Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Winlogon.exe @ 100%

Status
Not open for further replies.

Alshrim

IS-IT--Management
Jul 12, 2002
407
CA
Hey all -- .
Ok i have a quirky lil problem with my PC.

My winlogon.exe after about 10 minutes maxes to 100% and uses 50MB of Ram - I have installed Spybot and immunized, run ad-aware and deleted all malware on the machine and have spyware blaster on my pc preventing anymore from coming on .. but still - it maxes.

I run McAfee - fully updated - and have no virus' to my knowledge...

Anyone have this?? and has anyone fixed it?!

Alshrim
System Administrator
MCSE, MCP+Internet
 
What user is calling winlogon.exe...in other words is it System or the username when you look under Task Manager. We had a similar problem with a winlogon.exe process that was spyware and was not detected by Spybot, Adaware, etc...
 
Winlogon.exe can be a number of things, you'll need to do some sleuthing on your end and narrow it down. It can Netsky, or various malwares. Most likely the latter as your McAfee is not getting tripped. Look here for some starting info:

"'Tis an ill wind that blows no minds." - Malaclypse the Younger
 
It's the system that's calling the winlogon.exe ...

I have CWShredder - which kills malwares associated with CoolSearch - and it keeps killing CWSBootConf - but even after cleaning it.. if i run it again - it still has to remove it...

Alshrim
System Administrator
MCSE, MCP+Internet
 
Are you shutting down system restore before running CoolWebShredder? If you're not, that's why you're getting the recurrence.

"'Tis an ill wind that blows no minds." - Malaclypse the Younger
 
Where do i shut down system restore??

Alshrim
System Administrator
MCSE, MCP+Internet
 
ok.. I'll try that...

but what i meant was... I'll run the Shredder... and then it will say it removed 2 items...and then - without rebooting.. i'll run it again - and it says it had to remove it AGAIN...

so.. i find that a little curious..

Alshrim
System Administrator
MCSE, MCP+Internet
 
actually.. it was indeed turned off... :(

Getting weirder all the time...



Alshrim
System Administrator
MCSE, MCP+Internet
 
THis isn't the appropriate forum for log posting, but you might want to download Hijack This! ( scan your pc, and then paste the log into a post in forum760

"'Tis an ill wind that blows no minds." - Malaclypse the Younger
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top