winlogonhook & trojan-downloader-zlob

Discussion in 'Malware Help (A Specialist Will Reply)' started by wsudman, Mar 19, 2006.

  1. wsudman

    wsudman Private E-2

    I have these on my computer and have been trying to get rid of them all day. Have run spysweeper in safe, spybot, ad aware, cleanup, ccleaner, spyware blaster. Please help
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.



    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. wsudman

    wsudman Private E-2

    here is the log file
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's is not what I asked for. Please follow ALL the directions in my previous message. You MUST run the READ & RUN ME FIRST Before Asking for Support sticky thread steps.

    Also answer a question! Do you know what the below it?
    C:\Program Files\ABC\abc.exe
     
  5. wsudman

    wsudman Private E-2

    Here are the rest
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I repeat my question:
    Let's start by running the below procedure (note: you do not need to run the PandaActiveScan step given at the end):

    SpywareStrike, Smitfraud, SpySheriff, SpyAxe & PSGuard Removal

    Make sure you attach the smitfiles.txt log.
     
  7. wsudman

    wsudman Private E-2

    It is a bit torrent downloader
     
  8. wsudman

    wsudman Private E-2

    Here is the smittext file
     

    Attached Files:

  9. wsudman

    wsudman Private E-2

    I'm also having another problem. Getting rid of the virus may fix it I don't know.

    My DVD Burner ...Plextor PX 740A... is not working properly. It is working extremely slow. I opened procexp.exe while running it and IRQ's are using over 80% of the cpu. I looked to see if I had two devices with the same IRQ # but everything is fine. I have also updated the firmware for the dvd burner from plextors website. Please tell me if you have any suggestions.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I doubt it is related to malware and you may be better off asking about this in the Harware Forum, but one thing to check is to make sure DMA is enabled for the IDE controller that the burner is connected to. Quite often the interface reverts back to PIO mode and this will slow down the burner.

    Your CounterSpy log shows the below. Did you install this yourself?
    If not, look in Add/Remove programs for RAdmin or radmin or Radmin22 or Remote Administrator Service and uninstall if found. Let me know what you find and if you did or did not install this.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's continue with fixing your other outstanding problems.

    Let's download two tools we will need:

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winvll32.dll once and then click the kill button. After you have killed all of the winvll32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of winvll32.dll and kill it.

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O20 - Winlogon Notify: winepi32 - winepi32.dll (file missing)
    O20 - Winlogon Notify: winvll32 - C:\WINDOWS\SYSTEM32\winvll32.dll



    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.
    C:\WINDOWS\Downloaded Program Files\CONFLICT.1\YazzleActiveX.ocx
    C:\WINDOWS\Downloaded Program Files\YazzleActiveX.ocx
    C:\WINDOWS\system32\mssearchnet.exe
    C:\WINDOWS\system32\nvctrl.exe
    C:\WINDOWS\system32\ginuerep.dll
    C:\WINDOWS\system32\ywtr.dll
    C:\WINDOWS\SYSTEM32\winvll32.dll


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot don't run anything else until you do the below.

    Locate the below with Windows Explorer and delete them (most of them should already be gone but we need to double check)
    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6EHHRJDQ\support[1].php
    C:\WINDOWS\system32\1024\ldF75.tmp
    C:\WINDOWS\system32\ginuerep.dll
    C:\WINDOWS\system32\mssearchnet.exe
    C:\WINDOWS\system32\nvctrl.exe
    C:\WINDOWS\system32\ot.ico
    C:\WINDOWS\system32\ywtr.dll
    C:\WINDOWS\SYSTEM32\winvll32.dll
    C:\WINDOWS\TEMP\win3A1.tmp.exe <-- it would be best to delete all files in this temp folder


    Now attach a new HJT log here in your next message and tell me how the steps went.

    Also make sure you tell me how things are working now!
     
  12. wsudman

    wsudman Private E-2

    Trojan downloader & winlogonhook are still detected w/ spysweeper. Here is the hjt file.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have not answered my question about the below yet.
    Have HijackThis fix the below two lines:

    O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} (YazzleActiveX Control) - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
    O20 - Winlogon Notify: winvll32 - winvll32.dll (file missing)


    Reboot and run a new scan with Spy Sweeper and save the log and attach it.
     
  14. wsudman

    wsudman Private E-2

    I installed radmin. It's for my LAN. The port it utilizes is shut off at the router. Spysweeper still detected the same thing. Here is the log
     
  15. wsudman

    wsudman Private E-2

    Sorry forgot to attatch
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use Windows Explorer to look in your c:\windows\system32 folder. Tell me if you see the below file. Also tell me the file size and date:

    dfrgsrv.exe
     
  17. wsudman

    wsudman Private E-2

    There Is No Such File
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay here is what I want you to do. Print or save these steps to a notepad file locally to refer to if necessary because ALL browsers (including this one) must be closed when you do the following.
    • Run Spy Sweeper but do not start a scan yet.
    • Close ALL browser sessions and exit any other programs that are running except SpySweeper (and notepad if you needed it).
    • Open Task Manager by pressing CTRL-SHIFT-ESC.
    • In Task Manager's Process list, locate explorer.exe. Right click on it and select Kill process tree. Do not be alarmed! This will make your Desktop with icons disappear. It is only temporary.
    • Now run a full scan with Spy Sweeper and save a new log.
    • Now in Task Manager click File, New Task (Run...) and enter explorer.exe and click OK. Your Desktop should come back
    • Now attach the new Spy Sweeper log here.
    • Now reboot and run a new Spy Sweeper scan and tell me if it still finds the problem (yes that is two scans with SpySweeper, one to hopefully fix, and one to make sure it fixed).
    • If it does still find a problem, continue with the below Ewido scan and attach the Ewido log: Running Ewido Anti-Malware
     
  19. wsudman

    wsudman Private E-2

    Spysweeper is in the explore.exe process tree. How exactly am I supposed to run it?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that! It was a cut and paste type from a similar procedure I wrote. I forgot to change it to just End Process instead of End process tree (actually I said Kill instead of End too)
     
  21. wsudman

    wsudman Private E-2

    Viruses are gone!!! Thankyou. It also fixed the problem with the dvd burner. Thanks again
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not post the spysweeper log (or Ewido if you ran it).

    Also I would like to see a hopefully final HJT log.
     
  23. wsudman

    wsudman Private E-2

    Here are the log files
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it looks like shutting down Explorer allowed Spy Sweeper to really fix the problem.

    I see the below:

    C:\WINDOWS\System32\r_server.exe
    O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\System32\r_server.exe" /service (file missing)

    Are they part of the Remote Admin package you install. If so, just double check to make sure the C:\WINDOWS\System32\r_server.exe file is not missing. HijackThis will often shows these file as missing when they are not.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds