|
Winlogon.exe is a legitimate windows system file/ process. If you search your hard disk for winlogon.exe you may find it mention at C:\Windows\system32 and C:\Windows\SoftwareDistribution\download\.. folders. If you take your mouse pointer over the filename, you will see a small tooltip that says In Folder: C:\Windows\System32 You will also see a process winlogon.exe running in the task manager. Virus makers use this file name, usually they save it in different location, other than the default, so that the user does not get suspicious after seeing the process/es of this name running in the task manager. You will need to use special tools such as Windows Defender or Sysinternal's process explorer to find out the actual path of a process seen inside task manager. I have clubbed together the virus reports that have used this filename.
|
|
Winlogon Clones
