Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdater' = 'c:\Ufasoft\Coin\start.exe'
- 'C:\Ufasoft\Coin\coin-miner.exe' -a scrypt -o stratum+tcp://ltc.ghash.io:3333 -u mrlion.xx -p 200920751 -T 100 -t 2 -g No
- '<SYSTEM32>\wscript.exe' "C:\Ufasoft\Coin\run.vbs"
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\tmp1.tmp.bat" "
- C:\Ufasoft\Coin\run.vbs
- C:\Ufasoft\Coin\usft_ext.dll
- C:\Ufasoft\Coin\start.exe
- %TEMP%\tmp1.tmp.bat
- C:\Ufasoft\Coin\mpir.dll
- C:\Ufasoft\Coin\coineng.dll
- C:\Ufasoft\Coin\coin-miner.exe
- C:\Ufasoft\Coin\miner.dll
- C:\Ufasoft\Coin\coinutil.dll
- %TEMP%\tmp1.tmp.bat
- 'lt#.#hash.io':3333
- DNS ASK lt#.#hash.io
- ClassName: 'Indicator' WindowName: '(null)'