Home How it works Support Boost Connect Download

Boost Connect

Uncovering the DNA of programs.
Good programs    
1
6
7
,
7
9
6
 
Fair programs  
0
1
1
,
1
2
0
 
Bad programs 
0
0
4
,
2
7
7

What is winlogon.exe?

Part of Windows Logon Application by Microsoft

What is it?

Winlogon is the component of Windows that is responsible for handling the secure attention sequence, loading the user profile on logon, and optionally locking the computer when a screensaver is running (requiring another authentication step).
Description of winlogon.exe from Microsoft
Winlogon handles interface functions that are independent of authentication policy. It creates the desktops for the window station, implements time-out operations, and provides a set of support functions for the GINA. When Winlogon is in the logged-off state, users are prompted to identify themselves and provide authentication information. If a user provides correct user account information and no restrictions prevent it, the user is logged on and a shell program (such as Windows Explorer) is ex
(winlogon.exe is a system file that is installed with Windows)
Download Boost (100% FREE) Speed up Windows Logon Application and optimize your PC.

How does winlogon.exe run?

Process - winlogon.exe is an instance of a running program. This program executes under the SYSTEM account within Windows with extensive privileges on the local computer, and acts as the computer on the network.

Community

What is the community is seeing?What is the community is doing?
About 0.4% of all Boost users have the winlogon.exe process running.Of the 0.4% of winlogon.exe users, less than 1% have disabled it.
How resource intensive is winlogon.exe?
Comparison based on the average resource utilization across all programs.
0.00086% CPU8640.3%
Average CPU utilization across all programs is 0.00001%.
     1.28 MB RAM6.0%
Average private memory utilization across all programs is 21.53 MB.
 1 /min0.0%
Average I/O read and write operations for all programs is 2,253 per minute.
         6 GDI objects4.0%
Average number of GUI GDI and USER objects for all programs is 150.
Typical file (disk image) location:
C:\Windows\System32\winlogon.exe

Are there other versions of Windows Logon Application?

What else is related?

What Windows OS versions does this run on?

Windows 8 (6.2.9200.0)
Windows 8 Enterprise (6.2.9200.0)

About Microsoft Corporation

Microsoft, founded in 1975 by Bill Gates and Paul Allen, is a veteran software company, best known for its Microsoft Windows operating system and the Microsoft More...
Download Boost

File details

File name: winlogon.exe
Publisher: Microsoft Corporation (verified)
Name: Windows Logon Application
Description: Microsoft® Windows® Operating System
Version: 6.2.9200.16384 (win8_rtm.120725-1247)
Product version: 6.2.9200.16384
Size: 564.5 KB
Original file name: WINLOGON.EXE.MUI
Windows file protection: Yes

Resource utilization

CPU utilization averages
Total CPU: 0.0039514222%
Privileged CPU: 0.0030873961%
User CPU: 0.00086402615078%
Privileged CPU time: 182.17 ms
Privileged CPU time /min: 6 ms
CPU cycle count: 453,623,341
CPU cycle count /min: 17,938,753
Memory utilization averages
Committed memory: 55.85 MB
Peak committed memory: 64.13 MB
Paged memory: 1.28 MB
Peak paged memory: 3.38 MB
Paged system memory: 114.07 KB
Non-paged system memory: 7.79 KB
Working set memory: 9.94 MB
Peak working set memory: 16.94 MB
Min working set memory: 9.91 MB
Private memory: 1.28 MB
Page faults: 7,372
Page faults /min: 394
Process I/O averages
Total read operations: 5
Read operations /min: 1
Total read transfer: 486.94 KB
Read transfer /min: 28.43 KB
Total other operations: 2,261
Other operations /min: 211
Total other transfer: 490.03 KB
Other Transfer /min: 29.37 KB
GUI Object Averages
GDI objects: 6
Peak GDI objects: 59
Peak USER objects: 19
Resources
Handle count average: 144
Thread count average: 3
Thread resource averages
ntdll.dll

Process details

Runs as (owner): System
Integrety level: System
Windows platform: 64-bit
Child Process
Process Commands
winlogon.exe
C:\Windows\System32\WinLogon.exe -SpecialSession

Network connectivity

Windows Firewall allowed program: Yes

Image hashes

MD5: 75dd70a14145499c9f7d903cf9a8c91b
SHA-1: 77ec136b24adb07d8a44b1c81fcc5ce49ee90134

PE image details

Langauge*: Microsoft Visual C++
File entropy: 6.33818
File packed: No
Import Table
advapi32.dll
api-ms-win-base-bootconfig-l1-1-0.dll
api-ms-win-core-apiquery-l1-1-0.dll
api-ms-win-core-appcompat-l1-1-1.dll
api-ms-win-core-datetime-l1-1-1.dll
api-ms-win-core-debug-l1-1-1.dll
api-ms-win-core-delayload-l1-1-1.dll
api-ms-win-core-errorhandling-l1-1-0.dll
api-ms-win-core-errorhandling-l1-1-1.dll
api-ms-win-core-file-l1-1-1.dll
api-ms-win-core-file-l1-2-0.dll
api-ms-win-core-file-l1-2-1.dll
api-ms-win-core-file-l2-1-0.dll
api-ms-win-core-file-l2-1-1.dll
api-ms-win-core-handle-l1-1-0.dll
api-ms-win-core-heap-l1-1-0.dll
api-ms-win-core-heap-l1-2-0.dll
api-ms-win-core-heap-obsolete-l1-1-0.dll
api-ms-win-core-interlocked-l1-1-0.dll
api-ms-win-core-interlocked-l1-1-1.dll
api-ms-win-core-interlocked-l1-2-0.dll
api-ms-win-core-job-l2-1-0.dll
api-ms-win-core-kernel32-legacy-l1-1-1.dll
api-ms-win-core-libraryloader-l1-1-1.dll
api-ms-win-core-localization-l1-1-1.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-1.dll
api-ms-win-core-localregistry-l1-1-0.dll
api-ms-win-core-memory-l1-1-1.dll
api-ms-win-core-memory-l1-1-2.dll
api-ms-win-core-processenvironment-l1-1-0.dll
api-ms-win-core-processenvironment-l1-1-1.dll
api-ms-win-core-processenvironment-l1-2-0.dll
api-ms-win-core-processthreads-l1-1-1.dll
api-ms-win-core-processthreads-l1-1-2.dll
api-ms-win-core-profile-l1-1-0.dll
api-ms-win-core-psapi-l1-1-0.dll
api-ms-win-core-registry-l1-1-0.dll
api-ms-win-core-shutdown-l1-1-1.dll
api-ms-win-core-string-l1-1-0.dll
api-ms-win-core-string-obsolete-l1-1-0.dll
api-ms-win-core-synch-l1-1-1.dll
api-ms-win-core-synch-l1-2-0.dll
api-ms-win-core-sysinfo-l1-1-1.dll
api-ms-win-core-sysinfo-l1-2-0.dll
api-ms-win-core-sysinfo-l1-2-1.dll
api-ms-win-core-threadpool-l1-1-1.dll
api-ms-win-core-threadpool-l1-2-0.dll
api-ms-win-core-threadpool-legacy-l1-1-0.dll
api-ms-win-core-timezone-l1-1-0.dll
api-ms-win-core-wow64-l1-1-0.dll
api-ms-win-eventing-classicprovider-l1-1-0.dll
api-ms-win-eventing-controller-l1-1-0.dll
api-ms-win-eventlog-legacy-l1-1-0.dll
api-ms-win-obsolete-kernelbase-l1-1-0.dll
api-ms-win-power-base-l1-1-0.dll
api-ms-win-power-setting-l1-1-0.dll
api-ms-win-security-base-l1-1-0.dll
api-ms-win-security-base-l1-2-0.dll
api-ms-win-security-credentials-l1-1-0.dll
api-ms-win-security-credentials-l2-1-0.dll
api-ms-win-security-lsalookup-l1-1-1.dll
api-ms-win-security-lsalookup-l2-1-0.dll
api-ms-win-security-lsalookup-l2-1-1.dll
api-ms-win-security-lsapolicy-l1-1-0.dll
api-ms-win-service-management-l1-1-0.dll
api-ms-win-service-management-l2-1-0.dll
api-ms-win-service-winsvc-l1-2-0.dll
kernel32.dll
msvcrt.dll
ntdll.dll
powrprof.dll
psapi.dll
rpcrt4.dll
samcli.dll
secur32.dll
user32.dll
userenv.dll
winsta.dll
wtsapi32.dll
Stay up to date with news about Boost
Subscribe to our newsletter to receive the latest Boost news and discounts.
 
© 2016 Reason Software Company Inc.
228 Park Ave S #74122 New York, NY 10003
(646) 664-1038 | info@boostbyreason.com
How it works Privacy Terms Support Contact Download Donate Reason Software, the makers of Boost logo

Download Boost and enjoy your PC.

Increase your PC's performance.
Remove unwanted crapware.
Reduce your boot time.
Identify and resolves crashes.
Download the FREE unlimited trial of Boost!
No spyware, no adware, no bundles, no tricks.
Download

Save 40% on Boost

For a limited time, from now until Friday, December 9, 2016 you can purchase Boost for 40% off of the normal price, only $39.95 $24.95.
The instant online savings will be automatically applied during checkout.
 

100% Satisfaction Guarantee

Purchase with confidence. We stand behind Boost.
If for any reason you are not satisfied with your software purchase, simply contact our Customer Support within 30 days, and we'll refund the purchase price. We won't make you jump through hoops to get all your money back!