Next Generation Emulation banner

1 - 16 of 16 Posts

·
Finger of Doom
Joined
·
823 Posts
Discussion Starter #1
How the hell does that work?

Sometimes I've seen winlogon.exe using one of my cores to it's fullest in the task bar. However, knowing what it does, I find that VERY hard to believe.

Any ideas on why it does that?
 

·
Finger of Doom
Joined
·
823 Posts
Discussion Starter #3 (Edited)
No. I have yet to get the program(though I've had the intention to do it for some time now).

Be back once I have it.

Here you go:

NOTE: My OS is in Spanish, so if you need me to translate anything in the log I will.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:52:56 PM, on 12/13/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\ESRI\License\arcgis9x\lmgrd.exe
C:\Archivos de programa\IVT Corporation\BlueSoleil\BlueSoleilCS.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Java\jre6\bin\jqs.exe
C:\Archivos de programa\Java\jre6\bin\jusched.exe
C:\Archivos de programa\BitDefender\BitDefender 2008\bdagent.exe
C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Archivos de programa\Archivos comunes\Protexis\License Service\PsiService_2.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\Archivos comunes\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Archivos de programa\Archivos comunes\BitDefender\BitDefender Update Service\livesrv.exe
C:\Archivos de programa\ESRI\License\arcgis9x\ARCGIS.exe
C:\Archivos de programa\Logitech\Gaming Software\LWEMon.exe
C:\Archivos de programa\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
C:\Archivos de programa\Windows Media Player\WMPNSCFG.exe
C:\Archivos de programa\IVT Corporation\BlueSoleil\BsHelpCS.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Archivos de programa\Mozilla Firefox\firefox.exe
D:\Archivos de programa\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Yahoo!
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: Aplicación auxiliar de vínculos de Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7D4C3C93-341E-3B25-B546-5EA1CDCABACC} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Aplicación auxiliar de inicio de sesión - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Complemento del Asistente para Internet de Encarta - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Archivos de programa\acrobat6\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Archivos de programa\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Archivos de programa\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Asistente para Internet de Encarta - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Archivos de programa\acrobat6\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Archivos de programa\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Archivos de programa\Archivos comunes\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Archivos de programa\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Archivos de programa\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Archivos de programa\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Archivos de programa\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [amd_dc_opt] C:\Archivos de programa\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Archivos de programa\acrobat6\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [RocketDock] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Archivos de programa\Windows Media Player\WMPNSCFG.exe
O4 - HKLM\..\Policies\Explorer\Run: [ati2sgav] "C:\WINDOWS\system32\ati2sgav.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe (User 'Default user')
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://c:\archivos de programa\microsoft office\office12\excel.exe/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARCHIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARCHIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061023/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.0.97.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/ES-AR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - ijji - Where Gamers Unite!
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1137353991500
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - ijji - Where Gamers Unite!
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DD583921-A9E9-4FBF-9266-8DC2AB5EA0AF} (HGPlugin10USA Class) - ijji - Where Gamers Unite!
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9257F42B-6B69-46FB-A49B-9471E1713EFA}: NameServer = 200.51.212.7,200.51.211.7
O17 - HKLM\System\CCS\Services\Tcpip\..\{CE4C028E-2AF7-437D-BFFD-79C4042F6FF2}: NameServer = 200.51.212.7,200.51.211.7
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Archivos de programa\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: ArcGIS License Manager - Unknown owner - C:\Archivos de programa\ESRI\License\arcgis9x\lmgrd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Archivos de programa\Archivos comunes\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: BlueSoleilCS - Unknown owner - C:\Archivos de programa\IVT Corporation\BlueSoleil\BlueSoleilCS.exe
O23 - Service: BsHelpCS - Unknown owner - C:\Archivos de programa\IVT Corporation\BlueSoleil\BsHelpCS.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Archivos de programa\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Archivos de programa\Archivos comunes\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Archivos de programa\Java\jre6\bin\jqs.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Archivos de programa\Archivos comunes\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Archivos de programa\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Archivos de programa\Archivos comunes\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Archivos de programa\Archivos comunes\Protexis\License Service\PsiService_2.exe
O23 - Service: ServiceLayer - Unknown owner - C:\Archivos de programa\PC Connectivity Solution\ServiceLayer.exe (file missing)
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Archivos de programa\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Archivos de programa\Archivos comunes\BitDefender\BitDefender Communicator\xcommsvr.exe

--
End of file - 12990 bytes
 

·
Site Owner
Joined
·
14,909 Posts
probably some kind of virus.....or a rootkit
 

·
Registered
Joined
·
1,601 Posts
could be the vundo trojan, i had the same issue and the trojan vundo infects and resides in winlogon.exe therefore most antivirus apps cant remove it, or they say they did but a simple restart puts the trojan up again, the best anitvirus app ive seen against this trojan is norton internet security... oh by the way if anyone says norton isnt the best against this trojan is wrong since it is only the app to remove it fully and can remove all the variants
 

·
Banned
Joined
·
23,263 Posts
Norton sucks arse, i could remove this trojan in 10 minutes using safe mode, a crow bar and a cup of coffee.
 

·
Finger of Doom
Joined
·
823 Posts
Discussion Starter #8
That program found "iexplore.exe" to be "possibly" infected by the trojan and suspends/terminates the process(yet does not block or eliminate the thing).

Other than that, it's clean.
Any other ideas?
 

·
Registered
Joined
·
1,601 Posts
not all trojan vundo variants can be removed, by manual or any antivirus apps except norton internet security, i mean the new ones, removing them properly so they dont come after restart, dont damage the system by removing thetrojan from winlogon.exe and block the new variants, notron is best thus far.... and saying its crap is wrong when they have been updating it aggresively over the past two years in performance, program compatibility, stability and protectiion... no other antivirus/internet security app ive seen (ive tried mcaffee, zonealarm, nod32, avg full retail, panda, in multiple versions/updates, with different OSes and apps and i got my comp slowed to a crawl (zonealarm), vundo trojan variants and many various viruses/trojans come through autoprotect (all progs but norton IS 2008-2009 had the best protection with the latest updates) comes close in quality especially performance in norton internet security 2009, it is the fastest runng internet security to date as well as the least resources, thats what i call a quality update, sure others promised such updates still it had issues with p2p software and games where NIS 2009 had none .

i just hate people who complain about an app when they are complaining past and fixed issues, at norton fixed all the issues, nod32 still lets too many trojans through, the developers said they arent technically viruses but its tupid when there are vundo variants that kill winxp and winvista installations, zonealarm have issues with some apps and games where it makes your comp slow, so low it feels like a 486 running vista, sure some are fixed but the same app that has the issue fixed gets a small update and you have to wait 6 months for the developers to support it again, mcaffee is much more of a resource hog than NIS2009, AVG doesnt provide a decent autoprotect and cant remove and detect the new vundo variants

please note that i have test the server versions of all the antivirus/internet security apps as well and came accross same issues except avg, by far avg retail server editon is kick ass if you can afford it since it monitors/scans all the different servers that are running like file, exchange, iis, sql and many others

this method doesnt work on the new variants of vundo
 

·
Registered
Joined
·
415 Posts
not all trojan vundo variants can be removed, by manual or any antivirus apps except norton internet security, i mean the new ones, removing them properly so they dont come after restart, dont damage the system by removing thetrojan from winlogon.exe and block the new variants, notron is best thus far.... and saying its crap is wrong when they have been updating it aggresively over the past two years in performance, program compatibility, stability and protectiion... no other antivirus/internet security app ive seen (ive tried mcaffee, zonealarm, nod32, avg full retail, panda, in multiple versions/updates, with different OSes and apps and i got my comp slowed to a crawl (zonealarm), vundo trojan variants and many various viruses/trojans come through autoprotect (all progs but norton IS 2008-2009 had the best protection with the latest updates) comes close in quality especially performance in norton internet security 2009, it is the fastest runng internet security to date as well as the least resources, thats what i call a quality update, sure others promised such updates still it had issues with p2p software and games where NIS 2009 had none .

i just hate people who complain about an app when they are complaining past and fixed issues, at norton fixed all the issues, nod32 still lets too many trojans through, the developers said they arent technically viruses but its tupid when there are vundo variants that kill winxp and winvista installations, zonealarm have issues with some apps and games where it makes your comp slow, so low it feels like a 486 running vista, sure some are fixed but the same app that has the issue fixed gets a small update and you have to wait 6 months for the developers to support it again, mcaffee is much more of a resource hog than NIS2009, AVG doesnt provide a decent autoprotect and cant remove and detect the new vundo variants

please note that i have test the server versions of all the antivirus/internet security apps as well and came accross same issues except avg, by far avg retail server editon is kick ass if you can afford it since it monitors/scans all the different servers that are running like file, exchange, iis, sql and many others



this method doesnt work on the new variants of vundo
Why are you defending Norton so much? Do you work for the company or something, because you're getting so defensive about, and that was before anyone said anything about it. I used Norton to try and remove vundo a few months back, and it was worthless...did absolutely nothing. Heck, it didn't even detect I had it. Other scanners detected I had it, but couldn't remove it. I ended up using a combination of tools made just for removal of this virus and others similar to it in safe mode, and got rid of it. Personally, I wouldn't use Norton if you gave me a lifetime copy for free, it just doesn't do anything.
 

·
Registered
Joined
·
235 Posts
Just reinstall the OS, if you don't have anything backed up, you should do so in the future for future problems that might happen, that's what I do from now on. I partitioned my drive for the OS entirely away from other drives so it would be easier to reinstall the OS again incase I can't get it out or just to be safe.
 

·
Finger of Doom
Joined
·
823 Posts
Discussion Starter #13
I have a partition for my drive with the OS and some other programs in it. Reinstalling the OS, though? I'll only do it as a last resort thing. If I can avoid having to do that, I will.
 

·
Site Owner
Joined
·
14,909 Posts
I dont even use a partition. I use my raptor as my C drive. All my other drives have absolutely nothing to do with the OS.
 

·
Hackin 'n Slashin
Joined
·
28,630 Posts

·
Finger of Doom
Joined
·
823 Posts
Discussion Starter #16
Supposedly. All it did, though, was suspend and terminate iexplore.exe.
Yet, after a reset, the process is still open(even though it shouldn't).

I have yet to see winlogon.exe use 50% of my CPU, though(something triggers it, that I know. But I can't figure out just what).
 
1 - 16 of 16 Posts
Top