What is the process of Winlogon.exe? Win7 system Winlogon.exe introduction

  

In the process of using Win7 computer, if you use the comparison card, most users will open the task manager to see if there are hidden processes running. Now that a user opens the task manager and finds a process named Winlogon.exe, and does not know what process Winlogon.exe is, then this article will give you a detailed introduction to the Winlogon.exe process.

What is the process of Winlogon.exe:

1. Winlogon.exe is the user login program. This process is for managing user login and logout. And winlogon is activated when the user presses CTRL+ALT+DEL, and the security dialog is displayed. This process handles login and logout tasks. In fact, this process is required, its size is related to the time you log in;

2, wowexec.exe when you run some old applications (such as some 16-bit program) Or run the DOS command line program under the DOS console, you will find it in the process. Winlogon.exe is used to handle the login and login process of your system;

3. The role of this process in your system is very important. The normal path for this process should be C:\\Windows\\System32 and run as a SYSTEM user. If it is not the above path and it is not running in the SYSTEM user, it will be infected when you open the attachment sent by the virus;

4. More importantly, winlogon.exe will also steal the user's game account and online banking. Information, etc., let users constantly pop up spam advertisements while using the computer, and even pop up some user wins and other information.

It is recommended that you check whether your computer is poisoned from the following points:

1. Check the name and path of Winlogon.exe as other system processes. The name of Winlogon.exe is also indistinguishable. Capitalized, if you find it in the task manager, Winlogon.exe is sometimes uppercase and sometimes lowercase, which is normal! But you have to check carefully, in the name of the "O", is it the letter O, or the number 0? If it is the number 0, Winlog0n.exe is definitely a virus!

2. Next, check the path where Winlogon.exe is located. The normal Winlogon.exe should be located in the C:\\Windows\\System32 directory and run as the SYSTEM user. If you find it in the Task Manager as a non-SYSTEM user, or if its path is %Windows%, then this Winlogon.exe is definitely infected with the virus!

3, Winlogon.exe does not automatically require a connection to the network. Winlogon.exe is a local process, so it is definitely not automatically required to connect to the network! If you start TCPView2.4 and find that there is Winlogon.exe process in the process list to open a port to listen and request to connect to the network, then this Winlogon.exe must be hijacked by the Trojan horse, it should be cleared as soon as possible.

It is also recommended that you run the software Auto runs, then select Winlogon.exe and check which files it starts. Under normal circumstances, Winlogon.exe should start an executable file logonui.exe and 6 dll files, the specific name is as follows, if not these files, it is very suspicious!

Now I believe that everyone has a certain understanding of the Winlogon.exe process. After reading the above introduction, Winlogon.exe is an important system file, and it is easy to be infected with viruses, so users are browsing the web. Be sure to pay more attention to prevention.

Copyright © Windows knowledge All Rights Reserved