Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ngrun' = '"\ngru'
- %HOMEPATH%\Start Menu\Programs\Startup\WinUpdater.vbs
- '%APPDATA%\svchost.exe' -o stratum+tcp://xmr.crypto-pool.fr:3333 -u 46gA7bScFo3Zbua9fiHrTqT2UUCQ2AixAGTTWJAAnvhoax9L81FVGzV788mA5t7rHGgpp2Q3Y8GthfpBVQJgvUy812gqEed -p x
- %APPDATA%\1479220769_log.txt
- %APPDATA%\pools.txt
- %APPDATA%\svchost.exe
- 'xm#.##ypto-pool.fr':3333
- DNS ASK xm#.##ypto-pool.fr
- ClassName: 'Shell_TrayWnd' WindowName: ''