Windows Security
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
 
User Name:
Password:
Remember me
Go Back   ASP Free ForumsSystem AdministrationWindows Security

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread ASP Free Forums Sponsor:
  #1  
Old June 22nd, 2005, 06:45 PM
jmurrayhead jmurrayhead is offline
Moderator
ASP Free God 17th Plane (13000 - 13499 posts)
 
Join Date: Feb 2004
Location: Reston, VA, USA
Posts: 13,091 jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)  Folding Points: 88298 Folding Title: Advanced FolderFolding Points: 88298 Folding Title: Advanced FolderFolding Points: 88298 Folding Title: Advanced FolderFolding Points: 88298 Folding Title: Advanced FolderFolding Points: 88298 Folding Title: Advanced Folder
Time spent in forums: 3 Months 1 Week 11 h 23 m 46 sec
Reputation Power: 1580
Task Manager Problems - winupdates.exe

Hello,

I often see people having Task Manager problems, such as it won't open when pressing ctrl + alt + del and selecting Task Manager. I thought I would just put this little bit of info out:

Run a complete virus scan on your system. If you need to, go to symantec.com or trendmicro.com and use their free online virus detection.

If something is found, take care of that problem. If curing those problems doesn't take care of the Task Manager issue, browse to the C:\Program Files directory. If there is a folder names "winupdates", this is most likely your problem. Make sure you go to Folder Options and select "Show Hidden Files and Folders" as the folder may be hidden. If this folder exists, you will need to reboot into Safe Mode and delete the folder. You will need to reboot into Safe Mode because the worm process is running when your desktop loads. You can't delete a file when it is in use, and you obviously can't kill the process when you can't access the task manager.

Also, this worm write the following to the registry:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]

"winupdates"="C:\\Program Files\\winupdates\\winupdates.exe /auto"

You can just use the registry editor to delete this.

I hope this helps many out there having this problem. I just see it come up so often I figured I'd give some advice about it.

Reply With Quote
  #2  
Old July 2nd, 2005, 07:40 PM
oneMSBi's Avatar
oneMSBi oneMSBi is offline
Caution:Loderator Moose !
ASP Free Newbie (0 - 499 posts)
 
Join Date: May 2005
Location: India
Posts: 235 oneMSBi User rank is Corporal (100 - 500 Reputation Level)oneMSBi User rank is Corporal (100 - 500 Reputation Level)oneMSBi User rank is Corporal (100 - 500 Reputation Level)oneMSBi User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 1 Day 22 h 49 m 43 sec
Reputation Power: 6
this information on how to tackle a W32.HLLW.Gaobot.BC or the W32/Rbot-MM or W32/Gaobot.worm.gen is incomplete.

Quote:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]

"winupdates"="C:\\Program Files\\winupdates\\winupdates.exe /auto"


This entry is charecteristic of the worms i have mentioned above.

The correct and more complete process would be as follows. BUT REMEMBER THAT REMOVING MALWARE IS DIFFICULT TASK AND MUST BE CUSTOMISED FOR EACH INFECTION.

Download and install the following programs, If they're not on your computer, yet:

- AdAware SE: http://www.lavasoftusa.com/software/adaware/
- Spybot: http://www.safer-networking.org/
- CCleaner: http://www.ccleaner.com/ccdownload.php

Use Taskmanager (Ctrl-Alt-Del) to end these running processes if you can. Since it is very likely you will not be able to do so I recommnd you use Process Explorer freely available from SysInternals here
http://sysinternals.com/ntw2k/freeware/procexp.shtml

winupdates.exe

Next Go to Add/Remove Programs (START, settings, control Panel) and uninstall these apps (all may not be listed)
anything with a name similar to MyWay, MySearch, MyWebSearch, etc.

winupdates

Make sure you can view hidden and system files: if you do not know how to do this then you can find out how below.
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

Then Boot to safe mode: IF you do not know how then see the following link for information:
http://service1.symantec.com/SUPPOR...src=sec_doc_nam

Now Make sure all browser and all Windows Explorer windows closed.
Then:
1. Click Start, and then click Run. (The Run dialog box appears.)
2. Type regedit

Then click OK. (The Registry Editor opens.)

3. Navigate to each of the keys:
* HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run
* HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\
RunServices

4. In the right pane, delete any of the following values:
* "Microsoft Office Start"="winupdates.exe"
* "Configuration Loader"="svch0st.exe"

5. Exit the Registry Editor.


Delete the following folder IF still present on your computer:
C:\Program Files\winupdates

Reboot

Do a System-Scan with AdAware SE:

- Open AdAware SE
- First of all, check for updates.
To do this, click on 'Check for updates now', click the 'Connect'-button and, if there are new updates, click 'OK' and then 'Finish'.
- Now, do a system-scan by clicking the 'Start'-button.
- In the next screen, select 'Perform Full System scan' and click the 'Next'-button.

- When the scan is done, right-click in the list of items, that AdAware found, and select 'Select All', click the 'Next'-button and then 'the 'Finish'-button.
- Close AdAware SE.

Do a system-scan with Spybot:

- Open Spybot 1.4
- First, Check for updates
click the 'Search for updates'-button. If there are updates available, select them and click the 'Download updates'-button.
- Click 'Search and destroy' and then 'Check for problems'.
- Relax, while Spybot is performing it's scan.
- When Spybot is done, it will show a list of found items (or congratulate you with a clean computer). Click 'Fix selected problems' to delete the items.
- Close Spybot 1.4


Run CCleaner


Before first use, check under Options, Settings, and ensure "Only delete files in Windows Temp folder older than 48 hours" is unchecked.
Then open it and select the items you wish to clean up.

In the Windows Tab:

I recommend cleaning all entries in the "Internet Explorer" section except Cookies.
Clean all the entries in the "Windows Explorer" section
Clean all entries in the "System" section
Clean all entries in the "Advanced" section.

In the Applications Tab:
Clean all except cookies in the Firefox/Mozilla section if you use it.
Clean all in the Opera section if you use it.
Clean Sun Java in the Internet Section.
Clean any others that you choose.

Then click the "Run Cleaner" button

Finally, do an online scan using Trend Micro Housecall. It is available.

http://housecall.antivirus.com/

You can get better assistance on this over at another devshed forum below
http://forums.devshed.com/f117/s
Comments on this post
jmurrayhead agrees!
Shadow Wizard agrees: good info, looks like you have unlimited resource pool...
Nilpo agrees: Nice contribution....as always.

Reply With Quote
  #3  
Old July 2nd, 2005, 07:51 PM
jmurrayhead jmurrayhead is offline
Moderator
ASP Free God 17th Plane (13000 - 13499 posts)
 
Join Date: Feb 2004
Location: Reston, VA, USA
Posts: 13,091 jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)  Folding Points: 88298 Folding Title: Advanced FolderFolding Points: 88298 Folding Title: Advanced FolderFolding Points: 88298 Folding Title: Advanced FolderFolding Points: 88298 Folding Title: Advanced FolderFolding Points: 88298 Folding Title: Advanced Folder
Time spent in forums: 3 Months 1 Week 11 h 23 m 46 sec
Reputation Power: 1580
Nice add on, I've been unable to find that much information on it.

Reply With Quote
  #4  
Old July 2nd, 2005, 08:01 PM
oneMSBi's Avatar
oneMSBi oneMSBi is offline
Caution:Loderator Moose !
ASP Free Newbie (0 - 499 posts)
 
Join Date: May 2005
Location: India
Posts: 235 oneMSBi User rank is Corporal (100 - 500 Reputation Level)oneMSBi User rank is Corporal (100 - 500 Reputation Level)oneMSBi User rank is Corporal (100 - 500 Reputation Level)oneMSBi User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 1 Day 22 h 49 m 43 sec
Reputation Power: 6
cheers mate

you can find out more on this type of infection at the following websites
http://securityresponse.symantec.co....gaobot.bc.html
http://www.sophos.com/virusinfo/analyses/w32rbotmm.html

Reply With Quote
  #5  
Old March 29th, 2006, 11:24 AM
TY:D TY:D is offline
Registered User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Mar 2006
Posts: 1 TY:D User rank is Private First Class (20 - 50 Reputation Level)TY:D User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 2 m 23 sec
Reputation Power: 0
Sorry for being a thread-digger, but I just had to say thanks for this thread
I was stupid enough to d/l a 850-ish kb version of LimeWire and actually run it! (I checked it with AVG first though, and it gave me nada :\)

Once again, thanks
Comments on this post
Shadow Wizard agrees: cheers, good to know this forum is helpful.

Reply With Quote
  #6  
Old October 27th, 2006, 02:03 PM
awvt awvt is offline
Registered User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Oct 2006
Posts: 1 awvt User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 40 m 7 sec
Reputation Power: 0
Exclamation

Before doing any of this first check this info from microsoft support at:

URL=kb;en-us;314227

It appears that the task manager is just sort of "minimised". Right click the task bar then click "Task Manager" and one of the tabs ("Users") will open, then you just have to double click the edge of upper border to restore the Task Manager to normal. This solved my problem.

Quote:

Quote:
CAUSE
This behavior may occur if Task Manager is running in Tiny Footprint mode. If you double-click the empty space in the border around the tabs, Task Manager switches to this mode.


RESOLUTION
To switch Task Manager to its typical display mode, double-click the top border of the window.


MORE INFORMATION
When Task Manager is running in Tiny Footprint mode, you can resize the window.

Reply With Quote
Reply

Viewing: ASP Free ForumsSystem AdministrationWindows Security > Task Manager Problems - winupdates.exe


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump



 Free IT White Papers!
 
How to Present Effectively Online
This white paper offers practical and actionable advice on the key steps that any presenter should consider as they plan and execute a Webinar or online meeting.

 
Open Source Security Myths
Open Source Software (OSS) is computer software whose source code is available to the general public with relaxed or non-existent intellectual property restrictions (or arrangement such as the public domain), and is usually developed with the input of many contributors.

 
Power and Cooling Capacity Management for Data Centers
This paper describes the principles for achieving power and cooling capacity management.

 
Scalable, Fault-Tolerant NAS for Oracle - The Next Generation
For several years NAS has been evolving as a storage alternative for Oracle databases, and for good reason: NAS is quite often the simplest, most cost-effective storage approach for Oracle. Learn about the benefits that HP's approach to scalable NAS brings to Oracle environments in this comprehensive white paper.

 
Understanding Web Application Security Challenges
This white paper discusses many common threats and preventive measures for Web application security, and explains what you can do to help protect your organization.

 

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2009 by Developer Shed. All rights reserved. DS Cluster 4 hosted by Hostway
Stay green...Green IT