![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
So, I recently updated my COMODO firewall and it made a malware scan and found a Trojan in C:/Windows/system32/winlogon.exe .
It couldn't remove it so It quarantined it and after that I couldnt reboot into windows, I would get a blue screen stop error. So I uninstalled comodo thorugh safe mode and now It booted just fine.No other scan recognizes this file as trojan so I dont really know what I can do. Any thoughts? |
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
Bump, Plx
|
|
#3
|
||||
|
||||
|
Hi JhonnyB,
Welcome to the Malware Forum! I advise you not to bump as it leads to scoldings. What trojan did it find? It may have been a false positive. If you're having malware symptoms go through the READ & RUN ME FIRST and attach the requested scans. Alternatively, you could go to the Alternate Scans and run BitDefender and Panda and see if they come up with anything. These can only be run with Internet Explorer. They're both good. Thanks. abri |
|
#4
|
|||
|
|||
|
I ran the online scans and they didnt detect any malware. Also I may have some symptoms but I think they can be traced to other reasons and for the most part my laptop is working fine.
I did some reading and found out this file is genuine and has something to do with the boot process ,so that would explain why quarantining it gave me that error. But there are some trojans which pose as it. Still not sure why my firewall detects it as a threat, but Im more calm now. Thx |
|
#5
|
||||
|
||||
|
Hi jhonny,
If you happen to have the Combofix log and the MGlogs.zip, I could check them to see if the file you're worried about is infected. If you'd like for me to do this, please attach them to your next post. abri |
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
Hi abri, I didnt know there was another reply here, but I have attached the files in this post, so if you can check it out it would be cool.
Btw my OS is in czech so I dunno if that may be a problem to understand the log files. |
|
#7
|
||||
|
||||
|
Hi JhonnyB,
Please do the following: Download SDFix and save it to your Desktop. Double click SDFix.exe and it will extract the files to %systemdrive% (Drive that contains the Windows Directory, typically C:\SDFix) Please then reboot your computer in Safe Mode by doing the following :
|
|
#8
|
|||
|
|||
|
Done, it looks like it didnt find anything.
|
|
#9
|
||||
|
||||
|
Hi JhonnyB,
I'm always the optimist. I had hoped SDFix would pick up that lot of tmp files you have. I think what Comodo found was a false positive. Please do the following: Delete this file: C:\WINDOWS\system32\eRLog.ini And this folder: C:\WINDOWS\System32\drivers\down Then rename the following files in the box below by putting the name .old after them: (example: C:\WINDOWS\system32\SET479.tmp would become SET479.tmp.old) Quote:
And finally, please run C:\MGtools\GetLogs.bat and attach the fresh MGlogs.zip. Let me know how things are running. abri |
|
#10
|
|||
|
|||
|
Done, but I dont have the C:\WINDOWS\System32\drivers\down folder on my system.
|
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
Hi JhonnyB,
If your computer is running as it should and you do not see any changes in your programs after changing the names of the tmp files, I would like for you to delete them all. They'll be these renamed with .old at the end. Code:
C:\WINDOWS\SET431.tmp C:\WINDOWS\system32\SET479.tmp C:\WINDOWS\system32SET480.tmp C:\WINDOWS\system32SET484.tmp C:\WINDOWS\system32SET489.tmp C:\WINDOWS\system32SET464.tmp C:\WINDOWS\system32SET465.tmp C:\WINDOWS\system32SET47A.tmp C:\WINDOWS\system32SET47B.tmp C:\WINDOWS\system32SET47C.tmp C:\WINDOWS\system32SET481.tmp C:\WINDOWS\system32SET485.tmp C:\WINDOWS\system32SET486.tmp C:\WINDOWS\system32SET48B.tmp C:\WINDOWS\system32SET4DE.tmp C:\WINDOWS\system32SET4DF.tmp C:\WINDOWS\system32SET4EB.tmp Quote:
|
|
#12
|
|||
|
|||
|
So everything is working fine :d
Thanks a lot abri, I really appreciate it . |
|
#13
|
||||
|
||||
|
That's good to hear.
Enjoy your computering. |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| winlogon.exe | dlb | Software | 1 | 11-24-07 14:35 |
| winlogon.exe is using 50% of my CPU | richwill29 | Malware Removal | 1 | 06-02-06 11:13 |
| winlogon.exe | Rayor | Software | 2 | 05-15-06 21:36 |
| help!!!! with winlogon.exe | lightningboy | Software | 7 | 11-06-05 16:01 |
| Winlogon.exe | Panther270 | Malware Removal | 33 | 09-01-04 19:05 |