Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'msnn' = '<Full path to virus>'
- <Current directory>\debugAviso.txt
- 'at#####ovaresita.com':80
- at#####ovaresita.com/connectrc1.php
- DNS ASK at#####ovaresita.com
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''