Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'NVIDIA Driver Service' = '%APPDATA%\Microsoft\Treiber\NvTmru.exe'
- '%APPDATA%\Microsoft\Treiber\nvvsvc.exe' -o stratum+tcp://stratum.bitcoin.cz:3333 -u Metro.Miner -p pw -I 1
- '%APPDATA%\Microsoft\Treiber\NvTmru.exe'
- '%APPDATA%\New_Universal_RapidFire_by_Thealexzava.exe'
- %APPDATA%\Microsoft\Treiber\pdcurses.dll
- %APPDATA%\Microsoft\Treiber\libusb-1.0.dll
- %APPDATA%\Microsoft\Treiber\libjansson-4.dll
- %APPDATA%\Microsoft\Treiber\zlib1.dll
- %APPDATA%\Microsoft\Treiber\pthreadGC2.dll
- %APPDATA%\Microsoft\Treiber\poclbm121016.cl
- %APPDATA%\Microsoft\Treiber\libcurl-4.dll
- %APPDATA%\Microsoft\Treiber\nvvsvc.exe
- %APPDATA%\Microsoft\Treiber\NvTmru.exe
- %APPDATA%\New_Universal_RapidFire_by_Thealexzava.exe
- %APPDATA%\Microsoft\Treiber\libblkmaker_jansson-0.1-0.dll
- %APPDATA%\Microsoft\Treiber\libblkmaker-0.1-0.dll
- %APPDATA%\Microsoft\Treiber\API.class
- 'localhost':1039
- 'el######per390.el.funpic.de':80
- 'wp#d':80
- el######per390.el.funpic.de/version.php?hw########################################################
- wp#d/wpad.dat
- DNS ASK el######per390.el.funpic.de
- DNS ASK wp#d
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'