Re: XP Pro logons changed after recent Windows Update

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



"Steve" wrote

System is XP Pro XP2, all patches are up to day. Running on dynamic IP
DSL with Windows Firewall, Windows Defender and up to date AVG
anti-virus.

There are 2 user accounts, mine (strong password protected and an
admin), and my wife (no password, not admin level), along with the
admin account (strong password protected).

My wife logged on this morning as normal, checked e-mail and went to
get ready for work. When she came back to the PC, it was back at the
user login screen and started to ask her for a password. Nothing she
tried worked. I came down and tried to log into my account - and my
password no longer worked. Obviously checked caps lock and such -
nothing - couldn't log in.

When to shut it down and was prompted with an alert that another user
was logged in. The alert box didn't "look" quite right - not sure if
that was my imagination or not though - it seemed the font or something
about the type wasn't quite right.

Rebooted in safe mode and was able to log in as administrator fine and
changed my account password to a new one. Rebooted and I could get
into my account fine. I also noticed I had the "green shield" icon
stating that updates were recently done and an automatic reboot was
necessary (perhaps this is why my wife's desktop was back to a login
screen?)

In examining my tasklist, the only process running that didn't seem
familiar was uphclean.exe. When I google it, I see it's "User Profile
Hive Cleanup Service". When I searched for the physical file, I found
it in c:\Program Files\uphclean\ and the only other file in that
folder was a readme.txt. To the best of my recollection, I can't
recall ever seeing this in the tasklist before, and I know it's the
first time I've googled it.

When I had to leave for work, I went to shut down and was again given
the dialog box that said other users were logged onto the system.

Part of me thinks (hopes) this was an automatic reboot that didn't
check to see if uphclean.exe was running, and it somehow slightly
corrupted the user hive. Another part of me fears that uphclean.exe is
some sort of trojan and all hell is breaking loose in my machine.

Anyone see this happen before? What can I do to further investigate
and / or mitigate any damage short of a paranoid reformat?


What caused the problems in your system I don't know but Uphclean is a legitimate Windows file,. Though that doesn't mean the one on your system hasn't been altered, it doesn't seem likely. Uphclean helps to unload the registry when windows is shut down. It doesn't do anything else. It is not installed by windows update. Someone must have installed it.

UPHClean v1.6d readme.txt
http://download.microsoft.com/download/a/8/7/a87b3d05-cd04-4743-a23b-b16645e075ac/readme.txt

Troubleshooting profile unload issues
http://support.microsoft.com/?id=837115

.



Relevant Pages

  • Re: Need help closing security holes in my Windows XP home system!
    ... >>stop using the win xp user account with admin, ... >>windows as the admin, ... then you really don't understand security for the ...
    (comp.security.firewalls)
  • RE: [in] Re: [Full-Disclosure] IE is just as safe as FireFox
    ... The first account created on Windows is Administrator, ... and even it had poor initial security when it was really tested. ... doesn't require admin either). ...
    (Full-Disclosure)
  • Re: The sense of firewall (RISC OS 6.20)?
    ... default user account to "administrator". ... to the admin only). ... Windows and its endless security flaws ... logic of allowing remote untrusted code to be run by default, ...
    (comp.sys.acorn.networking)
  • Re: Validation of XP
    ... except to mention that UAC caused me to reboot to WinXP ... there shouldn't be any reason you need to run as admin to play a game. ... Windows doesn't do this or that natively, and one of those things is ... As for the default admin account, ...
    (microsoft.public.windowsxp.general)
  • Re: [Full-disclosure] Re: Google Talk cleartext credentials in processmemory
    ... Home users, perhaps, but there are a lot more WIndows ... Even in corp environments you still see some users running admin ... This account has admin privileges by default. ... right-click on the file and click on "run as" to install your software ...
    (Full-Disclosure)