Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'miner' = '<SYSTEM32>\miner.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'miner' = '<SYSTEM32>\miner.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'miner' = '%WINDIR%\SysWOW64\miner.exe'
- '<SYSTEM32>\attrib.exe' +h +s +r pthreadGC2.dll
- '<SYSTEM32>\attrib.exe' +h +s +r systen.exe
- '<SYSTEM32>\attrib.exe' +h +s +r "%TEMP%\1.tmp\miner.cmd"
- '<SYSTEM32>\attrib.exe' +h +s +r libcurl-4.dll
- '<SYSTEM32>\attrib.exe' +h +s +r Java.exe
- '<SYSTEM32>\reg.exe' add "hklm\software\microsoft\windows\currentversion\run" /v "miner" /t reg_sz /d "%WINDIR%\SysWOW64\miner.exe" /f
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\miner.cmd" "
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" /v "miner" /t reg_sz /d "<SYSTEM32>\miner.exe" /f
- '<SYSTEM32>\reg.exe' add "hklm\software\microsoft\windows\currentversion\run" /v "miner" /t reg_sz /d "<SYSTEM32>\miner.exe" /f
- %TEMP%\1.tmp\miner.cmd
- %TEMP%\1.tmp\miner.cmd
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'