Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.When posting your problem, do not run and post a ComboFix logs. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.
To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.
![]() ![]() |
Jan 27 2010, 12:24 AM
Post
#1
|
|
|
New Member ![]() Group: Members Posts: 2 Joined: 27-January 10 Member No.: 443,056 |
I'm new here; I just registered minutes ago. And I did so because of the box I'm looking at on my screen right now. I'm running Windows XP and just a few days ago, this strange box started popping up after I'm on line five to ten minutes. It looks a little like the old "Illegal Operation" box you used to get with Windows 95. It reads: AXWIN Frame Window: svchost.exe - application error. The instruction at "0x02d0f7a0" referenced memory at "0x02dof7a0". The memory could not be written." Then it tells me to click on OK to terminate the program or click on CANCEL to debug the program. If I do either, it shuts windows down. I get a box on the screen tellling me NT Authority\system is causing the shutdown via "Dcom server process launcher." As I said, it started popping up a few days ago. If I leave it alone and click neither OK not Cancel, the computer operates normally -- I simply move the box around. But it's very disconcerting. I have Malwarebytes, SuperAntiSpyware and Avast! and have run all three and they come up clean. I tried to restore the computer to a previous date -- I picked January 14, as it was a week or so before this popped up -- but I still can't get rid of it. And actually, I came to Bleeping Computer to download and run "Combofix," but while I know these things fairly well, it may be a bit more "tech heavy" than my abilities. Also, I googled "AXWIN" and found several hundred hits of users having the same problem I am, all within the last few days. Any ideas? Will Combofix do it? Is there anything else? L. A. Tarone |
|
|
|
Feb 9 2010, 10:18 AM
Post
#2
|
|
|
New Member ![]() Group: Members Posts: 2 Joined: 27-January 10 Member No.: 443,056 |
For what it's worth, this turned out to be the Rootkit virus. I'm happy to say that Combofix got rid of it. This really is a good program and it worked very well. I apparently had a bunch of other viruses, trojans, worms, etc., of which I wasn't even aware. But after running Combofix, the number of processes running dropped from something near 120 to 46. So, it worked every, very well.
L. A. Tarone |
|
|
|
Feb 9 2010, 01:52 PM
Post
#3
|
|
![]() Bleepin' Janitor ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 19,390 Joined: 9-July 05 From: Virginia, USA Member No.: 26,513 |
Glad to hear the issue has been resolved. However, please note the message text in blue at the top of this forum.
No one should be using ComboFix unless specifically instructed to do so by a Malware Removal Expert who can interpret the logs. Please read the pinned topic ComboFix usage, Questions, Help? - Look here. You were fortunate in this instance that no unforeseen consequences occurred. -------------------- "THE BAD GUYS DON'T NEED A SEARCH WARRANT. ARE YOU PROTECTED?"
Microsoft MVP - Windows Security 2007-2010 ![]() Member of UNITE, Unified Network of Instructors and Trusted Eliminators |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 20th March 2010 - 01:17 AM |