* System Security * I've got it bad...nothing will open!

View previous topic View next topic Go down

* System Security * I've got it bad...nothing will open!

Post by brysonprice on Sat Jun 20, 2009 12:55 am

I have the System Security 2009 spyware/virus on my computer. I have tried everything on this forum and then some and still can't get rid of it. NOTHING will work. Everything I try to open doesn't work. I even tried HiJack this...didn't work.

Any suggestions? Thank You!

***** When I try to get into safe mode, it says "Windows has encountered a problem and will shut down in 1 minute"


Last edited by brysonprice on Mon Jun 22, 2009 9:40 pm; edited 2 times in total

brysonprice
Intermediate
Intermediate

Posts Posts : 61
Joined Joined : 2009-06-20
OS OS : Vista 32 bit
Points Points : 27613
# Likes # Likes : 0

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by Origin on Sat Jun 20, 2009 2:56 am

Please download Ice Sword from [You must be registered and logged in to see this link.]

  1. Download the zip to your desktop and extract it.
  2. Open the Ice Sword folder and then launch IceSword.exe.
  3. Then look in the left hand bottom of the program and press "Registry"
  4. When the registry list opens, drag the line between the two windows so you can see which registry hive you need.
  5. Next, open the HKEY_LOCAL_MACHINE, and navigate to the following key:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

  6. Now look in the right side pane for two run values that are just random numbers.
  7. Once you have found the value(s), right click it and press "Delete"
  8. Okay the prompt and close IceSword.

**If you are unable to open the zipped file, download IceSword from here:

  • Please download IceSword from here, I unzipped it so you should only get the .exe file:

    [You must be registered and logged in to see this link.]

  • Once the file has downloaded, see if you can do the above instructions.


While my help is always free, please consider donating to keep this site alive: [You must be registered and logged in to see this link.]

[You must be registered and logged in to see this link.]

Origin
Master
Master

Posts Posts : 2685
Joined Joined : 2009-05-05
Gender Gender : Male
OS OS : Windows Xp Sp3
Points Points : 31463
# Likes # Likes : 0

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by brysonprice on Sat Jun 20, 2009 7:09 am

thanks for the quick response Smile

I tried to open the IceSword.exe , but it never opens. (it won't let me execute any programs)

anything else I can do ?

brysonprice
Intermediate
Intermediate

Posts Posts : 61
Joined Joined : 2009-06-20
OS OS : Vista 32 bit
Points Points : 27613
# Likes # Likes : 0

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by Belahzur on Sat Jun 20, 2009 2:48 pm

Rename IceSword.exe to winlogon.exe and see if it opens now.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245049
# Likes # Likes : 1

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by brysonprice on Sat Jun 20, 2009 3:40 pm

I changed the name to winlogon and when I try to open it, my computer flashes a blue screen with words really fast and then restarts : /

brysonprice
Intermediate
Intermediate

Posts Posts : 61
Joined Joined : 2009-06-20
OS OS : Vista 32 bit
Points Points : 27613
# Likes # Likes : 0

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by Origin on Sun Jun 21, 2009 2:39 pm

Lets try something in safe mode shall we:


Can you do the following in Safe Mode with Networking, as the computer is booting press and hold your "F8 Key" which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press your Enter key.

Note: With some computers if you press and hold a key as the computer is booting you will get a stuck key message. If this occurs, instead of pressing and holding the "F8 key", tap the "F8 key" continuously until you get the startup menu.) Once in the start up menu, select "Safe Mode with Networking", then do the following instructions:




1. If you are using Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

2. During the download, rename Combofix to Combo-Fix as follows:





3. It is important you rename Combofix during the download, but not after.
4. Please do not rename Combofix to other names, but only to the one indicated.
5. Close any open browsers.
6. We need to disable your local AV (Anti-virus) before running Combofix.

  • See [You must be registered and logged in to see this link.] for how to disable your AV. (Mcafee)
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***
  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouse click combofix's window whilst it's running. That may cause it to stall.


While my help is always free, please consider donating to keep this site alive: [You must be registered and logged in to see this link.]

[You must be registered and logged in to see this link.]

Origin
Master
Master

Posts Posts : 2685
Joined Joined : 2009-05-05
Gender Gender : Male
OS OS : Windows Xp Sp3
Points Points : 31463
# Likes # Likes : 0

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by JIMV on Sun Jun 21, 2009 4:22 pm

[You must be registered and logged in to see this link.] wrote:I have the System Security 2009 spyware/virus on my computer. I have tried everything on this forum and then some and still can't get rid of it. NOTHING will work. Everything I try to open doesn't work. I even tried HiJack this...didn't work.

Any suggestions? Thank You!

I was infected yesterday on my XP machine...this nasty thing has cut me off from the internet except to their site. SO, I cannot down load anything. I use Webroot Internet Essentials, which is up to date, but it didn't see this coming and cannot remove it. I cannot get to system restore, help, the internet, add or delete programs, etc. I cannot load a virus program via disk. In short, this mess has shut that PC down. I have run sweeps in safe mode without success...so, how do you get rid of this without having an ability to load a new program???

I also own webroots window washer...this has an erase function which I believe wipes the entire hard drive clean. If I use such a device, does any firmware remain to let me reload XP and then my other programs via the PC's disc drive??? The more I read of this thing, the more this sounds like to only real solution. If I take it to the shop, those folk will just wipe the disk and reload XP...can I do that at home and avoid the $100 fee?

JIMV
Novice
Novice

Posts Posts : 5
Joined Joined : 2009-06-21
OS OS : XP
Points Points : 27237
# Likes # Likes : 0

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by brysonprice on Sun Jun 21, 2009 5:56 pm

[You must be registered and logged in to see this link.] wrote:Lets try something in safe mode shall we:


Can you do the following in Safe Mode with Networking, as the computer is booting press and hold your "F8 Key" which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press your Enter key.

Note: With some computers if you press and hold a key as the computer is booting you will get a stuck key message. If this occurs, instead of pressing and holding the "F8 key", tap the "F8 key" continuously until you get the startup menu.) Once in the start up menu, select "Safe Mode with Networking", then do the following instructions:




1. If you are using Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

2. During the download, rename Combofix to Combo-Fix as follows:





3. It is important you rename Combofix during the download, but not after.
4. Please do not rename Combofix to other names, but only to the one indicated.
5. Close any open browsers.
6. We need to disable your local AV (Anti-virus) before running Combofix.

  • See [You must be registered and logged in to see this link.] for how to disable your AV. (Mcafee)
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***
  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouse click combofix's window whilst it's running. That may cause it to stall.

I opened safe mode, but then it said "Windows has encountered a problem and will restart automatically in 1 minute". When I tried to access the internet, the screen turned blue with some words and restarted.

Thanks for attempting to help...I hope we can figure out the problem : )

brysonprice
Intermediate
Intermediate

Posts Posts : 61
Joined Joined : 2009-06-20
OS OS : Vista 32 bit
Points Points : 27613
# Likes # Likes : 0

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by Origin on Mon Jun 22, 2009 8:54 pm

Download the GMER rootkit scan from here: [You must be registered and logged in to see this link.]

  1. Unzip it and start GMER.
  2. Click the >>> tab and then click the Scan button.
  3. Once done, click the Copy button.
  4. This will copy the results to your clipboard.
  5. Paste the results in your next reply.
Note:
If you're having problems with running GMER.exe, try it in safe mode. This tools works in safe mode.
You can also try renaming it since some malware blocks GMER.


While my help is always free, please consider donating to keep this site alive: [You must be registered and logged in to see this link.]

[You must be registered and logged in to see this link.]

Origin
Master
Master

Posts Posts : 2685
Joined Joined : 2009-05-05
Gender Gender : Male
OS OS : Windows Xp Sp3
Points Points : 31463
# Likes # Likes : 0

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by brysonprice on Mon Jun 22, 2009 9:41 pm

[You must be registered and logged in to see this link.] wrote:Download the GMER rootkit scan from here: [You must be registered and logged in to see this link.]

  1. Unzip it and start GMER.
  2. Click the >>> tab and then click the Scan button.
  3. Once done, click the Copy button.
  4. This will copy the results to your clipboard.
  5. Paste the results in your next reply.
Note:
If you're having problems with running GMER.exe, try it in safe mode. This tools works in safe mode.
You can also try renaming it since some malware blocks GMER.

Origin,

When I log into safe mode, it says "Windows has encountered a problem and will shut down in 1 minute". I tried it, it started scanning, but after a minute, it shut down.
Any other suggestions ?

brysonprice
Intermediate
Intermediate

Posts Posts : 61
Joined Joined : 2009-06-20
OS OS : Vista 32 bit
Points Points : 27613
# Likes # Likes : 0

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by Origin on Mon Jun 22, 2009 9:43 pm

Can you try it in normal mode instead of Safe Mode.


While my help is always free, please consider donating to keep this site alive: [You must be registered and logged in to see this link.]

[You must be registered and logged in to see this link.]

Origin
Master
Master

Posts Posts : 2685
Joined Joined : 2009-05-05
Gender Gender : Male
OS OS : Windows Xp Sp3
Points Points : 31463
# Likes # Likes : 0

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by brysonprice on Mon Jun 22, 2009 10:20 pm

[You must be registered and logged in to see this link.] wrote:Can you try it in normal mode instead of Safe Mode.

I tried it in both and I can't open any programs in either Safe or normal mode

brysonprice
Intermediate
Intermediate

Posts Posts : 61
Joined Joined : 2009-06-20
OS OS : Vista 32 bit
Points Points : 27613
# Likes # Likes : 0

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by Belahzur on Mon Jun 22, 2009 11:35 pm


  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
  • Double click DDS.scr to run.
  • When complete, two logs will open. Save both of the report to your Desktop.
  • Copy and paste DDS.txt back here, I don't need to see attach.txt.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245049
# Likes # Likes : 1

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by JIMV on Tue Jun 23, 2009 1:23 am

Any cure that requires a download is out for me as the vrus will not let me go to the internet on the infected machine...

JIMV
Novice
Novice

Posts Posts : 5
Joined Joined : 2009-06-21
OS OS : XP
Points Points : 27237
# Likes # Likes : 0

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by brysonprice on Tue Jun 23, 2009 1:32 am

[You must be registered and logged in to see this link.] wrote:

  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
  • Double click DDS.scr to run.
  • When complete, two logs will open. Save both of the report to your Desktop.
  • Copy and paste DDS.txt back here, I don't need to see attach.txt.

The "system Security" says "application cannot be executed. The file dds.scr is infected. Please activate your antivirus software".

brysonprice
Intermediate
Intermediate

Posts Posts : 61
Joined Joined : 2009-06-20
OS OS : Vista 32 bit
Points Points : 27613
# Likes # Likes : 0

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by Swampfox on Tue Jun 23, 2009 3:31 am

[You must be registered and logged in to see this link.] wrote:Please download Ice Sword from [You must be registered and logged in to see this link.]

  1. Download the zip to your desktop and extract it.
  2. Open the Ice Sword folder and then launch IceSword.exe.
  3. Then look in the left hand bottom of the program and press "Registry"
  4. When the registry list opens, drag the line between the two windows so you can see which registry hive you need.
  5. Next, open the HKEY_LOCAL_MACHINE, and navigate to the following key:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

  6. Now look in the right side pane for two run values that are just random numbers.
  7. Once you have found the value(s), right click it and press "Delete"
  8. Okay the prompt and close IceSword.

**If you are unable to open the zipped file, download IceSword from here:

  • Please download IceSword from here, I unzipped it so you should only get the .exe file:

    [You must be registered and logged in to see this link.]

  • Once the file has downloaded, see if you can do the above instructions.


I did this but I dont see the random numbers. The only value I see is the default and it does nothing when i delete it.

Swampfox
Novice
Novice

Posts Posts : 16
Joined Joined : 2009-06-23
OS OS : xp pro
Points Points : 27232
# Likes # Likes : 0

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by Origin on Tue Jun 23, 2009 4:20 pm

Swampfox please refrain from posting in other members posts are start your own, I would be happy to help you if you do.


No I don't think you should, many of those are crucial to the system.

Download MGtools from here: [You must be registered and logged in to see this link.]

Now follow the instructions on this page:

[You must be registered and logged in to see this link.]

Once you haver MGtools extracted to your C:\ drive there will be a file there called Analyze.exe That file will be HijackThis, now follow these directions:

  • Select Do a system scan and save a log file. This will open a notepad file of everything Hijack This found, copy and paste it back here.


While my help is always free, please consider donating to keep this site alive: [You must be registered and logged in to see this link.]

[You must be registered and logged in to see this link.]

Origin
Master
Master

Posts Posts : 2685
Joined Joined : 2009-05-05
Gender Gender : Male
OS OS : Windows Xp Sp3
Points Points : 31463
# Likes # Likes : 0

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by brysonprice on Tue Jun 23, 2009 8:10 pm

[You must be registered and logged in to see this link.] wrote:Swampfox please refrain from posting in other members posts are start your own, I would be happy to help you if you do.


No I don't think you should, many of those are crucial to the system.

Download MGtools from here: [You must be registered and logged in to see this link.]

Now follow the instructions on this page:

[You must be registered and logged in to see this link.]

Once you haver MGtools extracted to your C:\ drive there will be a file there called Analyze.exe That file will be HijackThis, now follow these directions:

  • Select Do a system scan and save a log file. This will open a notepad file of everything Hijack This found, copy and paste it back here.

This also won't open...no programs will open :hmm:

brysonprice
Intermediate
Intermediate

Posts Posts : 61
Joined Joined : 2009-06-20
OS OS : Vista 32 bit
Points Points : 27613
# Likes # Likes : 0

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by JIMV on Tue Jun 23, 2009 9:01 pm

did not work for me, but I am running an XP machine...

JIMV
Novice
Novice

Posts Posts : 5
Joined Joined : 2009-06-21
OS OS : XP
Points Points : 27237
# Likes # Likes : 0

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by brysonprice on Thu Jun 25, 2009 7:08 pm

anything else ?

brysonprice
Intermediate
Intermediate

Posts Posts : 61
Joined Joined : 2009-06-20
OS OS : Vista 32 bit
Points Points : 27613
# Likes # Likes : 0

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by Belahzur on Thu Jun 25, 2009 11:54 pm

Try renaming MGTools.exe to Winlogon.exe, see if the malware notices or not.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245049
# Likes # Likes : 1

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by brysonprice on Fri Jun 26, 2009 3:20 am

[You must be registered and logged in to see this link.] wrote:Try renaming MGTools.exe to Winlogon.exe, see if the malware notices or not.

I tried and it didn't work : /

brysonprice
Intermediate
Intermediate

Posts Posts : 61
Joined Joined : 2009-06-20
OS OS : Vista 32 bit
Points Points : 27613
# Likes # Likes : 0

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by brysonprice on Fri Jun 26, 2009 8:12 pm

I really just want to wipe my hard drive clean, but I need to be able to access the recovery discs and I can't ! I have already saved ALL info on my computer.

brysonprice
Intermediate
Intermediate

Posts Posts : 61
Joined Joined : 2009-06-20
OS OS : Vista 32 bit
Points Points : 27613
# Likes # Likes : 0

View user profile

Back to top Go down

Re: * System Security * I've got it bad...nothing will open!

Post by Belahzur on Sat Jun 27, 2009 1:30 am

I haven't given up yet. Smile


  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
  • Double click DDS.scr to run.
  • When complete, two logs will open. Save both of the report to your Desktop.
  • Copy and paste DDS.txt back here, I don't need to see attach.txt.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245049
# Likes # Likes : 1

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum