Technical Information
- '%WINDIR%\syswow64\regsvr32.exe' -s ..\fbd.dll
- %HOMEPATH%\fbd.dll
- <Current directory>\39061000
- <PATH_SAMPLE>.xls
- 'me#.#evsrm.com':80
- http://me#.#evsrm.com/wp-content/gtOOTHi3zkUbn8U6/
- http://me#.#evsrm.com/cgi-sys/suspendedpage.cgi
- DNS ASK me#.#evsrm.com
- '%WINDIR%\syswow64\regsvr32.exe' -s ..\fbd.dll' (with hidden window)