Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\h4ckkWJa5n7RRLk1kzL.lnk
- %HOMEPATH%\Start Menu\Programs\Startup\h4ckkWJa5n7RRLk1kzL.vbs
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 932
- %TEMP%\24A5D.dmp
- %TEMP%\dw.log
- %APPDATA%\h4ckkWJa5n7RRLk1kzL.exe
- %APPDATA%\h4ckkWJa5n7RRLk1kzL.exe
- %APPDATA%\h4ckkWJa5n7RRLk1kzL.exe
- %APPDATA%\h4ckkWJa5n7RRLk1kzL.exe
- 'c.##wd.se':443
- 'wp#d':80
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK c.##wd.se
- DNS ASK wp#d