Question

virus removal for logonui.exe

Asked by: MalcolmBishop

I have a virus that brought up the error message "logonui.exe    Application error.
The PC is a HP laptop XP service pack 2 running the full version of Mcafee Security Centre and AV program which was up to date on 11 April. I believe my grandson installed some games from discs he was given on that date, and that is when the problem started.
I have the 3-pc Mcafee program running 2 desktops and this laptop via wireless router and the 2 desktops are not affected. I am typing this question on one of them.
To get the laptop running in safe mode I tried to turn off system restore and got the error message
"cannot find    rundll32.exe
I copied this file from my desktop onto disc, then copied it to laptop and got System restore to turn off.
When I start the laptop in safe mode with Networking I can open Internet Explorer but the keyboard is disabled and I cannot type anything to get on anything other than my home page. After a few minutes IE goes to a porn site all on it's own.
Following various questions on EE I downloaded 3 programs on my working desktop PC and burned them to disc.
1 Stinger
2 Avast
3 Kaspersky
When I put the disc in the laptop and copy these 3 programmes to the desktop none of them will run. For Stinger I got an apparent error message
"Stinger may be infected. Cannot run"
The Avast and Kapersky ran for about 10 seconds of Startup then stopped completely.
When I run the laptop in Safe mode ( windows restore turned off ) the programmes will still not start from the desktop, so I tried to run them straight from the disc. Stinger ran from the disc for a couple of hours but did not seem to find the virus, and the other 2 programmes appear to startup for about 10 seconds then stop, I presume the virus is stopping them running. The Mcafee program on the Laptop will also not run and has a red cross on the Taskbar icon.
My 2 desktops are reporting through Mcafee Networking that the laptop does not have Mcafee running but don't have the facility to Virus check it.
I think I need a virus removal programme similar to Stinger that I can download on my working PC, then burn to disc, then put in Laptop to run from disc.
The virus is clever enough to stop Avert and Kaspersky running, but not Stinger.
Can anyone help with another type of Virus removal tool?

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-04-13 at 04:45:46ID24316886
Topics

Windows XP Operating System

,

Anti-Virus Applications

Participating Experts
5
Points
500
Comments
32

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. rundll32.exe
    I had this problem with rundll32.exe, where everytime i logged off or shut down the computer, it would say that runndll32.exe wasn't resoponding and that i should end the program to shut down. I tried many ways to correct this, including getting a new copy of the rundll32.ex...
  2. rundll32.exe
    Everytime i shut down computer I have to wait for rundll32.exe to end first. Then end rundll32.exe and computer shuts down.
  3. Wiping infected slave disc
    I have detected a bad infection (possible the blaster Worm and many others) in a secondary slave hard drive on my system that has infectec my primary one right after a fresh new OS install (Win XP Pro) Now im reformatting the main disc, of course with the slave disc unplugg...
  4. Rundll32.exe is infected by Malware
    On Win XP Pro SP2 PC, when most any program or sytem utility on PC is run an error comes up saying to Choose a Program to open "rundll.32.exe" with (i.e Like when you click a file and select "Open with". I,E THAT WINDOW is the one I mean.) Also same error...
  5. McAfee virus notification
    Hello McAfee Experts! We are running ePO 4.0 and VSE 8.5i I have set up a notification to mail me if a machine gets infected with a virus, as below; ePolicy Orchestrator Notification Rule: {NotificationRuleName} Rule Defined At: {BranchNodePath} Description: Notifications ...
  6. Malware Infection - rundll32.exe is infected / wuauclt…
    I have a client laptop (WinXP Pro OS) that has become infected with malware. The symptoms are that no programs will run. Control panel will not run. errors popup stating that rundll32.exe and wuauclt.exe are infected. There are also multiple "newupdates are ready for you...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: rgutweinPosted on 2009-04-13 at 04:48:33ID: 24129094

Have you tried Malwarebytes
http://www.malwarebytes.org/

After you install the program, make sure you run the updates to get the latest definitions (you will probably have to do it twice).  Then when you are done, make sure you run the Full (Thorough) scan instead of the "Quick" one.  If your computer will not let you install and run Malwarebytes because of the infection, then I suggest you take the Hard Drive out and slave it on a working computer with Malwarebytes on it and try running a scan that way.  

Good Luck!


Randy

 

by: skywalker39Posted on 2009-04-13 at 04:57:35ID: 24129124

Hi MalcolmBishop,

Spyware Doctor with AntiVirus is a really great tool in my own opinion. I would try it out, I would also try running it in both Normal Windows and in Safe Mode. To get in Safe Mode, reboot your computer while holding down or tapping the F8 key. Also to do a full scan. Here's the link: http://www.pctools.com/spyware-doctor-antivirus/

 

by: MalcolmBishopPosted on 2009-04-13 at 05:02:54ID: 24129147

Just tried malwarebytes and I get the first screen to pick the langauge, click OK, and the programme flashes up on screen and goes off.
This is a clever vurus!!!!

 

by: MalcolmBishopPosted on 2009-04-13 at 05:17:39ID: 24129215

Just installed Spyware doctor and so far it is running OK in Safe mode. Will try Normal mode when it finishes.
Any idea which virus is clever enough to stop
Avast
Kaspersky
Mcafee
Malwarebytes
from running on this laptop??

 

by: rgutweinPosted on 2009-04-13 at 05:19:17ID: 24129221

Your best bet is probably going to be slaving that Hard Drive onto another computer and running all your scans from there :)

 

by: MalcolmBishopPosted on 2009-04-13 at 05:32:03ID: 24129283

How do I slave this HD without removing it from Laptop?

 

by: MalcolmBishopPosted on 2009-04-13 at 05:33:45ID: 24129293

The Spyware doctor has frozen at 10% and none of the buttons will work so I cannot shut it down.

 

by: MalcolmBishopPosted on 2009-04-13 at 05:38:01ID: 24129314

Spyware doctor has now frozen.
This seems a clever virus.
Any more ideas or programmes please?

 

by: skywalker39Posted on 2009-04-13 at 05:38:25ID: 24129317

If your still having problems, I would suggest as rqutwein and take the drive and put it into another computer as slave, then run the anti-virus software that way.

 

by: rgutweinPosted on 2009-04-13 at 05:39:53ID: 24129326

Since you have a laptop, the Hard Drive is most likely a SATA.  You will need to take it out of the laptop, and put it into a desktop computer that is compatible with SATA drives.  You will probably need an extra SATA cable to connect that laptop drive to a desktop.

SATA drives don't have a master/slave relationship with the controller like IDE. SATA controllers have two channels that correspond to the two channels on an IDE controller, but each channel can only access one drive.

 

by: MalcolmBishopPosted on 2009-04-13 at 05:41:54ID: 24129331

I am reluctant to take out the laptop HD as I don't have any mounting kit to fit it in a desktop.
Is that the only way I can solve the problem?

 

by: vertsyeuxPosted on 2009-04-13 at 05:43:25ID: 24129338

Avast! have something called their BART CD.. Basically, it's a bootable CD with antivirus, registry repair, disk checker etc. built-in. This means you don't ever start the Windows on your infected laptop so the virus can't affect anything.. Might be worth a look if you don't want to dismantle your laptop

 

by: vertsyeuxPosted on 2009-04-13 at 05:55:56ID: 24129407

I did a google check - it seems all the antivirus companies do "portable" versions of their scanning/cleaning programs. This means you can run it from a USB flashdrive, and if you get a drive with a write-protect switch, it can't be written to.. The problem is of course, getting Windows to start without the virus  causing problems.. If you can find a "Windows Live" image, you can make a CD that will boot and let you run your antivirus program from a flashdrive..

 

by: MalcolmBishopPosted on 2009-04-13 at 06:05:51ID: 24129465

Not sure I understand what "windows Live" means. How do I get a bootable disc from Mcafee, as I pay them a full subscription anyway?

 

by: vertsyeuxPosted on 2009-04-13 at 06:12:54ID: 24129511

Here's what I get when I google it..

You could try BART PE http://www.nu2.nu/pebuilder/

It will allow you to boot from CD into a windows environment (pre-environment) where you can run all sorts of plug-ins, including the McAfee free command line scanner (with a GUI), McAfee stinger

Ultimate BootCD (http://www.ultimatebootcd.com) - Has F-Prot, McAfee, Avast and AVG

 

by: vertsyeuxPosted on 2009-04-13 at 06:18:22ID: 24129556

Incidentally, a "Live CD" is a CD that you can boot your pc from, and which runs Windows (or Linux etc.) entirely off the CD, the hard drive is not used.. However, you can still access the hard drive to carry out updates, remove viruses etc...

 

by: MalcolmBishopPosted on 2009-04-13 at 07:17:43ID: 24129957

Run the Spyware doctor, it found many problems. Paid the £40 subscription and it deleted the problems.
Re started Laptop and I now have error message
ati2evxx.exe
poping up about 4 times, instead of the logonui.exe.
any help please?

 

by: rgutweinPosted on 2009-04-13 at 07:20:02ID: 24129973

Try reinstalling your video drivers, since this file corresponds with an ATI Graphics card (hopefully that is what your laptop has).

http://www.neuber.com/taskmanager/process/ati2evxx.exe.html

 

by: MalcolmBishopPosted on 2009-04-13 at 08:52:20ID: 24130607

downloaded and reinstalled ATI drivers.
On restart the display seems ok but have error message
cccinstall.exe  application error.
Spyware doctor seems to be running ok
the red cross has gone from Mcafee icon, but Mcafee still won'y start. Is this a conflict with Spyware doctor??

 

by: MalcolmBishopPosted on 2009-04-13 at 08:59:10ID: 24130666

I suspect the virus is still there because I have run the malwarebytes programme on my other PC and it works OK. But it still won't run on Laptop. It flashes on for a couple of seconds then goes off.
Mcafee still won't start up.

 

by: MalcolmBishopPosted on 2009-04-13 at 09:07:50ID: 24130728

restarted laptop several times and run Spyware doctor and it keeps finding 30 to 40 virus/malware etc.
It suposedly fixes them, but on restart it all happens again.
Virus still there???

 

by: MalcolmBishopPosted on 2009-04-13 at 09:15:45ID: 24130790

watching spyware doctor closely during the scan it stops for a long time in the system 32 forlder on a file called
comsa32.
when spyware doctor continues it has found a trojan.
Should I delete comsa32   ??

 

by: rgutweinPosted on 2009-04-13 at 09:21:25ID: 24130839

 

by: MalcolmBishopPosted on 2009-04-13 at 09:38:29ID: 24130972

OK deleted.
When I went to msconfig to check the startup Items msconfig crashed. It won't let me run msconfig.
Also
Malwarebytes
Avert
Karsposky
still won't run from disc or desktop.
Getting desperate now, so restarted in safemode, run spyware doctor and it is still finding wormp2p agent, etc.

 

by: MalcolmBishopPosted on 2009-04-13 at 10:35:37ID: 24131353

Microsoft systems such as
disk defragmenter
msconfig
volume control
all will not run. They just come up with error message to send an error report to Microsoft.
Every time I run Spyware doctor in safe mode or Normal it is still finding things like
rootkit agent der
trojan downloader adp client.

is it not possible to get rid of these viruses??

 

by: orangutangPosted on 2009-04-13 at 10:45:29ID: 24131422

 

by: skywalker39Posted on 2009-04-13 at 12:20:19ID: 24132109

Have you tried doing a system restore? System restore has to be enabled for this to work.

 

by: MalcolmBishopPosted on 2009-04-13 at 12:27:15ID: 24132160

All the microsoft system like
system restore
disk defragmenter
msconfig
volume control
etc etc just crash out and give an error message.
Downloaded superanti spyware and managed to install it, but when it runs for about 5 mins it finds a lot of faults then the laptop crashes to blue screen and says something about "dumping data etc"

 

by: MalcolmBishopPosted on 2009-04-13 at 13:46:18ID: 24132772

Got superantispyware working in safemode.
This is last post for tonight.....bedtime....

 

by: warturtlePosted on 2009-04-14 at 06:26:04ID: 24137881

I suggest downloading ComboFix from http://subs.geekstogo.com/ComboFix.exe . Save it with a completely different name like jabba.exe. Reboot your PC in safe mode (if possible) and disable temporarily any anti-virus or anti-spyware solution or firewall and run ComboFix. It will create a log, please post that log to us. Don't use the mouse or keyboard while its running though, otherwise it may stall.

Please read the instructions on the below webpage:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

After running ComboFix in safe mode, run either MalwareBytes or SuperAntiSpyware as advised before and do full scan with them.

Let us know, how it goes.

 

by: MalcolmBishopPosted on 2009-04-16 at 11:46:39ID: 24161145

Hi, loaded superantispyware and ran in safe mode.
It removed a lot of files that appeared to be either windows or Microsoft.
I then got a blue screen with a Compaq message saying
stop c000021e
According to the HP website the message meant that c:/ drive needed resetting to Factory settings with their Rescue Disc. As I lost them recently I gave up. The Laptop is now at the Computer shop awaiting repair as I was desperate.
I am dissapointed with my failure as I always thought I new what I was doing.

 

by: warturtlePosted on 2009-04-17 at 09:07:51ID: 24169218

Did you try to reboot after the blue screen?? and were you able to reboot in safe mode? or normal mode? Its quite possible that SuperAntiSpyware deleted a virus which was registered as a driver, and that caused the blue screen to come up.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...