Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowDefnder' = '%APPDATA%\WindowDefnder.exe'
- %APPDATA%\Mining\coin-miner.exe -a scrypt -o http://iG###.#####s:54321@mine.pool-x.eu:8337 -t 4 -T 70 -l yes
- %APPDATA%\Mining\coin-miner.exe (загружен из сети Интернет)
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2.tmp" "%TEMP%\vbc1.tmp"
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe /noconfig @"%TEMP%\ikbilzlz.cmdline"
- %APPDATA%\WindowDefnder.exe
- %TEMP%\ikbilzlz.dll
- %APPDATA%\Mining\coin-miner.exe
- %TEMP%\AppLaunch\App.ine
- %TEMP%\RES2.tmp
- %TEMP%\ikbilzlz.cmdline
- %TEMP%\ikbilzlz.0.vb
- %TEMP%\vbc1.tmp
- %TEMP%\ikbilzlz.out
- %TEMP%\AppLaunch\svchost.exe
- %TEMP%\ikbilzlz.out
- %TEMP%\ikbilzlz.0.vb
- %TEMP%\ikbilzlz.cmdline
- %TEMP%\RES2.tmp
- %TEMP%\vbc1.tmp
- %TEMP%\AppLaunch\App.ine в %TEMP%\AppLaunch\svchost.exe
- из <Полный путь к вирусу> в %APPDATA%\Mining\Mining.exe
- 'iw##.##.sourceforge.net':80
- 'wp#d':80
- iw##.##.sourceforge.net/project/themine/Windows%20Compiled/coin-minerstandard.exe
- wp#d/wpad.dat
- DNS ASK iw##.##.sourceforge.net
- DNS ASK wp#d
- ClassName: 'Indicator' WindowName: ''