Okay so I've been getting A LOT of pos.tmp etc. files in my C: Drive and My Docs. I also have a Red X for the icon of my C Drive. I also have these "system messages":

System Warning:
Windows performed illegal operation. Your system files could have critical errors.
It could cause unpredictable or erratic behavior, freezes and crashes.
Fixing these errors can increase your computers's performance and prevent data your personal data loss.
Would you like to open System Troubleshooting center to fix the problem? (Recommended)

Your system could become unstable
A potential problem has been detected and Windows has been shutdown
buggy application to prevent damage to your computer.
****WXYZ.SYS - Address F73120AE base at C00000, DateStamp 36b072A3
Kernel Debugger Using: COM2 (Port 0x28f, Baud rate 192000)

SysFader: IEXPLORER.EXE - Potential Application Error
The instruction at "0x01d62739" referenced memory at "0x02354e50".
The memory could not be "read. Click OK to terminate.

Important - Potential Errors found in the system
During a scan of files at system startup,
potential errors in the system registry were found.
p-07-0100 irql: 1f SYSVER 0xff00024
NT_Kernel error 1256
KMODE_EXCEPTION_NOT_HANDLED

I had this problem yesterday morning. I googled the problem, and ran Vundofix which seemed to have fixed the problem yesterday morning. This computer was working all fine until about an hour ago, it came back. I ran Vundofix again and it's not fixing the damn thing now. How do I fix this? THANKS IN ADVANCE

Dani AI

Generated

Symptoms described by , and — many pos*.tmp files filling C:, fake “system” warnings and persistent desktop pop-ups even when not browsing, plus a red X overlay on the C: icon — are consistent with scareware/rogue-security families and lingering adware/rootkit components that refuse simple removal. A temporary fix from a single tool (as reported) often means a persistent component remains (startup entry, scheduled task, or rootkit) and is re-creating the files.

A practical triage checklist used in similar cases:

  • Immediately isolate the machine from the network to stop active downloads/updates.
  • Boot to Safe Mode (or Safe Mode with Networking only if an updated scanner must be downloaded) and run updated anti-malware scanners (full system scans). Tools commonly used include Malwarebytes Anti-Malware and a reputable anti-rootkit scanner; run multiple independent scanners rather than relying on one product.
  • Use Autoruns (or HijackThis for generation of a repair log, as suggested) to inspect Run/RunOnce, Services, Scheduled Tasks and Explorer shell overlays for suspicious entries. Collect and share a clean HijackThis-style log when asking for help so responders can point to specific entries.

When pos*.tmp files cannot be deleted:

  • They are usually locked by a running process. Identify the process with Process Explorer or by checking Autoruns/Services, terminate it in Safe Mode, then remove the files.
  • If that fails, delete the files from an external rescue environment (Windows PE or a Linux live-USB / rescue CD) so the malware cannot protect them.
  • Run disk and system checks (chkdsk C: /F /R) and, if system files look corrupted, sfc /scannow from a recovery console or admin command prompt.

If repeated cleaning attempts fail or the system is unstable, a full backup of personal data (scan backups on a clean machine before restore) followed by a clean OS reinstall is the most reliable recovery. Avoid clicking any of the fake “repair” dialogs and avoid running unfamiliar utilities without clear guidance — ComboFix/rootkit removers can fix infections but should be used with care. For focused help, a dedicated support thread including the OS version, AV products used, and a HijackThis/Autoruns log is the standard next step.

Recommended Answers

All 5 Replies

okay if you have HijackThis then do a system scan and post the logfile here if you do not have it download it from filehippo.com and download CCleaner and Spybot S&D if you dont already have them.

Okay so I've been getting A LOT of pos.tmp etc. files in my C: Drive and My Docs. I also have a Red X for the icon of my C Drive. I also have these "system messages":

System Warning:
Windows performed illegal operation. Your system files could have critical errors.
It could cause unpredictable or erratic behavior, freezes and crashes.
Fixing these errors can increase your computers's performance and prevent data your personal data loss.
Would you like to open System Troubleshooting center to fix the problem? (Recommended)

Your system could become unstable
A potential problem has been detected and Windows has been shutdown
buggy application to prevent damage to your computer.
****WXYZ.SYS - Address F73120AE base at C00000, DateStamp 36b072A3
Kernel Debugger Using: COM2 (Port 0x28f, Baud rate 192000)

SysFader: IEXPLORER.EXE - Potential Application Error
The instruction at "0x01d62739" referenced memory at "0x02354e50".
The memory could not be "read. Click OK to terminate.

Important - Potential Errors found in the system
During a scan of files at system startup,
potential errors in the system registry were found.
p-07-0100 irql: 1f SYSVER 0xff00024
NT_Kernel error 1256
KMODE_EXCEPTION_NOT_HANDLED

I had this problem yesterday morning. I googled the problem, and ran Vundofix which seemed to have fixed the problem yesterday morning. This computer was working all fine until about an hour ago, it came back. I ran Vundofix again and it's not fixing the damn thing now. How do I fix this? THANKS IN ADVANCE

I have exactly the same problem !
its terrible, these .tmp files take almost a GB
Another problem i have are lots and lots of (mostly IE )pop-ups
, even when not using any browser.
I've tried everything and some seem to work but they just keep coming back !
is there any way to fix this without such a hijackthing ?

I have the same problem. Thousands of pos*.tmp files on c:\ and My Documents and they can't be deleted. I'm also getting desktop pop-ups (when not surfing) and error messages.

A potential problem has been detected and Windows has been shutdown
buggy application to prevent damage to your computer.
****WXYZ.SYS - Address F73120AE base at C00000, DateStamp 36b072A3
Kernel Debugger Using: COM2 (Port 0x28f, Baud rate 192000).

Scanned with S&D, Spyware Doctor, Ad-Aware, Trojan Remover, CCleaner and found few trojans, but removing them didn't help.:icon_cry:

Anyone got a fix? thx

Hi, I'm new to this forum and I am having the same problem. Can anyone help me out with this? Thx

Ok guys. Can all those having problems please read the stickies at the head of the forum and then start their own thread. Will make it so much easier on everyone :).

This thread is now closed. If you need it reopened, please send a PM to one of our Mods.

Include the link to the thread and detail why you need it reopened.

If this is not your thread please start a New Topic.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.