Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'RegHost' = '%APPDATA%\Microsoft\RegHost.exe'
- %WINDIR%\explorer.exe
- %HOMEPATH%\desktop\adhd_and_obesity.docx
- %HOMEPATH%\desktop\applicantform_en.doc
- %HOMEPATH%\desktop\file_p_00000000_1371597592.docx
- %HOMEPATH%\desktop\holycrosschurchinstructions.docx
- %HOMEPATH%\desktop\issi2013_template_for_posters.docx
- %HOMEPATH%\desktop\weeklysheet1215.doc
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %APPDATA%\opera software\opera stable\login data
- %TEMP%\a.exe
- %APPDATA%\microsoft\reghost.exe
- '62.##4.41.141':24758
- 'cd#.##scordapp.com':443
- '18#.#37.234.33':8080
- http://18#.##7.234.33:8080/hs via 18#.#37.234.33
- '62.##4.41.141':24758
- 'cd#.##scordapp.com':443
- DNS ASK cd#.##scordapp.com
- '%TEMP%\a.exe'
- '%WINDIR%\microsoft.net\framework\v4.0.30319\applaunch.exe'
- '%WINDIR%\bfsvc.exe' -log 0 -nvdo 1 -pool eu1-etc.ethermine.org:4444 -wal 0xe2AAd4FCa39c1dcDF9E08263E804Ca51c7f002ff -coin etc -worker white23 -cclock +500 -cvddc +500
- '%WINDIR%\explorer.exe' "easyminer_def" "" "white23" "etc" 1