Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.16384 (winblue_rtm.130821-1623) 1.61%
6.3.9600.16384 (winblue_rtm.130821-1623) 2.62%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.21%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.04%
6.2.9200.16384 (win8_rtm.120725-1247) 0.72%
6.2.9200.16384 (win8_rtm.120725-1247) 0.55%
6.2.9200.16384 (win8_rtm.120725-1247) 0.13%
6.2.9200.16384 (win8_rtm.120725-1247) 11.20%
6.2.9200.16384 (win8_rtm.120725-1247) 1.39%
6.2.9200.16384 (win8_rtm.120725-1247) 0.72%
6.2.9200.16384 (win8_rtm.120725-1247) 0.38%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.08%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.08%
6.2.8250.0 (winmain_win8beta.120217-1520) 0.04%
6.2.8102.0 (winmain_win8m3.110823-1455) 0.08%
6.1.7601.17514 (win7sp1_rtm.101119-1850) 31.69%
6.1.7601.17514 (win7sp1_rtm.101119-1850) 16.43%
6.1.7601.17514 (win7sp1_rtm.101119-1850) 0.08%
6.1.7601.17514 (win7sp1_rtm.101119-1850) 0.04%
6.1.7601.17514 (win7sp1_rtm.101119-1850) 0.04%
6.1.7601.17514 (win7sp1_rtm.101119-1850) 0.04%
6.1.7601.17514 (win7sp1_rtm.101119-1850) 0.04%
6.1.7601.17514 (win7sp1_rtm.101119-1850) 0.08%
6.1.7600.16385 (win7_rtm.090713-1255) 2.79%
6.1.7600.16385 (win7_rtm.090713-1255) 2.28%
View more

Relationships

Parent process
Child processes
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
TraceMessage, EventWrite, EventEnabled, InitiateShutdownW, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, QueryTraceW, EnableTrace, ControlTraceW, StartTraceW, GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, RegisterTraceGuidsW, UnregisterTraceGuids, RegDeleteValueW, EventRegister, EventUnregister, EventWriteEndScenario, EventWriteStartScenario, EventActivityIdControl, RegEnumValueW, RegQueryInfoKeyW, RegSetValueExW, RegOpenKeyW, GetTokenInformation, OpenProcessToken, ConvertStringSidToSidW, LsaFreeMemory, LsaGetUserName, RevertToSelf, ImpersonateLoggedOnUser, CloseEventLog, GetEventLogInformation, OpenEventLogW, RegisterEventSourceW, DeregisterEventSource, LsaNtStatusToWinError, RegCreateKeyExW, CheckTokenMembership, DuplicateTokenEx, ConvertSidToStringSidW, CreateProcessAsUserW, AllocateLocallyUniqueId, ReportEventW, LogonUserW, RegSetKeySecurity, RegDeleteKeyW, RegGetValueA, EqualSid, CredFree, NotifyServiceStatusChangeW, NotifyBootConfigStatus, CreateWellKnownSid, LookupAccountSidW, RegDeleteTreeW, OpenSCManagerW, RegEnumKeyExW, CloseServiceHandle, OpenServiceW, QueryServiceConfigW, QueryServiceStatus, MD5Init, MD5Update, MD5Final, CredReadByTokenHandle, CheckForHiberboot, LsaOpenPolicy, LsaAddPrivilegesToAccount, LsaCreateAccount, LsaOpenAccount, LsaClose, LookupAccountNameW, LsaSetSystemAccessAccount
api-ms-win-base-bootconfig-l1-1-0.dll
NotifyBootConfigStatus
api-ms-win-core-apiquery-l1-1-0.dll
ApiSetQueryApiSetPresence
api-ms-win-core-appcompat-l1-1-1.dll
BaseInitAppcompatCacheSupport
api-ms-win-core-datetime-l1-1-1.dll
GetTimeFormatW, GetDateFormatW
api-ms-win-core-debug-l1-1-1.dll
DebugBreak, IsDebuggerPresent
api-ms-win-core-delayload-l1-1-1.dll
DelayLoadFailureHook, ResolveDelayLoadedAPI
api-ms-win-core-errorhandling-l1-1-0.dll
UnhandledExceptionFilter, SetLastError, SetErrorMode, SetUnhandledExceptionFilter, GetLastError
api-ms-win-core-errorhandling-l1-1-1.dll
SetUnhandledExceptionFilter, SetErrorMode, GetLastError, UnhandledExceptionFilter, SetLastError
api-ms-win-core-file-l1-1-1.dll
FileTimeToSystemTime, CompareFileTime, ReadFile, CreateFileW, GetShortPathNameW, GetFileAttributesW
api-ms-win-core-file-l1-2-0.dll
ReadFile, GetShortPathNameW, CompareFileTime, GetFileAttributesW, CreateFileW
api-ms-win-core-file-l1-2-1.dll
GetFileAttributesW, CreateFileW, CompareFileTime, GetShortPathNameW, ReadFile
api-ms-win-core-file-l2-1-0.dll
MoveFileExW
api-ms-win-core-file-l2-1-1.dll
MoveFileExW
api-ms-win-core-handle-l1-1-0.dll
CloseHandle, DuplicateHandle
api-ms-win-core-heap-l1-1-0.dll
HeapSize, HeapFree, GetProcessHeap, HeapAlloc, HeapSetInformation
api-ms-win-core-heap-l1-2-0.dll
GetProcessHeap, HeapSize, HeapFree, HeapSetInformation, HeapAlloc
api-ms-win-core-heap-obsolete-l1-1-0.dll
LocalReAlloc, LocalSize, LocalFree, LocalAlloc
api-ms-win-core-interlocked-l1-1-0.dll
InterlockedCompareExchange, InterlockedDecrement, InterlockedIncrement, InterlockedExchange
api-ms-win-core-interlocked-l1-1-1.dll
InterlockedExchange, InterlockedDecrement, InterlockedCompareExchange, InterlockedIncrement
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedExchange, InterlockedIncrement, InterlockedDecrement, InterlockedCompareExchange
api-ms-win-core-job-l2-1-0.dll
QueryInformationJobObject, TerminateJobObject, AssignProcessToJobObject, CreateJobObjectW, SetInformationJobObject
api-ms-win-core-kernel32-legacy-l1-1-1.dll
GetComputerNameW, RegisterWaitForSingleObject, UnregisterWait, GetStartupInfoA
api-ms-win-core-libraryloader-l1-1-1.dll
LoadLibraryExW, GetModuleHandleA, FindResourceExW, GetProcAddress, FreeLibrary, LoadResource, LockResource, GetModuleHandleW, GetModuleFileNameW, LoadStringW
api-ms-win-core-localization-l1-1-1.dll
FormatMessageW, GetThreadUILanguage
api-ms-win-core-localization-l1-2-0.dll
FormatMessageW, GetThreadUILanguage
api-ms-win-core-localization-l1-2-1.dll
FormatMessageW, GetThreadUILanguage
api-ms-win-core-localregistry-l1-1-0.dll
RegCloseKey, RegOpenKeyExW, RegDeleteValueW, RegEnumValueW, RegQueryInfoKeyW, RegSetValueExW, RegCreateKeyExW, RegSetKeySecurity, RegDeleteKeyExW, RegQueryValueExW
api-ms-win-core-memory-l1-1-1.dll
VirtualAlloc, VirtualUnlock, VirtualLock, VirtualFree
api-ms-win-core-memory-l1-1-2.dll
VirtualAlloc, VirtualFree, VirtualLock, VirtualUnlock, GetProcessWorkingSetSizeEx, SetProcessWorkingSetSizeEx
api-ms-win-core-processenvironment-l1-1-0.dll
SearchPathW, ExpandEnvironmentStringsW, GetCommandLineW, SetEnvironmentVariableW
api-ms-win-core-processenvironment-l1-1-1.dll
SetEnvironmentVariableW, ExpandEnvironmentStringsW, SearchPathW, GetCommandLineW
api-ms-win-core-processenvironment-l1-2-0.dll
SearchPathW, GetCommandLineW, SetEnvironmentVariableW, ExpandEnvironmentStringsW
api-ms-win-core-processthreads-l1-1-1.dll
OpenProcessToken, GetProcessTimes, ExitProcess, CreateThread, GetCurrentProcessId, SetThreadToken, GetCurrentThreadId, CreateRemoteThread, GetExitCodeProcess, CreateProcessW, CreateProcessAsUserW, ResumeThread, OpenThreadToken, SetPriorityClass, GetCurrentProcess, GetProcessId, TerminateThread, SetThreadPriority, GetCurrentThread, OpenProcess, TerminateProcess, IsProcessorFeaturePresent
api-ms-win-core-processthreads-l1-1-2.dll
TerminateThread, SetPriorityClass, GetCurrentProcess, SetThreadPriority, CreateProcessAsUserW, ResumeThread, OpenThreadToken, ExitProcess, TerminateProcess, GetProcessId, OpenProcess, CreateRemoteThread, GetCurrentThread, GetCurrentThreadId, GetProcessTimes, OpenProcessToken, GetCurrentProcessId, GetExitCodeProcess, CreateProcessW, CreateThread, SetThreadToken
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-psapi-l1-1-0.dll
QueryFullProcessImageNameW
api-ms-win-core-registry-l1-1-0.dll
RegSetKeySecurity, RegFlushKey, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, RegDeleteTreeW, RegQueryInfoKeyW, RegEnumValueW, RegGetValueA, RegEnumKeyExW, RegOpenCurrentUser, RegSetValueExW, RegCreateKeyExW, RegDeleteKeyExW, RegDeleteValueW, RegGetValueW
api-ms-win-core-shutdown-l1-1-1.dll
InitiateShutdownW
api-ms-win-core-string-l1-1-0.dll
CompareStringW, WideCharToMultiByte
api-ms-win-core-string-obsolete-l1-1-0.dll
lstrlenW
api-ms-win-core-synch-l1-1-1.dll
InitializeCriticalSection, LeaveCriticalSection, TryEnterCriticalSection, DeleteCriticalSection, ReleaseSRWLockExclusive, AcquireSRWLockExclusive, ResetEvent, EnterCriticalSection, ReleaseSRWLockShared, InitializeSRWLock, AcquireSRWLockShared, SleepEx, WaitForSingleObject, CreateEventW, SetEvent, OpenEventW, Sleep, WaitForSingleObjectEx
api-ms-win-core-synch-l1-2-0.dll
EnterCriticalSection, DeleteCriticalSection, ResetEvent, LeaveCriticalSection, SleepEx, ReleaseSRWLockExclusive, AcquireSRWLockExclusive, TryEnterCriticalSection, ReleaseSRWLockShared, OpenEventW, WaitForSingleObject, CreateEventW, InitializeSRWLock, SetEvent, WaitForSingleObjectEx, InitializeCriticalSection, AcquireSRWLockShared, Sleep
api-ms-win-core-sysinfo-l1-1-1.dll
GetSystemTimeAsFileTime, GetSystemWindowsDirectoryW, GetSystemDirectoryW, SystemTimeToTzSpecificLocalTime, GetVersionExW, GetTickCount64, GetTickCount
api-ms-win-core-sysinfo-l1-2-0.dll
GetTickCount64, GetVersionExW, GetSystemTimeAsFileTime, GetTickCount, GetSystemWindowsDirectoryW, GetSystemDirectoryW
api-ms-win-core-sysinfo-l1-2-1.dll
GetTickCount, GetSystemDirectoryW, GetTickCount64, GetSystemWindowsDirectoryW, GetVersionExW, GetSystemTimeAsFileTime
api-ms-win-core-threadpool-l1-1-1.dll
CreateTimerQueueTimer, QueueUserWorkItem, UnregisterWaitEx, DeleteTimerQueueTimer
api-ms-win-core-threadpool-l1-2-0.dll
CreateThreadpool, CreateThreadpoolWork, SetThreadpoolThreadMinimum, SetThreadpoolThreadMaximum, SubmitThreadpoolWork, TrySubmitThreadpoolCallback, CreateThreadpoolCleanupGroup, CloseThreadpool, CloseThreadpoolCleanupGroupMembers, CloseThreadpoolCleanupGroup, CloseThreadpoolWork
api-ms-win-core-threadpool-legacy-l1-1-0.dll
DeleteTimerQueueTimer, CreateTimerQueueTimer, QueueUserWorkItem, UnregisterWaitEx
api-ms-win-core-timezone-l1-1-0.dll
FileTimeToSystemTime, SystemTimeToTzSpecificLocalTime
api-ms-win-core-wow64-l1-1-0.dll
IsWow64Process
api-ms-win-eventing-classicprovider-l1-1-0.dll
TraceMessage
api-ms-win-eventing-controller-l1-1-0.dll
StartTraceW, ControlTraceW, EnableTraceEx2
api-ms-win-eventlog-legacy-l1-1-0.dll
ReportEventW, RegisterEventSourceW, DeregisterEventSource, GetEventLogInformation
api-ms-win-obsolete-kernelbase-l1-1-0.dll
LocalAlloc, lstrlenW, LocalFree
api-ms-win-power-base-l1-1-0.dll
PowerDeterminePlatformRoleEx
api-ms-win-power-setting-l1-1-0.dll
PowerSettingUnregisterNotification, PowerSettingRegisterNotification
api-ms-win-security-base-l1-1-0.dll
GetLengthSid, RevertToSelf, ImpersonateLoggedOnUser, CheckTokenMembership, DuplicateTokenEx, AllocateLocallyUniqueId, EqualSid, CreateWellKnownSid, GetTokenInformation, DuplicateToken, SetTokenInformation, GetSidIdentifierAuthority
api-ms-win-security-base-l1-2-0.dll
RevertToSelf, DuplicateToken, DuplicateTokenEx, CreateWellKnownSid, ImpersonateLoggedOnUser, SetTokenInformation, CheckTokenMembership, GetLengthSid, GetTokenInformation, IsValidSid, GetSidIdentifierAuthority, AllocateLocallyUniqueId, EqualSid
api-ms-win-security-credentials-l1-1-0.dll
CredUnmarshalCredentialW, CredFree
api-ms-win-security-credentials-l2-1-0.dll
CredReadByTokenHandle
api-ms-win-security-lsalookup-l1-1-1.dll
LsaLookupFreeMemory, LookupAccountSidLocalW, LsaLookupManageSidNameMapping
api-ms-win-security-lsalookup-l2-1-0.dll
LookupAccountNameW, LookupAccountSidW
api-ms-win-security-lsalookup-l2-1-1.dll
LookupAccountNameW, LookupAccountSidW
api-ms-win-security-lsapolicy-l1-1-0.dll
LsaClose, LsaStorePrivateData, LsaOpenPolicy
api-ms-win-service-management-l1-1-0.dll
StartServiceW, OpenServiceW, OpenSCManagerW, CloseServiceHandle
api-ms-win-service-management-l2-1-0.dll
QueryServiceConfigW, NotifyServiceStatusChangeW
api-ms-win-service-winsvc-l1-2-0.dll
QueryServiceStatus
kernel32.dll
DllMain, RegDeleteTreeW, RegEnumKeyExW, CreateProcessInternalW, BaseInitAppcompatCacheSupport, SleepEx, GetFileAttributesW, SetTimerQueueTimer, CreateRemoteThread, GetThreadUILanguage, GetVersionExW, GetTickCount64, WideCharToMultiByte, DebugBreak, UnhandledExceptionFilter, GetCurrentThreadId, QueryPerformanceCounter, GetModuleHandleA, SetUnhandledExceptionFilter, GetStartupInfoA, LoadLibraryExA, DelayLoadFailureHook, GetSystemDirectoryW, SetInformationJobObject, WaitForMultipleObjects, CreateThread, SetErrorMode, CreateFileW, ReadFile, GetModuleHandleW, GetProcessId, OpenEventW, CreateTimerQueueTimer, DeleteTimerQueueTimer, CreateProcessW, SearchPathW, AssignProcessToJobObject, TerminateProcess, GetTickCount, CompareFileTime, ResumeThread, FileTimeToSystemTime, SystemTimeToTzSpecificLocalTime, GetTimeFormatW, VirtualLock, GetProcessWorkingSetSize, SetProcessWorkingSetSize, VirtualUnlock, VirtualFree, CreateJobObjectW, GetCommandLineW, TerminateJobObject, ResetEvent, InterlockedCompareExchange, GetComputerNameW, InterlockedIncrement, InterlockedDecrement, DuplicateHandle, QueryInformationJobObject, RegisterWaitForSingleObject, OpenProcess, UnregisterWait, QueryFullProcessImageNameW, GetExitCodeProcess, GetProcessHeap, SetEnvironmentVariableW, CompareStringW, GetShortPathNameW, lstrlenW, ExpandEnvironmentStringsW, VirtualAlloc, GetCurrentProcessId, HeapSetInformation, LoadLibraryW, GetProcAddress, FreeLibrary, WaitForSingleObjectEx, InterlockedExchange, UnregisterWaitEx, Sleep, GetSystemTimeAsFileTime, MoveFileExW, LocalSize, LocalReAlloc, CreateEventW, SetEvent, CloseHandle, WaitForSingleObject, GetModuleFileNameW, LocalAlloc, LocalFree, SetLastError, FormatMessageW, FindResourceExW, LoadResource, LockResource, GetCurrentProcess, SetPriorityClass, GetCurrentThread, SetThreadPriority, HeapSize, HeapFree, HeapAlloc, HeapDestroy, HeapCreate, GetLastError, RegGetValueA, GetDateFormatW, LoadLibraryA, MultiByteToWideChar, GetSystemInfo, lstrcmpW, IsWow64Process, ResolveDelayLoadedAPI, QueueUserWorkItem, GetComputerNameExW
msvcrt.dll
DllMain
ntdll.dll
RtlEnterCriticalSection, EtwTraceMessage, NtShutdownSystem, RtlNtStatusToDosError, NtClose, NtQueryInformationToken, NtOpenProcessToken, WinSqmStartSession, WinSqmEndSession, EtwEventWrite, EtwEventEnabled, RtlGetNtProductType, NtQuerySystemInformation, NtSystemDebugControl, EtwGetTraceEnableFlags, EtwGetTraceEnableLevel, EtwGetTraceLoggerHandle, EtwRegisterTraceGuidsW, EtwUnregisterTraceGuids, RtlRemovePrivileges, EtwEventRegister, EtwEventUnregister, RtlDeleteCriticalSection, WinSqmSetDWORD, RtlpVerifyAndCommitUILanguageSettings, EtwEventWriteEndScenario, EtwEventWriteStartScenario, EtwEventActivityIdControl, NtOpenThreadToken, RtlCompareUnicodeString, RtlInitUnicodeStringEx, RtlSetEnvironmentVariable, RtlQueryEnvironmentVariable_U, RtlInitUnicodeString, RtlInitializeCriticalSection, RtlLengthSid, RtlInitString, NtAllocateLocallyUniqueId, WinSqmAddToStream, RtlDestroyEnvironment, TpSimpleTryPost, TpReleaseWork, TpWaitForWork, TpReleaseWait, TpWaitForWait, TpSetWait, TpPostWork, TpAllocWork, TpAllocWait, RtlExpandEnvironmentStrings_U, RtlCreateEnvironment, NtSetInformationToken, NtCreateToken, RtlAdjustPrivilege, TpWaitForTimer, RtlGetDaclSecurityDescriptor, RtlSetDaclSecurityDescriptor, RtlAddAce, NtAdjustPrivilegesToken, NtDuplicateToken, RtlUnhandledExceptionFilter, NtQueryInformationProcess, TpReleaseTimer, NtReplyPort, NtCompleteConnectPort, NtReplyWaitReceivePort, NtAcceptConnectPort, NtCreatePort, NtCreateEvent, RtlNtStatusToDosErrorNoTeb, RtlCopySid, RtlOpenCurrentUser, RtlFreeSid, NtSetSecurityObject, RtlSetSaclSecurityDescriptor, RtlAddMandatoryAce, RtlCreateAcl, RtlCreateSecurityDescriptor, RtlAllocateAndInitializeSid, RtlTimeToSecondsSince1980, TpSetTimer, TpAllocTimer, NtOpenDirectoryObject, NtInitiatePowerAction, RtlFreeUnicodeString, RtlDuplicateUnicodeString, NtFilterToken, RtlEqualSid, RtlLeaveCriticalSection, DbgBreakPoint, NtSetInformationProcess, DbgPrint, RtlFreeHeap, RtlAllocateHeap, NtOpenFile, RtlGUIDFromString, RtlStringFromGUID, NtOpenKey, NtEnumerateKey, NtQueryKey, NtQueryAttributesFile, NtUnloadKey, NtLoadKey, RtlSetOwnerSecurityDescriptor, RtlLengthSecurityDescriptor, RtlAddAccessAllowedAceEx, NtCreateKey, NtDeleteValueKey, NtQueryValueKey, NtSetValueKey, NtDeleteKey, LdrGetProcedureAddress, RtlInitAnsiString, LdrGetDllHandle, NtResetEvent, NtWaitForSingleObject, NtDeviceIoControlFile, RtlGetVersion, NtQuerySymbolicLinkObject, NtOpenSymbolicLinkObject, NtAllocateUuids, RtlConnectToSm, RtlSendMsgToSm, WinSqmIsOptedIn, RtlCompareMemory, RtlInitializeResource, RtlAcquireResourceExclusive, RtlReleaseResource, RtlDeleteResource, RtlLockBootStatusData, NtPowerInformation, RtlGetSetBootStatusData, RtlUnlockBootStatusData, RtlRegisterWait, RtlDeregisterWait, RtlGetAce, RtlAppendUnicodeToString, RtlCaptureStackBackTrace, NtSetEvent, NtOpenEvent, NtUnmapViewOfSection, DbgPrintEx, DbgPrompt, NtRequestPort, NtConnectPort, NtRequestWaitReplyPort, NtGetCachedSigningLevel, WinSqmSetString, RtlCopyLuid
powrprof.dll
PowerDeterminePlatformRoleEx, PowerSettingUnregisterNotification, PowerSettingRegisterNotification
psapi.dll
EnumProcessModules, GetModuleBaseNameW
rpcrt4.dll
RpcAsyncInitializeHandle, RpcAsyncCancelCall, RpcMgmtIsServerListening, RpcStringFreeW, RpcStringBindingComposeW, RpcBindingFromStringBindingW, RpcBindingSetAuthInfoExW, UuidFromStringW, NdrAsyncClientCall, RpcServerUnsubscribeForNotification, RpcServerSubscribeForNotification, I_RpcBindingIsClientLocal, RpcServerUnregisterIf, RpcBindingVectorFree, RpcEpUnregister, RpcServerListen, RpcEpRegisterW, RpcServerInqBindings, RpcServerRegisterIfEx, RpcServerUseProtseqW, NdrServerCall2, NdrAsyncServerCall, RpcRaiseException, RpcServerInqCallAttributesW, RpcServerTestCancel, I_RpcMapWin32Status, NdrClientCall2, RpcBindingCreateW, RpcBindingBind, RpcBindingUnbind, RpcBindingFree, I_RpcExceptionFilter, RpcAsyncAbortCall, RpcAsyncCompleteCall, RpcServerUseProtseqEpW, I_RpcBindingInqLocalClientPID, RpcImpersonateClient, RpcRevertToSelf
samcli.dll
NetUserGetInfo, NetUserGetInternetIdentityInfo
secur32.dll
LsaCallAuthenticationPackage, LsaFreeReturnBuffer, SeciAllocateAndSetIPAddress, SeciAllocateAndSetCallFlags, LsaLogonUser, SeciFreeCallContext, LsaRegisterLogonProcess, LsaLookupAuthenticationPackage, LsaGetLogonSessionData, ChangeAccountPasswordW, GetUserNameExW
user32.dll
CloseDesktop, FindWindowW, EnumWindows, RealGetWindowClassW, ShowWindow, DialogBoxParamW, GetDlgItemTextW, EndDialog, LoadImageW, GetDlgItem, SetThreadDesktop, LockWindowStation, UnlockWindowStation, SetWindowStationUser, UpdatePerUserSystemParameters, GetUserObjectInformationW, OpenInputDesktop, MessageBoxW, GetSystemMetrics, ExitWindowsEx, GetAsyncKeyState, CancelShutdown, CreateDesktopW, SystemParametersInfoW, GetKeyState, GetLastInputInfo, SetForegroundWindow, SetWindowPos, GetDesktopWindow, GetParent, GetWindowLongW, SwitchDesktopWithFade, LoadLocalFonts, RegisterLogonProcess, GetWindowRect, LoadStringW, SendMessageW, CreateWindowStationW, SetProcessWindowStation, CloseWindowStation, SetUserObjectSecurity, SwitchDesktop, EnumDisplayDevicesW, WaitForInputIdle, DwmLockScreenUpdates, LoadCursorW, CopyIcon, SetSystemCursor, DestroyCursor, RegisterSessionProcess
userenv.dll
GetUserProfileDirectoryW, GetAllUsersProfileDirectoryW
winsta.dll
WinStationGetUserCredentials, WinStationDisconnect, WinStationIsSessionRemoteable, _WinStationWaitForConnect, WinStationIsSessionPermitted, WinStationQueryInformationW, WinStationFreeMemory, WinStationNegotiateSession, WinStationFreeUserCredentials, WinStationReportUIResult, WinStationRedirectErrorMessage, WinStationPreCreateGlassReplacementSession, WinStationTerminateGlassReplacementSession
wtsapi32.dll
WTSQuerySessionInformationW, WTSFreeMemory

winlogon.exe

Windows Logon Application by Microsoft

Remove winlogon.exe
Version:   6.0.6001.18000 (longhorn_rtm.080118-1840)
MD5:   6d0773a3a65d28b663f334c90441d01a
SHA1:   50fbc12563e00f420f2891d7c73628b10ed229fa
SHA256:   9fd92a56ab1610460d14e4730a75e82302119d617c05384ab1a7213959948c59
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is winlogon.exe?

Winlogon is the component of Windows that is responsible for handling the secure attention sequence, loading the user profile on logon, and optionally locking the computer when a screensaver is running (requiring another authentication step).

About winlogon.exe (from Microsoft)

Winlogon handles interface functions that are independent of authentication policy. It creates the desktops for the window station, implements time-out operations, and provides a set of support functi

DetailsDetails

File name:winlogon.exe
Publisher:Microsoft Corporation
Product name:Windows Logon Application
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\winlogon.exe
Original name:WINLOGON.EXE.MUI
File version:6.0.6001.18000 (longhorn_rtm.080118-1840)
Product version:6.0.6001.18000
Size:396 KB (405,504 bytes)
Digital DNA
Entropy:6.338183
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Windows firewall allowed program
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\Windows\system32\winlogon.exe'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00761186%
0.028634%
Kernel CPU:0.00633785%
0.013761%
User CPU:0.00127401%
0.014873%
Kernel CPU time:312,468 ms/min
100,923,805ms/min
CPU cycles:238,044/sec
17,470,203/sec
Memory
Private memory:3.19 MB
21.59 MB
Private (maximum):7.53 MB
Private (minimum):5.75 MB
Non-paged memory:3.19 MB
21.59 MB
Virtual memory:64.04 MB
140.96 MB
Virtual memory (peak):73.51 MB
169.69 MB
Working set:6.31 MB
18.61 MB
Working set (peak):8.76 MB
37.95 MB
Page faults:4,103/min
2,039/min
I/O
I/O read transfer:992 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:5 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:291 Bytes/sec
448.09 KB/min
I/O other operations:41/sec
1,671/min
Resource allocations
Threads:3
12
Handles:133
600
GUI GDI count:21
103

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command line:winlogon.exe
Owner:SYSTEM
Parent process:svchost.exe (Host Process for Windows Services by Microsoft Corporation)

ResourcesThreads

Averages
 
ntdll.dll
Total CPU:0.29032629%
0.272967%
Kernel CPU:0.29032629%
0.107585%
User CPU:0.00000000%
0.165382%
CPU cycles:1,687,496/sec
5,741,424/sec
Memory:1.52 MB
1.16 MB
winlogon.exe (main module)
Total CPU:0.00305278%
Kernel CPU:0.00272811%
User CPU:0.00032467%
CPU cycles:67,528/sec
Memory:412 KB
RPCRT4.dll
Total CPU:0.00006009%
Kernel CPU:0.00006009%
User CPU:0.00000000%
CPU cycles:654/sec
Memory:1.26 MB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 8.1 23.00%
Windows 7 Home Premium 23.00%
Windows 8.1 Pro 10.50%
Windows 7 Ultimate 10.50%
Windows 8 5.50%
Windows 8.1 Single Language 5.00%
Windows 8 Single Language 3.50%
Windows 8 Pro 3.50%
Windows 8.1 Pro with Media Center 2.50%
Windows Vista Home Premium 2.50%
Windows 7 Professional 2.50%
Windows 7 Home Basic 1.50%
Windows 8 Enterprise N 1.00%
Windows 8 Enterprise 1.00%
Windows 8.1 N 0.50%
Windows Seven Black Edition 0.50%
Windows 8.1 Enterprise Evaluation 0.50%
Windows 7 Starter 0.50%
Windows 8.1 Enterprise 0.50%
Windows 8.1 Pro Preview 0.50%
Windows Vista Home Basic 0.50%
23 other Windows OS version

Distribution by countryDistribution by country

United States installs about 39.50% of Windows Logon Application.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
ASUS 19.62%
Dell 18.11%
Hewlett-Packard 14.72%
Lenovo 12.08%
Acer 11.70%
Toshiba 9.06%
Intel 3.02%
Sony 3.02%
GIGABYTE 2.64%
Alienware 2.26%
Samsung 1.89%
Medion 1.51%
Sahara 0.38%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE