Help with error please

#2
Yeah thats not good, Run your Anti-Virus and Spyware software. That would be the first thing I would do. If that does not get rid of it. Then you might have to go into safe mode and delete it your self.

ls1 FTL
 

kcnychief

█▄█ ▀█▄ █
Political User
#3
You can also remove the message from startup by clicking your Start button, go to Run, type "msconfig" and hit enter

The last tab to the right will be the startup tab, uncheck the box next to that file name and it won't occur at boot anymore. Then do a scan as NLM stated.
 
#4
Thanks for the help guys. I tried both suggestions with no sucsess.I've scanned with up to date versions of Ad-Aware,Spybot search & destroy and AVG7 Virus scan.
However I'm not sure about some files in Windows\System32\WineSecure.exe
Winsecure.001
Winsecure.003
Winsecure.006
Winsecure.007
I have deleted these files but they keep returning. I've done searches for Winsecure and it seems to be some kind of hyjacker but I can't figure out how to perminently get rid of it.
 

BouncingSoul

Stranger Than Fiction
Political User
#5
WineSecure.exe or WinSecure?

I cant find any info on WineSecure.exe but WinSecure is known spyware. I'd recommend HijackThis to remove it, post a log if you still can't get it.
 
#6
Sorry........should be WinSecure a little wine or something stronger would be good about now. It's at times like this I wish I DID drink. I will try HyjackThis and see how I make out.
Thanks
 

Mastershakes

OSNN Veteran Addict
#7
Post the log here. ;)

At first analysis, it does not look great - AfterNET Link

AfterNET said:
"

Line 0 (File "C:\WINDOWS\system32\Firewall.exe):
$Seconds = $TimeandDate[10]
$Seconds = ^ERROR

Error: Array variable has incorrect number of subscripts or subscript dimension range exceeded.
Are you seeing the above message in a box that suddenly popped-up on your computer? If so, you may have a trojan virus! A guy has been distributing a virus written in AutoIT3 which contains a keylogger, and connects to IRC networks to allow him to read the logged passwords. Part of the mechanics of this process relied on a website which has been taken down, resulting in the error message you see. This virus is _NOT_ detected by virus scanning software! Write down the location of the exe that gave you the popup message, and contact a professional to inspect your system for rootkits. Generally the virus is known as "Firewall.exe" but this may have changed in some versions.
Issue is fixed here - http://www.castlecops.com/p786112-quot_cleaned_quot_system_apparently_still_having_weird_pr.html

Let me know if you need a cleaner break down - but they managed to kill it. There is a trojan called
Trojan.Win32.Autoit.p in that firewall.exe file.
 
Last edited:
#8
Post the log here. ;)

At first analysis, it does not look great - AfterNET Link



Issue is fixed here - http://www.castlecops.com/p786112-quot_cleaned_quot_system_apparently_still_having_weird_pr.html

Let me know if you need a cleaner break down - but they managed to kill it. There is a trojan called
Trojan.Win32.Autoit.p in that firewall.exe file.

I deleted the file firewall.exe from windows\system32\ and this seems to have solved the problem......no more winsecure files have appeared. Sofar so good.
Thanks for all your help.
 

Members online

No members online now.

Latest posts

Latest profile posts

Perris Calderon wrote on Electronic Punk's profile.
Ep, glad to see you come back and tidy up...did want to ask a one day favor, I want to enhance my resume , was hoping you could make me administrator for a day, if so, take me right off since I won't be here to do anything, and don't know the slightest about the board, but it would be nice putting "served administrator osnn", if can do, THANKS

Been running around Quora lately, luv it there https://tinyurl.com/ycpxl
Electronic Punk wrote on Perris Calderon's profile.
All good still mate?
Hello, is there anybody in there? Just nod if you can hear me ...
Xie
What a long strange trip it's been. =)

Forum statistics

Threads
61,970
Messages
673,297
Members
89,016
Latest member
Poseeut