Hi there,
Hope you can help me out with the following issue I have since thursday; think point virus infected my laptop with vista 32bit. As soon this happened, I switched off internet en rebooted in safe mode. No idea where this virus came from, maybe an outdated Javascript?
From there in safe mode,I used taskmanager, shutdown process hotfix.exe en deleted the file.
I have had the latest windows update already, excluding the latest for the MS office. But I didn't use that on the day of infection.
Avast anti virus was running too.
I tried, malware bytes, super anti spyware and avast. All found virusses. Only after a 10 hour boot scan by Avast it turned out that almost all viruses where gone except at two locations; wininit.exe and explorer.exe
avast was not able to delete/repair these. I renaimed wininit.exe into wininit2.exe and manually deleted it. Now at this time of writing, no reboot has been settled yet.
I tried to understand all of the post: https://www.techspot.com/vb/topic154603.html but found difficulties.
I already used JavaRA to uninstall old versions.
I ran security check;
a Results of screen317's Security Check version 0.99.5
Windows Vista (UAC is disabled!)
Out of date service pack!!
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:
avast! Free Antivirus
Antivirus up to date!
```````````````````````````````
Anti-malware/Other Utilities Check:
Malwarebytes' Anti-Malware
Java(TM) 6 Update 22
Java(TM) 6 Update 2
Out of date Java installed!
Adobe Flash Player 10.1.53.64
Adobe Reader 9.4.0 - Nederlands
````````````````````````````````
Process Check:
objlist.exe by Laurent
Alwil Software Avast5 AvastSvc.exe
Alwil Software Avast5 AvastUI.exe
````````````````````````````````
DNS Vulnerability Check:
GREAT! (Not vulnerable to DNS cache poisoning)
``````````End of Log````````````
With the programm SystemLook I found out that there are several explorer.exe programms running on my pc:
SystemLook 04.09.10 by jpshortstuff
Log created at 10:21 on 25/10/2010 by Simon
Administrator - Elevation successful
========== filefind ==========
Searching for "winlogon.exe"
C:\WINDOWS\SoftwareDistribution\Download\2b4e48d0ede6112a59b10e3704a22eee\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe --a---- 314880 bytes [17:32 23/10/2010] [07:33 19/01/2008] C2610B6BDBEFC053BBDAB4F1B965CB24
C:\WINDOWS\System32\winlogon.exe --a---- 308224 bytes [08:44 02/11/2006] [09:45 02/11/2006] 9F75392B9128A91ABAFB044EA350BAAD
C:\WINDOWS\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe --a---- 308224 bytes [08:44 02/11/2006] [09:45 02/11/2006] 9F75392B9128A91ABAFB044EA350BAAD
Searching for "explorer.exe"
C:\WINDOWS\explorer.exe --a---- 2923520 bytes [13:04 08/12/2009] [13:04 08/12/2009] 69BD2E12B17DEC67A3BD48723D338E86
C:\WINDOWS\SoftwareDistribution\Download\2b4e48d0ede6112a59b10e3704a22eee\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe --a---- 2927104 bytes [17:33 23/10/2010] [07:33 19/01/2008] FFA764631CB70A30065C12EF8E174F9F
C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe --a---- 2923520 bytes [08:47 02/11/2006] [09:45 02/11/2006] FD8C53FB002217F6F888BCF6F5D7084D
C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe --a---- 2923520 bytes [13:34 08/12/2009] [13:34 08/12/2009] 6D06CD98D954FE87FB2DB8108793B399
C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe --a---- 2923520 bytes [13:04 08/12/2009] [13:04 08/12/2009] 37440D09DEAE0B672A04DCCF7ABF06BE
C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe --a---- 2923520 bytes [13:34 08/12/2009] [13:34 08/12/2009] BD06F0BF753BC704B653C3A50F89D362
C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe --a---- 2923520 bytes [13:04 08/12/2009] [13:04 08/12/2009] E7156B0B74762D9DE0E66BDCDE06E5FB
C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe --a---- 2927104 bytes [13:04 08/12/2009] [13:04 08/12/2009] 4F554999D7D5F05DAAEBBA7B5BA1089D
C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe --a---- 2927616 bytes [13:04 08/12/2009] [13:04 08/12/2009] 50BA5850147410CDE89C523AD3BC606E
Searching for "wininit.exe"
C:\WINDOWS\SoftwareDistribution\Download\2b4e48d0ede6112a59b10e3704a22eee\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe --a---- 96768 bytes [17:31 23/10/2010] [07:33 19/01/2008] 101BA3EA053480BB5D957EF37C06B5ED
C:\WINDOWS\System32\wininit.exe --a---- 95744 bytes [08:44 02/11/2006] [09:45 02/11/2006] F0A27AEEA77769D1463157C7FA40F755
C:\WINDOWS\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe --a---- 95744 bytes [08:44 02/11/2006] [09:45 02/11/2006] D4385B03E8CCCEE6F0EE249F827C1F3E
-= EOF =-
Hope that someone of your forum can help me cleaning the explorer.exe file. I do not have a dvd of my legitime vista, it was pre-installed and has a recovery partition on my laptop.
Hope you can help me out with the following issue I have since thursday; think point virus infected my laptop with vista 32bit. As soon this happened, I switched off internet en rebooted in safe mode. No idea where this virus came from, maybe an outdated Javascript?
From there in safe mode,I used taskmanager, shutdown process hotfix.exe en deleted the file.
I have had the latest windows update already, excluding the latest for the MS office. But I didn't use that on the day of infection.
Avast anti virus was running too.
I tried, malware bytes, super anti spyware and avast. All found virusses. Only after a 10 hour boot scan by Avast it turned out that almost all viruses where gone except at two locations; wininit.exe and explorer.exe
avast was not able to delete/repair these. I renaimed wininit.exe into wininit2.exe and manually deleted it. Now at this time of writing, no reboot has been settled yet.
I tried to understand all of the post: https://www.techspot.com/vb/topic154603.html but found difficulties.
I already used JavaRA to uninstall old versions.
I ran security check;
a Results of screen317's Security Check version 0.99.5
Windows Vista (UAC is disabled!)
Out of date service pack!!
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:
avast! Free Antivirus
Antivirus up to date!
```````````````````````````````
Anti-malware/Other Utilities Check:
Malwarebytes' Anti-Malware
Java(TM) 6 Update 22
Java(TM) 6 Update 2
Out of date Java installed!
Adobe Flash Player 10.1.53.64
Adobe Reader 9.4.0 - Nederlands
````````````````````````````````
Process Check:
objlist.exe by Laurent
Alwil Software Avast5 AvastSvc.exe
Alwil Software Avast5 AvastUI.exe
````````````````````````````````
DNS Vulnerability Check:
GREAT! (Not vulnerable to DNS cache poisoning)
``````````End of Log````````````
With the programm SystemLook I found out that there are several explorer.exe programms running on my pc:
SystemLook 04.09.10 by jpshortstuff
Log created at 10:21 on 25/10/2010 by Simon
Administrator - Elevation successful
========== filefind ==========
Searching for "winlogon.exe"
C:\WINDOWS\SoftwareDistribution\Download\2b4e48d0ede6112a59b10e3704a22eee\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe --a---- 314880 bytes [17:32 23/10/2010] [07:33 19/01/2008] C2610B6BDBEFC053BBDAB4F1B965CB24
C:\WINDOWS\System32\winlogon.exe --a---- 308224 bytes [08:44 02/11/2006] [09:45 02/11/2006] 9F75392B9128A91ABAFB044EA350BAAD
C:\WINDOWS\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe --a---- 308224 bytes [08:44 02/11/2006] [09:45 02/11/2006] 9F75392B9128A91ABAFB044EA350BAAD
Searching for "explorer.exe"
C:\WINDOWS\explorer.exe --a---- 2923520 bytes [13:04 08/12/2009] [13:04 08/12/2009] 69BD2E12B17DEC67A3BD48723D338E86
C:\WINDOWS\SoftwareDistribution\Download\2b4e48d0ede6112a59b10e3704a22eee\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe --a---- 2927104 bytes [17:33 23/10/2010] [07:33 19/01/2008] FFA764631CB70A30065C12EF8E174F9F
C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe --a---- 2923520 bytes [08:47 02/11/2006] [09:45 02/11/2006] FD8C53FB002217F6F888BCF6F5D7084D
C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe --a---- 2923520 bytes [13:34 08/12/2009] [13:34 08/12/2009] 6D06CD98D954FE87FB2DB8108793B399
C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe --a---- 2923520 bytes [13:04 08/12/2009] [13:04 08/12/2009] 37440D09DEAE0B672A04DCCF7ABF06BE
C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe --a---- 2923520 bytes [13:34 08/12/2009] [13:34 08/12/2009] BD06F0BF753BC704B653C3A50F89D362
C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe --a---- 2923520 bytes [13:04 08/12/2009] [13:04 08/12/2009] E7156B0B74762D9DE0E66BDCDE06E5FB
C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe --a---- 2927104 bytes [13:04 08/12/2009] [13:04 08/12/2009] 4F554999D7D5F05DAAEBBA7B5BA1089D
C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe --a---- 2927616 bytes [13:04 08/12/2009] [13:04 08/12/2009] 50BA5850147410CDE89C523AD3BC606E
Searching for "wininit.exe"
C:\WINDOWS\SoftwareDistribution\Download\2b4e48d0ede6112a59b10e3704a22eee\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe --a---- 96768 bytes [17:31 23/10/2010] [07:33 19/01/2008] 101BA3EA053480BB5D957EF37C06B5ED
C:\WINDOWS\System32\wininit.exe --a---- 95744 bytes [08:44 02/11/2006] [09:45 02/11/2006] F0A27AEEA77769D1463157C7FA40F755
C:\WINDOWS\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe --a---- 95744 bytes [08:44 02/11/2006] [09:45 02/11/2006] D4385B03E8CCCEE6F0EE249F827C1F3E
-= EOF =-
Hope that someone of your forum can help me cleaning the explorer.exe file. I do not have a dvd of my legitime vista, it was pre-installed and has a recovery partition on my laptop.