Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\winlogon.exe.lnk
- %TEMP%\RarSFX0\svchost.exe --algo scrypt --s 6 --threads 2 --quiet --url http://li#####npool.org:9332 --userpass alphadelta.1:test
- %TEMP%\RarSFX0\hstart.exe /NOCONSOLE /SILENT "MINE 2 THREADS.bat"
- %APPDATA%\winlogon.exe
- <SYSTEM32>\cmd.exe /c "MINE 2 THREADS.bat"
- %TEMP%\RarSFX0\MINE 2 THREADS.bat
- %TEMP%\RarSFX0\pthreadGC2.dll
- %TEMP%\RarSFX0\svchost.exe
- %APPDATA%\winlogon.exe
- %TEMP%\RarSFX0\hstart.exe
- %TEMP%\RarSFX0\libcurl-4.dll
- %TEMP%\RarSFX0\MINE 2 THREADS.bat
- %TEMP%\RarSFX0\hstart.exe
- %TEMP%\RarSFX0\libcurl-4.dll
- %TEMP%\RarSFX0\hstart.exe
- 'li####inpool.org':9332
- DNS ASK li####inpool.org
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''