Winlogon 6004

0 views
Skip to first unread message

Pricilla Igoe

unread,
Aug 5, 2024, 4:05:48 AM8/5/24
to opismisa
Ihave been unable to resolve this. I see that i was being associated with mrxsmb event ID 3019. Found a reference on AVG forums to remove firewall, linkscanner and webshield. Did this, this morning, waiting on results. So far the machine has not reported th mrxsmb error, buth the 6004 is still there.

I'm trying to make a Winlogon notification service that receive the logon message and then copies ntuser.dat (registry) from a central location (like roaming profile do) and when logoffs, reverts this (copy ntuser.dat to central location). I already made the service and it receives the SENS message, but I think SENS messages are received AFTER ntuser.dat is loaded; so I receive a "file in use message" trying to interact with ntuser.dat. I think SENS is not the way to do this, but the old hklm\xxx\x\x\winlogon\notify way is not working on windows vista and UP. So I'm lost here.


The SENS service is one layer below the notification services of Winlogon, in fact, the SENS itself is a service registered to Winlogon to receive notifications, and then, the SENS informs all the services that implement this second layer COM interfaces about changes in the states of the sessions such as Logon, Logoff, etc.


The user profile service (ProfSvc) is also a service that, like SENS, receives notifications from Winlogon and is responsible for executing the policies and movements of the NTUSER.DAT and other issues related to the registry and the user profile.


Under this Key are some REG_SZ with the possible events, like: Logon, Logoff, EndShell, Unlock, etc and the content its a comma separated string with the name of the service to load in order to notify.


My wife's Win7 computer was infected with Astromenda (and perhaps a couple others). I installed Malwarebytes and it detected a dozen infected files or registry entries (wish I had written down list - may be in logs). I then clicked the "quarantine" button to fix the issue. After reboot I am not able to login to any account on system.


Evidently the removal process (Malwarebytes?) decided to delete this link so that it no longer found my users directories (and failed as shown in log entries below). To make it more confusing, Windows decided to create a new set of subdirectories at C:\Users\XXXX that now had my new users within it (but still had invalid registry entries).


Recreating my Junction (symbolic link) and all is working again. After 4 years of no problems, I'll need to keep an eye on this. No need for further replies but I'll leave these breadcrumbs (and log entries below) in case it is useful for others.


Searching on the first event message "The winlogon notification subscriber failed a critical notification event." it appears to be a registry problem (such as the user not having permissions, bad, missing, or corrupted registry files). Odd that it would be corrupted for all of the users on this box. As I was looking for those registry files I recalled the changes I had made earlier for D:\Users.


We can't work on malware diagnostics and removal in this sub-section of the forum.



So, for expert assistance checking the system for malware remnants and damage, I suggest that you please follow the advice in this pinned topic: Available Assistance For Possibly Infected Computers.

It explains the options for free, expert help >>AND


The Microsoft Exchange Server Analyzer Tool queries theWin32_NTLogEvent Microsoft Windows ManagementInstrumentation (WMI) class to determine whether an Event 6004warning has been logged for MSExchangeTransport within thelast 24 hours.


The message categorizer examines messages that come to a SimpleMail Transfer Protocol (SMTP) server and determines what to do withthe messages. The messages may be destined for the localinformation store, for a remote host by using the message transferagent (MTA), or for a remote host by using SMTP. The categorizeralso handles distribution list expansion. The categorizer is aplug-in to the advanced queuing engine that performs LightweightDirectory Access Protocol (LDAP) queries against global catalogservers on TCP port 3268. The categorizer is basically a collectionof event sinks that perform advanced address resolution on everymessage that travels through the advanced queuing engine. Thecategorizer performs address resolution and mail forwarding, setscontent conversion flags, expands distribution lists, enforcesglobal settings, and generates delivery status notifications. Thecategorizer also detects alternative recipient routes and performsbifurcation, journaling, and many other functions.


As soon as a message enters the message categorizer, thecategorizer resolves the envelope sender by searching for theaddress in the proxy address attributes in theActive Directory directory service. The categorizer alsoresolves the envelope recipient by searching for each address inthe proxy addresses attribute in Active Directory. Forexample, if the list includes a distribution list, it expands thelist to include those members if distribution list expansion isallowed on the server.


This object monitors the DFS Replication configuration in Active Directory Domain Services (AD DS), and creates a Warning alert if it detects conflicting or duplicate configuration objects in AD DS. It does so by looking for the presence of DFS Replication Event 6004.

3a8082e126
Reply all
Reply to author
Forward
0 new messages