Author Topic: Virus: winlogon.exe & explore.exe  (Read 19123 times)

0 Members and 1 Guest are viewing this topic.

lchg

  • Guest
Virus: winlogon.exe & explore.exe
« on: October 11, 2010, 07:45:48 PM »
I am showing virus infection for the following files: winlogon.exe & explore.exe.   I ran ComboFix, but cannot reboot my computer.  Upon manual shutdown, the virus reappears.  The ComboFix log and an OTL file log are attached.  Any help is appreciated.  Thanks.

Jtaylor83

  • Guest
Re: Virus: winlogon.exe & explore.exe
« Reply #1 on: October 11, 2010, 07:55:11 PM »

lchg

  • Guest
Re: Virus: winlogon.exe & explore.exe
« Reply #2 on: October 11, 2010, 08:41:31 PM »
I tried Hitman Pro 3.5.6 earlier today.  It identifies the 2 files as infected; however, I get the following message from Hitman for both infected files:  "To maintain system stability, Windows must restor original version of this file.  Insert you Windows installation CD-ROM".  I found my operating system recovery CD and did as instructed, but the files in the HitMan screen change to Do Not Delete after hitting the next button.  The infected files still remain.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: winlogon.exe & explore.exe
« Reply #3 on: October 11, 2010, 08:57:52 PM »
Do you have access to another computer to copy those files?

Also could you look in your recycle bin to see if the copies were placed there

If you can get other copies then place them on your root c drive and let me know - I will then swap them

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes

lchg

  • Guest
Re: Virus: winlogon.exe & explore.exe
« Reply #5 on: October 11, 2010, 09:36:31 PM »
Okay, I got a copy of the files from another computer and have them on my root C drive (I see you have made a copy too, thanks).  Should I rerun Hitman and try to redirect it to my C drive?  It did not have a browse option before?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: winlogon.exe & explore.exe
« Reply #6 on: October 11, 2010, 09:49:37 PM »
Nope what we will do now if use Combofix to move them to make sure it is done safely

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

Quote
Fcopy::
C:\explorer.exe|c:\windows\explorer.exe
C:\winlogon.exe|c:\windows\system32\winlogon.exe

3. Then in the text file go to FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES

4. Save the above as CFScript.txt

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below.  This will start ComboFix again.




6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new OTListit log.

lchg

  • Guest
Re: Virus: winlogon.exe & explore.exe
« Reply #7 on: October 11, 2010, 10:19:29 PM »
The reports you requested are attached.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: winlogon.exe & explore.exe
« Reply #8 on: October 11, 2010, 10:43:19 PM »
Numpty CF did not work quite right so lets try again -  I will look at the logs whilst you do this

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

Quote
Fcopy::
c:\windows\system32\dllcache\winlogon.exe|c:\windows\system32\winlogon.exe

3. Then in the text file go to FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES

4. Save the above as CFScript.txt

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below.  This will start ComboFix again.




6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt .

lchg

  • Guest
Re: Virus: winlogon.exe & explore.exe
« Reply #9 on: October 11, 2010, 10:59:00 PM »
Here is the next ComboFix report.  Just so you know, the computer rebooted while running the ComboFix this time.  Thanks.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: winlogon.exe & explore.exe
« Reply #10 on: October 11, 2010, 11:08:48 PM »
What problems are you exoperiencing now ?

Combofix is making me work today

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

Quote
SRPeek::
c:\windows\explorer.exe

3. Then in the text file go to FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES

4. Save the above as CFScript.txt

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below.  This will start ComboFix again.




6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt .

lchg

  • Guest
Re: Virus: winlogon.exe & explore.exe
« Reply #11 on: October 11, 2010, 11:32:15 PM »
Sorry for the difficulties.  Looks like the explorer.exe file is still a problem.  The updated Combofix.txt is attached.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: winlogon.exe & explore.exe
« Reply #12 on: October 11, 2010, 11:43:01 PM »
No problem - I get to use commands that are rarely used  ;D

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

Quote
SCOPY::
RP5\A0007046.exe|c:\windows\explorer.exe

3. Then in the text file go to FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES

4. Save the above as CFScript.txt

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below.  This will start ComboFix again.




6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt .

lchg

  • Guest
Re: Virus: winlogon.exe & explore.exe
« Reply #13 on: October 12, 2010, 12:18:57 AM »
Here is the latest.  Sorry, but I have to run and may not get back to this until tomorrow.  I really appreciate your time and effort.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: winlogon.exe & explore.exe
« Reply #14 on: October 12, 2010, 09:38:45 PM »
No problem - I have been going over the logs to try and find the trigger as the file gets re-infected as soon as CF fixes it.  I have noticed an anomoly which I would like to clear now.  Follow this immediately with the CF script

 Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    Quote
    :OTL
    O15 - HKLM\..Trusted Domains: //about.htm/ ([]myui in Trusted sites)
    O15 - HKLM\..Trusted Domains: //Exclude.htm/ ([]myui in Trusted sites)
    O15 - HKLM\..Trusted Domains: //LanguageSelection.htm/ ([]myui in Trusted sites)
    O15 - HKLM\..Trusted Domains: //Message.htm/ ([]myui in Trusted sites)
    O15 - HKLM\..Trusted Domains: //MyAgttryCmd.htm/ ([]myui in Trusted sites)
    O15 - HKLM\..Trusted Domains: //MyAgttryNag.htm/ ([]myui in Trusted sites)
    O15 - HKLM\..Trusted Domains: //MyNotification.htm/ ([]myui in Trusted sites)
    O15 - HKLM\..Trusted Domains: //NOCLessUpdate.htm/ ([]myui in Trusted sites)
    O15 - HKLM\..Trusted Domains: //quarantine.htm/ ([]myui in Trusted sites)
    O15 - HKLM\..Trusted Domains: //ScanNow.htm/ ([]myui in Trusted sites)
    O15 - HKLM\..Trusted Domains: //strings.vbs/ ([]myui in Trusted sites)
    O15 - HKLM\..Trusted Domains: //Template.htm/ ([]myui in Trusted sites)
    O15 - HKLM\..Trusted Domains: //Update.htm/ ([]myui in Trusted sites)
    O15 - HKLM\..Trusted Domains: //VirFound.htm/ ([]myui in Trusted sites)

    :Commands
    [purity]
    [resethosts]
    [EMPTYFLASH]
    [CREATERESTOREPOINT]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
CFScript

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

Quote
KillAll::

SCOPY::
RP5\A0007046.exe|c:\windows\explorer.exe


3. Then in the text file go to FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES

4. Save the above as CFScript.txt

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below.  This will start ComboFix again.




6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new OTListit log.