Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Virus Trojan.Pandex!inf in winlogon.exe cannot remove repair or Quarantine
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > Virus Trojan.Pandex!inf in winlogon.exe cannot remove repair or Quarantine  
Forum Quick Jump
 
New Topic Post reply to : Virus Trojan.Pandex!inf in winlogon.exe cannot remove repair or Quarantine Printable version of : Virus Trojan.Pandex!inf in winlogon.exe cannot remove repair or Quarantine
[ << Previous Thread | Next Thread >> ]

Hebb
New Member


Date Joined Feb 2007
Total Posts : 3
 
   Posted 2-25-2007 1:36 (GMT +1)    Quote: Virus Trojan.Pandex!inf in winlogon.exe cannot remove repair or QuarantineAlert an admin about: Virus Trojan.Pandex!inf in winlogon.exe cannot remove repair or Quarantine
 
 My Antivirus program has detected a virus: Trojan.Pandex!inf in File: C:\WINDOWS\system32\winlogon.exe. However, it is unable to clean, remove, or quarintine the virus. Any suggestions?
 
Here is the hijackthis log:
 
Logfile of HijackThis v1.99.1
Scan saved at 6:44:56 PM, on 2/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Common Files\Virtual Token\vtserver.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\SKDAEMON.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\SM1BG.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Razer\razerhid.exe
C:\Program Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Eyeball\Eyeball Chat\EyeballChat.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\Razer\razertra.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Razer\razerofa.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Documents and Settings\Gardewine\Local Settings\Temporary Internet Files\Content.IE5\OD2RG56J\alternativ[1].exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 147.202.69.179:5190
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Image Helper - {31677ADF-17D9-5516-E17D-3E459D631863} - C:\WINDOWS\system\bplctw32.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Hot Key Kbd Daemon] SKDAEMON.EXE
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\razerhid.exe
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Eyeball Chat] "C:\Program Files\Eyeball\Eyeball Chat\EyeballChat.exe" -min
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/service_components/control/activex/TmHcmsX.CAB
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1172361933234
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe

Post Edited (Hebb) : 2/25/2007 12:48:22 AM GMT

Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14325
 
   Posted 2-25-2007 7:20 (GMT +1)    Quote: Virus Trojan.Pandex!inf in winlogon.exe cannot remove repair or QuarantineAlert an admin about: Virus Trojan.Pandex!inf in winlogon.exe cannot remove repair or Quarantine
Hi Hebb smile
 
 
Please download ATF Cleaner:
 http://www.atribune.org/ccount/click.php?id=1 by Atribune.
This program is for XP and Windows 2000 only
 
 
Download and install DrWebCureit:
 
 
 
Please print out or copy this page to Notepad as you will be in Safe Mode and unable to refer to this page.
 
 
 
Reboot into Safe  Mode   by tapping F8 after the BIOS has loaded.
The Windows Advanced Options Menu appears.
Ensure that the Safe mode option is selected.
Press Enter. The computer then begins to start in Safe mode.
 
 
 
 
 
 
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
NB. It's normal after running ATF cleaner that the PC will be slower to boot the first time.
 
 
Doubleclick the "drweb-cureit.exe" and click "ok" in the prompt window that will open , asking "start the express scan now".
It will first make a quick scan of your system, let it clean what it find, and when it says "done"
Click on the green screwdriver-
Actions Tab- Adware-Dialers-Riskware-Hacktools, use dropdown menu and select -Rename
Click on the drive(s) you want to scan . A red dot will mark the selected drive(s) . Then hit the green  arrow in lower right corner It will now scan your  drive(s), say yes to all
 
After the scan, in the Dr.Web CureIt menu on top, click file and choose save report list
Save the report to your desktop. The report will be called DrWeb.csv
Close Dr.Web Cureit.
 
Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
 
After reboot, post the contents of the log from Dr.Web you saved previously in your next reply along with new hijackthis log and tell how things are running.
 
 
 


Do NOT post your problem in someone elses thread.
Start a new topic so that it may receive proper attention. 
 

Back to Top
 

chimpmagnet
New Member


Date Joined Feb 2007
Total Posts : 8
 
   Posted 2-26-2007 12:23 (GMT +1)    Quote: Virus Trojan.Pandex!inf in winlogon.exe cannot remove repair or QuarantineAlert an admin about: Virus Trojan.Pandex!inf in winlogon.exe cannot remove repair or Quarantine
Touch,

Sorry I don't mean to hijack these threads but I know how worrying this virus is! I hope these guys aren't surfing important websites with this virus -- it sends data to remote hackers, so be careful.
Hebb --
To remove this trojan, use the free trial version of http://www.kaspersky.com/

This immediately detected the trojan.pandex!inf in my winlogon.exe and fixed it. Then I removed main.sys, runtime.sys and wsys.dll from the system32 folder.

Post Edited (chimpmagnet) : 2/26/2007 11:24:04 AM GMT

Back to Top
 

Hebb
New Member


Date Joined Feb 2007
Total Posts : 3
 
   Posted 2-26-2007 5:51 (GMT +1)    Quote: Virus Trojan.Pandex!inf in winlogon.exe cannot remove repair or QuarantineAlert an admin about: Virus Trojan.Pandex!inf in winlogon.exe cannot remove repair or Quarantine
Yeah, don't worry I haven't been doing anything that they would be able to get a hold of a cc number or anything like that. But I do need to fill out my university application and send in a fee with it so I need to get this off before i can do that.
Back to Top
 

Hebb
New Member


Date Joined Feb 2007
Total Posts : 3
 
   Posted 2-26-2007 10:34 (GMT +1)    Quote: Virus Trojan.Pandex!inf in winlogon.exe cannot remove repair or QuarantineAlert an admin about: Virus Trojan.Pandex!inf in winlogon.exe cannot remove repair or Quarantine
The virus is still being detected by my symantec Anti virus. Everytime I open up Internet explorer I get a notification of Trojan.Pandex!inf in winlogin.exe. I followed your steps to the letter but it still hasn't went away. Here are my new logs. Any further advice would be greatly appreciated.
 
Hijackthis:
Logfile of HijackThis v1.99.1
Scan saved at 3:29:58 PM, on 2/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Common Files\Virtual Token\vtserver.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\SKDAEMON.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\SM1BG.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Razer\razerhid.exe
C:\Program Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Eyeball\Eyeball Chat\EyeballChat.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\Razer\razertra.exe
C:\Program Files\Razer\razerofa.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\alternativ.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 147.202.69.179:5190
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Image Helper - {31677ADF-17D9-5516-E17D-3E459D631863} - C:\WINDOWS\system\bplctw32.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Hot Key Kbd Daemon] SKDAEMON.EXE
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\razerhid.exe
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Eyeball Chat] "C:\Program Files\Eyeball\Eyeball Chat\EyeballChat.exe" -min
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/service_components/control/activex/TmHcmsX.CAB
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1172361933234
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe
 
And Here's my log from Drweb:
 
bplctw32.dll;c:\windows\system;Trojan.Proxy.1442;Deleted.;
wuauclt.exe;c:\windows\temp;BackDoor.Bulknet;Will be cured after reboot.;
ta_battle.exe;C:\Documents and Settings\Gardewine\Desktop;Modification of BackDoor.Generic.872;Moved.;
osfilter.txt;C:\Program Files\IBM\IBM Rapid Restore Ultra;Probably SCRIPT.BATCH.Virus;;
mirc.exe;C:\Program Files\mIRC;Program.mIRC.616;Renamed.;
Process.exe;C:\SDFix\apps;Tool.Prockill;Renamed.;
A0064130.exe;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP291;BackDoor.Apex.40;Deleted.;
A0064158.sys;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP293;BackDoor.Bulknet;Deleted.;
A0064172.dll;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP293;Trojan.MulDrop.5450;Deleted.;
A0064181.sys;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP293;BackDoor.Bulknet;Deleted.;
A0065342.dll;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP296;BackDoor.Bulknet;Deleted.;
A0066342.dll;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP296;BackDoor.Bulknet;Deleted.;
A0068349.dll;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP296;BackDoor.Bulknet;Deleted.;
A0069349.dll;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP296;BackDoor.Bulknet;Deleted.;
A0069771.dll;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP297;BackDoor.Bulknet;Deleted.;
A0070199.dll;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP298;BackDoor.Bulknet;Deleted.;
A0070250.dll;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP298;Trojan.KeyLogger.565;Deleted.;
A0070251.exe;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP298;Program.SpyBuddy;Renamed.;
A0070254.dll;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP298;Trojan.KeyLogger.565;Deleted.;
A0070257.dll;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP298;Program.SpyBuddy;Renamed.;
A0070258.dll;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP298;Trojan.KeyLogger.565;Deleted.;
A0071283.dll;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP299;Trojan.Testie;Deleted.;
A0071284.dll;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP299;Trojan.Testie;Deleted.;
A0072407.dll;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP299;BackDoor.Bulknet;Deleted.;
A0073407.dll;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP300;BackDoor.Bulknet;Deleted.;
A0073411.sys;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP300;BackDoor.Bulknet;Deleted.;
A0073423.dll;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP300;BackDoor.Bulknet;Deleted.;
A0073427.sys;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP300;BackDoor.Bulknet;Deleted.;
A0073436.dll;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP300;BackDoor.Bulknet;Deleted.;
A0074438.sys;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP300;BackDoor.Bulknet;Deleted.;
A0074442.dll;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP300;Trojan.Proxy.1442;Deleted.;
A0074443.exe;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP300;Modification of BackDoor.Generic.872;Moved.;
A0074444.exe;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP300;Program.mIRC.616;Renamed.;
A0074445.exe;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP300;Tool.Prockill;Renamed.;
peqghhlm.exe;C:\WINDOWS\system32;Trojan.Proxy.1442;Deleted.;
wsys.dll;C:\WINDOWS\system32;BackDoor.Bulknet;Will be cured after reboot.;
wuauclt.exe;C:\WINDOWS\Temp;BackDoor.Bulknet;Deleted.;



Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14325
 
   Posted 2-27-2007 6:22 (GMT +1)    Quote: Virus Trojan.Pandex!inf in winlogon.exe cannot remove repair or QuarantineAlert an admin about: Virus Trojan.Pandex!inf in winlogon.exe cannot remove repair or Quarantine
Hi Hebb
 
 
Try this, it have helped other with same infection -
 
Run a SFC = System File Checker -
 
The main reason for using this utility is when you suspect there may be a problem with a Windows XP system file.
It is therefore worth checking to see if there are any corrupt system files using scannow sfc.
To do this simply go to the Run box on the Start Menu and type in:
sfc /scannow
This command will immediately initiate the Windows File Protection service  to scan all protected files and verify their integrity, replacing any files with which it finds a problem.


Reboot and tell how things are running


Do NOT post your problem in someone elses thread.
Start a new topic so that it may receive proper attention. 
 

Back to Top
 

dimos
New Member


Date Joined Feb 2008
Total Posts : 3
 
   Posted 2-17-2008 4:41 (GMT +1)    Quote: Virus Trojan.Pandex!inf in winlogon.exe cannot remove repair or QuarantineAlert an admin about: Virus Trojan.Pandex!inf in winlogon.exe cannot remove repair or Quarantine
I think this little post I have might be of help here, if not then sorry for the clog effect...
 
Well, it all started when poor innocent Magdy was sitting at his pc doing what he loves most following the WWF show updates online. Suddenly as he was searching for other Wrestling sites a pop-up appeared on one site and informed him that his machine was loaded with viruses and that their own nifty program could help rid him of his worries if only he were to click OK. Being the kind trusting fellow that he is, Magdy though, well why not? And SNAP went the trap. The program installed itself and indicated that there were 29 virus threats that it would soon now alleviate as soon as he would pay the due amount for such a noble service.  Thinking well about this Magdy and now Mourad, his brother, at his side, decided that they did not like the new Malware Crush program on their PC and proceeded to uninstall it. They then ran a scan with their on-system virus scanner McAfee but no viruses were to be found. So the case was closed and no worries remained.
A little later anxiety gnawed at Magdy’s conscience and he decided to call me, his technical advisor in such matters. So over I went with my toolkit of CDs. I sat at the machine and figured I’d first have a look at all the running processes on the machine. For this I usually like to use Sysinternals Process Explorer. I open up Google and quickly locate the site and click on the technet link for the process explorer page. Wham! The browser vanishes. A creepy feeling made its way down my spine but I shook it off, must be low on RAM or something. I’ll try again. This time I searched for the Malware Crush and I found a removal instructions page. Again I click on the link, it starts to load and then the browser vanishes again. The creepy feeling smacked me on the head this time and spread all through my mind.
“It’s a virus” I said. Or a Trojan, or a worm or whatever, the range of names just grows daily, but they’re all in the end a bunch of malicious programs made by some really stinky smelly people that don’t take showers enough.
Anyhow so I started up my UBCDW 3.10 (Ultimate Boot CD for windows) PE environment and started my scanning tools. I tried every single Anti-virus software on there and they all came up with a few bad cookies and that was it. I deleted the cookies, and whatever registry key they threw at me (making sure they were not important keys that were misidentified) and then restarted the pc. I tried again to load the web link for process Explorer and again I was burnt to see it vanish. !!!!, I thought. How do I get around this?
Well to get on to the sites I needed I ended up just right-clicking the links and downloading the pages I wanted locally and then viewed them with notepad to find the links for the zip files I needed. I did so for process explorer and soon had process explorer on the desktop in front of me. Smiling broadly I unzipped the program and ran it. SMACK! Another blow under the belt. Process explorer would no sooner start than vanish just like the internet explorer browser when it went to the virus-hated pages. This was one rough &^@% of a son.
At that point my aching sinus tract was not helping. I went home with the PC tower under my arm, laid it next  to my bed and crashed for a bit. When I got up I had decided not to be beaten by the virus, I was going to leave a full-format of the harddrive as a final resort. First I would fight.
I sat there at the UBCD environment and started downloading the tools I would use.
Process Explorer –  to see the processes that are running and any file-handles they were using
Process Monitor – to see which process was actually terminating the other processes that were running
ResHacker – to mutilate the prior pair’s appearance beyond recognition so that the virus would not identify them as hostiles
XVI32 – My favorite hex-editor to mess around on the binary level if not all identifiers were removed by Reshacker
RootkitRevealer and HiJackThis! – again to try and find the horrid little thing that was making the PC choke
Well first off I started the ResHacker and changed any references to the Process Explorer or procexp.exe so that they said banana republic or whatever, anything that filled up the correct amount of byte-space but was not a give-away of the process itself. I did the same for Process Monitor, RootkitRevealer and HiJackThis.
To my joy, after about ten tries with each program trying to get all the relevant strings out and finding the important ones (mainly window and dialog titles were the give-aways), the programs started and the virus was lulled into false-security. It was time to use the tools to find that little punk and put him out of action.
Process explorer showed me no signs of a rogue process running. I figured then that the virus must have infected one of the running processes. I confirmed this by running the old unmodified tools and the virus immediately shut them down.
I ran Process Monitor and then started up the unmodified tools several times in succession to get a good log of all the occurrences on the system and capture the virus red-handed as it terminated the processes that were running.
I could then see the unmodified exe start, set itself up and then fall down and die with a thread exit. However, I could not find a way to monitor the TerminateProcess API call for windows. In dismay I browsed around to see what was happening between every instance of the unmodified exe I had started. Nothing strange was apparent. Winlogon.exe seemed to be doing a few things but I wasn’t particularly sure what. I expanded the Path view and was surprised to see winlogon.exe reference a bbffdebdbfc.dll. Strange I had never run across such a name for a dll. I quickly googled the name but came up empty. I looked at the path again, C:\windows\system32\bbffdebdbfc.dll. I browsed to the file and tried to open it with XVI32. It was being used by another program and so I couldn’t access it. I went into Process explorer->Find->File Handle or Dll. I gave it the name of the file and sure enough, it belonged to the winlogon.exe process. It had the Dll listed under it’s open handles.  ( I remember also seeing a CreateFile() call on the dll, which according to an article I just read is one technique to obtain a file lock and block access to that file http://www.symantec.com/avcenter/reference/techniques.of.adware.and.spyware.pdf).
I double-clicked the dll and was shown a list of all the loaded modules for winlogon.exe.
For bbffdebdbfc.dll it had the following:
Description: DA resident module
Company Name: Analog Devices
Double-clicking the module in the list I was shown the dll properties.
The Strings tab showed me all the strings available inside the module with many insightful function names, but mainly TerminateProcess was the one to catch my attention. SUNABAGUN!
I looked at the process properties for winlogon.exe and found that it had indeed a started thread running with a start address at the beginning of bbffdebdbfc.dll. Wonderful, I thought. I selected the thread and killed it. I went back to the open file handles and closed the one for bbffdebdbfc.dll. Voila!  The process had let go of the dll and I was able to then open it up with XVI32 and explore it.
Well next was the process of removing all the dirt. First off we have to put back the original winlogon.exe. The system was running SP2 so I started the setup exe for SP2 which extracted the I386 folder into a temporary folder on another machine I had. I started the Cmd.exe and typed:
expand winlogon.ex_  winlogon.exe
I put that on a network share and started the infected machine with UBCD again and replaced the winlogon.exe file with the SP2 version and crossed my fingers.
 
Running Regedit off the UBCD I found HKCU\Software\Microsoft\Internet Explorer\Explorer
Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU\000 with a value of bbffdebdbfc. The registry value is to be removed.
 
I’ve failed to find references to the actual virus name except for the following website which
 
 
Back to Top
 
New Topic Post reply to : Virus Trojan.Pandex!inf in winlogon.exe cannot remove repair or Quarantine Printable version of : Virus Trojan.Pandex!inf in winlogon.exe cannot remove repair or Quarantine
 
Forum Information
Currently it is Friday, January 09, 2009 2:21 AM (GMT +1)
There are a total of 65.961 posts in 16.185 threads.
In the last 3 days there were 24 new threads and 93 reply posts. View Active Threads
Who's Online
This forum has 27794 registered members. Please welcome our newest member, schneevogel.
45 Guest(s), 1 Registered Member(s) are currently online.  Details
bindujagarla
5 Latest Threads
Vbs malware gen in phone memory card.. please help (1)09-01-2009 01:20:25 (bindujagarla)
Random pop-ups (0)09-01-2009 00:10:41 (yogendra)
Some nasty trojan (4)08-01-2009 23:58:06 (buioch)
Anybody can help me remove Downloader Conhook Trojan? (2)08-01-2009 23:20:29 (menkixede)
Help with slow computer and file removal (3)08-01-2009 23:12:07 (papy1)