Winlogon.exe, explorer.exe and more

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by plmcomputerservices, May 14, 2009.

  1. plmcomputerservices

    plmcomputerservices Private E-2

    Alright. I have a couple different problems popping up on this laptop of a friend.

    On boot and even after closing out, I get something that says it's from McAfee even though McAfee isn't installed on the computer.

    McAfee Virus Scan
    McAfee ActiveShield has found a suspect file on your computer.

    McAfee strongly recommends that you scan your computer now.


    Also, AVG Resident Shield alert pops up with

    winlogon.exe Trojan horse Win32/PEPatch.AO -object is whitelisted
    explorer.exe Trojan horse Win32/PEPatch.AO -object is whitelisted

    I've already removed over 400 objects with Malwarebytes, over 600 objects with Spybot and now it's just these last few problems that I need to push through and I can't find out a legit fix anywhere.

    Btw,
    SuperAntiSpyware doesn't run on reboot and neither would Malwarebytes, the computer would just sit there, explorer.exe wouldn't load and I couldn't run it by hitting ctl+alt+delete and then Run>explorer.exe like I can on other machines. I have to reboot again to load windows.

    I'm assuming that it's all because of the threats AVG finds.

    Attached are my MGtools log in zip format.
     
  2. plmcomputerservices

    plmcomputerservices Private E-2

    I don't think they got uploaded on that last post. Here we go.
     

    Attached Files:

  3. plmcomputerservices

    plmcomputerservices Private E-2

    Does anyone have any idea on how to fix this issue or does it normally take longer to get an answer in this forum?
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Could you please attach the log from running it then, as requested in the R&R?

    Can I also have the log from running SAS? :)

    I also need to see the log from running Combofix.


    You shouldn't bump... you'r thread would have been dealt with slightly quicker had you not added an extra un-neccesary post like you did. Please see the below for what I'm talking about:

    Don't Bump! It Only Hurts You!!!

    So I shall take a look thru your Mglogs.zip but I would also like to see the other logs mentioned above too.

    Thanks
    Kestrel13!
     
  5. plmcomputerservices

    plmcomputerservices Private E-2

    I've attached the logs. The log titled "log.txt" is my combofix log. The other two zip folders contain four logs each of the four scans I ran.
     

    Attached Files:

  6. plmcomputerservices

    plmcomputerservices Private E-2

    Latest ComboFix log posted. I ran this one since I think the first one I posted was ran before some of the other scans.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Mcafee most certainly is installed on this laptop. I can see it in your uninstall list from the newfiles.log

    1. If you wish to get rid of Mcafee then you will need to run this removal tool.

    Please download the McAfee Consumer Product Removal Tool

    Run this > Reboot your machine > and Run it again to get rid of remnants of McAfee.

    2. Please go to Add/Remove Programs and uninstall the following softwares:

    • J2SE Runtime Environment 5.0 Update 4
    • Freeze.com Toolbar
    • Viewpoint Media Player <--- as requested in step 1 of the R&R

    3. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT


    4. Now we need to use ComboFix to remove a bunch of malware files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    File::
    c:\windows\system32\vfq.dll 
    C:\WINDOWS\dirsaver.ini
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    "pPjgipitQcp"=-
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    5. Also delete all files in the below bold folder except ones from the current date (Windows will not let you delete the files from the current day).

    • C:\Documents and Settings\Leanna PLatt\Local Settings\Temp


    6. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6


    7. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix

    8. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    After reviewing your logs closer, your logs show that your Windows Operating system files have become infected and there is no known reliable fix for this. In addition there are many many other infected files. We could spend a lot of time trying to remove this infection, but odds are that it will not work because the nature of the infection has so many executable system files infected that as soon as we fix one file, other files that are infected will almost immediately or upon the next reboot, just reinfect the files. In addition, your PC would still basically be unreliable/untrustworthy even if we manage to fix the infected files that we can see since there could be many more that we are not seeing.

    The safest thing for you to do is backup your personal data immediately since your PC could possible become unbootable at any point in time. Do not back up any executable files. This includes programs that you have downloaded since any of them could be infected.

    Once you backup, you need to perform a total reinstall of Windows and all other necessary software. DO NOT reinstall from any executable files you backed up because they are most likely infected.
     
  9. plmcomputerservices

    plmcomputerservices Private E-2

    Hey Guys,

    I cleaned everything off with SuperAntiSpyware, HijackThis, Malwarebytes, AVG, and a regular ol' Windows SP2 disc. The spyware/antivirus programs shotgunned everything the found that you saw in the logs and by shutting off System Restore and running the scans in both safe mode and normal mode. Winlogon.exe, Explorer.exe, Lsass.exe, and the other .exe files were seen by AVG and replaced by the Windows SP2 disc by booting windows with the disc in and than running sfc.exe (Start>Run and than type SFC /SCANNOW in the box and click ok, http://freeforum.avg.com/read.php?4,182182,182625). Everything is back to running great now.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I suggest that you run a full system scan with your antivirus program and also I suggest that you attach a new log from MGtools. Quite frequently this infection will look like it is fixed and not be. It could come back in a short time frame unless ALL infected files were found and replaced. Depending on how far the infection had spread, you may have been lucky or it may just look like it. These infections also can infect the sfc program itself or just hook into it to make it not work properly and thus can wreak havoc on a PC.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds