Author Topic: Virus: winlogon.exe & explore.exe  (Read 18962 times)

0 Members and 1 Guest are viewing this topic.

lchg

  • Guest
Re: Virus: winlogon.exe & explore.exe
« Reply #15 on: October 12, 2010, 10:09:01 PM »
Here are the new reports/logs.  Thanks.  Not sure it matters, but my virus protection is now itentify ComboFix as a virus and deleting it off my desktop.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: winlogon.exe & explore.exe
« Reply #16 on: October 12, 2010, 10:45:31 PM »
Are you still getting alerts on explorer ?

If so I will have to use the big AV - This is a new version so I have not yet formulated proper instructions for it 

Download the latest Dr Web form here http://www.freedrweb.com/?lng=en

It will download as an 8 digit file

Run the file and agree to the enhanced mode
Run a quick scan initially - it will lock your desktop for the duration
About half way through it will ask to either buy or download the demo.  Close the box using the X
Allow it to cure
At the end a log will be generated please post that

lchg

  • Guest
Re: Virus: winlogon.exe & explore.exe
« Reply #17 on: October 12, 2010, 11:02:31 PM »
Yes, it is still showing as infected.  I will give the new version a try.

lchg

  • Guest
Re: Virus: winlogon.exe & explore.exe
« Reply #18 on: October 13, 2010, 02:57:50 PM »
The CureIt.log is too large to attach and has too many characters to post directly.  I can break the log down into 3 or 4 smaller text files and post separately.  Is that okay with you?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89127
  • No support PMs thanks
Re: Virus: winlogon.exe & explore.exe
« Reply #19 on: October 13, 2010, 04:46:22 PM »
Or you could upload it to Mediafire:

- Mediafire.com - Upload to http://www.mediafire.com/ and post the sharing link.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

lchg

  • Guest
Re: Virus: winlogon.exe & explore.exe
« Reply #20 on: October 13, 2010, 05:28:43 PM »
Thanks for the tip.  Here is the link: http://www.mediafire.com/file/xegq4h866bttkvc/CureIt.log

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89127
  • No support PMs thanks
Re: Virus: winlogon.exe & explore.exe
« Reply #21 on: October 13, 2010, 05:32:38 PM »
You're welcome, I mentioned it as essexboy does use it, so it should be easier for him to access it than on multiple smaller files. Hopefully he will be back on-line soon.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

lchg

  • Guest
Re: Virus: winlogon.exe & explore.exe
« Reply #22 on: October 13, 2010, 08:56:49 PM »
Not sure if this is useful information, but McAfee came up with the following message after running the CureIt scan:
File deleted - winlogon.exe 
Generic.dxl.ucd 
C:\Windows\system32\dllcode\winlogon

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: winlogon.exe & explore.exe
« Reply #23 on: October 13, 2010, 09:08:16 PM »
Intriguing Dr Web cleared explorer and winlogon in memory

Have you rebooted since the file was deleted ?


lchg

  • Guest
Re: Virus: winlogon.exe & explore.exe
« Reply #24 on: October 13, 2010, 09:13:27 PM »
It did not reboot automaticallt abd I did not reboot.  Should I reboot now or run CureIt again and then reboot?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: winlogon.exe & explore.exe
« Reply #25 on: October 13, 2010, 09:20:23 PM »
Reboot now please and let me know if you are still getting the explorer alert

lchg

  • Guest
Re: Virus: winlogon.exe & explore.exe
« Reply #26 on: October 13, 2010, 09:33:50 PM »
Rebooted and ran a scan with Hitman Pro.  The two files are still showing as infected.  This is a resilient virus!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: winlogon.exe & explore.exe
« Reply #27 on: October 13, 2010, 09:50:18 PM »
One further area to check

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window similar to this should open on your desktop:



  • If you are prompted with options, enter N at the prompt and press Enter[/i]
  • Press Enter[/i] again
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your deskop.  Please post the contents of that file.

lchg

  • Guest
Re: Virus: winlogon.exe & explore.exe
« Reply #28 on: October 13, 2010, 10:09:32 PM »
The file is attached

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: winlogon.exe & explore.exe
« Reply #29 on: October 13, 2010, 10:16:32 PM »
OK before we proceed does your computer have a recovery partition ? If so what is the make of your computer

Run MBRCheck.exe once again.
 
You will be presented with the following dialog:
 
Quote
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

 
Enter Y and press Enter.
 
The following dialog will be presented:
Quote
Options:
[1] Dump the MBR of a physical disk to file.
[2] Restore the MBR of a physical disk with a standard boot code.
[3] Exit.
 
Enter your choice:

 
Enter 1 and press Enter
 
The following dialog will be presented:
 
Quote
Enter the physical disk number to fix (0-99, -1 to cancel):

 
Enter 0 and press Enter
 
The program will ask for the file name to dump to, type dump.txt and Press Enter. You should see a Dumped successfully message. Type -1 and press Enter twice to exit the program. Save the dump.txt file to your desktop then attach it on your next reply.