Winlogon.exe and Explorer.exe Infected

Discussion in 'Malware Help (A Specialist Will Reply)' started by scottk15, Nov 28, 2010.

  1. scottk15

    scottk15 Private E-2

    Hi,
    My wife's netbook has unfortunately been infected by Think Point (I think) and after following all the steps as best as I could (could only boot in safe mode so had to re-re-boot several times) I have completed all of the steps in XP cleaning - I also ran MBR check - log attached.
    The original XP is in a hidden partition and I have recovery console now available and tried to fxmbr but with success.
    Any suggestion most welcome - Thanks, Scott.
     

    Attached Files:

  2. scottk15

    scottk15 Private E-2

    Second set of logs
     

    Attached Files:

  3. scottk15

    scottk15 Private E-2

    Re: Winlogon.exe and Explorer.exe Infected Please Help

    Whoops I forgot to say Please Help and I also had no success with FIXMBR.
    Thanks again Scott.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you can boot into the recovery console, do this:

    Once you are back to the C:\Windows> prompt of the Recovery Console, input the below bold font commands one at a time each followed by the enter key.
    copy D:\i386\explorer.ex_ explorer.exe
    cd system32
    copy D:\i386\winlogon.ex_ winlogon.exe
    exit
    This assumes your cd-rom drive is D:
    Reboot and tell me how things are running, while I look at your other logs.
     
  5. scottk15

    scottk15 Private E-2

    Hi Tim,

    no joy - the result was access denied - however this is an NC10 netbook - c & d are partitions - there is no external drive.
    Thanks
    Scott
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your message #3 indicated that you tried to run fixboot. This indicated to me you were able to get into the recovery console. Is this not true? Do you have your Windows CD? Is the recovery console installed?

    You may need to get an external disc drive to be able to fix this.
     
  7. scottk15

    scottk15 Private E-2

    Hi Tim - I have recovery console installed and working - installed by Combofix as part of the clean. Windows was pre-installed but there was no disc - in a hidden partition I think.
    I have an XP Media Centre Edition recovery disc for my desktop PC which I can use if the two files are the same? Otherwise I need to locate where the partition is on the laptop.
    Thanks, Scott
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2


    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      winlogon.exe
      explorer.exe
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  9. scottk15

    scottk15 Private E-2

    Hi Tim, Did as suggested but get no content result - can only run in safe mode will this make a difference - am I doing something wrong?
    Thanks, Scott.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download and save this XPsp3bu.exe to your C:\ root folder. You must do this properly. Now run the XPsp2bu.exe program by double clicking on it. You may or may not notice a quick flash of a black window. This is normal. The program runs quickly and just extracts some files we need.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    FCopy::
    C:\MGtools\temp\explorer.exemg | C:\Windows\explorer.exe
    C:\MGTools\temp\winlogon.exemg | C:\Windows\system32\winlogon.exe
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now attach the new combo log.
     
  11. scottk15

    scottk15 Private E-2

    All completed and log attached - initial run was in safe mode
    Thanks
    Scott
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Combo replaced the files, but I want to double check that all is OK. Please run combo again so we can see if it is still reporting the files as infected.
     
  13. scottk15

    scottk15 Private E-2

    Ran combo - it still reports files are infected - log attached

    Thanks, Scott
     

    Attached Files:

    • log.txt
      File size:
      12.2 KB
      Views:
      3
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have your OS CD? We may need to have you boot into the Recovery Console. You may need to borrow an XP Home edition cd to make this work.
     
    Last edited: Dec 3, 2010
  15. scottk15

    scottk15 Private E-2

    Hi Tim, windows was pre installed so there was no CD/DVD - I have a Media Centre Edition recovery disk from my desktop and also have recovery console installed on the netbook - do I need the XP Home recovery cd or will either of these do ?
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don;t think the recovery disc will let you boot into the recovery console. I may be wrong, but we need an install disc to copy the files from the disc to the system. Can you borrow one from someone?
     
  17. scottk15

    scottk15 Private E-2

    OK I will try to borrow one - it will probably take a couple of days as I am travelling this week - will post when I have one.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem. I will be here when you are ready. Once you have the disc, you will need to boot into the bios, change the boot order to cd-rom as first boot device, put in the disc and reboot.

    Once you are back to the C:\Windows> prompt of the Recovery Console, input the below bold font commands one at a time each followed by the enter key.
    copy D:\i386\explorer.ex_ explorer.exe
    cd system32
    copy D:\i386\winlogon.ex_ winlogon.exe
    exit


    Then boot back into normal mode and re-run ComboFix. Attach that log so we can see if you are clean.
     
    Last edited: Dec 5, 2010
  19. scottk15

    scottk15 Private E-2

    Hi I finally got hold of a system disk and I've copied the files across but now i get a fatal error and it won't even boot in safe mode - I did use SP1 original disks - do I need SP3?
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you can't boot in either normal or safe mode, and you have your windows installation key ( which should be on a sticker on the bottom of a laptop or the back of a tower ), you can use the disc to do a repair installation. If you need assistance with that, please post in the software forum. A repair install will not remove any malware, so you will need to come back to this thread when you are back up and running.
     
  21. scottk15

    scottk15 Private E-2

    Hi Tim, the netbook has no optical drive - so I ended up doing a full recovery - all logs now clean - thanks for your help.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Thanks for letting me know. Glad you are back up and running. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds