Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\skitonma.bat
- %ProgramFiles%\mithrander\cryonic.bat
- %ProgramFiles%\mithrander\skitonma.bat
- %ProgramFiles%\mithrander\nuklasherinmashni.exe
- %ProgramFiles%\mithrander\cikolpanima.vbs
- %ProgramFiles%\mithrander\mithikular.bat
- ClassName: 'EDIT' WindowName: ''
- '<SYSTEM32>\wscript.exe' "%ProgramFiles%\mithrander\cikolpanima.vbs"
- '%ProgramFiles%\mithrander\nuklasherinmashni.exe' --print-full --algo progpowz --url stratum+tcp://zano.luckypool.io:8877 --worker ANK1 --user iZ1UfMDczF6dyzkr6NByGRQK98z2SS9BsVrqeVJGh8qMMgT77uzBBjQcuGUXzhd9ksUGaH7ZU26pjXcGQWS9tMWA3oF7gHvUYuK2...
- '<SYSTEM32>\cmd.exe' /c ""%ProgramFiles%\mithrander\mithikular.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%ProgramFiles%\mithrander\cryonic.bat" "
- '<SYSTEM32>\xcopy.exe' skitonma.bat "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\". /Y
- '<SYSTEM32>\cmd.exe' /c ""%ProgramFiles%\mithrander\mithikular.bat" "
- '<SYSTEM32>\timeout.exe' /t 5