The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Virus hooked into winlogon.exe

    Discussion in 'Windows OS and Software' started by CGSUN, Jul 11, 2008.

  1. CGSUN

    CGSUN Notebook Guru

    Reputations:
    0
    Messages:
    56
    Likes Received:
    0
    Trophy Points:
    15
    Does anyone know how to unlock a .dll that has its hooks in a core XP file? Once I unhook the .dll the entire system shuts down. I don’t fancy doing a format, so I hope someone has a funky utility to help me :)

    I have tried with no luck:
    removeonboot.exe
    Unlocker.exe

    Trying from a dos prompt in a safe boot wont work, however it does delete but on return it is back.

    Virus generator appears to be called Vmoolty.dll
     
  2. Andy

    Andy Notebook Prophet

    Reputations:
    2,133
    Messages:
    6,399
    Likes Received:
    1
    Trophy Points:
    206
    When deleting the file through DOS, first switch of System Restore in Windows and then do the deletion....worth a try
     
  3. CGSUN

    CGSUN Notebook Guru

    Reputations:
    0
    Messages:
    56
    Likes Received:
    0
    Trophy Points:
    15
    Just tried that with no luck :(
    boy i smell a format :( there goes my weekend.
     
  4. CGSUN

    CGSUN Notebook Guru

    Reputations:
    0
    Messages:
    56
    Likes Received:
    0
    Trophy Points:
    15
    Further >
    that last reboot (with sysrestore off) was interesting; the virus took control of avira’s engine, shutting it down and infecting it. what a mess.
     
  5. Rodster

    Rodster Merica

    Reputations:
    1,805
    Messages:
    5,043
    Likes Received:
    396
    Trophy Points:
    251
    Have you tried Avast AV? While Avira is great at detecting Avast seems to do a better job eliminating viruses.
     
  6. csinth

    csinth Snitch?

    Reputations:
    181
    Messages:
    1,277
    Likes Received:
    0
    Trophy Points:
    55
    I would certainly say try Avast! Home Edition and a safemode scan and whatnot.
     
  7. Moocowz

    Moocowz Notebook Guru

    Reputations:
    0
    Messages:
    63
    Likes Received:
    0
    Trophy Points:
    15
    If you can't do it yourself, I strongly recommend Geeks to Go. http://www.geekstogo.com/forum/forums.html I once had a bad case of that winfixer adware that caused my CPU to soar to 100% when nothing was going on. I believe that it cause winlogon to eat up my CPU. Anyway, these guys helped me get rid of it.
     
  8. ravenmorpheus

    ravenmorpheus Notebook Deity

    Reputations:
    26
    Messages:
    846
    Likes Received:
    0
    Trophy Points:
    30
    Download shellexview.exe as well. It'll show you where the hook is in the registry and you'll be able to delete it that way, I had a similar virus that hooked my explorer.exe so it kept restarting every 4-5 seconds or so...
     
  9. CGSUN

    CGSUN Notebook Guru

    Reputations:
    0
    Messages:
    56
    Likes Received:
    0
    Trophy Points:
    15
    Cheers for everyone’s help!
    Avast’s engine was also quickly infected.

    I never did get to try shellx but I will grab a copy!

    What did work was unlocker.exe, although I had to have quick fingers before the system shut down. Unhooked and hit delete on the .dll generator in a ¼ second. It went.

    This is the same virus geeks-to-go said a complete format was the only way to remove