Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '{F86644DA-8935-34FF-57EA-AAAED00F348A}' = '"%APPDATA%\Iguku\ehili.exe"'
- %APPDATA%\Iguku\ehili.exe
- <SYSTEM32>\cscript.exe
- %APPDATA%\Iguku\o.d
- %TEMP%\tmp5b04c605.bat
- %APPDATA%\oemfpc.dat
- %APPDATA%\Iguku\ehili.exe
- 'ma####nancefree.eu':80
- ma####nancefree.eu/mz/l/ist.dat
- DNS ASK ma####nancefree.eu
- ClassName: 'Indicator' WindowName: ''