Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'AcidBurn Bank Catcher' = '%WINDIR%\iexplorer.scr'
- '<SYSTEM32>\regsvr32.exe' /s xyzzy.dll
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\regsvr32.exe' /s <SYSTEM32>\OSSMTP.dll
- '<SYSTEM32>\regsvr32.exe' /s xyzzy01.DLL
- <SYSTEM32>\OSSMTP.dll
- 'pa####s.aol.com.br':80
- 'localhost':1039
- pa####s.aol.com.br/EntregaCartao/OSSMTP.dll
- DNS ASK pa####s.aol.com.br
- ClassName: '' WindowName: ''