Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2283880F-EF87-4aac-8EBD-C9BCC8494AF5_46' = 'rundll32.exe "%APPDATA%\2283880F-EF87-4aac-8EBD-C9BCC8494AF5_46.avi", start'
- %TEMP%\9c79fe65-2324-4f2f-833c-5aa82744e4bd\wrk1c46.tmp_46
- %APPDATA%\2283880f-ef87-4aac-8ebd-c9bcc8494af5_46.avi
- %TEMP%\9c79fe65-2324-4f2f-833c-5aa82744e4bd\wrk2cca.tmp_46
- %TEMP%\9c79fe65-2324-4f2f-833c-5aa82744e4bd\wrk1c46.tmp_46
- '91.#88.60.5':80
- '%WINDIR%\syswow64\rundll32.exe' "%TEMP%\\9c79fe65-2324-4f2f-833c-5aa82744e4bd\wrk1C46.tmp_46", start first worker
- '%WINDIR%\syswow64\rundll32.exe' "%TEMP%\\9c79fe65-2324-4f2f-833c-5aa82744e4bd\wrk2CCA.tmp_46", start task worker