Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old November 26th, 2006, 08:55 AM
josephrot josephrot is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2006
Posts: 5 josephrot User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 37 m 39 sec
Reputation Power: 0
Hope you are still a member...

As of late Nov 2006, I am having the same trouble with winlogon.exe (this is the real file, not a similar name virus / trojan file) consuming 25-99% resources, as it keeps on running no matter what I do. System is Win XP Home with SP1, started with XP SP1, and continues when I updated SP1 to SP2.

All v irus and trojan scans from four anti-virus suppliers find nothing wrong...ALL the anti-virus are up to date.

We need to know HOW to easily replace winlogon.exe with the proper version one, as I am sure that if the XP O/S has gone through one or more security or other updates, the proper winlongon.exe version needs to be put back, maybe doing that will stop this crap.

MS needs to make available the winlogon.exe file so people can easily replace it, even if only to make SURE that it's not a defective winlogon.exe file, or perhaps a Registry problem that is causing winlogin.exe to keep on running and eating CPU resources.

Would appreciate any copy reply also being sent to my AOL Email: (E-Mail address blocked: See forums rules)

Many thanks!

Reply With Quote
  #2  
Old November 26th, 2006, 09:42 AM
megumi amatuka megumi amatuka is offline
Contributing User
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Jun 2004
Posts: 4,869 megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level) 
Time spent in forums: 2 Months 6 Days 21 h 24 m 42 sec
Reputation Power: 333
(Oo;?(No one answered? Sad.)

(^~;?(Hey, Josephrot. winlogon.exe is extracted from XP disk, SP1 or SP2.)

But this case is terribly infected and doesn't directly relate to winlogon.exe. Probably HJT didn't show 020 winlogon hacks entry then, though.

Reply With Quote
  #3  
Old November 26th, 2006, 01:14 PM
displeaser's Avatar
displeaser displeaser is offline
Periodically energetic Perler
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: May 2005
Location: Dublin, Ireland
Posts: 2,266 displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)  Folding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate Folder
Time spent in forums: 4 Weeks 5 h 23 m 13 sec
Reputation Power: 532
Hi,

welcome to Devshed.

Can you download hijackthis, run a scan and post the results of the Scan here.

Have you tried running the system file checker? If you havnt, open a command prompt and type:

sfc /scannow

What antivirus/Trojana scanners did you use?

Let us know how you get on.
Displeaser
__________________
Vi Veri Veniversum Vivus Vici.

Reply With Quote
  #4  
Old November 26th, 2006, 01:44 PM
aitken325i's Avatar
aitken325i aitken325i is offline
At a NO MA'AM meeting . . . .
Dev Shed God 18th Plane (13500 - 13999 posts)
 
Join Date: Mar 2004
Location: nr Edinburgh, Scotland
Posts: 13,549 aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)  Folding Points: 10110 Folding Title: Novice Folder
Time spent in forums: 5 Months 2 Weeks 1 Day 11 h 6 m 9 sec
Reputation Power: 1953
Thread split.

josephrot - it's always best to start a new thread.
__________________
The No Ma'am commandments:

1.) It is O.K. to call hooters 'knockers' and sometimes snack trays
2.) It is wrong to be French
3.) It is O.K. to put all bad people in a giant meat grinder
4.) Lawyers, see rule 3
5.) It is O.K. to drive a gas guzzler if it helps you get babes
6.) Everyone should car pool but me
7.) Bring back the word 'stewardesses'
8.) Synchronized swimming is not a sport
9.) Mud wrestling is a sport

Reply With Quote
  #5  
Old November 26th, 2006, 01:47 PM
josephrot josephrot is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2006
Posts: 5 josephrot User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 37 m 39 sec
Reputation Power: 0
Thank you to both Mugumi and displeaser for replies...

RATS, can't mention my Email address in the Forum, but that's understandable.

I have three XP Home / Pro systems, two are SP1 level, one is SP2. The SP1 one with the WINLOGON.EXE problem that keeps running on and on...

That is to say, the session boots up nicely, then WINLOGON.EXE does its work, then shuts down, only to again start up and all the while consumes great CPU resources as WINLOGON.EXE never really turns off and stays off as it should (comparing it to the other two normal systems)...

I am hopeful that re-installing WINLOGON.EXE from the on-the-machine O/S installer contents (these particular machines keep a copy of the entire XP CD on the machine as well as on a CD that I made for safety) will solve this nagging problem... but knowing MS and XP as I do, there's likely something else wrong that's causing WINLOGON.EXE to act this way, perhaps a new driver or other system level software that's not "letting go" of WINLOGON.EXE as it should or something like that. Rarely is XP ever that "easy to fix" by merely copying over a new copy of any file I have ever seen.

I am finding some mention of this problem as relates to Win 2003, and will hopefully locate a XP-specific entry or two in the MS Knowledge Base as well as 2003.

I have also tried many of the Registry Fix type applications, but to no avail or fix, in the hope they might locate some sort of Registry error.

Have used “all” the best quality anti-virus / anti-trojan / spyware out there.... Latest versions of Kapersky, Webroot SpySweeper, Spyware Doctor, and one or two others. Also utilize Grisoft AVG 7.5 continuously on the affected machine as well. All “say” nothing is wrong anywhere.

Will also run XP's System File Checker, to see what that shows or might do.

Thank you again for the ideas, and I will report back on what will hopefully fix this headache.

SMALL UPDATE: Yes, I am also inspecting with one or two normally superb and educational process explorer type applets.... hopefully will see what or who is doing what to WINLOGON.EXE

Joe
Knoxville, TN

Reply With Quote
  #6  
Old November 26th, 2006, 01:56 PM
displeaser's Avatar
displeaser displeaser is offline
Periodically energetic Perler
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: May 2005
Location: Dublin, Ireland
Posts: 2,266 displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)  Folding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate Folder
Time spent in forums: 4 Weeks 5 h 23 m 13 sec
Reputation Power: 532
Hi,

you might also want to have a look at process explorer. Services.exe runs under the winlogon process, so maybe one of your services is acting the bugger. Shut down any un-necessary services and see if that makes a difference.

Let us know how you get on with sfc /scannow and dont forget to post the hijackthis log.

Displeaser

Reply With Quote
  #7  
Old November 26th, 2006, 01:59 PM
aitken325i's Avatar
aitken325i aitken325i is offline
At a NO MA'AM meeting . . . .
Dev Shed God 18th Plane (13500 - 13999 posts)
 
Join Date: Mar 2004
Location: nr Edinburgh, Scotland
Posts: 13,549 aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)  Folding Points: 10110 Folding Title: Novice Folder
Time spent in forums: 5 Months 2 Weeks 1 Day 11 h 6 m 9 sec
Reputation Power: 1953
Sorry guys - I must have split the thread just as you were posting to it

Reply With Quote
  #8  
Old November 26th, 2006, 02:06 PM
displeaser's Avatar
displeaser displeaser is offline
Periodically energetic Perler
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: May 2005
Location: Dublin, Ireland
Posts: 2,266 displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)  Folding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate Folder
Time spent in forums: 4 Weeks 5 h 23 m 13 sec
Reputation Power: 532
Quote:
Originally Posted by aitken325i
Sorry guys - I must have split the thread just as you were posting to it


No probs Aitken, did get slightly confucing for a few mins though

Reply With Quote
  #9  
Old November 26th, 2006, 07:31 PM
josephrot josephrot is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2006
Posts: 5 josephrot User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 37 m 39 sec
Reputation Power: 0
WINLOGON.EXE eating up CPU, staying on

Quote:
Originally Posted by displeaser
Hi,

Let us know how you get on with sfc /scannow and dont forget to post the hijackthis log.

Displeaser


System File Checker reports all system files good, as expected, etc.

RE: << you might also want to have a look at process explorer. Services.exe runs under the winlogon process, so maybe one of your services is acting the bugger. Shut down any un-necessary services and see if that makes a difference.>>

Will do the above next. Thank you for the heads-up on process explorer from MS.

Reply With Quote
  #10  
Old November 26th, 2006, 07:38 PM
displeaser's Avatar
displeaser displeaser is offline
Periodically energetic Perler
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: May 2005
Location: Dublin, Ireland
Posts: 2,266 displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)  Folding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate Folder
Time spent in forums: 4 Weeks 5 h 23 m 13 sec
Reputation Power: 532
Quote:
Originally Posted by josephrot
System File Checker reports all system files good, as expected, etc.

RE: << you might also want to have a look at process explorer. Services.exe runs under the winlogon process, so maybe one of your services is acting the bugger. Shut down any un-necessary services and see if that makes a difference.>>

Will do the above next. Thank you for the heads-up on process explorer from MS.


Thats good anyway.

Very useful tool is process explorer, comes originally from sysinternals. Full list of utilities can be found here.

Also can you check your system/applications event logs to see if anything looks "dodgy" in there also post a hijackthis log for us to check.

Displeaser

Reply With Quote
  #11  
Old November 26th, 2006, 08:12 PM
megumi amatuka megumi amatuka is offline
Contributing User
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Jun 2004
Posts: 4,869 megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level) 
Time spent in forums: 2 Months 6 Days 21 h 24 m 42 sec
Reputation Power: 333
(^~;?(Winlogon haunter is, generally speaking, true Trojans.)

Mostly they work as Winlogon subprocess and not winlogon.exe itself. They are particularly malicious and stealth. HJT may not be enough.

Reply With Quote
  #12  
Old November 26th, 2006, 08:20 PM
displeaser's Avatar
displeaser displeaser is offline
Periodically energetic Perler
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: May 2005
Location: Dublin, Ireland
Posts: 2,266 displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)  Folding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate Folder
Time spent in forums: 4 Weeks 5 h 23 m 13 sec
Reputation Power: 532
Quote:
Originally Posted by megumi amatuka
(^~;?(Winlogon haunter is, generally speaking, true Trojans.)

Mostly they work as Winlogon subprocess and not winlogon.exe itself. They are particularly malicious and stealth. HJT may not be enough.


True, but process explorer may shed some light though. Is there anything newer then hjt that youve heard of Megumi?

josephrot:
Still do a HJT scan and post the results here, check your event log, Minimise your running services and see if the problem persists. if you have the problem can you check process explorer for anythin unusual and also maybe post a screenshot of the winlogon process with its child apps/dlls/process expanded.

Maybe run a Kaspersky online scan too (make a note of what ever it finds).

Theres nothing else we can do really until we get more info from you.

Displeaser

Reply With Quote