How to remove winlogon.exe

winlogon.exe

The module winlogon.exe has been detected as Risk.CoinMiner

winlogon.exe
Product Name:

Shadow Defender

Company Name:

SHADOWDEFENDER.COM

MD5: 8c7cdaa8007ec67ce2180213a538155d
Size: 5 MB
First Published: 2018-11-06 15:17:39 (6 years ago)
Latest Published: 2018-11-06 15:20:23 (6 years ago)
Status: Risk.CoinMiner (on last analysis)
Analysis Date: 2018-11-06 15:20:23 (6 years ago)
%desktop%
100.0%
Windows Server 2008 R2 100.0%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0005f2a7

PE Sections:

Name Size of data MD5
.text 512000 6d6e2f722436d22aa759cc5cb38f7028
.rdata 4866048 3c37af33b4166801f860d65b0d27c477
.data 73728 2d1bcdc2bb994928fbaa9e33ce85dcd6
.rsrc 69632 85a2eea5d26cf2db3489946d7e00e1bf

More information:

Download GridinSoft Anti-Malware - Removal tool for winlogon.exe