winlogon.exe

The executable winlogon.exe has been detected as malware by 24 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘SysManagerGold’.
MD5:
d87b50cbb5d500332f1451dec7fd0927

SHA-1:
baa94c1136c81b52786d2e1da00cb9fe8e62a8b6

Scanner detections:
24 / 68

Status:
Malware

Analysis date:
4/29/2024 3:03:02 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/PSW.Frethog.69756C
7.9.1.44

Emsisoft A-Squared
Trojan-Dropper.Delf!IK
4.5.0.41

avast!
Win32:Delf-FXK
2014.9-170316

AVG
Worm/Delf
2018.0.2438

Bitdefender
Trojan.Generic.137879
1.0.20.375

Comodo Security
Win32.Delf.BI
2755

Dr.Web
Win32.HLLW.Silly
9.0.1.075

ESET NOD32
Win32/Delf.BI
11.4551

Fortinet FortiGate
W32/Delf!tr
3/16/2017

F-Secure
Trojan.Generic.137879
11.2017-16-03_5

G Data
Trojan.Generic.137879
17.3.19

IKARUS anti.virus
Trojan-Dropper.Delf
t3scan.1.1.72.0

K7 AntiVirus
Virus.Win32.Delf.bi
13.7.10.881

Kaspersky
Virus.Win32.Delf
14.0.0.-1316

McAfee
Generic Delphi
5600.6094

Microsoft Security Essentials
PWS:Win32/Frethog.gen!C
1.163.1557.0

Norman
W32/Smalltroj.PTCF
11.20170316

Panda Antivirus
Trj/Agent.FMF
17.03.16.04

Prevx
Medium Risk Malware
3.0

Quick Heal
TrojanPWS.Frethog.gen
3.17.10.00

Rising Antivirus
Worm.Win32.Delf.yum
23.00.65.17314

Sophos
Mal/Behav-043
4.46

Trend Micro
WORM_AUTORUN.CSS
10.465.16

Vba32 AntiVirus
Virus.Win32.Delf.bi
3.12.10.11

File size:
68.1 KB (69,756 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Application data\sysmanager\winlogon.exe

File PE Metadata
Compilation timestamp:
5/26/2055 12:10:40 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x488C

Entry point:
55, 8B, EC, B9, 04, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, 57, B8, 44, 48, 40, 00, E8, DF, F3, FF, FF, 33, C0, 55, 68, C7, 4A, 40, 00, 64, FF, 30, 64, 89, 20, 6A, 01, E8, C6, F4, FF, FF, 8D, 45, EC, E8, 76, F5, FF, FF, 8B, 55, EC, B8, 80, 66, 40, 00, E8, 55, EA, FF, FF, 8D, 45, E8, E8, 1D, F6, FF, FF, 8B, 55, E8, B8, 78, 66, 40, 00, B9, E0, 4A, 40, 00, E8, A7, EB, FF, FF, 6A, 00, A1, 78, 66, 40, 00, E8, 9B, EC, FF, FF, 50, E8, 65, F4, FF, FF, 8D, 45, E4, E8, F1, F5, FF, FF, 8B, 55, E4, B8, 74...
 
[+]

Entropy:
2.9165

Developed / compiled with:
Microsoft Visual C++

Code size:
15 KB (15,360 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SysManagerGold

Command:
"C:\Documents and Settings\{user}\Application data\sysmanager\winlogon.exe"


Remove winlogon.exe - Powered by Reason Core Security