Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

winlogon.exe has encountered a problem and needed to be closed

Posted on 2011-05-04
9
Medium Priority
?
1,416 Views
Last Modified: 2012-05-11
Greetings,

I have a dedicated windows 2003 server in United states.Sometimes i cannot connect through remote desktop.Even the ping gives 100% packet loss.So i call the Date centre to restart my server.Once restarted ,all works.This happens quite often say 2 times a week.

As soon as the server restarts i get a stop message before the login screen

"stop error 0x00000050(0xffffffe8,0x00000001,0x8086c93d,0x00000000)"

Then i Login and it says "winlogon.exe has encountered a problem and needed to be closed".

In the event viewer i get as follows

"Reporting queued error: faulting application winlogon.exe, version 0.0.0.0, faulting module msvcrt.dll, version 7.0.3790.3959, fault address 0x00038efa".

Please give me a solution

Regards
0
Comment
Question by:Sam2009
  • 4
  • 4
9 Comments
 
LVL 5

Accepted Solution

by:
BatchV earned 2000 total points
ID: 35694292
This could be due to Virus, corruption of registry or application.
Make sure your anti-virus is up to date and the server is fully patched up with latest updates
0
 
LVL 17

Expert Comment

by:Chris Millard
ID: 35694456
I would pass this problem onto the support department of the company you are leasing the server from.

In the meantime, check the eventvwr for any signs of bad blocks on the disk. Also, run a full checkdisk and perhaps a system file check (sfc /scannow)
0
 

Author Comment

by:Sam2009
ID: 35696039
@Batch:

I have downloaded Malwarebytes Antimalware and scanned it.

Memory Processes Infected: 1
Memory Modules Infected: 1
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
c:\WINDOWS\Cluster\svchost.exe (Backdoor.Bot) -> 1916 -> No action taken.

Memory Modules Infected:
c:\WINDOWS\system32\KvumseD.dll (Backdoor.PcClient) -> No action taken.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\svchost (Backdoor.Bot) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyDocs (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\system32\KvumseD.dll (Backdoor.PcClient) -> No action taken.
c:\WINDOWS\Cluster\svchost.exe (Backdoor.Bot) -> No action taken.


I have removed all of them and restarted the server.Now i will wait and see if the issue happens again.

Regards
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:Sam2009
ID: 35696060
@ Batch  I am also doing the microsoft update now
@  Roy I will do (sfc /scannow) and update you
0
 
LVL 5

Expert Comment

by:BatchV
ID: 35696793
Virus is the cause of you problem, I recommend that you reboot the server and scan the complete server again to make sure it's clean.
0
 

Author Comment

by:Sam2009
ID: 35712949
Greetings,

@ Batch:I guess you are right.I did a full scan and removed all viruses i believe so .Now its second day with no issue .So let me wait for 3-4 days and update the ticket confirming issues has been resolved.ok

regards
0
 
LVL 5

Expert Comment

by:BatchV
ID: 35715018
Keep an eye on the events viewer as well and post any errors
0
 

Author Comment

by:Sam2009
ID: 35736151
@batch It went fine for last 5 days.Waiting 2 more days to close ticket
0
 
LVL 5

Expert Comment

by:BatchV
ID: 35736157
Glad it is all working fine
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, I had the need to build a standalone system to run a point-of-sale system. I’m running this on a low-voltage Atom processor, so I wanted a light-weight operating system, but still needed Windows. I chose to use Microsoft Windows Server 200…
Learn about cloud computing and its benefits for small business owners.
This Micro Tutorial will teach you how to add a cinematic look to any film or video out there. There are very few simple steps that you will follow to do so. This will be demonstrated using Adobe Premiere Pro CS6.
this video summaries big data hadoop online training demo (http://onlineitguru.com/big-data-hadoop-online-training-placement.html) , and covers basics in big data hadoop .

564 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question