Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WindowsFilterCheck' = 'C:\Arquivos de programas\<Virus name>.exe'
- [<HKLM>\SYSTEM\ControlSet001\Control\Session Manager] 'BootExecute' = ''
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\<Virus name>.exe
- %WINDIR%\winload.inf
- %WINDIR%\Arq.ini
- %WINDIR%\done.dll
- <SYSTEM32>\A_CRNJEUFU.txt
- <Full path to virus>
- %WINDIR%\Arq.ini
- 'localhost':1044
- 'h1.##pway.com':80
- '74.##5.232.51':25
- 'br.#sn.com':80
- 'ft##.#ravehost.com':21
- http://h1.##pway.com/primario/arq.ini
- DNS ASK gs####85.google.com
- DNS ASK h1.##pway.com
- DNS ASK gm######tp-in.l.google.com
- DNS ASK br.#sn.com
- DNS ASK ft##.#ravehost.com