Техническая информация
- %HOMEPATH%\My Documents\Windows\svccost.exe -t 6 -o http://ya##########ahoo.com:@pool.50btc.com:8332
- %HOMEPATH%\My Documents\Windows\winsvcs.exe
- %HOMEPATH%\My Documents\Windows\svccost.exe (загружен из сети Интернет)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\usft_ext[1].txt
- %HOMEPATH%\My Documents\Windows\miner.dll
- %HOMEPATH%\My Documents\Windows\usft_ext.dll
- %HOMEPATH%\My Documents\Windows\phatk.ptx
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\phatk[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\main[1].txt
- %HOMEPATH%\My Documents\Windows\winsvcs.exe
- %HOMEPATH%\My Documents\Windows\svccost.exe
- %HOMEPATH%\My Documents\Windows\tmp.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\m[1].txt
- %HOMEPATH%\My Documents\Windows\tmp.txt
- '14#.0.36.34':80
- 'localhost':1035
- 14#.0.36.34/u/usft_ext.txt
- 14#.0.36.34/u/phatk.txt
- 14#.0.36.34/u/main.txt
- 14#.0.36.34/u/m.txt