Annoying winantivirus2006 help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by bcasher7, Oct 13, 2006.

  1. bcasher7

    bcasher7 Private E-2

    I've gone through 3 days of trying to save you guys the trouble by following all the directions posted on this site...but I still keep getting all these spyware/antivirus pop-ups. I'm new to all of this and would really appreciate any help that one could give on how to get rid of this problem. I hope I've attatched all the proper things requested by your page!
    Thanks alot!
     

    Attached Files:

  2. bcasher7

    bcasher7 Private E-2

    Here's the rest!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. bcasher7

    bcasher7 Private E-2

    Thanks so much for the reply! Here ya go.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach the requested log from VundoFix!

    Is your copy of Ewido a paid or free trial version? If free trial then uninstall it now!

    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA} - C:\WINDOWS\system32\hknvyitc.dll (file missing)
    O2 - BHO: (no name) - {61D75B23-E2A5-0727-63D8-044BE1E59EC8} - C:\WINDOWS\system32\acrbwi.dll
    O2 - BHO: (no name) - {C831C999-116D-4866-A64E-32DD6A72F9BB} - C:\WINDOWS\system32\awtqp.dll (file missing)
    O2 - BHO: (no name) - {F0071ECC-A1A5-4386-8CA8-F1A247FDBCBB} - C:\WINDOWS\system32\ddaya.dll (file missing)
    O3 - Toolbar: (no name) - {C004DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
    O4 - HKLM\..\Run: [zvjostj.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\zvjostj.dll,khmpyrc
    O20 - Winlogon Notify: winmxw32 - winmxw32.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\system32\acrbwi.dll
    C:\WINDOWS\system32\Chip.dll
    C:\WINDOWS\system32\zvjostj.dll

    Now run Ccleaner.
    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode
    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    After reboot locate the below folders and delete if found:
    C:\Program Files\VSToolbar
    C:\Program Files\Common Files\{38AD29F3-07CA-1033-0622-050131050001}
    C:\Program Files\Common Files\{98AD29F3-07CA-1033-0622-050131050001}
    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp\
    C:\Documents and Settings\Joe Santoro\Local Settings\Temp\
    Now attach a the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. bcasher7

    bcasher7 Private E-2

    When I run Vundofix it says there is nothing found and doesn't give me an option to save a log. Everything seems to be running better now!
     

    Attached Files:

  7. bcasher7

    bcasher7 Private E-2

    Found the vudofix log!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and enable System Restore to create a new clean Restore Point.
    4. After doing the above, you should work thru the below link:
     
  9. bcasher7

    bcasher7 Private E-2

    Your awesome! Thanks alot for your help!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds