Author Topic: Virus: winlogon.exe & explore.exe  (Read 19119 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: winlogon.exe & explore.exe
« Reply #45 on: October 14, 2010, 09:10:39 PM »
Could you post the relevant part of the Dr Web log please - as the initial one I saw had no reference to that

If you have retrieved e-mail then you should be OK to use IE

lchg

  • Guest
Re: Virus: winlogon.exe & explore.exe
« Reply #46 on: October 14, 2010, 09:20:55 PM »
I not part of the log is of interest to you.  Here is the part of the log showing the compter as clean.  I can post other info if needed.

-----------------------------------------------------------------------------
Scan statistics
-----------------------------------------------------------------------------
Scanned: 10772
Infected: 0
Modifications: 0
Suspicious: 0
Adware: 0
Dialers: 0
Jokes: 0
Riskware: 0
Hacktools: 0
Cured: 0
Deleted: 0
Renamed: 0
Moved: 0
Ignored: 0
Scan speed: 3051 Kb/s
Scan time: 0:09:07
-----------------------------------------------------------------------------

=============================================================================
Total session statistics
=============================================================================
Scanned: 10772
Infected: 0
Modifications: 0
Suspicious: 0
Adware: 0
Dialers: 0
Jokes: 0
Riskware: 0
Hacktools: 0
Cured: 0
Deleted: 0
Renamed: 0
Moved: 0
Ignored: 0
Scan speed: 3018 Kb/s
Scan time: 0:09:13
=============================================================================

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: winlogon.exe & explore.exe
« Reply #47 on: October 14, 2010, 09:39:15 PM »
No 'tis OK I found it in the original log under a dat8 infection

I must remember to use Dr Web now in safe mode as opposed to normal as that appears to do the trick  ;D

Something new learnt

If Dr Web and your AV no longer show an infection, I would like you to run for 24 hours to ensure that it has gone.  Let me know and I will then remove my tools and clean up

lchg

  • Guest
Re: Virus: winlogon.exe & explore.exe
« Reply #48 on: October 14, 2010, 09:43:00 PM »
How often should I scan with Dr. Web?  Guess I will try IE now.  Thanks for all your help.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: winlogon.exe & explore.exe
« Reply #49 on: October 14, 2010, 09:46:14 PM »
If it did cure it in safe mode then there should be no further need to run it again

Keep an eye open for alerts on explorer.  Then come back in 24 and if there is nothing untoward happening I will remove my tools

lchg

  • Guest
Re: Virus: winlogon.exe & explore.exe
« Reply #50 on: October 15, 2010, 09:11:04 PM »
Everything still looks clear! ;D

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: winlogon.exe & explore.exe
« Reply #51 on: October 15, 2010, 09:29:10 PM »
OK that is good, plus I have learnt some extra power use of the latest Dr. Web  ;D
Currently working on the first true 64 bit virus.  May try Dr Web on that if my current methods fail  ;D


Delete Dr Web plus its associated log files

I will remove my tools now and give some recommendations, but I would like you to run for 24 hours or so and come back if you have any problems

 Now the best part of the day ----- Your log now appears clean  :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    Quote
    :Commands
    [resethosts]
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done

Click Start > Run  and copy/paste the following bolded text into the Run box and click OK:

ComboFix /Uninstall

Run OTL and hit the cleanup button.  It will remove all the programmes we have used plus itself.

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

SPRING CLEAN
 
Download and run Puran Disc Defragmenter

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes: It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit To learn more about how to protect yourself while on the internet read our little guide  How did I get infected in the first place ?
Keep safe  :wave: