Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WinHesp32' = '<SYSTEM32>\WinHatt32.exe'
- <SYSTEM32>\WinHatt32.exe
- <SYSTEM32>\WinHatt32.exe
- <Full path to file>
- 'vi##.f3322.org':3588
- DNS ASK vi##.f3322.org
- '<SYSTEM32>\WinHatt32.exe'
- '<SYSTEM32>\cmd.exe' /c del <Full path to file> > nul