Technical Information
- [<HKLM>\System\CurrentControlSet\Services\Video Remote Device Auto-Discovery Foundation] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Video Remote Device Auto-Discovery Foundation] 'ImagePath' = 'C:\robblfhvtv\zrrjdqdyvsg.exe'
- 'Video Remote Device Auto-Discovery Foundation' C:\robblfhvtv\zrrjdqdyvsg.exe
- %WINDIR%\robblfhvtv\kudnsssq
- C:\robblfhvtv\kudnsssq
- C:\robblfhvtv\petdf9ockmuifcu.exe
- C:\robblfhvtv\zrrjdqdyvsg.exe
- C:\robblfhvtv\ujznvttg.exe
- C:\robblfhvtv\ktmpczilhkg7
- C:\robblfhvtv\zrrjdqdyvsg.exe
- C:\robblfhvtv\ujznvttg.exe
- %WINDIR%\robblfhvtv\kudnsssq
- C:\robblfhvtv\petdf9ockmuifcu.exe
- %WINDIR%\robblfhvtv\kudnsssq
- '81.#34.1.9':45279
- '2.##.170.96':35711
- '18#.#52.148.185':41862
- '83.##0.75.248':22437
- '85.##6.62.161':29923
- '2.##.140.53':27577
- '18#.2.10.6':44843
- 'C:\robblfhvtv\petdf9ockmuifcu.exe'
- 'C:\robblfhvtv\zrrjdqdyvsg.exe'
- 'C:\robblfhvtv\ujznvttg.exe' "c:\robblfhvtv\zrrjdqdyvsg.exe"