help with winlogonhook removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by doofy, Aug 10, 2006.

  1. doofy

    doofy Private E-2

    Hi there guys,

    I have somehow managed to contract winlogonhook. This trojan came to me when I downloaded regcure. I have since tried to remove it with several of the suggestion from this board and also by downloading a lot of spyware. counterspy, adaware, spybot sd, spysweeper, ewido and I get rid of it and it just comes right on back.

    so I decided that after many fruitless attempts I would ask for assistance here.

    so if you can help me that would be great.

    Oh and I dont want to reformat.

    Cheers guys.
     
  2. doofy

    doofy Private E-2

    And I do have hijack this so if a log file is needed please let mwe know and I will post it.

    and any other relevant information you may need.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:

      • [*]runkeys.txt - the log from GetRunKey.bat
        [*]newfiles.txt - the log from ShowNew.bat
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  4. doofy

    doofy Private E-2

    Hi there,

    I have done all of the scans required. the first time I tried I did not get very far as pop ups were going baserk. but second time round everything went smoothly.

    A lot of trojans were found and a few other bits and bobs. I am not to sure what was deleted and what was not. however I think majority of the stuff was deleted and I am left with only a little now.

    Here are the logs for all scans.

    Thanks for your help.
     

    Attached Files:

  5. doofy

    doofy Private E-2

    and the second lot.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you have quite a few nasty problems! To name just a few, SmitFraud, Virtumonde, and Winlogonhook/conhook. We will need to work this is stages.

    But first a couple questions!

    1)You never installed and ran Spybot as requested in the READ & RUN ME. Why???

    2) Is your copy of CounterSpy a free trial or paid version.


    Let's being with the SmitFraud infection.

    Download SmitfraudFix (by S!Ri) to your Desktop.

    Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

    Open the SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter
    This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach that log in your next reply.

    Note: process.exe ( which is used my SmitFraudFIx ) is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. The below is a link to what process.exe is.

    http://www.beyondlogic.org/consulting/proc...processutil.htm


    IMPORTANT: Do NOT run any other options until you are asked to do so!
     
    Last edited: Aug 10, 2006
  7. doofy

    doofy Private E-2

    Hi there,

    Thanks for the help.

    here is the log from the smitfraudfix.


    Actually I did run spybot and allowed it to complete. it picked up about 5 things including smitfraud and smitfraud toolbar888 or something. spyquake was another I think.

    I ran all of the scans that were said to run and did not skip anything.

    I have spybot 1.4 permanently on my computer and is updated everytime I use it. however I did download it and install it again just to make sure and this was done twice.
     

    Attached Files:

  8. doofy

    doofy Private E-2

    and also my copy of counter spy is the trial version.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you did not follow the READ ME in the correct order because Spybot does not show as being installed in the ShowNew log.

    Uninstall the CounterSpy trial version!

    PLEASE READ ALL OF THESE INSTRUCTIONS FIRST BEFORE DOING ANYTHING. Ask any questions that you may have before starting.

    Please print out or copy these instructions to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. Again, if there's anything that you don't understand, ask your question(s) before moving on with the fixes.

    Reboot your computer into Safe Mode per the safe directions in the READ & RUN ME.

    Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.

    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

    The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach this log along in your next reply.

    Now attach new logs from Hijackthis.

    Also attach a new log from GetRunKey and also from ShowNew!

    Also tell me how things are working.
     
  10. doofy

    doofy Private E-2

    ok that scan is done.

    it did not ask me anything about wininet.dll so I will leave that up to you.

    The system seems a little sluggish still strartup applications are still rather slow to load up. and I have lost mt desktop background and internet preferences like start page and stuff after the scan but other than that it seems ok, there is no pop ups or anything so far.

    here are the new logs you asked for.

    I rebooted to computer back into safe mod after the scan and then booted it up again in normal mod with the internet disconnected to do the scans.
     

    Attached Files:

  11. doofy

    doofy Private E-2

    Oh and I am back in safe mode now with net work connections to reply to you here.
     

    Attached Files:

  12. doofy

    doofy Private E-2

    bump. incase it has been missed.
     
  13. doofy

    doofy Private E-2

    what do I need to do now.
     
  14. doofy

    doofy Private E-2

    UMMMMMM. Can someone please let me know what I need to do next.

    I have posted the last report that was asked of me. ^^^

    Cheers.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note: Each time you bump your thread, you make it take longer to get a response. Each time you do this, you send yourself to the bottom of the work queue. We work from oldest to newest. Bumping makes you newer and you are thus ignored until all older threads are answered first.


    You still do not have Spybot installed according to your ShowNew log and it shows all installed programs. Please install it now and run it. Then attach a log from Spybot. If it is already installed, then uninstall it. Reboot and then reinstall it because something is wrong if it is not showing in Add/Remove programs. Then get the log from Spybot and attach it.

    Also uninstall this:
    Kazaa Lite v2.1.0 [K++ Edition] [build 3]

    Then continue onto the below cleanup!

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of wingdm32.dll once and then click the kill button. After you have killed all of the wingdm32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    geebb.dll
    ddccc.dll

    Next double click on explorer.exe and again click once on each instance of wingdm32.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    ageebb.dll
    ddccc.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;<local>
    O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher 2006\SCActiveBlock.dll (file missing)
    O2 - BHO: (no name) - {47844552-8D1A-4722-A79E-1CB68C84D9A5} - (no file)
    O2 - BHO: (no name) - {4D7FED26-DBF5-47C4-B1DB-140D7620C595} - C:\WINDOWS\system32\geebb.dll
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O20 - Winlogon Notify: ddccc - C:\WINDOWS\system32\ddccc.dll (file missing)
    O20 - Winlogon Notify: geebb - C:\WINDOWS\system32\geebb.dll
    O20 - Winlogon Notify: wingdm32 - C:\WINDOWS\SYSTEM32\wingdm32.dll
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    del %windir%\temp\win*.*
    exit


    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\Program Files\Common Files\{C469DF28-0AE9-1033-0621-05122005003d}\Update.exe
    C:\WINDOWS\system32\geebb.dll
    C:\WINDOWS\system32\wingdm32.dll
    C:\WINDOWS\system32\bbeeg.ini
    C:\WINDOWS\system32\cccdd.ini

    If Killbox does not reboot or if you get a Pending Operations type error message just click OK to continue and then just reboot your PC yourself.


    After reboot locat the below folder and delete it if found:
    C:\Program Files\Common Files\{C469DF28-0AE9-1033-0621-05122005003d}

    Now attach a new HJT log and tell me how the steps went.

    Also attach a new log from ShowNew and a new log from GetRunKey.

    Make sure you tell me how things are working now!
     
    Last edited: Aug 12, 2006
  16. doofy

    doofy Private E-2

    Hi there Chaslang,

    My apologies for bumping the thread. I had no idea about working last to first.

    I saw that you had replied to others and thought you must have missed mine so again my apologies.

    Here is the spybot sd log.

    Spybot was installed on my compter however after reading you last post I went and had a look in the add removed prgrams and it was not there. I un installed it via the option in start>programs>spybot. I then re installed it and it is now in the add remove program files.

    here is the log.

    I will now go on to do the other stuff you listed.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I knew something had to be wrong with the Spybot installation. When you finish the other steps, make sure you attach all three logs as requested at the end of my message.
     
  18. doofy

    doofy Private E-2

    Hi there,

    Ok I have done all of the last list of things.

    The system is still running rather sluggish and startup apps are very slow to start.

    Throughout the process there wqere a few files that I was unable to find in the prcessxp and also again in the hijackthis, however having looked at the hjt scan it looked as if some of the files were there but they had changed the number from the ones you listed, they were all in the system 32 folder. I did not delete them as I did not know what it would do.

    So I will ask you what to do here

    Another things that is happening, i dont know if it is the microsft update or not. throught all of this and also just now I have the little yellow sheild popping up in the task bar saying it is downloading updates and then asking me to restart. After having those little green and blue sheilds install them selves on my desktop the other day I dont know if I trust this.

    I will let you look at the logs for all and decide for your self.

    Also is the fixme.rg file ok to delete from the desktop?

    The finishing scan logs are all below for you.

    Thanks for your help
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Like what file names exactly are you referring too?

    After I look at your logs, I will let you know if there are any visible malware problems.

    Yes!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now please download The Avenger by Swandog46 to your Desktop.
    • Double click on Avenger.zip to open the file and extract avenger.exe to your Desktop
    • Copy the below quoted text (which is a script for Avenger) into your clipboard by highlighting it and pressing
      CTRL+C
    Now, run The Avenger program by double clicking its icon on your Desktop.
    • Under "Script file to execute" choose "Input Script Manually".
    • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
    • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
    • Click Done
    • Now click on the Green Light to begin execution of the script
    • Answer "Yes" twice when prompted.
    The Avenger will automatically do the following:
    • It will Restart your computer. (When the script being executed contains "Drivers to Unload",
      The Avenger will actually reboot your system two times.)
    • On reboot, it will briefly open a black command window on your desktop, this is normal.
    • After the reboot, it creates a log file that should open with the results of Avenger’s actions. This log
      file will be located at C:\avenger.txt
    • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped
      them and moved the zip archives to C:\avenger\backup.zip.
    Please attach the c:\avenger.txt file to your next message.


    Now run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {A30B1E93-BECA-4C64-A6C7-D4117617BB57} - C:\WINDOWS\system32\ddccc.dll (file missing)
    O20 - AppInit_DLLs: C:\WINDOWS\system32\logonui.dll
    O20 - Winlogon Notify: wingdm32 - wingdm32.dll (file missing)

    Note that the O20 AppInit_DLLs line should hopefully already be gone from running Avenger.


    After clicking Fix, exit HJT.Now reboot in normal mode and post a new HJT log.

    Also attach a new log from ShowNew.

    Make sure you tell me how things are working now.
     
    Last edited: Aug 13, 2006
  21. doofy

    doofy Private E-2

    ok that is that batch of stuff done.

    the files that I was refering to earlier are files that you said not to worry about if they were not there and continue.

    The second file from hjt is no longer there anymore.

    Here is the logs. I have done 2 hjt logs. 1 is from before I fixed and the second is after.
     

    Attached Files:

  22. doofy

    doofy Private E-2

    and hjt after the fix.
     

    Attached Files:

  23. doofy

    doofy Private E-2

    The system seems to be running a bit faster now with start up apps loading faster and this includes the nortons.

    I dont know about any pop ups as yet. I had one earlier just before I started the fixes but as of yet I have not seen one. will wait and see.

    cheers.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to delete the below files if found:
    C:\WINDOWS\system32\logonui.dll
    C:\WINDOWS\system32\wnscpit.exe


    After that, if you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  25. doofy

    doofy Private E-2

    Hi there chaslang,

    Ok I have deleted those 2 files the first one went without a problem but the second one would not delete because it was being used by another program so used killbox and set it to delete the winscpit file on reboot, I can no longer find the file however my pc is running slower than it was with the malware on it now after deleting thos 2 files.

    Any ideas.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The file name was wnscpit.exe Is this what you deleted or was it some other file name?

    There is no reason that it would run slower after removing the malware. Did you start running the How to protect thread yet? If so, how far have you gotten.

    Attach a new log from ShowNew and also a new log from HJT.
     
  27. doofy

    doofy Private E-2

    Hi there chaslang.

    The file I deleted was the file wnscpit.exe. I searched for it with the search option and put in the whole path so I new it was the one to delete but for some reason it was being used by another application and could not be deleted. So like I said I used killbox and deleted it on reboot and it is now gone.

    I put an i in the file name on my last post thinking it was win instead of wn.

    Everything that was on the malware protection thread I already have or is already set up. The only thing that I did not have was firefox and I now am using that and enjoying it a lot better than explorer.

    My antivirus is nortons with a nortons firewall built in.

    I have adware with the vx2 cleaner and spybot sd and windows defender prior to my posting here.

    I have sun java.

    My avtive x or what ever it is called was allready on the setting you stated.

    so everything is fine in that sense and pretty much malware bulletproof.

    I ran spybot and adware after your last post just to be sure and they picked up nothing.

    Here are the logs for you. hopefully there is nothing there. I think I have waisted enought of your time for now.

    Thanks for the help.
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean!
     
  29. doofy

    doofy Private E-2

    Thanks for the help Chaslang.

    You have been great.

    Cheers Mate.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds