Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\desktop.ini.lnk
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%APPDATA%\System32\WinRing0x64.sys'
- 'WinRing0_1_2_0' %APPDATA%\System32\WinRing0x64.sys
- %APPDATA%\windows\odbcad64.dll
- %APPDATA%\system32\config.json
- %APPDATA%\system32\svchost.exe
- %APPDATA%\windows\odbcad64.dll
- 'xm#####.nanopool.org':14444
- 'xm#####.nanopool.org':14444
- DNS ASK xm#####.nanopool.org
- ClassName: 'EDIT' WindowName: ''
- '%APPDATA%\windows\odbcad64.dll' -p123
- '%APPDATA%\system32\svchost.exe'
- '%WINDIR%\syswow64\cmd.exe' /c wmic process where ExecutablePath='%HomeDrive%\\Users\\%username%\\AppData\\Roaming\\system32\\svchost.exe' delete' (with hidden window)
- '%APPDATA%\windows\odbcad64.dll' -p123' (with hidden window)
- '%APPDATA%\system32\svchost.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c wmic process where ExecutablePath='%HomeDrive%\\Users\\%username%\\AppData\\Roaming\\system32\\svchost.exe' delete
- '%WINDIR%\syswow64\wbem\wmic.exe' process where ExecutablePath='C:\\Users\\user\\AppData\\Roaming\\system32\\svchost.exe' delete