Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\RUN] 'ekpwniaarvx' = '<Full path to file>'
- User Account Control (UAC)
- Windows Security Center
- %WINDIR%\syswow64\sethc.exe
- %WINDIR%\ekpwniaarv.dll
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: '' WindowName: 'Aplicativo ItaГє'
- '%WINDIR%\syswow64\sethc.exe'