Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '' = '<SYSTEM32>\svchosts.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'avg' = 'C:\Arquivos de programas\avg.exe'
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\avg.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\MSNone] 'ImagePath' = '<DRIVERS>\msnone.sys'
- [<HKLM>\SYSTEM\ControlSet001\Services\MSNone] 'Start' = '00000001'
- '%WINDIR%\regedit.exe' /s %TEMP%\ars.reg
- '<SYSTEM32>\cmd.exe' /c "regedit /s %TEMP%\ars.reg"
- %TEMP%\ars.reg
- <SYSTEM32>\svchosts.exe
- %TEMP%\bloinstall2
- <DRIVERS>\msnone.sys
- 'ca###es.t35.com':80
- 'www.pn#####tancia.com.ar':80
- 'localhost':1038
- http://www.pn#####tancia.com.ar/vnc/banner2.jpg
- http://ca###es.t35.com/index.php
- DNS ASK ca###es.t35.com
- DNS ASK www.pn#####tancia.com.ar
- ClassName: 'Shell DocObject View' WindowName: ''
- ClassName: 'TabWindowClass' WindowName: ''
- ClassName: 'Internet Explorer_Server' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'NDDEAgnt' WindowName: 'NetDDE Agent'