Техническая информация
- [<HKLM>\software\Wow6432Node\microsoft\windows\currentversion\Policies\Explorer\Run] '19176' = '%ProgramFiles%\locals~1\Temp\msavudicw.pif'
- %WINDIR%\syswow64\svchost.exe
- %ProgramFiles%\locals~1\temp\msavudicw.pif
- 'ma###ery.club':80
- http://ma###ery.club/club/image.php
- DNS ASK ma###ery.club
- '%WINDIR%\syswow64\svchost.exe'