Norton 2006 keeps detecting winfixer and deleting, but seems to somehow still download sysprotect to computer. Symantecs instructions for deleting Winfixer indicate removal of multiple registry entries which NONE are in my registry. I'm usually fairly good t these things but have to admit I'm stumped on this one. Here's the HijackThis logfile. Any help greatly appreciated. Thanks, Robert
Logfile of HijackThis v1.99.1
Scan saved at 10:32:39 AM, on 6/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Double-click VundoFix.exe to run it. * Put a check next to Run VundoFix as a task. * You will receive a message saying vundofix will close and re-open in a minute or less. Click OK * When VundoFix re-opens,Click Scan for Vundo button. * Once the scan is complete, Right Click inside the listbox (white box) and click add more files * Copy&Paste the 2 entries below into the top 2 boxes
o C:\WINDOWS\system32\kbdjlm.dll o C:\WINDOWS\system32\mljgd.dll
* Click Add Files and Click Close Window * Click the Remove Vundo button. * You will receive a prompt asking if you want to remove the files, click YES * Once you click yes, your desktop will go blank as it starts removing Vundo. * When completed, it will prompt that it will shutdown your computer, click OK. * Turn your computer back on. * Please post the contents of C:\vundofix.txt and a new HiJackThis log.
C:\WINDOWS\system32\dgjlm.bak1 C:\WINDOWS\system32\dgjlm.bak2 C:\WINDOWS\system32\dgjlm.tmp C:\WINDOWS\system32\dgjlm.ini C:\WINDOWS\system32\dgjlm.ini2 C:\WINDOWS\system32\mljgd.dll C:\WINDOWS\system32\dgjlm.ini2 C:\WINDOWS\system32\dgjlm.bak2 C:\WINDOWS\system32\dgjlm.tmp C:\WINDOWS\system32\dgjlm.ini C:\WINDOWS\system32\dgjlm.ini2 C:\WINDOWS\system32\mljgd.dll Attempting to delete C:\WINDOWS\system32\mljgd.dll C:\WINDOWS\system32\mljgd.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\dgjlm.ini C:\WINDOWS\system32\dgjlm.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\dgjlm.bak1 C:\WINDOWS\system32\dgjlm.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\dgjlm.bak2 C:\WINDOWS\system32\dgjlm.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\dgjlm.ini2 C:\WINDOWS\system32\dgjlm.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\dgjlm.tmp C:\WINDOWS\system32\dgjlm.tmp Has been deleted!
Attempting to delete C:\WINDOWS\system32\kbdjlm.dll C:\WINDOWS\system32\kbdjlm.dll Has been deleted!
Performing Repairs to the registry. Done!
Logfile of HijackThis v1.99.1 Scan saved at 10:26:14 PM, on 6/25/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Your Java application is out of date.
Click start-->control panel-->add/remove programs
Scroll down the list and locate each instance of Java. Click
Remove. When the uninstallation completes, reboot the computer.
1. Click the Update Now line. When the update completes, please reboot the computer into
Safe mode.
2. Once in safe mode, open Ewido and click the "Scanner" button on the top line.
3. Click the "Complete System Scan" line to begin the scan.
4. When the scan is complete, click the "Save Report" button to save the report.
5. Click the "Scanner" button on the top to return to the results.
6. Click the "Set All Elements to" Recommended Action.
7. Click the "Apply all actions" button.
8. Click on the "Reports" Icon at the top.
9. Click on the report that was generated today to see the results on the right side.
10. Highlight the results on the right side and copy and paste them into Notepad. Save it to your Desktop to include in your next reply.
Next, please run a complete system scan using your on board Norton Antivirus software. Allow the software to remove whatever it finds.
Next, please run HijackThis again and put a check in the box next to these entries that may still exist:
Close all windows except for HijackThis then click
Fix Checked.
Locate and delete the following file indicated in
Bold text:
C:\WINDOWS\system32\
lanoxmp4.dll
Reboot back into your normal
Windows user mode.
Please run HijackThis again and post back a new HijackThis log along with the log from your Ewido scan. Also, please indicate how the computer is now performing for you and if you are having any other issues. Thanks!
Note that when Ewido quarantined items I recieved a message something to the effect that one of the items could not be individually quarantined as it was embedded in Java and did I want to quarantine the whole of that part of Java, to which I answered YES. My apologies for not having the wherewithall at the time to copy and past the exact message but thought I would mention it. All other instruction procedures performed flawlessly. Computer seems to be running much better for the very limited time I've had to use it. I will not have an opportunity to put it thru its paces for another 12-16 hours from now but will report back at that time.
Here is one of the logs you requested, I will include the other in the following post.
HKLM\SOFTWARE\Classes\CLSID\{98CC5E5F-7877-CB9D-3D33-989DA81B39DA} -> Adware.CoolWebSearch : No action taken. HKLM\SOFTWARE\Classes\CLSID\{C35AADB0-FE0C-8B29-3DF2-80B00335B70D} -> Adware.CoolWebSearch : No action taken. HKLM\SOFTWARE\Classes\AppID\{4F5E5D72-C915-4f3b-908B-527D064B0FAA} -> Adware.SysProtect : No action taken. HKLM\SOFTWARE\Classes\CLSID\{EF130E77-0A34-4365-BFB7-218FD3DDCD5F} -> Adware.SysProtect : No action taken. HKLM\SOFTWARE\Classes\Interface\{02946FD1-2D99-46E6-A790-3A089714EDD9} -> Adware.SysProtect : No action taken. HKLM\SOFTWARE\Classes\Interface\{A6E398B2-A288-4D76-B0D0-8F153D14B66E} -> Adware.SysProtect : No action taken. HKLM\SOFTWARE\Classes\Interface\{C88B2356-A6FE-41EC-B0FB-41F2C82C867E} -> Adware.SysProtect : No action taken. HKLM\SOFTWARE\Classes\TypeLib\{7EACF70B-302F-4049-AC68-2D62EB43E473} -> Adware.SysProtect : No action taken. HKLM\SOFTWARE\Classes\TypeLib\{FB42F450-C8B1-4799-99F1-87FA9CA92AB9} -> Adware.SysProtect : No action taken. HKLM\SOFTWARE\SysProtect -> Adware.SysProtect : No action taken. HKU\S-1-5-21-1957994488-115176313-682003330-1003\Software\SysProtect -> Adware.SysProtect : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.10\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.11\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.12\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.13\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.14\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.15\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.16\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.17\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.18\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.19\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.1\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.1\USYP_0001_N76M2004NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.20\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.21\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.22\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.2\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.2\USYP_0001_N76M2004NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.3\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.4\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.5\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.5\USYP_0001_N76M2004NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.6\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.6\USYP_0001_N76M2004NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.7\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.8\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.9\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\Downloaded Program Files\USYP_0001_N76M2004NetInstaller.exe -> Downloader.Small : No action taken. C:\WINDOWS\system32\MyDailyHoroscope17307.dll -> Dropper.Small.nj : No action taken. C:\WINDOWS\Downloaded Program Files\USYP_0001_N73M0704NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.f : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWA6P_0001_N822M1605NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.j : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UWA6P_0001_N822M1605NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.j : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.3\UWA6P_0001_N822M1605NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.j : No action taken. C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N822M1605NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.j : No action taken. C:\Documents and Settings\Robert\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-3f8f4c-7d51a44f.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : No action taken. C:\Documents and Settings\Robert\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-50c9a229-654f7bdd.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : No action taken. C:\Documents and Settings\Robert\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-5c0bdf13-4029f70e.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : No action taken. C:\Documents and Settings\Robert\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-5d989a67-62203896.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : No action taken. C:\Documents and Settings\Robert\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-6d181bc9-57596e86.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : No action taken. C:\Documents and Settings\Robert\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-71c172b1-1df8ad50.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : No action taken. C:\Documents and Settings\Robert\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-789d877d-6782b116.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : No action taken. C:\Documents and Settings\Robert\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv413.jar-3148796b-1ab0ebc3.zip/Dummy.class -> Not-A-Virus.Exploit.ByteVerify : No action taken. C:\Documents and Settings\Robert\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv422.jar-7450fc95-12771149.zip/Dummy.class -> Not-A-Virus.Exploit.ByteVerify : No action taken. C:\Documents and Settings\Robert\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv515.jar-664ae3ae-4108f783.zip/Dummy.class -> Not-A-Virus.Exploit.ByteVerify : No action taken. C:\Documents and Settings\Robert\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv57.jar-23f97ed6-7b3f2e25.zip/Dummy.class -> Not-A-Virus.Exploit.ByteVerify : No action taken. C:\Documents and Settings\Guest\Cookies\guest@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : No action taken. C:\Documents and Settings\Guest\Cookies\guest@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : No action taken. C:\Documents and Settings\Robert\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\proc.jar-55d8654d-1c23a2ff.zip/MainApp.class -> Trojan.ClassLoader.f : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.10\USYP_0001_N69M1703NetInstaller.exe -> Trojan.Fakealert : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.11\USYP_0001_N69M1703NetInstaller.exe -> Trojan.Fakealert : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.12\USYP_0001_N69M1703NetInstaller.exe -> Trojan.Fakealert : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.13\USYP_0001_N69M1703NetInstaller.exe -> Trojan.Fakealert : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.14\USYP_0001_N69M1703NetInstaller.exe -> Trojan.Fakealert : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.15\USYP_0001_N69M1703NetInstaller.exe -> Trojan.Fakealert : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.1\USYP_0001_N69M1703NetInstaller.exe -> Trojan.Fakealert : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWFX6_0001_N69M0903NetInstaller.exe -> Trojan.Fakealert : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.2\USYP_0001_N69M1703NetInstaller.exe -> Trojan.Fakealert : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UWFX6_0001_N69M0903NetInstaller.exe -> Trojan.Fakealert : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.3\USYP_0001_N69M1703NetInstaller.exe -> Trojan.Fakealert : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.4\USYP_0001_N69M1703NetInstaller.exe -> Trojan.Fakealert : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.5\USYP_0001_N69M1703NetInstaller.exe -> Trojan.Fakealert : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.6\USYP_0001_N69M1703NetInstaller.exe -> Trojan.Fakealert : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.7\USYP_0001_N69M1703NetInstaller.exe -> Trojan.Fakealert : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.8\USYP_0001_N69M1703NetInstaller.exe -> Trojan.Fakealert : No action taken. C:\WINDOWS\Downloaded Program Files\CONFLICT.9\USYP_0001_N69M1703NetInstaller.exe -> Trojan.Fakealert : No action taken. C:\WINDOWS\Downloaded Program Files\USYP_0001_N69M1703NetInstaller.exe -> Trojan.Fakealert : No action taken. C:\WINDOWS\Downloaded Program Files\UWAS6_0001_N69M0903NetInstaller.exe -> Trojan.Fakealert : No action taken. C:\WINDOWS\Downloaded Program Files\UWFX6_0001_N69M0903NetInstaller.exe -> Trojan.Fakealert : No action taken. C:\Documents and Settings\Robert\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\ok.class-377e0ae3-53fc9780.class -> Trojan.Nocheat : No action taken.
Logfile of HijackThis v1.99.1
Scan saved at 1:34:20 AM, on 6/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Did you run Ewido in safe mode? The CCleaner will remove your Java junk for you.
Download
CCleaner. Double click on the set up file and allow it to install to the default location. At the Cclean setup screen & Install options Uncheck the Add Ccleaner Yahoo Tool bar unless you want it.
Run CCleaner
Before first use, check under Options, "Advanced", and ensure "Only delete files in Windows Temp folder older than 48 hours" is unchecked.
Then open it and select the items you wish to clean up.
In the Windows Tab:
I recommend cleaning all entries in the "Internet Explorer" section except Cookies.
Clean all the entries in the "Windows Explorer" section
Clean all entries in the "System" section
Clean all entries in the "Advanced" section.
In the Applications Tab:
Clean all except cookies in the Firefox/Mozilla section if you use it.
Clean all in the Opera section if you use it.
Clean Sun Java in the Internet Section if you have it.
Clean any others that you choose.
Then click the "Run Cleaner" button. When finished, close the application.
Please perform this online scan:
F-Secure Online Scanner Next Generation Beta 1. Click on the link "
F-Secure Online Scanner Next Generation Beta".
2. You may receive an alert on the address bar at this point to install the ActiveX control.
3. Click on that alert and then Click
Insall ActiveX component.
4. Read the license agreement and click "
Accept".
5. Click "
Full System Scan" to download the scanning components and begin scan and cleaning.
6. When done click "Show report" and copy/paste its contents into your next reply.
Yes, ewido was run in safe mode. New instructions completed. Computer seems to be running fine. No signs of Winfixer or Sysprotect. Web browsing has returned to normal functioning ie Internet Explorer operating as normal. F-secure report attached. Thanks, Robert
Scanning Report
Monday, June 26, 2006 17:41:36 - 19:01:57
Computer name: ROBERTS-DELL Scanning type: Scan system for viruses, rootkits, spyware Target: C:\
OK, just for good measure, download and run
CWShredder Please launch the executable and then click "
Check for Update"
Download and install any updates.
Now, close any open windows except for CWShredder and then click
"
Fix ->"
You'll see three lines starting with "Restoring" to let you know the
scan is finished (It should take about a minute to run), then click
"
Next ->"
update your on board Norton Antivirus software.
Do Not Scan Yet.
Please
reboot the computer into
Safe mode,
run a complete system scan and allow the software to remove what it finds.
Reboot back into your normal Windows user mode and post back a new HijackThis log. Thanks!
All instructions performed. New HijackThis log below. Thanks
Logfile of HijackThis v1.99.1 Scan saved at 11:03:37 PM, on 6/27/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
1972vet
3305 Posts
294
0
Posted June 25th, 2006 22:00
Scroll down the list to locate the program SysProtect Free and click "Remove".
When the uninstallation completes, reboot the computer.
Please download VundoFix.exe to your desktop.
* Put a check next to Run VundoFix as a task.
* You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
* When VundoFix re-opens,Click Scan for Vundo button.
* Once the scan is complete, Right Click inside the listbox (white box) and click add more files
* Copy&Paste the 2 entries below into the top 2 boxes
o C:\WINDOWS\system32\kbdjlm.dll
o C:\WINDOWS\system32\mljgd.dll
* Click Add Files and Click Close Window
* Click the Remove Vundo button.
* You will receive a prompt asking if you want to remove the files, click YES
* Once you click yes, your desktop will go blank as it starts removing Vundo.
* When completed, it will prompt that it will shutdown your computer, click OK.
* Turn your computer back on.
* Please post the contents of C:\vundofix.txt and a new HiJackThis log.