|
winlogon.exe (5.1.2600.1106)
Enthalten in den Programmen |
Name: | Windows XP Home Edition, Deutsch |
Lizenz: | kommerziell |
Info-Link: | http://www.microsoft.com/windowsxp/ |
Dateidetails |
Dateipfad: | C:\WINDOWS\system32 \ winlogon.exe |
Dateidatum: | 2002-08-29 14:00:00 |
Version: | 5.1.2600.1106 |
Dateigröße: | 521.728 Bytes |
Prüfsumme und Datei-Hashwerte |
CRC32: | EFFDF5E1 |
MD5: | 6168 96B7 0828 6DA9 8D6A 0992 93F1 81D7 |
SHA1: | 3185 27E4 C475 E203 B220 2C43 7482 EACC C542 0195 |
Versions-Informationen |
Firmenname: | Microsoft Corporation |
Datei-Beschreibung: | Windows NT-Anmeldung |
Datei-Betriebssystem: | Windows NT, Windows 2000, Windows XP, Windows 2003 |
Datei-Typ: | Application |
Datei-Version: | 5.1.2600.1106 |
Interner Name: | winlogon |
Copyright: | © Microsoft Corporation. Alle Rechte vorbehalten. |
Ursprünglicher Dateiname: | WINLOGON.EXE |
Produktname: | Betriebssystem Microsoft® Windows® |
Produktversion: | 5.1.2600.1106 |
winlogon.exe wurde in den folgenden Reports gefunden:
|
W32.Neveg.A@mm |
Technische Details ...Copies itself as %Windir%systemwinlogon.exe. Note: %Windir% is a variable... ...".Prog" = "%Windir%systemwinlogon.exe" "BuildLab" = "%Windir%systemwinlogon.exe"... ..."ccApps" = "%Windir%systemwinlogon.exe" "FriendlyTypeName"... ..."Microsoft Visual SourceSafe"= "%Windir%systemwinlogon.exe" "RegDone" = "%Windir%systemwinlogon.exe"... ..."TEXTCONV" = "%Windir%systemwinlogon.exe" "WMAudio" = "%Windir%systemwinlogon.exe"... Entfernungs-Anweisungen ...".Prog" = "%Windir%systemwinlogon.exe" "BuildLab" = "%Windir%systemwinlogon.exe"... ..."ccApps" = "%Windir%systemwinlogon.exe" "FriendlyTypeName"... ..."Microsoft Visual SourceSafe"= "%Windir%systemwinlogon.exe" "RegDone" = "%Windir%systemwinlogon.exe"... ..."TEXTCONV" = "%Windir%systemwinlogon.exe" "WMAudio" = "%Windir%systemwinlogon.exe"... Quelle: http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.a@mm.html |
Backdoor.Graybird |
Technische Details ...%System%Svch0st.exe %System%Winlogon.exe %System%Explorer.exe... ..."winlogon"="%System%Winlogon.exe" "system"="%System%Explorer.exe"... Entfernungs-Anweisungen ..."winlogon"="%System%Winlogon.exe" "system"="%System%Explorer.exe"... Quelle: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.graybird.html |
W32.Marol@mm |
Technische Details ...itself as the following files: %Windir%Winlogon.exe %Windir%Marisol.exe... ..."Apnt" = "%Windir%winlogon.exe" "WorksCache" = "%Windir% empWkCVX.exe"... Entfernungs-Anweisungen ..."Apnt" = "%Windir%winlogon.exe" "WorksCache" = "%Windir% empWkCVX.exe"... Quelle: http://securityresponse.symantec.com/avcenter/venc/data/w32.marol@mm.html |
Backdoor.Trodal |
Technische Details ...Copies itself to %Windir%Winlogon.exe. Note: %Windir% is a variable.... ...Creates the registry value "winlogon"="%windir%winlogon.exe"... ...Sets the file timestamp of %Windir%Winlogon.exe to the same values as the file, %Windir%win.ini.... Entfernungs-Anweisungen ...right pane, delete the value: "winlogon"="%windir%winlogon.exe"... Quelle: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.trodal.html |
Backdoor.Dsklite |
Technische Details ...Copies itself as %Windir%Winlogon.exe. NOTE: %Windir% is a variable.... ..."Windows Logon Application"="%Windir%winlogon.exe" to the registry key:... Entfernungs-Anweisungen ...Scroll through the list and look for winlogon.exe. If you find the file, click... ..."Windows Logon Application"="%Windir%winlogon.exe" Exit the Registry Editor.... Quelle: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.dsklite.html |
Trojan.Hazzer |
Technische Details ...or: "winlogon"=<path to trojan>... ...L2logon.exe Winlogon.exe Tries to delete C:Msdos.exe.... Entfernungs-Anweisungen ...or: "winlogon"=<path to trojan>... Quelle: http://securityresponse.symantec.com/avcenter/venc/data/trojan.hazzer.html |
Spyware.TrueActive |
Technische Details ..._.exe; tamset.exe; sem.dll; winsdoc.dll; winlogon.exe When Spyware.TrueActive is... ...detected as Spyware.TrueActive) %Windir%winlogon.exe (main logger, detected as Spyware.TrueActive)... Quelle: http://securityresponse.symantec.com/avcenter/venc/data/spyware.trueactive.html |
Backdoor.Prorat |
Technische Details ...%System%Sservice.exe %Windir%Winlogon.exe Notes:... ...HKEY_LOCAL_MACHINESoftwareMicrosoftWindows NTCurrentVersionWinlogon from:... ...May inject a .dll file into the Winlogon process as a thread, which will end the processes of various security products.... Entfernungs-Anweisungen ...HKEY_LOCAL_MACHINESoftwareMicrosoftWindows NTCurrentVersionWinlogon In the right pane, modify... Quelle: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.prorat.html |
Backdoor.Beasty.H |
Technische Details ...Systray.exe Winlogon.exe NOTE:... Quelle: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.beasty.h.html |
Intruder Alert 3.6 W32_Netsky_D_Worm Policy |
following file to be monitored: #windirwinlogon.exe Last modified on:... ...... Quelle: http://securityresponse.symantec.com/avcenter/security/Content/2004.03.01.html |
|
|