View Full Version : Getting rid of a virus (Trojan)
I keep getting a message that says "Wind.exe has encountered a problem and need to be closed. for more info about this error, click here. I do not click here.
I went to Search and destroy and found a virus that may be causing me to keep getting this message. Microsoft.WindowsSecurityCenter_Disabled. I fix it by Spybot and each time I screen for viruses, it comes up. How can I place a quarrantine on the virus?
I thought this would be a simple question that in volved Spybot. Evidently there is no answer. Thank You
Hello GeneG.
Your second post was only a couple of hours after the topic was started, please be patient.
I keep getting a message that says "Wind.exe has encountered a problem and need to be closed. for more info about this error, click here. I do not click here.
Did Windows give you that message, and have you ran an anti-virus scan?
It would help to see the path of the Spybot-S&D detection, so please do the following:
Open SpyBot.
Check for problems.
When finished, right click and choose copy results (not the full report) to clipboard and post that into topic.
Regards.
User abort!: Scan was not completed successfully. ()
Microsoft.WindowsSecurityCenter_disabled: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Start!=W=2
--- Spybot - Search && Destroy version: 1.3 ---
2007-08-01 Includes\Cookies.sbi
2007-07-25 Includes\Dialer.sbi
2007-07-11 Includes\Hijackers.sbi
2007-07-25 Includes\Keyloggers.sbi
2007-08-01 Includes\Malware.sbi
2007-08-01 Includes\Revision.sbi
2007-05-30 Includes\Security.sbi
2007-08-01 Includes\Spybots.sbi
2007-08-01 Includes\Trojans.sbi
2005-02-17 Includes\Tracks.uti
2007-07-11 Includes\PUPS.sbi
2007-08-01 Includes\TrojansC.sbi
2007-08-01 Includes\SpybotsC.sbi
2007-08-01 Includes\SecurityC.sbi
2007-08-01 Includes\PUPSC.sbi
2007-08-01 Includes\MalwareC.sbi
2007-08-01 Includes\KeyloggersC.sbi
2007-08-01 Includes\HijackersC.sbi
2007-08-01 Includes\DialerC.sbi
2004-11-29 Includes\LSP.sbi
2007-06-06 Plugins\TCPIPAddress.dll
Hello.
Unless your operating system is WIN 95, please
upgrade to Spybot-S&D version 1.4 and run another scan.
Version 1.4 :Systems Supported (http://www.safer-networking.org/en/paragraphs/spybotsd_ossupport.html)
Uninstalling Previous Spybot-S&D (http://www.safer-networking.org/en/howto/uninstall.html)
Spybot-S&D Version 1.4 Download (http://www.spybot.info/en/download/index.html)
Tutorial (http://www.spybot.info/en/tutorial/index.html)
Of interest as we work towards Spybot-S&D version 1.5.
Announcing betas: TeaTimer / Updater / Vista integration (http://forums.spybot.info/showthread.php?t=9474)
Spybot-S&D Beta Forum (http://forums.spybot.info/forumdisplay.php?f=12)
Regards. :)
I downloaded the SB 1.4 and ran a check and it still came up.
Microsoft.WindowsSecurityCenter_disabled: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Start!=W=2
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2005-05-31 Update.exe (1.4.0.0)
2007-08-03 unins000.exe (51.41.0.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-05-23 advcheck.dll (1.5.3.0)
2007-01-02 Tools.dll (2.0.1.0)
2007-07-31 Includes\Cookies.sbi (*)
2007-07-25 Includes\Dialer.sbi (*)
2007-07-11 Includes\Hijackers.sbi (*)
2007-07-25 Includes\Keyloggers.sbi (*)
2007-08-01 Includes\Malware.sbi (*)
2007-07-31 Includes\Revision.sbi (*)
2007-05-30 Includes\Security.sbi (*)
2007-08-01 Includes\Spybots.sbi (*)
2007-08-01 Includes\Trojans.sbi (*)
2005-02-16 Includes\Tracks.uti
2007-07-11 Includes\PUPS.sbi (*)
2007-07-31 Includes\TrojansC.sbi (*)
2007-07-31 Includes\SpybotsC.sbi (*)
2007-07-31 Includes\SecurityC.sbi (*)
2007-07-31 Includes\PUPSC.sbi (*)
2007-07-31 Includes\MalwareC.sbi (*)
2007-07-31 Includes\KeyloggersC.sbi (*)
2007-07-31 Includes\HijackersC.sbi (*)
2007-07-31 Includes\DialerC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2007-06-06 Plugins\TCPIPAddress.dll
Hello GeneG.
Please see these two topics for a little background information:
http://forums.spybot.info/showpost.php?p=36937&postcount=15
http://forums.spybot.info/showthread.php?t=6894 particularly post #4.
If you did not make the changes by yourself, and would like someone to check the system, please follow the procedure in this link:
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)
Then start your own thread in the Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22)
If you do post a HJT log, please let me know so I can ask a helper to take a look as soon as possible.
That way we can set your mind at ease.
Best regards.
Thank you Tashi for your quick response and help. I am not too computor wise and would like any help you can offer. Thanks again, Gene
WesternAmerican
2007-09-02, 22:22
Thank you Tashi for your quick response and help. I am not too computor wise and would like any help you can offer. Thanks again, Gene
As a rule, you will find that the solutions offered on this forum will not work............they ask for all the data and never post any solutions after people submit to them..........bummer!:alien:
As a rule, you will find that the solutions offered on this forum will not work............they ask for all the data and never post any solutions after people submit to them..........bummer!:alien:WesternAmerican.
I fail to see what your response has to do with member GeneG's topic.
Information requested was given, member chose not to start a topic in our malware forum. Nothing to do with anyone else.
As to your own topic: http://forums.spybot.info/showthread.php?p=116169#post116169
You have received an answer to every question, is there anything else? If so please respond in your own thread.
Regards.
o yeah, flamed by tashi, yeah, whose got the reflexes, Tashi - you know it:eek: