Re: Virus Adds Registry Entrys



John wrote:
I have a fully patched XPSP2 system, some virus keeps on adding c:\windows\winlogon.exe, c:\windows\smss.exe into HKLM\software\microsoft\currentversion\run. I checked the c:\windows and those files do not exists in c:\windows. I know they normally live in system32 folder, and they do exists in system32 folder.

I ran Norton Antivirus, Window Defender and they could not find anything.

This system was previous infected with dsrss.exe, ieredir.exe, smss.exe, Trojan.Qhosts, and someother ones. The computer user kept on saying "NO" to popup for Windows Update, until it was too late.
Anybody know of a virus they maybe doing this.

Your machine is still not clean. Go through these general malware removal steps systematically - http://www.elephantboycomputers.com/page2.html#Removing_Malware

Include scanning with either Sysclean or Multi_AV, plus AVG Anti-Spyware (formerly Ewido - http://www.ewido.net/en/) and follow instructions to do all scans in Safe Mode.

When all else fails, run HijackThis and post your log in one of the specialty forums listed at the link above (not here, please).

Standard caveat: If the procedures look too complex - and there is no shame in admitting this isn't your cup of tea - take the machine to a professional computer repair shop (not your local version of BigStoreUSA). Please be aware that not all local shops are skilled at removing malware and even if they are, your computer may be so infested that Windows will need to be clean-installed. Have all your data backed up before you take the machine into a shop.


Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User
.



Relevant Pages

  • Re: system32
    ... System32 Folder Opens When Logging on to Windows ... It's far easier than mucking about in the registry. ...
    (microsoft.public.windowsxp.general)
  • Re: Automatic logoff from Welcome screen - help
    ... The file was available in the dllcache. ... into system32 folder and everything seems to be working fine. ... or use the parallel Windows XP installation to carryout ... Ramesh Srinivasan, ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: WMF Exploit question
    ... De-registering the DLL is not 100% protection, ... | After you rename the one in the System32 folder, Windows File Protection ... "Paolo Monti has released a temporary patch for the WMF vulnerability ...
    (microsoft.public.windowsxp.general)
  • Re: deleted lsass entries in the registry
    ... To reinstall the Windows Installer, ... HKLM> CS001\services \netlogon - string ImagePath that points to ...
    (microsoft.public.win2000.registry)
  • Re: CSRSS.EXE Virus That Wont Go Away
    ... When finished reboot and turn System Restore back on. ... >> is also a valid windows file located in the system32 folder, ... >> If none of the above fixes the issue then download Hijack this, run it, ...
    (microsoft.public.windowsxp.general)