winantivirus2006

Discussion in 'Malware Help (A Specialist Will Reply)' started by kingpinriz, Sep 18, 2006.

  1. kingpinriz

    kingpinriz Private E-2

    I know that people have already posted thread about removing this from thier cpu but i figured everyones cpu was different. I have this showing up like crazy. I think its bundled with a couple others. If anyone could please help I would greatly appreciate it. I dont even know how to back up xp. But i am halfway handy I just never worried about backing up. DOH! You can call me what you want I just want this of my cpu. I have downloaded hijack this. I havent really used it. I do however use spybot, adaware, and avast. I will also admit to tracking a reg key that said winantivirus2006 and deleted it. probly not best idea.
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    HI


    First off run these steps as WinAntiVirus is linked to the Winfixer family Virtumonde aka Trojan Vundo Removal - some people also refer to this as WinFixer

    then continue with the below steps which are designed to get you and us started on the removal of any malwre on your PC, once you have attached the requested logs the mlaware experts here can post further tailored instructions for you and your PC.


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. kingpinriz

    kingpinriz Private E-2

    thank you. I am reading this before work so as soon as i get in around 12hrs or so I will post those. I greatly appreciate it thanks
     
  4. kingpinriz

    kingpinriz Private E-2

    well i got all of the way to the panda but when downloading activex it sat at 50% and 0 sec remaining. What am i to do now? The only thing that found anything was spybot but it found wav2006 before and said fixed. I wil be back on in about 12 hrs. I can attach any logs you need then but i figured you would want them all at once. also i couldnt run bit defender. I was in safe mode with updated java. Let me know what you need and i will try again. And thanks for helping me I have a 4 year old girl she dosent need boobs in her face when she is on nick jr!!
     
  5. kingpinriz

    kingpinriz Private E-2

    Ok now ready to be helped

    I have finally got through with read and run me first. It took me a bit but I followed to a T. The only one i couldnt do is Bitdefender. I am still having winantivirus2006 and others come up hijacking browser. Here are all of my log files.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You MUST remain in one thread. I merged you back to this thread.

    You need to attach the GetRunKey log!

    You also need to run this Virtumonde aka Trojan Vundo Removal and attach the requested log.
     
    Last edited: Sep 21, 2006
  7. kingpinriz

    kingpinriz Private E-2

    sorry about that I didnt realize I will post the other logs as soon as i get home from work. About 9 central time. thanks for your help
     
  8. kingpinriz

    kingpinriz Private E-2

    ok here are the logs you requested. Vundofix found nothing and gave no log.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First install the current version of Sun Java from: Sun Java Runtime Environment

    Then uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2_03
    Viewpoint Media Player

    Also uninstall Windows Defender to avoid conflicts with eTrust PestPatrol Anti-Spyware.

    Now download two tools we will need:

    - Process Explorer


    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them
    while offline. You must exit all browsers before running the below steps and it would be best if you actually physically
    unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit
    all processes and items in your System tray.


    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen.
    Click on the Threads tab at the top.

    Once you see this screen click on each instance of ddayv.dll once and then click the kill button. After you have killed all of the ddayv.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of ddayv.dll and kill it. (If you do not find the dll, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    Is the below SearchAssitant something you configured? If not, fix it too. Otherwise skip it and continue.
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=w...L4IDp1kxE+582Q
    O2 - BHO: ADOUsefulNet Object - {22E85F2A-4A67-4835-B2C3-C575FE4EC322} - C:\WINDOWS\system32\ddayv.dll
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O20 - Winlogon Notify: ddayv - C:\WINDOWS\system32\ddayv.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if
    some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (
      or, after highlighting, right-click and choose copy):


    C:\WINDOWS\SYSTEM32\vyadd.ini2
    C:\WINDOWS\system32\ddayv.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot, also delete all files in the below folders except ones from the current date (Windows will not let you delete
    the files from the current day
    ).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Patrick\Local Settings\Temp

    Now attach a new HJT log and tell me how the steps went.

    Also attach a new log from ShowNew and a new log from GetRunKey.

    Make sure you tell me how things are working now!
     
  10. kingpinriz

    kingpinriz Private E-2

    everything went smooth due to good instructions. The only wierd thing I got was when I was deleting C:\WINDOWS\Temp I got a message saying cannot delete Perflib_Perfdata_5c4.dat. It sayed it was a Video cd movie. Also when I ran hjt i didnt see O4-HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe/auto. Everything seems to be running smooth. Now just two more questions.
    1. How do I get my icons back to normal? i can do it manually if needed.
    2. Dont laugh, well you can if you want,how do I create a restore point?
    Thank you, I owe you many times over
     

    Attached Files:

  11. kingpinriz

    kingpinriz Private E-2

    never mind on the icons:)
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still need to uninstall the below as I stated in message # 9:
    Java 2 Runtime Environment, SE v1.4.2_03
    Viewpoint Media Player
    Windows Defender

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  13. kingpinriz

    kingpinriz Private E-2

    Thank you for all of your time
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds