Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'PN' = '%WINDIR%\SysWOW64\rundll32.exe "%TEMP%\vrvhsgvja\ibtzw.dll",PathName'
- %TEMP%\vrvhsgvja\ibtzw.dll
- C:\1.txt
- '10#.#63.241.175':16300
- '10#.#63.241.193':6520
- '10#.#63.241.176':12354
- '%WINDIR%\syswow64\rundll32.exe' "%TEMP%\\vrvhsgvja\ibtzw.dll",PathName <Full path to file>