Windows XP misspelled at Logoff

Discussion in 'Software' started by Duffer128, Mar 1, 2014.

  1. Duffer128

    Duffer128 Private E-2

    I have a Dell Dimension E520 computer running windows xp service pack 3. Fully updated.

    There are three Users registered .

    A couple of days ago I wanted to Log off one User and Log on as one of the others.

    The normal Log off screen came up but the lower left hand corner of the screen displayed a misspelling of the words WINDOWS XP. It was spelled WINDOES XP . I used a digital camera to take two pictures of the screen , see attached images.

    I suspected malware or a virus so I ran Malwarebytes, Windows defender offline and Norton power eraser. They removed a few minor issues, but the misspelling persists. The screen with the misspelling works normally.

    Can anyone suggest what's happening

    Thanks
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    HI

    If you had a few minor malwares then I would suspect some more deep rooted ones perhaps as cannot think of anything off hand that would allow you to change that message.

    SO I would run the below guide and then start a new thread in our malware forum and attach the requested logs for our malware team to review

     
  3. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    Are you sure someone didn't edit that? My XP computers say Turn Off Computer.
     
  4. _nullptr

    _nullptr Major Geeky Geek Geek

    This can be done by modifying logonui.exe located in the system32 directory. You'll need to display hidden files and folders (the option is in Control Panel > Folder Options > View - Advanced settings) to locate the file. Upload logonui.exe to VirusTotal https://www.virustotal.com/ and provide a link for the scan result, so we can verify the file hash value.
     
  5. the mekanic

    the mekanic Major Mekanical Geek

    Just a few simple questions:

    Where did you get the install CDs or .iso files for this version of XP?

    How long have you personally owned this PC?
     
  6. Duffer128

    Duffer128 Private E-2

    I bought it from Dell about five years ago. Windows was preinstalled and they supplied product recovery disks. I reinstalled a couple of times using he original product recovery disks.

    One of the other replies posted asked if I edited the image . No I didn't edit it.
     
  7. Duffer128

    Duffer128 Private E-2

    I bought the computer from Dell, and I am the only user. I am a computer technician and have repaired and maintained computers for 20 plus years.
    Never came across anything like this .

    I'm puzzled by the misspelling.

    Maybe I should just reload windows and go on to something more productive.

    Thanks anyway.
     
  8. the mekanic

    the mekanic Major Mekanical Geek

    If it's malware holed up in the MBR, a reinstall won't make any difference.
     
  9. Duffer128

    Duffer128 Private E-2

    If i decide to re-install Windows xp, I will be sure to use fdisk or something else like fixmbr to create a new mbr.

    thanks
     
  10. Colemanguy

    Colemanguy MajorGeek

    Check the computers machine name/hostname.
     
  11. Duffer128

    Duffer128 Private E-2

    Thanks

    I uploaded and scanned and the result came back detection ratio 0/50 and with the following information. I cut and pasted it here.
    SHA256: 032b6d1f541f180a2fe619664ef180d3fd748aef7e311ba925fced74e7ed4713
    File name: logonui.exe
    Detection ratio: 0 / 50
     
  12. _nullptr

    _nullptr Major Geeky Geek Geek

    That file hash is legitimate.

    If you're comfortable with going into the windows registry, Go to Start > Run > regedit
    Navigate to the key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
    Then check the value named UIHost.
    It should be of type REG_EXPAND_SZ with a data value of logonui.exe
    Also look if there's a value named ginaDLL under the same registry key.
     
  13. C0rhHusk3r

    C0rhHusk3r Private First Class

    If you have repaired and maintained computers for so long, I'm really surprised you've never seen something like this. Don't know about the newer operating systems, but in the "olden days" of Win 95/98/2000 it was fairly easy to change such things as what you're seeing. There were various "tweaking" programs, or savvy users could do it by making simple edits to the registry. Did it myself a few times.
     
  14. Duffer128

    Duffer128 Private E-2

    I have been programming since 1960.
    At that time bits were flat,


    In earlier versions of Windows It was easy to locate and modify the Windows Welcome, Logon, Logoff, etc, etc image files . They were ordinary jpg or bmp files.

    It's a little more difficult now.

    Right now the Windows XP computer is running in a command prompt window.

    Starting in the root directory, I am running the this command:
    dir log*.* /s > result.txt

    It's kind of brute force, but let's see what comes up.
    That should identify and locate every filename that begins with log .
    Hopefully it will identify the logon and logoff image files.

    No luck there.

    Quoting Inspector Harry Callahan ( Clint Eastwood, Dirty Harry, Magnum force), "A man's got to know his limitations" ...

    I quit.

    Thank one and all.
     
  15. C0rhHusk3r

    C0rhHusk3r Private First Class

    What account type are the other users of this machine? If things such as this are a concern, perhaps fewer permissions would be in order. No telling what else one of them might try.
     
  16. Duffer128

    Duffer128 Private E-2

    There are several users , but all of them are me.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds