Winload.exe
Troj/Winload
Troj/Winload is a backdoor Trojan which will run in the background as a server process, allowing a remote user (using a client program) to gain access and control over the machine.
It copies itself to the Windows System directory as winload.exe and creates the registry entry HKLM\Software\Microsoft\Windows\CurrentVersion\Run\WinDLL = Windows System\winload.exe, so that the server process is run automatically each time the machine is restarted.
|