Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2283880F-EF87-4aac-8EBD-C9BCC8494AF5_40' = 'rundll32.exe "%APPDATA%\2283880F-EF87-4aac-8EBD-C9BCC8494AF5_40.avi", start'
- %TEMP%\insfa9.tmp
- %APPDATA%\2283880f-ef87-4aac-8ebd-c9bcc8494af5_40.avi
- '91.#88.60.5':80
- '34.##9.100.209':443
- '%WINDIR%\syswow64\rundll32.exe' "%TEMP%\insFA9.tmp", start first worker