Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'DeviceParinWizard' = '%TEMP%\DellDrve\DeviceParinWizard.exe'
- %TEMP%\DellDrve\DeviceParinWizard.exe
- <Текущая директория>\AutoRunApp.vbs
- %TEMP%\DellDrve\help_32_64.exe
- %TEMP%\DellDrve\1.txt
- <Текущая директория>\AutoRunApp.vbs
- 'xm#.#2pool.com':13531
- 'us###.qzone.qq.com':80
- '12#.#25.114.144':80
- http://us###.qzone.qq.com/fcg-bin/cgi_get_portrait.fcg?ui#############
- http://www.ba##u.com/ via 12#.#25.114.144
- DNS ASK xm#.#2pool.com
- DNS ASK us###.qzone.qq.com
- DNS ASK www.ba##u.com
- ClassName: '' WindowName: ''
- '<SYSTEM32>\wscript.exe' "<Текущая директория>\AutoRunApp.vbs"
- '%TEMP%\DellDrve\help_32_64.exe' --donate-level 1 --no-huge-pages --safe --cpu-priority 5 --max-cpu-usage 75 -v 0 -o xmr.f2pool.com:13531 -u 48gM3TSMCeufGf14Ug6XdRN1r8YAg8rh7TFBkh5iz3uSJujperZnPjpVQMNjMydFjaYEqpsc8Dd9T7w9Lfi6b...
- '<SYSTEM32>\cmd.exe' /c %TEMP%\DellDrve\help_32_64.exe --donate-level 1 --no-huge-pages --safe --cpu-priority 5 --max-cpu-usage 75 -v 0 -o xmr.f2pool.com:13531 -u 48gM3TSMCeufGf14Ug6XdRN1r8YAg8rh7TFBkh5iz3uSJujperZ...