Техническая информация
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'Load' = '%HOMEPATH%\scvhot\scvhots.exe'
- %WINDIR%\microsoft.net\framework\v2.0.50727\csc.exe
- %HOMEPATH%\scvhot\scvhots.exe
- %TEMP%\tmpe81d.tmp.bat
- %HOMEPATH%\scvhot\scvhots.exe
- %TEMP%\tmpe81d.tmp.bat
- 'po##.#upportxmr.com':80
- 'po##.#upportxmr.com':80
- DNS ASK po##.#upportxmr.com
- ClassName: 'EDIT' WindowName: ''
- '%HOMEPATH%\scvhot\scvhots.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\tmpE81D.tmp.bat" "' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\csc.exe' -a cryptonight -o pool.supportxmr.com:80 -u 453ys3CV57Nbg2XCekHZdJRHyGd4uSB1oTuWEs5btLfsYDKE71XAmUVYybZXVBeZDS34zWxkWL6pNRNPPXHChq6CGwNa5j4 -p cpu --av=0 -t 1 --donate-level=1' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\tmpE81D.tmp.bat" "
- '%WINDIR%\syswow64\attrib.exe' +s +a +h %HOMEPATH%\scvhot
- '%WINDIR%\syswow64\attrib.exe' +s +a +h %HOMEPATH%\scvhot\*
- '%WINDIR%\microsoft.net\framework\v2.0.50727\csc.exe' -a cryptonight -o pool.supportxmr.com:80 -u 453ys3CV57Nbg2XCekHZdJRHyGd4uSB1oTuWEs5btLfsYDKE71XAmUVYybZXVBeZDS34zWxkWL6pNRNPPXHChq6CGwNa5j4 -p cpu --av=0 -t 1 --donate-level=1