winlogon.exe

The executable winlogon.exe has been detected as malware by 32 anti-virus scanners.
Version:
1.1.09.04

MD5:
06e405a71f73a636b4373fadf624c634

SHA-1:
aedef13fd8a7101a1b91f22f21a2bea4f0e11b1d

SHA-256:
46ebf8aa5d0b15fab767f4996a9655bb709ef261e377b4e91cf68138e6550c90

Scanner detections:
32 / 68

Status:
Malware

Analysis date:
4/26/2024 1:14:00 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur.Pq0@uDdiASpi
5696344

Agnitum Outpost
Trojan.PWS.Siggen
7.1.1

AhnLab V3 Security
Trojan/Win32.Fsysna
2015.11.28

Arcabit
Trojan.Heur.E98CD2
1.0.0.624

avast!
Win32:Crypt-RHV [Trj]
151028-1

AVG
Win32/DH{gUph?}
2016.0.2912

Bitdefender
Gen:Trojan.Heur.Pq0@uDdiASpi
1.0.20.1655

Clam AntiVirus
Win.Trojan.Agent-812665
0.98/21102

Comodo Security
Backdoor.Win32.Delf.~DF
23668

Dr.Web
Trojan.Siggen6.46235
9.0.1.05190

Emsisoft Anti-Malware
Gen:Trojan.Heur.Pq0@uDdiASpi
10.0.0.5366

ESET NOD32
Win32/AHK.A worm
7.0.302.0

Fortinet FortiGate
W32/AHK.A!tr
11/27/2015

F-Secure
Gen:Trojan.Heur.Pq0@uDdiASpi
11.2015-27-11_6

G Data
Gen:Trojan.Heur.Pq0@uDdiASpi
15.11.25

IKARUS anti.virus
Trojan.Win32.Malex
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.212.17996

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.1056

Malwarebytes
Trojan.Agent.WNL
v2015.11.27.08

McAfee
Trojan.GenericR-CTB!06E405A71F73
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.211.1032.0

MicroWorld eScan
Gen:Trojan.Heur.Pq0@uDdiASpi
16.0.0.993

Norman
Gen:Trojan.Heur.Pq0@uDdiASpi
07.10.2015 03:16:12

nProtect
Trojan/W32.Fsysna.684544
15.11.27.01

Panda Antivirus
Trj/Genetic.gen
15.11.27.08

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1077

Quick Heal
Trojan.Malex.G4
11.15.14.00

Rising Antivirus
PE:Worm.VobfusEx!1.99DD [F]
23.00.65.151125

SUPERAntiSpyware
Trojan.Agent/Gen-Malex
9481

Trend Micro
TROJ_GEN.R0C1C0DKQ15
10.465.27

Vba32 AntiVirus
Trojan.Fsysna
3.12.26.4

VIPRE Antivirus
Threat.4726256
45400

File size:
668.5 KB (684,544 bytes)

Product version:
1.1.09.04

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\microsoft\windows\start menu\programs\startup\winlogon.exe

File PE Metadata
Compilation timestamp:
3/14/2013 3:42:12 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:rImivRRhfbXy4nVhJCH8aWX4YjhxuYhtRorESpY1PQJBuBJFuY47Oxq5E+5w+9Tk:rI5ZnXy4nVGcLuY7ur/pgoJYBJYYDP+6

Entry address:
0x824EA

Entry point:
E8, B2, 5E, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 83, 65, FC, 00, 53, 8B, 5D, 10, 85, DB, 75, 07, 33, C0, E9, 9A, 00, 00, 00, 56, 83, FB, 04, 72, 75, 8D, 73, FC, 85, F6, 74, 6E, 8B, 4D, 0C, 8B, 45, 08, 8A, 10, 83, C0, 04, 83, C1, 04, 84, D2, 74, 52, 3A, 51, FC, 75, 4D, 8A, 50, FD, 84, D2, 74, 3C, 3A, 51, FD, 75, 37, 8A, 50, FE, 84, D2, 74, 26, 3A, 51, FE, 75, 21, 8A, 50, FF, 84, D2, 74, 10, 3A, 51, FF, 75, 0B, 83, 45, FC, 04, 39, 75, FC, 72, C2, EB, 2E, 0F, B6, 40, FF, 0F, B6, 49, FF, EB, 46...
 
[+]

Entropy:
6.6191

Code size:
571.5 KB (585,216 bytes)

User Start Menu Item
Name:
winlogon.exe


Remove winlogon.exe - Powered by Reason Core Security