Technical Information
- utrrqs.exe process, GDI32.dll module
- utrrqs.exe process, USER32.dll module
- utrrqs.exe process, apphelp.dll module
- utrrqs.exe process, win32u.dll module
- <Current directory>\skinh_el.dll
- <Current directory>\works.bat
- <Current directory>\skinh_el.dll
- <Current directory>\works.bat
- 'hr##gs.com':80
- 'localhost':80
- http://www.hr##gs.com/tj
- http://ww#.#rcygs.com/
- DNS ASK hr##gs.com
- DNS ASK ww#.#rcygs.com
- DNS ASK if####.ip138.com
- ClassName: '' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c <Current directory>\works.bat
- '%WINDIR%\syswow64\net.exe' config workstation
- '%WINDIR%\syswow64\find.exe' "╣б╫≈╒╛╙≥"
- '%WINDIR%\syswow64\find.exe' /V "DNS"
- '%WINDIR%\syswow64\net1.exe' config workstation
- '%WINDIR%\syswow64\cmd.exe' /c <Current directory>\works.bat' (with hidden window)