Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '<File name>.exe' = '%APPDATA%\capp\<File name>.exe'
- %APPDATA%\capp\<File name>.exe
- %TEMP%\11468$7fb3024bd.tmp
- %ALLUSERSPROFILE%\Application Data\Isolated Storage\61BED6E1\59FD041E
- 'ne##.##rlawgroup.com':443
- 'wp#d':80
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK ne##.##rlawgroup.com
- DNS ASK wp#d