Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Defender' = '%WINDIR%\system\winlogon.exe'
- User Account Control (UAC)
- <DRIVERS>\etc\hosts
- http://www.rs#####nicativa.com.ar/admin/images/fotos/imaA8433.jpg
- http://rs#####nicativa.com.ar/admin/images/fotos/imaA8433.jpg
- http://www.yo##ube.com/watch?v=###########
- DNS ASK rs#####nicativa.com.ar
- DNS ASK yo##ube.com
- DNS ASK i.##img.com
- DNS ASK fo###.#oogleapis.com
- DNS ASK fo###.gstatic.com
- DNS ASK accounts.google.com
- DNS ASK r3########ne6n7l.googlevideo.com
- DNS ASK ss#.#static.com
- ClassName: 'DDEMLMom' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''