Here is a copy of my HijackThis log. I am getting both the winfixer as well as other "download this registry cleaner, spyware cleaner" pop-ups.
Thanks!
Logfile of HijackThis v1.99.1
Scan saved at 8:22:27 PM, on 11/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
My name is dobhar and I will be looking over your log. Please give me some time to go look it over and I will post back as soon as possible.
If you have any questions please post back as a reply to this Thread\Topic and I will be advised by email so I can return and help you. Do not start another Thread\Topic.
Please note that I am working on 4 logs ahead of yours so I may not get to posting a fix until tomorrow but I will try my best to get something to you tonight.
Lets' get to it...
_________________________________________________________________________________
Please print out or copy these instructions\tutorials to Notepad as the internet will not be (while in Safe Mode) availble to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes. ________________________________________________________________________________
Step 2. ========== Please download
Ewido Security Suite from
http://www.ewido.net/en/download/
(Note: As this is a trial version, after the 14 day trial period has expired Ewido will lose some functionality with it. Ewido will then will work as an On-Demand program, make sure to check for updates regularly).
- Install Ewido
- When installing the program, under "
Additonal Options" uncheck...
*
Install background guard *
Install scan via context menu - Launch ewido, there should now be an icon on your desktop, double-click it.
- The program will now open to the main screen.
- When you run ewido for the first time, you MAY get a warning "
Database could not be found!". Click OK. We will fix this in a moment.
- You will need to update ewido to the latest definition files:
* On the left hand side of the main screen click "
Update".
* Then click on "
Start Update".
- The update will start and a progress bar will show the updates being installed.
(Note: the status bar at the bottom will display "Update successful")
- Close Ewido.
(Note: If you are having problems with the updater, you can manually update ewido from http://www.ewido.net/en/download/updates/)
Step 3. ========== Please download
VundoFix.exe from
http://www.atribune.org/downloads/VundoFix.exe to your desktop.
- Double-click
VundoFix.exe to extract the files...This will create a
VundoFix folder on your desktop.
- After the files are extracted, please reboot your computer into Safe Mode.
Step 4. ========== - Reboot computer into "
Safe Mode" Using the
F8 method:
- As soon as the
BIOS is loaded begin
tapping the F8 key until the
Boot Menu appears
- Use the arrow keys to select the
Safe Mode menu item
(Note: For additional help in booting into Safe Mode, see the following site http://www.pchell.com/support/safemode.shtml)
Step 5. ========== We need to make sure all Hidden Files are showing so please:
* Open "
My Computer" then click on "
Tools" and from the drop down menu select "
Folder Options".
* Select the "
View" tab.
* Under the "
Hidden files and folders" heading SELECT "
Show hidden files and folders".
* UNCHECK the "
Hide file extensions for known types option".
* UNCHECK the "
Hide protected operating system files (recommended) option".
* Click "
Yes" to confirm.
* Click "
OK"
Step 6. ========== - Open the
VundoFix folder on your Desktop
- Double-click on
KillVundo.bat to run it
- You will first be presented with a warning. It should look like this:
VundoFix V2.15 by Atri By using VundoFix you agree that you are doing so at your own risk Press enter to continue....
- At this point press
enter one time.
- Next you will see:
Please Type in the filepath as instructed by the forum staff and then press enter:
-At this point please type the following file path
(Note: make sure to enter it exactly as below!):
C:\WINDOWS\system32\awvuv.dll
- Press
Enter to continue with the fix.
- Next you will see:
Please type in the second filepath as instructed by the forum staff then press enter:
- At this point please type the following file path
(Note: make sure to enter it exactly as below!):
C:\WINDOWS\system32\vuvwa.*
- Press
Enter to continue with the fix.
- The fix will run then
HijackThis will open...
-
Select\check the following entries below,
Double-check to make sure that only these entries are checked...
- Click the "
Fix checked" button...
- After you have fixed these items, close
HijackThis - Press
Enter to exit the VundoFix program then
manually reboot your computer.
- Once your machine reboots, reboot
BACK into "
Safe Mode" and continue with the instructions below.
Step 7. ========== Delete the following
File(s) in
BOLD only.
(Note: Don't be concern if can't find but advise if not found)
File(s)...
(Files specified without a full path will be lcoated in C:\WINDOWS\ or C:\WINDOWS\System32\)
wmediaplayer.exe = Delete This File
Step 8. ========== We now need to cleanup all the
Temp, Temorary Internet Files, Recycle Bin, etc... - Start the
CCleaner program
- Get into "
Options" => Select "
Advanced" => Deselect\uncheck "
Only delete files in Windows Temp folders older than 48 hours"
- We are only going to work with the "Cleaner" section.
(Note: Do not use the "Issues" section)
- click on the
Run Cleaner button in the lower right-hand corner
- After complete close program
- Empty Recycle Bin
Step 9. ========== - start
Ewido Security Suite - Click on "
Scanner.
(Note: Do not start any programs or open any windows while Ewido is scanning)
- Click on "
Complete System Scan", the scan will now begin.
- While the scan is in progress you will be promted to clean files, click "
OK".
- When it asks if you want to clean the first file, put a checkmark in the lower left corner of the box that says "
Perform action on all infections", then choose "
Clean" and click "
OK".
- Once the scan has completed, there will be a button located at the bottom of the screen named "
Save Report".
- Click "
Save Report".
- Now save the report .txt file to your desktop.
- Close Ewido.
Step 10. ========== - Reboot your COmputer into "Normal Mode"
- Run Panda's online virus scan from
http://www.pandasoftware.com/products/activescan.htm - Once you are on the Panda site click the "
Scan your PC" button
- A new window will open...click the big "
Check Now" button
- Enter your
Country - Enter your
State/Province - Enter your
Email - Select either
Home User or Company - Click the big
Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan
(Note: It will take a couple minutes)
- Click on "
Local Disks" to start the scan
- When the scan completes, if anything malicious is detected, click the
See Report button, then
Save Report and save it to a convenient location.
- Post Panda scan results in your next reply
Step 11. ========== - Post a fresh new HijackTHis log
- Post the Vundofix.txt log
- Post back Ewido scan log
- Post the Panda ActiveScan results
I am not sure if it worked - the things I deleted in step 6 were still in my HiJackThis log (the new one). Also, the panda scan picked up a spyware. When I was in safemode was I supposed to select administrator (I picked my name since that is what I usually log on with)? Also, for step 7, the file was not found. Please advise what I should do next!
Here are my logs:
Logfile of HijackThis v1.99.1 Scan saved at 2:36:18 AM, on 11/6/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
No problem...the VundoFix did it's job...we now just have to cleanup the leftovers. The "spyware" that Panda found was in one of your "System Restore" points. No worry's there as one of the steps in my {All Clean} speech is to clean them all out. Just don't use System restore until we clean out all the old ones as you most likely will get re-infected again.
I also have a recommendation...I see you have
Viewpoint installed...I recommend that you uninstall this program. Viewpoint components are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting "Disable auto‑updating for the Viewpoint Manager" ‑‑ the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.
To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.
Step 1. ========== Remove programs only if you decided to accept my recommendations. If not then skip Step 1 and continue on. We need to uninstall some programs
(if found in list) using "
Add or Remove Programs" in the Control Panel:
- Get into
Control Panel.
- Double-click "
Add or Remove Programs".
- Look in the
Currently installed programs box for each program listed below and if it is there:
- Click on it to select it.
- Click "
Change/Remove" (or "
Change") button.
- If you are prompted to confirm the removal of the program, click "
Yes"
Viewpoint Manager
Step 2. ========== We need to make sure all Hidden Files are showing so please:
* Open "
My Computer" then click on "
Tools" and from the drop down menu select "
Folder Options".
* Select the "
View" tab.
* Under the "
Hidden files and folders" heading SELECT "
Show hidden files and folders".
* UNCHECK the "
Hide file extensions for known types option".
* UNCHECK the "
Hide protected operating system files (recommended) option".
* Click "
Yes" to confirm.
* Click "
OK"
Step 3. ========== - Download
Killbox (by Option^Explicit) from
here to your Desktop
(Note: Do NOT use this yet!)
Step 4. ========== - Close all Windows and programs
- Run
HijackThis...
-
Select\check the following entries,
Double-check to make sure that only these entries are checked...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com O2 - BHO: MSEvents Object - {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - C:\WINDOWS\system32\awvuv.dll (file missing) O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe =>>>
Only if you decided to uninstall the Program
O4 - HKLM\..\Run: [Windows Media Player] wmediaplayer.exe O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\RunServices: [Windows Media Player] wmediaplayer.exe O16 - DPF: {B2FCED61-570E-11D3-B160-00A0C9E70E84} (OmniForm Form Control) - https://www4.lsac.org/LSACD_XMLWebServices/Http/OIFActiveX/ofmctl.cab O20 - Winlogon Notify: awvuv - C:\WINDOWS\system32\awvuv.dll (file missing) O23 - Service: CWShredder Service - Unknown owner - C:\Documents and Settings\Samantha\Local Settings\Temporary Internet Files\Content.IE5\8X6B012F\cwshredder[1].exe (file missing)
- Click the "
Fix checked" button...
- Close HijackThis
Step 5. ========== Delete the following
Folder(s) in
BOLD only.
(Note: Don't be concern if can't find but advise if not found)
Folder(s)... C:\Program Files\
AWS <<<= Delete This Folder
C:\Program Files\
Viewpoint <<<= Delete This Folder =>>>
Only if you decided to uninstall the Program
Step 6. ========== We now need to cleanup all the
Temp, Temorary Internet Files, Recycle Bin, etc... - Start the
CCleaner program
- Get into "
Options" => Select "
Advanced" => Deselect\uncheck "
Only delete files in Windows Temp folders older than 48 hours"
- We are only going to work with the "Cleaner" section.
(Note: Do not use the "Issues" section)
- click on the
Run Cleaner button in the lower right-hand corner
- After complete close program
- Make sure the recycle Bin is empty
Step 7. ========== We are going to delete the rest of the files that need to be removed using "Killbox" (by Option^Explicit).
- Navigate to your Desktop and double-click on
Killbox.exe to start the program.
- Select\check the
Delete on Reboot option.
- copy the file name(s) and path(s) below in BOLD to the field labeled "
Full Path of File to Delete"
C:\WINDOWS\System32\wmediaplayer.exe <<<= If you can't find it in this path try
C:\WINDOWS\wmediaplayer.exe
- Click the button that looks like a red circle with a white X in it..."
Delete File" button
- Click "
Yes" at the
Delete on Reboot prompt - Click "
Yes" at the
Reboot Now prompt.
- If you get a "
PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.
Step 7. ========== - Post back a fresh new HijackThis log
I still cannot find the wmediaplayer.exe file. The closest thing I can find is wmplayer.exe in a windows media player folder in C:\Program Files. There is nothing close to it in WINDOWS or WINDOWS\System32.
Also, there was a program called viewpoint media player. I only deleted the viewpoint manager - should I delete this one as well?
Without doing step 7 here is my log so far:
Logfile of HijackThis v1.99.1 Scan saved at 3:57:30 PM, on 11/6/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
I was curious about this line: O4 - Startup: Scheduler.lnk = C:\Program Files\SpyCatcher\Scheduler daemon.exe...I had installed spycatcher, but I know I removed the program. Why would I still have this?
When this is all said and done, I was wondering if you could suggest an anti-virus (and possibly an anti-spam program as well). I currently have Norton Antivirus 2003, but my subscription is about up so I was thinking of buying a new one instead of renewing my old one.
If you do NOT use the Viewpoint Media Player then I would uninstall it.
Is SpyCather listed in your "
Add or Remove Programs? If so then uninstall it and use HijackTHis to remove the O4 Entry if still listed. If not then just use HijackThis and remove that 04 Entry. Also delete the
C:\Program Files\SpyCatcher folder
I'm pretty sure it's gone but let's be on the safe side and try searching one more time using the following guidline...Windows XP's search feature is a little different. When you click on "Strong>All files and folders" on the left pane, click on the "
More advanced options" at the bottom. Make sure that "
Search system folders, Search hidden files and folders, and
Search subfolders are checked".
If you still cannot find the file then lets download a great free "File Search" program called "
Agent Ransack". I actually run the "Pro" version of the same program but the free works great.
If you still cannot find the file then let's try one more scanner...if it does not find the "Nasty" then I would say we are clear.
_________________________________________________________
Step 1. ========== - Downland and Install Agent Ransack from
here - After installig the program please start it
- In the
File Name: window enter
wmediaplayer.exe - In the
Look In: window take the default "
C:\" but if you have more than one Hard Drive then select "
Local Hard Drives" from the drop-down menu.
- Click "
Start Search" button to start the search
- If you find the file delete it
- If nothing found then go on to Step 2
Step 2. ========== - Download Stinger.exe from
here to your Desktop
- Double-Click the
Stinger.exe file on your Desktop to start the scan
- Do not start any programs or open any windows while the scan runs
- Advise if anything found
Step 3. ========== - Post back results of Stinger scan
- Post back a fresh new HJT log
As far as an Antivirus goes everybody has an opinion...I am a Symantec AV and a NOD32 AV fan. Others will say McAfee AV. Are you having or have you had any problems with Norton? I have 3 PC's going and Symantec AV 2005 is on 2 of them and on my main PC, which is what I'm using to write this I use NOD32. I also hear good things about Kaspersky AV. I good Free AV is AVG 7.0 from Grisoft.
First off...Congrats you have a clean log...:) Nice work...
Don't worry about the HTML error...I get them as well. You just re-submit and it posts.
The best approach to being protected is having layered protection...Antivirus, Online virus scanning to supplement AV (Like Panda & Trend Micro), Firewall, Antispyware (Like CounterSpy, SpySweeper, and MS Antispyware) and Spyware scanners (like Ad-Aware and Spybot S&D)
_______________________________________________
I can find nothing bad listed so I'm also posting my standard
{All Clean} speech below. It has good information and some recommended tools (Recommended by all who deal with Spyware Nasties). Tools like SpywareBlaster =>
SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. Definitley recommended!!
____________________________________
The last thing I need you to do is to reset your "Hidden files and folders". System files are hidden for a reason and we don't want to have them openly available and susceptible to accidental deletion.
Open "My Computer".
Click on "Tools" and from the drop down menu select "Folder Options".
Select the "View" tab.
Under the Hidden files and folders heading UNSELECT "Show Hidden files and folders".
CHECK the Hide protected operating system files (recommended) option".
Click "Yes" to confirm.
Click "OK".
_____________________________________
Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and reenable system restore to make sure there are no infected files found in a restore point. You can find instructions on how to enable and reenable system restore here:
Renable system restore with instructions from tutorial above
Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on theSecurity tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.
Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. See this link for a listing of some online & their stand-alone antivirus programs: Virus, Spyware, and Malware Protection and Removal Resources
Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly. For a tutorial on Firewalls and a listing of some available ones see the link below: Understanding and Using Firewalls
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software. A tutorial on installing & using this product can be found here: Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers
Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot. A tutorial on installing & using this product can be found here: Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer
Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. A tutorial on installing & using this product can be found here: Using SpywareBlaster to protect your computer from Spyware and Malware
Install IE-SPYAD - IE-SPYAD adds a list of sites and domains associated with advertisers, marketers, and crapware pushers to the Restricted sites zone of Internet Explorer. A tutorial on installing & using IE-SPYAD can be found here: Using IE-Spyad to enhance your privacy and security
Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.
Logfile of HijackThis v1.99.1 Scan saved at 5:59:19 PM, on 11/6/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
For some reason I couldn't find the copy of the stinger log anywhere. It says in the program "Scan initiated on Sun Nov 06 17:19:55 2005 / Number of clean files: 140473". It doesn't say anything about any viruses, trojans or variants. The other two search methods did not come up with anything either.
I don't have any problems with Norton, but I wasn't sure if there was anything better out there especially when it comes to handling both viruses and spyware. The 2003 version is only an antivirus one (is it even worth it to have anything more than say, the free AdAdware program?)
Thanks for all of your help. Hopefully the log above looks successful!
(I got this message while trying to post: "Your post has been changed because invalid HTML was found in the message body. The invalid HTML has been removed. Please review the message and submit the message when you are satisfied." So I am not sure what was changed above.)
dobhar
2 Intern
•
1132 Posts
198
0
Posted November 5th, 2005 21:00
My name is dobhar and I will be looking over your log. Please give me some time to go look it over and I will post back as soon as possible.
If you have any questions please post back as a reply to this Thread\Topic and I will be advised by email so I can return and help you. Do not start another Thread\Topic.
Please note that I am working on 4 logs ahead of yours so I may not get to posting a fix until tomorrow but I will try my best to get something to you tonight.
Thank You,