Home » Spyware Protection » Hijacked Browser Analysis » Re: HijackThisLog Analysis - Bluedaze » 

Winload.exe

Troj/Winload

Troj/Winload is a backdoor Trojan which will run in the background as a server process, allowing a remote user (using a client program) to gain access and control over the machine.

It copies itself to the Windows System directory as winload.exe and creates the registry entry HKLM\Software\Microsoft\Windows\CurrentVersion\Run\WinDLL = Windows System\winload.exe, so that the server process is run automatically each time the machine is restarted.


Mail this pageMail this page