winlogon.exe
Windows Logon Application by Microsoft
Version: | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) |
MD5: | 01c3346c241652f43aed8e2149881bfe |
SHA1: | a5396141cab8b22d9d88b28a814089537dce366a |
SHA256: | affd0973cd3128083417d407f62bc4a635fc25b65dbf52e91d3ab4ae2f9c1b4a |
This is a Windows system installed file with Windows File Protection (WFP) enabled.
What is winlogon.exe?
Winlogon is the component of Windows that is responsible for handling the secure attention sequence, loading the user profile on logon, and optionally locking the computer when a screensaver is running (requiring another authentication step).
About winlogon.exe (from Microsoft)
“Winlogon handles interface functions that are independent of authentication policy. It creates the desktops for the window station, implements time-out operations, and provides a set of support functi”
Details
File name: | winlogon.exe |
Publisher: | Microsoft Corporation |
Product name: | Windows Logon Application |
Description: | Microsoft® Windows® Operating System |
Typical file path: | C:\Windows\System32\winlogon.exe |
Original name: | WINLOGON.EXE.MUI |
File version: | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) |
Product version: | 5.1.2600.2180 |
Size: | 490.5 KB (502,272 bytes) |
Digital DNA |
Entropy: | 6.338183 |
File packed: | No |
Code language: | Microsoft Visual C++ |
.NET CLR: | No |
More details
Behaviors
Windows firewall allowed program
Exceptions allow programs to access to the Internet through an outbound connections
- Firewall exception for 'C:\Windows\system32\winlogon.exe'
Network connections
Access through an approved Windows firewall exception
[UDP] listens on port 1068
[UDP] listens on port 1052
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.01756280% | |
Kernel CPU: | 0.00949457% | |
User CPU: | 0.00806823% | |
Kernel CPU time: | 1,736 ms/min | |
Context switches: | 2/sec | |
Memory |
Private memory: | 6.93 MB | |
Private (maximum): | 5.21 MB | |
Private (minimum): | 3.31 MB | |
Non-paged memory: | 6.93 MB | |
Virtual memory: | 54.71 MB | |
Virtual memory (peak): | 60.29 MB | |
Working set: | 4.45 MB | |
Working set (peak): | 15.6 MB | |
Page faults: | 14,393/min | |
I/O |
I/O read transfer: | 4.92 KB/sec | |
I/O read operations: | 1/sec | |
I/O write transfer: | 892 Bytes/sec | |
I/O write operations: | 1/sec | |
I/O other transfer: | 568 Bytes/sec | |
I/O other operations: | 12/sec | |
Resource allocations |
Threads: | 19 | |
Handles: | 498 | |
GUI GDI count: | 44 | |
GUI USER count: | 13 | |
Process properties
Threads
Distribution by Windows OS
OS version | distribution |
Windows 8.1 |
23.00% |
|
Windows 7 Home Premium |
23.00% |
|
Windows 8.1 Pro |
10.50% |
|
Windows 7 Ultimate |
10.50% |
|
Windows 8 |
5.50% |
|
Windows 8.1 Single Language |
5.00% |
|
Windows 8 Single Language |
3.50% |
|
Windows 8 Pro |
3.50% |
|
Windows 8.1 Pro with Media Center |
2.50% |
|
Windows Vista Home Premium |
2.50% |
|
Windows 7 Professional |
2.50% |
|
Windows 7 Home Basic |
1.50% |
|
Windows 8 Enterprise N |
1.00% |
|
Windows 8 Enterprise |
1.00% |
|
Windows 8.1 N |
0.50% |
|
Windows Seven Black Edition |
0.50% |
|
Windows 8.1 Enterprise Evaluation |
0.50% |
|
Windows 7 Starter |
0.50% |
|
Windows 8.1 Enterprise |
0.50% |
|
Windows 8.1 Pro Preview |
0.50% |
|
Windows Vista Home Basic |
0.50% |
|
23 other Windows OS version |
Distribution by country
United States installs about 39.50% of Windows Logon Application.
Distribution by PC manufacturer
PC Manufacturer | distribution |
ASUS |
19.62% |
|
Dell |
18.11% |
|
Hewlett-Packard |
14.72% |
|
Lenovo |
12.08% |
|
Acer |
11.70% |
|
Toshiba |
9.06% |
|
Intel |
3.02% |
|
Sony |
3.02% |
|
GIGABYTE |
2.64% |
|
Alienware |
2.26% |
|
Samsung |
1.89% |
|
Medion |
1.51% |
|
Sahara |
0.38% |
|