![]() |
| ||
| 2 trojans reappear Hi, I am posting a result of a Malwarebytes scan. I have done it a few times over the last week or so, and these 2 Trjan.Agent reappear. I clean and remove them with Malwarebytes, but they ap[pear again at my next scan. Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\userinit.exe -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\userinit.exe -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) How can I get rid of them once and for all....or is it not necessary to touch them Thanks George p.s. am running Win XP pro SP3 |
| ||
| Re: 2 trojans reappear Please post a HiJackThis log. Judy |
| ||
| Re: 2 trojans reappear Userinit is normally a value [name] in the Winlogon key, and not a subkey of Winlogon. It's data entry would be C:\Windows\system32\userinit.exe Could you export and post that Winlogon key please [before you rerun MBAM]? |
| ||
| Re: 2 trojans reappear Hi, This is the hijack-this report, and I do not know how to post Winlogon info you request? Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 7:10:08 AM, on 12/4/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://excite.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe O23 - Service: VIPRE Antivirus + Antispyware (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe -- End of file - 1354 bytes |
| ||
| Re: 2 trojans reappear This will get the Winlogon key for us: ==Please copy the text in the box to a notepad [format/wordwrap unchecked] and save as showkey.bat to your desktop; dclick it to run, then post the file C:\showkey.txt reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /s >>C:\showkey.txt Post the notepad that opens. |
| ||
| Re: 2 trojans reappear Also: temporarialy disable system restore reboot run malwarebytes reboot re-enable system restore reboot yet again check again with malwarebytes trojans can keep reappearing because they can hide in the system restore folder |
| ||
| Re: 2 trojans reappear I hope this is what you needed? ! REG.EXE VERSION 3.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon AutoRestartShell REG_DWORD 0x1 DefaultDomainName REG_SZ GEORGE-6JXTPIR4 DefaultUserName REG_SZ George LegalNoticeCaption REG_SZ LegalNoticeText REG_SZ PowerdownAfterShutdown REG_SZ 0 ReportBootOk REG_SZ 1 Shell REG_SZ Explorer.exe ShutdownWithoutLogon REG_SZ 0 Userinit REG_SZ C:\WINDOWS\system32\userinit.exe, VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl" SfcQuota REG_DWORD 0xffffffff allocatecdroms REG_SZ 0 allocatedasd REG_SZ 0 allocatefloppies REG_SZ 0 cachedlogonscount REG_SZ 10 forceunlocklogon REG_DWORD 0x0 passwordexpirywarning REG_DWORD 0xe scremoveoption REG_SZ 0 AllowMultipleTSSessions REG_DWORD 0x1 UIHost REG_EXPAND_SZ logonui.exe LogonType REG_DWORD 0x1 Background REG_SZ 0 0 0 DebugServerCommand REG_SZ no SFCDisable REG_DWORD 0x0 WinStationsDisabled REG_SZ 0 HibernationPreviouslyEnabled REG_DWORD 0x1 ShowLogonOptions REG_DWORD 0x0 AltDefaultUserName REG_SZ George AltDefaultDomainName REG_SZ GEORGE-6JXTPIR4 AutoAdminLogon REG_SZ 0 System REG_SZ ChangePasswordUseKerberos REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63} <NO NAME> REG_SZ Wireless DllName REG_EXPAND_SZ gptext.dll NoGPOListChanges REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessWIRELESSPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861} <NO NAME> REG_SZ Folder Redirection ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx DllName REG_EXPAND_SZ fdeploy.dll NoMachinePolicy REG_DWORD 0x1 NoSlowLink REG_DWORD 0x1 PerUserLocalSettings REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x0 NoBackgroundPolicy REG_DWORD 0x0 GenerateGroupPolicy REG_SZ GenerateGroupPolicy EventSources REG_MULTI_SZ (Folder Redirection,Application)\0\0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} <NO NAME> REG_SZ Microsoft Disk Quota NoMachinePolicy REG_DWORD 0x0 NoUserPolicy REG_DWORD 0x1 NoSlowLink REG_DWORD 0x1 NoBackgroundPolicy REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 PerUserLocalSettings REG_DWORD 0x0 RequiresSuccessfulRegistry REG_DWORD 0x1 EnableAsynchronousProcessing REG_DWORD 0x0 DllName REG_EXPAND_SZ dskquota.dll ProcessGroupPolicy REG_SZ ProcessGroupPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39} <NO NAME> REG_SZ QoS Packet Scheduler ProcessGroupPolicy REG_SZ ProcessPSCHEDPolicy DllName REG_EXPAND_SZ gptext.dll NoUserPolicy REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3} <NO NAME> REG_SZ Scripts ProcessGroupPolicy REG_SZ ProcessScriptsGroupPolicy ProcessGroupPolicyEx REG_SZ ProcessScriptsGroupPolicyEx GenerateGroupPolicy REG_SZ GenerateScriptsGroupPolicy DllName REG_EXPAND_SZ gptext.dll NoSlowLink REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 NotifyLinkTransition REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} <NO NAME> REG_SZ Internet Explorer Zonemapping DllName REG_EXPAND_SZ iedkcs32.dll ProcessGroupPolicy REG_SZ ProcessGroupPolicyForZoneMap NoGPOListChanges REG_DWORD 0x1 RequiresSucessfulRegistry REG_DWORD 0x1 DisplayName REG_EXPAND_SZ @iedkcs32.dll,-3051 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} ProcessGroupPolicy REG_SZ SceProcessSecurityPolicyGPO GenerateGroupPolicy REG_SZ SceGenerateGroupPolicy ExtensionRsopPlanningDebugLevel REG_DWORD 0x1 ProcessGroupPolicyEx REG_SZ SceProcessSecurityPolicyGPOEx ExtensionDebugLevel REG_DWORD 0x1 DllName REG_EXPAND_SZ scecli.dll <NO NAME> REG_SZ Security NoUserPolicy REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 EnableAsynchronousProcessing REG_DWORD 0x1 MaxNoGPOListChangesInterval REG_DWORD 0x3c0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx GenerateGroupPolicy REG_SZ GenerateGroupPolicy ProcessGroupPolicy REG_SZ ProcessGroupPolicy DllName REG_SZ iedkcs32.dll <NO NAME> REG_SZ Internet Explorer Branding NoSlowLink REG_DWORD 0x1 NoBackgroundPolicy REG_DWORD 0x0 NoGPOListChanges REG_DWORD 0x1 NoMachinePolicy REG_DWORD 0x1 DisplayName REG_EXPAND_SZ @iedkcs32.dll,-3014 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A} ProcessGroupPolicy REG_SZ SceProcessEFSRecoveryGPO DllName REG_EXPAND_SZ scecli.dll <NO NAME> REG_SZ EFS recovery NoUserPolicy REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053} <NO NAME> REG_SZ 802.3 Group Policy DisplayName REG_EXPAND_SZ @dot3gpclnt.dll,-100 ProcessGroupPolicyEx REG_SZ ProcessLANPolicyEx GenerateGroupPolicy REG_SZ GenerateLANPolicy DllName REG_EXPAND_SZ dot3gpclnt.dll NoUserPolicy REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} <NO NAME> REG_SZ Microsoft Offline Files DllName REG_EXPAND_SZ %SystemRoot%\System32\cscui.dll EnableAsynchronousProcessing REG_DWORD 0x0 NoBackgroundPolicy REG_DWORD 0x0 NoGPOListChanges REG_DWORD 0x0 NoMachinePolicy REG_DWORD 0x0 NoSlowLink REG_DWORD 0x0 NoUserPolicy REG_DWORD 0x1 PerUserLocalSettings REG_DWORD 0x0 ProcessGroupPolicy REG_SZ ProcessGroupPolicy RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} <NO NAME> REG_SZ Software Installation DllName REG_EXPAND_SZ appmgmts.dll ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyObjectsEx GenerateGroupPolicy REG_SZ GenerateGroupPolicy NoBackgroundPolicy REG_DWORD 0x0 RequiresSucessfulRegistry REG_DWORD 0x0 NoSlowLink REG_DWORD 0x1 PerUserLocalSettings REG_DWORD 0x1 EventSources REG_MULTI_SZ (Application Management,Application)\0(MsiInstaller,Application)\0\0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27} <NO NAME> REG_SZ IP Security ProcessGroupPolicy REG_SZ ProcessIPSECPolicy DllName REG_EXPAND_SZ gptext.dll NoUserPolicy REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain Asynchronous REG_DWORD 0x0 Impersonate REG_DWORD 0x0 DllName REG_EXPAND_SZ crypt32.dll Logoff REG_SZ ChainWlxLogoffEvent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet Asynchronous REG_DWORD 0x0 Impersonate REG_DWORD 0x0 DllName REG_EXPAND_SZ cryptnet.dll Logoff REG_SZ CryptnetWlxLogoffEvent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll DLLName REG_SZ cscdll.dll Logon REG_SZ WinlogonLogonEvent Logoff REG_SZ WinlogonLogoffEvent ScreenSaver REG_SZ WinlogonScreenSaverEvent Startup REG_SZ WinlogonStartupEvent Shutdown REG_SZ WinlogonShutdownEvent StartShell REG_SZ WinlogonStartShellEvent Impersonate REG_DWORD 0x0 Asynchronous REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy Asynchronous REG_DWORD 0x1 DllName REG_EXPAND_SZ %SystemRoot%\System32\dimsntfy.dll Startup REG_SZ WlDimsStartup Shutdown REG_SZ WlDimsShutdown Logon REG_SZ WlDimsLogon Logoff REG_SZ WlDimsLogoff StartShell REG_SZ WlDimsStartShell Lock REG_SZ WlDimsLock Unlock REG_SZ WlDimsUnlock HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp DLLName REG_SZ wlnotify.dll Logon REG_SZ SCardStartCertProp Logoff REG_SZ SCardStopCertProp Lock REG_SZ SCardSuspendCertProp Unlock REG_SZ SCardResumeCertProp Enabled REG_DWORD 0x1 Impersonate REG_DWORD 0x1 Asynchronous REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule Asynchronous REG_DWORD 0x0 DllName REG_EXPAND_SZ wlnotify.dll Impersonate REG_DWORD 0x0 StartShell REG_SZ SchedStartShell Logoff REG_SZ SchedEventLogOff HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy Logoff REG_SZ WLEventLogoff Impersonate REG_DWORD 0x0 Asynchronous REG_DWORD 0x1 DllName REG_EXPAND_SZ sclgntfy.dll HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn DLLName REG_SZ WlNotify.dll Lock REG_SZ SensLockEvent Logon REG_SZ SensLogonEvent Logoff REG_SZ SensLogoffEvent Safe REG_DWORD 0x1 MaxWait REG_DWORD 0x258 StartScreenSaver REG_SZ SensStartScreenSaverEvent StopScreenSaver REG_SZ SensStopScreenSaverEvent Startup REG_SZ SensStartupEvent Shutdown REG_SZ SensShutdownEvent StartShell REG_SZ SensStartShellEvent PostShell REG_SZ SensPostShellEvent Disconnect REG_SZ SensDisconnectEvent Reconnect REG_SZ SensReconnectEvent Unlock REG_SZ SensUnlockEvent Impersonate REG_DWORD 0x1 Asynchronous REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv Asynchronous REG_DWORD 0x0 DllName REG_EXPAND_SZ wlnotify.dll Impersonate REG_DWORD 0x0 Logoff REG_SZ TSEventLogoff Logon REG_SZ TSEventLogon PostShell REG_SZ TSEventPostShell Shutdown REG_SZ TSEventShutdown StartShell REG_SZ TSEventStartShell Startup REG_SZ TSEventStartup MaxWait REG_DWORD 0x258 Reconnect REG_SZ TSEventReconnect Disconnect REG_SZ TSEventDisconnect HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon EulaAccepted REG_DWORD 0x0 Logon REG_SZ WLEventLogon Logoff REG_SZ WLEventLogoff Startup REG_SZ WLEventStartup Shutdown REG_SZ WLEventShutdown StartScreenSaver REG_SZ WLEventStartScreenSaver StopScreenSaver REG_SZ WLEventStopScreenSaver Lock REG_SZ WLEventLock Unlock REG_SZ WLEventUnlock StartShell REG_SZ WLEventStartShell PostShell REG_SZ WLEventPostShell Disconnect REG_SZ WLEventDisconnect Reconnect REG_SZ WLEventReconnect Impersonate REG_DWORD 0x1 Asynchronous REG_DWORD 0x0 SafeMode REG_DWORD 0x1 MaxWait REG_DWORD 0xffffffff DllName REG_EXPAND_SZ WgaLogon.dll Event REG_DWORD 0x0 InstallEvent REG_SZ 1.8.0031.9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings <NO NAME> REG_SZ Data REG_BINARY 01000000D08C9DDF0115D1118C7A00C04FC297EB010000009D9AFB1981461847A55F9F7C217A259604000000040000005300000003660000A800000010000000213DCF555732C840E3BA3E3E38183DA30000000004800000A000000010000000C6439CBFD7DBEF0EA8026F6615105265B0010000363F58BD84F18013DCDF01155251F01D37114B39153A90ABB3CE42CA8C48943C02D4E0329BCDA00D62C8E475C068AB0105324528432E35A3847893010423D1AE4F326ECD2DBFA84262C34F99FF49871622077AC74652160300B4F4833FDE4721F581F4C71D8574CFA10C5464BE50197A46A3E9CB34513DFFA6A0ABD95AFAC2C11D88F809222F4B16C9CB89447CC82289406949E93FBF08F6C1C9E8310024ACEFC2437D87B12C3B02AA47B57A7D1B888A18337D67172FF3A99560CCF2F0FC2577F23979A331D4103209589E0F4E4539B1D613A74CD71AD89DBE01411A23BC9A95D878C346F23CD7CD010F37FFAC9103B7AAAA61F7B5A063F96D973A3924A4EAED1CD5B1E0411AD07082BCE83DD1054AA03AED75740BBAB26A050A7BFBF70295B96FD3946EE830416555D2AFA2E1F16D88A71485D748922EF39E0999055509E9EB48965F52A06819CA01287355BEA152E2E181427465DB333BEFEBE6C092CDD74F47FDEC8F08A6CE7A041C810EC89CBFEF0A57A24A4DBB776858B4A627C361A07D6C5230158B2619B369625737EB6EB73A6175C420C44224D29F4199920D425D341FD1A17AC72C2371E4FE3151D259FE2F14000000ADC7218640ADD34D0637E9D2338745CBC08548B5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon DLLName REG_SZ wlnotify.dll Logon REG_SZ RegisterTicketExpiredNotificationEvent Logoff REG_SZ UnregisterTicketExpiredNotificationEvent Impersonate REG_DWORD 0x1 Asynchronous REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList HelpAssistant REG_DWORD 0x0 TsInternetUser REG_DWORD 0x0 SQLAgentCmdExec REG_DWORD 0x0 NetShowServices REG_DWORD 0x0 IWAM_ REG_DWORD 0x10000 IUSR_ REG_DWORD 0x10000 VUSR_ REG_DWORD 0x10000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Credentials ! REG.EXE VERSION 3.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon AutoRestartShell REG_DWORD 0x1 DefaultDomainName REG_SZ GEORGE-6JXTPIR4 DefaultUserName REG_SZ George LegalNoticeCaption REG_SZ LegalNoticeText REG_SZ PowerdownAfterShutdown REG_SZ 0 ReportBootOk REG_SZ 1 Shell REG_SZ Explorer.exe ShutdownWithoutLogon REG_SZ 0 Userinit REG_SZ C:\WINDOWS\system32\userinit.exe, VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl" SfcQuota REG_DWORD 0xffffffff allocatecdroms REG_SZ 0 allocatedasd REG_SZ 0 allocatefloppies REG_SZ 0 cachedlogonscount REG_SZ 10 forceunlocklogon REG_DWORD 0x0 passwordexpirywarning REG_DWORD 0xe scremoveoption REG_SZ 0 AllowMultipleTSSessions REG_DWORD 0x1 UIHost REG_EXPAND_SZ logonui.exe LogonType REG_DWORD 0x1 Background REG_SZ 0 0 0 DebugServerCommand REG_SZ no SFCDisable REG_DWORD 0x0 WinStationsDisabled REG_SZ 0 HibernationPreviouslyEnabled REG_DWORD 0x1 ShowLogonOptions REG_DWORD 0x0 AltDefaultUserName REG_SZ George AltDefaultDomainName REG_SZ GEORGE-6JXTPIR4 AutoAdminLogon REG_SZ 0 System REG_SZ ChangePasswordUseKerberos REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63} <NO NAME> REG_SZ Wireless DllName REG_EXPAND_SZ gptext.dll NoGPOListChanges REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessWIRELESSPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861} <NO NAME> REG_SZ Folder Redirection ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx DllName REG_EXPAND_SZ fdeploy.dll NoMachinePolicy REG_DWORD 0x1 NoSlowLink REG_DWORD 0x1 PerUserLocalSettings REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x0 NoBackgroundPolicy REG_DWORD 0x0 GenerateGroupPolicy REG_SZ GenerateGroupPolicy EventSources REG_MULTI_SZ (Folder Redirection,Application)\0\0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} <NO NAME> REG_SZ Microsoft Disk Quota NoMachinePolicy REG_DWORD 0x0 NoUserPolicy REG_DWORD 0x1 NoSlowLink REG_DWORD 0x1 NoBackgroundPolicy REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 PerUserLocalSettings REG_DWORD 0x0 RequiresSuccessfulRegistry REG_DWORD 0x1 EnableAsynchronousProcessing REG_DWORD 0x0 DllName REG_EXPAND_SZ dskquota.dll ProcessGroupPolicy REG_SZ ProcessGroupPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39} <NO NAME> REG_SZ QoS Packet Scheduler ProcessGroupPolicy REG_SZ ProcessPSCHEDPolicy DllName REG_EXPAND_SZ gptext.dll NoUserPolicy REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3} <NO NAME> REG_SZ Scripts ProcessGroupPolicy REG_SZ ProcessScriptsGroupPolicy ProcessGroupPolicyEx REG_SZ ProcessScriptsGroupPolicyEx GenerateGroupPolicy REG_SZ GenerateScriptsGroupPolicy DllName REG_EXPAND_SZ gptext.dll NoSlowLink REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 NotifyLinkTransition REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} <NO NAME> REG_SZ Internet Explorer Zonemapping DllName REG_EXPAND_SZ iedkcs32.dll ProcessGroupPolicy REG_SZ ProcessGroupPolicyForZoneMap NoGPOListChanges REG_DWORD 0x1 RequiresSucessfulRegistry REG_DWORD 0x1 DisplayName REG_EXPAND_SZ @iedkcs32.dll,-3051 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} ProcessGroupPolicy REG_SZ SceProcessSecurityPolicyGPO GenerateGroupPolicy REG_SZ SceGenerateGroupPolicy ExtensionRsopPlanningDebugLevel REG_DWORD 0x1 ProcessGroupPolicyEx REG_SZ SceProcessSecurityPolicyGPOEx ExtensionDebugLevel REG_DWORD 0x1 DllName REG_EXPAND_SZ scecli.dll <NO NAME> REG_SZ Security NoUserPolicy REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 EnableAsynchronousProcessing REG_DWORD 0x1 MaxNoGPOListChangesInterval REG_DWORD 0x3c0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx GenerateGroupPolicy REG_SZ GenerateGroupPolicy ProcessGroupPolicy REG_SZ ProcessGroupPolicy DllName REG_SZ iedkcs32.dll <NO NAME> REG_SZ Internet Explorer Branding NoSlowLink REG_DWORD 0x1 NoBackgroundPolicy REG_DWORD 0x0 NoGPOListChanges REG_DWORD 0x1 NoMachinePolicy REG_DWORD 0x1 DisplayName REG_EXPAND_SZ @iedkcs32.dll,-3014 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A} ProcessGroupPolicy REG_SZ SceProcessEFSRecoveryGPO DllName REG_EXPAND_SZ scecli.dll <NO NAME> REG_SZ EFS recovery NoUserPolicy REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053} <NO NAME> REG_SZ 802.3 Group Policy DisplayName REG_EXPAND_SZ @dot3gpclnt.dll,-100 ProcessGroupPolicyEx REG_SZ ProcessLANPolicyEx GenerateGroupPolicy REG_SZ GenerateLANPolicy DllName REG_EXPAND_SZ dot3gpclnt.dll NoUserPolicy REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} <NO NAME> REG_SZ Microsoft Offline Files DllName REG_EXPAND_SZ %SystemRoot%\System32\cscui.dll EnableAsynchronousProcessing REG_DWORD 0x0 NoBackgroundPolicy REG_DWORD 0x0 NoGPOListChanges REG_DWORD 0x0 NoMachinePolicy REG_DWORD 0x0 NoSlowLink REG_DWORD 0x0 NoUserPolicy REG_DWORD 0x1 PerUserLocalSettings REG_DWORD 0x0 ProcessGroupPolicy REG_SZ ProcessGroupPolicy RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} <NO NAME> REG_SZ Software Installation DllName REG_EXPAND_SZ appmgmts.dll ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyObjectsEx GenerateGroupPolicy REG_SZ GenerateGroupPolicy NoBackgroundPolicy REG_DWORD 0x0 RequiresSucessfulRegistry REG_DWORD 0x0 NoSlowLink REG_DWORD 0x1 PerUserLocalSettings REG_DWORD 0x1 EventSources REG_MULTI_SZ (Application Management,Application)\0(MsiInstaller,Application)\0\0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27} <NO NAME> REG_SZ IP Security ProcessGroupPolicy REG_SZ ProcessIPSECPolicy DllName REG_EXPAND_SZ gptext.dll NoUserPolicy REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain Asynchronous REG_DWORD 0x0 Impersonate REG_DWORD 0x0 DllName REG_EXPAND_SZ crypt32.dll Logoff REG_SZ ChainWlxLogoffEvent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet Asynchronous REG_DWORD 0x0 Impersonate REG_DWORD 0x0 DllName REG_EXPAND_SZ cryptnet.dll Logoff REG_SZ CryptnetWlxLogoffEvent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll DLLName REG_SZ cscdll.dll Logon REG_SZ WinlogonLogonEvent Logoff REG_SZ WinlogonLogoffEvent ScreenSaver REG_SZ WinlogonScreenSaverEvent Startup REG_SZ WinlogonStartupEvent Shutdown REG_SZ WinlogonShutdownEvent StartShell REG_SZ WinlogonStartShellEvent Impersonate REG_DWORD 0x0 Asynchronous REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy Asynchronous REG_DWORD 0x1 DllName REG_EXPAND_SZ %SystemRoot%\System32\dimsntfy.dll Startup REG_SZ WlDimsStartup Shutdown REG_SZ WlDimsShutdown Logon REG_SZ WlDimsLogon Logoff REG_SZ WlDimsLogoff StartShell REG_SZ WlDimsStartShell Lock REG_SZ WlDimsLock Unlock REG_SZ WlDimsUnlock HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp DLLName REG_SZ wlnotify.dll Logon REG_SZ SCardStartCertProp Logoff REG_SZ SCardStopCertProp Lock REG_SZ SCardSuspendCertProp Unlock REG_SZ SCardResumeCertProp Enabled REG_DWORD 0x1 Impersonate REG_DWORD 0x1 Asynchronous REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule Asynchronous REG_DWORD 0x0 DllName REG_EXPAND_SZ wlnotify.dll Impersonate REG_DWORD 0x0 StartShell REG_SZ SchedStartShell Logoff REG_SZ SchedEventLogOff HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy Logoff REG_SZ WLEventLogoff Impersonate REG_DWORD 0x0 Asynchronous REG_DWORD 0x1 DllName REG_EXPAND_SZ sclgntfy.dll HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn DLLName REG_SZ WlNotify.dll Lock REG_SZ SensLockEvent Logon REG_SZ SensLogonEvent Logoff REG_SZ SensLogoffEvent Safe REG_DWORD 0x1 MaxWait REG_DWORD 0x258 StartScreenSaver REG_SZ SensStartScreenSaverEvent StopScreenSaver REG_SZ SensStopScreenSaverEvent Startup REG_SZ SensStartupEvent Shutdown REG_SZ SensShutdownEvent StartShell REG_SZ SensStartShellEvent PostShell REG_SZ SensPostShellEvent Disconnect REG_SZ SensDisconnectEvent Reconnect REG_SZ SensReconnectEvent Unlock REG_SZ SensUnlockEvent Impersonate REG_DWORD 0x1 Asynchronous REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv Asynchronous REG_DWORD 0x0 DllName REG_EXPAND_SZ wlnotify.dll Impersonate REG_DWORD 0x0 Logoff REG_SZ TSEventLogoff Logon REG_SZ TSEventLogon PostShell REG_SZ TSEventPostShell Shutdown REG_SZ TSEventShutdown StartShell REG_SZ TSEventStartShell Startup REG_SZ TSEventStartup MaxWait REG_DWORD 0x258 Reconnect REG_SZ TSEventReconnect Disconnect REG_SZ TSEventDisconnect HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon EulaAccepted REG_DWORD 0x0 Logon REG_SZ WLEventLogon Logoff REG_SZ WLEventLogoff Startup REG_SZ WLEventStartup Shutdown REG_SZ WLEventShutdown StartScreenSaver REG_SZ WLEventStartScreenSaver StopScreenSaver REG_SZ WLEventStopScreenSaver Lock REG_SZ WLEventLock Unlock REG_SZ WLEventUnlock StartShell REG_SZ WLEventStartShell PostShell REG_SZ WLEventPostShell Disconnect REG_SZ WLEventDisconnect Reconnect REG_SZ WLEventReconnect Impersonate REG_DWORD 0x1 Asynchronous REG_DWORD 0x0 SafeMode REG_DWORD 0x1 MaxWait REG_DWORD 0xffffffff DllName REG_EXPAND_SZ WgaLogon.dll Event REG_DWORD 0x0 InstallEvent REG_SZ 1.8.0031.9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings <NO NAME> REG_SZ Data REG_BINARY 01000000D08C9DDF0115D1118C7A00C04FC297EB010000009D9AFB1981461847A55F9F7C217A259604000000040000005300000003660000A800000010000000213DCF555732C840E3BA3E3E38183DA30000000004800000A000000010000000C6439CBFD7DBEF0EA8026F6615105265B0010000363F58BD84F18013DCDF01155251F01D37114B39153A90ABB3CE42CA8C48943C02D4E0329BCDA00D62C8E475C068AB0105324528432E35A3847893010423D1AE4F326ECD2DBFA84262C34F99FF49871622077AC74652160300B4F4833FDE4721F581F4C71D8574CFA10C5464BE50197A46A3E9CB34513DFFA6A0ABD95AFAC2C11D88F809222F4B16C9CB89447CC82289406949E93FBF08F6C1C9E8310024ACEFC2437D87B12C3B02AA47B57A7D1B888A18337D67172FF3A99560CCF2F0FC2577F23979A331D4103209589E0F4E4539B1D613A74CD71AD89DBE01411A23BC9A95D878C346F23CD7CD010F37FFAC9103B7AAAA61F7B5A063F96D973A3924A4EAED1CD5B1E0411AD07082BCE83DD1054AA03AED75740BBAB26A050A7BFBF70295B96FD3946EE830416555D2AFA2E1F16D88A71485D748922EF39E0999055509E9EB48965F52A06819CA01287355BEA152E2E181427465DB333BEFEBE6C092CDD74F47FDEC8F08A6CE7A041C810EC89CBFEF0A57A24A4DBB776858B4A627C361A07D6C5230158B2619B369625737EB6EB73A6175C420C44224D29F4199920D425D341FD1A17AC72C2371E4FE3151D259FE2F14000000ADC7218640ADD34D0637E9D2338745CBC08548B5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon DLLName REG_SZ wlnotify.dll Logon REG_SZ RegisterTicketExpiredNotificationEvent Logoff REG_SZ UnregisterTicketExpiredNotificationEvent Impersonate REG_DWORD 0x1 Asynchronous REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList HelpAssistant REG_DWORD 0x0 TsInternetUser REG_DWORD 0x0 SQLAgentCmdExec REG_DWORD 0x0 NetShowServices REG_DWORD 0x0 IWAM_ REG_DWORD 0x10000 IUSR_ REG_DWORD 0x10000 VUSR_ REG_DWORD 0x10000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Credentials |
| ||
| Re: 2 trojans reappear Yep. Here in the last line of this block is the correct entry for userinit.exe: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon AutoRestartShell REG_DWORD 0x1 DefaultDomainName REG_SZ GEORGE-6JXTPIR4 DefaultUserName REG_SZ George LegalNoticeCaption REG_SZ LegalNoticeText REG_SZ PowerdownAfterShutdown REG_SZ 0 ReportBootOk REG_SZ 1 Shell REG_SZ Explorer.exe ShutdownWithoutLogon REG_SZ 0 Userinit REG_SZ C:\WINDOWS\system32\userinit.exe, Unfortunately the key that your MBAM keeps finding and removing "...CurrentVersion\Winlogon\Userinit" is not there, meaning that it has not re-occurred since last removed. Do you have a file: \Windows\system32\ntos.exe? |
| ||
| Re: 2 trojans reappear Yep. Here in the last line of this block is the correct entry for userinit.exe: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon AutoRestartShell REG_DWORD 0x1 DefaultDomainName REG_SZ GEORGE-6JXTPIR4 DefaultUserName REG_SZ George LegalNoticeCaption REG_SZ LegalNoticeText REG_SZ PowerdownAfterShutdown REG_SZ 0 ReportBootOk REG_SZ 1 Shell REG_SZ Explorer.exe ShutdownWithoutLogon REG_SZ 0 Userinit REG_SZ C:\WINDOWS\system32\userinit.exe, Unfortunately the key that your MBAM keeps finding and removing "...CurrentVersion\Winlogon\Userinit" is not there, meaning that it has not re-occurred since last removed. I think that there is another file being referenced in that trojan Userinit key, it is a rootkit and so is hidden. Possibly. Please: ==Download [with IE only!!] the latest standalone version of Blacklight from ftp://ftp.f-secure.com/anti-virus/tools/fsbl.exe - Start it, accept the agreement and Scan. ==Download this file to your DESKTOP: http://download.bleepingcomputer.com/sUBs/ComboFix.exe .....or this file: http://subs.geekstogo.com/ComboFix.exe -IMPORTANT! : disconnect from the web, turn off your Antivirus, Antispyware and Firewall for the duration of this scan. Don't forget to reset them before you go back on the web! - to run it dclick the Combofix.exe icon and follow the prompts to start it. When finished, it will produce a log, C:\Combofix.txt - post that log in your next reply. A word of caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs reboot to restore the desktop. |
| ||
| Re: 2 trojans reappear Before you do anything, make sure you backup your registry and if the following is successful, you should delete that registry backup. What you should try is download SpyHunter's Malware scanner and have try to remove the trojan.agent files. It is the most successful, but there is still no guarantee. Also, try using spybot search and destroy. |
| All times are GMT -4. The time now is 1:50 am. |
Forum system based on vBulletin Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
©2003 - 2009 DaniWeb® LLC