Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'winlogonx' = '%APPDATA%\winlogonx.exe'
- User Account Control (UAC)
- %APPDATA%\winlogonx.exe
- AVP.EXE
- ekrn.exe
- %APPDATA%\wbamiod.inf
- %APPDATA%\winlogonx.exe
- %APPDATA%\winlogonx.exe
- 'aa####.dyndns.infomz??':80
- 'aa####.dyndns.info':80
- 'da#####ez6.host22.com':80
- aa####.dyndns.infomz??/
- aa####.dyndns.info/win/eueu.php?up#############
- da#####ez6.host22.com/win/eueu.php?up#############
- DNS ASK aa####.dyndns.infomzђ
- DNS ASK aa####.dyndns.info
- DNS ASK da#####ez6.host22.com
- ClassName: 'Indicator' WindowName: ''