Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'RTDHCPL' = 'RTDHCPL.EXE'
- '<SYSTEM32>\RTDHCPLM.EXE' --url stratum+tcp://mine.pool-x.eu --threads=1 --userpass ahatblue.1:x
- '<SYSTEM32>\RTDHCPL.EXE' --url stratum+tcp://mine.pool-x.eu --threads=1 --userpass ahatblue.1:x
- '<SYSTEM32>\reg.exe' delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v RTHDCPL /f
- '%WINDIR%\regedit.exe' /s <SYSTEM32>\libcommon.reg
- '<SYSTEM32>\cmd.exe' /c ""<SYSTEM32>\cmpanel.bat" "
- <SYSTEM32>\RTDHCPL.EXE
- <SYSTEM32>\RTDHCPLM.EXE
- C:\ProgramData\Microsoft\RAC\Temp\sqlAEE4.tmp
- C:\ProgramData\Microsoft\RAC\Temp\sqlAEF5.tmp
- <SYSTEM32>\libcurl-4.dll
- <SYSTEM32>\zlib1.dll
- <SYSTEM32>\pthreadGC2.dll
- <SYSTEM32>\cmpanel.bat
- <SYSTEM32>\libcommon.reg
- C:\ProgramData\Microsoft\RAC\Temp\sqlAEE4.tmp
- C:\ProgramData\Microsoft\RAC\Temp\sqlAEF5.tmp
- 'mi##.pool-x.eu':80
- DNS ASK mi##.pool-x.eu
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'