logonui2.exe

Windows Logon UI

Max Secure Software India Pvt. Ltd.

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application logonui2.exe by Max Secure Software India Pvt has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by Max Secure Software India Pvt. Ltd.)

Product:
Microsoft® Windows® Operating System

Description:
Windows Logon UI

Version:
6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)

MD5:
75298a0b5932c74cce99ff5668bd36ec

SHA-1:
3facdaf3d4917a7256fdeea73fe6ca501b8d1771

SHA-256:
2d22a11da9bf84758aee87dde6d4b5ee41db8ee5a5cf354f7509ae22270a0d28

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/16/2024 3:23:08 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.MaxSecure.Optional.Meta (L)
16.2.13.11

File size:
510.2 KB (522,432 bytes)

Product version:
6.00.2900.2180

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
LOGONUI.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\max secure av ee client\logonui2.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
6/30/2010 12:53:42 AM

Valid to:
6/23/2012 10:57:42 AM

Subject:
E=tech@maxpcsecure.com, CN=Max Secure Software India Pvt. Ltd., O=Max Secure Software India Pvt. Ltd., L=pune, S=MH, C=IN

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012985618846

File PE Metadata
Compilation timestamp:
8/4/2004 11:32:57 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
12288:MMtqKNLaYjrIQQ1Bm5A0GDjLQQmn3GGd+GG:MMUgGYPOsQmnWE

Entry address:
0xB95D

Entry point:
6A, 70, 68, C0, 25, 00, 01, E8, A7, 02, 00, 00, 33, DB, 53, 8B, 3D, 94, 11, 00, 01, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 5D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, 99, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, 99, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 5D, FC, 6A, 02, FF, 15, A8, 14, 00, 01, 59, 83, 0D, 38, E4, 03, 01, FF, 83, 0D, 3C, E4...
 
[+]

Entropy:
6.9027

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
156 KB (159,744 bytes)

Remove logonui2.exe - Powered by Reason Core Security