logonui2.exe

Windows Logon UI

Max Secure Software India Pvt. Ltd.

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application logonui2.exe by Max Secure Software India Pvt has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by Max Secure Software India Pvt. Ltd.)

Product:
Microsoft® Windows® Operating System

Description:
Windows Logon UI

Version:
6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)

MD5:
220b5c54c6d4b7a041dd5496eb62f238

SHA-1:
c0fef1e8be2a2c9e331621001bf1774d646b6242

SHA-256:
d750084bf3156dcbb051f386cff56cad15b7baee51673c19be0d2b3943e872c5

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/20/2024 11:17:55 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.MaxSecure.Optional.Meta (L)
16.1.15.10

File size:
510.2 KB (522,432 bytes)

Product version:
6.00.2900.2180

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
LOGONUI.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\max internet security\logonui2.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
6/30/2010 12:53:42 AM

Valid to:
6/23/2012 10:57:42 AM

Subject:
E=tech@maxpcsecure.com, CN=Max Secure Software India Pvt. Ltd., O=Max Secure Software India Pvt. Ltd., L=pune, S=MH, C=IN

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012985618846

File PE Metadata
Compilation timestamp:
8/4/2004 11:32:57 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
12288:9MtqKNLaYjrf6dm5A0GDjLQQm53GGd+GG:9MUgGYPCwQm5WE

Entry address:
0xB95D

Entry point:
6A, 70, 68, C0, 25, 00, 01, E8, A7, 02, 00, 00, 33, DB, 53, 8B, 3D, 94, 11, 00, 01, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 5D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, 99, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, 99, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 5D, FC, 6A, 02, FF, 15, A8, 14, 00, 01, 59, 83, 0D, 38, E4, 03, 01, FF, 83, 0D, 3C, E4...
 
[+]

Entropy:
6.9012

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
156 KB (159,744 bytes)

Remove logonui2.exe - Powered by Reason Core Security