Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\startpa.bat
- %ProgramFiles%\experience\copy.bat
- %ProgramFiles%\experience\startpa.bat
- %ProgramFiles%\experience\kadhiurenadasa.exe
- %ProgramFiles%\experience\sonis.vbs
- %ProgramFiles%\experience\starano.bat
- ClassName: 'EDIT' WindowName: ''
- '<SYSTEM32>\wscript.exe' "%ProgramFiles%\Experience\sonis.vbs"
- '%ProgramFiles%\experience\kadhiurenadasa.exe' --print-full --algo progpowz --url stratum+tcp://zano.luckypool.io:8877 --worker 1K --user ZxDNgDfJwkQdKUUtZFj9MncqcR6a5cfmqaFCQFotMDEvchYUQsiKWdLBsDs3HTNSGwY9NaLfoKpenjLF4wRyBnXM2L5T9Cih1 --pa...
- '<SYSTEM32>\cmd.exe' /c ""%ProgramFiles%\Experience\starano.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%ProgramFiles%\Experience\copy.bat" "
- '<SYSTEM32>\xcopy.exe' startpa.bat "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\". /Y
- '<SYSTEM32>\cmd.exe' /c ""%ProgramFiles%\Experience\starano.bat" "
- '<SYSTEM32>\timeout.exe' /t 5