One way to differentiate between the legitimate and malicious processes is by checking their file properties. Right-click on the process in the Task Manager and select “”Properties.”” Look for details like the “”Description”” and “”Company”” fields. If they correspond to Microsoft and indicate it is the “”Windows Logon Application