WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


description* System Security * I've got it bad...nothing will open! Empty* System Security * I've got it bad...nothing will open!

more_horiz
I have the System Security 2009 spyware/virus on my computer. I have tried everything on this forum and then some and still can't get rid of it. NOTHING will work. Everything I try to open doesn't work. I even tried HiJack this...didn't work.

Any suggestions? Thank You!

***** When I try to get into safe mode, it says "Windows has encountered a problem and will shut down in 1 minute"

Last edited by brysonprice on 22nd June 2009, 9:40 pm; edited 2 times in total

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
Please download Ice Sword from HERE

  1. Download the zip to your desktop and extract it.
  2. Open the Ice Sword folder and then launch IceSword.exe.
  3. Then look in the left hand bottom of the program and press "Registry"
  4. When the registry list opens, drag the line between the two windows so you can see which registry hive you need.
  5. Next, open the HKEY_LOCAL_MACHINE, and navigate to the following key:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

  6. Now look in the right side pane for two run values that are just random numbers.
  7. Once you have found the value(s), right click it and press "Delete"
  8. Okay the prompt and close IceSword.

**If you are unable to open the zipped file, download IceSword from here:

............................................................................................

While my help is always free, please consider donating to keep this site alive: Donate

* System Security * I've got it bad...nothing will open! 2wg6fte

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
thanks for the quick response Smile...

I tried to open the IceSword.exe , but it never opens. (it won't let me execute any programs)

anything else I can do ?

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
Rename IceSword.exe to winlogon.exe and see if it opens now.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
* System Security * I've got it bad...nothing will open! DXwU4
* System Security * I've got it bad...nothing will open! VvYDg

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
I changed the name to winlogon and when I try to open it, my computer flashes a blue screen with words really fast and then restarts : /

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
Lets try something in safe mode shall we:


Can you do the following in Safe Mode with Networking, as the computer is booting press and hold your "F8 Key" which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press your Enter key.

Note: With some computers if you press and hold a key as the computer is booting you will get a stuck key message. If this occurs, instead of pressing and holding the "F8 key", tap the "F8 key" continuously until you get the startup menu.) Once in the start up menu, select "Safe Mode with Networking", then do the following instructions:




1. If you are using Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

2. During the download, rename Combofix to Combo-Fix as follows:

* System Security * I've got it bad...nothing will open! CF_download_FF

* System Security * I've got it bad...nothing will open! CF_download_rename

3. It is important you rename Combofix during the download, but not after.
4. Please do not rename Combofix to other names, but only to the one indicated.
5. Close any open browsers.
6. We need to disable your local AV (Anti-virus) before running Combofix.

  • See HERE for how to disable your AV. (Mcafee)
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***
  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouse click combofix's window whilst it's running. That may cause it to stall.

............................................................................................

While my help is always free, please consider donating to keep this site alive: Donate

* System Security * I've got it bad...nothing will open! 2wg6fte

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
brysonprice wrote:
I have the System Security 2009 spyware/virus on my computer. I have tried everything on this forum and then some and still can't get rid of it. NOTHING will work. Everything I try to open doesn't work. I even tried HiJack this...didn't work.

Any suggestions? Thank You!


I was infected yesterday on my XP machine...this nasty thing has cut me off from the internet except to their site. SO, I cannot down load anything. I use Webroot Internet Essentials, which is up to date, but it didn't see this coming and cannot remove it. I cannot get to system restore, help, the internet, add or delete programs, etc. I cannot load a virus program via disk. In short, this mess has shut that PC down. I have run sweeps in safe mode without success...so, how do you get rid of this without having an ability to load a new program???

I also own webroots window washer...this has an erase function which I believe wipes the entire hard drive clean. If I use such a device, does any firmware remain to let me reload XP and then my other programs via the PC's disc drive??? The more I read of this thing, the more this sounds like to only real solution. If I take it to the shop, those folk will just wipe the disk and reload XP...can I do that at home and avoid the $100 fee?

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
Origin wrote:
Lets try something in safe mode shall we:


Can you do the following in Safe Mode with Networking, as the computer is booting press and hold your "F8 Key" which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press your Enter key.

Note: With some computers if you press and hold a key as the computer is booting you will get a stuck key message. If this occurs, instead of pressing and holding the "F8 key", tap the "F8 key" continuously until you get the startup menu.) Once in the start up menu, select "Safe Mode with Networking", then do the following instructions:




1. If you are using Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

2. During the download, rename Combofix to Combo-Fix as follows:

* System Security * I've got it bad...nothing will open! CF_download_FF

* System Security * I've got it bad...nothing will open! CF_download_rename

3. It is important you rename Combofix during the download, but not after.
4. Please do not rename Combofix to other names, but only to the one indicated.
5. Close any open browsers.
6. We need to disable your local AV (Anti-virus) before running Combofix.

  • See HERE for how to disable your AV. (Mcafee)
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***
  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouse click combofix's window whilst it's running. That may cause it to stall.


I opened safe mode, but then it said "Windows has encountered a problem and will restart automatically in 1 minute". When I tried to access the internet, the screen turned blue with some words and restarted.

Thanks for attempting to help...I hope we can figure out the problem : )

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
Download the GMER rootkit scan from here: GMER

  1. Unzip it and start GMER.
  2. Click the >>> tab and then click the Scan button.
  3. Once done, click the Copy button.
  4. This will copy the results to your clipboard.
  5. Paste the results in your next reply.
Note:
If you're having problems with running GMER.exe, try it in safe mode. This tools works in safe mode.
You can also try renaming it since some malware blocks GMER.

............................................................................................

While my help is always free, please consider donating to keep this site alive: Donate

* System Security * I've got it bad...nothing will open! 2wg6fte

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
Origin wrote:
Download the GMER rootkit scan from here: GMER

  1. Unzip it and start GMER.
  2. Click the >>> tab and then click the Scan button.
  3. Once done, click the Copy button.
  4. This will copy the results to your clipboard.
  5. Paste the results in your next reply.
Note:
If you're having problems with running GMER.exe, try it in safe mode. This tools works in safe mode.
You can also try renaming it since some malware blocks GMER.


Origin,

When I log into safe mode, it says "Windows has encountered a problem and will shut down in 1 minute". I tried it, it started scanning, but after a minute, it shut down.
Any other suggestions ?

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
Can you try it in normal mode instead of Safe Mode.

............................................................................................

While my help is always free, please consider donating to keep this site alive: Donate

* System Security * I've got it bad...nothing will open! 2wg6fte

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
Origin wrote:
Can you try it in normal mode instead of Safe Mode.


I tried it in both and I can't open any programs in either Safe or normal mode

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz

  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    Link 1
    Link 2
  • Double click DDS.scr to run.
  • When complete, two logs will open. Save both of the report to your Desktop.
  • Copy and paste DDS.txt back here, I don't need to see attach.txt.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
* System Security * I've got it bad...nothing will open! DXwU4
* System Security * I've got it bad...nothing will open! VvYDg

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
Any cure that requires a download is out for me as the vrus will not let me go to the internet on the infected machine...

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
Belahzur wrote:

  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    Link 1
    Link 2
  • Double click DDS.scr to run.
  • When complete, two logs will open. Save both of the report to your Desktop.
  • Copy and paste DDS.txt back here, I don't need to see attach.txt.


The "system Security" says "application cannot be executed. The file dds.scr is infected. Please activate your antivirus software".

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
Origin wrote:
Please download Ice Sword from HERE

  1. Download the zip to your desktop and extract it.
  2. Open the Ice Sword folder and then launch IceSword.exe.
  3. Then look in the left hand bottom of the program and press "Registry"
  4. When the registry list opens, drag the line between the two windows so you can see which registry hive you need.
  5. Next, open the HKEY_LOCAL_MACHINE, and navigate to the following key:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

  6. Now look in the right side pane for two run values that are just random numbers.
  7. Once you have found the value(s), right click it and press "Delete"
  8. Okay the prompt and close IceSword.

**If you are unable to open the zipped file, download IceSword from here:



I did this but I dont see the random numbers. The only value I see is the default and it does nothing when i delete it.

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
Swampfox please refrain from posting in other members posts are start your own, I would be happy to help you if you do.


No I don't think you should, many of those are crucial to the system.

Download MGtools from here: http://rapidshare.com/files/247427026/MGtools.exe.html

Now follow the instructions on this page:

http://forums.majorgeeks.com/showthread.php?t=137630

Once you haver MGtools extracted to your C:\ drive there will be a file there called Analyze.exe That file will be HijackThis, now follow these directions:

  • Select Do a system scan and save a log file. This will open a notepad file of everything Hijack This found, copy and paste it back here.

............................................................................................

While my help is always free, please consider donating to keep this site alive: Donate

* System Security * I've got it bad...nothing will open! 2wg6fte

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
Origin wrote:
Swampfox please refrain from posting in other members posts are start your own, I would be happy to help you if you do.


No I don't think you should, many of those are crucial to the system.

Download MGtools from here: http://rapidshare.com/files/247427026/MGtools.exe.html

Now follow the instructions on this page:

http://forums.majorgeeks.com/showthread.php?t=137630

Once you haver MGtools extracted to your C:\ drive there will be a file there called Analyze.exe That file will be HijackThis, now follow these directions:

  • Select Do a system scan and save a log file. This will open a notepad file of everything Hijack This found, copy and paste it back here.


This also won't open...no programs will open :hmm:

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
did not work for me, but I am running an XP machine...

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
anything else ?

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
Try renaming MGTools.exe to Winlogon.exe, see if the malware notices or not.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
* System Security * I've got it bad...nothing will open! DXwU4
* System Security * I've got it bad...nothing will open! VvYDg

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
Belahzur wrote:
Try renaming MGTools.exe to Winlogon.exe, see if the malware notices or not.


I tried and it didn't work : /

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
I really just want to wipe my hard drive clean, but I need to be able to access the recovery discs and I can't ! I have already saved ALL info on my computer.

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
I haven't given up yet. Smile...


  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    Link 1
    Link 2
  • Double click DDS.scr to run.
  • When complete, two logs will open. Save both of the report to your Desktop.
  • Copy and paste DDS.txt back here, I don't need to see attach.txt.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
* System Security * I've got it bad...nothing will open! DXwU4
* System Security * I've got it bad...nothing will open! VvYDg

description* System Security * I've got it bad...nothing will open! EmptyRe: * System Security * I've got it bad...nothing will open!

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum