Spyagent bv!inf - winlogon.exe

Discussion in 'Malware Help (A Specialist Will Reply)' started by petecito, Apr 14, 2008.

  1. petecito

    petecito Private E-2

    Hi guys, hope you can help.

    McAfee keeps throwing up 'Spyagent bv!inf trojan - c:\winnt\system32\winlogon.exe' and can't quarantine the file. Laptop also runs pretty slowly although seemed to improve temporarily after running all the utilities. Have had this problem for many months and can't pinpoint any particular event that led to the infection.

    Attached are the logs.

    Many thanks for all your help.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Interesting, because that is a valid windows file......however, lets to this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Now go to start / run / type "services.msc" without quotes and see if that service is still listed.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\laflo\Local Settings\Temp\

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  3. petecito

    petecito Private E-2

    Hi TimW,

    Thanks for the prompt response!

    Followed your instructions to the letter. Managed to delete all files in C:WINNT\Temp but couldn’t delete much from the Local Settings temp location. Kept getting the message: “Cannot delete … Cannot find the specified file. Make sure you specify the correct path and filename”. Only had notepad and explorer open at the time.

    Ran MGtools but couldn’t get past ProcessDll.exe – Unable to Locate DLL. DLL mscoree.dll could not be found.

    Avenger log is attached plus whatever MG could produce.

    Hope you can make some sense of this!

    Thanks again,
    Pete
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you have any problems with the fix.bat run....?

    Please go to start / run / type "services.msc" without quotes and see if the Service: 50187 is still there.

    Next, run C:\MGtools\analyse.exe, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    * At the lower right, click on the Config button
    * Then click the Misc tools button
    * Select Delete an NT Service
    * Copy/paste 50187 into the box that opens, and press OK
    * If you receive any error messages just ignore them and continue.
    * Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Now re-Run C:\MGtools\analyse.exe and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Find and delete:
    C:\WINNT\C

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Tell me how that went and what problems you may still have, if any.
     
  5. petecito

    petecito Private E-2

    Hi Tim.

    No I didn’t have any problems with fix.bat

    Service 50187 is still there. Went to delete service 50187 through Mgtools but it says it is enabled and/or running. I went back to services.msc to stop it but it was already stopped. I exited HJT but there was no request to reboot so I guess I didn’t change anything at this point.

    I fixed/deleted O23 – Service: 50187 and rebooted

    C:\WINNT\C folder doesn’t exist so it wasn’t deleted

    Registry change was successful.

    Checked services again and 50187 was now disabled Went back to MGtools to try and delete the service, which was successful.

    Rebooted and now 50187 is no longer in the services list. Is this the offending item – am I done now?

    It's midnight in Sydney so I'm going to run another McAfee scan to see if it's still popping up.

    Cheers!
    Pete
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Removing that service was the (hopefully) last thing we needed to do...let me know how things are running.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type "%userprofile%\Desktop\cf" /u in the runbox and click OK.
    * Note: The space between the cf and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  7. petecito

    petecito Private E-2

    Hi Tim,

    The 50187 service is gone but unfortunately the trojan is still there.

    Note that I haven’t run ComboFix. I started to run it and got a ‘RemAdm-ProcLaunch!171’ message. I looked it up and found Major Geeks no longer advocated running ComboFix and that you've removed it from READ AND RUN ME (thread).

    What do you think? Where to from here?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are looking at an old Read and Run thread...that issue is gone with ComboFix....but if you downloaded it a while ago...delete it from the desktop and re-download it from the present Read and Run instructions.

    Run Combo, attach the log and also tell me the exact path to the reported trojan...and what is reporting it ( a log would be helpful).
     
  9. petecito

    petecito Private E-2

    Re-downloaded and ran Combofix, log attached.

    Paths to reported trojan are C:\WINNT\system32\WINLOGON.EXE and C:\WINNT\system32\winlogon.exe. It's McAfee that's reporting these trojans.

    Thanks,
    Peter
     

    Attached Files:

  10. petecito

    petecito Private E-2

    Post script to say I didn't run Combofix correctly.

    Re-ran Combofix, couldn't delete C:\WINNT\erdnt\Hiv-backup but carried on anyway.

    Proper log attached (ComboFix2.txt)

    Trojan still exists!
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    They are both legit files! I suspect that McAfee is giving a false positive (as it often does).

    I'll tell you what:
    Go to Bitscan link: agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
     
  12. petecito

    petecito Private E-2

    Hi Tim, apologies for the delayed reply!

    Ran Bit Defender, log attached. Bit Defender is still throwing up WINLOGON.EXE as McAfee does.

    I came to this site because my PC was running like a dog and something was continually uploading stuff from my machine and gobbling bandwith (still limited to some degree in Australia – can you believe it?!)

    After running all the utilities, both symptoms appear to have gone now so BIG BIG thanks for all your help. It looks like McAfee is telling me nonsense but then so is Bit Defender! Things are running much much better although there are a few glitches here and there I’m working through.

    What do you think?
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm also thinking it is a false positive as the date is:

    Sounds like your system is running OK?
     
  14. petecito

    petecito Private E-2

    Tim, how does the date make it a false positive? Isn't the date when I got infected? It's also round about when I installed McAfee.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try this ...go to:
    C:\WINNT\ServicePackFiles\i386\winlogon.exe
    Copy the winlogon.exe and paste it into C:\WINNT\system32\

    It should ask if you want to replace it/overwrite it...say yes.

    Now if you were able to do that...run another scan and tell me what happens.

    Yes...you started getting malware back in Oct 2007.
     
  16. petecito

    petecito Private E-2

    Tim, tried copying the winlogon.exe file but I couldn’t due to sharing violation (no surprise I imagine). The incumbent version is dated 2007-11-28, the date I started to get the problems.

    I tried reboot and safe mode with command prompt but still got a sharing violation.

    Anything else I can do to get this file reset?

    Cheers,
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I've slept.....how many users are on this system? Do you have to log on with a password?

    If you remove the password for you account ...we may bypass the need for the winlogon exe and be able to deal with it ...

    Also..go to the file and right click it ... properties ...is there a security tab?
     
  18. petecito

    petecito Private E-2

    There’s just one user – it’s a home laptop. We do log on but the password is blank.

    Removed the password for the account so that I log on automatically and then tried replacing the file with the service pack version. Still got the sharing violation problem although in safe mode with command prompt I get a different error message: “cannot access the file because it is being used by another process”

    No, there’s no security tab on the file properties.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is not malware ....

    It's part of your Thinkpad software....
     
  20. petecito

    petecito Private E-2

    If the winlogon.exe thrown up by McAfee isn't malware, what are you referring to here?
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That it is probably coincidental ....the process I showed you is for your particular laptop ...are you having other issues that would indicate malware (other than Mcafee's report)?
     
  22. petecito

    petecito Private E-2

    I don't think I'm having any other issues although laptop seems to be running slow again. I'll keep investigating. Cheers.
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds