How to remove winlogon.exe

winlogon.exe

The module winlogon.exe has been detected as Virtool.NSSM

winlogon.exe
Product Name:

NSSM 32-bit

MD5: 8a874af5c543a7fa5a4bef61e7a1c842
Size: 288 KB
First Published: 2017-07-25 05:14:19 (7 years ago)
Latest Published: 2024-03-15 23:25:46 (a year ago)
Status: Virtool.NSSM (on last analysis)
Analysis Date: 2024-03-15 23:25:46 (a year ago)
%windir%\prey\versions\1.3.9\node_modules\satan\lib\win32
%windir%\prey\versions\1.4.2\node_modules\satan\lib\win32
%windir%\prey\versions\1.4.0\node_modules\satan\lib\win32
%windir%\prey\versions\1.5.0\node_modules\satan\lib\win32
%windir%\prey\versions\1.4.1\node_modules\satan\lib\win32
%windir%\temp\prey-windows-1.6.9-x86.zip\prey-1.6.9\node_modules\satan\lib\win32
%windir%\prey\versions\1.6.6\node_modules\satan\lib\win32
%windir%\prey\versions\1.6.4\node_modules\satan\lib\win32
%windir%\prey\versions\1.6.8\node_modules\satan\lib\win32
%windir%\prey\versions\1.6.9\node_modules\satan\lib\win32
nssm.exe
winlogon.exe
$R04I2H2.exe
$RBECXX4.exe
$RGKVMLS.exe
United States 21.5%
Belgium 12.0%
United Kingdom 7.3%
Venezuela 7.3%
Ecuador 6.4%
Turkey 6.0%
Canada 6.0%
Australia 4.7%
Poland 4.3%
Thailand 3.4%
Czech Republic 3.4%
Argentina 2.6%
Suriname 1.7%
Brazil 1.3%
Russia 1.3%
Tunisia 1.3%
Peru 0.9%
Croatia 0.9%
Germany 0.9%
Chile 0.9%
New Zealand 0.9%
South Korea 0.4%
Denmark 0.4%
Romania 0.4%
Pakistan 0.4%
Saudi Arabia 0.4%
India 0.4%
Finland 0.4%
Greece 0.4%
France 0.4%
South Africa 0.4%
Japan 0.4%
Spain 0.4%
Windows 10 75.5%
Windows 7 19.3%
Windows 8.1 2.6%
Windows 8 2.1%
Windows XP 0.4%
Subsystem: Windows CUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x00013e53

PE Sections:

Name Size of data MD5
.text 114176 941138fc9588f894a9667ca350164874
.rdata 18944 2a6ddc225784dfe7d0dfa7ac774200df
.data 5120 4492984c066180a50b40cbb63640632f
.rsrc 155648 51554871c0103a4ab606f99329649a6c

More information:

Download GridinSoft Anti-Malware - Removal tool for winlogon.exe
­