Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'winlive' = '%WINDIR%\3nvy\alg.exe'
- %WINDIR%\3nvy\alg.exe
- <SYSTEM32>\regsvr32.exe /u -s "c:\arquivos de programas\scpad\sshib.dll"
- <SYSTEM32>\attrib.exe +r +s +h %WINDIR%\3nvy
- <SYSTEM32>\regsvr32.exe /u -s "c:\arquivos de programas\scpad\scpsssh2.dll"
- <SYSTEM32>\regsvr32.exe /u -s "c:\arquivos de programas\scpad\scpLIB.dll"
- <SYSTEM32>\regsvr32.exe /u -s "c:\arquivos de programas\scpad\scpMIB.dll"
- %WINDIR%\3nvy\alg.exe
- %WINDIR%\3nvy\alg.ex
- 'ba####e.hpg.com.br':80
- ba####e.hpg.com.br/jogos.html
- DNS ASK ba####e.hpg.com.br
- ClassName: '' WindowName: 'Certificado'
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''