UNSOLVED

LA_Cyn

updated

20 years ago

L

LA_Cyn

2 Posts

0

231

July 13th, 2006 23:00

WinAntiVirus Popup Driving Me Crazy! HJT Log

Hello & HELP,

===========================================
I posted this in the wrong section here (Virus/Spyware Information & Removal). Steve & ky331 said to post it here.
===========================================

I have a pop-up that is persistent! It's WinAntiVirus. It started popping up shortly after I switched to SBC/Yahoo DSL & my computer immediately started running very slow. When I use their IE browser WAV pops up shortly after I open it. I had a tech come & he couldn't get rid of it. After that I did several methods to try & remove it myself based on post I'd seen on forums.

First I used "Process Explorer" but the help posted said to look for a file with the name: playwms.dll or it spelled backwards. I had no files with that name but did have 3 named: awtqn.dll with numbers in front & behind them (5 awtqn.dll+0x23...) I didn't remove those because I didn't know if they were the WinAntiVirus. I next tried "FixVundo". It said no Vundo Trojans were found. I next tried VirtumundoBeGone with FixVundo & AVG Free came up saying it detected a virus: Win32/PEPatch. There was no info on it in the encyclopedia. The VGB log is below also.

I ran a HijackThis log that is also below. Any help would be greatly appreciated. BTW, I've stopped using IE & am using Mozilla which blocks it somewhat. It still tries to come up but all I see is a blank screen with WinAntiVirus in the header.

Thanx in Advance

********************

[07/13/2006, 15:26:07] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Owner\Desktop\VirtumundoBeGone.exe" )
[07/13/2006, 15:26:12] - Detected System Information:
[07/13/2006, 15:26:12] - Windows Version: 5.1.2600, Service Pack 2
[07/13/2006, 15:26:12] - Current Username: Owner (Admin)
[07/13/2006, 15:26:12] - Windows is in NORMAL mode.
[07/13/2006, 15:26:12] - Searching for Browser Helper Objects:
[07/13/2006, 15:26:12] - BHO 1: {02478D38-C3F9-4EFB-9B51-7695ECA05670} (Yahoo! Toolbar Helper)
[07/13/2006, 15:26:12] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[07/13/2006, 15:26:12] - BHO 3: {378337B6-F89D-4CAB-A106-BC9886E33D10} ()
[07/13/2006, 15:26:12] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/13/2006, 15:26:12] - Checking for HKLM\...\Winlogon\Notify\awtqn
[07/13/2006, 15:26:12] - Found: HKLM\...\Winlogon\Notify\awtqn - This is probably Virtumundo.
[07/13/2006, 15:26:12] - Assigning {378337B6-F89D-4CAB-A106-BC9886E33D10} MSEvents Object
[07/13/2006, 15:26:12] - BHO list has been changed! Starting over...
[07/13/2006, 15:26:12] - BHO 1: {02478D38-C3F9-4EFB-9B51-7695ECA05670} (Yahoo! Toolbar Helper)
[07/13/2006, 15:26:12] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[07/13/2006, 15:26:12] - BHO 3: {378337B6-F89D-4CAB-A106-BC9886E33D10} (MSEvents Object)
[07/13/2006, 15:26:12] - ALERT: Found MSEvents Object!
[07/13/2006, 15:26:12] - BHO 4: {53707962-6F74-2D53-2644-206D7942484F} ()
[07/13/2006, 15:26:12] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/13/2006, 15:26:12] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[07/13/2006, 15:26:12] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[07/13/2006, 15:26:12] - BHO 5: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} (UberButton Class)
[07/13/2006, 15:26:12] - BHO 6: {65D886A2-7CA7-479B-BB95-14D1EFB7946A} (YahooTaggedBM Class)
[07/13/2006, 15:26:12] - BHO 7: {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} (SidebarAutoLaunch Class)
[07/13/2006, 15:26:12] - Finished Searching Browser Helper Objects
[07/13/2006, 15:26:12] - *** Detected MSEvents Object
[07/13/2006, 15:26:12] - Trying to remove MSEvents Object...
[07/13/2006, 15:26:13] - Terminating Process: IEXPLORE.EXE
[07/13/2006, 15:26:13] - Terminating Process: RUNDLL32.EXE
[07/13/2006, 15:26:13] - Disabling Automatic Shell Restart
[07/13/2006, 15:26:13] - Terminating Process: EXPLORER.EXE
[07/13/2006, 15:26:13] - Suspending the NT Session Manager System Service
[07/13/2006, 15:26:13] - Terminating Windows NT Logon/Logoff Manager
[07/13/2006, 15:26:14] - Re-enabling Automatic Shell Restart
[07/13/2006, 15:26:14] - File to disable: C:\WINDOWS\System32\awtqn.dll
[07/13/2006, 15:26:14] - Renaming C:\WINDOWS\System32\awtqn.dll -> C:\WINDOWS\System32\awtqn.dll.vir
[07/13/2006, 15:26:14] - File successfully renamed!
[07/13/2006, 15:26:14] - Removing HKLM\...\Browser Helper Objects\{378337B6-F89D-4CAB-A106-BC9886E33D10}
[07/13/2006, 15:26:14] - Removing HKCR\CLSID\{378337B6-F89D-4CAB-A106-BC9886E33D10}
[07/13/2006, 15:26:14] - Adding Kill Bit for ActiveX for GUID: {378337B6-F89D-4CAB-A106-BC9886E33D10}
[07/13/2006, 15:26:14] - Deleting ATLEvents/MSEvents Registry entries
[07/13/2006, 15:26:14] - Removing HKLM\...\Winlogon\Notify\awtqn
[07/13/2006, 15:26:14] - Searching for Browser Helper Objects:
[07/13/2006, 15:26:14] - BHO 1: {02478D38-C3F9-4EFB-9B51-7695ECA05670} (Yahoo! Toolbar Helper)
[07/13/2006, 15:26:14] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[07/13/2006, 15:26:14] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[07/13/2006, 15:26:14] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/13/2006, 15:26:14] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[07/13/2006, 15:26:14] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[07/13/2006, 15:26:14] - BHO 4: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} (UberButton Class)
[07/13/2006, 15:26:14] - BHO 5: {65D886A2-7CA7-479B-BB95-14D1EFB7946A} (YahooTaggedBM Class)
[07/13/2006, 15:26:14] - BHO 6: {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} (SidebarAutoLaunch Class)
[07/13/2006, 15:26:14] - Finished Searching Browser Helper Objects
[07/13/2006, 15:26:14] - Finishing up...
[07/13/2006, 15:26:14] - A restart is needed.
[07/13/2006, 15:26:14] - Automatic Reboot on STOP Error is not set. User will have to manually restart.
[07/13/2006, 15:26:25] - Attempting to Restart via STOP error (Blue Screen!)

*************************
Logfile of HijackThis v1.99.1
Scan saved at 4:03:42 PM, on 7/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http

://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =

http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http

://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

http://dsl.sbc.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL

=

http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http

://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http

://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http

://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant

= www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch

= www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =

http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http

://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

www.google.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =

wmplayer.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet

Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar -

{EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program

Files\Yahoo!\Companion\Installs\cpn1\yt.dll
N1 - Netscape 4: user_pref("browser.startup.homepage",

"http://www.cwnet.com/"); (C:\Program

Files\Netscape\Users\cmalexander\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper -

{02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program

Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -

C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A}

- C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: SidebarAutoLaunch Class -

{F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program

Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} -

C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Alexa - {3CEFF6CD-6F08-4e4d-BCCD-FF7415288C3B} -

C:\WINDOWS\System32\SHDOCVW.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88}

- C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe

/STARTUP
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows

Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH

Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program

Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common

Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org

2.0\program\quickstart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program

Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Easy-WebPrint Add To Print List -

res://C:\Program

Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print -

res://C:\Program

Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program

Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program

Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Mail to a Friend... -

http://client.alexa.com/holiday/script/actions/mailto.htm
O8 - Extra context menu item: See Related Links -

http://client.alexa.com/holiday/script/actions/related.htm
O8 - Extra context menu item: Write a Review... -

http://client.alexa.com/holiday/script/actions/review.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}

- C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\WINDOWS\System32\msjava.dll
O9 - Extra button: SBC Yahoo! Services -

{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program

Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -

C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683}

- C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine

Advantage Validation Tool) -

http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class)

- C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} -

http://www.trueswitch.com/sbc/TrueInstallSBC.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o.

- C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -

C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. -

C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe