Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\stone.lnk
- Диспетчера задач (Taskmgr)
- %WINDIR%\child.exe
- %WINDIR%\childsong.exe
- %WINDIR%\stone.vbs
- %WINDIR%\1.bat
- %WINDIR%\start.bat
- <SYSTEM32>.bat
- <SYSTEM32>.exe
- 'po##.#upportxmr.com':5555
- DNS ASK po##.#upportxmr.com
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\childsong.exe'
- '%WINDIR%\child.exe'
- '%WINDIR%\syswow64\wscript.exe' "%WINDIR%\Stone.vbs"
- '<SYSTEM32>.exe' --auto --any --forever --keepalive --variation 0 --low -o pool.supportxmr.com:5555 -u 4Hm3YrYNgczRAP7jbGCZ7vA8XwbBR8DWMU7Bm9FKZqjxQXPPcwMP1kDbK3mtBSdt2c6TmLCPiMSXa39uBiEBwkg4FXqSXZE1GesPGGqsE6 ...
- '%WINDIR%\syswow64\cmd.exe' /c ""<SYSTEM32>.bat" "' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""%WINDIR%\1.bat" "' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""<SYSTEM32>.bat" "
- '%WINDIR%\syswow64\cmd.exe' /c ""%WINDIR%\1.bat" "
- '%WINDIR%\syswow64\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /f