Winlogonhook

Discussion in 'Malware Help (A Specialist Will Reply)' started by Eddiet, May 10, 2008.

  1. Eddiet

    Eddiet Private E-2

    :cry
    Hello is there anyone who can help me kill this thing? yes another victim of this pesky Trojan. I've tried everything and I can't get rid of it. It started with pop-up warnings about the infection, which I understand were false-positives. I killed those by now Internet Explorer doesn't work... I even tried loading Mozilla Firefox... still no luck.

    Per the instructions on this site, I followed all the steps for cleaning XP; steps 1, 2, & 3. I'm attaching my log files for the following programs:

    SASLog.txt
    Malware bytes.txt
    ComboFix.txt

    I have to send my MGlog file in another post.

    If there's anything you can do, I'd greatly appreciate it. I've spent hours dealing with this problem. Thanks in advance.
     

    Attached Files:

  2. Eddiet

    Eddiet Private E-2

    Hello .... well I think the procedures from this site removed the Winlogonhook Trojan (I think they did), but my browser still doesn't work and according to my Webroot Spy Sweeper, I have a new trojan; something called: trojan-phisher-metafisher...

    Can anyone help?... Per the pervious instructions for removing malware I'm attaching my MGlog text file.

    Thanks..
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Is your copy of Spy Sweeper a paid version or a free trial?

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    You should also uninstall ewido anti-spyware 4.0 which was discontinued long ago and replaced by AVG AntiSpyware.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKCU\..\Policies\Explorer\Run: [{58FB4F3F-063A-1033-0514-040306270001}] "C:\Program Files\Common Files\{58FB4F3F-063A-1033-0514-040306270001}\Update.exe" te-110-12-0000213
    O4 - HKCU\..\Policies\Explorer\Run: [{58FB4F3F-0256-1033-0514-040306270001}] "C:\Program Files\Common Files\{58FB4F3F-0256-1033-0514-040306270001}\Update.exe" te-110-12-0000213
    O20 - Winlogon Notify: wingmo32 - wingmo32.dll (file missing)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. Eddiet

    Eddiet Private E-2

    Hi chaslang... thanks for coming to the rescure. I followed your instructions to the letter, but I didn't have any success with the registry editor. I did not get a success message about adding to the registry. I doubled-clicked it (from the desktop) and I could read it, but that was it.

    I ran the Ccleaner program and C\MGtools\GetLogs.bat program, anyway. They seemed to work.

    By the way, I've had to copy these files and instructions from one PC and move them, via thumb drive, to the other PC. I can't get internet access from the PC infected machine.

    I'm attaching the files you requested:

    C:\ComboFix.txt
    C:\MGlogs.zip

    Oh yeah... by the way, my version of Webroot Spy Sweeper is a liscensed copy.

    Thanks again.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your PC lost the Windows File Association for .REG files. Let's fix it.

    Now Copy the bold text below to notepad. Save it as RegFix.reg to your desktop. Be sure the "Save as" type is set to "all files". Then Click Start, Run, and enter regedit and click OK. This will open the Registry Editor.

    In the Registry Editor click File and Import. Navigate to the RegFix.reg patch you saved on your Desktop and double click on it. Click OK at the prompt to add to the registry. Do you get a success message for this?
    Then retry the fixME.reg patch and continue on with the rest of the instructions.


    What happens? Do you get any error messages?
     
  6. Eddiet

    Eddiet Private E-2

    Hi chaslang... no luck... I created the new Regfix.reg file from your post.. I even made sure the "Save as" type was set to "all files". I also imported the file to the registry, but when I doule click on FixMe.reg (from the desk top) it doens't do anything but show the text file.
    I ran the other programs anyway; CCleaner and C:\MGTools\GetLogs.Bat... I'm geting the following error: ProcessDll.exe - .NET Framework Initialization Error.

    Thanks...
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then import it into the registry the same way as RegFix.reg Do you get a success message.


    This error was described in the Using MGtools link in the READ ME. You do not have the .NET software from Microsoft installed.
     
  8. Eddiet

    Eddiet Private E-2

    Hello Chaslang.. sorry to drop off the conversation last week, but i had to call it a night. I Followed your instructions and imported the new Restistry file to my HKEY, I got a success message, but explorer still doesn't work.

    Would you suggest a new browser, perhaps Firefox / Mozilla?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please be careful to say exactly what you mean! I assume you mean that Internet Explorer does not work. Explorer means Windows Explorer to us. What exactly happens when you use Internet Explorer? This may be more of an issue for the Software Forum. You should take a look at this: http://support.microsoft.com/kb/318378

    Yes try Mozilla FireFox and tell me if it works.
     
  10. Eddiet

    Eddiet Private E-2

    chaslang... thanks for the reply.

    :eek: Yes, I was referrring to Internet Explorer and I believe it's an older version (6.0.2800) Thanks for the redirect to the software forum. I scanned their postings earlier.

    The IE error message says, "The page cannot be displayed". I'm ready to give firefox a shot. thanks again... I'll keep you posted.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure that you are not blocking IE in your firewall? Shutdown ZoneAlarm and see if IE works.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds