Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2283880F-EF87-4aac-8EBD-C9BCC8494AF5_39' = 'rundll32.exe "%APPDATA%\2283880F-EF87-4aac-8EBD-C9BCC8494AF5_39.avi", start'
- %TEMP%\ins5c42.tmp
- %APPDATA%\2283880f-ef87-4aac-8ebd-c9bcc8494af5_39.avi
- '91.#88.60.5':80
- '%WINDIR%\syswow64\rundll32.exe' "%TEMP%\ins5C42.tmp", start first worker