Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2283880F-EF87-4aac-8EBD-C9BCC8494AF5_46' = 'rundll32.exe "%APPDATA%\2283880F-EF87-4aac-8EBD-C9BCC8494AF5_46.avi", start'
- %TEMP%\62dc8ca5-e0a0-4f7b-a149-b5a9d079bdaf\wrk9c3e.tmp_46
- %APPDATA%\2283880f-ef87-4aac-8ebd-c9bcc8494af5_46.avi
- %TEMP%\62dc8ca5-e0a0-4f7b-a149-b5a9d079bdaf\wrkba78.tmp_46
- %TEMP%\62dc8ca5-e0a0-4f7b-a149-b5a9d079bdaf\wrk9c3e.tmp_46
- '91.#88.60.5':80
- '%WINDIR%\syswow64\rundll32.exe' "%TEMP%\\62dc8ca5-e0a0-4f7b-a149-b5a9d079bdaf\wrk9C3E.tmp_46", start first worker
- '%WINDIR%\syswow64\rundll32.exe' "%TEMP%\\62dc8ca5-e0a0-4f7b-a149-b5a9d079bdaf\wrkBA78.tmp_46", start task worker