Question about Dell Microsoft Windows XP Home Edition

1 Answer

Windows start up

Dell 8600 desk top. When I start the computer and get to the screen to enter desktop I get message SAS window:winlogon.exe - application error
The instruction at 0x0170e3e8 referenced memory at 0x0170e3e8. The memory could not be "read"

Options click OK to terminate the program
Click on CANCEL to debug the program

Posted by on

1 Answer

  • Level 3:

    An expert who has achieved level 3 by getting 1000 points

    All-Star:

    An expert that got 10 achievements.

    MVP:

    An expert that got 5 achievements.

    Vice President:

    An expert whose answer got voted for 100 times.

  • Master
  • 667 Answers

Hi Booty - this might be the Netsky virus. Follow the link below for a removal tool. Read the instructions. If you need help with this just add a comment. If this solves your oroblem please rate this as fixed. If it doesn't help, DON'T RATE YET, just add a comment and I'll help you further. Thanks.

http://securityresponse1.symantec.com/sarc/sarc.nsf/html/w32.netsky@mm.removal.tool.html

Jeff

Posted on May 11, 2008

1 Suggested Answer

6ya6ya
  • 2 Answers

SOURCE: I have freestanding Series 8 dishwasher. Lately during the filling cycle water hammer is occurring. How can this be resolved

Hi,
a 6ya expert can help you resolve that issue over the phone in a minute or two.
best thing about this new service is that you are never placed on hold and get to talk to real repairmen in the US.
the service is completely free and covers almost anything you can think of (from cars to computers, handyman, and even drones).
click here to download the app (for users in the US for now) and get all the help you need.
goodluck!

Posted on Jan 02, 2017

Add Your Answer

Uploading: 0%

my-video-file.mp4

Complete. Click "Add" to insert your video. Add

×

Loading...
Loading...

Related Questions:

1 Answer

More than 1 csrss.exe


Start a command-line prompt (Windows-Key-plus-R-key).
Enter 'CD \' and press ENTER.
Enter 'DIR /S /A /P CSRSS.EXE*' and press ENTER.
You could have a computer-virus (in some folder "other" than WINDOWS\SYSTEM32) that has the same filename.

Jan 19, 2014 | Microsoft Windows 7 Professional 32 bit...

1 Answer

I have a dell laptop that i bought used and it had windows 8 preview on it well it expired about two weeks ago and now its a pain in the **** cuz it shuts down every two hours. On the bottom of my laotop...


Winlogon is a part of the Windows Login subsystem, and is necessary for user authorization and Windows activation checks. http://www.neuber.com/taskmanager/proces...

Note: The winlogon.exe file is located in the folder C:\Windows\System32. In other cases, winlogon.exe is a virus, spyware, trojan or worm! Check this with Security Task Manager." Microsoft designed Windows so many small applications perform their tasks without a user knowing about it. Normally, this will run smoothly and without flaw, but every once in a while, an issue can come up. Winlogon.exe is an application that runs on start-up, and its primary function is to monitor the use of other applications. Winlogon.exe typically only runs for about a minute or two when Windows first boots up, so if for some reason it is still running five or 10 minutes later, it could be infected. Spyware and other malware would infect this application because it can manipulate other programs in Windows, causing problems. If this is the case, the file might need to be removed.

if you want to remove this from Open "My Computer" and select the "C:" drive. Double click the "Windows" folder, then select "System 32." Navigate through the System 32 folder until you find "Winlogon.exe." Click the "Winlogon.exe" file and hit "Delete." Select "Yes" when asked if you're sure you want to remove the program.

Feb 02, 2013 | Microsoft Windows XP Home Edition

1 Answer

Wat is winlogon that appear in my desktop


The process "winlogon.exe" runs in the background.

Winlogon is a part of the Windows Login subsystem, and is necessary for user authorization and Windows activation checks. http://www.neuber.com/taskmanager/proces...

Note: The winlogon.exe file is located in the folder C:\Windows\System32. In other cases, winlogon.exe is a virus, spyware, trojan or worm! Check this with Security Task Manager."


Microsoft designed Windows so many small applications perform their tasks without a user knowing about it.


Normally, this will run smoothly and without flaw, but every once in a while, an issue can come up.


Winlogon.exe is an application that runs on start-up, and its primary function is to monitor the use of other applications.


Winlogon.exe typically only runs for about a minute or two when Windows first boots up, so if for some reason it is still running five or 10 minutes later, it could be infected.


Spyware and other malware would infect this application because it can manipulate other programs in Windows, causing problems.


If this is the case, the file might need to be removed.



if you want to remove this from


Open "My Computer" and select the "C:" drive.


Double click the "Windows" folder, then select "System 32." Navigate through the System 32 folder until you find "Winlogon.exe."


Click the "Winlogon.exe" file and hit "Delete." Select "Yes" when asked if you're sure you want to remove the program.


hope this helps

Sep 17, 2012 | Microsoft Windows XP Professional for PC

1 Answer

I have a problem of a massege on my desktop software counterfiet.After read a solution on similar problem, there is word asked tobe rename and delete.I tried locate the word GWATRAY EXE.please help.


The Windows Genuine Advantage process (Wgatray.exe) is a Windows XP application that checks the validity of your copy of Windows. You will notice a recurring message that reads, "This copy of Windows is not genuine" if the Wgatray.exe finds your system to be inauthentic. After a while, these messages become a nuisance. You can easily block the process and return to your normal computer activity.
Difficulty: Easy Instructions

    Run Task Manager
  1. 1

    Click the Windows logo in the bottom left corner of the screen. Click "Run" and type "taskmgr" in the dialog box. Click "OK."

  2. 2

    Open the "Processes" tab and highlight "wgatray.exe."

  3. 3

    Click "End Process." Exit the Task Manager.

  4. Remove the Files
  5. 1

    Open the "My Computer" icon on your desktop. Navigate the following folder paths:



    C > Windows > System 32



    C > Windows > System > dllcache

  6. 2

    Right-click and delete the "wgatray.exe" file.

  7. 3

    Open the Recycle Bin and click "Empty the Recycle Bin."

  8. Run Registry Editor
  9. 1

    Click "Start" and open "Run."

  10. 2

    Type "regedit" in the dialog box and click "OK."

  11. 3

    Navigate the follow registry path on the left panel of the window:



    HKEY_LOCAL_MACHINE > SOFTWARE > Microsoft >

    Windows NT > CurrentVersion > Winlogon > Notify

  12. 4

    Delete the folder "Winlogon." Exit the Registry Editor.

Jan 23, 2011 | HP Computers & Internet

1 Answer

Hi, i have a dell vostro 1520 laptop when loading up it has the windows xp screen then it goes to a blue screen with: STOP: c000021a {Fatal System Error} The windows logon process terminated...


This Solution is intended for advanced computer users. If you are not comfortable with advanced troubleshooting, you might want to ask someone for help or contact Technical Support.

When you use a server or a workstation that is running one of the operating systems that is listed in the "Applies to" section, you may receive the following error message: STOP: c000021a {Fatal System Error}
The Windows Logon Process system process terminated unexpectedly with a status of 0xc0000034 (0x00000000 0x0000000)
The system has been shutdown. Note The parameters in parentheses are specific to your computer configuration and may be different for each occurrence. uparrow.gifBack to the top CAUSE The STOP 0xC000021A error occurs when either Winlogon.exe or Csrss.exe fails. Wh... loadTOCNode(1, 'cause'); The STOP 0xC000021A error occurs when either Winlogon.exe or Csrss.exe fails. When the Windows NT kernel detects that either of these processes has stopped, it stops the system and raises the STOP 0xC000021A error. This error may have several causes. Among them are the following:
  • Mismatched system files have been installed.
  • A Service Pack installation has failed.
  • A backup program that is used to restore a hard disk did not correctly restore files that may have been in use.
  • An incompatible third-party program has been installed.

RESOLUTION To troubleshoot this problem, you must determine which of these processes faile... loadTOCNode(1, 'resolution'); To troubleshoot this problem, you must determine which of these processes failed and why.

To determine which process failed, register Dr. Watson as the default system debugger (if it is not already the default debugger). Dr. Watson for Windows NT logs diagnostic information about process failures to a log file (Drwtsn32.log). Also, you can configure this program to produce memory dump files of failed processes that you can analyze in a debugger to determine why a process fails.

To set up Dr. Watson to trap user-mode program errors, follow these steps:
  1. At a command prompt, type System Root\System32\Drwtsn32.exe -I, and then press ENTER.

    This command configures Dr. Watson as the default system debugger.
  2. At a command prompt, type System Root\System32\Drwtsn32.exe, and then select the following options: Append to existing log file
    Create crash dump
    Visual Notification
  3. After the computer restarts from the STOP 0xC000021A error, run Dr. Watson (Drwtsn32.exe).
  4. View the Dr. Watson log to determine what user mode process may be causing the problem.
  5. If the Dr. Watson log does not contain sufficient information to determine the cause of the problem, analyze the User.dmp file to determine the cause of the STOP 0xC000021A error.

    If Dr. Watson did not create a User.dmp file for either Winlogon.exe or Csrss.exe, you may have to use a different tool to generate a memory dump file of the process that fails. For more information, click the following article number to view the article in the Microsoft Knowledge Base: 241215 (http://support.microsoft.com/kb/241215/ ) How to use the Userdump.exe tool to create a dump file Note Follow the instructions in the Knowledge Base article to troubleshoot a process that shuts down with an exception. While you follow these instructions, monitor the following processes to troubleshoot the STOP 0xC000021A error:
    • Winlogon.exe
    • Csrss.exe
    Note Most STOP 0xC000021A errors occur because Winlogon.exe fails. This typically occurs because of a faulty third-party Graphical Identification and Authentication (GINA) DLL. The GINA is a replaceable DLL component that Winlogon.exe loads. The GINA implements the authentication policy of the interactive logon model. The GINA performs all identification and authentication user interactions.
It is very common for certain types of remote control software to replace the default Windows GINA DLL (Msgina.dll). Therefore, a good first step is to examine the system to see if it has a third-party GINA DLL. To do this, locate the following registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Value = GinaDLL REG_SZ
  • If the Gina DLL value is present and if it is anything other than Msgina.dll, it probably means that a third-party product has changed this value.
  • If this value is not present, the system uses Msgina.dll as the default GINA DLL.
If this error first occurred after the installation of a new or updated device driver, system service, or third-party program, the new software should be removed or disabled. Contact the manufacturer of the software to see if an update is available. For more information about hardware and software vendor contact information, visit the following Microsoft Web site: - http://support.microsoft.com/gp/vendors (http://support.microsoft.com/gp/vendors) Last known good configuration loadTOCNode(3, 'resolution'); If the previous steps in this article do not resolve the problem, start the computer by using the last known good configuration. To start the computer by using the last known good configuration, follow these steps:Note Because there are several versions of Microsoft Windows, the following steps may be different on your computer. If they are, see your product documentation to complete these steps.
  1. Click Start, and then click Shut Down.
  2. Click Restart, and then click OK.
  3. Press F8 at the indicated time:
    • For an x86-based computer: When a screen of text appears and then disappears , press F8. (The screen of text may include a memory test, lines about the BIOS, and other lines.) There may also be a prompt that tells you when to press F8.
    • For an Itanium architecture-based computer: After you make your selection from the boot menu, press F8. There may be a prompt that tells you when to press F8.
  4. Use the arrow keys to select Last Known Good Configuration, and then press ENTER.

    NUM LOCK must be off before the arrow keys on the numeric keypad will function.
  5. Use the arrow keys to highlight an operating system, and then press ENTER.
Notes
  • Choosing the Last Known Good Configuration startup option provides a way to recover from problems such as a newly added driver that may be incorrect for your hardware. However, it does not solve problems that are caused by corrupted or missing drivers or files.
  • When you choose the Last Known Good Configuration option, only the information in registry key HKLM\System\CurrentControlSet is restored. Any changes you have made in other registry keys remain.

Jan 18, 2011 | Dell Vostro 1510 Laptop Computer PC...

2 Answers

How do you remove Virtumonde from Windows XP? I have tried malwarebytes and Ad Adware both with no success. I use Avast 5.0 which didn't catch it and Spybot S & D doesn't even spot it as a virus. This...


As far as free tools, you will want to try VundoFix and/or VirtumundoBegone.

VirtuMonde manual removal instructions:
Kill VirtuMonde processes:
kopCFEWV.exe
castlecops[1].exe
unknown.exe
svci.exe
psdrv.exe
rasrun.exe
nwonknu.exe
editpad.exe
quicken.exe
winhost.exe
editpad.exewindowsupd2.exe
quicken.exe
winhost.exe
windowsupd2.exe
Delete VirtuMonde files\folders and unregister dll’s:
opnnljj.dll
cbxxywx.dll
nnnmmlk.dll
vtuspmn.dll
mllkk.dll
sstrs.dll
awtqqnl.dll
kopCFEWV.exe
gf1.0.0.2
castlecops[1].exe
ddcbabx.dll
iifddby.dll
2chkdsk
pmnlk.dll
SbCIe02b.dll
ssttr.dll
geebc.dll
pmnno.dll
jtr0079me.dll
hrj6051se.dll
unknown.exe
svci.exe
psdrv.exe
rasrun.exe
nwonknu.exe
cidrules.dll
rulesak.dll
lspak.dll
editpad.exe
quicken.exe
winhost.exe
unknown.exewindowsupd2.exe
svci.exe
psdrv.exe
rasrun.exe
nwonknu.exe

Remove VirtuMonde registry values (keys and subkeys):
MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\nnnmmlk
59B5C788-4D95-4610-B1ED-AD9DC7CD86E0
05029E1B-4C41-4681-8F7F-2AEC346136F4
01ABD624-98FE-4B37-81F2-4E5B41799B6B
1FB63E52-4D6E-48C1-A08F-F630FE50F337
5A4A2D56-931A-4733-9121-033A2D95A274
3F82D203-999F-4FF4-9F07-5F9EBFCCE20F
22E58089-6DB5-45D9-BF87-6C8975246D26
F73AF695-229D-4549-B1A0-20DA99A81F19
F00EFDF5-0042-4F5E-9F20-C688409CF918
B2030C9A-DE59-457D-A042-D827AD69C8F3
9CF8EE9B-0B2E-464A-9700-D7B46142BD99
SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\ssttr
SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\pmnno
662BB3E3-204F-44FA-A827-143B8AB4B036
C78658B2-CDE5-4FD1-B73B-B9FF478DBE54
B763C083-57E0-4993-B058-13008952DF68
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddcbabx
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\A05DA7E0-383C-4E99-A72A-742050A152A2
A05DA7E0-383C-4E99-A72A-742050A152A2
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\iifddby
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\6148028B-D532-4417-8C0B-5A4A0B745393
6148028B-D532-4417-8C0B-5A4A0B745393
D38439EC-4A7F-42b4-90C2-D810D7778FDD
Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnlk
2FCAB754-0535-470E-8F80-BACB6CA1ACC1
83B28A74-640D-48F4-9F51-E80EED7CC7E0
Software\Microsoft\Internet Explorer\Explorer Bars\83B28A74-640D-48F4-9F51-E80EED7CC7E0
D714A94F-123A-45CC-8F03-040BCAF82AD6
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssttr
22B271AB-3D0A-4CCB-8AD9-DD08183C356A
68616403-4FFB-4B19-B360-0B0B1F55D5EC
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnno
1B34D3EC-4AC7-41EC-ACC8-C9A2C0CBA2E5
D01C9902-73AF-47FF-B784-05FDB6604FCF
HKEY_LOCAL_MACHINE\software\targetsoft
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\*catw
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\windowsupd
HKEY_LOCAL_MACHINE\software\microsoft\windowsnt\currentversion\winlogon\notify\psdrv
HKEY_LOCAL_MACHINE\software\microsoft\windowsnt\currentversion\winlogon\notify\catw
HKEY_CURRENT_USER\software\microsoft\windowsupd
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce\*winlogon
13589181-4f0d-4553-b9f8-b4b72172c139
HKEY_LOCAL_MACHINE\software\targetsoftHKEY_CLASSES_ROOT\atlevents.atlevents
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\*catw
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\windowsupd
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psdrv
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\catw
HKEY_CURRENT_USER\software\microsoft\windowsupd
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce\*winlogon
HKEY_CLASSES_ROOT\clsid\{13589181-4f0d-4553-b9f8-b4b72172c139}
HKEY_CLASSES_ROOT\atlevents.atlevents

Mar 19, 2010 | Dell Dimension 3000 PC Desktop

1 Answer

Computer loads personal settings and then logs off instantly


Sounds like a malware issue I've seen before:

XP logs user off immediately when the user tries to log in - can't get to any desktop

Allegedly 3rd party advertising software Blazefind (homepage and searchbar highjacker)

Fix:

Boot to the Windows XP CD (RAID systems will need the RAID driver floppy during the bootup - hit the F6 key when directed in the bottom message).

Enter the Recovery Console by choosing 'R' at the Welcome to Setup screen.

Choose the OS shown (1) and hit enter.

Hit enter for a blank password if asked for one. If this isn't accepted, make sure that the user is using the correct XP CD (using a PRO version CD for a HOME version install or visa versa will result in a password rejection. If the user has upgraded to PRO over a HOME edition, try booting the HOME CD). If the CD is correct, and the user can't produce the correct Administrator password, then a clean reinstall of the OS (with full data loss) becomes the final answer.

Assuming the user now sees a command prompt, type "CD %systemroot%\system32" (without quotes) and hit ENTER. Normally the %systemroot% default is "c:\windows\" but this depends on if the system defaults were kept or changed during OS installation, of course.

Type "COPY USERINIT.EXE WSAUPDATER.EXE" (again, without quotes) and hit ENTER. This makes a copy of "userinit.exe" and simultaneously names the new copy "wsaupdater.exe".

Type "EXIT" and ENTER. Remove the XP CD while the system is restarting.

The user should now be able to log in normally... but there is one more thing that needs to be done or the issue will repeat itself when the user runs his anti-spyware program again.

Once logged into an administrator account, click the START button.

Choose RUN from the Start Menu.

Enter "REGEDT32" in the OPEN window (notice there is no "i" in edit) and click OK.

By clicking on the + signs next to each branch, click through the tree in the left pane until you get to

HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON

Click on the WINLOGON folder in the left pane tree, so that it is highlighted.

Look for "UserInit" in the right pane. It should have a value of "C:\WINDOWS\system32\wsaupdater.exe," (yes, there is a comma at the end of the value). Double-click on "UserInit" and carefully change its value to "C:\WINDOWS\system32\userinit.exe,". Click OK.

Close the Registry Editor. Reboot. Fix is complete. Anti-spyware programs will probably identify and remove "wsaupdater.exe" but the system is no longer using it.

Jan 27, 2010 | Dell Inspiron 6000 Notebook

1 Answer

Windowx xp booting time no icons appear.


Changing the default shell (all users):

1) open regedit (start menu > run, and type in regedit)
2) go to: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon.
3) Change Shell from explorer.exe to the new shell path e.g C:\Litestep\litestep.exe
4) log out and log back in.

Changing the default shell (only current user):

1) open regedit (start menu > run, and type in regedit).
2) go to: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon.
3) add a new string value (Edit > New > String Value) called shell. and set the value to the path of the new shell e.g C:\Litestep\litestep.exe.
4) log out and log back in.

http://support.microsoft.com/kb/228309

May 09, 2009 | Computers & Internet

1 Answer

When logging into windows vista, screen says locked. Once I type password in the desk top appears briefly and then goes back to login screen


Boot up your PC then when the bios screen disappears press F8 (to give you menu options like safe mode) one of these options is a vista repair option.....choose that and your pc should boot into windows properly....I believe this is a corrupt winlogon.exe....

Dec 06, 2008 | Computers & Internet

1 Answer

Start up msg


First
Open task manager and kill process wscript.exe.

Then
Delete VirusRemoval.vbs and Autorun.inf files from all usb drives.
Delete "c:\WINDOWS\system32\userinit.exe"

Then
Go to c:\Windows\System32 and delete the file VirusRemoval.vbs. It is super hidden so first go to Folder Options and check show hidden and check boxes. Also required for the above files.

Then
go to start>run and type regedit and enter
Go to HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
On the right side look for Shell which should have value of just explorer.exe.
delete anything at right side of explorer.exe if there is anything.

Under same key Winlogon also look for Userinit which should have value of
c:\WINDOWS\system32\userinit.exe,
Delete all the **** after the comma.

Then
Go to HKCU\Software\Microsoft\Internet Explorer\Main
On the right side locate Window Title and delete its value i.e. Sujin.com.np

Under the same key locate Start Page and delete its value i.e. http://sujin.com.np/

then go to Start Menu -> Run -> msconfig -> Startup tab -> uncheck .vbs files

Restart System

Jul 23, 2008 | Computers & Internet

Not finding what you are looking for?
Computers & Internet Logo

Related Topics:

123 people viewed this question

Ask a Question

Usually answered in minutes!

Top Dell Computers & Internet Experts

Les Dickinson
Les Dickinson

Level 3 Expert

18386 Answers

mukhtar21 shaikh
mukhtar21 shaikh

Level 3 Expert

2017 Answers

Computer Links

Level 3 Expert

2385 Answers

Are you a Dell Computer and Internet Expert? Answer questions, earn points and help others

Answer questions

Manuals & User Guides

Loading...