Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'F4D55F920000A21B000579CCB4EB2331' = '%ALLUSERSPROFILE%\F4D55F920000A21B000579CCB4EB2331\F4D55F920000A21B000579CCB4EB2331.exe'
- [<HKLM>\System\CurrentControlSet\Services\luafv] 'Start' = '00000001'
- Windows Security Center
- Windows Action Center
- %ALLUSERSPROFILE%\f4d55f920000a21b000579ccb4eb2331\f4d55f920000a21b000579ccb4eb2331.exe
- %ALLUSERSPROFILE%\f4d55f920000a21b000579ccb4eb2331\f4d55f920000a21b000579ccb4eb2331
- '11#.#55.235.9':80
- '%ALLUSERSPROFILE%\f4d55f920000a21b000579ccb4eb2331\f4d55f920000a21b000579ccb4eb2331.exe' "<Full path to file>"