Technical Information
- [<HKLM>\System\CurrentControlSet\Services\Wrstlm Gfghy] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Wrstlm Gfghy] 'ImagePath' = '<SYSTEM32>\Rbctu.exe -auto'
- 'Wrstlm Gfghy' <SYSTEM32>\Rbctu.exe -auto
- %WINDIR%\syswow64\rbctu.exe
- 'no##o.xyz':80
- 'no##o.xyz':8090
- DNS ASK no##o.xyz
- '%WINDIR%\syswow64\rbctu.exe' -auto
- '%WINDIR%\syswow64\rbctu.exe' -acsi