WinAntiVirus Popup Driving Me Crazy!

Discussion in 'Malware Help (A Specialist Will Reply)' started by LA_Cyn, Jul 13, 2006.

  1. LA_Cyn

    LA_Cyn Private E-2

    Hello & HELP, :eek:

    I have a pop-up that is persistent! It's WinAntiVirus. It started popping up shortly after I switched to SBC/Yahoo DSL & my computer immediately started running very slow. When I use their IE browser WAV pops up shortly after I open it. I had a tech come & $150+ later he couldn't get rid of it! After that I did several methods to try & remove it myself based on post I'd seen on forums.

    First I used "Process Explorer" but the help posted said to look for a file with the name: playwms.dll or it spelled backwards. I had no files with that name but did have 3 named: awtqn.dll with numbers in front & behind them (5 awtqn.dll+0x23...) I didn't remove those because I didn't know if they were the WinAntiVirus. I next tried "FixVundo". It said no Vundo Trojans were found. I next tried VirtumundoBeGone with FixVundo & AVG Free came up saying it detected a virus: Win32/PEPatch (which I put in the vault). There was no info on it in the encyclopedia.

    I ran a HijackThis log that I will be posting it as soon as the Major gives me the OK. Any help would be greatly appreciated. BTW, I've stopped using IE & am using Mozilla which blocks it somewhat. It still tries to come up but all I see is a blank screen with WinAntiVirus in the header.

    Thanx in Advance
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    What help posted are you referring too? Are you talking about some other site or here on MGs? There are maybe a thousand or more file names that have already been used by Vundo. And that number increases daily.

    No HijackThis logs are accepted until the below steps are complete.


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. LA_Cyn

    LA_Cyn Private E-2

    Thanks for the fast reply.

    I spent all morning doing everything you said in the "RUN & READ ME FIRST Before Asking for Support" section. Here I am several hours later ready to post my 3 logs.

    The "Process Explorer" I mentioned came from another forum. My tech sent me a link to try & get rid of the pop-up (since he couldn't do it & I didn't want to have to pay him again ). Problem was, the post was 2 years old. I found your site by searching for the specific problem. He even uninstalled ZoneAlarm because he said the firewall on SP2 was all the protection I needed.

    I want to say how much I appreciate the step-by-step instructions & the simple manner in which you explain things. I usually feel intimidated when I visit a "tech" site because most times they talk over my head. :confused: But your site made me feel very confident in doing the steps without fearing I'd mess something up. Bottom line, you didn't make me feel like a 'dummy.'

    Thanks Again
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Find another tech! He has know idea what he is doing or talking about. Since he could not remove the malware and sent you to an old link (and why didn't he just use the link), this indicates he know very little about malware. Saying that the Windows firewall is all you need shows incompetence.

    We try hard to keep it simple, but it is not easy since it can require complicated procedures to remove malware. They key is to follow steps exactly without skipping anything and follow them in the order written. It often pays to read thru all steps before starting and then ask questions if you don't understand something. It is better to do this before starting the procedure because typically it is important to run the procedure with any interruption or side tracking to do anything else. Even the simple act of running another process or opening a browser window can render a procedure ineffective.

    If you were running notepad ( C:\WINDOWS\SYSTEM32\notepad.exe ) please tell me and do not have it running anymore while obtaining HJT logs. Malware often does this and we must know the difference between what you are doing and malware.

    I need to get a little more info before we continue with cleaning the below steps will run very quickly.


    Download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Now run the below procedure and attach the runkeys.txt log.
    Now run the below procedure and attach the newfiles.txt log.
     
  5. LA_Cyn

    LA_Cyn Private E-2

    Would that be the notepad running on the taskbar (that my tech put there)? If so, I'm not sure how to get it off or stop it from running.

    Thanx
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you saying it is always loading each time you reboot your PC? You really must get a new Tech.

    Did you complete ALL the steps I gave you in message number 4??? if so, where are the logs! If not, what are you waiting for?

    Let's get a Startup List with Hijack This.

    Generating Startup Lists with HijackThis
    • Run HijackThis, click Open the Misc Tools section
    • Put a check in the List also minor sections (full) check box.
    • Now click the Generate StartupList Log button.
    • This will create a file named startuplist.txt in the same folder that HijackThis is installed into.
    • Also a notepad file will open with this startuplist in it.
    • Attach the startuplist.txt file to your next message.
     
  7. LA_Cyn

    LA_Cyn Private E-2

    My tech put a lot of additional stuff on the taskbar at startup.

    When I click "Restore Microsoft Original Hosts File" using HOSTER it says "ERROR: Cannot create file C:\WINDOWS\system32\DRIVERS\ETC\hosts" I uninstalled MS Java yesterday using the MSJVM Removal Tool from your "Protecting yourself from malware" article & installed the newest Sun Java, so I don't know if that is causing the error.

    Should I still run GetRunKey & ShowNew without having run HOSTER?

    Attached is the HijackThis startup log.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! I need those two logs.
     
  9. LA_Cyn

    LA_Cyn Private E-2

    Here are the 2 files: GetRunkey & Shownew
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run msconfig and select Normal Startup as requested in step 7 of the READ ME.

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of llqfixki.dll once and then click the kill button. After you have killed all of the llqfixki.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of llqfixki.dll and kill it. (If you do not find the dll, just continue on.)



    Now just exit Process Explorer.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1



    NOTE:
    HJT will popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    C:\WINDOWS\SYSTEM32\llqfixki.dll
    C:\WINDOWS\SYSTEM32\nqtwa.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.


    Now attach a new runkeys.txt log and a new HJT log.


    Tell me how the steps went, and also make sure you tell me how things are working now!
     
    Last edited: Jul 19, 2006
  11. LA_Cyn

    LA_Cyn Private E-2

    Attached are the new runkeys & HJT logs.
     

    Attached Files:

  12. LA_Cyn

    LA_Cyn Private E-2

    It looks like the runkeys log didn't upload. I'm trying again.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still did not attach it. Make sure you are attaching a new copy and not the same file as before. Give it a new name if necessary.

    You HJT log is clean! Are you having any other malware issues?

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!



    I will be on vacation until 7/31/06. One of the other Mods or Admins here may be able to pickup where I leave off.
     
  14. LA_Cyn

    LA_Cyn Private E-2

    Thank you for your help.

    I don't seem to be having any other malware issues currently. I will go back & do a system restore. And here is another attempt to upload my new runkeys log.
     
  15. LA_Cyn

    LA_Cyn Private E-2

    I keep getting an 'Upload Error.' It says "You have already attached this file in thread : WinAntiVirus Popup Driving Me Crazy!" no matter what I name the log.
     
  16. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Add a blank line to the end of the file, and try again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds