Техническая информация
- '%WINDIR%\inf\wpabaln32.exe'
- '%WINDIR%\inf\wpabaln32.exe' (загружен из сети Интернет)
- '<SYSTEM32>\regsvr32.exe' /s %WINDIR%\wshom.dll.dll
- %WINDIR%\wshom.dll.dll
- %WINDIR%\winlockdll.dll
- %WINDIR%\inf\wpabaln32.exe
- 'ww###.#apidupload.com':80
- 'localhost':1037
- ww###.#apidupload.com/file.php?fi############
- DNS ASK ww###.#apidupload.com
- ClassName: 'Shell_TrayWnd' WindowName: ''