Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Taakj2005100' = 'c:\Taakj2005\Coin\Taakj2005.exe'
- 'C:\Taakj2005\Coin\Start_Mine.exe' --url=stratum+tcp://power.wemineltc.com:3333 --userpass=lover83.raid83:love112233
- '<SYSTEM32>\wscript.exe' "C:\Taakj2005\Coin\run.vbs"
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\tmp1.tmp.bat" "
- ClassName: 'OLLYDBG' WindowName: '(null)'
- C:\Taakj2005\Coin\run.vbs
- %TEMP%\tmp1.tmp.bat
- C:\Taakj2005\Coin\Taakj2005.exe
- C:\Taakj2005\Coin\zlib1.dll
- C:\Taakj2005\Coin\Start_Mine.exe
- C:\Taakj2005\Coin\libcurl-4.dll
- C:\Taakj2005\Coin\pthreadGC2.dll
- %TEMP%\tmp1.tmp.bat
- 'po###.wemineltc.com':3333
- DNS ASK po###.wemineltc.com
- ClassName: 'Indicator' WindowName: '(null)'