Windows XP Community - XPHeads



Registry Mechanic - Free Scan Now

CROSS-POST - winlogon.exe consuming 50% CPU time

microsoft.public.windowsxp.help_and_support


Reply
  #1 (permalink)  
Old 06-06-2008, 04:59 PM
Mike in Nebraska
 
Posts: n/a
CROSS-POST - winlogon.exe consuming 50% CPU time
[also posted on microsoft.public.windowsxp.security_admin]
Running WinXP Pro SP3.
========
I did some checking yesterday to see why my PC was "slow" and found that
this process was using !50% of the CPU time. Did a reboot, same thing.
Googles it and saw I might have malware so I ran Symantec AV, Windows
Defender in full scan, Sysinternal's Rootkit Revealer, and Windows Malicious
Software Removal. They found nothing.

I ran Sysinternal's Process Explorer and found the following:

winlogon.exe >> Properties >> Threads
TID 3108 consumes ~52% of CPU time and CSwitch Delta is ~160, and Start
Address is winlogon.exe+0x39156, and Context Switches is ~68,000.

The total thread count for this process is 22.

I've gone through msconfig to pare down what auto-starts with the same
results.

What else should I check?

--
Mike Webb
Platte River Whooping Crane Maintenance Trust, Inc.
a conservation non-profit (501 (c)(3)) organization
Wood River, NE


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 06-06-2008, 10:40 PM
David H. Lipman
 
Posts: n/a
Re: MULTI-POST - winlogon.exe consuming 50% CPU time
From: "Mike in Nebraska" <Mike_Webb@whoopingcrane.org>

| [also posted on microsoft.public.windowsxp.security_admin]
| Running WinXP Pro SP3.
| ========
| I did some checking yesterday to see why my PC was "slow" and found that
| this process was using !50% of the CPU time. Did a reboot, same thing.
| Googles it and saw I might have malware so I ran Symantec AV, Windows
| Defender in full scan, Sysinternal's Rootkit Revealer, and Windows Malicious
| Software Removal. They found nothing.
|
| I ran Sysinternal's Process Explorer and found the following:
|
| winlogon.exe >> Properties >> Threads
| TID 3108 consumes ~52% of CPU time and CSwitch Delta is ~160, and Start
| Address is winlogon.exe+0x39156, and Context Switches is ~68,000.
|
| The total thread count for this process is 22.
|
| I've gone through msconfig to pare down what auto-starts with the same
| results.
|
| What else should I check?
|


Actullay you Multi-Posted not Cross-Posted.

Process Explorer shows the fully qualified path to the running process.

What is the fully qualified path to winlogon.exe ?



--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 06-07-2008, 12:17 AM
Mike_in_Nebraska
 
Posts: n/a
Re: MULTI-POST - winlogon.exe consuming 50% CPU time
I'm at home now, and I don't remember seeing it. I'll look at it
Monday.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 06-09-2008, 08:16 PM
Mike in Nebraska
 
Posts: n/a
Re: MULTI-POST - winlogon.exe consuming 50% CPU time
Sorry to reply so late ...... the path to the file is:
C:\WINDOWS\system32\winlogon.exe

Mike

"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:%2315LGZCyIHA.2340@TK2MSFTNGP04.phx.gbl...
> From: "Mike in Nebraska" <Mike_Webb@whoopingcrane.org>
>
> | [also posted on microsoft.public.windowsxp.security_admin]
> | Running WinXP Pro SP3.
> | ========
> | I did some checking yesterday to see why my PC was "slow" and found that
> | this process was using !50% of the CPU time. Did a reboot, same thing.
> | Googles it and saw I might have malware so I ran Symantec AV, Windows
> | Defender in full scan, Sysinternal's Rootkit Revealer, and Windows
> Malicious
> | Software Removal. They found nothing.
> |
> | I ran Sysinternal's Process Explorer and found the following:
> |
> | winlogon.exe >> Properties >> Threads
> | TID 3108 consumes ~52% of CPU time and CSwitch Delta is ~160, and Start
> | Address is winlogon.exe+0x39156, and Context Switches is ~68,000.
> |
> | The total thread count for this process is 22.
> |
> | I've gone through msconfig to pare down what auto-starts with the same
> | results.
> |
> | What else should I check?
> |
>
>
> Actullay you Multi-Posted not Cross-Posted.
>
> Process Explorer shows the fully qualified path to the running process.
>
> What is the fully qualified path to winlogon.exe ?
>
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>



Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 06-09-2008, 08:31 PM
David H. Lipman
 
Posts: n/a
Re: MULTI-POST - winlogon.exe consuming 50% CPU time
From: "Mike in Nebraska" <Mike_Webb@whoopingcrane.org>

| Sorry to reply so late ...... the path to the file is:
| C:\WINDOWS\system32\winlogon.exe
|
| Mike
|


That's the legitimate file. The question is are there hooks in Winlogon that is causing a
higher CPU utilization.

Download and execute HiJack This! (HJT)
http://www.trendsecure.com/portal/en...HJTInstall.exe

Save a log and open it in Notepad.

Find the lines that start with "O20 - Winlogon ..."
Copy and paste ONLY those lines in your reply.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 06-09-2008, 08:38 PM
Mike in Nebraska
 
Posts: n/a
Re: MULTI-POST - winlogon.exe consuming 50% CPU time
Did as suggested but no entries of "O20 Winlogon" were in the log file.

Mike
"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:OSf5D$myIHA.4772@TK2MSFTNGP03.phx.gbl...
> From: "Mike in Nebraska" <Mike_Webb@whoopingcrane.org>
>
> | Sorry to reply so late ...... the path to the file is:
> | C:\WINDOWS\system32\winlogon.exe
> |
> | Mike
> |
>
>
> That's the legitimate file. The question is are there hooks in Winlogon
> that is causing a
> higher CPU utilization.
>
> Download and execute HiJack This! (HJT)
> http://www.trendsecure.com/portal/en...HJTInstall.exe
>
> Save a log and open it in Notepad.
>
> Find the lines that start with "O20 - Winlogon ..."
> Copy and paste ONLY those lines in your reply.
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>



Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 06-09-2008, 09:13 PM
David H. Lipman
 
Posts: n/a
Re: MULTI-POST - winlogon.exe consuming 50% CPU time
From: "Mike in Nebraska" <Mike_Webb@whoopingcrane.org>

| Did as suggested but no entries of "O20 Winlogon" were in the log file.
|
| Mike


Thank you.
I am at a loss of why you have high utilization :-(

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 06-09-2008, 09:19 PM
Mike in Nebraska
 
Posts: n/a
Re: MULTI-POST - winlogon.exe consuming 50% CPU time
Well, maybe it's not all a loss of time. It would appear not to be malware.
"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:%23dpspWnyIHA.5520@TK2MSFTNGP06.phx.gbl...
> From: "Mike in Nebraska" <Mike_Webb@whoopingcrane.org>
>
> | Did as suggested but no entries of "O20 Winlogon" were in the log file.
> |
> | Mike
>
>
> Thank you.
> I am at a loss of why you have high utilization :-(
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>



Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 08:54 AM.


Registry Mechanic - Free Scan Now
Driver Scanner 2009 - Free Scan Now




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74