Search Results
(displaying 69 results)
(displaying 69 results)
Name | Filename | Description | Status |
Windows Services | winlogon.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\ Note: Use SDFix under supervision. | X |
winlogon.exe | winlogon.exe | Added by a variant of the SDBBOT Note: Located in \%WINDIR%\System32\drivers\ Note: Do not remove the legitimate file in \%WINDIR%\System32\ Note: Use SDFix under supervision. | X |
xp_system | winlogon.exe | Added by the Troj/Krepper-G TROJAN! Note: Located in \%WINDIR%\inetndata\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
WMAudio | winlogon.exe | Added by the W32.Neveg.A@mm WORM! Note: Located in \%WINDIR%\system\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
Winlogon | WINLOGON.EXE | Added by the W32/Punya-B WORM! Note: Located in \%AppData%\Windows\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
WINLOGON | WINLOGON.vbs | Added by the VBS.Ypsan.F@mm WORM! Note: Located in \%WINDIR%\System\ Note: Do not remove the legitimate program file \%WINDIR%\System32\WScript.exe | X |
winlogon | winlogon.exe | Added by the Backdoor.Trodal TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
winlogon | winlogon.exe | Hijacker or adult content dialler. Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
winlogon | winlogon.exe | Windows Logon Process - handles user logons described here Note: Located in \%WINDIR%\System32\ Note: Is malware if located in any other folder. | Y |
Windows Logon Applicationedc | winlogon.exe | Added by the Troj/DwnLdr-HGR TROJAN! Note: Located in \%UserProfile%\ Note: Use SDFix under supervision. | X |
Windows NT Update Manager | Winlogon.exe | Added by the W32/Agobot-NU WORM! Note: Located in \%WINDIR%\system\ Note: that those are zeroes in the filename and not capital "o" Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
Windows NT Logon Application | winlogon.scr | Added by the W32/Rbot-ALP WORM! Note: Located in \%WINDIR%\system\ | X |
Windows Messanger Control Center | winlogon.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\ Note: Use SDFix under supervision. | X |
Windows Logon Service | winlogon.pif | Added by the W32/Rbot-AOU WORM! Note: Located in \%WINDIR%\system\ | X |
Windows Logon Application | winlogon.exe | Added by the W32/Poebot-KW WORM! Note: Located in \%WINDIR%\system\ Note: Do not remove the legitimate file which is always found in \%WINDIR%\System32\ | X |
Windows Log Agent | winlogon.exe | Added by the TR/Keylogger.avk - Trojan TROJAN! Note: Located in \%Program Files%\Common Files\ Note: Read the link, Keylogger steals information Note: Do not remove the legitimate file which is always found in \%WINDIR%\System32\ | X |
Windows ARP Detectioncx | winlogon.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\ Note: Use SDFix under supervision. | X |
Windows Login Server | winlogon.exe | Identified by Kaspersky as Worm.Win32.AutoRun.atvs. Information at Threat Expert Note: Located in %ProgramFiles%\Common Files\System Note: This entry is loaded through one of the "Policies" startup keys. | X |
Service | winlogon.exe | Unidentified malware. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe program. Note: Located in \%Temp%\ Note: Do not remove the legitimate (winlogon.exe) file which is always found in \%Windir%\%System%\ | X |
Windows SafeAssist | winlogon.exe | Added by the Troj/VB-FGB Trojan! Note: Located in \%AppData%\ Note: Do not remove the legitimate (winlogon.exe) file which is always found in \%Windir%\%System%\ | X |
Windows Live Guards | winlogon.exe | Added by the Virus.Win32.Parite.b VIRUS! Note: Located in \%Program Files%\[note]Modifies the hosts file[/b] | X |
Windows SafeAssist | winlogon.exe | Added by an unidentified (Trojan.Agent) Note: Located in \%Documents and Settings%\User name\Application Data\ Note: Do not remove the legitimate winlogon.exe file which is always found in \%WINDIR%\%System%\ | X |
Windows Security Center | winlogon.exe | Added by the W32/Autorun-BEX WORM! Note: Located in \%AppData%\ Note: Spreads via removable media. | X |
SysManagerGold | winlogon.eXe | Added by the W32.SillyDC Note: Located in \%AppData%\SysManager\ | X |
UserLogon | winlogon.exe | Added by the Worm.Win32.AutoRun.acq Note: Located in \%UserProfile%\ | X |
NVIDIA Media Center Library | winlogon.exe | Added by W32/AutoRun-AZK WORM! Note: Located in \%WINDIR%\ Note: Spreads via removable media. | X |
Windows ARP Detectionc | winlogon.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. | X |
Windows Login Assistance | winlogon.exe | Identified by Sophos as Troj/Agent-LGL Note: Located in %AppData%\S05-3636-T34636-7574-BLAZEBOT-ASGET-UEIAASH | X |
networks | winlogon.exe | Added by the Worm.Win32.AutoRun.ctz Note: Located in \%WINDIR%\ Note: Do not remove the legitimate winlogon.exe file which is always found in \%WINDIR%\%System%\ | X |
MSMSGS | WINLOGON.EXE | Added by the W32.Korron.B is a worm that replaces some file types with a copy of itself. It also copies itself to all accessible drives on the compromised computer. Note: Located in \%Documents and Settings%\Administrator\Local Settings\Application Data\WINDOWS\ Note: Do not remove the legitimate WINLOGON.EXE file which is always found in \%WINDIR%\%System%\ | X |
Microsoft Windows logon process | winlogon.exe | Added by the Troj/FakeAV-IJ Note: Located in \%User%\Owner\AppData\Roaming\Microsoft\Windows\ Note: Do not remove the legitimate program file in \%WINDIR%\%System%\ | X |
CTEMON.EXE | winlogon.exe | Added by the Troj/FakeAv-FU TROJAN! Note: Located in \%Documents and Settings%\All Users\Application Data\ Note: This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file | X |
Window UDP Control Servic | winlogon.exe | Added by the W32/Rbot-GXN WORM! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\%System%\ | X |
screws | winlogon.exe | Identified by Sophos as Worm W32/VB-DWN Note: Located in \%WINDIR%\ | X |
ICQ Net | winlogon.exe | Added by the W32.Netsky.C@mm or W32.Netsky.D@mm or W32.Netsky.E@mm or W32.Netsky.K@mm WORM! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
RegDone | winlogon.exe | Added by the W32.Neveg.A@mm Note: Located in \%WINDIR%\system Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
nvchost | winlogon.exe | Added by the Troj/Klone-J TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
MSWinlogon | winlogon.exe | Added by the Troj/Agent-FZM TROJAN! Note: Located in \%WINDIR%\system Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
MSMSGS | winlogon.exe | Added by the W32.Rahiwi.A WORM! Note: Located in \%Documents and Settings%\Administrator\Local Settings\Application Data\WINDOWS\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
Microsoft Windows Logon Process | winlogon.exe | Added by the Troj/Proxyser-R TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
Microsoft Visual SourceSafe | winlogon.exe | Added by the W32.Neveg.A@mm Note: Located in \%WINDIR%\system Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
ICQNet | winlogon.exe | Added by the W32/NETSKY-C WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows winlogon.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup! | X |
ICQ Net | winlogon.exe | Added by the W32.Netsky.D@mm WORM! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
ROOT_Machine | winlogon.exe | Added by the Troj/Banker-FI TROJAN! Note: Located in \%WINDIR%\inf\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
Generic Host Process for Win32 Services | winlogon.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System\ Note: Use SDFix under supervision. Not to be confused by the original file in \%WINDIR%\System32\ folder. | X |
FriendlyTypeName | winlogon.exe | Added by the W32.Neveg.A@mm Note: Located in \%WINDIR%\system Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
Flash Driver | winlogon.exe | Added by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%Temp%\ Note: Use SDFix under supervision. | X |
Firewall auto setup | winlogon.exe | Identified by Norman as W32/Downloader Note: This worm\trojan is located in C:\%WINDIR%\Temp\ folder. Note: NoteThe filename spchost.exe has also been identified with this Keystroke Logger infection. | X |
CueX44_stil_here | WINLOGON.EXE | Added by the W32/Punya-A Worm Note: Read the link, alters file associations | X |
ccApps | winlogon.exe | Added by NEVEG.A WORM! Note - this is not the valid Windows Logon winlogon.exe process | X |
BuildLab | winlogon.exe | Added by the W32.Neveg.A@mm Note: Located in \%WINDIR%\system Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
Administrator | winlogon.exe | Added by the W32/Rubble-C Worm | X |
Streams Drivers | winlogon.exe | Added by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%Temp%\ Note: Use SDFix under supervision. | X |
WinAuth | winlogon.exe | Added by the TROJ_STRTPAGE.BE TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate file which is always found in \%WINDIR%\System32\ | X |
W1N32.DLL | WINLOGON .exe | Added by the TROJ_DROPPERFL.A TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate file which is always found in \%WINDIR%\System32\ | X |
Userinit | winlogon.exe | Added by a variant of the Troj/Dloader-TP TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate file which is always found in \%WINDIR%\System32\ | X |
userinit | winlogon.exe | Added by the Troj/Dloader-TP TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate file which is always found in \%WINDIR%\System32\ | X |
urudjeffni | winlogon.exe | Added by the W32/Romario-A WORM! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate file which is always found in \%WINDIR%\System32\ | X |
Torjan Program | WINLOGON.EXE | Added by Infostealer.Wowcraft.D TROJAN! horse that attempts to steal sensitive information related to online games and send it to a remote attacker. Note: This is not the legitimate Windows process WINLOGON.EXE (Which is always found in the System32 folder.) This trojan file (WINLOGON.EXE) is found in the Windows or Winnt folder. | X |
TEXTCONV | winlogon.exe | Added by the W32.Neveg.A@mm WORM! Note: Located in \%WINDIR%\system\ Note: Do not remove the legitimate file which is always found in \%WINDIR%\System32\ | X |
System Update2 | winlogon.exe | Added by the Troj/Autotroj-C WORM! Note: Located in \%WINDIR%\system\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
.Prog | winlogon.exe | Added by the W32.Neveg.A@mm Note: Located in \%WINDIR%\system Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
SmansaApp | winlogon.exe | Added by the W32/Romario-A WORM! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
SkynetRevenge | winlogon.scr | Added by the W32.Netsky.AA@mm WORM! Note: Located in \%WINDIR%\ | X |
runwinlogon | winlogon.exe | Identified as a variant of the SpamTool.Win32.Agent.gj malware. Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\ Note: Use SDFix under supervision. | X |
run= | winlogon.exe | CoolWebSearch parasite related. Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
RPCserv32g | WINLOGON.EXE | Added by the WORM_BOBAX.AD WORM! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
RPCserr32g | winlogon.exe | Added by the W32/Ritdoor-B WORM! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |
xp_system | services.exe or winlogon.exe | Added by the Trojan.Bookmarker.J TROJAN! Note: Located in \%WINDIR%\inet20004\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\ | X |