Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'fa27e83a4af4d71e58df7639a5c4de5c' = '"%APPDATA%\WLanConn.exe" ..'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'fa27e83a4af4d71e58df7639a5c4de5c' = '"%APPDATA%\WLanConn.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\fa27e83a4af4d71e58df7639a5c4de5c.exe
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%APPDATA%\WLanConn.exe" "WLanConn.exe" ENABLE
- %APPDATA%\wlanconn.exe
- <Full path to file>
- %APPDATA%\wlanconn.exe
- DNS ASK wi####sdef.ddns.net
- '%APPDATA%\wlanconn.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%APPDATA%\WLanConn.exe" "WLanConn.exe" ENABLE' (with hidden window)