Solved

winlogon.exe+0x39156 thread uses 50% CPU

Posted on 2007-11-25
4
885 Views
Last Modified: 2010-04-21
Hi,

I've found out that the winlogon thread [winlogon.exe+0x39156] uses 50% [or little less 49.90...].

The workstation seems to be clean from spyware, worms or viruses. The winlogon.exe is the right one [from XP SP2].

If I kill the thread, it reappears after a second. The only "strange" [except the 50% cpu usage !]  thing about this thread is the amount of context switching [about 300 per seconds].

Does someone have any idea to solve it ?

Thanks
0
Comment
Question by:asap-tfolliot
  • 2
4 Comments
 
LVL 22

Expert Comment

by:orangutang
ID: 20346669
0
 
LVL 32

Accepted Solution

by:
r-k earned 250 total points
ID: 20346839
Could be a corrupted user profile. Try logging in as another username and see if that makes a difference (create a test user if no other username exists).

Below is my checklist for this sort of problem:

This could be due to number of reasons. Among them:

(1) Hardware malfunction
(2) Malware or rootkit
(3) Corrupted user profile
(4) Misbehaving AV or other service or driver.

I would suggest the following:
(a) log-in as a different user - does the problem persist, if so then rule out  option (3) above.
(b) Disable any AV program or anything else unnecessary and see if that helps.
(c) Run Process Explorer from http://www.microsoft.com/technet/sysinternals/ProcessesAndThreads/ProcessExplorer.mspx
    It shows a lot more detail then Task Manager. In particular, if it shows CPU
    time being used by "Interrupts" then there might be a hardware problem.
(d) Scan your system for malware. At the very least, run the following two programs:
 (d.1) RootkitRevealer from: http://www.microsoft.com/technet/sysinternals/Security/RootkitRevealer.mspx
 (d.2) Download and run HijackThis from http://www.hijackthis.de/
       Copy-and-paste the resulting log back to that same web site (not here)
       Click on "Analyze", and then click on "Save Analysis" at the bottom of the next page.
       Review for anything unusual.
0
 

Author Closing Comment

by:asap-tfolliot
ID: 31410870
Hi,

The user profile was corrupted. 1st time I encounter this behavior with a corruped profile.

Thanks for your help !
0
 
LVL 22

Expert Comment

by:orangutang
ID: 20347323
What worked?
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

We have adopted the strategy to use Computers in Student Labs as the bulletin boards. The same target can be achieved by using a Login Notice feature in Group policy but it’s not as attractive as graphical wallpapers with message which grabs the att…
Step by step guide to Clean and Sort your windows registry! Introduction: Always remember: A Clean registry = Better performance = Save your invaluable time In this article we're going to clear our registry manually! Yes, manually! The e…
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now