Answers to your tech questions
Computer forums for help with removing malicious software (malware) and improving computer security

Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)

 
Reply to this topicStart new topic
> hello - winlogon.exe question, winlogon.exe registry changes
dofrdo
post Aug 29 2008, 10:34 AM
Post #1


New Member
*

Group: New Member
Posts: 4
Joined: 28-August 08
Member No.: 81,257
Operating System: XP



Hello everyone

I would characterize my computer knowledge at the intermediate level at best. So I often find my self at a loss when trying to understand some of the more complex ins and outs of computer functions.......Currently I am struggling to understand "winlogon.exe". I recently purchased "ad-aware pro" which includes a real-time feature that monitors all attempts to make registry changes. One name that has come up hundreds of times is "winlogon.exe". I probably would not have given it a second thought but I recently cleaned up my registry with a registry cleaner. What a difference in performance!!......my machine runs as smooth as silk since house cleaning my registry. Consequently, I am suspicious and guarded about any attempts to alter my registry for fear that I will loose the performance I gained. I have thus far blocked all attempts by "winlogon.exe" to make changes to my registry (over 200 blocks thus far)..further, I have noticed no ill affects by doing so. So the questions arise.........how important to the functioning of my computer are these changes that "winlogon.exe so desperately wants to make??.........if I allow them, will this slow down my computer either immediately or over time??............. if I disallow them is there any real consequence??...................I don't use "internet explorer" I use "firefox" exclusively.

any help with this would be much appreciated
thanks
Go to the top of the page
 
+Quote Post
tallin
post Aug 29 2008, 12:25 PM
Post #2


SuperMember
Group Icon

Group: Tech Classroom
Posts: 1,773
Joined: 21-March 06
From: Australia
Member No.: 52,151
Operating System: Windows XP/SP3




welcome.gif dofrdo,

QUOTE
The process "winlogon.exe" runs in the background. It's a part of the Windows Login subsystem. Winlogon is necessary for user authorization and checks the Windows XP activation code. Note: The winlogon.exe file is located in the folder C:\Windows\System32. In other cases, winlogon.exe is a virus, spyware, trojan or worm! Check this with Security Task Manager. Virus with same name:
W32.Netsky.D - see McAfee Symantec Corporation Trend Micro

Information from here

A very good program for you to dowload which attaches itself to your taskmanager is Process Library or Quick Access.

Hope this helps, keep us posted and again welcome to the forum.

kind regards,


Go to the top of the page
 
+Quote Post
Tallon41
post Aug 29 2008, 06:33 PM
Post #3


Authentic Member
**

Group: Authentic Member
Posts: 232
Joined: 28-August 08
From: So. Calif.
Member No.: 81,253
Operating System: 98SE, ME, 2000, XP, XP-64, VISTA, Server 2000, 2003, SBS 2003.




Though correct, that is not a good answer for the OPs question.

Yes winlogon controls users logging-in.

in this question there is 'something' wishing to alter winlogon. This purpose would not have anything to do with user logins.

Winlogon also monitors a great many system events that occur.

"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"

to name a few.

Anti-virus programs, place entries here, Anti-spyware programs, (like Ad-aware does now,)
As well as their Nasty counter-parts.
They appear as folders within the "notify" folder of the "winlogon" folder.

It is located in the registry at [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

With a presence here, Nasties can PREVENT a great many of the normal attempts at their removal, and can resurect from the dead.


normal entries in winlogon include:

crypt32chain
cryptnet
cscdll
NavLogon
ScCertProp
Schedule
sclgntfy
SensLogn
termsrv
WgaLogon

This list is not all there are by any means, but most users will have most of these entries.
google anything not on this list, and you will quickly see if it is a legit process or not.

Tallon41

Go to the top of the page
 
+Quote Post
dofrdo
post Aug 30 2008, 12:04 AM
Post #4


New Member
*

Group: New Member
Posts: 4
Joined: 28-August 08
Member No.: 81,257
Operating System: XP



Thank-you both for your input.................I would like to continue this discuss but should I be posting this in another forum??
Go to the top of the page
 
+Quote Post
tallin
post Aug 30 2008, 12:12 AM
Post #5


SuperMember
Group Icon

Group: Tech Classroom
Posts: 1,773
Joined: 21-March 06
From: Australia
Member No.: 52,151
Operating System: Windows XP/SP3




Hello drfrdo,

Thank you for asking.

Yes, it would be wise to start a new thread in the appropriate forum. Here is a link we often post to newcomers. I hope we can continue to help you when your new thread is posted.

Thanks again.

kind regards,
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

Collapse

> Similar Topics

    Topic Title Replies Topic Starter Views Last Action
No New Posts   7 MMctagg 50 Yesterday, 06:55 AM
Last post by: MMctagg
No New Posts   1 dark_armed 22 26th November 2008 - 03:07 AM
Last post by: Crow
No New Posts   9 sonykicks 50 23rd November 2008 - 07:53 PM
Last post by: sonykicks
No New Posts   5 dark_armed 50 20th November 2008 - 10:03 AM
Last post by: Tallon41

RSS Time is now: 1st December 2008 - 01:07 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy