winlogon.exe still @ 100% CPU after following Removal Guide

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by j1smith2@hotmail.com, Nov 7, 2007.

  1. j1smith2@hotmail.com

    j1smith2@hotmail.com Private E-2

    WinXP SP2 box

    CPU pegs @ 100% on winlogon.exe - seems to be at random times. Can reboot the machine and just let it sit inactive - come back an hour later and winlogon.exe is going full bore.

    Only fix seems to be hard power cycle.

    Attaching logs. Have followed READ & RUN ME FIRST Before Asking for Support. Well, at least down to the BitDefender online san. B/c of geographic location, this box only has dialup access. After waiting an hour for BitDefender to update virus definitions, it came back with an error and could not install the new defs. Exasperating.

    Went ahead and ran Bitdefender scan with old defs. Said it deleted Trojan.Peed.Gen from a FastStone dll. Didn't fix problem. Expect this was a false positive b/c nothing else reported it and downloaded directly from FastStone.org. Nonetheless, I haven't re-installed until this winlogon.exe issue gets resolved.

    Based on some other posts about similar problems, also ran VundoFix (no infected files found - V6.5.11) and ComboFix. Didn't see anything that particularly bothered me, but 1st time using these tools.

    Suggestions?
     

    Attached Files:

    Last edited: Nov 7, 2007
  2. j1smith2@hotmail.com

    j1smith2@hotmail.com Private E-2

    Re: winlogon.exe still @ 100% CPU after following Removal Guide (additional logs)

    additional logs attached
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    FastStone Image Viewer 3.2
    Viewpoint Media Player

    Then check and if present, delete:
    C:\Documents and Settings\All Users\Desktop\FastStone Image Viewer.lnk
    C:\Documents and Settings\Administrator\Application Data\FastStone
    C:\Documents and Settings\All Users\Application Data\Viewpoint
    C:\Program Files\FastStone Image Viewer
    C:\Program Files\Viewpoint

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.



    Tell me how things are running and what issues remain.
     
  4. j1smith2@hotmail.com

    j1smith2@hotmail.com Private E-2

    Made the changes you requested. Afraid it hasn't changed the status of anything. Over the course of the day, machine still freezes up.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is sounding more like a software or hardware issue ....what exactly are you doing when it "freezes"?

    Go to the control panel and click admin tools / event viewer and look for any problems in either application or system. Let me know what they are.
     
  6. j1smith2@hotmail.com

    j1smith2@hotmail.com Private E-2

    Winlogon.exe seems to peg out when the computer is idling.

    Rebooted this morning. Finished using OpenOffice for word processing around 9:00am. Left OpenOffice application open and left the machine sitting idle for most of the day. When I checked the box at 7:15pm, Winlogon.exe was running at 100% utilization. There was a Windows Security ballon saying that Symantec Endpoint Protection was disabled. At 8:55, it was still pegged and I power cycled.


    Couple of items of note from system / application logs:

    On 11/9 at at 7:18pm, log shows the Symantec successfully downloaded definition files from LiveUpdate. But when you open Symantec and check definitions, version is Tuesday, Oct 16, 2007 r9. Only internet connection is dialup - could have been online at 7:18 on 11/9 but did not initiate a virus update.

    There are also several Symantec Tamper Protection notices from AOL processes.

    Nothing else stands out
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right click the winlogon.exe and tell me what the properties/association is ...

    Is Symnatec a paid for application? And is AOL your ISP?

    If you disable symnatec...does the process stop?

    What happens if you kill the process?
     
  8. j1smith2@hotmail.com

    j1smith2@hotmail.com Private E-2

    Right click the winlogon.exe and tell me what the properties/association is ...

    Did a search of harddrive for winlogon.exe. Found it in
    c:\windows\system32 - file version 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    c:\windows\servicepackfiles\i386 (xpsp_sp2_rtm.040803-2158)
    Binary comparison showed that these are exactly the same file

    When I first boot up, winlogon.exe process is using 1,792k memory. When it is hogging processor, is at 4700k.
    Priority is set to High at bootup.




    Is Symnatec a paid for application? And is AOL your ISP?
    Yes, everything on this box is legitimately licensed.

    Symantec Endpoint Protection 11.0.780.1109
    Antivirus / spyware definitions Tues, Oct 16, 07 r9
    Proactive Threat Protection definitions Tues Oct 16, 07 r33
    Network Threat Protection Thur Oct 11, 07 r1

    AOL (9.0 VR Revision 4327.5006) is ISP for this box.



    If you disable symnatec...does the process stop?

    I think there are multiple processes associated with Symantec:
    ccapp.exe
    ccSvcHst
    Right-click on system tray and disable realtime protection doesn't seem to have any effect on these particular processes. But it doesn't remove icon from tray either...
    If you really want it disabled, I believe it will probably require some registry edits - don't know which particular keys though.


    Something else called CDAC11BA.exe - don't know what it is.

    Another possibly related process - Rtvscan.exe



    What happens if you kill the process?
    kill Rtvscan: no noticeable impact. But it re-spawns itself.
    kill ccSvcHst. exe: WinSecurity Center reports Enpoint is turned off, but Symantec is actually still actively running. Process re-spawns itself.
    Kill ccApp: can't tell that anything happened.
    kill CDAC11BA.exe : can't tell that anything happened.


    Rebooted so things weren't quite so molested - attached is a list of the processes that are running at startup. All the copies of SvcHost seem a bit strange

    Dialup connection is too slow to attempt to look up what all these processes are. I'll have to do a bit more research tomorrow.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    "cdac11ba.exe" is part of the copy-protection software
    "rtvscan.exe" is Symantec's Norton AntiVirus' realtime virus scanning application.

    Run Process Explorer 10.21

    Run Process Explorer

    To ascertain which service is causing the problem select the image
    producing the high CPU usage, right click, select Properties,
    Services. Note there are the full names and some explanation of what
    each service does.

    To trace the particular Service involved you need to turn off each
    service in turn and then restore it noting what effect it has on CPU
    usage. However, you need to take care and watch what other Services
    are dependent on that service. When you click on the Dependencies
    tab allow it a little time to display the information.

    Let me know what you find.
     
  10. j1smith2@hotmail.com

    j1smith2@hotmail.com Private E-2

    First time using ProcessExplorer. Sorry, but I'm not quite following your instructions.

    Right Click on Winlogon.exe, Properties - there is no Services tab.

    Haven't found a Dependencies tab either. Only thing I see is the process tree - which almost all the processes running on the box are children of winlogon.exe.


    When you say turn off a service, do you mean suspend the process? Restore a service mean resume that process?

    I assume that I should suspend the child processes in turn rather than the parent winlogon.exe process?

    Sorry for the elementary questions, just haven't quite synced up with the mechanics of the tool. Hate to ask you to babysit, but I need more specific instructions.

    I've attached a couple of screen shots from right after a clean boot - winlogon.exe hasn't gone haywire at this point.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Two things are evident from your screen shots .....symantec is using most of it and AOL is probably responsible for the rest ....so right click each of those items (yes the child ....) and suspend the service ....both programs I suspect are actively accessing the web. Then see if your cpu usage drops.
     
  12. j1smith2@hotmail.com

    j1smith2@hotmail.com Private E-2

    TimW,

    Thanks for all your help. Looks like your diagnosis of a likely hardware problem was spot on. I believe everything is probably cleared up now. Will watch it for a couple of days and let you know.


    Here's a synopsis:
    Task Manager reports Winlogon.exe running at 100% utilization.
    Process Explorer shows that it is actually a hardware interrupt problem.

    Started removing PCI cards.

    When I got rid of an old internal 56k modem, utilization dropped back to 0%. Apparently it was camping out on the bus.

    Again, thanks for your help :D
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet....glad you got it sorted out ...:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds