Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ShellExperienceHost' = '%TEMP%\System32\Logs\ShellExperienceHost.exe'
- %TEMP%\aut2b53.tmp
- %TEMP%\appdata\778899.exe
- %TEMP%\sourse.exe
- %TEMP%\aut4340.tmp
- %TEMP%\system32\logs\microsoftshellhost.exe
- %TEMP%\aut44b8.tmp
- %TEMP%\system32\logs\shellexperiencehost.exe
- %TEMP%\windowstask\microsoftshellhost.exe
- %TEMP%\windowstask\microsoftshellhost.exe
- %TEMP%\system32\logs\shellexperiencehost.exe
- %TEMP%\aut2b53.tmp
- %TEMP%\aut4340.tmp
- %TEMP%\aut44b8.tmp
- %TEMP%\appdata\778899.exe
- %TEMP%\system32\logs\microsoftshellhost.exe
- 'ip###ger.com':443
- DNS ASK ip###ger.com
- ClassName: 'Static' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\appdata\778899.exe' -p000111222q
- '%TEMP%\sourse.exe'
- '%TEMP%\system32\logs\shellexperiencehost.exe'
- '%TEMP%\windowstask\microsoftshellhost.exe' -o stratum+tcp://xmr.pool.minergate.com:45560 -u olegovolen@ya.ru -p x -t 0
- '<SYSTEM32>\cmd.exe' /c %TEMP%\WindowsTask\MicrosoftShellHost.exe -o stratum+tcp://xmr.pool.minergate.com:45560 -u olegovolen@ya.ru -p x -t 0' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c %TEMP%\WindowsTask\MicrosoftShellHost.exe -o stratum+tcp://xmr.pool.minergate.com:45560 -u olegovolen@ya.ru -p x -t 0