Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Sound Driver' = 'C:\Topol\autoexec.bat'
- C:\Topol\phoenix\hstart.exe (загружен из сети Интернет) /NOCONSOLE "phoenix.exe -u http://ma############:persianok@useast.btcguild.com:8332/ -k poclbm DEVICE=0 VECTORS WORKSIZE=128 AGGRESSION=1
- <SYSTEM32>\cmd.exe /c ""C:\Topol\autoexec.bat" "
- C:\Topol\phoenix\kernels\poclbm\__init__.py
- C:\Topol\phoenix\kernels\poclbm\BFIPatcher.py
- C:\Topol\phoenix\kernels\phatk\kernel.cl
- C:\Topol\phoenix\kernels\phatk\__init__.py
- C:\Topol\phoenix\kernels\phatk\BFIPatcher.py
- C:\Topol\phoenix\kernels\poclbm\kernel.cl
- C:\Topol\autoexec.bat
- C:\Userfile.txt
- C:\Topol\phoenix\hstart.exe
- C:\Topol\phoenix\XXMKLINK.EXE
- C:\Topol\phoenix\phoenix.exe
- C:\Topol\phoenix\phoenix.exe
- C:\Topol\autoexec.bat
- 'www.tr##ld.info':80
- www.tr##ld.info/btc/kernels/phatk/kernel.cl
- www.tr##ld.info/btc/kernels/poclbm/__init__.py
- www.tr##ld.info/btc/kernels/phatk/__init__.py
- www.tr##ld.info/btc/kernels/phatk/BFIPatcher.py
- www.tr##ld.info/btc/kernels/poclbm/BFIPatcher.py
- www.tr##ld.info/btc/phoenix.exe
- www.tr##ld.info/btc/hstart.exe
- www.tr##ld.info/btc/kernels/poclbm/kernel.cl
- www.tr##ld.info/btc/XXMKLINK.EXE
- DNS ASK www.tr##ld.info
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''