Infected with the winlogonhook trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by gman123, Jul 12, 2007.

  1. gman123

    gman123 Private E-2

    Looking for help with the trojan winlogonhook detected with spysweeper. This pesky trojan has been stuck on my computer for weeks and webroot hasn't been very helpful.
     
  2. gman123

    gman123 Private E-2

    sorry... i need to run some steps before attaching my hijackthis logfile
     
    Last edited: Jul 12, 2007
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Since winlogonhook often comes at the same time as Virtumonde infections and sometime even more, you really need to do the below.

    NOTE: It is critical that you follow our directions for installing and renaming HijackThis.exe as stated in step 7 of the below sticky.


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  4. gman123

    gman123 Private E-2

    Thank you for the help.... I've run through all the cleaning steps and unfortunately vitumonde and winlogon remain.... I'm posting my log files from the cleansing steps. Please let me know what else I can do.
     

    Attached Files:

  5. gman123

    gman123 Private E-2

    And the final three logs... I ran through the sticky thread in detailed... used CCleaner, defrag'ed my computer.... ran Spybot search and destroy... it found virtumonde but did not clean it... the same for all other anti-virus programs...

    CounterSpy could not be run due to my admin settings so I ran AVG Anti-Spyware

    I ran Spysweeper one last time... and it's showing winlogonhook still being there
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First a couple questions:
    1. Is Spy Sweeper a paid version or a free trial?
    2. Did you configure the below settings yourself:
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://wpad/wpad.dat
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=http://webcache.sfbay.sun.com:8080;gopher=http://webcache.sfbay.sun.com:8080;http=http://webcache.sfbay.sun.com:8080;https=http://webcache.sfbay.sun.com:8080
     
  7. gman123

    gman123 Private E-2

    1) yes... it's a paid subscription... i logged a ticket with Webroot, and they've been little to no help.

    2) i didn't configure the first two... however, the third I don't remember setting, but it looks to be the mail server to where I'm working.... at least the sfbay.sun.com part...
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ok then I recommend that you uninstall AVG Antispyware now to avoid conflicts. I hope you will find us to be a lot more help. ;)

    Okay! I added the first two to my fix below.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 7
    Java 2 Runtime Environment, SE v1.4.2_07
    Java(TM) SE Runtime Environment 6

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://wpad/wpad.dat
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUxdm080YYUS
    O16 - DPF: {00000005-0000-0000-0000-100009000004} - http://c.imputati.com/l/9d5807bd11a806b37f6e8618a8a0b4ff_35.exe
    O20 - Winlogon Notify: awtqp - C:\WINDOWS\system32\awtqp.dll (file missing)
    O20 - Winlogon Notify: awttq - C:\WINDOWS\system32\awttq.dll (file missing)
    O20 - Winlogon Notify: ddcbx - C:\WINDOWS\system32\ddcbx.dll (file missing)
    O20 - Winlogon Notify: ljjgh - C:\WINDOWS\system32\ljjgh.dll (file missing)
    O20 - Winlogon Notify: pmnol - C:\WINDOWS\system32\pmnol.dll (file missing)
    O20 - Winlogon Notify: urstq - C:\WINDOWS\system32\urstq.dll (file missing)
    O20 - Winlogon Notify: wingob32 - wingob32.dll (file missing)
    O20 - Winlogon Notify: wvuuvtq - wvuuvtq.dll (file missing)
    O20 - Winlogon Notify: xxywtsp - xxywtsp.dll (file missing)

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  9. gman123

    gman123 Private E-2

    The good news... is that it looks as if the trojan is gone...
    the very very bad news is that it looks as if windows/microsoft looks like it's hosed.... i can't access any of my office apps. and the Start > All Programs menu is completely gone... when i try to access an MS program it brings up a windows installer and doesn't load anything.... :cry
     

    Attached Files:

  10. gman123

    gman123 Private E-2

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that makes no sense since if you look at the log from Avenger, it failed to delete everything. Are you sure you only ran what was requested? Did you run anything else at all? Even your log from ShowNew indicates that something remove all information on installed programs that was in the Uninstall key in your registry. You can see this by looking at the end of your current newfiles.txt log and comparing to the end of your first log.

    Are you sure you were not playing with anything else including HJT on your own? Even your HJT log indicates some other items are now missing and we did not touch these.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see some other malware on your PC. Looks like you winlogon.exe file is infected or has been replace by a fake process.

    Also, all of the below just showed up in your newfiles.txt log. They were not there previously.
    Code:
    "C:\"
    avexport.bat  Jul 17 2007        3984  "avexport.bat"
    dhtjccsn.bat  Jul 17 2007        1080  "dhtjccsn.bat"
    jiglhwgs.bat  Jul 17 2007        1080  "jiglhwgs.bat"
    vddknvyi.bat  Jul 17 2007        1080  "vddknvyi.bat"
    zip.exe       Jul 17 2007      126976  "zip.exe"
    You should delete all of these files.

    Also delete the below files:
    Code:
    "C:\WINDOWS\system32\drivers\"
    idvbwejr.sys  Jul 17 2007       60416  "idvbwejr.sys"
    tcdhlfig.sys  Jul 17 2007       60416  "tcdhlfig.sys"
    xckouwdb.sys  Jul 17 2007       60416  "xckouwdb.sys"
    Fixing the winlogon.exe file is going to take some special steps and we will also have to do it in safe mode. But first I wanted to try removing the above items. Let me know if you have any problems removing the above files.
     
  13. gman123

    gman123 Private E-2

    I printed the instructions and followed them to a tee... I was pretty careful using HJT since I know i can mess up my desktop settings. I did have some issues running avenger. I cut and paste the quoted script, but it gave me several errors when running. I cut and pasted a second time and ran again.

    I knew I had some pretty nasty programs running, but this getting worrysome... any suggestions on backtracking i can do to resolve the MS office and Start > All Programs issues?
     
  14. gman123

    gman123 Private E-2

    I didn't have a problem deleting those files...
    Check the log like you mentioned for HJT... I see there are some items missing, but I don't know why.... I ran the initial scan to fix the issues... then the second to generate the log. I was toggling between the instructions and the txt file from the instructions above, but I don't think I checked anything that wasn't on the list...
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay hangon while I try to put something together specifically to attempt to remove the winlogon.exe infection.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm going to have you run a procedure below which will attempt to delete the infected winlogon.exe file and also another system file that appears to be infected (ws2_32.dll )and replace them with a good copies from your ServicePackFiles folder.
    • Print or save the below instructions locally because you need to close all browsers later.
    • Download the attached gman123.zip file to your Desktop.
    • Now double click on gman123.zip and extract the contents to your Desktop.
    • This should create two files on your Desktop. gman123.bat and process.exe.
    • Note some antivirus programs may falsely detect process.exe as malware. It is not malware. Don't worry about it if you see a message about process.exe. Allow it to run later when we run the procedure.
    • Now you need to boot into safe mode to run the below. It is necessary that when you login to safe mode that you login to the same user account where you just extracted the above files on the Desktop or else you will not find them.
    • Once in safe mode, shutdown ALL unnecessary applications including browsers
    • Now double click on the gman123.bat file to run the fix.
    • It will create a log file named: c:\FixWL.txt
    • After running this you will not be able to shutdown or restart your PC in the normal fashion. You will have to hold in the power button on your PC until it powers down.
    • Close ALL open windows now!!!!! Then continue!
    • Power down your PC now by holding in the power button. Wait about 15 seconds and then power back up.
    • Come back here and attach the c:\FixWL.txt file
    • After attach the C:\FixWL.txt file here.
    • Also attach new logs from ShowNew and HJT.
     

    Attached Files:

  17. gman123

    gman123 Private E-2

    Ran those...
     

    Attached Files:

    Last edited by a moderator: Jul 18, 2007
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That seems to have fixed the winlogon.exe file but not the other file. We will have to try another fix. Why do I now see the below in your newfiles.txt log?


    "DisplayName"="Microsoft Baseline Security Analyzer 1.2.1"
    "DisplayName"="Update for Windows XP (KB936357)"
    "DisplayName"="Windows Genuine Advantage Validation Tool (KB892130)"
    "DisplayName"="Windows Genuine Advantage Validation Tool (KB892130)"

    They were not there before!
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run the last procedure in safe mode as requested? This is important.

    I'm going to have you run a procedure below which will attempt to delete the infected winlogon.exe file and also another system file that appears to be infected (ws2_32.dll )and replace them with a good copies from your ServicePackFiles folder.
    • Print or save the below instructions locally because you need to close all browsers later.
    • Download the attached gman2.zip file to your Desktop.
    • Now double click on gman2.zip and extract the contents to your Desktop.
    • This should create two files on your Desktop. gman2.bat and process.exe.
    • Note some antivirus programs may falsely detect process.exe as malware. It is not malware. Don't worry about it if you see a message about process.exe. Allow it to run later when we run the procedure.
    • Now you need to boot into safe mode to run the below. It is necessary that when you login to safe mode that you login to the same user account where you just extracted the above files on the Desktop or else you will not find them.
    • Once in safe mode, shutdown ALL unnecessary applications including browsers
    • Now double click on the gman2.bat file to run the fix.
    • It will create a log file named: c:\FixWS2.txt
    • After running this you will not be able to shutdown or restart your PC in the normal fashion. You will have to hold in the power button on your PC until it powers down.
    • Close ALL open windows now!!!!! Then continue!
    • Power down your PC now by holding in the power button. Wait about 15 seconds and then power back up.
    Now after reboot continue with the below.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    • Come back here and attach the c:\FixWS2.txt file
    • Also attach new logs from ShowNew and HJT.
    What problems are you still seeing?
     
  20. gman123

    gman123 Private E-2

    sorry.... i didn't see the gman2.zip file you were referencing...
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry here it is!
     

    Attached Files:

  22. gman123

    gman123 Private E-2

    followed all the steps above...
     

    Attached Files:

    Last edited by a moderator: Jul 18, 2007
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run the gman2.bat procedure in safe mode as requested? It did not work and that is the only way it will work. Are you sure that you extracted ALL files fom the original gman123.zip to your Desktop? Do you see the process.exe file on your Desktop? Do you see it when you are in safe boot mode? Based on your newfiles.txt log, the gman123.bat and the process.exe file are not on your Desktop. gman2.bat is on your Desktop.

    Also the registry patch did not work properly. Did you get a success message? Did Spy Sweeper block it? Did Symantec block it? You should shutdown Spy Sweeper and Symantec and try the fixME.reg patch again. Tell me if you get a success message.

    Also you have not stated how things are currently running.
     
    Last edited: Jul 18, 2007
  24. gman123

    gman123 Private E-2

    yes.... i extracted all files to the desktop and ran them in safe mode. I removed the first gman123.bat file, but left the process.bat file when I ran the gman2.exe file. The registry update said it was successfully updated when I saved the file and opened it. The system is running fine with the exception of the MS issue I mentioned yesterday. I'm going to reinstall after i finish this fix.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You mean MS Office does not work at all? I have seen this get broken many times for unknown reasons. If is possible that malware did something and when the malware is removed it leaves the application in a broken state. It may be necessary to run this: Windows Installer CleanUp Utility

    You also had said this:
    Is this still occurring?
     
  26. gman123

    gman123 Private E-2

    yeah... i believe the maleware corrupted some of the MS office start up files or dll files. I'm going to reinstall once i get all this cleaned up.... the issue with my program menu still exists... i'm going to use the Windows Installer CleanUp Utility as you mentioned
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is the Start button there at all?
    Does your Desktop appear (like all icons, the taskbar, etc)?
     
  28. gman123

    gman123 Private E-2

    the start menu is there... everything still appears on the desktop... although the task bar does not show all the items it used to
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I wonder if they were uninstalled? Remember when I commented on your uninstall list changing at the end of the newfiles.txt log. See the newfiles.txt logs in message # 4 and then compare it to the end of the newfiles.txt log in message # 9.


    Do you know what the below file is for? If not, attach it here.
    C:\Documents and Settings\ikdcspap.txt

    Do you know what the beloe file is for?
    Code:
    C:\Documents and Settings\ngallego\Desktop\
    oajinit.sh    Jun 19 2007     9203967  "oajinit.sh"
    What is in the below folders? These are not valid Windows folders!
    Code:
    "C:\WINDOWS\system32\"
    %COMMO~1      Jul 17 2007              "%commonprogramfiles%"
    %PROGR~1      Jul 17 2007              "%programfiles%"
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may want to consider doing a System Restore to a point just before where your All Programs stuff disappeared. Hopefully that will fix this issue. Even if any malware comes back, we can always fix it again.
     
  31. gman123

    gman123 Private E-2

    1st file is oracle j initiator... a java applet for my work...
    i don't know about the others...

    I'll consider the system restore... thanks for all the help up to this point...
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then please attach the first file I requested and also tell me what you see in those two folders I asked about.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds