winlogon.exe

1

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘NVIDIA Media Center Library’.
Product:
1

Version:
1.00

MD5:
9bc5ddd45664025caf8d040585ccf679

SHA-1:
5da7cbecabfe5be3bdc46ed372b666877d34e30b

SHA-256:
9135f1daf545edad579e2bf5df8a7610c3f8fb295a66de1cf30f74019cc96813

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/29/2024 10:55:49 AM UTC  (today)

Scan engine
Detection
Engine version

Panda Antivirus
Suspicious file
17.03.12.07

Prevx
Medium Risk Malware
3.0

File size:
32 KB (32,768 bytes)

Product version:
1.00

Original file name:
55.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\luish18\luish181\winlogon.exe

File PE Metadata
Compilation timestamp:
6/2/2010 6:14:27 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x10E0

Entry point:
68, B8, 11, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, 46, 6E, FA, 55, D4, D4, F1, 47, 9F, 87, A4, FF, 04, 95, 13, 21, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 6A, 64, 51, 30, 7A, 61, 77, 00, 00, 00, 00, 00, 06, 00, 00, 00, CC, 29, 40, 00, 07, 00, 00, 00, 50, 22, 40, 00, 07, 00, 00, 00, 44, 1F, 40, 00, 07, 00, 00, 00, 00, 1F, 40, 00, 07, 00, 00, 00, AC, 1E, 40, 00, 01, 00, 03, 00, AC, 1C, 40, 00, 00, 00, 00, 00, FF, FF, FF, FF...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
24 KB (24,576 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
NVIDIA Media Center Library

Command:
C:\users\luish18\luish181\winlogon.exe


Scan winlogon.exe - Powered by Reason Core Security