Winlogonhook Removal Tested

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Mirken, Jul 31, 2006.

  1. Mirken

    Mirken Private E-2

    I have just encountered the winlogonhook trojan problem found in spysweeper. After reading, searching and downloading for hours I accidently discovered a much easier way to remove the stubborn SOB than those posted here and on the net.

    1. Run Spysweeper to find the trojan.

    2. Click next - expand the trojan location folder which is a registry file.

    3. Go to run - type "regedit"

    4. Open HKEY_LOCAL_MACHINE

    5. Find "Microsoft" and click on MSSGER (cant remember exactly but you'll see it in the spysweeper location, and delete the whole file.

    6. In spysweeper check the trojan for removal and wala all done.

    This way was tested on two systems, rebooted and swept again with no trojan detected. I hope it helps ppl because this %#^@ me to tears.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for the info but there is actually some more to clean up!

    The exact registry key location that Spy Sweeper mentions is:

    HKEY_LOCAL_MACHINE\software\microsoft\mssmgr

    However there are also other keys that are related and there are DLL files to delete. Here is an example:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winubg32

    The winubg32.dll file also needs to be delete.Typically found in C:\windows\System32
    Note this is an example file name. There are hundreds of variations.

    The key thing that all Spy Sweeper subscribers should be asking of Webroot is "Why they do not fix the problem". This has been going on for months and they still do not fix they problem even though their logs say they do.
     
  3. Mirken

    Mirken Private E-2

    I was able to remove the other traces of it and was only left with the HKEY_LOCAL_MACHINE\software\microsoft\mssmgr registry file and was unable to remove it. Webroot have a nice detailed file on their website about the winlogonhook trojan being of the highest risk, potentially enabling your system to be completely taken over. You would really think they would have fixed it by now. Please let me know if this works for others or was I just lucky in removing it.
     
  4. Mirken

    Mirken Private E-2

    HKEY_LOCAL_MACHINE\software\microsoft\mssmgr was the only registry file I had come up on the sweep. You would think that as Webroot have a lovely description on their definitions website saying that this winlogonhook trojan is their highest threat level and also on their top ten most dangerous trojan list, capable of having someone in total control mouse and keyboard included of your system, you would think they had fixed this by now. Does HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winubg32 come up on your SpySweeper scan? Was anyone else able to remove it this way?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what your messages are trying to say????

    They seem to be duplicate posts which are embedding part of my messages in them?

    The HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify registry key is part of the infection. Removing the HKEY_LOCAL_MACHINE\software\microsoft\mssmgr regisrtry key may or may not fix this key. I don't know at this time. It also may not remove the DLL file. I have seen more than a 100 forms (filenames change) of this infection.
     
    Last edited: Jul 31, 2006
  6. Mirken

    Mirken Private E-2

    Thanks for clearing that up, sorry about the double post. was supposed to edit, I'm retardard lol
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds