Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '10f15f201612d15d23 PM1' = '%TEMP%\\{1549DF-HFSD7H-83HD76-HDSY093-GSOEPU0}\Windows Defender.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '10f15f201612d15d23 PM2' = '%TEMP%\\{1549DF-HFSD7H-83HD76-HDSY083-GSOEPU0}\Windows Update.exe'
- '%TEMP%\{1549DF-HFSD7H-83HD76-HDSY093-GSOEPU0}\Windows Defender.exe'
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1748
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1752
- '%TEMP%\{1549DF-HFSD7H-83HD76-HDSY083-GSOEPU0}\Windows Update.exe'
- '<Current directory>\runner.exe' "-a cryptonight -o stratum+tcp://xmr.pool.minergate.com:45560 -u minergatersm@gmail.com -p x"
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe' -a cryptonight -o stratum+tcp://xmr.pool.minergate.com:45560 -u minergatersm@gmail.com -p x
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe
- %TEMP%\System.exe
- <Current directory>\runner.exe
- %TEMP%\{1549DF-HFSD7H-83HD76-HDSY083-GSOEPU0}\Windows Update.exe
- %TEMP%\{1549DF-HFSD7H-83HD76-HDSY093-GSOEPU0}\Windows Defender.exe
- 'ba####.site88.net':80
- 'mi####atersm.usa.cc':80
- 'wp#d':80
- http://ba####.site88.net/virus/viwer.php?id#################
- http://mi####atersm.usa.cc//virus/miner.php?id####################
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK ba####.site88.net
- DNS ASK mi####atersm.usa.cc
- DNS ASK wp#d
- ClassName: 'Shell_TrayWnd' WindowName: ''