Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\CRMSvc] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\CRMSvc] 'ImagePath' = '"%APPDATA%\CRMSvc\CRMSvc.exe"'
- %APPDATA%\CRMSvc\CRMSvc.exe
- %APPDATA%\CRMSvc\CRMSvc.InstallLog
- %APPDATA%\CRMSvc\CRMSvc.InstallState
- %APPDATA%\CRMSvc\CRMSvc.InstallLog
- %APPDATA%\CRMSvc\CRMSvc.InstallState
- 'wp#d':80
- '17#.9.8.183':2247
- '88.##8.58.40':2247
- '17#.#.118.173':2247
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK wp#d
- '%APPDATA%\CRMSvc\CRMSvc.exe' and Settings\\%USERNAME%\\Application Data\\CRMSvc\\CRMSvc.exe\" --install
- '%APPDATA%\CRMSvc\CRMSvc.exe' and Settings\\%USERNAME%\\Application Data\\CRMSvc\\CRMSvc.exe\"
- '<SYSTEM32>\sc.exe' failure \"CRMSvc\" reset= 2 actions= restart/10000