Technical Information
- %WINDIR%\explorer.exe
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: '', WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- %PROGRAMDATA%\mntemp
- '85.##7.171.197':4672
- ClassName: '18467-41' WindowName: ''
- '%WINDIR%\explorer.exe' -B --url=85.217.171.197:4672 -u upd -p upd --nicehash -t 1