Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\CRNJEUFU%USERNAME%.exe
- '<SYSTEM32>\ping.exe' 1.1.1.1 -n 1 -w 5000
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\ping.exe' 1.1.1.1 -n 1 -w 25000
- '<SYSTEM32>\ping.exe' 1.1.1.1 -n 1 -w 10000
- %APPDATA%\%USERNAME%CRNJEUFU.exe
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- '14#.#48.66.107':80
- 14#.#48.66.107/Cliente5/start