Re: winlogG.exe, winlogO.exe, winlogY.exe, winlogB, winlog.exe

From: Rick \ (rick_at_mvps.org)
Date: 10/23/04


Date: Sat, 23 Oct 2004 07:21:53 -0400

Hi Joe,

<said like Mr. Rogers>

Can you say "trojan"? I knew that you could.....

<ok, seriously>

They are trojan (virus) files. Follow these "relatively" simple removal
steps:

Restart in Safe mode by hitting F8 as Windows first begins to load on boot.
Logon as administrator. You can find help on doing this here:
http://www.rickrogers.org/fixes.htm#Safe%20mode

Start/search/files and folders, look for <filename> and delete it wherever
it is found.

Start/run regedit, expand the + signs to look under these keys:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg

Look in the right hand pane for the string or strings that load that file.
Delete just those strings that contain the reference. Do not delete other
strings or the keys from the left pane. Close the registry editor when
completed, make sure you check all strings.

Go to the Control Panel/System/System Restore tab. Check the box to "Turn
off system restore on all drives". Click apply/ok. This will remove all
restore points, however you don't want them back as some or all of them will
contain the virus depending upon how recently you got infected.

Restart the system normally. Go back to the Control Panel/System and restart
System Restore.

Update your antivirus software, run a full system scan.

-- 
Best of Luck,
Rick Rogers, aka "Nutcase" - Microsoft MVP
http://mvp.support.microsoft.com/
Associate Expert - WindowsXP Expert Zone
www.microsoft.com/windowsxp/expertzone
Windows help - www.rickrogers.org
"Joe" <Joe@discussions.microsoft.com> wrote in message 
news:24E8488F-FC07-4D4E-80B1-F6E994BC2B5D@microsoft.com...
> The above mentioned programs are requesting access to the internet. I get
> notified through my zone alarm. i have not allowed them to access since i 
> do
> not recognise any of them. can anyone please let me know what these 
> programs
> are, or are if they a threat. i've run a current virus scan and ad aware 
> and
> nothing was found. but as i said i do not recognise these programs nor 
> have i
> installed anything new. thanks. 


Relevant Pages

  • Re: canti.exe
    ... It's a trojan (virus) file. ... Restart in Safe mode by hitting F8 as Windows first begins to load on boot. ... Look in the right hand pane for the string or strings that load that file. ...
    (microsoft.public.windowsxp.general)
  • Re: iqkiajdb.exe file in WinXP Profesional keeps Not Responding and can not be deleted
    ... Trojan (virus) file. ... Restart in Safe mode by hitting F8 as Windows first begins to load on boot. ... Look in the right hand pane for the string or strings that load that file. ...
    (microsoft.public.windowsxp.general)
  • Re: uasdfbgibv.exe - what is this?
    ... It's a trojan (virus) file. ... Restart in Safe mode by hitting F8 as Windows first begins to load on boot. ... Look in the right hand pane for the string or strings that load that file. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: What does cdomeui.exe.file do?
    ... You don't want it accessing the internet ... Restart in Safe mode by hitting F8 as Windows first begins to load on boot. ... Look in the right hand pane for the string or strings that load that file. ... off system restore on all drives". ...
    (microsoft.public.windowsxp.general)
  • Re: cpu at the races
    ... Restart in Safe mode by hitting F8 as Windows first begins to load on boot. ... Look in the right hand pane for the string or strings that load that file. ... off system restore on all drives". ...
    (microsoft.public.windowsxp.general)