Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Ferrari' = '<SYSTEM32>\scvhost.exe'
- %TEMP%\129437_xeex.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\xfz[1].txt
- %TEMP%\129437_xeex.tmp
- 'd.##r8.com':80
- 'localhost':1035
- d.##r8.com/down/03/xfz.txt
- DNS ASK d.##r8.com