Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Services.exe' = '%TEMP%\Services.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
- %TEMP%\Services.exe
- 'xm#.#ine.pro':3333
- DNS ASK xm#.#ine.pro
- '%TEMP%\Services.exe'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe' -B --donate-level=0 -t 1 -a cryptonight --url=xmr.mine.pro:3333 -u 4BrL51JCc9NGQ71kWhnYoDRffsDZy7m1HUU7MRU4nUMXAHNFBEJhkTZV9HdaL4gfuNBxLPc3BeMkLGaPbF5vWtANQuka1XTqq2qMScxzg9 -p x -R --variant=-...