Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'tarjsdefy' = 'regsvr32.exe /s "%LOCALAPPDATA%\ApplicationHistory\tarjsdefy.dll"'
- msinfo32.exe
- %LOCALAPPDATA%\applicationhistory\tarjsdefy.dll
- '10#.#06.180.132':80
- http://10#.#06.180.132/en-us/3L+y8u/q8u/wuO6l84nkppPw7+zo8O7l7fA=
- '%CommonProgramFiles(x86)%\microsoft shared\msinfo\msinfo32.exe'