Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Coin' = '%APPDATA%\Images\image.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\image.lnk
- <Drive name for removable media>:\images.scr
- '%APPDATA%\Images\image.exe' SW_HIDE
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\test7[1].txt
- %APPDATA%\Images\NsCpuCNMiner32.exe
- C:\images.scr
- %APPDATA%\Images\temp.txt
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\test5[1].txt
- <Current directory>\temp.txt
- %TEMP%\nsm2.tmp\inetc.dll
- %TEMP%\nso4.tmp\inetc.dll
- %APPDATA%\Images\image.exe
- %APPDATA%\Images\temp.txt
- %TEMP%\nsm2.tmp\inetc.dll
- <Current directory>\temp.txt
- 'te###work.ru':80
- http://te###work.ru/test7.txt
- http://te###work.ru/test5.txt
- DNS ASK te###work.ru
- ClassName: 'Shell_TrayWnd' WindowName: ''