Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Defender' = '<DRIVERS>\winlogon.exe'
- Windows Task Manager (Taskmgr)
- Registry Editor (RegEdit)
- User Account Control (UAC)
- 'www.es####annunci.org':80
- 'www.ci#.cl':80
- 'www.od#####gontoperu.cofdfm':80
- 'localhost':1039
- 'co####dadjumper.com':80
- 'wp#d':80
- www.ci#.cl/web/contenido/image/instalaciones/http.config
- www.od#####gontoperu.cofdfm/uploadfds/articulos/aa/htdacces
- www.es####annunci.org/sito/images/themes/http.config
- co####dadjumper.com/Online/index.php?ma########################################
- wp#d/wpad.dat
- DNS ASK www.ci#.cl
- DNS ASK www.od#####gontoperu.cofdfm
- DNS ASK www.es####annunci.org
- DNS ASK co####dadjumper.com
- DNS ASK wp#d
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''