MajorGeeks Support Forums IOBit Software

Go Back   MajorGeeks Support Forums > Majorgeeks.Com - Support Forums > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 11-28-10, 15:44
scottk15 scottk15 is offline
Private E-2
 
Join Date: Feb 2009
Posts: 16
Thanks: 2
Thanked 0 Times in 0 Posts
Default Winlogon.exe and Explorer.exe Infected

Hi,
My wife's netbook has unfortunately been infected by Think Point (I think) and after following all the steps as best as I could (could only boot in safe mode so had to re-re-boot several times) I have completed all of the steps in XP cleaning - I also ran MBR check - log attached.
The original XP is in a hidden partition and I have recovery console now available and tried to fxmbr but with success.
Any suggestion most welcome - Thanks, Scott.
Attached Files
File Type: txt ComboFix.txt (13.5 KB, 2 views)
File Type: txt mbam-log-2010-11-28 (18-54-13).txt (1.7 KB, 1 views)
File Type: txt MBRCheck_11.28.10_21.32.26.txt (6.0 KB, 1 views)
File Type: zip MGlogs.zip (121.1 KB, 1 views)
Reply With Quote
Sponsored links
  #2  
Old 11-28-10, 15:45
scottk15 scottk15 is offline
Private E-2
 
Join Date: Feb 2009
Posts: 16
Thanks: 2
Thanked 0 Times in 0 Posts
Default Re: Winlogon.exe and Explorer.exe Infected

Second set of logs
Attached Files
File Type: txt rr.txt (2.2 KB, 0 views)
File Type: log SUPERAntiSpyware Scan Log - 11-28-2010 - 16-36-28.log (578 Bytes, 1 views)
Reply With Quote
  #3  
Old 11-28-10, 16:16
scottk15 scottk15 is offline
Private E-2
 
Join Date: Feb 2009
Posts: 16
Thanks: 2
Thanked 0 Times in 0 Posts
Default Re: Winlogon.exe and Explorer.exe Infected Please Help

Whoops I forgot to say Please Help and I also had no success with FIXMBR.
Thanks again Scott.
Reply With Quote
  #4  
Old 11-28-10, 16:59
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 44,616
Thanks: 377
Thanked 4,197 Times in 3,987 Posts
Default Re: Winlogon.exe and Explorer.exe Infected

If you can boot into the recovery console, do this:

Once you are back to the C:\Windows> prompt of the Recovery Console, input the below bold font commands one at a time each followed by the enter key.
copy D:\i386\explorer.ex_ explorer.exe
cd system32
copy D:\i386\winlogon.ex_ winlogon.exe
exit
This assumes your cd-rom drive is D:
Reboot and tell me how things are running, while I look at your other logs.
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
  #5  
Old 11-29-10, 16:07
scottk15 scottk15 is offline
Private E-2
 
Join Date: Feb 2009
Posts: 16
Thanks: 2
Thanked 0 Times in 0 Posts
Default Re: Winlogon.exe and Explorer.exe Infected

Hi Tim,

no joy - the result was access denied - however this is an NC10 netbook - c & d are partitions - there is no external drive.
Thanks
Scott
Reply With Quote
Sponsored links
  #6  
Old 11-29-10, 16:10
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 44,616
Thanks: 377
Thanked 4,197 Times in 3,987 Posts
Default Re: Winlogon.exe and Explorer.exe Infected

Your message #3 indicated that you tried to run fixboot. This indicated to me you were able to get into the recovery console. Is this not true? Do you have your Windows CD? Is the recovery console installed?

You may need to get an external disc drive to be able to fix this.
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Winlogon.exe / explorder.exe infected KingDeath Malware Removal 3 11-26-10 16:26
Help, winlogon and explorer infected lizmerrill Malware Removal 1 10-01-10 14:59
winlogon and explorer virus patch.fm and patch.fl jonathanseal Malware Removal 3 08-31-10 13:55
Cannot boot windows at all (winlogon.exe infected) SweatyBanana Software 3 08-02-09 17:40
Winlogon.exe, explorer.exe and more plmcomputerservices Malware Removal 9 05-20-09 23:51


All times are GMT -5. The time now is 08:29.


MajorGeeks.Com Home Page
| Admin Tools | All In One | Anti-Spyware | Anti-Virus | Appearance | Backup | Benchmarking | BIOS | Browsers | Covert Ops |
Data Recovery | Diagnostics | Drive Cleaners | Drive Utilities | Drivers | Driver Tools Ergonomics | Firewalls | Games | Game Tweaks | Graphics | Input Devices | Internet Tools | Macintosh | Mail Utilities | Memory | Messaging | Monitoring | Microsoft | Multimedia | Networking | Office Tools | Process Management | Processor | Registry | Security | System Info | Toys | Video | Miscellaneous
|

-->
Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger