Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\MicrosoftB.exe
- 'le###.vru.ac.th':80
- 'wp#d':80
- http://le###.vru.ac.th/images/user/file/botbitcoin.exe
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK le###.vru.ac.th
- DNS ASK wp#d
- ClassName: 'Shell_TrayWnd' WindowName: ''