2021.01.15 09:20

Trojan.winrule, BitCoinMiner

조회 수 271 추천 수 0 댓글 0
?

단축키

Prev이전 문서

Next다음 문서

크게 작게 위로 아래로 댓글로 가기 인쇄 첨부
?

단축키

Prev이전 문서

Next다음 문서

크게 작게 위로 아래로 댓글로 가기 인쇄 첨부

Trojan.winrule

 

*file
C:\Program Files\winrule\Uninstall.exe
C:\Program Files\winrule\WinRule.exe
C:\Program Files\winrule\WinRuleSync.exe
C:\Program Files\winrule\WinRuleSync_.exe
C:\Program Files\winrule\winruletask.exe
C:\Program Files\winrule\winruletask_.exe
C:\Program Files\winrule\WinRule_.exe

*reg_key
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Window Rules Manager
HKLM\SOFTWARE\okwinrule
HKLM\SYSTEM\CurrentControlSet\Services\WinRuleSvc
HKLM\SYSTEM\CurrentControlSet\Services\WinRuleSvc2

 

Trojan. BitCoinMiner

 

*file
c:\users\{USERNAME}\appdata\roaming\nscpucnminer\pools.txt
c:\users\{USERNAME}\appdata\roaming\nscpucnminer\nscpucnminer64.exe
c:\users\{USERNAME}\appdata\roaming\nscpucnminer\nscpucnminer32.exe
c:\users\{USERNAME}\appdata\roaming\img001.exe
c:\users\{USERNAME}\appdata\roaming\snappy\snappy.exe
c:\users\{USERNAME}\appdata\roaming\nsminer\img001.exe
c:\users\{USERNAME}\appdata\roaming\nsminer\img002.exe
c:\users\{USERNAME}\appdata\roaming\nsminer\nscpucnminer32.exe
c:\users\{USERNAME}\appdata\roaming\nsminer\pools.txt

*reg_key
HKCU\SOFTWARE\bifrost
HKCU\SOFTWARE\snappy

*reg_val
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\run | c:\users\{USERNAME}\appdata\roaming\nscpucnminer\img001.exe

 

11111.png

 


List of Articles
번호 제목 글쓴이 날짜 조회 수
» Trojan.winrule, BitCoinMiner file ezclean 2021.01.15 271
14 Trojan.TweakBit file ezclean 2021.02.17 3861
13 Trojan.ShopForRewards file ezclean 2021.02.18 227
12 Trojan.nscpucnminer file ezclean 2021.02.23 5639
11 Trojan.KaZaA file ezclean 2021.03.19 561
10 Trojan.ImageCropResize file ezclean 2021.04.05 615
9 Trojan.HSM file ezclean 2021.02.16 351
8 Trojan.HavijPro file ezclean 2021.04.22 1002
7 Trojan.DVD Region+CSS Free file ezclean 2021.03.22 275
6 Trojan.Clocker file ezclean 2021.02.25 1917
5 Trojan.Clocker file ezclean 2021.04.28 1417
4 Trojan.Cain file ezclean 2021.02.19 174
3 trojan.ASRF, DTeroVDTeroV file ezclean 2020.11.10 78
2 Trojan. remote manipulator system file ezclean 2021.03.17 125
1 Hacktool.TeraBIT Virus Maker file ezclean 2021.04.30 6914
Board Pagination Prev 1 Next
/ 1
XE Login