How to remove logonsession.exe
- File Details
- Overview
- Analysis
logonsession.exe
The module logonsession.exe has been detected as Suspicious Object
File Details
MD5: |
22be0a2cca82f98d42d493ca453b58e0 |
Size: |
199 KB |
First Published: |
2018-05-19 10:06:38 (6 years ago) |
Latest Published: |
2020-09-14 14:44:21 (4 years ago) |
Status: |
Suspicious Object (on last analysis) |
|
Analysis Date: |
2020-09-14 14:44:21 (4 years ago) |
Overview
Signed By: |
JWTS |
Status: |
Valid |
%commonappdata% |
%programfiles%\tsplus-es\userdesktop |
%programfiles%\tsplus-es\userdesktop |
%programfiles%\tsplus-es\userdesktop |
%programfiles%\tsplus-es\userdesktop |
%programfiles%\tsplus-es\userdesktop |
%sysdrive% |
%programfiles%\tsplus-es\userdesktop |
%commonappdata% |
%commonappdata% |
removelastfolders.exe |
logonsession.exe |
uninst.exe |
Windows Server 2012 R2 |
81.3% |
|
Windows 7 |
9.4% |
|
Windows 10 |
9.4% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0000142f |
Name |
Size of data |
MD5 |
.text |
18432 |
ccb1c280e3b0e27e1fb918f0f08def11 |
.rdata |
8704 |
e37e63e280130bddb8112b191c7e67cb |
.data |
3072 |
620b9cb1222dfbdffbd6f90fa59cdf84 |
.rsrc |
165888 |
1a412841ec7887775a628a38d100b7ae |
.reloc |
2048 |
1be61ee3fc0d94b385df3cc691afe0be |