Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

infected winlogon.exe and explorer.exe (windows xp sp3)


  • Please log in to reply
5 replies to this topic

#1 bheeter7

bheeter7

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:12:17 AM

Posted 20 August 2010 - 06:17 PM

Hi all,

I consider myself somewhat knowledgeable when it comes to repairing minor things on my system, but over the last two weeks, a nasty virus has backed me into a corner. I realize that I'm no malware/spyware expert per se, so please bear with me as I explain my issues. I did use Combofix about a month ago (it worked WONDERS!), but since then other people have used my machine and even combofix seems lacking. If worse comes to worse, I can use my recovery partition and wipe everything, but I hate to let this beat me.

The first time I used Combofix, I had an infected ATAPI.SYS file, which was deleted and restored no problem, and did followup scans to remove any remnants of the infection. I was in awe of how it worked. Though, a few weeks later (I share PC with a couple of roommates who are clueless) someone downloaded a .torrent file, and started to notice more redirects and firewall hogging the CPU, and after scanning with AVAST and ISOBit Security360, decided to try combofix again. That's when I noted the infected winlogon.exe and explorer.exe files. Combofix successfully completes, but the system reboots normally while the Combofix log is being generated (instead of waiting for the log to finish, then loading everything).

I know how anyone who responds to this will say that I didnt consult a helper first, but I'm sure many have fallen into the trap of thinking they can fix it themselves. As far as advice and info, I am at your mercy. I just ask that you don't remind me of my folly while providing a solution hehe. I can post my log if needed.

Thank you =)

BC AdBot (Login to Remove)

 


#2 hamluis

hamluis

    Moderator


  • Moderator
  • 56,106 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:11:17 PM

Posted 20 August 2010 - 06:28 PM

My suggestion would be to post your log, after reading the below instructions...at BC Virus, Trojan, Spyware, and Malware Removal Logs - http://www.bleepingcomputer.com/forums/forum22.html.

Preparation Guide, Before Using Malware Removal Tools and Requesting Help - http://www.bleepingcomputer.com/forums/topic34773.html.

This is the XP forum and most of us aren't qualified to deal with malware issues :thumbsup:, so we need to get you into the correct forum.

Louis

#3 bheeter7

bheeter7
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:12:17 AM

Posted 20 August 2010 - 06:35 PM

I'm sorry to post in the wrong place =( didnt realize this was just the general XP forum

#4 hamluis

hamluis

    Moderator


  • Moderator
  • 56,106 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:11:17 PM

Posted 20 August 2010 - 06:37 PM

No problem, it happens often. The important thing is to get your situation to the correct forum :thumbsup:.

Louis

#5 bheeter7

bheeter7
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:12:17 AM

Posted 20 August 2010 - 06:42 PM

ty for guiding me to the right place :thumbsup:

#6 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,993 posts
  • ONLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:12:17 AM

Posted 20 August 2010 - 11:06 PM

Hello,

I'm deleting your new topic as you neglected to post the logs we need there.

Please follow the instructions in ==>This Guide<== starting at step 6.

Once the proper logs are created, then make a NEW TOPIC and post it ==>HERE<== Since you have run ComboFix, please include the ComboFix log in the new topic. Please be sure to include a description of your computer issues and what you have done to try to resolve them.


If you cannot produce any of the other logs, then please create the new topic anyway, include the information that you were unable to produce the other logs and why and include the ComboFix log along with a description of your computer issues.

Orange Blossom :thumbsup:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users