Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'explorer' = '%WINDIR%\deftesrg.exe -o stratum+tcp://xmr-eu1.nanopool.org:14444 -u 49x5oE5W2oT3p97fdH4y2hHAJvANKK86CYPxct9EeUoV3HKjYBc77X3...
- %WINDIR%\Tasks\Manager.job
- %WINDIR%\Manager.exe
- %WINDIR%\deftesrg.exe
- %TEMP%\~DF5FD0.tmp
- %TEMP%\~DF603A.tmp
- 'zt##cker.ml':80
- 'xm#####.nanopool.org':14444
- http://zt##cker.ml/click.php?cn###############
- DNS ASK zt##cker.ml
- DNS ASK xm#####.nanopool.org
- '%WINDIR%\deftesrg.exe' -o stratum+tcp://xmr-eu1.nanopool.org:14444 -u 49x5oE5W2oT3p97fdH4y2hHAJvANKK86CYPxct9EeUoV3HKjYBc77X3hb3qDfnAJCHYc5UtipUvmag7kjHusL9BV1UviNSk/129 -p x --donate-level=1 -B -t 1