Share via

CampaignManager running at shutdown and preventing normal shutdown.

Anonymous
2019-10-17T02:28:16+00:00

What the heck is going on? I can find nothing useful of this. And I view this as a security and privacy issue. 

Started two days ago, when I went to shut down a PC (Windows Pro 10 build 1903) I was confronted with a warning that "CampaignManager" was still running. I research here and not that I am NOT in a domain. I am not connected to a local workgroup. (I have not introduced and USB stick or foreign device to this PC.) This is the ONLY Windows PC in a network of Linux computers. In each case I killed the process and exited. 

I do find a reference to CampaignManager in the registry (see below in part) which references " \Microsoft\Windows\UNP\RunCampaignManager"

A search for "CampaignManager" on the PC reveals nothing

A search for UNP reveals a bunch but now where the regedit would have me look. (see jpg attached.)

Why would something installed in March become active in October and what is this about?

Reg Key:

Key Name:          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{0AAC2C9B-C9C4-4F9F-BC88-FE2F0F0F553B}

Class Name:        <NO CLASS>

Last Write Time:   5/28/2019 - 11:55 AM

Value 0

  Name:            Path

  Type:            REG_SZ

  Data:            \Microsoft\Windows\UNP\RunCampaignManager

Value 1

  Name:            Hash

  Type:            REG_BINARY

  Data:            

00000000   cc dd 4b b5 96 4e a8 dd - 7d ed 78 62 11 9f 7b af  ÌÝKµ.N¨Ý}íxb..{¯

00000010   6c 65 a3 a6 1b 11 02 5f - 3f 74 8f 91 57 3b 5f 16  le£¦..._?t..W;_.

Value 2

  Name:            Schema

  Type:            REG_DWORD

  Data:            0x10002

Value 3

  Name:            SecurityDescriptor

  Type:            REG_SZ

  Data:            D:P(A;;GA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;BA)(A;;FRFX;;;AU)

Value 4

  Name:            URI

  Type:            REG_SZ

  Data:            \Microsoft\Windows\UNP\RunCampaignManager

Value 5

  Name:            Triggers

  Type:            REG_BINARY

  Data:            

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

5 answers

Sort by: Most helpful
  1. Anonymous
    2019-10-17T04:36:41+00:00

    Hi Mike,

    UNP (Universal Notification Platform) is a component of the Windows Update Service, I believe it was first introduced in version 1703, if memory serves me correctly.

    UNP/CampaignManager.exe can also be present if a home/Wi-Fi network is or has ever been used or setup on the PC.

    On my Win 10 Pro version 1903 build 18362.418 Workstation that has never been joined to any network in anyway, home, Wi-Fi, work or otherwise, the UNP/CampaignManager.exe file does not exist. (File Explorer snapshots below):

    The System32 UNP folder:

    The Program Files UNP folder contains Log files only:

    These are .etl (Windows Performance Analyzer) log files.

    Now, being that all of the updates related to versions 1703 thru 1903 have installed successfully on this device (and no network has ever been setup), these log files are empty.

    Now, that being said, the CampaignManager.exe file name has been known to be used by some malicious  (spyware, adware, trackers etc.) software to disguise themselves as a legit Windows OS entity. In such a case as being possible I would recommend running a MBAM Free scan as it specifically targets the above and PUP's as well, (note that any Potentially Unwanted Program results that are flagged may be something that you may want to keep, in such a case check the scan log for the file locations to research). 

    Hope this can help and Good Luck!

    -Richard

    Standard Disclaimer: Any non-Microsoft websites provided here appear to be providing accurate, safe information. Watch out for any ads on these sites that may advertise products frequently classified as PUP's (Potentially Unwanted Programs). Thoroughly research any product/program advertised on any site before you decide to download and install it.

    3 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2019-10-17T06:00:48+00:00

    Ok,

    Perform a "Restart" instead of (or before) a shutdown and startup as they are two different (slightly but importantly) things.

    (Even if Fast Start is disabled I would still recommend the same).

    I'm going offline now, will be back in at some point in the morrow.

    -Richard

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2019-10-17T05:47:13+00:00

    MalwareBytes didn't like some 'search' values for Chrome and Yahoo.

    It noticed three files connected to my CCTV equipment; Been there for years. I need them to access the CCTV server with Internet Explorer (until I junk the CCTV box for a newer one). I can't access the CCTV server with anything else. The three always scan as if there are bad.

    Other than that, it found nothing. 

    I did quarantine all but those three files and now the tab bar in Chrome is funky, but I won't know much more until I try to shut down later.

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2019-10-17T05:29:25+00:00

    Hi Mike,

    Yes I did mistype, thanks for pointing that out.

    To be sure I ran/reran a C: drive search for "CampaignManager" on the workstation and the result was:

    Your thread.

    Let us know how the MBAM scan goes and Good Luck!

    -Richard

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2019-10-17T04:56:30+00:00

    Hi Richard,

    The PC in question does not have WiFi.

    A scan for CampainManager.exe produced nothing.

    In case you mis-typed  I ran a scan for CampaignManager.exe and found nothing

    I ran the following:

    SFC /SCANNOW

    DISM /Online /Cleanup-Image /AnalyzeComponentStore

    DISM /Online /Cleanup-Image /StartComponentCleanup

    DISM /Online /Cleanup-Image /CheckHealth

    DISM /Online /Cleanup-Image /ScanHealth

    DISM /Online /Cleanup-Image /RestoreHealth 

    And  since there were problems with some corrupted files I ran these again.

    SFC /SCANNOW

    DISM /Online /Cleanup-Image /AnalyzeComponentStore

    -- and got: Component Store Cleanup Recommended : No

    followed by:

    PS C:\WINDOWS\system32> DISM /Online /Cleanup-Image /CheckHealth                                                        

    Deployment Image Servicing and Management tool

    Version: 10.0.18362.1

    Image Version: 10.0.18362.418

    No component store corruption detected.

    The operation completed successfully.

    I will download the Malwarebytes and see what it finds. 

    Thanks.

    1 person found this answer helpful.
    0 comments No comments