Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run\] 'taskhost' = '"%APPDATA%\taskhost.exe"'
- %TEMP%\ixp000.tmp\ethern~1.exe
- %TEMP%\ixp000.tmp\hwidsp~1.exe
- %APPDATA%\taskhost.exe
- %TEMP%\pmstart.exe
- 'google.com':80
- 'i.###img.com':443
- 'i.###img.com':443
- DNS ASK google.com
- DNS ASK i.###img.com
- '%TEMP%\ixp000.tmp\ethern~1.exe'
- '%TEMP%\ixp000.tmp\hwidsp~1.exe'
- '%APPDATA%\taskhost.exe'
- '%TEMP%\pmstart.exe' -pool eu1.ethermine.org:4444 -wal 0xbe4254d614f7096f3a1b24596f1e4f5ab497f31c -worker yxFqNmgq -log 0 -fcm 0 -powlim 75
- '%TEMP%\ixp000.tmp\ethern~1.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C TIMEOUT /T 5 /NOBREAK && "%APPDATA%\taskhost.exe"' (со скрытым окном)
- '%TEMP%\ixp000.tmp\hwidsp~1.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C "%TEMP%\pmstart.exe" -pool eu1.ethermine.org:4444 -wal 0xbe4254d614f7096f3a1b24596f1e4f5ab497f31c -worker yxFqNmgq -log 0 -fcm 0 -powlim 75' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C TIMEOUT /T 5 /NOBREAK && "%APPDATA%\taskhost.exe"
- '%WINDIR%\syswow64\timeout.exe' /T 5 /NOBREAK
- '%WINDIR%\syswow64\cmd.exe' /C "%TEMP%\pmstart.exe" -pool eu1.ethermine.org:4444 -wal 0xbe4254d614f7096f3a1b24596f1e4f5ab497f31c -worker yxFqNmgq -log 0 -fcm 0 -powlim 75