Stupid WinFixer Popups

Discussion in 'Malware Help (A Specialist Will Reply)' started by TheGuest, Sep 10, 2005.

  1. TheGuest

    TheGuest Private E-2

    Hey everyone,
    I'm new here, recently I've been having problems with WinFixer popups. So, I was wondering if someone would please take the time to help me get rid of this problem. I've attached my HJT log. Thanks.
     

    Attached Files:

  2. TheGuest

    TheGuest Private E-2

    Can anyone please help?
     
  3. AbbySue

    AbbySue MajorGeeks Administrator

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  4. TheGuest

    TheGuest Private E-2

    AbbySue,
    I've attached my new log after following the instructions you provided.
     

    Attached Files:

  5. AbbySue

    AbbySue MajorGeeks Administrator

    Good morning!:)

    I looked over your log and I'm pretty sure you will need to use 1, possibly 2 additional utilities in order to remove a couple things. As I have not personally used these utilities I'm not comfortable at this point in telling you to use them so I have contacted chas for input/assistance. One of us will get back to you ASAP.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's start by downloading two tools we will need:

    - Process Explorer 9.2

    - Pocket KillBox

    Extract them to there own folder somewhere that you will be able to locate them later.

    We need to stop using MSconfig to control startups so that we can find any other possible problems. So run msconfig again and select Normal Startup. Then continue with the below steps.

    Reboot in Safe Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of awvtr.dll once and then click the kill button. After you have killed all of the awvtr.dll's under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of awvtr.dll and kill it.

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\system32\awvtr.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O20 - Winlogon Notify: awvtr - C:\WINDOWS\system32\awvtr.dll


    Copy the bold text below to notepad. Save it as fixVundo.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.


    C:\WINDOWS\SYSTEM32\rtvwa.ini
    C:\WINDOWS\SYSTEM32\rtvwa.ini2
    C:\WINDOWS\SYSTEM32\rtvwa.bak
    C:\WINDOWS\SYSTEM32\rtvwa.bak1
    C:\WINDOWS\SYSTEM32\rtvwa.bak2
    C:\WINDOWS\SYSTEM32\rtvwa.tmp
    C:\WINDOWS\system32\awvtr.dll

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot post a new HJT log.
     
  7. TheGuest

    TheGuest Private E-2

    Hey chaslang,
    I've posted my hjt log.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not do what I asked with MSconfig! Select Normal Startup!

    Your log should be from normal boot mode not safe mode. Post a new one! But it looks like the Virtumundo problem is fixed. How is it working?
     
  9. TheGuest

    TheGuest Private E-2

    It is in normal startup, but I'll run another log. I think the problem is fixed, no more WinFixer or any other ads popping up anymore.
     
  10. TheGuest

    TheGuest Private E-2

    Here's another log.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now you are in normal startup! Your previous log was still showing msconfig controlling startups.

    Okay! Now your log is clean! To help keep it that way, make sure you see the below:

    How to Protect yourself from malware!
     
  12. TheGuest

    TheGuest Private E-2

    The popups are back. I don't know what the problem is, it was fine last night, but tonight I keep on getting WinFixer popups. Should we start again?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Was System Restore off (check to make sure)? That's the first step in the READ ME FIRST.

    Post a new HJT log?
     
  14. TheGuest

    TheGuest Private E-2

    System Restore was off and is still off. I've attached a new log.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They are back because the Virtumundo infection came back now with new files. Were you surfing anywhere in particular after we last got this fixed? I would sure like to know where these are coming from.


    Please print these instructions out for use in Safe Mode with no Networking.

    Please download VundoFix.exe to your desktop.
    • Double-click VundoFix.exe to extract the files
    • This will create a VundoFix folder on your desktop.
    • After the files are extracted, please reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.
    • Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat
    • You will first be presented with a warning and a list of forums to seek help at. Iit should look like this
    • At this point press enter one time.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):

    C:\WINDOWS\system32\ssttt.dll

    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):

    C:\WINDOWS\system32\tttss.*

    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • The fix will run then HijackThis will open.
    • In HiJackThis, please place a check next to the following items and click FIX CHECKED:
    O2 - BHO: MSEvents Object - {52B1DFC7-AAFC-4362-B103-868B0683C697} - C:\WINDOWS\system32\ssttt.dll
    O20 - Winlogon Notify: ssttt - C:\WINDOWS\system32\ssttt.dll



    • After you have fixed these items, close Hijackthis and Press any key to Force a reboot of your computer.
    • Pressing any key will cause a "Blue Screen of Death" this is normal, do not worry!
    • Once your machine reboots please attach a new HJT log from normal mode.
     
  16. TheGuest

    TheGuest Private E-2

    Thanks a lot for your help chaslang. I've attached another log.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your Vundo problem is now gone. How are things working?
     
  18. TheGuest

    TheGuest Private E-2

    Things are working fine now. Thanks so much for taking the time to help me. Much appreciated.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds