MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 02-22-08, 06:37
JhonnyB JhonnyB is offline
Private First Class
 
Join Date: Jan 2006
Posts: 61
Thanks: 5
Thanked 0 Times in 0 Posts
Default Winlogon.exe ??

So, I recently updated my COMODO firewall and it made a malware scan and found a Trojan in C:/Windows/system32/winlogon.exe .
It couldn't remove it so It quarantined it and after that I couldnt reboot into windows, I would get a blue screen stop error.
So I uninstalled comodo thorugh safe mode and now It booted just fine.No other scan recognizes this file as trojan so I dont really know what I can do.
Any thoughts?
Reply With Quote
Sponsored links
  #2  
Old 02-22-08, 14:44
JhonnyB JhonnyB is offline
Private First Class
 
Join Date: Jan 2006
Posts: 61
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: Winlogon.exe ??

Bump, Plx
Reply With Quote
  #3  
Old 02-22-08, 19:02
abri's Avatar
abri abri is offline
Major Geek
 
Join Date: May 2005
Location: inside the Trojan Horse
Posts: 6,000
Thanks: 24
Thanked 47 Times in 46 Posts
Default Re: Winlogon.exe ??

Hi JhonnyB,
Welcome to the Malware Forum!

I advise you not to bump as it leads to scoldings. What trojan did it find? It may have been a false positive. If you're having malware symptoms go through the READ & RUN ME FIRST and attach the requested scans. Alternatively, you could go to the Alternate Scans and run BitDefender and Panda and see if they come up with anything. These can only be run with Internet Explorer. They're both good.

Thanks.
abri
Reply With Quote
  #4  
Old 02-24-08, 06:25
JhonnyB JhonnyB is offline
Private First Class
 
Join Date: Jan 2006
Posts: 61
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: Winlogon.exe ??

I ran the online scans and they didnt detect any malware. Also I may have some symptoms but I think they can be traced to other reasons and for the most part my laptop is working fine.
I did some reading and found out this file is genuine and has something to do with the boot process ,so that would explain why quarantining it gave me that error.
But there are some trojans which pose as it. Still not sure why my firewall detects it as a threat, but Im more calm now.
Thx
Reply With Quote
  #5  
Old 02-24-08, 20:29
abri's Avatar
abri abri is offline
Major Geek
 
Join Date: May 2005
Location: inside the Trojan Horse
Posts: 6,000
Thanks: 24
Thanked 47 Times in 46 Posts
Default Re: Winlogon.exe ??

Hi jhonny,
If you happen to have the Combofix log and the MGlogs.zip, I could check them to see if the file you're worried about is infected. If you'd like for me to do this, please attach them to your next post.
abri
Reply With Quote
Sponsored links
  #6  
Old 03-03-08, 12:12
JhonnyB JhonnyB is offline
Private First Class
 
Join Date: Jan 2006
Posts: 61
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: Winlogon.exe ??

Hi abri, I didnt know there was another reply here, but I have attached the files in this post, so if you can check it out it would be cool.
Btw my OS is in czech so I dunno if that may be a problem to understand the log files.
Attached Files
File Type: txt ComboFix.txt (14.7 KB, 4 views)
File Type: zip MGlogs.zip (39.1 KB, 2 views)
Reply With Quote
  #7  
Old 03-03-08, 16:13
abri's Avatar
abri abri is offline
Major Geek
 
Join Date: May 2005
Location: inside the Trojan Horse
Posts: 6,000
Thanks: 24
Thanked 47 Times in 46 Posts
Default Re: Winlogon.exe ??

Hi JhonnyB,
Please do the following:

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for attaching back to the forum).
  • Attach Report.txt with your next post.
abri
Reply With Quote
  #8  
Old 03-03-08, 18:09
JhonnyB JhonnyB is offline
Private First Class
 
Join Date: Jan 2006
Posts: 61
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: Winlogon.exe ??

Done, it looks like it didnt find anything.
Attached Files
File Type: txt Report.txt (4.3 KB, 2 views)
Reply With Quote
  #9  
Old 03-03-08, 22:40
abri's Avatar
abri abri is offline
Major Geek
 
Join Date: May 2005
Location: inside the Trojan Horse
Posts: 6,000
Thanks: 24
Thanked 47 Times in 46 Posts
Default Re: Winlogon.exe ??

Hi JhonnyB,
I'm always the optimist. I had hoped SDFix would pick up that lot of tmp files you have. I think what Comodo found was a false positive.

Please do the following:

Delete this file: C:\WINDOWS\system32\eRLog.ini

And this folder: C:\WINDOWS\System32\drivers\down

Then rename the following files in the box below by putting the name .old after them:
(example: C:\WINDOWS\system32\SET479.tmp would become SET479.tmp.old)
Quote:
C:\WINDOWS\SET431.tmp
C:\WINDOWS\system32\SET479.tmp
C:\WINDOWS\system32SET480.tmp
C:\WINDOWS\system32SET484.tmp
C:\WINDOWS\system32SET489.tmp
C:\WINDOWS\system32SET464.tmp
C:\WINDOWS\system32SET465.tmp
C:\WINDOWS\system32SET47A.tmp
C:\WINDOWS\system32SET47B.tmp
C:\WINDOWS\system32SET47C.tmp
C:\WINDOWS\system32SET481.tmp
C:\WINDOWS\system32SET485.tmp
C:\WINDOWS\system32SET486.tmp
C:\WINDOWS\system32SET48B.tmp
C:\WINDOWS\system32SET4DE.tmp
C:\WINDOWS\system32SET4DF.tmp
C:\WINDOWS\system32SET4EB.tmp
Also, if you do not use Windows Messenger (not to be confused with MSN Messenger!!) I would like you to run Disable/Remove Windows Messenger

And finally, please run C:\MGtools\GetLogs.bat and attach the fresh MGlogs.zip.

Let me know how things are running.
abri
Reply With Quote
  #10  
Old 03-04-08, 04:42
JhonnyB JhonnyB is offline
Private First Class
 
Join Date: Jan 2006
Posts: 61
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: Winlogon.exe ??

Done, but I dont have the C:\WINDOWS\System32\drivers\down folder on my system.
Attached Files
File Type: zip MGlogs.zip (39.5 KB, 3 views)
Reply With Quote
Sponsored links
  #11  
Old 03-05-08, 16:06
abri's Avatar
abri abri is offline
Major Geek
 
Join Date: May 2005
Location: inside the Trojan Horse
Posts: 6,000
Thanks: 24
Thanked 47 Times in 46 Posts
Default Re: Winlogon.exe ??

Hi JhonnyB,
If your computer is running as it should and you do not see any changes in your programs after changing the names of the tmp files, I would like for you to delete them all. They'll be these renamed with .old at the end.
Code:
C:\WINDOWS\SET431.tmp
C:\WINDOWS\system32\SET479.tmp
C:\WINDOWS\system32SET480.tmp
C:\WINDOWS\system32SET484.tmp
C:\WINDOWS\system32SET489.tmp
C:\WINDOWS\system32SET464.tmp
C:\WINDOWS\system32SET465.tmp
C:\WINDOWS\system32SET47A.tmp
C:\WINDOWS\system32SET47B.tmp
C:\WINDOWS\system32SET47C.tmp
C:\WINDOWS\system32SET481.tmp
C:\WINDOWS\system32SET485.tmp
C:\WINDOWS\system32SET486.tmp
C:\WINDOWS\system32SET48B.tmp
C:\WINDOWS\system32SET4DE.tmp
C:\WINDOWS\system32SET4DF.tmp
C:\WINDOWS\system32SET4EB.tmp
After you've deleted them, please reboot and make sure your computer is still working as it should. If so, you can run the final cleanup instructions in the box below:
Quote:
Your logs look good. If you're not experiencing any malware symptoms, please do the following:
  • If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
  • If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
  • If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
  • Go to add/remove programs and uninstall HijackThis.
  • Then go into Windows Explorer and find MGTools directly under C:\ (or the root drive where your operating system is installed).
  • Open the MGTools folder and delete the contents.
  • Then delete the folder itself.
  • Look for any leftover logs on your desktop and if found delete them
  • Run CCleaner
  • After you've completed the above, please follow the instructions at this link for setting a clean restore point. Disable and Enable System Restore!
  • Once you've done this, please take a look at the link that follows. It's a good read and has some good information to help you prevent further malware invasions.

    How to Protect Yourself from Malware
Let us know how things went!
abri
Reply With Quote
  #12  
Old 03-05-08, 17:14
JhonnyB JhonnyB is offline
Private First Class
 
Join Date: Jan 2006
Posts: 61
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: Winlogon.exe ??

So everything is working fine :d
Thanks a lot abri, I really appreciate it .
Reply With Quote
  #13  
Old 03-05-08, 17:30
abri's Avatar
abri abri is offline
Major Geek
 
Join Date: May 2005
Location: inside the Trojan Horse
Posts: 6,000
Thanks: 24
Thanked 47 Times in 46 Posts
Default Re: Winlogon.exe ??

That's good to hear.
Enjoy your computering.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
winlogon.exe dlb Software 1 11-24-07 14:35
winlogon.exe is using 50% of my CPU richwill29 Malware Removal 1 06-02-06 11:13
winlogon.exe Rayor Software 2 05-15-06 21:36
help!!!! with winlogon.exe lightningboy Software 7 11-06-05 16:01
Winlogon.exe Panther270 Malware Removal 33 09-01-04 19:05


All times are GMT -5. The time now is 12:51.

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds


All content Copyright MajorGeeks.com source code Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger