Technical Information
- '<Current directory>\system32.exe' (downloaded from the Internet)
- '<Current directory>\system32.exe'
- <Current directory>\system32.exe
- <Current directory>\system32.exe
- '35.##8.19.161':80
- 'wp#d':80
- http://35.##8.19.161/primedice3/verify.php?hw#######################################
- http://35.##8.19.161/primedice2/updater.exe
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK wp#d
- ClassName: 'Shell_TrayWnd' WindowName: ''