winlogon.exe changed firefox memory

Discussion in 'Malware Help (A Specialist Will Reply)' started by svantevit, Jun 21, 2008.

  1. svantevit

    svantevit Private E-2

    outpost blocks firefox's internet access due to memory modification made by winlogon.exe. process firefox.exe cannot be closed diffrently than using task manager. if not closed then on windows shutting down message about xpcom:eventreceiver pops-up.
    i followed read & run instructions, downloaded and used ccleaner, spybot, superantispyware and malwarebytes anti-malware. those tell me that my system is clean.
    what can i do to solve that problem ?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    First we need to determine if your in the correct forum. The only way for us to know that is if you complete ALL of the instructions in the READ & RUN ME and attach all of the requested logs for us to look at. Then we can suggest what your next step should be.
     
  3. svantevit

    svantevit Private E-2

    yes, sir!

    this is how it goes
     

    Attached Files:

  4. abri

    abri MajorGeek

    Hi svantevit,

    Please attach the MGlogs.zip as well. When you click on the Manage Attachments button, look for this file (not folder) directly under the drive where your operating system is located (usually local drive C:\ )

    abri
     
  5. svantevit

    svantevit Private E-2

    this should be it, isn't it ?
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {254C7995-C7F8-4584-AFAB-A0988AB1AFE0} - (no file)
    O2 - BHO: (no name) - {74FE5B36-22A6-4971-A360-E95C07F9CE73} - (no file)
    O20 - Winlogon Notify: winblr32 - C:\WINDOWS\SYSTEM32\winblr32.dll

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Administrator\Local Settings\Temp

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. svantevit

    svantevit Private E-2

    i've done everything from 1st to the very last letter. went smoothly. thanks a lot.
    current logs are attached and i will let you know how things are working within 24 hours. is that all right ?
    i am pretty stunned 'cause solution was given so swiftly and accurately. is there any way to learn about spyware removal mechanics under your guidence ?
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    While I would like to be able to do this, the truth is that we are just way to busy here and understaffed to have the time to train people. It takes a significant amount of time to properly do this. There are a few sites that I will give a few links to below that you can enroll for training at. Make sure that you are serious about wanting to do this as this is not something that you will learn over night. It takes dedication and a significant amount of time. The more experience you actually have with the Windows Operating Systems to begin with, the easier/smoothier your training will proceed. Check out the below sites:

    spywareinfo.com
    tomcoyote.org
    geekstogo.com
    bleepingcomputer.com



    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. svantevit

    svantevit Private E-2

    My system now runs well again. Thank you very much. I will go through some training in order to understand better how things are running. In return for your help I'd like to do something for you and/or majorgeeks. If I'd be useful after accomplishing some trainings, I will be ready.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. And good luck with your training.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds