Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\sistemm.lnk
- <Текущая директория>\q0.bat
- <Текущая директория>\Buildhid.exe
- C:\ProgramData\Build.exe
- C:\ProgramData\drive.exe
- C:\ProgramData\sistem.exe
- %WINDIR%\drive.exe
- %WINDIR%\sistem.exe
- %WINDIR%\start.cmd
- %WINDIR%\xmrig.exe
- 'xm#.###l.minergate.com':45700
- DNS ASK xm#.###l.minergate.com
- ClassName: 'EDIT' WindowName: ''
- '<Текущая директория>\Buildhid.exe' -pjhgfrgtrnjgnbbdgdjnjh8y45u90uy8hgufbnfkjhxbjdbjdxbdjkbjbuibfubi -dC:\ProgramData
- 'C:\ProgramData\Build.exe'
- '%WINDIR%\xmrig.exe' -B --max-cpu-usage 60 -o stratum+tcp://xmr.pool.minergate.com:45700 -u nortongetio@yandex.ru -p sistem -k
- '<SYSTEM32>\cmd.exe' /c ""<Текущая директория>\q0.bat" "
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\start.cmd" "