Technical Information
- [<HKCU>\software\microsoft\windows\currentversion\run] '<File name>' = 'wscript.exe //B "%APPDATA%\<File name>.js"'
- %APPDATA%\microsoft\windows\start menu\programs\startup\<File name>.js
- %APPDATA%\<File name>.js
- 'to##oot.ru':80
- http://to##oot.ru/gate.php
- DNS ASK to##oot.ru