Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe rundll32.exe helh.oso vtfeb'
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\helh.oso
- 'it####owtime.net':80
- it####owtime.net/css/ss.php?id##################################
- DNS ASK it####owtime.net