Winanti virus pro, and also sysprotect problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by krazykaz_nz, Jul 5, 2006.

  1. krazykaz_nz

    krazykaz_nz Private E-2

    Hi there, I have been thru and followed all the directions with Hijack This and spyware bot etc. And am still having problems with popups and sysprotect installing itself on my computer.

    here are the scan files that were saved from pandasoftware scan, hijack this and bitdefender

    What am I to do now? I'm at my wits end and am seriously considering formatting my computer to solve all problems. Not what I really want to do but may have to yet.

    Thank you for your time and I hope you can help?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You must go back to step 7 of the READ ME and follow the directions exactly. You did not install HijackThis properly and you will not get any backups of things we fix. Please install it as instructed to avoid any further delay in get your malware fixed. Then attach a new HJT log.

    Also run the below two very fast scans which will provide some necessary info to work up a fix for you.

    Run the below procedure and attach the runkeys.txt log.
    Now run the below procedure and attach the newfiles.txt log.
     
  3. krazykaz_nz

    krazykaz_nz Private E-2

    ok So i think i got it this time. Im sure I followed the instructions as per requested? and also have run the other programs.


    Hopefully this works this time? Thank you again.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of mlljk.dll once and then click the kill button. After you have killed all of the mlljk.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below two DLLs:
    byxvsqo.dll


    Next double click on explorer.exe and again click once on each instance of mlljk.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below two DLLs:
    byxvsqo.dll


    Now just exit Process Explorer.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.1\UWA6P_0001_N73M0604NETINSTALLER.EXE

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\PCHealth\HelpCtr\System\panels\blank.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\PCHealth\HelpCtr\System\panels\blank.htm
    O4 - HKLM\..\Run: [NI.USYP_0001_N85M2606] "C:\WINDOWS\Downloaded Program Files\CONFLICT.1\USYP_0001_N85M2606NetInstaller.exe" -nag
    O4 - HKLM\..\Run: [NI.UWA6P_0001_N73M0604] "C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWA6P_0001_N73M0604NetInstaller.exe" -nag
    O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgNZ2405.exe



    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    del %windir%\temp\win*.*
    del %windir%\g*.dll
    exit



    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\Documents and Settings\Karen Bamford\Local Settings\Application Data\a134d1ae.exe
    C:\WINDOWS\g273921.dll
    C:\WINDOWS\compstuic.dll
    c:\windows\downloaded program files\UWA6P_0001_N822M1605NetInstaller.exe
    c:\windows\downloaded program files\CONFLICT.1\UWA6P_0001_N73M0604NETINSTALLER.EXE
    C:\WINDOWS\system32\adl.exe
    c:\windows\system32\admparsel.dll
    C:\WINDOWS\system32\byxvsqo.dll
    C:\WINDOWS\SYSTEM32\compstuic.dll
    C:\WINDOWS\SYSTEM32\mlljk.dll
    C:\WINDOWS\SYSTEM32\kjllm.tmp
    C:\WINDOWS\SYSTEM32\kjllm.ini
    C:\WINDOWS\SYSTEM32\kjllm.ini2


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now attach a new HJT log and tell me how the steps went.

    Also attach a new log from ShowNew.
    Make sure you tell me how things are working now!
     
  5. krazykaz_nz

    krazykaz_nz Private E-2

    hi there, have followed your instructions once again. Had a couple of problems. when i went to start, run, cmd, and typed in del%windir%\g*.dll it said couldn't access was in use.

    Then when I went to killbox, and typed in C:\WINDOWS\g273921.dll it froze Killbox, and I had to restart, yet when I did it after restarting it worked fine.

    Now I have attached the ShowNew log and also the HJT log but after restarting and having a look at the puter, i still have the compstuic.dll on my computer. The pc-cillin virus software i have is picking it up. its coming up as ADW_DELF.BZR
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to re run everything from the previous procedure accept this:
    All the other problems are still there. You need to get killbox to work correctly and accept all the fileanames and then make sure it reboots after the last filename is entered.
     
  7. krazykaz_nz

    krazykaz_nz Private E-2

    Ok I realised what I did wrong last time with Killbox. at the end of the list i forgot to say yes to reboot, and so i just rebooted manually and it didn't actually remove anything. This time I did it correctly and I think it might be fixed? Nothing froze or anything like that so I hope you say yes its fixed.

    New showNew files and HJT files are attached for your viewing pleasure (or not so pleasure)

    Thank you so much for your time and help.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\WINDOWS\system32\clc.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {03C04564-3AB9-4106-837E-2E4160A444C9} - C:\WINDOWS\System32\mlljk.dll (file missing)
    O2 - BHO: (no name) - {062492AF-392E-479D-BF52-A7A4BCA00307} - C:\WINDOWS\compstuic.dll (file missing)
    O4 - HKCU\..\Run: [clc] C:\WINDOWS\system32\clc.exe
    O20 - Winlogon Notify: cfgmngr32 - C:\WINDOWS\g273921.dll (file missing)
    O20 - Winlogon Notify: winhoo32 - winhoo32.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\system32\clc.exe <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.
     
  9. krazykaz_nz

    krazykaz_nz Private E-2

    ok hopefully this time.

    It appears to still be running fine. Still no annoying popups, so heres hoping.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds