Technical Information
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\msiexec.exe'
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- 'ye##5.com':80
- '20#.#6.232.182':80
- http://ye##5.com/system.php
- DNS ASK ye##5.com
- DNS ASK up####.microsoft.com