Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '774f3dc69d40b042d0b3ee9738ce7853' = '"%APPDATA%\winIogon.exe" ..'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '774f3dc69d40b042d0b3ee9738ce7853' = '"%APPDATA%\winIogon.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\774f3dc69d40b042d0b3ee9738ce7853.exe
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%APPDATA%\winIogon.exe" "winIogon.exe" ENABLE
- %APPDATA%\winiogon.exe
- DNS ASK wi####on.myftp.org
- '%APPDATA%\winiogon.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%APPDATA%\winIogon.exe" "winIogon.exe" ENABLE' (with hidden window)