1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

new winlogon.exe

Discussion in 'Security and Privacy' started by keywester, 2004/11/03.

Thread Status:
Not open for further replies.
  1. 2004/11/03
    keywester

    keywester Inactive Thread Starter

    Joined:
    2002/12/20
    Messages:
    257
    Likes Received:
    0
    A few days ago I started getting a warning that winlogon.exe had been replaced.

    Since I had never encountered this before and being unable to discern an obvious culprit based on limited activity at that time and suspecting malware as the cause, I updated Adaware, Spybot, A2, Swatit, etc…, and performed scans, with no actual malware found. In retrospect, the only thing that appears as potentially obvious is that about that point in time I applied M$’s Security Updates KB841533, KB873376, KB834707, KB841356, and KB840987 (I am still running XP SP1…). Would I be safe to conclude that the security updates changed winlogon given that no malware was found (yes, the winlogon exe exists in window\system32, but not in \windows…)?
     
  2. 2004/11/03
    charlesvar

    charlesvar Inactive Alumni

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Hello keywester,

    FWIW, my version on an XP Home SP2 system:

    size = 490 KB, version 5.1.2600.2180

    Locations: \System32 and in \ServicePackFiles\i386

    Regards - Charles
     

  3. to hide this advert.

  4. 2004/11/03
    JoeHobart

    JoeHobart Inactive Alumni

    Joined:
    2004/05/19
    Messages:
    919
    Likes Received:
    1
    "I started getting a warning that winlogon.exe had been replaced "

    What does this mean? Who gave you the error? What exactly did it say?
     
  5. 2004/11/03
    keywester

    keywester Inactive Thread Starter

    Joined:
    2002/12/20
    Messages:
    257
    Likes Received:
    0
    It is a warning message from System Safety Monitor - the text of which basically indicates something to the effect that the exe has the same name but is not the same exe... will post back with exact text if necessary but the bottom line is that the exe has been updated or replaced...
     
  6. 2004/11/03
    charlesvar

    charlesvar Inactive Alumni

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    I run SSM as well, and got a slew of new version warnings w/ install of SP2 - don't remember winlogon specifically. Since then have the newest SSM version w/o that original config file, so can't check it that way.

    Went back into SP2's uninstall file - pre SP2 windows, and sure enough that version of winlogon is 5.1.2600.1106 - size is 504 KB.

    So I would say that since SP2 incorporates patches that you're downloading for SP1, that this is legit.

    Regards - Charles
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.