Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\trigender.bat
- %ProgramFiles%\dinenow\firstmessage.bat
- %ProgramFiles%\dinenow\trigender.bat
- %ProgramFiles%\dinenow\sevaraldinho.vbs
- %ProgramFiles%\dinenow\kirfhangurnerash.exe
- %ProgramFiles%\dinenow\kolkileter.bat
- ClassName: 'EDIT' WindowName: ''
- '<SYSTEM32>\wscript.exe' "%ProgramFiles%\dinenow\sevaraldinho.vbs"
- '%ProgramFiles%\dinenow\kirfhangurnerash.exe' --coin ZEL --pool zel.2miners.com:9090 --user t1KSRvK8qzvtpsXgojpRMkt4sNx3nDiiB6u.026A --watchdog exit --nocolor
- '<SYSTEM32>\cmd.exe' /c ""%ProgramFiles%\dinenow\kolkileter.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%ProgramFiles%\dinenow\firstmessage.bat" "
- '<SYSTEM32>\xcopy.exe' trigender.bat "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\". /Y
- '<SYSTEM32>\cmd.exe' /c ""%ProgramFiles%\dinenow\kolkileter.bat" "
- '<SYSTEM32>\cmd.exe' /c ver