2021.01.15 09:20

Trojan.winrule, BitCoinMiner

조회 수 271 추천 수 0 댓글 0
?

단축키

Prev이전 문서

Next다음 문서

크게 작게 위로 아래로 댓글로 가기 인쇄 첨부
?

단축키

Prev이전 문서

Next다음 문서

크게 작게 위로 아래로 댓글로 가기 인쇄 첨부

Trojan.winrule

 

*file
C:\Program Files\winrule\Uninstall.exe
C:\Program Files\winrule\WinRule.exe
C:\Program Files\winrule\WinRuleSync.exe
C:\Program Files\winrule\WinRuleSync_.exe
C:\Program Files\winrule\winruletask.exe
C:\Program Files\winrule\winruletask_.exe
C:\Program Files\winrule\WinRule_.exe

*reg_key
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Window Rules Manager
HKLM\SOFTWARE\okwinrule
HKLM\SYSTEM\CurrentControlSet\Services\WinRuleSvc
HKLM\SYSTEM\CurrentControlSet\Services\WinRuleSvc2

 

Trojan. BitCoinMiner

 

*file
c:\users\{USERNAME}\appdata\roaming\nscpucnminer\pools.txt
c:\users\{USERNAME}\appdata\roaming\nscpucnminer\nscpucnminer64.exe
c:\users\{USERNAME}\appdata\roaming\nscpucnminer\nscpucnminer32.exe
c:\users\{USERNAME}\appdata\roaming\img001.exe
c:\users\{USERNAME}\appdata\roaming\snappy\snappy.exe
c:\users\{USERNAME}\appdata\roaming\nsminer\img001.exe
c:\users\{USERNAME}\appdata\roaming\nsminer\img002.exe
c:\users\{USERNAME}\appdata\roaming\nsminer\nscpucnminer32.exe
c:\users\{USERNAME}\appdata\roaming\nsminer\pools.txt

*reg_key
HKCU\SOFTWARE\bifrost
HKCU\SOFTWARE\snappy

*reg_val
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\run | c:\users\{USERNAME}\appdata\roaming\nscpucnminer\img001.exe

 

11111.png

 


  1. PUP.YouTubeAdBlock, Grakat

  2. PUP. SoSoIm, MSNMonitor

  3. PUP.Mallapp, professional cleaning Software

  4. PUP.PCPurifier, Catered

  5. PUP.DriverDoc, RinoReader

  6. Adware.SpywareRemover, CloudGuard

  7. Adware.HPProtector, WeatherTool

  8. PUP.TorrentSearch, RegEasy

  9. PUP.HohoSearch, Popfreeka

  10. Adware.Linkury, Netfilter

  11. Trojan. RegistryTool, AdwareAlert

  12. PUP.UCalendar, WebInternet

  13. PUP. Guffins, PriceLess

  14. Adware.DVDVideoSoft, FileRubber

  15. Adware.CoolVerte, Grape

  16. Adware.dvdvideosoft, UniversalDriver

  17. Trojan.winrule, BitCoinMiner

  18. PUP.DealPly, MinerGate

  19. Trojan.TechAgent, Ghapoly

  20. Adware.BlueMoon, FileSubmit

Board Pagination Prev 1 2 3 4 5 6 ... 8 Next
/ 8
XE Login