GeekPolice
Welcome to GeekPolice.net!

From "wow" to "whoa" - we're teaching practical technology and helping others with tech support. Join our family here!

You are viewing the forum as a "Guest" which doesn't give you member privileges to ask questions or post comments.

Take 30 seconds to register or log in below and unlock the limitations of this website to discover new computer knowledge!

Virus on my computer will not let me open any of my software programs

View previous topic View next topic Go down

Virus on my computer will not let me open any of my software programs

Post by lynnieh on Sun Jan 10, 2010 10:07 pm

Last night we got a virus from the internet, I can not run any of the anti-virus software. I was able to download IceSword and get it to run, but nȯne of my other software programs run, not even notepad. Every few minutes my IE pop open and it goes to porn sites. I tried installing HackThis, OTL and these will not open.
Please help!

lynnieh
Beginner
Beginner

Status :
Online
Offline

Posts : 3
Joined : 2010-01-10
Gender : Female
OS : xp
Points : 25223
# Likes : 0

View user profile

Back to top Go down

Re: Virus on my computer will not let me open any of my software programs

Post by Belahzur on Sun Jan 10, 2010 10:22 pm

Okay, we'll use IceSword.
LIST]
[*] Please open IceSword.
[*] Now, on the left hand side tool, hit the Process button at the top of the list.
[*] Just above the list, there is a log button, press that and save the log to your Desktop.
[*] Next, hit the Startup on the left side list.
[*] Press the log button again.
[*] Post the two logs in your next reply.
[/LIST]


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Virus on my computer will not let me open any of my software programs

Post by lynnieh on Sun Jan 10, 2010 10:27 pm

Thank you!
Process Log/
Process:

System Idle Process
System
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\KeyboardSurrogate.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\CCPROXY.EXE
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\scardsvr.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\tabtip.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\tcserver.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\smss.exe
C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Fingerprint Sensor\ATSwpNav.exe
C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\digtizer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVAPSVC.EXE
C:\WINDOWS\system32\o2flash.exe
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
C:\Program Files\Softex\OmniPass\OmniServ.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE
C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
C:\WINDOWS\system32\KADxMain.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Softex\OmniPass\scureapp.exe
C:\Program Files\Fujitsu\fjdvrupd\fjdvrupd.exe
C:\WINDOWS\system32\wisptis.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\tabbtnu.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Fujitsu\Utils\FjDspMon.exe
C:\Program Files\Fujitsu\Utils\FjEvents.exe
C:\Program Files\Fujitsu\Utils\FjMnuIco.exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\ilvpki\yxlusysguard.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\IceSword122en\IceSword.exe
/
Startup Log/
Startup:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
TabletWizard
C:\WINDOWS\help\SplshWrp.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
TabletTip
"C:\Program Files\Common Files\microsoft shared\ink\tabtip.exe" /resume

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SynTPEnh
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
igfxhkcmd
C:\WINDOWS\system32\hkcmd.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
igfxpers
C:\WINDOWS\system32\igfxpers.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
AGRSMMSG
AGRSMMSG.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ATSwpNav
"C:\Program Files\Fingerprint Sensor\ATSwpNav" -run

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
LoadFUJ02E3
C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
FjStrtAp
c:\Program Files\Fujitsu\Utils\FjStrtAp.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IndicatorUtility
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
LoadBtnHnd
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ccApp
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
URLLSTCK.exe
C:\Program Files\Norton Internet Security\UrlLstCk.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
KADxMain
C:\windows\system32\KADxMain.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IntelZeroConfig
"C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IntelWireless
"C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
OmniPass
C:\Program Files\Softex\OmniPass\scureapp.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
FJUPDNV_Chitose
C:\Program Files\Fujitsu\fjdvrupd\fjdvrupd.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
BrMfcWnd
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ControlCenter3
C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
QuickTime Task
"C:\Program Files\QuickTime\qttask.exe" -atboottime

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
iTunesHelper
"C:\Program Files\iTunes\iTunesHelper.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
BlackBerryAutoUpdate
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
dojvcxqo
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\ilvpki\yxlusysguard.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
MSMSGS
"C:\Program Files\Messenger\msmsgs.exe" /background

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Remark£º)

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Bluetooth Manager.lnk
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (Remark£º)

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Cisco Systems VPN Client.lnk
C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe (Remark£º)

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
desktop.ini


C:\Documents and Settings\Administrator\Start Menu\Programs\Startup
desktop.ini

lynnieh
Beginner
Beginner

Status :
Online
Offline

Posts : 3
Joined : 2010-01-10
Gender : Female
OS : xp
Points : 25223
# Likes : 0

View user profile

Back to top Go down

Re: Virus on my computer will not let me open any of my software programs

Post by Belahzur on Sun Jan 10, 2010 10:33 pm

Hello.


  • Open IceSword again.
  • Go into the Process list again, and right click on the following filename:

    yxlusysguard.exe

  • Select Terminate Process.

Please download and run this tool.

Download Malwarebytes' Anti-Malware from [You must be registered and logged in to see this link.]

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Virus on my computer will not let me open any of my software programs

Post by lynnieh on Sun Jan 10, 2010 11:10 pm

Thank you so much, our computer is working again! Here is the log file
Malwarebytes' Anti-Malware 1.44
Database version: 3537
Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.13

1/10/2010 3:04:42 PM
mbam-log-2010-01-10 (15-04-42).txt

Scan type: Quick Scan
Objects scanned: 129042
Time elapsed: 22 minute(s), 53 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 2
Registry Data Items Infected: 3
Folders Infected: 7
Files Infected: 20

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jvm.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\AvScan (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\idid (Trojan.Sasfix) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\oledll (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dojvcxqo (Trojan.FakeAlert.N) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (Explorer.exe rundll32.exe fimp.elo pufxcp) Good: (Explorer.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\STC (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65 (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\bin (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\bin\classic (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\lib (Fake.Dropped.Malware) -> Quarantined and deleted successfully.

Files Infected:
C:\RECYCLER\S-1-5-21-2328200581-3523396507-3994907741-500\Dc187\wmiprvse.exe (Worm.Autorun.One Cool Dude -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fimp.elo (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\pdfupd.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\20.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\21.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\26.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4XQVLDEB\Flash_Plugin_v10_0_42_34[1].exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\U6QNH0D8\load[1].exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\spool\prtprocs\w32x86\27.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\cbt.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\bin\hpi.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\bin\java.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\bin\JdbcOdbc.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\bin\verify.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\bin\zip.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\bin\classic\jvm.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\lib\i18n.jar (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\lib\rt.jar (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\lib\sunrsasign.jar (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Desktop\explorer.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.

lynnieh
Beginner
Beginner

Status :
Online
Offline

Posts : 3
Joined : 2010-01-10
Gender : Female
OS : xp
Points : 25223
# Likes : 0

View user profile

Back to top Go down

Re: Virus on my computer will not let me open any of my software programs

Post by Belahzur on Mon Jan 11, 2010 12:45 am

Hello.

  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
  • Double click DDS.scr to run.
  • When complete, two logs will open. Save both of the report to your Desktop.
  • Copy and paste BOTH LOGS back here, use more than one post if needed.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum