Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\explorer.lnk
- C:\miner\lksmn.bat
- C:\miner\ygrdd.vbs
- C:\miner\build.exe
- C:\miner\config.json
- C:\miner\db.rar
- C:\miner\rar.exe
- C:\miner\wkhrhy.vbs
- C:\miner\kygk.bat
- C:\miner\rar.exe
- C:\miner\wkhrhy.vbs
- ClassName: 'EDIT' WindowName: ''
- '<SYSTEM32>\wscript.exe' "C:\miner\ygrdd.vbs"
- 'C:\miner\rar.exe' e -p6882 db.rar
- '<SYSTEM32>\wscript.exe' "C:\miner\wkhrhy.vbs"
- '<SYSTEM32>\cmd.exe' /c tasklist /NH /FI "IMAGENAME eq taskmgr.exe"
- '<SYSTEM32>\tasklist.exe' /NH /FI "IMAGENAME eq taskmgr.exe"
- '<SYSTEM32>\powercfg.exe' -change -standby-timeout-ac 0
- '<SYSTEM32>\cmd.exe' /c ""C:\miner\kygk.bat" "
- '<SYSTEM32>\cmd.exe' /c ""C:\miner\lksmn.bat" "