Apoint.exe C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE C:\Program Files\dfsdfsf\kiss.exe C:\Program Files\Apoint2K\Apntex.exe C:\Program Files\BrightEcho\LanRoad PPPoE Client\LanRoadDialupE.exe C:\Program Files\uTorrent\uTorrent.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\s33r.exe C:\s33r.com C:\WINDOWS\system32\s33r.exe C:\WINDOWS\system32\s33r.com C:\WINDOWS\system32\ntvdm.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://global.acer.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [LaunchApp] Alaunch O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [XP HOT ReHard] hard63.exe O4 - HKLM\..\Run: [MicroSoft HardMuscle] kdjfdssdl.com O4 - HKLM\..\Run: [kiss] C:\Program Files\dfsdfsf\S.exe O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti O4 - HKLM\..\RunServices: [XP HOT ReHard] hard63.exe O4 - HKLM\..\RunServices: [MicroSoft HardMuscle] kdjfdssdl.com O4 - HKLM\..\RunOnce: [XP HOT ReHard] hard63.exe O4 - HKLM\..\RunOnce: [MicroSoft HardMuscle] kdjfdssdl.com O4 - HKCU\..\Run: [XP HOT ReHard] hard63.exe O4 - HKCU\..\Run: [MicroSoft HardMuscle] kdjfdssdl.com O4 - HKCU\..\RunOnce: [XP HOT ReHard] hard63.exe O4 - HKCU\..\RunOnce: [MicroSoft HardMuscle] kdjfdssdl.com O4 - HKUS\S-1-5-21-448486026-1417066420-3376078148-1005\..\Run: [XP HOT ReHard] hard63.exe (User '?') O4 - HKUS\S-1-5-21-448486026-1417066420-3376078148-1005\..\Run: [MicroSoft HardMuscle] kdjfdssdl.com (User '?') O4 - HKUS\S-1-5-21-448486026-1417066420-3376078148-1005\..\RunOnce: [XP HOT ReHard] hard63.exe (User '?') O4 - HKUS\S-1-5-18\..\Run: [XP HOT ReHard] hard63.exe (User '?') O4 - HKUS\S-1-5-18\..\RunOnce: [XP HOT ReHard] hard63.exe (User '?') O4 - HKUS\.DEFAULT\..\Run: [XP HOT ReHard] hard63.exe (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [XP HOT ReHard] hard63.exe (User 'Default user') O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O17 - HKLM\System\CCS\Services\Tcpip\..\{0AC28033-324F-4BCE-BFDE-40AA5621DCCC}: NameServer = 202.188.0.133 202.188.1.5 -- End of file - 3660 bytes
__________________ Lucky Star Desktop Buddies!!! http://www.megaupload.com/?d=G7286Z46 MY BIOs Spoiler ![]() Whoever made this have my respect: Uncolored version http://www.youtube.com/watch?v=hjE4fi0E0DU Colored version http://www.youtube.com/watch?v=2N1e-nRZfjo Dancing XD Spoiler Click here to feed me a Rare Candyhttp://www.youtube.com/watch?v=l3Q9oR2M20Y http://www.youtube.com/watch?v=9d-tMet-un4 | |
| |
| | #8 (permalink) |
| BANNED ![]() Join Date: Apr 2007 Location: 404 - Not Found
Posts: 2,869
Rep Power: 0 ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Hard63.exe is a worm that will replicate itself. http://www.threatexpert.com/report.a...3-328d1dd1b527 "A network-aware worm that attempts to replicate across the existing network(s)" "A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment" Another interesting is this "MS04-011: LSASS Overflow exploit". Do you know which anti-virus software you're using at the moment? |
| |
| | #9 (permalink) |
| Head Tech Guru ![]() ![]() ![]() Join Date: Apr 2007
Posts: 1,849
Rep Power: 679 ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
According to the HijackThis report, you are not running any anti-virus software and you are still on XP SP1. Let's try to suppress the spread of the worm by getting an anti-virus suite working now. Download and install avast! Home: http://www.avast.com/eng/avast_4_home.html When you first install avast! it will ask you to do an offline system scan upon your next reboot. Accept this and restart your computer. Now, before your OS boots up, avast! will run in a command prompt mode scanning your computer before the system processes run. If that does not run automatically, then install and reboot as normal, click on the avast! icon on your desktop, right-click on the program, click "schedule boot-time scan" and complete the boxes. Once you have run avast! and cleaned your system, update your Windows install. Apply all high risk patches and update to SP3.
__________________ ![]() Sig created by blitzbullet ![]() AnimeA's *Official* Tech Guru ![]() Read my web security review of the latest security programs! http://www.animea.net/forums/f20/bla...-review-16114/ |
| |
| | #10 (permalink) |
| BANNED ![]() Join Date: Apr 2007 Location: 404 - Not Found
Posts: 2,869
Rep Power: 0 ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
OH LOL! I didn't read the beginning of the report. Fail. Fail. Fail =/ Is avast! really suitable? It deletes infected files, as was the case when I ran it. In this case it seems that the worm don't infect files, but what if there's more nasty stuff lurking in his system? There was no disinfection option when I ran it in boot-mode(and not the normal mode either), which resulted in some pretty necessary windows-dlls being removed -.- And alex1 thinks his computer will get really slow if he update to sp2..and probably even slower if he installs sp3. We tried to convince him to do it before..but we were unsuccessful... Last edited by Anon-sama; 09-06-2008 at 05:04 PM. |
| |
![]() |
| Thread Tools | |
| Display Modes | |
| |
All times are GMT. The time now is 07:11 AM.
© 2008 AnimeA Privacy policy - Terms of Serivce - Legal Disclaimer - Contact Us
AnimeA has been optimized for usage in Firefox.








this happened more frequently lately

Konata~
Miyuki~
Tsukasa~



















Linear Mode
