English | Deutsch


Is winlog.exe safe?

Winlog.exe is a executable file (a program) within Windows. The filename extension .exe denotes an executable file. You should only run executable files from publishers you trust, because executable files can potentially change your computer settings or harm your computer. The free file information forum can help you determine if winlog.exe is a virus, trojan, spyware, or adware that you can remove, or a file belonging to a Windows system or to an application you can trust.


Winlog.exe file information

The process known as I9EaTqnCyd or kTIjrcY2xa or Adobe Photoshop (version CS4 KeyGen [RkChimaira]) or OlmTlrTqj or KeyScreen or Generic Host Process for Win32 Services or Realtek Azalia Audio - Event Monitor or Setup

appears to belong to software sxVOGUsVVL or GDThJ3jrD or Microsoft® Windows (version 2000 Operating System) or Adobe Photoshop (version CS4 KeyGen [RkChimaira]) or bgeRqDDYya or KeyScreen or Setup or Microsoft Windows Operating System

by Microsoft (www.microsoft.com) or N5R or 5JXVPH3xHC or VpgDUQE5ddo or Banner or Realtek Semiconductor (www.realtek.com.tw).

Description: Winlog.exe is not essential for Windows and will often cause problems. The file winlog.exe is located in the folder C:\Windows\System32. Known file sizes on Windows 7/XP are 175,104 bytes (67% of all occurrences), 21,460 bytes and 16 more variants. http://www.file.net/process/winlog.exe.html 
The file is not a Windows system file. There is no description of the program. The software starts upon Windows startup (see Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, C:\Windows\win.ini, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx, HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell, HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run). The program is not visible. The file is located in the Windows folder, but it is not a Windows core file. Therefore the technical security rating is 77% dangerous, however also read the users reviews.

Recommended: Identify winlog.exe related errors

If winlog.exe is located in a subfolder of "C:\Documents and Settings", the security rating is 67% dangerous. The file size is 144,384 bytes (22% of all occurrences), 2,117,632 bytes and 19 more variants. The program is not visible. It is not a Windows core file. The program starts when Windows starts (see Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, C:\Windows\win.ini, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx, HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell, HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run). The software has no file description. Winlog.exe is able to monitor applications.

If winlog.exe is located in a subfolder of "C:\Program Files", the security rating is 52% dangerous. The file size is 229,376 bytes (14% of all occurrences), 319,488 bytes and 5 more variants. Winlog.exe is not a Windows core file. There is no information about the author of the file. The program has no visible window. The application is loaded during the Windows boot process (see Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, C:\Windows\win.ini, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx, HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell, HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run). Winlog.exe is able to monitor applications, record inputs, hide itself and manipulate other programs.

If winlog.exe is located in the folder C:\Windows, the security rating is 68% dangerous. The file size is 65,170 bytes (28% of all occurrences), 464,384 bytes and 4 more variants.

If winlog.exe is located in a subfolder of C:\Windows\System32, the security rating is 78% dangerous. The file size is 123,624 bytes (50% of all occurrences), 531,926 bytes, 466,432 bytes or 270,848 bytes.

If winlog.exe is located in a subfolder of C:\Windows, the security rating is 52% dangerous. The file size is 319,488 bytes (50% of all occurrences) or 1,449,984 bytes.

If winlog.exe is located in a subfolder of C:\, the security rating is 36% dangerous. The file size is 923,657 bytes.

External information from Paul Collins:

Important: Some malware also uses the file name winlog.exe, for example Infostealer or W32.SillyFDC (detected by Symantec), and VirTool:Win32/VBInject.gen!CC or Backdoor:Win32/IRCbot.DL (detected by Microsoft). Therefore, you should check the winlog.exe process on your PC to see if it is a threat. We recommend Security Task Manager for verifying your computer's security. This was one of the Top Download Picks of The Washington Post and PC World.



Score

User Comments

its a virus. once it gets in to your computer, the files where it is in become shortcuts.
  Vee  
where i know that it is a type of virus and any type of virus is virus so it is dangerious.
  chandra prakash   (further information)
it's a log spoofer. will alter your log files to make seem size appropriate even though you might have just had some srpize trojans uploaded, some files exfiltrated.
  crypninja  
This process name is used as the default name for many RATs. Be warned, its a virus.
  Door_Theif  
Automatically copies itself onto your flashdrive from local user directory AppData along with an autorun.ini. When you click to open your flashdrive from My Computer, it copies the winlog.exe file to your computer. Just delete from startup (run=msconfig) and do a search and delete all instance of the file
  iStar19  

   
Bad virus keylogger if im not mistaken
  cmptr  
Win32/PSW.Fignotok.E
  ☺☻Back/ ; \Door☻☺.Graybird[ViP]  
More comments can be found here:
    (further information)

Rating chart

Summary: Average user rating of winlog.exe: based on 22 votes with 9 reviews.
One user thinks winlog.exe is essential for Windows or an installed application. One user thinks it's probably harmless. One user thinks it's neither essential nor dangerous. 6 users suspect danger. 13 users think winlog.exe is dangerous and recommend removing it. 5 users don't grade winlog.exe ("not sure about it").


Do you have additional information?
What do you know about winlog.exe: 
How do you rate it: 
Link for more info's: 
Your Name: 


Winlog scanner


Security Task Manager shows all running Windows tasks including embedded hidden functions (e.g. keyboard or browser monitoring, autostart entry). A unique security risk rating indicates the likelihood of the process being potential spyware, malware, keylogger or a Trojan.

Malwarebytes Anti-Malware detects and removes sleeping spyware, adware, trojans, keyloggers, malware and tracking threats from your hard disk. Ideal supplement to Security Task Manager.

SpeedUpMyPC scans, cleans, repairs and optimizes your computer.


Other processes


winlog.exe [all]