Winlogon.exe constantly at 50% CPU

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by pfcGump, Nov 19, 2007.

  1. pfcGump

    pfcGump Private E-2

    I know this has probably been discussed before, but I recently noticed my server was slowing down. When I checked Task Manager, I noticed there are two winlogon.exe processes running. Both show the user as SYSTEM, but one of them constantly runs at 50-60% CPU utilization.

    I am running Windows 2003 Standard Edition with SP2. It's a web server I use to host some family sites. I've also got FileZilla Server running to access SFTP traffic for file uploads. There isn't no monitor hooked up so I only use RDP to connect to it. This problem only showed up about 4-6 weeks ago.

    The only change I remember making before this started showing up was the installation of a print drive for an old HP printer I was toying with, but I have since uninstalled everything that I can from the Add/Remove Programs option in Control Panel. I've also run the TrendMicro Housecall to try and clean things up a bit, but there was nothing detected other than some normal cookies.

    I have a HJT log file but won't post it until told to do so. Any help would be greatly appreciated.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Are multiple users logged in when you saw the two winlogon.exe processes?


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    Read & RUN ME FIRST Before Asking for Support
     
  3. pfcGump

    pfcGump Private E-2

    I'll run through the instructions tonight.

    There aren't any other users logged in, but I wasn't sure if connecting via RDP made a difference. The server has been rebooted multiple times since I disconnected and threw away the monitor, so I don't think there's a session active on the console.

    I post the logs soon.

    Pfc Gump :major
     
  4. pfcGump

    pfcGump Private E-2

    Here are the log files after running the READ & RUN ME FIRST procedure. I ran AVG Antispyware tool twice and couldn't get it to give me an option for saving the log file.

    Thanks in advance for your help.

    Is the fact that I'm seeing 2 instances of winlogon.exe in task manager when I can only account for one user being logged in a potential cause for concern?

    pfcGump
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your second winlogon.exe is just due to the Remote Desktop Connection running. I wanted to see the logs to be sure what it was from but it is a normal behavior when you use RDP.

    Your logs are clean but you do need to uninstall the below old Sun Java versions:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 2
    Java(TM) SE Runtime Environment 6 Update 1

    Also you need to get an antivirus and firewall installed.
     
  6. pfcGump

    pfcGump Private E-2

    Thanks chaslang,

    I don't know what did it, but both winlogon.exe process are mostly idle now. After I ran all the checks and posted my logs, one of the processes was still hanging around the 50-60% range, but I waited a few hours and checked again and all seems fine. I did pull out an old monitor and plugged it back into the server, but it doubtful that had anything to do with it.

    Thanks again. One more happy MajorGeeks customer.

    pfcGump
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds