Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Ufagfe' = '%APPDATA%\Feabcy\fahydu.exe'
- %WINDIR%\syswow64\msiexec.exe
- %TEMP%\877820985
- %TEMP%\nsl8724.tmp\system.dll
- %APPDATA%\feabcy\fahydu.exe
- 'ma####ation.host':80
- DNS ASK ma####ation.host
- '%WINDIR%\syswow64\msiexec.exe'