Техническая информация
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'taskost.exe' = '%APPDATA%\Microsoft\Internet Explorer\WinDrv\taskost.exe'
- %WINDIR%\legit.ini
- %WINDIR%\semilegit.ini
- %WINDIR%\s.exe
- %WINDIR%\w.exe
- %WINDIR%\sulfurious.dll
- %TEMP%\aut276d.tmp
- %APPDATA%\microsoft\internet explorer\windrv\taskost.exe
- %TEMP%\aut27ac.tmp
- %APPDATA%\microsoft\internet explorer\windrv\windrv.exe
- %APPDATA%\microsoft\internet explorer\windrv\taskost.exe
- %APPDATA%\microsoft\internet explorer\windrv\windrv.exe
- %TEMP%\aut276d.tmp
- %TEMP%\aut27ac.tmp
- 'xm#.###l.minergate.com':45560
- DNS ASK xm#.###l.minergate.com
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\w.exe'
- '%WINDIR%\s.exe'
- '%APPDATA%\microsoft\internet explorer\windrv\taskost.exe'
- '%APPDATA%\microsoft\internet explorer\windrv\windrv.exe' -a cryptonight -o stratum+tcp://xmr.pool.minergate.com:45560 -u preacher4x@gmail.com -p x -t 2
- '%APPDATA%\microsoft\internet explorer\windrv\windrv.exe' -a cryptonight -o stratum+tcp://xmr.pool.minergate.com:45560 -u preacher4x@gmail.com -p x -t 2 (со скрытым окном)