WINLOGON.EXE – Virus Sality

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

WINLOGON.EXE – Virus Sality removal

FileMD5Virus Alias
WINLOGON.EXE 1066a92ea2aed438270b3ccf0e04c778 Virus Sality
WINLOGON.EXE 1066a92ea2aed438270b3ccf0e04c778 Trojan Agent
WINLOGON.EXE 1066a92ea2aed438270b3ccf0e04c778 Trojan Swisyn

WINLOGON.EXE size: 110592 bytes
WINLOGON.EXE hash: 1066A92EA2AED438270B3CCF0E04C778

Created files:

C:\9133ed
%TEMP%\winckdx.exe
%WinDir%\winlogon.exe
D:\9137e0
D:\cert\VBoxCertUtil.exe
D:\OS2\VBoxControl.exe
D:\OS2\VBoxService.exe
D:\VBoxWindowsAdditions-amd64.exe

Autostart registry keys:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\winlogon.exe: c:\windows\winlogon.exe

Detected by UnHackMe:

WINLOGON.EXE
Default location: %WinDir%\WINLOGON.EXE

Dropper information:
MD5: 1066a92ea2aed438270b3ccf0e04c778
File size: 110592 bytes

Leave a Reply