1. Welcome! Please take a few seconds to create your free account to post threads, make some friends, remove a few ads while surfing and much more. ClutchFans has been bringing fans together to talk Houston Sports since 1996. Join us!

winlogin.exe, yuetyutr.dll - does anybody know how to get rid of this trojan/worm

Discussion in 'BBS Hangout' started by what, Jun 10, 2005.

Tags:
  1. what

    what Member

    Joined:
    Dec 4, 2003
    Messages:
    14,621
    Likes Received:
    2,593
    I have tried serveral programs and many things that are supposed to remove them but nothing does. Microsoft Spyware said it removed it but no it is still there and a-squared as well. I have tried to manuelly delete the file, but nothing works it keeps coming back after I delete it.
     
  2. Dennis2112

    Dennis2112 Member

    Joined:
    Dec 7, 1999
    Messages:
    1,187
    Likes Received:
    3
    Possible answer

    Look for a program called "process explorer"

    I am pretty sure it is free to download

    After boot up, execute the program and see what the parent program is that is starting the worms. The program will allow you to suspend or end the worm so you can delete it.


    I hope that helps...
     
  3. what

    what Member

    Joined:
    Dec 4, 2003
    Messages:
    14,621
    Likes Received:
    2,593
    thanks for the help. Stupid me, but I didn't realize before I posted this that the a-sqaured program worked. I needed to reboot. Finally removed. I bet I had that worm on my computer for 2 years.
     
  4. Manny Ramirez

    Manny Ramirez The Music Man

    Joined:
    Jul 31, 2001
    Messages:
    28,899
    Likes Received:
    5,770
    What exactly does this winlogin.exe, yuetyutr.dll trojan/worm thing do? Like what are some of its characteristics? Because I think I have the same thing is why I am asking.
     
  5. what

    what Member

    Joined:
    Dec 4, 2003
    Messages:
    14,621
    Likes Received:
    2,593
    it has the potential to takescontrol of your computer, basically:

    The worm contains its own IRC client, allowing it to connect to specified IRC servers and join a channel to listen for commands from the worm's creator.

    One such command is to exploit the DCOM RPC vulnerability: The worm generates random IP addresses. Once the IP address is generated, it sends specially formed data, which exploits the DCOM RPC vulnerability, to that particular IP address.


    Creates a hidden Cmd.exe remote shell that will listen on TCP port 4444, allowing an attacker to issue remote commands on an infected system.


    Creates a thread running as a TFTP server, listening on UDP port 69. When the worm receives a request from a computer to which it can connect using the DCOM RPC exploit, it will send Nstask32.exe or Winlogin.exe to that particular computer and tell it
     
  6. Sishir Chang

    Sishir Chang Member

    Joined:
    Nov 12, 2000
    Messages:
    11,064
    Likes Received:
    8
    How do you know you have it? Can Spybot catch it?
     
  7. what

    what Member

    Joined:
    Dec 4, 2003
    Messages:
    14,621
    Likes Received:
    2,593
    Microsoft spyware caught mine. But I kinda already knew I had it and was trying to use microsoft to remove it.

    If I were you, instead of me telling you where to look in registry, download a-sqaured spyware, either at tucows or a-square website. Then run it and see what it finds. After you remove all the spyware you need to reboot and you should be good to go.

    You might need to bring up msconfig once you reboot so that you can remove the reference in your startup file.
     

Share This Page

  • About ClutchFans

    Since 1996, ClutchFans has been loud and proud covering the Houston Rockets, helping set an industry standard for team fan sites. The forums have been a home for Houston sports fans as well as basketball fanatics around the globe.

  • Support ClutchFans!

    If you find that ClutchFans is a valuable resource for you, please consider becoming a Supporting Member. Supporting Members can upload photos and attachments directly to their posts, customize their user title and more. Gold Supporters see zero ads!


    Upgrade Now