winlogonhook is the bane of my existence

Discussion in 'Malware Help (A Specialist Will Reply)' started by brz, Apr 4, 2006.

  1. brz

    brz Private E-2

    here's the deal: I've followed the Winlogonhook Removal Procedure, read and performed multiple malware removal "Read Me's" and scanned my infected office PC with Ewido Security Suite (have had that for almost a year now), Ad-Aware (had that for a while too), Spybot (also had that prior to this virus fiasco), TrojanHunter and online scanners like Panda and Trend Housecall. I've gone in and out of regedit looking for rogue entries, booted and rebooted in Safe Mode, Normal Mode, you name it. I've read other posts on this topic (here and in other forums) and tried applying it to my situation [e.g. tried to "fix/delete" 'O20 - Winlogon Notify: winjrd32 - winjrd32.dll (file missing)' in the HT log below but it keeps reappearing]. I think I've tried everything a layperson can do to kill this thing on my own. But always, in the end, Spy Sweeper finds this "winlogonhook" and says it's a trojan horse.

    Attached is my most recent HT log (not done in Safe Mode - wasn't sure if it should be in Normal or Safe) and my Spy Sweeper logfile from the past few scans (which were done yesterday and today between scans with other software like ewido and trojanhunter etc). can someone please help? I need a little one-on-one attention with this.

    Oh and you also might want to know that this nasty 'winlogonhook' seems to be a direct after-effect / side-effect of a recent run-in I had with SpywareQuake, SpywareStrike, and WinFixer which I think/thought I had successfully removed a few days ago (though maybe not completely?). thanks in advance.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Did you actually run a Spy Sweeper scan with explorer.exe shutdown with no Desktop showing?

    Is the below something you configured?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = fakeproxy


    Is your copy of Spy Sweeper the free trial or a paid version? When did you install Windows Defender? Before or after first trying to remove the Winlogonhook problem?

    You did not attach the Ewido log as requested and we did not request a HijackThis log. HJT logs are only accpeted after the READ & RUN ME sticky has been run.
     
  3. brz

    brz Private E-2

    yes. I believe it was Spy Sweeper. but that was a few days ago. should I do it again?

    yes. because I was having problems with an 'ActiveX controls' box that kept popping up at random times, and something I read somewhere said that configuring my IE proxy that way (in IE preferences) might help. I never use Internet Explorer.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, those steps must be followed exactly. You must end the Explorer.exe process which blanks the Desktop while running the scan.

    Did it do anything for you? You will need to use Internet Explorer sometimes. Some websites require it and you cannot get your updates from Microsoft without IE.
     
  5. brz

    brz Private E-2

    oops.. here's the rest
    paid subscriber
    not sure. it was recently. I think it might've been when I was tackling those other malware issues - when I was doing one of those Read Me / Removal procedures, but I can't be sure of the exact date.
    I did the READ & RUN ME (I've done so many damn Read & Run Me's it's ridiculous). see attached Ewido log. thanks for your help so far.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you did not do the READ & RUN ME. If you had, you would have attached to logs from the online scanners in step 6 which were not run accoring to your HJT log.
     
  7. brz

    brz Private E-2

    yeah but I already did it at least once, and it obviously didn't help.

    I'm not getting the ActiveX warnings anymore, and I have it configured to not use the proxy server settings when accessing *.microsoft.com and *.webroot.com so I can get updates.
     
  8. brz

    brz Private E-2

    I did do it. I just didn't do it today and I didn't do it right before posting my HJT log. so I might've overlooked some stuff when starting this thread. sorry. look. I've been scouring so many of these forums and running so many different scans etc while also just trying to stay on top of my workload here and understand what is up with this 'trojan agent.' it's also not that easy to keep all this protocol for the different forums straight, and your READ & RUN isn't exactly the most articulate / easy to follow. all I know is that each of these removal processes hasn't worked so far. if you really want me to drop everything and run your READ & RUN ME right now, I will. so. doing it all again now.. thanks
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually the READ ME is quite easy to follow. It goes into great detail to explain things to the end user. That is part of the reason it is so long. But you did not run ALL of it. Step 6 was never run. If it was, the remnants from it would show in your log.

    What I want you to run is the Winlogon Removal Procedure exactly as it is written.
     
  10. brz

    brz Private E-2

    ok. amazing. I did it again, and this time no 'winlogonhook' showed up both times. but my question to you now is: do I need to do anything to prevent it from coming back before I shutdown/restart my computer? for instance - should I disable (then enable) system restore or anything like that? I mean. I just don't trust that it's really gone, so I'm probably going to run at least a couple more scans (Ewido scan and maybe another Spy Sweeper) to make sure, but first I want to make sure there isn't some special protocol I should follow first.

    and what about all this different malware-removal related software I have on my computer now - should I keep all of it? what should I have running on a regular basis? also, I'm suddenly (as of the last 3 hours) getting a 'windows security alert' that keeps saying I might not have antivirus software installed (?!) which seems ridiculous to me, since I haven't removed any programs, only added the recommended scanners and kept what I had before (because it was basic stuff like ewido, spybot and ad-aware). can you offer a quick word of advice on that or should I just go back to the forum(s) and look for clues?

    THANKS

    THANK YOU
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    You are more than likely all clean but just make sure the below three lines are deleted (fixed) using HijackThis if they still exist.
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgUS2404.exe
    O20 - Winlogon Notify: winjrd32 - winjrd32.dll (file missing)

    As far as what to keep goes, keep Spy Sweeper and uninstall MS Windows Defender and Ewido. The other tools mentioned in the READ ME should all be kept as they either do not use any resources (except when scanning) or the use very little resource and are worth having for additional scanners/cleaners.

    After fixing those lines with HJT and uninstalling Windows Defender and Ewido, reboot and attach a new HJT log.

    The messages from Windows Security Center you are getting may indicate some kind of problem with your Symantec application not working correctly. Perhaps you need to uninstall it, reboot, and reinstall it. Looks like it is supposed to be your Security Center and not Windows.
     
    Last edited: Apr 4, 2006
  12. brz

    brz Private E-2

    wait. delete Ewido? really? some tech guy gave me that last year and said "it's one of the best" and that I should have it. I paid for it. no? and should I be worried if this 'windows security alert' is suddenly telling me I don't seem to have antivirus software?
     
  13. brz

    brz Private E-2

    sorry. sorry. for some reason i'm not seeing your whole post and missing stuff at the bottom upon first read.. i see that part about the antivirus software now.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ewido is very good. Spy Sweeper is even better. But using both at the same time causes a drain of system resources. And since you bought Spy Sweeper, it is better to keep it. I assume you have no support for Ewido since you did not buy it. Thus you cannot update it.

    Re-read my last message. I was editing it when you came back online.
     
  15. brz

    brz Private E-2

    no i bought it too
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well then it is up to you what you want to do. If you do not mind the performance hit on your PC and also do not mind the potential conflict that can occur due to both of them trying to monitor for malware activities, then keep it. This is a similar problem to what can occur with multiple antivirus applications being installed.
     
  17. brz

    brz Private E-2

    can't I just disable one of them (like Spy Sweeper) so it's not running all the time but I still have it in case I need it?

    also, just to confirm: I don't need to do anything with 'System Restore' before rebooting and attaching that HJT log you requested?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That will not really work properly since services will still load. You would have to not only stop standard processes from loading, you would also have to stop the services from loading. You could try doing this using MSCONFIG but this will also result in you always booting in what is called Selective Startup mode. Again it's your decision based on what you want to live with and if you feel comfortable with. Personally I see no need for two similar full applications like this. I use the below and NEVER have any problems:
    • 1 antivirus (different PCs use a different AV for test purposes) Avast, AVG, Antivir, McAfee
    • 1 firewall (ZoneAlarm or Sygate on different PCs)
    • 1 full blocking/scanning/removal tool (Spy Sweeper, MS Windows Defender or MS Antispyware again on different PCs I use different apps)
    • and all of the below are always installed
      • SpywareBlaster with full protection
      • Spybot with SDhelper and Immunize (No Teatimer)
      • Ad-Aware SE (just for scanning)
    • my router also has a hardware firewall
    If you want to make sure you do not have infected restore points saved on your PC, you need to flush them by disabling System Restore. If for some reason you have restore points that you really think you need (even though they could have infections) do not flush them. You should have a pretty good idea yourself whether you think you really need any restore points that are currently on your system.
     
  19. brz

    brz Private E-2

    ok. cool. I deleted the HJT entries you mentioned. so now I'm going to close out of everything. disable System Restore. reboot. re-enable System Restore. run HJT. attach that log. then finally go home for the night (and eventually download one of those free antivirus applications tomorrow). thanks again for all your help with this.
     
  20. brz

    brz Private E-2

    see attached HJT log after "fix" and reboot.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but do not install one of those while you still have Symantec installed. You should download the one you want, then disconnect from the internet and uninstall Symantec. Then reboot and install the new antivirus and reconnect to the internet so it can get updates.
     
  22. brz

    brz Private E-2

    ok. but I'm not sure I even have Symantec. all I can find is Symantic Live Update but I'm not sure what it's updating (?) - if anything - or is that the name of their antivirus software? (sorry. this computer wasn't mine a year ago, so I can't vouch for its software history, and I'm not sure what kind of antivirus software it has on it right now)
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here is what you have from Symantec based on your HJT log.
    ccapp.exe is a process belonging to Norton AntiVirus. It is responsible for the auto-protect and email checking facilities. The running process is loaded by the O4 line containing the same file name.
    sndmon.exe is Symantec Net Driver Monitor and it relates to network security.
    symwsc.exe is a process belonging to the Symantec Security Center.


    Let's get an installed programs list from HijackThis!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds