really weird situation: have windows explorer stuck as desktop
Join Date: May 2006
Posts: 86,123
hmm quick google search showed bn10.tmp is bad news. I went ahead and deleted it.
Join Date: Sep 2007
Posts: 43,574
thats good news then. Maybe you got the source of the problem.
How did you delete it?
I know with Comodo if you can't delete a file, you can manually quarantine and keep it from executing, but if you were able to delete it for good then thats good.
Comodo is pretty pop up heavy, pretty alert heavy, but it's very thorough. If you can get past the amount of alerts, it's easy to appreciate.
Join Date: May 2006
Posts: 86,123
i just went through my computer to the folder it was in and straight deleted then emptied recycle bin.
Join Date: Sep 2007
Posts: 43,574
have you tried rebooting to see if you still get the alert from Comodo about it modifying files?
Do you still have the .dll?
Join Date: May 2006
Posts: 86,123
my last reboot i got the same stuff, except it was bn20.tmp instead of bn10
the winctrl32.dll is still there
Join Date: Sep 2007
Posts: 43,574
hmm.
Ok, lets see if you can quarantine those files.
Open Comodo - Defense + - My quarantined files (common tasks) - Add - Browse for the files and quarantine. Try to quarantine the .dll and the .tmp
Also, open Comodo - Defense + - View active process list - look through it, if you find the port21fs.exe, click it to highlight it, right click - terminate and quarantine.
Edit - if you find that port21fs.exe in the active process list, go ahead and click it to highlight - right click - show full path before you terminate and quarantine, to see if we can locate where it is on your computer.
... have you tried deleting the .tmp in safe mode?
Last edited by LirvA; 05-18-2008 at 08:12 PM.
Join Date: Sep 2007
Posts: 43,574
Also, let's see if any unknowns are connecting to the internet.
Open Comodo - Firewall - view active connections (common tasks) - if you see that port21fs.exe, show full path then terminate connection, and if you see any that don't look familar, google them to see if you can find out if they are known to be safe, if not, find the full path and terminate connection, then quarantine them through the Denfense + section.
Join Date: May 2006
Posts: 86,123
i was able to delete the .tmp in regular mode, its gone now
port21fs has been gone for a while now
.dll is quarantined
Join Date: May 2006
Posts: 86,123
all active connections are things I know. Just firefox, aim, and the windows stuff
Join Date: Sep 2007
Posts: 43,574
ok, go ahead and reboot to see if you still get the Comodo alerts, let me know, then go ahead and post another HijackThis log here in this thread.
Join Date: Sep 2007
Posts: 43,574
I believe this issue has been resolved, Mods feel free to lock this thread.
dkgojackets feel free to p.m. me if you have any further troubles.
Join Date: May 2006
Posts: 86,123
fwiw i dont like having my threads locked
thanks for your help itt, I'll come back if anything bad happens
Join Date: Sep 2007
Posts: 43,574
"fwiw i dont like having my threads locked"
All apologies, I understand.
"thanks for your help itt, I'll come back if anything bad happens"
you're very welcome, glad to help.