Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Winupdate' = '%APPDATA%\Winupdate\winupdate.exe'
- %HOMEPATH%\My Documents\Windows\winsvchost.exe -t 2 -o http://pr#############gger:nissbogger@eu.triplemining.com:8344
- %APPDATA%\Winupdate\winupdate.exe
- %HOMEPATH%\My Documents\Windows\winsvchost.exe (загружен из сети Интернет)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\phatk[1].txt
- %HOMEPATH%\My Documents\Windows\usft_ext.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\usft_ext[1].txt
- %HOMEPATH%\My Documents\Windows\phatk.cl
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\phatk[1].cl
- %HOMEPATH%\My Documents\Windows\phatk.ptx
- %HOMEPATH%\My Documents\Windows\coinutil.dll
- %HOMEPATH%\My Documents\Windows\winsvchost.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\main[1].txt
- %APPDATA%\Winupdate\winupdate.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\coinutil[1].txt
- %HOMEPATH%\My Documents\Windows\miner.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\miner[1].txt
- '14#.0.36.38':80
- 'localhost':1036
- 14#.0.36.38/u2/usft_ext.txt
- 14#.0.36.38/u2/phatk.txt
- 14#.0.36.38/u2/phatk.cl
- 14#.0.36.38/u2/main.txt
- 14#.0.36.38/u2/miner.txt
- 14#.0.36.38/u2/coinutil.txt
- ClassName: 'Indicator' WindowName: ''