Winlogon Clones

Winlogon.exe is a legitimate windows system file/ process. If you search your hard disk for winlogon.exe you may find it mention at C:\Windows\system32 and C:\Windows\SoftwareDistribution\download\.. folders. If you take your mouse pointer over the filename, you will see a small tooltip that says 

In Folder: C:\Windows\System32
Description: Windows NT Logon Application
Company: Microsoft Corporation
File Version: x.x.xxxx.xxxx
Date Created:x/x/xxxx x:xx AM/PM
Size: xxx KB

You will also see a process winlogon.exe running in the task manager. Virus makers use this file name, usually they save it in different location, other than the default, so that the user does not get suspicious after seeing the  process/es of this name running in the task manager. You will need to use special tools such as Windows Defender or Sysinternal's process explorer to find out the actual path of a process seen inside task manager. I have clubbed together the virus reports that have used this filename.

 

 

Title Filter     Display # 
# Article Title Author Hits
1 %AppData%\ winlogon.exe Administrator 1267
2 Home Video.avi.exe, Home Video.exe Administrator 2369
3 tynqz.exe,Isass.exe,winIogon.exe,aehivemf.exe,nycd.exe Administrator 923
4 Windows User Administrator 861
5 winlogon.exe Administrator 3
6 winlogon.exe, cssrs.exe, winhelp32.exe 1784
7 xircom\ services.exe, winlogon.exe Administrator 1105
 

Search within this site

Read in your language



Useful Links