Winlogon.exe (Microsoft Windows Logon Process vs Trojan / Virus)

Winlogon.exe is an integrated process Microsoft in Windows OS and is required for authentication (login / logout) system users or check activation it (the system). Moreover, Winlogon is responsible and protection system by the exact delimitation of the permissions of the registered users (for example, the user administrator are full control and ordinary users typically only have access read-only).

Because it is an essential process for Windows, winlogon.exe is the target of many malware that either attaches to it in case of a possible infection or them "borrow" to induce users name in error. Location legitimize this process the system will always C: \Windows\System32. If you find this process to another location on hddOr notice that began to consume more resources abnormally, you should perform a thorough scan of the system because, most likely, it is a virus (worm), trojan or adware.

One of the most famous trojans affecting winlogon.exe process is Vundo (or Virtumondoor MS Juan) Trojan "available" in many ways, so that they cause infections ranging from benign infection to very severe (in which case formatting and reinstalling the system is the only solution). Some of the symptoms of Vundo infection are:

  • advertising popups for fake antivirus
  • screensaver Blue Screen of Death
  • off Windows automatically Updates
  • off Task Manager, registry Editor si msconfig
  • booting failure in Safe Mode
  • Repeated errors explorer.exe
  • inaccessibility of sites, the majority of security products
  • smallsorabad space on the hdd
  • overwrite or rename dll-hate
  • modifying the registries so that they are reactivated every time the system is restarted or started

Many other trojans or viruses use names similar to that of winlogon.exe, an example being winIogon.exe (I capitalized instead of it), a process often associated with polymorphic virus Win32.Virut (Unfortunately, it can not be removed only by a complete format and reinstall the system), very common and prevalent in recent years. Therefore we recommend that you do everything yourself updateespecially antivirus programs in a timely manner, thus maintaining a high security of the system.

Passionate about technology, I enjoy writing on StealthSettings.com since 2006. I have a rich experience in operating systems: macOS, Windows, and Linux, as well as in programming languages and blogging platforms (WordPress) and for online stores (WooCommerce, Magento, PrestaShop).

How to » Task Manager » Winlogon.exe (Microsoft Windows Logon Process vs Trojan / Virus)
Leave a Comment