Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\afagmuch] 'Startup' = 'WLStartupEvent'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\afagmuch] 'DllName' = 'afagmuch.dll'
- <SYSTEM32>\winlogon.exe
- <SYSTEM32>\afagmuch.dll
- 'sm##.gmail.com':25
- DNS ASK sm##.gmail.com
- '<Private IP address>':1034