QUOTE (dbm @ Feb 16 2009, 11:42 AM)

I was also receiving the false positive winlogon.exe error. I ran a full virus scan Thursday, and at BitDefender's suggestion moved the winlogon.exe to quarantine. I then reran the virus scan to make sure that my system was clean. Approximately five minutes into the scan, my system crashed. Since then, it cannot be rebooted. I receive a BSOD error message each time. I've tried to boot in safe mode, last known good configuration, and every other option.
System Info
XP Service Pack 2
BitDefender Total Security 2009
Due to the fact that the system was purchased from Dell, I do not have an XP CD to attempt to repair my XP installation.
Using a different PC, I was online for thirty minutes yesterday using the chat function with a customer service rep who promised me an e-mail solution that he never sent. I have not had access to my system or data for four days due to this error, and I am desperate for assistance.
I have seen several different manifestations of this problem - affected over 50 PCs here with over 40 having Blue Screen of Death. The differences for me have been in the order updates and scans took place during the night.
To Fix,
1) Find a good version of C:\windows\system32\winlogon.exe on a different PC with the same OS and copy it to a CD or floppy. Our latest version is 5.1.2600.5512, size is 496K.
2) Enable boot from CD in the BIOS if not already enabled.
3) Since you don't have an OS reinstall CD from Dell (it is a cheap available option), use any Win XP OS reinstall disk you get hold of.
You may be able to do the file copy using a Linux tool bootable CD also such as Killdisk or Super FDisk. It just has to support NTFS
filesystem. The instructions below refer to a reinstallation CD but the others would be similar.
4) Boot from it, select Recovery Console, keyboard and login if needed. You should end up at:
C:\windows> prompt.
5) Put CD or floppy containing winlogon.exe in drive. If you have 2 CD drives put it in the 2nd one, otherwise eject the 'Reinstall CD' (use a paperclip in the hole if neccesary) or use a floppy. USB drives wouldn't work for us.
6) Do the following at the commandline prompts:
CD system32<Enter> (moves current directory to C:\Windows\system32)
copy D:winlogon.exe<Enter> (assuming D drive contains CD, might be A: for floppy or other
You can chane current drive E:<Enter> dir<Enter> to find drive.)
exit<Enter>
7) During reboot, remove CD/floppy.
8) System should reboot to login screen.
9) Login.
10) As soon as BD shows up in taskbar, update it so it won't delete winlogon again.
11) Check BD quarantine and restore winlogon if there. If the new copy is still in c:\windows\system32 dirctory from step 6 BD won't restore the old copy.
12) Check for the Winlogon.exe file in C:\Windows\System32 for safety.
There is also a copy in C:\Windows\ServicePackFiles\I386.
Good luck.