| Vendor: Microsoft |
| Product: Windows |
| Vendor Website: |
| Last Seen by PC Pitstop: No Data |
PC Pitstop has analyzed this process and determined that there is a high likelihood that it is bad.
PC Pitstop has analyzed this process and determined that the safety of this process is questionable.
PC Pitstop has analyzed this process and determined that there is a high likelihood that it is good.
This process is a Microsoft or Windows process, but many viruses use this file name to escape notice.Purpose: winlogon.exe - This program initializes some functions of Windows each time a user logs in. Usually it should not appear in running programs because it completes its work in less than a minute. If it is still running then there may be some type of configuration problem with your system. See the detailed description for troubleshooting information.
winlogon.exe is a user invoked program and a normal part of PC operations. No action required.
PC Pitstop recommends WinPatrol Plus for monitoring all of the background activity on your PC. WinPatrol Plus provides an easy to understand descriptions of over 15,000 processes and programs.
Percentage of recently scanned PC's with this process running: 22.87%
Average CPU use for this program: 0%
Average RAM for this program: 3 MB
| Program Name | MD5 Count |
| winlogon.exe |
MD5 Hashes
|
||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| # | Status | MD5 | File Info | Last Seen | Signed | Day | Week | Month | Threat info | |||
| 1 |
![]() |
0xed0ef0a136dec83df69f04118870003e | ![]() |
6/14/2013 | ![]() |
3584 | 9400 | 66934 | Not Applicable | |||
| 2 |
![]() |
0x9f75392b9128a91abafb044ea350baad | ![]() |
6/14/2013 | ![]() |
2 | 13 | 40 | Not Applicable | |||
| 3 |
![]() |
0x898e7c06a350d4a1a64a9ea264d55452 | ![]() |
6/14/2013 | ![]() |
241 | 2655 | 14503 | Not Applicable | |||
| 4 |
![]() |
0x37cdb7e72eb66ba85a87cbe37e7f03fd | ![]() |
6/14/2013 | ![]() |
5 | 71 | 329 | Not Applicable | |||
| 5 |
![]() |
0xefcefab70aeb72b6bf49109546c8a55e | ![]() |
6/12/2013 | ![]() |
0 | 1 | 1 | Not Applicable | |||
| 6 |
![]() |
0x6580dfd88204cfdd6be1a5d63ed466d6 | ![]() |
6/12/2013 | ![]() |
0 | 201 | 201 | Trojan.Win32.Generic!BT | |||
| 7 |
![]() |
0xb1cf6c7cf54dff1bc7862e9830cad607 | ![]() |
6/11/2013 | ![]() |
0 | 1 | 1 | Not Applicable | |||
| 8 |
![]() |
0x8ec6a4ab12b8f3759e21f8e3a388f2cf | ![]() |
6/10/2013 | ![]() |
0 | 2 | 2 | Not Applicable | |||
| 9 |
![]() |
0xc06ba1f360cef6ab51f41b3d0d5fe92d | ![]() |
6/10/2013 | ![]() |
0 | 7 | 54 | Not Applicable | |||
| 10 |
![]() |
0x3517bcb9cd8f9ac3ac875cda90295c80 | ![]() |
6/3/2013 | ![]() |
0 | 0 | 3 | Not Applicable | |||
| 11 |
![]() |
0x37347864754fb3d1741cb0e0a140d12b | ![]() |
5/28/2013 | ![]() |
0 | 0 | 1 | Not Applicable | |||
| 12 |
![]() |
0xd9227d1c42d5deee201a11be7c1888f7 | ![]() |
5/20/2013 | ![]() |
0 | 0 | 1 | Not Applicable | |||
| 13 |
![]() |
0x24176ab453aa92c900af3d81ca25588d | ![]() |
5/16/2013 | ![]() |
0 | 0 | 2 | Not Applicable | |||
| 14 |
![]() |
0xc0bdb5b733f52cae411497a5d93e0ed8 | ![]() |
5/6/2013 | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 15 |
![]() |
0xf5379cb411d1c8aed5a76f41dbb243ce | ![]() |
5/2/2013 | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 16 |
![]() |
0x27b9090058946cf9b008d797fc43dafb | ![]() |
5/1/2013 | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 17 |
![]() |
0x26aa38b02108cb9232561d0ca1c74218 | ![]() |
4/21/2013 | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 18 |
![]() |
0x00fc417211738840dd47ac48a091e0d6 | ![]() |
4/15/2013 | ![]() |
0 | 0 | 0 | Trojan.Win32.Generic!BT | |||
| 19 |
![]() |
0x7a6fa97825fa65f0ecb7a16405156996 | ![]() |
4/14/2013 | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 20 |
![]() |
0xa0e8324248df30f58851565c50e2a3b7 | </tr></table>'>![]() |
4/12/2013 | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 21 |
![]() |
0xd32dc5d0a010d0c1718c40eaa8c5cdd4 | ![]() |
4/2/2013 | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 22 |
![]() |
0x40dbcaca7d3c2deef5727baa4ed62f57 | ![]() |
3/3/2013 | ![]() |
0 | 0 | 0 | Trojan.Win32.Ircbrute | |||
| 23 |
![]() |
0xc72b882b11d50320724e08dd44025695 | ![]() |
12/12/2012 | ![]() |
0 | 0 | 0 | Nuclear Prank | |||
| 24 |
![]() |
0xf400801f649c5e55bce53429c1d3057d | ![]() |
10/2/2012 | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 25 |
![]() |
0xfdd3bc435aca21ccadf4f52787ae52bd | ![]() |
9/26/2012 | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 26 |
![]() |
0xecb52c2f242c03d3af8bbce366df7407 | ![]() |
9/22/2012 | ![]() |
0 | 0 | 0 | Trojan.Win32.Generic!BT | |||
| 27 |
![]() |
0x37ca17cce865589ff8460572ea2eef79 | ![]() |
7/2/2012 | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 28 |
![]() |
0xbdfb197ab00399edc032679441853429 | ![]() |
5/29/2012 | ![]() |
0 | 0 | 0 | Trojan.Win32.Generic!BT | |||
| 29 |
![]() |
0x50ea324bd721820424356b59c97b9fc6 | ![]() |
No Data | ![]() |
0 | 0 | 0 | Trojan.Win32.Generic!BT | |||
| 30 |
![]() |
0xff94e423cb3e43f7f8eb396bd6c47d6c | ![]() |
No Data | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 31 |
![]() |
0xa0dcc2c99129c80e5cbeccdfcfc9f294 | ![]() |
No Data | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 32 |
![]() |
0xa64e14836a2d5060fb68227de41e1cad | ![]() |
No Data | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 33 |
![]() |
0xabf7f77d12ff10dbc3fabc69e8437589 | ![]() |
No Data | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 34 |
![]() |
0xa009f248433e3d72556b0960cf580b15 | ![]() |
No Data | ![]() |
0 | 0 | 0 | Trojan.Win32.Generic.pak!cobra | |||
| 35 |
![]() |
0xe8d4635cd7349fe626f99f801da9be28 | ![]() |
No Data | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 36 |
![]() |
0x0ed0ef0a136dec83df69f04118870003 | ![]() |
No Data | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 37 |
![]() |
0x6a08946d14efd9d4a083218643481de9 | ![]() |
No Data | ![]() |
0 | 0 | 0 | Trojan.Win32.Generic!BT | |||
| 38 |
![]() |
0xf14168937db12f0c3ce99725241b6300 | ![]() |
No Data | ![]() |
0 | 0 | 0 | Trojan.Win32.Generic!BT | |||
| 39 |
![]() |
0xbcf777e3af77d378d318b0c5c373493c | ![]() |
No Data | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 40 |
![]() |
0x54cb01b41fe219d365d70a813f8611a5 | ![]() |
No Data | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 41 |
![]() |
0x6ddb3f336aceb6596a34092af3aa9ea1 | ![]() |
No Data | ![]() |
0 | 0 | 0 | Virus.Win32.Bamital.c (v) | |||
| 42 |
![]() |
0x0bf4d1321a1e6e43234e390ff4f7aa00 | ![]() |
No Data | ![]() |
0 | 0 | 0 | Trojan.Win32.Generic!BT | |||
| 43 |
![]() |
0x6e0d1466f9a1e7b826484bb1531ff0d5 | ![]() |
No Data | ![]() |
0 | 0 | 0 | Trojan.Win32.Generic!BT | |||
| 44 |
![]() |
0xe75e3bd7c1f2ef823e27ef9a78c7c7fe | ![]() |
No Data | ![]() |
0 | 0 | 0 | VirTool.Win32.Obfuscator.hg!a (v) | |||
| 45 |
![]() |
0x481addbb21037489eacfcb308b1be2b0 | ![]() |
No Data | ![]() |
0 | 0 | 0 | Trojan-Downloader.Win32.Small | |||
| 46 |
![]() |
0x3960138ca598e375970022fee32b94ef | ![]() |
No Data | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 47 |
![]() |
0x5d14f6bf681f261ffaa7ab81321f36a4 | ![]() |
No Data | ![]() |
0 | 0 | 0 | Trojan.Win32.Generic!BT | |||
| 48 |
![]() |
0xbba8a0ee4bd5dd7a636810a73e281932 | ![]() |
No Data | ![]() |
0 | 0 | 0 | Virus.Win32.Bamital.d (v) | |||
| 49 |
![]() |
0x2703edf6ba181a933d1d4e0f946615ff | ![]() |
No Data | ![]() |
0 | 0 | 0 | Virus.Win32.Bamital.d (v) | |||
| 50 |
![]() |
0x96c09715d7d5d423ab8c012828714542 | ![]() |
No Data | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 51 |
![]() |
0x77b8445eb46ed55d18bffaaa907ba9e5 | ![]() |
No Data | ![]() |
0 | 0 | 0 | Trojan.Win32.Generic!BT | |||
| 52 |
![]() |
0x990902c450c517cfcc63e158237bbe1d | ![]() |
No Data | ![]() |
0 | 0 | 0 | Trojan.Win32.Generic!BT | |||
| 53 |
![]() |
0x62076ebac75f9531c202a19e199a16bf | ![]() |
No Data | ![]() |
0 | 0 | 0 | Trojan.Win32.Ertfor.B.1 (v) | |||
| 54 |
![]() |
0x9b0e23d54a5c9df7a782bc9bd47c4744 | ![]() |
No Data | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 55 |
![]() |
0xd8f6289defcef8ddbc36511485169548 | ![]() |
No Data | ![]() |
0 | 0 | 0 | Not Applicable | |||
| 56 |
![]() |
0x394709f8be53f80195e895c637526d21 | ![]() |
No Data | ![]() |
0 | 0 | 0 | BehavesLike.Win32.Malware.bsm (vs) | |||
MD5 Hashes
|
|||||||||
|---|---|---|---|---|---|---|---|---|---|
| # | Status | MD5 | Last Seen | File Date | Revision | Common Name | Size | ||
| 1 |
![]() |
0x6680494e2c930e2c6ecebe4617f963ce | 4/26/2013 6:33:00 AM | Unknown | Unknown | Legitimate WinLogon | 546 KB | ||
| 2 |
![]() |
0xa739b89e6f01ed5790443268ee7146c4 | 3/16/2013 8:26:00 PM | Unknown | Unknown | Legitimate WinLogon | 496 KB | ||
| 3 |
![]() |
0x6f98c48fd363309cb6b0ad65ae273106 | 10/24/2012 11:23:00 AM | Unknown | Unknown | Legitimate WinLogon | 1038 KB | ||
| 4 |
![]() |
0x0c710ef2b4b53c4391d80156fec2e857 | 9/9/2012 4:15:00 PM | Unknown | Unknown | Legitimate WinLogon | 496 KB | ||
| 5 |
![]() |
0xb3cec9f08de6612d9ba73bb85cc5883f | 7/28/2012 7:27:00 AM | Unknown | Unknown | Legitimate WinLogon | 498 KB | ||
| 6 |
![]() |
0x0b475c7090f1fa3679d9e4c5518b8a49 | 7/11/2012 10:15:00 AM | Unknown | Unknown | Legitimate WinLogon | 531 KB | ||
| 7 |
![]() |
0x875efe3433dd48670650abcb49991f08 | 7/7/2012 2:40:00 PM | Unknown | Unknown | Legitimate WinLogon | 532 KB | ||
| 8 |
![]() |
0x6e7f0d28074ed5ee4c326e18f0686d87 | 4/28/2012 10:24:00 PM | Unknown | Unknown | Legitimate WinLogon | 496 KB | ||
| 9 |
![]() |
0x7fe905c35931a3ccd9ef44b1a36eb304 | 4/25/2012 3:40:00 PM | Unknown | Unknown | Legitimate WinLogon | 526 KB | ||
| 10 |
![]() |
0x65be8ef628e9f247e0226486f4426545 | 4/22/2012 10:00:00 PM | Unknown | Unknown | Legitimate WinLogon | 496 KB | ||
| 11 |
![]() |
0x4525aafec2773000ed9688123826d648 | 4/5/2012 11:18:00 AM | Unknown | Unknown | Legitimate WinLogon | 495 KB | ||
| 12 |
![]() |
0xdec033ad465c0f3fac326665c8d07c4c | 3/25/2012 7:42:00 PM | Unknown | Unknown | Legitimate WinLogon | 490 KB | ||
| 13 |
![]() |
0xab697a36259aa31eadeec075b5b388ae | 3/5/2012 10:25:00 AM | Unknown | Unknown | Legitimate WinLogon | 483 KB | ||
| 14 |
![]() |
0x1fcd53dde73cfef8901a03ba5afbc01e | 2/25/2012 2:00:00 PM | Unknown | Unknown | Legitimate WinLogon | 177 KB | ||
| 15 |
![]() |
0x947e0e5d86f22499d4d4193453dbc115 | 2/8/2012 4:06:00 PM | Unknown | Unknown | Legitimate WinLogon | 532 KB | ||
| 16 |
![]() |
0xed0ef0a136dec83df69f04118870003e | 2/8/2012 4:56:00 AM | Unknown | Unknown | Legitimate WinLogon | 496 KB | ||
| 17 |
![]() |
0xb4aa8ae0f18e5dfcf99a671a181d3edc | 2/8/2012 4:25:00 AM | Unknown | Unknown | Legitimate WinLogon | 516 KB | ||
| 18 |
![]() |
0x53a8857723277b1d6d5ee60a9f85b117 | 2/8/2012 3:52:00 AM | Unknown | Unknown | Legitimate WinLogon | 497 KB | ||
| 19 |
![]() |
0xea16f83b5e4964c100f6098ce9874927 | 2/8/2012 3:38:00 AM | Unknown | Unknown | Legitimate WinLogon | 491 KB | ||
| 20 |
![]() |
0xa55b8899d2ea2e800061bcfd456e34dc | 2/8/2012 3:07:00 AM | Unknown | Unknown | Legitimate WinLogon | 534 KB | ||
| 21 |
![]() |
0x57021a062c8e266c0a2a636450364b43 | 2/8/2012 2:58:00 AM | Unknown | Unknown | Legitimate WinLogon | 496 KB | ||
| 22 |
![]() |
0x01c3346c241652f43aed8e2149881bfe | 2/8/2012 2:53:00 AM | Unknown | Unknown | Legitimate WinLogon | 490 KB | ||
| 23 |
![]() |
0xd1bac55bc35a0ca735aea19f609f2b22 | 2/8/2012 2:20:00 AM | Unknown | Unknown | Legitimate WinLogon | 496 KB | ||
| 24 |
![]() |
0xdd73d6b9f6b4cb630cf35b438b540174 | 2/8/2012 12:14:00 AM | Unknown | Unknown | Legitimate WinLogon | 500 KB | ||
| 25 |
![]() |
0x6e8ca4fcb30282f216f5db9dd58a5f81 | 2/7/2012 8:47:00 PM | Unknown | Unknown | Legitimate WinLogon | 490 KB | ||
MD5 Hashes
|
|||||||||
|---|---|---|---|---|---|---|---|---|---|
| # | Status | MD5 | Last Seen | File Date | Revision | Common Name | Size | ||
| 1 |
![]() |
0x9ee60f627770428367028e7cf5367f6d | 4/3/2013 3:34:00 PM | Unknown | Unknown | WinLogon trojan | 79 KB | ||
| 2 |
![]() |
0x54cb01b41fe219d365d70a813f8611a5 | 8/1/2012 1:54:00 PM | Unknown | Unknown | WinLogon trojan | 50 KB | ||
| 3 |
![]() |
0xef44b817dceb4c3bfd21fd3d08b5d28d | 2/8/2012 4:20:00 AM | Unknown | Unknown | WinLogon trojan | 41 KB | ||
| 4 |
![]() |
0x9622d732b1b8c643f8ca8e20bbfc7129 | 10/27/2011 10:02:00 AM | Unknown | Unknown | WinLogon trojan | 298 KB | ||
| 5 |
![]() |
0xa4895d25e316051a20ce3e27bb5faa93 | 9/9/2011 4:57:00 AM | Unknown | Unknown | WinLogon trojan | 97 KB | ||
| 6 |
![]() |
0xf2cb18f01d5a9ca313dbf3e5fd286c8d | 9/9/2011 4:57:00 AM | Unknown | Unknown | WinLogon trojan | 46 KB | ||
| 7 |
![]() |
0x2152217bd031166b0c969a8cd23ed41f | 8/31/2011 1:46:00 PM | Unknown | Unknown | WinLogon trojan | 44 KB | ||
| 8 |
![]() |
0x97a82153c30bb73ee26c4e2cbcd977f5 | 8/23/2011 11:52:00 PM | Unknown | Unknown | WinLogon trojan | 105 KB | ||
| 9 |
![]() |
0xab2c1a97c4a949bd9ffe6f87114865e2 | 8/21/2011 11:38:00 PM | Unknown | Unknown | WinLogon trojan | 39 KB | ||
| 10 |
![]() |
0x19a433c37ae624147d30b9014c4b4ba7 | 8/3/2011 | Unknown | Unknown | WinLogon trojan | 680 KB | ||
| 11 |
![]() |
0x84d38450b159b7d78291804acf3e2c1f | 6/23/2011 10:38:00 PM | Unknown | Unknown | WinLogon trojan | 3055 KB | ||
| 12 |
![]() |
0x0bea50a919cc7676c80a4c88e5e82b45 | 4/3/2011 3:16:00 PM | Unknown | Unknown | WinLogon trojan | 108 KB | ||
| 13 |
![]() |
0xc51a426d90af0cdcb97c10bb4ea12696 | 3/19/2011 11:20:00 PM | Unknown | WinLogon trojan | 41 KB | |||
| 14 |
![]() |
0x8cab7b161d8472b753f0872672bbf30e | 3/3/2011 2:13:00 PM | Unknown | Unknown | WinLogon trojan | 532 KB | ||
| 15 |
![]() |
0xbdfc1f8d2b43a9e5cc1130b8188a3ab4 | 1/22/2011 2:36:00 AM | Unknown | Unknown | WinLogon trojan | 109 KB | ||
| 16 |
![]() |
0x83720b921ee79a6397caf8c548ff7c59 | 12/31/2010 5:26:00 PM | Unknown | Unknown | WinLogon trojan | 124 KB | ||
| 17 |
![]() |
0xb6d86545f6d07c059edfcfbf6e7e2bb1 | 11/9/2010 11:43:00 PM | Unknown | Unknown | WinLogon trojan | 156 KB | ||
| 18 |
![]() |
0x52953ecb71ee81b90aaee2936d4caa6b | 11/8/2010 7:15:00 PM | Unknown | Unknown | WinLogon trojan | 406 KB | ||
| 19 |
![]() |
0x9235cc9dc7452927f5c08e89b6802cd1 | 10/2/2010 11:29:00 PM | Unknown | Unknown | WinLogon trojan | 97 KB | ||
| 20 |
![]() |
0x8cce0e5c1aa18e4aec3aa09817e726cb | 9/12/2010 8:14:00 AM | Unknown | Unknown | WinLogon trojan | 144 KB | ||
| 21 |
![]() |
0x1f7636dc8948a5031be90d0ba36696c0 | 8/30/2010 9:31:00 PM | Unknown | Unknown | WinLogon trojan | 95 KB | ||
| 22 |
![]() |
0xcf4e8198665877663f9cc66f0ee9253b | 8/25/2010 12:37:00 AM | Unknown | Unknown | WinLogon trojan | 28 KB | ||
| 23 |
![]() |
0x2ca72990fe8f0c214603d138b51d217d | 8/6/2010 11:44:00 PM | Unknown | Unknown | WinLogon trojan | 44 KB | ||
| 24 |
![]() |
0xdbf57eb92b2d11902fc35c9e1fe5b849 | 6/28/2010 10:02:00 AM | Unknown | Unknown | WinLogon trojan | 19 KB | ||
| 25 |
![]() |
0x329c68136b5a1101f3faa370f1774e7f | 6/26/2010 7:19:00 PM | Unknown | Unknown | WinLogon trojan | 175 KB | ||
PC Pitstop is the undisputed leader in PC diagnostics. Our running process library is culled from our database of over 100 million PC diagnostics and scans.
› Driver ScanA file name alone may not be enough for positive identification. PC Pitstop's Overdrive tests and spyware scan use information such as the company name, product name, or install directory.
If you are unable to identify a file, ask about it in our forums after running our full tests.