Persistent winlogonhook

Discussion in 'Malware Help (A Specialist Will Reply)' started by spinynorman, Jul 13, 2006.

  1. spinynorman

    spinynorman Private E-2

    Hi, I'm having trouble removing winlogonhook as reported by Webrootspysweeper beta ver 5.
    trojan agent winlogonhook - HKLM\software\microsoft\mssmgr\

    Whilst trying to remove it I have come across a number of other trojans adware etc. I think I have cleared most of them other than winlogonhook but would really appreciate some assurance. I have tried the sticky thread removal process unsuccessfully. I have completed the READ & RUN ME FIRST. Please review my attached logs.

    Spiny
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    We will try to fix this based on the info posted but you may have some other hidden files that we will need to locate and remove. We will know after doing the below fixes.

    First a couple questions:
    - Is your copy of Spy Sweeper a free trial or a paid version?
    - Is your copy of Ewido a free trial or a paid version?

    - Do you know what the below is? No valid program should be installed like this!
    O23 - Service: Firebird Guardian Service (InterBaseGuardian) - Unknown owner - C:\Program.exe (file missing)
    O23 - Service: Firebird Server (InterBaseServer) - Unknown owner - C:\Program.exe (file missing)


    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winrnt32.dll once and then click the kill button. After you have killed all of the winrnt32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of winrnt32.dll and kill it. (If you do not find the dll, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [msci] C:\DOCUME~1\Andrew\LOCALS~1\Temp\2005928221948_mcinfo.exe /insfin
    O4 - HKLM\..\Run: [Cleanup] C:\DOCUME~1\Andrew\LOCALS~1\Temp\2005928221948_mcappins.exe /v=3 /cleanup
    O16 - DPF: {00000000-0000-0000-0000-100005000004} - http://code.trasferimento.biz/l/7dd04dc3de26103658885564207478a3_35.exe
    O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
    O20 - Winlogon Notify: winrnt32 - winrnt32.dll (file missing)


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    del %windir%\temp\win*.*
    exit


    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.
    C:\WINDOWS\SYSTEM32\winrnt32.dll

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot, use Windows Explore to delete ALL files in the below folder:
    C:\Documents and Settings\Andrew\Local Settings\Temp <--- note that Windows will have a few of these files in use and you cannot delete them. Just work around them and delete the rest.

    Now attach a new HJT log and tell me how the steps went.

    Now Run the below procedure and attach the newfiles.txt log.

    Make sure you tell me how things are working now!
     
  3. spinynorman

    spinynorman Private E-2

    Chaslang,

    Thanks very much for your help.

    In response to your questions:
    Both spysweeper and Ewido are trial versions.
    Firebird is part of a program called Ezijobs. I think it Firebird looked after the authentication/licensing process. I havent used it in ages and dont need it anymore so have uninstalled it.

    Process explorer did not find any instances of winrnt32.dll.

    I followed your instructions and have attached the HJT log and newfiles.
    Note, shownew.bat didn't like running in windows, I just kept clicking ignore until it got through.
    I also attached a copy of my latest Spy Sweeper log as it still finds instances of winlogonhook and now conhook.

    The pc seems to be running ok but I'm worried that it is still not clean and that some keylogger is going to come along and spook me.

    regards
    spiny
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you would be better off uninstalling them since they expire after the trial period. That is unless you plan on buying ONE of them. You have Windows Defender installed now as you active protection and you only want one such tool installed. To run multiple tools will eat up to many system resources, slow your system down, and could cause conflicts with each other.

    You have a problem in your OS and some files are missing. Do one of the below based on which version Win XP you have.

    For Windows XP Pro: download and run XPproFix
    For Windows XP Home: download and run XPHomeFix

    Then run ShowNew again and attach a new log. I need this to locate the hidden problems related to winlogonhook/conhook that Spy Sweeper will not fix even though they say they do.

    I see some Symantec antivirus or internet security software still running but you have Bitdefender now. The below is what I see:

    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    Did you have Symantec and uninstall it? Make sure ALL of it is uninstalled. We may need to remove this service manually.
     
  5. spinynorman

    spinynorman Private E-2

    Cool, XPprofix worked; new logs attached.

    I did have Norton Internet Security and uninstalled it via Control Panel. There are no files left in the Symantec directory. How do I uninstall the service manually?

    I will remove Ewido and Spysweeper once I have the current problem fixed. I originally downloaded them to try some of the fixes mentioned elsewhere.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Symantec Core LC ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Symantec Core LC

    If you receive any error messages just ignore them and continue.

    Now exit HJT and reboot when it tells you it needs to.

    After reboot, make sure the below line is no longer showing in HJT! If it shows, try fixing it:

    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


    Locate the below files and delete them! Tell me if you have any problems deleting any of these.
    C:\WINDOWS\SYSTEM32\clci.exe
    C:\WINDOWS\SYSTEM32\ssprs.dll
    C:\WINDOWS\SYSTEM32\oqtwa.tmp
    C:\WINDOWS\SYSTEM32\ghkmp.ini
    C:\WINDOWS\SYSTEM32\oqtwa.ini
    C:\WINDOWS\SYSTEM32\oqtwa.ini2
     
  7. spinynorman

    spinynorman Private E-2

    Wow!! I think you've fixed it.

    After following your above instructions the line below no longer appeared in the HJT log.
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    Clci.exe and ssprs.dll deleted ok.
    oqtwa.* and ghkmp.ini were nowhere to be found.

    I then ran another Webroot Spysweeper and there was no further evidence of winlogonhook or conhook.

    Thanks a heap, I really appreciate you being so helpful.

    Is now the time to disable Windows' system restore feature?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds