Unsolved

This post is more than 5 years old

5204

July 1st, 2004 22:00

windatemanager.exe running in background after each restart.

Hi,

I recently re-formated my computer.  Before doing so, I always kept my OS and AV updated and never had a worm causing me trouble.  The thing is that I reinstalled Windows XP and then Service Pack 1 and as I was downloding the ENORMOUS amount of CRITICAL updates I got 6 worms (Blaster and Korgo included) through out the process.  Finally I think I have removed them all, but once in a while when I restart the computer I get a windatemanager.exe process that takes over all my upload bandwith of my internet conection and blocks any other software that tries to use the internet, and is not until I end the process that I can use my system normally.  I've been using google to figure out which process should be in the task manager and which one shouldn't but I cannot seem to find anything about windatemanager.exe.  Do you have any idea what it is?  All my AV scans come out negative, Ad-aware does not detect any spyware and all the patches and critical updates of Win XP had been installed already.  I have runned searches on my hdd and cannot find that exe file.  Also when searching the registry with regedit I find keys that reference to the windatemanager.exe file with no path and with descriptions like MSN Updater.

Any ideas ?

Thanks in advance

 

Golden_Eye

933 Posts

July 2nd, 2004 11:00

Hi, We need to make you aware that many, many logs are being posted.  Because we are few, all volunteers with families and real jobs, we will have to ask you to be patient.  We work the logs in the order they come in, if you would like us to look at your computer, please follow the instructions below. One of the experts (trained at SpywareInfo & Tom Coyote) will assist with your log as soon as possible. They may ask for a fresh log as rebooting can mutate the newest infections.

 

We need you to download and install an analysis and repair tool called Hijackthis.
 
Download the zipped file from here: http://www.majorgeeks.com/download3155.html.  Please see the following link for information about downloading and other FAQ's.  There is also a link there to an .exe version of HijackThis if there is anyone who absolutely can not open a .zip file.  Please use this for that purpose only due to limited bandwidth, thank you.   http://russelltexas.com/malware/faqhijackthis.htm

 

Please unzip Hijackthis.zip or move the hijackthis.exe file into a new folder you create in the root (first) level of the C: drive. Name this folder HJT for best and safest results. Don't place it on the Wallpaper, in a temp folder, or in the root level of the C: drive or the My Documents folder. It will create many backup files and they need to be stored in a unique Hijackthis folder. If it is properly placed it will look like this:   C:\HJT\HijackThis.exe.

Hijackthis FAQ (Frequently Asked Questions) at:  http://russelltexas.com/malware/faqhijackthis.htm
 
After downloading, and unzipping the hijackthis file into a safe folder you create (preferably a folder named HJT in the first level of the C: drive)...run Hijackthis, click on the 'scan' button and then 'save log' button.
 
Copy and paste the contents of the text file you save into a reply to this message. A lot of posters make mistakes here in copying and pasting so reread the left info sidebar called Copy and Paste at http://www.tomcoyote.com/hjt
 
Special Notice! Hijackthis is a powerful tool that edits the brains of Windows (the Registry). DO NOT FIX anything in the Hijackthis log screen without assistance from the experts! Most of the line items in the scanned log are normal for Windows operation. Hijackthis should identify the vast majority of your problems and enable us to help you clean them off your system.
 

Stay in this thread for continuity. Reply to this message.
 
Thanks,
 
pskelley
In Training at TomCoyote.com and Spywareinfo.com

Please be aware only the following DellForum members were trained at TomCoyote.com and SpywareInfo.com to help with malware like viruses, worms, adware, scumware, foistware and crudware in general. They are also the only experts specifically trained to analyze and advise on Hijackthis logs: Texruss, Baskar1234, Grinler, ChrisRLG, SpotCheckBilly, and pskelley. (If you are one of our classmates and not on this list email me for an addition to this list...we need all the help we can get *;-) 

1 Message

July 7th, 2004 18:00

Sorry to interrupt thisthread. I have the exact same problem as this guy. Here is the HighJackThis report that i got:

Logfile of HijackThis v1.98.0
Scan saved at 15:53:21, on 07-07-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Archivos comunes\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\Archivos comunes\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Archivos de programa\Archivos comunes\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\spoolsvc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\lssas.exe
C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe
C:\Archivos de programa\Messenger\msmsgs.exe
C:\Archivos de programa\Norton AntiVirus\navapsvc.exe
C:\Archivos de programa\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\cmd.exe
C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Archivos de programa\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Archivos de programa\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Archivos de programa\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Archivos de programa\Archivos comunes\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Microsoft Windows Updater] svchostz.exe
O4 - HKLM\..\Run: [Microsoft Message Machine] msmesg32.exe
O4 - HKLM\..\Run: [Microsoft AUT Update] MSlti16.exe
O4 - HKLM\..\Run: [Microsoft System] lssas.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Archivos de programa\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [Microsoft Update Debugger] wincfg32.exe
O4 - HKLM\..\Run: [Msn Updater] windatemanager.exe
O4 - HKLM\..\Run: [Microsofts Updatez] cmsssr.exe
O4 - HKLM\..\Run: [Microsoft Update Clinic] svsipconfig.exe
O4 - HKLM\..\Run: [Microsoft Spooler] spoolsvc.exe
O4 - HKLM\..\Run: [Microsoft Sinsup] odjiwjf.exe
O4 - HKLM\..\RunServices: [Microsoft Windows Updater] svchostz.exe
O4 - HKLM\..\RunServices: [Microsoft Message Machine] msmesg32.exe
O4 - HKLM\..\RunServices: [Microsoft AUT Update] MSlti16.exe
O4 - HKLM\..\RunServices: [Microsoft System] lssas.exe
O4 - HKLM\..\RunServices: [Microsoft Update Debugger] wincfg32.exe
O4 - HKLM\..\RunServices: [Msn Updater] windatemanager.exe
O4 - HKLM\..\RunServices: [Microsofts Updatez] cmsssr.exe
O4 - HKLM\..\RunServices: [Microsoft Update Clinic] svsipconfig.exe
O4 - HKLM\..\RunServices: [Microsoft Spooler] spoolsvc.exe
O4 - HKLM\..\RunServices: [Microsoft Sinsup] odjiwjf.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Microsoft Windows Updater] svchostz.exe
O4 - HKCU\..\Run: [Microsoft Message Machine] msmesg32.exe
O4 - HKCU\..\Run: [Microsoft AUT Update] MSlti16.exe
O4 - HKCU\..\Run: [Microsoft System] lssas.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Microsoft Update Debugger] wincfg32.exe
O4 - HKCU\..\Run: [Msn Updater] windatemanager.exe
O4 - HKCU\..\Run: [Microsoft Spooler] spoolsvc.exe
O4 - HKCU\..\Run: [Microsoft Sinsup] odjiwjf.exe
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\MSMSGS.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{41F5B144-18E2-4E0C-B8D9-484CC9ED98C1}: NameServer = 200.28.4.129 200.28.4.130

933 Posts

July 7th, 2004 20:00

panchato;

I am sorry, we only work on one log in a thread.  Please go here:

http://forums.us.dell.com/supportforums/board?board.id=si_virus

choose "New Message", then post your log in a new thread.  Thanks...pskelley

Message Edited by pskelley on 07-07-2004 05:10 PM

No Events found!

Top