Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] 'AppInit_DLLs' = ',%TEMP%\551ymg.dll'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\a.baT" "
- %TEMP%\a.baT
- %TEMP%\551ymg.dll
- 'www.by####allation.com':80
- http://www.by####allation.com/admin/install.asp?in###################
- DNS ASK www.by####allation.com
- ClassName: 'GxWindowClassD3d' WindowName: ''