Winantivruspro2006 infection-- Is it actually gone now?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Stvn, Jan 17, 2007.

  1. Stvn

    Stvn Private E-2

    Hi Guys!!

    Thanks very much for this forum. I’ve tried to follow your instructions to the letter, but my apologies in advance if my inexperience causes me to incorrectly apply a step. Recently I’ve removed malware using smitfraudfix, but the “winantiviruspro2006freeinstall” pop-up was a remaining pest. I found your site and ran through all the steps. The Results are attached.

    The “winantiviruspro2006freeinstall” pop-up seems to have gone away, but I would appreciate an expert opinion of my systems hygiene, as logs seem to say that not all suspect files removed!

    Spybot gave these two warnings:

    Microsoft.WindowsSecurityCenter.AntiVirusDisableNotify (HKEY_LOCAL_MACHINE_\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify!=dword:0)

    Microsoft.WindowsSecurityCenter.FirewallDisableNotify (HKEY_LOCAL_MACHINE_\SOFTWARE\Microsoft\Security Center\ FirewallDisableNotify!=dword:0)

    I’m running McAfee, so (hopefully wisely) I’ve ignored them as per http://forums.spybot.info/showthread.php?t=9850

    Counterspy: Found “WildTangent” adware. This seems to be (somewhat contentiously) considered harmless- it’s a Dell PC so it probably came with it.- should I tell CounterSpy to remove it? “Orf” from the Wild Tangent company gave a spirited defence & removal instructions on this forum http://forums.winamp.com/showthread.php?threadid=74109 .

    One question: Should the PC remain in “normal start-up mode” or should it be in the “selective start-up” mode for normal use?

    Thanks again-- next i'll work through the protection information.

    Steven.
     

    Attached Files:

  2. Stvn

    Stvn Private E-2

    winantivirus2006 removal--Is it actually all gone now?

    Second set of logs!
     

    Attached Files:

    Last edited by a moderator: Jan 17, 2007
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You still have some problems to fix!

    First Run this ViewpointKiller to remove Viewpoint Media software.

    Now goto Add/Remove prorgams and uninstall this old Sun Jav version: Java 2 Runtime Environment, SE v1.4.2_03


    Now I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    How are things working now?
     
  4. Stvn

    Stvn Private E-2

    Thanks for the quick reply!

    I've completed step 1

    ViewpointKiller gave the following result

    Viewpoint Media Player NO
    Viewpoint Manager NO
    Viewpoint Toolbar NO
    You're clean!

    The process.exe info link is no longer available however.

    First SmitFraudFix log is attached. I'm about to progress to step 2.
     

    Attached Files:

  5. Stvn

    Stvn Private E-2

    Step 2

    Here's the new SmitfraudFix file...
     

    Attached Files:

  6. Stvn

    Stvn Private E-2

    ...and here's the 3 other new logs.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please goto Add/Remove Programs and uninstall the below:
    Search Assist
    System Alert Popup
    If you do not find these or they will not uninstall, make sure to tell me.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NI.UWA6P_0001_N91M1807] "C:\documents and settings\vic\application data\winantiviruspro2006freeinstall[1].exe" -nag
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\documents and settings\vic\application data\winantiviruspro2006freeinstall[1].exe
    C:\Program Files\Video ActiveX Object\pmsngr.exe

    Now run Ccleaner .

    Now reboot in normal mode
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now locate the below folder and delete it if found:
    C:\Program Files\Video ActiveX Object

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. Stvn

    Stvn Private E-2

    Thanks for continued support!

    I'm out of town till Monday so can't run latest fixes immediately, but will do so as soom as I return. Just letting you know so you don't think i'm being ungrateful:)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Just don't wait too long! Attach the logs when finished.
     
  10. Stvn

    Stvn Private E-2

    Hi, back into the battle!

    "Search assist" successfully ininstalled. Shortly after a window appearing saying that "Google has blocked an attempt by a program to access the internet" (window disappeared before I could note exact wording)

    "System Alert Popup" attempt to uninstall gave an error message- "An error occured while trying to remove System Alert Popup. It may have aready been uninstalled. Would you like to remove System Alert Popup from the Add or Remove Programs list?" I said yes to this.

    Unable to locate the above files.

    Still unable to find the above file after reboot.


    PC seems to be functioning OK so far.

    Thanks:)
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall:
    C:\Documents and Settings\Vic\Local Settings\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  12. Stvn

    Stvn Private E-2

    Thanks Chaslang!

    completed all instructions, except...
    ...as those folders didn't seem to exist anymore. I assume this is no problem.

    And a few final questions...

    1. Is it better to set Windows to “Hide hidden, system files & folders” for normal PC use?

    2. Should “MSConfig Startup Mode” be set to “normal” or “selective startup” for normal PC use?

    3. How often should CCleaner be run?

    4. How often should the Spybot scan be run?

    Thank you.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not a problem! But normally they are left behind by the uninstall.



    My personal preference is to never hide anything. Why let malware have a hiding place? If you don't feel comfortable in allowing system files and others to show because you or someone else may delete them by mistake , then hide them again but remember that this does allow malware to hide too.

    Normal Startup!

    Both of these depend on how much surfing and downloading, installing/uninstalling etc you and other users of the PC do. If you are just doing average amounts of activities like mentioned, twice a month is sufficient. If you are a download freek ;) , weekly would be best.
     
    Last edited: Jan 25, 2007
  14. Stvn

    Stvn Private E-2

    Chaslang,

    Many many many thanks for your assistance. I'm extremely grateful for your rapid, clear and detailed advice- especially your insistance on a proper logging proceedure. You guys are doing amazing work here against the forces of evil. The computer I fixed was recently purchased by a friend... I've learnt a lot, and will give her a stern lecture!

    Thanks again for taking the time to deal with this.

    Regards,

    Steven.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Happy I could help and teach at the same time. ;)

    Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds