Help removing Winlogon Trojan/Worm

Discussion in 'Malware Help (A Specialist Will Reply)' started by shewolf, Sep 9, 2006.

  1. shewolf

    shewolf Specialist

    My problem?? Comuter restarts on its own especially when I run Ad-Aware SE (in both safe and normal boot mode). When computer restarts I get that pop up from Microsoft telling me its a winlogon.exe error and to send error report. I click send and once completed I can click for more information and it tells me that the error may have been caused by a Winlogon Trojan/Worm.
    I have done the steps in "Read Me First" and am attaching all the things that it tells me to attach when posting.
    I can not find any files named runkeys.txt so I am not sure if that didn't save or do anything on my computer or not. I have 10 xrkey.txt files .
    Thanks for any help anyone can give me.
    SW:)
     

    Attached Files:

  2. shewolf

    shewolf Specialist

    Here is the hjt log file now..
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the directions in step 6 of the READ ME and attach the requested log from GetRunKey. Make sure you use the current version of GetRunKey. (You ShowNew version is out of date too).

    Also follow the directions in step 7 of the READ ME which highlighted the importance of renaming HijackThis.exe. You have the exact problem for which this is most important.

    Then attach a new HJT log.
     
  4. shewolf

    shewolf Specialist

    I have no runkeys.txt in my C drive I only have 10 xrkeys.txt
    I have even used the xphomefix and reran the getrunkey.bat file and still I don't have a runkeys.txt in my C drive.

    As for out of date ?? How do I update the GetRunKey and ShowNew when I am downloading them directly from Majorgeeks per the instructions and clickable areas on the Read Me First.

    I have attached a new HJT log and another newfiles.txt

    Thanks
    sw:)
     

    Attached Files:

  5. shewolf

    shewolf Specialist

    Ok I realized that my sunjava was out of date so I updated that and tried the getrunkey.bat yet again to get the text file of runkeys.txt , still can't get that file even when I run the XPHomeFix and rerun the getrunkey.bat file.

    I have attached the new HJT and the updated newfiles.txt hope this helps and hopefully you can tell me how to get my runkeys.txt file as it is just not working for me for some reason.

    One more thing I can't tell you what it is as it happens so fast I don't have a clue nor can I read anything. When I click on my computer and it opens I get another window that opens and closes really fast. So, like I said it happens so fast that I can't view it to see what it is thats opening and closing in a split second. Just thought I would let you know that this is happening tome as well.


    Thanks,
    sw:)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The files you are mentioning are intermediate temp files created by GetRunKey while building the log. They are deleted when it finishes running but only if it runs and terminates properly. I see what your problem is now! I figured it out from your ShowNew log. You used a non-valid username for MS-DOS applications. You have Gary & Darla This is a bad idea. All users should have their own user accounts to avoid changing each other's settings and for security purposes. I will give you a modified version of GetRunKey.bat to use. I made a patch to the program to avoid a DOS level problem due to this. Please download the current version from the same link and use it to get a log.

    You just need to go back to the same links and download them again and you will have the current version. You aleady have the current version of ShowNew! After doing the above, you will have the current GetRunKey.
     
    Last edited: Sep 12, 2006
  7. shewolf

    shewolf Specialist

    Ok it worked here is the runkeys.txt along with an updated newfiles.txt do you need a new HJT log?

    I see from other posts that things that others are experiencing I am experiencing as well. Such as I get a pop up for a split second when I open my documents, when I click on something within Firefox sometimes I get a pop up but the popup is opened in IE and I don't even have IE open as I use Firefox for my browser. Just thought I would let you know of that as it will enable you to help me better.

    Can you either tell me how to change it or point me in the right direction so I can change my non-valid username to one that is valid?

    Thanks,
    sw:)
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First you need to run MSconfig and select Normal Startup as requested in the READ ME. Then attach a new GetRunKey and a new HJT log.

    You cannot truly change the account name and have all files and environment variable change with it. The account name itself can be changed but this will only change what you see when you login. Nothing else will actually be changed. Thus, there is no fix other than to create new accounts. Don't worry about it, but I do recommend that you have separate accounts for each user.
     
  9. shewolf

    shewolf Specialist

    ok even though you only requested a new getrun and hjt log I am attaching the newfiles log as well just to be safe and save time incase you need it.
    thanks for all the help
    sw:)
     

    Attached Files:

  10. shewolf

    shewolf Specialist

    Ok I want to say thank you for taking the time to try and help me out but it has come to the point that I am just going to have to "dump" my computer by reformatting or whatever you want to call it. I am typing this on my 2nd computer as I can't even get to the log in screen on my infected computer.

    When I start the computer up it brings up the computer name and goes to the windows xp screen with that scrolling bluebar and then it blinks a couple times and stays black. My monitor light stays green to tell me that there is still a connection between the monitor and the tower. It has been 15 minutes and my monitor is still black it will not show me the sign in screen.

    Anyhow thank you for trying to take the time to help me out I really do appreciate major geeks and the service that you all provide.

    sw:)
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We may still be able to fix it! Can you boot in safe mode? If so, try doing the below!


    Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to the following key and take ownership of it (explained further down):

    HKEY_LOCAL_MACHINE\software\microsoft\mssmgr

    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the Menu
    • Select Take Ownership
    • Now leave RegistrarLite running and continue
    • Now run the REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate to HKEY_LOCAL_MACHINE\software\microsoft\mssmgr
    • Does the above mssmgr key still exist! If so, right click on it and select Delete.
    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    After completing ALL of the above instructions, continue here!

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of wincqt32.dll once and then click the kill button. After you have killed all of the wincqt32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    vturp.dll

    Next double click on explorer.exe and again click once on each instance of wincqt32.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    vturp.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O2 - BHO: (no name) - {128A429E-63D6-20AE-5161-0319E9F314DA} - C:\WINDOWS\system32\cunvqre.dll
    O2 - BHO: (no name) - {347438D0-5205-4336-B690-D69E7FAB2AD9} - C:\WINDOWS\system32\vturp.dll
    O2 - BHO: (no name) - {60C85B4E-A272-4C43-9A6B-95FA7DEC1D4D} - (no file)
    O2 - BHO: (no name) - {B0DAD720-92FD-4CEB-A1AC-CC8FD228F1EF} - (no file)
    O4 - Startup: .protected
    O4 - Global Startup: .protected
    O20 - Winlogon Notify: vturp - C:\WINDOWS\system32\vturp.dll
    O20 - Winlogon Notify: wincqt32 - wincqt32.dll (file missing)
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.


    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    del %windir%\temp\win*.*
    exit

    If you get an error message while doing the above command prompt step, just ignore it and continue!

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\Gary & Darla\Start Menu\Programs\Startup\.protected
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\.protected
    C:\WINDOWS\system32\ismini.exe
    C:\WINDOWS\system32\cunvqre.dll
    C:\WINDOWS\system32\jssqrkg.dll
    C:\WINDOWS\system32\ssqnkif.dll
    C:\WINDOWS\system32\vturp.dll
    C:\WINDOWS\system32\prutv.ini
    C:\WINDOWS\system32\{0322CDEC-C35B-4EE8-BF06-22CA693D1377}.dat

    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folders and delete them if found:
    C:\Program Files\Ultimate Defender
    C:\Program Files\Common Files\{B486BCC2-0874-1033-0629-030506030001}

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp\
    C:\Documents and Settings\Gary & Darla\Local Settings\Temp

    Now attach a new HJT log and tell me how the steps went.

    Also attach a new log from ShowNew and a new log from GetRunKey.

    Make sure you tell me how things are working now!
     
    Last edited: Sep 13, 2006
  12. shewolf

    shewolf Specialist

    I could not get into safemode.. the computer just kept hanging up and giving me a black screen.. So I just "dumped" it ..

    After I reloaded everything I found in the Add/Remove that Viewpoint Media Player and it was there with an icon to resemble windows media player. I thought that was kind of strange that it loaded into a "fresh" system right off.

    Almost done with all my updates will go thru the read me first steps to double make sure that I am free of everything and will post the requested logs.

    Thanks for everything and trying..

    sw:)
     
  13. shewolf

    shewolf Specialist

    Ok I have re-done the Read Me First and I hope that everything is fine now.. (crosses fingers).
    Here are my scans to double check to be sure especially since I had that Viewpoint Media Player in the Add/Remove programs right off from a fresh computer..

    Thanks again for everything..
    sw:)
     

    Attached Files:

  14. shewolf

    shewolf Specialist

    last 2 scans..
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it would not normally be on a PC if you install the OS from a real Microsoft CD. But if you installed from a CD given to you by a PC manufacturer it may. However as soon as you installed AIM, you got the Viewpoint junk without them even asking you. It will be installed anytime you install anything from AOL.

    You also have BigFix running which is a huge resource hog. Consider uninstalling if you don't need it. If you do want to have it, then just stop it from loading at startup by fixing the O4 line in HJT.

    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe

    You can just run it manually if you ever need it. Anytime I get a new PC, the first things to be uninstalled are:
    - anything AOL related
    - BigFix and other supposed debug tools from the PC vendor
    - any internet security suites
    - any other trial ware
     
  16. shewolf

    shewolf Specialist

    Thank you so much for your input, time and help..

    It really is appreciated everything you all do here for us with computer problems & questions..

    Keep up the great work..

    Darla (sw)
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and as we tell everyone, be sure to check out the below:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds