Author Topic: winlogon.exe, explorer.exe, and win32patched.gb  (Read 904 times)

0 Members and 1 Guest are viewing this topic.

Offline Sojourner

  • Newbie
  • *
  • Posts: 8
winlogon.exe, explorer.exe, and win32patched.gb
« on: January 12, 2011, 06:28:58 PM »
I am coming here from the Gardenweb.  Yesterday I found the above problems.

I downloaded and installed Avast, and already had malwarebytes and adaware.

I started full scans of my spyware/malware programs last night to try to identify and clean out this virus, which I also got in the course of a recipe search, apparently from the Food Network.

Unfortunately my son got up this morning, saw my netbook sitting there with the clamshell up, thought I'd left it on by accident, and shut it down.

Now it won't boot, not even in safe mode. I know the winlogon.exe file was corrupted and had scheduled a boot scan in Avast, but what it does now is cycle constantly between the blue screen with a message that flashes past far too quickly for me to read it, and the windows boot screen. It never comes up.

Since it was shut down before I got up this morning, I also didn't get to write down my XP license number, so even though I have access to an external DVD and an XP installation disk, I DON'T have a valid license # to enter.

I fear my netbook is bricked, all because of a recipe for apple streusel pie.

If I can't get it to boot I can't provide any of the log files you guys want, so it may just be permanently bricked at this point.  With only 2 GB of onboard memory I doubt I could run Win7 even if I wanted to pay for the license (a new netbook would probably actually be cheaper).  I don't think I can even get an XP license anymore (although I had a valid copy on there I don't have the license # written down).

If there's any help you can give me I'd appreciate it.

Thanks.

Offline R-C

  • Hero Member
  • *****
  • Posts: 2651
  • Laissez les bons temps rouler!
Re: winlogon.exe, explorer.exe, and win32patched.gb
« Reply #1 on: January 12, 2011, 06:34:05 PM »
Glad to see you managed to find your way here, just be patient the team here will be along and help you.
registered Linux user:476595
May inspiration fill your heart and hands, run down your legs onto your feet and cause Spontaneous Dancing! :dance:

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: winlogon.exe, explorer.exe, and win32patched.gb
« Reply #2 on: January 12, 2011, 08:00:45 PM »
Hi, Sojourner.

If you cannot get to safe mode, normal mode or "last known good configuration", I can't give you tools to run.  However, you may want to try a Kaspersky Rescue Disk:  http://support.kaspersky.com/viruses/rescuedisk?level=2

If that isn't successful, another option to try is to Perform a Repair Installation

You may be able to access the license key via a Ubuntu CD Saving files on a corrupt OS

To boot from CD, place the CD in the tray, restart computer and either tap repeatedly the Boot Menu key given on first screen to choose CD drive, or see if it prompts you to Press Any Key to Boot CD - if not, set CD drive as first to boot in BIOS setup also listed on first boot screen.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline Sojourner

  • Newbie
  • *
  • Posts: 8
Re: winlogon.exe, explorer.exe, and win32patched.gb
« Reply #3 on: September 19, 2011, 02:11:56 PM »
OK, sorry for the long absence, have been pretty ill.

Here's the problem - this is an EEE PC and it has no CD ROM drive.  It has an SDHC slot and it has USB ports.  I had thought to get a bootable image on an SDHC card but I've not been able to find clear instructions for how to do that.  I'm also not sure how to get a bootable image on a flashdrive and I think I might have to buy a new flashdrive to do that anyway - seems to me there was some architectural differences that made only some flashdrive's bootable?  Or you can't run executables from all of them?  Or I'm just way behind the times.  At any rate I'm not sure how to be able to boot from either.

I do now have access to another laptop running XP, and a set of XP installation disks.

Any help?

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: winlogon.exe, explorer.exe, and win32patched.gb
« Reply #4 on: September 19, 2011, 09:35:54 PM »
Hi, Sojourner.

I am sorry to hear you have been ill and hope all is well now. 

Since you have USB ports and access to a second computer, see if the Microsoft Standalone System Scanner will run.  Note that it will wipe everything off the flashdrive so be sure there isn't anything there you want to keep.  See my tutorial at Setting Up the Microsoft Standalone System Sweeper Beta.

,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline Sojourner

  • Newbie
  • *
  • Posts: 8
Re: winlogon.exe, explorer.exe, and win32patched.gb
« Reply #5 on: September 20, 2011, 12:15:54 AM »
OK trying this, so far no luck.  I can boot that on my son's Dell Laptop, but it won't boot on my EEE PC.  I've even gone so far as to disable all boot devices except what ASUS is calling "Removable Media" (which I assume means an SDHC card or flash drive) and no luck so far.

USB Devices are enable
USB 2 is enabled
CardReader is enabled
quick boot is disabled
quiet boot is disabled
boot boster is enabled (I'm going to try disabling this, it says "Boost BIOS POST speed")

Not sure what else I should be checking re bios settings

Still looking into this ...

Also when I try to update once it's booted on the Dell, I get the following error:

"Error code 0x80072ee7: Server name or address could not be resolved"

I'll try to download the update files and install manually from the Dell, but I doubt that's what's keeping it from booting from the flashdrive on the eeePC.

Offline Sojourner

  • Newbie
  • *
  • Posts: 8
Re: winlogon.exe, explorer.exe, and win32patched.gb
« Reply #6 on: September 20, 2011, 12:50:10 AM »
Apparently the eeePC should be recognizing my flash drive within the BIOS, but it does not.  I'm not sure what "Removable device" really is, but apparently it's NOT the Flash drive.

Is there a way to get the sweeper onto an SDHC card instead of the flash drive?  Maybe I can get it to see that ...

Offline Sojourner

  • Newbie
  • *
  • Posts: 8
Re: winlogon.exe, explorer.exe, and win32patched.gb
« Reply #7 on: September 20, 2011, 01:11:47 AM »
OK, I've got it booting from the Flash drive.  Weird setup, even when the flash drive is the ONLY device enabled for boot, it still requires intervention to boot from the flash drive.  Removable drive IS the flash drive (contrary to what some other eeePC owners have said).

It's running Win XP, 32 bit, pretty sure it's service pack 2 unless service pack 3 was released prior to January when the poor lil' thing got bricked.

I have not been able to update the Sweeper, can't find the right files, but what I've got is running on the eeePC now.

Will post back with results...

Thanks for the help so far.

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: winlogon.exe, explorer.exe, and win32patched.gb
« Reply #8 on: September 20, 2011, 01:45:07 AM »
So far, you've walked yourself through it.  :) 

If you still cannot boot the eeePC normally after running the System Sweeper, try the Kaspersky Rescue Disk.  It can be installed on a Flashdrive:  http://support.kaspersky.com/faq/?qid=208282163
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline Sojourner

  • Newbie
  • *
  • Posts: 8
Re: winlogon.exe, explorer.exe, and win32patched.gb
« Reply #9 on: September 20, 2011, 02:17:56 AM »
I had looked at that earlier, but at that time, the link to the utility to copy the ISO file to a flash drive was broken - I assumed permanently, but it's working now.  When I went to the user's manual, it said you needed an ISO editor to be able to do that.  Could not find a free one so I kind of gave up on that.

However I have the utility now, will have to see whether I need it.

Ultimately I'd like to have a bootable SDHC  card which I could just leave in the CardReader, disable that in the BIOS to protect it from malware, and then in an emergency situation I could just reenable the CardReader and have access to my internal hard drive for cleaning and/or data backup.  I know this is supposed to be possible - there are a ton of these little netbooks out there with no internal HD, only a small (like 2G to 4G) SSD, but have not been able to figure out how yet.

Sweeper is still running.  It warned of potential malware immediately it started running - I'm assuming it found whatever crap is in the root/boot sector/whatever, since the malware was coopting the boot process before it ever even completed booting.  Hatums le malware!

Offline Sojourner

  • Newbie
  • *
  • Posts: 8
Re: winlogon.exe, explorer.exe, and win32patched.gb
« Reply #10 on: September 20, 2011, 04:10:09 AM »
OK, successfully ran the System Sweeper and it found 3 instances of Bamital, A virust tool called JS.OBFUSCATOR.AG, a Trojan Downloader called Java.openconection.EE, and a Java exploit called CVE-2010-0840.W.  Disinfected the 3 instances of Bamital and removed the rest, reported success.

Currently I am updating my onboard virus software pursuant to running that again, but the little Netbook is now booting again.

Can you help me to identify which files are needed to keep the System Sweeper up to date?  I've not been able to find that out on the MS website, they don't seem to list it or it's updates with the rest of the security software and searches just send me to the other security software.

Thanks for the help.

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: winlogon.exe, explorer.exe, and win32patched.gb
« Reply #11 on: September 20, 2011, 02:08:15 PM »
Hi, Sojourner.

Getting the Netbook to boot again is just the first step.  Now we need to follow through to ensure there aren't any leftovers.  Please follow the instructions in Log Posting Instructions.

As to updating the Microsoft System Sweeper, you can find that in the "Updating the Definitions" section of my tutorial, linked above:

Quote
After starting the infected computer with Standalone System Sweeper do the following to insure that the most recent definitions are installed:

    Click on the Help drop down arrow menu.
    Click on Check for updates.
    Click on Download.


In the event the infected computer does not have an Internet connection, the updates can be manually transported to the infected machine.  The definitions are the same for Standalone System Sweeper as used with Microsoft Security Essentials.

    Download the latest definitions from the Malware Protection Center Portal, selecting the correct version for the infected computer:
    -- mpam-fe.exe is for the 32-bit version   
    -- mpam-fex64.exe is for the 64-bit version
    Transport the saved definitions to the infected computer, selecting the Browse button to navigate to the location of the saved definitions.




,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline Sojourner

  • Newbie
  • *
  • Posts: 8
Re: winlogon.exe, explorer.exe, and win32patched.gb
« Reply #12 on: September 21, 2011, 05:51:39 AM »
Dang, sorry about that.  Hovering doesn't show me the actual name of the file.  Unless you actually click one of those links you don't get to see the file name.  I misinterpreted the redirect as the file name so I thought I wasn't in the right place.  My bad.  Downloaded the right one, I'll install and rerun tomorrow.  Thanks.