Timeline
htbot with MD5 e515267ba19417974a63b51e4f7dd9e9.
Wed Apr 22 11:52:04 CEST 2015
Started win9 already infected
Thu Apr 22 18:10 CEST 2015
Approximately at this hour the VM was powered off alone. Weird.