ANTÍDOTO Security

GPLControl.exe: Windows persistence and reinfection

GPLControl.exe is a filename observed in the real infection pattern that led to ANTÍDOTO. In that case it was found under C:\Users\Public\Libraries\ and linked to Windows startup persistence.

Why it matters

Deleting shortcuts from a USB drive does not solve the problem if a Windows persistence mechanism remains active. A clean removable drive can be infected again when connected to the affected computer.

Observed indicator

In our analyzed sample, GPLControl.exe matched the same known SHA-256 as USB-Explorer.exe:

3F3E84744C41D44CE8EC2CBBB6E97B837B5EA9E18CADEE57781497AD23D80E09
A filename alone is not enough to classify arbitrary software as malware. ANTÍDOTO correlates names with hashes, persistence and the surrounding infection pattern.