Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\Setup.exe
- '%PROGRAM_FILES%\svchost.exe' -a 5 -o http://po##.#0btc.com:8332 -u zlovredvreditel@yahoo.com -t 2
- '%HOMEPATH%\Start Menu\Programs\Startup\Setup.exe'
- %PROGRAM_FILES%\miner.dll
- %PROGRAM_FILES%\coinutil.dll
- %PROGRAM_FILES%\usft_ext.dll
- %PROGRAM_FILES%\openssl.dll
- %PROGRAM_FILES%\svchost.exe
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- %PROGRAM_FILES%\Company\NewProduct\Uninstall.ini
- %PROGRAM_FILES%\Company\NewProduct\Uninstall.exe
- %PROGRAM_FILES%\Company\NewProduct\Uninstall.exe
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- 'po##.50btc.com':8332
- DNS ASK po##.50btc.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'