Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'spoolsv.exe' = '%HOMEPATH%\Templates\svchost.exe'
- '%HOMEPATH%\Templates\spoolsv.exe' -g no -o http://ID###########ilk:6at2ZuRt@bitcoinpool.com:8334
- '%HOMEPATH%\Templates\spoolsv.exe' (загружен из сети Интернет)
- %HOMEPATH%\Templates\phatk.ptx
- %HOMEPATH%\Templates\spoolsv.exe
- %HOMEPATH%\Templates\usft_ext.dll
- %HOMEPATH%\Templates\svchost.exe
- %HOMEPATH%\Templates\miner.dll
- 'sh###send.com':80
- sh###send.com/download/q9atm
- sh###send.com/download/1vupa
- sh###send.com/download/by5qh
- sh###send.com/download/eqlo5
- DNS ASK sh###send.com
- ClassName: 'Indicator' WindowName: '(null)'