logonscreenservice.exe

Actual Multiple Monitors

Actual Tools

The executable logonscreenservice.exe, “Actual Multiple Monitors Service” has been detected as malware by 3 anti-virus scanners. It runs as a separate (within the context of its own process) windows Service named “Actual Multiple Monitors Service”.
Publisher:
Actual Tools  (signed and verified)

Product:
Actual Multiple Monitors

Description:
Actual Multiple Monitors Service

Version:
8.5.3

MD5:
f8351eff9fd993aa59640210f686fe5c

SHA-1:
3a26a411d7df2d190c478784fbab67090845d5ce

SHA-256:
3eddcf8f016eb40310328fbbfd93f64627e6f6b1bd4bed50edf5acddeed30b86

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
4/19/2024 11:24:31 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Floxif.H virus
6.3.12010.0

F-Prot
W32/Floxif.B
4.6.5.141

F-Secure
Win32.Floxif.A
5.16.24

File size:
161.7 KB (165,623 bytes)

Product version:
8.5.3

Copyright:
Copyright © Actual Tools 2002-2015

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\actual multiple monitors\logonscreenservice.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/11/2014 5:00:00 AM

Valid to:
5/13/2017 4:59:59 AM

Subject:
CN=Actual Tools, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Actual Tools, L=Krasnoyarsk, S=Russian Federation, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
388EA8CA52C1E2419BF5297D440DA927

File PE Metadata
Compilation timestamp:
9/20/2015 3:46:58 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xFE78

Entry point:
E9, 5E, BC, FF, FF, EC, 33, C0, 89, 45, EC, 89, 45, F0, B8, 90, FD, 01, 00, E8, 6C, 59, FF, FF, 33, C0, 55, 68, 11, FF, 01, 00, 64, FF, 30, 64, 89, 20, E8, B1, 28, FF, FF, 85, C0, 75, 07, E8, E4, FD, FF, FF, EB, 48, 8D, 55, F0, B8, 01, 00, 00, 00, E8, F9, 28, FF, FF, 8B, 45, F0, BA, 28, FF, 01, 00, E8, 54, 6A, FF, FF, 84, C0, 74, 07, E8, 17, EC, FF, FF, EB, 23, 8D, 55, EC, B8, 01, 00, 00, 00, E8, D4, 28, FF, FF, 8B, 45, EC, BA, 3C, FF, 01, 00, E8, 2F, 6A, FF, FF, 84, C0, 74, 05, E8, DA, ED, FF, FF, 33, C0...
 
[+]

Entropy:
7.3756

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
60 KB (61,440 bytes)

Service
Display name:
Actual Multiple Monitors Service

Service name:
amm_LSService

Type:
Win32OwnProcess


Remove logonscreenservice.exe - Powered by Reason Core Security