Техническая информация
- '<SYSTEM32>\taskkill.exe' /im /f Setup.exe
- '<SYSTEM32>\taskkill.exe' /im /f Uninstall.exe
- ClassName: 'RegMonClass', WindowName: ''
- ClassName: 'FileMonClass', WindowName: ''
- %TEMP%\85E30116.TMP
- %TEMP%\Yeni.bat
- %TEMP%\Uninstall.exe
- 'xm#.###l.minergate.com':45560
- DNS ASK xm#.###l.minergate.com
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\Uninstall.exe' -o stratum+tcp://xmr.pool.minergate.com:45560 -u mingci@mynet.com -p -x -k --algo=cryptonight-lite --av=1 --donate-level=1 --safe -B
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Yeni.bat" "