Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdater' = 'c:\Ufasoft\Coin\Chrome.exe'
- '<SYSTEM32>\ntvdm.exe' -f -i1
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\tmp1.tmp.bat" "
- %TEMP%\tmp1.tmp.bat
- C:\Ufasoft\Coin\run.vbs
- C:\Ufasoft\Coin\cryp.dll
- C:\Ufasoft\Coin\Chrome.exe
- %WINDIR%\Temp\scs3.tmp
- %WINDIR%\Temp\scs2.tmp
- C:\Ufasoft\Coin\coinutil.dll
- C:\Ufasoft\Coin\coineng.dll
- C:\Ufasoft\Coin\coin-miner.exe
- C:\Ufasoft\Coin\usft_ext.dll
- C:\Ufasoft\Coin\mpir.dll
- C:\Ufasoft\Coin\miner.dll
- %TEMP%\tmp1.tmp.bat
- %WINDIR%\Temp\scs3.tmp
- %WINDIR%\Temp\scs2.tmp
- 'pa###bin.com':80
- 'wp#d':80
- pa###bin.com/raw.php?i=########
- wp#d/wpad.dat
- DNS ASK pa###bin.com
- DNS ASK wp#d
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-bf8.bfc.390001'