Техническая информация
- <SYSTEM32>\notepad.exe
- %APPDATA%\google\libs\wr64.sys
- %APPDATA%\google\libs\g.log
- %TEMP%\pnotubmf.tmp
- 'xm#.#miners.com':2222
- 'xm#.#miners.com':2222
- DNS ASK xm#.#miners.com
- '<SYSTEM32>\cmd.exe' /c wmic PATH Win32_VideoController GET Name, VideoProcessor > "%APPDATA%\Google\Libs\g.log"
- '<SYSTEM32>\wbem\wmic.exe' PATH Win32_VideoController GET Name, VideoProcessor
- '<SYSTEM32>\notepad.exe' etjpsxquybuiivtk 6E3sjfZq2rJQaxvLPmXgsA4f0StS9pic9Xw++oZ1mnasCD7XnRLS04n/3PSQs4Y84pH6HdXcfRXqeTwPYKLEtUkC6Mth3tjZxXmSfOgx0xy7c23enKxSdqFAk9K3UrEWZoLSMt5i9D16IpPCEz3BlwKyUcuKSy7D78zChKJucKpBVe6m...