Technical Information
- %HOMEPATH%\BacAvs.exe (downloaded from the Internet)
- %WINDIR%\cteplay.exe
- <SYSTEM32>\rundll32.exe <SYSTEM32>\shell32.dll,OpenAs_RunDLL %WINDIR%\cteplay.pps
- <SYSTEM32>\cmd.exe /c ""%WINDIR%\cteplay.bat" "
- %HOMEPATH%\BacAvs.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\anel[1].cdc
- %HOMEPATH%\BTStacMsn.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\aliancas[1].cdc
- %WINDIR%\cteplay.bat
- %WINDIR%\cteplay.exe
- %WINDIR%\cteplay.pps
- 'www.ca###sbijus.com':80
- 'localhost':1035
- www.ca###sbijus.com/produto/brincos.cdc
- www.ca###sbijus.com/produto/anel.cdc
- www.ca###sbijus.com/produto/aliancas.cdc
- DNS ASK www.ca###sbijus.com
- '<Private IP address>':1036
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''