Home Malware Programs Trojans LolaWeb.winhost

LolaWeb.winhost

Posted: March 28, 2006

LolaWeb.winhost is a Trojan horse which drops a copy of itself name WINTT.EXE or WINH.EXE in windows directory and adds itself in the registry to make it start each time a user logs in.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 WINH.EXE
    2 WINTT.EXE

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}Browsetothekey:HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunIntherightpanedeletethevaluecalledWinhostifitexists.
Loading...