Техническая информация
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\<Имя вируса>.exe
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\ping.exe' 1.1.1.1 -n 1 -w 15000
- %TEMP%\CRNJEUFU-CRNJEUFU-tempname.exe
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- 'sj#.#g.gov.br':80
- 'go###e.com.br':80
- sj#.#g.gov.br/media/app.exe
- DNS ASK sj#.#g.gov.br
- DNS ASK go###e.com.br