Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdater' = 'c:\Ufasoft\Coin\start.exe'
- 'C:\Ufasoft\Coin\coin-miner.exe' -a scrypt -o stratum+tcp://gigahash.wemineltc.com:3334 -u sarah.sara -p 12345 -T 100 -t 4 -g No
- '<SYSTEM32>\wscript.exe' "C:\Ufasoft\Coin\run.vbs"
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\tmp1.tmp.bat" "
- C:\Ufasoft\Coin\scrypt.cl
- C:\Ufasoft\Coin\phatk.cl
- C:\Ufasoft\Coin\run.vbs
- C:\Ufasoft\Coin\start.exe
- %TEMP%\tmp1.tmp.bat
- C:\Ufasoft\Coin\usft_ext.dll
- C:\Ufasoft\Coin\coineng.dll
- C:\Ufasoft\Coin\coin-miner.exe
- C:\Ufasoft\Coin\coinutil.dll
- C:\Ufasoft\Coin\mpir.dll
- C:\Ufasoft\Coin\miner.dll
- %TEMP%\tmp1.tmp.bat
- 'gi#####h.wemineltc.com':3334
- DNS ASK gi#####h.wemineltc.com
- ClassName: 'Indicator' WindowName: '(null)'