Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'winlgr' = '%WINDIR%\winlgr.exe'
- '%WINDIR%\winlgr.exe'
- '%WINDIR%\winlgr.exe' (downloaded from the Internet)
- '<SYSTEM32>\reg.exe' ADD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v winlgr /t REG_SZ /d %WINDIR%\winlgr.exe
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\winn.cmd" "
- %WINDIR%\winlgr.exe
- %WINDIR%\winn.cmd
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\winlgr[1].exe
- %TEMP%\~DF4D9F.tmp
- 's1#.##loadfa.com':80
- 'localhost':1036
- s1#.##loadfa.com/files/3/w1kanq6pgllw6u/winlgr.exe
- DNS ASK s1#.##loadfa.com