K well just started experiencing this and i don’t know what happened. What ever program i open, whether is be a game, avast, or anything, as soon as press a button on my keyboard, it automatically closes. No warning or nothing. I have run 3 throughout virus scans, found some junk, deleted some of it, but some of it wouldn’t actually delete so i went to delete it manually. Although i have run all these virus scans and got rid of everything on my computer this still happens. I tried a system recovery to 2 weeks ago, even though this started a couple days ago.
Anyone able to help out about this issue? It is really crippling me on doing the stuff i need to do and i’ve run out of ideas.
I don’t really wanna do a system recovery since i have so much stuff on this computer i can’t afford the time to download it all again and install
If anyone has any suggestions please tell me and say how to do them since i am kinda blunted at this stuff
Very strange problem. Do you have a key stuck on your keyboard or something?
nope, everything works perfectly fine when i type in a webpage. I even tried using the on-screen keyboard when trying to log in on a game but it closed like i was using my actual keyboard. So i know that know that nothing is wrong with my keyboard and i don’t what it is
Well, have you tried scanning your computer for viruses and malware in safe mode?
How about using programs in safe mode, do they close then too?
k, well scythe i will try doing the stuff in safemode. Also i found something out. Theres a thing that avast will pick up and it puts a thing in my Temp folder under local settings. the thing that shows up is a bunch of numbers and it usually puts more than one. Then i delete them with advast but an hour or so later they come back…
you mean in the avast4 folder in Temp and a file name like unp(bunchofnumbers).tmp ?
This is where avast unpacks (hence the unp bit at the front) files so they may be scanned, after successful completion these unp------.tmp files are (should be) removed.
k well i did a virus scan last night on windows safe mode, found one thing, deleted it, but nothing is fixed.
As for the thing that keeps coming up, i have it right here i will give you what it says
File name: C:\DOCUME~1(name)\LOCALS~1\Temp\841466020.exe[FSG]
Malware Name: Win32:Agent-BSU [trj
Malware type: Trojan Horse
VPS version: 090121-0, 21/01/2009
Press Delete on that and then this one came up
File name: C;\WINDOWS\TEMP\BN4.tmp
Malware name: Win32:Trojan-gen {Other}
Malware Type: Virus/Worm
VPS Version: 090122-0, 22/01/2009
Press Delete this one came up…
File name: C:\WINDOWS\system32\drivers\ati6mvxx.sys
Malware name: Win32:Protector-B [Rtk]
Malware type: Rootkit
VPS version:090122-0, 22/01/2009
nothing came up after that one
Assuming that this isn’t a hardware problem, I guess the next step would be to download Malware Bytes from http://malwarebytes.org and install it. Update it as well, but don’t run it yet.
Then, reboot into safe mode again, and do a quick scan.
Let us know what you find. You can post the log file that it creates for us to look over.
A boot-time scan is more effective as in safe mode you are still in windows and some malware could be hiding from scans. The boot-time scan happens before windows starts so if something is hiding other malware (like the rootkit detection below), it might be discovered during that scan and be better able to deal with it…
File name: C:\WINDOWS\system32\drivers\ati6mvxx.sys Malware name: Win32:Protector-B [Rtk] Malware type: Rootkit VPS version:090122-0, 22/01/2009
The MBAM application suggested is a good tool to have in addition to avast.
K well i did as scythe instructed, and it came up with ALOT i mean ALOT of everything…
so i got the log file which i’ll paste soon but i clicked “Remove selected” so it came up they were removed but some were not removed…
i will open up avast and press a button see if it closes or not but here is the log file
Malwarebytes’ Anti-Malware 1.33
Database version: 1680
Windows 5.1.2600 Service Pack 3
22/01/2009 12:17:23 PM
mbam-log-2009-01-22 (12-17-16).txt
Scan type: Quick Scan
Objects scanned: 54699
Time elapsed: 3 minute(s), 53 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 7
Registry Values Infected: 8
Registry Data Items Infected: 13
Folders Infected: 1
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\hgfdge4unjdfdg.dll (Trojan.Agent) → No action taken.
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID{c5bf49a2-94f3-42bd-f434-3604812c8955} (Trojan.Zlob.H) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{c5bf49a2-94f3-42bd-f434-3604812c8955} (Trojan.Agent) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{c5bf49a2-94f3-42bd-f434-3604812c8955} (Trojan.Agent) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{7c109800-a5d5-438f-9640-18d17e168b88} (Trojan.Zlob) → No action taken.
HKEY_CLASSES_ROOT\homeview (Trojan.DNSChanger) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explsbsm.exelper Objects (Trojan.Zlob) → No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler{c5bf49a2-94f3-42bd-f434-3604812c8955} (Trojan.Zlob.H) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft WinUpdate (Backdoor.Bot) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\searchmigrateddefaulturl (Trojan.Zlob) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Trojan.Zlob) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\searchurl (Trojan.Zlob) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\searchmigrateddefaulturl (Trojan.Zlob) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Trojan.Zlob) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\searchurl (Trojan.Zlob) → No action taken.
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Hijack.Search) → Bad: (http://internetsearchservice.com/search?q=%s) Good: (http://www.google.com/) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Hijack.Search) → Bad: (http://internetsearchservice.com/search?q=%s) Good: (http://www.google.com/) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Hijack.Search) → Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Hijack.Search) → Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) → Bad: (http://internetsearchservice.com/search?q={searchTerms}) Good: (http://www.google.com/) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) → Bad: (http://internetsearchservice.com/search?q={searchTerms}) Good: (http://www.google.com/) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogOff (Hijack.StartMenu) → Bad: (1) Good: (0) → No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces{090ded8a-1407-4896-b283-bd136379e832}\NameServer (Trojan.DNSChanger) → Data: 85.255.112.204;85.255.112.83 → No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces{61b2b7cd-dab9-472a-a895-d0e38f8da0b4}\NameServer (Trojan.DNSChanger) → Data: 85.255.112.204;85.255.112.83 → No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces{090ded8a-1407-4896-b283-bd136379e832}\NameServer (Trojan.DNSChanger) → Data: 85.255.112.204;85.255.112.83 → No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces{61b2b7cd-dab9-472a-a895-d0e38f8da0b4}\NameServer (Trojan.DNSChanger) → Data: 85.255.112.204;85.255.112.83 → No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces{090ded8a-1407-4896-b283-bd136379e832}\NameServer (Trojan.DNSChanger) → Data: 85.255.112.204;85.255.112.83 → No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces{61b2b7cd-dab9-472a-a895-d0e38f8da0b4}\NameServer (Trojan.DNSChanger) → Data: 85.255.112.204;85.255.112.83 → No action taken.
Folders Infected:
C:\Documents and Settings\Monte\Start Menu\Programs\homeview (Trojan.DNSChanger) → No action taken.
Files Infected:
C:\WINDOWS\system32\hgfdge4unjdfdg.dll (Trojan.Zlob.H) → No action taken.
A boot-time scan is more effective as in safe mode you are still in windows and some malware could be hiding from scans.
Sorry DavidR, I always say safe mode, but I mean boot time scan. Malware and spyware scanners should be ran under safe mode.
I just gotta remember to tell people the right thing!
As for Stud, it says “No Action Taken” on everything it seems. Did you make sure to check all the items before clicking remove selected? If not, you may have to do it again.
yea… i took the log before i hit the clear button so…
On occasion it requires a reboot to clear some of the malware (unloading services/drivers, etc.) but normally that would be made clear.
You say some were not removed, what were they ?
I’m not sure… but i just did another scan and it found nothing at all and when i run a program now it won’t close when i hit any key.
Thanks for the help as everything is normal again, and i will keep this program for future use in case this happens again.
And what program it is that won’t close ?
Where is the ‘any’ key, sorry couldn’t help myself ;D
Where is the 'any' key, sorry couldn't help myself
lol.
no it’s a good thing a program won’t close when i hit the any key…
o by the way, the any key, i don’t know how you don’t know, but mine is located just to the right of the space bar ![]()