The new forums will be named Coin Return (based on the most recent vote)! You can check on the status and timeline of the transition to the new forums here.
The Guiding Principles and New Rules document is now in effect.

winlogon.exe: Virus or not?

KING LITERATEKING LITERATE Registered User regular
edited February 2011 in Help / Advice Forum
Googling it only adds to the confusion. Some sites say it's a virus, others not
pic.jpg

What do you guys think?

Diamond FC: 3867 1354 8291
TWITTER TWATS
KING LITERATE on

Posts

  • L Ron HowardL Ron Howard The duck MinnesotaRegistered User regular
    edited February 2011
    Not a virus.

    L Ron Howard on
  • BoomShakeBoomShake The Engineer Columbia, MDRegistered User regular
    edited February 2011
    First Google result
    The process "winlogon.exe" runs in the background. Winlogon is a part of the Windows Login subsystem, and is necessary for user authorization and Windows activation checks.

    Note: The winlogon.exe file is located in the folder C:\Windows\System32. In other cases, winlogon.exe is a virus, spyware, trojan or worm!

    BoomShake on
  • L Ron HowardL Ron Howard The duck MinnesotaRegistered User regular
    edited February 2011
    The virus one has a much larger footprint.

    L Ron Howard on
  • HevachHevach Registered User regular
    edited February 2011
    The virus one has a much larger footprint.

    Also, based on the one time I encountered it, you'll have two winlogin.exe's in the task list, one of which will be owned by the current user.

    Hevach on
  • urahonkyurahonky Cynical Old Man Registered User regular
    edited February 2011
    The reason it rings alarm bells for me is that it doesn't have a description, while mine does.... Can you right click-> open file location and see it there?

    urahonky on
  • ashridahashridah Registered User regular
    edited February 2011
    While this is hardly definitive, that Winlogon.exe process is using about 10 times more memory than the ones on any of my machines. (mine are win7 though, and you don't mention which version of windows you have), and as urahonky mentions, it's missing the process description. The file properties and other parts of it should read "Windows Logon Application". If your version of winlogon.exe doesn't have that set, then it's more likely that something's not quite right.

    I'd be looking to do a scan and cleanup from a clean system, if you can, just to be on the safe side.

    ashridah on
  • Hahnsoo1Hahnsoo1 Make Ready. We Hunt.Registered User, Moderator, Administrator admin
    edited February 2011
    The winlogon.exe process can be a system resource, but it's a common target for various trojans and worms. The one I've experienced (from clicking a link, of all things) was the Vundo worm, but there are many many others. Typically, the virus/trojan one will be in a directory other than the System directory, like in Documents and Settings.

    Hahnsoo1 on
    8i1dt37buh2m.png
  • KING LITERATEKING LITERATE Registered User regular
    edited February 2011
    ashridah wrote: »
    While this is hardly definitive, that Winlogon.exe process is using about 10 times more memory than the ones on any of my machines. (mine are win7 though, and you don't mention which version of windows you have), and as urahonky mentions, it's missing the process description. The file properties and other parts of it should read "Windows Logon Application". If your version of winlogon.exe doesn't have that set, then it's more likely that something's not quite right.

    I'd be looking to do a scan and cleanup from a clean system, if you can, just to be on the safe side.

    I'm using Vista Ultimate, and the reason I didn't have a description for winlogon was because I wasn't logged on as Administrator.

    Anyway, here's what my Task Manager looks like now (take note Office is only there because of a homework assignment I'm currently doing)
    pic34.jpg

    pic35.jpg

    KING LITERATE on
    Diamond FC: 3867 1354 8291
    TWITTER TWATS
  • KING LITERATEKING LITERATE Registered User regular
    edited February 2011
    Okay, now I'm really worried. I don't really think it's supposed to duplicates:
    Untitled-1.jpg

    KING LITERATE on
    Diamond FC: 3867 1354 8291
    TWITTER TWATS
  • UltimanecatUltimanecat Registered User regular
    edited February 2011
    What are you worried about in that picture? It's fine to have multiple instances of svchost.exe running if that is what's concerning you.

    Ultimanecat on
    SteamID : same as my PA forum name
  • Psychotic OnePsychotic One The Lord of No Pants Parts UnknownRegistered User regular
    edited February 2011
    If you are really worried try running Malware Bytes and what ever Anti-virus you have on your computer. If its a fake it should be found and killed by either program.

    Psychotic One on
  • ronyaronya Arrrrrf. the ivory tower's basementRegistered User regular
    edited February 2011
    If you worry about this sort of thing, go download Microsoft's sysinternals process explorer. Set it to show command line and user name.

    This is what it'll look like:
    procexpg.png

    Lots more info to chew on. It can check file digital signatures, too.

    ronya on
    aRkpc.gif
Sign In or Register to comment.