remove Spy-Agent.bv!inf

Discussion in 'Malware Help (A Specialist Will Reply)' started by alnn_nks, Mar 5, 2007.

  1. alnn_nks

    alnn_nks Private E-2

    I cannot post in the correct thread so I hope the author will read this:

    this virus infects winlogon.exe

    the solution is to run the recovery console either from the windows setup CDROM (R pressed when you run setup)

    then browse to C:\windows\system32\
    rename winlogon.exe to winlogon.old (just in case)
    then change directory to c:\windows\Servicepackfiles\
    copy winlogon.exe from this location to c:\windows\system32\
    restart windows

    as long as windows boots ok then you can delete the infected winlogon.old

    Unfortunately while running throught the malware removal instructions something has happened to my internet settings, once i connect to the internet my computer now restarts immediately with no blue screen or error message.

    If anyone can help me with this i would appreciate it i would prefer not to reinstall windows :)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Thanks but the fix I gave will also work when run properly. Not all people have the ability to boot to the recovery console since the majority of PC manufacturers neglect to provide a bootable CD for the OS shipped with the PC. If the person I was helping eventually could not get my fix to work (which runs automatically to fix the problem), I would have asked if a bootable CD was available as my next step. It is not required though since if you follow my steps and kill smss.exe and then winlogon.exe, you can then replace the winlogon.exe file immediately since it is no longer running.

    What malware problems were you having that prompted you to run "removal instructions" and exactly what did you run/do? Can you run in safe mode? If you were running the READ & RUN ME, where are your logs?
     
  3. alnn_nks

    alnn_nks Private E-2

    Thanks for the offer of help but i have had to reinstall windows (use pc for work) couldnt afford more downtime.

    Works fine now though :mad:)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds