TechSpot

WinAntiSpyware2006 ,Popup Virus

By slopjaw
Sep 19, 2006
  1. I have a compaq presario 8000 series pc with this WinAntiSpyware2006, WinAntiViruspro2006 pop ups going crazy, i was reading on this forum how to fix it,but it seems pretty techical for me to do ,my question is if i use the system recovery program which reformats the hard drive and restores everything , will that take care of this problem ? i don't think theres any other easy fix out there is there ?
     
  2. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Yes, reformatting will certainly get rid of the nasties. Just make sure you disconnect from the net and don`t reconnect until you have installed your firewall software.

    Alternatively, you might want to try fixing your problem without a reformat.

    If you do, go HERE and follow the instructions exactly. Post fresh HJT and Ewido logs as attachments into this thread, only after doing the above.

    Obviously it`s completely up to you how you wish to proceed.

    Regards Howard :)

    This thread is for the use of slopjaw only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  3. slopjaw

    slopjaw TS Rookie Topic Starter Posts: 22

    Nasty Pop-ups

    Went through every step that was listed , now done and getting a new one wanting to install sys. doctor 2006, also got a big blue blank pop-up and the little one with a notice that your pc has errors in its registerey. Let me ask this , It dosen't say to be off line or on line except for i believe one place ,i went off line whenever i could to do some of the scans, but like the 4 tools i had to refer back to get directions , its alot to remember, i hope i've done the log attachment ok, i not very expeirenced with these forms and things,this pc i'm working on belongs to a friend of mine and i'm trying to help her out, I told her the worst thing to do is let the kids on there and to start downloading all kinds of junk ,so she ask me to clean it up and this is what it turns out to be, what a headache !!!!!!!!! I really want to thank you for your help.
     
  4. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

    Turn off system restore.(XP/ME only) See how here.> http://www.bleepingcomputer.com/forums/tutorial56.html

    Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how here.> http://www.bleepingcomputer.com/forums/tutorial61.html

    In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how here.> http://www.bleepingcomputer.com/forums/tutorial62.html

    Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

    Click on the processes tab and end process for(if there).

    ALCXMNTR.EXE
    IM-svr.EXE

    Close task manager.

    Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

    R3 - Default URLSearchHook is missing

    O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)

    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

    O4 - HKLM\..\Run: [IMprocess] C:\Documents and Settings\Owner\My Documents\download\IM-svr.EXE

    O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe

    O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSYYYYYYYYUS

    O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)

    O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)

    O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)

    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)

    O16 - DPF: {6AA85413-165C-4200-8154-71166077B22E} - http://scripts.downloadv3.com/binaries/IA/sysiasvc32_EN_XP.cab

    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab

    O16 - DPF: {8B3B8135-9DAA-40E7-8941-962795F9C1CB} - http://scripts.downloadv3.com/binaries/IA/syswbsvc32_EN_XP.cab

    O16 - DPF: {B2B0AEDF-7CDF-4792-BB67-7654AD1E1B13} - http://scripts.downloadv3.com/binaries/IA/sysinetsvc32_EN_XP.cab

    O16 - DPF: {BE5A7132-329F-4319-B781-2A83BFE51534} - http://akamai.downloadv3.com/binaries/P2EClient/EGAUTH_1045_EN_XP.cab

    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.21.13/ttinst.cab

    O16 - DPF: {D8B94E9A-A34B-4253-BF48-C7CB7F2CFDB0} - http://scripts.downloadv3.com/binaries/P2EClient/EGAUTH_1046_EN_XP.cab

    Click on the fix checked button.

    Close HJT.

    Locate and delete the following bold files and/or directories(if there).

    C:\Documents and Settings\Owner\My Documents\download\IM-svr.EXE

    ALCXMNTR.EXE Search the system for this file and delete all instances of it.

    Reboot into normal mode, turn system restore back on and rehide your protected OS files.

    Post fresh HJT and Ewido logs.


    Regards Howard :)

    This thread is for the use of slopjaw only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  5. slopjaw

    slopjaw TS Rookie Topic Starter Posts: 22

    Nasty Pop-ups

    OK, I followed the last set of directions you gave me ,very easy, so when i was done i rebooted the pc and surfed around to see what would happen, things are getting better but were just not there yet. 1st. i have a hijackthis shortcut on my desktop ,is that ok ? Now while i'm online it seems to happen the first 5 to 10 minutes and than it seems to clear up. What i get is a full screen white or blue window that is blank,in the top title bar ,one said http://www.winantispyware.com-spyware detected-Microsoft Internet Explorer provided by comcast, 2nd said www.errorsafe.com-error detected -microsoft ie provided by comcast,3rd said www.winantivirus.com- error detected-microsoft ie provided by comcast. these pop-up roll up behind the main window, show up on the task bar, so when i close main window there it is and i close it.At least now when i close it ,another one dos'nt come right back. This is leaps and bounds better than before,also the pc i'm working on is usually hooked up to comcast innernet service, while i've got it hooked into my service witch is adelphia ,i don't know if that would be a problem or not. One or two things you told me to search for was not there so i moved on and completed the task. Man you guys are sharp !!!!!!! What should i do next ? Again thank you very much. Kenny
     
  6. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Your HJT log is clean.

    However, let HJT fix these entries in normal mode.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

    Then, do the following.

    Click start/run and type services.msc into the run box and press the enter key.

    When the window appears, maximise it. Double click on the following services(if there) and select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

    Messenger. Note: This has nothing to do with MSN messenger etc.

    Close the services window.

    Reboot your computer and let me know the outcome.

    Regards Howard :)

    This thread is for the use of slopjaw only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  7. slopjaw

    slopjaw TS Rookie Topic Starter Posts: 22

    Nasty Pop-ups

    ok surfed around for awhile ,got the same 3 full screen pop-ups only this time they did'nt come up as fast as before, the last one came up when i came back to this site to post and they did'nt have the comcast part on them ,getting closer. messenger was off also.
     
  8. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Your HJT log is clean as a whistle.

    Download the Ccleaner programme from HERE.

    Make sure all browser windows are closed.

    Run the programme and make sure all boxes are ticked under the Windows and Applications tabs. Run the programme several times until nothing is found. Click the Issues button, then click the scan for issues button. Click the fix selected issues button and click fix all selected issues. Repeat this until no more issues are found.

    Let me know the outcome please.

    Regards Howard :)
     
  9. slopjaw

    slopjaw TS Rookie Topic Starter Posts: 22

    Nasty Pop-ups

    Ran Cclaaner several times ,jumped back online same thing although i got a couple other pop-ups that were wed site related. but the same big 3 are still there without the comcast extension. So close but yet so far away !!!!!
     
  10. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Turn off system restore.(XP/ME only) See how here.> http://www.bleepingcomputer.com/forums/tutorial56.html

    Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how here.> http://www.bleepingcomputer.com/forums/tutorial61.html

    In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how here.> http://www.bleepingcomputer.com/forums/tutorial62.html


    Go to c:\documents and settings\your username\local settings\ and delete as many files as you can in the temp folder. Do this for all users.

    Run IE and click on the tools menu, select internet options and then click the delete cookies button. Click the delete files button and tick the box that says delete all off line content. Click ok.

    Close IE.

    Reboot into normal mode, turn system restore back on and rehide your protected OS files.


    Download and install Firefox from HERE. Stop using IE except for Windows updates and the odd site that doesn`t support Firefox.

    Let me know if this helps.

    Regards Howard :)

    This thread is for the use of slopjaw only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  11. slopjaw

    slopjaw TS Rookie Topic Starter Posts: 22

    Nasty Pop-ups

    ok ,went into all temp folders, took care of all of that. jumped back online to download firefox and when i was going to the site i got the pop-up back, only this time it was back to normal ,not blank anymore, it had the ad in it for antispam and all that,clicked it off than the other smaller one came up, it was like back in the beginning, its strange after i deleted all those temp folders it came back ? I downloaded firefox and hav'nt got any pop-up at all . I went ahead and ran hijack again to get another log file for you, i'm getting sick !! What next ?
     
  12. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Your HJT log is clean.

    Please post a fresh Ewido log.

    Obviously Firefox is stopping the popups, but like you I would like to get to the bottom of this.

    Regards Howard :)
     
  13. slopjaw

    slopjaw TS Rookie Topic Starter Posts: 22

    Nasty Pop-ups

    Ran Ewido, found 3 infections, i put them in quarantine
     
  14. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Their just tracking cookies and nothing to be unduly concerned about.

    Download and install Spyware Blaster from HERE. Make sure it`s fully updated, then click enable all protection. This will help to block a lot of bad cookies and websites from both IE and Firefox. This application doesn`t run in the background and so doesn`t use system resources.

    Regards Howard :)
     
  15. slopjaw

    slopjaw TS Rookie Topic Starter Posts: 22

    Nasty Pop-ups

    Whats next?
     
  16. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Look in this directory and delete winantivirus if there.

    C:\PROGRAM FILES\COMMON FILES\WinAntiVirus Pro 2006

    Regards Howard :)
     
  17. slopjaw

    slopjaw TS Rookie Topic Starter Posts: 22

    Nasty Pop-ups

    Not there my friend ? I'm going to retire for the eveing ,its about midnight and i gotta work in the morning so i'll check back tommorow eveing , give it some more thought and when i get home i'll play around with IE and se what happens ,thanks again
     
  18. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Download the Autoruns programme from HERE.

    Attach the Autoruns log.

    Regards Howard :)

    This thread is for the use of slopjaw only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  19. slopjaw

    slopjaw TS Rookie Topic Starter Posts: 22

    Nasty Pop-ups

    Hope i did this right, is this the right log file ?
     
  20. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    The only file I can find that should be deleted is this one.

    C:\WINDOWS\System32\DOLPHI~1.SCR

    Click start/search/all files and folders/more advanced options, make sure search system folders/search hidden files and folders/search subfolders are all ticked.

    Type winantivirus in the all or part of the filename box and click search. Delete any winantivirus entries found.

    Let me know the outcome.

    Regards Howard :)
     
  21. slopjaw

    slopjaw TS Rookie Topic Starter Posts: 22

    Nasty Pop-ups

    i could notfind the system 32 file or any intance of it, the search turned up nothing but a couple temp files witch looked related to this web site. While i was waiting on your last post i deleted some more junk that was on the pc, so maybe thats where it went, let me ask this, the hard drive in this pc has a partition witch is the system recovrery files , they don't give you a system restore disk with these things anymore, if i would reformatt what are the chances the pop up virus would be in those system restore files and i might still have the problem ?
     
  22. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    I doubt the popup files would be in the restore partition.

    However, before you resort to a format, I`d like you to try a couple of things.

    First, I`d like you to update your Java install.

    Go to add remove programmes in your control panel
    Search in the list for all previous installed versions of Java. (J2SE Runtime Environment)
    It should have next icon next to it. Select it and click Remove.

    Then Download and install the newest version from HERE.

    http://www.java.com/en/download/manual.jsp

    Once you`ve done that, follow these instructions.

    Download Brute Force Uninstaller http://www.merijn.org/files/bfu.zip and unzip it to it’s own folder (c:\BFU).

    Right click on this link http://metallica.geekstogo.com/EGDACCESS.bfu and choose 'Save As' (or 'Save Target As) in order to download EGDACCESS Remover. Save it in the folder you made earlier (c:\BFU).

    Start the Brute Force Uninstaller by double clicking BFU.exe

    In the scriptline to execute copy and paste c:\bfu\EGDACCESS.bfu
    Press execute and let it do its job.

    Wait for the complete script execution box to popup and press OK.
    Press exit to terminate the BFU program.

    Please let me know the outcome.

    Regards Howard :)
     
  23. slopjaw

    slopjaw TS Rookie Topic Starter Posts: 22

    Nasty Pop-ups

    what is the outcome suposed to be ,i confussed ?
     
  24. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    The outcome I`m looking for is an end to your popup problem.

    Regards Howard :)
     
  25. slopjaw

    slopjaw TS Rookie Topic Starter Posts: 22

    Nasty Pop-ups

    after i done all that i surfed around on about 20 sites i have bookmarked and did'nt get anything ,so i restarted the pc and what do you know there back but a little different, i got 1 for a game ,1for mp3 just for free.com and i got the little box that gives a notice that your pc has tracks of aldult sitesyuo had visited and a small white box at the same time just above the pc clock, than i click it off and get the full screen drive cleaner ppop-ut , As befor norton comes up and say a virus has been detected- drivecleaner it said C:\...\INSTALLDRIVECLEANERSTART[1].CAB. Iwas a little confussed the last time because that program really went fast and i was wondering what would happen , that stuff really runs fast. Do you have much more in your dictionary ,ha,ha :)
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...