Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\HD-Audio 9.3.8.981.lnk
- '<SYSTEM32>\wscript.exe' "C:\JVOIl16.tmp\ozO.vbs"
- 'C:\JVOIl16.tmp\taskhostky.exe' -second
- '<SYSTEM32>\attrib.exe' +h C:\JVOIl16.tmp
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: '', WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- %APPDATA%\RUT_settings\Logs\rms_log_2017-07.html
- C:\JVOIl16.tmp\ozO.vbs
- C:\JVOIl16.tmp\taskhostky.exe
- 'ru##ls.com':563
- 'ru##ls.com':5655
- 'ru##ls.com':80
- http://ru##ls.com/utils/inet_id_notify.php?te####
- DNS ASK se####.rutils.com
- DNS ASK ru##ls.com
- ClassName: '' WindowName: 'Windows Security Alert'
- ClassName: '18467-41' WindowName: ''
- ClassName: '' WindowName: 'Iiiaauaiea nenoaiu aaciianiinoe Windows'
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''