Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Update' = '%ALLUSERSPROFILE%\select.bat'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Firewall' = '%ALLUSERSPROFILE%\svchosd.exe'
- '%ALLUSERSPROFILE%\svchosd.exe'
- from <Full path to file> to %ALLUSERSPROFILE%\svchosd.exe
- '5.#.63.54':80
- http://5.#.63.54/crypto/gate?ac######