VersionsVersions

6.3.9600.16384 (winblue_rtm.130821-1623) 1.66%
6.3.9600.16384 (winblue_rtm.130821-1623) 2.70%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.22%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.04%
6.2.9200.16384 (win8_rtm.120725-1247) 0.74%
6.2.9200.16384 (win8_rtm.120725-1247) 0.57%
6.2.9200.16384 (win8_rtm.120725-1247) 0.13%
6.2.9200.16384 (win8_rtm.120725-1247) 11.54%
6.2.9200.16384 (win8_rtm.120725-1247) 1.44%
6.2.9200.16384 (win8_rtm.120725-1247) 0.74%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.09%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.09%
6.2.8250.0 (winmain_win8beta.120217-1520) 0.04%
6.2.8102.0 (winmain_win8m3.110823-1455) 0.09%
6.1.7601.17514 (win7sp1_rtm.101119-1850) 32.67%
6.1.7601.17514 (win7sp1_rtm.101119-1850) 16.94%
6.1.7601.17514 (win7sp1_rtm.101119-1850) 0.09%
6.1.7601.17514 (win7sp1_rtm.101119-1850) 0.04%
6.1.7601.17514 (win7sp1_rtm.101119-1850) 0.04%
6.1.7601.17514 (win7sp1_rtm.101119-1850) 0.04%
6.1.7601.17514 (win7sp1_rtm.101119-1850) 0.04%
6.1.7600.16385 (win7_rtm.090713-1255) 2.87%
6.1.7600.16385 (win7_rtm.090713-1255) 2.35%
6.1.7600.16385 (win7_rtm.090713-1255) 2.44%
6.1.7600.16385 (win7_rtm.090713-1255) 1.00%
6.1.7600.16385 (win7_rtm.090713-1255) 0.04%
6.0.6001.18000 (longhorn_rtm.080118-1840) 6.18%
6.0.6001.18000 (longhorn_rtm.080118-1840) 0.04%
6.0.6001.18000 (longhorn_rtm.080118-1840) 1.35%
6.0.6001.18000 (longhorn_rtm.080118-1840) 0.44%
6.0.6000.16386 (vista_rtm.061101-2205) 0.35%
6.0.6000.16386 (vista_rtm.061101-2205) 0.04%
5.2.3790.3959 (srv03_sp2_rtm.070216-1710) 0.09%
5.1.2600.5788 (xpsp_sp3_qfe.090402-1315) 0.04%
5.1.2600.5788 (xpsp_sp3_qfe.090402-1315) 0.52%
5.1.2600.5788 (xpsp_sp3_qfe.090402-1315) 0.04%
5.1.2600.5739 (xpsp_sp3_qfe.090107-1304) 0.09%
5.1.2600.5587 (xpsp_sp3_qfe.080424-1259) 0.09%
5.1.2600.5512 (xpsp.080413-2113) 9.19%
5.1.2600.5512 (xpsp.080413-2113) 0.09%
5.1.2600.5512 (xpsp.080413-2113) 0.09%
5.1.2600.5512 (xpsp.080413-2113) 0.09%
5.1.2600.5512 (xpsp.080413-2113) 0.04%
5.1.2600.5512 (xpsp.080413-2113) 0.04%
5.1.2600.5512 (xpsp.080413-2113) 0.04%
5.1.2600.3311 (xpsp.080212-0010) 0.09%
5.1.2600.3300 (xpsp.080125-2034) 0.04%
5.1.2600.3244 (xpsp.071030-1542) 0.04%
5.1.2600.3160 built by: xpsp_sp2_qfe(pavang) 0.04%
5.1.2600.2645 (xpsp.050331-1524) 0.04%
View more

Relationships

winlogon.exe

Windows Logon Application by Microsoft

Remove winlogon.exe
This is a Windows system installed file with Windows File Protection (WFP) enabled.
Warning 12 antivirus scanners has detected malware in various versions of winlogon.exe.

Overview

There are 56 versions of winlogon.exe in the wild, the latest version being 6.3.9600.16384 (winblue_rtm.130821-1623). winlogon.exe is run as a standard windows process with the logged in user's account privileges. The average file size is about 447.21 KB. During the process's lifecycle, the typical CPU resource utilization is about 0.0032% including both foreground and background operations, the average private memory consumption is about 2.37 MB with the maximum memory reaching around 7.85 MB. Addionally, typically read and write I/O disk operations is about 3.82 KB per minute for reads and 44 Bytes per minute for writes.

What is winlogon.exe?

Winlogon is the component of Windows that is responsible for handling the secure attention sequence, loading the user profile on logon, and optionally locking the computer when a screensaver is running (requiring another authentication step).

About winlogon.exe (from Microsoft)

Winlogon handles interface functions that are independent of authentication policy. It creates the desktops for the window station, implements time-out operations, and provides a set of support functi

DetailsDetails

File name:winlogon.exe
Publisher:Microsoft Corporation
Product name:Windows Logon Application
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\winlogon.exe
Original name:WINLOGON.EXE.MUI

BehaviorsBehaviors

(Note, the behaviors below are for all versions of winlogon.exe, select a unique version for details.)
Windows firewall allowed program
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\WINDOWS\system32\winlogon.exe'

MalwareMalware detections

Based on 40+ industry antivirus scanners, 12 of them detected the following malware.
Antivirus engineEngine versionDetectionFile version
Avira AntiVir 7.11.57.138 TR/Patched.CX.155 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Comodo Internet Security 14936 UnclassifiedMalware 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Emsisoft Anti-Malware 3.0.0.596 Trojan.Generic.9686422 (B) 6.1.7601.17514 (win7sp1_rtm.101119-1850)
eSafe 7.0.17.0 Win32.Banker 5.1.2600.5512 (xpsp.080413-2113)
Ikarus T3.1.3.5.0 Trojan.Win32.Patched 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Kingsoft 2013.1.5.217 Win32.Troj.Patched.c.(kcloud) 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Norman 6.08.06 W32/Troj_Generic.ADXUQ 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
nProtect 2012-10-24.02 Trojan/W32.Genome.547328.D 5.1.2600.5512 (xpsp.080413-2113)
Symantec 20101.3.2.89 WS.Reputation.1 5.1.2600.3300 (xpsp.080125-2034)
The Hacker None Trojan/Patched.cx 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Trend Micro HouseCall 9.700.0.1001 TROJ_GEN.USHRH30 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
VIPRE Antivirus 15056 Trojan-Downloader.Win32.Small 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)

VersionsAll file variations of winlogon.exe

MD5SHA-1File size
7c94fda3809015b8f2208d2e1c221f17 2e2f86c0fbb19e7db1b7c6cd9f45934a567134e9 551.5 KB
306eb21e5b480ae9065ea55ac8c35936 5d998639bbc961171518b5dfa02cfdff0c0cddc6 549 KB
deb887ea2ebedf01644a200b4bdb181b d00a42f154550dd0b452527356bd4219ecefb910 545 KB
29a02accc5a9fc862fd2ee8e459a7499 b2ac8452fdaf26985a2d76e815ebbca4d9ec216e 446 KB
c06ba1f360cef6ab51f41b3d0d5fe92d a66d3ac3b828ceee4da8b6d92db98b3dd84caf5d 402 KB
93ab226c07a9789b2ec7b41f73602f76 6cb925a64dbd8225ed9c309ce89ea4f476a1792a 504.5 KB
d75035a24ff8d5a489366c685030db4c 0c3b148a7b885d7989c4853ccc8c8266d74b9d96 402 KB
bcf2036a0dd579e47c008c133550283e c619b7636615127030e0970b01e7fa3cedf1081e 505 KB
87da6aca9af2f536c68471787d1b3f4a 1ac9bac8ff6be09d4ef6be1bb3eb1d8149d32665 402 KB
75dd70a14145499c9f7d903cf9a8c91b 77ec136b24adb07d8a44b1c81fcc5ce49ee90134 564.5 KB
7ff135eceb263bb7b26b1d06afe49548 63fbb376ea4f5d4fd89605e63b92b79b9d27e607 503.5 KB
09d592f8cee432c7ab824043f988638f 857c7932cf04ae6469a7c51d6da4b4fb1b216234 401 KB
1e3b3ee8c4836509134b8a6af8a438cf 4cb4d0d8aac1499e26d21a8a0df72e135da891a1 384.5 KB
d1ec3edfadbb83b6a7f78f3f1733c5a1 649c2f0efe2e3eee17615f0006e5cb4d8a271095 313 KB
1151b1baa6f350b1db6598e0fea7c457 434856b834baf163c5ea4d26434eeae775a507fb 381.5 KB
6d13e1406f50c66e2a95d97f22c47560 b8561be07a37c7414d6e059046ab0ad2c24bd2ad 280 KB
1562571d6b1541098e677c3bb78709a0 344a9fe7b9c6f3cb24923e6aa50aa5f2e4267ad4 279 KB
87a00ed70fec36d0dd968e5058c29aa1 9d9e8c4f35b0b5d6077d71eb279bb3195c71979b 380.5 KB
4979c8cd732219d76228702ffdba908b 893786adc5ceca46b29719c1bb7eced9b1efc7ce 381.5 KB
9effb152bca501cd95982b0847bc3fa8 188a000356bb1aff72ef4f4337be2224469f49f6 280.5 KB
998507b046ba314ce8245364c686fa67 77fcd41efc88b1a6c15cf52554e74cc47b87d5df 297 KB
37cdb7e72eb66ba85a87cbe37e7f03fd cd0f4b3711a415272def132b83f6fc29d76ee4ad 279 KB
8ec6a4ab12b8f3759e21f8e3a388f2cf 2d7d1dd2e339334bdfea49d9e271ae36094eb6ee 279 KB
da3e2a6fa9660cc75b471530ce88453a 98b5b064b00a94b43a260b37cd62273c93a9206e 380.5 KB
132328df455b0028f13bf0abee51a63a a69cd8e02532e7c782767218ace03c60df5f3a71 380 KB
8b14f5feddb412bbc0a9b1f8beabdc59 f13cc088b5e5582145334d8410925369525a3961 298.5 KB
898e7c06a350d4a1a64a9ea264d55452 6d63303f3912633c8a9a6e2b3cb74d60220cf7a2 307 KB
856491fced98093d824b9eb2892f564a 35965825f7246eb7c81488bffeef7918ca4dea46 396.5 KB
6d0773a3a65d28b663f334c90441d01a 50fbc12563e00f420f2891d7c73628b10ed229fa 396 KB
c2610b6bdbefc053bbdab4f1b965cb24 145787476862969411875c30e3ef177bc8ac1863 307.5 KB
9f75392b9128a91abafb044ea350baad 53919f23c338fa6bcd05a41544f674a81fdac92e 301 KB
a3fea6ed9fd3cf07219a632e4a716226 38f49ae825d3f46ed86850dbd4e7db9a6b12a6f5 301 KB
901c7e44d11c00ca9d48ba1a866fdc4b c050f186712cbfe4fcca4c7765b4e8d9f8dbf51f 922 KB
66913dbe51c5642041c132cfa947910b 3156d228d9964bd87812ba44d9a951f002efd618 545.5 KB
53a8857723277b1d6d5ee60a9f85b117 45e29cef3100d12d24a9a36992bfd37ea5739ca7 497.5 KB
f7831c8dd6e3e7d795041a61fedc0a65 a8df515a242b09281917d1e302f8617033da5452 536 KB
5dfcba4e70da51cf67022f7c207feaa8 ab6031a60c989826f3774632ffb3f2be3c45c62b 497.5 KB
d1bac55bc35a0ca735aea19f609f2b22 2c4fd4ee572db797febd8e46471979f8475ea783 496 KB
ed0ef0a136dec83df69f04118870003e f77a7cd78877527023ebfb35e83b75ef59d3df07 496 KB
7dd9ce78dd441eea2bbaff6d3eeaad08 0683491bdb705d2b52df86e0ae53415e7edf78e0 544 KB
a55b8899d2ea2e800061bcfd456e34dc 3ce9bf880803641888efba468feef74ed60d598f 534.5 KB
c64e97cc32e4662f2972fe7e8fa9b6ce d5fd82cfdd553b256ef2f24d86a6f1e6daa92cfc 544 KB
bcedf9dccbc807108ce34c9834074c34 283e6e1d78fdfd283cb367fa1289164ebc0003b7 495 KB
9dc7d2c3a0956a9ff82c4dd5596613a8 2b9951ff8a573ede4cf0c3e87a7922cc41a53668 492.5 KB
739103085ce0ee74192b7b9245cae66a 5c758056c78cb1127dffbbf51ac42f2676c611e9 555.5 KB
57021a062c8e266c0a2a636450364b43 71063839e8db9ba3ab758c648d82f8d8932fe114 496 KB
7c87833890a151e4c88c086797ef1d98 818da86d4dc4f96d8d58c4ee0ac97767582ecce6 496 KB
56adf995fff58eb7d0dd0819343fb0eb 3ef6d12ed274153c948b88304f84cda89fe7bfec 496 KB
051a52001d625f316ce81a539bd25192 7b8a4d0d5cbe7d10fe1c0c3c41b96ffec95a50f3 495 KB
986ec72d788e00e8e397b7bb7f5a9e45 44f6fa3b5869dfdf43f0ecf2e431d09d24ea9e81 491 KB
b4592fce66ab5cefcafb9fa0d8a04d24 68b6fa2540b1d4b8f8f2dfd82693853c3cafaaf1 491 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 28.50%
Windows 7 Ultimate 17.25%
Windows 8.1 13.50%
Windows 8 7.50%
Windows 8.1 Pro 6.00%
Windows 7 Professional 5.25%
Windows 8 Pro 4.50%
Windows 8.1 Single Language 2.75%
Windows Vista Home Premium 2.75%
Windows 8 Single Language 2.25%
Windows 7 Home Basic 1.75%
Windows 8.1 Pro with Media Center 1.50%
Windows 8 Enterprise 0.75%
Windows 7 Starter 0.75%
Windows 8.1 Pro Preview 0.75%
Windows 8 Enterprise N 0.50%
Windows 8.1 Enterprise 0.50%
Windows 8 Pro with Media Center 0.50%
Windows 7 Enterprise 0.50%
Windows 8.1 N 0.25%
Windows Seven Black Edition 0.25%
28 other Windows OS version

Distribution by countryDistribution by country

United States installs about 38.38% of Windows Logon Application.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 17.61%
ASUS 16.51%
Hewlett-Packard 15.60%
Acer 11.38%
Lenovo 10.64%
Toshiba 10.28%
Sony 5.87%
Intel 2.94%
GIGABYTE 2.39%
Samsung 1.83%
Alienware 1.28%
Medion 1.10%
MSI 0.73%
American Megatrends 0.55%
Gateway 0.37%
NEC 0.37%
Compaq 0.37%
Sahara 0.18%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE