Help with Malware/ logonui.exe Application errors

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ETRAIN, Nov 2, 2009.

  1. ETRAIN

    ETRAIN Private E-2

    Hello, I contracted a virus yesterday that caused a host of problems on my PC. Clicking on links would lead to ads, the folders options after right clicking my start menu and clicking explore ended up being deleted, and I ended up being locked out to making changes to the registry.

    When I would log on, there would be an error message reading: logonui.exe Application error.

    The instruction at 0x006002d9 referenced memory at 0x006002d9. The referenced memory could not be written.

    It then gives me a choice to terminate or debug.

    Whenever I rebooted my computer, I would get the above message and after clicking terminate or debug (they both seemingly did the same thing), when my screen would load, no programs would come up and a message would read:

    Windows logon ui has encountered an error and will need to close. It would also say that Windows' data execution prevention prevented it from being opened. I wouldn't even be able to open Windows Task Manager.

    I would have to hold the power button to shut off and then turn it back on. Interestingly enough, while I would get the logonui.exe errors, I would be able to enter windows without it crashing.

    I tried to follow the Read and Run Me First as best as I could. Before I could even do that, I had to download some programs on my other computer and install them onto the broken one so I could make changes to the registry and allow my computer to access hidden files.

    Also, I had to install the software for the Read and Run Me first through a flash drive because the browser hijack prevented me from opening up the locations to download. I created a folder in the C drive for them.

    After running everything, the browser hijack is gone, and most of the serious problems that compromised my computer have disappeared.

    I reran Malwarebytes and Superantispyware after everything and several pieces of malware remained and still have not been deleted.

    However, I'm still not able to access Microsoft.com, the logonui.exe error remains, my computer crashes on reboots, and I'm still reading malware that I can't delete.

    I'm going to send the logs for all the Read and Run First applications. Since I performed the malwarebytes scan after following the instructions (I thought perhaps my computer was 100% fixed), I'll send the more recent log.

    I await instructions on what to do next.
    Thank you.
     

    Attached Files:

  2. ETRAIN

    ETRAIN Private E-2

    And the MGlogs as well.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Sorry to give you the bad news but you will have to do a total clean reinstall.

    I can see the reason for your problems. Your logs show that your Windows Operating system files have become infected by a Virut infection and there is no known reliable fix for this. In addition there are many many other infected files. We could spend a lot of time trying to remove this infection, but odds are that it will not work because the nature of the infection has so many executable system files infected that as soon as we fix one file, other files that are infected will almost immediately or upon the next reboot, just reinfect the files. In addition, your PC would still basically be unreliable/untrustworthy even if we manage to fix the infected files that we can see since there could be many more that we are not seeing.

    The safest thing for you to do is backup your personal data immediately since your PC could possibly become unbootable at any point in time. Do not back up any executable files. This includes programs that you have downloaded since any of them could be infected. Anything you may have already backed up that is an executable type file (things you downloaded to install programs....etc) are most likely infected and will cause you to be reinfected if you reuse these files.

    Once you backup, you need to format partitions and reinstall Windows and all other software especially your protection software. Then install all updates for all software. DO NOT reinstall from any executable file backups you made while this PC was infected or you will just be reinstalling the infection.
     
  4. ETRAIN

    ETRAIN Private E-2

    Not exactly the news I wanted to hear, but whatever must be done will be done. I appreciate the prompt reply. Thank you.
     
  5. ETRAIN

    ETRAIN Private E-2

    I've been thinking about getting a new computer anyway, so I'll probably just ditch the broken one and by a new PC.

    I backed up some Word documents and movies I didn't have backed up onto an external hard drive. I didn't back up any .exe files, though there were a small handful of .exe files already on the external. Those could be deleted though, most are freeware that wouldn't take long to download. I disabled autorun on my other computer, plugged in the external and scanned it with my Norton 360. It found one W32.virut.cf virus on the external and says it removed the risk. I rebooted, rescanned, and Norton found nothing.

    I read up on the virus a little bit and it looks like it's real difficult to get rid of (as my case is a testament to), though that's when it's already been installed on the computer itself. From what you may know of the virus, is it that easy to get rid of from an external hard drive, or is it just messing with my Norton?

    I know that may sound like a silly question, but since I'm probably going to purchase a new computer, I want to make sure I don't reinfect it with the same thing that chewed through my old computer. If Norton really did destroy it, and I'm going to get rid of my old comp, then I should be free of the blasted thing. Needless to say, I won't run the external on any computer until I get a go-ahead.

    Again, thanks for all the help and advice.
     
  6. ETRAIN

    ETRAIN Private E-2

    Disregard my latest message. I scanned the external multiple times with different anti-viruses and found nothing. I purchased a new computer, scanned again, found nothing, installed the backed up files, and everything is running smoothly.

    Thank you for your assistance.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds