Recommended Driver Scanner

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] winlogon.exe problem

[Fixed] Hijackthis! Logs - [Fixed] winlogon.exe problem posted in the Security & Safety forums; I accidently opened a malicious exe and I had a ton of spyware and viruses installed. I got rid of a lot of them, but I think a trojan or ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 01-15-2006
Silver Member
 
Join Date: Jun 2005
Location: Canada
Posts: 218
Nathan - See this Members User comments on their Profile page Nathan - See this Members User comments on their Profile page
Default [Fixed] winlogon.exe problem

I accidently opened a malicious exe and I had a ton of spyware and viruses installed. I got rid of a lot of them, but I think a trojan or something is still around. My winlogon.exe file is using about 70%+ of cpu and I can't figure out how to fix it. Here's my HJT log:
Attached Files
File Type: log hijackthis.log (11.0 KB, 1 views)


__________________

  #2  
Old 01-15-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Nathan , first please run an Ewido scan first and post the log from that. Then run a Panda active scan here and post the log from that aswell

http://www.pandasoftware.com/product...ACHEHINT=Guest

Also uninstall Red Swoosh in add/remove programs if present and then post a new hjt log please.

Also windows isn't updated but you should now wait with that untill youre clean.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 01-16-2006
Silver Member
 
Join Date: Jun 2005
Location: Canada
Posts: 218
Nathan - See this Members User comments on their Profile page Nathan - See this Members User comments on their Profile page
Default

Ok, my ewido and panda logs are attached.

I uninstalled "red swoosh" too and attached a new HJT log. What is red swoosh anyway? I don't remember installing it...
Attached Files
File Type: txt ewido.txt (4.5 KB, 2 views)
File Type: txt Activescan.txt (6.8 KB, 2 views)
File Type: log hijackthis.log (8.6 KB, 3 views)


__________________

  #4  
Old 01-16-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Here is some info on red swoosh:
http://www.auditmypc.com/process/rsednclient.asp

First run ccleaner , and then click on Start->Settings->Control Panel->Java Plug-in and click on the Cache tab. Then click on the Clear button and hit OK.
If you have Java 1.5, do this instead. Start->Control Panel->Java->Settings->Delete Files and click OK and OK.

And then post a new hjt log from normal mode , the f2/f3 entry's are messed up somehow from this one. Did you edit the log?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 01-16-2006
Silver Member
 
Join Date: Jun 2005
Location: Canada
Posts: 218
Nathan - See this Members User comments on their Profile page Nathan - See this Members User comments on their Profile page
Default

Ok, I cleaned up those java problems. I rebooted into normal mode and winlogon.exe wasn't using any cpu, so I think it's fixed. I didn't the edit original log though. Just in case there are any more problems here's the log from normal mode:
Attached Files
File Type: log hijackthis.log (9.4 KB, 2 views)


__________________

  #6  
Old 01-16-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

And now the f2/f3 entry's are gone from the log completly..:icon_scra wierd..

and do you know why Whatpulse is running on youre pc?

http://whatpulse.org/whatis/


And can you upload this file:

O4 - HKCU\..\Run: [aupd] C:\WINDOWS\System32\symsvcsa.exe

to this site and report back the result:

http://www.virustotal.com/flash/index_en.html


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #7  
Old 01-16-2006
Silver Member
 
Join Date: Jun 2005
Location: Canada
Posts: 218
Nathan - See this Members User comments on their Profile page Nathan - See this Members User comments on their Profile page
Default

I'm aware that whatpulse is running, I'm recording my keys and clicks count.

Here's the result:

Antivirus Version Update Result
AntiVir 6.33.0.77 01.15.2006 no virus found
Avast 4.6.695.0 01.15.2006 no virus found
AVG 718 01.14.2006 Klone
Avira 6.33.0.77 01.15.2006 no virus found
BitDefender 7.2 01.15.2006 GenPack:Trojan.Galapoper.E
CAT-QuickHeal 8.00 01.14.2006 (Suspicious) - DNAScan
ClamAV devel-20051123 01.15.2006 no virus found
DrWeb 4.33 01.15.2006 Trojan.Galapoper
eTrust-Iris 7.1.194.0 01.15.2006 no virus found
eTrust-Vet 12.4.1.0 01.13.2006 Win32/Sinteri
Ewido 3.5 01.15.2006 Trojan.Small
Fortinet 2.54.0.0 01.15.2006 W32/KlonePacked.B-tr
F-Prot 3.16c 01.13.2006 could be infected with an unknown virus
Ikarus 0.2.59.0 01.13.2006 no virus found
Kaspersky 4.0.2.24 01.16.2006 Packed.Win32.Klone.b
McAfee 4674 01.13.2006 Galapoper
NOD32v2 1.1366 01.15.2006 probably a variant of Win32/TrojanProxy.Lager.F
Norman 5.70.10 01.13.2006 no virus found
Panda 9.0.0.4 01.15.2006 Suspicious file
Sophos 4.01.0 01.15.2006 no virus found
Symantec 8.0 01.16.2006 no virus found
TheHacker 5.9.2.074 01.14.2006 no virus found
UNA 1.83 01.13.2006 Win32.CRYPT.virus
VBA32 3.10.5 01.15.2006 Trojan.Galapoper


__________________


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[FIXED] Computer Restarts: Very Wierd Problem! Confused Help! Ali2005 Windows XP/2000 4 11-16-2005 10:09 PM
[Pending] Serious Problem w/WinME & Hard Disk alexandrazenas Windows 95, 98 & ME 3 07-18-2005 06:33 PM
[Resolved] Major XP Crashing Problem...Please Help Slimreaper Windows XP/2000 7 06-11-2005 06:16 PM
[Answered] Windows XP SP2 Problem luvko031503 Windows XP/2000 18 04-23-2005 02:52 PM

All times are GMT +1. The time now is 05:43 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top