PC Pitstop is the undisputed leader in PC diagnostics. Our running process library is culled from our database of over 100 million PC diagnostics and scans.

Tip from the PitCrew

Every process running on your computer takes up CPU cycles and valuable memory. For optimal PC performance and resource utilization, you should be aware of every process on your computer. PC Pitstop designed this process library to help you know which processes are worthwhile and others that slow system performance.

Furthermore, perhaps the quickest and most straight forward method to detect malware is through a running process analysis.

Process Library

  

More than one possible match was found; all matches are listed below in order of their prevalence. This only tells you what the file and the correct action might be.

To understand which possibility is actually running on your own system, perform an Overdrive test and then look at the Software|Processes tab.


Match #1

winlogon.exe (Legitimate WinLogon)

Percentage of recently scanned PC's with this process running: 38.45%
Average CPU use for this program: 0%
Average RAM for this program: 4 MB


PC Pitstop Analysis

winlogon.exe - This program initializes some functions of Windows each time a user logs in. Usually it should not appear in running programs because it completes its work in less than a minute. If it is still running then there may be some type of configuration problem with your system. See the detailed description for troubleshooting information.


Recommendation

Win Patrol

winlogon.exe is a user invoked program and a normal part of PC operations. No action required.

PC Pitstop recommends WinPatrol Plus for monitoring all of the background activity on your PC. WinPatrol Plus provides a easy to understand descriptions of over 15,000 processes and programs.



Identification

In addition to the file name, winlogon.exe, the following version information is used to identify the file. If the file does not match this information, it may be a different file. To ensure the file is absolutely correct, run a free and comprehensive scan.

Vendor contains:Microsoft
Product contains:Windows
File name contains:\system32

To view version information with Windows Explorer, right-click the file and click Properties, Version.


MD5 Hashes

MD5 hashes is the way that computers can define the uniqueness of a file. Anti malware vendors frequently use this technique to detect and clean malware. It is common for a program to have multiple MD5 hashes as the developers create newer versions of the program. For the program called winlogon.exe, we have detected more than 20 different MD5 hashes. Click on a hash to research the hash in Google.
MD5 Report Summary
Program NameMD5 Count
winlogon.exe> 20
#MD5Size
10x4166454e2bcfcc20d1b8a5ac9feab243504832 bytes
20xdb847557f28b6ea1ec14bfbe5b4ff966314368 bytes
30xc2610b6bdbefc053bbdab4f1b965cb24314880 bytes
40xd52005f80e99d3853e5629b8c4b2dc9e308224 bytes
50xc6033ad39b14f015a5144129cc2363e9313344 bytes
60x85c0d6bd769aab1b007b21cca9a346c8177424 bytes
70x9f75392b9128a91abafb044ea350baad308224 bytes
80x41cdd395dfbb291baa896deb4b6d8c65314880 bytes
90xd1280608c54100184ea52ed9de88522a12288 bytes
100x91d002284a0e826a92a13bec9e6374f5162816 bytes
110xbb1daf6a5737652646d52665251a0265186640 bytes
120x513319e00583211c2f500b20754bc78a416768 bytes
130x01c3346c241652f43aed8e2149881bfe502272 bytes
140x6103e3d493819df8fab6cc026aad136c314368 bytes
150xece76f6d06dc50cfcf990cd7ed47942f308224 bytes
160xfcb59d25d628b4d3181dc816d14679dd505344 bytes
170xfd46b348fca32a1987b9a32b6ba81d2e504832 bytes
180xa3fea6ed9fd3cf07219a632e4a716226308224 bytes
190xed0ef0a136dec83df69f04118870003e507904 bytes
200x213c80d912880bbf04453d09ffccb28c510976 bytes

PC Pitstop Database Comparisons

Every week, we update our information about the running programs identified during the previous week's testing. winlogon.exe (Legitimate WinLogon) has been seen on 38.45% of systems tested at PC Pitstop. As a point of comparison, it is rare for a particular malicious program (virus or spyware) to be seen on more than one or two percent of all systems tested. The average RAM memory usage for this process was 4 MB. The average CPU load for this program was 0%.


Detailed Description and/or Removal Instructions

http://www.google.com/search?q=winlogon+site%3Asupport.microsoft.com


Match #2

winlogon.exe (WinLogon trojan)

Percentage of recently scanned PC's with this process running: 0.02%
Average CPU use for this program: 0%
Average RAM for this program: 3 MB


PC Pitstop Analysis

winlogon.exe file name used by the WinLogon trojan has the same name as a legitimate Microsoft file. However, the trojan can be identified by these traits: it does not contain vendor/product information saying it is from Microsoft; it is installed in a directory other than Windows system32; it is always running and often uses large amounts of memory and cpu time. If the file information does not show the vendor being Microsoft, then this is most likely the WinLogon trojan.


Recommendation

CA AntiVirus

winlogon.exe is a VIRUS. Stop all work until the virus is removed or you run the risk of spreading the virus to other people. Worse yet, the virus may be doing harm to your computer and your information.

winlogon.exe is a virus and should be removed immediately to avoid doing further harm. PC Pitstop recommends CA Antivirus in these types of situations.



Identification

The file name alone identifies this program.


MD5 Hashes

MD5 hashes is the way that computers can define the uniqueness of a file. Anti malware vendors frequently use this technique to detect and clean malware. It is common for a program to have multiple MD5 hashes as the developers create newer versions of the program. For the program called winlogon.exe, we have detected more than 20 different MD5 hashes. Click on a hash to research the hash in Google.
MD5 Report Summary
Program NameMD5 Count
winlogon.exe> 20
#MD5Size
10x9f472b33711035a5174f4f7f2ea5398f42675 bytes
20xff5cc85b80cc9ac826e7e54c83fd6e1943008 bytes
30x52953ecb71ee81b90aaee2936d4caa6b416241 bytes
40xb6d86545f6d07c059edfcfbf6e7e2bb1159744 bytes
50x5a1e3b99e00dd5df99cc316ecfff5fb941385 bytes
60x7f1ab5d388af649e2c6ef32bf698edca42638 bytes
70xdbf57eb92b2d11902fc35c9e1fe5b84920000 bytes
80x1218c2020437e80c69878201330afd4512288 bytes
90xa042ec98487ca36544b4281c80a1a4a243476 bytes
100x834a7ee4425fb9f1eae3092fee886e4c91136 bytes
110xb524995de3a3a7fc987ce779cef59ff2159744 bytes
120x14cd92ade7a40a70f5004bf2f0c2d83142669 bytes
130x5d497602fa5333e3aa5be02b634268d6109056 bytes
140x8ee669ac26dbe34e5c5bd59f73fc2d84111616 bytes
150xe65b9179a1a18ca163baedc2be3f158a45508 bytes
160x12c2d46ee1e9231116a183607e4487b691136 bytes
170xee4a12519daf4c9e148e3b61aafca8c744453 bytes
180x5a6cd4bda85793bb752f48e1bae1764442698 bytes
190x435e8cf80df80af88848d4d9d905c690155648 bytes
200x3fa6c6a8f625f9e56fa2f38e6487beaf39424 bytes

PC Pitstop Database Comparisons

Every week, we update our information about the running programs identified during the previous week's testing. winlogon.exe (WinLogon trojan) has been seen on 0.02% of systems tested at PC Pitstop. As a point of comparison, it is rare for a particular malicious program (virus or spyware) to be seen on more than one or two percent of all systems tested. The average RAM memory usage for this process was 3 MB. The average CPU load for this program was 0%.


Detailed Description and/or Removal Instructions

http://www.pestpatrol.com/pestinfo/w/winlogonexe.asp

Important note: A file name alone may not be enough for positive identification. PC Pitstop's Overdrive tests and spyware scan use information such as the company name, product name, or install directory. If you are unable to identify a file, ask about it in our forums after running our full tests.