Winlogon.exe

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dr_psikick, Nov 22, 2006.

  1. dr_psikick

    dr_psikick Private E-2

    Hi there! hopefully you guys can help me...
    This is my girlfriend's computer (ACER 4002wlmi), she works with autocad and 3ds, but latetly the computer was really slow. I checked the taskmanager and there were two apps winlogon.exe (one, winlogon.exe by system and the other WINLOGON.exe by user) and a couple of other strange things that an AVG, ewido and ad-aware scans resolve (at least i suppose...). the fake winlogon is supposed locatated at Windows dir, but i can´t find it. this is really slowing down the computer and prevents Aston shell from loading in the startup, what makes my girlfriend very angry... and you know women when they are angry... so please help me...

    here is the hijack log:


    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.

    thanks,
    helder
     
    Last edited by a moderator: Nov 22, 2006
  2. dr_psikick

    dr_psikick Private E-2

    new hijackthis log...
     

    Attached Files:

  3. dr_psikick

    dr_psikick Private E-2

    OK I dind't respect the posting rules... sorry
    I have read the instructions sticky and now i'll post the logs.
    Hopefully you'll forgive me...
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please attach the other logs requested in the READ ME.

    - CounterSpy
    - Bitdefender Online scan
    - PandaActiveScan

    Also go back to step 2 of the READ & RUN ME and follow those steps properly! That is why you could not find the file you were looking for. But there are more than just that one.


    You also did not install and run Spybot -Search & Destroy as requested. Why did you skip so much of the READ & RUN ME?


    Now to get you started on fixing the malware, let's remove a malware service first.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Update Service For Windows
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pastewinupdate into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.
    After reboot attach a new HJT log.
     
    Last edited: Nov 22, 2006
  5. dr_psikick

    dr_psikick Private E-2

    Thanks for the support.
    Sorry for not doing everything before, but now I did what you told me to do plus the scans posted in the read me first post.
    The various scans did clean somethings (a lot actually) but the main problem is still here: the WINLOGON.EXE keeps preventing Aston shell from loading because it uses explorer shell to try contact Alexa.j688.com[202.102.7.78] - acording to spygate firewall...
    So I'll post 3 of the logs here: Getrunkey,shownew,HJT
     

    Attached Files:

  6. dr_psikick

    dr_psikick Private E-2

    And now the 3 others:panda,bitdefender and counterspy.

    Do you need any other info, such as system specs or security software I use?
    Thanks
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 7
    Java 2 Runtime Environment, SE v1.4.2_04

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Continue by downloading a tools we will need - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\WINDOWS\WINLOGON.EXE

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: Shell=Explorer.exe 1
    O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll (file missing)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Torjan Program] C:\WINDOWS\WINLOGON.EXE
    O4 - HKLM\..\RunServices: [Torjan Program] C:\WINDOWS\WINLOGON.EXE
    O9 - Extra button: Chinese Navigation - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll (file missing)
    O9 - Extra 'Tools' menuitem: Chinese Navigation - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll (file missing)
    O20 - AppInit_DLLs: C:\WINDOWS\system32\drivers\ntdebug.dll

    NOTE: HJT will popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
    C:\WINDOWS\ExERoute.exe
    C:\WINDOWS\WINLOGON.EXE
    C:\WINDOWS\system32\cws.exe
    C:\WINDOWS\system32\interest.exe
    C:\WINDOWS\system32\ineptpui.dll
    C:\WINDOWS\system32\lylk.dat
    C:\WINDOWS\system32\qproecss.exe
    C:\WINDOWS\system32\drivers\ntdebug.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Program Files\CNNIC

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Mariana Ara£jo\Local Settings\Temp

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. dr_psikick

    dr_psikick Private E-2

    I've followed the steps but the WINLOGON.EXE is still here alive and kicking, also upon reboot the firewall (sygate) didn't start automaticly as it should...
    Couldn't find the dir C:\Program Files\CNNIC to delete;
    I don't think that killbox.exe deleted all the files as suposed (i looked in the log) only this:

    C:\WINDOWS\ExERoute.exe
    C:\WINDOWS\WINLOGON.EXE
    C:\WINDOWS\system32\ineptpui.dll
    C:\WINDOWS\system32\lylk.dat
    C:\WINDOWS\system32\qproecss.exe

    So it skiped:

    C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
    C:\WINDOWS\system32\cws.exe
    C:\WINDOWS\system32\interest.
    C:\WINDOWS\system32\drivers\ntdebug.dll

    But i checked and they are not there...

    -----
    I checked \system32 folder and there are some hidden files created all at the same time when the problems started:

    rundll32.com
    MSCONFIG.COM
    finder.com
    dxdiag.com
    command (shortcut)

    I hope this info can help. The requested logs are attatched.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try one more time and also add those other files to the list. They are part of the infection.

    First Run Pocket Killbox and select File, Cleanup, Delete All Backups


    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\WINDOWS\WINLOGON.EXE

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: Shell=Explorer.exe 1
    O4 - HKLM\..\Run: [Torjan Program] C:\WINDOWS\WINLOGON.EXE
    O4 - HKLM\..\RunServices: [Torjan Program] C:\WINDOWS\WINLOGON.EXE

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\ExERoute.exe
    C:\WINDOWS\WINLOGON.EXE
    C:\WINDOWS\system32\dxdiag.com
    C:\WINDOWS\system32\finder.com
    C:\WINDOWS\system32\MSCONFIG.COM
    C:\WINDOWS\system32\regedit.com
    C:\WINDOWS\system32\rundll32.com
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!
     
  10. dr_psikick

    dr_psikick Private E-2

    Hi Chaslang!
    still no luck... WINLOGON.EXE still running after reboot.
    Those files we deleted just respawn, not all thos.
    I´m using 2xExplorer to browse the file system, and now i´m able to see a bunch of files in various locations, all with the same size, date and hour:

    c:\WINDOWS\1.com
    c:\WINDOWS\ExERoute.exe
    c:\WINDOWS\explorer.com
    c:\WINDOWS\finder.com
    c:\WINDOWS\WINLOGON.EXE
    c:\WINDOWS\Debug\DebugProgram.exe
    c:\WINDOWS\system32\command (shortcut with dos icon)
    c:\WINDOWS\system32\dxdiag.com
    c:\WINDOWS\system32\finder.com
    c:\WINDOWS\system32\MSCONFIG.COM
    c:\WINDOWS\system32\regedit.com
    c:\WINDOWS\system32\rundll32.com
    c:\Program Files\Common Files\iexplore (shortcut with dos icon)
    c:\Program Files\Internet Explorer\iexplore.com
    d:\pagefile (shortcut with dos icon)

    Also one folder (with others inside) was created at the same time as that files and seems to be accessed when the computer reboots:

    C:\Documents and Settings\Mariana Araújo\Local Settings\Apps
    C:\Documents and Settings\Mariana Araújo\Local Settings\Apps\2.0
    C:\Documents and Settings\Mariana Araújo\Local Settings\Apps\2.0\ONHWDGCJ.8NJ
    C:\Documents and Settings\Mariana Araújo\Local Settings\Apps\2.0\ONHWDGCJ.8NJ\WDP3XO4D.H29
    C:\Documents and Settings\Mariana Araújo\Local Settings\Apps\2.0\ONHWDGCJ.8NJ\WDP3XO4D.H29\manifests

    The logs you requested are attached.
    Sorry for not answering sooner but we are in different time zones... And many thanks for your help.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is your PC set to show extensions for known file types as requested in step 2 of the READ ME. The reason I ask is because you list the below:

    c:\WINDOWS\system32\command (shortcut with dos icon)
    c:\Program Files\Common Files\iexplore (shortcut with dos icon)

    When they should be listed as
    c:\WINDOWS\system32\command.pif
    c:\Program Files\Common Files\iexplore.pif

    Is there also a filenamed C:\windows\services.exe
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download and install the below and use it to do a full registry backup. We are going to have to do some registry edits and I want to be sure we have a backup to restore from.

    Erunt

    Let me know when you have done that. Mean while, I'll look into whether or not I can automate some of the information retrieval and also the removal process. I'm not sure if if I can. I may need you to do some manual editing in the registry. Are you familiar with using Regedit? Also not that this program makes a false copy of regedit.exe and calls it regedit.com which is the malware itself. Because of this, will will have to install and use the below program to avoid this problem. So also install the below

    Registrar Lite
     
  13. dr_psikick

    dr_psikick Private E-2


    Yes it is set to show extensions, but it only shows what I told you no extension. The icon is dos shortcut but the size of the files is the same as the others.

    I have done the reg backup as you told and installed the other program, so I'm ready to start when you can.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry!!!! It took a while to write this script and I had some issues at home to take care of.

    Download and extract the attached ZIP file to D:\VIRUS TOOLS\ShowNew\

    Yes I want it in the same folder with ShowNew so I can use some files already located there.

    Then run the FixAutex.bat file. It will attempt to delete some files ***ociated with the infection, but it is not a complete fix. I need to see the registry keys that will be put into a log file name c:\autoinfo.txt attach this log file to your next message. This infection puts a lot of entries into the registry.
     

    Attached Files:

    Last edited: Nov 24, 2006
  15. dr_psikick

    dr_psikick Private E-2

    Hei!
    You don't need to say sorry, I thank you a lot for all the trouble and work...
    I runed the file from the specified location and attached the requested log.

    I wish I were a geek... I feel terrible for not being able to resolve this kind of things (more complicated...)
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if you can find and delete the below files:
    C:\Program Files\Internet Explorer\xye1.dat
    C:\Program Files\Internet Explorer\xye1.exe
    C:\Program Files\Internet Explorer\zt.dat

    Tell me what you find and if you could delete them.

    Note:DO NOT REBOOT OR SHUTDOWN YOUR PC. If you need to log off before we complete this, that's okay. Just don't shutdown or reboot. I have to run out for a little while now too. Be back later.
     
  17. dr_psikick

    dr_psikick Private E-2

    I found them and I deleted them.
    Ok, I wait for your next instructions.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think I missed one! Does this file still exist?

    C:\WINDOWS\WINLOGON.EXE

    If so, delete it too!
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now download this new version of FixAutex.zip and extract both files into the ShowNew folder. Run the FixAutex.bat like last time.

    Attach the new log too! Attach this new log BEFORE your continue otherwise you will overwrite it later and I want to see before and after logs.

    Now locate the new fixautex.reg patch that was just extracted from the FixAutex.zip file and double click on fixautex.reg. When it prompts you about adding this to the registry say yes. Tell me if you get a success message.

    Now run FixAutex.bat again and attach the second log.
     

    Attached Files:

    Last edited: Nov 24, 2006
  20. dr_psikick

    dr_psikick Private E-2

    yes it does exist, and can't delete it, by the away WINLOGON.EXE is running. maybe that's why I cant delete it?
    In windows folder besides WINLOGON.EXE, there're:
    1.com
    ExERoute.exe
    explorer.com
    finder.com
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and stop the C:\Windows\Winlogon.exe process like we did in previous steps then do what I just gave you in message # 19.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not sure what I meant! This is what I mean

    You can then exit HijackThis. Make sure you run the FixAutex.bat file immediately afterwards.
     
  23. dr_psikick

    dr_psikick Private E-2

    Can't add the file to registry - error message says that the file is not a registry file and you can only import binary registry from within the registry editor.

    I attatched the log from FixAutex.bat (before)
     

    Attached Files:

  24. dr_psikick

    dr_psikick Private E-2

    Just saw the 2 messages.
    I stop it and deleted it
    then I did the other step again with the same results no sucess with the reg file.

    Attached the fixautex log
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the FIxAutex.Zip file again. I modified it just now to fix the registry patch. Try the patch again and let me know the results.

    Download it from the attachment in msg # 19!
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    DARN!!!!!! These a bug in the .bat file. Hold on while I fix it!!!!
     
  27. dr_psikick

    dr_psikick Private E-2

    ok done.
    the logs attached
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay to avoid confusion I'm attaching the current FixAutex.zip file here. Extract both files from it again thus overwriting the old ones.

    Make sure that c:\windows\winlogon.exe has not restarted. If it did, kill it with HJT.

    Also look for ExERoute.exe and kill it if it is running!

    Run the new FixAutex.bat file and attach log 1!

    Then run the registry patch.

    Then run FixAutex.bat again and attach the second log.
     

    Attached Files:

  29. dr_psikick

    dr_psikick Private E-2

    done.

    One thing, cant run HJT or any other .exe file. lucky i didnt close this browser...
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    The below file is still showing even though it listed as deleted in the first log.

    C:\WINDOWS\ExERoute.exe

    Is this process running? If so, kill it with HJT.

    See if you can delete the C:\WINDOWS\ExERoute.exe file. Does it stay delete?
    If you were able to delete the file, get a new log from FixAutex.bat
     
  31. dr_psikick

    dr_psikick Private E-2

    MAJOR PROBLEM

    Can´t start any program including notepad. cant do what you told me to


    PLEASE HELP
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Darn it! Something is blocking this last fixme.reg patch from posting properly. It is filter the first three letters of ***ociations and replacing it with ***

    I'm going to add it to a new copy of FixAutex.zip for you to download (attached here). You can then just double click on the fixme.reg patch.
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what is causing this! It may be a residual effect from trying to remove this malware since it had itself spread all over your PC.

    I ***ume this means you cannot run HijackThis because it is not currently running?
     
  34. dr_psikick

    dr_psikick Private E-2

    Deleted C:\WINDOWS\ExERoute.exe

    But please help me because i can´t run any program or .exe file and soon my girlfriend needs to work with autocad she has a deadline until monday...
     
  35. dr_psikick

    dr_psikick Private E-2


    didn't understand just click in fixme.reg or first fixautex.bat then fixautex.reg and finally fixme.reg?
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I attached a new version of FixAutex.zip to msg #32.

    I wanted you to download it and extract the files from it and then double click on the fixme.reg patch that is in the ZIP file. Can this be done?

    When you click Start, Run and enter cmd do you get a Command prompt window?

    When you click CTRL-SHIFT-ESC, does Task Manager open?
     
  37. dr_psikick

    dr_psikick Private E-2

    When i try to open notepad (example) error message says:
    This file does not have a program ***ociated with it for performing this action. Create an ***ociation in Folder Options control panel.
     
  38. dr_psikick

    dr_psikick Private E-2

    Done the fixme.reg patch.

    When i enter cmd in run dialog apears one message similar to the one i told you in the last post;
    ctrl-shift-esc works fine it open the task manager.
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Exactly what happens?


    Click on File and select New Task (Run...) and enter command.

    Does a command prompt open?

    Try typing in regedit

    Does regedit open?
     
  40. dr_psikick

    dr_psikick Private E-2

    In both situation appearsone box similar to those that appears when you try to open a kink of file that is not registered:

    To open this file, windows need to know what program created it...
    ...what do you want to do?
    use the web service to find the appropriate program or
    select the program from a list
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download this new FixAutex.zip file attach in this message.

    Extract all files.

    Double click on the NEW fixautex.reg file. Did this add into the registry okay.

    Then run the new FixAutex.bat file. Attach the new log.

    Has this changed anything?
     

    Attached Files:

  42. dr_psikick

    dr_psikick Private E-2

    I'm afraid not can't start anything...
    the log are attatched
     

    Attached Files:

  43. dr_psikick

    dr_psikick Private E-2

    That backup we made before start editing, will it be any good, just in case?
    If so how can we use it? It's because is really important that the computer can start programs... And I am very hurried...
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The fixme.reg patch does not appear to have been added to the registry according to your log. Are you sure it added in okay? Try again. If you get a success message then attach a new log from FixAutex.bat so I can verify that it added in.
     
  45. dr_psikick

    dr_psikick Private E-2

    done it again, still no changes.
     

    Attached Files:

  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that patch now worked. I trying to figure out if anything in the fixautex.reg patch could have cause this problem. I have not found anything yet. I'm still looking. It is possible that the removal of the worm has messed things up and that we just need to reboot. But I'm a little worried about trying a reboot with this problem occurring. I'm not sure what would happen at reboot.

    I do notice something else of concern. Tell me what you see in the below four folders that are new folders from around the date of infection:
    Code:
    C:\WINDOWS\
    CSC           23 Nov 2006              "CSC"
    DOWN          21 Nov 2006              "down"
    DOWNLOAD      21 Nov 2006              "Download"
    INTEL         21 Nov 2006              "Intel"
    
     
  47. dr_psikick

    dr_psikick Private E-2

    If I click on one file -EXEMPLE: .dwg it starts the autocad

    so if you need me to use notepad for something i just need to use some .txt file that exists and then save it with other name.
     
  48. dr_psikick

    dr_psikick Private E-2

    \CSC

    Inside 8 empty folders d1,d2,d3,d4,d5,d6,d7,d8 and two files: 00000001 and 00000002 (no extensions) - all same date

    \down

    empty

    \Download

    empty

    \Intel

    empty
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete the down, Download, and Intel folders!

    Do the below files exist?

    C:\windows\system32\command.com
    C:\windows\system32\rundll32.exe

    If so what are their file sizes and dates?
     
  50. dr_psikick

    dr_psikick Private E-2

    Deleted the folders.

    \system32\command.com -exists- date 10.08.2004 - size 50,620
    \system32\rundll32.exe -exists- date 10.08.2004 - size 33,280
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds