WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionVirus on my computer will not let me open any of my software programs EmptyVirus on my computer will not let me open any of my software programs

more_horiz
Last night we got a virus from the internet, I can not run any of the anti-virus software. I was able to download IceSword and get it to run, but nȯne of my other software programs run, not even notepad. Every few minutes my IE pop open and it goes to porn sites. I tried installing HackThis, OTL and these will not open.
Please help!

descriptionVirus on my computer will not let me open any of my software programs EmptyRe: Virus on my computer will not let me open any of my software programs

more_horiz
Okay, we'll use IceSword.
LIST]
[*] Please open IceSword.
[*] Now, on the left hand side tool, hit the Process button at the top of the list.
[*] Just above the list, there is a log button, press that and save the log to your Desktop.
[*] Next, hit the Startup on the left side list.
[*] Press the log button again.
[*] Post the two logs in your next reply.
[/LIST]

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Virus on my computer will not let me open any of my software programs DXwU4
Virus on my computer will not let me open any of my software programs VvYDg

descriptionVirus on my computer will not let me open any of my software programs EmptyRe: Virus on my computer will not let me open any of my software programs

more_horiz
Thank you!
Process Log/
Process:

System Idle Process
System
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\KeyboardSurrogate.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\CCPROXY.EXE
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\scardsvr.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\tabtip.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\tcserver.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\smss.exe
C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Fingerprint Sensor\ATSwpNav.exe
C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\digtizer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVAPSVC.EXE
C:\WINDOWS\system32\o2flash.exe
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
C:\Program Files\Softex\OmniPass\OmniServ.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE
C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
C:\WINDOWS\system32\KADxMain.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Softex\OmniPass\scureapp.exe
C:\Program Files\Fujitsu\fjdvrupd\fjdvrupd.exe
C:\WINDOWS\system32\wisptis.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\tabbtnu.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Fujitsu\Utils\FjDspMon.exe
C:\Program Files\Fujitsu\Utils\FjEvents.exe
C:\Program Files\Fujitsu\Utils\FjMnuIco.exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\ilvpki\yxlusysguard.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\IceSword122en\IceSword.exe
/
Startup Log/
Startup:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
TabletWizard
C:\WINDOWS\help\SplshWrp.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
TabletTip
"C:\Program Files\Common Files\microsoft shared\ink\tabtip.exe" /resume

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SynTPEnh
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
igfxhkcmd
C:\WINDOWS\system32\hkcmd.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
igfxpers
C:\WINDOWS\system32\igfxpers.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
AGRSMMSG
AGRSMMSG.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ATSwpNav
"C:\Program Files\Fingerprint Sensor\ATSwpNav" -run

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
LoadFUJ02E3
C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
FjStrtAp
c:\Program Files\Fujitsu\Utils\FjStrtAp.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IndicatorUtility
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
LoadBtnHnd
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ccApp
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
URLLSTCK.exe
C:\Program Files\Norton Internet Security\UrlLstCk.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
KADxMain
C:\windows\system32\KADxMain.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IntelZeroConfig
"C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IntelWireless
"C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
OmniPass
C:\Program Files\Softex\OmniPass\scureapp.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
FJUPDNV_Chitose
C:\Program Files\Fujitsu\fjdvrupd\fjdvrupd.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
BrMfcWnd
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ControlCenter3
C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
QuickTime Task
"C:\Program Files\QuickTime\qttask.exe" -atboottime

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
iTunesHelper
"C:\Program Files\iTunes\iTunesHelper.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
BlackBerryAutoUpdate
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
dojvcxqo
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\ilvpki\yxlusysguard.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
MSMSGS
"C:\Program Files\Messenger\msmsgs.exe" /background

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Remark£º)

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Bluetooth Manager.lnk
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (Remark£º)

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Cisco Systems VPN Client.lnk
C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe (Remark£º)

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
desktop.ini


C:\Documents and Settings\Administrator\Start Menu\Programs\Startup
desktop.ini

descriptionVirus on my computer will not let me open any of my software programs EmptyRe: Virus on my computer will not let me open any of my software programs

more_horiz
Hello.


  • Open IceSword again.
  • Go into the Process list again, and right click on the following filename:

    yxlusysguard.exe

  • Select Terminate Process.

Please download and run this tool.

Download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Virus on my computer will not let me open any of my software programs DXwU4
Virus on my computer will not let me open any of my software programs VvYDg

descriptionVirus on my computer will not let me open any of my software programs EmptyRe: Virus on my computer will not let me open any of my software programs

more_horiz
Thank you so much, our computer is working again! Here is the log file
Malwarebytes' Anti-Malware 1.44
Database version: 3537
Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.13

1/10/2010 3:04:42 PM
mbam-log-2010-01-10 (15-04-42).txt

Scan type: Quick Scan
Objects scanned: 129042
Time elapsed: 22 minute(s), 53 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 2
Registry Data Items Infected: 3
Folders Infected: 7
Files Infected: 20

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jvm.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\AvScan (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\idid (Trojan.Sasfix) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\oledll (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dojvcxqo (Trojan.FakeAlert.N) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (Explorer.exe rundll32.exe fimp.elo pufxcp) Good: (Explorer.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\STC (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65 (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\bin (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\bin\classic (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\lib (Fake.Dropped.Malware) -> Quarantined and deleted successfully.

Files Infected:
C:\RECYCLER\S-1-5-21-2328200581-3523396507-3994907741-500\Dc187\wmiprvse.exe (Worm.Autorun.One Cool Dude -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fimp.elo (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\pdfupd.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\20.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\21.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\26.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4XQVLDEB\Flash_Plugin_v10_0_42_34[1].exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\U6QNH0D8\load[1].exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\spool\prtprocs\w32x86\27.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\cbt.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\bin\hpi.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\bin\java.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\bin\JdbcOdbc.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\bin\verify.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\bin\zip.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\bin\classic\jvm.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\lib\i18n.jar (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\lib\rt.jar (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\STC\QA65\wwwroot\jre\lib\sunrsasign.jar (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Desktop\explorer.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.

descriptionVirus on my computer will not let me open any of my software programs EmptyRe: Virus on my computer will not let me open any of my software programs

more_horiz
Hello.

  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    Link 1
    Link 2
  • Double click DDS.scr to run.
  • When complete, two logs will open. Save both of the report to your Desktop.
  • Copy and paste BOTH LOGS back here, use more than one post if needed.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Virus on my computer will not let me open any of my software programs DXwU4
Virus on my computer will not let me open any of my software programs VvYDg

descriptionVirus on my computer will not let me open any of my software programs EmptyRe: Virus on my computer will not let me open any of my software programs

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum