Technical Information
- [HKLM\software\Wow6432Node\microsoft\windows\currentversion\Policies\Explorer\Run] '28007' = '%ProgramFiles%\locals~1\temp\msavfqpi.scr'
- %WINDIR%\syswow64\svchost.exe
- %ProgramFiles%\locals~1\temp\msavfqpi.scr
- '34.##9.100.209':443
- DNS ASK ap#####atecheckerd.com
- '%WINDIR%\syswow64\svchost.exe'