Do I have a trojan?

Discussion in 'Windows XP Help and Support' started by eatup, Jul 29, 2015.

  1. eatup

    eatup

    Joined:
    Aug 4, 2014
    Messages:
    1,184
    Likes Received:
    24
    I've been noticing on both XP partitions, there is a process that always occupies the top two spots in taskmanager processes and that is unsecapp.exe. I checked the web and this process is used for asynchronous call-backs in web clients. I also have MSE installed btw, so maybe this is using unsecapp.exe to asynchronously dl the definition updates?

    Anyways. can anyone else confirm that they always have this process at or near the top of their taskmanager list even with higher priority than iexplore.exe?
     
    eatup, Jul 29, 2015
    #1
  2. eatup

    eatup

    Joined:
    Aug 4, 2014
    Messages:
    1,184
    Likes Received:
    24
    I suspect this is a sabotagie attempt by you know who seeing how it's on both XP partitions. I happened to manually dl the very last MSE definition (supposed) for XP on July 14, 2015. This could be the root cause. They did this with the last MSE version prior to XP EOL last year (it caused your system to halt rendering it useless until you uninstalled the program). I suspect they doped the very last MSE definition as well.

    Will have to reinstall my XPses again this weekend using MSE definitions I dled in June to see if unsecapp.exe never pops up again. I suspect there will no problem if you let the MSE program auto-update itself (yes, my MSE program still gets definition updates well past the cutoff date for XP which was back in July 14 and probably until 2020). The danger comes when you run the .exe definition update package that you manually dled as that could have included other goodies besides just the malware signatures...
     
    Last edited: Jul 29, 2015
    eatup, Jul 29, 2015
    #2
  3. eatup

    Elizabeth23

    Joined:
    Dec 10, 2012
    Messages:
    5,847
    Likes Received:
    756
    Location:
    Florida
    no, various programs and windows WMI are using unsecapp.exe, The only time I saw it was when I had avast installed, just checked my task manager now and it is not running

    I have one of these on my computer located at:

    C:\WINDOWS\system32\wbem.
     
    Elizabeth23, Jul 29, 2015
    #3
  4. eatup

    eatup

    Joined:
    Aug 4, 2014
    Messages:
    1,184
    Likes Received:
    24
    I don't have avast installed and this thing loads up at boot. I'm not suggesting that this unsecapp.exe is the actual virus. It may be the virus is calling this process, which is why it''s on on my system 100% of the time.

    Anyways, whoever created this virus that has to rely on unsecapp.exe, thnx for making it obvious. Otherwise I wouldn't have suspected something is amiss!
     
    eatup, Jul 30, 2015
    #4
  5. eatup

    eatup

    Joined:
    Aug 4, 2014
    Messages:
    1,184
    Likes Received:
    24
    UPDATE: Recently I inherited a spare monitor and thought I'd hook it up to my laptop. I had also purchased a very cheap Logitech USB keyboard + mouse combo to go with the setup.

    I can't rule out the very last MSE definition that I manually updated, but I think this unsecapp.exe only appeared after I started using the Logitech USB devices. I'm reading that ppl are complaining after they updated their Logitech software, unsecapp.exe started appearing in their taskmanager as well. But the previous version of the Logitech software didn't have to rely on this process, which leads me to believe I'm being spied on.

    Anyways, I shall go back to using the laptop's keyboard and touchpad. Having a large external monitor is nice for watching movies, but not much else...
     
    eatup, Jul 30, 2015
    #5
  6. eatup

    Elizabeth23

    Joined:
    Dec 10, 2012
    Messages:
    5,847
    Likes Received:
    756
    Location:
    Florida
    Elizabeth23, Jul 31, 2015
    #6
  7. eatup

    eatup

    Joined:
    Aug 4, 2014
    Messages:
    1,184
    Likes Received:
    24
    I already wiped my HDD clean and reinstalled the two instances of XP. Will use autorun next time some suspicious process pops up...
     
    eatup, Jul 31, 2015
    #7
  8. eatup

    Elizabeth23

    Joined:
    Dec 10, 2012
    Messages:
    5,847
    Likes Received:
    756
    Location:
    Florida
    okay, :)
     
    Elizabeth23, Aug 1, 2015
    #8
  9. eatup

    eatup

    Joined:
    Aug 4, 2014
    Messages:
    1,184
    Likes Received:
    24
    OMFG, unsecapp.exe is back! Unpluged the USB keyboard/mouse to do fresh reinstalls.

    Applied all 280-ish updates to the first XP partition. No sight of unsecapp.exe right before I install MSE. I did the manual definition update first using June 08 .exe file then allowed MSE to auto-update again to Jul 31... (And no, I don't have any other anti-malware programs installed other than MSE).

    And what do you know? Stupid unsecapp.exe like I had never reinstalled the OS!

    In a way I'm relieved it's not the Logitech USB keyboard/mouse spyware drivers, so I can continue to "dock" the laptop to my ext monitor setup.

    Tried to find out what's loading unsecapp.exe on boot with SysInternals Autoruns. Autoruns did not find any entries! Unbelievable!

    How do I auto-kill this process on boot? Could there be something in services.msc that I can disable to make this process go away? (I know it has something to do with talking asynchronously to a remote admin computer, but I've already disabled remote help and server, or so I think)

    There is also the 2nd XP partition which I've yet to install anything. I will use that one to find out/confirm when exactly did unsecapp.exe pop up, and I will not apply the manual MSE June 08 file this time around. I will let the program auto-update itself straight to Aug 01...
     
    Last edited: Aug 1, 2015
    eatup, Aug 1, 2015
    #9
  10. eatup

    Elizabeth23

    Joined:
    Dec 10, 2012
    Messages:
    5,847
    Likes Received:
    756
    Location:
    Florida
    Elizabeth23, Aug 1, 2015
    #10
  11. eatup

    eatup

    Joined:
    Aug 4, 2014
    Messages:
    1,184
    Likes Received:
    24
    Well, I just figured out the cause of my grief... My Intel wireless software!

    I uninstalled the one I got from Intel's www and reinstalled the OEM one. Poof! No more unsecapp.exe!
     
    eatup, Aug 1, 2015
    #11
  12. eatup

    Elizabeth23

    Joined:
    Dec 10, 2012
    Messages:
    5,847
    Likes Received:
    756
    Location:
    Florida
    glad you figured that out, but you can tell from your experience that the unsecapp.exe is not a virus or a trojan in this case, just a file needed for your software.
     
    Elizabeth23, Aug 2, 2015
    #12
Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments (here). After that, you can post your question and our members will help you out.