NotebookForums.com › Forums › Notebook Manufacturers › Dell Forums › Dell Home (Inspiron, XPS, Studio) › Need Help Removing Winantivirus Pro 2006!!! Very Hazrdous Trojan!!
New Posts  All Forums:Forum Nav:

Need Help Removing Winantivirus Pro 2006!!! Very Hazrdous Trojan!!

post #1 of 18
Thread Starter 
Hi guys. I didnt kno where else to turn to. Ive tried everything. I recently had this trojan virus call WinAntiVirusPro2006 infect my Dell M170. Its creates this annoying pop up for an advertisement and its slowing my PC down like molasses. I ran 8 different anti-adware/spyware scans including Spybot, Adaware, Spycatcher express, Vundo Fix, etc. with no success. I ran my anti-virus program Avast no success. Does anyone know a solution to getting rid of this trojan I can seem to find a solution anywhere on the web. Any and all help will be greatly appreciated. Just in case someone requests it here is my hijack this log:

Logfile of HijackThis v1.99.1
Scan saved at 1:10:44 PM, on 9/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Creative\Feature Mode Utility\CTModUtl.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpyCatcher 2006\Protector.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\UDPixel\UDPixel_en.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\SpyCatcher 2006\SpyCatcher.exe
C:\Program Files\SpyCatcher 2006\Scheduler daemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\dwwin.exe
C:\DOCUME~1\RONALD~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [CTFeatureModeUtility] C:\Program Files\Creative\Feature Mode Utility\CTModUtl.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Startup: Scheduler.lnk = C:\Program Files\SpyCatcher 2006\Scheduler daemon.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Startup: UDPixel.lnk = C:\Program Files\UDPixel\UDPixel_en.exe
O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.7) - http://gameadvisor.futuremark.com/global/msc37.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/35/...l/gtdownde.cab
O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\puresp.dll
O20 - AppInit_DLLs: interceptor.dll,c:\progra~1\google\google~1\goec62~1.dll,wbsys.dll c:\progra~1\google\google~1\goec62~1.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Unknown owner - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" -k runservice (file missing)
O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
post #2 of 18
post #3 of 18
Thread Starter 
Thanks for the feedback odious but none of that was of any help to me only to the people who posted their hijackthis log. Can anyone review mine and give me some advice or know any other alternative solution?? THANKS!!
post #4 of 18
Hi GOD OF WAR

I had the same problem last month on my XPS Gen 2, although I'm not sure if it is the exact same trojan. It was also an antivirus trojan that caused annoying pop-ups and generated a false infection warning about some fictitious virus constantly poping up. I don't remember the name of the trojan, though. It would also hijack my home page whenever I logged into the Internet so that it took me directly to this Antivirus server which was probably attempting to trick me into buying something that would clear up this issue.

I use McAfee Antivirus. At first, McAfee didn't pick this up, probably because it was so new that McAfee didn't recognize it. But after a few days of automatic updates, McAfee was finally able to recognize and clean out the trojan. My computer is now back to normal.

Maybe you should try McAfee.

Good luck,
Rayt
post #5 of 18
Ugh! My friend's laptop had this same virus about 2-3 months ago. Like you said, I tried all the free programs out there to no avail. We finally had to reformat the computer and reinstall the OS to return it to normal.
post #6 of 18
Why doesn't anyone EVER suggest System Restore. This is a guaranteed way of removing anything like this that gets installed. Just restore to the day before you "accidentally" installed this software...poof...it's gone!
post #7 of 18
post #8 of 18
Quote:
GOD_OF_WAR has exceeded their stored private messages quota and can not accept further messages until they clear some space.

hmm
post #9 of 18
Thread Starter 
Thanks for the feedback guys I really appreciate it. By searching forums all over the web I realized that this virus is practically new and alot of anti-virus programs dont know its true definition bcuz its a unique type of trojan. I will try the methods you suggested Pine Sol and will re-post the results jus in case it works and someone else wants to know hoe to get rid of the trojan. Thanks again guys!!
post #10 of 18
Quote:
Originally Posted by RushFan
Why doesn't anyone EVER suggest System Restore. This is a guaranteed way of removing anything like this that gets installed. Just restore to the day before you "accidentally" installed this software...poof...it's gone!

Yeah when I get a virus or trojan, if mcafee can't see it then I do a system restore. If that doesn't work, then I reformat.
post #11 of 18
Quote:
Originally Posted by RRF985
Yeah when I get a virus or trojan, if mcafee can't see it then I do a system restore. If that doesn't work, then I reformat.

Well, the easiest way to get around any of these problems is to not install a virus.

It's kind of an obvious solution, but for some reason, few people seem to consider it...
post #12 of 18
2nd easiest.... Ghost or Acronis True Image.
post #13 of 18
Thread Starter 
Quote:
Originally Posted by Pirx
Well, the easiest way to get around any of these problems is to not install a virus.

It's kind of an obvious solution, but for some reason, few people seem to consider it...

Huh?! Who in their right mind would install something they knew was a virus?? Im confused?
post #14 of 18
it was a joke....and system restore is not a good option for any decent virus out there imo...in fact i just disable sys restore....solving my own problems gives me a good warm feeling inside
post #15 of 18
Thread Starter 
Quote:
Originally Posted by zzpulp
it was a joke....and system restore is not a good option for any decent virus out there imo...in fact i just disable sys restore....solving my own problems gives me a good warm feeling inside
oh ok lol!! gotcha

P.S.- Anyone care to be nice enough to analyze my hijackthis file PLZ!! Thanks!!
post #16 of 18
Another good means of protection is not using IE as your browser. I'm guessing you do use IE if you had a trojan downloaded, probably by hijacking ActiveX. IE is the most risky program you can use on your computer.

Use Firefox or some other alternative browser.
post #17 of 18
HijackThis log file analyzer:
http://www.hijackthis.de

It lists information about each process in your log, along with its opinion on good, bad, or unknown. You appear to have nothing of interest.

Oh and Ranick I just noticed, I believe your signature is wrong - the resolution is 1920x1200.
post #18 of 18
Thread Starter 
Quote:
Originally Posted by ricky28269
HijackThis log file analyzer:
http://www.hijackthis.de

It lists information about each process in your log, along with its opinion on good, bad, or unknown. You appear to have nothing of interest.

Oh and Ranick I just noticed, I believe your signature is wrong - the resolution is 1920x1200.
Thanx for the input. I use firefox and opera as my web browsers depends on my mood. And guess what guys I found out how to get rid of the trojan and I hope this helps anyone else ho has it bcuz it surprisingly helped me. I realized I had an older version of spybot version d13. I uninstalled version d13, downloaded and installed version d14 and ran it. Guess what it found both instances of this trojan plus 4 others and now Im squeaky clean!! Good Luck to everyone else and thanx again for the feedback guys!!
New Posts  All Forums:Forum Nav:
  Return Home
NotebookForums.com › Forums › Notebook Manufacturers › Dell Forums › Dell Home (Inspiron, XPS, Studio) › Need Help Removing Winantivirus Pro 2006!!! Very Hazrdous Trojan!!