Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 19, 2013, 04:24:58 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
662961
Posts
70576
Topics
145151
Members
Latest Member:
liquidcat
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
Help - CCE
modified winlogon is this a real threat
« previous
next »
Pages:
[
1
]
2
Author
Topic: modified winlogon is this a real threat (Read 7667 times)
donut53
Comodo Family Member
Offline
Posts: 71
modified winlogon is this a real threat
«
on:
August 04, 2012, 12:12:17 PM »
After running CCE quick scan it showed one threat. I choose to ignore the threat for now and ran a scan using CIS. The results of CIS scan were no threats found. Here is the text info from the CCE scan.
====== System Information ======
Computer Name: HPDESKTOP
Log on User: John
Memory Size: 7.75 GB.
Windows Directory: C:\Windows
Windows Version: 7 (64bit)
CCE Version: 2.5.242177.201
Virus database version: 13147
[12:45:29] Scan started.
====== Cleanup results ======
Global WINLOGON SYSCHANGE Ignore OK
What should I do?
Logged
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 16661
Re: modified winlogon is this a real threat
«
Reply #1 on:
August 04, 2012, 04:34:45 PM »
Please check the digital signature of the winlogon file to see it has a valid digital signature by Microsoft.
To know for sure that winlogon.exe is the original file you can use Sigcheck to see if it is digitally signed by Microsoft.
Download this
zip archive
and unpack it to C:\Program Files\SysinternalsSuite\ . When done run sigcheck.reg to add it to the registry.
When this is done navigate to the system32 folder, look up and select winlogon.exe click right and choose Signature from the context menu. A black command box will pop up. See if it is signed or not.
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
donut53
Comodo Family Member
Offline
Posts: 71
Re: modified winlogon is this a real threat
«
Reply #2 on:
August 05, 2012, 12:11:07 PM »
Quote from: EricJH on August 04, 2012, 04:34:45 PM
Please check the digital signature of the winlogon file to see it has a valid digital signature by Microsoft.
To know for sure that winlogon.exe is the original file you can use Sigcheck to see if it is digitally signed by Microsoft.
Download this
zip archive
and unpack it to C:\Program Files\SysinternalsSuite\ . When done run sigcheck.reg to add it to the registry.
When this is done navigate to the system32 folder, look up and select winlogon.exe click right and choose Signature from the context menu. A black command box will pop up. See if it is signed or not.
I am unable to get a black command box to open.. I right click on the file and select signature but then I get a box asking what program to open the mui file..
Logged
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 16661
Re: modified winlogon is this a real threat
«
Reply #3 on:
August 05, 2012, 12:49:01 PM »
That's odd and has me stuck for answer....
I asked the other mods to take a look at this problem.
«
Last Edit: August 05, 2012, 12:57:01 PM by EricJH
»
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13195
Volunteer Moderator
Re: modified winlogon is this a real threat
«
Reply #4 on:
August 05, 2012, 01:16:55 PM »
Please run the extra tool 'Autoruns' and click on the 'Winlogon' part in the left menu.
Then post a screenshot of the results please so we might see what has been changed.
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
donut53
Comodo Family Member
Offline
Posts: 71
Re: modified winlogon is this a real threat
«
Reply #5 on:
August 05, 2012, 02:32:59 PM »
Quote from: Ronny on August 05, 2012, 01:16:55 PM
Please run the extra tool 'Autoruns' and click on the 'Winlogon' part in the left menu.
Then post a screenshot of the results please so we might see what has been changed.
Here it is and I also provided screenshot of the cce scan..
Does it make sense to you that CCE would show a threat but CIS does not?
«
Last Edit: August 05, 2012, 02:48:01 PM by donut53
»
Logged
jay2007tech
Malware Research Group
Global Moderator
Comodo's Hero
Offline
Posts: 1795
Re: modified winlogon is this a real threat
«
Reply #6 on:
August 05, 2012, 07:02:11 PM »
how about this
Click on "start"
Click on "All Programs"
Click on "Accessories"
Click on "Command Prompt" <---------Right Click on -
RUN AS ADMIN
type in "sfc /scannow" <----without the " "
Logged
It's hard being a crooked Admin when the files won't pass an md5checksum test. But like any other good crooked Admin it can be done, it just takes time(and lots of it) and a few aspirins
donut53
Comodo Family Member
Offline
Posts: 71
Re: modified winlogon is this a real threat
«
Reply #7 on:
August 05, 2012, 07:55:13 PM »
Quote from: jay2007tech on August 05, 2012, 07:02:11 PM
how about this
Click on "start"
Click on "All Programs"
Click on "Accessories"
Click on "Command Prompt" <---------Right Click on -
RUN AS ADMIN
type in "sfc /scannow" <----without the " "
Ran sfc /scannow earlier today and no problems or issues were found..
«
Last Edit: August 05, 2012, 08:24:39 PM by donut53
»
Logged
jay2007tech
Malware Research Group
Global Moderator
Comodo's Hero
Offline
Posts: 1795
Re: modified winlogon is this a real threat
«
Reply #8 on:
August 05, 2012, 08:02:00 PM »
Quote
Ran sfc /scannow earlier today and no problems or issues were found..
If thats your only issue, I wouldn't worry about it
Logged
It's hard being a crooked Admin when the files won't pass an md5checksum test. But like any other good crooked Admin it can be done, it just takes time(and lots of it) and a few aspirins
languy99
Global Moderator
Comodo's Hero
Offline
Posts: 3944
Re: modified winlogon is this a real threat
«
Reply #9 on:
August 05, 2012, 10:55:38 PM »
go to start and type msconfig, please post a pic of each tab. Thanks
Logged
http://www.youtube.com/languy99
Software Reviews for all.
Follow me on Twitter
http://twitter.com/#!/languy99
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13195
Volunteer Moderator
Re: modified winlogon is this a real threat
«
Reply #10 on:
August 06, 2012, 11:33:29 AM »
There are several stages of 'winlogon' e.g. in win.ini and system.ini, registry etc.
The CCE entrie doesn't show a clue where to look for modified things, I'd suggest to run a MBAM scan to see if that shows more details.
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 16661
Re: modified winlogon is this a real threat
«
Reply #11 on:
August 06, 2012, 12:48:31 PM »
Just thinking out loud. May be it is responding to the file not found situation? Try disabling the autorun entry with the file not found error and try again.
Also try running checkdisk to see if the file system is intact. Run chkdsk /f from the command prompt and allow Windows to run chkdsk on the next boot.
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
donut53
Comodo Family Member
Offline
Posts: 71
Re: modified winlogon is this a real threat
«
Reply #12 on:
August 07, 2012, 10:11:50 AM »
Quote from: languy99 on August 05, 2012, 10:55:38 PM
go to start and type msconfig, please post a pic of each tab. Thanks
Here they are
Logged
donut53
Comodo Family Member
Offline
Posts: 71
Re: modified winlogon is this a real threat
«
Reply #13 on:
August 07, 2012, 10:35:44 AM »
Quote from: EricJH on August 06, 2012, 12:48:31 PM
Just thinking out loud. May be it is responding to the file not found situation? Try disabling the autorun entry with the file not found error and try again.
Not sure what you want me to do.. Please help me understand.. ty
Fixed the quote. Eric
«
Last Edit: August 07, 2012, 06:14:28 PM by EricJH
»
Logged
donut53
Comodo Family Member
Offline
Posts: 71
Re: modified winlogon is this a real threat
«
Reply #14 on:
August 07, 2012, 11:07:06 AM »
Quote from: Ronny on August 06, 2012, 11:33:29 AM
There are several stages of 'winlogon' e.g. in win.ini and system.ini, registry etc.
The CCE entrie doesn't show a clue where to look for modified things, I'd suggest to run a MBAM scan to see if that shows more details.
Do you think this is even an issue.. MBAM and CIS do not find any threats.. Only CCE
Logged
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.227 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com