Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdater' = '<Current directory>'
- %HOMEPATH%\Start Menu\Programs\Startup\d1gd5gd15.lnk
- '<SYSTEM32>\schtasks.exe' /Create /SC minute /MO 20 /TN taskhost /TR <Full path to file>
- <Full path to file>
- 'pa###bin.com':443
- 'wp#d':80
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK pa###bin.com
- DNS ASK wp#d