Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'tsiVideo' = 'rundll32.exe %TEMP%\\mdi064.dll,runme'
- %TEMP%\mdi064.dll
- '17#.#4.128.129':1337
- '%TEMP%\iswizard05\indexer.exe' -poolip=176.34.128.129 -poolport=1337 -pooluser=AcacZaAuyFP5k1ywfjPhkPk5vR7XaX5VD6 -poolpassword=x -genproclimit=2
- '<SYSTEM32>\rundll32.exe' %TEMP%\\mdi064.dll,runme