Is the Winlogon.exe process a virus? Win7 system Winlogon.exe introduction

  
                

Do you know what process Winlogon.exe is under Win7? Recently, a friend checked the task manager and found that the Winlogon.exe process is running. He didn't know what the process was. After the query, it was found that Winlogon.exe is probably a virus. Is the Winlogon.exe process a virus? ? Let's take a look at it with Xiaobian.

Winlogon.exe is what process:

1, Winlogon.exe program is user login, user management is the process of logging in and out. And winlogon is activated when the user presses CTRL+ALT+DEL, and the security dialog is displayed. This process handles login and logout tasks. In fact, this process is required, its size is related to the time you log in;

2, wowexec.exe when you run some old applications (such as some 16-bit program) Or run the DOS command line program under the DOS console, you will find it in the process. Winlogon.exe is used to handle the login and login process of your system;

3. The role of this process in your system is very important. The normal path for this process should be C:\\Windows\\System32 and run as a SYSTEM user. If it is not the above path and it is not running in the SYSTEM user, it will be infected when you open the attachment sent by the virus;

4. More importantly, winlogon.exe will also steal the user's game account and online banking. Information, etc., let users constantly pop up spam advertisements while using the computer, and even pop up some user wins and other information.

It is recommended that you check whether your computer is poisoned from the following points:

1. Check the name and path of Winlogon.exe as other system processes. The name of Winlogon.exe is also indistinguishable. Capitalized, if you find it in the task manager, Winlogon.exe is sometimes uppercase and sometimes lowercase, which is normal! But you have to check carefully, in the name of the "O", is it the letter O, or the number 0? If it is the number 0, Winlog0n.exe is definitely a virus!

2. Next, check the path where Winlogon.exe is located. The normal Winlogon.exe should be located in the C:\\Windows\\System32 directory and run as the SYSTEM user. If you find it in the Task Manager as a non-SYSTEM user, or if its path is %Windows%, then this Winlogon.exe is definitely infected with the virus!

3, Winlogon.exe does not automatically require a connection to the network. Winlogon.exe is a local process, so it is definitely not automatically required to connect to the network! If you start TCPView2.4 and find that there is Winlogon.exe process in the process list to open a port to listen and request to connect to the network, then this Winlogon.exe must be hijacked by the Trojan horse, it should be cleared as soon as possible.

It is also recommended that you run the software Auto runs, then select Winlogon.exe and check which files it starts. Under normal circumstances, Winlogon.exe should start an executable file logonui.exe and 6 dll files, the specific name is as follows, if not these files, it is very suspicious!

Through the above introduction, it is not difficult to see that the Winlogon.exe process is not a virus, but it is easy to be held hostage by viruses. The method of determining whether Winlogon.exe is infected with a virus has been introduced above. Let's learn.

Copyright © Windows knowledge All Rights Reserved