Winlogon.exe

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dr_psikick, Nov 22, 2006.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay those are good!

    Now download and extract all files from the newest FixAutex.zip.

    Double click on the fixautex2.reg patch. Did it add it okay???

    If it adds in successfully, get a new log from FixAutex.bat and attach it.
    Any change to status?
     

    Attached Files:

    Last edited: Nov 25, 2006
  2. dr_psikick

    dr_psikick Private E-2

    where is the file to download?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Darn it! Working on too many things at the same time. It's in the previous message now! Sorry about that.
     
  4. dr_psikick

    dr_psikick Private E-2

    Log attached.

    I was suposed to run only the fixautex2.reg, right?

    No,no changes.
     

    Attached Files:

  5. dr_psikick

    dr_psikick Private E-2

    afterall there are changes when i type cmd or regedit into the run dialog it apears one message saying "acess denied".
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you do the below or is this blocked due to your problem? If you cannot do it, I will added to the FixAutex.zip file collection.

    Now Copy the bold text below to notepad. Save it as EXEfix.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  7. dr_psikick

    dr_psikick Private E-2

    I did it (just open one .txt file and saved with EXEfix.reg name).

    No changes just like previous post
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay here are our alternatives!

    • reboot and see what happens! I'm not sure what will happen since you say you cannot run anything.
    • run Erunt and restore the registry to what it was before we started making changes. This will not put back the files that we deleted related to the malware but we don't want them anyway. However it is possible that by restoring the registry that the items added back in can phone home to the malware source and get them added back in again. Also since these registry keys being restored will point to malware files that no longer exist, there could still be problems with getting things running properly.
    • slowly and selective do manual restore of individual registry keys back to what they were in your very first log from running the first version of FixAutex.bat. Based on what is in that original file I should be able to restore the keys back to what they were but in a slower selective fashion. I'm not sure that this will fix anything either. We always have a quick way to repair (remove the malware) registry keys by quickly running the fixautex2.reg patch.
    Do you have a preference?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have a question though! Can you now run EXE files by clicking on them? This did not work before ...is that correct? Does it work now?

    What time is it in Finland? About 7am?
     
  10. dr_psikick

    dr_psikick Private E-2

    I don't think I can just run Erunt, because is an .exe right and i can´t run that.

    reboot... ok but i'm not in my country (in portuguese and i'm currently in finland) and i don´t have Windows cd, backup's...

    So how much time do you think it will take to do the last choice? Are you up to do it?
     
  11. dr_psikick

    dr_psikick Private E-2


    No i can´t but i can start the program if i click on a file associated to it(.dwg - starts autocad). It still don´t work...

    In finland is 8am and in New Jersey 5am?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We can give it a go and see where it takes us!

    No! We are 7 hours behind you. It is currently 1:08 am!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How are you able to double click on .reg files? Do you have a Windows Explorer session open? How did you get it to run?
     
  14. dr_psikick

    dr_psikick Private E-2

    I have a 2xexplorer open but i can open windows explorer via control panel or just inserting a pen drive it pops up
     
  15. dr_psikick

    dr_psikick Private E-2

    so if you want to continue please do my girlfriend will sleep more a couple of hours... then she has to work... on this computer (only we got here)
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try something! When you ran Erunt it should have created a backup folder. I'm not sure what or where you saved it. I think a default may be something like:

    C:\Windows\ERDNT\ and then it inserts the date.

    Can you locate the folder with the backups?
     
  17. dr_psikick

    dr_psikick Private E-2

    yes, located
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you click on ERDNT.exe, do you get the same message as for other programs?

    What happens if you double click on the icon for it on your Desktop?
     
  19. dr_psikick

    dr_psikick Private E-2

    yes unfortunally...
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you see a file named ERDNT.INF ? If so right click on it and select install! Did this run?
     
  21. dr_psikick

    dr_psikick Private E-2

    No.
    apears message saying "access denied"

    Also a few steps ago i was able to right click on files (any kind) and do open with... Now apears always the same message "access denied"
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is strange! We have not changed anything in a number of messages.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you right click Start and locate My Computer and right click on it and select Properties? Does this open up the System Properties window?

    If you do not have My Computer showing in the Start Menu, is it on your Desktop where you can right click on it?
     
  24. dr_psikick

    dr_psikick Private E-2

    It doesn't show properties error message says that i don't have a program associated and i must go to folder options...

    Both start menu and desktop and via explorer
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also tell me if you are able to do the below:

    Now Download the Registry Search Tool

    Unzip to your Desktop and double click on regsrch.vbs
    (if you have script protection in your antuvirus program, please allow this to run)

    In the dialog that opens enter the following:

    finder.com

    Press 'OK'

    The search will run for a while then alert you when it is finished. Press 'OK' and copy the contents of the WordPad window and attach it to this thread.

    If the above worked, repeat the above for each of the below
    explorer.com
    ExERoute.exe
    dxdiag.com
    iexplore.com
    msconfig.com
    rundll32.com
    regedit.com
     
  26. dr_psikick

    dr_psikick Private E-2

    It did open i put finder.com in the box but i'm not sure if anything is really happening...

    it seems not or just doesnt find anything (?)

    IN the task manager I noted the most strange thing I ever seen Explorer process is only spending 9.240K in memory it usually goes about 20 or 30K
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It may not be finding anything! Try searching for majorgeeks just as a test. There should be entries for this.

    Are you sure about the numbers! Explorer will use a lot more then 20 or 30 K. It will use typically in the 20,000 K to 30,000 K range which is really 20 M to 30 M.
    Do you guys use periods where we (in the US) use commas to separate thousands? So when you said 9.240K perhaps you meant 9,240 K (in my language) or in reality 9.240 M.
     
  28. dr_psikick

    dr_psikick Private E-2

    It search but I think it just cant open the wordpad to deliver the results

    About the explorer is taking 7.960K (8M) and usually 20.000 - 30.000 (20 - 30M)
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure why but it could be just due to the fact that many things are not running right now.

    Download the attached Command.zip file and extract the contents (which is command.pif ) into the C:\windows\system32 folder.

    Any change to status?
     

    Attached Files:

  30. dr_psikick

    dr_psikick Private E-2

    no, still the same
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is strange that you cannot run things like EXEs but you can run .bat files. Also the EXE files can be run from inside the .bat files. We are doing that with FixAutex.bat
    In fact download the current attached FixAutex.zip and extract ALL files into the same location as in the past and run the new version of fixautex.bat and attach a new log.

    Also run ShowNew and GetRunKey and attach new logs!
     

    Attached Files:

  32. dr_psikick

    dr_psikick Private E-2

    Attached the requested logs
     

    Attached Files:

  33. dr_psikick

    dr_psikick Private E-2

    Can you make a .bat file to run cmd and from there i can try to run programs, if so it would really nice
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you mean you just want to open a command prompt?

    What programs are you going to try to run from a command prompt? You will need to access them via the full path or you will have to change to their directories. Also we don't know (at least not yet) if you can run anything like an EXE from the command prompt.

    What are the below newly installed programs that I see!
    Code:
    "C:\Program Files\"
    @LASTS~1      25 Nov 2006              "@Last Software"
    AMBIEN~1      25 Nov 2006              "Ambient Design"
    And what are the below too!
    Code:
    "C:\Documents and Settings\Mariana Ara£jo\Local Settings\Temp\"
    kcao7lca.zip  25 Nov 2006        2481  "kcao7lca.zip"
    xqxmuiyt.zip  25 Nov 2006        2481  "xqxmuiyt.zip"
     
  35. dr_psikick

    dr_psikick Private E-2

    The programs I need them to a work I must do, just put them last night... they are ok (clean).

    The other two files i don't have any idea, but they seem nasty... same size and time...
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would empty that folder or at a minimum delete those files.

    What about my question about what you need to do from a command prompt? But anyway since, I modified fixautex.bat again, I also added a file named OpenCP.bat and put it in the ZIP. Download and extract ALL. Then run OpenCP.bat But the question is can you do what you want from this command prompt.
     

    Attached Files:

  37. dr_psikick

    dr_psikick Private E-2

    about the .bat file, i just need to run autocad2007. because when i click in one .dwg file it opens in autocad2006 (I got both) and the files are not compatible...

    If you want to go sleep or something just tell me I understand, you've been very helpfull already, but of course I would be delighted if you can help a litle more
     
  38. dr_psikick

    dr_psikick Private E-2

    did you upload the file already? do I run fiautex.bat?
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You never answered whether you tried running Erunt from the Desktop icon! That's assuming you allowed it to add a Desktop icon.
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is attached in message # 86. Just extract all files and run the OpenCP.bat file. This will open a command prompt window.

    Yes you can run a new FixAutex.bat and attach the log so I can see the results of what I added. There was another registry key that was infected so I added detection of it.
     
  41. dr_psikick

    dr_psikick Private E-2

    Attached log.

    About Erunt I did try but the same as the other programs error message saying that i need to associate the file via folder options
     

    Attached Files:

  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will need to tell me the full path to the Autocad 2007 process (exe file) that you want to run and I could put it in a .bat to see if it will work.

    Pretty soon! I'm just about ready to crash.

    I would really like to reboot your PC but I'm afraid to do that since you need to get some work done and who knows what will happen after boot. It may work perfectly or you may not even be able to get back to where we are right now. We could added a few commands to your autoexec.bat file which runs at startup. We could have it automatically open an IE session and maybe a couple other things. But with what is going on, I don't know if it will get that far. I can still restore the registry keys back to what they were before we started and we can also restore many of the files from the infection because they are backed up in the !Killbox folder. I'm not sure if that would be better or worse and I'm not sure if it will solve the problem with not being able to run things.
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this registry patch if you can. LNK (Shortcut) File Association Fix

    Does it make it so you can click on the shortcut for Erunt on your Desktop and get it to run?
     
  44. dr_psikick

    dr_psikick Private E-2

    No it doesn't, still the same message

    About the autocad location:
    C:\Program Files\AutoCAD 2007\acad.exe

    Any final sugestion/instruction
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From your command prompt window (did it open when you ran OpenCP.bat), type in C:\Program Files\AutoCAD 2007\acad.exe

    What happens?
     
  46. dr_psikick

    dr_psikick Private E-2

    couldn't write \Program Files in the prompt i think because the space(?) so i copy the .bat file you made inside autocad dir and it WOOORKSS!!!!!

    I'm almost happy!!!
     
  47. dr_psikick

    dr_psikick Private E-2

    Should we try to reboot now? and if any problems we continue tomorrow?
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know if your PC will boot okay! It may work fine or you may have problems getting things to run. Do you want to try it right now? Do you have any other way to get back on line if you run into problems?

    DO YOU HAVE A C:\Autoexec.bat file ? If so can you put it into a Zip and attach it here?

    Download the attached newest FixAutex.zip and extract ALL files.

    I added a RunAcad.bat see if it calls Autocad 2007 for you.

    I also added Reinfect.bat which will attempt reinfection. It will restore the bad files from C:\!Killbox and it will restore the registry keys by automatically merging in the reinfect.reg patch. DO you want to do this?????

    I don't know what will happen
     

    Attached Files:

  49. dr_psikick

    dr_psikick Private E-2

    My autoexec.bat
     

    Attached Files:

  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's empty! Extract the attached one to your c:\ folder

    I have it open AutoCad, Internet Explorer and Windows Explorer sessions when it is run. These should all open when you boot up. I'm assuming this would hopefully get you to a condition like you are in right now as long as nothing else goes wrong!

    Do you want to try it right now before I go to sleep? Or would you prefer to keep the PC running as is so you can access AutoCad?

    Did you try the RunAcad.bat file? Did it work?
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds