Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\efdconn.lnk
- %HOMEPATH%\desktop\efdconn.lnk
- %APPDATA%\efdconn\agent-startup.cmd
- %APPDATA%\efdconn\agent.cmd
- %APPDATA%\efdconn\agent.jar
- %APPDATA%\efdconn\agent.nsi
- %TEMP%\hsperfdata_user\2032
- %APPDATA%\efdconn\logs.log
- '%WINDIR%\syswow64\cmd.exe' /C "%APPDATA%\efdconn\agent.cmd"
- '%WINDIR%\syswow64\tasklist.exe' /NH /FI "IMAGENAME eq javaw.exe"
- '%WINDIR%\syswow64\find.exe' /I "javaw.exe"