What is the "winlogon.exe" ?

Our database contains 3174 different files for filename winlogon.exe . You can also check most distributed file variants with name winlogon.exe. This files most often belongs to product Microsoft® Windows® Operating System. and were most often developed by company Microsoft Corporation. This files most often have description Windows Logon Application. Agregate rating is 4(4) stars - based on 74 reviews.This is executable file. You can find it running in Task Manager as the process winlogon.exe.

winlogon.exe is in most cases the Windows System process responsible for managing user logon and logoff. winlogon is active when the user presses CTRL+ALT+DEL and shows user interface. Specifically for Windows OS : winlogon.exe is a core process from Windows login manager. It handles both login and logout procedures on Windows system. This program is critically important for running of Windows system. Some antiviruses may mark it as a virus. Also as a key process for MS Windows, it can be a target for many viruses. Scan is recommended. Check the MD5 version and directory, it should be located in the %SYSDIR%

winlogon.exe Process

File details of most used file with name "winlogon.exe"

Microsoft® Windows® Operating System
Microsoft Corporation
Windows Logon Application
Operating System:
Windows 7
High oc2

Is the Process "winlogon.exe" Safe or Threat ?

77% of reviewed files are marked as Safe .
21% of reviewed files are marked as Threat .
28% of reviewed files are marked as System file.
Latest new variant of the file with name "winlogon.exe" was discovered 4368 days ago. Our database contains 435 variants of the file "winlogon.exe" with final rating Safe and 260 variants with final rating Threat . Final ratings are based on file reviews, discovered date, users occurence and antivirus scan results.
Process with filename "winlogon.exe" can be Safe or Threat. You must define more file attributes to determine right rating. Our freeware awards winning tool provides easiest way to check your files via our database. Tool contains many useful functions for keep your system under control and uses minimum system resources.
Filename "winlogon.exe" is used by Microsoft Windows System files. Many threats uses filenames of System Processes to camouflage itself. You should consider suspected any file which uses system filename and is not stored in system directory or has invalid file version information. Correct system file contains full file version information from Microsoft.

User Reviews of the "winlogon.exe"

There are multiple files in compliance with actual filter settings. All reviews for this files will be displayed.

Reviews for all files with name "winlogon.exe"

  • SAFErating from user Yo for file C:\Windows\System32\winlogon.exe (Variant: 41881675)

    Safe as long as it is part of System32

  • SAFErating from user ben for file C:\Windows\System32\winlogon.exe (Variant: 41170491)


  • SAFErating from user Ben for file C:\Windows\System32\winlogon.exe (Variant: 41170491)


  • SAFErating from user roofjunkie for file C:\Windows\System32\winlogon.exe (Variant: 40502443)


  • THREATrating from user Z8fuc2Ud3 for file %USERPROFILE%\ROSALESPH1\winlogon.exeflag es

  • THREATrating from user Stiv for file C:\Windows\System32\winlogon.exe

  • SAFErating from user street for file C:\Windows\System32\winlogon.exe

  • SAFErating from user Bert for file C:\Windows\System32\winlogon.exe

  • THREATrating from user ЛЕКСАНДЕР for file %TEMP%\winlogon.exeflag ru

  • SAFErating from user noviczky for file C:\Windows\System32\winlogon.exeflag sk

  • SAFErating from user 3hlav for file C:\Windows\System32\winlogon.exe

  • SAFErating from user Mikel for file C:\Windows\System32\winlogon.exe

  • SAFErating from user Олег Разин for file C:\Windows\System32\winlogon.exe

  • THREATrating from user MikeOne for file %DESKTOP%\writer\writer\winlogon.exe (Variant: 19573890)

    Keylogger/Trojan virus

  • THREATrating from user MikeOne for file %USERPROFILE%\Templates\O86060Z\winlogon.exe (Variant: 19733867)

    Worm/Win32.VB virus

  • THREATrating from user MikeOne for file %USERPROFILE%\058527563614\winlogon.exe (Variant: 19401617)

    In this MD5 version the file is infected by a Trojan virus.
    In this MD5 version the file is infected by a Trojan virus.

  • THREATrating from user MikeOne for file %APPDATA%\Microsoft\Windows\Templates\O63636Z\winlogon.exe (Variant: 19462057)

    In this version the file is not signed or marked as a Windows file. Scan is recommended.
    In this version the file is not signed or marked as a Windows file. Scan is recommended.

  • SAFErating from user MikeOne for file C:\Windows\System32\winlogon.exe (Variant: 19528110)

    "Winlogon is the component of Microsoft Windows operating systems that is responsible for handling the secure attention sequence, loading the user profile on logon, and optionally locking the computer when a screensaver is running (requiring another authentication step)." - see more on http://en.wikipedia.org/wiki/Winlogon.exe
    "Winlogon is the component of Microsoft Windows operating systems that is responsible for handling the secure attention sequence, loading the user profile on logon, and optionally locking the computer when a screensaver is running (requiring another authentication step)." - see more on http://en.wikipedia.org/wiki/Winlogon.exe

  • SAFErating from user rots for file C:\Windows\System32\winlogon.exe

  • SAFErating from user MikeOne for file C:\Windows\System32\winlogon.exe (Variant: 15565645)

    winlogon.exe is a core process from Windows login manager. It handles both login and logout procedures on Windows system. This program is critically important for running of Windows system. Some antiviruses may mark it as a virus. Also as a key process for MS Windows, it can be a target for many viruses. Scan is recommended. Check the MD5 version and directory, it should be located in the %SYSDIR%

  • SAFErating from user Admin for file C:\Windows\System32\winlogon.exe (Variant: 12228908)

    Windows 8 Logon component

  • SAFErating from user MikeOne for file C:\Windows\System32\winlogon.exe (Variant: 10115300)

    "Winlogon is the component of Microsoft Windows operating systems that is responsible for handling the secure attention sequence, loading the user profile on logon, and optionally locking the computer when a screensaver is running (requiring another authentication step)." - see more on http://en.wikipedia.org/wiki/Winlogon.exe

  • SAFErating from user 3hlav for file C:\Windows\System32\winlogon.exe (Variant: 508532)

    The process "winlogon.exe" runs in the background. Winlogon is a part of the Windows Login subsystem, and is necessary for user authorization and Windows activation checks. Note: The winlogon.exe file is located in the folder C:\Windows\System32. In other cases, winlogon.exe is a virus, spyware, trojan or worm!

  • THREATrating from user MikeOne for file %TEMP%\winlogon.exe (Variant: 309544)

    In this MD5 version, this file was marked by most antiviruses as Trojan.Win32.Jorik virus. Remove it from Your computer. Scan is recommended. Check the MD5 hash and file location, there can more files with this name.

  • SAFErating from user D.S.Denton for file C:\Windows\System32\winlogon.exe (Variant: 2151357)

    With this MD5-hash this file is Windows XP SP3 Logon Process, patched decoration program "ResPatch" style - "Black-Dark" version - 3.12.2008

  • SAFErating from user loveboy_lion for file C:\Windows\System32\winlogon.exe

  • SAFErating from user Lasse for file C:\Windows\System32\winlogon.exe

  • SAFErating from user via2305 for file C:\Windows\System32\winlogon.exe

  • SAFErating from user newada2000 for file C:\Windows\System32\winlogon.exe

  • SAFErating from user Littlebits for file C:\Windows\System32\winlogon.exe (Variant: 676254)

    Windows Logon Application

  • SAFErating from user Admin for file C:\Windows\System32\winlogon.exe (Variant: 502180)

    Windows Logon Application

  • SAFErating from user lucien for file C:\Windows\System32\winlogon.exe (Variant: 676254)

    The process "winlogon.exe" runs in the background. Winlogon is a part of the Windows Login subsystem, and is necessary for user authorization and Windows activation checks. http://www.neuber.com/taskmanager/process/winlogon.exe.html Note: The winlogon.exe file is located in the folder C:\Windows\System32. In other cases, winlogon.exe is a virus, spyware, trojan or worm! Check this with Security Task Manager/AV Tools

  • SAFErating from user Moraxv for file C:\Windows\System32\winlogon.exe

  • SAFErating from user UPieper for file C:\Windows\System32\winlogon.exe

  • SAFErating from user Dark Star for file C:\Windows\System32\winlogon.exe

  • THREATrating from user MikeOne for file %TEMP%\winlogon.exe (Variant: 82284)

    In this MD5 version, this file was marked by most antiviruses as Trojan.Generic.3854898 virus. Remove it from Your computer. Scan is recommended. Check the MD5 hash and file location, there can more files with this name.

  • THREATrating from user MikeOne for file C:\Windows\System32\winlogon.exe (Variant: 46333)

    In this MD5 version, this file was marked by most antiviruses as Trojan/W32.Agent virus. Remove it from Your computer. Scan is recommended. Check the MD5 hash and file location, there can more files with this name.

  • THREATrating from user MikeOne for file C:\Windows\System32\winlogon.exe (Variant: 17922)

    In this MD5 version, this file was marked by most antiviruses as WPACracked.Winlogon.B virus. Remove it from Your computer. Scan is recommended. Check the MD5 hash and file location, there can more files with this name.

  • SAFErating from user MikeOne for file C:\Windows\System32\winlogon.exe (Variant: 14286)

    winlogon.exe is a core process from Windows login manager. It handles both login and logout procedures on Windows system. This program is critically important for running of Windows system. Some antiviruses may mark it as a virus. Also as a key process for MS Windows, it can be a target for many viruses. Scan is recommended. Check the MD5 version and directory, it should be located in the %SYSDIR%

  • THREATrating from user MikeOne for file %TEMP%\Local Settings\Application Data\winlogon.exe (Variant: 12456)

    In this MD5 version, this file was marked by most antiviruses as Email-Worm.Win32.Brontok virus. Remove it from Your computer. Scan is recommended. Check the MD5 hash and file location, there can more files with this name.

  • THREATrating from user MikeOne for file %APPDATA%\S85-28348346-UIT83-G3-72366-GDSG-1732735\winlogon.exe (Variant: 6743)

    Generally, the Winlogon is a part of the Windows Login subsystem, process necessary for user authorization and Windows XP activation checks. Comonly it is stored in the %System32% windows directory. In this MD5 version it is malware marked by most antiviruses as a Trojan.Win32.Antavmu.

  • THREATrating from user Admin for file %USERPROFILE%\Configurações locais\Dados de aplicativos\winlogon.exe (Variant: 2204)

    Most of Antiviruses detects this file as Threat (W32/Rontokbro).

  • SAFErating from user Admin for file C:\Windows\System32\winlogon.exe