I mistakenly removed my System32\Winlog.exe file! Please help me...

Z

zenith

Having suspected that my PC was hijacked by keyloggers, I ran a proces
with "Security Task Manager" yesterday. The result of the process wa
that Security Task Manager sort of implied that there was somethin
mysterious about the C:\WINDOWS\System32\Winlog.exe file. I decided t
try to quarantain the file, since Security Task Manager assured me tha
I would be able to restore it should I regret my action. As soon as
quarantained the winlog.exe file, my computer shut down, and now i
shuts down some 15 seconds after log in every time. I ofcourse wen
right back into Security Task Manager and clicked on the restore butto
in the Quarantain, but got an error message saying: "An error ocurre
when copying the file Winlog.exe to \??\C:\Windows\System32". I woul
appreciate your help in solving this problem. Currently I'm able t
work online using the Safe Mode. Prior to this thing happening wit
winlog.exe, I was trying to solve another problem I had and it require
that I disabled my "System Restore". After the problem with my compute
shutting down because I quarantained winlog.exe, I tried enabling syste
restore and to restore my computer back to the latest date prior to m
problem, but I get a message saying that Safe Mode doesn't provid
access to "System Restore".

Browser: IE
OS: WinXP (Professional
 
J

jopa66

I suggest you run Antivirus and Spyware checks in Safe Mode.

winlog.exe is a process belonging to the Salfeld Personal Security tool
which is used to set parental controls to your computer. This program is
non-essential process to the running of the system, but should not be
terminated unless suspected to be causing problems. Note: winlog.exe is also
a process which is registered as the W32.Agobot.LF virus. It takes advantage
of the Windows LSASS vulnerability, which creates a buffer overflow and
instigates your computer to shut down. To see more information about this
vulnerability please look at the following Microsoft bulletin:
http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx This is a
registered security risk and should be removed immediately. Note2:
winlog.exe is also registered as the eventlog logging tool which can be used
in a malicious way to gather information from your computer.
See additional details here:
http://whatsmyip.auditmypc.com/process/winlog.asp
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top