maniac Posted May 18, 2007 Posted May 18, 2007 Hello all. I'm getting a spate of an single error occuring with the winlogon.exe file, as pictured below. It's started this morning on a couple of machines, and seems to be spreading, which is worrying me as I can't find out what's causing it! I'm immediatly thinking virus, but sophos is reporting nothing and is completely up-to-date. I've seen 12 machines now with the error, and I expect I'm going to find more as the afternoon progresses. Can anyone help, Google hasn't been much help so far!! Cheers, Mike. P.S I should add that clicking either button causes the machine to shut down and reboot, then the error occurs again. We've solved it by re-imaging all the machines affected so far, but I'm still puzzled as to what's causing it!
Geoff Posted May 18, 2007 Posted May 18, 2007 Do you use any software that replaces the MSGINA with its own (Citrix or Netware for example?)
maniac Posted May 18, 2007 Author Posted May 18, 2007 Nope, completely generic network from that point of view. We do run ranger as you can see, but that doesn't modify that part of windows as far as I know??
bishopsgarthstockton Posted May 18, 2007 Posted May 18, 2007 daft question, have you checked the services.
Guest Posted May 18, 2007 Posted May 18, 2007 Are you running WSUS? Could ba an update that the machines are recieving?
maniac Posted May 18, 2007 Author Posted May 18, 2007 I can't get onto any affected machines to check services or logs etc. Yes we are running WSUS, and that's a good point because machines are set to update on a thursday, meaning most updates are applied at the next reboot, which would have been this morning. Cheers, Mike.
maniac Posted May 18, 2007 Author Posted May 18, 2007 Just checked our WSUS, and the latest updates in that are dated 08/05/2007 which means they would have been installed last week. There's been no updates downloaded this week, so it's very unlikely to be this causing the problem. Mike.
bishopsgarthstockton Posted May 18, 2007 Posted May 18, 2007 http://www.auditmypc.com/process/msgina.asp take a look at this
bishopsgarthstockton Posted May 18, 2007 Posted May 18, 2007 can you get in the affected system through safemode and replace the effected files?
maniac Posted May 18, 2007 Author Posted May 18, 2007 it does the same in safemode! I can get onto the machines hdd by using \\machinename\c$\ and look at the files, but I can't do anything with the winlogon.exe file, as it's in use of course! So far I've not had any more reports, so maybe it's just one of those things. I've had it suggested that some of the kids may be causing it, as there's been a spate of kids attempting to 'hack' the system recently. Again the problem is I've no idea how they might be doing it, or even what they might be doing to the system to cause this error! I guess I'm just going to have to keep monitoring the situation. Mike.
Finch7 Posted May 18, 2007 Posted May 18, 2007 do you have anything running that might be attempting to remove a virus/spyware. Just read this, you may want to too... http://www.lavasoftsupport.com/index.php?showtopic=3013
bishopsgarthstockton Posted May 18, 2007 Posted May 18, 2007 Do you have any key loging software that can flash on yopur screen certain words a user has typed in to google i.e. hack. then you could monitor them. also do they have access to removable storage? do a search for .bat files etc in all user directories. Im sure there is software that you can boot from with ntfs rather than fat32 so you could then restore the .exe and any other related files that are causing the problem. otherwise suppose you would have to send a image to it
robert.mabbutt Posted May 18, 2007 Posted May 18, 2007 What about plugging the hard disk into another machine to restore the damaged file? Robert
ZeroHour Posted May 18, 2007 Posted May 18, 2007 Just FYI people, I believe Ranger etc link into MSGINA as its the only way I believe you can control CTRL+ALT+DEL. I would remote Ranger of the client and see if it goes away then. What AV you got as well?
maniac Posted May 18, 2007 Author Posted May 18, 2007 No key logging software. I can see the last person who logged onto each machine, but there's no pattern of users on affected machines. Yes students do have access to removable storage like USB keys, this was deamed necessary. I've been unsucessfull is stopping them running EXE files from these as well, so at the moment the kids can run anything they like if it's on their flash drive. We do have protection on our server that stops them storing .EXE, .BAT, .COM and other executable files in their home areas, the minute it sees a disallowed extension it deletes the file. It's easier to re-image the machines using RIS than taking them to bits to replace. I just looked at the winlogon.exe file on an affected machine, and the file size and date etc. seem to be correct when compared to a machine that's working properly. I've only had one more report of this error, so hopefully that'll be the last I see of it. Still interested to try and find what caused it in the first place. Mike.
bishopsgarthstockton Posted May 18, 2007 Posted May 18, 2007 yeh, if you do find out would you let us know. Intresting
bishopsgarthstockton Posted May 18, 2007 Posted May 18, 2007 Mike, You can prevent installation of software from removable devices from: User configuration Administrative templates Windows Components Windows installer prevent removable media source for any install Kev
_Bat_ Posted October 1, 2009 Posted October 1, 2009 Having exactly the same issue here. Did you ever find a resolution? We would be extremely grateful. This seems to have happened since we installed SP3, but not necessarily the cause.
bossman Posted October 1, 2009 Posted October 1, 2009 I have had a couple of instances where this has happened it seems that one of the applications has either had a problem installing and therefore cannot be read from memory on start up thus causing this issue if you find the offending app then re-install this should go away or re-image whichever the quickest. 1
mthomas08 Posted October 20, 2009 Posted October 20, 2009 Am I doing something wrong? If i set it as say 4pm, If I log on any time after that ( even 30 mins ) it will give the warning and then shut down. But if I leave it at logon screen it just sits there. Ive looked through the threads, Im not getting any errors but it just sits there looking pretty.
millerd1978 Posted October 21, 2009 Posted October 21, 2009 I'm had the exact same issue for some time now , it happens intermittently and to random machines just after you get to the login screen. Only happens when on network & if you leave network cable out until login screen then it logs in ok. I've tried everything i can think of , reimaged , updated drivers for NIC , installed second NIC , removed / readded from domain , re-registered dns..checked event logs on server , everything else you can think of... It even happened to a VM and also to a brand new reimaged PC as soon as it was plugged into network.. Anyone have any thoughts ?
mthomas08 Posted October 21, 2009 Posted October 21, 2009 weirdly enough its working, i made sure group policy settings were going to the PC by right clicking the pc and getting the details. Changed the count down to 20 seconds and made sure the clock was synching with the server. also made sure the software deployed to it alright through GPO. So yeah all working now, even get a beep when the PC has got the shutdown signal. So lucky here its working a treat. Fantastic bit of software.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now