Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'RDO89' = '%APPDATA%\WinKeys\WinKeys.exe'
- User Account Control (UAC)
- '%APPDATA%\WinKeys\WinKeys.exe'
- %APPDATA%\WinKeys\WinKeys_.tmp
- %APPDATA%\WinKeys\WinKeys.exe
- %APPDATA%\WinKeys\funcs.dll
- 'sm###.uol.com.br':587
- DNS ASK sm###.uol.com.br
- ClassName: 'Indicator' WindowName: ''
- ClassName: '' WindowName: 'RDO89_'