Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe , %TEMP%\controller.exe http://www.thecarolinaweigh.com/images/default/line'
- 'th#####linaweigh.com':80
- http://www.th#####linaweigh.com/images/default/controller.exe
- http://www.th#####linaweigh.com/images/default/s.exe
- http://www.th#####linaweigh.com/images/default/b1.dll
- http://www.th#####linaweigh.com/images/default/b2.dll
- http://www.th#####linaweigh.com/images/default/c1.dll
- http://www.th#####linaweigh.com/images/default/c2.dll
- http://www.th#####linaweigh.com/images/default/c3.dll
- http://www.th#####linaweigh.com/images/default/c4.dll
- http://www.th#####linaweigh.com/images/default/c5.dll
- DNS ASK th#####linaweigh.com