New here

Discussion in 'Malware Help (A Specialist Will Reply)' started by vwjobo, Jul 27, 2006.

  1. vwjobo

    vwjobo Private E-2

    well I Hoope i can find info here on how to remove this darn winantivirus pro thing
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    HI and Welcome


    I have moved your post to the malware part of the forum, in which we have a guide for you to initially follow, please do follow it closely and good luck :)


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
     
  3. vwjobo

    vwjobo Private E-2

    I ran all the steps here are my logs. I still have this darn WinAntiVirus Pro 2006 pop Up. Looked at the other post tried theres and still the same.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of psqlpwd.dll once and then click the kill button. After you have killed all of the psqlpwd.dll under winlogon click ok. (If you do not find the dll, just continue on.)



    Next double click on explorer.exe and again click once on each instance of psqlpwd.dll and kill it. (If you do not find the dll, just continue on.)



    Now just exit Process Explorer.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\Program Files\Common Files\{54CBCA5E-0724-1033-0215-060215060001}\Update.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=20065&k=
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=20065&k=
    O4 - HKLM\..\Run: [defender] C:\\dfndrad_5.exe
    O4 - HKLM\..\Run: [keyboard] C:\\kybrdad_5.exe
    O4 - HKLM\..\Run: [hxqvmzuA] C:\WINDOWS\hxqvmzuA.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O20 - Winlogon Notify: psfus - C:\WINDOWS\SYSTEM32\psqlpwd.dll



    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.


    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\Documents and Settings\Joey\Local Settings\Temp\b122.exe
    C:\Program Files\Common Files\{54CBCA5E-0724-1033-0215-060215060001}\services.dll
    C:\Program Files\Common Files\{54CBCA5E-0724-1033-0215-060215060001}\Update.exe
    C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N91M1807NetInstaller.exe
    C:\dfndrad_5.exe
    C:\kybrdad_5.exe
    C:\WINDOWS\hxqvmzuA.exe
    C:\WINDOWS\keyboard1.dat
    C:\WINDOWS\SYSTEM32\psqlpwd.dll


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now delete the below folder if found:
    C:\Program Files\Common Files\{54CBCA5E-0724-1033-0215-060215060001}

    Now attach a new HJT log and tell me how the steps went.

    Now run the below procedure and attach the runkeys.txt log.
    Now run the below procedure and attach the newfiles.txt log.
    Make sure you tell me how things are working now!
     
  5. vwjobo

    vwjobo Private E-2

    Here are my new logs the steps went fine no problems at all. Taank you very much I will let you know how this is working.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks better but I just realize you had HijackThis installed here:


    C:\Documents and Settings\Joey\My Documents\analyse\analyse.exe

    That is where we ask you not to install it. You should install to the below for possible future use:

    C:\Program Files\HijackThis\analyse.exe

    Now Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach a new runkeys.txt log and also let me know how things are working!

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  7. vwjobo

    vwjobo Private E-2

    I moved HJT sorry about that. Everything was going fine then all of a suddden Pop. The WinAntiVirus Pop-Up Agian. Here is the new log you wanted though
     

    Attached Files:

  8. vwjobo

    vwjobo Private E-2

    I also just noticed that my finger print reader will not work now I will re-download the driver for that though.
     
  9. vwjobo

    vwjobo Private E-2

    Fingerprint scanner works fine now.Updated Driver.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you still getting popups? If so do the below:

    • click Start, Run, and enter msconfig and click OK! Now select Normal Startup and OK your way out of MSconfig. Reboot if it tells you it needs to, then continue.
    • Attach a new log from ShowNew
    • Attach a new HJT log.
     
  11. vwjobo

    vwjobo Private E-2

    Yes I Am Still getting the WinAntiVirus Pro 2006 Pop-Up :(. Here are the new logs Thank you so much for all the help so far...
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now run Windows Explorer and delete all files and subfolders in the below folder of your PC. Note: Windows may have a couple files in use in this folder and may block their deletion. This is normal. Just work around those files and delete the others. Typically the ones in use are from the current date.

    C:\Documents and Settings\Joey\Local Settings\TEMP

    You still have something present I asked you to fix in a message # 4! It did not show in your log in message #7 but it shows now. Let's repeat the cleanup!



    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of psqlpwd.dllonce and then click the kill button. After you have killed all of the psqlpwd.dllunder winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of psqlpwd.dlland kill it. (If you do not find the dll, just continue on.)


    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O20 - Winlogon Notify: psfus - C:\WINDOWS\SYSTEM32\psqlpwd.dll

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.
    C:\WINDOWS\SYSTEM32\psqlpwd.dll

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now attach a new HJT log and tell me how the steps went. Also attach a new log from ShowNew!

    Make sure you tell me how things are working now!
     
    Last edited: Jul 31, 2006
  13. vwjobo

    vwjobo Private E-2

    Here are the new logs sorry I May have skipped over a step Sorry, i thought i did that step correctly. I do not see the in Process Explorer, The Pane is on the left that the files are in but when I Open them to the threads they are not there. Hope this helps out some more.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Now your log is clean again. Are you still having problems? If not, make sure you do what I gave you in message # 6. In fact, I'll just repeat it to be clear.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds