Jump to content

Winlogon Malware | Script Host Disabled

Recommended Posts



Merry Christmas!! Hope you all got to enjoy this festive with your loved ones.


I'm very sorry to come with trouble in this good day.


I unaccidentally allowed access of this "winlogon" from a thumbdrive. I can only see shortcuts in the thumbdrive, in order to access the real directory you need to double click those shortcuts and that when they prompt you with this winlogon.


The first symptom is it quickly disconnects any devices that is connected to my PC (external harddisk,etc) and when you open browser and search "virus" or "winlogon remove" or "malwarebytes", it quickly shutdowns the browser.


However, things has got better. Though, I still can't access my taskmanager as with MalwareBytes (the parameter is incorrect).

My best guess is winlogon has already been removed, but apparently my Windows Script Host is still being Disabled.


I couldn't run HijackThis (the parameter is incorrect) but I manage to run this tool called dds(doesnt do squat) and here is the dds content and attach content..


I use Microsoft Security Essential and the following is my sysinfo:

OS Version: Microsoft Windows 7 Home Premium, Service Pack 1, 64 bitProcessor: Intel(R) Core(TM) i7-2670QM CPU @ 2.20GHz, Intel64 Family 6 Model 42 Stepping 7RAM: 8GBGraphics Card: NVIDIA GeForce GT 540M, 2047 MbMotherboard: Dell Inc., 0NJT03Antivirus: Microsoft Security Essentials, Updated and Enabled
Link to post
Share on other sites

Hello bitemalware and :welcome:! My name is Borislav and I will be glad to help you solve your malware problem.

Please note:

  • If you are a paying customer, you have the privilege to contact the help desk at Consumer Support. If you choose this option to get help, please let me know.
  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.
  • Do not perform any kind of scanning and fixing without my instructions. If you want to proceed on your own, please let me know.
P2P/Piracy Warning:

If you're using Peer 2 Peer software such as µTorrent, StreamTorrent or similar you must either fully uninstall them or completely disable them from running while being assisted here.

Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.

If you have illegal/cracked software, cracks, keygens etc. on the system, please remove or uninstall them now and read the policy on Piracy.

Please generate a new fresh DDS log files.

Link to post
Share on other sites

  • Root Admin

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

This topic is now closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.