winlogon hook and numerous others

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by yama73, Sep 10, 2006.

  1. yama73

    yama73 Private E-2

    I have read and run the "read & run first"
    spysweeper detects winlogon hook, I tried the special removal procedure. I could not boot into safe mode for the other scans I will attatch my logs in this and 1 more posts Please help
    thank you
     

    Attached Files:

  2. yama73

    yama73 Private E-2

    winlogon hook and numerous others part 2

    here are the other log files
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: winlogon hook and numerous others part 2

    Welcome to Majorgeeks!

    Did your problems start sometime recently? Perhaps sometime since Sept 1st or 3rd?
    You install the below on the 1st and then the 3rd:
    Code:
    C:\Program Files\
    POPCAP~1      Sep  1 2006              "PopCap Games"
    TRUSTY~1      Sep  3 2006              "TrustyFilesPro"
    Perhaps the are conrtibutors to your problems. You have more problems then winlogonhook. You also have Virtumonde, SmitFraud, and other misc trojan infections.

    Let's start by working on an infection in the Smitfraud family and we will move on to the others after fixing SmitFraud. It will take to steps to complete the removal of Smitfraud. Here is the first.

    Now Download SmitfraudFix (by S!Ri) to your Desktop.

    Extract all the files to your Destop. A folder named
    SmitfraudFix will be created on your Desktop.

    Open the
    SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter
    This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach that log in your next reply.

    Note:process.exe ( which is used my SmitFraudFIx ) is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. The below is a link to what process.exe is.

    http://www.beyondlogic.org/consulting/proc...processutil.htm


    IMPORTANT: Do NOT run any other options until you are asked to do so!
     
  4. yama73

    yama73 Private E-2

    here is my smitfraud fix log
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay here is the second step to remove Smitfraud.

    PLEASE READ ALL OF THESE INSTRUCTIONS FIRST BEFORE DOING ANYTHING.
    Ask any questions that you may have before starting.

    Please print out or copy these instructions to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. Again, if there's anything that you don't understand, ask your question(s) before moving on with the fixes.

    Reboot your computer into Safe Mode per the safe directions in the READ & RUN ME.

    Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.

    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

    The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach this log along in your next reply.

    After doing the above and attach the new rapport.txt log, also attach a new log from the below:
    - HJT log
    - GetRunKey
    - ShowNew
     
  6. yama73

    yama73 Private E-2

    here are my new hjc, newfiles and rapport logs
     

    Attached Files:

  7. yama73

    yama73 Private E-2

    here is my runkey log
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is your copy of Spy Sweeper a trial version or a paid version?

    Some items like Virtrumonde and winlogonhook that were in your previous logs are not showing now. Did you perform some other cleaning steps on your own or on another forum?

    How are thing working now?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds