Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ODX' = '%TEMP%\ODX\svchost.exe'
- '' (downloaded from the Internet)
- %TEMP%\nsp2.tmp
- %TEMP%\nsk3.tmp\System.dll
- %APPDATA%\1337\v3miner.exe
- %APPDATA%\1337\Loader.exe
- %TEMP%\ODX\svchost.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\Service[1].txt
- %TEMP%\ODX\Service.exe
- %TEMP%\nsk3.tmp\System.dll
- 'localhost':1036
- 'qo###sign.ml':80
- http://qo###sign.ml/ODX/Service.txt
- DNS ASK qo###sign.ml
- '%APPDATA%\1337\v3miner.exe'
- '%APPDATA%\1337\Loader.exe'
- '%TEMP%\ODX\svchost.exe'
- '%TEMP%\ODX\Service.exe' --max-cpu-usage=60 -o stratum+tcp://xmr.pool.minergate.com:45700 -u semenist@bk.ru -p x