A Digital Age Deserves A Digital Leader

winlogon.exe

Postby plazmo » Fri Feb 20, 2004 5:37 pm

ok .. so really to get rid of this prob i need to run an anti-trojan prog not a anti-virus...

probly some stupid keylogger...as its not makin any difference to performance or speed of my pc like most trojans.... thanks to every one for the help ....

yeah at the mo im trying avast anti-virus out it seems to workin really good compared to others i used..
PRO Level 9
User avatar
Posts: 367
Joined: Sun Dec 28, 2003 4:27 pm
Location: uk

Postby ginogsm » Fri Feb 20, 2004 5:38 pm

Guardian wrote:I think he is using Windows 2000 or earlier I could be wrong though


Unless he's using Win 95/98 ( that don't have winlogon.exe ) he should not have c:\windows folder ( NT and 2K are using Winnt ). I don't know about WinMe. 2k's winlogon.exe is about 178kb and found at c:\winnt\system32.
PROfessional Member
User avatar
Posts: 4832
Joined: Tue Jan 13, 2004 7:41 am
Location: Frankfurt , Germany
Real Name: George

Postby OsirisX » Fri Feb 20, 2004 5:40 pm

plazmo, there are some nice spyware removers listed in the serity section.
OsirisX

"The only thing that interferes with my learning is my education." - Albert Einstein
PROfessional Member
User avatar
Posts: 4261
Joined: Mon Dec 29, 2003 9:45 pm
Location: USA, CT

Postby plazmo » Fri Feb 20, 2004 5:42 pm

i am using xp .. nt and 2000 never really cought my eye i skipped them.

cheers for the help :notworthy
PRO Level 9
User avatar
Posts: 367
Joined: Sun Dec 28, 2003 4:27 pm
Location: uk

Postby MinusDriver » Fri Feb 20, 2004 5:43 pm

I would run this first: http://www.anti-trojan.net/en/
(14 day free trial of the software as well as the online scan)

Then go here: Click Here

Install Spybot Search&Destroy and run scan on your PC

Let us know what happens

Thanks,
PRO Level 13
User avatar
Posts: 813
Joined: Thu Jan 08, 2004 9:47 pm
Location: Atlanta, GA
Real Name: Michael

Postby SCgone » Fri Feb 20, 2004 5:45 pm

It's a downloader trojan and it usually renames itself as another Windows file, usually taskmon or system.exe but could be named anything. It then places itself in the registry at HKCU\Software\Microsoft\Windows\CurrentVersion\Run
PRO PLATINUM
Posts: 6879
Joined: Thu Mar 14, 2002 11:59 pm
Location: South Carolina, USA

Postby plazmo » Fri Feb 20, 2004 5:47 pm

i got search and destroy and a trojan hunter...along with loads of other progs like spy sweeper..adware .. and many more free stand alone virus and trojan removers that run from a cd

but if i delete my winlogon.exe my xp wont boot up proply and ill end up installing xp... ? wont i :confused
PRO Level 9
User avatar
Posts: 367
Joined: Sun Dec 28, 2003 4:27 pm
Location: uk

Postby ginogsm » Fri Feb 20, 2004 5:47 pm

Bell1 wrote:It's a downloader trojan and it usually renames itself as another Windows file, usually taskmon or system.exe but could be named anything. It then places itself in the registry at HKCU\Software\Microsoft\Windows\CurrentVersion\Run


This great info. ^*^ Thanx. I think I'm going to need it at company's network.
PROfessional Member
User avatar
Posts: 4832
Joined: Tue Jan 13, 2004 7:41 am
Location: Frankfurt , Germany
Real Name: George

Postby SCgone » Fri Feb 20, 2004 6:18 pm

plazmo wrote:i got search and destroy and a trojan hunter...along with loads of other progs like spy sweeper..adware .. and many more free stand alone virus and trojan removers that run from a cd

but if i delete my winlogon.exe my xp wont boot up proply and ill end up installing xp... ? wont i :confused


With the XP CD in your drive, try running from the Start>Run
sfc /scannow
This will replace any missing system files. Yes, you can't delete it, but since it's a trojan, it's not self-replicating so once it's gone, it's gone. Also, you will need to turn off system restore before running any of your antivirus programs, since this trojan will remain in restore. After removal, then you would need to turn it back on. That is, if you're using XP

1. Right click the My Computer icon on the Desktop and click on Properties.
2. Click on the System Restore tab.
3. Put a check mark next to 'Turn off System Restore on All Drives'.
Ok out.
PRO PLATINUM
Posts: 6879
Joined: Thu Mar 14, 2002 11:59 pm
Location: South Carolina, USA

Postby MinusDriver » Fri Feb 20, 2004 6:29 pm

Thanks Bob well said :)
PRO Level 13
User avatar
Posts: 813
Joined: Thu Jan 08, 2004 9:47 pm
Location: Atlanta, GA
Real Name: Michael

PreviousNext

Return to Security & Virus

Who is online

Users browsing this forum: No registered users and 2 guests

cron
cron