Техническая информация
- [<HKLM>\software\Wow6432Node\microsoft\windows\currentversion\Policies\Explorer\Run] '56412' = '%ProgramFiles%\locals~1\temp\msfvwt.cmd'
- %WINDIR%\syswow64\svchost.exe
- %ProgramFiles%\locals~1\temp\msfvwt.cmd
- 'di##shot.us':80
- http://di##shot.us/free/image.php
- DNS ASK di##shot.us
- '%WINDIR%\syswow64\svchost.exe'