WinAntivirusPro has invaded.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by wonderpants, Jul 4, 2006.

  1. wonderpants

    wonderpants Private E-2

    Hello,

    I've been having a huge problem with hijacks recently, and I was hoping you might have some advice. I've gone through everything in "READ & RUN ME FIRST." My results are attached. Thanks!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the directions in step 7 of the READ & RUN ME exactly and attach a HijackThis log.

    Now run the below procedure and attach the newfiles.txt log.

     
  3. wonderpants

    wonderpants Private E-2

    Here you go:
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see you have had some of these problems for almost a month.

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of gebcy.dll once and then click the kill button. After you have killed all of the gebcy.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below two DLLs:
    ljjijkk.dll


    Next double click on explorer.exe and again click once on each instance of gebcy.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below two DLLs:
    ljjijkk.dll

    Now just exit Process Explorer.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\DOCUME~1\COMPY3~1\MYDOCU~1\WNSXS~1\MHTA~1.EXE
    C:\PROGRA~1\COMMON~1\CROSOF~1.NET\javaw.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
    R3 - URLSearchHook: (no name) - {395D63FA-F33C-81B3-4CC8-D3BFA9FC80B1} - C:\WINDOWS\system32\dlstjp.dll (file missing)
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O4 - HKCU\..\Run: [Flmjl] C:\DOCUME~1\COMPY3~1\MYDOCU~1\WNSXS~1\MHTA~1.EXE
    O4 - HKCU\..\Run: [Arur] "C:\PROGRA~1\COMMON~1\CROSOF~1.NET\javaw.exe" -vt ndrv
    O20 - AppInit_DLLs: C:\WINDOWS\system32\ntvdm.dll




    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    del %windir%\temp\win*.*
    exit


    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\Documents and Settings\Compy 386\My Documents\WNSXS~1\MHTA~1.EXE
    C:\Program Files\Common Files\CROSOF~1.NET\javaw.exe
    C:\WINDOWS\system32\ntvdm.dll
    C:\WINDOWS\SYSTEM32\gebcy.dll
    C:\WINDOWS\SYSTEM32\ljjijkk.dll
    C:\WINDOWS\SYSTEM32\ycbeg.ini
    C:\WINDOWS\SYSTEM32\ycbeg.ini2


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot, delete all files in the below folders (Windows will have 2 or 3 in use and you will not be able to delete them - just work aroun them)
    C:\Documents and Settings\Compy 386\Local Settings\TEMP
    C:\Windows\Temp

    Now attach a new HJT log and tell me how the steps went.
    Make sure you tell me how things are working now!
     
    Last edited: Jul 11, 2006
  5. wonderpants

    wonderpants Private E-2

    Okay, I did all the stuff I was told with relatively few problems, although I did get the following message:

    -------------------------------------------------------------------------
    An unexpected error has occurred at procedure: modBackup_MakeBackup(sItem=O20 - AppInit_DLLs: C:\WINDOWS\system32\ntvdm.dll)
    Error #5 - Invalid procedure call or argument

    Please email me at merijn@spywareinfo.com, reporting the following:
    * What you were trying to fix when the error occurred, if applicable
    * How you can reproduce the error
    * A complete HijackThis scan log, if possible

    Windows version: Windows NT 5.01.2600
    MSIE version: 6.0.2900.2180
    HijackThis version: 1.99.1

    This message has been copied to your clipboard.
    Click OK to continue the rest of the scan.

    -------------------------------------------------------------------------

    This popped up when I closed that process in Process Explorer.
    The other thing was, while I was in the dos prompt, it told me:

    "Could Not Find C:\WINDOWS\temp\win*.*"

    I don't think this was a problem, because I didn't have anything in C:\WINDOWS\temp at the last step when I went to clear it out.

    Lastly, according to the HijackThis log, I still have a gebcy process.
    I haven't gotten any of the popups I used to get, but I'd get them infrequently anyway since I usually use Firefox, and I only just rebooted after fixing things.

    Thanks for the help, though. I really appreciate it.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay your active infections are gone. Just have HijackThis fix the below lines and then attach a new HJT log:


    O2 - BHO: (no name) - {26B063C4-9AFC-43B9-B3F7-CA80BA2A4106} - C:\WINDOWS\system32\gebcy.dll (file missing)
    O2 - BHO: (no name) - {395D63FA-F33C-81B3-4CC8-D3BFA9FC80B1} - C:\WINDOWS\system32\dlstjp.dll (file missing)
    O20 - Winlogon Notify: winbug32 - winbug32.dll (file missing)

    Let me know if everything is running OK now.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds