Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'IilpOjira' = 'regsvr32.exe "%ALLUSERSPROFILE%\IilpOjira\IilpOjira.dat"'
- <SYSTEM32>\fontdrvhost.exe
- <SYSTEM32>\wudfhost.exe
- <SYSTEM32>\spoolsv.exe
- <SYSTEM32>\sihost.exe
- <SYSTEM32>\taskhostw.exe
- %TEMP%\iawrivtiw\iilpojira.dat