winlogon.exe

כמהקשהחאגימיםלמדינותלאיודעים

मजबूतहोजाएगालेकिनयहमहत्वपूर्णहै

The executable winlogon.exe, “मजबूतहोजाएगालेकिनयहमहत्वपूर्णहै” has been detected as malware by 35 anti-virus scanners.
Publisher:
मजबूतहोजाएगालेकिनयहमहत्वपूर्णहै

Product:
כמהקשהחאגימיםלמדינותלאיודעים

Description:
मजबूतहोजाएगालेकिनयहमहत्वपूर्णहै

Version:
1.08.3.3

MD5:
0c37f80de1a488f409388b37db462d95

SHA-1:
ed068057ad82762bcbe1682a9d0431b1de10fee4

SHA-256:
6cdd0d9dfa61b6b39736114f84d5fe79c353ac215605c091f16e333a501d7008

Scanner detections:
35 / 68

Status:
Malware

Analysis date:
4/25/2024 11:01:02 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Zusy.104634
623

Agnitum Outpost
Trojan.Zapchast
7.1.1

AhnLab V3 Security
Trojan/Win32.Genome
2015.03.29

Avira AntiVirus
BDS/Bladabindi.ajoos
3.6.1.96

avast!
MSIL:GenMalicious-ATS [Trj]
2014.9-150522

AVG
MSIL4
2016.0.3101

Baidu Antivirus
Trojan.Win32.Fsysna
4.0.3.15522

Bitdefender
Gen:Variant.Zusy.104634
1.0.20.710

Comodo Security
UnclassifiedMalware
21569

Dr.Web
Trojan.DownLoader10.63222
9.0.1.0142

Emsisoft Anti-Malware
Gen:Variant.Zusy.104634
8.15.05.22.02

ESET NOD32
MSIL/Kryptik.AFO (variant)
9.11390

Fortinet FortiGate
MSIL/Kryptik.ABO!tr
5/22/2015

F-Prot
W32/S-c2cf3380
v6.4.7.1.166

F-Secure
Gen:Variant.Zusy.104634
11.2015-22-05_6

G Data
Gen:Variant.Zusy.104634
15.5.25

IKARUS anti.virus
Trojan.MSIL.Zapchast
t3scan.1.8.9.0

K7 AntiVirus
Trojan
13.202.15410

Kaspersky
Trojan.Win32.Fsysna
14.0.0.2002

Malwarebytes
Backdoor.Bot
v2015.05.22.02

McAfee
Artemis!0C37F80DE1A4
5600.6757

Microsoft Security Essentials
Backdoor:MSIL/Bladabindi
1.1.11502.0

MicroWorld eScan
Gen:Variant.Zusy.104634
16.0.0.426

NANO AntiVirus
Trojan.Win32.DownLoader10.degwcg
0.30.8.659

Norman
Kryptik.STUB
11.20150522

Panda Antivirus
Trj/Chgt.D
15.05.22.02

Qihoo 360 Security
Win32/Trojan.611
1.0.0.1015

Quick Heal
Trojan.Fsysna.r3
5.15.14.00

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GEN.R0C2C0DHV14
7.2.142

Trend Micro
TROJ_GEN.R0C2C0DHV14
10.465.22

Vba32 AntiVirus
Trojan.MSIL.Disfa
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
38850

ViRobot
Trojan.Win32.A.Fsysna.159232.A[h]
2014.3.20.0

Zillya! Antivirus
Trojan.Fsysna.Win32.2520
2.0.0.2119

File size:
155.5 KB (159,232 bytes)

Product version:
1.08.3.3

Copyright:
Copyright © 2014

Trademarks:
כמהקשהחאגימיםלמדינותלאיודעים

Original file name:
Stub.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\winlogon.exe

File PE Metadata
Compilation timestamp:
8/25/2014 6:40:50 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:I40uQY45qIvNbBLdUNkEUnQ9itLKiha6SanGHOu8mNU:N0u4bM3cQ8G/6SanGH0m

Entry address:
0x2582E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.8724

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
142.5 KB (145,920 bytes)

Remove winlogon.exe - Powered by Reason Core Security