Got winlogonhook virus / trojan i think

Discussion in 'Malware Help (A Specialist Will Reply)' started by Pimped, Oct 22, 2007.

  1. Pimped

    Pimped Private E-2

    Hey guys

    I kept on getting disconnected from the network in a strange way recently and after searching i realised i had the "(WMPNetworkSvc)" trojan probs. I would have to restart to allow my computer to communicate to the network.

    I have tight vnc and i forwarded ports on my firewall so that i could control my oc remotely. so this was a big mistake. also, i had windows media 11, which ive downgraded to windows media 9, but i had that windows media 11 set up for network file sharing with the xbox i used to have. i realised that the (WMPNetworkSvc) process was active and i thought it may be a virus, so i deleted it before i downgraded it.

    now what happens is whan i press pause on my multimedia wireless keyboard while im watching a video in windows media (v9, 10 and 11 all had this same prob, hence the downgrade), and then pressed play again, the computer would freeze and the sound would come but very slow pictures and wmplayer.exe would hog 100% of the CPU.

    Please help, im totally bummed :(

    Cheers
     

    Attached Files:

  2. Pimped

    Pimped Private E-2

    done :(
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a trojan. It is for Window Media Player. See: http://www.liutilities.com/products/wintaskspro/processlibrary/wmpnetwk/

    If you are having a problem with Windows Media Player you will have to post in the Software Forum since it is not a malware problem. But if you just want to get rid of this service from Windows Media Player, try the below.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Windows Media Player Network Sharing Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteWMPNetworkSvc into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.
    You should also run the below since you may have a rootkit like service running.

    Download this file - combofix.exe
    1. Double click combofix.exe & follow the prompts.
    2. When finished, it will produce a log ( C:\combofix.txt ) for you. Attach this log to your next reply See: HOW TO: Attach Items To Your Post
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.
     
  4. Pimped

    Pimped Private E-2

    dear chaslang, thank you for your reply. before i continue with following the above instructions, i have to make sure it is definitely not a virus.

    I no longer have the wmpnetwork file, so it is not doing the cpu 100%, instead its wmplayer.exe hogging the cpu. i think maybe it is because it is trying to run a service that doesnt exist, but im not the pro here! lol

    ok if you definitely still think its the software, then i shall continue.

    yeah i saw the rootkit thing. I had a virtumonde virus picked up in a scan i did a few weeks back because i was afraid of the winlogonhook trojan thing. it hasnt been picked up in the scans i have done through the tutorial so im confused.

    thanks

    EDIT: Attached, combofix.txt. Did it twice, first time counterspy kept on blockign it and asking me if i want to allow it or not, and i think this may have spoilt the test so i kept the old version as combodfixold.txt and did it again and am now uploading combofix.txt

    EDIT 2: Forgot to attach log from registrybooster from that link you gave me for lutilities
     

    Attached Files:

    Last edited: Oct 22, 2007
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your only malware issues are Messenger Plus! Live which we requested that you uninstall in the READ ME. Installing the above is more than likely where you go the Vundo infection that your PC still shows a few residual signs of. Delete the below files if they still exist:

    C:\WINDOWS\system32\rtstv.bak1
    C:\WINDOWS\system32\rtstv.bak2

    Other than the above you have no real malware issues but I do have a few things you should do.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below folders which may be left behind by the uninstall:
    C:\Documents and Settings\HP_Owner\Application Data\Sunbelt Software
    C:\Documents and Settings\HP_Owner\Application Data\Uniblue
    C:\Program Files\Sunbelt Software


    What is the below folder for?
    REPAOR 21 Oct 2007 "Repaor"


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 9

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Did you do what I requested in my last message to remove the service or not? If you did then attach a new HJT log.

    We don't want logs from this. It is not useful to us in removing malware since it mostly shows things that have nothing to do with malware and that are not really problems.
     
  6. Pimped

    Pimped Private E-2

    I know about the msn plus live problem, but i just made sure that i clicked NO to the sponsor program. Is that not safe enough?

    Can you confirm that alcxmonitor is a known problem, because i believed it to be a part of a software for my computer. i think for the motherboard? i googled it and it doesnt seem to be a problem, can you jjust clarify because i dont want to do an irrepairable action. i removed the other 2 lines though.
    That is just me misspelling "Repair" lol

    Uninstall the below old versions of software:

    I didnt because it wasnt started and couldnt be started because the file was missing, but i think i should go ahead and remove now anyway. but i seriously think something is wrong with windows media because i think someone has hacked my computer, which is why the computer would just cut off from the network, as in no more internet connectivity and couldnt reach the router. And msn would tell me there is a problem with key ports when i troubleshooted the connection. hence thinking that someone had hijacked all ports. At that time, it was the wmpnetworksvc process that was hogging the processor. i deleted that file and uninstalled windows media down to 10. Then after that thepause issue came about in windows media 10 and 11.

    What do you require me to do now and what do i need to give you?

    EDIT: new hjt log, just removed wmpnetwork service
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you feel comfortable with this scurge of the internet program on your PC then it is your decision. It cannot be trusted and who knows what it will do during any updates. This programs as caused millions of people issues and that is why we don't recommend using it even if you elect not to install the sponsor programs.


    Yes this is related to Realtek AC97 Audio however it is not a required process and it monitors your actions. See the below:

    http://www.bleepingcomputer.com/startups/Alcxmntr.exe-245.html

    http://www.castlecops.com/s180-Alcxmntr_exe.html


    Your logs show no signs of any problems other than what I already posted.

    What do you require me to do now and what do i need to give you?[/quote]Did you complete all the other instructions? Did you apply the registry patch and was it successfully added?
     
  8. Pimped

    Pimped Private E-2

    lol, Right you are then. I only got it for the sending multiple nudges!

    Ok will remove the ALCXmonitor! :)

    Yes, i installed java, removed the other 2 thing in hjt, added the reg patch.

    Will remove alcx now. Thanks mate, theres nothing you can do to help me now. i have to try and figure out what the hell is up with wmplayer. its still freezing. If i try to load another film once the current film is playeing or has finished, it hogs the cpu, has to be closed. same for playing after pausing, etc etc

    Thanks for all ur help mate and a happy belated birthday :)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can try posting in the Software Forum for additional help on this.

    Thanks. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds